fix(tools): bound file primitive processing before reads and edits - #6757
Merged
Merged
Conversation
added 2 commits
September 29, 2026 05:26
Reserve tools/file.rs and tools/file/tests.rs for reports 64/129. Plan reuses the existing validated regular-file opener and mutation owner, adds a separate 16 MiB processing bound, and preserves lossless edit semantics. Implementation and all qualification gates are pending; this checkpoint claims no test success.
Reuse validated regular-file handles and a 16 MiB whole-source cap. Poll read cancellation, select line ranges without per-line allocation, and reject replacement/line-ending growth before atomic mutation while preserving existing byte and receipt contracts. Validation: production library check passed; 36 focused Rust tests passed, 0 failed/ignored; npm test 670 passed; npm run check:web passed. Two independent source reviews plus formatting/diff checks passed. First test build caught a test-only metadata move; corrected to a borrow before the passing retry. Post-run npm counter was corrected for Node26 spec output using existing logs, without rerunning passing gates.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No-Issue: verified file primitive processing-limit findings from the current audit.
The lowercase read/write/edit primitives previously loaded complete files before applying response limits and could block when a target was a pipe. Reuse the existing validated regular-file opener, bound actual source reads to a 16 MiB processing cap, and check cancellation between chunks. Select read ranges without allocating one pointer per newline. Check replacement and restored-line-ending growth before allocation or atomic replacement, while preserving raw bytes, BOMs, line endings and mutation receipts.
The processing cap is separate from the model-visible output budget. These primitives now refuse nonregular or multiply linked targets and files over the processing cap with actionable errors. Hidden compatibility readers and PDF extraction retain their existing behavior; the cap is not a total-process memory guarantee. Once atomic replacement starts, report its actual completion.
Validation: production library check passed. npm test: 670 passed; npm run check:web: passed. Two independent source reviews, formatting and diff checks passed. All 36 focused Rust tests passed (0 failed, 0 ignored), including seven new bounds/cancellation/nonregular-target/growth regressions and existing raw-byte/line-ending/receipt/page-union coverage. The first test build found a test-only metadata move; a borrowing correction passed the retry. The npm counter was reconciled against Node26 spec-format output after both gates exited zero; no passing gate was repeated.