Skip to content

fix: capture child and descriptor stdout in JSON envelopes - #420

Open
codeforester wants to merge 7 commits into
security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confifrom
bug/379-20261003-bug-json-single-envelope-stdout-contract-is-broken-by-any-wr
Open

codeforester wants to merge 7 commits into
security/385-20261003-security-validate-trust-of-ancestor-discovered-project-confifrom
bug/379-20261003-bug-json-single-envelope-stdout-contract-is-broken-by-any-wr

Conversation

@codeforester

Copy link
Copy Markdown
Contributor

JSON invocations now capture process descriptor 1 as well as Python stdout, so inherited subprocess output remains inside the single envelope. A concurrent drain avoids pipe deadlocks, the native path enforces the JSON capture limit, and descriptor restoration precedes envelope emission.

The guides state the boundaries: wait for children, flush native stdio before returning, and use NDJSON for large output. A child retaining stdout causes a bounded capture error.

Validation: 618 tests and 254 subtests; strict typing and repository style; real-process tests parse the whole stdout document after Python, descriptor, original-stream, and child writes and exercise native overflow.

Train: follows #419. Fixes #379.

…or-discovered-project-confi' into bug/379-20261003-bug-json-single-envelope-stdout-contract-is-broken-by-any-wr
…or-discovered-project-confi' into bug/379-20261003-bug-json-single-envelope-stdout-contract-is-broken-by-any-wr
…or-discovered-project-confi' into bug/379-20261003-bug-json-single-envelope-stdout-contract-is-broken-by-any-wr
…or-discovered-project-confi' into bug/379-20261003-bug-json-single-envelope-stdout-contract-is-broken-by-any-wr
…or-discovered-project-confi' into bug/379-20261003-bug-json-single-envelope-stdout-contract-is-broken-by-any-wr

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant