Repository navigation
Conversation
lusoris
enabled auto-merge (squash)
May 29, 2026 10:26
lusoris
disabled auto-merge
May 29, 2026 11:43
lusoris
marked this pull request as draft
May 29, 2026 11:43
lusoris
force-pushed
the
fix/pr50-residual-conflict-markers
branch
from
May 29, 2026 12:12
f2109f7 to
46f5e26
Compare
Expands PR #181 to cover the docs/research/ and docs/adr/_index_fragments/ files left behind by the 40-file initial sweep. All conflicts originate from 24bb5da trying to revert the ADR-0700 path rename (libvmaf/ -> core/, python/vmaf/ -> compat/python-vmaf/) and the VMAFx rebrand; HEAD side kept verbatim per the resolution policy because the canonical tree already carries the renamed paths and VMAFx branding. Net change is purely the removal of <<<<<<< / ======= / >>>>>>> envelopes plus the discarded incoming-side lines (258 deletions, 0 insertions); no file content was edited beyond marker resolution.
lusoris
marked this pull request as ready for review
May 29, 2026 13:11
… fix Two follow-up fixes after the PR #181 CI run: 1. docs/state.md (CLAUDE.md §12 r13 / ADR-0165): Add a "Recently closed" row for T-CASCADING-CONFLICT-MARKERS-PR50-RESIDUAL-2026-05-29. Commit 24bb5da left committed git conflict markers across 38 files (PR #174 covered the CI YAML subset; PR #181 sweeps the remainder). The state.md touch gate flagged the omission. 2. .gitleaks.toml: gitleaks 8.24.3 evaluates allowlist `paths` regex against the scanned file's *absolute* path (e.g. `/repo/ai/...`) when --source is an absolute directory. Patterns anchored with `^` only matched files directly at the source root (so `^go\.sum$` worked, but `^ai/src/.../README\.md$` and `^subprojects/` never matched anything). The README's `- key: src01_hrc00_576x324` example tripped the generic-api-key entropy rule despite being explicitly allowlisted. Rewrote subdirectory patterns to drop the leading `^` (and prefix with `/` where root-anchoring is desired); `^go\.sum$`-style root-anchored single-file patterns kept as-is via `/go\.sum$`. Local verification with the pinned CI gitleaks v8.24.3 image: 0 leaks (was 2: one allowlisted-but-not-skipped README finding plus a separate `vmaf-fixtures` regex-allowlisted pair). Bytes scanned drops 162 MB -> 39 MB because subprojects/, build/, builddir*/, .git/, gen/go/ are now actually skipped. Also fixes the PR body item name to match the deliverables-check parser exactly ("Reproducer / smoke-test command" not "Reproducer / smoke-test"); body edited via gh pr edit, not in this commit.
Follow-up to c70dfd7. The previous commit unblocked the in-tree README + workflow YAML allowlist failures, but gitleaks scans the full git history when `fetch-depth: 0` is set, and 2 historical findings remained from commit `c35b50e4de` (Netflix upstream, 2016-01-30): random YUV pixel bytes in `resource/yuv/src01_hrc00_ 576x324.yuv:1` and `resource/yuv/src01_hrc01_576x324.yuv:1` trip the `generic-api-key` and `sourcegraph-access-token` entropy gates respectively. Today those fixtures live at `python/test/resource/yuv/...` — already allowlisted — but the pre-2016-rename path `resource/yuv/` was not. Added the historical path so the full-history scan stops flagging upstream Netflix commits. Local reproduce on a fresh full-history clone with the pinned CI gitleaks v8.24.3 image: 3619 commits scanned, 0 leaks found (was 2 leaks).
This was referenced May 29, 2026
Contributor
Author
This was referenced May 29, 2026
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
Two Open rows in docs/state.md cited PRs that were CLOSED-not-merged and flagged as follow-up by the PR #291 closing agent. Verified against master tip bbcaa8d and master state of the underlying issues: 1. T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 — migrated from Open to Recently closed (superseded). The conflict markers only existed on the unmerged scaffold branch tip 35a1fb6. PR #91 (merged 2026-05-29T09:37:48Z) landed ADR-0753 resolution-aware dispatch via the adm_cm_device() consumer without extending dispatch into filter1d_8(), so master never carried the build-failing scaffold variant. PR #214 (the planned conflict-marker cleanup) was CLOSED-not-merged 2026-05-30 when its base scaffold branch was abandoned. core/src/feature/cuda/ integer_vif_cuda.c::filter1d_8() on master uses the clean unconditional cuLaunchKernel paths. 2. T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 — kept Open but the dead PR #215 citation removed. The C++23 Wave 8 conversion of core/src/read_json_model.c is still pending on master (still a .c source per core/src/meson.build:1578); PR #215 was CLOSED-not-merged 2026-05-30. Owner field rewritten to "Owner-driven; pending fresh PR per ADR-0846 Wave 8". Scope-coordinated with DRAFT PR #291 (docs/state-md-drift-sync — already migrates the 3 Vulkan rows + T-LEGACY-RUNNER-ANSNR-BROKEN + T-LEGACY-RUNNER-STUB-MISSING). Row 203 (T-LEGACY-RUNNER-STUB-MISSING-2026-05-29) cites closed PRs #213 and #181 as OPEN but is left untouched here since PR #291 already rewrites it. Net Open count -1; total T-row count unchanged (153). No code changes — documentation cleanup only. Deliverables (ADR-0108): - no digest needed: state.md hygiene - no alternatives: only-one-way reconciliation - no rebase-sensitive invariants - Reproducer: `gh pr view 214 -R VMAFx/vmafx --json state,mergedAt` returns `{"state":"CLOSED","mergedAt":null}`; `grep -nE '^(<{7}|={7}|>{7})( |$)' core/src/feature/cuda/integer_vif_cuda.c` on master returns empty; `ls core/src/read_json_model.*` returns only `.c` and `.h`. - Changelog: changelog.d/changed/state-md-closed-pr-row-sweep.md - no rebase impact: docs only Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
Two Open rows in docs/state.md cited PRs that were CLOSED-not-merged and flagged as follow-up by the PR #291 closing agent. Verified against master tip bbcaa8d and master state of the underlying issues: 1. T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 — migrated from Open to Recently closed (superseded). The conflict markers only existed on the unmerged scaffold branch tip 35a1fb6. PR #91 (merged 2026-05-29T09:37:48Z) landed ADR-0753 resolution-aware dispatch via the adm_cm_device() consumer without extending dispatch into filter1d_8(), so master never carried the build-failing scaffold variant. PR #214 (the planned conflict-marker cleanup) was CLOSED-not-merged 2026-05-30 when its base scaffold branch was abandoned. core/src/feature/cuda/ integer_vif_cuda.c::filter1d_8() on master uses the clean unconditional cuLaunchKernel paths. 2. T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 — kept Open but the dead PR #215 citation removed. The C++23 Wave 8 conversion of core/src/read_json_model.c is still pending on master (still a .c source per core/src/meson.build:1578); PR #215 was CLOSED-not-merged 2026-05-30. Owner field rewritten to "Owner-driven; pending fresh PR per ADR-0846 Wave 8". Scope-coordinated with DRAFT PR #291 (docs/state-md-drift-sync — already migrates the 3 Vulkan rows + T-LEGACY-RUNNER-ANSNR-BROKEN + T-LEGACY-RUNNER-STUB-MISSING). Row 203 (T-LEGACY-RUNNER-STUB-MISSING-2026-05-29) cites closed PRs #213 and #181 as OPEN but is left untouched here since PR #291 already rewrites it. Net Open count -1; total T-row count unchanged (153). No code changes — documentation cleanup only. Deliverables (ADR-0108): - no digest needed: state.md hygiene - no alternatives: only-one-way reconciliation - no rebase-sensitive invariants - Reproducer: `gh pr view 214 -R VMAFx/vmafx --json state,mergedAt` returns `{"state":"CLOSED","mergedAt":null}`; `grep -nE '^(<{7}|={7}|>{7})( |$)' core/src/feature/cuda/integer_vif_cuda.c` on master returns empty; `ls core/src/read_json_model.*` returns only `.c` and `.h`. - Changelog: changelog.d/changed/state-md-closed-pr-row-sweep.md - no rebase impact: docs only Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
Two Open rows in docs/state.md cited PRs that were CLOSED-not-merged and flagged as follow-up by the PR #291 closing agent. Verified against master tip bbcaa8d and master state of the underlying issues: 1. T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 — migrated from Open to Recently closed (superseded). The conflict markers only existed on the unmerged scaffold branch tip 35a1fb6. PR #91 (merged 2026-05-29T09:37:48Z) landed ADR-0753 resolution-aware dispatch via the adm_cm_device() consumer without extending dispatch into filter1d_8(), so master never carried the build-failing scaffold variant. PR #214 (the planned conflict-marker cleanup) was CLOSED-not-merged 2026-05-30 when its base scaffold branch was abandoned. core/src/feature/cuda/ integer_vif_cuda.c::filter1d_8() on master uses the clean unconditional cuLaunchKernel paths. 2. T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 — kept Open but the dead PR #215 citation removed. The C++23 Wave 8 conversion of core/src/read_json_model.c is still pending on master (still a .c source per core/src/meson.build:1578); PR #215 was CLOSED-not-merged 2026-05-30. Owner field rewritten to "Owner-driven; pending fresh PR per ADR-0846 Wave 8". Scope-coordinated with DRAFT PR #291 (docs/state-md-drift-sync — already migrates the 3 Vulkan rows + T-LEGACY-RUNNER-ANSNR-BROKEN + T-LEGACY-RUNNER-STUB-MISSING). Row 203 (T-LEGACY-RUNNER-STUB-MISSING-2026-05-29) cites closed PRs #213 and #181 as OPEN but is left untouched here since PR #291 already rewrites it. Net Open count -1; total T-row count unchanged (153). No code changes — documentation cleanup only. Deliverables (ADR-0108): - no digest needed: state.md hygiene - no alternatives: only-one-way reconciliation - no rebase-sensitive invariants - Reproducer: `gh pr view 214 -R VMAFx/vmafx --json state,mergedAt` returns `{"state":"CLOSED","mergedAt":null}`; `grep -nE '^(<{7}|={7}|>{7})( |$)' core/src/feature/cuda/integer_vif_cuda.c` on master returns empty; `ls core/src/read_json_model.*` returns only `.c` and `.h`. - Changelog: changelog.d/changed/state-md-closed-pr-row-sweep.md - no rebase impact: docs only Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
…overage + #336 state.md row sweep + #383 README badges + #337 ADR-0865 ANSNR) (#529) * docs(libvmaf): doxygen comments on 15 undocumented public C-API entry points Round-2 follow-on to PR #302 (which closed five targeted gap-findings in libvmaf.h / picture.h / dnn.h). This pass covers the public surfaces that PR #302 left untouched, focusing on the headers the ffmpeg patch stack, the upcoming Go/Rust bindings, and the embedded MCP server consume. Entry points documented: - feature.h (file was 100 % undocumented): - VmafFeatureDictionary (struct doc + ownership-transfer rules) - vmaf_feature_dictionary_set - vmaf_feature_dictionary_free - model.h: - VmafModelFlags (enum + per-flag semantics) - VmafModelConfig (struct + per-field doc) - vmaf_model_load - vmaf_model_load_from_path - vmaf_model_feature_overload (incl. opts_dict ownership transfer) - vmaf_model_destroy (incl. do-not-destroy-after-collection-handoff) - VmafModelCollection (struct doc) - VmafModelCollectionScoreType (enum doc) - VmafModelCollectionScore (struct + per-field doc) - vmaf_model_collection_load - vmaf_model_collection_load_from_path - vmaf_model_collection_feature_overload - vmaf_model_collection_destroy - dnn.h: - vmaf_dnn_session_close (pair-with-open contract) Each block documents the negative-errno return convention, NULL-safety, ownership-transfer semantics, and the destroy-pairing required to avoid double-free of collection-owned sub-models. No semantic / no ABI change. Cleanup pass (CLAUDE.md §12 r12 — touched-file lint-clean rule): the three Netflix-copyright include guards (__VMAF_FEATURE_H__ / __VMAF_MODEL_H__ / __VMAF_DNN_H__) trip clang-tidy's bugprone-reserved-identifier check. Renaming them would diverge from Netflix/vmaf master and break port-only upstream sync (CLAUDE.md §10), so each #ifndef / #define gets an inline NOLINT citing the upstream-mirror invariant — the exact pattern ADR-0278 endorses for load-bearing upstream-parity identifiers. Build + lint: - meson setup build-cpu-doc core -Denable_cuda=false -Denable_sycl=false - ninja -C build-cpu-doc (35 targets touched by header change; clean) - clang-tidy -p build-cpu-doc on all 3 touched headers: 0 fork-local warnings (the 3 reserved-identifier warnings present on master are now NOLINT-cited; remaining warnings are in system headers and suppressed). - pre-commit run --files <all 5 touched files>: green. ADR-0108 deliverables: - Research digest: no digest needed — trivial doc-only addition over Netflix-stable signatures already covered by the existing reference manual. - Decision matrix: no alternatives needed — only-one-way fix; the ownership-transfer text matches the implementation in core/src/model.c and core/src/dict.c verbatim. - AGENTS.md invariant note: no rebase-sensitive invariants — the doc text sits above unchanged upstream signatures; future merges from Netflix produce tractable 3-way merges. The NOLINT cites name the invariant they preserve (upstream-mirror include guards). - Reproducer / smoke test: see PR body. - Changelog fragment: changelog.d/added/libvmaf-public-header-doc-comments-round2.md. - Rebase notes: docs/rebase-notes.md updated with a dedicated section. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * test(go): expand cmd/vmafx-{controller,server,mcp} coverage Add unit tests for the lowest-coverage Go cmd/ subpackages identified by the master-tip workflow audit (Section F). No behavior change. Coverage deltas (against origin/master tip bbcaa8d): cmd/vmafx-controller 18.6% -> 32.4% (+13.8 pp) cmd/vmafx-controller/nodes 80.7% -> 82.5% (+1.8 pp) cmd/vmafx-server 27.5% -> 47.9% (+20.4 pp) cmd/vmafx-mcp 3.5% -> 24.6% (+21.1 pp) New test files: - cmd/vmafx-controller/main_extra_test.go 405 method-not-allowed on /healthz, /readyz, /v1/score; 400 invalid-JSON body; 500 scorer-error mapping via a stub vmaf binary; runHTTP graceful shutdown bounded by GracefulShutdownTimeout; envOr default+override; version(). - cmd/vmafx-controller/nodes/registry_edge_test.go Get(unknown), distinct-IDs-for-same-name contract pin, Heartbeat updates JobsRunning + advances LastHeartbeat (reaper eviction predicate), concurrent Register/Heartbeat under -race, defensive-copy assertion on All(). - cmd/vmafx-server/main_extra_test.go Same shape as the controller HTTP server tests; pins the PR #300 bounded-timeout shutdown invariant. - cmd/vmafx-mcp/impl_test.go All arg helpers (strArg, intArg, floatArg, boolArg, hasArg); every pure helper (classifySourceResolution, modelResolutionClass, resolutionMismatchWarning, inferBackendFromPayload, inferBackendFromSym, stripModelExt, toFFmpegPixfmt, pickWorstFrames, floatFromAny, roundF, truncate); representative handler error paths (handleProbeBackend missing/unknown backend, handleDescribeModel missing name, handleVmafScore invalid path / zero dimensions, handleCompareModels empty list). Pins the errorResult().IsError == true invariant from project memory (MCP isError must be True so clients branch correctly). Drive-by fix: .gitignore anchored the Go binary-ignore rules with a leading slash so they only match the repo-root binaries, not any path component sharing the name. Without this, untracked files like cmd/vmafx-server/main_extra_test.go were silently ignored by `git add`. Verification: go test -race -cover ./cmd/vmafx-controller/... \ ./cmd/vmafx-server/... \ ./cmd/vmafx-mcp/... go vet ./... All green; no behavior change. The pre-existing cmd/vmafx-operator/internal/controller failure (kubebuilder envtest needs etcd binaries on PATH) is unrelated to this change and reproduces on a clean origin/master checkout. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * docs(state): reconcile 2 Open rows that cited CLOSED PRs (#214, #215) Two Open rows in docs/state.md cited PRs that were CLOSED-not-merged and flagged as follow-up by the PR #291 closing agent. Verified against master tip bbcaa8d and master state of the underlying issues: 1. T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 — migrated from Open to Recently closed (superseded). The conflict markers only existed on the unmerged scaffold branch tip 35a1fb6. PR #91 (merged 2026-05-29T09:37:48Z) landed ADR-0753 resolution-aware dispatch via the adm_cm_device() consumer without extending dispatch into filter1d_8(), so master never carried the build-failing scaffold variant. PR #214 (the planned conflict-marker cleanup) was CLOSED-not-merged 2026-05-30 when its base scaffold branch was abandoned. core/src/feature/cuda/ integer_vif_cuda.c::filter1d_8() on master uses the clean unconditional cuLaunchKernel paths. 2. T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 — kept Open but the dead PR #215 citation removed. The C++23 Wave 8 conversion of core/src/read_json_model.c is still pending on master (still a .c source per core/src/meson.build:1578); PR #215 was CLOSED-not-merged 2026-05-30. Owner field rewritten to "Owner-driven; pending fresh PR per ADR-0846 Wave 8". Scope-coordinated with DRAFT PR #291 (docs/state-md-drift-sync — already migrates the 3 Vulkan rows + T-LEGACY-RUNNER-ANSNR-BROKEN + T-LEGACY-RUNNER-STUB-MISSING). Row 203 (T-LEGACY-RUNNER-STUB-MISSING-2026-05-29) cites closed PRs #213 and #181 as OPEN but is left untouched here since PR #291 already rewrites it. Net Open count -1; total T-row count unchanged (153). No code changes — documentation cleanup only. Deliverables (ADR-0108): - no digest needed: state.md hygiene - no alternatives: only-one-way reconciliation - no rebase-sensitive invariants - Reproducer: `gh pr view 214 -R VMAFx/vmafx --json state,mergedAt` returns `{"state":"CLOSED","mergedAt":null}`; `grep -nE '^(<{7}|={7}|>{7})( |$)' core/src/feature/cuda/integer_vif_cuda.c` on master returns empty; `ls core/src/read_json_model.*` returns only `.c` and `.h`. - Changelog: changelog.d/changed/state-md-closed-pr-row-sweep.md - no rebase impact: docs only Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * chore(meta): README badge audit + Cargo / pyproject repo-metadata sweep Audit + backfill the fork's repo-metadata surface so cargo / pip / GitHub all advertise the canonical VMAFx/vmafx URLs: - README.md: add Rust CI + Go CI workflow badges (both workflows ship on master but were not surfaced). All five pre-existing workflow badges already point at VMAFx/vmafx and reference real, active, master-green workflows; verified via the Actions API. License, Conventional Commits, OpenSSF Scorecard, ko-fi badges already present. - Cargo.toml: add [workspace.package] with repository / homepage / documentation / license / authors. Both workspace members (bindings/rust/vmafx-sys, core/src/feature/rust/tad) switched to workspace-inherited metadata so URL drift is impossible across the Rust workspace. cargo metadata confirms both crates now expose the VMAFx/vmafx URLs. - pyproject.toml (root, ai/, tools/vmaf-tune, tools/vmaf-roi-score, tools/ensemble-training-kit, dev-llm/, mcp-server/vmaf-mcp/): add [project.urls] with Homepage / Repository / Documentation / Issues / Changelog. All seven fork-authored projects now ship the same URL block; the package indexes (PyPI / internal) get a consistent repository link. - deploy/helm/vmafx/Chart.yaml: already correct (home + sources already point at VMAFx/vmafx). No change needed. - changelog.d/fixed/ + docs/rebase-notes.md: deliverables. Coordination with PR #331 (rebrand sweep): #331 only touches the line-1 copyright header of two of the seven pyproject files; this PR adds a new [project.urls] block below — no merge conflict. Deep-dive deliverables (ADR-0108): - Research digest: no digest needed: trivial repo-metadata sweep. - Decision matrix: no alternatives: only-one-way fix (URLs must match the rebrand target). - AGENTS.md invariant: no rebase-sensitive invariants — fork-only metadata files, none mirror upstream Netflix. - Reproducer: `cargo metadata --no-deps --format-version 1 | jq` + `python3 -c "import tomllib; tomllib.loads(open('pyproject.toml','rb').read().decode())"`. - CHANGELOG fragment: changelog.d/fixed/readme-badges-metadata-audit.md. - Rebase note: added to docs/rebase-notes.md (impact: none, fork-only). * docs(adr): author ADR-0865 for ANSNR sunset (closes PR #38 ADR-0108 gap) PR #38 (merged 2026-05-28) removed `float_ansnr` from the C backend but cited `Parent ADR-0709` in its body — ADR-0709 is the Phase 4b distributed-platform umbrella and contains zero ANSNR content. PR #295 + PR #324 inherited the bad cite. No dedicated ANSNR-sunset ADR existed in tree. This change: - Authors `docs/adr/0865-ansnr-sunset-pre-vmaf-metric-drop.md` as the missing parent ADR, back-dated to 2026-05-28 (PR #38 merge date) so the dependency chain (ADR-0865 -> PR #38 -> ADR-0749 Python sunset) is consistent. - Documents the historical mis-cite in the new ADR's `## Notes` section so future readers landing on PR #38 can recover the trail. PR bodies on the remote are immutable merge-history and cannot be rewritten. - Adds the index fragment + `_order.txt` row; regenerates `docs/adr/README.md` via `scripts/docs/concat-adr-index.sh`. - Adds `docs/state.md` row (Updated note + Recently-closed entry). - Adds `docs/rebase-notes.md` entry documenting the rebase invariant (upstream still ships `ansnr` extractors; fork must keep deleting). - Adds `changelog.d/changed/ansnr-sunset-adr-authoring.md` fragment. In-tree audit confirmed zero `ADR-0709` references mis-cite ANSNR — all remaining tree-side `ADR-0709` cites correctly point at Phase 4b distributed-platform content. No tree-side citation fix-up required. Docs-only PR. No code changes. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * chore(bundle): add changelog fragment for doc-sweep bundle batch-1 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> Co-authored-by: Lusoris <lusoris@pm.me>
lusoris
added a commit
that referenced
this pull request
Jun 12, 2026
…CI) (#868) * fix(codeql): resolve HIGH-severity security-cpp-high alerts (23 sites) - cpp/integer-multiplication-cast-to-long (11): pre-cast one operand to size_t / double / ptrdiff_t before int*int multiplications in cambi.c, float_vif.c (log message), iqa/convolve.c (img_offset), moment.c, psnr.c, and vif_tools.c (four memcpy size expressions). Add stddef.h to convolve.c for ptrdiff_t. - cpp/incomplete-parity-check (3): change `% 2 == 1` to `% 2 != 0` in vif_tools.c (assert), svm.cpp (powi loop), pdjson.c (JSON object key/value alternation). The == 1 form is wrong for negative operands; != 0 is always correct. - cpp/wrong-type-format-argument (2): fix float_vif.c error log that printed size_t fields scaled_w/scaled_h with %d; change to %zu. - cpp/world-writable-file-creation (1): in vmaf.cpp replace bare fopen("wb") with open(O_WRONLY|O_CREAT|O_TRUNC, 0644)+fdopen() on POSIX so the created file is never world-writable independent of the caller's umask. Add <fcntl.h>. - cpp/path-injection (4): in test_output.c resolve the mkstemp-created path through realpath() immediately after creation, breaking the taint chain from getenv("TMPDIR") to the vmaf_write_output call site. - cpp/toctou-race-condition (2): skipped — both sites are in test cleanup (RMDIR after stat assertion). The stat result drives a test assertion, not a security-sensitive access decision; no atomic replacement of open() is applicable to rmdir. Reported as skipped. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(codeql): resolve security-python-and-ci CodeQL alerts Fixes 18 open CodeQL alerts across the Python and CI categories: - yaml.github-actions.security.run-shell-injection (#661): move github.event_name, github.base_ref, and github.event.before from inline ${{...}} interpolation to env: vars in the SYCL clang-tidy detect step of lint-and-format.yml. - python.lang.security.use-defused-xml-parse (#216, #217): replace xml.etree.ElementTree with defusedxml.ElementTree in feature_extractor.py and quality_runner.py; add defusedxml>=0.7.1 to python/pyproject.toml and python/requirements.txt. - py/undefined-export (#352, #353, #354, #616): restructure aiutils/__init__.py to do a conditional eager import of the parquet helpers so the names are defined when pyarrow is present, and only include them in __all__ when the import succeeded. - py/stack-trace-exposure (#178, #179, #585): log exception detail server-side and return a generic message to the HTTP client in http_transport.py _handle_score (invalid JSON, bad params, scorer error branches). - python.lang.security.audit.dangerous-subprocess-use-tainted-env-args (#227, #372): add shlex.quote() around user-supplied path arguments passed into shell strings in extract_ugc_features.py and test_bbb_e2e_v5_bug_cluster.py. - py/file-not-closed (#677, #678): replace bare open() calls with context managers in test_coverage_round3.py. - py/redundant-comparison (#427, #431): remove redundant assert not (x != y) lines that duplicate the preceding assert x == y. - py/equals-hash-mismatch (#182): convert RdPoint to frozen=True dataclass so __eq__ and __hash__ are generated consistently. - py/inheritance/signature-mismatch (#197): add result_dict=None default to EnsembleVmafQualityRunner._populate_result_dict so the signature is compatible with the base class. - py/multiple-definition (#201): drop redundant assignment to feature_found in feature_extractor.py wildcard discovery path. - py/str-format/surplus-named-argument (#204): remove unused dataset= kwarg from the format() call in routine.py. Skipped: python.lang.security.audit.insecure-file-permissions (#373) — the Unix socket at 0o660 is intentional (Go sidecar node must write to it and runs as the same UNIX group); tightening to 0o644 would break the IPC channel. Skipped: py/path-injection (#180, #181) — _validate_path() already resolves the path and checks it against an allowlist before any file operation; the data flow is secure and the CodeQL dataflow trace is a false positive on this allowlisted pattern. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Lusoris <lusoris@pm.me> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
24bb5daf89(post-merge-train sweep) across 38 filescore/path) side taken in every conflict; thelibvmaf/side from24bb5daf89discarded.github/codeql-config.yml,.semgrepignore,ai/src/aiutils/jsonl_utils.py,ai/src/vmaf_train/registry.py,core/AGENTS.md,core/test/test_hip_smoke.c, and 32docs/filesReproducer
Expected after merge:
cleanChecklist
core/side)changelog.d/fixed/pr50-residual-conflicts.md🤖 Generated with Claude Code