mimosa 1.0.3: guard shapes not credited by taint analysis (5 reproducible defects) + request incremental git-gate
Maintainer thường phản hồi trong vòng 3 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 30/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- git, node.js, python, typescript
Hướng nghiên cứu
Start by reviewing the five reproductions and the requested sanitizer patterns, then inspect mimosa_triage.json and the .mimosa/history stop-hook records. The scope spans taint recognition, git-tree selection, staged-diff scanning, timeout handling, and seeded-simulation exceptions. Done means the upstream report is submitted, its tracking id is recorded, and the requested behavior is addressed or clearly tracked.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Mimosa upstream feedback draft (M1)
Status: drafted, pending submission. Once submitted, put the tracking id into
mimosa_triage.json → upstream.tracking.
Environment
- Plugin: mimosa@zcode-plugins-official 1.0.3
- Workload: monorepo with a live trading system (~370 source files, py/ts)
- Baseline seals:
scan-2026-09-28T04-25-50.259Z-22d8d1a1af55(62 findings),
scan-2026-09-28T04-39-14.508Z-223908513145(32 findings post-fix)
Five reproducible defects / gaps
-
Sink-wrapped guard not credited.
chainlink_poll.pyalready called
guard_url(url)at URL construction (landed in a reviewed commit); its
urlopenkept being flagged. Movingguard_url(...)inline into the
Request(...)constructor at the sink statement still does not clear the
finding. Expected: a call to a guard function wrapping the URL argument at
or near the sink should satisfy the SSRF rule (scheme+host+resolved-IP are
all enforced by the guard). -
Same-shaped fix clears one file but not another. A function-entry
urlsplitscheme+hostname allowlist clearedpmracer/pmracer/history.py
andpmracer/scripts/probe_sources.pybut not
pmracer/scripts/backfill_candles_35d.py(byte-for-byte same shape).
Suggest a documented, deterministic recognition contract for guard shapes. -
Helper-mediated guards are opaque.
_safe_join()(containment via
os.path.realpath+commonpath) results still get flagged at every
downstreamopen(). Same for cross-moduleguard_url. Expected: local or
cross-file sanitizer functions be recognized (even via an explicit
allowlist of guard function names configured per project). -
Git gate scans the wrong tree. Committing in
C:\repo-devwhile the
ZCode workspace isC:\repomade the L3 gate report findings with
C:\repo\...paths (stale live tree), blocking every dev-tree commit until
a subprocess bypass was used. Expected: resolve the tree from the git
command itself (-C,cdchains) or the tool payload cwd, and scan only
the committing tree; ideally scan only the commit's staged diff
(focusFiles) instead of the whole project. -
Scan runs are frequently
inconclusivevia node spawnSync ETIMEDOUT.
Five consecutive stop-hook runs in.mimosa/historyareinconclusive
withspawnSync <node.exe> ETIMEDOUTon core files (tail_engine,
shadow_engine, accounts). Expected: configurable timeout, retry, and an
explicit verdictEffect policy when the scanner times out.
Requested sanitizer recognition (would clear our remaining 23 high)
| Pattern id | Shape | Files |
|---|---|---|
| sink-inline-guard | urlopen(Request(guard_url(url), ...)) |
planb feeds/ledger/truth/tail_engine/context (7 sites) |
| entry-allowlist | urlsplit scheme+host allowlist at helper entry |
backfill, datastreams probe, price_history |
| inline-dotdot | explicit '..' in path.parts (or string split) before open() |
identity, calibration, counter_report, segment_analysis_v2 |
| safe-join-inline-dotdot | _safe_join() + re-stated inline check at sink |
regime_lab, segment_analysis |
The seeded-randomness rule also fires on random.Random(seed) used for
statistical simulation (bootstrap / CRN Monte-Carlo); those sites cannot move
to secrets without breaking reproducibility. A project-level rule tweak or
a # mimosa: seeded-simulation annotation contract would help.
- Ngôn ngữ chính
- Python
- Star
- 73
- Fork
- 46
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của zai-org/zcode-plugins
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
zai-org/zcode-plugins#14 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 45/100
zai-org/zcode-plugins#58 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
zai-org/zcode-plugins#57 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
zai-org/zcode-plugins#54 ·
Maintainer thường phản hồi trong vòng 3 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 15/100
zai-org/zcode-plugins#53 ·
Maintainer thường phản hồi trong vòng 3 ngày
Tất cả issue của zai-org/zcode-plugins
Issue tương tự
-
[Bug] @deck.gl/arcgis dist import resolves to unpublished @deck.gl/core source path (9.3.11, 9.4.0)Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
workflow: a tick's dispatch counts as 'only this step', and no review self-grants a round unattendedĐang mởworkflow
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
kristofdegrave/homeassistant-smart-charging#1505 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
New Submission: TropWATERĐang mởmetadata submission
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
-
Wrongly named dashboard variableĐang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
canonical/content-cache-operator#163 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[submission]Đang mởsubmission
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 65/100
leanprover/lean-eval-submissions#1852 ·
Maintainer thường phản hồi trong vòng 1 ngày