Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,8 @@
**Vulnerability:** Raw `stop()` and `warning()` calls without `call. = FALSE` in `llcont.R` and `vuongtest.R` exposed execution stack/call details when raised.
**Learning:** While some instances of `stop()` inside `tryCatch()` were previously fixed to hide the call stack, other standalone exceptions and warnings still leaked call context. Security must be consistently applied across the entire codebase.
**Prevention:** Always set `call. = FALSE` when using `stop()` or `warning()` to enforce a secure-by-default boundary and prevent internal execution paths from being disclosed to the end user.

## 2026-08-07 - Add input validation for exported functions
**Vulnerability:** Unvalidated arguments passed to exported functions (`vuongtest` and `icci`) could bypass top-level `stop(..., call. = FALSE)` safeguards and trigger raw R errors deep inside internal logic, leaking internal execution contexts.
**Learning:** In R codebases, exported functions must explicitly validate argument types, lengths, and bounds (e.g., `length(x) == 1`, `match.arg()`) to fail securely and avoid information disclosure.
**Prevention:** Always strictly validate the type, length, and bounds of user inputs at the very beginning of exported functions, using `stop(..., call. = FALSE)` to securely halt execution on invalid input.
4 changes: 4 additions & 0 deletions R/icci.R
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,10 @@
#' @export
icci <- function(object1, object2, conf.level=.95, ll1=llcont, ll2=llcont) {

if (!is.numeric(conf.level) || length(conf.level) != 1 || is.na(conf.level) || conf.level <= 0 || conf.level >= 1) {
stop("Argument 'conf.level' must be a single numeric value between 0 and 1.", call. = FALSE)
}

## check objects, issue warnings/errors, get classes/calls
obinfo <- check.obj(object1, object2)
callA <- obinfo$callA; classA <- obinfo$classA
Expand Down
7 changes: 6 additions & 1 deletion R/vuongtest.R
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,12 @@
#' @importMethodsFrom lavaan coef fitted logLik vcov
#' @importFrom methods slotNames
#' @export
vuongtest <- function(object1, object2, nested=FALSE, adj="none", ll1=llcont, ll2=llcont, score1=NULL, score2=NULL, vc1=vcov, vc2=vcov) {
vuongtest <- function(object1, object2, nested=FALSE, adj=c("none", "aic", "bic"), ll1=llcont, ll2=llcont, score1=NULL, score2=NULL, vc1=vcov, vc2=vcov) {

if (!is.logical(nested) || length(nested) != 1 || is.na(nested)) {
stop("Argument 'nested' must be a single logical value.", call. = FALSE)
}
adj <- match.arg(adj)

## check objects, issue warnings/errors, get classes/calls
obinfo <- check.obj(object1, object2)
Expand Down
Loading