Team Ai
Datasetpublic

Brunobkr/llama.cpp_AlgMor24_github

ΩFFFΣLLIa • llama.cpp • AlgMor24 ██████╗ ███████╗███████╗███████╗██╗ ██╗ ██╗ █████╗ ██╔═══██╗██╔════╝██╔════╝██╔════╝██║ ██║ ██║██╔══██╗ ██║ ██║█████╗ █████╗ █████╗ ██║ ██║ ██║███████║ ██║ ██║██╔══╝ ██╔══╝ ██╔══╝ ██║ ██║ ██║██╔══██║ ╚██████╔╝██║ ██║ ███████╗███████╗███████╗██║██║ ██║ ╚═════╝ ╚═╝ ╚═╝ ╚══════╝╚══════╝╚══════╝╚═╝╚═╝ ╚═╝ High-Performance LLM / VLM Inference & Autonomous Agentic Ecosystem… See the full description on the dataset page: https://huggingface.co/datasets/Brunobkr/llama.cpp_AlgMor24_github.

sourceHugging Faceupdated 2mo agoView on Hugging Face
0likes3.1kdownloads
security.test.js360 linesDownload Raw Back to test
1'use strict'2 3const test = require('tape')4const fastURI = require('..')5 6test('parse marks malformed authority and port inputs as errors', (t) => {7  const malformedCases = [8    {9      input: 'http://[::1]foo',10      expectedError: 'URI path must start with "/" when authority is present.'11    },12    {13      input: 'http://[::1]:80abc/path',14      expectedError: 'URI path must start with "/" when authority is present.'15    },16    {17      input: 'http://example.com:80abc/path',18      expectedError: 'URI path must start with "/" when authority is present.'19    },20    {21      input: 'http://[::1]:65536',22      expectedError: 'URI port is malformed.'23    }24  ]25 26  t.plan(malformedCases.length)27 28  malformedCases.forEach(({ input, expectedError }) => {29    t.equal(fastURI.parse(input).error, expectedError, input)30  })31})32 33test('normalize does not canonicalize malformed URLs into different valid URLs', (t) => {34  const malformedCases = [35    'http://[::1]foo',36    'http://[::1]:80abc/path',37    'http://example.com:80abc/path',38    'http://[::1]:65536'39  ]40 41  t.plan(malformedCases.length)42 43  malformedCases.forEach((input) => {44    t.equal(fastURI.normalize(input), input, input)45  })46})47 48test('equal returns false when either side is malformed', (t) => {49  const malformedPairs = [50    ['http://[::1]foo', 'http://[::1]/foo'],51    ['http://[::1]:80abc/path', 'http://[::1]/abc/path'],52    ['http://example.com:80abc/path', 'http://example.com/abc/path'],53    ['http://[::1]:65536', 'http://[::1]:65536/']54  ]55 56  t.plan(malformedPairs.length)57 58  malformedPairs.forEach(([left, right]) => {59    t.equal(fastURI.equal(left, right), false, `${left} != ${right}`)60  })61})62 63test('normalize preserves encoded authority delimiters in host', (t) => {64  const cases = [65    ['http://trusted.com%40evil.com/', 'http://trusted.com%40evil.com/'],66    ['http://example.com%3A8080/', 'http://example.com%3A8080/'],67    ['http://example.com%2Fevil.com/path', 'http://example.com%2Fevil.com/path'],68    ['http://example.com%23fragment/path', 'http://example.com%23fragment/path'],69    ['http://example.com%3Fq=evil/path', 'http://example.com%3Fq=evil/path'],70    ['http://user%3Apass%40evil.com/', 'http://user%3Apass%40evil.com/'],71    ['http://user@trusted.com%40evil.com/', 'http://user@trusted.com%40evil.com/'],72    ['https://trusted.com%40evil.com/', 'https://trusted.com%40evil.com/'],73    ['ws://trusted.com%40evil.com/chat', 'ws://trusted.com%40evil.com/chat'],74    ['wss://trusted.com%40evil.com/chat', 'wss://trusted.com%40evil.com/chat']75  ]76 77  t.plan(cases.length)78 79  cases.forEach(([input, expected]) => {80    t.equal(fastURI.normalize(input), expected, input)81  })82})83 84test('parse preserves encoded authority delimiters in host', (t) => {85  const cases = [86    ['http://trusted.com%40evil.com/', 'trusted.com%40evil.com'],87    ['http://example.com%3A8080/', 'example.com%3A8080'],88    ['http://user%3Apass%40evil.com/', 'user%3Apass%40evil.com']89  ]90 91  t.plan(cases.length)92 93  cases.forEach(([input, expectedHost]) => {94    t.equal(fastURI.parse(input).host, expectedHost, input)95  })96})97 98test('equal returns false when encoded delimiters differ from live delimiters', (t) => {99  const pairs = [100    ['http://trusted.com%40evil.com/', 'http://trusted.com@evil.com/'],101    ['http://example.com%3A8080/', 'http://example.com:8080/']102  ]103 104  t.plan(pairs.length)105 106  pairs.forEach(([left, right]) => {107    t.equal(fastURI.equal(left, right, {}), false, `${left} != ${right}`)108  })109})110 111test('resolve preserves encoded authority delimiters', (t) => {112  const result = fastURI.resolve('http://base.com/', '//trusted.com%40evil.com/path')113  const parsed = fastURI.parse(result)114 115  t.plan(1)116  t.notEqual(parsed.host, 'evil.com', '//trusted.com%40evil.com/path')117})118 119test('serialize escapes authority delimiters in host field', (t) => {120  const result = fastURI.serialize({ scheme: 'http', host: 'trusted.com@evil.com', path: '/' })121  const parsed = fastURI.parse(result)122 123  t.plan(1)124  t.notEqual(parsed.host, 'evil.com', 'host: trusted.com@evil.com')125})126 127test('normalize does not double-decode %2540 into a live @', (t) => {128  const result = fastURI.normalize('http://trusted.com%2540evil.com/')129  const parsed = fastURI.parse(result)130 131  t.plan(1)132  t.notEqual(parsed.host, 'trusted.com@evil.com', 'http://trusted.com%2540evil.com/')133})134 135test('parse canonicalises IDN / Unicode hosts to their ASCII form', (t) => {136  const cases = [137    {138      input: 'http://127。0。0。1/',139      expectedHost: '127.0.0.1',140      description: 'full-width ideographic stops as octet separators'141    },142    {143      input: 'http://example.com/',144      expectedHost: 'example.com',145      description: 'fullwidth e as first letter'146    },147    {148      input: 'http://納豆.example.org/',149      expectedHost: 'xn--99zt52a.example.org',150      description: 'CJK label requiring punycode'151    }152  ]153 154  t.plan(cases.length * 2)155 156  cases.forEach(({ input, expectedHost, description }) => {157    const parsed = fastURI.parse(input)158    t.notOk(parsed.error, `parse should not set error: ${description}`)159    t.equal(parsed.host, expectedHost, `host canonicalised to ASCII: ${description}`)160  })161})162 163test('parse rejects a literal backslash in the authority as malformed (RFC 3986)', (t) => {164  // Regression for the host-confusion bypass: a literal "\" is invalid RFC 3986165  // syntax and must be flagged malformed, not silently rewritten. Otherwise "\"166  // acts as a host delimiter here while Node's native URL parses a different167  // host, defeating a host-based SSRF/redirect/origin allowlist.168  const cases = [169    'http://evil.com\\@allowed.com',170    'https://169.254.169.254\\@trusted.example.com',171    'http://127.0.0.1\\@public.example.com',172    'https://attacker.com\\@api.internal',173    'http://a\\@b',174    'ws://evil.com\\@allowed.com/chat',175    'wss://evil.com\\@allowed.com/chat',176    'http://evil.com\\%40allowed.com',177    '//evil.com\\@allowed.com'178  ]179 180  t.plan(cases.length)181 182  cases.forEach((input) => {183    t.equal(184      fastURI.parse(input).error,185      'URI authority must not contain a literal backslash.',186      input187    )188  })189})190 191test('normalize does not canonicalize a literal-backslash URI into a different valid URL', (t) => {192  const cases = [193    'http://evil.com\\@allowed.com',194    'https://attacker.com\\@api.internal'195  ]196 197  t.plan(cases.length)198 199  cases.forEach((input) => {200    t.equal(fastURI.normalize(input), input, input)201  })202})203 204test('parse leaves percent-encoded %5C untouched as encoded data (not rejected)', (t) => {205  // Only the literal "\" byte is rejected; %5C stays valid encoded data and206  // does not diverge from the native URL parser, so it must not be flagged.207  const input = 'http://evil.com%5C@allowed.com'208  const parsed = fastURI.parse(input)209 210  t.plan(2)211  t.notOk(parsed.error, '%5C is valid encoded data, not malformed')212  t.equal(parsed.host, new URL(input).hostname, '%5C host matches native URL (no divergence)')213})214 215test('parse does not reject a literal backslash in the query or fragment', (t) => {216  // The rejection is scoped to the authority/path (the host-confusion surface);217  // a backslash after "?"/"#" is normalized as encoded data as before.218  const parsed = fastURI.parse('http://host.example.com/?x=\\y#z\\w')219 220  t.plan(2)221  t.notOk(parsed.error, 'backslash in query/fragment does not mark the URI malformed')222  t.equal(parsed.host, 'host.example.com', 'host parsed normally')223})224 225test('parse rejects a malformed authority introducer (\\\\, /\\, \\/) in place of //', (t) => {226  // Regression: "\\", "/\\", "\\/" after the scheme colon are not valid authority227  // introducers. Node's URL treats "\\" as interchangeable with "/" on special228  // schemes, so "http:\\\\evil.com/path" would be parsed as host "evil.com" by229  // Node, but fast-uri must reject it as malformed to prevent SSRF/redirect bypass.230  const cases = [231    'http:\\\\evil.com/path',232    'http:/\\evil.com/path',233    'http:\\/evil.com/path',234    'ws:\\\\evil.com/chat',235    'wss:\\\\evil.com/chat',236    'ftp:\\\\evil.com/',237    '\\\\evil.com/path'238  ]239 240  t.plan(cases.length)241 242  cases.forEach((input) => {243    t.equal(244      fastURI.parse(input).error,245      'URI authority must not contain a literal backslash.',246      input247    )248  })249})250 251test('normalize does not canonicalize a malformed-authority-introducer URI', (t) => {252  const cases = [253    'http:\\\\evil.com/path',254    'http:/\\evil.com/path'255  ]256 257  t.plan(cases.length)258 259  cases.forEach((input) => {260    t.equal(fastURI.normalize(input), input, input)261  })262})263 264test('equal returns false for malformed-authority-introducer URIs', (t) => {265  const pairs = [266    ['http:\\\\evil.com/path', 'http://evil.com/path'],267    ['http:/\\evil.com/path', 'http://evil.com/path']268  ]269 270  t.plan(pairs.length)271 272  pairs.forEach(([left, right]) => {273    t.equal(fastURI.equal(left, right), false, `${left} != ${right}`)274  })275})276 277test('resolve throws on malformed authority introducer', (t) => {278  // resolve() returns a plain string with no error field, so the only safe279  // behavior is to throw when either component has a malformed authority.280  const pairs = [281    ['https://allowed.com/', '\\\\evil.com/path'],282    ['\\\\evil.com/path', 'https://allowed.com/'],283    ['https://allowed.com/', 'http:/\\evil.com/path'],284    ['https://allowed.com/', 'http:\\/evil.com/path']285  ]286 287  t.plan(pairs.length)288 289  pairs.forEach(([base, rel]) => {290    t.throws(291      () => fastURI.resolve(base, rel),292      /URI authority must not contain a literal backslash/,293      `${base} + ${rel}`294    )295  })296})297 298test('parse rejects a whitespace-split authority introducer (TAB, LF, CR)', (t) => {299  // The WHATWG URL parser removes TAB (U+0009), LF (U+000A) and CR (U+000D) from300  // the input before parsing, so a stripped character wedged into the introducer301  // ("/<TAB>\\", "/<TAB>/", or a leading "<TAB>//") reaches an authority in Node302  // while fast-uri would otherwise fold it into the path. These must be rejected303  // like the adjacent "\\", "/\\", "\\/" forms.304  const cases = [305    { input: '/\t\\evil.com/path', expectedError: 'URI authority must not contain a literal backslash.' },306    { input: '/\t/evil.com/path', expectedError: 'URI authority introducer must not contain whitespace.' },307    { input: '/\n\\evil.com/path', expectedError: 'URI authority must not contain a literal backslash.' },308    { input: '/\r\\evil.com/path', expectedError: 'URI authority must not contain a literal backslash.' },309    { input: '\t//evil.com/path', expectedError: 'URI authority introducer must not contain whitespace.' },310    { input: '\t/\\evil.com/path', expectedError: 'URI authority must not contain a literal backslash.' },311    { input: 'https:/\t/evil.com/path', expectedError: 'URI authority introducer must not contain whitespace.' }312  ]313 314  t.plan(cases.length)315 316  cases.forEach(({ input, expectedError }) => {317    t.equal(fastURI.parse(input).error, expectedError, JSON.stringify(input))318  })319})320 321test('resolve throws on a whitespace-split authority introducer', (t) => {322  const pairs = [323    ['https://allowed.com/', '/\t\\evil.com/path'],324    ['https://allowed.com/', '/\t/evil.com/path'],325    ['https://allowed.com/', '/\n\\evil.com/path'],326    ['/\t/evil.com/path', 'https://allowed.com/']327  ]328 329  t.plan(pairs.length)330 331  pairs.forEach(([base, rel]) => {332    t.throws(333      () => fastURI.resolve(base, rel),334      /URI authority (must not contain a literal backslash|introducer must not contain whitespace)/,335      `${JSON.stringify(base)} + ${JSON.stringify(rel)}`336    )337  })338})339 340test('parse does not reject valid authority introducer patterns', (t) => {341  // No false positives: "//" introducer and scheme-less "//" must be valid.342  const cases = [343    'http://good.com/',344    'https://good.com/',345    'ws://good.com/chat',346    'wss://good.com/chat',347    'ftp://good.com/',348    '//good.com/path',349    '/absolute/path',350    'relative/path'351  ]352 353  t.plan(cases.length)354 355  cases.forEach((input) => {356    const parsed = fastURI.parse(input)357    t.notOk(parsed.error, input)358  })359})360 
Brunobkr/llama.cpp_AlgMor24_github · Team Ai