Skip to content

fix: three high-quality bug fixes - #280

Open
Ricardo-M-L wants to merge 1 commit into
TencentCloudADP:mainfrom
Ricardo-M-L:fix/three-bugs
Open

fix: three high-quality bug fixes#280
Ricardo-M-L wants to merge 1 commit into
TencentCloudADP:mainfrom
Ricardo-M-L:fix/three-bugs

Conversation

@Ricardo-M-L

Copy link
Copy Markdown

This PR fixes: three high-quality bug fixes

1. Security: SQL injection in PhoenixUtils.get_trace_url_by_id
   Escape single quotes to prevent filter expression injection.

2. Security: path traversal in FileEditLocal._resolve_filepath
   Add work_dir boundary check before returning resolved path.

3. Logic: wrong variable in BaseBenchmark.preprocess_one
   Save and return processed_sample instead of original sample.

4. Logic: get_next_task returns str instead of Subtask
   Return None when no tasks available, update return type to Subtask | None.

5. Missing await: worker.run_streamed in _run_task
   Add await to fix TypeError when accessing result properties.

6. Missing await: Runner.run_streamed in _start_streaming
   Add await in both branches (trace and no-trace).

7. AssignerAgent.assign_task handles None from get_next_task
   Return None early when no task available.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant