Arthur Baars
015fb81d82
Merge b79f8f1890 into 702c647556
2021-10-25 15:03:09 +00:00
Arthur Baars
b79f8f1890
Fix CI jobs
2021-10-25 17:01:50 +02:00
shati-patel
8cd86ae8f5
Move queries.xml to src
2021-10-25 17:01:50 +02:00
shati-patel
b23b3c33f6
Add a queries.xml file (for CWE coverage) docs
2021-10-25 17:01:50 +02:00
Arthur Baars
de38570424
Merge identical-files.json
2021-10-25 17:01:44 +02:00
Arthur Baars
1bf4542c89
Remove github/codeql submodule
2021-10-25 16:42:45 +02:00
Arthur Baars
ddbba403f8
Update CodeSpaces configuration
2021-10-25 16:42:45 +02:00
Arthur Baars
aeb9ace694
Add ruby to CODEOWNERS
2021-10-25 16:42:45 +02:00
Arthur Baars
7741a72cc5
Merge remote-tracking branch 'codeql-ruby/rc/3.3' into codeql/rc/3.3
2021-10-25 16:41:36 +02:00
Arthur Baars
8ce7b287d1
Update dependabot config
2021-10-25 16:13:37 +02:00
Arthur Baars
3554e8d105
Drop LICENSE and CODE_OF_CONDUCT.md
2021-10-25 16:13:37 +02:00
Arthur Baars
2de757335f
Update Ruby workflows
2021-10-25 16:13:35 +02:00
Arthur Baars
068beeff56
Move create-extractor-pack Action
2021-10-25 16:12:08 +02:00
Arthur Baars
d2ea732539
Remove CodeSpaces configuration
2021-10-25 16:12:08 +02:00
Arthur Baars
ba32c54038
Move files to ruby subfolder
2021-10-25 16:11:59 +02:00
Shati Patel
702c647556
Merge pull request #6904 from shati-patel/ruby-query-help
...
Docs: Add Ruby to query help pages
2021-10-18 16:13:50 +01:00
shati-patel
b9ede183b0
Docs: Add Ruby to query help pages
2021-10-18 11:48:24 +01:00
Dave Bartolomeo
91b2ee2f10
Merge pull request #6822 from github/lgtm.com
...
Make sure the lgtm.com branch is an ancestor of rc/3.3
2021-10-06 06:58:13 -04:00
Geoffrey White
4c6f4ef14b
Revert "C++: change note" and "C++: Exclusion rules for system macros"
...
This reverts commit a055c86c4f .
This reverts commit 237a7d34b8 .
2021-10-06 10:21:19 +01:00
Nick Rolfe
1d58f8cd50
Merge pull request #320 from github/rasmuswl/fix-hasLocationInfo-url
2021-09-29 13:23:08 +01:00
Tom Hvitved
c69762bc14
Merge pull request #317 from github/hvitved/disable-operation-resolution
...
Temporarily disable operation call resolution
2021-09-29 14:17:05 +02:00
Rasmus Wriedt Larsen
3a270abcdc
Fix hasLocationInfo URL reference
...
Port of https://github.com/github/codeql/pull/6775
2021-09-29 14:04:25 +02:00
Tom Hvitved
10d19bf05b
Temporarily disable operation call resolution
2021-09-29 09:40:41 +02:00
Tom Hvitved
5219b1a8b9
Merge pull request #310 from github/hvitved/more-instanceof
...
More uses of `instanceof` in the external/internal AST layer
2021-09-27 16:11:04 +02:00
Tom Hvitved
8018c1525d
Merge pull request #314 from github/hvitved/setter-method-call-base
...
Strengthen the type of `SetterMethodCall`
2021-09-27 15:29:07 +02:00
Nick Rolfe
79c2f09585
Merge pull request #302 from github/rm_tokeninfo_idx
...
Remove unused columns from tokeninfo tables
2021-09-27 14:19:38 +01:00
Nick Rolfe
b2c4daecd5
Merge pull request #303 from github/nickrolfe/node_kind_id
...
Use integer comparisons instead of strings when scanning ERB files
2021-09-27 14:18:10 +01:00
Tom Hvitved
317303cdad
Strengthen the type of SetterMethodCall
2021-09-27 14:05:28 +02:00
Arthur Baars
2a4747b27e
Merge pull request #313 from github/hmac-remove-unicode-char
...
Remove unicode character from doc string
2021-09-27 12:57:21 +02:00
Harry Maclean
3e100bc2a9
Remove unicode character from doc string
...
We require that all source code is in ASCII.
2021-09-27 11:40:04 +01:00
Jonas Jensen
06b36f742e
Merge pull request #6745 from andersfugmann/handle_overflow_for_upperbound
...
C++: Handle overflow for upperbound
2021-09-27 10:32:49 +02:00
Alexander Eyers-Taylor
8debae1a3b
Merge pull request #6753 from github/aibaars/fix-typo
...
Fix typo in language spec
2021-09-24 17:21:14 +01:00
Rasmus Wriedt Larsen
547cbb6322
Merge pull request #6331 from porcupineyhairs/pythonXpath
...
Python : Improve Xpath Injection Query
2021-09-24 18:11:08 +02:00
Rasmus Wriedt Larsen
d39df18544
Python: Minor test cleanup
2021-09-24 16:11:27 +02:00
Tom Hvitved
793368d670
More uses of instanceof in the external/internal AST layer
2021-09-24 15:55:15 +02:00
Arthur Baars
7d3a219f63
Fix typo in language spec
...
Thanks to https://github.com/github/codeql/issues/6750
2021-09-24 15:47:09 +02:00
Geoffrey White
3e1bc66984
Merge pull request #6733 from MathiasVP/fix-qldoc-in-initialize-dynamic-allocation-instruction
...
C++/C#: Fix QLDoc on `InitializeDynamicAllocationInstruction`.{`getAllocationAddressOperand` and `getAllocationAddress`}
2021-09-24 14:30:03 +01:00
Rasmus Wriedt Larsen
26d2fbd217
Python: Fix new XPath injection query
...
Fixes the typo `ETXpath` => `ETXPath`
2021-09-24 15:11:34 +02:00
Rasmus Wriedt Larsen
913a679ef5
Python: Replace old XPath injection query
2021-09-24 15:10:41 +02:00
Anders Peter Fugmann
aebde189f8
C++: Apply peer review suggestion
...
Co-authored-by: Jonas Jensen <jbj@github.com >
2021-09-24 15:09:23 +02:00
Anders Schack-Mulligen
66c206cc61
Merge pull request #6747 from bmuskalla/organizeUtils
...
Java: Organize `utils` into separate directories
2021-09-24 15:05:51 +02:00
Rasmus Wriedt Larsen
c9640ffdbc
Python: Minor adjustments to XPath Injection
2021-09-24 15:02:39 +02:00
Mathias Vorreiter Pedersen
24214002a1
C#/C++: Sync identical files.
2021-09-24 13:13:09 +01:00
Mathias Vorreiter Pedersen
eba1b0bc15
Respond to review comments.
2021-09-24 13:12:58 +01:00
Rasmus Wriedt Larsen
289660067c
Merge branch 'main' into pythonXpath
2021-09-24 13:53:38 +02:00
Harry Maclean
74982cb3aa
Merge pull request #307 from github/hmac-outgoing-http-2
...
Model some more HTTP clients
2021-09-24 12:30:48 +01:00
Mathias Vorreiter Pedersen
69541d3628
Merge pull request #6744 from rdmarsh2/rdmarsh2/dtt-subpath
...
C++: add subpaths to DefaultTaintTracking
2021-09-24 11:58:31 +01:00
Tom Hvitved
141f5f7605
Merge pull request #308 from github/hvitved/operation-method-call
...
Make `{Unary,Binary}Operation` a sub class of `MethodCall`
2021-09-24 12:51:07 +02:00
Anders Fugmann
c9c41252e3
C++: Update test results in SimpleRangeAnalysis
2021-09-24 12:23:48 +02:00
Tom Hvitved
30d2df53c6
Include MethodCall.getAChild in {Unary,Binary}Operation.getAChild
2021-09-24 12:08:54 +02:00
Anders Fugmann
3437cf2909
C++: only use upperbound if there are no overflows in the guard
2021-09-24 11:46:58 +02:00
Anders Fugmann
d7afd86a27
C++: Add test case exposing problem with overflows for upperBound predicate
2021-09-24 11:44:05 +02:00
Benjamin Muskalla
38ca5aba98
Move test generator into subdirectory
2021-09-24 11:13:04 +02:00
Benjamin Muskalla
4e6a8d991e
Move stub generator into subdirectory
2021-09-24 11:12:41 +02:00
Benjamin Muskalla
cb0a567c03
Merge pull request #6743 from github/workflow/coverage/update
...
