Skip to content

test(ci): exact-line assert in grok-build config test (CodeQL #740/#741) - #7628

Merged
diegosouzapw merged 1 commit into
release/v3.8.49from
fix/codeql-740-grok-url-substring
Jul 18, 2026
Merged

diegosouzapw merged 1 commit into
release/v3.8.49from
fix/codeql-740-grok-url-substring

Conversation

@diegosouzapw

Copy link
Copy Markdown
Owner

What

Replaces two URL-substring assertions in tests/integration/cli-settings-grok-build.test.ts (lines 146 & 203) with exact line membership.

Why

CodeQL js/incomplete-url-substring-sanitization (HIGH) flags content.includes("https://example.test/v1") as a URL-substring check. It's a false positive — the test asserts a TOML [model.custom-thing] section round-trips untouched through the grok-build config handler; there is no URL sanitization and example.test is a reserved test TLD.

But #740 + #741 are the only open CodeQL alerts repo-wide right now (they replaced #737 the moment it closed), and check:codeql-ratchet counts alerts repo-wide → they keep Quality Ratchet red on every open PR. This closes them at the source.

Fix

const preservedLines = content.split("\n").map((line) => line.trim());
assert.ok(
  preservedLines.includes("[model.custom-thing]") &&
    preservedLines.includes('base_url = "https://example.test/v1"'),
  "..."
);

Exact line membership is stronger than the old substring check — it verifies the URL sits on the base_url key, not merely somewhere in the file — and is no longer a substring-of-URL sink, so CodeQL stops flagging it. The handler preserves the section byte-for-byte, so exact match holds.

Validation (Hard Rule #18)

node --import tsx/esm --test tests/integration/cli-settings-grok-build.test.ts → 9 pass, 0 fail.

File exists only on release/v3.8.49 (added by #7241) — no main companion needed.

CodeQL js/incomplete-url-substring-sanitization (HIGH) flags
content.includes("https://example.test/v1") in the grok-build config
preservation test as a URL-substring check. It's a false positive — a
test asserting a TOML section round-trips, not URL sanitization — but it
is the only pair of open CodeQL alerts repo-wide, so check:codeql-ratchet
keeps Quality Ratchet red on every open PR.

Replace the two URL-substring checks with exact line membership
(content.split + Array.includes on the full 'base_url = "..."' line).
Stronger (verifies the URL is on the base_url key, not merely present)
and no longer a substring-of-URL sink. All 9 tests pass.
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@diegosouzapw

Copy link
Copy Markdown
Owner Author

Verified — the two CodeQL alerts (#740/#741) map exactly to lines 146 and 203 in this file, and the exact-line assertion is strictly stronger than the old substring check (it pins the URL to the base_url key, not just "somewhere in the file"). Ran the suite locally: 9/9 pass. The two red checks are unrelated base-red (mutation-test-coverage flagging an unrelated Microsoft Designer test file, and the shared Unit Tests fast-path base-red). Merge-ready.

@diegosouzapw
diegosouzapw merged commit 9b3ad09 into release/v3.8.49 Jul 18, 2026
10 checks passed
@diegosouzapw
diegosouzapw deleted the fix/codeql-740-grok-url-substring branch July 19, 2026 21:01
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
…uzapw#740/diegosouzapw#741) (diegosouzapw#7628)

Validated in local merge-train @ 8f27177d1 (full parity suite green: typecheck+file-size+complexity+cognitive+changelog+unit shards 1&2+vitest)
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…uzapw#740/diegosouzapw#741) (diegosouzapw#7628)

Validated in local merge-train @ 8f27177d1 (full parity suite green: typecheck+file-size+complexity+cognitive+changelog+unit shards 1&2+vitest)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant