Conversation
bounded() sliced smtp_detail/failure_reason/failure_code/review_resolution at a raw byte offset with no rune-boundary check, unlike its sibling SafeDiagnostic(). Route it through SafeDiagnostic() so both share the same truncation rule. Fixes tokencanopy#1055
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #1055.
bounded()sliced diagnostic text at a raw byte offset, so a multi-byte rune landing on the 2048-byte cap got cut mid-rune.SafeDiagnostic()already does this correctly for a different call site (model.go); this routesbounded()through it instead of keeping a second, slightly wrong copy of the same logic.Added a test that feeds a
RecipientSnapshot.Detailsized so the cap always splits the last rune, through the realReconstruct()path. It fails on main: the returnedsmtp_detailis invalid UTF-8, and after the JSON round-trip incloneTransitionit's actually longer than the cap it's meant to enforce (U+FFFD substitution grows the trailing bytes).Client surface checklist
No API or client surface change, internal-only fix.
Test plan
go test ./internal/messagelifecycle/...: the new test is red without this change, green with it. Rest of the package suite is unaffected.make fmt-check,go build ./...,go vet ./internal/messagelifecycle/...clean.