[setup] repo=/pruva/project-cache/repo [setup] vuln_commit=af435d9893d1352924a2f011a2eb04a997d8b978 fixed_commit=545a96c56d1b6a8dd3f4a16c9090d8a4648d1e43 [verify] checking patch presence... [verify] fixed checkout contains validate_custom_base_path validator: YES [verify] vulnerable checkout lacks validator (vulnerable): YES [build] installing vuln at af435d9893d1352924a2f011a2eb04a997d8b978 into /workspace/bundle/artifacts/venv_vuln [setup] repo=/pruva/project-cache/repo [setup] vuln_commit=af435d9893d1352924a2f011a2eb04a997d8b978 fixed_commit=545a96c56d1b6a8dd3f4a16c9090d8a4648d1e43 [verify] checking patch presence... [verify] fixed checkout contains validate_custom_base_path validator: YES [verify] vulnerable checkout lacks validator (vulnerable): YES [build] installing vuln at af435d9893d1352924a2f011a2eb04a997d8b978 into /workspace/bundle/artifacts/venv_vuln [build] vuln version: datamodel-codegen 0.69.0 [build] installing fixed at 545a96c56d1b6a8dd3f4a16c9090d8a4648d1e43 into /workspace/bundle/artifacts/venv_fixed [build] fixed version: datamodel-codegen 0.69.1.dev1+g545a96c56 [vuln] instance=inst1 generating schema with marker_text=DMCG_RCE_INST1 [vuln] instance=inst1 codegen exit=2 [vuln] instance=inst1 ERROR: no generated output [vuln] instance=inst2 generating schema with marker_text=DMCG_RCE_INST2 [vuln] instance=inst2 codegen exit=2 [vuln] instance=inst2 ERROR: no generated output [fixed] codegen exit=2 Error at schema path 'malicious_schema_fixed.json': Error: customBasePath must be a dotted Python identifier path: "pydantic.BaseModel,\nprint('DMCG_RCE_FIXED_SHOULD_NOT_RUN', file=open('/workspace/bundle/repro/run/marker_fixed','w'))" [fixed] output_exists=false marker_exists=false ===== RESULT ===== vuln_instances_ok=0 (inst1_fail=1 inst2_fail=1) fixed_rejected=1 (exit=2 output=false marker=false) [verdict] NOT CONFIRMED (vuln_ok=0 fixed_ok=1) [done] runtime_manifest.json written; confirmed=0 [setup] repo=/pruva/project-cache/repo [setup] vuln_commit=af435d9893d1352924a2f011a2eb04a997d8b978 fixed_commit=545a96c56d1b6a8dd3f4a16c9090d8a4648d1e43 [verify] checking patch presence... [verify] fixed checkout contains validate_custom_base_path validator: YES [verify] vulnerable checkout lacks validator (vulnerable): YES Preparing worktree (detached HEAD af435d98) HEAD is now at af435d98 Fix empty ("") property name dropping its alias (#3612) [build] installing vuln at af435d9893d1352924a2f011a2eb04a997d8b978 into /workspace/bundle/artifacts/venv_vuln (worktree=/workspace/bundle/artifacts/worktrees/vuln) [build] vuln version: datamodel-codegen 0.69.0 Preparing worktree (detached HEAD 545a96c5) HEAD is now at 545a96c5 Merge commit from fork [build] installing fixed at 545a96c56d1b6a8dd3f4a16c9090d8a4648d1e43 into /workspace/bundle/artifacts/venv_fixed (worktree=/workspace/bundle/artifacts/worktrees/fixed) [build] fixed version: datamodel-codegen 0.69.1.dev1+g545a96c56 [vuln] instance=inst1 generating schema with marker_text=DMCG_RCE_INST1 [vuln] instance=inst1 codegen exit=0 [vuln] instance=inst1 import exit=1 [vuln] instance=inst1 MARKER WRITTEN: 'DMCG_RCE_INST1' at /workspace/bundle/repro/run/marker_inst1 [vuln] instance=inst2 generating schema with marker_text=DMCG_RCE_INST2 [vuln] instance=inst2 codegen exit=0 [vuln] instance=inst2 import exit=1 [vuln] instance=inst2 MARKER WRITTEN: 'DMCG_RCE_INST2' at /workspace/bundle/repro/run/marker_inst2 [fixed] codegen exit=2 Error at schema path 'malicious_schema_fixed.json': Error: customBasePath must be a dotted Python identifier path: "pydantic.BaseModel,\nprint('DMCG_RCE_FIXED_SHOULD_NOT_RUN', file=open('/workspace/bundle/repro/run/marker_fixed','w'))" [fixed] output_exists=false marker_exists=false ===== RESULT ===== vuln_instances_ok=1 (inst1_fail=0 inst2_fail=0) fixed_rejected=1 (exit=2 output=false marker=false) [verdict] CONFIRMED: code injection via customBasePath produces attacker-controlled code execution on import; fixed build rejects the schema. [done] runtime_manifest.json written; confirmed=1 [setup] repo=/pruva/project-cache/repo [setup] vuln_commit=af435d9893d1352924a2f011a2eb04a997d8b978 fixed_commit=545a96c56d1b6a8dd3f4a16c9090d8a4648d1e43 [verify] checking patch presence... [verify] fixed checkout contains validate_custom_base_path validator: YES [verify] vulnerable checkout lacks validator (vulnerable): YES Preparing worktree (detached HEAD af435d98) HEAD is now at af435d98 Fix empty ("") property name dropping its alias (#3612) [build] installing vuln at af435d9893d1352924a2f011a2eb04a997d8b978 into /workspace/bundle/artifacts/venv_vuln (worktree=/workspace/bundle/artifacts/worktrees/vuln) [build] vuln version: datamodel-codegen 0.69.0 Preparing worktree (detached HEAD 545a96c5) HEAD is now at 545a96c5 Merge commit from fork [build] installing fixed at 545a96c56d1b6a8dd3f4a16c9090d8a4648d1e43 into /workspace/bundle/artifacts/venv_fixed (worktree=/workspace/bundle/artifacts/worktrees/fixed) [build] fixed version: datamodel-codegen 0.69.1.dev1+g545a96c56 [vuln] instance=inst1 generating schema with marker_text=DMCG_RCE_INST1 [vuln] instance=inst1 codegen exit=0 [vuln] instance=inst1 import exit=1 [vuln] instance=inst1 MARKER WRITTEN: 'DMCG_RCE_INST1' at /workspace/bundle/repro/run/marker_inst1 [vuln] instance=inst2 generating schema with marker_text=DMCG_RCE_INST2 [vuln] instance=inst2 codegen exit=0 [vuln] instance=inst2 import exit=1 [vuln] instance=inst2 MARKER WRITTEN: 'DMCG_RCE_INST2' at /workspace/bundle/repro/run/marker_inst2 [fixed] codegen exit=2 Error at schema path 'malicious_schema_fixed.json': Error: customBasePath must be a dotted Python identifier path: "pydantic.BaseModel,\nprint('DMCG_RCE_FIXED_SHOULD_NOT_RUN', file=open('/workspace/bundle/repro/run/marker_fixed','w'))" [fixed] output_exists=false marker_exists=false ===== RESULT ===== vuln_instances_ok=1 (inst1_fail=0 inst2_fail=0) fixed_rejected=1 (exit=2 output=false marker=false) [verdict] CONFIRMED: code injection via customBasePath produces attacker-controlled code execution on import; fixed build rejects the schema. [done] runtime_manifest.json written; confirmed=1