Commit Graph

5 Commits

Author SHA1 Message Date
can1357 c66fac2ddd fix(tools): let an existing literal selector-list filename stay writable
Probe the full target with probeLiteralPathExists before classifying it as a
mis-dispatched read-selector list, matching the single-selector guard, so an
existing POSIX file like 'report:1-2;archive:3-4' can still be overwritten.
2026-07-28 10:59:36 +02:00
roboomp 4ac322db93 fix(tools): refuse write targets shaped as a read-selector list
The read-selector-misfire guard (#6123/#6387) short-circuited whenever
`content` was non-empty, so a semicolon-joined list of read selectors
(`a.txt:1-2;b/c.txt:3-4`) passed as a write path with content fell through
to ordinary filesystem creation and silently built a nested directory tree
in the workspace. `read` accepts no such list, so this shape is always a
mis-dispatched multi-file read.

Refuse any target that splits on `;` into 2+ segments each carrying its own
read selector, regardless of `content` — the non-empty-content escape hatch
covers a lone selector-shaped filename, never a `;`-list.

Fixes #6809
2026-07-27 14:20:33 +00:00
roboomp 144043ad48 fix(coding-agent): used session settings in file guards
Passed session-scoped settings through Edit and Write generated-file checks and fell back to schema defaults when no global singleton exists.

Guarded inline image sizing against an uninitialized global settings proxy and added isolated-session regression coverage.

Fixes #6549
2026-07-24 22:42:38 +00:00
roboomp 75668387db fix(write): guarded selector-shaped archive members
Applied the read-selector misfire check to archive members after loading
the archive entry map and before mutation. Missing empty selector-shaped
members now fail closed, while existing literal members remain writable.

Added regression coverage proving rejected writes leave archives unchanged.
2026-07-23 20:07:07 +00:00
roboomp c232c3af76 fix(write): reject local read-selector-shaped write targets
A read-only step that mis-dispatches read as write passes the full read
expression (src/foo.tsx:1-260:raw) as the target. Because a literal colon
filename is legal on POSIX (#4618), write resolved it to filesystem creation
and reported success, leaving a stray zero-byte file the model could not
recover from - the local analogue of the xd:// near-miss guard (#6123).

assertNotReadSelectorMisfire now fails closed when the tail parses as a
read-tool selector, the literal target is missing, and content is empty,
pointing at the equivalent read(...). Non-empty content stays the escape
hatch and existing literal colon filenames remain writable.

Fixes #6387
2026-07-23 18:39:36 +00:00