Skip to content

Claude/magical franklin d6gsu5 - #12

Merged
caparomula merged 9 commits into
mainfrom
claude/magical-franklin-d6gsu5
Oct 2, 2026
Merged

caparomula merged 9 commits into
mainfrom
claude/magical-franklin-d6gsu5

Conversation

@caparomula

Copy link
Copy Markdown
Collaborator

No description provided.

claude added 9 commits October 2, 2026 00:43
The README and the extension README linked to the latest release, which
GitHub never resolves to a pre-release, so a reader was sent past the
test build of the next version. Both now link to the releases page.
doc/STANDALONE.md says that the one-line installers skip pre-releases
and that a pre-release is tried by building the code.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
All 42 open Dependabot alerts (21 high, 16 medium, 5 low) were in the
extension's package-lock.json, and every one came through @vscode/vsce,
the packaging tool: undici, fast-uri, js-yaml, brace-expansion,
markdown-it, linkify-it, form-data, tmp, qs, uuid, and lodash. These are
development dependencies; the extension has no runtime dependencies and
is packaged with --no-dependencies, so none of them is in the .vsix.

npm audit fix updated them within the ranges package.json already
allows, so only the lock file changes. Every alert's vulnerable range
matched the old lock file and none matches the new one; npm audit
reports no vulnerabilities. A clean npm ci compiles, the extension's 38
tests pass, and vsce packages the .vsix.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
…ed up front

msgpack-core 0.9.8 has CVE-2026-21452 (GHSA-cw39-r4h6-8j3x, high):
readPayload(int) allocates the declared length before reading, so a
header declaring 2 GB over a few bytes of data exhausts the heap. The
parsed-log disk cache reader calls it for binary and extension values.
That reader is not on the load path and reads only the server's own
CRC-checked files, so the exposure was small, but the OutOfMemoryError
escaped read()'s catch (Exception) instead of rejecting the file.

0.9.12 reads a declared length over 64 MB in chunks and fails when the
input ends. A parameterized test writes a valid, checksummed cache file
whose one value declares about 2 GB in BIN32 or EXT32 form, and checks
that read() returns null while this thread allocates under 32 MB. On
0.9.8 it aborts the test run with "Java heap space"; on 0.9.12 it
passes. Dependabot does not see Gradle dependencies, so this was found
by querying OSV for the runtime classpath; the other eight runtime
libraries have no known vulnerabilities.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
…tests

npm test ran node --test out/test/, and Node 21 and later reject a
directory there, so the extension's tests could not run on a current
Node. No single command line works everywhere: Node 20 takes a directory
but no wildcard, Windows' shell does not expand one, and with no
argument Node 22 also runs the TypeScript sources and declaration files.
src/test/runTests.ts lists the compiled *.test.js files beside it and
runs them in one node --test process; finding none is a failure. It is
compiled into out/test, which is not packaged.

CI only compiled the extension, which is why the failure went unseen.
It now runs npm test on Linux and Windows. The 38 tests pass on Node
20.20 and 22.22; a failing test and an empty test directory each fail
the run. doc/DEVELOPMENT.md and the changelog say so.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
…'s libraries

GitHub's dependency graph does not read build.gradle, so Dependabot only
ever alerted on the extension's npm packages; the msgpack-core
vulnerability in the server JAR was found by hand. A new CI job, on
pushes to main only, runs gradle/actions/dependency-submission, which
submits the dependencies Gradle resolves (runtime, test, and build
plugins). It needs contents: write, granted to that job alone.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
Without an order, the Settings editor lists an extension's settings
alphabetically, which put Additional Log Directories before Log
Directory. Each setting now has an order: the log directory, the
additional directories, the team number, the TBA API key, Claude Code,
then the Java path, the WPILib year, and the heap.

The TBA API key setting was marked deprecated, and the Settings editor
hides a deprecated setting that has no value, so there was no field for
the key. It is now a write-only field: a key pasted into it is moved
into VS Code's secret storage and the setting is cleared, so no
settings file keeps it, and ignoreSync keeps Settings Sync from
uploading it in the meantime. Its description links the commands that
set the key in a masked box and remove it.

The Settings editor writes a text setting each time typing pauses for a
second, so a key is moved only after the field has been unchanged for
three seconds; a key still being typed is not stored in pieces. Moves
run one at a time, and no longer wait for their notification: one that
nobody closed held up every later move. A key in the user's settings
now replaces the stored key (it was ignored when one was stored, while
the message said it was saved). A key in a workspace's settings still
never replaces a stored key, since it may be a teammate's committed
with the project, and the message now says which key is in use. The
editor refreshes a focused field only once the user leaves it, so a key
pasted into a field still showing the stored one is appended to it; the
part after the stored key is taken as the new key. Changing the key
field no longer restarts the server; storing the key does.

The decisions are in src/tbaKey.ts, without the VS Code API, with
tests; the manifest tests check the order, the field's declaration,
and that every command a description links to is declared. In VS Code
1.101 and 1.140, driven through the real Settings editor: the order is
as listed, a pasted key, a key typed with a pause, and a key pasted
into a stale field each end up in secret storage exactly (read back
from VS Code's store after it quit), settings.json keeps none of them,
the description's link removes the stored key, and a key in a
project's committed settings is removed from that file with a warning.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
build.gradle and, through syncExtensionVersion, the extension's
package.json and lock file. The release workflow publishes a tag only
when it matches this version.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
…r once

Found by the extension tests' first run on Windows CI. A relative log
folder resolved inside the project has backslashes (C:\robot\logs),
while the same folder given as an absolute path kept its forward
slashes (C:/robot/logs). The paths were compared as strings, so the
folder was passed to the server twice and its logs listed twice. A
trailing separator, a .. segment, or another letter case did the same.

Directories are now compared as the file system names them: normalized,
without a trailing separator, and ignoring case on Windows. Each is
passed normalized, the first spelling kept. combineLogDirectories takes
the platform's path rules as an optional argument, so the tests check
the Windows and the POSIX rules on every platform.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
The previous commit also passed every folder normalized, so on Windows
"/logs" became "\logs", which changed what four tests pin down and
failed them on Windows CI. Folders are compared as the file system names
them, as before, but each is passed as written, the first spelling of
a folder kept.

Checked by running the directory tests with Node's Windows path rules
in place of the platform's: they reproduce the five failures Windows
CI reported against the previous commit, and pass with this one, except
the home-folder test, which fails there only because this machine's
home folder is a POSIX path; it passes on Windows.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015wo6ufDtEY27NQ8ctU5ns5
@caparomula
caparomula merged commit 41ab71c into main Oct 2, 2026
3 checks passed
@caparomula
caparomula deleted the claude/magical-franklin-d6gsu5 branch October 2, 2026 15:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants