fix: bound keras zip config traversal - #1555
Conversation
Performance BenchmarksCompared
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2447f8e23b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2447f8e23b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8d6fa15c82
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8d6fa15c82
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Critical review found and fixed an additional bounded-traversal bypass beyond the existing review threads: Validation:
Shell GitHub credentials reject pushes in this environment. @codex apply/push local commits |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fe046f2191
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Completed the final critical review and published the exact validated tree at In addition to removing the unused constant from the live code-quality thread, this closes the remaining traversal gaps found during adversarial QA: downstream layer/inbound/compile consumers now receive an iterative bounded projection; independently bounded CVE detectors retain original-config boundary visibility; nested kwargs are not double-counted or recursively rescanned; admitted scalar security fields survive depth/item exhaustion; omitted fields do not create synthetic Final associated validation: 492 passed, 73 optional-dependency skips; 31 focused adversarial budget tests; Ruff, formatting, mypy, and diff checks clean. All review threads are resolved, and the remote diff is exactly the intended three files. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c0b536989a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Summary
Testing
|
|
Published final validated head Late review findings addressed:
Validation on the exact published tree:
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8ecc44aab1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| ): | ||
| break |
There was a problem hiding this comment.
Preserve security fields at item boundary
When a dict is the last item admitted by max_items, this break can fire while queuing its first scalar child, before the item-limit fallback that preserves security keys runs. That projects an already-admitted Lambda/custom layer as {}, so the scan is only inconclusive and misses the layer finding.
Useful? React with 👍 / 👎.
| _CONFIG_PROJECTION_KEYS_AFTER_STRING_LIMIT: ClassVar[frozenset[str]] = frozenset( | ||
| { |
There was a problem hiding this comment.
Preserve nested callable keys after overflow
After a prior string overflow, keys not in this allowlist are dropped; that includes activation and initializer fields scanned by _check_nested_serialized_module_references. A layer with config.activation -> posix.system becomes only inconclusive, missing CVE-2025-1550. guidance
Useful? React with 👍 / 👎.
Summary
config.jsondepth, admitted/pending work, direct-field work, string count, and total string charactersget_fileCVE detectors on the original configget_filecallable shapeskwargsURL extraction across nestedget_filecallsget_fileextraction semantics and their regression matrixAdversarial review
The review reproduced and fixed:
kwargsstrings being double-countedkwargssubtrees being rescanned once per ancestorget_filefindingsget_fileevidenceNoneplaceholders producing false structural evidenceThe final read-only audit's two boundedness findings were fixed and covered by regressions.
Validation
get_fileand unsafe-deserialization CVE classes: 64 passedgit diff --checkmainin three filesOptional dependency skips require unavailable HDF5/ONNX packages. Per review policy, the full repository suite was left to CI.
Published head:
8ecc44aab1c57c701280bb61224a0b98c0eec6cd