{"record":{"id":"3e28f5f6337e3f8c","repo":"affaan-m/ECC","slug":"arguments-must-not-contain-nul-bytes","errorCode":null,"errorMessage":"Arguments must not contain NUL bytes.","messagePattern":"Arguments must not contain NUL bytes\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"skills/terminal-opener/scripts/open-terminal.js","lineNumber":76,"sourceCode":"  const firstSeparatorIndex = separatorIndexes.length > 0 ? Math.min(...separatorIndexes) : -1;\n  const resemblesExecutablePath = isAbsolutePath(value)\n    || (firstSeparatorIndex >= 0 && (whitespaceIndex < 0 || firstSeparatorIndex < whitespaceIndex));\n\n  if (whitespaceIndex >= 0 && !resemblesExecutablePath) {\n    throw new Error(\n      'Executable must be one argv entry, not an interpolated shell command string.'\n    );\n  }\n  if (!resemblesExecutablePath && /[;&|<>`$]/.test(value)) {\n    throw new Error(\n      'Executable must be one argv entry, not an interpolated shell command string.'\n    );\n  }\n}\n\nfunction validateArgv(argv) {\n  for (const argument of argv) {\n    if (argument.includes('\\0')) throw new Error('Arguments must not contain NUL bytes.');\n  }\n}\n\nfunction readValue(argv, index, option) {\n  const value = argv[index + 1];\n  if (value === undefined || value.startsWith('--')) {\n    throw new Error(`Missing value for ${option}.`);\n  }\n  return value;\n}\n\nfunction parseArgs(argv, context = {}) {\n  const env = context.env || process.env;\n  const initialTerminal = env.ECC_TERMINAL || DEFAULT_TERMINAL;\n  const initialCwd = context.cwd || process.cwd();\n  const options = {\n    argv: [],\n    cwd: initialCwd,","sourceCodeStart":58,"sourceCodeEnd":94,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/terminal-opener/scripts/open-terminal.js#L58-L94","documentation":"validateArgv iterates every argument intended for the spawned process and rejects any containing a NUL byte. NUL cannot appear in OS argv entries, so passing one would cause the spawn call to fail obscurely; the script surfaces a clear error instead.","triggerScenarios":"Programmatic callers building the post-`--` argument list from buffers, JSON with `\\u0000`, or string truncation bugs that left a NUL in an argument.","commonSituations":"Reading args from binary config data; template engines inserting control characters; inter-process data passed through fixed-size C buffers that NUL-pad strings.","solutions":["Sanitize each argument with `arg.replace(/\\0/g, '')` before calling.","Trace and fix the upstream source producing the NUL byte.","Validate argv contents programmatically before invoking the script."],"exampleFix":"// before\nconst argv = ['--', rawArgFromBuffer];\n// after\nconst argv = ['--', rawArgFromBuffer.replace(/\\0/g, '')];","handlingStrategy":"validation","validationCode":"const clean = (args) => { args.forEach(a => { if (typeof a !== 'string' || a.includes('\\0')) throw new Error('argv entries must be NUL-free strings'); }); return args; };","typeGuard":"function isNulFreeArgv(args) {\n  return Array.isArray(args) && args.every(a => typeof a === 'string' && !a.includes('\\0'));\n}","tryCatchPattern":"try {\n  parseArgs(process.argv);\n} catch (e) {\n  if (/must not contain NUL bytes/.test(e.message)) {\n    console.error('An argument contains a NUL byte; sanitize the value source');\n  } else throw e;\n}","preventionTips":["Sanitize all programmatically built arguments.","Validate JSON inputs for \\u0000 before passing values through.","Avoid binary-safe buffer slicing when constructing strings.","Add argv sanitation at process boundaries."],"tags":["cli","validation","argv"],"backgroundTag":"invalid-argument-value","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}