[security] Unbounded edge allocation: cross-file import resolution creates F*C*K edges from a tiny corpus
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
Direzione di ricerca
Start with graphify/extract.py, especially _resolve_cross_file_imports at lines 2123-2253 and the edge creation around line 2235; then trace how extract(), build(), the watch loop, and to_json/to_cypher materialize the graph. Reproduce the described 401-file corpus and verify that matching imports only create relevant deduplicated edges, the 100,000-edge budget raises a clear ValueError, and large graph artifacts are not produced.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Security Finding: Unbounded edge allocation: cross-file import resolution creates FCK edges from a tiny corpus
Severity: HIGH (CVSS 7.1)
CWE: CWE-770
Repository: Graphify-Labs/graphify
Affected: graphify/extract.py:2235
Description
extract._resolve_cross_file_imports (extract.py:2123-2253) iterates every imported name and, for each, adds an edge from EVERY local class in the importing file (lines 2235-2247). Cost is O(files x imported_names x local_classes) with no cap on edges, nodes, or edges-per-node anywhere in extract()/build(). A 5.26 MB generated corpus (401 files: one module defining 2000 classes, 400 files each defining 8 classes and importing all 2000 names) produced 6,405,600 edges and 5,601 nodes, driving peak RSS to ~2.1-2.7 GB and 6.6-21s of work. The subsequent watch rebuild and to_json/to_cypher then materialize all of it again.
Impact
A small, easily authored source tree forces multi-gigabyte memory use and multi-million-edge graphs. Because graphify runs this rebuild automatically via the watch loop and the post-commit git hook, simply committing the crafted files triggers the exhaustion. graph.json/GRAPH_REPORT.md/observed outputs grow proportionally, exhausting disk as well.
Remediation
Cross-file import resolution no longer emits a cartesian product of every imported name by every class in the importing file. Each class node is now mapped to the identifiers its own body references, and a uses edge is emitted only for classes that actually mention the imported name (or its alias), with (source, target) pairs deduplicated so repeated import statements cannot multiply edges. A hard global budget (_MAX_CROSS_FILE_EDGES = 100,000) aborts with a clear ValueError before more memory is allocated, so a small crafted corpus can no longer drive multi-gigabyte extraction/build memory or multi-million-edge graph.json artifacts.
Affected Code
graphify-main/graphify/extract.py:2235
line = node.start_point[0] + 1
for name in imported_names:
tgt_nid = stem_to_entities[target_stem].get(name)
if tgt_nid:
for src_class_nid in local_classes:
new_edges.append({
"source": src_class_nid,
"target": tgt_nid,
"relation": "uses",
"confidence": "INFERRED",
"source_file": str_path,
"source_location": f"L{line}",
"weight": 0.8,
})
Verification
Adversarially verified (GLM) — passed.
Reported by OpenClaw BountyBot via Failsafe Nexus (Pandora) automated security analysis. Please review carefully before acting.
- Lingua principale
- Python
- Stelle
- 124k
- Fork
- 11.9k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di Graphify-Labs/graphify
-
test(elixir): add a defguardp regression testForse già presa @ClockZW l’ha presa 1 giorno fa. Apertagood first issue help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 90/100
Graphify-Labs/graphify#4076 ·
I maintainer di solito rispondono entro 1 giorno
-
test(php): parametrize the language-construct test across all constructsForse già presa @xiehuanyi l’ha presa oggi. Apertagood first issue help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
Graphify-Labs/graphify#4075 ·
I maintainer di solito rispondono entro 1 giorno
-
test(zig): assert a tagged-union nested-struct payload's fields are not mintedForse già presa @Jarvis-J-Jacob l’ha presa oggi. Apertagood first issue help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
Graphify-Labs/graphify#4074 ·
I maintainer di solito rispondono entro 1 giorno
-
test(rust): positive same-family cross-language base resolutionForse già presa @xiehuanyi l’ha presa oggi. Apertagood first issue help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
Graphify-Labs/graphify#4073 ·
I maintainer di solito rispondono entro 1 giorno
-
fix(astro): port the U+2028 trailing-comment terminator from the Svelte maskerForse già presa @Sourya-Prabaharan l’ha presa 1 giorno fa. Apertagood first issue help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 90/100
Graphify-Labs/graphify#4072 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di Graphify-Labs/graphify
Issue simili
-
needs-human needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
gke-labs/kube-agents#2400 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Device Details tables: FS/SF columns contradict each other (nfet_01v8 Vt row, pfet_01v8 Idsat row)Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
google/skywater-pdk#450 ·
-
Drained trajectory arrays are overwritten when the sequence buffer is reusedForse già presa @sylvesterkaczmarek l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
google-deepmind/bsuite#56 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
LearningCircuit/local-deep-research#7206 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
chingu-voyages/V62-tier3-team-33#285 ·
I maintainer di solito rispondono entro 1 giorno