FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Python: Model `bytearray` construction and `take_bytes` by tausbn · Pull Request #22746 · github/codeql · GitHub

Repository navigation

Python: Model bytearray construction and take_bytes - #22746

Open
tausbn wants to merge 1 commit into
mainfrom
tausbn/python315-model-bytearray-and-take-bytes
Open

tausbn wants to merge 1 commit into
mainfrom
tausbn/python315-model-bytearray-and-take-bytes

Conversation

tausbn commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

We model these as string-like taint preserving steps.

We model these as string-like taint preserving steps.
tausbn marked this pull request as ready for review October 2, 2026 13:37
tausbn requested a review from a team as a code owner October 2, 2026 13:37
Copilot AI balanced review requested due to automatic review settings October 2, 2026 13:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Choose a reason Spam Abuse Off Topic Outdated Duplicate Resolved Low Quality

Copilot review overview

🟢 Approval recommended

The implementation matches the documented behavior and includes comprehensive focused tests.

Review effort: Balanced
Findings: None

What changed in this PR

Adds taint-preserving models for Python byte-array construction and extraction.

Changes:

  • Models taint flow through bytearray(...) and bytearray.take_bytes.
  • Adds coverage for bound, unbound, aliased, partial, and consuming calls.
  • Documents the analysis improvement.
File Description
TaintTrackingPrivate.qll Implements byte-array taint steps.
test_bytearray.py Tests supported flows and known imprecision.
2026-09-22-python315-take-bytes.md Adds the change note.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants


Back | FazBrowse Home | New Git URL