Skip to content

A7 — Client never verifies response id #18

Description

@yashranaway

Backlog item §A · A7 — mirrored from docs/roadmap/improvements-backlog.md.

What the audit found

Failure paths return
id:"unknown" (HP/Transport.swift:201,222); LocalSocketClient.send
doesn't check correlation. Echo the request id everywhere and assert
client-side.


Milestone: Phase 1 — Trust the build

Before changing behaviour here, read docs/roadmap/what-is-excellent.md — the contracts listed there must survive the fix — and AGENTS.md for build, test, and review conventions.

Definition of done: the change ships with the test named above (or an equivalent), CI is green, and the corresponding line in the backlog file is checked off in the same PR.

Activity

  1. added
    backlogTracked in docs/roadmap/improvements-backlog.md
    type:bugDefect in shipped behaviour
    area:core-protocolHeadlessProtocol: wire protocol, validation, transport
    on Aug 5, 2026
  2. yashranaway commented on Aug 5, 2026

    @yashranaway
    CollaboratorAuthor

    Fixed in #85 (merged). GitHub only auto-closed #15 from that PR — Closes #15 and #18 needs a closing keyword per issue, so this one needed closing by hand.

    The host now echoes the request id as soon as it can decode one, so validation failures stay correlated, and the client rejects any other id. CommandResponse.unknownRequestIdentifier remains the one documented exception, for replies where the host could not read the request at all.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:core-protocolHeadlessProtocol: wire protocol, validation, transportbacklogTracked in docs/roadmap/improvements-backlog.mdpriority:mediumScheduled, not blockingtype:bugDefect in shipped behaviour

    Type

    No type

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions