Skip to content

fix: do not panic on non-UTF-8 filenames when matching ignore patterns - #409

Merged
Byron merged 1 commit into
Byron:mainfrom
Mathjk:fix/ignore-from-nonutf8
Sep 30, 2026
Merged

Byron merged 1 commit into
Byron:mainfrom
Mathjk:fix/ignore-from-nonutf8

Conversation

@Mathjk

@Mathjk Mathjk commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Fixes #408.

Bug

On Windows, NTFS filenames may legally contain unpaired surrogates (creatable via verbatim paths), which cannot be represented in UTF-8. IgnorePatterns::is_excluded converts every walked entry to a BString via the panicking gix::path::into_bstr, so a single such filename anywhere in a scanned tree aborts dua (exit 0xC0000409) whenever --ignore-from is used — in list, aggregate and stacks modes, and in clean's entry filtering too. --ignore-dirs is unaffected (it compares paths directly, no UTF-8 conversion).

Fix

Use the fallible gix::path::try_into_bstr and treat an unconvertible path as not excluded — a path that is not valid UTF-8 can never match a (UTF-8) pattern, so skipping is semantics-preserving.

Verification

  • Before: panic at gix-path/src/convert.rs:80, process abort, on list/aggregate/stacks/clean filtering.
  • After: entries are kept in output (they cannot be excluded anyway); all modes complete; --ignore-dirs and no-flag paths unchanged.
  • New #[cfg(windows)] regression test builds a lone-surrogate OsString via from_wide and asserts is_excluded returns false instead of panicking; cargo test --lib: 87/87 green.

Related sites (out of scope here)

Two other into_bstr uses panic on the same input class — src/clean/git.rs (Git-aware expendable check) and src/interactive/widgets/glob.rs (TUI glob search), reachable via dua clean/dua i. Kept them untouched for a minimal diff; happy to cover in this PR or a follow-up — whichever you prefer.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unconvertible filenames incorrectly bypass wildcard patterns that should exclude them.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Prevents Windows crashes when ignore matching encounters filenames with unpaired surrogates.

Changes:

  • Uses fallible path conversion.
  • Adds a Windows regression test.
File Description
src/​common.rs Handles unconvertible paths and tests surrogate-containing names.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/common.rs Outdated
On Windows, NTFS filenames may contain unpaired surrogates that cannot be
represented in UTF-8. `IgnorePatterns::is_excluded` converted each entry's
relative path with the panicking `gix::path::into_bstr`, so a single such
name anywhere in a scanned tree aborted the whole process when
`--ignore-from` was used - in list, aggregate and stacks modes alike, as
well as in `clean`'s entry filtering.

Match on the OS string's encoded bytes instead - `OsStr::as_encoded_bytes`
yields a self-synchronizing UTF-8 superset (WTF-8 on Windows, the raw bytes
on Unix) which represents lone surrogates losslessly. The glob matcher then
compares bytes, so wildcard patterns that don't spell out the invalid code
unit, like `*` or `*.txt`, still match such names instead of silently
letting them through.

Fixes Byron#408
@Mathjk
Mathjk force-pushed the fix/ignore-from-nonutf8 branch from 861a23b to 22d5588 Compare September 29, 2026 21:15
@Byron

Byron commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Thanks a lot!

This also reminds of making the gix-path primitives non-panicking.

@Byron
Byron merged commit 37e6aa8 into Byron:main Sep 30, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(panic): --ignore-from crashes on non-UTF-8 filenames on Windows

3 participants