Skip to content

fix: distinguish urllib parsing from network access - #812

Open
sholmes222 wants to merge 1 commit into
NVIDIA:mainfrom
sholmes222:fix/lp1-urllib-parse
Open

sholmes222 wants to merge 1 commit into
NVIDIA:mainfrom
sholmes222:fix/lp1-urllib-parse

Conversation

@sholmes222

@sholmes222 sholmes222 commented Oct 9, 2026 •

Copy link
Copy Markdown

Why

LP1 treated any urllib reference as network access. That incorrectly required a network permission for local URL parsing through urllib.parse.

What changed

  • Detect urllib.request, including from urllib import request, as network-capable.
  • Exclude urllib.parse, which only parses local strings.
  • Add regression coverage for URL parsing and both supported request import forms.

Verification

  • Focused LP1 tests cover the false positive and both request import forms.
  • DCO is present on the signed commit.
  • CI is running for the current head.

@sholmes222
sholmes222 force-pushed the fix/lp1-urllib-parse branch from 0ce3e8f to fc13fe3 Compare October 9, 2026 13:17
Keep urllib.request detection while excluding urllib.parse URL parsing from LP1 network capability findings.

Signed-off-by: sholmes222 <sam.holmes@control-plane.io>
@sholmes222
sholmes222 force-pushed the fix/lp1-urllib-parse branch from fc13fe3 to 74a3561 Compare October 9, 2026 15:46
@sholmes222

Copy link
Copy Markdown
Author

Self-review update for 74a3561:

  • The original narrowing correctly excluded urllib.parse, but missed from urllib import request.
  • The matcher now covers both urllib.request and the request alias import.
  • Regression coverage verifies that URL parsing does not trigger LP1 while both network-capable import forms do.

CI is running for the updated head.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant