Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

mimosa 1.0.3: guard shapes not credited by taint analysis (5 reproducible defects) + request incremental git-gate

Aperta
#52 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 3 giorni

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
30/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
git, node.js, python, typescript

Direzione di ricerca

Start by reviewing the five reproductions and the requested sanitizer patterns, then inspect mimosa_triage.json and the .mimosa/history stop-hook records. The scope spans taint recognition, git-tree selection, staged-diff scanning, timeout handling, and seeded-simulation exceptions. Done means the upstream report is submitted, its tracking id is recorded, and the requested behavior is addressed or clearly tracked.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Mimosa upstream feedback draft (M1)

Status: drafted, pending submission. Once submitted, put the tracking id into
mimosa_triage.json → upstream.tracking.

Environment

  • Plugin: mimosa@zcode-plugins-official 1.0.3
  • Workload: monorepo with a live trading system (~370 source files, py/ts)
  • Baseline seals: scan-2026-09-28T04-25-50.259Z-22d8d1a1af55 (62 findings),
    scan-2026-09-28T04-39-14.508Z-223908513145 (32 findings post-fix)

Five reproducible defects / gaps

  1. Sink-wrapped guard not credited. chainlink_poll.py already called
    guard_url(url) at URL construction (landed in a reviewed commit); its
    urlopen kept being flagged. Moving guard_url(...) inline into the
    Request(...) constructor at the sink statement still does not clear the
    finding. Expected: a call to a guard function wrapping the URL argument at
    or near the sink should satisfy the SSRF rule (scheme+host+resolved-IP are
    all enforced by the guard).

  2. Same-shaped fix clears one file but not another. A function-entry
    urlsplit scheme+hostname allowlist cleared pmracer/pmracer/history.py
    and pmracer/scripts/probe_sources.py but not
    pmracer/scripts/backfill_candles_35d.py (byte-for-byte same shape).
    Suggest a documented, deterministic recognition contract for guard shapes.

  3. Helper-mediated guards are opaque. _safe_join() (containment via
    os.path.realpath + commonpath) results still get flagged at every
    downstream open(). Same for cross-module guard_url. Expected: local or
    cross-file sanitizer functions be recognized (even via an explicit
    allowlist of guard function names configured per project).

  4. Git gate scans the wrong tree. Committing in C:\repo-dev while the
    ZCode workspace is C:\repo made the L3 gate report findings with
    C:\repo\... paths (stale live tree), blocking every dev-tree commit until
    a subprocess bypass was used. Expected: resolve the tree from the git
    command itself (-C, cd chains) or the tool payload cwd, and scan only
    the committing tree; ideally scan only the commit's staged diff
    (focusFiles) instead of the whole project.

  5. Scan runs are frequently inconclusive via node spawnSync ETIMEDOUT.
    Five consecutive stop-hook runs in .mimosa/history are inconclusive
    with spawnSync <node.exe> ETIMEDOUT on core files (tail_engine,
    shadow_engine, accounts). Expected: configurable timeout, retry, and an
    explicit verdictEffect policy when the scanner times out.

Requested sanitizer recognition (would clear our remaining 23 high)

Pattern id Shape Files
sink-inline-guard urlopen(Request(guard_url(url), ...)) planb feeds/ledger/truth/tail_engine/context (7 sites)
entry-allowlist urlsplit scheme+host allowlist at helper entry backfill, datastreams probe, price_history
inline-dotdot explicit '..' in path.parts (or string split) before open() identity, calibration, counter_report, segment_analysis_v2
safe-join-inline-dotdot _safe_join() + re-stated inline check at sink regime_lab, segment_analysis

The seeded-randomness rule also fires on random.Random(seed) used for
statistical simulation (bootstrap / CRN Monte-Carlo); those sites cannot move
to secrets without breaking reproducibility. A project-level rule tweak or
a # mimosa: seeded-simulation annotation contract would help.

Lingua principale
Python
Stelle
73
Fork
46
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di zai-org/zcode-plugins

Tutte le issue di zai-org/zcode-plugins

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.