Skip to content

2040 — Code Scanning Alert Audit and Cleanup for Issue #1243

Date: 2026-09-08 Scope: All 22 open GitHub code-scanning alerts on VMAFx/vmafx audited against origin/master for issue #1243. Standing Policy: Agents analyse and fix; the maintainer decides dismissals. Accepted findings are resolved in source code where applicable, and no alert is dismissed via API/UI by the agent.


1. Executive Summary

A full audit of all 22 open code-scanning alerts was conducted against origin/master (19c8a4be1d027ee894bb62fa34cf639884ef4ac5). PR scans in CI are incremental and may be stale relative to the authoritative branch state.

  • Real Code Defects Fixed:
  • Alerts 1030 & 1031 (CodeQL cpp/loop-variable-changed in core/tools/cli_parse.cpp:506, 532): cli_split() and cli_unescape() mutated their loop variables (i += 2U / i++, and r++) within the bodies of for loops. Converted to idiomatic while loops.
  • Alert 951 (CodeQL cpp/commented-out-code in core/test/test_model_feature_overload_ownership.c:183): A comment explaining the defect in Netflix/vmaf#1242 terminated with a semicolon (reports);), tripping CodeQL's heuristic statement extractor. Changed to a comma.
  • Alerts 970 & 971 (CodeQL py/unused-global-variable in mcp-server/vmaf-mcp/src/vmaf_mcp/server.py:375, 376): An obsolete block of duplicate constant sets (_VALID_AOM_CTCS, _VALID_NFLX_CTCS, etc.) at lines 375–396 was accidentally reintroduced. Removed the dead block and placed _VALID_OUTPUT_FMTS into the canonical constants section at lines 508–528.

  • Load-Bearing Pattern Retained per ADR-0138:

  • Alert 1005 (CodeQL cpp/integer-multiplication-cast-to-long in core/src/feature/iqa/convolve.c:155): Reports float multiplication converted to double. Widening the scalar multiply breaks the bit-exactness contract with AVX2, AVX-512, and NEON SIMD kernels (which multiply in float and widen after) and causes test_iqa_convolve to fail. Follow-up Research-2031 proved every production path — including signed MS-SSIM pyramid overshoot and PU21 — keeps the exact flagged product at or below 2^28, far below FLT_MAX; the expression now has executable domain coverage and a single-query source suppression.

  • Candidate Dismissals Catalogued for Maintainer:

  • All remaining open alerts (17 alerts) were audited and catalogued with specific rationales for maintainer review and dismissal.

2. Complete Open Alert Inventory & Dispositions

Alert # Tool Rule ID File : Line Severity Disposition Technical Justification
1036 CodeQL cpp/unused-local-variable core/build/meson-private/.../testfile.c:5 Note Candidate for Dismissal Transient compiler feature-probe file generated by Meson during configuration. Not part of versioned repository source; cannot be suppressed via source.
1031 CodeQL cpp/loop-variable-changed core/tools/cli_parse.cpp:506 Note Fixed cli_split() modified loop counter i inside for (size_t i = 0U; s[i] != '\0'; i++). Refactored to while (s[i] != '\0').
1030 CodeQL cpp/loop-variable-changed core/tools/cli_parse.cpp:532 Note Fixed cli_unescape() advanced read pointer r++ inside for (const char *r = s; *r != '\0'; r++). Refactored to while (*r != '\0').
1005 CodeQL cpp/integer-multiplication-cast-to-long core/src/feature/iqa/convolve.c:155 High Resolved in Source (narrow suppression) Intentional float multiply per ADR-0138; widening breaks bit-exactness with SIMD twins. Research-2031 proves the complete SSIM/MS-SSIM/PU21 production domain bounds the flagged product by 2^28, adds executable coverage, and scopes the official CodeQL suppression to this expression only.
1003 CodeQL cpp/unused-static-variable core/tools/cli_parse.cpp:321 Note Candidate for Dismissal (False Positive) Variadic template parameter pack Rest &&...rest in usage(). When called with 1 format arg (sizeof...(Rest) == 0), CodeQL models the empty pack expansion as an unused variable.
1002 CodeQL cpp/unused-local-variable core/tools/cli_parse.cpp:321 Note Candidate for Dismissal (False Positive) Sibling of Alert 1003; empty template parameter pack artifact.
971 CodeQL py/unused-global-variable mcp-server/.../server.py:376 Note Fixed Unused _VALID_NFLX_CTCS in duplicate constants block at lines 375–396. Removed dead block.
970 CodeQL py/unused-global-variable mcp-server/.../server.py:375 Note Fixed Unused _VALID_AOM_CTCS in duplicate constants block at lines 375–396. Removed dead block.
955 CodeQL cpp/include-non-header core/test/test_model.c:28 Note Candidate for Dismissal (False Positive) White-box unit test text-including model.c to inspect static built_in_models per ADR-0278 / ADR-0141. Annotated with NOLINTNEXTLINE(bugprone-suspicious-include).
951 CodeQL cpp/commented-out-code core/test/..._ownership.c:183 Note Fixed Heuristic false positive: comment line ending in ; (reports);) mistranslated as commented-out C statement. Replaced ; with ,.
949 Semgrep insecure-hash-algorithm-sha1 compat/.../decorator.py:147 Warning Candidate for Dismissal (False Positive) Non-cryptographic memoization cache key. Hardened with usedforsecurity=False (PEP 451 / FIPS) and # nosemgrep.
948 Semgrep insecure-hash-algorithm-sha1 compat/.../decorator.py:120 Warning Candidate for Dismissal (False Positive) Same as Alert 949: non-cryptographic memoization cache key with usedforsecurity=False and # nosemgrep.
947 Semgrep insecure-hash-algorithm-sha1 compat/.../decorator.py:48 Warning Candidate for Dismissal (False Positive) Same as Alert 949: non-cryptographic memoization cache key with usedforsecurity=False and # nosemgrep.
946 Semgrep insecure-file-permissions ai/sidecar/online_trainer.py:430 Warning Candidate for Dismissal Unix-domain socket mode 0o660 grants user+group read/write with 0 world access for IPC with Go peer. Preceded by srv.bind(), annotated with # nosemgrep.
943 CodeQL cpp/include-non-header core/test/test_feature.cpp:29 Note Candidate for Dismissal (False Positive) White-box unit test text-including feature_name.cpp for option table test isolation per ADR-0729 Wave 3.
927 CodeQL cpp/equality-on-floats core/src/predict.c:302 Note Candidate for Dismissal (False Positive) Exact sentinel comparison st->guided_score != st->sentinel where sentinel is exactly 0.0 (ADR-0138 / ADR-0139 bit-exactness). Epsilon compare would corrupt near-zero chroma scores.
918 CodeQL py/cyclic-import mcp-server/.../http_transport.py:443 Note Fixed in Source (2026-09-23) HTTP scoring now crosses the shared http_scoring.py interface; http_transport.py no longer imports server.py. The production import-DAG regression walks function-local imports too.
917 CodeQL py/cyclic-import mcp-server/.../server.py:4245 Note Fixed in Source (2026-09-23) Partner alert to 918. server.py installs the canonical adapter and may start the HTTP transport; the HTTP transport has no return dependency. Hosted closure awaits the next CodeQL run on merged master.
908 CodeQL cpp/include-non-header core/test/test_luminance_tools.cpp:20 Note Candidate for Dismissal (False Positive) White-box unit test text-including luminance_tools.cpp to exercise static internal functions (range_foot_head, normalize_range) per ADR-0731.
168 CodeQL cpp/equality-on-floats core/src/feature/feature_name.cpp:146 Note Candidate for Dismissal (False Positive) Exact equality comparison (opt->default_val.d == ...) for option default detection (ADR-0138 / ADR-0139). Epsilon compare would distort option serialization.
3 Scorecard CIIBestPracticesID Repository Root Low Candidate for Dismissal (Organizational) Requires external OpenSSF foundation application and manual badge assignment (ADR-0263). Documented in docs/state.md.
1 Scorecard CodeReviewID Repository Root High Candidate for Dismissal (Process) Solo-maintainer repository artifact: squash-merging author PRs does not emit multi-party review events (ADR-0263). Documented in docs/state.md.

3. Verification

  1. Fast Unit Test Suite:
ninja -C core/build -j4
meson test -C core/build --suite=fast -j4

Result: 119/119 OK.

  1. Targeted CLI and Test Executables:
./core/build/test/test_cli_parse_long_only_args
./core/build/test/test_model_feature_overload_ownership

Result: 9/9 OK, 8/8 OK.

  1. Python & MCP Tests:
ruff check mcp-server/vmaf-mcp/src/vmaf_mcp/server.py
black --check mcp-server/vmaf-mcp/src/vmaf_mcp/server.py
VMAF_MCP_ALLOW=$PWD pytest mcp-server/vmaf-mcp/tests -q

Result: Ruff clean, Black clean, 375 passed, 42 skipped.

  1. Netflix Golden Gate: Preserved bit-exact values; no assertAlmostEqual modified.