Skip to content

Escape lineage metadata and surface actionable diagnostics - #41

Merged
Chinmay Singh (chisingh) merged 2 commits into
mainfrom
fix/lineage-html-escaping
Sep 24, 2026
Merged

Chinmay Singh (chisingh) merged 2 commits into
mainfrom
fix/lineage-html-escaping

Conversation

@xingdi-eric-yuan

@xingdi-eric-yuan Xingdi (Eric) Yuan (xingdi-eric-yuan) commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Fixes #37.

Escape untrusted experiment short names, branch-name fallbacks, and manifest test counts when rendering timeline cards and compact lineage trees. These values now appear as literal text rather than becoming active HTML in the generated local artifact.

Escaping stays at the output boundary: stored metadata is unchanged, existing report/title escaping is retained, and ordinary numeric, zero, missing, and empty count behavior is preserved.

Actionable feedback

HTML-like metadata is valid text and is escaped without reporting an error. Actual generation problems are surfaced to the host agent:

  • Required directory/index/output failures emit contextual ERROR messages on stderr and exit 1, without a traceback or a success message. An invalid explicit --shadow-dir is not replaced with a different shadow.
  • Malformed optional manifests/reports, skipped or duplicate index rows, and unreachable lineage emit WARNING messages with paths, fields or line numbers and repair/retry guidance. These recoverable cases can still produce a partial view.
  • Missing optional artifacts remain normal. Invalid Unicode is detected before opening an existing output for replacement.

The skill instructs the host to forward stderr even on a successful exit and repair the reported input before rerunning. The helper does not invoke a model or retry automatically.

Verification

298 Viewer/lineage tests passed. Coverage includes both renderers, generated chain/fresh/tree views, both manifest count fields, branch fallbacks, Unicode/quotes/ampersands, input immutability, and the real CLI. HTML parser assertions verify literal rendered text and the absence of injected elements/attributes; the original 16 escaping regressions failed before the fix.

Real-file CLI regressions also cover required read/write/encoding failures, wrong explicit shadow paths, warnings for invalid optional metadata and index rows, absent optional inputs, and safe literal metadata producing no error.

This addresses script injection into the generated local HTML artifact. Verification uses parser and CLI tests rather than interactive browser automation.

Based directly on current main; independent of #33 and the reconciler path-containment fix for #36.

Escape short names, branch fallbacks, and test counts at rendering boundaries. Add parser and CLI regressions while preserving metadata and count display semantics.

Fixes #37

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Report required input/output failures with repair guidance, replace silent optional-data fallbacks with contextual warnings, and keep ordinary escaped metadata successful. Document stderr forwarding and agent-managed retries.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@xingdi-eric-yuan Xingdi (Eric) Yuan (xingdi-eric-yuan) changed the title Escape untrusted lineage metadata in generated HTML Escape lineage metadata and surface actionable diagnostics Sep 23, 2026

@chisingh Chinmay Singh (chisingh) left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

@chisingh
Chinmay Singh (chisingh) merged commit 395dde4 into main Sep 24, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

dream-lineage.py: short and tests fields are not HTML-escaped in lineage.html

2 participants