Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -61,6 +61,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
- LSP frame header parsing is now bounded on both single-line length and header count per frame, closing an unbounded-memory-growth path from a malicious or malfunctioning spawned LSP server. (#457, #463)
- CodeQL workflow now triggers on `pull_request` instead of `pull_request_target`, closing a "pwn request" path where a fork PR's `build.rs`/proc-macros ran during `autobuild` with a base-repository `GITHUB_TOKEN` and could poison the default-branch Actions cache. (#464, #469)
- **Workspace-roots validation now fails closed** — Breaking change: the diagnostics pump and rename/code-action edit filtering previously allowed unrestricted access when no workspace roots were configured; both now reject with no unrestricted opt-in, so embedders must call `Translator::set_workspace_roots` with real roots before serving any path-taking request. (#449)
- Position-encoding conversion no longer amplifies one LSP response into unbounded disk reads: line text is now cached and read incrementally per response, and a per-response byte budget bounds the disk I/O any navigation/references/workspace-symbol/call-hierarchy/inlay-hints/rename response can trigger; references, goto-X, and workspace-symbol are additionally capped on result count. (#474, #486)

## [0.5.0] - 2026-09-06

Expand Down
466 changes: 459 additions & 7 deletions crates/mcpls-core/src/bridge/state.rs

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions crates/mcpls-core/src/bridge/translator/diagnostics.rs
Original file line number Diff line number Diff line change
Expand Up @@ -243,6 +243,7 @@ impl Translator {
tracker: tracker.clone(),
// Never read here -- see `EMPTY_WORKSPACE_ROOTS`'s doc.
workspace_roots: EMPTY_WORKSPACE_ROOTS.clone(),
line_cache: super::encoding_ctx::new_line_cache(),
};
let mut result = Vec::with_capacity(diag_info.diagnostics.len());
for d in &diag_info.diagnostics {
Expand Down
25 changes: 25 additions & 0 deletions crates/mcpls-core/src/bridge/translator/dto.rs
Original file line number Diff line number Diff line change
Expand Up @@ -97,13 +97,25 @@ pub struct HoverResult {
pub struct DefinitionResult {
/// Locations of the definition.
pub locations: Vec<Location>,
/// Whether `locations` was capped below the LSP server's full response
/// (see `MAX_NORMALIZED_LOCATIONS`, #474) -- if `true`, more locations
/// exist than are returned here. Omitted (defaults to `false`) when
/// serialized.
#[serde(default, skip_serializing_if = "is_false")]
pub truncated: bool,
}

/// Result of a references request.
#[derive(Debug, Clone, Serialize, Deserialize, JsonSchema)]
pub struct ReferencesResult {
/// Locations of all references.
pub locations: Vec<Location>,
/// Whether `locations` was capped below the LSP server's full response
/// (see `MAX_NORMALIZED_LOCATIONS`, #474) -- if `true`, more references
/// exist than are returned here. Omitted (defaults to `false`) when
/// serialized.
#[serde(default, skip_serializing_if = "is_false")]
pub truncated: bool,
}

/// Diagnostic severity.
Expand Down Expand Up @@ -276,6 +288,13 @@ pub struct WorkspaceSymbol {
pub struct WorkspaceSymbolResult {
/// List of symbols found.
pub symbols: Vec<WorkspaceSymbol>,
/// Whether more symbols matched than are returned in `symbols` -- set
/// whenever any are dropped, whether by the caller's own smaller
/// `limit` or by the server-side maximum it's clamped to (see
/// `MAX_NORMALIZED_LOCATIONS`, #474); this does not distinguish which of
/// the two caused it. Omitted (defaults to `false`) when serialized.
#[serde(default, skip_serializing_if = "is_false")]
pub truncated: bool,
}

/// A single code action.
Expand Down Expand Up @@ -454,6 +473,12 @@ pub struct SignatureHelpResult {
pub struct LocationsResult {
/// Locations found.
pub locations: Vec<Location>,
/// Whether `locations` was capped below the LSP server's full response
/// (see `MAX_NORMALIZED_LOCATIONS`, #474) -- if `true`, more locations
/// exist than are returned here. Omitted (defaults to `false`) when
/// serialized.
#[serde(default, skip_serializing_if = "is_false")]
pub truncated: bool,
}

/// A single inlay hint entry.
Expand Down
Loading
Loading