Commit Graph
16 Commits
Author SHA1 Message Date
google-labs-jules[bot] cb42a80044 Fix: Address PR comments on parameter validation
- Added OverflowError handling for seed conversion to prevent crashes with infinite inputs.
- Added explicit NaN/Inf checks for float parameters before clamping, as min/max operations propagate NaN.
- Added NaN/Inf checks for seeds to prevent invalid conversions.
2026-01-24 07:34:42 +00:00
google-labs-jules[bot] 180cac0744 Fix: Harden shader parameter validation to prevent DoS
- Validate and clamp `seed` and `base_seed` parameters to the safe 64-bit integer range [-9e18, 9e18] to prevent PyTorch `RuntimeError` crashes.
- Enable and enforce clamping for float parameters (`scale`, `warp_strength`, etc.) to reasonable bounds (+/- 1,000,000) to prevent numerical instability or Infinity/NaN propagation.
- Update `shader_params_reader.py` to implement these checks in `validate_and_sanitize_params`.
2026-01-24 07:15:33 +00:00
google-labs-jules[bot] 428c632985 Fix: Remove side-effect global seed reset in random helpers
Fixes a vulnerability where `ShaderParamsReader.random_val` and `CurlNoiseGenerator.random_val` were calling `torch.manual_seed()` unnecessarily. These helper functions use deterministic math (sin/frac hashing) and do not rely on the PyTorch RNG state. The unnecessary `manual_seed` call was resetting the global random state as a side effect, potentially affecting other components or leading to predictable sequences if interleaved with other random operations.

- Removed `torch.manual_seed` from `ShaderParamsReader.random_val` in `shader_params_reader.py`
- Removed `torch.manual_seed` from internal `random_val` in `shaders/curl_noise.py`
- Added regression test `verification/verify_seed_reset.py`
- Documented in `.jules/sentinel.md`
2026-01-21 07:30:11 +00:00
google-labs-jules[bot] 7a7916ea71 🛡️ Sentinel: Fix integer bypass in shape_type validation
- Addressed review feedback regarding `shape_type` integer bypass.
- Implemented `LEGACY_SHAPE_MAPPING` to strictly validate integer inputs (1, 2, 3) and map them to their string equivalents.
- Invalid integers now default to 'none', consistent with the allowlist policy.
- Fixed import logic in `verification/verify_params_validation.py` to handle torch dependency check correctly.
- Added regression tests for legacy and invalid integer shape types.
2026-01-20 08:07:07 +00:00
google-labs-jules[bot] f989f09582 🛡️ Sentinel: [HIGH] Enforce allowlist validation for shader parameters
🚨 Severity: HIGH
💡 Vulnerability: String parameters (`shader_type`, `shape_type`, `colorScheme`) were read without validation against predefined allowed values. This could allow unexpected strings to propagate through the system, potentially causing application crashes (DoS) or unexpected behavior in downstream components.
🎯 Impact: Prevents processing of malformed or malicious configuration inputs that could disrupt service availability or logic integrity.
🔧 Fix: Implemented strict Allowlist Validation in `ShaderParamsReader.validate_and_sanitize_params`. Invalid inputs now default to safe values (e.g., "tensor_field", "none").
✅ Verification: Added `verification/verify_params_validation.py` which confirms that invalid strings are now sanitized while valid inputs are preserved.
2026-01-20 07:38:15 +00:00
google-labs-jules[bot] d83e7eddc9 🛡️ Sentinel: [HIGH] Fix DoS risk in DirectShaderNoiseKSampler
- Enforce input validation for direct parameters in `DirectShaderNoiseKSampler`.
- Update `ShaderParamsReader.validate_and_sanitize_params` to check `shaderOctaves` alias.
- Clamps `octaves` to 20 to prevent resource exhaustion.
2026-01-19 07:33:46 +00:00
google-labs-jules[bot] 4b4d196fbd Fix DoS vulnerability via unbounded shader parameters
- Implemented `validate_and_sanitize_params` in `ShaderParamsReader`.
- Clamped `octaves` parameter to a safe range (1-20) and cast to integer to prevent infinite loops.
- Ensured type safety for other critical parameters (`scale`, `intensity`, etc.).
- Prevented potential resource exhaustion attacks via malformed `shader_params.json`.
2026-01-18 07:36:50 +00:00
google-labs-jules[bot] eda4505958 🛡️ Sentinel: [MEDIUM] Enhance file access security in shader_params_reader
Restrict `get_shader_params` to only allow reading `.json` files that are:
1. Physically located within the extension directory (preventing symlink bypass).
2. Located within the `data/` subdirectory or are the default `shader_params.json` in the extension root (enforcing least privilege).

This prevents potential path traversal, symlink attacks, or unauthorized file reads within the extension directory.

- Added strict file extension check.
- Added strict directory scope check using `os.path.commonpath`.
- Implemented robust case-sensitive-aware comparison using `os.path.normcase`.
- Updated `.jules/sentinel.md` with security learnings.
2026-01-17 17:27:58 +00:00
google-labs-jules[bot] a81c424eba 🛡️ Sentinel: [MEDIUM] Enhance file access security in shader_params_reader
Restrict `get_shader_params` to only allow reading `.json` files that are either located within the `data/` subdirectory or are the default `shader_params.json` in the extension root. This prevents potential path traversal or arbitrary file read vulnerabilities within the extension directory.

- Added strict file extension check.
- Added strict directory scope check using `os.path.commonpath`.
- Implemented robust case-sensitive-aware comparison using `os.path.normcase` to handle cross-platform casing variations safely (preventing bypasses on Linux while supporting Windows).
- Updated `.jules/sentinel.md` with security learnings.
2026-01-17 16:39:31 +00:00
google-labs-jules[bot] b7a9d7b850 🛡️ Sentinel: [MEDIUM] Enhance file access security in shader_params_reader
Restrict `get_shader_params` to only allow reading `.json` files that are either located within the `data/` subdirectory or are the default `shader_params.json` in the extension root. This prevents potential path traversal or arbitrary file read vulnerabilities within the extension directory.

- Added strict file extension check.
- Added strict directory scope check using `os.path.commonpath`.
- Implemented robust case-insensitive comparison using `.lower()` to handle cross-platform casing variations (e.g. `Data/` vs `data/` on Linux).
- Updated `.jules/sentinel.md` with security learnings.
2026-01-17 08:55:55 +00:00
google-labs-jules[bot] a51d551843 🛡️ Sentinel: [MEDIUM] Enhance file access security in shader_params_reader
Restrict `get_shader_params` to only allow reading `.json` files that are either located within the `data/` subdirectory or are the default `shader_params.json` in the extension root. This prevents potential path traversal or arbitrary file read vulnerabilities within the extension directory.

- Added strict file extension check.
- Added strict directory scope check using `os.path.commonpath`.
- Updated `.jules/sentinel.md` with security learnings.
2026-01-17 07:24:43 +00:00
Æmotion Studio ea235ff5d2 Merge pull request #11 from AEmotionStudio/bolt-vectorize-color-interpolation-16542257857809526268
⚡ Bolt: Vectorize color interpolation for faster shader generation
2026-01-15 00:09:48 -08:00
AEmotionStudio 0a54bd637c chore: remove accidental placeholder comment 2026-01-14 23:58:30 -08:00
google-labs-jules[bot] b8364b9329 Vectorize color interpolation in ShaderParamsReader
Optimized `_interpolate_colors` in `ShaderParamsReader` to use `torch.bucketize` and vectorized indexing instead of iterating over color stops. This improves performance from O(Stops) to O(1) in terms of kernel launches/Python overhead.

Updated `CurlNoiseGenerator` to use the optimized shared implementation instead of its own slower local version.

Also fixed a regression in `apply_shape_mask` hexgrid calculation.
2026-01-15 07:36:02 +00:00
google-labs-jules[bot] c084bfd98a 🛡️ Sentinel: [CRITICAL] Fix Path Traversal in ShaderParamsReader
Sanitized `custom_path` input in `ShaderParamsReader.get_shader_params` to prevent reading arbitrary files outside the extension directory.

- Uses `os.path.realpath` to resolve symlinks and absolute paths.
- Uses `os.path.commonpath` to ensure the resolved path is within the allowed `EXTENSION_DIR`.
- Implements a fail-safe fallback to the default parameters file if a traversal attempt is detected.
- Includes error handling for potential `ValueError` on Windows (cross-drive paths).
2026-01-15 07:16:55 +00:00
Æmotion 7a8510fe43 Initial commit of ComfyUI-ShaderNoiseKSampler 2025-05-22 14:34:34 -07:00