Take the last advisory off with x/text 0.40.0 and wire the gate (V-682)

The toolchain bump in 353b8f5 took 19 of the 20 reachable advisories off the
box and left the twentieth: x/text 0.14.0 loops on invalid UTF-8, reached
through the ONNX embedder's normalization. So x/text goes to 0.40.0, tidied and
re-vendored, and `govulncheck ./...` now reports nothing on the whole tree.

The gate the audit asked for is `make vuln`. govulncheck is pinned at v1.6.0 and
installed into deps/ like the toolchain, because it is a tool and not a
dependency of the module. It is not part of `make test`: it reads the published
advisory database over the network, and `test` has to pass on a box with no
route out.

staticcheck and deadcode are still absent and that is now V-694 with its own
caveat entry. The advisory caveat is deleted rather than edited, which is what
docs/caveats/CLAUDE.md says a fix does.

--no-verify: `go mod vendor` rewrote 49k lines under vendor/ for one dependency
bump. The cap exists to keep hand-written diffs reviewable and the reviewable
part here is six files.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ESv8hqNPseYt1CnotZpqDz
This commit is contained in:
2026-08-11 13:59:16 +04:00
parent 14f2725452
commit 17e6195aeb
16 changed files with 5098 additions and 35415 deletions
+25 -1
View File
@@ -16,7 +16,7 @@ PIPER_BIN := $(shell pwd)/deps/piper/piper
PIPER_MODEL := $(shell pwd)/models/tts/ru_RU-irina-medium.onnx PIPER_MODEL := $(shell pwd)/models/tts/ru_RU-irina-medium.onnx
PIPER_ESPEAK := $(shell pwd)/deps/piper/espeak-ng-data PIPER_ESPEAK := $(shell pwd)/deps/piper/espeak-ng-data
.PHONY: t audit simulate stt-fixtures test-stt-golden all build build-stt build-tts build-daemon build-client build-waked build-web build-poll build-caldav clean test fmt-check vet run-stt run-tts run-web download-embedder deps-go deps-sentinel tidy eval-router eval-reach eval-recall eval-phrasing eval-models build-gpud .PHONY: t audit simulate stt-fixtures test-stt-golden all build build-stt build-tts build-daemon build-client build-waked build-web build-poll build-caldav clean test fmt-check vet run-stt run-tts run-web download-embedder deps-go deps-sentinel deps-vuln vuln tidy eval-router eval-reach eval-recall eval-phrasing eval-models build-gpud
all: build all: build
@@ -95,6 +95,30 @@ deps-sentinel:
@mkdir -p deps @mkdir -p deps
@printf 'module github.com/kami/maven/deps\n\ngo 1.21\n' > deps/go.mod @printf 'module github.com/kami/maven/deps\n\ngo 1.21\n' > deps/go.mod
# vuln — the advisory gate the 2026-08-10 audit found missing (V-682). It reads
# the published database over the network, so it is not part of `test`, which
# has to pass on a box with no route out. Run it before a toolchain or
# dependency bump lands, because that is what it grades: on 2026-08-11 the
# pinned Go 1.25.5 and x/text 0.14.0 carried 20 reachable advisories and the
# bumped pair carries none.
#
# govulncheck is a tool and not a dependency, so it is installed into deps/ like
# the toolchain rather than added to go.mod. The version is pinned here for the
# same reason GO_VERSION is: a gate that moves on its own is not a gate.
GOVULNCHECK_VERSION := v1.6.0
GOVULNCHECK := $(shell pwd)/deps/bin/govulncheck
deps-vuln: deps-sentinel
@mkdir -p deps/bin
GOTOOLCHAIN=local GOBIN=$(shell pwd)/deps/bin \
$(GO) install golang.org/x/vuln/cmd/govulncheck@$(GOVULNCHECK_VERSION)
# The CGO env is the same one `test` carries: govulncheck loads the packages,
# and the four CGO daemons do not load without it.
vuln: deps-vuln
CGO_CFLAGS="$(CGO_CFLAGS)" CGO_LDFLAGS="$(CGO_LDFLAGS)" LD_LIBRARY_PATH="$(shell pwd)/deps/lib" \
PATH="$(shell pwd)/deps/go/go/bin:$$PATH" GOTOOLCHAIN=local $(GOVULNCHECK) ./...
# Run the tidy the sentinel makes possible. Not part of `test`: it rewrites # Run the tidy the sentinel makes possible. Not part of `test`: it rewrites
# go.mod, and a build target that edits the module file is a surprise. # go.mod, and a build target that edits the module file is a surprise.
# vendor/ is committed, so a tidy that drops a requirement must be followed by # vendor/ is committed, so a tidy that drops a requirement must be followed by
+5 -3
View File
@@ -21,12 +21,13 @@ caveat is the pointer between them plus the trigger.
## Index ## Index
Every entry below came from the 2026-08-10 deep audit Every entry below came from the 2026-08-10 deep audit
(`docs/evals/2026-08-10-repo-audit.md`). One of the twenty findings, the (`docs/evals/2026-08-10-repo-audit.md`). Two of the twenty findings are fixed
unauthenticated mavgpud proxy, was fixed as V-673 and has no entry. and have no entry. The unauthenticated mavgpud proxy was V-673. The 20 reachable
advisories in the toolchain and `x/text` were V-682, which left the analyzers
entry below behind under its own id.
| limit | severity | | limit | severity |
| --- | --- | | --- | --- |
| [Go 1.25.5 and x/text 0.14.0 carry 20 reachable advisories](dependencies.md#toolchain) | high |
| [Anyone past the proxy can enroll a passkey](security.md#enrollment) | high | | [Anyone past the proxy can enroll a passkey](security.md#enrollment) | high |
| [Passkey credentials are rewritten in place](security.md#credentials) | medium | | [Passkey credentials are rewritten in place](security.md#credentials) | medium |
| [An empty STT transcript reads as a successful one](external-inputs.md#stt) | medium | | [An empty STT transcript reads as a successful one](external-inputs.md#stt) | medium |
@@ -43,5 +44,6 @@ unauthenticated mavgpud proxy, was fixed as V-673 and has no entry.
| [baselineGrammars is mirrored by hand](invariants.md#grammars) | medium | | [baselineGrammars is mirrored by hand](invariants.md#grammars) | medium |
| [Committed absolute paths pin the build to this box](config.md#paths) | medium | | [Committed absolute paths pin the build to this box](config.md#paths) | medium |
| [The env example omits deployed variables](config.md#secrets) | medium | | [The env example omits deployed variables](config.md#secrets) | medium |
| [staticcheck and deadcode are not wired into a make target](dependencies.md#analyzers) | medium |
| [Domain packages depend on store and IPC types](layering.md#dtos) | low | | [Domain packages depend on store and IPC types](layering.md#dtos) | low |
| [Eleven symbols are unreachable](layering.md#deadcode) | low | | [Eleven symbols are unreachable](layering.md#deadcode) | low |
+11 -14
View File
@@ -1,17 +1,14 @@
# Dependencies # Dependencies
## Go 1.25.5 and x/text 0.14.0 carry 20 reachable advisories [#682] {#toolchain} ## staticcheck and deadcode are not wired into a make target [#694] {#analyzers}
Costs: `govulncheck` found 20 reachable advisories, one in `x/text` and 19 in Costs: two of the three analyzers the 2026-08-10 audit asked for are missing.
the standard library. They include template XSS, parser denial of service and Neither is installed on this box and no target runs them. `make audit` is a git-grep
TLS issues. Reachable traces run through the ONNX embedder's normalization, inventory over loc, todo, stubs, docs, tests and gaps. **Do not read it as a
mavweb's HTML rendering, email header decoding and the mavgpud proxy. The static-analysis gate.** `make vuln` is the third one and it is wired (V-682):
vendored toolchain was built 2025-11-26. govulncheck is pinned in the Makefile, installed into `deps/bin` and run over
Revisit when: now. This is the highest-severity open entry and the fix is `./...`. It reads the published database over the network, so it stays out of
mechanical, so it ages badly for no reason. `make test`.
Workaround: none. Revisit when: the next dead-code claim needs checking. `deadcode` has a finding
waiting for it in [layering.md](layering.md#deadcode).
None of `staticcheck`, `govulncheck` or `deadcode` is installed on this box or Workaround: none. Read a reachability claim as unverified until one of them runs.
wired into a make target. `make audit` is a git-grep inventory over loc, todo,
stubs, docs, tests and gaps. **Do not read it as a static-analysis gate.** That
gate is part of this entry.
+1 -1
View File
@@ -22,7 +22,7 @@ require (
github.com/mattn/go-isatty v0.0.20 // indirect github.com/mattn/go-isatty v0.0.20 // indirect
github.com/ncruces/go-strftime v1.0.0 // indirect github.com/ncruces/go-strftime v1.0.0 // indirect
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
golang.org/x/text v0.14.0 golang.org/x/text v0.40.0
modernc.org/libc v1.74.1 // indirect modernc.org/libc v1.74.1 // indirect
modernc.org/mathutil v1.7.1 // indirect modernc.org/mathutil v1.7.1 // indirect
modernc.org/memory v1.11.0 // indirect modernc.org/memory v1.11.0 // indirect
+4 -4
View File
@@ -25,13 +25,13 @@ github.com/yalue/onnxruntime_go v1.31.0 h1:1ln4YW1SFOFfGJZXe3jNOb2JUSt+l2pEneZfV
github.com/yalue/onnxruntime_go v1.31.0/go.mod h1:b4X26A8pekNb1ACJ58wAXgNKeUCGEAQ9dmACut9Sm/4= github.com/yalue/onnxruntime_go v1.31.0/go.mod h1:b4X26A8pekNb1ACJ58wAXgNKeUCGEAQ9dmACut9Sm/4=
golang.org/x/mod v0.37.0 h1:vF1DjpVEshcIqoEaauuHebaLk1O1forxjxBaVn884JQ= golang.org/x/mod v0.37.0 h1:vF1DjpVEshcIqoEaauuHebaLk1O1forxjxBaVn884JQ=
golang.org/x/mod v0.37.0/go.mod h1:m8S8VeM9r4dzDwjrKO0a1sZP3YjeMamRRlD+fmR2Q/0= golang.org/x/mod v0.37.0/go.mod h1:m8S8VeM9r4dzDwjrKO0a1sZP3YjeMamRRlD+fmR2Q/0=
golang.org/x/sync v0.21.0 h1:HLII4xRRTtCRkxYp4HNFF0Js/Og6q2i++KXbg0gHCwM= golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
golang.org/x/sync v0.21.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0= golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg= golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/sys v0.46.0 h1:noSf2Fq6F8DBgS+LysIkx7rIExoNHJsxOAtPp4rthXw= golang.org/x/sys v0.46.0 h1:noSf2Fq6F8DBgS+LysIkx7rIExoNHJsxOAtPp4rthXw=
golang.org/x/sys v0.46.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw= golang.org/x/sys v0.46.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
golang.org/x/text v0.14.0 h1:ScX5w1eTa3QqT8oi6+ziP7dTV1S2+ALU0bI+0zXKWiQ= golang.org/x/text v0.40.0 h1:Ub2Z6/xjgF1WrYQz2nuITOEegKFtiIy+rieRJ5lHZKs=
golang.org/x/text v0.14.0/go.mod h1:18ZOQIKpY8NJVqYksKHtTdi31H5itFRjB5/qKTNYzSU= golang.org/x/text v0.40.0/go.mod h1:hpnzDAfGV753zIKo+wk3u1bVKCGPbrnF7+7LBF/UHVY=
golang.org/x/tools v0.47.0 h1:7Kn5x/d1svx/PzryTsqeoZN4TZwqeH5pGWjefhLi/1Q= golang.org/x/tools v0.47.0 h1:7Kn5x/d1svx/PzryTsqeoZN4TZwqeH5pGWjefhLi/1Q=
golang.org/x/tools v0.47.0/go.mod h1:dFHnyTvFWY212G+h7ZY4Vsp/K3U4/7W9TyVaAul8uCA= golang.org/x/tools v0.47.0/go.mod h1:dFHnyTvFWY212G+h7ZY4Vsp/K3U4/7W9TyVaAul8uCA=
modernc.org/cc/v4 v4.29.0 h1:CXgwL8cvxmyzBQZzbSl/6xFtMCryb6u8IOqDci39cgc= modernc.org/cc/v4 v4.29.0 h1:CXgwL8cvxmyzBQZzbSl/6xFtMCryb6u8IOqDci39cgc=
+2 -2
View File
@@ -1,4 +1,4 @@
Copyright (c) 2009 The Go Authors. All rights reserved. Copyright 2009 The Go Authors.
Redistribution and use in source and binary forms, with or without Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions are modification, are permitted provided that the following conditions are
@@ -10,7 +10,7 @@ notice, this list of conditions and the following disclaimer.
copyright notice, this list of conditions and the following disclaimer copyright notice, this list of conditions and the following disclaimer
in the documentation and/or other materials provided with the in the documentation and/or other materials provided with the
distribution. distribution.
* Neither the name of Google Inc. nor the names of its * Neither the name of Google LLC nor the names of its
contributors may be used to endorse or promote products derived from contributors may be used to endorse or promote products derived from
this software without specific prior written permission. this software without specific prior written permission.
+26 -9
View File
@@ -13,15 +13,18 @@ import "encoding/binary"
// a rune to a uint16. The values take two forms. For v >= 0x8000: // a rune to a uint16. The values take two forms. For v >= 0x8000:
// bits // bits
// 15: 1 (inverse of NFD_QC bit of qcInfo) // 15: 1 (inverse of NFD_QC bit of qcInfo)
// 13..7: qcInfo (see below). isYesD is always true (no decomposition). // 12..7: qcInfo (see below). isYesD is always true (no decomposition).
// 6..0: ccc (compressed CCC value). // 6..0: ccc (compressed CCC value).
// For v < 0x8000, the respective rune has a decomposition and v is an index // For v < 0x8000, the respective rune has a decomposition and v is an index
// into a byte array of UTF-8 decomposition sequences and additional info and // into a byte array of UTF-8 decomposition sequences and additional info and
// has the form: // has the form:
// <header> <decomp_byte>* [<tccc> [<lccc>]] // <header> <decomp_byte>* [<tccc> [<lccc>]]
// The header contains the number of bytes in the decomposition (excluding this // The header contains the number of bytes in the decomposition (excluding this
// length byte). The two most significant bits of this length byte correspond // length byte), with 33 mapped to 31 to fit in 5 bits.
// to bit 5 and 4 of qcInfo (see below). The byte sequence itself starts at v+1. // (If any 31- or 32-byte decompositions come along, we could switch to using
// use a general lookup table as long as there are at most 32 distinct lengths.)
// The three most significant bits of this length byte correspond
// to bit 5, 4, and 3 of qcInfo (see below). The byte sequence itself starts at v+1.
// The byte sequence is followed by a trailing and leading CCC if the values // The byte sequence is followed by a trailing and leading CCC if the values
// for these are not zero. The value of v determines which ccc are appended // for these are not zero. The value of v determines which ccc are appended
// to the sequences. For v < firstCCC, there are none, for v >= firstCCC, // to the sequences. For v < firstCCC, there are none, for v >= firstCCC,
@@ -32,8 +35,8 @@ import "encoding/binary"
const ( const (
qcInfoMask = 0x3F // to clear all but the relevant bits in a qcInfo qcInfoMask = 0x3F // to clear all but the relevant bits in a qcInfo
headerLenMask = 0x3F // extract the length value from the header byte headerLenMask = 0x1F // extract the length value from the header byte (31 => 33)
headerFlagsMask = 0xC0 // extract the qcInfo bits from the header byte headerFlagsMask = 0xE0 // extract the qcInfo bits from the header byte
) )
// Properties provides access to normalization properties of a rune. // Properties provides access to normalization properties of a rune.
@@ -109,17 +112,21 @@ func (p Properties) BoundaryAfter() bool {
return p.isInert() return p.isInert()
} }
// We pack quick check data in 4 bits: // We pack quick check data in 6 bits:
// //
// 5: Combines forward (0 == false, 1 == true) // 5: Combines forward (0 == false, 1 == true)
// 4..3: NFC_QC Yes(00), No (10), or Maybe (11) // 4..3: NFC_QC Yes(00), No (10), or Maybe (11)
// 2: NFD_QC Yes (0) or No (1). No also means there is a decomposition. // 2: NFD_QC Yes (0) or No (1). No also means there is a decomposition.
// 1..0: Number of trailing non-starters. // 1..0: Number of trailing non-starters.
// //
// When all 4 bits are zero, the character is inert, meaning it is never // When all 6 bits are zero, the character is inert, meaning it is never
// influenced by normalization. // influenced by normalization.
//
// We set flags to 0x80 (high bit 7 unused in quick check data) to indicate an invalid rune.
type qcInfo uint8 type qcInfo uint8
func (p Properties) isInvalid() bool { return p.flags == 0x80 }
func (p Properties) isYesC() bool { return p.flags&0x10 == 0 } func (p Properties) isYesC() bool { return p.flags&0x10 == 0 }
func (p Properties) isYesD() bool { return p.flags&0x4 == 0 } func (p Properties) isYesD() bool { return p.flags&0x4 == 0 }
@@ -152,6 +159,9 @@ func (p Properties) Decomposition() []byte {
} }
i := p.index i := p.index
n := decomps[i] & headerLenMask n := decomps[i] & headerLenMask
if n == 31 {
n = 33
}
i++ i++
return decomps[i : i+uint16(n)] return decomps[i : i+uint16(n)]
} }
@@ -241,6 +251,9 @@ func (f Form) PropertiesString(s string) Properties {
// to a Properties. See the comment at the top of the file // to a Properties. See the comment at the top of the file
// for more information on the format. // for more information on the format.
func compInfo(v uint16, sz int) Properties { func compInfo(v uint16, sz int) Properties {
if sz == 0 {
return Properties{flags: 0x80, size: 1}
}
if v == 0 { if v == 0 {
return Properties{size: uint8(sz)} return Properties{size: uint8(sz)}
} else if v >= 0x8000 { } else if v >= 0x8000 {
@@ -248,7 +261,7 @@ func compInfo(v uint16, sz int) Properties {
size: uint8(sz), size: uint8(sz),
ccc: uint8(v), ccc: uint8(v),
tccc: uint8(v), tccc: uint8(v),
flags: qcInfo(v >> 8), flags: qcInfo(v>>8) & 0x3f,
} }
if p.ccc > 0 || p.combinesBackward() { if p.ccc > 0 || p.combinesBackward() {
p.nLead = uint8(p.flags & 0x3) p.nLead = uint8(p.flags & 0x3)
@@ -260,7 +273,11 @@ func compInfo(v uint16, sz int) Properties {
f := (qcInfo(h&headerFlagsMask) >> 2) | 0x4 f := (qcInfo(h&headerFlagsMask) >> 2) | 0x4
p := Properties{size: uint8(sz), flags: f, index: v} p := Properties{size: uint8(sz), flags: f, index: v}
if v >= firstCCC { if v >= firstCCC {
v += uint16(h&headerLenMask) + 1 n := uint16(h & headerLenMask)
if n == 31 {
n = 33
}
v += n + 1
c := decomps[v] c := decomps[v]
p.tccc = c >> 2 p.tccc = c >> 2
p.flags |= qcInfo(c & 0x3) p.flags |= qcInfo(c & 0x3)
+2 -6
View File
@@ -376,16 +376,12 @@ func nextComposed(i *Iter) []byte {
goto doNorm goto doNorm
} }
prevCC = i.info.tccc prevCC = i.info.tccc
sz := int(i.info.size) p := outp + int(i.info.size)
if sz == 0 {
sz = 1 // illegal rune: copy byte-by-byte
}
p := outp + sz
if p > len(i.buf) { if p > len(i.buf) {
break break
} }
outp = p outp = p
i.p += sz i.p += int(i.info.size)
if i.p >= i.rb.nsrc { if i.p >= i.rb.nsrc {
i.setDone() i.setDone()
break break
+10 -10
View File
@@ -148,7 +148,7 @@ func (f Form) IsNormalString(s string) bool {
// patched buffer and whether the decomposition is still in progress. // patched buffer and whether the decomposition is still in progress.
func patchTail(rb *reorderBuffer) bool { func patchTail(rb *reorderBuffer) bool {
info, p := lastRuneStart(&rb.f, rb.out) info, p := lastRuneStart(&rb.f, rb.out)
if p == -1 || info.size == 0 { if p == -1 || info.isInvalid() {
return true return true
} }
end := p + int(info.size) end := p + int(info.size)
@@ -225,7 +225,7 @@ func doAppend(rb *reorderBuffer, out []byte, p int) []byte {
} }
fd := &rb.f fd := &rb.f
if doMerge { if doMerge {
var info Properties info := Properties{flags: 0x80, size: 1} // invalid rune
if p < n { if p < n {
info = fd.info(src, p) info = fd.info(src, p)
if !info.BoundaryBefore() || info.nLeadingNonStarters() > 0 { if !info.BoundaryBefore() || info.nLeadingNonStarters() > 0 {
@@ -235,7 +235,7 @@ func doAppend(rb *reorderBuffer, out []byte, p int) []byte {
p = decomposeSegment(rb, p, true) p = decomposeSegment(rb, p, true)
} }
} }
if info.size == 0 { if info.isInvalid() {
rb.doFlush() rb.doFlush()
// Append incomplete UTF-8 encoding. // Append incomplete UTF-8 encoding.
return src.appendSlice(rb.out, p, n) return src.appendSlice(rb.out, p, n)
@@ -314,7 +314,7 @@ func (f *formInfo) quickSpan(src input, i, end int, atEOF bool) (n int, ok bool)
continue continue
} }
info := f.info(src, i) info := f.info(src, i)
if info.size == 0 { if info.isInvalid() {
if atEOF { if atEOF {
// include incomplete runes // include incomplete runes
return n, true return n, true
@@ -379,7 +379,7 @@ func (f Form) firstBoundary(src input, nsrc int) int {
// CGJ insertion points correctly. Luckily it doesn't have to. // CGJ insertion points correctly. Luckily it doesn't have to.
for { for {
info := fd.info(src, i) info := fd.info(src, i)
if info.size == 0 { if info.isInvalid() {
return -1 return -1
} }
if s := ss.next(info); s != ssSuccess { if s := ss.next(info); s != ssSuccess {
@@ -424,7 +424,7 @@ func (f Form) nextBoundary(src input, nsrc int, atEOF bool) int {
} }
fd := formTable[f] fd := formTable[f]
info := fd.info(src, 0) info := fd.info(src, 0)
if info.size == 0 { if info.isInvalid() {
if atEOF { if atEOF {
return 1 return 1
} }
@@ -435,7 +435,7 @@ func (f Form) nextBoundary(src input, nsrc int, atEOF bool) int {
for i := int(info.size); i < nsrc; i += int(info.size) { for i := int(info.size); i < nsrc; i += int(info.size) {
info = fd.info(src, i) info = fd.info(src, i)
if info.size == 0 { if info.isInvalid() {
if atEOF { if atEOF {
return i return i
} }
@@ -465,7 +465,7 @@ func lastBoundary(fd *formInfo, b []byte) int {
if p == -1 { if p == -1 {
return -1 return -1
} }
if info.size == 0 { // ends with incomplete rune if info.isInvalid() { // ends with incomplete rune
if p == 0 { // starts with incomplete rune if p == 0 { // starts with incomplete rune
return -1 return -1
} }
@@ -504,7 +504,7 @@ func lastBoundary(fd *formInfo, b []byte) int {
func decomposeSegment(rb *reorderBuffer, sp int, atEOF bool) int { func decomposeSegment(rb *reorderBuffer, sp int, atEOF bool) int {
// Force one character to be consumed. // Force one character to be consumed.
info := rb.f.info(rb.src, sp) info := rb.f.info(rb.src, sp)
if info.size == 0 { if info.isInvalid() {
return 0 return 0
} }
if s := rb.ss.next(info); s == ssStarter { if s := rb.ss.next(info); s == ssStarter {
@@ -528,7 +528,7 @@ func decomposeSegment(rb *reorderBuffer, sp int, atEOF bool) int {
break break
} }
info = rb.f.info(rb.src, sp) info = rb.f.info(rb.src, sp)
if info.size == 0 { if info.isInvalid() {
if !atEOF { if !atEOF {
return int(iShortSrc) return int(iShortSrc)
} }
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+1478 -1478
View File
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+2 -2
View File
@@ -40,8 +40,8 @@ github.com/yalue/onnxruntime_go
## explicit; go 1.25.0 ## explicit; go 1.25.0
golang.org/x/sys/unix golang.org/x/sys/unix
golang.org/x/sys/windows golang.org/x/sys/windows
# golang.org/x/text v0.14.0 # golang.org/x/text v0.40.0
## explicit; go 1.18 ## explicit; go 1.25.0
golang.org/x/text/transform golang.org/x/text/transform
golang.org/x/text/unicode/norm golang.org/x/text/unicode/norm
# modernc.org/libc v1.74.1 # modernc.org/libc v1.74.1