Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

read and read_document block forever on a pipe, and read without end from a link to a device

未关闭
#1,490 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
72/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
go
领域
cli, devtools

调研方向

Start with OpenRegular and ReadRegularHead in internal/skills, then trace readTool in internal/exec/bare/tools.go, sniffSense and readSenseFile in internal/session/tools_sense.go, and readDocument in internal/session/tools_doc.go. Run the FIFO reproduction and the ordinary-file command first. Done means the listed unit and e2e cases return promptly, preserve ordinary-file reads, and the manual page in internal/manual/chat/ states the exact refusal.

由索引模型根据 Issue 内容生成。

描述

area:tools bug

What happened

The worker's file-reading hands open whatever path they are given with a blocking open and read it with an unbounded os.ReadFile. A path that is a FIFO (named pipe), or a link to a device such as /dev/zero or /dev/tty, therefore either blocks at the open for as long as nothing writes to the pipe, or reads without end until memory runs out. The turn holding that tool call cannot finish.

This is on dev@f101ad2e7 and unchanged on santos/dev2 (#1410). #1410's review fixed the same class of fault in skill discovery and the Claude Code settings readers (one opener, OpenRegular, in internal/skills, which checks the file type, opens with O_NONBLOCK and bounds the read), but the worker-facing read doors do not use it. The committed path a model is most likely to be pointed at is a skill: use_skill checks that a SKILL.md is a regular file when it hands out the path, and the file can be swapped for a pipe or a link after that check.

The shell door that runs the same read as read_document, today:

$ mkfifo notes.md
$ timeout 6 codeaf doc notes.md; echo "exit=$?"
exit=124

codeaf doc real.md on an ordinary file prints it and exits 0 at once.

Replication

Deterministic (no model).

d=$(mktemp -d) && cd "$d"
mkfifo notes.md
echo '# hi' > real.md
timeout 6 codeaf doc real.md;  echo "exit=$?"   # prints "# hi", exit=0
timeout 6 codeaf doc notes.md; echo "exit=$?"   # prints nothing, exit=124: blocked in the open

The read hand has no shell door, so its twin is a Go test in internal/exec/bare: make a FIFO in t.TempDir(), call ReadTool(dir, 0).Execute(ctx, json.RawMessage({"path":"notes.txt"})) with a 2-second context, and observe it has not returned when the context ends. The session's read wrapper blocks before that, in sniffSense's os.Open (a .txt name is not in its extension table, so it opens the file to sniff magic bytes).

Do not point the reproduction at a link to /dev/zero without a memory limit (ulimit -v): the unbounded read allocates until the process is killed.

Field (real models). In a scratch repository with mkfifo notes.txt, run codeaf exec "read notes.txt and tell me what it says" --timeout 2m with OPENROUTER_API_KEY set. The model's read call never returns and the run ends on the wall. Budget: under a cent.

Where

  • internal/exec/bare/tools.go: readTool (data, err := os.ReadFile(absPath)), and the same os.ReadFile(absPath) further down the file in the edit hand's read of the old content.
  • internal/session/tools_sense.go: sniffSense (file, err := os.Open(absolute)) and readSenseFile (os.ReadFile(absolute) after a size check that a device or a pipe passes with size 0).
  • internal/session/tools_doc.go: readDocument's local rung (data, err := os.ReadFile(absolute)) and looksLikePlainText (file, err := os.Open(absolute)).

The fix

A path that is not a regular file, or a link to one that is not, is refused at once in the hand's own words, the way skill discovery already refuses one. For example: notes.md is not a regular file (a pipe), so it was not read. Reads are bounded at each hand's existing size ceiling. All of these doors should use one opener; internal/skills' OpenRegular / ReadRegularHead is the shape to reuse or move somewhere both packages can import.

Acceptance

  • e2e: codeaf doc notes.md on a FIFO exits within a second with exit 1 and the refusal sentence on stderr; the same command on an ordinary file still prints it and exits 0.
  • e2e: codeaf doc zero.md, where zero.md is a link to /dev/zero, refuses at once and allocates nothing (run it under ulimit -v 500000).
  • Unit: read (bare and the session wrapper) and read_document return the refusal within 100 ms for a FIFO, a link to /dev/zero and a link to /dev/tty, and still read an ordinary file and a link to one.
  • Unit (law): no os.Open / os.ReadFile on a model-supplied path remains in the three files above outside the shared opener.
  • The manual page that covers read and read_document (internal/manual/chat/) states the refusal in its exact words.
主要语言
Go
星标
115
派生
14
平均合并
9 小时 38 分钟
30 天内合并 PR
749

环境准备

我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

Agent-Field/CodeAF 的其他 Issue

查看 Agent-Field/CodeAF 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。