Document analyzer boundaries and finish review leftovers#23
Merged
Conversation
State the Semgrep CE intrafile taint boundary and the process-group kill semantics in docs/analyzer.md, and write down the semgrep-core upgrade procedure (version const, CI pipx pin, CI version assertion) since the adapter rides a private core interface. Cache tool-binary digests in the adapter test helper so the integration suite stops re-hashing the 200 MiB core per request, and cover the tool_sha256 omission when no tool is configured.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
docs/analyzer.mdnow states the Semgrep CE boundary explicitly: taint is tracked within a single file, so flows crossing a file boundary produce no finding. Also documents the process-group kill on cancel (Kill analyzer process groups on deadline #22) and thesemgrep-coreupgrade procedure (semgrepCoreVersionconst,semgrep==CI pin, CI-versionassertion) since the adapter rides Semgrep's private core interface.semgrep-coreon every request (13.5s → 7.8s locally).TestExternalAnalyzerOmitsToolDigestWithoutTool: withoutROOM_ANALYZER_TOOL_FILE,tool_sha256is absent from the provider request (fails if theomitemptyor conditional population regresses).Test plan
go test ./...clean; integration suite green against realsemgrep-core1.139.0