fix: resolve gosec alerts in files this change touches

Code scanning reports alerts on every line of a touched file. Mark the
gRPC auth env var name and the mock backend's staged-path reads as
reviewed, and log the error when evicting a model after its connection
fails instead of dropping it.

Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Ettore Di Giacinto <mudler@localai.io>
This commit is contained in:
Ettore Di Giacinto committed 2026-09-27 08:42:12 +00:00
1 parent 27ceda46b0
commit 9e95ef0dbd
3 files changed
+12 -5

No files matched your search

+1 -1
View File
@@ -1098,7 +1098,7 @@ func NewBackendServer(model AIModel) pb.BackendServer {
}
// AuthTokenEnvVar is the environment variable used to configure gRPC bearer token auth.
const AuthTokenEnvVar = "LOCALAI_GRPC_AUTH_TOKEN"
const AuthTokenEnvVar = "LOCALAI_GRPC_AUTH_TOKEN" // #nosec G101 -- the name of an environment variable, not a credential
// validateToken extracts the bearer token from gRPC metadata and validates it.
func validateToken(ctx context.Context, expected string) error {
+9 -3
View File
@@ -479,7 +479,9 @@ func (ml *ModelLoader) Load(opts ...Option) (grpc.Backend, error) {
// Wrap remote models so connection errors during inference trigger eviction
if m.Process() == nil {
client = newConnectionEvictingClient(client, o.modelID, func() {
ml.ShutdownModel(o.modelID)
if err := ml.ShutdownModel(o.modelID); err != nil {
xlog.Debug("evicting a model after its connection failed", "model", o.modelID, "error", err)
}
})
}
return client, nil
@@ -503,7 +505,9 @@ func (ml *ModelLoader) Load(opts ...Option) (grpc.Backend, error) {
// Wrap remote models so connection errors during inference trigger eviction
if m := ml.CheckIsLoaded(o.modelID); m != nil && m.Process() == nil {
client = newConnectionEvictingClient(client, o.modelID, func() {
ml.ShutdownModel(o.modelID)
if err := ml.ShutdownModel(o.modelID); err != nil {
xlog.Debug("evicting a model after its connection failed", "model", o.modelID, "error", err)
}
})
}
return client, nil
@@ -544,7 +548,9 @@ func (ml *ModelLoader) Load(opts ...Option) (grpc.Backend, error) {
// Wrap remote models so connection errors during inference trigger eviction
if m := ml.CheckIsLoaded(o.modelID); m != nil && m.Process() == nil {
model = newConnectionEvictingClient(model, o.modelID, func() {
ml.ShutdownModel(o.modelID)
if err := ml.ShutdownModel(o.modelID); err != nil {
xlog.Debug("evicting a model after its connection failed", "model", o.modelID, "error", err)
}
})
}
return model, nil
+2 -1
View File
@@ -648,6 +648,7 @@ func (m *MockBackend) AudioTranscription(ctx context.Context, in *pb.TranscriptR
rms := 0.0
if dst != "" {
// #nosec G304 -- test-only mock backend reading the path core just staged
if data, err := os.ReadFile(dst); err == nil {
if len(data) >= 44 {
wavSR = int(binary.LittleEndian.Uint32(data[24:28]))
@@ -1018,7 +1019,7 @@ func (m *MockBackend) ModelMetadata(ctx context.Context, in *pb.ModelOptions) (*
// survive resampling (DC is sample-rate independent). Near-zero DC maps to a
// neutral vector equidistant from both. Returns nil for unreadable audio.
func voiceEmbedFromWAV(path string) []float32 {
data, err := os.ReadFile(path)
data, err := os.ReadFile(path) // #nosec G304 -- test-only mock backend reading the path core just staged
if err != nil || len(data) < 44 {
return nil
}