Skip to content

fix(p6): avoid target-word matches inside longer identifiers - #815

Draft
chrisknvidia wants to merge 2 commits into
mainfrom
feat/christopherk/p6-identifier-boundaries
Draft

chrisknvidia wants to merge 2 commits into
mainfrom
feat/christopherk/p6-identifier-boundaries

Conversation

@chrisknvidia

@chrisknvidia chrisknvidia commented Oct 10, 2026 •

Copy link
Copy Markdown
Collaborator

P6 reports HIGH from the truncated return PROMPT match inside return PROMPT_INJECTION_PATTERNS. Camelcase and other identifier continuations have the same problem.

Require complete terminal target nouns in P6, including across normalized text, declared-marker reconstruction, and overlapping scan windows. Keep genuine protected-prompt extraction detectable, including complete plural/configuration nouns and intentionally reconstructed requests. Preserve mapped source locations and use a bounded per-artifact provenance cache with the runner's directive ownership and runtime callback.

Related to #523. Ordinary full-word local return prompt provenance remains outside this focused change; this PR does not close the broader issue.

Validation:

  • Required Ruff lint and formatting scope (src/, tests/) and 142 focused tests pass.
  • RG: 1,423 independent actual-runner probes; TG: 210 probes, including cache eviction, deadlines, finding caps, and disclosure recall. A separate manual edge/security review found no additional actionable defect.
  • Installed baseline/fix wheels with identical 70 dependency versions: 24 JSON/SARIF scans per version pass, covering ASCII/Unicode identifiers, transformed disclosures, large ownership-window input, source locations, exit codes, and completeness.
  • Baseline creation/suppression and cross-version singular-target suppression pass; six singular control locations and match fingerprints remain stable. A fresh console CLI changes the identifier fixture from two P6 findings/risk 41 to zero/risk 0.
  • Broad local nonprovider test segments report 9,258 passes/one failure, 1,489 passes/one failure, and 2,247 passes/two failures. The batch-worker, real-CLI reporting and MCP initialization timeout failures also reproduce on pristine main. The FIFO-swap subprocess timeout remains unexplained: its isolated main test passed, its changed-head retry reported failure before reporting was interrupted during pytest temporary-directory cleanup, and separate five-second milestone controls time out during registry import on both versions before reaching the FIFO scan. These results are not a full-suite pass.
  • At commit 59f14e4966f3170b0b0d738d1de42e873efb5ce6, GitHub lint, DCO, OpenCode TypeScript and Docker smoke pass; the full unit job is still running.

Complete plural/configuration matches now include the whole target noun, so baselines keyed to formerly truncated match text may need regeneration. Singular complete-target baseline compatibility was verified separately.

This remains draft while full unit CI is pending and the required native Bugbot and Security Review passes are unavailable. The manual review and RG/TG do not substitute for those passes. No provider-backed model or hosted consumer pipeline validation has been performed.

Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Signed-off-by: Christopher Kevin <christopherk@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant