Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

ExactTextMatching reports a match for an empty or whitespace-only target

Đang mở Phù hợp với người mới
#2,881 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
91/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
python
Lĩnh vực
security, testing

Hướng nghiên cứu

Bắt đầu trong pyrit/analytics/text_matching.py tại ExactTextMatching.is_match(), sau đó so sánh với phần coverage hiện có của test_target_too_short trong tests/unit/analytics/test_text_matching.py. Bổ sung coverage cho các target rỗng và chỉ chứa khoảng trắng, đồng thời giữ nguyên việc matching đối với các target không rỗng, rồi chạy các test text-matching tập trung. Được xem là hoàn tất khi các target rỗng không còn match và hành vi hiện có vẫn được giữ nguyên.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Describe the bug

ExactTextMatching.is_match() guards an empty text (if not text: return False) but not an empty target, and "" in anything is True in Python. With the default ignore_whitespace=True the check is reachable with a whitespace-only target too, because target.strip() turns it into "".

Its sibling in the same module, ApproximateTextMatching, has the opposite behaviour and says why:

if len(target) < self._n:
    return 0.0  # Confidence is too low for short targets

That rule is pinned by tests/unit/analytics/test_text_matching.py::test_target_too_short. So the two implementations of the same TextMatching interface disagree on a degenerate target.

This matters beyond the helper: DecodingScorer defaults to ExactTextMatching(case_sensitive=False) and calls it with no guard on user_piece.original_value and user_piece.converted_value — while guarding the adjacent decoded_text on the very next lines with if decoded_text and .... MessagePiece.converted_value defaults to "", so when no converter ran, the converted_value check matches every response and the scorer reports a successful decoding.

Steps/Code to Reproduce
from pyrit.analytics import ApproximateTextMatching, ExactTextMatching

print(ExactTextMatching().is_match(target="", text="I refuse to help with that."))
print(ExactTextMatching().is_match(target="   \n ", text="I refuse to help with that."))
print(ExactTextMatching(case_sensitive=True).is_match(target="", text="anything"))
print(ExactTextMatching(ignore_whitespace=False).is_match(target="", text="hello"))
print(ApproximateTextMatching().is_match(target="", text="hello world"))  # sibling
Expected Results

The first four should be False: a target that carries no content cannot be found in the text. The sibling already returns False. is_match(target="refuse", text="I refuse to help") should stay True.

Actual Results
True
True
True
True
False
Screenshots

Not applicable.

Versions
  • OS: macOS
  • Python version: 3.11
  • PyRIT version: installed from main in editable mode (pyrit/analytics/text_matching.py)
  • Existing coverage: tests/unit/analytics/test_text_matching.py::test_empty_text covers an empty text only; no test covers an empty target.
Proposed direction

I would add the symmetric guard to ExactTextMatching.is_match — return False when the (whitespace-normalised) target is empty — and a test mirroring test_target_too_short. That keeps the fix in the shared abstraction, so DecodingScorer and any other caller are covered without touching them. Happy to send a PR if that matches your intent; I am also happy to guard the two call sites in DecodingScorer instead if you prefer the narrower change.

Ngôn ngữ chính
Python
Star
4.5k
Fork
896
Merge trung bình
2 ngày 19 giờ
Pull request đã merge (30 ngày)
206

Chuẩn bị môi trường

Chúng tôi chưa kiểm tra các tệp thiết lập môi trường của dự án này. Hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của microsoft/PyRIT

Tất cả issue của microsoft/PyRIT

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.