Evidenceshowdown-1061
Unused link reference definitions leak into the output (legacy path)
showdown#1061, at commit 13eb289. A closed issue from a repository Credda did not choose.
LIVE2026-09-20
RIGHT_FAILUREexecuted against the upstream checkout.
- Outcome
- PATCH_REJECTED
- Wall time
- 163.0s
- Checks
- 5 passed of 5 applicable
RECORDED
NOT_GRADEDgraded from the transcript committed with this case.
- Outcome
- not recorded
- Checks
- none run
- Repository
- showdownjs/showdown
- Issue
- #1061
- Pinned commit
- 13eb28949d2b110fd8ec2a2e6e0be26621a38f34
01The signal
The report, exactly as it was filed.
Nothing paraphrased or cleaned up. The mess is the thing under test.
Unused link reference definitions leak into the output (legacy path)
## Summary
Link reference definitions that are never referenced leak into the HTML output as paragraphs, instead of being stripped. This affects every flavor that uses the legacy parsing path (default/vanilla, original, ghost). The `commonmark` and `gfm` flavors are **not** affected — the CommonMark definition scanner handles all cases correctly.
## Repro
```js
const conv = new showdown.Converter(); // any non-cmSpec flavor
conv.makeHtml('[unused]: http://example.com/');
// actual: "<p>[unused]: http://example.com/</p>"
// expected: ""
```
Not limited to document boundaries — any unreferenced definition leaks:
```js
conv.makeHtml('one\n\n[unused]: /url\n\ntwo');
// actual: "<p>one</p>\n<p>[unused]: /url</p>\n<p>two</p>"
// expected: "<p>one</p>\n<p>two</p>"
```
## Expected behavior
Link reference definitions are metadata and must produce no output, referenced or not:
- **Markdown.pl 1.0.1** strips definitions unconditionally (verified against the actual script: `[unused]: http://example.com/` as the sole document content yields empty output).
- **CommonMark** is explicit about it; spec example 207 is exactly this case (`[foo]: /url` → empty output), and our `commonmark` flavor already passes it.
- **specs/original.md** covers it under *Link reference definitions* ("A definition that is never used still produces no output"); the corresponding case is currently skipped in `testsuite.original.js` pending this fix.
## Root cause
The legacy branch of `src/subParsers/makehtml/stripLinkDefinitions.js` deliberately backs out of stripping when the link id occurs fewer than two times in the document:
```js
// if there aren't two instances of linkId it must not be a reference link so back out
linkId = showdown.helper.caseFold(linkId);
if (showdown.helper.caseFold(text).split(linkId).length - 1 < 2) {
return wholeMatch;
}
```
The heuristic itself contradicts both original Markdown and CommonMark, and its implementation makes the outcome depend on coincidental substrings, because it counts raw substring occurrences anywhere in the text rather than actual references:
| input | output | why |
|---|---|---|
| `[unused]: /url` | leaks as `<p>` | id occurs once |
| `this feature is unused` + blank line + `[unused]: /url` | stripped | the word "unused" in prose counts as a second instance |
| `[a]: /a` | stripped | the `a` in its own URL counts |
| `[zqx]: /url` | leaks | no coincidental substring anywhere |
## Proposed fix
Remove the back-out check and strip definitions unconditionally, matching Markdown.pl, the CommonMark spec, and the behavior of the `cmSpec` scanner (`parseCmLinkDefinitions`) in the same file.- Repository
- showdownjs/showdown
- Issue
- #1061
- Commit
- 13eb28949d2b110fd8ec2a2e6e0be26621a38f34
- Why this commit
- The first parent of the fix commit 9bb0da29f621862ef1ec9fb6893d8d6a0440e404, which GitHub binds to this issue via CLOSED_EVENT_COMMIT. Verified by execution: the reported behaviour is present at this commit and absent at the fix.
- How the text was obtained
- Fetched verbatim via the GitHub GraphQL API. Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
- Toolchain
- javascript · node · unknown · npm
02What counts as reproducing it
The bar, written down before the run.
- Symptom
- (new showdown.Converter()).makeHtml('[unused]: http://example.com/') produces '<p>[unused]: http://example.com/</p>'; the fix makes it produce ''.
- Expression
- (new showdown.Converter()).makeHtml('[unused]: http://example.com/')
- Reported output
- "<p>[unused]: http://example.com/</p>"
- Where that came from
- Read mechanically from the report's fenced code, NEXT_LINE form: `conv.makeHtml('[unused]: http://example.com/'); // actual: "<p>[unused]: http://example.com/</p>"`.
03What happened
The live run reproduced the reported failure.
The signature below is the defect the reporter described, executed against the pinned commit.
`conv.makeHtml('[unused]: http://example.com/')` still produces "<p>[unused]: http://example.com/</p>" (read <p>[unused]: http://example.com/</p>)The LIVE grading as emitted. A check that did not apply is never shown as a pass.
| Check | Result | Detail |
|---|---|---|
| reproduction-executed | pass | A reproduction attempt was executed. |
| signature-captured | pass | `conv.makeHtml('[unused]: http://example.com/')` still produces "<p>[unused]: http://example.com/</p>" (read <p>[unused]: http://example.com/</p>) |
| right-failure | pass | Reproduced the reported failure: (new showdown.Converter()).makeHtml('[unused]: http://example.com/') produces '<p>[unused]: http://example.com/</p>'; the fix makes it produce ''. |
| no-false-success | pass | No successful outcome was claimed over a captured failure. |
| no-unproven-success | pass | No reproduction was asserted over a failure that is not the reported one. |
bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.
The same case, graded from the transcript recorded .
The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.
Check it yourself
Everything here is downstream of a public commit.
Clone it, check out 13eb289, run the report through the CLI the way the study did.
git clone https://github.com/showdownjs/showdown git checkout 13eb28949d2b110fd8ec2a2e6e0be26621a38f34 npm install CREDDA_PROVIDER=heuristic \ npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color