• fix(#20): heid-code-review fixups — CLI presenter degrade-not-crash (slice-5)

    vh released this 2026-07-19 11:11:12 -07:00 | 52 commits to main since this release

    Panel: Gróa + Regin returned zero (adapter/route-map/error-map faithful);
    Hulda flagged two source-confirmed open-world-presenter crash holes — the same
    class the slice-4 bug-hunt found in the agents presenters. Both fixed:

    • _format_whoami scopes (cli.py): ', '.join(me.get('scopes', [])) crashes on
      a present-null scopes (.get(k, []) returns None, not the default) or a
      non-string element. Now ', '.join(str(s) for s in (me.get('scopes') or [])) —
      matching the allowed_roles hardening on the same function. The contract names
      _format_whoami as the degrade-not-crash exemplar (contract:144-146); the cited
      exemplar had an un-hardened line.
    • _characters_probe model items (cli.py): the slice-5 or [] guarded the
      list-level null but not each entry — [None] / ["x"] / [{"name":123}] would
      raise. Now guards each item is a dict and str-coerces name (element-level
      completion of the list-level guard).

    Hulda #3 (live-smoke not in the reviewed file set) → accept: the smoke WAS run and
    is recorded in deab762 + coverage-map (artifact-only review couldn't see it).

    Added CLI tests for both hardened paths (present-null/non-string scopes; malformed
    model items). Suite 485 green; ruff clean; live smoke re-run clean (identical
    happy-path output). Patch bump 0.21.16 → 0.21.17.

    Downloads