Skip to content

refactor(security): resolve all 180 CodeQL alerts across Python and Go - #3

Merged
dalroot merged 1 commit into
masterfrom
refactor/codeql-security-cleanup
Oct 4, 2026
Merged

dalroot merged 1 commit into
masterfrom
refactor/codeql-security-cleanup

Conversation

@dalroot

@dalroot dalroot commented Oct 4, 2026

Copy link
Copy Markdown
Owner

Remediation of 180 CodeQL Security & Quality Alerts

This PR resolves all 180 CodeQL / GitHub Security static analysis alerts across Python backend components and the Go Hawal Core v2 engine.

Summary of Fixes:

  1. Python Exception Handling (py/empty-except, py/catch-base-exception - 146 alerts):

    • Replaced bare except: and catch-all except BaseException: across app/server.py, agent/agent.py, app/static/js/agent.py, bin/hawal, app/db.py, app/auth.py, app/config.py, and app/geoip.py with targeted, explicit exceptions (sqlite3.Error, json.JSONDecodeError, ConnectionError, OSError, socket.error, etc.).
    • Ensured unhandled fatal errors like KeyboardInterrupt / SystemExit are not swallowed inappropriately.
  2. File Permissions (py/overly-permissive-file - 13 alerts):

    • Restricted file permissions in agent/agent.py, app/static/js/agent.py, and app/server.py from world-accessible (0o755) to secure user/group accessible (0o750 / 0o640), eliminating CodeQL warnings while preserving system execution privileges.
  3. Go Core Conversions & Variable Scoping (go/incorrect-integer-conversion, go/useless-assignment-to-local - 4 alerts):

    • In core/v2/carrier/rawpaq/raw_linux.go, validated port bounds (0 <= p <= 65535) and converted safely to uint16 to avoid integer truncation/overflow.
    • In core/v2/secure/handshaker.go, eliminated context variable shadowing and unused variable assignments.
  4. Code Cleanups & Assertions (py/unused-import, py/repeated-import, py/imprecise-assert, py/unused-global-variable - 17 alerts):

    • Removed unused and duplicate imports across app/geoip.py, app/ping_tool.py, app/backhaul.py, app/hawal_engine.py, server.py, and agent/agent.py.
    • Updated _VERSION_CACHE in-place to avoid unused global assignment.
    • Refactored tests/test_auth.py to use assertGreater instead of assertTrue(a > b).
    • Rebuilt Hawal Core binaries cleanly (bin/hawal-core and app/static/bin/hawal-core).

Verification:

  • go test ./... in core passed 100%.
  • python3 -m unittest discover -s tests passed 100%.
  • python3 -m py_compile across all modified files passed with 0 errors.

- Replace bare except with specific exceptions in agent, panel, and CLI
- Enforce integer bounds check on rawpaq network ports (0 <= port <= 65535)
- Restrict file permission masks from 0755 to 0750
- Remove redundant imports and unused variables
- Fix assertGreater in auth test suite
@dalroot
dalroot merged commit 30c7baa into master Oct 4, 2026
5 of 6 checks passed
@dalroot
dalroot deleted the refactor/codeql-security-cleanup branch October 4, 2026 21:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant