Repository navigation
fix: ten issues from the second 2026-10-08 read-only audit - #173
Merged
Merged
Conversation
14 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary / 摘要
A second read-only audit of the snapshot merged in #172 listed 19 findings. Each was checked against the source; this PR fixes the ten that are real and small. The rest are left alone: they are low-impact, theoretical for the bundled plugins, or need a product decision.
claimed:<iso>; when the process ended before it released or resolved the claim, every later resume answered 409 and the player could only abandon it. The suspension sweep now releases such claims: every claim at server start on SQLite and memory (one process owns the store), claims older than one hour on PostgreSQL (another process may be resuming). The player may then resume again, the same as after a resume that failed; an external call the ended run had made is not undone.DataStoregainsreleaseStaleSuspensionClaims.PreStateCommithook. The declared-effects guard ran only before the hook, so a hook could move a write to a namespace the runtime did not declare.ctx.media.ingestUrlread the whole body of each 3xx response, outsidemaxBytes. On the old code the new test runs the worker out of heap.resolveI18nText;pregamereads the world throughctx.worldinstead of a store method only bundled plugins receive.Type of change / 变更类型
Verification / 验证方式
pnpm checkpnpm testpnpm test:pg(store contract 1165 passed, none skipped; server integration 28 passed)pnpm e2e:smoke/pnpm e2e— not run; the only UI change is one error line in the Operator Access pane, covered by its unit testpnpm validate:world worlds/emberback worlds/haruka-academypnpm e2e:verify— not runThe new tests for the proposal guard and the redirect body were run against the unfixed source: the first fails, the second crashes the worker with an out-of-memory error.
Not verified / 未验证:
COVEL_SUSPENSION_TTL_MSwith a dead claim is released and then expired in the same sweep. One existing test asserted that a very old claim is never swept; it now uses a fresh claim.tabletop-ruleskeeps its own attribute-name fallback: it ships self-contained and the plugin i18n gate rejects a hand-written language fallback.Related issue / context / 关联
Follows #172. Audit report:
devs/docs/audits/2026-10-08-readonly-audit-2/(gitignored).Docs sync / 文档同步
docs/reference/updated for changed contracts, APIs, tools, or protocol —docs/reference/api.md(Suspend / Resume).en.mdsibling changed together —docs/guide/env-registry.mddocs/CHANGELOG.mdhas an entry under[Unreleased]for user-visible changesAGENTS.mdupdated if packages, root scripts, or conventions changed — n/a