Follow-up on @tomaioo's signature-verification panic fix in PR #235.
1. Clippy on Rust 1.95+ flags `len() % 2 != 0` with the
`manual_is_multiple_of` lint, which was failing the `rust` CI job
on PR #235 and blocking merge. Switch to `is_multiple_of(2)`.
2. Add an explicit `is_ascii()` guard before slicing. With only the
length check, a non-ASCII input (e.g. `"é"` — 2 bytes but 1 char)
would survive the length check before `from_str_radix` caught it.
The explicit guard makes the rejection intent clear and avoids
relying on the post-slice error path.
3. Extract the hex-parsing into a private `parse_public_key_hex`
helper. PyO3-bound `#[pymethods]` are awkward to unit-test from
Rust (need a Python interpreter via `prepare_freethreaded_python`);
a plain function is testable with no GIL boilerplate.
4. Add 5 unit tests covering the security boundary:
- empty input -> Some(empty vec)
- valid hex decodes to the right bytes
- odd-length rejected without panic (the original bug)
- non-hex chars rejected (previously silently filtered)
- multi-byte UTF-8 rejected without panic
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
`verify_signature` slices `public_key_hex[i..i + 2]` without validating that the input length is even. An odd-length or otherwise malformed string can trigger an out-of-bounds panic, which may crash the process (or at minimum terminate the request path), creating a denial-of-service vector if this method is reachable from untrusted input.
Signed-off-by: tomaioo <203048277+tomaioo@users.noreply.github.com>
* feat: add interactive agent confirmation mode and fix tool loading
- Add `interactive` and `confirm_callback` params to ToolUsingAgent and
NativeReActAgent so CLI sessions can prompt user before tool execution
- Fix tool resolution in `ask` and `chat` commands to fall back to
config.tools.enabled when no --tools flag is provided
- Register shell_exec tool in tools/__init__.py auto-discovery
- Add dspy and gepa as optional learning extras (learning-dspy, learning-gepa)
- Fix openjarvis-rust lock version (1.0.0 → 0.1.0)
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(cli): support configured tool defaults and confirmations
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>