Skip to content

fix: keep surrogate pairs whole when truncating file names - #148

Merged
jerelvelarde merged 2 commits into
CopilotKit:mainfrom
Mrdifferent2022:fix/sanitize-filename-surrogate
Oct 6, 2026
Merged

jerelvelarde merged 2 commits into
CopilotKit:mainfrom
Mrdifferent2022:fix/sanitize-filename-surrogate

Conversation

@Mrdifferent2022

Copy link
Copy Markdown
Contributor

Problem

sanitizeFileName filtered code points, joined them, and then sliced the UTF-16 string at 180 units. A non-BMP character (emoji) straddling that boundary was split into a lone surrogate: the stored display name was corrupted and did not survive a UTF-8 round trip (the isolated half becomes U+FFFD).

Fix

Slice the code-point array before joining, so the 180-character bound never lands inside a surrogate pair.

Verification

  • Extended tests/resource-ids.test.ts: a name whose 180th code point is an emoji is kept whole, and a name truncated at the boundary has no split pair (code-point count asserted).
  • Full suite passes locally.

Co-authored-by: Claude noreply@anthropic.com

Mrdifferent2022 and others added 2 commits October 6, 2026 14:37
sanitizeFileName joined code points and then sliced the UTF-16 string,
so a non-BMP character straddling the 180-character boundary was split
into a lone surrogate that corrupted the stored display name.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@jerelvelarde jerelvelarde left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Value: filename truncation keeps boundary surrogate pairs whole. Four resource-ID regressions passed. Template states problem and verification; no live providers involved. Names remain bounded and filesystem paths use UUIDs. Existing isolated-surrogate input is outside this fix. Updated-main diff reviewed; no actionable security finding. Merge after required CI.

@jerelvelarde
jerelvelarde merged commit 2ca0ffc into CopilotKit:main Oct 6, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants