2040 — Code Scanning Alert Audit and Cleanup for Issue #1243¶
Date: 2026-09-08 Scope: All 22 open GitHub code-scanning alerts on VMAFx/vmafx audited against origin/master for issue #1243. Standing Policy: Agents analyse and fix; the maintainer decides dismissals. Accepted findings are resolved in source code where applicable, and no alert is dismissed via API/UI by the agent.
1. Executive Summary¶
A full audit of all 22 open code-scanning alerts was conducted against origin/master (19c8a4be1d027ee894bb62fa34cf639884ef4ac5). PR scans in CI are incremental and may be stale relative to the authoritative branch state.
- Real Code Defects Fixed:
- Alerts 1030 & 1031 (
CodeQL cpp/loop-variable-changedincore/tools/cli_parse.cpp:506, 532):cli_split()andcli_unescape()mutated their loop variables (i += 2U/i++, andr++) within the bodies offorloops. Converted to idiomaticwhileloops. - Alert 951 (
CodeQL cpp/commented-out-codeincore/test/test_model_feature_overload_ownership.c:183): A comment explaining the defect in Netflix/vmaf#1242 terminated with a semicolon (reports);), tripping CodeQL's heuristic statement extractor. Changed to a comma. -
Alerts 970 & 971 (
CodeQL py/unused-global-variableinmcp-server/vmaf-mcp/src/vmaf_mcp/server.py:375, 376): An obsolete block of duplicate constant sets (_VALID_AOM_CTCS,_VALID_NFLX_CTCS, etc.) at lines 375–396 was accidentally reintroduced. Removed the dead block and placed_VALID_OUTPUT_FMTSinto the canonical constants section at lines 508–528. -
Load-Bearing Pattern Retained per ADR-0138:
-
Alert 1005 (
CodeQL cpp/integer-multiplication-cast-to-longincore/src/feature/iqa/convolve.c:155): Reports float multiplication converted to double. Widening the scalar multiply breaks the bit-exactness contract with AVX2, AVX-512, and NEON SIMD kernels (which multiply in float and widen after) and causestest_iqa_convolveto fail. Follow-up Research-2031 proved every production path — including signed MS-SSIM pyramid overshoot and PU21 — keeps the exact flagged product at or below2^28, far belowFLT_MAX; the expression now has executable domain coverage and a single-query source suppression. -
Candidate Dismissals Catalogued for Maintainer:
- All remaining open alerts (17 alerts) were audited and catalogued with specific rationales for maintainer review and dismissal.
2. Complete Open Alert Inventory & Dispositions¶
| Alert # | Tool | Rule ID | File : Line | Severity | Disposition | Technical Justification |
|---|---|---|---|---|---|---|
| 1036 | CodeQL | cpp/unused-local-variable | core/build/meson-private/.../testfile.c:5 | Note | Candidate for Dismissal | Transient compiler feature-probe file generated by Meson during configuration. Not part of versioned repository source; cannot be suppressed via source. |
| 1031 | CodeQL | cpp/loop-variable-changed | core/tools/cli_parse.cpp:506 | Note | Fixed | cli_split() modified loop counter i inside for (size_t i = 0U; s[i] != '\0'; i++). Refactored to while (s[i] != '\0'). |
| 1030 | CodeQL | cpp/loop-variable-changed | core/tools/cli_parse.cpp:532 | Note | Fixed | cli_unescape() advanced read pointer r++ inside for (const char *r = s; *r != '\0'; r++). Refactored to while (*r != '\0'). |
| 1005 | CodeQL | cpp/integer-multiplication-cast-to-long | core/src/feature/iqa/convolve.c:155 | High | Resolved in Source (narrow suppression) | Intentional float multiply per ADR-0138; widening breaks bit-exactness with SIMD twins. Research-2031 proves the complete SSIM/MS-SSIM/PU21 production domain bounds the flagged product by 2^28, adds executable coverage, and scopes the official CodeQL suppression to this expression only. |
| 1003 | CodeQL | cpp/unused-static-variable | core/tools/cli_parse.cpp:321 | Note | Candidate for Dismissal (False Positive) | Variadic template parameter pack Rest &&...rest in usage(). When called with 1 format arg (sizeof...(Rest) == 0), CodeQL models the empty pack expansion as an unused variable. |
| 1002 | CodeQL | cpp/unused-local-variable | core/tools/cli_parse.cpp:321 | Note | Candidate for Dismissal (False Positive) | Sibling of Alert 1003; empty template parameter pack artifact. |
| 971 | CodeQL | py/unused-global-variable | mcp-server/.../server.py:376 | Note | Fixed | Unused _VALID_NFLX_CTCS in duplicate constants block at lines 375–396. Removed dead block. |
| 970 | CodeQL | py/unused-global-variable | mcp-server/.../server.py:375 | Note | Fixed | Unused _VALID_AOM_CTCS in duplicate constants block at lines 375–396. Removed dead block. |
| 955 | CodeQL | cpp/include-non-header | core/test/test_model.c:28 | Note | Candidate for Dismissal (False Positive) | White-box unit test text-including model.c to inspect static built_in_models per ADR-0278 / ADR-0141. Annotated with NOLINTNEXTLINE(bugprone-suspicious-include). |
| 951 | CodeQL | cpp/commented-out-code | core/test/..._ownership.c:183 | Note | Fixed | Heuristic false positive: comment line ending in ; (reports);) mistranslated as commented-out C statement. Replaced ; with ,. |
| 949 | Semgrep | insecure-hash-algorithm-sha1 | compat/.../decorator.py:147 | Warning | Candidate for Dismissal (False Positive) | Non-cryptographic memoization cache key. Hardened with usedforsecurity=False (PEP 451 / FIPS) and # nosemgrep. |
| 948 | Semgrep | insecure-hash-algorithm-sha1 | compat/.../decorator.py:120 | Warning | Candidate for Dismissal (False Positive) | Same as Alert 949: non-cryptographic memoization cache key with usedforsecurity=False and # nosemgrep. |
| 947 | Semgrep | insecure-hash-algorithm-sha1 | compat/.../decorator.py:48 | Warning | Candidate for Dismissal (False Positive) | Same as Alert 949: non-cryptographic memoization cache key with usedforsecurity=False and # nosemgrep. |
| 946 | Semgrep | insecure-file-permissions | ai/sidecar/online_trainer.py:430 | Warning | Candidate for Dismissal | Unix-domain socket mode 0o660 grants user+group read/write with 0 world access for IPC with Go peer. Preceded by srv.bind(), annotated with # nosemgrep. |
| 943 | CodeQL | cpp/include-non-header | core/test/test_feature.cpp:29 | Note | Candidate for Dismissal (False Positive) | White-box unit test text-including feature_name.cpp for option table test isolation per ADR-0729 Wave 3. |
| 927 | CodeQL | cpp/equality-on-floats | core/src/predict.c:302 | Note | Candidate for Dismissal (False Positive) | Exact sentinel comparison st->guided_score != st->sentinel where sentinel is exactly 0.0 (ADR-0138 / ADR-0139 bit-exactness). Epsilon compare would corrupt near-zero chroma scores. |
| 918 | CodeQL | py/cyclic-import | mcp-server/.../http_transport.py:443 | Note | Fixed in Source (2026-09-23) | HTTP scoring now crosses the shared http_scoring.py interface; http_transport.py no longer imports server.py. The production import-DAG regression walks function-local imports too. |
| 917 | CodeQL | py/cyclic-import | mcp-server/.../server.py:4245 | Note | Fixed in Source (2026-09-23) | Partner alert to 918. server.py installs the canonical adapter and may start the HTTP transport; the HTTP transport has no return dependency. Hosted closure awaits the next CodeQL run on merged master. |
| 908 | CodeQL | cpp/include-non-header | core/test/test_luminance_tools.cpp:20 | Note | Candidate for Dismissal (False Positive) | White-box unit test text-including luminance_tools.cpp to exercise static internal functions (range_foot_head, normalize_range) per ADR-0731. |
| 168 | CodeQL | cpp/equality-on-floats | core/src/feature/feature_name.cpp:146 | Note | Candidate for Dismissal (False Positive) | Exact equality comparison (opt->default_val.d == ...) for option default detection (ADR-0138 / ADR-0139). Epsilon compare would distort option serialization. |
| 3 | Scorecard | CIIBestPracticesID | Repository Root | Low | Candidate for Dismissal (Organizational) | Requires external OpenSSF foundation application and manual badge assignment (ADR-0263). Documented in docs/state.md. |
| 1 | Scorecard | CodeReviewID | Repository Root | High | Candidate for Dismissal (Process) | Solo-maintainer repository artifact: squash-merging author PRs does not emit multi-party review events (ADR-0263). Documented in docs/state.md. |
3. Verification¶
- Fast Unit Test Suite:
Result: 119/119 OK.
- Targeted CLI and Test Executables:
./core/build/test/test_cli_parse_long_only_args
./core/build/test/test_model_feature_overload_ownership
Result: 9/9 OK, 8/8 OK.
- Python & MCP Tests:
ruff check mcp-server/vmaf-mcp/src/vmaf_mcp/server.py
black --check mcp-server/vmaf-mcp/src/vmaf_mcp/server.py
VMAF_MCP_ALLOW=$PWD pytest mcp-server/vmaf-mcp/tests -q
Result: Ruff clean, Black clean, 375 passed, 42 skipped.
- Netflix Golden Gate: Preserved bit-exact values; no
assertAlmostEqualmodified.