Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
118 commits
Select commit Hold shift + click to select a range
188656c
sync repo
AdilElFarissi Jun 24, 2026
67b04db
set back the file ending for the cross OS compatibility
AdilElFarissi Jun 24, 2026
977b91a
Create security-scan.yml
AdilElFarissi Jun 26, 2026
8baa484
Add OpenSim.sln needed by the security workflow...
AdilElFarissi Jun 26, 2026
32dc80d
Merge branch 'master' of https://github.com/AdilElFarissi/opensim
AdilElFarissi Jun 26, 2026
fd63568
Update security-scan.yml
AdilElFarissi Jun 26, 2026
3f4711f
Fix security-scan.yml
AdilElFarissi Jun 26, 2026
566589f
Update security-scan.yml
AdilElFarissi Jun 26, 2026
9be0810
Update security-scan.yml
AdilElFarissi Jun 26, 2026
62eb7e5
Create codeql.yml
AdilElFarissi Jun 26, 2026
8344e4c
Update .gitignore
AdilElFarissi Jun 26, 2026
fcb3164
Create copilot-instructions.md
AdilElFarissi Jun 27, 2026
b412911
Update security-scan.yml
AdilElFarissi Jun 27, 2026
086b1c2
Update security-scan.yml
AdilElFarissi Jun 27, 2026
798b4a1
Merge branch 'opensim:master' into master
AdilElFarissi Jun 27, 2026
7dab488
Update security-scan.yml
AdilElFarissi Jun 27, 2026
0ccb5b9
Merge branch 'master' of https://github.com/AdilElFarissi/opensim
AdilElFarissi Jun 27, 2026
a8d0f26
style: resolve static security vulnerabilities via OpenRouter AI
AdilElFarissi Jun 27, 2026
1fd9187
Merge pull request #1 from AdilElFarissi/openrouter-ai-patches
AdilElFarissi Jun 27, 2026
0be5a29
Update security-scan.yml
AdilElFarissi Jun 27, 2026
e22af02
Update security-scan.yml
AdilElFarissi Jun 27, 2026
07e204c
Update security-scan.yml
AdilElFarissi Jun 27, 2026
acdf6cf
Update security-scan.yml
AdilElFarissi Jun 27, 2026
b3ac62a
Update security-scan.yml
AdilElFarissi Jun 27, 2026
8098c07
Update security-scan.yml
AdilElFarissi Jun 27, 2026
059fa1d
Update security-scan.yml
AdilElFarissi Jun 27, 2026
b37af16
Update security-scan.yml
AdilElFarissi Jun 27, 2026
b6b3f16
Update security-scan.yml
AdilElFarissi Jun 27, 2026
efdaf99
Update security-scan.yml
AdilElFarissi Jun 27, 2026
a8aefca
Update security-scan.yml
AdilElFarissi Jun 27, 2026
8a9d1af
Update security-scan.yml
AdilElFarissi Jun 27, 2026
548801e
Update security-scan.yml
AdilElFarissi Jun 27, 2026
3d9bb71
Update security-scan.yml
AdilElFarissi Jun 27, 2026
5b54aca
Update security-scan.yml
AdilElFarissi Jun 27, 2026
c52f18e
Update security-scan.yml
AdilElFarissi Jun 27, 2026
4dd0c5c
Update security-scan.yml
AdilElFarissi Jun 27, 2026
ef50c50
Update security-scan.yml
AdilElFarissi Jun 27, 2026
8b8dfbd
Update security-scan.yml
AdilElFarissi Jun 27, 2026
aa79497
Update security-scan.yml
AdilElFarissi Jun 27, 2026
a94c0ac
Update security-scan.yml
AdilElFarissi Jun 27, 2026
333ba2d
Update security-scan.yml
AdilElFarissi Jun 28, 2026
70bcc5d
Update security-scan.yml
AdilElFarissi Jun 28, 2026
2cf4c1a
Potential fix for code scanning alert no. 18: Unvalidated local point…
AdilElFarissi Jun 28, 2026
a006aa2
Potential fix for code scanning alert no. 23: Unvalidated local point…
AdilElFarissi Jun 28, 2026
a5a0360
update ai workflow tests...
AdilElFarissi Jun 28, 2026
4427edb
Update security-scan.yml
AdilElFarissi Jun 28, 2026
3bbb25d
Update security-scan.yml
AdilElFarissi Jun 28, 2026
4b49e6f
Update security-scan.yml
AdilElFarissi Jun 28, 2026
668bf10
Update security-scan.yml
AdilElFarissi Jun 28, 2026
becd139
Update security-scan.yml
AdilElFarissi Jun 29, 2026
53a8274
Update security-scan.yml
AdilElFarissi Jun 29, 2026
adedf7c
Update security-scan.yml
AdilElFarissi Jun 29, 2026
0b9c367
Update security-scan.yml
AdilElFarissi Jun 29, 2026
55ec39a
Update security-scan.yml
AdilElFarissi Jun 29, 2026
859a7ac
Update security-scan.yml
AdilElFarissi Jun 29, 2026
59f1f39
Update security-scan.yml
AdilElFarissi Jun 29, 2026
8c197e2
Update security-scan.yml
AdilElFarissi Jun 29, 2026
5d70229
Update security-scan.yml
AdilElFarissi Jun 29, 2026
45d0d2c
Update security-scan.yml
AdilElFarissi Jun 29, 2026
81a65ed
Update security-scan.yml
AdilElFarissi Jun 29, 2026
348027d
Update .gitattributes
AdilElFarissi Jul 2, 2026
e0fd3eb
Merge branch 'opensim:master' into master
AdilElFarissi Jul 2, 2026
f58ca25
removal of unused using and AI tests
AdilElFarissi Jul 2, 2026
6428bbf
