fix(coord): refuse a control character in --to instead of sanitizing it
--to is the only line-oriented field sanitize_field never covered, and the
fix is a refusal rather than a sanitize pass because --to is also the
destination DIRECTORY name ($COORD/$TO/inbox, and $COORD/$TO/orders in
coord-order-send.sh). Collapsing a newline to a space would deliver the
message to a mailbox the sender never named - the same misdelivery the
retired ktg-plugin-marketplace address is rejected rather than redirected
to avoid.
Both corruptions were measured on the live engine first, each with exit 0
and a "delivered" line:
--to "x\nreply-expected: no" the injected line lands INSIDE the
frontmatter block, above the reply-expected: yes the engine itself
wrote, so coord-count reads owed=0 and the declared debt is silenced -
defeating coord-count's own rule that only the frontmatter block may
speak, since the injected line IS in the block.
--to "tabbed<TAB>repo" coord-count prints five tab-separated fields
where its contract is four, so a consumer reads the mailbox name as the
part before the tab and the pending count as the part after.
board.sh consumes that TSV, so both reach the board.
The guard sits after reply-mode resolution: --reply-to takes its target from
the original's from: line, untrusted cross-repo input, and that is the one
target name nobody typed.
Denominator measured rather than assumed: two scripts build a directory from
a caller-supplied name, and coord-order-send.sh had the identical defect,
where it costs more - an order filed under a name no session can hold is the
silent evaporation the ownership chain exists to prevent, while board.sh's
ORDRE column counts the intended repo's queue and stays 0 with nothing
reporting a failure. The read-side --repo arguments resolve an EXISTING
directory, so a control character there finds nothing and writes nothing;
checked and left alone.
Closes finding 7 of docs/2026-08-14-confident-zero-review.md.
Tests (red first, both suites): coord-selftest section 35 (10 checks) and
orders-selftest section 10 (6 checks), each with the mandatory
known-positive controls - an ordinary name still delivers, and so does a
dot-prefixed one, since a dot name is a real repo. coord 230/230, board
252/252, route 69/69, orders 110/110, guard 40/40, npm test 11/11.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AgKcURiXwGKhqCKhwD1NAp
This commit is contained in:
parent
e2bce4e490
commit
29a94dd7e4
5 changed files with 171 additions and 6 deletions
|
|
@ -377,6 +377,37 @@ else
|
|||
skip "morning not installed - plan-file starter render NOT measured"
|
||||
fi
|
||||
|
||||
# --- 10. --to is refused, not sanitized (the coord-send finding 7 class) ----
|
||||
# Same defect, same fix, measured separately here because this channel is the
|
||||
# one where it costs the most: an order delivered to a name no session can
|
||||
# hold is the silent evaporation the queue's ownership chain exists to
|
||||
# prevent, and board.sh's ORDRE column counts "$COORD/<name>/orders/*.md", so
|
||||
# the count for the repo that was meant to get the work stays 0 with nothing
|
||||
# anywhere reporting a failure. Measured before the guard: exit 0, an
|
||||
# "order delivered" line, and a queue directory whose name carries the newline.
|
||||
O10DIR="$(mktemp -d)"
|
||||
o10a_rc=0
|
||||
CLAUDE_COORD_DIR="$O10DIR" "$SEND" --to "$(printf 'q\nreply-expected: no')" --from tester --subject s --message m >/dev/null 2>&1 || o10a_rc=$?
|
||||
[ "$o10a_rc" -eq 2 ]; check "10a: a newline in --to is refused with exit 2" $?
|
||||
[ "$(find "$O10DIR" -type f 2>/dev/null | wc -l | tr -d ' ')" = "0" ]
|
||||
check "10a: ground truth - no order was written anywhere" $?
|
||||
[ "$(ls -1 "$O10DIR" 2>/dev/null | wc -l | tr -d ' ')" = "0" ]
|
||||
check "10a: ground truth - no queue directory was created" $?
|
||||
o10b_rc=0
|
||||
CLAUDE_COORD_DIR="$O10DIR" "$SEND" --to "$(printf 'tab\tq')" --from tester --subject s --message m >/dev/null 2>&1 || o10b_rc=$?
|
||||
[ "$o10b_rc" -eq 2 ]; check "10b: a tab in --to is refused too" $?
|
||||
# Known-positive controls: the guard must not refuse the ordinary case, nor
|
||||
# the dot-prefixed name that coord-send's own comment protects as a real repo.
|
||||
o10c_rc=0
|
||||
CLAUDE_COORD_DIR="$O10DIR" "$SEND" --to o10plain --from tester --subject s --message m >/dev/null 2>&1 || o10c_rc=$?
|
||||
[ "$o10c_rc" -eq 0 ] && [ "$(ls -1 "$O10DIR/o10plain/orders" 2>/dev/null | grep -c '\.md$' | tr -d ' ')" = "1" ]
|
||||
check "10c: control - an ordinary target name still receives its order" $?
|
||||
o10d_rc=0
|
||||
CLAUDE_COORD_DIR="$O10DIR" "$SEND" --to .profile --from tester --subject s --message m >/dev/null 2>&1 || o10d_rc=$?
|
||||
[ "$o10d_rc" -eq 0 ] && [ "$(ls -1 "$O10DIR/.profile/orders" 2>/dev/null | grep -c '\.md$' | tr -d ' ')" = "1" ]
|
||||
check "10d: control - a dot-prefixed target name still receives its order" $?
|
||||
/bin/rm -rf "$O10DIR" 2>/dev/null
|
||||
|
||||
echo
|
||||
echo "orders-selftest: $PASS passed, $FAIL failed, $SKIP skipped (of $((PASS+FAIL+SKIP)) checks)"
|
||||
[ "$FAIL" -eq 0 ] || exit 1
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue