fix(redirect): report redirection failures with bash's strerror wording - #2319
Merged
Merged
Conversation
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
bashkit | 04d1e2d | Commit Preview URL Branch Preview URL |
Aug 21 2026, 10:11 AM |
Redirection diagnostics rendered the Rust error-enum `Display`, so a missing file reported `bash: /nope: io error: file not found` where real bash reports `bash: /nope: No such file or directory`. Besides the parity gap this broke the nightly fuzz gate. `glob_fuzz` run 218 failed on input `</r\0ustc/`: the shell drops the NUL during expansion, so the redirect target became `/rustc/` *after* the target's own input pre-filter ran, and the unrecognized `io error:` template was reported as a TM-INF-016 host-path leak rather than a shell echo. `redirect_error_reason` drops the enum prefix and substitutes bash's strerror text — but only for messages that restate their `io::ErrorKind` and nothing more: the VFS placeholders in `ERRNO_RESTATING_MESSAGES`, and errors carrying a `raw_os_error` (whose Display appends a non-bash `(os error N)` suffix). Every other message survives verbatim, because a backend-specific reason tells an agent why in a way the bare errno cannot: `filesystem is read-only` must not collapse into `Permission denied`, and a custom `FileSystem` impl's wording is the only diagnostic its embedder gets. Those specific reasons are covered instead by adding their fixed templates to the harness echo filter, alongside the remaining errno templates.
chaliy
force-pushed
the
claude/pensive-hypatia-92oe7p
branch
from
August 21, 2026 10:10
cad9ae6 to
04d1e2d
Compare
2 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
Redirection failures no longer print the Rust error-enum
Display.ls < /nopenow saysbash: /nope: No such file or directory— real bash's wording — instead ofbash: /nope: io error: file not found.The substitution is deliberately narrow: only messages that restate their
io::ErrorKindand nothing more are replaced. A backend's own reason survives verbatim, because it tells an agent why in a way the bare errno cannot.This also unbreaks the nightly fuzz gate (
glob_fuzz), currently red onmain.Why
Two problems, one root cause.
Parity. Every redirection diagnostic rendered
crate::Error'sDisplay, which prefixesio error:and emits the VFS's internal message. Real bash prints the Cstrerrorstring.Red CI.
fuzz.ymlrun 218 failed on input</r\0ustc/:glob_fuzzpre-filters inputs that literally contain aUNIVERSAL_BANNEDshape, but the shell drops the NUL byte during word expansion — so the redirect target became/rustc/after that filter had already run. The leak detector suppresses such echoes only for lines matching a recognized real-shell template, andio error: file not foundis not one. A genuine echo of user input was reported as a TM-INF-016 host-path leak.Fixing the wording fixes both: the diagnostic becomes bash-accurate and recognizable as an echo.
Before / After
Real bash, for reference:
The crash input replayed through the actual fuzz target, rebuilt against this branch:
(before this branch, the same command aborted with
libFuzzer: deadly signal)New scaffold, which replays all three scripts
glob_fuzzbuilds from one input:Risk
Redirection error text changes. The first push of this branch collapsed every failure to bare errno text and turned 8 checks red — two Python binding tests asserting on the read-only reason, one of them backed by a custom
FileSystemimpl. That is exactly the information loss the narrow rule now avoids, and both tests pass unmodified. No test assertions were changed to accommodate this PR.Verified locally: workspace lib/bins/tests, doc tests,
realfs,failpoints,proptest_security,pytest(788 passed), clippy-D warnings,cargo fmt,check_okf.py,check_doc_links.py, plus a 10-minuteglob_fuzzsession against the rebuilt target.Expanding the harness echo filter narrows leak detection slightly. The added entries are fixed templates that quote the redirect target verbatim, same rationale as the existing entries; the byte-length cap and host-canary check still run on unfiltered stderr.
Two known-environmental local failures, both green on
mainin CI and unrelated to this diff:ssh_supabase_connects(sandbox blocks outbound port 22) andtest_tm_dos_021_fork_bomb_blocked(segfaults in a debug build; CI builds release).Checklist