{"record":{"id":"30493c0a15c16faa","repo":"Hmbown/CodeWhale","slug":"expected-explicit-block","errorCode":null,"errorMessage":"expected explicit block","messagePattern":"expected explicit block","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"crates/tui/src/hooks/executor.rs","lineNumber":5583,"sourceCode":"        assert_eq!(payload[\"turn_id\"], \"turn_test\");\n    }\n\n    #[cfg(unix)]\n    #[test]\n    fn explicit_message_denial_never_copies_raw_process_diagnostics() {\n        let dir = tempfile::tempdir().expect(\"tempdir\");\n        let command = r#\"printf '%s\\n' '{\"reason\":\"blocked /Users/alice/private --run token=SUPERSECRET\"}'; printf '%s\\n' 'stderr-secret /tmp/private' >&2; exit 2\"#;\n        let executor = HookExecutor::new(\n            HooksConfig {\n                enabled: true,\n                hooks: vec![Hook::new(HookEvent::MessageSubmit, command)],\n                ..HooksConfig::default()\n            },\n            dir.path().to_path_buf(),\n        );\n        let outcome = executor.execute_message_submit_transform(&HookContext::new(), \"hello\");\n        let MessageSubmitOutcome::Blocked { reason } = outcome else {\n            panic!(\"expected explicit block\");\n        };\n        assert_eq!(reason, \"blocked [path] [argument] [secret]\");\n        for secret in [\"alice\", \"SUPERSECRET\", \"stderr-secret\", \"/tmp/private\"] {\n            assert!(!reason.contains(secret), \"leaked {secret}: {reason}\");\n        }\n    }\n\n    #[cfg(unix)]\n    #[test]\n    fn foreground_pipe_capture_is_bounded_while_verbose_child_is_drained() {\n        let hook = Hook::new(\n            HookEvent::SessionStart,\n            \"head -c 200000 /dev/zero | tr '\\\\0' o; head -c 200000 /dev/zero | tr '\\\\0' e >&2\",\n        )\n        .with_timeout(5);\n        let executor = HookExecutor::new(HooksConfig::default(), PathBuf::from(\".\"));\n        let result = executor.execute_sync(&hook, &HashMap::new());\n        assert!(result.success, \"{:?}\", result.error);","sourceCodeStart":5565,"sourceCodeEnd":5601,"githubUrl":"https://github.com/Hmbown/CodeWhale/blob/433685b2024e7bc4c99e1e2e326bcad39b4d9d65/crates/tui/src/hooks/executor.rs#L5565-L5601","documentation":"Test assertion message from explicit_message_denial_never_copies_raw_process_diagnostics: the hook executor was expected to emit an explicit structured denial block (sanitized reason) but did not. The test verifies that when a hook command denies a message submit, raw process diagnostics (stdout/stderr containing secrets like tokens and private paths) are never copied into the denial payload; this error means sanitization/structure regressed.","triggerScenarios":"Thrown at crates/tui/src/hooks/executor.rs:5583 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Run the test and inspect the actual denial payload produced by the HookExecutor","Ensure the denial path emits an explicit block with the hook's stated reason only","Verify stdout/stderr of the denied process are not forwarded verbatim (the fixture plants a token and private paths to catch leaks)"],"exampleFix":null,"handlingStrategy":"fallback","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"433685b2024e7bc4c99e1e2e326bcad39b4d9d65","analyzedAt":"2026-09-15T12:24:24.634Z","contentChangedAt":"2026-09-15T12:24:24.634Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}