eigenlsp JSON escaping is not UTF-8-safe (bypasses the #1048 chokepoint)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
Research direction
Start at eigenlsp's json_escape_to and compare it with the eigs_utf8_sanitize and lint_json_escape path; inspect tools/lint_diag_writers.sh and how it handles eigenlsp emitters. Done means the escaping and fixed-buffer truncation are UTF-8-safe, the emitter coverage is addressed, and the 320-byte-edge syntax-error case produces valid UTF-8 JSON-RPC.
Written by the indexing model from the issue text.
Description
Found by the blind critic on PR #1332, and pre-existing on main.
eigenlsp's json_escape_to does not validate UTF-8, and its "syntax error: %s" snprintf into full[320] can cut a multi-byte character in half. The lint path is protected by eigs_utf8_sanitize and lint_json_escape (#1048), but this LSP path bypasses both. No input that feeds it multi-byte text was found today, so this is latent.
Done when
- eigenlsp's JSON escaping goes through the same UTF-8-safe chokepoint as
--lint --json, or an equivalent one, and its fixed buffers truncate on character boundaries. -
tools/lint_diag_writers.sh(#1332) derives eigenlsp's JSON emitters too, or the PR states why they are out of its population. - Calibrated once: a syntax error whose message carries a multi-byte character at the 320-byte edge produces valid UTF-8 JSON-RPC.
- Dominant language
- C
- Stars
- 3
- Forks
- 7
- Avg merge
- 3h 58m
- Merged PRs (30d)
- 105
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from InauguralSystems/EigenScript
-
area:lint-tooling bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
InauguralSystems/EigenScript#1340 ·
Maintainers usually reply within 1 day
-
area:stdlib found-by:code-review kind:silent-wrong
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
InauguralSystems/EigenScript#1338 ·
Maintainers usually reply within 1 day
-
area:lint-tooling found-by:critic kind:docs-drift
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
InauguralSystems/EigenScript#1335 ·
Maintainers usually reply within 1 day
-
area:ci found-by:critic kind:gate-defect
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
InauguralSystems/EigenScript#1311 ·
Maintainers usually reply within 1 day
-
enrolment: decide test_gc_runner_controls.py (exempt vs enrol) and whether floors need a ratchetOpenarea:gates found-by:critic kind:decision
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
InauguralSystems/EigenScript#1280 · 1 comment ·
Maintainers usually reply within 1 day
All issues in InauguralSystems/EigenScript
Similar issues
-
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
ClickHouse/pg_clickhouse#383 · 1 comment ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
johnsonjh/emu2-cpm86#68 · 1 comment ·
Maintainers usually reply within 1 day
-
Zenmap CrashOpenZenmap
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
BasedHardware/omi#19306 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
fastfetch-cli/fastfetch#2619 ·
Maintainers usually reply within 1 day