Skip to content

Escape HTTP error responses as valid JSON - #46

Merged
O6lvl4 merged 2 commits into
developfrom
dot/escape-http-error-json
Oct 4, 2026
Merged

O6lvl4 merged 2 commits into
developfrom
dot/escape-http-error-json

Conversation

@O6lvl4

@O6lvl4 O6lvl4 commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

The HTTP bridge already escapes successful response bodies, but its four error paths interpolate text directly into JSON. An unsupported method such as BAD"METHOD produces invalid JSON; the Almide parser can return a truncated error instead of the original text.

Reuse escape_json_text on every error path and add a regression in wasm_rt_test.almd covering quotes, backslashes, control characters (including NUL), and Unicode. Unsupported methods are rejected before any request is sent.

Verification on Linux, using the pinned Almide v0.63.0-rc1 binary (reports 0.63.0), Rust 1.99.0, Wasmtime 47.0.2, and codopsy 2.2.0:

  • Regression fails on the original native implementation and passes after the fix. A separate focused Rust harness also fails before and passes after for six method values.
  • almide test src/wasm_rt_test.almd --ci --run wt_http_request: 2 tests passed, 50 filtered out.
  • almide check for main and the changed test file, native Porta build, and the no-OpenSSL link check pass.
  • All 17 Python evaluator unit tests, saved benchmark/evaluation audits, and the code-quality gate (90/A) pass.
  • Full almide test --ci: 6 WASM files pass; 3 native file runs reach the same existing Unix-socket test and fail with EPERM. An independent Python AF_UNIX socket creation reproduces the executor restriction.
  • Process-level integration passes the initial WASM/MCP/Unicode, version, resources/prompts, host-import, and HTTP redirect checks, then stops because this executor has no usable Landlock support (ENOSYS).

The full local suite is therefore not green. Platform enforcement needs the normal CI runners. No permission-policy changes are included; #45 is separate.

@O6lvl4
O6lvl4 marked this pull request as ready for review October 4, 2026 01:11
@O6lvl4
O6lvl4 merged commit 123bef3 into develop Oct 4, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant