fix(llm-security): YAML/workflow parser divergence — block scalars + bare if: (#32,#33,#43)
#33 the frontmatter parser collected a block-scalar body (description: |) but did not skip it, so an indented name:/allowed_tools: inside the body re-matched as a top-level key and overrode the real values TRG-shadow and permission checks depend on; the parser now consumes block-scalar bodies as opaque content. #32 block-scalar headers carrying indentation/chomping indicators (|2, >-, |-2) were not recognized, so their bodies never reached the run: injection sink; now matched via a proper indicator/chomping regex. #43 the B4 actor auth-bypass detector inspected only braced ${{ }} expressions, missing the canonical bare 'if: github.actor == ...' form (Synacktiv Dependabot-spoof false negative); bare if: expressions now emit a synthetic event the detector reads. Suite 2004/0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TcQyMTQfyrsAapaCMPxTtQ
This commit is contained in:
parent
207385fbbe
commit
b224e18b42
8 changed files with 244 additions and 7 deletions
|
|
@ -20,7 +20,10 @@ const EXPR_RE = /\$\{\{\s*([\s\S]+?)\s*\}\}/g;
|
|||
const KV_RE = /^([A-Za-z_][\w-]*)\s*:\s*(.*)$/;
|
||||
const LIST_KV_RE = /^-\s+([A-Za-z_][\w-]*)\s*:\s*(.*)$/;
|
||||
const TRIGGER_RE = /^([a-z_]+)(?::|$)/;
|
||||
const BLOCK_SCALAR_VALUES = new Set(['|', '>', '|-', '>-', '|+', '>+']);
|
||||
// Block-scalar header: `|` or `>` plus optional indentation indicator
|
||||
// (1-9) and chomping indicator (`+`/`-`), in either order (`|2`, `>-`,
|
||||
// `|-2`, `>2-`, ...). Bare-literal matching missed indicator forms (#32).
|
||||
const BLOCK_SCALAR_RE = /^[|>](?:[1-9][+-]?|[+-][1-9]?)?$/;
|
||||
|
||||
/**
|
||||
* Strip comments after first unquoted `#`. Workflows rarely embed `#`
|
||||
|
|
@ -131,6 +134,7 @@ export function extractTriggers(lines) {
|
|||
* parent: string,
|
||||
* parentChain: string[],
|
||||
* blockScalar: boolean,
|
||||
* bare?: boolean,
|
||||
* }[],
|
||||
* }}
|
||||
*/
|
||||
|
|
@ -177,7 +181,7 @@ export function parseWorkflow(text) {
|
|||
if (kv) {
|
||||
const key = kv[1];
|
||||
const value = kv[2];
|
||||
const isBlock = BLOCK_SCALAR_VALUES.has(value);
|
||||
const isBlock = BLOCK_SCALAR_RE.test(value);
|
||||
const exprs = !isBlock && value ? findExpressions(raw, i + 1) : [];
|
||||
for (const e of exprs) {
|
||||
events.push({
|
||||
|
|
@ -187,6 +191,20 @@ export function parseWorkflow(text) {
|
|||
blockScalar: false,
|
||||
});
|
||||
}
|
||||
// Bare `if:` values (no `${{ }}`) are auto-evaluated as expressions
|
||||
// by the runner — emit them so actor auth-bypass checks see the
|
||||
// canonical unbraced form (#43).
|
||||
if (key === 'if' && !isBlock && value && exprs.length === 0) {
|
||||
events.push({
|
||||
line: i + 1,
|
||||
column: raw.indexOf(value) + 1,
|
||||
expr: value.trim(),
|
||||
parent: key,
|
||||
parentChain: [...stack.map(s => s.key), key],
|
||||
blockScalar: false,
|
||||
bare: true,
|
||||
});
|
||||
}
|
||||
stack.push({ indent, key, isBlockScalar: isBlock });
|
||||
continue;
|
||||
}
|
||||
|
|
@ -196,7 +214,7 @@ export function parseWorkflow(text) {
|
|||
if (lkv) {
|
||||
const key = lkv[1];
|
||||
const value = lkv[2];
|
||||
const isBlock = BLOCK_SCALAR_VALUES.has(value);
|
||||
const isBlock = BLOCK_SCALAR_RE.test(value);
|
||||
const exprs = !isBlock && value ? findExpressions(raw, i + 1) : [];
|
||||
for (const e of exprs) {
|
||||
events.push({
|
||||
|
|
@ -206,6 +224,18 @@ export function parseWorkflow(text) {
|
|||
blockScalar: false,
|
||||
});
|
||||
}
|
||||
// Same bare `if:` handling as the KV branch (#43).
|
||||
if (key === 'if' && !isBlock && value && exprs.length === 0) {
|
||||
events.push({
|
||||
line: i + 1,
|
||||
column: raw.indexOf(value) + 1,
|
||||
expr: value.trim(),
|
||||
parent: key,
|
||||
parentChain: [...stack.map(s => s.key), key],
|
||||
blockScalar: false,
|
||||
bare: true,
|
||||
});
|
||||
}
|
||||
// List items create a deeper synthetic indent so subsequent
|
||||
// sibling keys at the same column still resolve to this item.
|
||||
stack.push({ indent: indent + 2, key, isBlockScalar: isBlock });
|
||||
|
|
|
|||
|
|
@ -19,7 +19,9 @@ export function parseFrontmatter(content) {
|
|||
const result = {};
|
||||
|
||||
// Parse simple key: value pairs
|
||||
for (const line of block.split('\n')) {
|
||||
const lines = block.split('\n');
|
||||
for (let lineIdx = 0; lineIdx < lines.length; lineIdx++) {
|
||||
const line = lines[lineIdx];
|
||||
const trimmed = line.trim();
|
||||
if (!trimmed || trimmed.startsWith('#')) continue;
|
||||
|
||||
|
|
@ -44,12 +46,13 @@ export function parseFrontmatter(content) {
|
|||
// Handle multi-line description with |
|
||||
if (value === '|' || value === '>') {
|
||||
const descLines = [];
|
||||
const lines = block.split('\n');
|
||||
const lineIdx = lines.indexOf(line);
|
||||
for (let i = lineIdx + 1; i < lines.length; i++) {
|
||||
const dLine = lines[i];
|
||||
if (/^\S/.test(dLine) && !dLine.startsWith(' ') && !dLine.startsWith('\t')) break;
|
||||
descLines.push(dLine.replace(/^ /, ''));
|
||||
// Consume the body line — block-scalar content is an opaque
|
||||
// string, never re-parsed as key: value pairs (#33).
|
||||
lineIdx = i;
|
||||
}
|
||||
value = descLines.join('\n').trim();
|
||||
}
|
||||
|
|
|
|||
|
|
@ -274,7 +274,7 @@ async function scanFile(absPath, targetPath, stderrLog) {
|
|||
`${relPath}: ${ev.expr}.`,
|
||||
file: relPath,
|
||||
line: ev.line,
|
||||
evidence: `\${{ ${ev.expr} }}`,
|
||||
evidence: ev.bare ? ev.expr : `\${{ ${ev.expr} }}`,
|
||||
owasp: 'LLM06',
|
||||
recommendation:
|
||||
'Use `github.event.pull_request.user.login` (immutable per PR) ' +
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue