Skip to content

Strip control characters from feedback attachment filenames - #9548

Closed
austinywang wants to merge 2 commits into
mainfrom
issue-5717-feedback-composer-multipart-filename-onl
Closed

austinywang wants to merge 2 commits into
mainfrom
issue-5717-feedback-composer-multipart-filename-onl

Conversation

@austinywang

@austinywang austinywang commented Aug 4, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #5717

Summary

  • Strip Foundation control characters from feedback attachment filenames before interpolating them into multipart Content-Disposition headers.
  • Exercise the real FeedbackComposerClient.submit request path with a filesystem filename containing a quote, CR/LF, tab, DEL, and another C0 control.

Testing

  • Red at 3f54edb0d8: swift test --package-path Packages/macOS/CmuxFeedback --scratch-path <isolated-path> --filter FeedbackComposerClientTests on aws-m4pro-6 failed because the captured filename field still contained raw control bytes.
  • Green at 8d3737500e: the same remote command passed the regression test (1 test, 1 suite).
  • ./scripts/reload-cloud.sh --tag sym5717: remote build completed on leased fleet slot cmux9s-mac-mini.1; no local fallback was used. The default Blacksmith lane queued, and an earlier fleet slot was skipped after exposing a missing Zig 0.16.0 toolchain.
  • Tagged runtime check through /tmp/cmux-debug-sym5717.sock: cmux feedback --email test@example.com --body <test-message> --image <fixture> sent a filename whose input hex was 63617074757265220d0a696e6a656374656401097f2e706e67; the local capture endpoint received captureinjected.png with no control bytes. The tagged app was then stopped and its stale socket removed.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.


Summary by cubic

Strip control characters from feedback attachment filenames before building multipart Content-Disposition headers to prevent header injection and malformed uploads (fixes #5717). Added a test through FeedbackComposerClient.submit that uses a filename with quotes, CR/LF, tab, DEL, and other C0 controls, and asserts the sent name is sanitized.

Written for commit 8d37375. Summary will update on new commits.

Review in cubic

@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@austinywang, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 4 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: cc3ba502-93d8-4b90-a8b5-cb6c09c208fd

📥 Commits

Reviewing files that changed from the base of the PR and between 7dcb2bf and 8d37375.

📒 Files selected for processing (2)
  • Packages/macOS/CmuxFeedback/Sources/CmuxFeedback/Client/FeedbackComposerClient.swift
  • Packages/macOS/CmuxFeedback/Tests/CmuxFeedbackTests/FeedbackComposerClientTests.swift

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@lawrencecchen lawrencecchen added the stale-revisit Closed after 30+ days without activity; preserved for possible revisit or reopening. label Sep 23, 2026
@teamleaderleo

Copy link
Copy Markdown
Collaborator

Revived as #14783

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

stale-revisit Closed after 30+ days without activity; preserved for possible revisit or reopening.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feedback composer multipart filename only strips quotes, not CR/LF

3 participants