Skip to content

fix: skip FIRE scoring when tag coordinates run past the sequence - #137

Closed
mrvollger wants to merge 2 commits into
release/v0.13from
fix/136-fire-coords-out-of-range
Closed

mrvollger wants to merge 2 commits into
release/v0.13from
fix/136-fire-coords-out-of-range

Conversation

@mrvollger

@mrvollger mrvollger commented Aug 29, 2026 •

Copy link
Copy Markdown
Member

Fixes #136.

ft fire --ont panicked with range start index 4294944243 out of range for slice of length 9910.

Cause

The input BAM holds hard-clipped supplementary alignments that keep nuc/msp tags from the full-length read. The tag coordinates run past the clipped SEQ. On reverse-strand records the coordinate flip (read_length - end) wraps below zero as a u32. get_bp_count then slices the sequence with these values and panics.

Fix

ft fire checks the raw molecular coordinates of the msp, m6a, and cpg annotations before it scores a record. If a coordinate runs past the sequence, it warns and writes the record to the output unchanged:

WARN skipping FIRE for 4bd15181-...: msp coordinates extend past the 9910 bp sequence (hard-clipped supplementary alignment?)

Verified on the issue's sample: all 146 records process, with two warnings and no panic.

Regression test

tests/data/ont_hardclip_supplementary.bam holds two scorable primary reads plus the two crashing reads (one forward, one reverse) from the issue's sample.

Patch release (0.13.1)

This PR targets release/v0.13, a new maintenance branch cut from the v0.13.0 tag. Main already has unreleased breaking commits, so the next release from main is 0.14.0. release-plz opens its release PR against the branch that runs the workflow, so this branch gets its own 0.13.1 release PR.

The second commit backports the CI plumbing the branch needs:

  • CI runs on PRs that target release/**.
  • The release-plz workflow triggers on pushes to release/** (push events use the pushed branch's workflow file, so this copy only acts on this branch).
  • cargo-dist is dispatched on the released tag instead of main, so binaries build from the patched 0.13.x source.

Release steps after merge:

  1. release-plz opens chore: release (v0.13.1) against release/v0.13. Merge it.
  2. release-plz publishes to crates.io, tags v0.13.1, cuts the GitHub release, and fires cargo-dist for the binaries.

Order matters: release 0.13.1 before the pending 0.14.0 release PR (#132) merges. After 0.14.0 is on crates.io, release-plz refuses to bump 0.13.x ("the local package has already a different version with respect to the registry package"). The forward-port to main is #138. 0.13.1 also carries #142, the ft call-peaks --haps fix for #140.

Main

The forward-port (#138) moves this check into the reader so every command drops these annotations, not only FIRE. That is a behavior change for extract and pileup, so it ships in 0.14.0 and this PR stays FIRE-only.

Mitchell R. Vollger added 2 commits August 29, 2026 10:01
Hard-clipped supplementary alignments can keep nuc/msp tag coordinates
from the full-length read. Their MSP coordinates run past the clipped
SEQ, and reverse-strand records wrap the flipped index below zero. Both
made ft fire panic with an out-of-range slice index.

ft fire now checks the raw molecular coordinates before it scores a
record. A record that fails the check gets a warning and is written to
the output unchanged.

Fixes #136
CI now runs on PRs that target release/** branches. The release-plz
workflow copy on this branch triggers on pushes to release/**, so a
merged fix opens a patch release PR against the branch, the same flow
main has. cargo-dist is dispatched on the released tag instead of main,
so binaries build from the patched 0.13.x source.
@mrvollger

Copy link
Copy Markdown
Member Author

Superseded by #138: the check moves into the reader so every command drops these annotations, and it ships in 0.14.0 instead of a patch. Branch kept for reference.

@mrvollger mrvollger closed this Sep 18, 2026
mrvollger added a commit that referenced this pull request Sep 18, 2026
Cherry-pick of the CI commit from the closed #137. Without it nothing
releases from this branch: the release-plz workflow here still triggers
only on pushes to `main`, so merging #142 opened no 0.13.1 release PR.

- CI runs on PRs that target `release/**`.
- release-plz triggers on pushes to `release/**` and on
`workflow_dispatch`. Push events use the pushed branch's workflow file,
so this copy only acts on this branch.
- cargo-dist is dispatched on the released tag instead of `main`, so
binaries build from the patched 0.13.x source.

Merging this is itself a push to `release/v0.13`, so release-plz will
run and open the `chore: release` PR for 0.13.1 with the #142 fix.

Co-authored-by: Mitchell R. Vollger <mvollger@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant