From 412cbd51c6f4f3fd2c9111044330954903a9a6c3 Mon Sep 17 00:00:00 2001 From: soubarna Date: Mon, 5 Oct 2026 17:29:31 +0530 Subject: [PATCH] fix: triage semgrep SQL findings --- src/fenris/local_day.py | 4 ++-- src/fenris/pruning.py | 10 +++++----- src/fenris/store.py | 10 +++++----- 3 files changed, 12 insertions(+), 12 deletions(-) diff --git a/src/fenris/local_day.py b/src/fenris/local_day.py index 481a798..e42b509 100644 --- a/src/fenris/local_day.py +++ b/src/fenris/local_day.py @@ -394,7 +394,7 @@ def repair_legacy_local_day_evidence(conn: sqlite3.Connection) -> int: "bytes_written": row[2], "bytes_read": row[3], "segment_id": row[4], "local_tz": row[5], } - for row in conn.execute(sample_select) + for row in conn.execute(sample_select) # nosemgrep: sqlalchemy-execute-raw-query -- query text is built from constant fragments only; no external input ] for previous, current in pairwise(samples): start = previous["ts"] @@ -1018,7 +1018,7 @@ def query_local_day_summary( """ tz_filter = " AND tz_name = ?" if tz_name else "" params = (local_date, tz_name) if tz_name else (local_date,) - row = conn.execute( + row = conn.execute( # nosemgrep: sqlalchemy-execute-raw-query -- only constant fragments are concatenated; values are bound via ? placeholders "SELECT local_date, tz_name, tz_offset, utc_start, utc_end, " " bytes_written, bytes_read, coverage, sample_count, complete, " " activity_seconds, activity_intervals, activity_incomplete, " diff --git a/src/fenris/pruning.py b/src/fenris/pruning.py index 529c242..3d8278c 100644 --- a/src/fenris/pruning.py +++ b/src/fenris/pruning.py @@ -336,7 +336,7 @@ def prune_old_samples( if owns_transaction: conn.execute("BEGIN IMMEDIATE") else: - conn.execute(f"SAVEPOINT {savepoint}") + conn.execute(f"SAVEPOINT {savepoint}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- savepoint name is a function-local constant; SQLite cannot bind identifiers try: rows = _sample_rows(conn) @@ -344,7 +344,7 @@ def prune_old_samples( if owns_transaction: conn.commit() else: - conn.execute(f"RELEASE SAVEPOINT {savepoint}") + conn.execute(f"RELEASE SAVEPOINT {savepoint}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- savepoint name is a function-local constant; SQLite cannot bind identifiers return 0 newest_id = rows[-1][0] @@ -361,12 +361,12 @@ def prune_old_samples( if owns_transaction: conn.commit() else: - conn.execute(f"RELEASE SAVEPOINT {savepoint}") + conn.execute(f"RELEASE SAVEPOINT {savepoint}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- savepoint name is a function-local constant; SQLite cannot bind identifiers return len(expired) except Exception: if owns_transaction: conn.rollback() else: - conn.execute(f"ROLLBACK TO SAVEPOINT {savepoint}") - conn.execute(f"RELEASE SAVEPOINT {savepoint}") + conn.execute(f"ROLLBACK TO SAVEPOINT {savepoint}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- savepoint name is a function-local constant; SQLite cannot bind identifiers + conn.execute(f"RELEASE SAVEPOINT {savepoint}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- savepoint name is a function-local constant; SQLite cannot bind identifiers raise diff --git a/src/fenris/store.py b/src/fenris/store.py index 0576f2b..ae7d08d 100644 --- a/src/fenris/store.py +++ b/src/fenris/store.py @@ -60,7 +60,7 @@ def init_store(store_path: Path) -> sqlite3.Connection: if current_version == 0: # New database - create schema _create_schema(conn) - conn.execute(f"PRAGMA user_version={SCHEMA_VERSION}") + conn.execute(f"PRAGMA user_version={SCHEMA_VERSION}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- SCHEMA_VERSION is an int constant; PRAGMA cannot bind parameters conn.commit() elif current_version > SCHEMA_VERSION: # Unknown newer version - refuse @@ -311,7 +311,7 @@ def _apply_migrations(conn: sqlite3.Connection, current_version: int): conn.execute("BEGIN IMMEDIATE") try: migration(conn) - conn.execute(f"PRAGMA user_version={target_version}") + conn.execute(f"PRAGMA user_version={target_version}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- target_version is an int key of the static migrations map; PRAGMA cannot bind parameters conn.commit() except Exception: conn.rollback() @@ -336,7 +336,7 @@ def _migrate_1_to_2(conn: sqlite3.Connection) -> None: ).fetchall()} for column in ("unattributed_bytes_written", "unattributed_bytes_read"): if column not in cols: - conn.execute( + conn.execute( # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- column comes from a hardcoded tuple; DDL cannot bind identifiers f"ALTER TABLE day_aggregates ADD COLUMN {column} INTEGER DEFAULT 0" ) @@ -393,7 +393,7 @@ def _migrate_4_to_5(conn: sqlite3.Connection) -> None: ("last_sample_id", "INTEGER"), ): if column not in local_cols: - conn.execute( + conn.execute( # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- column and declaration come from a hardcoded tuple; DDL cannot bind identifiers f"ALTER TABLE local_days ADD COLUMN {column} {declaration}" ) _create_local_day_shared_evidence(conn) @@ -435,7 +435,7 @@ def migrate_to_latest(store_path: Path) -> int: # Version 0 means no schema — create fresh (issue #73) if current_version == 0: _create_schema(conn) - conn.execute(f"PRAGMA user_version={SCHEMA_VERSION}") + conn.execute(f"PRAGMA user_version={SCHEMA_VERSION}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- SCHEMA_VERSION is an int constant; PRAGMA cannot bind parameters conn.commit() conn.close() return SCHEMA_VERSION