Skip to content

fix(output): upstream-derived text never reaches the terminal raw (PHARN-17) - #211

Merged
PrzemekGalarowicz merged 1 commit into
mainfrom
claude/bold-archimedes-5czyyn
Sep 24, 2026
Merged

PrzemekGalarowicz merged 1 commit into
mainfrom
claude/bold-archimedes-5czyyn

Conversation

@PrzemekGalarowicz

Copy link
Copy Markdown
Contributor

Problem

  • Extractor errors pasted raw entry names and typeflag bytes into their messages, e.g. unsupported type '2': …/n^[[2K^M^[[32mOK. reportFatal then printed them to stderr, which allows a faked "OK", a line erase, or an OSC 52 clipboard write.
  • The unknown-capability list stripped C0/C1 characters but let Unicode format characters through (U+202E, U+200B).

Fix

  • Extractor: refuses an entry whose full path (prefix + name, decoded as UTF-8) contains a C0/C1 or \p{Cf} character. This check runs before any other entry rule. Refusal messages show the name sanitized, and an unprintable typeflag is shown as its code (0x1b). Ordinary non-ASCII names still extract.
  • New lib/terminal-safe.ts: the one shared display sanitizer. unknown-capabilities.ts now uses it.
  • logError (the fatal sink shared by every fatal path) strips the same set of characters but keeps \n and \t.

Tests

  • 9 cases fail on the old code: 6 extractor cases, 2 sink cases, and U+202E in the unknown-capability list. A new terminal-safe.test.ts covers the sanitizer.
  • Local gates, run as a non-root user on node 22: all green. 1464/1464 tests pass and statement coverage is 97.24%.

Advisory

THREAT-MODEL.md §2 should list the new extractor refusal. That file is write-protected, so a maintainer has to add it.

🤖 Generated with Claude Code

https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc


Generated by Claude Code

…ARN-17)

Extractor errors interpolated raw entry names and typeflag bytes, which
reportFatal printed to stderr (fake "OK", line erase, OSC 52), and the
unknown-capability list let Unicode format characters (U+202E) through.

- tar-extract refuses an entry path holding a C0/C1 or \p{Cf} character,
  judged first, and renders names/typeflags safely in its messages
- new lib/terminal-safe.ts: the one display sanitizer, now also used by
  unknown-capabilities
- logError (the fatal sink) strips the same set, keeping \n and \t

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc
@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 3174f4b6-8696-48f8-9709-ae8c14db4a79


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@PrzemekGalarowicz
PrzemekGalarowicz merged commit 0010521 into main Sep 24, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants