Skip to content

fix(import): tag synced chunk sources as taint:external_sync - #247

Closed
CodeGhost21 wants to merge 1 commit into
tinyhumansai:mainfrom
CodeGhost21:fix/import-chunk-taint
Closed

CodeGhost21 wants to merge 1 commit into
tinyhumansai:mainfrom
CodeGhost21:fix/import-chunk-taint

Conversation

@CodeGhost21

@CodeGhost21 CodeGhost21 commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The v1 importer tagged only memory_docs rows with taint:external_sync (#201), because v1's chunk tier kept no taint. But the chunk store holds most synced content: a Gmail sync files every message there under the owner gmail-sync:<connection>. In v2 those chunks share one store with the user's own memory, so they arrived indistinguishable from it.

This decides from each chunk's owner instead. A chunk source is tagged taint:external_sync unless every chunk's owner is one the host writes itself: cron, cron:<id>, or the archivist's session key (a JSON object with a thread_id). Connector owners (gmail-sync:…, slack:…), an agent's own label, and a blank owner are all external, failing closed as the memory_docs decode does. A chunk store without the owner column gets no tag.

Found in an internal dry run for tinyhumansai/openhuman#7005. A real v1 store imported 532 Gmail chunk sources into hosted CortexDB with no external tag, while the 500 matching memory_docs rows were tagged.

Related issue

Part of tinyhumansai/openhuman#7005 (taint and provenance criterion). Follows #201.

API or behavior changes

Behavior: imported chunk sources with a non-host owner now carry taint:external_sync in meta.tags. No public API change (ChunkStore gains a crate-private owner flag). Not breaking.

Validation

Commands actually run, with their outcome:

  • cargo fmt --all -- --check: clean
  • cargo clippy --all-targets --all-features -- -D warnings: clean
  • cargo build --all-targets --all-features: ok
  • cargo test --all-features: all suites pass, 0 failures
  • RUSTDOCFLAGS="-D warnings" cargo doc --no-deps --all-features: ok

Tests

New in tests/legacy_import.rs:

  • chunk_sources_a_connector_synced_are_tagged_external: gmail-sync/slack owners are tagged; cron, cron:<id> and the JSON session key are not.
  • a_chunk_owner_the_host_does_not_write_fails_closed: a source mixing host and synced chunks, a blank owner, an arbitrary label, the look-alike cronjob, and JSON without thread_id are all tagged.
  • a_chunk_store_without_the_owner_column_gets_no_taint.

The first two fail on main and pass with the change. The fixture helper chunk() now writes the real host owner cron instead of the placeholder me, so existing chunk tests keep their meaning. Added owned_chunk() for tests that set the owner.

Documentation

src/import/README.md (Taint section), the import module docs, the chunks section docs and the EXTERNAL_SYNC_TAG rustdoc now describe the chunk rule and why v2 departs from v1 here.

Checklist

  • The change is focused on one logical change
  • No new #[allow(...)], #[ignore], or relaxed lints
  • No secrets, tokens, or .env contents in the diff or the description

Summary by CodeRabbit

  • New Features
    • Imported chunk sources are now marked as externally synced when they include content owned by a connector or another non-host source. Host-owned sources remain unmarked.
    • External-source marking applies across the entire source if any chunk has a non-host owner.
    • Chunk stores without ownership information continue to import without an external-sync mark.
    • Externally synced content is excluded from v1 external-effect tool decisions.

v1's chunk tier kept no taint, so the importer tagged only memory_docs rows
with taint:external_sync. But the chunk store holds most synced content: a
Gmail sync files every message there under the owner gmail-sync:<connection>.
In v2 those chunks share one store with the user's own memory, and arrived
indistinguishable from it.

Decide from each chunk's owner instead: a source is external unless every
chunk's owner is one the host writes itself (cron, cron:<id>, or the
archivist's JSON session key with a thread_id). Anything else, including a
blank owner, fails closed as the memory_docs decode does. A store without the
owner column gets no tag.
@tinysweeper

tinysweeper Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 6 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Changes requested
Priority: high
Reviewed head: 82054f3957a8
Updated: 1791528393 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 4 Active findings 6
Tests 2 Noted findings 0
Documentation 1 Resolved findings 0
Configuration 0 Pending checks/questions 0

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

  • high · critique · Reject empty host-owner identifiers — This treats malformed owners such as `cron:`, `cron: `, `{"thread_id":""}`, and `{"thread_id":" "}` as host-owned. The surrounding contract says anything other than a valid `cron:< (crates/tinymemory\-integrations/src/import/sections/chunks\.rs:222)
  • medium · critique · Add regression tests for ownership-based tainting — This introduces new behavior without tests covering the failure paths: a store with the `owner` column containing a non-host owner, a source mixing host and external owners, and a (crates/tinymemory\-integrations/src/import/sections/chunks\.rs:131)
  • medium · critique · Insert the requested owner into the test fixture — `owned_chunk` currently inserts the literal owner `cron` rather than its `owner` argument. Consequently this row is stored as host-owned even though the test expects it to represen (crates/tinymemory\-integrations/tests/legacy\_import\.rs:891)
  • medium · critique · Make the mixed-owner fixture actually mixed — Both calls ultimately insert `owner = 'cron'`, because the helper ignores its `owner` parameter. The purported mixed source therefore contains no synced chunk, so this test cannot (crates/tinymemory\-integrations/tests/legacy\_import\.rs:926)
  • medium · security · Require a non-empty cron owner identifier — `starts_with("cron:")` accepts `cron:` with no identifier, classifying that malformed or externally supplied owner as host-owned. Such a chunk source will avoid `taint:external_syn (crates/tinymemory\-integrations/src/import/sections/chunks\.rs:222)
  • medium · e2e · Cover the new chunk taint tagging with an end-to-end run — This new tagging decides which imported content is treated as externally synced, which downstream keeps out of external-effect tool decisions. The new tests in tests/legacy_import. (crates/tinymemory\-integrations/src/import/sections/chunks\.rs:131)

Before merge

  • Address Reject empty host-owner identifiers (crates/tinymemory\-integrations/src/import/sections/chunks\.rs).
Agent review details

critique

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 7 files; 5 findings. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: crates/tinymemory\-integrations/src/import/sections/chunks\.rs — Reject empty host-owner identifiers
  • Evidence: crates/tinymemory\-integrations/src/import/sections/chunks\.rs — Add regression tests for ownership-based tainting
  • Evidence: crates/tinymemory\-integrations/tests/legacy\_import\.rs — Insert the requested owner into the test fixture
  • Evidence: crates/tinymemory\-integrations/tests/legacy\_import\.rs — Make the mixed-owner fixture actually mixed

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 6 files; 1 finding. 1 file was not security-reviewed: crates/tinymemory-integrations/src/import/README.md (prose or tabular data). (1 observation(s) grouped into shared inline comments) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: crates/tinymemory\-integrations/src/import/sections/chunks\.rs — Require a non-empty cron owner identifier

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The change tags legacy chunk sources `taint:external_sync` when any chunk's `owner` is not one the host writes, failing closed on blank, connector, agent-label and non-session JSON owners, and skips stores without the `owner` column. The new tests exercise each of those branches against real legacy databases — connector sync, `cron`/`cron:<id>`, session-key JSON, mixed sources, blank and label owners, and the missing column — and each would fail if the classification regressed. Docs and module comments were updated to match. The change looks sound and safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The description accurately matches the diff: chunk sources now carry `taint:external_sync` unless every chunk's owner is `cron`, `cron:<id>`, or a JSON session key with a `thread_id`, stores without the `owner` column get no tag, and tests plus docs cover each rule as stated. The change looks sound and safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

e2e

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The change adds `taint:external_sync` tagging for chunk sources based on the `owner` column, decided host-side during legacy import. The repository's e2e harness (integration/cortexdb) contains nothing that imports a legacy workspace and observes the tag, and no e2e workflow ran; coverage is entirely the crate-level integration tests in tests/legacy_import.rs, which exercise the importer directly rather than a running system. The behaviour has an external surface (the tag on imported items, which gates external-effect tool decisions) and no end-to-end test drives it. (1 observation(s) grouped into shared inline comments) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: crates/tinymemory\-integrations/src/import/sections/chunks\.rs — Cover the new chunk taint tagging with an end-to-end run
Evidence and run details
  • Models: gpt-5.6-luna, glm-5.3-flash
  • Spend: $0.013321
  • Tokens: 305163 input · 17209 output · 36956 cached · 0 embedding
Head State Pass summary
82054f3957a8 changes requested 6 active finding(s), 0 resolved finding(s) (at 1791528393)

tinysweeper 0.1.0

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: aba4af14-f37b-4858-a267-a78335b55ae0
📥 Commits

Reviewing files that changed from the base of the PR and between fc4c2b0 and 82054f3.

📒 Files selected for processing (7)
  • crates/tinymemory-integrations/src/import/README.md
  • crates/tinymemory-integrations/src/import/mod.rs
  • crates/tinymemory-integrations/src/import/sections/chunks.rs
  • crates/tinymemory-integrations/src/import/sections/memory_docs.rs
  • crates/tinymemory-integrations/src/import/workspace/schema.rs
  • crates/tinymemory-integrations/tests/legacy_import.rs
  • crates/tinymemory-integrations/tests/support/mod.rs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Chunk imports now read chunk owners when the store has an owner column. The importer tags a source as externally synced when any chunk in that source has an owner that is not recognized as host-owned. Documentation and tests describe and cover this behavior.

Changes

Chunk Owner Tagging

Layer / File(s) Summary
Owner detection and source tagging
crates/tinymemory-integrations/src/import/workspace/schema.rs, crates/tinymemory-integrations/src/import/sections/chunks.rs, crates/tinymemory-integrations/src/import/mod.rs, crates/tinymemory-integrations/src/import/sections/memory_docs.rs, crates/tinymemory-integrations/src/import/README.md
ChunkStore records whether the owner column exists. The importer reads owners and adds EXTERNAL_SYNC_TAG to a source if any chunk owner is not cron, starts with cron:, or is a JSON object with a string thread_id. Stores without an owner column are not tagged by this check.
Ownership test coverage
crates/tinymemory-integrations/tests/support/mod.rs, crates/tinymemory-integrations/tests/legacy_import.rs
Test helpers can insert chunks with explicit owners. Import tests cover connector owners, host owners, blank and unrecognized owners, source-level tagging, and stores without an owner column.

Priority: ⬆️ High

Estimated code review effort: 2 (Simple) | ~15 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant ChunkStore
  participant ChunkQuery
  participant OwnerClassifier as is_host_owner
  participant SourceItem as source_item
  ChunkStore->>ChunkQuery: Provide owner-column availability
  ChunkQuery->>OwnerClassifier: Supply each chunk owner
  OwnerClassifier-->>SourceItem: Return host-owner classification
  SourceItem->>SourceItem: Add EXTERNAL_SYNC_TAG when any owner is non-host
Loading

Suggested reviewers: m3ga-mind

Merge Risk

Merge Risk: ⚪ Minimal · up to 82054

Chunk sources from non-host owners are now tagged as externally synced, and stores without an owner column are unchanged. No merge-blocking risk was found.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 82054

The change adds external-content labels without removing existing labels. No introduced security regression was established. However, the ownership conventions and downstream enforcement remain unverified, and upgrading does not automatically relabel previously imported content.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The demonstrated scope is imported source items from the selected legacy workspace, including profile-specific source identities, persisted into the supplied destination engine. Downstream tool or external-effect exposure depends on host policy not established by the available source.

Trust Boundaries and Controls

  • inferred — Legacy owner metadata is now a provenance-control input. If an external writer could supply a host-shaped owner, that source would avoid the new automatic tag. Producer authority and downstream interpretation of tag absence remain unverified. The base also lacked automatic tagging for that content, so this conditional path does not establish introduced or worsened exposure.

Resilience and Maintainability Implications

  • observed — Resume correctness assumes the legacy store has not changed between runs. Checkpoints are cursors rather than provenance-version markers; they do not independently coordinate concurrent legacy mutation or reclassify acknowledged items after an upgrade.

Hardening Proposals

  • proposed — Establish a producer-to-consumer provenance contract that reserves host owner forms, validates their identifiers, and defines conservative treatment of unavailable provenance. Confirm downstream policy does not equate missing tags with authenticated host origin.
  • proposed — If rollout must remediate prior imports, use explicit reconciliation by stable legacy source identity, including cleanup of older untagged copies, rather than relying on checkpoint resume or fingerprint-based replay.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the main change: tagging synced chunk sources with taint:external_sync.
Docstring Coverage Passed Docstring coverage is 92.86% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 14 functions across 6 files. (1 skipped: 1 …
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
⚔️ Resolve merge conflicts 💡
  • Resolve merge conflict in branch fix/import-chunk-taint
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit checks each chunk in line
“Is cron the owner? Then it’s fine.”
A connector tag is noted with care
The source gets marked when outsiders are there
Blank names join the same review
The tests hop through the cases too
Then off I go, with carrots in view

Comment @coderabbitai help to get the list of available commands.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 1 lane(s) blocking, worst finding is high.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0133 · 305,163 in / 17,209 out · 36,956 cached (12%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0076 · 174,675 in / 8,716 out  · 20,855 cached (12%) · gpt-5.6-luna, glm-5.3-flash
security:    $0.0054 · 96,311 in  / 5,852 out  · 14,309 cached (15%) · gpt-5.6-luna
tests:       $0.0001 · 8,502 in   / 346 out    · 64 cached (1%)      · glm-5.3-flash
description: $0.0001 · 8,558 in   / 163 out    · 1,536 cached (18%)  · glm-5.3-flash
e2e:         $0.0001 · 9,200 in   / 599 out    · 64 cached (1%)      · glm-5.3-flash

let Some(owner) = owner.map(str::trim).filter(|owner| !owner.is_empty()) else {
return false;
};
if owner == "cron" || owner.starts_with("cron:") {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique confident

Reject empty host-owner identifiers

This treats malformed owners such as cron:, cron: , {"thread_id":""}, and {"thread_id":" "} as host-owned. The surrounding contract says anything other than a valid cron:<id> or archivist session key is external, so a source with one of these owners will omit taint:external_sync and can be treated as trusted despite not having a valid host owner. Require a nonblank suffix and a nonblank thread_id before accepting these forms.


Additional security observation

priority medium confident

Require a non-empty cron owner identifier

[RULE] insufficient-input-validation

starts_with("cron:") accepts cron: with no identifier, classifying that malformed or externally supplied owner as host-owned. Such a chunk source will avoid taint:external_sync, allowing untrusted content to bypass the repository's external-content safeguards. Require the suffix after cron: to be non-empty (and preferably non-whitespace).

Suggested change for this observation (reference only)

if owner == "cron"
        || owner
            .strip_prefix("cron:")
            .is_some_and(|id| !id.trim().is_empty())
    {

[RULE] fail-closed-validation ·

}
}
push_unique(&mut tags, format!("source_kind:{}", source.source_kind));
if store.owner

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Add regression tests for ownership-based tainting

This introduces new behavior without tests covering the failure paths: a store with the owner column containing a non-host owner, a source mixing host and external owners, and a store without the column. The repository rules require tests for every behavior change and coverage of failure paths; add deterministic regression tests in the prescribed test location.


Additional e2e observation

priority medium likely

Cover the new chunk taint tagging with an end-to-end run

[RULE] e2e-uncovered

This new tagging decides which imported content is treated as externally synced, which downstream keeps out of external-effect tool decisions. The new tests in tests/legacy_import.rs call LegacyWorkspace::open directly against fixture SQLite files; they are importer-level tests, not the running system. The e2e harness (integration/cortexdb, mock_inference.py) never imports a legacy workspace and never observes taint:external_sync on a chunk-sourced item, and no e2e workflow triggered for this head. An end-to-end test would have to import a real legacy workspace containing a gmail-sync-owned chunk store and observe through the running system that the resulting memory is excluded from an external-effect tool decision. The two lexical candidates (no-hyde-multihop.env's comment mentioning 'document', bitemporal-enforce.env's comment mentioning 'source') are unrelated comments, not coverage.

[RULE] missing-tests ·

"gmail-sync:ca_1",
);
owned_chunk(&chunks, "k2", "document", "gmail:msg", 0, "gmail-sync:ca_1");
owned_chunk(&chunks, "k3", "chat", "slack:c1", 0, "slack:conn");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Insert the requested owner into the test fixture

owned_chunk currently inserts the literal owner cron rather than its owner argument. Consequently this row is stored as host-owned even though the test expects it to represent a Slack connector, and the assertions do not test the behavior described by the test. Update the fixture helper or construct these rows with the intended owner before relying on these assertions.

[RULE] invalid-test-fixture ·

let dir = tempfile::tempdir().unwrap();
let chunks = chunk_store(dir.path());
// One synced chunk taints the whole source.
owned_chunk(&chunks, "k1", "chat", "mixed", 0, "cron");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Make the mixed-owner fixture actually mixed

Both calls ultimately insert owner = 'cron', because the helper ignores its owner parameter. The purported mixed source therefore contains no synced chunk, so this test cannot verify that one external chunk taints the entire source and may fail once the owner-sensitive import behavior is correct.

[RULE] invalid-test-fixture ·

@tinysweeper tinysweeper Bot added the priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition. label Oct 9, 2026
@CodeGhost21

Copy link
Copy Markdown
Contributor Author

Closing as superseded by #246, which merged while this was open.

This PR came from an internal dry run for tinyhumansai/openhuman#7005: a real v1 store imported 532 Gmail chunk sources (gmail-sync: owners) with no taint:external_sync tag. #246's skip_connector_syncs takes the other route and leaves connector content out of the import entirely. Checked against the same store, its chunk rules match all 532 of those sources and keep the one internal chat source. Once tinyhumansai/openhuman#7148 turns the option on, the untagged-sync gap no longer exists, and tagging only non-connector chunks would contradict #246's choice not to rely on taint.

On the review: the cron: / {"thread_id":""} finding was valid. The owned_chunk findings were not (it binds ?4 to its owner argument, and the new tests failed on main). Moot now in any case.

@CodeGhost21 CodeGhost21 closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant