fix(scanner): detect multiline unbounded retry loops#57
Open
rksharma-owg wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #21
Summary
multilinerule field and pass--multilineto ripgrep for those ruleswhile TrueLLM retry loops as a low-confidence warningbreak,timeout, andmax_retriesboundsProblem and root cause
P17.6 contained a dotall pattern, but the scanner still invoked ripgrep in line-oriented mode. As a result, the rule missed typical Python loops where
while Trueandchat(),complete(), orgenerate()are on separate lines. Its metadata also emittedfail/medium even though this deliberately heuristic rule is specified aswarn/low.The new rule-level flag keeps multiline scanning opt-in. A zero-width lookahead lets P17.6 inspect the loop body while pinning the finding to the
while Trueline.DSGAI mapping
Tests added
Validation
/tmp/dsgai-issue21-venv/bin/python -m pytest tests/test_runner.py -q -p no:cacheprovider— 28 passed, 1 skipped (the opt-in live OSV test)--checkcommands — all synchronizedunbounded_retry.py:5, statuswarn(scanner exit 1 is expected for fixture findings)yamllint, ShellCheck, Markdown link check,compileall, andgit diff --check— passedChecklist
AI assistance
AI assistance was used during the audit and test drafting. I reproduced the issue against the real CLI and independently reviewed and ran every submitted change.