Skip to content

Avoid iOS 16 URL parsing crash in stringWithUserAndPasswordStripped - #13

Draft
o-nnerb wants to merge 2 commits into
mainfrom
fix/ios16-url-percent-encoded-crash
Draft

o-nnerb wants to merge 2 commits into
mainfrom
fix/ios16-url-percent-encoded-crash

Conversation

@o-nnerb

@o-nnerb o-nnerb commented Sep 8, 2026

Copy link
Copy Markdown
Member

Summary

  • URL.user()/.password() (the percent-encoded accessors) share internal parsing code with URL.host(percentEncoded:) on iOS 16, and calling them there can crash inside host parsing even though host is never touched here (same crash signature as https://forums.swift.org/t/70452).
  • Gates the fast path on iOS 17 instead of iOS 16 (the version these APIs were actually introduced in), so iOS 16 falls back to the legacy, non-percent-encoded user/password properties, which don't hit the bug.
  • Previously merged into beta via Avoid iOS 16 URL parsing crash in stringWithUserAndPasswordStripped #4; this re-targets the same fix at main since main now tracks upstream directly rather than carrying this fork's cumulative history (see the release integration branch for where this and the fork's other pending work live together).

Test plan

  • swift build clean.
  • No test coverage added — this is a crash-avoidance gate with no observable behavior difference on iOS 17+; a regression test would need to run on iOS 16 specifically to exercise the crash path.

🤖 Generated with Claude Code

URL.user()/password() (the percent-encoded accessors) share internal
parsing code with URL.host(percentEncoded:) on iOS 16, and calling
them there can crash inside host parsing even though host is never
touched here. Gate the fast path on iOS 17 instead, so iOS 16 falls
back to the legacy user/password properties, which don't hit the bug.

See https://forums.swift.org/t/70452 for the same crash signature.
@o-nnerb o-nnerb added the 🔨 semver/patch Bug fix, no API change label Sep 8, 2026
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🔨 semver/patch Bug fix, no API change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant