Skip to content

fix(tools): bound file primitive processing before reads and edits - #6757

Merged
Hmbown merged 2 commits into
mainfrom
fix/bounded-file-contract-io
Sep 29, 2026
Merged

Hmbown merged 2 commits into
mainfrom
fix/bounded-file-contract-io

Conversation

@Hmbown

@Hmbown Hmbown commented Sep 29, 2026

Copy link
Copy Markdown
Owner

No-Issue: verified file primitive processing-limit findings from the current audit.

The lowercase read/write/edit primitives previously loaded complete files before applying response limits and could block when a target was a pipe. Reuse the existing validated regular-file opener, bound actual source reads to a 16 MiB processing cap, and check cancellation between chunks. Select read ranges without allocating one pointer per newline. Check replacement and restored-line-ending growth before allocation or atomic replacement, while preserving raw bytes, BOMs, line endings and mutation receipts.

The processing cap is separate from the model-visible output budget. These primitives now refuse nonregular or multiply linked targets and files over the processing cap with actionable errors. Hidden compatibility readers and PDF extraction retain their existing behavior; the cap is not a total-process memory guarantee. Once atomic replacement starts, report its actual completion.

Validation: production library check passed. npm test: 670 passed; npm run check:web: passed. Two independent source reviews, formatting and diff checks passed. All 36 focused Rust tests passed (0 failed, 0 ignored), including seven new bounds/cancellation/nonregular-target/growth regressions and existing raw-byte/line-ending/receipt/page-union coverage. The first test build found a test-only metadata move; a borrowing correction passed the retry. The npm counter was reconciled against Node26 spec-format output after both gates exited zero; no passing gate was repeated.

CodeWhale Bot added 2 commits September 29, 2026 05:26
Reserve tools/file.rs and tools/file/tests.rs for reports 64/129. Plan reuses the existing validated regular-file opener and mutation owner, adds a separate 16 MiB processing bound, and preserves lossless edit semantics. Implementation and all qualification gates are pending; this checkpoint claims no test success.
Reuse validated regular-file handles and a 16 MiB whole-source cap. Poll read cancellation, select line ranges without per-line allocation, and reject replacement/line-ending growth before atomic mutation while preserving existing byte and receipt contracts.

Validation: production library check passed; 36 focused Rust tests passed, 0 failed/ignored; npm test 670 passed; npm run check:web passed. Two independent source reviews plus formatting/diff checks passed. First test build caught a test-only metadata move; corrected to a borrow before the passing retry. Post-run npm counter was corrected for Node26 spec output using existing logs, without rerunning passing gates.
Copilot AI balanced review requested due to automatic review settings September 29, 2026 13:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Hmbown
Hmbown merged commit cb95c5b into main Sep 29, 2026
35 checks passed
@Hmbown
Hmbown deleted the fix/bounded-file-contract-io branch September 29, 2026 17:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants