phase 5
This commit is contained in:
Executable
+100
@@ -0,0 +1,100 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Phase 5 audit for cross-request/static state risks in site files."""
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
from dataclasses import asdict, dataclass
|
||||
from pathlib import Path
|
||||
|
||||
ROOT = Path(__file__).resolve().parents[2]
|
||||
SITE = ROOT / "site"
|
||||
|
||||
PATTERNS = [
|
||||
("static local/global", "static "),
|
||||
("once hook", "ONCE("),
|
||||
("init hook", "INIT("),
|
||||
("background task", "task_"),
|
||||
]
|
||||
|
||||
SKIP_PARTS = {".git", "tmp", "work", "bin", "pkg", "__pycache__"}
|
||||
|
||||
|
||||
@dataclass
|
||||
class Finding:
|
||||
path: str
|
||||
line: int
|
||||
kind: str
|
||||
text: str
|
||||
note: str
|
||||
|
||||
|
||||
def iter_files() -> list[Path]:
|
||||
result: list[Path] = []
|
||||
for path in SITE.rglob("*"):
|
||||
if not path.is_file():
|
||||
continue
|
||||
if any(part in SKIP_PARTS for part in path.parts):
|
||||
continue
|
||||
if path.suffix not in {".uce", ".h", ".txt"}:
|
||||
continue
|
||||
result.append(path)
|
||||
return sorted(result)
|
||||
|
||||
|
||||
def note_for(kind: str, text: str) -> str:
|
||||
if kind in {"once hook", "init hook"}:
|
||||
return "Audit behavior under per-request wasm workspaces; ONCE/INIT may need host-side cache semantics if used for cross-request state."
|
||||
if kind == "background task":
|
||||
return "Task APIs cross request lifetimes; verify they are host handles, not guest statics."
|
||||
return "Check whether state is request-local, immutable, or intentionally persistent; unit statics reset per wasm workspace."
|
||||
|
||||
|
||||
def scan() -> list[Finding]:
|
||||
findings: list[Finding] = []
|
||||
for path in iter_files():
|
||||
try:
|
||||
lines = path.read_text(encoding="utf-8").splitlines()
|
||||
except UnicodeDecodeError:
|
||||
continue
|
||||
for lineno, line in enumerate(lines, 1):
|
||||
stripped = line.strip()
|
||||
if stripped.startswith("//") or stripped.startswith("# "):
|
||||
continue
|
||||
for kind, needle in PATTERNS:
|
||||
if needle in line:
|
||||
findings.append(Finding(
|
||||
path=str(path.relative_to(ROOT)),
|
||||
line=lineno,
|
||||
kind=kind,
|
||||
text=stripped[:180],
|
||||
note=note_for(kind, stripped),
|
||||
))
|
||||
return findings
|
||||
|
||||
|
||||
def write_reports(findings: list[Finding], out_dir: Path) -> None:
|
||||
out_dir.mkdir(parents=True, exist_ok=True)
|
||||
(out_dir / "site-static-audit.json").write_text(json.dumps([asdict(f) for f in findings], indent=2) + "\n")
|
||||
lines = ["# Phase 5 site static-state audit", ""]
|
||||
if not findings:
|
||||
lines.append("No candidate cross-request/static-state patterns found.")
|
||||
else:
|
||||
lines.extend(["| file | line | kind | code | note |", "|---|---:|---|---|---|"])
|
||||
for f in findings:
|
||||
code = f.text.replace("|", "\\|")
|
||||
note = f.note.replace("|", "\\|")
|
||||
lines.append(f"| {f.path} | {f.line} | {f.kind} | `{code}` | {note} |")
|
||||
(out_dir / "site-static-audit.md").write_text("\n".join(lines) + "\n")
|
||||
|
||||
|
||||
def main() -> int:
|
||||
out_dir = Path("/tmp/uce/wasm-phase5")
|
||||
findings = scan()
|
||||
write_reports(findings, out_dir)
|
||||
print(f"Found {len(findings)} candidate static/cross-request patterns")
|
||||
print(f"wrote {out_dir / 'site-static-audit.json'} and {out_dir / 'site-static-audit.md'}")
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
raise SystemExit(main())
|
||||
Reference in New Issue
Block a user