Archived
runtime: HTTP replies truncated to fs_read's file length — Content-Length lied, onboarding trapped #78
Closed
tim.lingo
wants to merge 2 commits from
fix/http-fs-read-len into main
pull from: fix/http-fs-read-len
merge into: :main
:main
:stage
:dev
:fix/runtime-stack-on-dev
:fix/runtime-growth-guard
:fix/runtime-shim-retire
:fix/runtime-extract-text
:feat/el-speaks
:wire/write-realizes-signal
:fix/singleton-guards-the-state
:fix/transduce-decomposition
:design/correspondence-and-censorship
:docs/correspondence-and-ownership-2026-08-16
:fix/geometry-readable
:docs/builtin-recipe-gate
:fix/sigpipe
:feat/grounding-gradient
:fix/utf8-truncation
:fix/ground-echo-and-self
:fix/think-stance
:fix/cross-cutting-concerns
:feat/el-geometry-transduce
:fix/awareness-thread-engram-race
:fix/think-anchor
:fix/geometry-ingest
:fix/state-get-leak
:wt/soul-runtime-reconcile
:fix/bool-is-int-like
:fix/eq-operand-inference
:fix/missing-import-is-an-error
:feat/alloc-accounting-containers
:fix/math-log-base10
:fix/compiler-quadratic-strlen
:feat/alloc-accounting
:fix/elc-rebuildable-compiler-builtins
:fix/engram-query-param-and-seed-link
:merge-pr103-v2
:merge-swarm-ccr-v2
:feat/engram-ggml-cosine-batch
:improve/ggml-cosine-fp32-and-init
:fix/nsbx-tooling-hardening
:feat/transduce-unify
:fix/engram-search-latency-reconciled
:feat/engram-metal-cosine-batch
:feat/reframe-region-setop
:worktree-agent-a1bb8ac67d9006e08
:feat/neuron-sandbox
:worktree-agent-af50f3458d7754f19
:worktree-agent-acc02900ef4ade35e
:worktree-agent-aaf04b0a9714c4070
:worktree-agent-a6577c8211c332c5b
:worktree-agent-a6177cda24c71d1df
:worktree-agent-a55d5c2d0e8f2c88b
:worktree-agent-a7e7a591a07291058
:worktree-agent-a456e0cf8cd2ee361
:worktree-agent-a0dc4a33cf5558d4e
:worktree-agent-ac2381b0b9615ab20
:wt/swarm-ccr
:integration/langfaculty-20260814
:feat/nsbx-dev-env
:stage-elp-native-lang
:docs/operator-naming-convention
:stage-elp-lang-consolidation
:stage-elp-es-port
:engram-tiered-storage
:feat/engram-reseed-route
:feat/el-route-decorators
:test/dev-ci-baseline
:fix/cgi-identity-emission-clean
:fix/cgi-identity-emission
:reconcile/el-cluster-windows-runtime
:fix/durable-response-truncation
:fix/engram-lexical-tokenized-search
:fix/http-fs-read-len
:hotfix/ci-stage-main-publish-hardening
:hotfix/ci-dev-publish-hardening
:hotfix/stage-elc-engram-integration
:feat/ranked-engram-search
:hotfix/win-runtime-portability
:hotfix/runtime-engram-get-node-by-label
:feat/engram-semantic-search
:hotfix/elc-fixes
:hotfix/el-runtime-leak-and-persist
:integrate/local-main-commits
:fix/runtime-load-merge-2026-06-30
:fix/windows-rusage-guard
:fix/http-response-truncation
:salvage/tim-wip-presync-20260625
:feat/windows-el-runtime
:fix/runtime-integrity-reconcile
:fix/engram-save-atomic-darwin
:chore/live-darwin-runtime
:feat/wm-api-and-http-serve-async
:fix/engram-node-full-field-corruption
:fix/llm-model-and-utf8
:fix/elb-monolithic-link
:fix/ci-gcloud-install-order
:fix/native-test-precompile-runtime
:fix/ci-base-dev-first-run
:fix/elc-parser-elb-build
:fix/elc-oom-checkout
:fix/css-str-join-separator
:fix/html-template-if-style-script
:fix/elb-gcc-bracket-depth
:fix/ci-openssl-linker
:feat/ci-hook-test
:feat/native-testing
:runtime/integrate
:fix/http-serve-1-arg-compat
:feat/el-html-templates
:feat/js-browser-runtime
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "fix/http-fs-read-len"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What customers hit: every fresh install trapped at 'Set your safety contact' with 'Couldn't save… check your connection', and configured users saw the gate re-appear every launch. Deterministic on every machine.
Root cause: the binary-safe fs_read length hint (
_tl_fs_read_len) is consumed by the HTTP send path for ANY body on the same request. A handler that fs_reads a file and wraps it into a larger reply (safety-contact GET/POST) gets its reply truncated to the file's length — Content-Length lies AND the send stops short, cutting the JSON mid-field. The app correctly refuses the mangled reply. Also latent: a stale hint LARGER than a later body over-reads heap memory out the socket (privacy-grade risk).Fix (
f34270d): pair the hint with the exact buffer pointer it describes; the send path honors it only when the response IS that buffer (PNG/binary serving keeps working — the hint follows the worker's copy-out); both reset at request start. Also portsengram_get_node_by_label(from releases/v1.0.0) — needed by soul.el session continuity in local mode; not-found returns "" ("{}" flips the truthiness check in emit_session_start_event). Note: neuron repo's dist/elp-c-decls.h needs the prototype or arm64 implicit declaration truncates the returned pointer (added there, uncommitted; the decls generator should emit it).Related: memory.el still string-compares engram_save's int return (#80) — re-applied as build fixups; imprint_respond echo placeholder (#81).
Verified: genesis boot + byte-math E2E — safety-contact GET/POST/GET all Content-Length==body and JSON-parse clean; /health + /api/config regressions match; 30s heartbeat survival. neuron-ui packaging now runs a response-integrity gate that boots a genesis brain and fails on any truncated/unparseable probe.
🤖 Generated with Claude Code
The binary-safe fs_read length (_tl_fs_read_len) was consumed by the HTTP response path for ANY body, even when the handler wrapped the file into a larger reply. Content-Length then lied AND the send stopped short: the safety-contact routes returned 178 of 208/218 bytes, cut mid-'set_at' — unparseable JSON. The desktop app read that as failure: fresh installs trapped at 'Set your safety contact' (POST reply mangled) and configured users saw the gate re-appear every launch (GET reply mangled). Worse, a stale hint LARGER than a later body would over-read heap memory out the socket. Fix: pair the hint with the exact buffer pointer it describes; consume it only when the response IS that buffer (binary file serving keeps working, the hint follows the worker's copy); reset both at request start. Also ports engram_get_node_by_label (from releases/v1.0.0) needed by soul.el session continuity in local mode — not-found returns "" (matches shipped behavior; '{}' flips the truthiness check upstream). Verified: genesis boot + byte-math E2E on :7797 sandbox — safety-contact GET/POST/GET all Content-Length==body, json-parse clean; /health, /api/config regressions match. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>Superseded by #79 (durable pointer-identity truncation fix, both runtimes), landing on main via the dev->stage->main chain (PR #80/#81). #78 only touched the mainline runtime and was 21 commits behind main; #79 also fixes the v1.0.0 release runtime the desktop souls compile against — which is what kept the Windows brain truncating. Closing as superseded.