0.64.25 workspace.reorder with out-of-range index crashes app (unchecked Array.insert)
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 84/100
Rechercherichtung
Beginne bei WorkspaceReorderCoordinator.reorderWorkspace(tabId:toIndex:isDragOperation:explicitGroupId:) und verfolge, wie ControlCommandCoordinator.handle(_:) den control-socket index dorthin weitergibt. Führe workspace.reorder mit einem toIndex außerhalb des gültigen Bereichs aus und überprüfe, dass die App weiterläuft, während die Anfrage sicher abgewiesen oder als No-op behandelt wird.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Confirmed customer report
An out-of-range toIndex sent to workspace.reorder over the control socket kills the app with EXC_BREAKPOINT / SIGTRAP on the main thread: Array._checkIndex -> Array.insert(_:at:) in WorkspaceReorderCoordinator.reorderWorkspace(tabId:toIndex:isDragOperation:explicitGroupId:) via ControlCommandCoordinator.handle(_:). No clamping or validation happens before the insert, so any client that computes a bad index (custom sidebar, CLI, extension) gets a guaranteed crash instead of an error.
The reporter was drag-reordering in a custom sidebar (fork of Examples/CustomSidebars/workspaces.js) with 5 workspaces in one window; the drop dispatched workspace.reorder with an index out of range for the internal array, and the whole app died, losing two workspaces from the window.
The reporter notes this is easy to hit from the documented data contract: a sidebar author only has workspaces[i].index to work from, and that value can disagree with the array reorderWorkspace indexes into. The shipped workspaces.js example computes its index the same way.
Evidence
Crash report: cmux-2026-09-21-143234.ips, incident 55593AFE-A396-4FB3-ACEE-2D69684271B4.
Workaround (reporter side): clamp the index to [0, count-1] before calling cmux("workspace.reorder").
- Reporter: florian.freudenberg@zenjob.com
Source report: Gmail 1a0c3fddfbb3944b
Environment:
- cmux 0.64.25 (build 106, commit b685a275c)
- macOS 26.6.2 (Build 25G83)
- Mac15,6, Apple M3 Pro, 36 GB
Expected
A control command arriving over the socket should never be able to terminate the app. reorderWorkspace should clamp or early-return on an out-of-range toIndex, making a bad index a no-op error rather than a crash.
- Vorherrschende Sprache
- Swift
- Sterne
- 27.3k
- Forks
- 2.4k
- Ø Merge
- 12 Std. 48 Min.
- Gemergte PRs (30 T.)
- 533
Beitragsleitfaden
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus manaflow-ai/cmux
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
manaflow-ai/cmux#12940 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
manaflow-ai/cmux#12915 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
manaflow-ai/cmux#12873 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 74/100
manaflow-ai/cmux#12652 ·
-
enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 74/100
manaflow-ai/cmux#12640 ·
Alle Issues in manaflow-ai/cmux
Ähnliche Issues
-
type: docs
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 95/100
googleapis/google-cloud-swift#971 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
bitcoindevkit/bdk-ffi#1125 ·
-
Move wallpaper setting Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
mozilla-mobile/firefox-ios#35743 ·
-
triage
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
ionic-team/capacitor#8616 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 80/100
paritytech/host-rust-core#868 ·