Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

mimosa 写入门禁误报:零输入静态 SQL 的 QueryRow 形态被判注入硬拒,且该类 finding 无法铸 exclusion 锚

Đang mở
#59 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 3 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
38/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
go, sql
Lĩnh vực
security, tooling

Hướng nghiên cứu

Reproduce the report with internal/data/migrate_test.go and inspect the security_scan deep output, findings.json, hook-state findingEvents, and the README-referenced CLI behavior. Compare the QueryRow static SQL finding with the exclusion identity.anchor and line_hash paths. Done means the false positive is handled or a usable exclusion anchor is emitted and verified against the listed test case.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

环境

  • ZCode Desktop 3.14.3(Windows)+ WSL 项目;插件 mimosa 1.0.3;MIMOSA_HOOK_BLOCK 默认 graded
  • 宿主语言 Go;被拦文件为集成测试 internal/data/migrate_test.go(TimescaleDB 测试夹具)

现象:静态字面量 SQL 的测试代码被判「高危 · SQL 注入」硬拒

PreToolUse 门禁将候选 diff 区域内的如下既有代码判为高危注入并 deny:

if err := st.Pool().QueryRow(ctx, `SELECT count(*) FROM metrics`).Scan(&rows); err != nil {
  • 该形态零用户输入(静态字面量、测试夹具);同文件新增的静态 INSERT 字面量全部判净放行——仅 QueryRow(ctx, \SQL`)` 形态命中
  • 门禁按候选 diff 区域判定:只要一次编辑的 old_string 覆盖到含此形态的既有行(哪怕实际改动与 SQL 无关),整个写入被硬拒。项目里既有测试大量含此形态,导致这些文件事实上不可编辑,只能靠收窄编辑锚点绕行

工具面缺口(误报无法自救)

  1. exclusion 锚只能用深扫 findings.json 的 identity.anchor,但 security_scan(deep,含 focusFiles 指向该文件)不产出任何 *_test.go finding——门禁误报无锚可铸
  2. hook-state findingEvents 的 line_hash 与 exclusion anchor 派生不同源。同一 finding 实证:line_hash e75974d4… ≠ anchor 64a7244…(deploy.go 命令注入)。用 line_hash 铸 exclusion 条目无效(已实测,仍拦)
  3. README 提及的 mimosa scan <file> 单文件 CLI 未随插件分发(PATH 与 ~/.zcode/mimosa-zcode/ 均无),无第三条铸锚路径

期望

  • 静态字面量 SQL(尤其测试文件)不判注入
  • 或:门禁拦截输出 / hook-state 附带可铸的 identity.anchor;或 exclusions 支持 line_hash / file+line 形态

附带观察(可能属宿主而非插件,供参考)

Windows 桌面启动 + WSL 项目形态下 MIMOSA_HOOK_BLOCK 传值不达:registry 用户级配置正确、宿主完整重启后,WSLENV 名单到达 WSL 侧 server 进程而变量值未达,ask 模式无法启用(该形态下 zcode-server 经 /init 直拉、不加载 shell rc,WSLENV 是唯一通道)。

Ngôn ngữ chính
Python
Star
73
Fork
46
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của zai-org/zcode-plugins

Tất cả issue của zai-org/zcode-plugins

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.