mirror of
https://github.com/github/codeql.git
synced 2026-04-30 11:15:13 +02:00
Python: Show unresolved calls for field-flow tests
This commit is contained in:
@@ -0,0 +1,23 @@
|
||||
import python
|
||||
private import semmle.python.dataflow.new.internal.PrintNode
|
||||
private import semmle.python.dataflow.new.internal.DataFlowPrivate as DataFlowPrivate
|
||||
private import semmle.python.ApiGraphs
|
||||
import TestUtilities.InlineExpectationsTest
|
||||
|
||||
class UnresolvedCallExpectations extends InlineExpectationsTest {
|
||||
UnresolvedCallExpectations() { this = "UnresolvedCallExpectations" }
|
||||
|
||||
override string getARelevantTag() { result = ["unresolved_call"] }
|
||||
|
||||
override predicate hasActualResult(Location location, string element, string tag, string value) {
|
||||
exists(location.getFile().getRelativePath()) and
|
||||
exists(CallNode call |
|
||||
not exists(DataFlowPrivate::DataFlowCall dfc | dfc.getNode() = call) and
|
||||
not call = API::builtin(_).getACall().asCfgNode() and
|
||||
location = call.getLocation() and
|
||||
tag = "unresolved_call" and
|
||||
value = prettyExpr(call.getNode()) and
|
||||
element = call.toString()
|
||||
)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,2 @@
|
||||
import python
|
||||
import experimental.dataflow.TestUtil.UnresolvedCalls
|
||||
@@ -1,7 +1,7 @@
|
||||
import sys
|
||||
import os
|
||||
|
||||
sys.path.append(os.path.dirname(os.path.dirname((__file__))))
|
||||
sys.path.append(os.path.dirname(os.path.dirname((__file__)))) # $ unresolved_call=os.path.dirname(..) unresolved_call=sys.path.append(..)
|
||||
from testlib import *
|
||||
|
||||
# These are defined so that we can evaluate the test code.
|
||||
@@ -42,7 +42,7 @@ def setFoo(obj, x):
|
||||
SINK_F(obj.foo)
|
||||
obj.foo = x
|
||||
|
||||
@expects(2)
|
||||
@expects(2) # $ unresolved_call=expects(..) unresolved_call=expects(..)(..)
|
||||
def test_indirect_assign():
|
||||
myobj = MyObj("OK")
|
||||
|
||||
@@ -53,7 +53,7 @@ def test_indirect_assign():
|
||||
def test_indirect_assign_method():
|
||||
myobj = MyObj("OK")
|
||||
|
||||
myobj.setFoo(SOURCE)
|
||||
myobj.setFoo(SOURCE) # $ unresolved_call=myobj.setFoo(..)
|
||||
SINK(myobj.foo) # $ MISSING: flow
|
||||
|
||||
|
||||
@@ -79,7 +79,7 @@ def test_direct_if_assign(cond = False):
|
||||
SINK(myobj.foo) # $ flow="SOURCE, l:-4 -> myobj.foo"
|
||||
|
||||
|
||||
@expects(2)
|
||||
@expects(2) # $ unresolved_call=expects(..) unresolved_call=expects(..)(..)
|
||||
def test_direct_if_always_assign(cond = True):
|
||||
myobj = MyObj(NONSOURCE)
|
||||
myobj.foo = SOURCE
|
||||
@@ -157,7 +157,7 @@ def test_nested_obj():
|
||||
def test_nested_obj_method():
|
||||
x = SOURCE
|
||||
a = NestedObj()
|
||||
a.getObj().foo = x
|
||||
a.getObj().foo = x # $ unresolved_call=a.getObj()
|
||||
SINK(a.obj.foo) # $ MISSING: flow
|
||||
|
||||
# ------------------------------------------------------------------------------
|
||||
@@ -173,12 +173,12 @@ def test_nested_obj_method():
|
||||
# scope tests into multiple functions, since we wouldn't know which one did the initial
|
||||
# import that does all the printing :|
|
||||
|
||||
@expects(18 + 2)
|
||||
@expects(18 + 2) # $ unresolved_call=expects(..) unresolved_call=expects(..)(..)
