Files
dstalk/agents/audits/findings-registry.md
XiuChengWu 0e41c8c6f6
Some checks failed
CI / Determine matrix (push) Has been cancelled
CI / ${{ matrix.os }} / ${{ matrix.build_type }} (push) Has been cancelled
W15: workflow improvements — EXPRESS fast-path, audit→fix closed loop, metadata self-check (W15.1-W15.3)
- W15.1 (杨帆): Add EXPRESS fast-path to §11 state machine (T17/T18, E1-E6 conditions, escalation safety valve)
- W15.2 (王测): Add §14 audit→fix closed loop — findings-registry.md, severity-driven auto-triage, CRITICAL blocking rule
- W15.3 (胡桐): Create scripts/check_agents_metadata.py (5-check: YAML parse, rating range, group/member refs, duplicate IDs)
- Fix YAML orphan bugs in 3 profiles: devops-hu, engineer-sun, security-cao (perf_log entries outside array)
- Pre-fill findings-registry.md with 10 historical findings from W11.1/W11.7 audits

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-05-27 18:19:37 +08:00

2.7 KiB
Raw Blame History

Audit Findings Registry

维护人: grp-quality-core (王测) 格式定义: 见 agents/WORKFLOW.md §14.2 最后更新: 2026-05-27 (W15.2 初始化,从 W11.1/W11.7 审计报告提取)


Open Findings

ID Severity Source Title Status Assigned To Fix Wave Verified By
F-11.7-1 CRITICAL W11.7-destructive-test.md build/bin/dstalk-cli.exe corrupt copy (MD5 d8e8c92b vs 803ca2ea); all commands treated as AI prompt, exit code always 3 OPEN
F-11.7-2 MEDIUM W11.7-destructive-test.md /clear reports [OK] even when session unavailable (g_session==null) — main.cpp:168-172 OPEN
F-11.7-3 LOW W11.7-destructive-test.md /context silent no-output when session unavailable; no else branch — main.cpp:175-185 OPEN
F-11.7-4 LOW W11.7-destructive-test.md /file write (no args) matched as unknown command instead of usage hint OPEN
F-11.1-1 HIGH W11.1-context-audit.md C++ exception (std::bad_alloc)穿越ABI边界违反plugin-abi §5.3trim_impl (L114-226) 无try/catch → std::terminate() OPEN
F-11.1-2 HIGH W11.1-context-audit.md strdup返回值未检查OOM时静默失败+泄漏L138-141/L219-222 循环内4次strdup无nullptr检查 OPEN
F-11.1-3 MEDIUM W11.1-context-audit.md context_set_max_tokens死APIg_max_tokens从未被读取L21/L243-244 OPEN
F-11.1-4 LOW W11.1-context-audit.md UTF-8解码无越界保护L42-64, L96-104多字节序列假设后续字节有效 OPEN
F-11.1-5 LOW W11.1-context-audit.md token计数逻辑重复L34-68 vs L91-106 ~90%重复) OPEN
F-11.1-6 LOW W11.1-context-audit.md 0xC0/0xC1过短编码未识别L52, L100仅影响token估算计数 OPEN

Closed Findings

ID Severity Source Title Closed Date Fix Wave Verified By
暂无已关闭发现

Change Log

Date Change Author
2026-05-27 W15.2 初始化,从 W11.1/W11.7 提取 10 条发现 王测 (qa-wang)