Repository navigation
fix: decode nested encodings symmetrically - #4123
Ricky Gummadi (Ricky-G) merged 2 commits into
Conversation
Gate ambiguous outer-layer decoding on an English gain or a printable base64/hex decode benefit, keeping Python and Rust aligned. Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
PR Review Summary
Verdict: AI review comments are untrusted advisory output. The summary reports workflow-generated completion status only, not model-authored pass/fail claims. |
MohammadHaroonAbuomar
left a comment
There was a problem hiding this comment.
- agent-governance-rust/agentmesh/src/normalize.rs:1 Both license-header checks fail because this file has lacked the two-line Microsoft MIT header since #2991 and the checks are diff-scoped; add the header and they go green.
Add the MIT header to the Rust normalization module and rename the non-printable regression tests for spelling checks. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com>
Added the requested copyright and license header to |
MohammadHaroonAbuomar
left a comment
There was a problem hiding this comment.
Approving at 3fcf324. The only changes since the verified 0cc316c are the license header on normalize.rs and the non_printable rename in both test names; both license-header checks and the spell check are green, and the fuzzing job still running is not required. The decoder change was verified in the previous round: all six wrapper-outside nesting forms decode with both tags in Python and Rust with no divergence, the printable-UTF-8 gate refuses binary and control-heavy payloads even when wrapped, ordinary text with percent escapes, entities, hex-looking words and JSON escapes is untouched, and the depth and ratio caps hold on large nested input.
* fix: decode nested encodings symmetrically Gate ambiguous outer-layer decoding on an English gain or a printable base64/hex decode benefit, keeping Python and Rust aligned. Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * fix: address normalize review feedback Add the MIT header to the Rust normalization module and rename the non-printable regression tests for spelling checks. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> --------- Signed-off-by: Ricky Gummadi <ricky.gummadi@outlook.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Signed-off-by: yuvrajsingh2428 <offcyuvi2428@gmail.com>
Summary
Restore symmetric nested-encoding normalization in Python and Rust. Percent-, Unicode-escape-, and HTML-entity-wrapped base64/hex payloads now decode fully and emit both transform tags.
Fixes #3502 and #3521.
Problem
The ambiguous outer-layer guard required an English-marker gain. When decoding revealed another encoded blob, both sides scored zero, leaving the six reported nesting forms verbatim with no transform metadata. PR #3503 was closed unmerged, so the defect remains on
main.Changes
agent-governance-python/agent-os/src/agent_os/normalize.pyagent-governance-python/agent-os/tests/test_normalize.pyagent-governance-rust/agentmesh/src/normalize.rsTesting
python -m pytest agent-governance-python/agent-os/tests/test_normalize.py -q— 23 passed.cargo test --manifest-path agent-governance-rust/agentmesh/Cargo.toml normalize— passed.python -m ruff check --select E,F,W --ignore E501 ...— passed.rustfmt --edition 2021 --check agent-governance-rust/agentmesh/src/normalize.rs— passed.cargo fmt --checkstill reports a pre-existing formatting difference inagentmesh/src/prompt_injection_embedding.rs; the changed module is formatted.