Repository navigation
Octet-as-char meaning fork: declared std.encoding ASCII route, rfc_5280 Time fails closed, honest non-UTF-8 fixture + RFM - #13384
Merged
gunbai-bot[bot] merged 1 commit intoOct 5, 2026
Conversation
…80 Time refuses non-ASCII; honest non-UTF-8 fixture + RFM Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This was referenced Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
XL-2 follow-up (manager lively-crane-656): the four OCTET-AS-CHAR sites of RFM
bare_from_code_point_binds_the_total_seed_builtin. Stacked on #13378 (still open, branchsession/bright-fox-380-fcp); retarget/merge after it lands.These sites spelled a BYTE as a character. That is a second meaning for
from_code_point(DESIGN §3, meaning fork), so none migrate tofrom_code_point. The derivation was approved by the manager before any code was written.Derivation
std.bytesandstd.machine_wordUInt8own octets, andstd.encodingowns encodings. No ASCII or Latin-1 route existed.UTCTime/GeneralizedTimeare VisibleString subsets, so ASCII only (X.680 §46–47, RFC 5280 §4.1.2.5).std.encoding ascii_decode_octets(List<Int>) -> AsciiDecodeOutcome.AsciiDecoded{text}|AsciiNonAscii{at, octet}.std.coercion unicode_scalar_fold.Migrated identities
Several of these modules are outside the required gate.
extdeps.git.object_store::git_ascii_field_textascii_decode_octets. NUL stays refused by git field policy (it is the delimiter), so behaviour is unchanged.extdeps.standards.rfc_5280::ascii_ofread_time_textconsumesascii_decode_octets. A non-ASCII Time octet refuses with the new armX509Refusal::X509TimeNotAscii{at, octet}.test.claim.git_upstream_model_witness::witness_git_ls_tree_z_preserves_non_utf8_path_octetsstd.bytes octets_bytes([255, …]), so the non-UTF-8 property is held at the decode interface. Its only bare call was the TAB constant, nowstd.unicode.scalar char_text(c: 9)(a Char constant, not an octet decode).test.manual.git_upstream_model_execution::git_r0_typed_execution_read_backraw_namewasconcat(from_code_point(255), ".dag"), written through the String path carrier. On disk that isC3 BF .dag, valid UTF-8, so it never exercised a non-UTF-8 path. Renamed honestly tonon_ascii_name(char_text(c: 255)).Behaviour change: rfc_5280
ascii_ofwas total: it spelled any octet as Latin-1 text, which is an implicit lossy crossing. A Time carrying a non-ASCII octet now refuses (X509TimeNotAscii) instead of being admitted as fabricated text. This fails closed, as DESIGN §5 requires. A VisibleString cannot carry 0x80..0xFF, so a conforming certificate is unaffected.Gap recorded (DESIGN §4d)
New RFM
gunbc.recurring_failure_mode.non_utf8_path_fixture_spelled_through_a_string_path_carrier. No executing path proves a real non-UTF-8 filesystem→git→read-back round trip, becauseextdeps.filesystem's path carrier isString.The parent RFM's OCTET-AS-CHAR population is updated to 0 identities, 4 dispositioned. No new bare
from_code_pointcaller is added. The CHAR-kind identities in the same modules (git_store_object_canonical_hash_inputNUL,ls_tree_z_record) belong to the CHAR population and are untouched here.Controls (claims run remotely on the exact head with
--claim-run)test.claim.ascii_decode_octets_witness_test(new):[0, 9, 65, 127]decodes exactly, NUL included.[46, 255, 128]refuses at position 1 with octet 255.test.claim.x509_rfc5280_witness_test::a_non_ascii_time_octet_refuses_and_an_ascii_time_reads:X509TimeNotAscii{at:1, octet:178}."22Z".the_sample_leaf_reads_as_openssl_reads_it(validity goes throughread_time).x509_rfc5280_witness_test(15/15)git_upstream_model_witness_test(all, including the non-UTF-8 witness and everygit_ascii_field_textconsumer)heal_candidate_witness_test(12/12;gunbc.heal_candidateconsumesgit_ascii_field_text)test.manual.git_upstream_model_execution: FAIL on the runner identically on the base branch (std.unicode.scalar: partial from_code_point (typed refusal) + char_text; migrate v2 callers #13378 head, same dispatch), so the failure predates this change. The log shows the fixture writingÿ.dag, which confirms the UTF-8 finding.false):git_r0_typed_execution_read_back→GitR0LiveFixtureExecutionRefused { diagnostic: "git-ls-tree-z-decode-refused" }, raised whereextdeps.git.object_store git_decode_ls_tree_zdecodes thegit -c core.quotePath=false ls-tree -z --format=…%x00…stdout. The inner cause, which the test discards ascause: _, isGitLsTreeZFramingRefused { GitNulQuartetIncompleteRecord { field_count: 0 } }. The result is identical on the std.unicode.scalar: partial from_code_point (typed refusal) + char_text; migrate v2 callers #13378 base. Not rostered underdag/gunbc/recurring_failure_mode; the manager will route it.No
floor_cross_claim_pure_producers_warmrows; no fill-debt rows needed.🤖 Generated with Claude Code