Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Distinct repositories reuse clone and embedding state through name collisions

Abierto
#607 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
45/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
python
Área
backend, security

Línea de trabajo

Start with Repo._extract_repo_name and trace how its returned name is used to build databases/{repo.name}.pkl under repo.root_path. Reproduce the collision with the GitHub and GitLab URLs given in the issue, then verify that distinct canonical repository URLs produce distinct storage keys and no existing clone or index state is reused.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Affected versions: confirmed on main at commit d92819a9 (the project publishes no tagged release).

Summary

Repo._extract_repo_name derives the clone/embedding storage key only from the last two URL path segments (owner_repo). This drops the host and any subgroup path segments beyond the last two, so two different repositories (different host, or a GitLab subgroup path sharing its last two segments with a different repo) can derive the same storage key and reuse each other's clone/index state.

Details

owner = url_parts[-2]
repo = url_parts[-1].replace(".git", "")
repo_name = f"{owner}_{repo}"
save_db_file = os.path.join(repo.root_path, "databases", f"{repo.name}.pkl")

https://github.com/acme/widget and https://gitlab.com/acme/widget derive the identical key acme_widget, as do https://gitlab.com/acme/widget and https://gitlab.com/some/other/group/acme/widget.

POC

(available upon request)

Impact

A caller who primes a colliding storage key (indexing a repository they control whose derived name matches a target's) causes a later request for the real target to reuse that state: cross-repository source disclosure and integrity confusion in the served wiki/chat content.

Suggested fix: key storage with a digest of the canonical scheme, host, full repository path, and type. A fix is included in the linked PR.

Fix: #594

Lenguaje dominante
Python
Estrellas
18.1k
Forks
2k
Métricas de merge de PR
Sin PR fusionados en 30 d

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de AsyncFuncAI/deepwiki-open

Todos los issues de AsyncFuncAI/deepwiki-open

Issues similares

Más issues de Python

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.