{"record":{"id":"74d1c7872ee6aa2c","repo":"affaan-m/ECC","slug":"cwd-must-not-contain-a-nul-byte","errorCode":null,"errorMessage":"--cwd must not contain a NUL byte.","messagePattern":"--cwd must not contain a NUL byte\\.","errorType":"validation","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"skills/terminal-opener/scripts/open-terminal.js","lineNumber":47,"sourceCode":"  --help, -h         Show this help.\n\nAlways pass the executable and arguments as separate entries after --.\nShell command strings are not accepted.\n`;\n}\n\nfunction isAbsolutePath(value) {\n  return path.isAbsolute(value) || path.win32.isAbsolute(value);\n}\n\nfunction validateTerminalName(value) {\n  if (!/^[A-Za-z0-9][A-Za-z0-9_.-]*$/.test(value)) {\n    throw new Error('Invalid terminal name; use a simple adapter name such as wezterm.');\n  }\n}\n\nfunction validateCwd(value) {\n  if (value.includes('\\0')) throw new Error('--cwd must not contain a NUL byte.');\n  if (!isAbsolutePath(value)) throw new Error('--cwd must be an absolute path.');\n}\n\nfunction validateExecutable(value) {\n  if (!value || /[\\0\\r\\n]/.test(value)) {\n    throw new Error('Executable must be a non-empty argv entry without control bytes.');\n  }\n\n  const whitespaceIndex = value.search(/\\s/);\n  const separatorIndexes = [value.indexOf('/'), value.indexOf('\\\\')].filter(index => index >= 0);\n  const firstSeparatorIndex = separatorIndexes.length > 0 ? Math.min(...separatorIndexes) : -1;\n  const resemblesExecutablePath = isAbsolutePath(value)\n    || (firstSeparatorIndex >= 0 && (whitespaceIndex < 0 || firstSeparatorIndex < whitespaceIndex));\n\n  if (whitespaceIndex >= 0 && !resemblesExecutablePath) {\n    throw new Error(\n      'Executable must be one argv entry, not an interpolated shell command string.'\n    );","sourceCodeStart":29,"sourceCodeEnd":65,"githubUrl":"https://github.com/affaan-m/ECC/blob/8321021c54d670126ce3b2969d5deb880b4b0c2a/skills/terminal-opener/scripts/open-terminal.js#L29-L65","documentation":"validateCwd rejects any --cwd value containing a NUL byte (\\0). NUL bytes are not valid in filesystem paths and can truncate strings in C-level path APIs, so the script fails fast rather than passing a corrupt path to the OS. This is a defensive validation before spawning the terminal process.","triggerScenarios":"Calling open-terminal.js with `--cwd $'some\\0path'`, typically from programmatic argv construction, shell interpolation of binary data, or a config file that embedded a raw NUL.","commonSituations":"Scripts that build argv from concatenated buffers or env vars containing binary data; JSON configs where \\u0000 slipped in; buggy templating that inserted control characters.","solutions":["Inspect the cwd value and remove the NUL byte (re-trim/escape the source string).","If generated programmatically, sanitize with `value.replace(/\\0/g, '')` or validate before passing.","Fix the upstream producer (config file, command substitution) that introduced the NUL byte."],"exampleFix":"// before\nspawnScript(['--cwd', someBuffer.toString()]); // contains \\0\n// after\nconst cwd = someBuffer.toString('utf8').replace(/\\0/g, '');\nspawnScript(['--cwd', cwd]);","handlingStrategy":"validation","validationCode":"if (typeof cwd !== 'string' || cwd.includes('\\0')) throw new Error('cwd must be a NUL-free string');","typeGuard":"function isCleanPathValue(v) {\n  return typeof v === 'string' && v.length > 0 && !v.includes('\\0');\n}","tryCatchPattern":"try {\n  parseArgs(process.argv);\n} catch (e) {\n  if (/must not contain a NUL byte/.test(e.message)) {\n    console.error('cwd contains a NUL byte; sanitize the value source');\n  } else throw e;\n}","preventionTips":["Sanitize any value derived from buffers or binary data before use.","Reject \\u0000 in JSON config parsing upstream.","Avoid fixed-size C-buffer handoffs that NUL-pad strings.","Validate paths before spawning processes."],"tags":["cli","validation","path"],"backgroundTag":"invalid-argument-value","analyzedSha":"8321021c54d670126ce3b2969d5deb880b4b0c2a","analyzedAt":"2026-09-16T10:08:13.343Z","contentChangedAt":"2026-09-16T10:08:13.343Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}