Files
GOD-CWAK/BUGS_FOUND.md

294 lines
14 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# BUGS_FOUND.md
## FIXED (2026-05-22 — all 47 resolved)
| # | Severity | File(s) | Fix summary |
|---|----------|---------|-------------|
| 1 | CRITICAL | orchestrator.py | CAPTCHA → manual-pause mode; no infinite re-queue; documented honestly |
| 2 | CRITICAL | orchestrator.py | Rate-limited proxy returned to pool via `return_proxy()` instead of dropped |
| 3 | CRITICAL | login_client.py | Removed broad `facebook.com` catch-all; success requires cookies or explicit URL fragments; added privacy/help/about/terms to failure_url_fragments |
| 4 | CRITICAL | file_io.py | Added `stream_passwords()` generator; added `count_passwords()`; `load_passwords()` uses streaming |
| 5 | CRITICAL | orchestrator.py | `_retry_queue` replaces `_password_index -= 1`; workers drain retry queue first; per-password retry cap |
| 6 | HIGH | password_generator.py | `symbols_between=True` auto-adds `{word}{sym}{num}` and `{num}{sym}{word}` to active patterns |
| 7 | HIGH | login_client.py | Generic sites: GET login page, scrape all `<input type="hidden">` fields into POST payload |
| 8 | HIGH | login_client.py | `session.cookies.clear()` called at start of every `attempt_login()` |
| 9 | HIGH | orchestrator.py | CAPTCHA max-retry enforced: after `_max_captcha_retries` password is skipped, not re-queued |
| 10 | HIGH | pool.py | `fetch_and_validate()` merges via `add_proxies()` instead of full reset |
| 11 | HIGH | validator.py | `test_batch_sync` uses `new_event_loop() / run_until_complete() / close()` pattern |
| 12 | HIGH | file_io.py | `save_valid_proxies()` reads existing file, merges, dedupes, then writes |
| 13 | HIGH | setup_tab.py | `pull_model` iterates `resp.iter_lines()`, returns True only on `"status":"success"` |
| 14 | HIGH | captcha/*.py | Added pipeline docstrings: "manual from Setup tab only; will be wired in future release" |
| 15 | HIGH | attack_tab.py | Added Direct Mode CTkCheckBox; no-proxy start shows confirmation dialog |
| 16 | MEDIUM | password_generator.py, password_builder_tab.py | `estimate()` docstring and UI label say "upper bound" |
| 17 | MEDIUM | combinatorics.py | `generate_number_suffixes()` has `max_count=5000` cap |
| 18 | MEDIUM | file_io.py | `save_passwords(dedupe=True)` loads existing, unions, dedupes, writes |
| 19 | MEDIUM | pool.py | `mark_dead()` rebuilds queue from `_all_valid` after removal |
| 20 | MEDIUM | pool.py | Low-water qsize check moved inside `with self._lock:` block |
| 21 | MEDIUM | config.py | Removed `PROXIFLY_API_KEY/URL/FALLBACK_URL` |
| 22 | MEDIUM | fetcher.py | `_IP_PORT_RE` extended to match `hostname:port` patterns |
| 23 | MEDIUM | setup_tab.py | `_on_save_config` starts from `DEFAULT_OLLAMA_CONFIG`, merges all keys |
| 24 | MEDIUM | app.py, setup_tab.py | `GODCWAKApp` creates `self.captcha_solver`; setup_tab reloads shared instance |
| 25 | MEDIUM | ollama_client.py | Replaced shallow regex with balanced-brace extractor + fenced-block support |
| 26 | MEDIUM | orchestrator.py, attack_tab.py | Added `passwords_completed` field; UI uses completions not dispatch index |
| 27 | MEDIUM | main.py | `check_dependencies()` now checks `aiohttp` and `aiohttp_socks` |
| 28 | MEDIUM | requirements.txt | Removed pandas/colorama/python-dotenv; added playwright as optional comment |
| 29 | MEDIUM | logs_tab.py | CSV export uses `encoding="utf-8-sig"` for Excel BOM compatibility |
| 30 | MEDIUM | file_io.py | `load_passwords()` deduplicates with `dict.fromkeys()` preserving order |
| 31 | MEDIUM | password_builder_tab.py | `camel_case` omitted from UI (duplicates first_letter_caps); `sequential_numbers` defaults off |
| 32 | MEDIUM | pool.py | `_refresh_worker` logs WARNING when 0 proxies added; stores `_last_refresh_count` |
| 33 | LOW | captcha_solver.py | `_model_family()` now called from `_default_prompt()` to select OCR vs vision prompt |
| 34 | LOW | captcha_solver.py | `_parse_answer` tile mode: `digit_count >= 1` (was `>= 2`) |
| 35 | LOW | config.py, main.py | `DATA_DIR.mkdir()` moved to `ensure_dirs()` function; called at startup |
| 36 | LOW | GODCWAK.bat | First-run detection: checks `.installed` sentinel; runs pip install on first launch |
| 37 | LOW | pool.py | Stale "Proxifly" reference removed from `fetch_and_validate` |
| 38 | LOW | requirements.txt | Already covered by #28 |
| 39 | LOW | browser_controller.py | Missing browser error caught specifically; logs "Run: playwright install chromium" |
| 40 | LOW | orchestrator.py | `stop()` sets `_stop_event`; workers check it; `join(timeout=3.0)` on all threads |
| 41 | UI/UX | workflow.py, setup/attack/logs tabs | Reordered: 01 PW Builder, 02 Proxy, 03 Setup, 04 Attack, 05 Logs |
| 42 | UI/UX | attack_tab.py | Proxies chip now says "✗ NEED PROXIES" (red) not "optional" |
| 43 | UI/UX | proxy_manager_tab.py | TEST ALL runs 10 concurrent threads (semaphore); reduces test time ~10× |
| 44 | UI/UX | password_builder_tab.py | Min/max sliders clamp each other so min ≤ max is always enforced |
| 45 | UI/UX | proxy_manager_tab.py | Saved proxies load as orange "SAVED" state; green only after live TEST |
| 46 | UI/UX | password_builder_tab.py | CANCEL button appears during generation; sets `_cancel_generation` flag |
| 47 | UI/UX | attack_tab.py | Live log truncation increased from 28 → 50 chars for proxy and password |
---
> Full bug hunt & edge-case audit — GODCWAK (Python 3.12)
> Date: 2026-05-22
> All `.py` files compile. Import smoke tests pass. Issues below are from code review + targeted runtime checks.
---
## Summary
| Severity | Count |
|----------|------:|
| CRITICAL | 5 |
| HIGH | 10 |
| MEDIUM | 17 |
| LOW | 8 |
| UI/UX | 7 |
| **Total** | **47** |
---
## CRITICAL
### 1. CAPTCHA detected but never solved during attack
**Files:** `src/attack/orchestrator.py`, `src/gui/attack_tab.py`, `src/captcha/*`
**Issue:** Orchestrator only calls `on_captcha(proxy)` — no screenshot, no `CaptchaSolver`, no browser. Attack tab logs and flashes border. Full CAPTCHA pipeline (`screenshotter`, `coord_mapper`, `ollama_client`, `browser_controller`) is dead code.
**Edge case:** Any CAPTCHA response → infinite re-queue loop.
**Fix:** Wire capture → Ollama solve → submit answer (or pause for manual solve).
### 2. Rate-limited proxies leak from pool
**Files:** `src/attack/orchestrator.py``_release_proxy_after_attempt`
**Issue:** On rate limit, proxy is dropped (`current_proxy = None`) but never `return_proxy()` or `mark_dead()`.
**Edge case:** Pool drains over long runs with rate limits.
**Fix:** Return to pool after cooldown or quarantine queue.
### 3. Facebook false-positive login success
**Files:** `src/attack/login_client.py``_analyse`
**Issue:** URL containing `facebook.com` without `login` can be marked SUCCESS without `c_user`/`xs` cookies (e.g. privacy/checkpoint pages).
**Edge case:** `https://www.facebook.com/privacy/...` → bogus SUCCESS.
**Fix:** Require success cookies or explicit success URL fragments only.
### 4. Full wordlist loaded into RAM on START
**Files:** `src/gui/attack_tab.py`, `src/utils/file_io.py`
**Issue:** `load_passwords()` reads entire `data/passwords.txt` into a list.
**Edge case:** GPU-generated millions of passwords → OOM / GUI freeze.
**Fix:** Streaming password iterator + resume checkpoint.
### 5. Password index race on re-queue
**Files:** `src/attack/orchestrator.py`
**Issue:** `_password_index -= 1` on no-proxy/CAPTCHA under lock, but multiple workers can still duplicate the same password.
**Edge case:** Empty proxy pool + 3 workers → same password tried in parallel.
**Fix:** Per-password retry queue or per-worker cursors.
---
## HIGH
### 6. `symbols_between` checkbox does nothing
**Files:** `src/engine/password_generator.py`, `src/gui/password_builder_tab.py`
**Issue:** Flag only gates symbol list building; no `{sym}`-between pattern logic. Verified: `{word}{num}` only → no symbols inserted.
**Fix:** Auto-add `{word}{sym}{num}` patterns when enabled, or remove checkbox.
### 7. Generic sites POST without CSRF tokens
**Files:** `src/attack/login_client.py``SiteConfig.for_url`
**Issue:** Clears `token_patterns`; most sites reject bare username/password POST.
**Fix:** Auto-scrape hidden inputs or user-defined token map in Attack tab.
### 8. Thread-local session keeps cookies across passwords
**Files:** `src/attack/login_client.py`
**Issue:** Worker reuses one session for all attempts; failed login may pollute cookies for next password.
**Fix:** Clear cookies per attempt or new session per password.
### 9. CAPTCHA max retry is logged but not enforced
**Files:** `src/attack/orchestrator.py`
**Issue:** After `_max_captcha_retries`, still re-queues same password forever.
**Fix:** Skip password or halt with user prompt.
### 10. `fetch_and_validate` resets entire pool
**Files:** `src/proxy/pool.py`
**Issue:** Replaces `_all_valid` and rebuilds queue; ignores in-flight proxies. Not GUI-wired but dangerous if called during attack.
**Fix:** Merge new proxies instead of full reset.
### 11. `asyncio.run()` from background threads
**Files:** `src/proxy/validator.py`, `src/proxy/pool.py`
**Issue:** New event loop per validation batch from daemon threads; fragile under load.
**Fix:** Dedicated async thread or sync HTTP validator.
### 12. Proxy COMMIT overwrites saved file
**Files:** `src/gui/proxy_manager_tab.py`, `src/utils/file_io.py`
**Issue:** `save_valid_proxies` writes only current UI greens; prior committed proxies lost.
**Fix:** Merge + dedupe on commit.
### 13. `OllamaManager.pull_model` false success
**Files:** `src/gui/setup_tab.py`
**Issue:** Returns True on HTTP 200 without consuming pull stream.
**Fix:** Iterate stream until `"status":"success"`.
### 14. CAPTCHA pipeline modules unused
**Files:** `src/captcha/ollama_client.py`, `coord_mapper.py`, `screenshotter.py`, `browser_controller.py`
**Issue:** Never imported from attack/GUI flow.
**Fix:** Wire or remove.
### 15. Attack starts with zero proxies
**Files:** `src/gui/attack_tab.py`
**Issue:** Warns but allows START; all traffic from real IP.
**Fix:** Block START or explicit “direct mode” toggle.
---
## MEDIUM
### 16. Password estimate diverges from actual count
**Files:** `src/engine/password_generator.py`
### 17. `generate_number_suffixes` combinatorial explosion (09999 + padding variants)
**Files:** `src/engine/combinatorics.py`
### 18. `save_passwords` always appends → duplicate wordlist bloat
**Files:** `src/utils/file_io.py`, `password_builder_tab.py`
### 19. `mark_dead` doesnt remove proxy already sitting in queue
**Files:** `src/proxy/pool.py`
### 20. Low-water proxy refresh race (`qsize()` outside lock)
**Files:** `src/proxy/pool.py`
### 21. Dead `PROXIFLY_*` config keys
**Files:** `config.py`
### 22. Proxy fetcher IPv4-only regex (no hostnames/IPv6)
**Files:** `src/proxy/fetcher.py`
### 23. Setup save omits some fields (`top_p`, timeout) from JSON
**Files:** `src/gui/setup_tab.py`
### 24. Save config creates throwaway `CaptchaSolver` — no global instance
**Files:** `src/gui/setup_tab.py`
### 25. `OllamaVisionClient._parse_response` shallow JSON regex
**Files:** `src/captcha/ollama_client.py`
### 26. `stats.passwords_tried` tracks dispatch index, not completions
**Files:** `src/attack/orchestrator.py`
### 27. `main.check_dependencies` missing aiohttp/aiohttp-socks
**Files:** `main.py`
### 28. `requirements.txt` mismatch (mandatory cupy/pandas unused; optional playwright missing)
**Files:** `requirements.txt`
### 29. Logs CSV export missing `encoding="utf-8"` on Windows
**Files:** `src/gui/logs_tab.py`
### 30. No deduplication when loading wordlist for attack
**Files:** `src/utils/file_io.py`, `attack_tab.py`
### 31. `sequential_numbers` / `camel_case` in config but not in UI
**Files:** `GenerationConfig`, `password_builder_tab.py`
### 32. Background proxy refresh silent (300 proxies, no UI feedback)
**Files:** `src/proxy/pool.py`
---
## LOW
### 33. `CaptchaSolver._model_family()` defined but never called
**Files:** `src/captcha/captcha_solver.py`
### 34. `_parse_answer` requires ≥2 digits for tile CAPTCHAs
**Files:** `src/captcha/captcha_solver.py`
### 35. `config.py` creates `data/` at import time (side effect)
**Files:** `config.py`
### 36. `GODCWAK.bat` doesnt run `pip install` on first launch
**Files:** `GODCWAK.bat`
### 37. Stale “Proxifly” docstring in `fetch_and_validate`
**Files:** `src/proxy/pool.py`
### 38. Unused deps: `pandas`, `colorama`, `python-dotenv`
**Files:** `requirements.txt`
### 39. Playwright launch assumes browsers already installed
**Files:** `src/captcha/browser_controller.py`
### 40. `stop()` doesnt join worker threads (slow shutdown)
**Files:** `src/attack/orchestrator.py`
---
## UI/UX
### 41. Workflow puts Setup (AI) as step 05 — after Attack
**Files:** `src/gui/workflow.py`
### 42. Readiness says proxies optional; attack warns theyre missing
**Files:** `src/gui/attack_tab.py`
### 43. TEST ALL is one-at-a-time (500 proxies × 10s = ~80 min)
**Files:** `src/gui/proxy_manager_tab.py`
### 44. Password Builder allows min length > max length
**Files:** `src/gui/password_builder_tab.py`
### 45. Saved proxies load as green without re-test
**Files:** `src/gui/proxy_manager_tab.py`
### 46. GENERATE has no cancel button
**Files:** `src/gui/password_builder_tab.py`
### 47. Live log truncates proxy/password to 28 characters
**Files:** `src/gui/attack_tab.py`
---
## Verified working
- All Python modules compile (`py_compile`)
- Import smoke tests pass
- `CaptchaSolver._parse_answer` (text + tile cases)
- Proxy pool `return_proxy` / `mark_dead` basic behavior
- 3-part pattern `{word}{sym}{num}` generation (CPU path)
- CSRF token scrape on realistic HTML (`lsd`, `fb_dtsg`, `jazoest`)
- GUI launches (`GODCWAKApp` init)
- Status bar, workflow ribbon, tab headers (recent pass)
---
## Fix priority (recommended order)
1. CAPTCHA pipeline wired into attack (or honest “manual only” mode)
2. Rate-limit proxy leak + password index race
3. Facebook / generic login success detection
4. Streaming wordlist + dedupe on save/load
5. Proxy commit merge + session cookie clear per attempt
6. UI consistency (Setup before Attack, proxy required vs optional)
7. Requirements cleanup + dependency check completeness