chore(codeql): reconcile protected main into #2106 - #2195
Conversation
…2194) Let a repository declare literal path prefixes in .github/edge-policy-artifact-paths.txt that hold research/data artifacts (SPSS .sav, serialized model objects, numeric arrays, ...) not shaped like documentation, and admit binary content there on the same evidence terms documentation paths already get. Security property: evaluate_pull_request now threads an optional base_ref and resolves the declaration only from that ref, never the pull-request head, so a PR cannot self-authorize admission of its own binary by adding or widening the declaration in the same diff. A new test proves the same-PR case is refused. .github/workflows/opencode- review.yml threads the pull_request_target event's already-available github.event.pull_request.base.sha with no new permissions. Suffix decision: a declared-prefix file whose suffix has no BINARY_DOCUMENT_MAGIC entry (most research formats) is admitted only on "no diff patch + fetched bytes are not valid UTF-8" evidence, so a file that decodes as valid UTF-8 is always still content-scanned. Runtime-named files (_runtime_path_rule) stay rejected inside a declared prefix exactly as inside docs/ today. Declaration parsing is bounded (64 entries, 8-segment depth) and rejects absolute paths, ".." traversal, and globs with a PolicyError naming the offending entry; a missing declaration file behaves identically to before this feature existed. pingora_edge_policy.py stays at 100% branch coverage and 100% interrogate docstring coverage. Refs #2193, #2149, #2116. Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
9defd52
into
fix/codeql-versioned-handler-bootstrap
There was a problem hiding this comment.
| if suffix not in BINARY_DOCUMENT_MAGIC: | ||
| try: | ||
| raw.decode("utf-8") | ||
| except UnicodeDecodeError: | ||
| return True |
There was a problem hiding this comment.
🟡 Large declared artifacts remain blocked
Declared artifacts over 1 MiB never reach _binary_documentation_evidence_confirms's non-UTF-8 admission. The size exception admits only PDFs, so large SAV, RDS, and NPZ changes remain unmergeable.
Learn more
The Contents API stops inlining files above MAX_FILE_BYTES. In that case, _load_raw_file_bytes raises ContentSizeExceededError before these lines receive any bytes. The exception handler immediately above admits only .pdf, so the new declared-prefix path does not support large opaque research formats.
Example: A base declaration contains local, and a PR adds local/model.npz at 2 MiB. GitHub returns encoding: "none" and the accurate size. The scanner rejects the file instead of applying the declared non-UTF-8 artifact rule.
Recommended fix: For declared artifacts, follow the Contents response's blob SHA through the bounded Git Blobs API and apply the same UTF-8 test to those bytes. Preserve a hard upper bound and fail closed when the blob cannot be fetched or validated.
Was this helpful? React with 👍 or 👎 to provide feedback.
| # A base ref threaded into evaluate_pull_request may be either a branch name | ||
| # (e.g. "main", "release/2026.09") or a commit SHA -- whatever the calling | ||
| # workflow already has on the pull_request event without new permissions. | ||
| # Bounded charset/length, no ".." traversal, and no leading/trailing "/". | ||
| BASE_REF_RE = re.compile(r"^[A-Za-z0-9](?:[A-Za-z0-9._/-]{0,253}[A-Za-z0-9])?$") |
There was a problem hiding this comment.
🟡 Valid base refs are rejected
BASE_REF_RE rejects valid branch names ending in - or _. evaluate_pull_request therefore fails before loading declarations from those documented refs.
Learn more
Git branch names may end in - or _; only a trailing slash and Git's other ref-format restrictions need rejection here. The regular expression instead requires an alphanumeric final character, despite evaluate_pull_request documenting branch names as supported base refs.
Example: A caller passes the valid branch release- as base_ref. Validation raises PolicyError("Pull-request base ref is malformed"), and no declaration or PR evidence is loaded.
Recommended fix: Validate the bounded character set independently from the no-leading-or-trailing-slash rule. Accept legal terminal characters such as - and _, while retaining the existing traversal and length checks.
Was this helpful? React with 👍 or 👎 to provide feedback.
| if isinstance(exc, HTTPError) and exc.code == 404: | ||
| raise ArtifactDeclarationNotFoundError( | ||
| f"GitHub API reported no resource for policy evidence at {url}" | ||
| ) from exc |
There was a problem hiding this comment.
| if suffix not in BINARY_DOCUMENT_MAGIC: | ||
| try: | ||
| raw.decode("utf-8") | ||
| except UnicodeDecodeError: | ||
| return True |
Ordinary non-force reconciliation of protected
main@91be6442906c7b6b4f600272c953699708394327into canonical CodeQL bootstrap branchfix/codeql-versioned-handler-bootstrapafter #2194 advanced the protected base. This helper carries the protected-main Pingora/OpenCode artifact-path delta without changing #2106's seven-path canonical CodeQL repair. No predecessor check/review evidence transfers; #2106 must reacquire exact-head acceptance after this merge.