Skip to content

fix(rules): attribute format mismatches to s901 - #1613

Merged
mldangelo-oai merged 7 commits into
mainfrom
mdangelo/codex/fix-rule-code-auto-attribution
Jun 10, 2026
Merged

mldangelo-oai merged 7 commits into
mainfrom
mdangelo/codex/fix-rule-code-auto-attribution

Conversation

@mldangelo-oai

@mldangelo-oai mldangelo-oai commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • assign failed core file-format validation checks directly to S901
  • prevent incidental terms such as zlib from relabeling those checks as S603
  • keep compatible container discrepancies at DEBUG without an S901 code, so severity overrides cannot promote benign wrappers
  • retain existing message-based rule inference for legacy scanner checks

Campaign evidence

A SafeTensors/zlib routing collision produced both an S901 mismatch and a duplicate S603 finding. Core emitted Format Validation without a rule code, so ScanResult selected the first catalog regex matching the message. The word zlib matched S603 before the later S901 mismatch rule.

The routing collision is handled separately in #1623. This PR uses a genuine zlib-wrapped malicious payload to isolate rule attribution from that routing fix.

Validation

  • focused attribution, malicious-positive, benign-negative, compatible-container, and ONNX routing regressions: 5 passed
  • Ruff format and lint pass across required source and test paths
  • mypy passes across 473 source files
  • full non-slow/non-integration run reached 12,409 passed and 359 skipped; the two local failures were unrelated (read-only HOME cache access and a pre-existing shard-alias test)

@github-actions

github-actions Bot commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Workflow run and artifacts

Performance Benchmarks

Compared 12 shared benchmarks with a regression threshold of 15%.
Status: 0 regressions, 0 improved, 12 stable, 0 new, 0 missing.
Aggregate shared-benchmark median: 1.409s -> 1.394s (-1.1%).

Workload Benchmark Target Size Files Baseline Current Change Status
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_base64] nested_base64 98 B 1 555.6us 534.5us -3.8% stable
warm-cache-rescan tests/benchmarks/test_scan_benchmarks.py::test_scan_warm_cached_repository_rescan release-candidate 547.3 KiB 32 104.18ms 101.18ms -2.9% stable
padded-multi-stream-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_padded_multi_stream_upload multi_stream_padded 4.1 KiB 1 608.3us 599.0us -1.5% stable
mixed-model-repository tests/benchmarks/test_scan_benchmarks.py::test_scan_release_candidate_repository release-candidate 547.3 KiB 32 486.90ms 479.49ms -1.5% stable
chunked-upload-stream tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_chunked_upload_stream chunked_stream 278.2 KiB 1 111.71ms 110.11ms -1.4% stable
direct-malicious-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_direct_malicious_upload malicious_reduce 52 B 1 516.7us 509.3us -1.4% stable
suspicious-pickle-intake tests/benchmarks/test_scan_benchmarks.py::test_scan_suspicious_pickle_intake suspicious-intake 183.8 KiB 4 142.34ms 140.36ms -1.4% stable
clean-training-checkpoint tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_clean_training_checkpoint safe_large 278.2 KiB 1 107.36ms 106.81ms -0.5% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_raw] nested_raw 78 B 1 537.8us 535.6us -0.4% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_hex] nested_hex 130 B 1 566.0us 568.3us +0.4% stable
single-checkpoint-preflight tests/benchmarks/test_scan_benchmarks.py::test_scan_single_checkpoint_before_load single_checkpoint.pkl 183.0 KiB 1 69.99ms 69.71ms -0.4% stable
duplicate-heavy-registry tests/benchmarks/test_scan_benchmarks.py::test_scan_duplicate_registry_snapshot registry-snapshot 915.2 KiB 13 383.64ms 383.40ms -0.1% stable

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Exact current head: 355226d65aa559be809a00bb6b5d317b391c9ec9. This supersedes the mistyped full SHA in my preceding comment.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep them coming!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai
mldangelo-oai enabled auto-merge (squash) June 10, 2026 14:21
@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Exact current head SHA: f0a1998. This head includes the latest origin/main via a normal merge.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Swish!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Exact current head SHA: ce771f5. This head includes latest origin/main commit e8dc55e via a normal merge.

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Exact current head SHA: 1d13b12. This head includes latest origin/main commit c769097 via a normal merge.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Nice work!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Exact current head SHA: 2e3ee8c. This head includes latest origin/main commit e407fb4 via a normal merge.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Another round soon, please!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai
mldangelo-oai merged commit 22bc654 into main Jun 10, 2026
27 of 28 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/fix-rule-code-auto-attribution branch June 10, 2026 15:35
@github-actions github-actions Bot mentioned this pull request Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant