Severity: P2 (client-triggerable crash) · Tier-1 (mechanical)
Co-maintained repo (Pascal = architect).
Location: packages/live_ui/lib/live_ui/runtime/screen_component.ex:182 + packages/unified_iur/lib/unified_iur/interaction.ex:99-102
decode_interaction rescues only ArgumentError, then calls Interaction.new/1, which only matches %Interaction{} / list / map. A base64 term that decodes safely to a bare value (integer/tuple/binary — all permitted under [:safe]) hits no new/1 clause -> FunctionClauseError, unrescued -> process crash. Bounded (LV re-mounts; [:safe] blocks code-exec) but a client-triggerable crash on the canonical event path.
Fix: add a catch-all Interaction.new(_), do: {:error, …} or broaden the rescue to [ArgumentError, FunctionClauseError] returning {:error, :invalid_canonical_interaction}.
2026-05-28 cross-repo review — see ariston-ui docs/audits/cross-repo-review-2026-05-28.md (finding C6).
Severity: P2 (client-triggerable crash) · Tier-1 (mechanical)
Co-maintained repo (Pascal = architect).
Location:
packages/live_ui/lib/live_ui/runtime/screen_component.ex:182+packages/unified_iur/lib/unified_iur/interaction.ex:99-102decode_interactionrescues onlyArgumentError, then callsInteraction.new/1, which only matches%Interaction{}/ list / map. A base64 term that decodes safely to a bare value (integer/tuple/binary — all permitted under[:safe]) hits nonew/1clause ->FunctionClauseError, unrescued -> process crash. Bounded (LV re-mounts;[:safe]blocks code-exec) but a client-triggerable crash on the canonical event path.Fix: add a catch-all
Interaction.new(_), do: {:error, …}or broaden the rescue to[ArgumentError, FunctionClauseError]returning{:error, :invalid_canonical_interaction}.2026-05-28 cross-repo review — see ariston-ui
docs/audits/cross-repo-review-2026-05-28.md(finding C6).