verify(P43): code review — 1 P0 auto-fixed, 1 P1 auto-fixed, 3 P1 flagged
---ci--- phase: 43 milestone: v1.9 status: verify lessons: - P0 fix: run_platform.sh HITL gate passed approver via string interpolation into Python (GITHUB_ACTOR injection vector) — fixed by passing env vars (ACDL_HITL_*) read via os.environ - P1 fix: attestation_matrix._is_fresh accepted future-dated artifacts (negative age bypassed freshness) — fixed with negative-age guard + test - P1 flagged: WizClient._post does not check GraphQL errors (silent empty-list mask) - P1 flagged: WizClient._post no SSRF validation on WIZ_API_URL - P1 flagged: contract_resolver._load_env duplicates environment_check.load (can drift) ---/ci--- Multi-persona review of the v1.9 diff (v1.8.0..HEAD). Review pass 2 (post-complete) caught issues the initial self-review missed: P0-INJECT (auto-fixed): scripts/run_platform.sh Step 7b interpolated $APPROVER (GITHUB_ACTOR/GITEA_ACTOR) directly into a Python string literal — an attacker-controllable username containing shell/python metacharacters would execute arbitrary Python. Fixed: approver, contract id, and env are now passed as environment variables to the subprocess and read via os.environ[...] (no string interpolation). P1-FRESHNESS (auto-fixed): core/attestation_matrix.py _is_fresh accepted future-dated artifacts (negative age.days <= window_days). Fixed: added age.total_seconds() < 0 guard rejecting future timestamps. Test added: test_freshness_rejects_future_dated_artifact. 3 P1 flagged for post-hoc: - WizClient._post does not surface GraphQL errors (silent empty mask) - WizClient._post no SSRF validation on WIZ_API_URL (operator-supplied, low risk) - contract_resolver._load_env duplicates environment_check.load (drift risk) REVIEW.md updated with the findings. 494 tests pass; run_ci.sh + run_platform.sh --check-only green.
This commit is contained in:
@@ -128,6 +128,13 @@ def test_freshness_outside_window():
|
||||
assert _is_fresh(artifact, "functional_correctness") is False
|
||||
|
||||
|
||||
def test_freshness_rejects_future_dated_artifact():
|
||||
"""A future-dated artifact (negative age) must not bypass freshness (review fix)."""
|
||||
future = datetime.datetime.now(datetime.timezone.utc) + datetime.timedelta(days=100)
|
||||
artifact = {"timestamp": future.isoformat(), "type": "x", "payload": {}}
|
||||
assert _is_fresh(artifact, "operational_readiness") is False
|
||||
|
||||
|
||||
def test_freshness_days_table_has_all_concerns():
|
||||
"""The freshness table covers all operator-supplied concerns."""
|
||||
for concern in ["functional_correctness", "performance_baseline", "security_posture",
|
||||
|
||||
Reference in New Issue
Block a user