fix: triage semgrep SQL findings
This commit is contained in:
@@ -394,7 +394,7 @@ def repair_legacy_local_day_evidence(conn: sqlite3.Connection) -> int:
|
|||||||
"bytes_written": row[2], "bytes_read": row[3],
|
"bytes_written": row[2], "bytes_read": row[3],
|
||||||
"segment_id": row[4], "local_tz": row[5],
|
"segment_id": row[4], "local_tz": row[5],
|
||||||
}
|
}
|
||||||
for row in conn.execute(sample_select)
|
for row in conn.execute(sample_select) # nosemgrep: sqlalchemy-execute-raw-query -- query text is built from constant fragments only; no external input
|
||||||
]
|
]
|
||||||
for previous, current in pairwise(samples):
|
for previous, current in pairwise(samples):
|
||||||
start = previous["ts"]
|
start = previous["ts"]
|
||||||
@@ -1018,7 +1018,7 @@ def query_local_day_summary(
|
|||||||
"""
|
"""
|
||||||
tz_filter = " AND tz_name = ?" if tz_name else ""
|
tz_filter = " AND tz_name = ?" if tz_name else ""
|
||||||
params = (local_date, tz_name) if tz_name else (local_date,)
|
params = (local_date, tz_name) if tz_name else (local_date,)
|
||||||
row = conn.execute(
|
row = conn.execute( # nosemgrep: sqlalchemy-execute-raw-query -- only constant fragments are concatenated; values are bound via ? placeholders
|
||||||
"SELECT local_date, tz_name, tz_offset, utc_start, utc_end, "
|
"SELECT local_date, tz_name, tz_offset, utc_start, utc_end, "
|
||||||
" bytes_written, bytes_read, coverage, sample_count, complete, "
|
" bytes_written, bytes_read, coverage, sample_count, complete, "
|
||||||
" activity_seconds, activity_intervals, activity_incomplete, "
|
" activity_seconds, activity_intervals, activity_incomplete, "
|
||||||
|
|||||||
@@ -336,7 +336,7 @@ def prune_old_samples(
|
|||||||
if owns_transaction:
|
if owns_transaction:
|
||||||
conn.execute("BEGIN IMMEDIATE")
|
conn.execute("BEGIN IMMEDIATE")
|
||||||
else:
|
else:
|
||||||
conn.execute(f"SAVEPOINT {savepoint}")
|
conn.execute(f"SAVEPOINT {savepoint}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- savepoint name is a function-local constant; SQLite cannot bind identifiers
|
||||||
|
|
||||||
try:
|
try:
|
||||||
rows = _sample_rows(conn)
|
rows = _sample_rows(conn)
|
||||||
@@ -344,7 +344,7 @@ def prune_old_samples(
|
|||||||
if owns_transaction:
|
if owns_transaction:
|
||||||
conn.commit()
|
conn.commit()
|
||||||
else:
|
else:
|
||||||
conn.execute(f"RELEASE SAVEPOINT {savepoint}")
|
conn.execute(f"RELEASE SAVEPOINT {savepoint}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- savepoint name is a function-local constant; SQLite cannot bind identifiers
|
||||||
return 0
|
return 0
|
||||||
|
|
||||||
newest_id = rows[-1][0]
|
newest_id = rows[-1][0]
|
||||||
@@ -361,12 +361,12 @@ def prune_old_samples(
|
|||||||
if owns_transaction:
|
if owns_transaction:
|
||||||
conn.commit()
|
conn.commit()
|
||||||
else:
|
else:
|
||||||
conn.execute(f"RELEASE SAVEPOINT {savepoint}")
|
conn.execute(f"RELEASE SAVEPOINT {savepoint}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- savepoint name is a function-local constant; SQLite cannot bind identifiers
|
||||||
return len(expired)
|
return len(expired)
|
||||||
except Exception:
|
except Exception:
|
||||||
if owns_transaction:
|
if owns_transaction:
|
||||||
conn.rollback()
|
conn.rollback()
|
||||||
else:
|
else:
|
||||||
conn.execute(f"ROLLBACK TO SAVEPOINT {savepoint}")
|
conn.execute(f"ROLLBACK TO SAVEPOINT {savepoint}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- savepoint name is a function-local constant; SQLite cannot bind identifiers
|
||||||
conn.execute(f"RELEASE SAVEPOINT {savepoint}")
|
conn.execute(f"RELEASE SAVEPOINT {savepoint}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- savepoint name is a function-local constant; SQLite cannot bind identifiers
|
||||||
raise
|
raise
|
||||||
|
|||||||
+5
-5
@@ -60,7 +60,7 @@ def init_store(store_path: Path) -> sqlite3.Connection:
|
|||||||
if current_version == 0:
|
if current_version == 0:
|
||||||
# New database - create schema
|
# New database - create schema
|
||||||
_create_schema(conn)
|
_create_schema(conn)
|
||||||
conn.execute(f"PRAGMA user_version={SCHEMA_VERSION}")
|
conn.execute(f"PRAGMA user_version={SCHEMA_VERSION}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- SCHEMA_VERSION is an int constant; PRAGMA cannot bind parameters
|
||||||
conn.commit()
|
conn.commit()
|
||||||
elif current_version > SCHEMA_VERSION:
|
elif current_version > SCHEMA_VERSION:
|
||||||
# Unknown newer version - refuse
|
# Unknown newer version - refuse
|
||||||
@@ -311,7 +311,7 @@ def _apply_migrations(conn: sqlite3.Connection, current_version: int):
|
|||||||
conn.execute("BEGIN IMMEDIATE")
|
conn.execute("BEGIN IMMEDIATE")
|
||||||
try:
|
try:
|
||||||
migration(conn)
|
migration(conn)
|
||||||
conn.execute(f"PRAGMA user_version={target_version}")
|
conn.execute(f"PRAGMA user_version={target_version}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- target_version is an int key of the static migrations map; PRAGMA cannot bind parameters
|
||||||
conn.commit()
|
conn.commit()
|
||||||
except Exception:
|
except Exception:
|
||||||
conn.rollback()
|
conn.rollback()
|
||||||
@@ -336,7 +336,7 @@ def _migrate_1_to_2(conn: sqlite3.Connection) -> None:
|
|||||||
).fetchall()}
|
).fetchall()}
|
||||||
for column in ("unattributed_bytes_written", "unattributed_bytes_read"):
|
for column in ("unattributed_bytes_written", "unattributed_bytes_read"):
|
||||||
if column not in cols:
|
if column not in cols:
|
||||||
conn.execute(
|
conn.execute( # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- column comes from a hardcoded tuple; DDL cannot bind identifiers
|
||||||
f"ALTER TABLE day_aggregates ADD COLUMN {column} INTEGER DEFAULT 0"
|
f"ALTER TABLE day_aggregates ADD COLUMN {column} INTEGER DEFAULT 0"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -393,7 +393,7 @@ def _migrate_4_to_5(conn: sqlite3.Connection) -> None:
|
|||||||
("last_sample_id", "INTEGER"),
|
("last_sample_id", "INTEGER"),
|
||||||
):
|
):
|
||||||
if column not in local_cols:
|
if column not in local_cols:
|
||||||
conn.execute(
|
conn.execute( # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- column and declaration come from a hardcoded tuple; DDL cannot bind identifiers
|
||||||
f"ALTER TABLE local_days ADD COLUMN {column} {declaration}"
|
f"ALTER TABLE local_days ADD COLUMN {column} {declaration}"
|
||||||
)
|
)
|
||||||
_create_local_day_shared_evidence(conn)
|
_create_local_day_shared_evidence(conn)
|
||||||
@@ -435,7 +435,7 @@ def migrate_to_latest(store_path: Path) -> int:
|
|||||||
# Version 0 means no schema — create fresh (issue #73)
|
# Version 0 means no schema — create fresh (issue #73)
|
||||||
if current_version == 0:
|
if current_version == 0:
|
||||||
_create_schema(conn)
|
_create_schema(conn)
|
||||||
conn.execute(f"PRAGMA user_version={SCHEMA_VERSION}")
|
conn.execute(f"PRAGMA user_version={SCHEMA_VERSION}") # nosemgrep: sqlalchemy-execute-raw-query, formatted-sql-query -- SCHEMA_VERSION is an int constant; PRAGMA cannot bind parameters
|
||||||
conn.commit()
|
conn.commit()
|
||||||
conn.close()
|
conn.close()
|
||||||
return SCHEMA_VERSION
|
return SCHEMA_VERSION
|
||||||
|
|||||||
Reference in New Issue
Block a user