Refuse a manifest whose inner message version is not one (closes #169) #173

Merged
clawbot merged 1 commits from issue-169-inner-version into next 2026-10-07 15:25:47 +02:00
Collaborator

Loading a manifest checked the outer message's version but never the inner message's, so an inner message of version 0, or of a later version, loaded as if it were version one. docs/FORMAT.md requires VERSION_ONE in both. deserializeInner now refuses any other inner version with errUnknownVersion, the error an unknown outer version already gets. The check runs as soon as the inner message is decoded, before the UUID checks.

Closes #169.

What the diff does not show:

  • Two tests in mfer/deserialize_path_test.go, TestDeserializeRefusesEntriesThatDecodeTooLarge and TestDeserializeDropsUnknownFields, built inner messages by hand with no version and expected them to load. They now write version one, as craftInnerBytes in the same file already did. The three bytes this adds to the decoded-size test's message leave both of its cases on the same side of the limit.
  • The builder has always written inner version one, so no manifest mfer wrote earlier is refused by this.

Model: opus-5-5

Loading a manifest checked the outer message's `version` but never the inner message's, so an inner message of version 0, or of a later version, loaded as if it were version one. `docs/FORMAT.md` requires `VERSION_ONE` in both. `deserializeInner` now refuses any other inner version with `errUnknownVersion`, the error an unknown outer version already gets. The check runs as soon as the inner message is decoded, before the UUID checks. Closes https://git.eeqj.de/sneak/mfer/issues/169. What the diff does not show: - Two tests in `mfer/deserialize_path_test.go`, `TestDeserializeRefusesEntriesThatDecodeTooLarge` and `TestDeserializeDropsUnknownFields`, built inner messages by hand with no version and expected them to load. They now write version one, as `craftInnerBytes` in the same file already did. The three bytes this adds to the decoded-size test's message leave both of its cases on the same side of the limit. - The builder has always written inner version one, so no manifest mfer wrote earlier is refused by this. Model: opus-5-5
clawbot added the needs-review label 2026-10-07 14:42:20 +02:00
clawbot self-assigned this 2026-10-07 14:42:20 +02:00
clawbot added 1 commit 2026-10-07 14:42:21 +02:00
Loading a manifest checked only the outer message's version, so an
inner message of version 0 or a later version loaded as if it were
version one, although docs/FORMAT.md requires VERSION_ONE in both.
deserializeInner now refuses any other inner version with the same
error as an unknown outer version. Two existing tests built inner
messages with no version and expected them to load; they now write
version one.

Model: opus-5-5
Author
Collaborator

Review passed, on next at f663f4242d06dcfe473ec9a089be5351d24f006d.

Model: opus-5-5

Review passed, on `next` at `f663f4242d06dcfe473ec9a089be5351d24f006d`. Model: opus-5-5
clawbot merged commit 01ff67a38e into next 2026-10-07 15:25:47 +02:00
clawbot deleted branch issue-169-inner-version 2026-10-07 15:25:48 +02:00
Sign in to join this conversation.