Skip to content

fix(lean-archive,#codeql): run_lean9_demos.py syntax + update_demos_v2.py ReDoS - #16182

Merged
myia-ai-01 merged 3 commits into
mainfrom
feature/codeql-errors-critical
Sep 16, 2026
Merged

myia-ai-01 merged 3 commits into
mainfrom
feature/codeql-errors-critical

Conversation

@jsboige

@jsboige jsboige commented Sep 14, 2026 •

Copy link
Copy Markdown
Owner

Grain: LIGHT/guard — lane myia-po-2027:CoursIA-2 — prev: DEEP/notebook-python #16136

fix(lean-archive,#codeql): run_lean9_demos.py syntax + update_demos_v2.py ReDoS

Résumé

Deux corrections dans MyIA.AI.Notebooks/SymbolicAI/Lean/scripts/_archive/ (chemin archivé) :

  1. run_lean9_demos.py : IndentationError ligne 511 causé par un merge cassé. Le bloc DEMOS = [...] original (4 démos, lignes 466-509) était suivi de :

    • ligne 510 : ], (virgule parasite)
    • lignes 511-513 : fragments de dict orphelins (complexity, strategy, },)
    • lignes 514-544 : un second bloc dupliqué de 4 démos avec son propre ] ligne 544, jamais assigné ni itéré

    La boucle principale (enumerate(DEMOS, 1)) affiche /4, donc le bloc canonique est l'original à 4 démos. Fix : ligne 510 devient ] (suppression de la virgule parasite) + suppression lignes 511-544. −34 lignes. py_compile OK.

  2. update_demos_v2.py : CodeQL py/redos (alertes fix(genai): resolve Path import and GENAI_ROOT issues in Image notebooks #88 ligne 86, fix(genai): Audio TTS notebook OPENAI_DIRECT_API_KEY + other GenAI fixes #89 ligne 106). La première correction par regex au commit 4310914426 conservait des quantificateurs imbriqués et a été justement re-signalée. Le head exact f1b1803126 remplace donc les deux callsites par un helper unique _match_demos_block : recherche de l'ouverture DEMOS = [ puis compteur de crochets mono-passe, profondeur décrémentée jusqu'au ] fermant. Complexité O(n), aucun état de backtracking. +33 / −8 lignes ; py_compile OK ; entrée d'attaque DEMOS=[{{{{...×50 testée sans croissance exponentielle.

  3. cross-series/matching-cv/main.py : le commit intermédiaire rend FLASK_DEBUG piloté par l'environnement, défaut désormais livré byte-identique par fix(matching-cv,#codeql): env-driven FLASK_DEBUG default False #16183 (mergée). Le blob du head est identique à main : convergence propre, aucun delta effectif au merge.

Preuves vérifiables

# Critère Résultat
1 py_compile.compile(NB, doraise=True) OK sur les 2 scripts archivés
2 ReDoS helper mono-passe O(n), entrée d'attaque sans backtracking
3 git diff --stat au head 3 files, +35 / −43
4 Delta effectif vs main courant 2 scripts archivés ; matching-cv/main.py déjà byte-identique via #16183
5 Pre-commit hooks tous PASS

Périmètre CodeQL

Cette PR adresse les erreurs CodeQL #88 + #89 (py/redos sur update_demos_v2.py). Les alertes seront auto-resolues au merge par GitHub (analyse incrémentale).

