a tool row with no cmd no longer execs the utterance (V-581)

An enabled row whose Cmd is empty built argv from the spoken args alone. So
args[0] became the program name, and free text picked the binary. A proposal is
drafted with no cmd. /tools can enable one before anybody fills it in, so
reaching this took no compromise. Exec now refuses such a row with ErrNotEnabled
before it builds argv. TestExecEmptyCmdRefuses pins it.

Three smaller reads in the same sweep. CapabilityOf parsed a Home Assistant
entity id by hand where smarthome.DomainOf already does it. The fallback for an
id with no dot is unchanged. GroupByDomain built its map key twice per row. The
zenmoney and Home Assistant HTTP clients read an error body before checking the
status that discards it. The status check moved ahead of the read in both.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-06 03:11:53 +04:00
parent 316fb197a8
commit f4a021d3da
5 changed files with 47 additions and 16 deletions
+6 -5
View File
@@ -229,15 +229,16 @@ func (c *Client) diff(ctx context.Context, serverTimestamp int64) (diffResponse,
return diffResponse{}, err
}
defer res.Body.Close()
if res.StatusCode != http.StatusOK {
// The status only, and read before the body: the body of a failed diff
// can echo account data, this string reaches the log, and there is no
// reason to pull megabytes of an error page into memory to discard it.
return diffResponse{}, fmt.Errorf("zenmoney diff: %s", res.Status)
}
raw, err := io.ReadAll(io.LimitReader(res.Body, 32<<20))
if err != nil {
return diffResponse{}, err
}
if res.StatusCode != http.StatusOK {
// The status only. The body of a failed diff can echo account data, and
// this string reaches the log.
return diffResponse{}, fmt.Errorf("zenmoney diff: %s", res.Status)
}
var out diffResponse
if err := json.Unmarshal(raw, &out); err != nil {
return diffResponse{}, fmt.Errorf("zenmoney diff: decode: %w", err)