Skip to content

fix: reject ambiguous JSON catalogs and translation responses - #10

Merged
Tom-R-Main merged 3 commits into
mainfrom
codex/json-integrity
Sep 4, 2026
Merged

Tom-R-Main merged 3 commits into
mainfrom
codex/json-integrity

Conversation

@Tom-R-Main

@Tom-R-Main Tom-R-Main commented Sep 4, 2026 •

Copy link
Copy Markdown
Owner

Summary

Reject ambiguous JSON before decoding can discard content. Duplicate decoded object members and flattened-key collisions now fail with or without --strict, including catalog reads, rewrites, and LLM translation responses.

  • Add shared, bounded decoding with stable error codes, JSON pointer locations, and byte offsets. Never include translation values in integrity errors.
  • Preserve valid dotted, nested, empty-key, array, and metadata structures; reject serialization that would overwrite content or change requested identities.
  • Keep malformed candidates visible in discovery and fail configuration checks. Carry structured failures through validation and translation jobs, and protect pseudolocale replacement even with --force.

Verification

  • Full go test ./... -race -count=1 with coverage: passed; aggregate statement coverage 78.4%.
  • go vet ./..., golangci-lint run, and CLI build: passed.
  • npm wrapper tests (4), package version consistency, and package dry-run: passed.
  • Collision regression: 100 normal and 100 strict validations consistently reject ambiguous input.
  • Acceptance coverage checks malformed source/target workflows, filtered diagnostics, approval invalidation, zero provider calls for malformed catalog input, and unchanged local artifacts.
  • HTTP-backed mock provider tests reject duplicate/colliding responses after exactly one request, retain structured job errors, and leave target, manifest, and translation memory unchanged.
  • Three bounded fuzz runs exercised decoder, catalog roundtrip, and response parsing with no failures.
  • Fixed the review-reported array append regression: numeric indices insert in order, including nested and root arrays. Regression tests passed 20 repeats; independent review confirmed comparator ordering and identity preservation.
  • Independent implementation and coverage reviews completed. Cross-platform CI remains the remote gate.

Plan completion and scope

JSON-integrity scope is complete. The separate existing-bundle retargeting patch follows this one. ExecuFunction configuration and catalogs were not changed; no live LLM calls were made.

CLI onboarding documentation and Unreleased notes explain the new failures and recovery. Version remains 0.2.0: this PR does not tag, merge, or publish a release.

Detect decoded duplicate members and flattened leaf collisions before values can be lost. Preserve valid catalog identities and make malformed LLM responses terminal.

Signed-off-by: Tom Main <tom@execufunction.com>
Retain malformed discovery candidates and structured validation and translation errors. Protect forced pseudolocale writes and cover repeated validation and side-effect-free failures with synthetic acceptance tests.

Signed-off-by: Tom Main <tom@execufunction.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-04T21:53:09.594195Z 59b2b4f PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 59b2b4f43e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/formats/json.go Outdated
Signed-off-by: Tom Main <tom@execufunction.com>
@Tom-R-Main
Tom-R-Main merged commit ab8b412 into main Sep 4, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant