Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

ExactTextMatching reports a match for an empty or whitespace-only target

オープン 初心者向け
#2,881 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
91/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
python
領域
security, testing

調査の方向性

pyrit/analytics/text_matching.py の ExactTextMatching.is_match() から始め、tests/unit/analytics/test_text_matching.py にある既存の test_target_too_short のカバレッジと比較します。空の target と空白のみの target のカバレッジを追加し、空でない target のマッチングを維持したうえで、対象を絞った text-matching テストを実行します。空の target がマッチしなくなり、既存の動作が維持されていれば完了です。

索引モデルが issue の本文から書いたものです。

説明

Describe the bug

ExactTextMatching.is_match() guards an empty text (if not text: return False) but not an empty target, and "" in anything is True in Python. With the default ignore_whitespace=True the check is reachable with a whitespace-only target too, because target.strip() turns it into "".

Its sibling in the same module, ApproximateTextMatching, has the opposite behaviour and says why:

if len(target) < self._n:
    return 0.0  # Confidence is too low for short targets

That rule is pinned by tests/unit/analytics/test_text_matching.py::test_target_too_short. So the two implementations of the same TextMatching interface disagree on a degenerate target.

This matters beyond the helper: DecodingScorer defaults to ExactTextMatching(case_sensitive=False) and calls it with no guard on user_piece.original_value and user_piece.converted_value — while guarding the adjacent decoded_text on the very next lines with if decoded_text and .... MessagePiece.converted_value defaults to "", so when no converter ran, the converted_value check matches every response and the scorer reports a successful decoding.

Steps/Code to Reproduce
from pyrit.analytics import ApproximateTextMatching, ExactTextMatching

print(ExactTextMatching().is_match(target="", text="I refuse to help with that."))
print(ExactTextMatching().is_match(target="   \n ", text="I refuse to help with that."))
print(ExactTextMatching(case_sensitive=True).is_match(target="", text="anything"))
print(ExactTextMatching(ignore_whitespace=False).is_match(target="", text="hello"))
print(ApproximateTextMatching().is_match(target="", text="hello world"))  # sibling
Expected Results

The first four should be False: a target that carries no content cannot be found in the text. The sibling already returns False. is_match(target="refuse", text="I refuse to help") should stay True.

Actual Results
True
True
True
True
False
Screenshots

Not applicable.

Versions
  • OS: macOS
  • Python version: 3.11
  • PyRIT version: installed from main in editable mode (pyrit/analytics/text_matching.py)
  • Existing coverage: tests/unit/analytics/test_text_matching.py::test_empty_text covers an empty text only; no test covers an empty target.
Proposed direction

I would add the symmetric guard to ExactTextMatching.is_match — return False when the (whitespace-normalised) target is empty — and a test mirroring test_target_too_short. That keeps the fix in the shared abstraction, so DecodingScorer and any other caller are covered without touching them. Happy to send a PR if that matches your intent; I am also happy to guard the two call sites in DecodingScorer instead if you prefer the narrower change.

主要言語
Python
スター
4.5k
フォーク
896
平均マージ
2日 19時間
マージ済み PR(30日)
206

環境構築

このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

microsoft/PyRIT のほかの issue

microsoft/PyRIT の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。