afd23ed2c191c00edaf9798a2e1fd0141e1fe7e7
A defensive review (prompted by an external File Pilot NULL-write crash in its per-directory stats roll-up) checked whether Librarian shares that bug class: a derived index guarded by a stale count/offset rather than the destination's bounds. Found and fixed one latent instance: `window_for` clamped `end` to `count` but not `start`, so a list that shrank under a stale scroll offset could yield an inverted `start..end` that violates the documented `0..count` contract and panics any caller that slices `rows[start..end]` (the grid does). Clamp `start` to `end` so the window is always well-formed. - Add `rapid_churn_never_leaves_a_stale_row_index`: drives a real create/delete burst (the `.lock` trigger) through the notify watcher and asserts reconciliation (`retain_below` + the window clamp) never leaves an out-of-bounds row index. - Extend `visible_window_*` with a stale-scroll-past-end contract case. - Document the analysis in docs/crash_class_review_filepilot.md. Full librarian-app suite green (51); fmt + clippy clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Description
No description provided
438 KiB
Languages
Rust
98%
PowerShell
2%