Skip to content

fix(static): ignore command-line flags as marker directives - #697

Open
efegokdemir wants to merge 2 commits into
NVIDIA:mainfrom
efegokdemir:fix/avoid-code-flag-marker
Open

efegokdemir wants to merge 2 commits into
NVIDIA:mainfrom
efegokdemir:fix/avoid-code-flag-marker

Conversation

@efegokdemir

Copy link
Copy Markdown

Summary

Prevent the bounded declared-marker parser from treating the drop portion of command-line flags such as --cap-drop as a natural-language removal directive. The parser now requires fallback removal verbs not to start immediately after a hyphen or word character, and a regression test covers a Docker argv list in Python source.

Testing

  • Reproduced obfuscated_instruction_text and incomplete analysis with the issue's Docker argv example before the fix.
  • uv run pytest tests/nodes/analyzers/test_security_reconstruction.py -k 'command_line_flag or equivalent_declared_marker_forms or ambiguous_equivalent_forms' -q (50 passed)
  • uv run ruff check src/ tests/ (passed)
  • uv run pytest -m 'not integration and not provider' -q (started, but the local process stopped after approximately 12% without a final result; not claimed as passed)
  • git diff --check

Issue

Fixes #695

Signed-off-by: Efe <efe@rexcode.co.uk>
@elliottwaves-20

Copy link
Copy Markdown

Thanks for the quick fix! I tested the PR head (d50c4ed) against the cases from #695, static scan with --no-llm:

Input v2.12.0 this PR
10-line Docker argv reproducer from the issue obfuscated_instruction_text, 1 file partial complete
The original ~290-line file the reproducer was reduced from partial complete
File with dict keys such as {"Path": path, "Read": True, "Write": False, "Delete": False} partial still partial (obfuscated_instruction_text)

So the --cap-drop case is fixed. The dictionary-key case mentioned at the end of #695 still reproduces. A public file that triggers it (lines 35 and 39):
https://github.com/elliottwaves-20/agent-guard/blob/04a25ab401dacb58976accaade1a86d9b948aa98/tests/test_dynamic.py

Since the PR says Fixes #695, that case would be lost when the issue closes. It could either be covered here, or I can open a separate issue for it, whichever you prefer.

Signed-off-by: Efe <efe@rexcode.co.uk>
@efegokdemir

Copy link
Copy Markdown
Author

Thanks for reproducing the remaining dictionary-key case. I verified it was within #695's stated scope and fixed it in 524f51a. The bounded unsupported-marker parser now ignores directive-like words inside structural mapping/list keys, with a regression test for the Path/Read/Write/Delete dictionary; the existing command-line flag regression remains covered.

Validation: uv run pytest with the command-line, dictionary-key, equivalent-marker, and ambiguous-marker selections (51 passed), Ruff check, Ruff format check, and git diff --check.

@elliottwaves-20

Copy link
Copy Markdown

Thank you for picking this up so quickly, and for covering the dictionary-key case as well. Once this lands in a release, I'll re-run our original reproduction (the Docker argv list and the Path/Read/Write/Delete mapping) against it and report back here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

obfuscated_instruction_text on a Docker argv list (--cap-drop) in Python source

2 participants