mass simplifications...
AdilElFarissi Jul 2, 2026
f32c301
Potential fix for code scanning alert no. 16: Unvalidated local point…
AdilElFarissi Jul 2, 2026
50bfab4
Delete OpenSim.sln
AdilElFarissi Jul 5, 2026
f0ace91
Delete fix_code.py
AdilElFarissi Jul 5, 2026
a403086
Potential fix for code scanning alert no. 5221: Invalid string format…
AdilElFarissi Jul 5, 2026
81bd765
Add GitHub Actions workflow for mass autofix
AdilElFarissi Jul 5, 2026
7e9b9d2
Update copilot instructions with new coding guidelines
AdilElFarissi Jul 5, 2026
dbfc329
Add instruction to check for breaking changes
AdilElFarissi Jul 5, 2026
22053d0
Remove pip upgrade from mass-autofix workflow
AdilElFarissi Jul 5, 2026
95ab03b
Enhance mass autofix script for security alerts
AdilElFarissi Jul 5, 2026
3730fea
Enhance mass autofix workflow with custom instructions
AdilElFarissi Jul 5, 2026
2013c29
Fix base URL formatting in mass-autofix.yml
AdilElFarissi Jul 5, 2026
0e5f5bc
Enhance mass-autofix workflow with scheduling and fixes
AdilElFarissi Jul 5, 2026
876ed68
Fix syntax for success status code check in autofix
AdilElFarissi Jul 5, 2026
16bbe00
Update mass-autofix.yml
AdilElFarissi Jul 5, 2026
516527b
Update mass-autofix.yml
AdilElFarissi Jul 5, 2026
9df77a2
Update mass-autofix.yml
AdilElFarissi Jul 5, 2026
f19cab7
test & force rescan
AdilElFarissi Jul 5, 2026
2ae367c
Fix formatting issue in mass-autofix.yml
AdilElFarissi Jul 5, 2026
4f52ec1
Delete .github/workflows/mass-autofix.yml
AdilElFarissi Jul 5, 2026
eb5f0b2
Create mass-code-autofix.yml
AdilElFarissi Jul 5, 2026
7aac959
Fix status code comparison in workflow file
AdilElFarissi Jul 5, 2026
ea025f8
Update mass-code-autofix.yml
AdilElFarissi Jul 5, 2026
1cbb349
Merge branch 'master' of https://github.com/AdilElFarissi/opensim
AdilElFarissi Jul 5, 2026
a5d79fd
Update mass-code-autofix.yml
AdilElFarissi Jul 5, 2026
63835e2
Update mass-code-autofix.yml
AdilElFarissi Jul 5, 2026
b30d49d
Update mass-code-autofix.yml
AdilElFarissi Jul 5, 2026
83b0fc5
test copilot autofix
AdilElFarissi Jul 5, 2026
4f07f4d
Update mass-code-autofix.yml
AdilElFarissi Jul 5, 2026
a2dd359
Update autofix.sh
AdilElFarissi Jul 5, 2026
f62f0cb
update autofixer
AdilElFarissi Jul 5, 2026
2ce9d6d
Update mass-code-autofix.yml
AdilElFarissi Jul 5, 2026
7fb1280
Update mass-code-autofix.yml
AdilElFarissi Jul 5, 2026
4cd89f9
Update mass-code-autofix.yml
AdilElFarissi Jul 5, 2026
a57df61
Update mass-code-autofix.yml
AdilElFarissi Jul 6, 2026
83e4a0f
Update mass-code-autofix.yml
AdilElFarissi Jul 7, 2026
7bf8949
Commit Autofix #5577 (cs/invalid-string-formatting)
AdilElFarissi Jul 7, 2026
bc00456
Commit Autofix #5575 (cs/unvalidated-local-pointer-arithmetic)
AdilElFarissi Jul 7, 2026
d254789
Remove redundant return statement in Meshmerizer.cs
AdilElFarissi Jul 7, 2026
201f102
Fix missing closing brace in Meshmerizer.cs
AdilElFarissi Jul 7, 2026
f277284
Remove Semgrep scan from security-scan.yml
AdilElFarissi Jul 7, 2026
cb3da44
Refactor Meshmerizer to use pointer arithmetic
AdilElFarissi Jul 7, 2026
d17b47b
Commit Autofix #5575 (cs/unvalidated-local-pointer-arithmetic)
AdilElFarissi Jul 7, 2026
de66224
Optimize pointer usage for data processing
AdilElFarissi Jul 7, 2026
6fd69ae
Update mass-code-autofix.yml
AdilElFarissi Jul 7, 2026
54bc121
Update mass-code-autofix.yml
AdilElFarissi Jul 7, 2026
7552eda
Update mass-code-autofix.yml
AdilElFarissi Jul 7, 2026
79b8389
Update mass-code-autofix.yml
AdilElFarissi Jul 7, 2026
1b82382
Update mass-code-autofix.yml
AdilElFarissi Jul 7, 2026
2c71106
Update mass-code-autofix.yml
AdilElFarissi Jul 7, 2026
7cfb6d0
Merge branch 'opensim:master' into master
AdilElFarissi Jul 7, 2026
ecb7b60
Update mass-code-autofix.yml
AdilElFarissi Jul 8, 2026
26e1dd5
Merge branch 'master' of https://github.com/AdilElFarissi/opensim
AdilElFarissi Jul 8, 2026
ebd478d
Update mass-code-autofix.yml
AdilElFarissi Jul 8, 2026
a8c8a91
style: resolve static security vulnerabilities via OpenRouter AI
AdilElFarissi Jul 9, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -21,3 +21,4 @@
*.so binary
*.dylib binary
*.anim binary
*.cs text eol=lf
20 changes: 20 additions & 0 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
# OpenSimulator AI Code Remediation Rules

You are an automated code repair agent fixing vulnerabilities and bugs in OpenSimulator (C# / .NET 8). You must strictly follow these structural and architectural rules to avoid breaking legacy systems.

## 1. Threading & Memory Architecture
* **No Thread-Unsafe State Modifications**: OpenSimulator heavily relies on multi-threaded scene updates. Never introduce unsynchronized global states or un-threaded collections.
* **Locking Protocols**: When fixing race conditions, always use existing synchronization objects (e.g., `lock (m_sceneGraph)`). Do not introduce nested locks that could cause deadlocks.
* **Avoid GC Spikes**: Do not rewrite loops to use heavy LINQ expressions in high-frequency update loops (e.g., `Scene.Update()`). Keep memory allocations low to prevent Garbage Collection spikes.

## 2. Network & Serialization Boundaries
* **Protocol Compatibility**: OpenSimulator interacts with legacy client viewers (like Second Life viewers) using fixed UDP/TCP packet structures. Do not alter packet serialization layouts or byte orderings when fixing buffer overflows or input validation bugs.
* **No Breaking API Changes**: Do not change public method signatures or data contracts in the `OpenSim.Framework` or `OpenSim.Region.Framework` namespaces, as third-party modules rely on them.
* **Change WebHttpRequest to HttpClient**: Always replace WebHttpRequest and similar functions with HttpClient. The HttpClient must be initialized using the GetNewGlobalHttpClient(timeout) method from OpenSim/Framework/WebUtil.cs.

## 3. Code Style & Generation Constraints
* **Respect Prebuild Blueprints**: Do not manually modify `.csproj` or `.sln` files. All project structures are driven dynamically by `prebuild.xml`. If a dependency change is required, modify `prebuild.xml` instead.
* **Logging Standards**: When fixing error handling or catch blocks, use the internal Log4Net interface (`m_log.Error(...)`). Do not use `Console.WriteLine` or standard System.Diagnostics tracing.
* **Null Safety**: Prioritize modern C# 8+ null-coalescing operators (`??=`) and patterns, but ensure compatibility with existing legacy type checking systems used across the codebase.
* ** Check Breaking Changes**: Check the method references if the current change break something where the method is used and rework the fix if is the case.
* **Add Missing Summary**: If the context method doesn't have a summary, add a short summary explaining the method, its parameters, the expected return value, and exceptions.
105 changes: 105 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,105 @@
# For most projects, this workflow file will not need changing; you simply need
# to commit it to your repository.
#
# You may wish to alter this file to override the set of languages analyzed,
# or to provide custom queries or build logic.
#
# ******** NOTE ********
# We have attempted to detect the languages in your repository. Please check
# the `language` matrix defined below to confirm you have the correct set of
# supported CodeQL languages.
#
name: "CodeQL Advanced"

on:
push:
branches: [ "master" ]
pull_request:
branches: [ "master" ]
schedule:
- cron: '17 20 * * 4'

jobs:
analyze:
name: Analyze (${{ matrix.language }})
# Runner size impacts CodeQL analysis time. To learn more, please see:
# - https://gh.io/recommended-hardware-resources-for-running-codeql
# - https://gh.io/supported-runners-and-hardware-resources
# - https://gh.io/using-larger-runners (GitHub.com only)
# Consider using larger runners or machines with greater resources for possible analysis time improvements.
runs-on: ${{ (matrix.language == 'swift' && 'macos-latest') || 'ubuntu-latest' }}
permissions:
# required for all workflows
security-events: write

# required to fetch internal or private CodeQL packs
packages: read

# only required for workflows in private repositories
actions: read
contents: read

strategy:
fail-fast: false
matrix:
include:
- language: actions
build-mode: none
- language: csharp
build-mode: none
- language: javascript-typescript
build-mode: none
- language: python
build-mode: none
# CodeQL supports the following values keywords for 'language': 'actions', 'c-cpp', 'csharp', 'go', 'java-kotlin', 'javascript-typescript', 'python', 'ruby', 'rust', 'swift'
# Use `c-cpp` to analyze code written in C, C++ or both
# Use 'java-kotlin' to analyze code written in Java, Kotlin or both
# Use 'javascript-typescript' to analyze code written in JavaScript, TypeScript or both
# To learn more about changing the languages that are analyzed or customizing the build mode for your analysis,
# see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning.
# If you are analyzing a compiled language, you can modify the 'build-mode' for that language to customize how
# your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages
steps:
- name: Checkout repository
uses: actions/checkout@v4

# Add any setup steps before running the `github/codeql-action/init` action.
# This includes steps like installing compilers or runtimes (`actions/setup-node`
# or others). This is typically only required for manual builds.
# - name: Setup runtime (example)
# uses: actions/setup-example@v1

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.

# For more details on CodeQL's query packs, refer to: https://docs.github.com/en/code-security/code-scanning/automatically-scanning-your-code-for-vulnerabilities-and-errors/configuring-code-scanning#using-queries-in-ql-packs
# queries: security-extended,security-and-quality

# If the analyze step fails for one of the languages you are analyzing with
# "We were unable to automatically build your code", modify the matrix above
# to set the build mode to "manual" for that language. Then modify this step
# to build your code.
# ℹ️ Command-line programs to run using the OS shell.
# 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun
- name: Run manual build steps
if: matrix.build-mode == 'manual'
shell: bash
run: |
echo 'If you are using a "manual" build mode for one or more of the' \
'languages you are analyzing, replace this with the commands to build' \
'your code, for example:'
echo ' make bootstrap'
echo ' make release'
exit 1

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
with:
category: "/language:${{matrix.language}}"
Loading