fix(context): strip controls from provenance pointers#350
Closed
SUaDtL wants to merge 2 commits into
Closed
Conversation
Record the SMARTS selection and audited task start before the implementation commit. This preserves the task board's required queued-to-in-progress transition.
Sanitize document names, claim text, and line ranges before assembling freshness-gated additional context. Suppress provenance records whose document key becomes empty after sanitization. CHANGELOG: Harden provenance context pointers against control-character restructuring.
Collaborator
Author
|
Superseded by #313, the single hackathon review surface. This PR's recorded head and changes are represented in #313's exact 16-PR / 29-commit / 126-path source manifest. PR #313 passed final exact-head CI at commit 6173b1d and remains open and unmerged. Closing this source PR to avoid parallel review; please continue review and discussion on #313. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security posture
The sanitizer removes Unicode categories Cc, Cf, Zl, and Zp before pointer construction and before the 150-token budget is applied. Malformed values fail silent. Reviewers found an adjacent document-key path during the first pass; that path is covered by the same sanitizer in the final diff. Security, architecture, and coverage re-reviews report no remaining findings.
Verification