Repository navigation
fix(lean-archive,#codeql): run_lean9_demos.py syntax + update_demos_v2.py ReDoS - #16182
Conversation
…2.py ReDoS Two fixes in MyIA.AI.Notebooks/SymbolicAI/Lean/scripts/_archive/: 1. run_lean9_demos.py: corrupted merge artefact at lines 510-544. The original DEMOS=[...] block (4 demos, lines 466-509) was followed by "],\," (parasitic comma), three orphan dict fragments (complexity, strategy, },), and a duplicate second block of 4 demos (514-544) with its own closing "]\". The main loop iterates enumerate(DEMOS, 1) with "/4" formatter, so the canonical block is the original 4. py_compile fails with IndentationError line 511. Fix: replace line 510 "],\" with "]" and delete lines 511-544 inclusive. -34 lines. py_compile OK. 2. update_demos_v2.py: CodeQL flags py/redos (alerts #88 line 86, #89 line 106) on the regex r"(DEMOS\s*=\s*\[[^\]]*(?:\{[^}]*\}[^\]]*)*\])" the inner (?:\{[^}]*\}[^\]]*)* can match each iteration in two ambiguous ways (empty via [^\]]* OR via the group), leading to exponential backtracking on inputs with many "{}{}" sequences. Fix: rewrite to r"(DEMOS\s*=\s*\[(?:[^\[\]]*\{[^}]*\})*[^\[\]]*\])" which uses a single character class [^\[\]]* that excludes BOTH [ and ], eliminating the ambiguity. py_compile OK; regex still matches the canonical 2-demo block (verified on synthetic input). Both files are in _archive/ (not in production). CodeQL alerts #88, #89 will need to be dismissed via CodeQL UI after the PR merges. Co-Authored-By: Claude Haiku 4.5 (1M context) <noreply@anthropic.com>
Replaces app.run(debug=True) with an env-driven flag (FLASK_DEBUG, default False). CodeQL flagged py/flask-debug at line 286 as a security risk: debug=True exposes the Werkzeug debugger console which allows arbitrary code execution via the browser. Local dev can still opt-in with FLASK_DEBUG=true. Same pattern as the existing ENABLE_PERFORMANCE_LOGS env var (line 39). Co-Authored-By: Claude Haiku 4.5 (1M context) <noreply@anthropic.com>
|
Trivial-diff advisory (#15740, non bloquant). |
Path-collision (organ #13359/#13615)Cette PR #16182 (
|
… bracket counter The previous 'ReDoS fix' (commit 4310914) was incorrect: it rewrote [^\]]*(?:\{[^}]*\}[^\]]*)*[^\]]* into (?:[^\[\]]*\{[^}]*\})*[^\[\]]* — still nested quantifiers with overlapping character classes, still flagged by CodeQL py/redos on input starting with 'DEMOS=[' followed by many '{{'. This commit replaces the regex with a single-pass bracket counter (_match_demos_block): depth tracking over [ and ], no backtracking, O(n). Three tests pass: 1. Normal DEMOS = [ { ... }, { ... } ] block 2. ReDoS attack input (50 nested braces) — no exponential time 3. Nested brackets inside demo JSON — correctly finds closing ] Resolves CodeQL alerts #129, #130 (Inefficient regular expression).
|
[G-VAR-3 OVERRIDE] lane myia-po-2027:CoursIA-2 -- next: notebook-python #16136 Candidate tenue plus de 24 h. Le picker de la lane impose la réparation de ses PRs existantes et nomme #16136 ; lecture complète effectuée : le notebook SemanticWeb est bien un grain de contenu, le correctif de syntaxe est poussé, mais les deux levées B.0 restent à obtenir avant admission. Cet override ne verdit pas #16182 : CI latest-wins et lecture finale restent dues. |
|
G-VAR-2 light cap reached (advisory, non bloquant). |
Grain: LIGHT/guard — lane myia-po-2027:CoursIA-2 — prev: DEEP/notebook-python #16136
fix(lean-archive,#codeql): run_lean9_demos.py syntax + update_demos_v2.py ReDoS
Résumé
Deux corrections dans
MyIA.AI.Notebooks/SymbolicAI/Lean/scripts/_archive/(chemin archivé) :run_lean9_demos.py:IndentationErrorligne 511 causé par un merge cassé. Le blocDEMOS = [...]original (4 démos, lignes 466-509) était suivi de :],(virgule parasite)complexity,strategy,},)]ligne 544, jamais assigné ni itéréLa boucle principale (
enumerate(DEMOS, 1)) affiche/4, donc le bloc canonique est l'original à 4 démos. Fix : ligne 510 devient](suppression de la virgule parasite) + suppression lignes 511-544. −34 lignes.py_compileOK.update_demos_v2.py: CodeQLpy/redos(alertes fix(genai): resolve Path import and GENAI_ROOT issues in Image notebooks #88 ligne 86, fix(genai): Audio TTS notebook OPENAI_DIRECT_API_KEY + other GenAI fixes #89 ligne 106). La première correction par regex au commit4310914426conservait des quantificateurs imbriqués et a été justement re-signalée. Le head exactf1b1803126remplace donc les deux callsites par un helper unique_match_demos_block: recherche de l'ouvertureDEMOS = [puis compteur de crochets mono-passe, profondeur décrémentée jusqu'au]fermant. Complexité O(n), aucun état de backtracking. +33 / −8 lignes ;py_compileOK ; entrée d'attaqueDEMOS=[{{{{...×50testée sans croissance exponentielle.cross-series/matching-cv/main.py: le commit intermédiaire rendFLASK_DEBUGpiloté par l'environnement, défaut désormais livré byte-identique par fix(matching-cv,#codeql): env-driven FLASK_DEBUG default False #16183 (mergée). Le blob du head est identique àmain: convergence propre, aucun delta effectif au merge.Preuves vérifiables
py_compile.compile(NB, doraise=True)git diff --statau headmaincourantmatching-cv/main.pydéjà byte-identique via #16183Périmètre CodeQL
Cette PR adresse les erreurs CodeQL #88 + #89 (py/redos sur
update_demos_v2.py). Les alertes seront auto-resolues au merge par GitHub (analyse incrémentale).Restent autres findings CodeQL non-addressés ici (split par domaine, PRs séparées) :
py/flask-debugEmail Jared Broad: finaliser le brouillon et envoyer #31MyIA.AI.Notebooks/cross-series/matching-cv/main.py:286→ PR2 (cross-series)py/clear-text-storage-sensitive-dataEPITA IA Symbolique (20 mai): Finalisation serie complete #55scripts/genai-stack/core/auth_manager.py:256→ FAUX POSITIF :.envest gitignored (secrets-hygiene rule 1) → dismiss via UI après PR3 ou commentaire sur l'alertepy/clear-text-*archivés (8 alertes dans_archive/oudocs/archive/) → dismiss via UI (won't fix - archived)Acceptance
py_compileOK sur les 2 fichiersenumerate(DEMOS, 1)avec/4correspond au tableau final (4 entrées)Diff au head exact
Le troisième fichier est déjà byte-identique à
maindepuis #16183 : il disparaît du delta effectif de merge. Exception seulement résidu final mesuré (#15719/#15740) : les deux alertes ReDoS sont les deux callsites du même helper archivé et le défaut syntaxique est l'unique blocDEMOScassé ; aucune douzaine d'instances homogènes n'existe à grouper.🤖 Generated with Claude Code