Skip to content

bug(git-read): call labels render control bytes before validation #581

Description

@ooiuuii

Problem

The three Git read tools concatenate call-label arguments directly into their TUI text. Pi's native ToolExecutionComponent renders these labels before execute() rejects invalid arguments, so execution validation does not protect this earlier display boundary.

Reproduction

At main f6b49ae59605b1276b8267f2886d22c03f01533c, feed harmless OSC-title, CSI and bidi-control fixtures into the registered git_show, git_diff, and git_log call labels through the actual native component. Control bytes reach component output even though the actual execute calls subsequently reject the same arguments.

This demonstrates unsafe display output, not an observed terminal takeover. No real terminal command or clipboard manipulation was attempted.

Expected

Sanitize the final call-label projection and normalize it to one line, following the existing file-search display pattern. Preserve raw canonical arguments, Git argv, execution validation and result rendering.

New tests on unchanged production: 6 failures / 1 ordinary-label control pass. A shared display helper fixes all six displayed argument positions; the complete focused Git group passes 20/20.

This is independent of #570 (post-execution failure status), #564 (Git argv boundary), and #368 (shared process helpers). It applies before those execution/result paths and can be reviewed independently.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions