Skip to content

docs: record the round-17 maintenance run - #57

Merged
StvLi merged 1 commit into
mainfrom
docs/maintain-round-17
Sep 30, 2026
Merged

StvLi merged 1 commit into
mainfrom
docs/maintain-round-17

Conversation

@StvLi

@StvLi StvLi commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Adds §22 to dsh-ros2-maintain.md and refreshes the header. Documentation only — no code changes.

The round in one paragraph: the three ReDoS alerts round 16 deliberately left unfixed were measured before being fixed, and only one turned out to be real and reachable, so the round's main contribution is a triage corrected by measurement rather than the fix itself.

Highlights, all with the evidence in the section:

Adds §22 and refreshes the header. The round's substance, in short:

- The three ReDoS alerts round 16 deliberately left unfixed were measured
  **before** being fixed. Only one is real and reachable: parseTopicList,
  `![' + ' '.repeat(n) + 'x'`, 14.8 s at n=4000 (k=2.11, synchronous, so it
  blocks the whole event loop). A second reachable shape was found while
  writing the tests: `'['.repeat(n) + ' ]x]'`, 697 ms at n=20000 (k=2.00).
  parseNodeInfo is quadratic only with a `\n`, which its caller strips;
  parseSafetyEcho is not reproducible at all. So "3 real, low risk" becomes
  "1 real / 1 unreachable / 1 not reproducible".

- Measured, not argued: the two pumps survive `parseLines()`'s trim, which is
  why they are reachable from the real entry point. Testing the bare regex
  would have drawn the wrong conclusion for parseNodeInfo.

- Dependabot: 4 → 3. #43 (vitest, dev-only) merged. #42/#45/#46 all raise a
  declared *floor*, and CI installs the devDependency each PR itself bumps —
  so green proves "works with the new version", never "the new version is the
  right floor". Both peers are type-only (zero runtime imports). The live
  harness provides cordis 4.0.2 / dsh-skill 0.1.5-rc.1, so #42 would put the
  floor above the deployment. Escalated to issue #56 rather than deferred a
  third time.

- Closes round 16's last open observation: gen 24 landed clean
  (lifecycleState running, deferDeadline 0, pendingResume false).

- Corrects round 16's own snapshot table, which said main had 344 tests while
  its §21.8 said 347. Measured baseline before any of this round's changes is
  347 — the table had captured main before #51 merged.

- Security: CodeQL 13 → 10 open (exactly the three ReDoS, no new rules);
  audits clean; publish surface 9/9 clean with 14 seeded .pyc files and a
  positive control that removes a guard and shows the .pyc does ship.
@StvLi
StvLi merged commit 1c9ea44 into main Sep 30, 2026
5 checks passed
@StvLi
StvLi deleted the docs/maintain-round-17 branch September 30, 2026 20:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant