fix: 22 validated bug fixes from adversarial bug hunt - #272
Merged
Merged
Conversation
WebSocket/session: torn frames after write timeout (dead conn state
re-created while a parked sender blocks) - dead latch is now sticky;
validateSessionToken mints before compare on 401 probes (file rewrite +
token rotation under attacker control) - compare/deny before any write;
strict path on legacy sessions now denies outright. saveLocked restores
Messages/boundary on failed save (permanent ErrConflict). VectorIndex
Search embeds outside the mutex.
Config/artifact: expandEnv no longer eats the byte after a bare '$';
ParseEnvelope strips UTF-8 BOM (envelope JSON with file:// refs was
delivered unvalidated).
Danger/approvals: denylist match collapses internal whitespace
("git push" bypass); trustAll honors TrustShortcutAllowed (excluded
classes always prompt - 3 legacy tests re-pinned to the documented
contract); trust grants record approvals so friction engages; ClassifyURL
strips trailing-dot hostnames (169.254.169.254.).
Tools: browser lazy-init race (mutex); browser snapshot rune-boundary
truncation; multi_grep surfaces root walk errors; batch_patch preview
renders truthful hunks at the real offset; bg_start distinguishes
malformed JSON from empty command.
Hardening: mcpclient closes stdout pipe on Start failure; redact detects
fused secret names (MYAPITOKEN); session audit load fails closed on
unreadable files (no history rewrite); JSON session export omits
auth_token; budget RecordExternal rejects/clamps non-finite or
overflowing external costs; skills cache GCs other projects' entries;
AddFact trims once so merge detection, dedup, and corpus agree.
Adversarial diff review: blockers fixed (strict-bootstrap dead path,
gofmt); low findings noted for follow-up.
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
odek | 206bfec | Commit Preview URL Branch Preview URL |
Sep 27 2026, 09:06 AM |
- session: saveLocked snapshot is now an element copy — trimToFileCapLocked compacts the slice in place, so a header-copy snapshot restored shifted contents after a failed post-trim save. - redact: fused-name suffix match uses >= so bare PASSWORD/TOKEN/SECRET env names register as sensitive. - serve: dead-latched WS write states are swept past 4096 entries (dead + not held by a parked sender), bounding memory on connection-churning clients; the sticky-dead invariant below the cap is unchanged. Deferred (next hunt): budget clamp can silently mask real overruns under repeated negative external deltas (needs per-delta clamp + event); patchPreviewDiff hunk header byte/line math; fused-name plurals.
Test files and functions renamed from bug-hunt workflow markers to descriptive names (bughunt/redbugs/bugfix/TestRED_ dropped); comments rewritten to state current behavior as invariants instead of narrating the historical defect. Semantics unchanged; all touched packages green.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes 22 bugs (1 high, 11 medium, 10 low) found by a 6-agent adversarial bug hunt, all validated RED-first (failing test before fix, green after), plus an adversarial diff review whose blockers are addressed in this PR.
High
Medium
$("cost: $ 5" → "cost: $5").Low (10)
mcpclient stdout-pipe leak on Start failure; redact fused secret names (MYAPITOKEN); session audit fail-closed on unreadable files; JSON export omits auth_token; trust grants record approvals (friction engages); ClassifyURL trailing-dot hostnames; browser snapshot rune-boundary truncation; batch_patch truthful preview hunks; bg_start malformed-JSON error message; memory AddFact consistent trim.
Test plan
go build ./...,go vet ./...,go test ./internal/...,go test ./cmd/odek/(93s), race runs on changed packages.