Tom Hvitved
|
14561c414b
|
Merge pull request #14225 from hvitved/ruby/fix-bad-join
Ruby: Fix a bad join
|
2023-09-15 10:59:24 +02:00 |
|
Tom Hvitved
|
c83a29c27f
|
Ruby: Fix a bad join
Before
```
Evaluated relational algebra for predicate Sinatra#e09174a3::Sinatra::ErbLocalsAccessSummary#fff@22c05bb6 with tuple counts:
212957 ~2195% {1} r1 = JOIN _Constant#54e8b051::ConstantValue::getStringlikeValue#0#dispred#ff_Expr#6fb2af19::Expr::getConstantV__#shared WITH Expr#6fb2af19::Pair::getKey#0#dispred#ff_1#join_rhs ON FIRST 1 OUTPUT Lhs.1
43862468 ~6045% {2} r2 = JOIN r1 WITH Call#841c84e8::MethodCall::getMethodName#0#dispred#ff_10#join_rhs ON FIRST 1 OUTPUT Rhs.1, Lhs.0
43862468 ~6581% {2} r3 = JOIN r2 WITH AST#a6718388::AstNode::getLocation#0#dispred#ff ON FIRST 1 OUTPUT Rhs.1, Lhs.1
43844886 ~40661% {2} r4 = JOIN r3 WITH locations_default ON FIRST 1 OUTPUT Rhs.1, Lhs.1
15004 ~8295% {3} r5 = JOIN r4 WITH project#Sinatra#e09174a3::Sinatra::ErbLocalsHashSyntheticGlobal#ffff_201#join_rhs ON FIRST 1 OUTPUT Rhs.2, Lhs.1, Rhs.1
15004 ~8890% {3} r6 = SCAN r5 OUTPUT ("sinatra_erb_locals_access()" ++ In.0 ++ "#" ++ In.1), In.2, In.1
return r6
```
After
```
Evaluated relational algebra for predicate Sinatra#e09174a3::Sinatra::ErbLocalsAccessSummary#fff@f6249cga with tuple counts:
10237 ~0% {3} r1 = JOIN locations_default_10#join_rhs WITH project#Sinatra#e09174a3::Sinatra::ErbLocalsHashSyntheticGlobal#ffff_201#join_rhs ON FIRST 1 OUTPUT Lhs.1, Rhs.1, Rhs.2
4015 ~5% {3} r2 = JOIN r1 WITH AST#a6718388::AstNode::getLocation#0#dispred#ff_10#join_rhs ON FIRST 1 OUTPUT Rhs.1, Lhs.1, Lhs.2
825 ~96% {3} r3 = JOIN r2 WITH Call#841c84e8::MethodCall::getMethodName#0#dispred#ff ON FIRST 1 OUTPUT Rhs.1, Lhs.1, Lhs.2
940 ~0% {4} r4 = JOIN r3 WITH Constant#54e8b051::ConstantValue::getStringlikeValue#0#dispred#ff_10#join_rhs ON FIRST 1 OUTPUT Rhs.1, Lhs.1, Lhs.2, Lhs.0
325402 ~0% {4} r5 = JOIN r4 WITH Expr#6fb2af19::Expr::getConstantValue#0#dispred#ff_10#join_rhs ON FIRST 1 OUTPUT Rhs.1, Lhs.1, Lhs.2, Lhs.3
231819 ~133147% {3} r6 = JOIN r5 WITH Expr#6fb2af19::Pair::getKey#0#dispred#ff_1#join_rhs ON FIRST 1 OUTPUT Lhs.2, Lhs.3, Lhs.1
231819 ~138805% {3} r7 = SCAN r6 OUTPUT ("sinatra_erb_locals_access()" ++ In.0 ++ "#" ++ In.1), In.2, In.1
return r7
```
|
2023-09-14 21:34:17 +02:00 |
|
Tom Hvitved
|
c0e600c515
|
Merge pull request #12672 from hvitved/ruby/implicit-array-reads-at-sinks
Ruby: Allow for implicit array reads at all sinks during taint tracking
|
2023-09-14 15:39:37 +02:00 |
|
Tom Hvitved
|
61bfc4ec09
|
Merge pull request #14204 from hvitved/ruby/simplify-viable-callable
Ruby: Simplify `viableSourceCallableNonInit`
|
2023-09-14 15:36:47 +02:00 |
|
Tom Hvitved
|
e258324960
|
Ruby: Allow for implicit array reads at all sinks during taint tracking
|
2023-09-14 09:40:05 +02:00 |
|
Alex Ford
|
79c305c1a1
|
Merge pull request #14124 from alexrford/rb/dataflow-query-refactor
Ruby: Use the new dataflow API for checked in queries
|
2023-09-13 14:24:47 +01:00 |
|
Tom Hvitved
|
f15cbb9316
|
Ruby: Simplify viableSourceCallableNonInit
|
2023-09-13 14:25:28 +02:00 |
|
Tom Hvitved
|
f3a78efe03
|
Ruby: Fix semantic merge conflict
|
2023-09-13 14:04:20 +02:00 |
|
Alex Ford
|
b5ec99cb2f
|
Ruby: fix missing qldoc
|
2023-09-13 12:28:19 +01:00 |
|
Tom Hvitved
|
7400b4741e
|
Merge pull request #14108 from hvitved/dataflow/more-consistency-checks
Data flow: Add `ArgumentNode` consistency checks
|
2023-09-13 11:30:51 +02:00 |
|
Tom Hvitved
|
88d2e2590f
|
Ruby: Rename LambdaSelfParameterNode to LambdaSelfReferenceNode
|
2023-09-13 08:52:22 +02:00 |
|
Tom Hvitved
|
b470c36c82
|
Ruby: Implement multipleArgumentCallExclude
|
2023-09-12 20:05:11 +02:00 |
|
Alex Ford
|
5b013dd5d2
|
Merge branch 'main' into rb/dataflow-query-refactor
|
2023-09-07 14:57:38 +01:00 |
|
Alex Ford
|
947fa0de62
|
Ruby: fix qldoc warnings
|
2023-09-07 14:57:04 +01:00 |
|
Alex Ford
|
4a01de13ef
|
