Skip to content

test: add path_security security property tests - #99

Merged
HC-ONLINE merged 1 commit into
mainfrom
test/path-security-security-properties
Oct 1, 2026
Merged

HC-ONLINE merged 1 commit into
mainfrom
test/path-security-security-properties

Conversation

@HC-ONLINE

@HC-ONLINE HC-ONLINE commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

Adds 5 security-property tests to ests/unit/utils/test_path_security.py covering gaps identified during the Fase 7 audit of
esolve_and_validate_path():

  • Prefix confusion (absolute): a sibling dir sharing the base name prefix (export-attacker) is rejected
  • Prefix confusion (relative): ../export2/file.json is rejected
  • Bare ..: resolves to parent of base, rejected
  • Encoded traversal: ..%2f..%2fescape.json stays a literal filename inside base (no decoding layer)
  • Drive-relative (win32): C:evil.yaml either rejected or contained inside base

Rationale

These properties were exercised empirically during the CodeQL #9/#10/#11 investigation (31 attack cases, 0 bypasses) but were not asserted in the unit suite.

Validation

  • pytest tests/unit/utils/test_path_security.py: 36 passed, 2 skipped
  • uff check . /
  • uff format --check . / pyright: clean
  • git diff --check: clean

@HC-ONLINE
HC-ONLINE merged commit 8375e89 into main Oct 1, 2026
6 checks passed
@HC-ONLINE
HC-ONLINE deleted the test/path-security-security-properties branch October 5, 2026 15:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant