Repository navigation
PRODUCE-PY P2f: the cold read's four fixes before 0.1.0 - #3
Merged
Merged
Conversation
The static scanner now reports any route to a digest module outside pin.py: an imported alias (from .pin import hashlib), an attribute (pin.hashlib), a name, a string naming one, a sys.modules lookup that names one or is not a literal, and import_module or __import__ with a non-literal name. A run-time test records each hashlib constructor call by its calling frame while the five commands and every helper run, and fails on any typedstandards module but pin. The cold read's four routes join the offender tree. Red first: the old scanner returned [] over the four routes; temporary offending calls in _sidecar.py failed the guards, including one with names built at run time that only the run-time test caught. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ru4PYga7Zf8HANgotZKs4u Signed-off-by: Nathan Storey <npstorey@users.noreply.github.com>
The date and time check now leaves out the URL's authority (the host fact and the encoded host in the link), so 192.168.1.10:8080 no longer reads as 10:80. It also checks the URL past its authority as written and percent-decoded, so a time in the path, query or fragment is refused: the cell carries the URL encoded, which had hidden a time's colon from the check. Red first: the IP-with-port URL was refused, and a time in the query (raw or encoded) or fragment was accepted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ru4PYga7Zf8HANgotZKs4u Signed-off-by: Nathan Storey <npstorey@users.noreply.github.com>
Only the five commands, cli_version() and show without a result run the CLI; the README now says so, and that pin, badge_cell, comparison_cell, sidecar and show(record, result) run without Node. A test pins both halves with the Node override pointed at a missing file. The CLAUDE.md link is absolute, and a test fails on any relative link or image in the README. CHANGELOG entries under Unreleased. Red first: the link test caught [CLAUDE.md](CLAUDE.md). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ru4PYga7Zf8HANgotZKs4u Signed-off-by: Nathan Storey <npstorey@users.noreply.github.com>
Owner
Author
|
GO — CAT PLAN (the program seat), bound to head Read from GitHub and disk, 2026-10-04:
The owner merges with |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This fixes four low findings from the cold read of P1 and P2 (npstorey/typedstandards#135, comment 5979743999): findings 1, 2, 3 and 4b. The owner ruled that these land before 0.1.0 is cut. No version heading is added and
__version__is unchanged; the release PR follows this one.Branch:
ts135/p2f-coldread-fixes· Head:83c486853536777516b19da9741b71f18cd570fb· Base:mainat2a8ac5dSize:
git diff --numstat main...HEAD: 7 files, +246 −22.Blast zone: this branch only. Files touched:
tests/guards.pytests/test_guards.pytests/test_badge.pytests/test_readme.py(new)src/typedstandards/_badge.pyREADME.mdCHANGELOG.md_cli.py,_commands.py,_node.py,errors.pyand the CI workflow are unchanged.The fixes
pin.py: an imported alias (from .pin import hashlib), an attribute (pin.hashlib), a name, a string naming one, asys.moduleslookup that names one or uses a non-literal key, andimport_moduleor__import__with a non-literal name. The cold read's four routes are now in the offender tree.hashlibconstructor call by its calling frame while the five commands and every helper run. It fails on anytypedstandardsmodule other thanpin; third-party frames are not counted. It also asserts that it sawpin's own call, so the recorder is shown to work.hash_imports(PACKAGE, allow=frozenset())still names onlypin.py.sign,withdraw,attest,view,verify,cli_version(), andshowwithout a result run the CLI and need Node.pin,badge_cell,comparison_cell,sidecarandshow(record, result)run without it. A test pins both halves, withTYPEDSTANDARDS_NODEpointed at a missing file. The code was already correct, so this test passes before and after; the fix itself is the text.badge_cellaccepts a host with a port. The date and time check now leaves out the URL's authority, so192.168.1.10:8080andrecords.example.org:8443are accepted.?t=12:30) or the fragment was accepted before this change, not refused.CLAUDE.mdlink is now absolute, and a test fails on any relative Markdown link or image (#anchorlinks are allowed).Acceptance
Each red below was driven locally.
[]over the four routes, and the offender-tree test failed on the four missing files. Temporary offending calls in_sidecar.pyfailed both guards. One of them, a route with names built at run time, failed only the run-time test.locate_nodeandrunis in the phase reporttest_the_helpers_need_no_nodepassedhttps://192.168.1.10:8080/…was refused; a time in the query (raw and encoded) or the fragment was accepted[CLAUDE.md](CLAUDE.md)Checks run locally on the head
From a clean clone at
83c4868, withUV_PYTHONset for each run:ruff checkandruff format --checkare clean.gitleaks git --log-opts="main..HEAD"scanned 3 commits and found no leaks. These runs were on macOS (arm64). CI has not run on this head yet: it runs once the branch is pushed.There are three commits. Each is signed (
G) and carries oneSigned-off-by: Nathan Storey <npstorey@users.noreply.github.com>, equal to the author email.Model: Claude Opus 5.5 (
claude-opus-5-5).🤖 Generated with Claude Code
https://claude.ai/code/session_01Ru4PYga7Zf8HANgotZKs4u