Ruby: avoid toString in query warning
|
2023-09-07 14:54:50 +01:00 |
|
Alex Ford
|
0aee7f6ac6
|
Ruby: qlformat
|
2023-09-07 14:47:02 +01:00 |
|
Alex Ford
|
a893911dba
|
Ruby: Use a newtype instead of DataFlow::FlowState for insecure-download
|
2023-09-07 14:22:18 +01:00 |
|
Alex Ford
|
75fdde543f
|
Ruby: Use a newtype instead of DataFlow::FlowState for hardcoded-data
|
2023-09-07 14:13:26 +01:00 |
|
Alex Ford
|
0d7d5a35c9
|
Ruby: Use a newtype instead of DataFlow::FlowState for code-injection
|
2023-09-07 13:39:10 +01:00 |
|
Alex Ford
|
dfc3b33910
|
Ruby: Use a newtype instead of DataFlow::FlowState for unicode-bypass-validation
|
2023-09-07 12:09:47 +01:00 |
|
Tom Hvitved
|
a06a9ffa29
|
Address review comments
|
2023-09-06 11:01:54 +02:00 |
|
Tom Hvitved
|
6de315d086
|
Add change note
|
2023-09-06 11:01:54 +02:00 |
|
Tom Hvitved
|
48e2dcfa35
|
Ruby: Reimplement flow through captured variables using field flow
|
2023-09-06 11:00:55 +02:00 |
|
Tom Hvitved
|
4a1163b38c
|
Merge pull request #14109 from hvitved/ruby/hide-desugared-assignments-in-dataflow
|
2023-09-04 19:59:33 +02:00 |
|
Alex Ford
|
98851736d6
|
Revert "Ruby: configsig rb/tainted-format-string"
This reverts commit f5860cb4818dc3c07eeb6731e75bf5df203dd48f.
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
bf6837cca0
|
Revert "Ruby: configsig rb/http-to-file-access"
This reverts commit e77ba1589663905c952cdb643ab66885760b27bd.
|
2023-09-03 17:20:06 +01:00 |
|
Alex Ford
|
b6d12f8b1c
|
Ruby: configsig rb/zip-slip
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
ebf2a2e1f5
|
Ruby: configsig rb/unicode-bypass-validation
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
7445fc43f9
|
Ruby: configsig rb/regexp-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
494b7b3fdf
|
Ruby: configsig rb/polynomial-redos
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
04d3d04317
|
Ruby: configsig rb/regex/badly-anchored-regexp
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
77f3a70376
|
Ruby: renames for rb/xpath-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
42cd58695d
|
Ruby: configsig rb/url-redirection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
f79796a644
|
Ruby: configsig rb/shell-command-constructed-from-input
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
f03f670312
|
Ruby: configsig rb/html-constructed-from-input
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
8ad6c72ba2
|
Ruby: configsig rb/unsafe-deserialization
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
461bc0d359
|
Ruby: configsig rb/unsafe-code-construction
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
3e23a6e021
|
Ruby: configsig rb/server-side-template-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
0a73ebdbee
|
Ruby: configsig rb/tainted-format-string
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
f5e433940f
|
Ruby: renames for rb/stored-xss
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
030aae5693
|
Ruby: configsig rb/stack-trace-exposure
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
bf1cb33be3
|
Ruby: configsig rb/sql-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
ba8ff0710d
|
Ruby: configsig rb/request-forgery
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
df9173502e
|
Ruby: configsig rb/sensitive-get-query
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
593d9a48d4
|
Ruby: configsig rb/reflected-xss
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
ad2bbfb265
|
Ruby: configsig rb/path-injection
|
2023-09-03 17:20:05 +01:00 |
|
Alex Ford
|
867e47bcdd
|
Ruby: renames for rb/log-injection
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
eb34bbbfd2
|
Ruby: renames for rb/ldap-injection
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
d46eceb5f4
|
Ruby: configsig rb/kernel-open
|
2023-09-03 17:20:04 +01:00 |
|
Alex Ford
|
a8ad0d8ff5
|
Ruby: renames for rb/insecure-download
|
2023-09-03 17:20:04 +01:00 |
|