correction securité sandbox

This commit is contained in:
Chevallier
2026-07-07 11:13:40 +02:00
parent 7b1a975f06
commit 5f06de19e0

View File

@@ -2,8 +2,11 @@ import subprocess
import json import json
import time import time
from fastapi import FastAPI from fastapi import FastAPI
import logging
app = FastAPI() app = FastAPI()
logger = logging.getLogger(__name__)
SEMGREP_TIMEOUT = 300.0
@app.post("/scan/{repo_name}") @app.post("/scan/{repo_name}")
async def scan_repository(repo_name: str): async def scan_repository(repo_name: str):
@@ -11,13 +14,43 @@ async def scan_repository(repo_name: str):
issues_list = [] issues_list = []
start_time = time.time() start_time = time.time()
result = subprocess.run( try:
["semgrep", "scan", "--config=p/r2c-security-audit", "--json", "--quiet", repo_path], secure_command = f"ulimit -f 10240 && semgrep scan --config=p/r2c-security-audit --json --quiet {repo_path}"
capture_output=True,
text=True result = subprocess.run(
) secure_command,
shell=True,
duration = round(time.time() - start_time, 2) capture_output=True,
text=True,
timeout=SEMGREP_TIMEOUT
)
duration = round(time.time() - start_time, 2)
exit_code = result.returncode
stderr_output = result.stderr
timeout_triggered = False
is_executable = True
except subprocess.TimeoutExpired as te:
logger.error(f"[Sandbox] Semgrep a dépassé le timeout sur {repo_name}")
duration = round(time.time() - start_time, 2)
exit_code = -1
stderr_output = f"L'analyse statique a été coupée : Timeout de {SEMGREP_TIMEOUT}s dépassé."
timeout_triggered = True
is_executable = False
return {
"results": {
"is_executable": is_executable,
"runtime": {
"exit_code": exit_code,
"stdout": "",
"stderr": stderr_output,
"duration_seconds": duration,
"timeout_triggered": timeout_triggered
},
"issues": []
}
}
try: try:
if result.stdout.strip(): if result.stdout.strip():
@@ -41,11 +74,11 @@ async def scan_repository(repo_name: str):
"results": { "results": {
"is_executable": is_executable, "is_executable": is_executable,
"runtime": { "runtime": {
"exit_code": 0, # <-- ON FORCE À 0 ICI : Tout s'est bien passé pour le scanner "exit_code": exit_code,
"stdout": "Scan statique universel effectué avec succès.", "stdout": "Scan statique universel effectué avec succès.",
"stderr": stderr_output, "stderr": stderr_output,
"duration_seconds": duration, "duration_seconds": duration,
"timeout_triggered": False "timeout_triggered": timeout_triggered
}, },
"issues": issues_list "issues": issues_list
} }