fix: classify pytorch zip symlink targets - #1573
mldangelo-oai merged 3 commits into
Conversation
Performance BenchmarksCompared
|
|
Critical review complete and fixes published in The final patch closes both directions of target-classification error: relative parent paths that remain within the archive are accepted, while traversal, UNC/Windows paths, invalid encodings, empty/NUL targets, and oversized targets fail closed. Absolute dot segments are normalized before critical-system attribution, and finding evidence is bounded/redacted. Focused validation: 19 symlink/timeout tests passed; Ruff, formatting, mypy, and |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 943995b8b5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex Publication handoff for all four unresolved symlink-target threads: apply local fix commit The fix adds bounded-prefix reads with completeness tracking, Current-main validation:
Direct push still fails with |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 943995b8b5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Local review repair is complete on current The validated repair:
Validation: focused PyTorch ZIP symlink slice @codex address that feedback by applying the equivalent changes to |
|
Summary
Testing
Full pytest was not run, matching the PR campaign guidance to use the focused PyTorch ZIP symlink slice. |
943995b to
e5f60cd
Compare
e5f60cd to
032c95d
Compare
|
Published the reviewed follow-up as The duplicate review findings are addressed:
Focused QA: 21 passed, 773 deselected; touched-file Ruff, mypy, and diff checks are clean. |
|
Published the reviewed fix at Review findings addressed:
Focused QA: 21 passed, 773 deselected; scoped Ruff format/check, mypy, and |
|
Published the latest-main critical-review fixes in |
|
Published the final critical-review hardening in Two additional gaps are closed:
Final focused QA: 35 passed, 773 deselected; valid data-descriptor and forced-ZIP64 probes passed; touched-file Ruff, mypy, and diff checks are clean. All review threads are resolved. |
Summary
surrogateescapeso non-UTF-8 targets still receive traversal classificationmainat21956abfe97ec8312bb4f6312b5da99ec0fa640eFalse-positive and false-negative fixes
Focused validation
806 passed, 5 warnings35 passed, 773 deselectedgit diff --checkcleanPublished commit:
2b2fb4f548d79d9a6f5380dd284f76dea0c79592Published tree:
7df9a6a009130673453fe0dfb8e1fce99af3cc84