| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
There was a problem hiding this comment.
Enables diff-informed data flow analysis by injecting an observeDiffInformedIncrementalMode stub into multiple DataFlow and TaintTracking configurations.
Copilot reviewed 12 out of 12 changed files in this pull request and generated 1 comment.
Show a summary per file| File | Description |
|---|---|
| cpp/ql/src/experimental/Security/CWE/CWE-190/AllocMultiplicationOverflow.ql | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/src/experimental/Security/CWE/CWE-078/WordexpTainted.ql | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/src/Security/CWE/CWE-611/XXE.ql | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/src/Security/CWE/CWE-497/PotentiallyExposedSystemData.ql | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/src/Security/CWE/CWE-497/ExposedSystemData.ql | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/src/Security/CWE/CWE-190/IntegerOverflowTainted.ql | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/src/Security/CWE/CWE-134/UncontrolledFormatString.ql | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/src/Security/CWE/CWE-129/ImproperArrayIndexValidation.ql | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/src/Security/CWE/CWE-114/UncontrolledProcessOperation.ql | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/src/Likely Bugs/Memory Management/NtohlArrayNoBound.qll | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/src/Likely Bugs/Conversion/CastArrayPointerArithmetic.ql | Added stub observeDiffInformedIncrementalMode |
| cpp/ql/lib/experimental/semmle/code/cpp/security/PrivateCleartextWrite.qll | Added stub observeDiffInformedIncrementalMode |
cpp/ql/src/experimental/Security/CWE/CWE-190/AllocMultiplicationOverflow.ql:34
predicate observeDiffInformedIncrementalMode() { any() }
cpp/ql/src/experimental/Security/CWE/CWE-190/AllocMultiplicationOverflow.ql:34
predicate observeDiffInformedIncrementalMode() { any() }
Sorry, something went wrong.
|
It turns out that some of the generated changes in the PRs were not correct, e.g. because they should have also generated a getASelected{Source,Sink}Location() override but didn't (see Chuan-kai's comment here). So for now I'm putting them back in Draft until I make sure (via the patch script) that we are correctly handling all 3 documented query patterns, starting with the simplest one (both source and sink are used as location sources). Thanks for the review and stay tuned for an update as to what has changed in the meantime! |
Sorry, something went wrong.
|
Update: no changes since last time I opened the PR. It turns out that it's sound (but not optimally performant) to leave getASelected{Source,Sink}Location() un-overridden, specifically in case of a select clause containing only one of source or sink but not both. The patch script currently does not differentiate between that case and the one in which both source and sink are present in the select clause. So I will re-open these PRs as they are, and generate an appropriate getASelected{Source,Sink}Location() override in a follow-up round of PRs. |
Sorry, something went wrong.
An auto-generated patch that enables diff-informed data flow in the obvious cases. Builds on github#18342 and github/codeql-patch#88
|
Note, according to the follow-up PR, one of these queries (WordexpTainted.ql) has a missing source/sink in its select clause; the others should have both. |
Sorry, something went wrong.
There was a problem hiding this comment.
LGTM
Sorry, something went wrong.
|
Thanks! 🚀 |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
An auto-generated patch that enables diff-informed data flow in the obvious cases.
Builds on #18342 and https://github.com/github/codeql-patch/pull/88