Loading a manifest checked the outer message's version but never the inner message's, so an inner message of version 0, or of a later version, loaded as if it were version one. docs/FORMAT.md requires VERSION_ONE in both. deserializeInner now refuses any other inner version with errUnknownVersion, the error an unknown outer version already gets. The check runs as soon as the inner message is decoded, before the UUID checks.
Two tests in mfer/deserialize_path_test.go, TestDeserializeRefusesEntriesThatDecodeTooLarge and TestDeserializeDropsUnknownFields, built inner messages by hand with no version and expected them to load. They now write version one, as craftInnerBytes in the same file already did. The three bytes this adds to the decoded-size test's message leave both of its cases on the same side of the limit.
The builder has always written inner version one, so no manifest mfer wrote earlier is refused by this.
Model: opus-5-5
Loading a manifest checked the outer message's `version` but never the inner message's, so an inner message of version 0, or of a later version, loaded as if it were version one. `docs/FORMAT.md` requires `VERSION_ONE` in both. `deserializeInner` now refuses any other inner version with `errUnknownVersion`, the error an unknown outer version already gets. The check runs as soon as the inner message is decoded, before the UUID checks.
Closes https://git.eeqj.de/sneak/mfer/issues/169.
What the diff does not show:
- Two tests in `mfer/deserialize_path_test.go`, `TestDeserializeRefusesEntriesThatDecodeTooLarge` and `TestDeserializeDropsUnknownFields`, built inner messages by hand with no version and expected them to load. They now write version one, as `craftInnerBytes` in the same file already did. The three bytes this adds to the decoded-size test's message leave both of its cases on the same side of the limit.
- The builder has always written inner version one, so no manifest mfer wrote earlier is refused by this.
Model: opus-5-5
Loading a manifest checked only the outer message's version, so an
inner message of version 0 or a later version loaded as if it were
version one, although docs/FORMAT.md requires VERSION_ONE in both.
deserializeInner now refuses any other inner version with the same
error as an unknown outer version. Two existing tests built inner
messages with no version and expected them to load; they now write
version one.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Loading a manifest checked the outer message's
versionbut never the inner message's, so an inner message of version 0, or of a later version, loaded as if it were version one.docs/FORMAT.mdrequiresVERSION_ONEin both.deserializeInnernow refuses any other inner version witherrUnknownVersion, the error an unknown outer version already gets. The check runs as soon as the inner message is decoded, before the UUID checks.Closes #169.
What the diff does not show:
mfer/deserialize_path_test.go,TestDeserializeRefusesEntriesThatDecodeTooLargeandTestDeserializeDropsUnknownFields, built inner messages by hand with no version and expected them to load. They now write version one, ascraftInnerBytesin the same file already did. The three bytes this adds to the decoded-size test's message leave both of its cases on the same side of the limit.Model: opus-5-5
Review passed, on
nextatf663f4242d06dcfe473ec9a089be5351d24f006d.Model: opus-5-5