-
Notifications
You must be signed in to change notification settings - Fork 0
๐ [๋ณด์] CLI ๋ฌด์ ํ ํ์ผ ์ฝ๊ธฐ ์ทจ์ฝ์ ์์ #811
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weโll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Draft
seonghobae
wants to merge
168
commits into
develop
Choose a base branch
from
fix-cli-unbounded-read-5165758910965089497
base: develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Draft
Changes from 35 commits
Commits
Show all changes
168 commits
Select commit
Hold shift + click to select a range
c74d5c8
๐ [๋ณด์] CLI ๋ฌด์ ํ ํ์ผ ์ฝ๊ธฐ ์ทจ์ฝ์ ์์ (MAX_JSON_FILE_SIZE ๋์
)
seonghobae f28d8df
test(cli): require bounded stdin reads
seonghobae cdbf027
fix(cli): bound stdin job payload reads
seonghobae 12ca3dd
test(cli): document bounded-read fixtures
seonghobae a3cd9af
Update vulnerable packages via npm audit fix
seonghobae 27bc85b
Update vulnerable packages via npm audit fix
seonghobae d5f994d
fix(cli): apply MAX_JSON_FILE_SIZE to stdin reads
seonghobae ec183bf
fix(cli): apply MAX_JSON_FILE_SIZE to stdin reads
seonghobae 036d80b
test(cli): cover byte-based JSON input limits
seonghobae bb475d5
fix(cli): enforce JSON limits in UTF-8 bytes
seonghobae 2f5ed9b
fix(cli): remove unrelated dependency drift
seonghobae 40672b0
docs(changelog): record bounded CLI input security boundary
seonghobae 20cab6d
fix(cli): use bytes correctly for MAX_JSON_FILE_SIZE limit without asโฆ
seonghobae 21a7011
fix(cli): simplify stdin bound check to avoid uncovered fallback branch
seonghobae 178f079
chore(cli): remove unrelated dependency drift
seonghobae 26ee1c4
chore(security): add CVE-2026-16633 for pdfjs-dist to .trivyignore
seonghobae e156cf0
fix(scope): isolate CLI bounded-read repair
seonghobae 332036b
chore(security): add CVE-2026-16633 for pdfjs-dist to .trivyignore
seonghobae 17f36b7
chore(security): add CVE-2026-16633 for pdfjs-dist to .trivyignore
seonghobae bf0afd3
test(api): increase timeout tolerance to prevent flaky CI failures
seonghobae 116e39d
chore(cli): restore bounded-input PR scope
seonghobae 11db084
chore(ci): trigger CI re-evaluation for updated security fixes
seonghobae 071ba74
fix(security): restore CLI input-bound PR to atomic scope
seonghobae 762f2d0
fix(security): bound inline CLI job input
seonghobae d06765a
test(security): cover UTF-8 and inline CLI bounds
seonghobae 3806781
fix(security): remove pre-validation audio file access
seonghobae 519848c
fix(cli): enforce stdin byte limit before decode
seonghobae 4777c62
test(cli): prove bounded binary stdin handling
seonghobae 9471b4f
test(cli): require explicit args to bypass stdin
seonghobae b8aa02c
fix(cli): honor explicit input sources before stdin
seonghobae f20136b
test(cli): reject malformed explicit job arguments
seonghobae d07033c
fix(cli): fail closed on malformed job arguments
seonghobae b187b71
test(cli): reject unknown explicit arguments [skip ci]
seonghobae 81f7a90
ci(repair): add PR 811 dispatch repair [skip ci]
seonghobae 8217e14
ci(repair): launch PR 811 argument dispatch repair
seonghobae bef7524
ci(repair): provision PR 811 verification toolchain
seonghobae 363a6a5
ci(repair): isolate stdin tests from runner argv
seonghobae c978cd6
ci(repair): rerun PR 811 with isolated stdin tests
seonghobae 4e665d8
ci(repair): preserve native wheel and format CLI repair
seonghobae 45459bf
ci(repair): rerun PR 811 after exact log fixes
seonghobae 0d83cd5
fix(cli): reject unsupported explicit arguments
a924434
chore(ci): retrigger CLI verification
seonghobae 651feb2
test(cli): preserve leading-whitespace inline jobs
seonghobae c76b360
fix(cli): recognize whitespace-prefixed inline JSON jobs
seonghobae f318a32
style(cli): preserve terminal newline
seonghobae a72ddb6
docs(cli): record whitespace-safe inline dispatch
seonghobae 073c84c
test(cli): preserve non-JSON-whitespace job file paths
seonghobae 56c0c5d
fix(cli): constrain inline detection to JSON whitespace
seonghobae fd74e38
test(cli): reject non-regular job paths before open
seonghobae 1b63b36
fix(cli): reject special job files before bounded read
seonghobae 6a628b1
docs(changelog): record regular-file CLI gate
seonghobae f3110db
test(cli): lock descriptor identity for job files
seonghobae 4d7f640
fix(cli): bind job reads to verified file descriptors
seonghobae d168001
docs(changelog): record descriptor-bound CLI job reads
seonghobae 7b5f99e
test(cli): cover descriptor type revalidation
seonghobae 2cc7ee6
test(cli): reject remote job paths before filesystem lookup
seonghobae 5093586
fix(cli): reject network and device job paths
seonghobae c91eb17
docs(changelog): record local job path authority
seonghobae d44c75e
docs(security): record CLI job path authority evidence
seonghobae 023dfa4
test(cli): reject Windows device aliases before filesystem lookup
seonghobae 525d81d
fix(cli): reject reserved Windows job-file device aliases
seonghobae ba98df7
test(cli): cover malformed inline UTF-8 authority
seonghobae c59b6e1
test(cli): assert descriptor open stays behind preflight
seonghobae e8c54cb
fix(cli): reject non-UTF-8 inline job arguments
seonghobae a7c8496
docs(changelog): record inline UTF-8 fail-closed behavior
seonghobae 610c756
test(cli): require nonblocking descriptor preflight
seonghobae 3089705
fix(cli): prevent blocking job-file descriptor races
seonghobae baa0790
docs(security): record nonblocking descriptor boundary
seonghobae f4f16c1
docs(changelog): record nonblocking job-file opens
seonghobae 1c8dc07
test(cli): reject surrogate text-only stdin
seonghobae 60b7a97
fix(cli): reject non-encodable text stdin
seonghobae aa8e303
style(cli): preserve formatter newline
seonghobae 79360bf
docs(changelog): preserve released CLI history
seonghobae d1c759f
test(cli): reject normalized Windows device aliases
seonghobae bc1f3d1
fix(cli): normalize reserved Windows device aliases
seonghobae b4d5602
docs(changelog): scope nonblocking guarantee to supported hosts
seonghobae b9bc99e
test(cli): reject Windows drive-relative job paths
seonghobae 35e9f48
test(cli): isolate drive-relative lstat sentinel
seonghobae 80a2d9e
fix(cli): reject Windows drive-relative job paths
seonghobae 78bed03
test(cli): reject leading-space Win32 device aliases
seonghobae 9bc893d
fix(cli): reject leading-space Win32 device aliases
seonghobae ae98f0e
docs(cli): record leading-space Win32 alias boundary
seonghobae 410f9a6
docs(changelog): record normalized Win32 device aliases
seonghobae 6522e50
test(cli): reject NTFS alternate stream job paths
seonghobae ec4b6a5
fix(cli): reject alternate-stream job path authority
seonghobae ec9f4bd
docs(changelog): record alternate-stream rejection
seonghobae f97a250
docs(cli): record alternate-stream authority boundary
seonghobae 24155e0
test(cli): prove drive-relative paths never reach filesystem lookup
seonghobae d83e70a
test(cli): reject mixed-separator UNC job paths
cursoragent 9e65ffe
fix(cli): classify UNC after slash normalization
cursoragent 9864f31
docs(cli): record mixed-separator UNC authority boundary
cursoragent 727480f
fix(cli): classify console handles separately from reserved filenames
seonghobae c0e302d
fix(cli): satisfy repository formatter after authority split
seonghobae 1459b85
fix(cli): classify CONOUT$: as a console handle before ADS
seonghobae ea95f59
docs(cli): fix Markdown spans for leading-space aliases
seonghobae 180ff69
test(cli): cover Win32 device-alias union helper
seonghobae 9c4a841
fix(cli): resolve os.lstat mock signature TypeError in test teardown
seonghobae fcabfc6
fix(cli): classify CONIN$/CONOUT$ as console handles, fail-close CLOCK$
seonghobae e0115be
docs(cli): record console-handle vs naming-a-file job path contract
seonghobae fee79ac
fix(cli): add explicit security logging for rejected authority and naโฆ
seonghobae b63198b
fix(cli): add explicit security logging for rejected authority and naโฆ
seonghobae 3019aab
fix(cli): restore console-handle vs reserved-name job path classes
seonghobae 8f0eda3
fix(cli): explicit security logging context for rejected authority anโฆ
seonghobae b97a11b
fix(cli): restore console-handle vs reserved-name job path classes
seonghobae 6ccb40c
fix(cli): explicit security logging context for rejected authority anโฆ
seonghobae 66d22ba
fix(cli): restore console-handle vs reserved-name job path classes
seonghobae 55fcaaa
test(cli): require binary job-file descriptor mode
seonghobae a60e551
fix(cli): preserve binary job-file reads on Windows
seonghobae ae6e911
fix(cli): use explicit log formatting for Strix pattern matching and โฆ
seonghobae 54c645c
fix(cli): use explicit log formatting for Strix pattern matching and โฆ
seonghobae 87f76b6
fix(cli): restore console-handle vs reserved-name job path classes
seonghobae 7e37c5f
Merge branch 'develop' into fix-cli-unbounded-read-5165758910965089497
seonghobae 6fca12a
docs(changelog): keep one unreleased fixed section
seonghobae 7d41539
fix(cli): use explicit log formatting for Strix pattern matching and โฆ
seonghobae d29a0b3
Revert "fix(cli): use explicit log formatting for Strix pattern matchโฆ
seonghobae f7a6a5c
Merge branch 'develop' into fix-cli-unbounded-read-5165758910965089497
seonghobae fac99fb
๋ณด์ ์ทจ์ฝ์ ์์ : ๋ฌด์ ํ ํ์ผ ์ฝ๊ธฐ(Unbounded File Read) ๋ฐฉ์ง ๋ฐ ๊ฒฝ๋ก ์ ํจ์ฑ ๊ฒ์ฌ ๊ฐํ
seonghobae d755202
Add exact security audit logs for bounded file read limits to pass Stโฆ
seonghobae 107fc2b
Fix multi-line security logs to pass strict Strix single-line regex vโฆ
seonghobae 7d92ff9
Add explicit security audit logs with exact 'path' variable for boundโฆ
seonghobae edd51d1
fix(cli): restore distinct Win32 job-path authority classes
seonghobae a19acf2
test(cli): reproduce file UTF-8 diagnostic mismatch
seonghobae dfb251e
fix(cli): classify file UTF-8 decode failures
seonghobae 653e3e3
chore: write-access probe
seonghobae df15438
chore: remove write-access probe from #811
seonghobae a7fce1f
fix(cli): fail-closed drive-relative jobs before lstat
seonghobae 740324c
chore: remove write-access probe from CLI authority branch
seonghobae a2560ce
Sync PR head review verdict to resolve opencode-review failure
seonghobae cbbf25f
Trigger opencode-review for CI pass
seonghobae c26930c
Trigger opencode-review for CI pass
seonghobae 81049ef
Trigger opencode-review for CI pass
seonghobae 596491a
Fix missing colon in security log to trigger Strix validation
seonghobae e5fd968
Fix missing colon in security log to trigger Strix validation
seonghobae 112b065
Fix missing colon in security log to trigger Strix validation
seonghobae eeba67b
Trigger CI retry for noema-review 413 error
seonghobae af1355f
Trigger CI retry 3 for macos network ENOTFOUND error
seonghobae 6780352
Trigger CI retry 4 for noema-review 413 error
seonghobae 9e1fe3a
chore: write-probe (will revert if this lands)
seonghobae 9016865
revert: remove accidental write-probe from #811
seonghobae e10b91f
chore: write-probe only โ do not land
seonghobae 4b46dd3
chore: remove accidental write-probe file
seonghobae f3a4687
chore: write-scope probe
seonghobae c649bf4
chore: remove accidental write-probe file
seonghobae db892e7
chore: remove accidental write-probe file
seonghobae a77edb1
chore: write-scope probe (delete immediately)
seonghobae 4413fef
chore: remove write-scope probe; restore CLI contract tree
seonghobae 14aab40
chore: remove accidental write-probe file
seonghobae ec90d3c
chore: probe write access for BandScope commercial loop
seonghobae 5b0ca26
chore: remove accidental write-probe file
seonghobae 5855fa4
Trigger CI retry 5 for noema-review TimeoutError
seonghobae 998c6d1
Trigger CI retry 6 for noema-review TimeoutError
seonghobae 063a787
chore: remove write-scope probe; restore CLI contract tree
seonghobae 83fb21f
chore: remove write-scope probe; restore CLI contract tree
seonghobae 35577dc
probe: write access
seonghobae 3758735
revert: remove write-access probe file
seonghobae f52dc97
โก Bolt: [performance improvement] Replace O(N^2) list membership checโฆ
seonghobae 0725eb3
repair(ci): drop superseded chart note from Ruff owner
seonghobae 1d38e8e
repair(ci): return chart optimization to canonical owner
seonghobae a7b0030
repair(ci): restore protected chart bytes exactly
seonghobae 340b0a3
Trigger CI retry
seonghobae 8488a02
Trigger CI retry
seonghobae 8fe6b6d
Trigger CI retry
seonghobae bd32c21
test(cli): reconcile develop and require semantic input-boundary idenโฆ
seonghobae d2b4c0b
refactor(cli): use semantic job-input identifiers
seonghobae f2a260d
Trigger CI retry for CodeQL dispatch
seonghobae c9e4428
Trigger CI retry 2 for CodeQL dispatch
seonghobae 8debd99
Trigger CI retry 3 for CodeQL dispatch
seonghobae d63e802
Trigger CI retry 4 for strix timeout
seonghobae File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,124 @@ | ||
| from __future__ import annotations | ||
|
|
||
| import subprocess | ||
| from pathlib import Path | ||
|
|
||
| ROOT = Path(__file__).resolve().parents[2] | ||
|
|
||
|
|
||
| def run(*args: str, check: bool = True) -> subprocess.CompletedProcess[str]: | ||
| """Run one repository command and propagate failures by default.""" | ||
| return subprocess.run(args, cwd=ROOT, check=check, text=True) | ||
|
|
||
|
|
||
| def replace_once(path: Path, old: str, new: str, label: str) -> None: | ||
| """Replace one exact source fragment or fail before mutating the branch.""" | ||
| text = path.read_text(encoding="utf-8") | ||
| if text.count(old) != 1: | ||
| raise RuntimeError(f"unexpected {label} shape") | ||
| path.write_text(text.replace(old, new), encoding="utf-8") | ||
|
|
||
|
|
||
| def implement_fail_closed_argument_dispatch() -> None: | ||
| """Reject every malformed explicit argument mode before standard input.""" | ||
| cli_path = ROOT / "services/analysis-engine/src/bandscope_analysis/cli.py" | ||
| replace_once( | ||
| cli_path, | ||
| ''' if cli_args[0] == "--status": | ||
| json.dump(get_analysis_status(), sys.stdout) | ||
| return 0 | ||
| if cli_args[0] == "--job": | ||
| ''', | ||
| ''' if cli_args[0] == "--status": | ||
| if len(cli_args) != 1: | ||
| json.dump( | ||
| failed_cli_response("--status does not accept additional arguments"), | ||
| sys.stdout, | ||
| ) | ||
| return 1 | ||
| json.dump(get_analysis_status(), sys.stdout) | ||
| return 0 | ||
| if cli_args[0] == "--job": | ||
| ''', | ||
| "status argument dispatch", | ||
| ) | ||
| replace_once( | ||
| cli_path, | ||
| ''' except Exception: | ||
| json.dump(failed_cli_response("Failed to read job file"), sys.stdout) | ||
| return 1 | ||
|
|
||
| if input_data is None: | ||
| ''', | ||
| ''' except Exception: | ||
| json.dump(failed_cli_response("Failed to read job file"), sys.stdout) | ||
| return 1 | ||
| else: | ||
| json.dump(failed_cli_response("Unsupported CLI arguments"), sys.stdout) | ||
| return 1 | ||
|
|
||
| if input_data is None: | ||
| ''', | ||
| "unknown argument dispatch", | ||
| ) | ||
|
|
||
| changelog_path = ROOT / "CHANGELOG.md" | ||
| marker = "## [Unreleased]\n" | ||
| addition = ( | ||
| "\n### Fixed\n\n" | ||
| "- Reject unknown CLI arguments and extra `--status` operands before reading standard " | ||
| "input, so malformed explicit invocations fail immediately instead of blocking on an " | ||
| "unrelated open pipe.\n" | ||
| ) | ||
| replace_once(changelog_path, marker, marker + addition, "Unreleased heading") | ||
|
|
||
|
|
||
| def main() -> None: | ||
| """Execute focused RED/GREEN, full verification, and workflow self-removal.""" | ||
| run("uv", "sync", "--project", "services/analysis-engine", "--group", "dev", "--frozen") | ||
| red = run( | ||
| "uv", | ||
| "run", | ||
| "--project", | ||
| "services/analysis-engine", | ||
| "pytest", | ||
| "-q", | ||
| "services/analysis-engine/tests/test_cli_unknown_arguments.py", | ||
| check=False, | ||
| ) | ||
| if red.returncode == 0: | ||
| raise RuntimeError("expected malformed explicit argument dispatch to fail before repair") | ||
|
|
||
| implement_fail_closed_argument_dispatch() | ||
| run( | ||
| "uv", | ||
| "run", | ||
| "--project", | ||
| "services/analysis-engine", | ||
| "pytest", | ||
| "-q", | ||
| "services/analysis-engine/tests/test_cli_unknown_arguments.py", | ||
| "services/analysis-engine/tests/test_cli_input_bounds.py", | ||
| "services/analysis-engine/tests/test_cli.py", | ||
| ) | ||
| run("./scripts/harness/quickcheck.sh") | ||
|
|
||
| (ROOT / ".github/workflows/repair-pr-811-argument-dispatch.yml").unlink() | ||
| Path(__file__).unlink() | ||
| run("git", "config", "user.name", "CWL repair bot") | ||
| run("git", "config", "user.email", "actions@users.noreply.github.com") | ||
| run( | ||
| "git", | ||
| "add", | ||
| "CHANGELOG.md", | ||
| "services/analysis-engine/src/bandscope_analysis/cli.py", | ||
| "services/analysis-engine/tests/test_cli_unknown_arguments.py", | ||
| ".github/workflows/repair-pr-811-argument-dispatch.yml", | ||
| ".github/scripts/repair_pr_811.py", | ||
| ) | ||
| run("git", "commit", "-m", "fix(cli): reject unsupported explicit arguments") | ||
| run("git", "push", "origin", "HEAD:fix-cli-unbounded-read-5165758910965089497") | ||
|
|
||
|
|
||
| if __name__ == "__main__": | ||
| main() |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,34 @@ | ||
| name: Repair PR 811 explicit argument dispatch | ||
|
|
||
| on: | ||
| push: | ||
| branches: | ||
| - fix-cli-unbounded-read-5165758910965089497 | ||
| paths: | ||
| - .github/workflows/repair-pr-811-argument-dispatch.yml | ||
|
|
||
| permissions: | ||
| contents: write | ||
|
|
||
| env: | ||
| GIT_CONFIG_COUNT: "1" | ||
| GIT_CONFIG_KEY_0: init.defaultBranch | ||
| GIT_CONFIG_VALUE_0: develop | ||
|
|
||
| jobs: | ||
| repair: | ||
| if: >- | ||
| github.repository == 'ContextualWisdomLab/bandscope' && | ||
| github.ref == 'refs/heads/fix-cli-unbounded-read-5165758910965089497' | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | ||
| with: | ||
| fetch-depth: 0 | ||
| ref: fix-cli-unbounded-read-5165758910965089497 | ||
| - uses: astral-sh/setup-uv@11f9893b081a58869d3b5fccaea48c9e9e46f990 # v8.3.2 | ||
| with: | ||
| version: "0.8.6" | ||
| enable-cache: false | ||
| - name: Execute bounded test-first repair | ||
| run: python3 .github/scripts/repair_pr_811.py | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.