Skip to content

Fix truncate_str panicking mid-character without ansi-parsing - #296

Merged
djc merged 1 commit into
console-rs:mainfrom
lenamonj:fix-truncate-str-byte-index
Sep 2, 2026
Merged

djc merged 1 commit into
console-rs:mainfrom
lenamonj:fix-truncate-str-byte-index

Conversation

@lenamonj

@lenamonj lenamonj commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

truncate_str panics on multi-byte input when built without ansi-parsing:

// default-features = false, features = ["std", "unicode-width"]
console::truncate_str("你好世界", 5, "");
// panicked at src/utils.rs:978:15:
// end byte index 5 is not a char boundary; it is inside '好'

The not(ansi-parsing) branch slices with &s[..width.saturating_sub(tail.len())]: a byte offset used as a column count, and the tail charged by len() instead of its display width. It now walks chars against a budget of width - str_width(tail) and cuts on a boundary, matching the ansi-parsing branch.

That also merges char_width's two definitions into one gated on unicode-width. The not(ansi-parsing) copy returned 1 for every char, so it disagreed with str_width in builds that enable unicode-width.

Tests are gated per feature state like the ones beside them; both fail on main with the panic above. All seven make test configurations pass, plus cargo fmt --check and cargo clippy.

Two related bugs in the same class are not in this PR: read_line_initial_text mixes initial.len() with a char index (non-ASCII initial text discards typed input), and Windows read_secure backspace uses rv.truncate(rv.len() - 1). Happy to file either separately.

Found with AI assistance; verified and reviewed by me.

lenamonj added a commit to lenamonj/jeffy-loop that referenced this pull request Sep 1, 2026
unicode-width, bidict and console, all pure-shape picks, all converged in
their first round - the first wave where every target did. Nine of nine
targets have now converged across waves 6, 7 and 8.

console yielded three Highs of one class, a byte length used where a
character index or display column was meant: read_line_initial_text
silently discarding everything typed after non-ASCII initial text,
truncate_str panicking mid-character without ansi-parsing, and Windows
read_secure panicking on backspace over non-ASCII in a password. The
second is upstream as console-rs/console#296, chosen as one PR rather
than a slate because it is a pure function a reviewer can verify in one
command; reachability was proven from a dependent crate.

Scorecard: 101 tested, 74 fixed, 27 failed, 73 converged across 13
languages; every number derived from the journals by script.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VCT5TPf6uidh4Y8AQtMzaJ
@lenamonj
lenamonj force-pushed the fix-truncate-str-byte-index branch from 74015ef to b8721c4 Compare September 1, 2026 15:56
@lenamonj

lenamonj commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Fixed in the force-push above: the test asserted display widths in every configuration, but char_width is 1 per char without unicode-width. Now gated per feature state. All seven make test configurations pass.

@djc

djc commented Sep 1, 2026

Copy link
Copy Markdown
Member

Please reword all the slop in your description and comments.

@lenamonj

lenamonj commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Done, both reworded.

@lenamonj
lenamonj force-pushed the fix-truncate-str-byte-index branch from b8721c4 to 79255e2 Compare September 1, 2026 18:01
Comment thread src/utils.rs Outdated
Comment thread src/utils.rs Outdated
The not(ansi-parsing) branch sliced the string with
&s[..width.saturating_sub(tail.len())]: a byte offset used as a column
count, and the tail charged by len() instead of its display width. It
now walks chars against a budget of width - str_width(tail) and cuts on
a char boundary, matching the ansi-parsing branch.

That also merges char_width's two definitions into one gated on
unicode-width. The not(ansi-parsing) copy returned 1 for every char, so
it disagreed with str_width in builds that enable unicode-width.

Tests are gated per feature state like the ones beside them; both fail
on main with the panic.
@lenamonj
lenamonj force-pushed the fix-truncate-str-byte-index branch from 79255e2 to 8cc5505 Compare September 2, 2026 10:05

@djc djc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Much better, thanks!

@djc
djc merged commit abf0358 into console-rs:main Sep 2, 2026
20 checks passed
@lenamonj
lenamonj deleted the fix-truncate-str-byte-index branch September 5, 2026 12:53
kodiakhq Bot pushed a commit to pdylanross/fatigue that referenced this pull request Sep 14, 2026
Bumps console from 0.16.4 to 0.16.6.

Release notes
Sourced from console's releases.

0.16.6
What's Changed

Fix truncate_str panicking mid-character without ansi-parsing by @​lenamonj in console-rs/console#296
perf: accelerate printable ASCII text width by @​dexhunter in console-rs/console#297
fix: measure the truncation tail in visible columns, not raw width by @​youdie006 in console-rs/console#298
Prepare 0.16.6 by @​djc in console-rs/console#299

0.16.5
What's Changed

Strip OSC and DCS sequences to support e.g. OSC 8 hyperlinks over tmux. by @​khoek in console-rs/console#280




Commits

4329b77 Bump version to 0.16.6
bdf46b0 utils: wrap tests in module
4f54213 fix: measure the truncation tail in visible columns
ed342d0 test: consolidate text width regression coverage
48b99e9 perf: accelerate printable ASCII text width
abf0358 Fix truncate_str panicking mid-character without ansi-parsing
ac3cb73 Bump version to 0.16.5
97a91ae ansi: strip OSC and DCS sequences
See full diff in compare view




Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants