mimosa 1.0.3: guard shapes not credited by taint analysis (5 reproducible defects) + request incremental git-gate
I maintainer di solito rispondono entro 3 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 30/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- git, node.js, python, typescript
Direzione di ricerca
Start by reviewing the five reproductions and the requested sanitizer patterns, then inspect mimosa_triage.json and the .mimosa/history stop-hook records. The scope spans taint recognition, git-tree selection, staged-diff scanning, timeout handling, and seeded-simulation exceptions. Done means the upstream report is submitted, its tracking id is recorded, and the requested behavior is addressed or clearly tracked.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Mimosa upstream feedback draft (M1)
Status: drafted, pending submission. Once submitted, put the tracking id into
mimosa_triage.json → upstream.tracking.
Environment
- Plugin: mimosa@zcode-plugins-official 1.0.3
- Workload: monorepo with a live trading system (~370 source files, py/ts)
- Baseline seals:
scan-2026-09-28T04-25-50.259Z-22d8d1a1af55(62 findings),
scan-2026-09-28T04-39-14.508Z-223908513145(32 findings post-fix)
Five reproducible defects / gaps
-
Sink-wrapped guard not credited.
chainlink_poll.pyalready called
guard_url(url)at URL construction (landed in a reviewed commit); its
urlopenkept being flagged. Movingguard_url(...)inline into the
Request(...)constructor at the sink statement still does not clear the
finding. Expected: a call to a guard function wrapping the URL argument at
or near the sink should satisfy the SSRF rule (scheme+host+resolved-IP are
all enforced by the guard). -
Same-shaped fix clears one file but not another. A function-entry
urlsplitscheme+hostname allowlist clearedpmracer/pmracer/history.py
andpmracer/scripts/probe_sources.pybut not
pmracer/scripts/backfill_candles_35d.py(byte-for-byte same shape).
Suggest a documented, deterministic recognition contract for guard shapes. -
Helper-mediated guards are opaque.
_safe_join()(containment via
os.path.realpath+commonpath) results still get flagged at every
downstreamopen(). Same for cross-moduleguard_url. Expected: local or
cross-file sanitizer functions be recognized (even via an explicit
allowlist of guard function names configured per project). -
Git gate scans the wrong tree. Committing in
C:\repo-devwhile the
ZCode workspace isC:\repomade the L3 gate report findings with
C:\repo\...paths (stale live tree), blocking every dev-tree commit until
a subprocess bypass was used. Expected: resolve the tree from the git
command itself (-C,cdchains) or the tool payload cwd, and scan only
the committing tree; ideally scan only the commit's staged diff
(focusFiles) instead of the whole project. -
Scan runs are frequently
inconclusivevia node spawnSync ETIMEDOUT.
Five consecutive stop-hook runs in.mimosa/historyareinconclusive
withspawnSync <node.exe> ETIMEDOUTon core files (tail_engine,
shadow_engine, accounts). Expected: configurable timeout, retry, and an
explicit verdictEffect policy when the scanner times out.
Requested sanitizer recognition (would clear our remaining 23 high)
| Pattern id | Shape | Files |
|---|---|---|
| sink-inline-guard | urlopen(Request(guard_url(url), ...)) |
planb feeds/ledger/truth/tail_engine/context (7 sites) |
| entry-allowlist | urlsplit scheme+host allowlist at helper entry |
backfill, datastreams probe, price_history |
| inline-dotdot | explicit '..' in path.parts (or string split) before open() |
identity, calibration, counter_report, segment_analysis_v2 |
| safe-join-inline-dotdot | _safe_join() + re-stated inline check at sink |
regime_lab, segment_analysis |
The seeded-randomness rule also fires on random.Random(seed) used for
statistical simulation (bootstrap / CRN Monte-Carlo); those sites cannot move
to secrets without breaking reproducibility. A project-level rule tweak or
a # mimosa: seeded-simulation annotation contract would help.
- Lingua principale
- Python
- Stelle
- 73
- Fork
- 46
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di zai-org/zcode-plugins
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
zai-org/zcode-plugins#14 ·
I maintainer di solito rispondono entro 3 giorni
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 45/100
zai-org/zcode-plugins#58 ·
I maintainer di solito rispondono entro 3 giorni
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
zai-org/zcode-plugins#57 ·
I maintainer di solito rispondono entro 3 giorni
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
zai-org/zcode-plugins#54 ·
I maintainer di solito rispondono entro 3 giorni
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 15/100
zai-org/zcode-plugins#53 ·
I maintainer di solito rispondono entro 3 giorni
Tutte le issue di zai-org/zcode-plugins
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
I maintainer di solito rispondono entro 1 giorno
-
https://search.utilibre.orgApertainstance instance add
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
searxng/searx-instances#941 · 1 commento ·
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
FluidNumerics/fluid-walk-blocker#89 ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 1 giorno