fix: detect operator archive Python execution paths - #1538
Conversation
…chive-python-operator-detector
Performance BenchmarksCompared
|
Detect itemgetter, multi-accessor selection, mapping defaults, literal and assigned containers, and preserve benign accessor behavior.
|
Critical review fixes pushed in Addressed false negatives for literal Focused validation only, per review policy:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 06852a75e3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
I completed a critical review and prepared local commit The local fix addresses all four open review findings:
The review also found and fixed additional false negatives and false positives around Validation on the exact local commit:
Only |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e70b3870b2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex Please apply the completed review fix from local commit Files:
Required changes:
Local commits: Validation after merging main:
All five unresolved review threads have commit-specific replies. Please publish the implementation before resolving them. |
|
Summary
Committed changes as Testing
|
|
@codex address that feedback Local repair handoff for the five unresolved review threads is commit The patch:
Validation: |
|
Summary
Committed the changes as Testing
|
|
Published the fully reviewed repair as |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 227e856603
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "append": {2}, | ||
| "get": {2, 3}, | ||
| "insert": {3}, | ||
| "pop": {1, 2, 3}, |
There was a problem hiding this comment.
Handle no-arg methodcaller pop
For methodcaller('pop') with no pop argument, this leaves lookup_name empty, so list pop() (last item) is never resolved; payload=[print, os.system]; operator.methodcaller('pop')(payload)('id') runs without S101. Keep this malicious path covered per guidance.
Useful? React with 👍 / 👎.
| if not isinstance(value_node, ast.Dict): | ||
| return None |
There was a problem hiding this comment.
Expand tracked dicts in literal unpacking
For {**updates} where updates is a tracked static dict, this returns None rather than expanding the alias, so operator.itemgetter('run')({**updates})('id') misses os.system even though update(**updates) is modeled. Fresh evidence: this direct unpack path. guidance.
Useful? React with 👍 / 👎.
| if isinstance(target_element, ast.Name): | ||
| self._bind_name(target_element.id, resolved_names) | ||
| else: | ||
| self._shadow_binding_target(target_element) |
There was a problem hiding this comment.
Preserve starred accessor unpacking
When a multi-result accessor is unpacked into a starred target, this shadows the star capture instead of binding the slice, so _, *rest = operator.attrgetter('getcwd','system')(os); rest[0]('id') executes os.system without S101. Fresh evidence: starred destructuring. guidance.
Useful? React with 👍 / 👎.
Summary
methodcallerwriters, and literal/tracked mapping expansion.Validation
227e8566038cc1408dc4ac8bceca65aa9674f3e3PROMPTFOO_DISABLE_TELEMETRY=1 uv run --frozen pytest -q tests/scanners/test_zip_scanner.py: 829 passed, 4 optional ONNX skipsgit diff --check: clean