Update CSV framework coverage reports
2021-09-24 09:23:35 +02:00
Robert Marsh
3189c578a4
C++: Add QLDoc to subpaths in DefaultTaintTracking
2021-09-23 22:42:38 -07:00
Robert Marsh
c2b356ab08
C++: add subpaths to DefaultTaintTracking
2021-09-23 21:00:45 -07:00
github-actions[bot]
ceb9a0bd6b
Add changed framework coverage reports
2021-09-24 00:08:02 +00:00
Tom Hvitved
edfdfb1fa4
Make {Unary,Binary}Operation a sub class of MethodCall
2021-09-23 19:13:55 +02:00
Harry Maclean
88885a222e
Model the RestClient HTTP client
2021-09-23 16:32:15 +01:00
Harry Maclean
4cf520c2df
Model the Faraday HTTP client
2021-09-23 16:32:15 +01:00
Harry Maclean
ee51298633
Model the Excon HTTP client
2021-09-23 16:32:15 +01:00
Tom Hvitved
ca2ff9a863
Merge pull request #305 from github/hvitved/desugar/array-literals
...
Desugar array literals to `::Array.[]`
2021-09-23 17:30:34 +02:00
Anders Schack-Mulligen
a031b2a090
Merge pull request #6493 from atorralba/atorralba/cleartext-storage-query-refactor
...
Java: Refactor Cleartext Storage queries
2021-09-23 16:31:17 +02:00
Tony Torralba
b52a2cd292
Apply code review comments
...
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com >
2021-09-23 15:48:15 +02:00
Arthur Baars
40f0112e8a
Merge pull request #297 from github/aibaars/alert-suppression
...
Alert suppression and file classifier query
2021-09-23 15:37:19 +02:00
Anders Schack-Mulligen
6be4b3bac6
Merge pull request #6725 from emilejq/date-format
...
Java: Remove requirements for final and access mods from DateFormatThreadUnsafe
2021-09-23 15:02:17 +02:00
Harry Maclean
4f9518a9c6
Merge pull request #293 from github/hmac-code-injection
...
Add query for Code Injection
2021-09-23 13:50:48 +01:00
Tom Hvitved
f347505542
Merge pull request #277 from github/hvitved/flow-summaries
...
Add support for flow summaries
2021-09-23 14:31:52 +02:00
Harry Maclean
41608ef47b
Address review comments
2021-09-23 12:26:54 +01:00
Tom Hvitved
68d41f9f12
Address review comments
2021-09-23 12:39:47 +02:00
Rasmus Wriedt Larsen
f14e3f6007
Merge pull request #5445 from jorgectf/jorgectf/python/ldapinsecureauth
...
Python: Add LDAP Insecure Authentication query
2021-09-23 11:08:13 +02:00
Emile El-Qawas
83fb41e414
Add visibility constraints; Fix non-compliant code
2021-09-23 09:55:49 +01:00
Tony Torralba
d0b9920cac
Fix encryption sanitizer
...
It now discards sensitive exprs (sources) instead of sinks for better precision
2021-09-23 10:42:30 +02:00
Tony Torralba
51d2b5225e
Remove cached property from SensitiveSource::flowsTo
2021-09-23 10:42:30 +02:00
Tony Torralba
563e8a2bd6
Remove unused library
2021-09-23 10:42:30 +02:00
Tony Torralba
a30554e97c
Refactored cleartext storage libraries
2021-09-23 10:42:30 +02:00
Harry Maclean
83705c5787
Merge pull request #306 from github/hmac-outgoing-http
...
Model outgoing HTTP requests as remote flow sources
2021-09-23 09:34:44 +01:00
Rasmus Wriedt Larsen
ef6e502ff0
Python: Make LDAP global options test better
...
Before it didn't really showcase that we know it can make connections
secure.
2021-09-23 10:18:18 +02:00
Chris Smowton
93daaf5b5b
Merge pull request #6174 from joefarebrother/guava-collections
...
Java: Model Guava collections package
2021-09-23 09:13:24 +01:00
Rasmus Wriedt Larsen
70489b2fc2
Merge branch 'main' into jorgectf/python/ldapinsecureauth
2021-09-23 10:05:56 +02:00
Harry Maclean
5826f2c279
Move Net::HTTP modelling into http_clients module
...
This seems a more convenient place to keep all the HTTP client
modelling.
2021-09-23 09:04:20 +01:00
Harry Maclean
b658bacab3
Simplify Net::HTTP modelling
2021-09-23 09:04:01 +01:00
Harry Maclean
3000587849
Add Net::HTTP request modelling
2021-09-23 09:04:01 +01:00
Harry Maclean
2bdea01c8a
Add HTTP::Client concept
2021-09-23 09:04:01 +01:00
Tom Hvitved
27c45d8dda
Merge pull request #6731 from hvitved/remove-reduced-env-var
...
Remove `CODEQL_REDUCE_FILES_FOLDERS_RELATIONS`
2021-09-23 09:39:17 +02:00
Chris Smowton
3123abfac3
Merge pull request #6711 from bananabr/AndroidLoggingFix
...
Fix Android logging signature
2021-09-22 17:23:04 +01:00
Alex Ford
21e31a47d9
Merge pull request #283 from github/file-system-sources
...
Start modelling some file system access concepts
2021-09-22 16:45:13 +01:00
Alex Ford
b769aa67c2
test for IO.open as a way of creating an IO instance
2021-09-22 16:29:10 +01:00
Joe Farebrother
522c6e01d2
Sort models by class and name
2021-09-22 15:23:01 +01:00
Alex Ford
0092c0279b
Apply suggestions from code review
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-09-22 14:28:15 +01:00
yoff
14a31a2299
Merge pull request #6732 from RasmusWL/minor-sqlalchemy-comment-fixes
2021-09-22 15:15:52 +02:00
Mathias Vorreiter Pedersen
35baff8bac
C#/C++: Sync identical files.
2021-09-22 13:32:29 +01:00
Mathias Vorreiter Pedersen
5969c227ab
C++: Fix QLDoc on 'getAllocationAddressOperand' and 'getAllocationAddress'.
2021-09-22 13:32:20 +01:00
Tom Hvitved
e670fdbb82
Move two predicates in FlowSummaryImplSpecific.qll
2021-09-22 14:12:46 +02:00
Rasmus Wriedt Larsen
8badba26b8
Python: Minor SQLALchemy comment fixes
2021-09-22 13:58:29 +02:00
Chris Smowton
24e3ad4e18
Remove unnecessary type constraint
2021-09-22 10:54:24 +01:00
Mathias Vorreiter Pedersen
a66f83644b
Merge pull request #6728 from rdmarsh2/rdmarsh/sql-models-followup
...
C++: Add additional functions to the SQL models
2021-09-22 10:19:51 +01:00
Tom Hvitved
364dab6990
Remove CODEQL_REDUCE_FILES_FOLDERS_RELATIONS
2021-09-22 09:43:56 +02:00
Edoardo Pirovano
b960857fc2
Merge pull request #6722 from edoardopirovano/update-analyze-docs
...
Update documentation to reflect changes to `database analyze`
2021-09-22 08:29:45 +01:00
yoff
65d3373ad3
Merge pull request #6727 from RasmusWL/fix-sqlalchemy-query
...
Python: Merge SQLAlchemy TextClause injection into `py/sql-injection`
2021-09-22 09:29:28 +02:00
Tom Hvitved
a37737d065
Replace string kind with boolean preservesValue
2021-09-22 09:28:55 +02:00
Robert Marsh
3108817717
C++: Add additional functions to the SQL models
2021-09-21 17:34:01 -07:00
Tom Hvitved
888183f26d
Desugar array literals to ::Array.[]
2021-09-21 21:27:29 +02:00
Rasmus Wriedt Larsen
d44f279339
Python: Fix .qhelp
2021-09-21 20:35:03 +02:00
Rasmus Wriedt Larsen
a83bb39d0f
Python: Merge SQLAlchemy TextClause injection into py/sql-injection
...
As discussed in a meeting today, this will end up presenting an query
suite that's easier to use for customers.
Since https://github.com/github/codeql/pull/6589 has JUST been merged,
if we get this change in fast enough, no end-user will ever have run
`py/sqlalchemy-textclause-injection` as part of LGTM.com or Code
Scanning.