Restent autres findings CodeQL non-addressés ici (split par domaine, PRs séparées) :

  • py/flask-debug Email Jared Broad: finaliser le brouillon et envoyer #31 MyIA.AI.Notebooks/cross-series/matching-cv/main.py:286 → PR2 (cross-series)
  • py/clear-text-storage-sensitive-data EPITA IA Symbolique (20 mai): Finalisation serie complete #55 scripts/genai-stack/core/auth_manager.py:256 → FAUX POSITIF : .env est gitignored (secrets-hygiene rule 1) → dismiss via UI après PR3 ou commentaire sur l'alerte
  • py/clear-text-* archivés (8 alertes dans _archive/ ou docs/archive/) → dismiss via UI (won't fix - archived)
  • 6 warnings divers → à traiter dans des PRs séparées si nécessaire

Acceptance

  • py_compile OK sur les 2 fichiers
  • Regex fixée et testée
  • Boucle enumerate(DEMOS, 1) avec /4 correspond au tableau final (4 entrées)

Diff au head exact

MyIA.AI.Notebooks/SymbolicAI/Lean/scripts/_archive/run_lean9_demos.py | 34 deletions
MyIA.AI.Notebooks/SymbolicAI/Lean/scripts/_archive/update_demos_v2.py | 33 insertions, 8 deletions
MyIA.AI.Notebooks/cross-series/matching-cv/main.py                    | 2 insertions, 1 deletion
3 files changed, 35 insertions(+), 43 deletions(-)

Le troisième fichier est déjà byte-identique à main depuis #16183 : il disparaît du delta effectif de merge. Exception seulement résidu final mesuré (#15719/#15740) : les deux alertes ReDoS sont les deux callsites du même helper archivé et le défaut syntaxique est l'unique bloc DEMOS cassé ; aucune douzaine d'instances homogènes n'existe à grouper.

🤖 Generated with Claude Code

myia-po-2027 and others added 2 commits September 14, 2026 18:17
…2.py ReDoS

Two fixes in MyIA.AI.Notebooks/SymbolicAI/Lean/scripts/_archive/:

1. run_lean9_demos.py: corrupted merge artefact at lines 510-544. The
   original DEMOS=[...] block (4 demos, lines 466-509) was followed by
   "],\," (parasitic comma), three orphan dict fragments (complexity,
   strategy, },), and a duplicate second block of 4 demos (514-544) with
   its own closing "]\". The main loop iterates enumerate(DEMOS, 1) with
   "/4" formatter, so the canonical block is the original 4. py_compile
   fails with IndentationError line 511. Fix: replace line 510 "],\" with
   "]" and delete lines 511-544 inclusive. -34 lines. py_compile OK.

2. update_demos_v2.py: CodeQL flags py/redos (alerts #88 line 86, #89
   line 106) on the regex
   r"(DEMOS\s*=\s*\[[^\]]*(?:\{[^}]*\}[^\]]*)*\])"
   the inner (?:\{[^}]*\}[^\]]*)* can match each iteration in two
   ambiguous ways (empty via [^\]]* OR via the group), leading to
   exponential backtracking on inputs with many "{}{}" sequences.
   Fix: rewrite to
   r"(DEMOS\s*=\s*\[(?:[^\[\]]*\{[^}]*\})*[^\[\]]*\])"
   which uses a single character class [^\[\]]* that excludes BOTH [ and
   ], eliminating the ambiguity. py_compile OK; regex still matches the
   canonical 2-demo block (verified on synthetic input).

Both files are in _archive/ (not in production). CodeQL alerts #88, #89
will need to be dismissed via CodeQL UI after the PR merges.

Co-Authored-By: Claude Haiku 4.5 (1M context) <noreply@anthropic.com>
Replaces app.run(debug=True) with an env-driven flag (FLASK_DEBUG,
default False). CodeQL flagged py/flask-debug at line 286 as a security
risk: debug=True exposes the Werkzeug debugger console which allows
arbitrary code execution via the browser.

Local dev can still opt-in with FLASK_DEBUG=true. Same pattern as the
existing ENABLE_PERFORMANCE_LOGS env var (line 39).

Co-Authored-By: Claude Haiku 4.5 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added the trivial-diff-advisory Diff trivial : grain META mecanique sans fournee ni exception ecrite (#15740) label Sep 14, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Trivial-diff advisory (#15740, non bloquant).
genre guard dans la famille META (docs/guard/ledger/readme/test) + diff de 38 lignes changees (<= 100) + aucune exception ecrite dans le body : le litmus de la trivialite (une douzaine d'instances scannees a la suite) est credible. Le verdict est ADVISORY -- fournir une fournée ou citer une exception de la forme #15719 l'eteint.
La demande : une fournee (le geste pourrait comprendre ~10x plus d'instances), OU une exception ecrite dans le body de la forme « exception seulement residu final mesure » (#15719). Editer le body re-deroule cet organe et retire le label.

@github-actions

github-actions Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Path-collision (organ #13359/#13615)

Cette PR #16182 (fix(lean-archive,#codeql): run_lean9_demos.py syntax + update_demos_v2.py ReDoS) touche au moins un chemin de fichier aussi modifie par d'autres PRs ouvertes. Risque de double-livraison (meme fichier livre deux fois, 2x le travail et 2x les runs CI). Advisory : parfois legitime (tranches coordonnees, partition paths: explicite, PRs empilees exclues) -- l'organe rend visible, il ne bloque pas.

… bracket counter

The previous 'ReDoS fix' (commit 4310914) was incorrect: it rewrote
[^\]]*(?:\{[^}]*\}[^\]]*)*[^\]]* into (?:[^\[\]]*\{[^}]*\})*[^\[\]]* — still
nested quantifiers with overlapping character classes, still flagged by
CodeQL py/redos on input starting with 'DEMOS=[' followed by many '{{'.

This commit replaces the regex with a single-pass bracket counter
(_match_demos_block): depth tracking over [ and ], no backtracking,
O(n). Three tests pass:
1. Normal DEMOS = [ { ... }, { ... } ] block
2. ReDoS attack input (50 nested braces) — no exponential time
3. Nested brackets inside demo JSON — correctly finds closing ]

Resolves CodeQL alerts #129, #130 (Inefficient regular expression).
@myia-ai-01

Copy link
Copy Markdown
Collaborator

[G-VAR-3 OVERRIDE] lane myia-po-2027:CoursIA-2 -- next: notebook-python #16136

Candidate tenue plus de 24 h. Le picker de la lane impose la réparation de ses PRs existantes et nomme #16136 ; lecture complète effectuée : le notebook SemanticWeb est bien un grain de contenu, le correctif de syntaxe est poussé, mais les deux levées B.0 restent à obtenir avant admission. Cet override ne verdit pas #16182 : CI latest-wins et lecture finale restent dues.

@github-actions github-actions Bot added the variation-light-cap-reached Lane ayant deja merge une LIGHT aujourd'hui (cap G-VAR-2 atteint) label Sep 16, 2026
@github-actions

Copy link
Copy Markdown
Contributor

G-VAR-2 light cap reached (advisory, non bloquant).
La lane myia-po-2027:CoursIA-2 a deja consomme son budget LIGHT du jour (#16183 (merge a 2026-09-16T12:48:44Z)).
G-VAR-2 plafonne a max(1, grains_mergees_du_jour // 3) LIGHT par lane et par jour,
toutes categories LIGHT confondues
(guard, doc, refs, ... partagent un seul budget) :
c'est un RATIO, pas un plafond plat. La decision de merge reste au coordinateur.

@github-actions github-actions Bot added variation-adjacency-deep-med Adjacence DEEP/MED hors LIGHT : §2 l'autorise si substance distincte (coordinateur) and removed trivial-diff-advisory Diff trivial : grain META mecanique sans fournee ni exception ecrite (#15740) labels Sep 16, 2026
@myia-ai-01
myia-ai-01 merged commit 49e1881 into main Sep 16, 2026
21 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

variation-adjacency-deep-med Adjacence DEEP/MED hors LIGHT : §2 l'autorise si substance distincte (coordinateur) variation-light-cap-reached Lane ayant deja merge une LIGHT aujourd'hui (cap G-VAR-2 atteint)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants