mirror of
https://github.com/github/codeql.git
synced 2026-04-25 00:35:20 +02:00
Merge remote-tracking branch 'upstream/main' into logging
This commit is contained in:
@@ -1,9 +0,0 @@
|
||||
# See here for image contents: https://github.com/microsoft/vscode-dev-containers/tree/v0.236.0/containers/cpp/.devcontainer/base.Dockerfile
|
||||
|
||||
# [Choice] Debian / Ubuntu version (use Debian 11, Ubuntu 18.04/22.04 on local arm64/Apple Silicon): debian-11, debian-10, ubuntu-22.04, ubuntu-20.04, ubuntu-18.04
|
||||
FROM mcr.microsoft.com/vscode/devcontainers/cpp:0-ubuntu-22.04
|
||||
|
||||
USER root
|
||||
ADD root.sh /tmp/root.sh
|
||||
ADD update-codeql.sh /usr/local/bin/update-codeql
|
||||
RUN bash /tmp/root.sh && rm /tmp/root.sh
|
||||
@@ -1,25 +0,0 @@
|
||||
{
|
||||
"extensions": [
|
||||
"github.vscode-codeql",
|
||||
"hbenl.vscode-test-explorer",
|
||||
"ms-vscode.test-adapter-converter",
|
||||
"slevesque.vscode-zipexplorer",
|
||||
"ms-vscode.cpptools"
|
||||
],
|
||||
"settings": {
|
||||
"files.watcherExclude": {
|
||||
"**/target/**": true
|
||||
},
|
||||
"codeQL.runningQueries.memory": 2048
|
||||
},
|
||||
"build": {
|
||||
"dockerfile": "Dockerfile",
|
||||
},
|
||||
"runArgs": [
|
||||
"--cap-add=SYS_PTRACE",
|
||||
"--security-opt",
|
||||
"seccomp=unconfined"
|
||||
],
|
||||
"remoteUser": "vscode",
|
||||
"onCreateCommand": ".devcontainer/swift/user.sh"
|
||||
}
|
||||
@@ -1,34 +0,0 @@
|
||||
set -xe
|
||||
|
||||
BAZELISK_VERSION=v1.12.0
|
||||
BAZELISK_DOWNLOAD_SHA=6b0bcb2ea15bca16fffabe6fda75803440375354c085480fe361d2cbf32501db
|
||||
|
||||
# install git lfs apt source
|
||||
curl -s https://packagecloud.io/install/repositories/github/git-lfs/script.deb.sh | bash
|
||||
|
||||
# install gh apt source
|
||||
(type -p wget >/dev/null || (sudo apt update && sudo apt-get install wget -y)) \
|
||||
&& sudo mkdir -p -m 755 /etc/apt/keyrings \
|
||||
&& wget -qO- https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo tee /etc/apt/keyrings/githubcli-archive-keyring.gpg > /dev/null \
|
||||
&& sudo chmod go+r /etc/apt/keyrings/githubcli-archive-keyring.gpg \
|
||||
&& echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/githubcli-archive-keyring.gpg] https://cli.github.com/packages stable main" | sudo tee /etc/apt/sources.list.d/github-cli.list > /dev/null \
|
||||
|
||||
apt-get update
|
||||
export DEBIAN_FRONTEND=noninteractive
|
||||
apt-get -y install --no-install-recommends \
|
||||
zlib1g-dev \
|
||||
uuid-dev \
|
||||
python3-distutils \
|
||||
python3-pip \
|
||||
bash-completion \
|
||||
git-lfs \
|
||||
gh
|
||||
|
||||
# Install Bazel
|
||||
curl -fSsL -o /usr/local/bin/bazelisk https://github.com/bazelbuild/bazelisk/releases/download/${BAZELISK_VERSION}/bazelisk-linux-amd64
|
||||
echo "${BAZELISK_DOWNLOAD_SHA} */usr/local/bin/bazelisk" | sha256sum --check -
|
||||
chmod 0755 /usr/local/bin/bazelisk
|
||||
ln -s bazelisk /usr/local/bin/bazel
|
||||
|
||||
# install latest codeql
|
||||
update-codeql
|
||||
@@ -1,20 +0,0 @@
|
||||
#!/bin/bash -e
|
||||
|
||||
URL=https://github.com/github/codeql-cli-binaries/releases
|
||||
LATEST_VERSION=$(curl -L -s -H 'Accept: application/json' $URL/latest | sed -e 's/.*"tag_name":"\([^"]*\)".*/\1/')
|
||||
CURRENT_VERSION=v$(codeql version 2>/dev/null | sed -ne 's/.*release \([0-9.]*\)\./\1/p')
|
||||
if [[ $CURRENT_VERSION != $LATEST_VERSION ]]; then
|
||||
if [[ $UID != 0 ]]; then
|
||||
echo "update required, please run this script with sudo:"
|
||||
echo " sudo $0"
|
||||
exit 1
|
||||
fi
|
||||
ZIP=$(mktemp codeql.XXXX.zip)
|
||||
curl -fSqL -o $ZIP $URL/download/$LATEST_VERSION/codeql-linux64.zip
|
||||
unzip -q $ZIP -d /opt
|
||||
rm $ZIP
|
||||
ln -sf /opt/codeql/codeql /usr/local/bin/codeql
|
||||
echo installed version $LATEST_VERSION
|
||||
else
|
||||
echo current version $CURRENT_VERSION is up-to-date
|
||||
fi
|
||||
@@ -1,15 +0,0 @@
|
||||
set -xe
|
||||
|
||||
git lfs install
|
||||
|
||||
# add the workspace to the codeql search path
|
||||
mkdir -p /home/vscode/.config/codeql
|
||||
echo "--search-path /workspaces/codeql" > /home/vscode/.config/codeql/config
|
||||
|
||||
# create a swift extractor pack with the current state
|
||||
cd /workspaces/codeql
|
||||
bazel run swift/create-extractor-pack
|
||||
|
||||
#install and set up pre-commit
|
||||
python3 -m pip install pre-commit --no-warn-script-location
|
||||
$HOME/.local/bin/pre-commit install
|
||||
6
.github/workflows/swift.yml
vendored
6
.github/workflows/swift.yml
vendored
@@ -48,12 +48,6 @@ jobs:
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: ./swift/actions/build-and-test
|
||||
build-and-test-linux:
|
||||
if: github.repository_owner == 'github'
|
||||
runs-on: ubuntu-22.04
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: ./swift/actions/build-and-test
|
||||
qltests-macos:
|
||||
if: ${{ github.repository_owner == 'github' && github.event_name == 'pull_request' }}
|
||||
needs: build-and-test-macos
|
||||
|
||||
@@ -2,10 +2,16 @@ if (($null -ne $env:LGTM_INDEX_INCLUDE) -or ($null -ne $env:LGTM_INDEX_EXCLUDE)
|
||||
Write-Output 'Path filters set. Passing them through to the JavaScript extractor.'
|
||||
} else {
|
||||
Write-Output 'No path filters set. Using the default filters.'
|
||||
# Note: We're adding the `reusable_workflows` subdirectories to proactively
|
||||
# record workflows that were called cross-repo, check them out locally,
|
||||
# and enable an interprocedural analysis across the workflow files.
|
||||
# These workflows follow the convention `.github/reusable_workflows/<nwo>/*.ya?ml`
|
||||
$DefaultPathFilters = @(
|
||||
'exclude:**/*',
|
||||
'include:.github/workflows/**/*.yml',
|
||||
'include:.github/workflows/**/*.yaml',
|
||||
'include:.github/workflows/*.yml',
|
||||
'include:.github/workflows/*.yaml',
|
||||
'include:.github/reusable_workflows/**/*.yml',
|
||||
'include:.github/reusable_workflows/**/*.yaml',
|
||||
'include:**/action.yml',
|
||||
'include:**/action.yaml'
|
||||
)
|
||||
|
||||
@@ -2,10 +2,16 @@
|
||||
|
||||
set -eu
|
||||
|
||||
# Note: We're adding the `reusable_workflows` subdirectories to proactively
|
||||
# record workflows that were called cross-repo, check them out locally,
|
||||
# and enable an interprocedural analysis across the workflow files.
|
||||
# These workflows follow the convention `.github/reusable_workflows/<nwo>/*.ya?ml`
|
||||
DEFAULT_PATH_FILTERS=$(cat << END
|
||||
exclude:**/*
|
||||
include:.github/workflows/**/*.yml
|
||||
include:.github/workflows/**/*.yaml
|
||||
include:.github/workflows/*.yml
|
||||
include:.github/workflows/*.yaml
|
||||
include:.github/reusable_workflows/**/*.yml
|
||||
include:.github/reusable_workflows/**/*.yaml
|
||||
include:**/action.yml
|
||||
include:**/action.yaml
|
||||
END
|
||||
|
||||
@@ -6,7 +6,7 @@ on:
|
||||
|
||||
jobs:
|
||||
test1:
|
||||
runs-on: ubuntu-22.04
|
||||
runs-on: ubuntu-24.04
|
||||
outputs:
|
||||
job_output: ${{ steps.source.outputs.value }}
|
||||
steps:
|
||||
|
||||
@@ -491,7 +491,7 @@ jobs:
|
||||
|
||||
send_results:
|
||||
name: Send results to webhook
|
||||
runs-on: ubuntu-22.04
|
||||
runs-on: ubuntu-24.04
|
||||
if: always()
|
||||
needs: [
|
||||
setup,
|
||||
|
||||
@@ -3,7 +3,7 @@ on:
|
||||
|
||||
jobs:
|
||||
test:
|
||||
runs-on: ubuntu-22.04
|
||||
runs-on: ubuntu-24.04
|
||||
if: >
|
||||
(github.event.workflow_run.event == 'pull_request' ||
|
||||
github.event.workflow_run.event == 'pull_request_target') &&
|
||||
|
||||
@@ -3,7 +3,7 @@ on:
|
||||
|
||||
jobs:
|
||||
test:
|
||||
runs-on: ubuntu-22.04
|
||||
runs-on: ubuntu-24.04
|
||||
steps:
|
||||
- name: Run Issue form parser
|
||||
id: parse
|
||||
|
||||
@@ -7,7 +7,7 @@ on:
|
||||
jobs:
|
||||
test1:
|
||||
if: github.event.comment.body == '@metabase-bot run visual tests'
|
||||
runs-on: ubuntu-22.04
|
||||
runs-on: ubuntu-24.04
|
||||
steps:
|
||||
- name: Fetch issue
|
||||
uses: octokit/request-action@v2.x
|
||||
|
||||
@@ -7,7 +7,7 @@ on:
|
||||
jobs:
|
||||
test1:
|
||||
if: github.event.comment.body == '@metabase-bot run visual tests'
|
||||
runs-on: ubuntu-22.04
|
||||
runs-on: ubuntu-24.04
|
||||
steps:
|
||||
- name: Fetch issue
|
||||
uses: octokit/request-action@v2.x
|
||||
|
||||
@@ -21,9 +21,9 @@ jobs:
|
||||
matrix:
|
||||
include:
|
||||
- language: javascript
|
||||
os: ubuntu-22.04
|
||||
os: ubuntu-24.04
|
||||
- language: ruby
|
||||
os: ubuntu-22.04-16core
|
||||
os: ubuntu-24.04-16core
|
||||
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
|
||||
@@ -981,7 +981,8 @@ private module Cached {
|
||||
or
|
||||
exists(CompareValueNumber cmp, Operand left, Operand right, AbstractValue v |
|
||||
test = cmp and
|
||||
cmp.hasOperands(left, right) and
|
||||
pragma[only_bind_into](cmp)
|
||||
.hasOperands(pragma[only_bind_into](left), pragma[only_bind_into](right)) and
|
||||
isConvertedBool(left.getDef()) and
|
||||
int_value(right.getDef()) = 0 and
|
||||
unary_compares_eq(valueNumberOfOperand(left), op, k, areEqual, v)
|
||||
|
||||
@@ -1,8 +1,9 @@
|
||||
/**
|
||||
* This library offers a view of preprocessor branches (`#if`, `#ifdef`,
|
||||
* `#ifndef`, `#elif` and `#else`) as blocks of code between the opening and
|
||||
* closing directives, with navigable parent-child relationships to other
|
||||
* blocks. The main class is `PreprocessorBlock`.
|
||||
* `#ifndef`, `#elif`, `#elifdef`, `#elifndef`, and `#else`) as blocks of
|
||||
* code between the opening and closing directives, with navigable
|
||||
* parent-child relationships to other blocks. The main class is
|
||||
* `PreprocessorBlock`.
|
||||
*/
|
||||
|
||||
import cpp
|
||||
@@ -32,10 +33,10 @@ private int getPreprocIndex(PreprocessorBranchDirective directive) {
|
||||
|
||||
/**
|
||||
* A chunk of code from one preprocessor branch (`#if`, `#ifdef`,
|
||||
* `#ifndef`, `#elif` or `#else`) to the directive that closes it
|
||||
* (`#elif`, `#else` or `#endif`). The `getParent()` method
|
||||
* allows these blocks to be navigated as a tree, with the root
|
||||
* being the entire file.
|
||||
* `#ifndef`, `#elif`, `#elifdef`, `#elifndef`, or `#else`) to the
|
||||
* directive that closes it (`#elif`, `#elifdef`, `#elifndef`, `#else`,
|
||||
* or `#endif`). The `getParent()` method allows these blocks to be
|
||||
* navigated as a tree, with the root being the entire file.
|
||||
*/
|
||||
class PreprocessorBlock extends @element {
|
||||
PreprocessorBlock() {
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
import semmle.code.cpp.models.interfaces.ArrayFunction
|
||||
import semmle.code.cpp.models.interfaces.Taint
|
||||
import semmle.code.cpp.models.interfaces.DataFlow
|
||||
import semmle.code.cpp.models.interfaces.Alias
|
||||
import semmle.code.cpp.models.interfaces.SideEffect
|
||||
|
||||
@@ -8,7 +9,7 @@ import semmle.code.cpp.models.interfaces.SideEffect
|
||||
* guaranteed to be side-effect free.
|
||||
*/
|
||||
private class PureStrFunction extends AliasFunction, ArrayFunction, TaintFunction,
|
||||
SideEffectFunction
|
||||
SideEffectFunction, DataFlowFunction
|
||||
{
|
||||
PureStrFunction() {
|
||||
this.hasGlobalOrStdOrBslName([
|
||||
@@ -25,23 +26,48 @@ private class PureStrFunction extends AliasFunction, ArrayFunction, TaintFunctio
|
||||
this.getParameter(bufParam).getUnspecifiedType() instanceof PointerType
|
||||
}
|
||||
|
||||
/** Holds if `i` is a locale parameter that does not carry taint. */
|
||||
private predicate isLocaleParameter(ParameterIndex i) {
|
||||
this.getName().matches("%\\_l") and i + 1 = this.getNumberOfParameters()
|
||||
}
|
||||
|
||||
override predicate hasTaintFlow(FunctionInput input, FunctionOutput output) {
|
||||
// For these functions we add taint flow according to the following rules:
|
||||
// 1. If the parameter is of a pointer type then there is taint from the
|
||||
// indirection of the parameter. Otherwise, there is taint from the
|
||||
// parameter.
|
||||
// 2. If the return value is of a pointer type then there is taint to the
|
||||
// indirection of the return. Otherwise, there is taint to the return.
|
||||
exists(ParameterIndex i |
|
||||
(
|
||||
input.isParameter(i) and
|
||||
exists(this.getParameter(i))
|
||||
or
|
||||
input.isParameterDeref(i) and
|
||||
this.getParameter(i).getUnspecifiedType() instanceof PointerType
|
||||
) and
|
||||
exists(this.getParameter(i)) and
|
||||
// Functions that end with _l also take a locale argument (always as the last argument),
|
||||
// and we don't want taint from those arguments.
|
||||
(not this.getName().matches("%\\_l") or exists(this.getParameter(i + 1)))
|
||||
not this.isLocaleParameter(i)
|
||||
|
|
||||
if this.getParameter(i).getUnspecifiedType() instanceof PointerType
|
||||
then input.isParameterDeref(i)
|
||||
else input.isParameter(i)
|
||||
) and
|
||||
(
|
||||
output.isReturnValueDeref() and
|
||||
this.getUnspecifiedType() instanceof PointerType
|
||||
or
|
||||
if this.getUnspecifiedType() instanceof PointerType
|
||||
then output.isReturnValueDeref()
|
||||
else output.isReturnValue()
|
||||
)
|
||||
or
|
||||
// If there is taint flow from *input to *output then there is also taint
|
||||
// flow from input to output.
|
||||
this.hasTaintFlow(input.getIndirectionInput(), output.getIndirectionOutput()) and
|
||||
// No need to add taint flow if we already have data flow.
|
||||
not this.hasDataFlow(input, output)
|
||||
}
|
||||
|
||||
override predicate hasDataFlow(FunctionInput input, FunctionOutput output) {
|
||||
exists(int i |
|
||||
input.isParameter(i) and
|
||||
not this.isLocaleParameter(i) and
|
||||
// These functions always return the same pointer as they are given
|
||||
this.hasGlobalOrStdOrBslName([strrev(), strlwr(), strupr()]) and
|
||||
this.getParameter(i).getUnspecifiedType() instanceof PointerType and
|
||||
output.isReturnValue()
|
||||
)
|
||||
}
|
||||
|
||||
@@ -33,8 +33,9 @@ predicate allocSink(HeuristicAllocationExpr alloc, DataFlow::Node sink) {
|
||||
)
|
||||
}
|
||||
|
||||
predicate readsVariable(LoadInstruction load, Variable var) {
|
||||
load.getSourceAddress().(VariableAddressInstruction).getAstVariable() = var
|
||||
predicate readsVariable(LoadInstruction load, Variable var, IRBlock bb) {
|
||||
load.getSourceAddress().(VariableAddressInstruction).getAstVariable() = var and
|
||||
bb = load.getBlock()
|
||||
}
|
||||
|
||||
predicate hasUpperBoundsCheck(Variable var) {
|
||||
@@ -46,10 +47,18 @@ predicate hasUpperBoundsCheck(Variable var) {
|
||||
)
|
||||
}
|
||||
|
||||
predicate nodeIsBarrierEqualityCandidate(DataFlow::Node node, Operand access, Variable checkedVar) {
|
||||
exists(Instruction instr | instr = node.asOperand().getDef() |
|
||||
readsVariable(instr, checkedVar) and
|
||||
any(IRGuardCondition guard).ensuresEq(access, _, _, instr.getBlock(), true)
|
||||
predicate variableEqualityCheckedInBlock(Variable checkedVar, IRBlock bb) {
|
||||
exists(Operand access |
|
||||
readsVariable(access.getDef(), checkedVar, _) and
|
||||
any(IRGuardCondition guard).ensuresEq(access, _, _, bb, true)
|
||||
)
|
||||
}
|
||||
|
||||
predicate nodeIsBarrierEquality(DataFlow::Node node) {
|
||||
exists(Variable checkedVar, Instruction instr, IRBlock bb |
|
||||
instr = node.asOperand().getDef() and
|
||||
readsVariable(instr, checkedVar, bb) and
|
||||
variableEqualityCheckedInBlock(checkedVar, bb)
|
||||
)
|
||||
}
|
||||
|
||||
@@ -72,14 +81,11 @@ module TaintedAllocationSizeConfig implements DataFlow::ConfigSig {
|
||||
)
|
||||
or
|
||||
exists(Variable checkedVar, Instruction instr | instr = node.asOperand().getDef() |
|
||||
readsVariable(instr, checkedVar) and
|
||||
readsVariable(instr, checkedVar, _) and
|
||||
hasUpperBoundsCheck(checkedVar)
|
||||
)
|
||||
or
|
||||
exists(Variable checkedVar, Operand access |
|
||||
readsVariable(access.getDef(), checkedVar) and
|
||||
nodeIsBarrierEqualityCandidate(node, access, checkedVar)
|
||||
)
|
||||
nodeIsBarrierEquality(node)
|
||||
or
|
||||
// block flow to inside of identified allocation functions (this flow leads
|
||||
// to duplicate results)
|
||||
|
||||
@@ -7741,6 +7741,32 @@ WARNING: module 'TaintTracking' has been deprecated and may be removed in future
|
||||
| taint.cpp:809:8:809:9 | p2 | taint.cpp:809:7:809:9 | * ... | TAINT |
|
||||
| taint.cpp:811:12:811:28 | call to SysAllocStringLen | taint.cpp:812:8:812:9 | p3 | |
|
||||
| taint.cpp:812:8:812:9 | p3 | taint.cpp:812:7:812:9 | * ... | TAINT |
|
||||
| taint.cpp:817:42:817:46 | p_out | taint.cpp:817:42:817:46 | p_out | |
|
||||
| taint.cpp:817:42:817:46 | p_out | taint.cpp:819:4:819:8 | p_out | |
|
||||
| taint.cpp:817:62:817:65 | p_in | taint.cpp:817:62:817:65 | p_in | |
|
||||
| taint.cpp:817:62:817:65 | p_in | taint.cpp:818:20:818:23 | p_in | |
|
||||
| taint.cpp:818:19:818:23 | * ... | taint.cpp:819:19:819:19 | q | |
|
||||
| taint.cpp:818:20:818:23 | p_in | taint.cpp:818:19:818:23 | * ... | TAINT |
|
||||
| taint.cpp:819:3:819:8 | * ... [post update] | taint.cpp:817:42:817:46 | p_out | |
|
||||
| taint.cpp:819:3:819:8 | * ... [post update] | taint.cpp:819:4:819:8 | p_out [inner post update] | |
|
||||
| taint.cpp:819:3:819:25 | ... = ... | taint.cpp:819:3:819:8 | * ... [post update] | |
|
||||
| taint.cpp:819:4:819:8 | p_out | taint.cpp:819:3:819:8 | * ... | TAINT |
|
||||
| taint.cpp:819:12:819:17 | call to strchr | taint.cpp:819:3:819:25 | ... = ... | |
|
||||
| taint.cpp:819:19:819:19 | q | taint.cpp:819:12:819:17 | call to strchr | TAINT |
|
||||
| taint.cpp:819:22:819:24 | 47 | taint.cpp:819:12:819:17 | call to strchr | TAINT |
|
||||
| taint.cpp:822:33:822:35 | out | taint.cpp:822:33:822:35 | out | |
|
||||
| taint.cpp:822:33:822:35 | out | taint.cpp:826:27:826:29 | out | |
|
||||
| taint.cpp:822:50:822:51 | in | taint.cpp:822:50:822:51 | in | |
|
||||
| taint.cpp:822:50:822:51 | in | taint.cpp:826:33:826:34 | in | |
|
||||
| taint.cpp:826:26:826:29 | ref arg & ... | taint.cpp:822:33:822:35 | out | |
|
||||
| taint.cpp:826:26:826:29 | ref arg & ... | taint.cpp:826:27:826:29 | out [inner post update] | |
|
||||
| taint.cpp:826:27:826:29 | out | taint.cpp:826:26:826:29 | & ... | |
|
||||
| taint.cpp:826:32:826:34 | ref arg & ... | taint.cpp:822:50:822:51 | in | |
|
||||
| taint.cpp:826:32:826:34 | ref arg & ... | taint.cpp:826:33:826:34 | in [inner post update] | |
|
||||
| taint.cpp:826:33:826:34 | in | taint.cpp:826:32:826:34 | & ... | |
|
||||
| taint.cpp:830:20:830:34 | call to indirect_source | taint.cpp:832:23:832:24 | in | |
|
||||
| taint.cpp:831:15:831:17 | out | taint.cpp:832:18:832:20 | out | |
|
||||
| taint.cpp:831:15:831:17 | out | taint.cpp:833:8:833:10 | out | |
|
||||
| vector.cpp:16:43:16:49 | source1 | vector.cpp:17:26:17:32 | source1 | |
|
||||
| vector.cpp:16:43:16:49 | source1 | vector.cpp:31:38:31:44 | source1 | |
|
||||
| vector.cpp:17:21:17:33 | call to vector | vector.cpp:19:14:19:14 | v | |
|
||||
|
||||
@@ -810,4 +810,25 @@ void test_sysalloc() {
|
||||
|
||||
auto p3 = SysAllocStringLen((LPOLESTR)indirect_source(), 10);
|
||||
sink(*p3); // $ ir MISSING: ast
|
||||
}
|
||||
|
||||
char* strchr(const char*, int);
|
||||
|
||||
void write_to_const_ptr_ptr(const char **p_out, const char **p_in) {
|
||||
const char* q = *p_in;
|
||||
*p_out = strchr(q, '/');
|
||||
}
|
||||
|
||||
void take_const_ptr(const char *out, const char *in) {
|
||||
// NOTE: We take the address of `out` in `take_const_ptr`'s stack space.
|
||||
// Assigning to this pointer does not change `out` in
|
||||
// `test_write_to_const_ptr_ptr`.
|
||||
write_to_const_ptr_ptr(&out, &in);
|
||||
}
|
||||
|
||||
void test_write_to_const_ptr_ptr() {
|
||||
const char* in = indirect_source();
|
||||
const char* out;
|
||||
take_const_ptr(out, in);
|
||||
sink(out); // $ SPURIOUS: ast
|
||||
}
|
||||
@@ -626,6 +626,11 @@ signatureMatches
|
||||
| taint.cpp:725:10:725:15 | strtol | (XCHAR *,const XCHAR *,int) | CSimpleStringT | CopyCharsOverlapped | 2 |
|
||||
| taint.cpp:727:6:727:16 | test_strtol | (char *) | CStringT | CStringT | 0 |
|
||||
| taint.cpp:785:6:785:15 | fopen_test | (char *) | CStringT | CStringT | 0 |
|
||||
| taint.cpp:815:7:815:12 | strchr | (LPCOLESTR,int) | CComBSTR | Append | 1 |
|
||||
| taint.cpp:815:7:815:12 | strchr | (char,int) | CStringT | CStringT | 1 |
|
||||
| taint.cpp:815:7:815:12 | strchr | (const XCHAR *,int) | CStringT | CStringT | 1 |
|
||||
| taint.cpp:815:7:815:12 | strchr | (const YCHAR *,int) | CStringT | CStringT | 1 |
|
||||
| taint.cpp:815:7:815:12 | strchr | (wchar_t,int) | CStringT | CStringT | 1 |
|
||||
| vector.cpp:333:6:333:35 | vector_iterator_assign_wrapper | (LPCOLESTR,int) | CComBSTR | Append | 1 |
|
||||
| vector.cpp:333:6:333:35 | vector_iterator_assign_wrapper | (char,int) | CStringT | CStringT | 1 |
|
||||
| vector.cpp:333:6:333:35 | vector_iterator_assign_wrapper | (const XCHAR *,int) | CStringT | CStringT | 1 |
|
||||
@@ -2029,6 +2034,12 @@ getParameterTypeName
|
||||
| taint.cpp:802:6:802:22 | SysAllocStringLen | 0 | const OLECHAR * |
|
||||
| taint.cpp:802:6:802:22 | SysAllocStringLen | 0 | const wchar_t * |
|
||||
| taint.cpp:802:6:802:22 | SysAllocStringLen | 1 | unsigned int |
|
||||
| taint.cpp:815:7:815:12 | strchr | 0 | const char * |
|
||||
| taint.cpp:815:7:815:12 | strchr | 1 | int |
|
||||
| taint.cpp:817:6:817:27 | write_to_const_ptr_ptr | 0 | const char ** |
|
||||
| taint.cpp:817:6:817:27 | write_to_const_ptr_ptr | 1 | const char ** |
|
||||
| taint.cpp:822:6:822:19 | take_const_ptr | 0 | const char * |
|
||||
| taint.cpp:822:6:822:19 | take_const_ptr | 1 | const char * |
|
||||
| vector.cpp:13:6:13:9 | sink | 0 | int |
|
||||
| vector.cpp:14:27:14:30 | sink | 0 | vector> & |
|
||||
| vector.cpp:14:27:14:30 | sink | 0 | vector> & |
|
||||
|
||||
@@ -1,10 +1,16 @@
|
||||
| #elif defined GREEN | preprocblock.cpp:10:0:11:0 | #ifndef BLUE |
|
||||
| #elif defined GREEN | preprocblock.cpp:14:0:15:0 | #if 0 |
|
||||
| #elif defined GREEN | preprocblock.cpp:16:0:17:0 | #else |
|
||||
| #elifdef GREEN | preprocblock23.cpp:11:0:12:0 | #if 0 |
|
||||
| #elifdef GREEN | preprocblock23.cpp:13:0:14:0 | #elifndef BLUE |
|
||||
| (no parent) | file://:0:0:0:0 | |
|
||||
| (no parent) | header.h:0:0:8:0 | header.h |
|
||||
| (no parent) | preprocblock23.cpp:0:0:22:0 | preprocblock23.cpp |
|
||||
| (no parent) | preprocblock.cpp:0:0:25:0 | preprocblock.cpp |
|
||||
| header.h | header.h:3:0:7:0 | #ifndef HEADER_H |
|
||||
| preprocblock23.cpp | preprocblock23.cpp:7:0:7:0 | #ifdef RED |
|
||||
| preprocblock23.cpp | preprocblock23.cpp:8:0:17:0 | #elifdef GREEN |
|
||||
| preprocblock23.cpp | preprocblock23.cpp:18:0:21:0 | #else |
|
||||
| preprocblock.cpp | preprocblock.cpp:6:0:6:0 | #ifdef RED |
|
||||
| preprocblock.cpp | preprocblock.cpp:7:0:20:0 | #elif defined GREEN |
|
||||
| preprocblock.cpp | preprocblock.cpp:21:0:24:0 | #else |
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
// preprocblock23.cpp
|
||||
// semmle-extractor-options: -std=c++23
|
||||
|
||||
#include "header.h"
|
||||
#define GREEN
|
||||
|
||||
#ifdef RED
|
||||
#elifdef GREEN
|
||||
#include "header.h"
|
||||
|
||||
#if 0
|
||||
#include "header.h" // not reached
|
||||
#elifndef BLUE
|
||||
#include "header.h"
|
||||
#endif
|
||||
|
||||
#include "header.h"
|
||||
#else
|
||||
|
||||
// ...
|
||||
|
||||
#endif
|
||||
@@ -1,3 +1,7 @@
|
||||
| preprocblock23.cpp:4:1:4:19 | #include "header.h" | preprocblock23.cpp:0:0:22:0 | preprocblock23.cpp |
|
||||
| preprocblock23.cpp:9:2:9:20 | #include "header.h" | preprocblock23.cpp:8:0:17:0 | #elifdef GREEN |
|
||||
| preprocblock23.cpp:14:3:14:21 | #include "header.h" | preprocblock23.cpp:13:0:14:0 | #elifndef BLUE |
|
||||
| preprocblock23.cpp:17:2:17:20 | #include "header.h" | preprocblock23.cpp:8:0:17:0 | #elifdef GREEN |
|
||||
| preprocblock.cpp:3:1:3:19 | #include "header.h" | preprocblock.cpp:0:0:25:0 | preprocblock.cpp |
|
||||
| preprocblock.cpp:8:2:8:20 | #include "header.h" | preprocblock.cpp:7:0:20:0 | #elif defined GREEN |
|
||||
| preprocblock.cpp:11:3:11:21 | #include "header.h" | preprocblock.cpp:10:0:11:0 | #ifndef BLUE |
|
||||
|
||||
@@ -3,7 +3,6 @@
|
||||
<PropertyGroup>
|
||||
<OutputType>Exe</OutputType>
|
||||
<TargetFramework>net5.0</TargetFramework>
|
||||
<ImplicitUsings>enable</ImplicitUsings>
|
||||
<Nullable>enable</Nullable>
|
||||
</PropertyGroup>
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
{
|
||||
"sdk": {
|
||||
"version": "5.0.408"
|
||||
"version": "9.0.100"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
<Project Sdk="Microsoft.NET.Sdk.Web">
|
||||
|
||||
<PropertyGroup>
|
||||
<TargetFramework>net9.0</TargetFramework>
|
||||
<Nullable>enable</Nullable>
|
||||
<ImplicitUsings>enable</ImplicitUsings>
|
||||
</PropertyGroup>
|
||||
|
||||
</Project>
|
||||
@@ -0,0 +1,20 @@
|
||||
<!DOCTYPE html>
|
||||
<html lang="en">
|
||||
|
||||
<head>
|
||||
<meta charset="utf-8" />
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
||||
<base href="/" />
|
||||
<link rel="stylesheet" href="bootstrap/bootstrap.min.css" />
|
||||
<link rel="stylesheet" href="app.css" />
|
||||
<link rel="stylesheet" href="BlazorTest.styles.css" />
|
||||
<link rel="icon" type="image/png" href="favicon.png" />
|
||||
<HeadOutlet />
|
||||
</head>
|
||||
|
||||
<body>
|
||||
<Routes />
|
||||
<script src="_framework/blazor.web.js"></script>
|
||||
</body>
|
||||
|
||||
</html>
|
||||
@@ -0,0 +1,23 @@
|
||||
@inherits LayoutComponentBase
|
||||
|
||||
<div class="page">
|
||||
<div class="sidebar">
|
||||
<NavMenu />
|
||||
</div>
|
||||
|
||||
<main>
|
||||
<div class="top-row px-4">
|
||||
<a href="https://learn.microsoft.com/aspnet/core/" target="_blank">About</a>
|
||||
</div>
|
||||
|
||||
<article class="content px-4">
|
||||
@Body
|
||||
</article>
|
||||
</main>
|
||||
</div>
|
||||
|
||||
<div id="blazor-error-ui">
|
||||
An unhandled error has occurred.
|
||||
<a href="" class="reload">Reload</a>
|
||||
<a class="dismiss">🗙</a>
|
||||
</div>
|
||||
@@ -0,0 +1,96 @@
|
||||
.page {
|
||||
position: relative;
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
}
|
||||
|
||||
main {
|
||||
flex: 1;
|
||||
}
|
||||
|
||||
.sidebar {
|
||||
background-image: linear-gradient(180deg, rgb(5, 39, 103) 0%, #3a0647 70%);
|
||||
}
|
||||
|
||||
.top-row {
|
||||
background-color: #f7f7f7;
|
||||
border-bottom: 1px solid #d6d5d5;
|
||||
justify-content: flex-end;
|
||||
height: 3.5rem;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
}
|
||||
|
||||
.top-row ::deep a, .top-row ::deep .btn-link {
|
||||
white-space: nowrap;
|
||||
margin-left: 1.5rem;
|
||||
text-decoration: none;
|
||||
}
|
||||
|
||||
.top-row ::deep a:hover, .top-row ::deep .btn-link:hover {
|
||||
text-decoration: underline;
|
||||
}
|
||||
|
||||
.top-row ::deep a:first-child {
|
||||
overflow: hidden;
|
||||
text-overflow: ellipsis;
|
||||
}
|
||||
|
||||
@media (max-width: 640.98px) {
|
||||
.top-row {
|
||||
justify-content: space-between;
|
||||
}
|
||||
|
||||
.top-row ::deep a, .top-row ::deep .btn-link {
|
||||
margin-left: 0;
|
||||
}
|
||||
}
|
||||
|
||||
@media (min-width: 641px) {
|
||||
.page {
|
||||
flex-direction: row;
|
||||
}
|
||||
|
||||
.sidebar {
|
||||
width: 250px;
|
||||
height: 100vh;
|
||||
position: sticky;
|
||||
top: 0;
|
||||
}
|
||||
|
||||
.top-row {
|
||||
position: sticky;
|
||||
top: 0;
|
||||
z-index: 1;
|
||||
}
|
||||
|
||||
.top-row.auth ::deep a:first-child {
|
||||
flex: 1;
|
||||
text-align: right;
|
||||
width: 0;
|
||||
}
|
||||
|
||||
.top-row, article {
|
||||
padding-left: 2rem !important;
|
||||
padding-right: 1.5rem !important;
|
||||
}
|
||||
}
|
||||
|
||||
#blazor-error-ui {
|
||||
background: lightyellow;
|
||||
bottom: 0;
|
||||
box-shadow: 0 -1px 2px rgba(0, 0, 0, 0.2);
|
||||
display: none;
|
||||
left: 0;
|
||||
padding: 0.6rem 1.25rem 0.7rem 1.25rem;
|
||||
position: fixed;
|
||||
width: 100%;
|
||||
z-index: 1000;
|
||||
}
|
||||
|
||||
#blazor-error-ui .dismiss {
|
||||
cursor: pointer;
|
||||
position: absolute;
|
||||
right: 0.75rem;
|
||||
top: 0.5rem;
|
||||
}
|
||||
@@ -0,0 +1,19 @@
|
||||
<div class="top-row ps-3 navbar navbar-dark">
|
||||
<div class="container-fluid">
|
||||
<a class="navbar-brand" href="">BlazorTest</a>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<input type="checkbox" title="Navigation menu" class="navbar-toggler" />
|
||||
|
||||
<div class="nav-scrollable" onclick="document.querySelector('.navbar-toggler').click()">
|
||||
<nav class="flex-column">
|
||||
|
||||
<div class="nav-item px-3">
|
||||
<NavLink class="nav-link" href="test">
|
||||
<span class="bi bi-plus-square-fill-nav-menu" aria-hidden="true"></span> Test
|
||||
</NavLink>
|
||||
</div>
|
||||
|
||||
</nav>
|
||||
</div>
|
||||
@@ -0,0 +1,105 @@
|
||||
.navbar-toggler {
|
||||
appearance: none;
|
||||
cursor: pointer;
|
||||
width: 3.5rem;
|
||||
height: 2.5rem;
|
||||
color: white;
|
||||
position: absolute;
|
||||
top: 0.5rem;
|
||||
right: 1rem;
|
||||
border: 1px solid rgba(255, 255, 255, 0.1);
|
||||
background: url("data:image/svg+xml,%3csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 30 30'%3e%3cpath stroke='rgba%28255, 255, 255, 0.55%29' stroke-linecap='round' stroke-miterlimit='10' stroke-width='2' d='M4 7h22M4 15h22M4 23h22'/%3e%3c/svg%3e") no-repeat center/1.75rem rgba(255, 255, 255, 0.1);
|
||||
}
|
||||
|
||||
.navbar-toggler:checked {
|
||||
background-color: rgba(255, 255, 255, 0.5);
|
||||
}
|
||||
|
||||
.top-row {
|
||||
height: 3.5rem;
|
||||
background-color: rgba(0,0,0,0.4);
|
||||
}
|
||||
|
||||
.navbar-brand {
|
||||
font-size: 1.1rem;
|
||||
}
|
||||
|
||||
.bi {
|
||||
display: inline-block;
|
||||
position: relative;
|
||||
width: 1.25rem;
|
||||
height: 1.25rem;
|
||||
margin-right: 0.75rem;
|
||||
top: -1px;
|
||||
background-size: cover;
|
||||
}
|
||||
|
||||
.bi-house-door-fill-nav-menu {
|
||||
background-image: url("data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' width='16' height='16' fill='white' class='bi bi-house-door-fill' viewBox='0 0 16 16'%3E%3Cpath d='M6.5 14.5v-3.505c0-.245.25-.495.5-.495h2c.25 0 .5.25.5.5v3.5a.5.5 0 0 0 .5.5h4a.5.5 0 0 0 .5-.5v-7a.5.5 0 0 0-.146-.354L13 5.793V2.5a.5.5 0 0 0-.5-.5h-1a.5.5 0 0 0-.5.5v1.293L8.354 1.146a.5.5 0 0 0-.708 0l-6 6A.5.5 0 0 0 1.5 7.5v7a.5.5 0 0 0 .5.5h4a.5.5 0 0 0 .5-.5Z'/%3E%3C/svg%3E");
|
||||
}
|
||||
|
||||
.bi-plus-square-fill-nav-menu {
|
||||
background-image: url("data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' width='16' height='16' fill='white' class='bi bi-plus-square-fill' viewBox='0 0 16 16'%3E%3Cpath d='M2 0a2 2 0 0 0-2 2v12a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V2a2 2 0 0 0-2-2H2zm6.5 4.5v3h3a.5.5 0 0 1 0 1h-3v3a.5.5 0 0 1-1 0v-3h-3a.5.5 0 0 1 0-1h3v-3a.5.5 0 0 1 1 0z'/%3E%3C/svg%3E");
|
||||
}
|
||||
|
||||
.bi-list-nested-nav-menu {
|
||||
background-image: url("data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' width='16' height='16' fill='white' class='bi bi-list-nested' viewBox='0 0 16 16'%3E%3Cpath fill-rule='evenodd' d='M4.5 11.5A.5.5 0 0 1 5 11h10a.5.5 0 0 1 0 1H5a.5.5 0 0 1-.5-.5zm-2-4A.5.5 0 0 1 3 7h10a.5.5 0 0 1 0 1H3a.5.5 0 0 1-.5-.5zm-2-4A.5.5 0 0 1 1 3h10a.5.5 0 0 1 0 1H1a.5.5 0 0 1-.5-.5z'/%3E%3C/svg%3E");
|
||||
}
|
||||
|
||||
.nav-item {
|
||||
font-size: 0.9rem;
|
||||
padding-bottom: 0.5rem;
|
||||
}
|
||||
|
||||
.nav-item:first-of-type {
|
||||
padding-top: 1rem;
|
||||
}
|
||||
|
||||
.nav-item:last-of-type {
|
||||
padding-bottom: 1rem;
|
||||
}
|
||||
|
||||
.nav-item ::deep .nav-link {
|
||||
color: #d7d7d7;
|
||||
background: none;
|
||||
border: none;
|
||||
border-radius: 4px;
|
||||
height: 3rem;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
line-height: 3rem;
|
||||
width: 100%;
|
||||
}
|
||||
|
||||
.nav-item ::deep a.active {
|
||||
background-color: rgba(255,255,255,0.37);
|
||||
color: white;
|
||||
}
|
||||
|
||||
.nav-item ::deep .nav-link:hover {
|
||||
background-color: rgba(255,255,255,0.1);
|
||||
color: white;
|
||||
}
|
||||
|
||||
.nav-scrollable {
|
||||
display: none;
|
||||
}
|
||||
|
||||
.navbar-toggler:checked ~ .nav-scrollable {
|
||||
display: block;
|
||||
}
|
||||
|
||||
@media (min-width: 641px) {
|
||||
.navbar-toggler {
|
||||
display: none;
|
||||
}
|
||||
|
||||
.nav-scrollable {
|
||||
/* Never collapse the sidebar for wide screens */
|
||||
display: block;
|
||||
|
||||
/* Allow sidebar to scroll for tall menus */
|
||||
height: calc(100vh - 3.5rem);
|
||||
overflow-y: auto;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,20 @@
|
||||
@rendermode InteractiveServer
|
||||
|
||||
<input @bind="Param1" @bind:event="onchange" @bind:after="Fire">
|
||||
|
||||
@code {
|
||||
[Parameter]
|
||||
public string? Param1 { get; set; } = "";
|
||||
|
||||
[Parameter]
|
||||
public EventCallback<string?> ValueChanged { get; set; }
|
||||
|
||||
[Parameter]
|
||||
public EventCallback<string?> Param1Changed { get; set; }
|
||||
|
||||
private void Fire()
|
||||
{
|
||||
ValueChanged.InvokeAsync(Param1);
|
||||
Param1Changed.InvokeAsync(Param1);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,11 @@
|
||||
@rendermode InteractiveServer
|
||||
|
||||
<div>
|
||||
<p>Value from InputText: @Value</p>
|
||||
<p>Raw value from InputText: @(new MarkupString(Value))</p>
|
||||
</div>
|
||||
|
||||
@code {
|
||||
[Parameter]
|
||||
public string Value { get; set; } = "";
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
@page "/Error"
|
||||
@using System.Diagnostics
|
||||
|
||||
<PageTitle>Error</PageTitle>
|
||||
|
||||
<h1 class="text-danger">Error.</h1>
|
||||
<h2 class="text-danger">An error occurred while processing your request.</h2>
|
||||
|
||||
@if (ShowRequestId)
|
||||
{
|
||||
<p>
|
||||
<strong>Request ID:</strong> <code>@RequestId</code>
|
||||
</p>
|
||||
}
|
||||
|
||||
<h3>Development Mode</h3>
|
||||
<p>
|
||||
Swapping to <strong>Development</strong> environment will display more detailed information about the error that occurred.
|
||||
</p>
|
||||
<p>
|
||||
<strong>The Development environment shouldn't be enabled for deployed applications.</strong>
|
||||
It can result in displaying sensitive information from exceptions to end users.
|
||||
For local debugging, enable the <strong>Development</strong> environment by setting the <strong>ASPNETCORE_ENVIRONMENT</strong> environment variable to <strong>Development</strong>
|
||||
and restarting the app.
|
||||
</p>
|
||||
|
||||
@code{
|
||||
[CascadingParameter]
|
||||
private HttpContext? HttpContext { get; set; }
|
||||
|
||||
private string? RequestId { get; set; }
|
||||
private bool ShowRequestId => !string.IsNullOrEmpty(RequestId);
|
||||
|
||||
protected override void OnInitialized() =>
|
||||
RequestId = Activity.Current?.Id ?? HttpContext?.TraceIdentifier;
|
||||
}
|
||||
@@ -0,0 +1,125 @@
|
||||
@page "/"
|
||||
@page "/test/{urlParam?}"
|
||||
@rendermode InteractiveServer
|
||||
|
||||
<PageTitle>TestPage</PageTitle>
|
||||
|
||||
<div>
|
||||
<h3>Route parameter</h3>
|
||||
<p>Go to: <a href="/test/@XssUrl">/test/@XssUrl</a></p>
|
||||
<p>Parameter from URL: @UrlParam</p>
|
||||
<p>Raw parameter from URL: @((MarkupString)UrlParam)</p>
|
||||
</div>
|
||||
|
||||
<hr />
|
||||
|
||||
<div>
|
||||
<h3>Query parameter</h3>
|
||||
<p>Go to: <a href="/test/?qs=@XssUrl">/test/?qs=@XssUrl</a></p>
|
||||
<p>Parameter from query string: @QueryParam</p>
|
||||
<p>Raw parameter from query string: @(new MarkupString(QueryParam))</p>
|
||||
</div>
|
||||
|
||||
<hr />
|
||||
|
||||
<div>
|
||||
<h3>Bind InputText component</h3>
|
||||
<InputText @bind-Value="InputValue1" />
|
||||
<p>Value from InputText: @InputValue1</p>
|
||||
<p>Raw value from InputText: @(new MarkupString(InputValue1))</p>
|
||||
</div>
|
||||
|
||||
<hr />
|
||||
|
||||
<div>
|
||||
<h3>Bind input element</h3>
|
||||
<input @bind="InputValue2">
|
||||
<p>Value from InputText: @InputValue2</p>
|
||||
<p>Raw value from InputText: @(new MarkupString(InputValue2))</p>
|
||||
</div>
|
||||
|
||||
<hr />
|
||||
|
||||
<div>
|
||||
<h3>Bind through object property</h3>
|
||||
<input @bind="Container1.Value">
|
||||
<p>Value from InputText: @Container1.Value</p>
|
||||
<p>Raw value from InputText: @(new MarkupString(Container1.Value))</p>
|
||||
</div>
|
||||
|
||||
<hr />
|
||||
|
||||
<div>
|
||||
<h3>Input component with custom event</h3>
|
||||
<MyInput Param1="@InputValue3" ValueChanged="MyInputChanged" />
|
||||
<p>Value from InputText: @InputValue3</p>
|
||||
<p>Raw value from InputText: @(new MarkupString(InputValue3))</p>
|
||||
</div>
|
||||
|
||||
<hr />
|
||||
|
||||
<div>
|
||||
<h3>Input component with binding</h3>
|
||||
<MyInput @bind-Param1="InputValue4" />
|
||||
<p>Value from InputText: @InputValue4</p>
|
||||
<p>Raw value from InputText: @(new MarkupString(InputValue4))</p>
|
||||
</div>
|
||||
|
||||
<hr />
|
||||
|
||||
<div>
|
||||
<h3>Input, Output components</h3>
|
||||
<MyInput @bind-Param1="InputValue5" />
|
||||
<MyOutput Value="@InputValue5" />
|
||||
</div>
|
||||
|
||||
<hr />
|
||||
|
||||
<div>
|
||||
<h3>Bind InputText, Output component</h3>
|
||||
<InputText @bind-Value="InputValue6" />
|
||||
<MyOutput Value="@InputValue6" />
|
||||
</div>
|
||||
|
||||
@code {
|
||||
|
||||
public class Container
|
||||
{
|
||||
public string? Value { get; set; } = "";
|
||||
}
|
||||
|
||||
private const string XssUrl = "<b>aaaa<%2Fb>";
|
||||
private const string XssUrl2 = "<b>aaaa</b>";
|
||||
|
||||
[Parameter]
|
||||
public string UrlParam { get; set; } = "";
|
||||
|
||||
[SupplyParameterFromQuery(Name = "qs")]
|
||||
public string QueryParam { get; set; } = "";
|
||||
|
||||
public string InputValue1 { get; set; } = "";
|
||||
public string InputValue2 { get; set; } = "";
|
||||
public string InputValue3 { get; set; } = "";
|
||||
public string InputValue4 { get; set; } = "";
|
||||
public string InputValue5 { get; set; } = "";
|
||||
public string InputValue6 { get; set; } = "";
|
||||
|
||||
public Container Container1 { get; set; } = new Container();
|
||||
|
||||
protected override void OnInitialized()
|
||||
{
|
||||
InputValue1 = XssUrl2;
|
||||
InputValue2 = XssUrl2;
|
||||
Container1.Value = XssUrl2;
|
||||
InputValue3 = XssUrl2;
|
||||
InputValue4 = XssUrl2;
|
||||
InputValue5 = XssUrl2;
|
||||
InputValue6 = XssUrl2;
|
||||
|
||||
}
|
||||
|
||||
private void MyInputChanged(string value)
|
||||
{
|
||||
InputValue3 = value;
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,6 @@
|
||||
<Router AppAssembly="typeof(Program).Assembly">
|
||||
<Found Context="routeData">
|
||||
<RouteView RouteData="routeData" DefaultLayout="typeof(Layout.MainLayout)" />
|
||||
<FocusOnNavigate RouteData="routeData" Selector="h1" />
|
||||
</Found>
|
||||
</Router>
|
||||
@@ -0,0 +1,10 @@
|
||||
@using System.Net.Http
|
||||
@using System.Net.Http.Json
|
||||
@using Microsoft.AspNetCore.Components.Forms
|
||||
@using Microsoft.AspNetCore.Components.Routing
|
||||
@using Microsoft.AspNetCore.Components.Web
|
||||
@using static Microsoft.AspNetCore.Components.Web.RenderMode
|
||||
@using Microsoft.AspNetCore.Components.Web.Virtualization
|
||||
@using Microsoft.JSInterop
|
||||
@using BlazorTest
|
||||
@using BlazorTest.Components
|
||||
@@ -0,0 +1,27 @@
|
||||
using BlazorTest.Components;
|
||||
|
||||
var builder = WebApplication.CreateBuilder(args);
|
||||
|
||||
// Add services to the container.
|
||||
builder.Services.AddRazorComponents()
|
||||
.AddInteractiveServerComponents();
|
||||
|
||||
var app = builder.Build();
|
||||
|
||||
// Configure the HTTP request pipeline.
|
||||
if (!app.Environment.IsDevelopment())
|
||||
{
|
||||
app.UseExceptionHandler("/Error", createScopeForErrors: true);
|
||||
// The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
|
||||
app.UseHsts();
|
||||
}
|
||||
|
||||
app.UseHttpsRedirection();
|
||||
|
||||
app.UseStaticFiles();
|
||||
app.UseAntiforgery();
|
||||
|
||||
app.MapRazorComponents<App>()
|
||||
.AddInteractiveServerRenderMode();
|
||||
|
||||
app.Run();
|
||||
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"$schema": "http://json.schemastore.org/launchsettings.json",
|
||||
"profiles": {
|
||||
"http": {
|
||||
"commandName": "Project",
|
||||
"dotnetRunMessages": true,
|
||||
"launchBrowser": true,
|
||||
"applicationUrl": "http://localhost:5047",
|
||||
"environmentVariables": {
|
||||
"ASPNETCORE_ENVIRONMENT": "Development"
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
{
|
||||
"Logging": {
|
||||
"LogLevel": {
|
||||
"Default": "Information",
|
||||
"Microsoft.AspNetCore": "Warning"
|
||||
}
|
||||
},
|
||||
"AllowedHosts": "*"
|
||||
}
|
||||
@@ -0,0 +1,5 @@
|
||||
{
|
||||
"sdk": {
|
||||
"version": "9.0.100"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,51 @@
|
||||
html, body {
|
||||
font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif;
|
||||
}
|
||||
|
||||
a, .btn-link {
|
||||
color: #006bb7;
|
||||
}
|
||||
|
||||
.btn-primary {
|
||||
color: #fff;
|
||||
background-color: #1b6ec2;
|
||||
border-color: #1861ac;
|
||||
}
|
||||
|
||||
.btn:focus, .btn:active:focus, .btn-link.nav-link:focus, .form-control:focus, .form-check-input:focus {
|
||||
box-shadow: 0 0 0 0.1rem white, 0 0 0 0.25rem #258cfb;
|
||||
}
|
||||
|
||||
.content {
|
||||
padding-top: 1.1rem;
|
||||
}
|
||||
|
||||
h1:focus {
|
||||
outline: none;
|
||||
}
|
||||
|
||||
.valid.modified:not([type=checkbox]) {
|
||||
outline: 1px solid #26b050;
|
||||
}
|
||||
|
||||
.invalid {
|
||||
outline: 1px solid #e50000;
|
||||
}
|
||||
|
||||
.validation-message {
|
||||
color: #e50000;
|
||||
}
|
||||
|
||||
.blazor-error-boundary {
|
||||
background: url(data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iNTYiIGhlaWdodD0iNDkiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgeG1sbnM6eGxpbms9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkveGxpbmsiIG92ZXJmbG93PSJoaWRkZW4iPjxkZWZzPjxjbGlwUGF0aCBpZD0iY2xpcDAiPjxyZWN0IHg9IjIzNSIgeT0iNTEiIHdpZHRoPSI1NiIgaGVpZ2h0PSI0OSIvPjwvY2xpcFBhdGg+PC9kZWZzPjxnIGNsaXAtcGF0aD0idXJsKCNjbGlwMCkiIHRyYW5zZm9ybT0idHJhbnNsYXRlKC0yMzUgLTUxKSI+PHBhdGggZD0iTTI2My41MDYgNTFDMjY0LjcxNyA1MSAyNjUuODEzIDUxLjQ4MzcgMjY2LjYwNiA1Mi4yNjU4TDI2Ny4wNTIgNTIuNzk4NyAyNjcuNTM5IDUzLjYyODMgMjkwLjE4NSA5Mi4xODMxIDI5MC41NDUgOTIuNzk1IDI5MC42NTYgOTIuOTk2QzI5MC44NzcgOTMuNTEzIDI5MSA5NC4wODE1IDI5MSA5NC42NzgyIDI5MSA5Ny4wNjUxIDI4OS4wMzggOTkgMjg2LjYxNyA5OUwyNDAuMzgzIDk5QzIzNy45NjMgOTkgMjM2IDk3LjA2NTEgMjM2IDk0LjY3ODIgMjM2IDk0LjM3OTkgMjM2LjAzMSA5NC4wODg2IDIzNi4wODkgOTMuODA3MkwyMzYuMzM4IDkzLjAxNjIgMjM2Ljg1OCA5Mi4xMzE0IDI1OS40NzMgNTMuNjI5NCAyNTkuOTYxIDUyLjc5ODUgMjYwLjQwNyA1Mi4yNjU4QzI2MS4yIDUxLjQ4MzcgMjYyLjI5NiA1MSAyNjMuNTA2IDUxWk0yNjMuNTg2IDY2LjAxODNDMjYwLjczNyA2Ni4wMTgzIDI1OS4zMTMgNjcuMTI0NSAyNTkuMzEzIDY5LjMzNyAyNTkuMzEzIDY5LjYxMDIgMjU5LjMzMiA2OS44NjA4IDI1OS4zNzEgNzAuMDg4N0wyNjEuNzk1IDg0LjAxNjEgMjY1LjM4IDg0LjAxNjEgMjY3LjgyMSA2OS43NDc1QzI2Ny44NiA2OS43MzA5IDI2Ny44NzkgNjkuNTg3NyAyNjcuODc5IDY5LjMxNzkgMjY3Ljg3OSA2Ny4xMTgyIDI2Ni40NDggNjYuMDE4MyAyNjMuNTg2IDY2LjAxODNaTTI2My41NzYgODYuMDU0N0MyNjEuMDQ5IDg2LjA1NDcgMjU5Ljc4NiA4Ny4zMDA1IDI1OS43ODYgODkuNzkyMSAyNTkuNzg2IDkyLjI4MzcgMjYxLjA0OSA5My41Mjk1IDI2My41NzYgOTMuNTI5NSAyNjYuMTE2IDkzLjUyOTUgMjY3LjM4NyA5Mi4yODM3IDI2Ny4zODcgODkuNzkyMSAyNjcuMzg3IDg3LjMwMDUgMjY2LjExNiA4Ni4wNTQ3IDI2My41NzYgODYuMDU0N1oiIGZpbGw9IiNGRkU1MDAiIGZpbGwtcnVsZT0iZXZlbm9kZCIvPjwvZz48L3N2Zz4=) no-repeat 1rem/1.8rem, #b32121;
|
||||
padding: 1rem 1rem 1rem 3.7rem;
|
||||
color: white;
|
||||
}
|
||||
|
||||
.blazor-error-boundary::after {
|
||||
content: "An error has occurred."
|
||||
}
|
||||
|
||||
.darker-border-checkbox.form-check-input {
|
||||
border-color: #929292;
|
||||
}
|
||||
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
Binary file not shown.
|
After Width: | Height: | Size: 1.1 KiB |
@@ -0,0 +1,20 @@
|
||||
| BlazorTest/Components/App.razor |
|
||||
| BlazorTest/Components/Layout/MainLayout.razor |
|
||||
| BlazorTest/Components/Layout/NavMenu.razor |
|
||||
| BlazorTest/Components/MyInput.razor |
|
||||
| BlazorTest/Components/MyOutput.razor |
|
||||
| BlazorTest/Components/Pages/Error.razor |
|
||||
| BlazorTest/Components/Pages/TestPage.razor |
|
||||
| BlazorTest/Components/Routes.razor |
|
||||
| BlazorTest/Components/_Imports.razor |
|
||||
| BlazorTest/Program.cs |
|
||||
| [...]/Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator/Components_App_razor.g.cs |
|
||||
| [...]/Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator/Components_Layout_MainLayout_razor.g.cs |
|
||||
| [...]/Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator/Components_Layout_NavMenu_razor.g.cs |
|
||||
| [...]/Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator/Components_MyInput_razor.g.cs |
|
||||
| [...]/Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator/Components_MyOutput_razor.g.cs |
|
||||
| [...]/Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator/Components_Pages_Error_razor.g.cs |
|
||||
| [...]/Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator/Components_Pages_TestPage_razor.g.cs |
|
||||
| [...]/Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator/Components_Routes_razor.g.cs |
|
||||
| [...]/Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator/Components__Imports_razor.g.cs |
|
||||
| test-db/working/implicitUsings/GlobalUsings.g.cs |
|
||||
@@ -0,0 +1,29 @@
|
||||
import csharp
|
||||
|
||||
private string razorSourceGenerator() {
|
||||
result =
|
||||
"Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator"
|
||||
}
|
||||
|
||||
private string getPath(File f) {
|
||||
result = f.getRelativePath() and
|
||||
not exists(result.indexOf(razorSourceGenerator()))
|
||||
or
|
||||
exists(int index1, string path | path = f.getRelativePath() |
|
||||
// pattern =
|
||||
// "Microsoft.CodeAnalysis.Razor.Compiler/Microsoft.NET.Sdk.Razor.SourceGenerators.RazorSourceGenerator" and
|
||||
// index1 = f.getRelativePath().indexOf(pattern) and
|
||||
// index2 =
|
||||
// f.getRelativePath()
|
||||
// .indexOf("_ql_csharp_ql_integration_tests_all_platforms_blazor_build_mode_none_") and
|
||||
// result =
|
||||
// "[...]/" + f.getRelativePath().substring(index1, index1 + pattern.length()) + "/[...]" +
|
||||
// f.getRelativePath().substring(index2, f.getRelativePath().length())
|
||||
index1 = path.indexOf(razorSourceGenerator()) and
|
||||
result = "[...]/" + f.getRelativePath().substring(index1, path.length())
|
||||
)
|
||||
}
|
||||
|
||||
from File f
|
||||
where f.fromSource() or f.getExtension() = "razor"
|
||||
select getPath(f)
|
||||
@@ -0,0 +1,8 @@
|
||||
| BlazorTest/Components/MyOutput.razor:5:53:5:57 | access to property Value |
|
||||
| BlazorTest/Components/Pages/TestPage.razor:11:48:11:55 | access to property UrlParam |
|
||||
| BlazorTest/Components/Pages/TestPage.razor:20:60:20:69 | access to property QueryParam |
|
||||
| BlazorTest/Components/Pages/TestPage.razor:29:53:29:63 | access to property InputValue1 |
|
||||
| BlazorTest/Components/Pages/TestPage.razor:38:53:38:63 | access to property InputValue2 |
|
||||
| BlazorTest/Components/Pages/TestPage.razor:47:53:47:68 | access to property Value |
|
||||
| BlazorTest/Components/Pages/TestPage.razor:56:53:56:63 | access to property InputValue3 |
|
||||
| BlazorTest/Components/Pages/TestPage.razor:65:53:65:63 | access to property InputValue4 |
|
||||
@@ -0,0 +1,7 @@
|
||||
import semmle.code.csharp.security.dataflow.flowsinks.Html
|
||||
|
||||
from HtmlSink sink, File f
|
||||
where
|
||||
sink.getLocation().getFile() = f and
|
||||
(f.fromSource() or f.getExtension() = "razor")
|
||||
select sink
|
||||
@@ -0,0 +1,5 @@
|
||||
import pytest
|
||||
|
||||
@pytest.mark.ql_test("DB-CHECK", xfail=True)
|
||||
def test(codeql, csharp):
|
||||
codeql.database.create(build_mode="none")
|
||||
@@ -13,6 +13,8 @@ public class CollectionFlow
|
||||
|
||||
public static void SinkElem<T>(T[] ts) => Sink(ts[0]);
|
||||
|
||||
public static void SinkLastElem<T>(T[] ts) => Sink(ts[^1]);
|
||||
|
||||
public static void SinkListElem<T>(IList<T> list) => Sink(list[0]);
|
||||
|
||||
public static void SinkDictValue<T>(IDictionary<int, T> dict) => Sink(dict[0]);
|
||||
@@ -21,6 +23,8 @@ public class CollectionFlow
|
||||
|
||||
public static T First<T>(T[] ts) => ts[0];
|
||||
|
||||
public static T Last<T>(T[] ts) => ts[^1];
|
||||
|
||||
public static T ListFirst<T>(IList<T> list) => list[0];
|
||||
|
||||
public static T DictIndexZero<T>(IDictionary<int, T> dict) => dict[0];
|
||||
@@ -73,6 +77,15 @@ public class CollectionFlow
|
||||
Sink(First(c.As)); // no flow
|
||||
}
|
||||
|
||||
public void ArrayInitializerImplicitIndexFlow()
|
||||
{
|
||||
var a = new A();
|
||||
var c = new CollectionFlow() { As = { [^1] = a } };
|
||||
Sink(c.As[^1]); // flow
|
||||
SinkLastElem(c.As); // flow
|
||||
Sink(Last(c.As)); // flow
|
||||
}
|
||||
|
||||
public void ArrayAssignmentFlow()
|
||||
{
|
||||
var a = new A();
|
||||
@@ -93,6 +106,16 @@ public class CollectionFlow
|
||||
Sink(First(@as)); // no flow
|
||||
}
|
||||
|
||||
public void ArrayAssignmentImplicitIndexFlow()
|
||||
{
|
||||
var a = new A();
|
||||
var @as = new A[1];
|
||||
@as[^1] = a;
|
||||
Sink(@as[^1]); // flow
|
||||
SinkLastElem(@as); // flow
|
||||
Sink(Last(@as)); // flow
|
||||
}
|
||||
|
||||
public void ListAssignmentFlow()
|
||||
{
|
||||
var a = new A();
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
24
csharp/ql/test/library-tests/index/Index.cs
Normal file
24
csharp/ql/test/library-tests/index/Index.cs
Normal file
@@ -0,0 +1,24 @@
|
||||
using System;
|
||||
|
||||
public class Container
|
||||
{
|
||||
public object[] Buffer { get; } = new object[10];
|
||||
}
|
||||
|
||||
public class TestIndex
|
||||
{
|
||||
public void M()
|
||||
{
|
||||
var c = new Container()
|
||||
{
|
||||
Buffer =
|
||||
{
|
||||
[0] = new object(),
|
||||
[1] = new object(),
|
||||
[^1] = new object()
|
||||
}
|
||||
};
|
||||
c.Buffer[4] = new object();
|
||||
c.Buffer[^3] = new object();
|
||||
}
|
||||
}
|
||||
2
csharp/ql/test/library-tests/index/Index.expected
Normal file
2
csharp/ql/test/library-tests/index/Index.expected
Normal file
@@ -0,0 +1,2 @@
|
||||
| Index.cs:18:18:18:19 | ^... | Index.cs:18:19:18:19 | 1 |
|
||||
| Index.cs:22:18:22:19 | ^... | Index.cs:22:19:22:19 | 3 |
|
||||
4
csharp/ql/test/library-tests/index/Index.ql
Normal file
4
csharp/ql/test/library-tests/index/Index.ql
Normal file
@@ -0,0 +1,4 @@
|
||||
import csharp
|
||||
|
||||
from IndexExpr e
|
||||
select e, e.getExpr()
|
||||
@@ -24,4 +24,3 @@ project/build/intermediates/merged_manifests/release/AndroidManifest.xml
|
||||
project/build/intermediates/packaged_manifests/release/AndroidManifest.xml
|
||||
project/src/main/AndroidManifest.xml
|
||||
project/src/main/java/com/github/androidsample/Main.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -23,4 +23,3 @@ project/build/intermediates/merged_manifests/release/AndroidManifest.xml
|
||||
project/build/intermediates/packaged_manifests/release/AndroidManifest.xml
|
||||
project/src/main/AndroidManifest.xml
|
||||
project/src/main/java/com/github/androidsample/Main.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -23,4 +23,3 @@ project/build/intermediates/merged_manifests/release/AndroidManifest.xml
|
||||
project/build/intermediates/packaged_manifests/release/AndroidManifest.xml
|
||||
project/src/main/AndroidManifest.xml
|
||||
project/src/main/java/com/github/androidsample/Main.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -23,4 +23,3 @@ project/build/intermediates/merged_manifests/release/AndroidManifest.xml
|
||||
project/build/intermediates/packaged_manifests/release/AndroidManifest.xml
|
||||
project/src/main/AndroidManifest.xml
|
||||
project/src/main/java/com/github/androidsample/Main.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -26,4 +26,3 @@ project/build/intermediates/merged_manifests/release/AndroidManifest.xml
|
||||
project/build/intermediates/packaged_manifests/release/AndroidManifest.xml
|
||||
project/src/main/AndroidManifest.xml
|
||||
project/src/main/java/com/github/androidsample/Main.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -26,4 +26,3 @@ project/build/intermediates/merged_manifests/release/AndroidManifest.xml
|
||||
project/build/intermediates/packaged_manifests/release/AndroidManifest.xml
|
||||
project/src/main/AndroidManifest.xml
|
||||
project/src/main/java/com/github/androidsample/Main.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -26,4 +26,3 @@ project/build/intermediates/merged_manifests/release/AndroidManifest.xml
|
||||
project/build/intermediates/packaged_manifests/release/AndroidManifest.xml
|
||||
project/src/main/AndroidManifest.xml
|
||||
project/src/main/java/com/github/androidsample/Main.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -26,4 +26,3 @@ project/build/intermediates/merged_manifests/release/AndroidManifest.xml
|
||||
project/build/intermediates/packaged_manifests/release/AndroidManifest.xml
|
||||
project/src/main/AndroidManifest.xml
|
||||
project/src/main/java/com/github/androidsample/Main.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -23,4 +23,3 @@ project/build/intermediates/merged_manifests/release/AndroidManifest.xml
|
||||
project/build/intermediates/packaged_manifests/release/AndroidManifest.xml
|
||||
project/src/main/AndroidManifest.xml
|
||||
project/src/main/java/com/github/androidsample/Main.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -5,10 +5,9 @@
|
||||
| Number of diagnostics from CodeQL Java extractor with severity 6 | 2 |
|
||||
| Number of expressions with known type | 1 |
|
||||
| Number of expressions with unknown type | 6 |
|
||||
| Number of files | 607 |
|
||||
| Number of files | 606 |
|
||||
| Number of files with extension class | 604 |
|
||||
| Number of files with extension java | 1 |
|
||||
| Number of files with extension properties | 1 |
|
||||
| Number of lines of code | 7 |
|
||||
| Number of lines of code with extension java | 7 |
|
||||
| Percentage of calls with call target | 20 |
|
||||
|
||||
@@ -4,4 +4,3 @@
|
||||
.gradle/vcs-1/gc.properties
|
||||
gradle/wrapper/gradle-wrapper.properties
|
||||
src/main/java/com/fractestexample/Test.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -2,4 +2,3 @@ gradle/verification-metadata.xml
|
||||
gradle/wrapper/gradle-wrapper.properties
|
||||
src/main/java/com/example/App.java
|
||||
src/test/java/com/example/AppTest.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -4,4 +4,3 @@
|
||||
.gradle/vcs-1/gc.properties
|
||||
gradle/wrapper/gradle-wrapper.properties
|
||||
src/main/java/com/fractestexample/Test.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -4,5 +4,4 @@ src/main/resources/my-app.properties
|
||||
src/main/resources/page.xml
|
||||
src/main/resources/struts.xml
|
||||
src/test/java/com/example/AppTest.java
|
||||
test-db/log/ext/javac.properties
|
||||
test-db/working/settings.xml
|
||||
|
||||
@@ -5,5 +5,4 @@ src/main/resources/my-app.properties
|
||||
src/main/resources/page.xml
|
||||
src/main/resources/struts.xml
|
||||
src/test/java/com/example/AppTest.java
|
||||
test-db/log/ext/javac.properties
|
||||
test-db/working/settings.xml
|
||||
|
||||
@@ -11,5 +11,4 @@ submod2/src/main/resources/my-app.properties
|
||||
submod2/src/main/resources/page.xml
|
||||
submod2/src/main/resources/struts.xml
|
||||
submod2/src/test/java/com/example/AppTest2.java
|
||||
test-db/log/ext/javac.properties
|
||||
test-db/working/settings.xml
|
||||
|
||||
@@ -5,5 +5,4 @@ src/main/resources/my-app.properties
|
||||
src/main/resources/page.xml
|
||||
src/main/resources/struts.xml
|
||||
src/test/java/com/example/AppTest.java
|
||||
test-db/log/ext/javac.properties
|
||||
test-db/working/settings.xml
|
||||
|
||||
@@ -4,5 +4,4 @@ src/main/resources/my-app.properties
|
||||
src/main/resources/page.xml
|
||||
src/main/resources/struts.xml
|
||||
src/test/java/com/example/AppTest.java
|
||||
test-db/log/ext/javac.properties
|
||||
test-db/working/settings.xml
|
||||
|
||||
@@ -4,4 +4,3 @@
|
||||
.gradle/vcs-1/gc.properties
|
||||
gradle/wrapper/gradle-wrapper.properties
|
||||
src/main/java/com/fractestexample/Test.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -4,5 +4,4 @@ src/main/resources/my-app.properties
|
||||
src/main/resources/page.xml
|
||||
src/main/resources/struts.xml
|
||||
src/test/java/com/example/AppTest.java
|
||||
test-db/log/ext/javac.properties
|
||||
test-db/working/settings.xml
|
||||
|
||||
@@ -26,5 +26,4 @@ maven-project-2/src/main/resources/my-app.properties
|
||||
maven-project-2/src/main/resources/page.xml
|
||||
maven-project-2/src/main/resources/struts.xml
|
||||
maven-project-2/src/test/java/com/example/AppTest4.java
|
||||
test-db/log/ext/javac.properties
|
||||
test-db/working/settings.xml
|
||||
|
||||
@@ -3,4 +3,3 @@ src/main/resources/my-app.properties
|
||||
src/main/resources/page.xml
|
||||
src/main/resources/struts.xml
|
||||
src/test/java/com/example/AppTest.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -1,2 +1 @@
|
||||
Test.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -1,2 +1 @@
|
||||
Test.java
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -5,5 +5,3 @@
|
||||
app/src/main/java/test/App.java
|
||||
app/src/test/java/test/AppTest.java
|
||||
gradle/wrapper/gradle-wrapper.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -5,5 +5,3 @@
|
||||
gradle/wrapper/gradle-wrapper.properties
|
||||
src/main/java/com/example/App.java
|
||||
src/test/java/com/example/AppTest.java
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -8,5 +8,3 @@ target/classes/my-app.properties
|
||||
target/classes/page.xml
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -8,5 +8,3 @@ target/classes/my-app.properties
|
||||
target/classes/page.xml
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -6,5 +6,3 @@ src/test/java/com/example/AppTest.java
|
||||
target/classes/my-app.properties
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -13,5 +13,3 @@ target/classes/my-app.properties
|
||||
target/classes/page.xml
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -8,5 +8,3 @@ target/classes/my-app.properties
|
||||
target/classes/page.xml
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -6,5 +6,3 @@ src/test/java/com/example/AppTest.java
|
||||
target/classes/my-app.properties
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -3,5 +3,3 @@ src/main/resources/my-app.properties
|
||||
src/test/java/com/example/AppTest.java
|
||||
target/classes/my-app.properties
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -6,5 +6,3 @@ src/test/java/com/example/AppTest.java
|
||||
target/classes/my-app.properties
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -8,5 +8,3 @@ target/classes/my-app.properties
|
||||
target/classes/page.xml
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -9,5 +9,3 @@ target/classes/my-app.properties
|
||||
target/classes/page.xml
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -9,5 +9,3 @@ target/classes/my-app.properties
|
||||
target/classes/page.xml
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -9,5 +9,3 @@ target/classes/my-app.properties
|
||||
target/classes/page.xml
|
||||
target/classes/struts.xml
|
||||
target/maven-archiver/pom.properties
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -3,11 +3,10 @@
|
||||
| Number of calls with missing call target | 0 |
|
||||
| Number of expressions with known type | 1 |
|
||||
| Number of expressions with unknown type | 0 |
|
||||
| Number of files | 543 |
|
||||
| Number of files | 542 |
|
||||
| Number of files with extension class | 538 |
|
||||
| Number of files with extension jar | 1 |
|
||||
| Number of files with extension java | 2 |
|
||||
| Number of files with extension properties | 1 |
|
||||
| Number of lines of code | 7 |
|
||||
| Number of lines of code with extension java | 7 |
|
||||
| Percentage of calls with call target | 100 |
|
||||
|
||||
@@ -3,11 +3,10 @@
|
||||
| Number of calls with missing call target | 0 |
|
||||
| Number of expressions with known type | 1 |
|
||||
| Number of expressions with unknown type | 0 |
|
||||
| Number of files | 610 |
|
||||
| Number of files | 609 |
|
||||
| Number of files with extension class | 605 |
|
||||
| Number of files with extension jar | 1 |
|
||||
| Number of files with extension java | 2 |
|
||||
| Number of files with extension properties | 1 |
|
||||
| Number of lines of code | 7 |
|
||||
| Number of lines of code with extension java | 7 |
|
||||
| Percentage of calls with call target | 100 |
|
||||
|
||||
@@ -6,5 +6,3 @@ gradle/verification-metadata.xml
|
||||
gradle/wrapper/gradle-wrapper.properties
|
||||
src/main/java/com/example/App.java
|
||||
src/test/java/com/example/AppTest.java
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -6,5 +6,3 @@ gradle/verification-metadata.xml
|
||||
gradle/wrapper/gradle-wrapper.properties
|
||||
src/main/java/com/example/App.java
|
||||
src/test/java/com/example/AppTest.java
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
@@ -7,5 +7,3 @@ gradle/wrapper/gradle-wrapper.properties
|
||||
src/main/java/com/github/springbootsample/SpringBootSampleApplication.java
|
||||
src/main/resources/application.properties
|
||||
src/test/java/com/github/springbootsample/SpringBootSampleApplicationTests.java
|
||||
test-db/log/ext/javac-1.properties
|
||||
test-db/log/ext/javac.properties
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user