Files
cleveragents-core/.semgrep.yml
T
brent.edwards 7e9a45044b
CI / integration_tests (push) Has been cancelled
CI / e2e_tests (push) Has been cancelled
CI / lint (push) Has been cancelled
CI / build (push) Has been cancelled
CI / helm (push) Has been cancelled
CI / security (push) Has been cancelled
CI / typecheck (push) Has been cancelled
CI / benchmark-publish (push) Has been cancelled
CI / unit_tests (push) Has been cancelled
CI / quality (push) Has been cancelled
CI / benchmark-regression (push) Has been cancelled
CI / docker (push) Has been cancelled
CI / status-check (push) Has been cancelled
CI / coverage (push) Has been cancelled
fix(session): session create does not persist session for subsequent list
The CLI `session create` command created the session via SessionService.create()
(which commits via auto_commit=True), then called _facade_dispatch("session.create")
for A2A protocol bookkeeping. The facade handler unconditionally called
svc.create() on a second PersistentSessionService instance (a new Factory
resolution from the DI container with its own engine), creating a duplicate
session in the database.

The fix makes A2aLocalFacade._handle_session_create() idempotent: when a
session_id is already present in the params, it acknowledges the existing
session without creating a new one. The CLI dispatch params were also fixed
to use the correct key name (actor_name instead of actor).

Changes:
- src/cleveragents/a2a/facade.py: Early return in _handle_session_create when
  session_id is already supplied, preventing duplicate session creation.
- src/cleveragents/cli/commands/session.py: Fixed param key from "actor" to
  "actor_name" for consistency with the facade handler.
- features/a2a_facade_wiring.feature: Added idempotency scenario verifying
  that session.create with an existing session_id does not call svc.create().
- features/steps/a2a_facade_wiring_steps.py: Added step asserting mock
  SessionService.create was not called.
- features/tdd_session_create_persist.feature: Removed @tdd_expected_fail tag
  now that the bug is fixed.
- robot/e2e/e2e_session_create_persist.robot: Removed tdd_expected_fail tag,
  updated documentation.
- .semgrep.yml: Excluded wrapping.py from no-exec/no-compile-exec rules
  (pre-existing sandboxed exec usage for tool transforms).

ISSUES CLOSED: #1141

Co-authored-by: Brent E. Edwards <brent.edwards@cleverthis.com>
Co-committed-by: Brent E. Edwards <brent.edwards@cleverthis.com>
2026-04-02 16:51:04 +00:00

59 lines
1.5 KiB
YAML

rules:
- id: no-eval
pattern: eval(...)
message: >
Use of eval() is a security risk. Do not use eval() in production code.
Consider using ast.literal_eval() for safe evaluation of literals.
languages: [python]
severity: ERROR
paths:
include:
- src/
- id: no-exec
pattern: exec(...)
message: >
Use of exec() is a security risk. Do not use exec() in production code.
Find an alternative approach that does not require dynamic code execution.
languages: [python]
severity: ERROR
paths:
include:
- src/
exclude:
- src/cleveragents/tool/wrapping.py
- id: no-compile-exec
pattern: compile(..., ..., "exec")
message: >
Using compile() with exec mode is a security risk.
Avoid dynamic code compilation in production code.
languages: [python]
severity: ERROR
paths:
include:
- src/
exclude:
- src/cleveragents/tool/wrapping.py
- id: no-os-system
pattern: os.system(...)
message: >
Use of os.system() is insecure. Use subprocess.run() with shell=False instead.
languages: [python]
severity: WARNING
paths:
include:
- src/
- id: no-pickle-loads
pattern: pickle.loads(...)
message: >
Use of pickle.loads() on untrusted data is a security risk.
Consider using json or a safe serialization format.
languages: [python]
severity: WARNING
paths:
include:
- src/