Repository navigation
interpreter: read response_format as the WireFormat variant the emitter reads; refuse other spellings (silent JSON decode of Text) - #13228
Conversation
…t variant, as the emitter does; refuse any other spelling dispatch_rest read response_format only as a string literal and defaulted every other spelling to Json, so response_format: Text (github.Pulls.Diff's typed spelling) was silently JSON-decoded while emitted code read it as text. It now reads through v1.std.core transport_response_format and authored_name_at, the emitter's own reading. Replay witnesses: a plain-text body under Text reads as text (RED before: RestBodyUndecodable at 200), and an unrecognized spelling refuses. RFM row response_format_variant_silently_read_as_json. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tter's reading; the interpreter's after #13228) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…grain (DESIGN 4c; parse phase refused annotations inside the service body) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
briansrls
left a comment
There was a problem hiding this comment.
Reviewed exact head bf0d1546e4c9b7b3130571f32ad51cfa81f81a5e. Approved.
The defect and repair are correctly scoped to the live interpreter path:
- The old interpreter read only a string literal and treated every non-string spelling as absence, so the typed
Textvariant fell through to the Json default. The new path reads the same transport property node and authored variant name used by emission, keeps absence as Json, admits onlyText/Json, and refuses every other authored spelling instead of guessing. - The replay is discriminating. A plain-text 200 under bare
Textmust return the body withRestOk; quoted"Text"must refuse at the response-format decision. The existing Json success control prevents the witness frame or REST replay from being generally broken. - No current production operation depends on the quoted spelling;
github.Pulls.Diffuses the typed variant. The repair therefore restores the declared behavior without a compatibility alias for the invalid spelling. - This is an admissible seed-interpreter maintenance change: it fixes a production semantic defect in the interpreter path the current stack uses, and #13225's log read cannot honestly land on top of the old behavior.
The recurring-failure row is also honest about the remaining ceiling: emitted code still treats a non-Text authored name as Json rather than refusing. That means this PR aligns the valid WireFormat spellings and makes the interpreter fail closed; it does not yet make the property one parse-time typed value shared by both realizations. The row's next-rung trigger correctly owns that broader repair.
Two prose phrases should not be read more strongly than the code: the system is not fully 'unified' for invalid spellings yet, and the witness comment saying neither realization can take quoted Text is stronger than the RFM's accurate statement that emission still falls through to Json. Those are non-blocking because the modeled production contract and debt row are correct.
Exact-head required CI is still running; land only after it is green.
…ops and witness to RestResult Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A silent wrong answer (DESIGN §5), with a discriminating RED.
The interpreter's
dispatch_restreadtransport rest { response_format }only as a string literal and defaulted every other spelling to Json. Emitted code (v1.compiler.emit_rustemit_plain_response_body) reads the authoredstd.serializationWireFormatvariant instead. So one declaration had two meanings:response_format: Text, the typed spellinggithub.Pulls.Diffuses, was JSON-decoded by the interpreter."Text"worked in the interpreter and was read as Json by emitted code.Probe, live against api.github.com, with the PR-diff Accept header on #13225. Two operations identical except for the spelling:
Text:RestBodyUndecodable { status: 200, cause: JSON body did not decode: expected value at line 1 column 1 }"Text":RestOk, 2,964 diff lines.Fix. The interpreter now reads the property through the emitter's own
v1.std.coretransport_response_format+authored_name_at:TextandJsonare accepted.No module on main uses the quoted spelling.
github.Pulls.Diffis the one user, and it is now read as declared.Witnesses (
test.claim.rest_exchange_replay_test, hermetic replay through the realdispatch_rest):a_text_response_format_reads_a_plain_body_as_textan_unrecognized_response_format_refuses_rather_than_defaulting_to_jsonOn the current main-built interpreter these two came back
FF, with the existingrest_success_projects_rest_okcontrolT. That is the RED. I could not build the fixed interpreter in my session: local builds fail on host thread limits, and the remote executor refuses to run the interpreter without a cgroup memory limit. So the GREEN is this PR's own floor run, which executes these witnesses.RFM row
response_format_variant_silently_read_as_jsonnames the remaining gap: emitted code still treats any non-Textspelling as Json without refusing. Its ceiling is structural: decode the property asWireFormatonce at parse, for both realizations.Ordering with #13225. #13225 currently uses
"Text". Once this lands, that spelling refuses, so I'll switch #13225 to bareTextin the same motion.🤖 Generated with Claude Code