Bugfix audit (round 2)
Regression notes after PR #20
NoteRelated
Follow-up to PR #20 (Fix full-repo audit bugs). This pass covers regressions and new silent bugs introduced after that merge (Discord SSRF hardening side effects, DICIE serve, sample corpus store, RF splits, eval free-routing).
Issues → fixes
| Issue | Severity | Symptom | Fix |
|---|---|---|---|
| #28 | Critical | /analyze PDF/PNG attachments always fail |
Pass inbox files via local_path= instead of file_url |
| #29 | High | SSRF via HTTP redirects to private IPs | Disable auto-redirects; re-validate every hop; size cap |
| #30 | High | DICIE upload path traversal via record_id |
Sanitize record_id; resolve path under temp dir |
| #31 | High | Upsert keeps stale gold fields | Replace field set per role on non-empty fields |
| #32 | High | RF typed/noisy split leakage (+ crash) | Split by unique record_id; object dtype + fallback |
| #33 | Medium | Carrier Name: extracted as patient |
Line-leading Name: / Patient: only |
| #34 | Medium | PNG collisions for :: vs __ IDs |
Hash-suffixed _cache_safe_id in render_forms |
| #35 | Medium | Eval cost wrong after free fallback | Persist used model; $0 when is_free_model |
Code touchpoints
src/discord_bot/commands.py,src/discord_bot/tools.py— #28, #29src/docie/serve.py— #30src/storage/store.py— #31src/classification/random_forest.py— #32src/docie/extract.py— #33src/extraction/render_forms.py— #34evaluation/eval_harness.py,src/utils/llm_client.py— #35tests/test_bugfix_regressions.py— regression coverage for #28–#35
Verification
pytest tests/test_bugfix_regressions.py tests/test_discord_bot.py \
tests/test_document_store.py tests/test_random_forest.py \
tests/test_docie_pipeline.py tests/test_eval_harness.py -qOut of scope / already fixed in PR #20
Silent OCR confidence, VLM decode, ACORD substring FPs, Discord private-IP / file:// host checks (initial), BIO/bbox LayoutLM issues, OCR noise banding, skeleton dates/splits, eval latency-on-failure, memo judge correct, etc.