summaryrefslogtreecommitdiff
path: root/src/Mini.zig
diff options
context:
space:
mode:
authorGabriel Schneider <[email protected]>2026-09-29 14:37:21 -0300
committerGabriel Schneider <[email protected]>2026-10-01 00:12:16 -0300
commitd678a63e0abf2ba8994225a9f0fd0047fee4025a (patch)
tree9c1a13fe7895ec162e9ee24de2913f2375375241 /src/Mini.zig
parent25c847e28ae77f5c648d423d64011736f55eda4a (diff)
downloadpardes-d678a63e0abf2ba8994225a9f0fd0047fee4025a.tar.gz
pardes-d678a63e0abf2ba8994225a9f0fd0047fee4025a.zip
Every catch unreachable, orelse unreachable and syscall assert outside tests is a real refusal or says why it cannot fire
A sweep for round 23's crash: a run's answer (pty/run) was bufPrint'd into 48 bytes with catch unreachable, so a foreground program's long name (macOS gives up to 32 bytes) panicked; it now cuts at the room, keeping its newline, in 96 bytes. The rest were numbers into buffers sized for them, a braille codepoint, pthread calls on the queue's own mutex, and pdf_view's resolved outline entries: each now carries a one-line comment saying why it cannot fire. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Diffstat (limited to 'src/Mini.zig')
-rw-r--r--src/Mini.zig6
1 files changed, 6 insertions, 0 deletions
diff --git a/src/Mini.zig b/src/Mini.zig
index ac9a8e85..a6aef15a 100644
--- a/src/Mini.zig
+++ b/src/Mini.zig
@@ -49,6 +49,7 @@ const Row = struct {
const end = modal.nextGrapheme(row.text, row.at);
const grapheme = row.text[row.at..end];
row.left = File.graphemeDisplayWidth(grapheme);
+ // unreachable below: `generate` refuses a source that is no UTF-8
const n = std.unicode.utf8ByteSequenceLength(grapheme[0]) catch unreachable;
const cp = std.unicode.utf8Decode(grapheme[0..n]) catch unreachable;
const blank = switch (cp) {
@@ -108,6 +109,7 @@ fn render(output: ?Result, source: []const u8, styles: []const u8) !usize {
if (output) |out| {
@memset(out.content[offset..][0..spaces], ' ');
@memset(out.colors[offset..][0..spaces], 0);
+ // unreachable: U+2800 plus a u8 mask is a braille codepoint, always three bytes
_ = std.unicode.utf8Encode(@as(u21, 0x2800) + mask, out.content[offset + spaces ..][0..3]) catch unreachable;
@memset(out.colors[offset + spaces ..][0..3], color);
}
@@ -313,3 +315,7 @@ test "Mini publishes only complete snapshots and content replacement drops metad
const path = try std.fmt.bufPrint(&path_buf, "{s}/mini.txt", .{dir});
try std.testing.checkAllAllocationFailures(std.testing.allocator, Case.run, .{path});
}
+
+test "Mini refuses a file that is no UTF-8, before its decoding could panic" {
+ try std.testing.expectError(error.InvalidUtf8, generate(std.testing.allocator, "ok \xff\xfe bad\n\xc3", ""));
+}