Skip to content

Fix extra-language CI compare/smoke for HeaderStore typing - #39

Merged
thomasklemm merged 10 commits into
mainfrom
cursor/extra-language-ci-a318
Oct 6, 2026
Merged

thomasklemm merged 10 commits into
mainfrom
cursor/extra-language-ci-a318

Conversation

@thomasklemm

@thomasklemm thomasklemm commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Merge-ready on c942f5d3 — do not merge (await human).

Soft Bar B = 299. Upstream CI green; mergeStateStatus=CLEAN; 0 unresolved review threads.

Coordinate with rubys#503: do not flip FORGERY_SLOT back to true (see store notes).

Cause → fix

FORGERY_SLOT=[true] + empty CSRF stub on extras → POST 422 / Crystal KeyError / Python None.to_s + missing ActionController; Elixir unused attrs + While stubs.

  • Default forgery off; authenticity_token.rb enables when real tokens load
  • Nil-safe token fetch; Python ActionController import; selective elixir_wrap
  • Counter-while strip helpers; @ivar << + negative local-<< test

Test plan

  • Soft Bar B = 299
  • Upstream ci:full green on c942f5d3
Open in Web Open in Cursor 

cursoragent and others added 7 commits October 6, 2026 17:36
Seed RBS `@ivar` decls into parse_library_with_rbs so empty `[]`
initializers stamp Array[String] (not Untyped) for Go/Kotlin/C#/Swift.
Go value-position IIFEs clear void_method so ternary tails return.
Kotlin/C# cast Long list indexes to Int. Rust to_s on Array[String]
index reads prefers the field-table elem type so key_at does not
Option-map a plain String.

Co-Authored-By: Cursor Agent <noreply@cursor.com>

Co-authored-by: Thomas Klemm <github@tklemm.eu>
HeaderStore `@vals` is Array[String] after RBS ivar seeding, but
`[]=` still takes String?. After header_value_ok? rejects nil, emit
`?: ""` / `?? ""` on list writes so MutableList<String> / List<string>
typecheck.

Co-Authored-By: Cursor Agent <noreply@cursor.com>

Co-authored-by: Thomas Klemm <github@tklemm.eu>
Crystal casts size to Int64; C# keeps bool/long hoists non-nullable;
Elixir renames []__loop helpers and uses fname on bareword calls;
Kotlin normalizes regex NUL to \u0000; Python maps tr to maketrans;
Swift hoists subscript locals, coalesces String? into [String], and
emits var for mutable array constants.

Co-Authored-By: Cursor Agent <noreply@cursor.com>

Co-authored-by: Thomas Klemm <github@tklemm.eu>
Hash#dup now shallow-copies on Kotlin/C# so form_with's attrs.delete
does not erase opts[:method]. Elixir mutable array constants use
Process + List.replace_at, and module attributes are injected into
every defmodule in the file. Also address CodeRabbit: ivar-only list
elem lookup, csharp hoist SAW_NIL, go value_iife clears return_ty,
kotlin regex escape parity, RBS ivars win after method fallback,
python tr pads unequal lengths.

Co-Authored-By: Cursor Agent <noreply@cursor.com>

Co-authored-by: Thomas Klemm <github@tklemm.eu>
Bring in Masked CSRF and other tip-of-main fixes so compare/smoke
failures track current runtime rather than a 28-commit lag.

Co-authored-by: Thomas Klemm <github@tklemm.eu>
Merge of tip-of-main exposed remaining extra-language failures:
- while_to_recursion now carries locals assigned in the loop or
  read after it (HeaderStore `found`), and mutator posts end in
  `self` so a skipped `unless` still returns the struct.
- `@arr << v` and Int-indexed `__index_put__` emit as list ops.
- Go forces parens on inherited `verify_authenticity_token`.
- C# Hash#dup preserves Dictionary<K,V>; Python tr parenthesizes
  the receiver before `.translate`.

Soft Bar B stays 299.

Co-Authored-By: Cursor Agent <noreply@cursor.com>

Co-authored-by: Thomas Klemm <github@tklemm.eu>
Local transpile+native of real-blog after Masked CSRF merge found:
- Elixir `header_key_ok?__loop` is illegal (`?` mid-name); rewrite to
  `header_key_ok_p__loop` in elixir_fn_name.
- Go must not force-parens `performed?` — it is the Performed field.
- ViewHelpers needs ActionController import (TS + Rust) for
  masked_authenticity_token; rust AC shim stubs CSRF helpers that
  process_action now inherits.

Soft Bar B stays 299.

Co-Authored-By: Cursor Agent <noreply@cursor.com>

Co-authored-by: Thomas Klemm <github@tklemm.eu>
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

cursoragent and others added 3 commits October 6, 2026 19:47
rewrite_expr already rebound `@arr << v` to a struct append, but
mutates_record only recognized accessor-style `errors <<`. Registry
and trailing record return now agree for HeaderStore `@keys << key`.

Co-Authored-By: Cursor Agent <noreply@cursor.com>

Co-authored-by: Thomas Klemm <github@tklemm.eu>
Hosted CI on 6c39d4f failed compare-extra + smoke for csharp/crystal/
python/elixir/go/kotlin/swift because FORGERY_SLOT defaulted on while
extras only ship the empty masked_authenticity_token stub — every POST
became 422 (Crystal KeyError / Python None.to_s on the way).

- Default FORGERY_SLOT off; authenticity_token.rb enables it when the
  real masked implementation loads (ruby family only).
- Nil-safe params.fetch("authenticity_token", "") for Crystal/Python.
- Drop trailing nil on verify_authenticity_token (elixir unused record).
- Recursive sanitize_location strips (elixir While / keep unused).
- elixir_wrap injects module attrs only into modules that reference them.
- Python view_helpers imports ActionController for form tokens.

Soft Bar B stays 299.

Co-Authored-By: Cursor Agent <noreply@cursor.com>

Co-authored-by: Thomas Klemm <github@tklemm.eu>
- strip_leading/trailing_controls: canonical counter while (early
  return + i+=1/i-=1) so Elixir lowers to recursion without stack
  risk from per-char recursive calls on long padded locations.
- ivar << test passes `key` param; add negative local-<< fallback.

Soft Bar B stays 299.

Co-Authored-By: Cursor Agent <noreply@cursor.com>

Co-authored-by: Thomas Klemm <github@tklemm.eu>
@thomasklemm
thomasklemm merged commit 4b77850 into main Oct 6, 2026
50 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants