You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Three RED-first fixes, each pinned by failing tests on main:
1. resource (FileResolver.Load, HIGH): opening a FIFO (or other special
file) in the workspace with no writer blocked the @-resource load in
the syscall forever — ctx is not observable there — and the FIFO's
zero size passed the cap, leaving the subsequent ReadAll unbounded.
The open now uses O_NONBLOCK (a no-op for regular files) and
non-regular files are rejected outright.
2. mcpclient (readLoop routing, HIGH): any parseable line was routed by
id — a spec-legal server-to-client REQUEST (JSON-RPC 2.0: carries
"method") whose id collided with an in-flight call delivered
{result:null} to the waiter and the real response was dropped when it
arrived. Lines carrying "method" are now skipped: they are never
responses to our calls.
3. mcpclient (CallTool envelope + notes, MED): a multi-item result
[envelope, trailing note] was joined with "\n" before the envelope
probe — the trailing data failed the JSON parse and the RAW envelope
JSON, including artifact refs that must never reach the model
unvalidated, was delivered as plain text, bypassing artifact-ref
validation entirely. Each text item is now parsed for the envelope;
non-envelope items are preserved after the rendered form (through the
per-server result cap).
Dropped after honest verification: the claimed base64url blind spot in
the unread-script decode pass — for realistic payloads the leading
pre-boundary run still decodes the injection phrase, and no payload
could be constructed where every run stays under the 24-char candidate
threshold. No RED, no fix.
0 commit comments