Skip to content

Vendored echidnabot: 4 Hypatia code_safety findings must be fixed upstream (baselined in #586) #588

Description

@hyperpolymath

Problem

PR #586 makes bots/echidnabot/ a pinned sync of hyperpolymath/echidnabot (drift gate: vendored-bot-drift.yml). The fleet copy can no longer be edited locally, but Hypatia scans it and reports four code_safety findings in vendored upstream code:

File (fleet path) Rule Assessment
bots/echidnabot/fuzz/fuzz_targets/fuzz_hmac.rs:29 unwrap_without_check (high) Hmac::new_from_slice on a constant key in a fuzz target; HMAC accepts any key length, so it cannot fail
bots/echidnabot/src/adapters/mod.rs:290 unwrap_without_check (high, 5x) test helper assert_child_reaped
bots/echidnabot/src/api/rate_limit.rs:54 expect_in_hot_path (medium) mutex-poisoning expect
bots/echidnabot/src/scheduler/job_queue.rs:216 expect_in_hot_path (medium) index from position() under the same lock

#586 adds them to .hypatia-baseline.json with expires_at and this issue as tracking_issue, so governance / Validate Hypatia Baseline and the Hypatia code-scanning context stop failing on code that must be fixed upstream.

Acceptance criteria

  • Each finding is fixed, or annotated in the way Hypatia accepts, in hyperpolymath/echidnabot (the canonical source).
  • bots/echidnabot/FLEET-SYNC.json is bumped to an upstream rev containing those fixes, via scripts/sync-vendored-bot.sh echidnabot --sync --rev <sha>.
  • The four baseline entries that cite this issue are removed from .hypatia-baseline.json, and governance / Validate Hypatia Baseline stays green without them.

Deferral issue under AGENTS.md §5c item 3, filed from #586.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions