Skip to content

fix(codeql): add barrier model for validate_export_path_only - #97

Merged
HC-ONLINE merged 1 commit into
mainfrom
codeql/validate-export-path-only-barrier
Oct 1, 2026
Merged

HC-ONLINE merged 1 commit into
mainfrom
codeql/validate-export-path-only-barrier

Conversation

@HC-ONLINE

@HC-ONLINE HC-ONLINE commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Adds validate_export_path_only.ReturnValue as a barrierModel (path-injection) to the existing model pack.

Alerts #6/#7/#8 (config_service.py:369/441/442) are false positives: the function always returns a path contained within allowed_base or raises an exception (fail-closed).

A/B validation (CodeQL 2.27.1, default suite, fresh databases): 22/6 → 19/3, exact delta of −3, non-pi results identical (16/16).

@HC-ONLINE
HC-ONLINE merged commit ea3a76f into main Oct 1, 2026
6 checks passed
@HC-ONLINE
HC-ONLINE deleted the codeql/validate-export-path-only-barrier branch October 5, 2026 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant