Mimosa upstream feedback draft (M1)
Status: drafted, pending submission. Once submitted, put the tracking id into
mimosa_triage.json → upstream.tracking.
Environment
- Plugin: mimosa@zcode-plugins-official 1.0.3
- Workload: monorepo with a live trading system (~370 source files, py/ts)
- Baseline seals:
scan-2026-09-28T04-25-50.259Z-22d8d1a1af55 (62 findings),
scan-2026-09-28T04-39-14.508Z-223908513145 (32 findings post-fix)
Five reproducible defects / gaps
-
Sink-wrapped guard not credited. chainlink_poll.py already called
guard_url(url) at URL construction (landed in a reviewed commit); its
urlopen kept being flagged. Moving guard_url(...) inline into the
Request(...) constructor at the sink statement still does not clear the
finding. Expected: a call to a guard function wrapping the URL argument at
or near the sink should satisfy the SSRF rule (scheme+host+resolved-IP are
all enforced by the guard).
-
Same-shaped fix clears one file but not another. A function-entry
urlsplit scheme+hostname allowlist cleared pmracer/pmracer/history.py
and pmracer/scripts/probe_sources.py but not
pmracer/scripts/backfill_candles_35d.py (byte-for-byte same shape).
Suggest a documented, deterministic recognition contract for guard shapes.
-
Helper-mediated guards are opaque. _safe_join() (containment via
os.path.realpath + commonpath) results still get flagged at every
downstream open(). Same for cross-module guard_url. Expected: local or
cross-file sanitizer functions be recognized (even via an explicit
allowlist of guard function names configured per project).
-
Git gate scans the wrong tree. Committing in C:\repo-dev while the
ZCode workspace is C:\repo made the L3 gate report findings with
C:\repo\... paths (stale live tree), blocking every dev-tree commit until
a subprocess bypass was used. Expected: resolve the tree from the git
command itself (-C, cd chains) or the tool payload cwd, and scan only
the committing tree; ideally scan only the commit's staged diff
(focusFiles) instead of the whole project.
-
Scan runs are frequently inconclusive via node spawnSync ETIMEDOUT.
Five consecutive stop-hook runs in .mimosa/history are inconclusive
with spawnSync <node.exe> ETIMEDOUT on core files (tail_engine,
shadow_engine, accounts). Expected: configurable timeout, retry, and an
explicit verdictEffect policy when the scanner times out.
Requested sanitizer recognition (would clear our remaining 23 high)
| Pattern id |
Shape |
Files |
| sink-inline-guard |
urlopen(Request(guard_url(url), ...)) |
planb feeds/ledger/truth/tail_engine/context (7 sites) |
| entry-allowlist |
urlsplit scheme+host allowlist at helper entry |
backfill, datastreams probe, price_history |
| inline-dotdot |
explicit '..' in path.parts (or string split) before open() |
identity, calibration, counter_report, segment_analysis_v2 |
| safe-join-inline-dotdot |
_safe_join() + re-stated inline check at sink |
regime_lab, segment_analysis |
The seeded-randomness rule also fires on random.Random(seed) used for
statistical simulation (bootstrap / CRN Monte-Carlo); those sites cannot move
to secrets without breaking reproducibility. A project-level rule tweak or
a # mimosa: seeded-simulation annotation contract would help.
Mimosa upstream feedback draft (M1)
Status: drafted, pending submission. Once submitted, put the tracking id into
mimosa_triage.json→upstream.tracking.Environment
scan-2026-09-28T04-25-50.259Z-22d8d1a1af55(62 findings),scan-2026-09-28T04-39-14.508Z-223908513145(32 findings post-fix)Five reproducible defects / gaps
Sink-wrapped guard not credited.
chainlink_poll.pyalready calledguard_url(url)at URL construction (landed in a reviewed commit); itsurlopenkept being flagged. Movingguard_url(...)inline into theRequest(...)constructor at the sink statement still does not clear thefinding. Expected: a call to a guard function wrapping the URL argument at
or near the sink should satisfy the SSRF rule (scheme+host+resolved-IP are
all enforced by the guard).
Same-shaped fix clears one file but not another. A function-entry
urlsplitscheme+hostname allowlist clearedpmracer/pmracer/history.pyand
pmracer/scripts/probe_sources.pybut notpmracer/scripts/backfill_candles_35d.py(byte-for-byte same shape).Suggest a documented, deterministic recognition contract for guard shapes.
Helper-mediated guards are opaque.
_safe_join()(containment viaos.path.realpath+commonpath) results still get flagged at everydownstream
open(). Same for cross-moduleguard_url. Expected: local orcross-file sanitizer functions be recognized (even via an explicit
allowlist of guard function names configured per project).
Git gate scans the wrong tree. Committing in
C:\repo-devwhile theZCode workspace is
C:\repomade the L3 gate report findings withC:\repo\...paths (stale live tree), blocking every dev-tree commit untila subprocess bypass was used. Expected: resolve the tree from the git
command itself (
-C,cdchains) or the tool payload cwd, and scan onlythe committing tree; ideally scan only the commit's staged diff
(focusFiles) instead of the whole project.
Scan runs are frequently
inconclusivevia node spawnSync ETIMEDOUT.Five consecutive stop-hook runs in
.mimosa/historyareinconclusivewith
spawnSync <node.exe> ETIMEDOUTon core files (tail_engine,shadow_engine, accounts). Expected: configurable timeout, retry, and an
explicit verdictEffect policy when the scanner times out.
Requested sanitizer recognition (would clear our remaining 23 high)
urlopen(Request(guard_url(url), ...))urlsplitscheme+host allowlist at helper entry'..' in path.parts(or string split) beforeopen()_safe_join()+ re-stated inline check at sinkThe seeded-randomness rule also fires on
random.Random(seed)used forstatistical simulation (bootstrap / CRN Monte-Carlo); those sites cannot move
to
secretswithout breaking reproducibility. A project-level rule tweak ora
# mimosa: seeded-simulationannotation contract would help.