Skip to content

docs: correct the round-16 CodeQL triage counts and record the measured result - #52

Merged
StvLi merged 2 commits into
mainfrom
docs/maintain-round-16-corrections
Sep 29, 2026
Merged

StvLi merged 2 commits into
mainfrom
docs/maintain-round-16-corrections

Conversation

@StvLi

@StvLi StvLi commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Two accuracy fixes to §21, which the round-16 run had just merged.

The triage table did not add up. It listed js/remote-property-injection as 12 (actually 13) and js/insecure-temporary-file as 6 (actually 8) — 25 rows against a stated total of 29. A breakdown whose parts do not sum to the whole is not a breakdown, and a maintenance log is only worth keeping if its numbers are counted rather than estimated.

Prediction replaced by measurement. §21.3.3 and §21.8 said to check next round that the alert count fell to roughly 17 once #51 landed. It has landed, so the real figure is recorded: 29 → 13, mapped one-to-one onto the actions taken.

Category Before → after Because
js/remote-property-injection (generated) 13 → 0 paths-ignore: docs/archify/**
js/file-system-race 1 → 0 O_EXCL
js/shell-command-constructed-from-input 1 → 0 shq()
Remaining 13 all in the triaged deliberately not fixed / by design buckets

The remaining 13 are 3 ReDoS + 8 temp-file + 2 file-access-to-http, with no unexpected new rule — which is the point: the drop was predicted in advance and landed entirely inside the predicted buckets, and that agreement is the evidence the triage was correct rather than a post-hoc story.

Docs-only; no code or workflow changes.

…sult

Two fixes to the section added in the round-16 run.

The triage table's own arithmetic was wrong: `js/remote-property-injection`
was written as 12 (it is 13) and `js/insecure-temporary-file` as 6 (it is 8),
which summed to 25 against a stated total of 29. A "29 alerts" breakdown whose
rows do not add up to 29 is not a breakdown; the rows must be counted, not
estimated from a glance at the rule list.

With #51 merged, the post-fix state is now measured rather than predicted:
**29 → 13**, and the drop maps one-to-one onto the actions taken — 13 generated
`archify` alerts gone via `paths-ignore`, `js/file-system-race` gone via
`O_EXCL`, `js/shell-command-constructed-from-input` gone via `shq()`. The
remaining 13 are exactly the triaged "deliberately not fixed / by design" set
(3 ReDoS, 8 temp-file, 2 file-access-to-http), with no unexpected new rule.

That the drop was predictable and landed entirely inside the predicted buckets
is itself the evidence that the triage was right, so §21.8's "check it dropped
to ~17 next round" becomes a recorded 13 plus a simple no-regression check.
§21.5 and §21.8 said the reload request had been registered; now it is confirmed
with the actual evidence rather than asserted — journal原文
(`restart requested (gen 24): plugin-change`, 04:22:47 CST), the state file
(`lifecycleState: deferred`, `coalesced: true`), and `deferDeadline − updatedAt
= 900000 ms`, which matches the documented 900 s hard deadline.

Also records a correction that matters for the next run: the first activation
FAILED, and not because of the package. The restricted ctx does not expose
`logger`:

    sandbox ctx does not expose "logger". Available: ctx.tools.register / ctx.on /
    ctx.provide / the timer helpers after injecting timer, …

So the "lazy package that just logs one line" recipe carried in §20.5 is no
longer usable as written. The replacement is a genuinely empty `apply()`, which
is both sufficient and safer: dsh-phoenix triggers on the `cordis_run` call
itself, not on anything apply() does, so a package that acquires no capability
has no way to fail.

The second activation produced `restart already in-flight; coalesced
plugin-change`, confirming phoenix de-duplicates in-flight restart requests
rather than per-package.
@StvLi
StvLi merged commit 444be2d into main Sep 29, 2026
5 of 7 checks passed
@StvLi
StvLi deleted the docs/maintain-round-16-corrections branch September 29, 2026 20:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant