Merge nucleic/olive-ember-seal-q7vk into dev

This commit is contained in:
2026-07-18 15:14:54 -07:00
parent 19218c7dae
commit 5ff6fd8631
5 changed files with 192 additions and 2 deletions
+21 -1
View File
@@ -6,7 +6,27 @@ stays open until fixed in the fork (or upstream) and re-verified by the corpus.
## Open
(none)
### D2 — non-ASCII bytes re-encoded through `read`/`echo` under C/empty locale
- **Found**: narOS N0 rootfs validation (first real-world install run under the
divert): with `/bin/sh → nash`, `ca-certificates`' postinst
(`update-ca-certificates`, a `while read`-over-conf loop) mangled the UTF-8
filename `NetLock_Arany_=Class_Gold=_Főtanúsítvány.crt` and failed the
whole image build. Worked around structurally in `os/mkimage/build-rootfs.sh`
(the divert is now always the image's last configure step), but any
*runtime* `apt install` inside narOS still runs postinsts under nash, so this
blocks narOS/M3 forcing gates until fixed.
- **Repro** (nash `0.4.0` musl arm64, empty locale):
`echo 'Főtanúsítvány' | nash -c 'while read x; do echo "$x"; done'` —
bash emits the input bytes unchanged (`F \305\221 t a n \303\272 …`); nash
emits each byte Latin-1→UTF-8 double-encoded (`F \303\205 \302\221 …`).
- **Suspected root cause**: brush decodes input bytes to `String` with a lossy/
Latin-1 assumption on the `read` path (or at word-splitting) instead of
keeping raw bytes; on output the char sequence is re-encoded as UTF-8.
POSIX shells treat variable values as byte strings.
- **Severity**: silent data corruption (not a parse failure, so the §4.1
bash-fallback cannot catch it). Needs a corpus case (`utf8-bytes-passthru`)
and a byte-preservation sweep of read/expansion/heredoc paths.
## Closed