|
||||
def test_global_scope():
|
||||
import fieldflow.test_global
|
||||
|
||||
fieldflow.test_global.func_defined_before()
|
||||
fieldflow.test_global.func_defined_after()
|
||||
fieldflow.test_global.func_defined_before() # $ unresolved_call=fieldflow.test_global.func_defined_before()
|
||||
fieldflow.test_global.func_defined_after() # $ unresolved_call=fieldflow.test_global.func_defined_after()
|
||||
|
||||
# ------------------------------------------------------------------------------
|
||||
# Global flow cases that doesn't work in this file, but works in test_global.py
|
||||
@@ -194,40 +194,40 @@ SINK(obj2.foo) # $ flow="SOURCE, l:-1 -> obj2.foo"
|
||||
|
||||
# apparently these if statements below makes a difference :O
|
||||
# but one is not enough
|
||||
cond = os.urandom(1)[0] > 128
|
||||
cond = os.urandom(1)[0] > 128 # $ unresolved_call=os.urandom(..)
|
||||
|
||||
if cond:
|
||||
pass
|
||||
|
||||
# def test_constructor_assign():
|
||||
obj2 = MyObj(SOURCE)
|
||||
SINK(obj2.foo) # $ MISSING: flow="SOURCE, l:-1 -> obj2.foo"
|
||||
obj2 = MyObj(SOURCE) # $ unresolved_call=MyObj(..)
|
||||
SINK(obj2.foo) # $ unresolved_call=SINK(..) MISSING: flow="SOURCE, l:-1 -> obj2.foo"
|
||||
|
||||
if cond:
|
||||
pass
|
||||
|
||||
# def test_constructor_assign():
|
||||
obj2 = MyObj(SOURCE)
|
||||
SINK(obj2.foo) # $ MISSING: flow="SOURCE, l:-1 -> obj2.foo"
|
||||
obj2 = MyObj(SOURCE) # $ unresolved_call=MyObj(..)
|
||||
SINK(obj2.foo) # $ unresolved_call=SINK(..) MISSING: flow="SOURCE, l:-1 -> obj2.foo"
|
||||
|
||||
# def test_constructor_assign_kw():
|
||||
obj3 = MyObj(foo=SOURCE)
|
||||
SINK(obj3.foo) # $ MISSING: flow="SOURCE, l:-1 -> obj3.foo"
|
||||
obj3 = MyObj(foo=SOURCE) # $ unresolved_call=MyObj(..)
|
||||
SINK(obj3.foo) # $ unresolved_call=SINK(..) MISSING: flow="SOURCE, l:-1 -> obj3.foo"
|
||||
|
||||
# def test_fields():
|
||||
SINK(fields_with_local_flow(SOURCE)) # $ MISSING: flow="SOURCE -> fields_with_local_flow(..)"
|
||||
SINK(fields_with_local_flow(SOURCE)) # $ unresolved_call=fields_with_local_flow(..) unresolved_call=SINK(..) MISSING: flow="SOURCE -> fields_with_local_flow(..)"
|
||||
|
||||
# --------------------------------------
|
||||
# method calls
|
||||
# --------------------------------------
|
||||
|
||||
# def test_indirect_assign_method():
|
||||
myobj2 = MyObj("OK")
|
||||
myobj2.setFoo(SOURCE)
|
||||
SINK(myobj2.foo) # $ MISSING: flow="SOURCE, l:-1 -> myobj2.foo"
|
||||
myobj2 = MyObj("OK") # $ unresolved_call=MyObj(..)
|
||||
myobj2.setFoo(SOURCE) # $ unresolved_call=myobj2.setFoo(..)
|
||||
SINK(myobj2.foo) # $ unresolved_call=SINK(..) MISSING: flow="SOURCE, l:-1 -> myobj2.foo"
|
||||
|
||||
# def test_nested_obj_method():
|
||||
x2 = SOURCE
|
||||
a2 = NestedObj()
|
||||
a2.getObj().foo = x2
|
||||
SINK(a2.obj.foo) # $ MISSING: flow="SOURCE, l:-3 -> a2.obj.foo"
|
||||
a2 = NestedObj() # $ unresolved_call=NestedObj()
|
||||
a2.getObj().foo = x2 # $ unresolved_call=a2.getObj()
|
||||
SINK(a2.obj.foo) # $ unresolved_call=SINK(..) MISSING: flow="SOURCE, l:-3 -> a2.obj.foo"
|
||||
|
||||
Reference in New Issue
Block a user