Repository navigation
Conversation
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…den output Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Gate review (claude-opus-5-5) finding 1 at fc0c045: BLOCKER, CI red.
Cause: Suggested fix: wrap the buffer in a mutex-guarded |
|
Gate review (claude-opus-5-5) finding 2 at fc0c045: BLOCKER, vendor text reaches the model uncapped on the decode-error path.
Reproduced at this head with a scratch test (not pushed) that drives the real tool over MCP and sets With a 100000-byte value the tool error is 100126-100154 bytes for each enum-validated field: Success path is fine: the same injection (ESC, CSI, C1 U+009B/U+0085, U+200B, U+2028, >256 bytes) into every free-text field ( Suggested fix: in |
|
Gate review (claude-opus-5-5) finding 3 at fc0c045: mutation survivors. The author's "0 survivors" does not reproduce after the field reorder. I ran a fresh sweep: 118 valid hand-written mutants over Every survivor was checked against the pinned library's input validation. Real gaps: vendor free text the library accepts as-is, so dropping the cleaning goes unnoticed. Today only
I confirmed each field above is accepted by the decoder with ESC + U+009B + U+0085 + U+200B + U+2028 + >256 bytes. The production code cleans them correctly today (my injection probe: all CLEAN, at most 256 bytes); the tests just would not catch a regression. This is the same class of survivor the cli gate required fixing. Fix: inject the payload into every vendor string field of the wire fixture, and assert the cleaned value and the 256-byte cap per field. Minor test gaps (real but low impact):
Equivalent (no action): [40] plan_id (env-sourced, UUID-checked); [41] [43] [45] [46] [48] [51] [52] enum fields that the library rejects unless they are an exact enum value. [86]/[87] unrepresentable-decimal propagation: JSON decimal literals always terminate, so this is unreachable from the wire. It still deserves one DTO-level test, because silently dropping the error would turn money into Lint: |
|
Gate verdict (claude-opus-5-5): CHANGES REQUESTED at fc0c045. Not merged. Blockers:
Verified OK at this head:
Local evidence (fresh
Any new commit restarts the gate. |
…race Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Closes #48. Tracking: LeanerCloud/cloud-commitments-platform#786.
Adds
cudly_archera_comparison, a read-only tool that compares an Archera commitment plan (current offer and alternatives per line item, plus plan-wide hypotheticals) usingpkg/insuranceat the existing go pin (16b57954, which includes the go#331 key-leak fix andContractTerms()). No go.mod change.ARCHERA_API_KEY,ARCHERA_ORG_ID,ARCHERA_PLAN_IDare read from the environment on each call (never tool arguments). Unset or blank returns an error naming the missing variables and makes zero requests.*insurance.Clientand key live in call locals only, never a struct field; production passeshc=nil(SSRF-hardened client). Fixed origin https://api.archera.ai, GET only, no retries, redirects not followed.archera request failed: HTTP <status>; retry after <n>s(delta-seconds, capped 24h by the library) orretry after: not given. Vendor message is dropped.internal/archera/dto.gofield for field: exact decimal strings (no float, no division, no USD), unknown as null, product support onlysupported/unknown, both disclosures verbatim frompkg/common, vendor strings control-char stripped and capped at 256 bytes, result capped at 512 KiB. Enums and maxItems forcontract_terms/payment_options/line_item_idsare in the input schema.CUDLY_MCP_ENABLE_REAL_PURCHASESor spend caps, no audit record. README, CHANGELOG,server.json(keyisSecret) and the MCPB manifest (keysensitive) are updated.Tests (offline; RoundTripper asserting https://api.archera.ai, no live calls): a distinct-value fixture for every field with full-output golden comparison driven through the MCP protocol, filters, not-configured/partial config (zero requests), 429/401-echo/302 errors with the key absent from result and protocol bytes, vendor-string cleaning, size cap, schema bounds,
%v/%+v/%#vof tool and client.Mutation sweep (91 hand-built mutants over the mapping, config, error and schema code): the first run had 9 real survivors (schema bounds/enums, descriptor fields, UTC fetched_at); tests were added and a re-run of those mutants has 0 survivors. Not re-run in full after a field-reorder lint fix.
Open owner item (#47 follow-up): the mcpb
privacy_policiesURL is unchanged and no URL was invented; it still needs an owner decision because this tool sends data to api.archera.ai.Local verification:
make lintclean,go test -short ./...green (fixture/httptest-based; no real Archera call was made).🤖 Generated with Claude Code
Summary by CodeRabbit