Run3 patch generation
Generating and saving git-compatible patch files for Apache Druid source code.From its SKILL.md
npx -y skills add cxcscmu/SkillLearnBench --skill run3_patch-generationAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
0.9 KB, 188 tokens by cl100k_base, as published. Nobody here has run it
To address the vulnerability, identify the JavaScriptConfig class responsible for deserializing the malicious payload. Use grep to locate the handling of the empty string key "".
Create a patch file at /root/patches/fix-js-config.patch that removes the setter method or the logic inside JavaScriptConfig (or its factory/builder) that maps the empty string to the enabled configuration.
Example approach:
- Locate
src/main/java/org/apache/druid/js/JavaScriptConfig.java. - Inspect the JSON deserialization logic. If there is a method like
setor a@JsonCreatorthat accepts"", modify the code to ignore or explicitly throw an exception when such a key is encountered. - Generate the patch using:
cd /root/druid git diff > /root/patches/fix-js-config.patch
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.