You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Fix indexed path traversal and prepare v1.1.0 for agent runtime integration - #179
Prepare tgrep v1.1.0 for Copilot CLI agent runtime integration, harden ordinary indexed file reads, and remove the flaky live-memory comparison. This PR includes the requested path-containment and macOS test fixes in addition to version metadata; it is no longer metadata-only.
Version preparation
Set workspace.package.version from 1.0.11 to 1.1.0.
Synchronize tgrep-cli / tgrep-core in the root Cargo.lock and tgrep-core in fuzz/Cargo.lock.
Both crates inherit the workspace version; CLI version output and Windows VERSIONINFO continue to derive from it.
Indexed-read containment and review follow-up
Validate stored content-index and filename-sidecar paths before use, sharing validation with shared-base/checkpoint readers. Reject invalid UTF-8, non-normalized or escaping paths, and Windows path prefixes/alternate streams where applicable. Preserve valid Unix colon-bearing names, with a builder/reader/rooted-open/sidecar round-trip regression.
Use existing pinned-root file handles for ordinary local and server content reads, indexed metadata sorting, and file-stamp collection. Descendant symlinks/reparse points are not followed.
Require an absolute, resolvable metadata root covering the requested scope; otherwise scan the requested tree instead of guessing the index root. The requested root remains the authority for local content reads; metadata hashes are not treated as authentication.
Preserve the public collect_filestamps -> HashMap<String, FileStamp> signature. This best-effort compatibility API diagnoses and omits unsafe/unreadable paths. Add try_collect_filestamps -> Result<HashMap<String, FileStamp>> for fallible callers, retaining omission of missing files. Both APIs use the same validated rooted-open helper.
Enforce source-byte limits during local, scan, and server reads, not only in metadata prefilters. A shared bounded reader consumes at most limit + 1 bytes and rejects oversized input before decoding/caching. Local mmap uses an explicitly approved extent and rechecks the same handle before accepting the mapping. The explicit-file exemption from the inherited default cap is unchanged.
Retain raw source-byte counts in cached decoded entries. A stricter query cannot accept oversized cached content based on its smaller decoded length; a bounded fresh read allows a subsequently smaller replacement to become eligible. Server size-prefilter optimizations do not bypass read-time bounds.
Document indexes as local generated output that must not be committed or distributed with repositories. Explicit-file and scan-follow semantics are unchanged.
Add deterministic coverage for stored-path rejection, whole/subtree containment, pinned-handle mmap/decoding, ordinary server cold/cache/encoding paths before reconciliation, metadata-root fallback, and Windows alternate-stream rejection. Additional review regressions cover growth, capped mappings, raw-versus-decoded sizes, cache replacements, exact/zero/unlimited caps, and bounded byte consumption. Fixtures use invented data only.
Deterministic memory-budget tests
Replace comparisons between separate live memory samples with fixed-input tests of the selection policy used by production.
Cover private-byte preference, lazy RSS fallback, zero/maximum values, and unavailable counters on every platform. Verify RSS is not queried when private bytes are available and is queried exactly once otherwise.
Retain a single-sample supported-platform smoke test. Runtime selection remains private bytes first, RSS only as fallback; no retries, sleeps, or widened tolerances are introduced.
Review follow-up commit: 195ecb1e781f6b7fd6dd63bf9b43b1b8125381f9. It addresses all three inline threads plus the related local-read size-limit finding in the review summary. The branch started from main at 677a4baa1a8d5e5c886feaff7140a5a12cacd550.
Validation
Completed locally on Windows for the review follow-up:
Core library: 315 passed. corrupt_index_reader, shared_worktrees, and snapshot_consistency: 41 passed.
Latest CLI unit suite: 282 passed, 1 ignored, including the new bounded-read/cache regressions and the deterministic memory-budget tests.
indexed_containment, indexed_files, indexed_hidden, large_file_search, default_max_filesize, and concurrent_search: 34 passed.
All Cargo test commands used --locked --offline. Final follow-up diff contains seven Rust files only; no dependency churn, manifest/lockfile edits, or vendor changes.
Native Unix-specific regressions, including the new colon-filename round trip, are included for CI but were not executed locally. The previously observed macOS memory-sampling flake is addressed by the deterministic tests above.
Release boundary
No runtime-repository edits or integration implementation, tags, release publication, workflow dispatches, or pipeline changes. Checksum generation and Windows signing/release-build work remain in the compliant internal Azure DevOps pipeline and are unchanged here. Vendored code, vendor/ignore/Cargo.lock, and historical benchmark/provenance data are untouched. This description does not include the coordinated-disclosure report, reporter details, or a standalone exploit generator.
Replace comparisons between live memory samples with fixed-input coverage of private-byte preference, lazy RSS fallback, and unavailable counters. Keep a single-sample platform smoke test and preserve runtime selection behavior.
Co-authored-by: Copilot App <[email protected]>
Shengyu Fu (shengyfu)
changed the title
Bump version to 1.1.0 for agent runtime integration
Fix indexed path traversal and prepare v1.1.0 for agent runtime integration
Oct 7, 2026
The size check is only a metadata snapshot; read_open_text_lossy then maps or reads the handle without a byte bound. If the file grows after this check, --max-filesize can still search and allocate beyond the requested limit. Pass the limit into the read path and reject data beyond limit + 1, including before accepting an mmap.
Preserve Unix colon filenames and the legacy file-stamp API. Enforce source-byte limits during local and server reads, including mmap and cached content, with deterministic regressions.
Co-authored-by: Copilot App <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prepare tgrep v1.1.0 for Copilot CLI agent runtime integration, harden ordinary indexed file reads, and remove the flaky live-memory comparison. This PR includes the requested path-containment and macOS test fixes in addition to version metadata; it is no longer metadata-only.
Version preparation
workspace.package.versionfrom1.0.11to1.1.0.tgrep-cli/tgrep-corein the rootCargo.lockandtgrep-coreinfuzz/Cargo.lock.Indexed-read containment and review follow-up
collect_filestamps -> HashMap<String, FileStamp>signature. This best-effort compatibility API diagnoses and omits unsafe/unreadable paths. Addtry_collect_filestamps -> Result<HashMap<String, FileStamp>>for fallible callers, retaining omission of missing files. Both APIs use the same validated rooted-open helper.limit + 1bytes and rejects oversized input before decoding/caching. Local mmap uses an explicitly approved extent and rechecks the same handle before accepting the mapping. The explicit-file exemption from the inherited default cap is unchanged.Deterministic memory-budget tests
Review follow-up commit:
195ecb1e781f6b7fd6dd63bf9b43b1b8125381f9. It addresses all three inline threads plus the related local-read size-limit finding in the review summary. The branch started frommainat677a4baa1a8d5e5c886feaff7140a5a12cacd550.Validation
Completed locally on Windows for the review follow-up:
corrupt_index_reader,shared_worktrees, andsnapshot_consistency: 41 passed.indexed_containment,indexed_files,indexed_hidden,large_file_search,default_max_filesize, andconcurrent_search: 34 passed.cargo check --locked --offline --quiet --workspace --tests: passed.cargo clippy --locked --offline --quiet --workspace --all-targets -- -D warnings: passed.cargo fmt --all -- --checkand CRLF-awaregit diff --check: passed. The decoder's committed CRLF line endings are preserved.cargo metadata --locked --offline --format-version 1graphs: root 194 packages, separate fuzz workspace 111 packages; tgrep package versions remain1.1.0.cargo build --locked --offline --quiet -p tgrep-cli --bin tgrep: passed. Built CLI returns exit 0, empty stderr, and exact stdouttgrep 1.1.0\n.--locked --offline. Final follow-up diff contains seven Rust files only; no dependency churn, manifest/lockfile edits, or vendor changes.Native Unix-specific regressions, including the new colon-filename round trip, are included for CI but were not executed locally. The previously observed macOS memory-sampling flake is addressed by the deterministic tests above.
Release boundary
No runtime-repository edits or integration implementation, tags, release publication, workflow dispatches, or pipeline changes. Checksum generation and Windows signing/release-build work remain in the compliant internal Azure DevOps pipeline and are unchanged here. Vendored code,
vendor/ignore/Cargo.lock, and historical benchmark/provenance data are untouched. This description does not include the coordinated-disclosure report, reporter details, or a standalone exploit generator.