Skip to content

fix(client-runtime): prevent oversized thread search crashes - #136

Merged
gannonh merged 1 commit into
mainfrom
cursor/prevent-oversized-thread-search-da58
Aug 26, 2026
Merged

gannonh merged 1 commit into
mainfrom
cursor/prevent-oversized-thread-search-da58

Conversation

@gannonh

@gannonh gannonh commented Aug 26, 2026 •

Copy link
Copy Markdown
Owner

Closes #133

What Changed

Thread content search decoded its JSON cache key with JSON.parse plus Schema.decodeUnknownSync. A query over the 200-character contract, or a malformed key, threw during React render in web and mobile.

ThreadSearchKey is now Schema.fromJsonString around the existing tuple. Decode uses Schema.decodeUnknownOption. Invalid keys return { matches: [], isLoading: false } and do not call getSearchAtom. Valid merge, failure ignore, and local title search are unchanged.

Why

The command palette and mobile thread search subscribe to this shared atom. The hook only enforces the 2-character minimum, so a 201-character query still reached the atom and aborted the client.

Scope

  • packages/client-runtime/src/state/threadSearch.ts
  • packages/client-runtime/src/state/threadSearch.test.ts

Out of scope: server limit, truncation, new copy, ranking, snippets, web/mobile hook files, T3 identity.

Blast Radius

Web command palette and mobile thread search both use createThreadSearchResultsAtomFamily. They get empty content matches for an invalid query and keep title search. No contract, server, or layout change.

Verification

  • vp test run packages/client-runtime/src/state/threadSearch.test.ts (6 passed)
  • vp run --filter @kata-sh/code-client-runtime typecheck (exit 0; pre-existing discovery.ts suggestion only)
  • Diff identity search for @t3tools/, T3CODE_, t3code, pingdotgg/t3code: clean
  • CI on 104addbe: Check, Test, Mobile Native Static Analysis, Release Smoke green
  • Web command palette: 201-character query stayed up; shortening to sett restored Open settings; reopen restored the root list with no reload

Command palette with a 201-character query still open
Palette after shortening the query to sett, Open settings selected

Live mobile thread-search pass is blocked on this VM (no emulator). Mobile uses the same atom covered by the tests.

Acceptance matrix: #133 (comment)
Build report: #133 (comment)

Checklist

  • This PR is small and focused
  • I explained what changed and why
  • I included before/after screenshots for any UI changes (not applicable; layout unchanged)
  • I included a video for animation/interaction changes (not applicable)

Parent: #124. Upstream: pingdotgg/t3code#6633 at 421088c27.

To show artifacts inline, enable in settings.

Open in Web Open in Cursor 

Thread content search threw during render when a cache key was
malformed or the query exceeded the 200-character contract.

Refs #133

Co-authored-by: Gannon Hall <gannonh@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Aug 26, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: dc36821f-51ee-4944-9227-aeca06e7be98


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gannonh
gannonh marked this pull request as ready for review August 26, 2026 19:01
@gannonh
gannonh merged commit bd30df2 into main Aug 26, 2026
5 checks passed
@gannonh
gannonh deleted the cursor/prevent-oversized-thread-search-da58 branch August 26, 2026 19:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Vendor-pull slice 3c: prevent oversized thread search crashes

2 participants