Observed behavior: At default-branch commit 69deb505c0ff11148b35a10130176cf08d77f7ab, the public pure sanitizeError export retains a private path tail after an unrecognized adjacent file-shaped token. Fictional input https://outer.test/x?q=file://h.invalid/Users/afile://h2.invalid/Users/b produces https://outer.test/x?q=file://h.invalid<path>://h2.invalid/Users/b on its first pass. A second pass further redacts it.
A related backslash-tail input file://host.invalid?x=a\Users\a-file://h2.invalid/Users/b produces file://host.invalid?x=a<path>://h2.invalid/Users/b on its first pass.
Expected behavior: Private file path tails should not remain visible in a once-sanitized error. Preserve deliberate non-file URL recognition semantics while deciding how a path scanner should consume or classify these ambiguous tails.
Root cause: The scanner consumes file-shaped scheme letters into a preceding redacted path and stops at the colon. No nested-file start marker exists: the letter-glued literal fails the non-letter prefix rule, while the pathless backslash-tail path resets query context. The remaining forward-slash path is still classified as URL authority material.
How to reproduce safely: Call the public pure sanitizeError export once and twice with either literal above. No daemon, filesystem, network, credentials, or real data is needed.
Environment:
- Agent: Bug1060 owner; GLM-5.3 Max planning review discovery
- Connector: pure sanitizer export, Node25.9.0
- OS: Fedora Linux
Tracking: Distinct from #1060's recognized adjacent nested literal fix, which preserves recognized scheme boundaries without broadening prefix eligibility. Also distinct from #1077's compound quoted idempotence and #1111's bracketed HTTPS stability case. Discovered in #1060 planning before implementation; outside frozen S4 of #968, with no native campaign parenting. The recognized-literal fix for #1060 is PR #1127: #1127. This is a baseline finding, not a spent-round P2 deferral.
Observed behavior: At default-branch commit
69deb505c0ff11148b35a10130176cf08d77f7ab, the public puresanitizeErrorexport retains a private path tail after an unrecognized adjacent file-shaped token. Fictional inputhttps://outer.test/x?q=file://h.invalid/Users/afile://h2.invalid/Users/bproduceshttps://outer.test/x?q=file://h.invalid<path>://h2.invalid/Users/bon its first pass. A second pass further redacts it.A related backslash-tail input
file://host.invalid?x=a\Users\a-file://h2.invalid/Users/bproducesfile://host.invalid?x=a<path>://h2.invalid/Users/bon its first pass.Expected behavior: Private file path tails should not remain visible in a once-sanitized error. Preserve deliberate non-file URL recognition semantics while deciding how a path scanner should consume or classify these ambiguous tails.
Root cause: The scanner consumes file-shaped scheme letters into a preceding redacted path and stops at the colon. No nested-file start marker exists: the letter-glued literal fails the non-letter prefix rule, while the pathless backslash-tail path resets query context. The remaining forward-slash path is still classified as URL authority material.
How to reproduce safely: Call the public pure
sanitizeErrorexport once and twice with either literal above. No daemon, filesystem, network, credentials, or real data is needed.Environment:
Tracking: Distinct from #1060's recognized adjacent nested literal fix, which preserves recognized scheme boundaries without broadening prefix eligibility. Also distinct from #1077's compound quoted idempotence and #1111's bracketed HTTPS stability case. Discovered in #1060 planning before implementation; outside frozen S4 of #968, with no native campaign parenting. The recognized-literal fix for #1060 is PR #1127: #1127. This is a baseline finding, not a spent-round P2 deferral.