cli-list-path-fabricates-default-metadata-when-load-path-honest
Solution written to ~/solution.md.
I cloned gethilo/hilo, reproduced the defect at the broken commit e113f59, applied the real fix, and verified it end-to-end with a Rust toolchain I installed in the sandbox.
Root cause: Two code paths read the same .vfs/plugins/ directory. PluginRuntime::load_plugin was de-fabricated in e113f59 (wasm header check, hooks: []), but PluginRegistry::discover — the list path — never read the file at all. It mapped every .wasm extension to version: "0.2.0" and a hardcoded HookRef { on: "file_write", priority: 0 }, so a bare module reported hooks: 0 on load and 1 hooks on list.
Fix (2de2af2):
- Extract check_wasm_bytes() in runtime.rs as the single shared magic/version validator.
- registry.rs::discover now calls it, skips invalid files, and emits honest version: "?", hooks: [], edge_types: []; listing is sorted.
Verification (all executed):
- Before fix: LOAD -> hooks=0 vs LIST -> x v0.2.0 hooks=1 (reproduced).
- After fix: LOAD -> hooks=0 and LIST -> x v? hooks=0; garbage/bad-version files skipped.
- Live CLI: load prints hooks: 0, list prints x v? — 0 hooks.
- cargo test -p hilo_plugins → 17/17 pass (incl. test_registry_discover_skips_invalid_wasm).
- cargo test -p hilo-cli --test cli plugin_ → 2/2 pass (the literal AC4 test plugin_load_valid_header_persists_and_lists).
The markdown contains the root-cause analysis, the exact code/diff, a guardrail rule for load/list siblings, and the full verification transcript.
# Evidence - Problem class: cli-list-path-fabricates-default-metadata-when-load-path-honest - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-22T21:39:18.245Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "When one CLI surface is de-fabricated but its sibling surface still stamps default metadata, the defect survives the fix. Hilo plugin load was made honest (wasm magic check, no fabricated hooks) but PluginRegistry::discover (the plugin list path) kept stamping a default file_write hook + hardcoded 0.2.0 version, so a bare module listed 1 hooks after loading with hooks: 0. Rule: when de-fabricating one surface of a load/list pair, grep for the sibling reading the same data and fix both in the same commit. Fix shape: shared validation helper (check_wasm_bytes) + honest manifests (skip invalid files, version unknown).", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "cli-list-path-fabricates-default-metadata-when-load-path-honest", "provider": "openrouter", "solved_at": "2026-09-22T21:39:18.245Z", "version": ""}Solution written to ~/solution.md.
I cloned gethilo/hilo, reproduced the defect at the broken commit e113f59, applied the real fix, and verified it end-to-end with a Rust toolchain I installed in the sandbox.
Root cause: Two code paths read the same .vfs/plugins/ directory. PluginRuntime::load_plugin was de-fabricated in e113f59 (wasm header check, hooks: []), but PluginRegistry::discover — the list path — never read the file at all. It mapped every .wasm extension to version: "0.2.0" and a hardcoded HookRef { on: "file_write", priority: 0 }, so a bare module reported hooks: 0 on load and 1 hooks on list.
Fix (2de2af2):
- Extract check_wasm_bytes() in runtime.rs as the single shared magic/version validator.
- registry.rs::discover now calls it, skips invalid files, and emits honest version: "?", hooks: [], edge_types: []; listing is sorted.
Verification (all executed):
- Before fix: LOAD -> hooks=0 vs LIST -> x v0.2.0 hooks=1 (reproduced).
- After fix: LOAD -> hooks=0 and LIST -> x v? hooks=0; garbage/bad-version files skipped.
- Live CLI: load prints hooks: 0, list prints x v? — 0 hooks.
- cargo test -p hilo_plugins → 17/17 pass (incl. test_registry_discover_skips_invalid_wasm).
- cargo test -p hilo-cli --test cli plugin_ → 2/2 pass (the literal AC4 test plugin_load_valid_header_persists_and_lists).
The markdown contains the root-cause analysis, the exact code/diff, a guardrail rule for load/list siblings, and the full verification transcript.
# Evidence - Problem class: cli-list-path-fabricates-default-metadata-when-load-path-honest - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-22T21:39:18.245Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "When one CLI surface is de-fabricated but its sibling surface still stamps default metadata, the defect survives the fix. Hilo plugin load was made honest (wasm magic check, no fabricated hooks) but PluginRegistry::discover (the plugin list path) kept stamping a default file_write hook + hardcoded 0.2.0 version, so a bare module listed 1 hooks after loading with hooks: 0. Rule: when de-fabricating one surface of a load/list pair, grep for the sibling reading the same data and fix both in the same commit. Fix shape: shared validation helper (check_wasm_bytes) + honest manifests (skip invalid files, version unknown).", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "cli-list-path-fabricates-default-metadata-when-load-path-honest", "provider": "openrouter", "solved_at": "2026-09-22T21:39:18.245Z", "version": ""}