fix(static): ignore command-line flags as marker directives - #697
efegokdemir wants to merge 2 commits into
Conversation
Signed-off-by: Efe <efe@rexcode.co.uk>
|
Thanks for the quick fix! I tested the PR head (
So the Since the PR says |
Signed-off-by: Efe <efe@rexcode.co.uk>
|
Thanks for reproducing the remaining dictionary-key case. I verified it was within #695's stated scope and fixed it in 524f51a. The bounded unsupported-marker parser now ignores directive-like words inside structural mapping/list keys, with a regression test for the Path/Read/Write/Delete dictionary; the existing command-line flag regression remains covered. Validation: uv run pytest with the command-line, dictionary-key, equivalent-marker, and ambiguous-marker selections (51 passed), Ruff check, Ruff format check, and git diff --check. |
|
Thank you for picking this up so quickly, and for covering the dictionary-key case as well. Once this lands in a release, I'll re-run our original reproduction (the Docker argv list and the Path/Read/Write/Delete mapping) against it and report back here. |
Summary
Prevent the bounded declared-marker parser from treating the
dropportion of command-line flags such as--cap-dropas a natural-language removal directive. The parser now requires fallback removal verbs not to start immediately after a hyphen or word character, and a regression test covers a Docker argv list in Python source.Testing
obfuscated_instruction_textand incomplete analysis with the issue's Docker argv example before the fix.uv run pytest tests/nodes/analyzers/test_security_reconstruction.py -k 'command_line_flag or equivalent_declared_marker_forms or ambiguous_equivalent_forms' -q(50 passed)uv run ruff check src/ tests/(passed)uv run pytest -m 'not integration and not provider' -q(started, but the local process stopped after approximately 12% without a final result; not claimed as passed)git diff --checkIssue
Fixes #695