Skip to content

Vendored echidnabot: 4 Hypatia code_safety findings must be fixed upstream (baselined in #586) #588

Description

@hyperpolymath

Problem

PR #586 makes bots/echidnabot/ a pinned sync of hyperpolymath/echidnabot (drift gate: vendored-bot-drift.yml). The fleet copy can no longer be edited locally, but Hypatia scans it and reports four code_safety findings in vendored upstream code:

File (fleet path) Rule Assessment
bots/echidnabot/fuzz/fuzz_targets/fuzz_hmac.rs:29 unwrap_without_check (high) Hmac::new_from_slice on a constant key in a fuzz target; HMAC accepts any key length, so it cannot fail
bots/echidnabot/src/adapters/mod.rs:290 unwrap_without_check (high, 5x) test helper assert_child_reaped
bots/echidnabot/src/api/rate_limit.rs:54 expect_in_hot_path (medium) mutex-poisoning expect
bots/echidnabot/src/scheduler/job_queue.rs:216 expect_in_hot_path (medium) index from position() under the same lock

#586 adds them to .hypatia-baseline.json with expires_at and this issue as tracking_issue, so governance / Validate Hypatia Baseline and the Hypatia code-scanning context stop failing on code that must be fixed upstream.

Acceptance criteria

  • Each finding is fixed, or annotated in the way Hypatia accepts, in hyperpolymath/echidnabot (the canonical source).
  • bots/echidnabot/FLEET-SYNC.json is bumped to an upstream rev containing those fixes, via scripts/sync-vendored-bot.sh echidnabot --sync --rev <sha>.
  • The four baseline entries that cite this issue are removed from .hypatia-baseline.json, and governance / Validate Hypatia Baseline stays green without them.

Deferral issue under AGENTS.md §5c item 3, filed from #586.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions