fix(zsh): harden _radian_version_check against a contaminated version cache - #528
Merged
Merged
Conversation
… cache The R-vs-radian version-drift check compared the cached value to the current R version with no validation of either side. If the cache ever held radian's own version string (format "0.6.16" -- indistinguishable from a real X.Y.Z version by a plain semver regex) instead of R's, the next login produced a nonsensical warning like "R changed: 0.6.16 -> 4.6.1" even though nothing was actually wrong. R has not shipped a major version below 2 in decades; radian has never left major version 0. Require major >= 2 on both the freshly-read R version and the cached value before comparing -- a malformed or contaminated value is now silently ignored (and self-heals on write) instead of producing a false warning. E2E: extracted the live function, stubbed R, and ran it against an isolated HOME/cache in 3 scenarios -- contaminated cache (no warning, cache self-heals), genuine version change (warns correctly), and no change (silent). All three passed against the actual shipped code. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
The previous commit's ^[2-9][0-9]*\. regex only matched when the LEADING digit was 2-9, so a future double-digit major like R 10.x (leading digit 1) would be wrongly rejected as "not a real version" despite 10 >= 2. Caught in review before merge, not by a user report. Corrected to ^([1-9][0-9]+|[2-9])\. -- true major >= 2, single or multi-digit. Re-ran the full E2E suite plus 2 new double-digit-major cases (10.0.0 vs 9.9.9 must warn, 10.0.0 vs 10.0.0 must not) against the actual shipped function; all 5 scenarios pass. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
_radian_version_check's R-vs-radian version-drift warning compared the cached version to the current R version with no validation of either sideX.Y.Zshaped, e.g.0.6.16— indistinguishable from a real R version by a plain semver regex) instead of R's, the next login produced a nonsensical warning likeR changed: 0.6.16 -> 4.6.1even though nothing was actually wrongTest plan
zsh -n zsh/.zshrc— syntax cleanR, ran it against an isolatedHOME/cache in 3 scenarios against the actual shipped code:0.6.16vs real4.6.1) → no warning, cache self-heals to4.6.14.5.0vs4.6.1) → warns correctly4.6.1vs4.6.1) → silent^[0-9]+\.[0-9]+\.[0-9]+$regex) was caught by this same E2E process — it still fired on the contaminated-cache case since radian's version also matches that shape — corrected to the major->=2 check before landing🤖 Generated with Claude Code