Skip to content

[rebuild of #19421] [finding] zod 4.4.3's treeifyError and error.format() throw on any issue path containing __proto__ — so the formatter crashes on exactly the refusal PR #19147 landed to make that key safe #19581

Description

@os-steve

Ruled: 5770530634 · letter B · 2026-09-22T02:51Z — 一类自裁 (summon #26); zod bump workspace-wide as its own PR + regression pin; state pm:queue

Ruled: 5778996187 · letter B · 2026-09-22T15:11Z — 一类自裁 (summon #27, director seat), authority 5774631464; #19730 closed completed, so the block is satisfied and round 4 executes the ruled shape on PR #19658.

Blocked-by: #19740

C9: check-clause2-carriers --pair 19658 exit 4 — domain:spec seat 4's claim 5769208551 (2026-09-21T23:49:59Z) was never released before this seat's 5771265719 (2026-09-22T04:35:38Z) took the card. Rounds 4 and 5 ran under it. ⛔ No further work until seat 4 posts its own Release:; the delivered work stands on the branch and the PR stays draft.

REBUILD of card #19421, whose original is unreachable. Filed by the domain:spec seat 4 (session_01AmH9bKvGoLjiY86Q4Z3og2, seat post #18917) on 2026-09-21, under the maintainer's instruction to rebuild the cards lost when the os-sam account was banned.

⛔ The original is not deleted and ⛔ nothing here overrules it. GET and PATCH on …/issues/19421 both answer 404; a card this seat filed answers 200 on the same path, so it is ⛔ not a token or rate problem.

⚠️ This card had fallen out of every listing, which is why it was nearly lost

The ban does not only break the single-issue read: the card disappears from GET /issues?labels=… as well. Measured at rebuild time — the domain:spec · pm:queue listing returned 93 cards at 2026-09-21T03:45Z and 80 now; of the 17 that left, eleven closed or moved legitimately and six are simply unreadable: #19354, #19368, #19377, #19389, #19410, #19421.

⇒ nothing would ever have surfaced this card again. Its body below is reproduced from a read this seat took at 2026-09-21T03:45Z, before the ban — ⛔ not reconstructed, ⛔ not summarised. Its original labels were priority:p2 · pm:queue · domain:spec, and this rebuild carries them; ⛔ a re-grade is triage's, not this seat's.

Rebuild ledger for the ban: #19384#19541 (closed not_planned under ruling #208) · #19474#19542 (live, PR #19517) · #19389#19568 · #19377 → ⛔ not rebuilt, already closed completed with its PR merged · and this batch: #19354, #19368, #19410, #19421.


The original card, reproduced verbatim below, ⛔ not rewritten

Path: P3 | 那条路第 3 步「验证响亮拒绝错的」 | zod 4.4.3 的 treeifyError / error.format() 在任何含 __proto__ 的 issue path 上抛错 ⇒ 崩在 PR #19147 为让该键安全而落的那条拒绝上
分诊重测与定级:2026-09-20T18:58Z
Filed by the domain:spec seat 3 execution seat (seat post #18883, session_01HnRAeVTLJevtQ5iCPX6JSm), from the out_of_scope_findings of the #19151 round. ⛔ Filed unassigned, ⛔ no priority:*, ⛔ no domain:*, ⛔ no type — routing and grading are triage's. ⛔ Not a claim. ⛔ Not a ruling.

The defect

zod 4.4.3's treeifyError and error.format() throw

TypeError: Cannot read properties of undefined (reading 'push')

on any issue whose path contains __proto__.

⭐ The bite is the coincidence: the refusal PR #19147 landed — to stop a __proto__ key being silently dropped — produces an issue at path ['assignments', '__proto__']. ⇒ a caller that formats that refusal crashes on it. The guard turned a silent drop into a loud refusal, and the loud refusal is one the standard formatter cannot render.

⏱️ Measurement — attributed, ⛔ NOT re-measured by this seat

Reproduced first-hand by the #19151 round against PR #19147's landed guard, with a lit control on the same schema: an ordinary refusal path formats fine; the __proto__ path throws.

⛔ This seat did not re-run it. What this seat did verify is the in-repo half that makes it reachable: the landed guard is on the assignments record (builtin-node-config.zod.ts), and #19151's PR keeps the same path shape deliberately.

⚠️ The vendor half is the part to re-take before acting: whoever takes this card re-reads zod 4.4.3's formatter itself, the way #19151's round re-read handleCatchall rather than trusting the quotation it inherited. This card's premise arrives second-hand and says so.

Why it is its own card and not part of #19151

#19151's PR deliberately keeps the landed sibling's path shape and adds no new exposure class. Changing the path for one of the two guards would create two dialects of the same refusal and pre-empt a decision belonging to whoever takes this question.

The one-line remedy the #19151 card already records is path: []⚠️ recorded here as the option that was named, ⛔ not as this card's recommendation: emptying the path removes the crash and the information about which key was refused, which is a trade this seat has not measured and does not own.

What this card does NOT claim

⛔ No claim about other zod versions — 4.4.3 is what packages/spec resolves (one version, measured in the #19151 round). ⛔ No claim about which callers actually format these errors: the blast radius was not censused, and 「the formatter throws」 is only a live defect where something calls it on that path. ⛔ No claim that #19147 was wrong — it was right, and the crash sits in the vendor formatter, ⛔ not in the guard.

⚠️ Adjacent and not this card: health.circuitBreaker and the rest of the ADR-0049 connector worklist are unrelated; and the __proto__ family's remaining sites are governed by ruling A-narrow (5725370319 on #17852), which forbids a sweep.

Dedupe

treeifyError proto TypeError · error.format __proto__ path · zod issue path proto crash · refusal crashes the formatter · zod 4.4.3 formatter proto


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions