CVE-2022-35920: python3Packages.sanic, backport upstream fix (no version bump) - #29
Conversation
Comparison against the upstream fixTranscription lane (this PR's payload): the added and removed code lines of the embedded patch are identical to the upstream fix commit, normalized for whitespace. The cross-family Reviewer attested this; the check here was recomputed independently against the bundle's upstream-fix.patch. Blind-authoring lane (separate measurement, not this payload): when the same CVE was given to claude-opus-4-8 with only the vulnerability description and the pre-fix source, never the upstream patch, the graded result against the human fix was: PARTIAL (swapped abspath for realpath, kept the flawed prefix check). Report: trace data/reports/authoring-accuracy-vs-human-2026-09-04.json. Across the nine review PRs opened 2026-09-05 the blind lane scored 1 exact, 2 equivalent, 3 partial, 3 wrong. The pipeline's Reviewer plus cert gate is what stands between the blind lane's error rate and a merge candidate. |
This PR authors the upstream fix as an in-tree patch against the current nixpkgs version (no version bump). An agent generated it; a cross-family reviewer verified it transcribes the upstream commit, and a cert proved the bundled reproducer goes red→green. A human maintainer must still confirm sufficiency before merging:
Opened as a draft deliberately — mark Ready-for-review only after the boxes above are checked.
Evidence: CVE-2022-35920 (human-review-required) trace bundle
9de765cb36399834https://github.com/Ad-Astra-Computing/trace/.github/workflows/steward.yml@refs/heads/mainhttps://token.actions.githubusercontent.com83a5f62886c8df8e9fb7ff4561a537b64a492db9Verify locally
Generated by trace.