Skip to content

fix(mcp): mask Unicode profile credentials without panicking - #1180

Open
joshrotenberg wants to merge 4 commits into
mainfrom
codex/unicode-profile-mask
Open

joshrotenberg wants to merge 4 commits into
mainfrom
codex/unicode-profile-mask

Conversation

@joshrotenberg

@joshrotenberg joshrotenberg commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Scope

Fixes #1179. Leaves #1173 open.

The dedicated empty kickoff commit and visible draft preceded implementation. Current pushed checkpoint: e505bb3. Refreshed with main 1453352; the merge changes only the already-approved GitHub Actions dependency pin. Rust source/tests/manifests/lockfile are identical to implementation checkpoint 3a4a27b.

Change

  • Replace unsafe byte-offset credential slicing with Unicode-scalar iteration, preserving suffix order.
  • Fully mask credentials of at most eight Unicode scalar values, independent of UTF-8 byte length.
  • Preserve ASCII, empty-value, environment-reference and keyring-reference behavior.
  • Three regression tests cover multibyte prefixes/suffixes, short Unicode values, references and ASCII boundaries.

The PR diff changes only crates/redisctl-mcp/src/tools/profile.rs. No profile storage, policy, target selection, migration, credential provisioning or release changes.

Evidence

The original masking expression panicked for synthetic emoji-prefixed/suffixed credentials; an ASCII control did not. No real credentials or customer services were used.

At implementation checkpoint 3a4a27b:

  • All-feature focused credential-mask regressions: 3 pass.
  • cargo test --workspace --all-features: pass for non-ignored unit, integration and documentation tests, including skills resources and copied-binary stdio.
  • Minimal-feature focused credential-mask regressions: 3 pass.
  • Formatting, diff checks and all-target/all-feature Clippy with warnings denied: pass.

Fresh at final head e505bb3: formatting, diff checks and all-target/all-feature Clippy pass. The code-identical tests above were not redundantly rerun after a workflow-only merge.

Docker availability was refreshed and the daemon is unavailable. Existing ignored Docker/live tests were not run locally or counted as passing. The upstream proc-macro-error2 future-incompatibility warning remains; it is not a Clippy failure.

Final diff re-reviewed October 6 for ASCII compatibility, UTF-8 boundaries, suffix order, short-value masking and scope isolation. Current-head validation is complete at e505bb30febbd8bb60bb332b5292b6b4cbf0b45e: 10 successful checks and 6 expected skips, no failed or pending checks. CI passed Quick Checks, all three unit jobs, hosted integration/Redis command-safety smoke tests, Linux all-feature workspace tests and Linux/macOS/Windows builds. Dist plan passed; release artifact/publication jobs and main-only coverage were skipped as expected, not claimed as release evidence. Cargo-deny/audit/docs workflows were not triggered by this source-only diff under their existing path filters; no gate is bypassed or changed.

Implementation and intended validation are complete, so this PR is ready for human review. GitHub's required approval remains separate. No merge, release, credential storage, onboarding contract or migration default change is initiated.

Readiness reconciled October 6 at approximately 12:07 PDT. No code changes or redundant test reruns were needed after final-head CI completion.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(mcp): avoid Unicode credential masking panics in profile_show

1 participant