From 7b533db4fb704df2da158492719823a5523848a5 Mon Sep 17 00:00:00 2001 From: Owen Mansel-Chan <62447351+owen-mc@users.noreply.github.com> Date: Wed, 12 Nov 2025 15:10:29 +0000 Subject: [PATCH] Sort models and tests alphabetically --- .../org.apache.commons.fileupload.model.yml | 12 ++++++------ ...rg.apache.commons.fileupload.util.model.yml | 6 +++--- .../dataflow/taintsources/FileUpload.java | 18 +++++++++--------- 3 files changed, 18 insertions(+), 18 deletions(-) diff --git a/java/ql/lib/ext/org.apache.commons.fileupload.model.yml b/java/ql/lib/ext/org.apache.commons.fileupload.model.yml index 66a0d329641..e7f61572164 100644 --- a/java/ql/lib/ext/org.apache.commons.fileupload.model.yml +++ b/java/ql/lib/ext/org.apache.commons.fileupload.model.yml @@ -3,13 +3,13 @@ extensions: pack: codeql/java-all extensible: sourceModel data: - - ["org.apache.commons.fileupload", "FileItem", True, "getInputStream", "()", "", "ReturnValue", "remote", "manual"] - - ["org.apache.commons.fileupload", "FileItem", True, "getFieldName", "()", "", "ReturnValue", "remote", "manual"] - - ["org.apache.commons.fileupload", "FileItem", True, "getContentType", "()", "", "ReturnValue", "remote", "manual"] - - ["org.apache.commons.fileupload", "FileItem", True, "getString", "()", "", "ReturnValue", "remote", "manual"] - - ["org.apache.commons.fileupload", "FileItem", True, "getName", "()", "", "ReturnValue", "remote", "manual"] - - ["org.apache.commons.fileupload", "FileItem", True, "getString "(String)", "", "ReturnValue", "remote", "manual"] - ["org.apache.commons.fileupload", "FileItem", True, "get", "()", "", "ReturnValue", "remote", "manual"] + - ["org.apache.commons.fileupload", "FileItem", True, "getContentType", "()", "", "ReturnValue", "remote", "manual"] + - ["org.apache.commons.fileupload", "FileItem", True, "getFieldName", "()", "", "ReturnValue", "remote", "manual"] + - ["org.apache.commons.fileupload", "FileItem", True, "getInputStream", "()", "", "ReturnValue", "remote", "manual"] + - ["org.apache.commons.fileupload", "FileItem", True, "getName", "()", "", "ReturnValue", "remote", "manual"] + - ["org.apache.commons.fileupload", "FileItem", True, "getString", "()", "", "ReturnValue", "remote", "manual"] + - ["org.apache.commons.fileupload", "FileItem", True, "getString", "(String)", "", "ReturnValue", "remote", "manual"] - ["org.apache.commons.fileupload", "FileItemStream", True, "getContentType", "()", "", "ReturnValue", "remote", "manual"] - ["org.apache.commons.fileupload", "FileItemStream", True, "getFieldName", "()", "", "ReturnValue", "remote", "manual"] - ["org.apache.commons.fileupload", "FileItemStream", True, "getName", "()", "", "ReturnValue", "remote", "manual"] diff --git a/java/ql/lib/ext/org.apache.commons.fileupload.util.model.yml b/java/ql/lib/ext/org.apache.commons.fileupload.util.model.yml index ed1e24d410d..e2336cf8b8b 100644 --- a/java/ql/lib/ext/org.apache.commons.fileupload.util.model.yml +++ b/java/ql/lib/ext/org.apache.commons.fileupload.util.model.yml @@ -3,7 +3,7 @@ extensions: pack: codeql/java-all extensible: summaryModel data: - - ["org.apache.commons.fileupload.util", "Streams", True, "copy", "(InputStream,OutputStream,boolean)", "", "Argument[0]", "Argument[1]", "taint", "manual"] - - ["org.apache.commons.fileupload.util", "Streams", True, "copy", "(InputStream,OutputStream,boolean,byte[])", "", "Argument[0]", "Argument[1]", "taint", "manual"] - ["org.apache.commons.fileupload.util", "Streams", True, "asString", "(InputStream)", "", "Argument[0]", "ReturnValue", "taint", "manual"] - - ["org.apache.commons.fileupload.util", "Streams", True, "asString", "(InputStream,String)", "", "Argument[0]", "ReturnValue", "taint", "manual"] \ No newline at end of file + - ["org.apache.commons.fileupload.util", "Streams", True, "asString", "(InputStream,String)", "", "Argument[0]", "ReturnValue", "taint", "manual"] + - ["org.apache.commons.fileupload.util", "Streams", True, "copy", "(InputStream,OutputStream,boolean)", "", "Argument[0]", "Argument[1]", "taint", "manual"] + - ["org.apache.commons.fileupload.util", "Streams", True, "copy", "(InputStream,OutputStream,boolean,byte[])", "", "Argument[0]", "Argument[1]", "taint", "manual"] \ No newline at end of file diff --git a/java/ql/test/library-tests/dataflow/taintsources/FileUpload.java b/java/ql/test/library-tests/dataflow/taintsources/FileUpload.java index 6cec8c1f658..f1d6e7ca569 100644 --- a/java/ql/test/library-tests/dataflow/taintsources/FileUpload.java +++ b/java/ql/test/library-tests/dataflow/taintsources/FileUpload.java @@ -18,32 +18,32 @@ public class FileUpload { public void test() throws Exception { sink(filePart.getContentType()); // $ hasRemoteValueFlow sink(filePart.getHeader("test")); // $ hasRemoteValueFlow - sink(filePart.getInputStream()); // $ hasRemoteValueFlow - sink(filePart.getHeaders("test")); // $ hasRemoteValueFlow sink(filePart.getHeaderNames()); // $ hasRemoteValueFlow - sink(filePart.getSubmittedFileName()); // $ hasRemoteValueFlow + sink(filePart.getHeaders("test")); // $ hasRemoteValueFlow + sink(filePart.getInputStream()); // $ hasRemoteValueFlow sink(filePart.getName()); // $ hasRemoteValueFlow + sink(filePart.getSubmittedFileName()); // $ hasRemoteValueFlow - sink(fileItem.getName()); // $ hasRemoteValueFlow sink(fileItem.get()); // $ hasRemoteValueFlow - sink(fileItem.getString()); // $ hasRemoteValueFlow sink(fileItem.getContentType()); // $ hasRemoteValueFlow sink(fileItem.getFieldName()); // $ hasRemoteValueFlow sink(fileItem.getInputStream()); // $ hasRemoteValueFlow sink(fileItem.getName()); // $ hasRemoteValueFlow + sink(fileItem.getName()); // $ hasRemoteValueFlow + sink(fileItem.getString()); // $ hasRemoteValueFlow + sink(fileItemStream.getContentType()); // $ hasRemoteValueFlow sink(fileItemStream.getFieldName()); // $ hasRemoteValueFlow sink(fileItemStream.getName()); // $ hasRemoteValueFlow - sink(fileItemStream.getContentType()); // $ hasRemoteValueFlow sink(fileItemStream.openStream()); // $ hasRemoteValueFlow sink(jakartaPart.getContentType()); // $ hasRemoteValueFlow sink(jakartaPart.getHeader("test")); // $ hasRemoteValueFlow - sink(jakartaPart.getInputStream()); // $ hasRemoteValueFlow - sink(jakartaPart.getHeaders("test")); // $ hasRemoteValueFlow sink(jakartaPart.getHeaderNames()); // $ hasRemoteValueFlow - sink(jakartaPart.getSubmittedFileName()); // $ hasRemoteValueFlow + sink(jakartaPart.getHeaders("test")); // $ hasRemoteValueFlow + sink(jakartaPart.getInputStream()); // $ hasRemoteValueFlow sink(jakartaPart.getName()); // $ hasRemoteValueFlow + sink(jakartaPart.getSubmittedFileName()); // $ hasRemoteValueFlow } } \ No newline at end of file