Skip to content

node:path: name relative()'s buffers by role instead of by position - #39125

Merged
alii merged 1 commit into
mainfrom
farm/a3247df1/path-relative-buffer-names
Aug 15, 2026
Merged

alii merged 1 commit into
mainfrom
farm/a3247df1/path-relative-buffer-names

Conversation

@robobun

@robobun robobun commented Aug 15, 2026

Copy link
Copy Markdown
Collaborator

Problem

  • bun run rust:mordant reports two arg_named_like_other_param findings in src/runtime/node/path.rs, carried in mordant-baseline.toml: relative_posix_t and relative_windows_t each call resolve_*_t(&[from], buf2, buf3), passing their buf2 as the callee's buf parameter while the callee also has a same-typed parameter named buf2, so the call reads like a transposed argument.
  • The calls are correct. relative_*_t resolves to into its own buf (which also backs the returned slice), so from has to be resolved into a different buffer, and the third buffer is lent to both resolve_*_t calls as scratch and then reused to accumulate the .. segments. Only the positional names (buf2, buf3) made that look like a mistake.

Fix

  • Rename the second and third buffers of relative_posix_t, relative_windows_t, their _js_t wrappers and relative_js_t to from_buf and tmp_buf, and update the comments that named them. The calls now read resolve_*_t(&[from], from_buf, tmp_buf) and resolve_*_t(&[to], buf, tmp_buf). resolve_posix_t / resolve_windows_t and their other callers are untouched.
  • Pure rename, no behavior change.
  • mordant-baseline.toml: regenerated the [bun_runtime] section. This drops the arg_named_like_other_param:src/runtime/node/path.rs entry, and also narrowed_two_ways:src/runtime/node/node_crypto_binding.rs, whose finding crypto: store PBKDF2's key length as usize #37648 removed without touching the baseline (it merged a few minutes after ci: pin mordant at the renamed lints; rename the disabled list and baseline keys to match #38875 regenerated the file). Happy to drop that second line if this PR should stay strictly scoped.
  • Verified:
    • MORDANT_BASELINE_WRITE=1 cargo dylint --all -p bun_runtime --no-deps (the rust:mordant:baseline script scoped to the one crate this touches; bun_runtime has no cargo features, so the crate is compiled the same way as in the workspace run) rewrites [bun_runtime] with exactly those two entries removed and nothing added.
    • bun bd test test/js/node/path/: 123 pass, 3 skip (Windows-only), 0 fail. relative.test.js exercises both path.posix.relative and path.win32.relative, so both renamed functions run on Linux.

Background

  • mordant is the lint pack bun run rust:mordant runs (pinned in Cargo.toml under [workspace.metadata.dylint]). mordant-baseline.toml is a ratchet: per (lint, file) counts of pre-existing findings that CI tolerates, so fixing a site means also deleting its baseline entry, and a stale entry silently absorbs one new finding of that kind in that file.
  • arg_named_like_other_param fires when an argument is spelled with the name of a callee parameter other than the one it is bound to, and the two parameters share a type (so an actual swap would compile). Renaming the value on either side so the names no longer cross is the intended way to clear a correct call.

relative_posix_t and relative_windows_t resolve `from` into their second
buffer and use the third as scratch for both resolve_*_t calls, so the
calls passed `buf2` as the callee's `buf` parameter and read like a
transposed argument (mordant's arg_named_like_other_param). The calls
are correct: `buf` is taken by `to` and the returned slice. Rename the
two buffers to from_buf and tmp_buf and drop the baseline entry.

Regenerating the baseline for bun_runtime also drops the
narrowed_two_ways entry for node_crypto_binding.rs, which #37648 fixed
without removing it.
@coderabbitai

coderabbitai Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@robobun, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 31 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 2099de74-ca9b-4e95-842d-08567edcd6a2

📥 Commits

Reviewing files that changed from the base of the PR and between 88a6398 and bc537a5.

📒 Files selected for processing (2)
  • mordant-baseline.toml
  • src/runtime/node/path.rs

Comment @coderabbitai help to get the list of available commands.

@robobun

robobun commented Aug 15, 2026 •

Copy link
Copy Markdown
Collaborator Author
Updated 11:05 AM PT - Aug 15th, 2026

@robobun, your commit bc537a5 is building: #98341

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — pure local-variable/parameter rename to clear a lint finding, no behavior change.

What was reviewed:

  • Confirmed every buf2/buf3 occurrence inside relative_posix_t, relative_windows_t, their _js_t wrappers, and relative_js_t was renamed; remaining buf2 hits in path.rs all belong to other functions.
  • Checked resolve_posix_t/resolve_windows_t signatures — new argument names no longer alias a differently-positioned callee parameter, so the baseline entry removal is correct.
  • relative_posix_t/relative_windows_t have no other callers beyond the updated wrappers.
Extended reasoning...

Overview

This PR renames two &mut [T] parameters (buf2 → from_buf, buf3 → tmp_buf) in relative_posix_t, relative_windows_t, and the three thin wrappers that thread them through (relative_posix_js_t, relative_windows_js_t, relative_js_t) in src/runtime/node/path.rs. It updates a handful of comments that referenced the old names, and drops two entries from mordant-baseline.toml: the arg_named_like_other_param:src/runtime/node/path.rs entry this rename resolves, and a stale narrowed_two_ways:src/runtime/node/node_crypto_binding.rs entry the author explains was orphaned by a merge race between #37648 and #38875.

Security risks

None. This is a lexical rename of local buffer bindings with no change to types, ordering of arguments at call sites, buffer sizing, or control flow. No user-facing surface changes.

Level of scrutiny

Low. The diff is mechanical and self-contained: I grepped path.rs for residual buf2/buf3 references and confirmed none remain within the touched functions (lines 2395–2780); all other buf2 hits belong to join_*_t, resolve_*_t, and to_namespaced_path_*, which the PR intentionally leaves alone. The callee signatures (resolve_posix_t(paths, buf, buf2) / resolve_windows_t(paths, buf, buf2)) confirm the lint's original complaint and that the new names (from_buf, tmp_buf) no longer collide. Argument order is preserved at every call site — this compiles to identical code.

Other factors

  • The only callers of relative_posix_t/relative_windows_t are the two _js_t wrappers updated in this diff, so the rename is complete.
  • The extra baseline deletion (narrowed_two_ways:...node_crypto_binding.rs) is a ratchet-file cleanup the author regenerated and explicitly flagged; since the baseline is a per-(lint,file) tolerance count, removing a stale entry only tightens CI and cannot mask a regression.
  • Author reports bun bd test test/js/node/path/ passes (123 pass / 3 skip), which covers both path.posix.relative and path.win32.relative — appropriate coverage for a no-op rename.

@alii
alii merged commit 99158b4 into main Aug 15, 2026
11 of 14 checks passed
@alii
alii deleted the farm/a3247df1/path-relative-buffer-names branch August 15, 2026 18:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants