refactor(security): resolve all 180 CodeQL alerts across Python and Go - #3
Merged
Merged
Conversation
- Replace bare except with specific exceptions in agent, panel, and CLI - Enforce integer bounds check on rawpaq network ports (0 <= port <= 65535) - Restrict file permission masks from 0755 to 0750 - Remove redundant imports and unused variables - Fix assertGreater in auth test suite
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Remediation of 180 CodeQL Security & Quality Alerts
This PR resolves all 180 CodeQL / GitHub Security static analysis alerts across Python backend components and the Go Hawal Core v2 engine.
Summary of Fixes:
Python Exception Handling (
py/empty-except,py/catch-base-exception- 146 alerts):except:and catch-allexcept BaseException:acrossapp/server.py,agent/agent.py,app/static/js/agent.py,bin/hawal,app/db.py,app/auth.py,app/config.py, andapp/geoip.pywith targeted, explicit exceptions (sqlite3.Error,json.JSONDecodeError,ConnectionError,OSError,socket.error, etc.).KeyboardInterrupt/SystemExitare not swallowed inappropriately.File Permissions (
py/overly-permissive-file- 13 alerts):agent/agent.py,app/static/js/agent.py, andapp/server.pyfrom world-accessible (0o755) to secure user/group accessible (0o750/0o640), eliminating CodeQL warnings while preserving system execution privileges.Go Core Conversions & Variable Scoping (
go/incorrect-integer-conversion,go/useless-assignment-to-local- 4 alerts):core/v2/carrier/rawpaq/raw_linux.go, validated port bounds (0 <= p <= 65535) and converted safely touint16to avoid integer truncation/overflow.core/v2/secure/handshaker.go, eliminated context variable shadowing and unused variable assignments.Code Cleanups & Assertions (
py/unused-import,py/repeated-import,py/imprecise-assert,py/unused-global-variable- 17 alerts):app/geoip.py,app/ping_tool.py,app/backhaul.py,app/hawal_engine.py,server.py, andagent/agent.py._VERSION_CACHEin-place to avoid unused global assignment.tests/test_auth.pyto useassertGreaterinstead ofassertTrue(a > b).bin/hawal-coreandapp/static/bin/hawal-core).Verification:
go test ./...incorepassed 100%.python3 -m unittest discover -s testspassed 100%.python3 -m py_compileacross all modified files passed with 0 errors.