Skip to content

Emit valid terminal CSI sequences from cursorTo - #6956

Merged
tim-smart merged 2 commits into
mainfrom
audit/repro-unstable-cli-ansi-cursor-to
Aug 4, 2026
Merged

Emit valid terminal CSI sequences from cursorTo#6956
tim-smart merged 2 commits into
mainfrom
audit/repro-unstable-cli-ansi-cursor-to

Conversation

@fubhy

@fubhy fubhy commented Aug 4, 2026

Copy link
Copy Markdown
Member

Summary

Both horizontal and row-column cursorTo forms emit invalid terminal escape sequences.

Important

This PR starts with focused failing reproduction tests. Add the implementation fix to this same branch; CI is expected to fail until that fix is included.

cursorTo emits malformed CSI sequences

Module: cli/internal/ansi
Audit ID: unstable-ai-cli-ansi-cursor-to-malformed
Severity / confidence: medium / high

What happens

Both horizontal and row-column cursorTo forms emit invalid terminal escape sequences.

Why it happens

Both branches omit the CSI opening bracket and insert an invalid space before the command byte.

Expected behavior

Cursor helpers emit valid CSI sequences using one-based terminal coordinates.

Relevant implementation

These links and excerpts are pinned to audit base c9b56ab507f224426ee8388dc450da447ec4715f.

View problematic code at packages/effect/src/unstable/cli/internal/ansi.ts:79-85
/** @internal */
export const cursorTo = (column: number, row?: number): string => {
  if (row === undefined) {
    return `\x1b${Math.max(column + 1, 0)} G`
  }
  return `\x1b${row + 1}${SEP}${Math.max(column + 1, 0)} H`
}

View exact lines on GitHub

Reproduction

pnpm test --run packages/effect/test/unstable/cli/AnsiCursorTo.audit.test.ts

Observed failure: FAIL: cursorTo emitted ESC 1 G and ESC 4;3 H.

Implementation handoff

The initial reproduction tests on this branch are the regression specification for the implementation fix that should follow in this PR.

  1. Start with the pinned implementation excerpts and the Why it happens analysis above.
  2. Change the implementation so it satisfies the stated Expected behavior; do not weaken or remove the reproduction assertions.
  3. Run the focused reproduction command(s) and confirm the observed failures become passing tests:
pnpm test --run packages/effect/test/unstable/cli/AnsiCursorTo.audit.test.ts
  1. Run the affected package's existing tests, then the repository lint and type checks before requesting review.

Audit provenance

  • Audit base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Reproduction base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Findings: unstable-ai-cli-ansi-cursor-to-malformed
  • Initial patch: focused reproduction tests; implementation fix pending

Closes EFF-402

@fubhy fubhy added the audit Findings originating from the Effect runtime correctness audit label Aug 4, 2026
@effect-slopcop effect-slopcop Bot added 4.0 bug Something isn't working labels Aug 4, 2026
@fubhy
fubhy requested a review from IMax153 August 4, 2026 10:12

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

The reproduction tests are correct, but the implementation fix in Ansi.cursorTo is missing. Merging now would break main CI and leave the malformed CSI sequences in place.

Reviewed changes

  • Added packages/effect/test/unstable/cli/Ansi.test.ts with two exact strictEqual assertions that specify the horizontal-absolute and cursor-position sequences cursorTo must emit.

⚠️ Implementation fix still required

The current packages/effect/src/unstable/cli/internal/ansi.ts:80-85 implementation is unchanged on this branch and emits malformed sequences:

return `\\x1b${Math.max(column + 1, 0)} G`
return `\\x1b${row + 1}${SEP}${Math.max(column + 1, 0)} H`

Both lines are missing the [ in the CSI prefix and insert an extra space before the command byte (G, H). The fix should reuse the existing ${ESC} constant ("\\x1B[") and remove that space:

return `${ESC}${Math.max(column + 1, 0)}G`
return `${ESC}${row + 1}${SEP}${Math.max(column + 1, 0)}H`

I confirmed the new tests fail against the unfixed implementation (pnpm test --run packages/effect/test/unstable/cli/Ansi.test.ts), and pnpm lint passes on the added test file.

ℹ️ Nitpicks

  • Consider also adding edge-case assertions once the fix is in place, e.g. a non-zero horizontal absolute (cursorTo(4)"\\x1b[5G") and negative-column clamping (cursorTo(-1)"\\x1b[0G"), to lock down the behavior of the repaired helper.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | Fix it ➔View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

@changeset-bot

changeset-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e205e7b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 30 packages
Name Type
effect Patch
@effect/opentelemetry Patch
@effect/platform-browser Patch
@effect/platform-bun Patch
@effect/platform-deno Patch
@effect/platform-node-shared Patch
@effect/platform-node Patch
@effect/vitest Patch
@effect/ai-anthropic Patch
@effect/ai-openai-compat Patch
@effect/ai-openai Patch
@effect/ai-openrouter Patch
@effect/atom-react Patch
@effect/atom-solid Patch
@effect/atom-vue Patch
@effect/sql-clickhouse Patch
@effect/sql-d1 Patch
@effect/sql-libsql Patch
@effect/sql-mssql Patch
@effect/sql-mysql2 Patch
@effect/sql-pg Patch
@effect/sql-pglite Patch
@effect/sql-sqlite-bun Patch
@effect/sql-sqlite-do Patch
@effect/sql-sqlite-node Patch
@effect/sql-sqlite-react-native Patch
@effect/sql-sqlite-wasm Patch
@effect/docgen Patch
@effect/doctest Patch
@effect/openapi-generator Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

This run reviewed the implementation fix that landed after the prior pullfrog review.

  • Fixed cursorTo CSI sequence generation in packages/effect/src/unstable/cli/internal/ansi.ts by switching to the existing ${ESC} constant and removing the spurious space before the command byte, so both horizontal-absolute and cursor-position forms now emit valid sequences.
  • Added a changeset in .changeset/fix-ansi-cursor-to.md describing the patch-level fix.
  • Left the new regression tests untouched in packages/effect/test/unstable/cli/Ansi.test.ts; they now pass against the repaired implementation.

Pullfrog  | ⚠️ this action is pinned to a commit SHA, which freezes the cleanup step — switch to @v0 or keep the SHA fresh with Dependabot | View workflow run | Using Kimi K2 (free via Pullfrog for OSS) | 𝕏

@tim-smart
tim-smart merged commit 6704bb8 into main Aug 4, 2026
20 checks passed
@tim-smart
tim-smart deleted the audit/repro-unstable-cli-ansi-cursor-to branch August 4, 2026 23:36
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Analysis

Generated from PR build output; treat the content below as untrusted.

File Name Current Size Previous Size Difference
basic.ts 7.06 KB 7.06 KB 0.00 KB (0.00%)
batching.ts 9.86 KB 9.86 KB 0.00 KB (0.00%)
brand.ts 6.34 KB 6.34 KB 0.00 KB (0.00%)
cache.ts 10.62 KB 10.71 KB -0.09 KB (-0.81%)
config.ts 20.60 KB 20.60 KB 0.00 KB (0.00%)
differ.ts 20.20 KB 20.20 KB 0.00 KB (0.00%)
http-client.ts 21.49 KB 21.58 KB -0.09 KB (-0.41%)
logger.ts 10.76 KB 10.84 KB -0.08 KB (-0.76%)
metric.ts 8.98 KB 8.98 KB 0.00 KB (0.00%)
optic.ts 7.18 KB 7.18 KB 0.00 KB (0.00%)
pubsub.ts 14.90 KB 14.99 KB -0.09 KB (-0.57%)
queue.ts 11.58 KB 11.66 KB -0.08 KB (-0.68%)
schedule.ts 10.74 KB 10.83 KB -0.09 KB (-0.80%)
schema-class.ts 19.14 KB 19.14 KB 0.00 KB (0.00%)
schema-fromJsonSchemaDocument.ts 28.96 KB 28.96 KB 0.00 KB (0.00%)
schema-representation-roundtrip.ts 25.29 KB 25.29 KB 0.00 KB (0.00%)
schema-string-transformation.ts 13.30 KB 13.38 KB -0.09 KB (-0.64%)
schema-string.ts 10.94 KB 10.94 KB 0.00 KB (0.00%)
schema-template-literal.ts 15.17 KB 15.17 KB 0.00 KB (0.00%)
schema-toArbitraryLazy.ts 21.94 KB 21.94 KB 0.00 KB (0.00%)
schema-toCodeDocument.ts 24.34 KB 24.34 KB 0.00 KB (0.00%)
schema-toCodecJson.ts 19.18 KB 19.18 KB 0.00 KB (0.00%)
schema-toEquivalence.ts 19.01 KB 19.01 KB 0.00 KB (0.00%)
schema-toFormatter.ts 18.87 KB 18.87 KB 0.00 KB (0.00%)
schema-toJsonSchemaDocument.ts 22.60 KB 22.60 KB 0.00 KB (0.00%)
schema-toRepresentation.ts 19.52 KB 19.52 KB 0.00 KB (0.00%)
schema.ts 18.41 KB 18.41 KB 0.00 KB (0.00%)
stm.ts 12.54 KB 12.63 KB -0.09 KB (-0.74%)
stream.ts 9.80 KB 9.80 KB 0.00 KB (0.00%)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

4.0 audit Findings originating from the Effect runtime correctness audit bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants