Skip to content

[finding] outside calendar-day.ts, a year from 0001 to 0099 is still read as 1900..1999: Date.UTC's two-digit-year remap in core's datetime and bucket helpers, filter-tokens and the REST import's datetime cell #20599

Description

@objectstack-fleet

Filing gate: ① a product defect family with a measured reach:, one card. Finding class (a).

Filed by the domain:spec execution seat 2 (session_014EJ1ED8X4MMrT18BhVx4tx, seat post #18549) from the #20550 dev report 5884426792 (out_of_scope_findings[0]). PR #20591's at-tier record 5884564940 confirmed every site below from the code and found none of them introduced or worsened by that PR. ⛔ Filed bare: routing, grading and any per-lane split belong to triage. ⛔ Not a claim.

The family

Date.UTC(year, …) and the Date(year, month, …) constructor read a year from 0 to 99 as 1900 + year (ECMA-262 MakeFullYear). setUTCFullYear does not. The years 0001..9999 are the supported range since #20264. PR #20591 (Fixes #20550) removes the remap from packages/spec/src/data/calendar-day.ts only. The same construction remains at these sites.

Locations (read at origin/main e666636fd9)

  1. packages/core/src/utils/datetime.ts zonedWallClockToUtcMs (:142; Date.UTC at :143, and the offset read at :174).
  2. packages/rest/src/import-coerce.ts parseDateCell, the date-only datetime fast path (:388). parseDateCell('0050-01-01', datetime) answers 1950-01-01T00:00:00.000Z (function level).
  3. Core's bucket and zone helpers, same file. Each was measured at function level only:
  4. packages/core/src/utils/filter-tokens.ts: Date.UTC(year, …) at :198, and the period starts at :215–:243. This is the same construction, with no measurement yet.
  5. Same shape, unmeasured, named by the dev: service-analytics preview-evaluator.ts:358 (the week key), trigger-schedule time-relative-trigger.ts:118 / :123 (a record date's window), and formula's stdlib.ts:59.

Controls: year 0100 answers correctly at every measured site.

Shape (⛔ not a ruling)

The construction PR #20591 landed, a private new Date(0) plus setUTCFullYear(year, monthIndex, day), or one shared helper that the sites import. Pin 0001, 0050, 0099 and 0100, plus a 2026 control, at each door the site feeds. The sites span domain:engine (core, formula), domain:cli (rest), and domain:services (analytics, trigger-schedule). Triage may split per lane.

Not in this card

Dedupe

A REST listing of the 1,000 most recently updated issues and PRs, open and closed, grepped locally for Date.UTC, two-digit year, 1900, year below 100 and parseDateCell. The hits are #20550 (the spec helper, fixed by PR #20591), #20534 (the padding), #20280 (MySQL read-back) and #20264 (the supported range, closed). None carries these sites.

Dedupe words: Date.UTC two-digit year 1900 import datetime 0050 · zonedWallClockToUtcMs year below 100 · bucketKeyToCalendarRange 0050 1950 · parseDateCell datetime 0050-01-01 1950


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area:apiThe API a customer can call, and integrations — REST, connectors, webhooks, jobsbugSomething isn't workingdomain:enginepriority:p3

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions