Skip to content

fix(core): forward-slash provenance references on every platform - #61

Open
Apageoflove wants to merge 1 commit into
tigerless-labs:mainfrom
Apageoflove:fix/provenance-separator
Open

Apageoflove wants to merge 1 commit into
tigerless-labs:mainfrom
Apageoflove:fix/provenance-separator

Conversation

@Apageoflove

Copy link
Copy Markdown

Fixes the second family of #55 (one correction to that issue below).

_store_provenance returned str(relative_to(...)), which embeds the win32 separator, and three read-side guards then refused those references: the membership gate in trace.read compares strings (an explicit --pointer must appear in the record's provenance), and _legacy rejects any backslash outright as part of its only-stored-excerpt-files stance. Net effect: a store written on win32 could not trace its own provenance, the CLI exiting with not a range cited by this memory or unsupported provenance depending on entry point.

The write side now stores relative_to(...).as_posix(), so new references are forward-slash on every platform. The read side normalises both comparison surfaces, the gate and _legacy, before any validation runs, so stores written before the fix stay readable too.

The security posture is unchanged. Normalisation happens before the PurePosixPath guards, so traversal attempts via either separator are still caught by the dot-part check; a dedicated test pins that archive backslash dot-dot backslash escape.md is refused. One documented edge, same as #58: a pathological POSIX filename containing a literal backslash now normalises like a separator.

Verification, on real win32: test_no_provenance_and_legacy_excerpt goes red to green (verified by stashing the fix). Full unit suite 482 passed / 21 failed against the 481/22 pre-fix state, and the failure-set diff is exactly one test, the target. New tests: forward-slash stored references, a manufactured backslash reference tracing through the CLI, and the traversal pin; the traversal pin passes on the pre-fix code too, since the old code rejected every backslash, so it guards the new surface rather than driving red-green.

Correction to #55 while here: only one of the four progressive_trace failures was the separator bug; the other three fail on win32 at symlink setup (WinError 1314, no symlink privilege), a separate environment class, not separators.

Second family of tigerless-labs#55. _store_provenance returned str(relative_to(...)),
which embeds the win32 separator, and three read-side guards then
refused those references: the membership gate in trace.read compares
strings, and _legacy rejects any backslash outright. A store written on
win32 could not trace its own provenance.

Write side now stores relative_to(...).as_posix(). Read side normalises
both comparison surfaces (the gate and _legacy) before validating, so
stores written before the fix stay readable. The security posture is
unchanged: normalisation happens before the PurePosixPath guards, so
traversal via either separator is still caught by the dot-part check,
pinned by a dedicated test.

On real win32: test_no_provenance_and_legacy_excerpt goes red to green;
the three remaining progressive_trace failures on this machine are
symlink-privilege setup errors (WinError 1314), not separator issues.
Full unit suite 482 passed / 21 failed against the 481/22 pre-fix
state, failure-set diff exactly one: the target test.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant