Observed behavior: At reviewed Bug #925 candidate
d97557afa050276d8b03d0e643577eb921dc701f, the public pure
sanitizeError export is non-idempotent for the fictional input
'file://host'['/private']?next/Users/SECRET. The first pass returns
'file://host'['<path>']?next/Users/SECRET; a second pass changes it to
'file://host'['<path>']?next<path>.
Current default branch returns the first-pass form and remains stable, so this
is an unmerged candidate interaction rather than a shipped regression.
Expected behavior: One sanitization pass should produce output that remains
stable under repeated sanitization when non-delimiter query text separates a
quoted file path from a later slash-prefixed path.
Root cause: The quoted-path state retained for bracket-wrapper handling
classifies the later slash differently before and after the first path is
replaced by <path>. The intervening ?next text bypasses the direct
?/Users boundary covered by Bug #925's current tests.
How to reproduce safely: Call the exported pure sanitizer with the literal
fictional string above, then sanitize the first output again and compare the
exact results. No filesystem, daemon, network, credentials, or production data
are involved.
Resolution context: Discovered by the refreshed exact-head review of Bug
#925 and PR #1080 after candidate d97557af was published. It is distinct from
Bug #1010's pathless query-bracket state, Bug #1111's nested HTTPS tail, and the
closed intermediate-candidate Bug #1077.
Campaign scope: Accepted P2 deferred after the initial remediation budget
was exhausted. Native Bug outside the frozen S3 and S4 inventories; link only
and do not add it as a native child of the campaign Epic.
Environment:
Observed behavior: At reviewed Bug #925 candidate
d97557afa050276d8b03d0e643577eb921dc701f, the public puresanitizeErrorexport is non-idempotent for the fictional input'file://host'['/private']?next/Users/SECRET. The first pass returns'file://host'['<path>']?next/Users/SECRET; a second pass changes it to'file://host'['<path>']?next<path>.Current default branch returns the first-pass form and remains stable, so this
is an unmerged candidate interaction rather than a shipped regression.
Expected behavior: One sanitization pass should produce output that remains
stable under repeated sanitization when non-delimiter query text separates a
quoted file path from a later slash-prefixed path.
Root cause: The quoted-path state retained for bracket-wrapper handling
classifies the later slash differently before and after the first path is
replaced by
<path>. The intervening?nexttext bypasses the direct?/Usersboundary covered by Bug #925's current tests.How to reproduce safely: Call the exported pure sanitizer with the literal
fictional string above, then sanitize the first output again and compare the
exact results. No filesystem, daemon, network, credentials, or production data
are involved.
Resolution context: Discovered by the refreshed exact-head review of Bug
#925 and PR #1080 after candidate
d97557afwas published. It is distinct fromBug #1010's pathless query-bracket state, Bug #1111's nested HTTPS tail, and the
closed intermediate-candidate Bug #1077.
Campaign scope: Accepted P2 deferred after the initial remediation budget
was exhausted. Native Bug outside the frozen S3 and S4 inventories; link only
and do not add it as a native child of the campaign Epic.
Environment: