Fix crashes and lost messages - #2
Merged
Merged
Conversation
A review of the codebase found these bugs. Crashes: - The switcher's down key set pick to -1 with no matches, and the next refilter indexed matches[-1]. - Opening a space kept the old thread cursor, so an event during the load left it past the end and enter indexed out of range. - Image and GIF decoding allocated by the declared size. A small file could declare gigabytes. Sizes are now checked with DecodeConfig, and GIFs are cut to a bounded number of frames before decoding. Lost or wrong messages: - Messages that arrived while a space loaded were replaced by the load result. They are now merged in. - A live reply to a thread outside the loaded history showed without its root, and loading older history then dropped the full thread. The thread is now fetched when its first reply arrives. - The first message in a new space was dropped when it beat the membership event. The space is now fetched first. - A failed page of older history blocked further loads until restart. Untrusted content: - Sender names, attachment names and quote labels go through clean. The renderer turns OSC 8 sequences into links, so stripC1 on the frame doesn't cover them. - The login callback ignores requests without our state, such as /favicon.ico, instead of failing the login, and never blocks on a repeated redirect. Smaller fixes: - Selecting the first thread or message no longer scrolls its first line out of view. - "*a* *b*" bolds both words. - Deleting a message keeps the selection on the same thread or message. - Switching spaces drops a pending edit or quote. - A config.json with only a topic keeps the baked-in OAuth client.
KimNorgaard
force-pushed
the
fix-bug-hunt
branch
from
October 3, 2026 11:57
cc0ccc3 to
361c9bf
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the bugs from a review of the codebase. Two crashes come from normal keyboard use, and any member of a space could crash the client with an image. Messages could also be dropped silently. Rebased on #1, which already covers escape stripping and card link schemes.
matches[-1]target()DecodeConfigbefore decoding, and cut GIFs to a bounded number of frames withgifPrefixloadingOlderon errors so one failed page doesn't block older historyclean. The renderer turns OSC 8 into links, sostripC1on the frame doesn't catch them./favicon.ico, and never block on a repeated redirect*a* *b*config.jsononly sets a topic (README updated)Known gap: a delete or edit event that arrives while a space loads can still be overwritten by the load result.
Tested with:
🤖 Generated with Claude Code