Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

mimosa 1.0.3: guard shapes not credited by taint analysis (5 reproducible defects) + request incremental git-gate

Đang mở
#52 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 3 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
30/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
git, node.js, python, typescript
Lĩnh vực
devtools, security, tooling

Hướng nghiên cứu

Start by reviewing the five reproductions and the requested sanitizer patterns, then inspect mimosa_triage.json and the .mimosa/history stop-hook records. The scope spans taint recognition, git-tree selection, staged-diff scanning, timeout handling, and seeded-simulation exceptions. Done means the upstream report is submitted, its tracking id is recorded, and the requested behavior is addressed or clearly tracked.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Mimosa upstream feedback draft (M1)

Status: drafted, pending submission. Once submitted, put the tracking id into
mimosa_triage.json → upstream.tracking.

Environment

  • Plugin: mimosa@zcode-plugins-official 1.0.3
  • Workload: monorepo with a live trading system (~370 source files, py/ts)
  • Baseline seals: scan-2026-09-28T04-25-50.259Z-22d8d1a1af55 (62 findings),
    scan-2026-09-28T04-39-14.508Z-223908513145 (32 findings post-fix)

Five reproducible defects / gaps

  1. Sink-wrapped guard not credited. chainlink_poll.py already called
    guard_url(url) at URL construction (landed in a reviewed commit); its
    urlopen kept being flagged. Moving guard_url(...) inline into the
    Request(...) constructor at the sink statement still does not clear the
    finding. Expected: a call to a guard function wrapping the URL argument at
    or near the sink should satisfy the SSRF rule (scheme+host+resolved-IP are
    all enforced by the guard).

  2. Same-shaped fix clears one file but not another. A function-entry
    urlsplit scheme+hostname allowlist cleared pmracer/pmracer/history.py
    and pmracer/scripts/probe_sources.py but not
    pmracer/scripts/backfill_candles_35d.py (byte-for-byte same shape).
    Suggest a documented, deterministic recognition contract for guard shapes.

  3. Helper-mediated guards are opaque. _safe_join() (containment via
    os.path.realpath + commonpath) results still get flagged at every
    downstream open(). Same for cross-module guard_url. Expected: local or
    cross-file sanitizer functions be recognized (even via an explicit
    allowlist of guard function names configured per project).

  4. Git gate scans the wrong tree. Committing in C:\repo-dev while the
    ZCode workspace is C:\repo made the L3 gate report findings with
    C:\repo\... paths (stale live tree), blocking every dev-tree commit until
    a subprocess bypass was used. Expected: resolve the tree from the git
    command itself (-C, cd chains) or the tool payload cwd, and scan only
    the committing tree; ideally scan only the commit's staged diff
    (focusFiles) instead of the whole project.

  5. Scan runs are frequently inconclusive via node spawnSync ETIMEDOUT.
    Five consecutive stop-hook runs in .mimosa/history are inconclusive
    with spawnSync <node.exe> ETIMEDOUT on core files (tail_engine,
    shadow_engine, accounts). Expected: configurable timeout, retry, and an
    explicit verdictEffect policy when the scanner times out.

Requested sanitizer recognition (would clear our remaining 23 high)

Pattern id Shape Files
sink-inline-guard urlopen(Request(guard_url(url), ...)) planb feeds/ledger/truth/tail_engine/context (7 sites)
entry-allowlist urlsplit scheme+host allowlist at helper entry backfill, datastreams probe, price_history
inline-dotdot explicit '..' in path.parts (or string split) before open() identity, calibration, counter_report, segment_analysis_v2
safe-join-inline-dotdot _safe_join() + re-stated inline check at sink regime_lab, segment_analysis

The seeded-randomness rule also fires on random.Random(seed) used for
statistical simulation (bootstrap / CRN Monte-Carlo); those sites cannot move
to secrets without breaking reproducibility. A project-level rule tweak or
a # mimosa: seeded-simulation annotation contract would help.

Ngôn ngữ chính
Python
Star
73
Fork
46
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của zai-org/zcode-plugins

Tất cả issue của zai-org/zcode-plugins

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.