You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
#1568 made RemoteActorRef canonicalise a bare /user/x so that delivery, death watch, equals and toString() agree whichever spelling was passed. The 2026-09-18 verification found the canonicaliser (src/ActorPath.ts:234-237, path.replace(/^\/+/, '')) is prefix-only, so the same class of divergence survives for other spellings:
/user/x/ → targetPath = actor-ts://sys/user/x/ while .path = actor-ts://sys/user/x; /user//x likewise. Delivery works (tree resolution collapses segments) and equals agrees, but toString() differs and two refs /user/x and /user/x/ to one actor send two watch frames (RemoteWatcher keys on the string). Readers: RemoteActorRef.ts:53,82, RemoteWatcher.ts:110-127, RefCodec.ts:72.
parsePathSegments' regex (ActorPath.ts:200, (.*)) excludes \n/\r, so any string containing a line terminator yields []; a bare '\n' becomes targetPath = 'actor-ts://sys/\n' while .path collapses onto the root — the root-collapse [Bug] RemoteActorRef accepts a bare /user/… path and silently targets the system root #1568 removed for other garbage. Pre-existing for the full form; tests/unit/ActorPath.test.ts:152-179 covers no line-terminator input.
The refFor pass-through in WorkerMesh.ts:223-225 is unpinned: reverting the de-duplication commit leaves every suite green, and WorkerMesh.test.ts's mesh and worker share one system name, so a future refFor that re-prefixes with a different name would not be caught.
Proposed
Canonicalise through parsePathSegments (collapse separators, refuse or normalise line terminators the way assertValidName refuses control characters) and add the three spellings plus '\n' to the strictness tests; one refFor test with distinct mesh/worker system names.
#1568 made
RemoteActorRefcanonicalise a bare/user/xso that delivery, death watch,equalsandtoString()agree whichever spelling was passed. The 2026-09-18 verification found the canonicaliser (src/ActorPath.ts:234-237,path.replace(/^\/+/, '')) is prefix-only, so the same class of divergence survives for other spellings:/user/x/→targetPath = actor-ts://sys/user/x/while.path = actor-ts://sys/user/x;/user//xlikewise. Delivery works (tree resolution collapses segments) andequalsagrees, buttoString()differs and two refs/user/xand/user/x/to one actor send two watch frames (RemoteWatcher keys on the string). Readers:RemoteActorRef.ts:53,82,RemoteWatcher.ts:110-127,RefCodec.ts:72.parsePathSegments' regex (ActorPath.ts:200,(.*)) excludes\n/\r, so any string containing a line terminator yields[]; a bare'\n'becomestargetPath = 'actor-ts://sys/\n'while.pathcollapses onto the root — the root-collapse [Bug]RemoteActorRefaccepts a bare/user/…path and silently targets the system root #1568 removed for other garbage. Pre-existing for the full form;tests/unit/ActorPath.test.ts:152-179covers no line-terminator input.refForpass-through inWorkerMesh.ts:223-225is unpinned: reverting the de-duplication commit leaves every suite green, andWorkerMesh.test.ts's mesh and worker share one system name, so a futurerefForthat re-prefixes with a different name would not be caught.Proposed
Canonicalise through
parsePathSegments(collapse separators, refuse or normalise line terminators the wayassertValidNamerefuses control characters) and add the three spellings plus'\n'to the strictness tests; onerefFortest with distinct mesh/worker system names.Refs #1568.
Filed from the 2026-09-18 issue wave (#1568 verification (concerns 1, 2, 3)).