Skip to content

Commit df0c232

Browse files
committed
fix(ci): reject non-regular scanner reports without blocking
Signed-off-by: Adrien Langou <alangou@nvidia.com>
1 parent 8dc7c24 commit df0c232

2 files changed

Lines changed: 46 additions & 2 deletions

File tree

‎tasks/scripts/codex_security_diagnostics.py‎

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@
1010
import json
1111
import os
1212
import shutil
13+
import stat
1314
import subprocess
1415
import time
1516
from pathlib import Path
@@ -18,9 +19,15 @@
1819
def read_document(path: Path) -> tuple[dict, str]:
1920
# Never echo parser errors, paths, or arbitrary scanner-generated text.
2021
try:
21-
if path.is_symlink():
22+
if not stat.S_ISREG(path.lstat().st_mode):
2223
return {}, "invalid"
23-
with path.open("rb") as stream:
24+
# Check the opened file too: the path may change after lstat().
25+
flags = (
26+
os.O_RDONLY | getattr(os, "O_NONBLOCK", 0) | getattr(os, "O_NOFOLLOW", 0)
27+
)
28+
with os.fdopen(os.open(path, flags), "rb") as stream:
29+
if not stat.S_ISREG(os.fstat(stream.fileno()).st_mode):
30+
return {}, "invalid"
2431
data = stream.read(4 * 1024 * 1024 + 1)
2532
if len(data) > 4 * 1024 * 1024:
2633
return {}, "oversized"

‎tasks/scripts/codex_security_diagnostics_test.py‎

Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -128,6 +128,43 @@ def test_missing_invalid_and_symlinked_reports_do_not_echo_contents(tmp_path):
128128
assert coverage_summary(tmp_path)["coverage_document"] == "invalid"
129129

130130

131+
@pytest.mark.skipif(not hasattr(os, "mkfifo"), reason="requires named pipes")
132+
@pytest.mark.parametrize(
133+
("filename", "field"),
134+
[
135+
("coverage.json", "coverage_document"),
136+
("scan-manifest.json", "manifest_document"),
137+
],
138+
)
139+
def test_fifo_report_does_not_block_diagnostics(tmp_path, filename, field):
140+
scan = tmp_path / "scan"
141+
scan.mkdir()
142+
os.mkfifo(scan / filename)
143+
output = tmp_path / "diagnostics.json"
144+
result = subprocess.run(
145+
[
146+
sys.executable,
147+
str(SCRIPT),
148+
"--scan-dir",
149+
str(scan),
150+
"--output",
151+
str(output),
152+
"--",
153+
sys.executable,
154+
"-c",
155+
"raise SystemExit(2)",
156+
],
157+
capture_output=True,
158+
text=True,
159+
check=False,
160+
timeout=5,
161+
)
162+
assert result.returncode == 2
163+
report = json.loads(output.read_text())
164+
assert report["exit_code"] == 2
165+
assert report[field] == "invalid"
166+
167+
131168
def test_scan_output_directory_stays_empty_until_scanner_writes(tmp_path):
132169
scan = tmp_path / "scan"
133170
output = tmp_path / "diagnostics.json"

0 commit comments

Comments
 (0)