Skip to content

fix(security): merge overlapping redaction ranges - #261

Draft
rabesss wants to merge 1 commit into
mainfrom
dot/fix-258-range-union
Draft

rabesss wants to merge 1 commit into
mainfrom
dot/fix-258-range-union

Conversation

@rabesss

@rabesss rabesss commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Fixes #258.

Extend an overlapping credential span through the full union rather than dropping its tail. Preserve contained, disjoint and adjacent-span behavior.

Validation

  • Reproduced both reported failures before the fix
  • Added 15 boundary cases, a 1,296-pair coverage oracle and the encoded escaped-quote regression
  • Secrets tests and race tests pass; new regressions pass 20 repetitions
  • Full vet, golangci-lint v2.12.1 (0 issues), and build with -buildvcs=false pass
  • Independent review found no issues

Full go test ./... was attempted. The unchanged baseline fails network-dependent client tests and nine player tests because this cloud sandbox cannot resolve example.com or bind AF_UNIX sockets. Worktree builds require -buildvcs=false due to the environment's VCS lookup. Hosted CI and Security passed on the final head: https://github.com/rabesss/impartus-cli/actions/runs/37479404062. The latest title check also passes.

This does not address the separate plain-text escaped-quote issue #257.

@rabesss
rabesss force-pushed the dot/fix-258-range-union branch from df9b66e to 492cac9 Compare October 6, 2026 14:29
@rabesss rabesss changed the title fix(secrets): merge overlapping redaction ranges fix(security): merge overlapping redaction ranges Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(secrets): merge overlapping ranges in replaceRawCredentialRanges

1 participant