Conversation
45 bugs fixed with code changes across 24 files: - Critical: infinite retry loop, tool results dropped in recovery, TOCTOU race on team file, streaming executor race conditions, bash permission bypasses - Medium: OOM from large file edits, image compression fallthrough, MCP cleanup failures, non-null assertion crashes, skill loading FD exhaustion - Low: silent error swallowing, deprecated API usage, input sanitization 12 bugs documented with security comments (architectural constraints) 12 bugs verified as pre-existing fixes (inaccurate bug reports) All fixes verified with 76 passing bun tests (0 failures). See FIXES.md for detailed changelog.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
OpenClaude — Bug Fixes
Comprehensive fix for all 77 bugs identified in BUGS_README.md audit.
Summary
Critical Fixes (🔴)
API & Retry Layer
withRetry.ts— Fixed infinite loop in persistent retry mode. Clamp changed fromattempt = maxRetriestoattempt = maxRetries - 1so the for-loop terminates correctly.withRetry.ts— Madeis529Errormore robust with structured JSON parsing fallback instead of fragile substring match.withRetry.ts—getRetryAfterMsnow handles HTTP-date format (RFC 7231) viaDate.parse()fallback.withRetry.ts— Resetconsecutive529Errorsto 0 whenFallbackTriggeredErroris thrown, preventing false fallback cascades on the fallback model.Query Engine
query.ts— Included...toolResultsinmax_output_tokens_recoverystate so tool outputs aren't silently dropped on retry.query.ts— ResetcontinuationNudgeCountto 0 onstop_hook_blockingtransition, preventing infinite nudge loops across turns.query.ts— WrappedpendingToolUseSummaryawait in try/catch to prevent Haiku API errors from terminating the query loop.Tool Executor
StreamingToolExecutor.ts— Addeddiscardedcheck inprocessQueue()before executing queued tools, preventing wasted execution after streaming fallback.StreamingToolExecutor.ts— Added 5-minute global tool timeout to prevent indefinite hangs at the orchestration layer.Bash Security
bashSecurity.ts— Documented the sync constraint onisSafeHeredoc()callingbashCommandIsSafe_DEPRECATED()with security rationale.bashPermissions.ts— Added 16 interpreter commands (python, node, ruby, perl, php, lua, awk, etc.) toBARE_SHELL_PREFIXESto prevent dangerousBash(python3:*)auto-approve rules.BashTool.tsx— Documented security dependency onsplitCommand_DEPRECATED.Agent & Spawn
AgentTool.tsx— Increased cleanup timeout from 1s to 5s, added error logging when MCP cleanup fails.spawnMultiAgent.ts— Added async mutex (withTeamFileLock) around team file read-modify-write to prevent TOCTOU race conditions (3 locations).Medium Fixes (🟡)
File Tools
FileEditTool.ts— ReducedMAX_EDIT_FILE_SIZEfrom 1 GiB to 256 MiB to prevent OOM (V8 loads file + edit into memory).FileEditTool.ts— AddedtrimEnd()normalization check to catch no-op edits that differ only in trailing whitespace.File{Write,Edit,Read}Tool.ts— Changed.catch(() => {})to.catch(err => logError(err))for skill directory loading failures.FileReadTool.ts— AddedMAX_FILE_READ_LISTENERS = 100limit with warning on leak detection.FileReadTool.ts— Throws error instead of returning uncompressed 50MB image when both compression paths fail.FileReadTool.ts— AddedELOOPerror handling for symlink loops.FileReadTool.ts— RemovedMath.floor(stats.mtimeMs)to preserve full mtime precision (nanosecond on ext4).Skill System
loadSkillsDir.ts— Batched concurrent directory walks (max 16) to prevent file descriptor exhaustion.SkillTool.ts— Replaced allremoteSkillModules!non-null assertions with?.safe access.SkillTool.ts— AddedhooksandallowedToolstoSAFE_SKILL_PROPERTIES.loadSkillsDir.ts— AddedMAX_CONDITIONAL_SKILLS = 500limit to prevent unbounded map growth.bundledSkills.ts— Added duplicate skill name warning inregisterBundledSkill().bundledSkills.ts— Reset extraction promise on failure to allow retry on transient FS errors.bundledSkills.ts— Added resolved-path verification (startsWith(baseDir)) as defense-in-depth for path traversal.Web Tools
WebFetchTool.ts— Replacedprocess.env.FIRECRAWL_API_KEY!with null check + error throw.WebFetchTool.ts— Sanitized redirect URL in output message to prevent shell metacharacter injection.Agent Tools
runAgent.ts— Added logging when provider override changes agent model.runAgent.ts— ChangedallowedToolsto merge with existing session rules instead of replacing entirely.spawnMultiAgent.ts— Changed--model ${quote()}to--model=${quote()}for robust shell parsing.Streaming Executor
progressAvailableResolveto prevent resolver leaks.Other
CronCreateTool.ts— Added minimum 1-minute interval check for cron expressions.ConfigTool.ts— AddedMAX_CONFIG_VALUE_LENGTH = 100_000sanitization for string settings.errors.ts— AddederrorDetailsfallback check inisPromptTooLongMessage().errorUtils.ts— IncreasedmaxDepthfrom 5 to 10 for error chain extraction.Low Fixes (🟢)
setTimeoutargument-passing in PowerShellTool.length > 0guards for queue access in REPLeditorTimerReftimeout.catch(() => {})to.catch(err => log(...))in main.tsxsnipProjection!andsnipModule!with?.safe access in QueryEngineNot Fixed (Documented)
These bugs were reviewed and determined to be intentional behavior, fundamental limitations, or require architectural changes:
clearSkillCaches()on command reload@mendable/firecrawl-js,duck-duck-scrapedon't accept AbortSignal)Agenttool schema incompatible with OpenAI/Codex API — missingsubagent_typeinrequiredarray #46 — Already handled by abort signal propagation and task lifecycleTest Results
Run with:
bun test bugfixes.test.ts