2021-09-21 20:21:42 +02:00
Alex Ford
70c2be8ca3
Files library tests
2021-09-21 19:08:03 +01:00
Alex Ford
05a04f4835
Files.qll library implementation
2021-09-21 19:07:55 +01:00
Alex Ford
6315621b16
use instanceof extensions for some filesystem concepts
2021-09-21 19:02:11 +01:00
Alex Ford
d1f2258d45
revamp weak file permissions query
2021-09-21 19:02:11 +01:00
Alex Ford
25300cb2b4
start modelling some file access concepts
2021-09-21 19:02:11 +01:00
Robert Marsh
d62f76afa6
Merge pull request #6133 from MathiasVP/promote-sql-pqxx
...
C++: Promote `cpp/sql-injection-via-pqxx` out of experimental
2021-09-21 10:13:57 -07:00
Robert Marsh
97c2917c16
Merge pull request #6409 from JordyZomer/main
...
cpp: Add query to detect unsigned integer to signed integer conversio…
2021-09-21 09:57:44 -07:00
Joe Farebrother
3cd675bfff
Manually fill in most of the remaining support method calls
2021-09-21 17:56:18 +01:00
Mathias Vorreiter Pedersen
478093aa89
Update cpp/ql/lib/semmle/code/cpp/models/interfaces/Sql.qll
...
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com >
2021-09-21 17:51:24 +01:00
Emile El-Qawas
dcae1c5c04
DateFormatThreadUnsafe - Remove requirements for final and access modifiers
2021-09-21 16:50:48 +01:00
Joe Farebrother
6e9bee1be7
Add missing models
2021-09-21 16:32:49 +01:00
Joe Farebrother
25d6e00b1a
Implement gen methods for MapDifference
2021-09-21 16:30:12 +01:00
Joe Farebrother
a47897bdf9
Implement Table gen methods
2021-09-21 15:29:06 +01:00
Anders Schack-Mulligen
2c41de6648
Merge pull request #6720 from aschackmull/java/isunreachableincall-joinorder
...
Java: Fix join-order in isUnreachableInCall.
2021-09-21 16:07:42 +02:00
Anders Schack-Mulligen
dd1bed02e8
Merge pull request #6721 from aschackmull/dataflow/subpaths01-joinorder
...
Dataflow: Fix join-order in subpaths01
2021-09-21 16:05:41 +02:00
Mathias Vorreiter Pedersen
bd5edc7ae5
Respond to review comments.
2021-09-21 14:29:26 +01:00
Mathias Vorreiter Pedersen
dfe932d053
Add missing conjunct in PostgreSqlEscapeFunction's 'escapesSqlArgument' predicate.
2021-09-21 12:14:45 +01:00
Nick Rolfe
dd31473dff
Merge pull request #301 from github/fix_source_archive
...
Fix filenames in source archives
2021-09-21 11:37:02 +01:00
Jonas Jensen
a055c86c4f
C++: change note
2021-09-21 11:58:04 +02:00
Nick Rolfe
d60410e6b8
Use integer comparisons instead of strings when scanning ERB files
2021-09-21 10:50:04 +01:00
Jonas Jensen
237a7d34b8
C++: Exclusion rules for system macros
...
Unwanted results were reported for our JPL Rule 24 queries. Including
system headers with complex macros could lead to unpredictable alerts
from these rules.
2021-09-21 11:31:13 +02:00
Edoardo Pirovano
5a28a796af
Update documentation to reflect changes to database analyze
2021-09-21 10:16:12 +01:00
Tom Hvitved
cdc359527a
Resolve semantic conflicts after rebase
2021-09-21 11:14:11 +02:00
yoff
4adb0c75bd
Merge pull request #6589 from RasmusWL/promote-sqlalchemy
...
Python: Promote modeling of SQLAlchemy
2021-09-21 11:08:41 +02:00
Tom Hvitved
564c76c41f
Address review comments
2021-09-21 11:04:53 +02:00
Tom Hvitved
08dc6d79ef
Add support for flow summaries
2021-09-21 11:04:53 +02:00
Rasmus Wriedt Larsen
4a16be2cba
Merge pull request #6557 from yoff/python/port-modification-of-default-value
...
Python: port modification of default value
2021-09-21 10:12:12 +02:00
Rasmus Wriedt Larsen
f8e6ba633a
Python: Fix .expected for new subpaths query predicate
2021-09-21 09:40:13 +02:00
Rasmus Wriedt Larsen
c7c8e2f3e3
Merge branch 'main' into promote-sqlalchemy
2021-09-21 09:36:07 +02:00
Nick Rolfe
3201f30098
Update dbscheme stats
2021-09-20 23:13:38 +01:00
Nick Rolfe
e97adff21d
Add upgrade script to remove unused tokeninfo columns
2021-09-20 22:42:13 +01:00
Nick Rolfe
6a17dfd228
Remove file column from tokeninfo tables.
2021-09-20 22:42:13 +01:00
Nick Rolfe
6f059638d2
Remove idx column from tokeninfo tables.
2021-09-20 22:42:13 +01:00
Nick Rolfe
143256e673
Fix filenames in source archives
2021-09-20 22:17:45 +01:00
Nick Rolfe
c183e05c49
Merge pull request #300 from github/fix_tests
...
Fix tests
2021-09-20 16:19:40 +01:00
Nick Rolfe
d27f8a6d24
Add empty subpaths section to expected test output
2021-09-20 15:56:58 +01:00
Anders Schack-Mulligen
eaf05305ff
Merge pull request #6709 from aschackmull/java/local-taint-collections
...
Java: Add container flow to the local taint flow relation.
2021-09-20 16:04:45 +02:00
Tom Hvitved
8aaabe8b1e
Merge pull request #299 from github/hvitved/actions-reuse
...
Add two 'composite' actions for reusing logic
2021-09-20 15:55:28 +02:00
Nick Rolfe
6f7d4fef70
Merge pull request #287 from github/unsafe-deserialization
...
rb/unsafe-deserialization query
2021-09-20 14:23:30 +01:00
Nick Rolfe
8af12a164a
Merge pull request #298 from github/trap_extension
...
Fix trap extension for source files without extensions
2021-09-20 14:23:01 +01:00
Anders Schack-Mulligen
044623a360
Dataflow: Sync.
2021-09-20 14:58:28 +02:00
Anders Schack-Mulligen
07c05528ef
Dataflow: Fix join-order in subpaths01.
2021-09-20 14:58:12 +02:00
Tom Hvitved
e201dae672
Add two 'composite' actions for reusing logic
2021-09-20 14:52:02 +02:00
Anders Schack-Mulligen
c72e385a47
Java: Fix join-order in isUnreachableInCall.
2021-09-20 14:09:09 +02:00
Nick Rolfe
c30c7b380d
Replace if let with match.
2021-09-20 12:22:55 +01:00
Nick Rolfe
0936c4cd7b
Fix trap extension for source files without extensions
...
We were writing files with names like `Gemfile..trap.gz`. Now fixed to
`Gemfile.trap.gz`.
2021-09-20 12:11:00 +01:00
Tom Hvitved
4bfbf62e13
Merge pull request #296 from github/hvitved/empty-location
...
Extract a special empty location
2021-09-20 13:05:27 +02:00
Tom Hvitved
1393dc9eb4
Update extractor/src/main.rs
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-09-20 12:50:24 +02:00
Mathias Vorreiter Pedersen
797966fd3d
C++: Change the names of the new classes and predicates to match the upcoming 'CommandExecutionFunction' class.
2021-09-20 11:49:09 +01:00
Tom Hvitved
82d463e86e
Merge pull request #6718 from hvitved/csharp/xss-subpath
...
C#: Add `subpaths` predicate to XSS queries
2021-09-20 12:47:27 +02:00
Harry Maclean
95e50cedad
Add query for Code Injection
...
This query finds cases where user input flows to an argument to `eval`
or `send`, which can execute arbitrary Ruby code.
2021-09-20 11:35:45 +01:00
Rasmus Wriedt Larsen
97c0f1c7b7
Python: Apply suggestions from code review
...
Co-authored-by: yoff <lerchedahl@gmail.com >
2021-09-20 12:04:46 +02:00
Tom Hvitved
64507ab316
Merge pull request #6712 from hvitved/csharp/subsumption-perf-take2
...
C#: Speedup type subsumption calculation
2021-09-20 11:59:24 +02:00
Tom Hvitved
b9c4abe7dc
C#: Fix qldoc typos
2021-09-20 10:42:01 +02:00
Tom Hvitved
6d315a5d16
C#: Add subpaths predicate to XSS queries
2021-09-20 10:40:54 +02:00
Anders Schack-Mulligen
187b7e117c
Merge pull request #6715 from github/workflow/coverage/update
...
Update CSV framework coverage reports
2021-09-20 10:19:16 +02:00
Harry Maclean
916b844557
Merge pull request #280 from github/hmac-cli-injection
...
Add CLI Injection query
2021-09-20 08:54:01 +01:00
Tom Hvitved
b2d0c60a02
Replace hasLocationInfo with getLocation in API::Node
2021-09-20 09:52:26 +02:00
Tom Hvitved
58d06715fc
Extract a special empty location
2021-09-20 09:52:26 +02:00
github-actions[bot]
f0e7be7d56
Add changed framework coverage reports
2021-09-20 00:08:08 +00:00
Tom Hvitved
c6c1ad1b90
C#: Update toString for nested types
2021-09-18 19:51:37 +02:00
Tom Hvitved
07fe29cc67
C#: Speedup type subsumption calculation
2021-09-18 19:51:37 +02:00
Alex Ford
36289aa9d9
Merge pull request #255 from github/reflected-xss
...
rb/reflected-xss query
2021-09-17 18:32:48 +01:00
Joe Farebrother
4929c66e60
Implement gen methods for collections and maps
2021-09-17 17:37:46 +01:00
Harry Maclean
739661eb10
Test that KernelMethodCall is specific enough
...
Calls to `UnknownModule.system`, where `UnknownModule` is a module that
we know nothing about, should not be identified as instances of
`KernelMethodCall`.
2021-09-17 17:02:17 +01:00
Harry Maclean
64a8cedaa7
Generalise the concept of a Kernel method call
2021-09-17 17:02:17 +01:00
Harry Maclean
599dc28ffa
Add another test for shell interpretation
2021-09-17 17:02:17 +01:00
Harry Maclean
f8359767bc
Exclude non-shell interpreted args
...
Update the CommandInjection query to only consider sinks where the
argument is interpreted by a shell. If the argument is passed directly
to a subprocess then it's not vulnerable to shell injection.
2021-09-17 17:02:17 +01:00
Harry Maclean
c8e9a592f0
Update CLI injection tests
...
Cover more cases, like sinks after (but not guarded by) barrier guards.
2021-09-17 17:02:17 +01:00
Harry Maclean
d046fb0591
Separate open3 pipeline methods
...
These have a slightly different structure than the other open3 methods.
2021-09-17 17:02:17 +01:00
Harry Maclean
174ba25c66
Update SystemCommandExecution to new pattern
...
The new pattern is to use the new instanceof keyword in the class
definition, instead of constraining the "superclass" via a member field.
2021-09-17 17:02:17 +01:00
Harry Maclean
cbc14ccda9
Make KernelSystemCall more specific
...
Test that calls to`system` on modules other than `Kernel` are excluded,
such as in this example:
module Foo
def self.system(*args); end
end
# This is not a call to Kernel.system
Foo.system("bar")
2021-09-17 17:02:17 +01:00
Harry Maclean
fb23a2e3bf
Add SubshellHeredocExecution
...
This is a form of command execution:
result = <<`EOF`
echo foo bar #{baz}
EOF
2021-09-17 17:02:17 +01:00
Harry Maclean
799ef4e4c9
Add barrier guards for CLI injection
2021-09-17 17:02:17 +01:00
Harry Maclean
4ecc78effc
Kernel#system -> Kernel.system
2021-09-17 17:02:17 +01:00
Harry Maclean
8f65d78cb5
Add Shellwords.escape as CLI injection sanitizer
2021-09-17 17:02:17 +01:00
Harry Maclean
fe8fc0697b
Add qhelp for CLI Injection query
2021-09-17 17:02:17 +01:00
Harry Maclean
4a0d7c528a
Add top-level CLI injection query and tests
2021-09-17 17:02:17 +01:00
Harry Maclean
8440fe2ba9
Add CommandInjection dataflow config
2021-09-17 17:02:17 +01:00
Harry Maclean
a8f0bce1d1
Add SystemCommandExecution concept
...
A SystemCommandExecution is a method call or builtin that executes a
system command, either directly or via a subshell.
2021-09-17 17:02:17 +01:00
Joe Farebrother
3ef09da1df
Add models for more of methods; update stubs
2021-09-17 16:57:49 +01:00
Nick Rolfe
3c05101961
Merge pull request #290 from github/extract_gemfile
...
Automatically extract Gemfiles
2021-09-17 16:42:30 +01:00
Nick Rolfe
3d23575a38
Merge pull request #292 from github/regexp_slash_az
...
Don't parse `\A` and `\Z` as `RegExpConstant`
2021-09-17 16:42:13 +01:00
Daniel Santos
9e41f43ee2
Fix: android.util.Log is final. No inheritance handling is needed.
2021-09-17 10:15:48 -05:00
Anders Schack-Mulligen
2cbad4aed6
Merge pull request #6600 from atorralba/atorralba/fix-conditionalbypass
...
Java: Fix performance of the query User-controlled bypass of sensitive method
2021-09-17 16:07:39 +02:00
Tamás Vajk
3247794e2f
Merge pull request #6196 from tamasvajk/feature/sql-sinks
...
C#: Migrate SQL sinks to CSV format
2021-09-17 14:36:57 +02:00
Joe Farebrother
e946f49b64
[Test gen] Gen methods for Set and Iterator
2021-09-17 11:22:50 +01:00
Joe Farebrother
0bff1b4afb
Implement get methods
2021-09-17 11:08:09 +01:00
Tamas Vajk
8232698254
C#: Migrate SQL sinks to CSV format
2021-09-17 10:21:31 +02:00
Tamás Vajk
6a78aa7840
Merge pull request #6461 from tamasvajk/feature/service-stack
...
C#: Add ServiceStack support
2021-09-17 10:16:20 +02:00
Daniel Santos
032a7e71fe
Update Logging.qll
...
Simplified using a set-literal as suggested by @intrigus-lgtm
2021-09-16 13:03:26 -05:00
Ethan Palm
b73a2f7d56
Merge pull request #6667 from ethanpalm/indirect-build-tracing-docs
...
Add indirect build tracing docs
2021-09-16 12:36:56 -04:00
Ethan P
4d7aa5c945
Update example note
2021-09-16 09:29:35 -07:00
Daniel Santos
af8b2b6d9c
Fix Android logging signature in java/ql/src/experimental/semmle/code/java/Logging.qll
2021-09-16 11:24:06 -05:00
Anders Schack-Mulligen
a67db45454
Merge pull request #6612 from Marcono1234/marcono1234/literal-getLiteral-usage
...
Java: Replace incorrect usage of `Literal.getLiteral()`
2021-09-16 17:00:32 +02:00
Joe Farebrother
1111afc031
Update tests for new support methods; fix bad model
2021-09-16 15:23:03 +01:00
Joe Farebrother
54dbd7c0bd
[Test gen] Add more support method implementations
2021-09-16 15:23:03 +01:00
Joe Farebrother
ef5bf87672
[Test gen] Distinguish default support methods
2021-09-16 15:23:03 +01:00
Joe Farebrother
eb45e67784
Generate tests for modified models
2021-09-16 15:23:02 +01:00
Joe Farebrother
1eacbd88b8
Fix up some incorrect models; simplify/remove some redundand ones
2021-09-16 15:23:02 +01:00
Joe Farebrother
a89bd32eb0
Factor out content manipulating methods from tests to a separate file
2021-09-16 15:23:02 +01:00
Joe Farebrother
56a2dc632b
Move tests around and remove files used for generating tests
2021-09-16 15:23:02 +01:00
Joe Farebrother
7dded52de2
Add change note
2021-09-16 15:23:02 +01:00
Joe Farebrother
8425a94729
Mark failing tests as missing
...
I'm not sure why these tests don't work.
2021-09-16 15:23:02 +01:00
Joe Farebrother
7bf55fbc49
Update stubs to not include package protected members
2021-09-16 15:23:02 +01:00
Joe Farebrother
39349f3763
Fix failing test
2021-09-16 15:23:02 +01:00
Joe Farebrother
60c6158152
Fill in implementations of getters for synthetic fields
2021-09-16 15:23:01 +01:00
Joe Farebrother
225e70a8d0
Fill in implementations fo getMapKey/Value
2021-09-16 15:23:01 +01:00
Joe Farebrother
338a6f2114
Fill in implementations for getElement
2021-09-16 15:23:01 +01:00
Joe Farebrother
cd7c7c3152
Implement array getters/constructors in generated tests
2021-09-16 15:23:01 +01:00
Joe Farebrother
84748cda76
Increase field flow branch limit.
...
I'm a little concerned that this appears to be necassary for tests; as it may mean that results involving these flow steps may not be found in real-world projects.
2021-09-16 15:23:01 +01:00
Joe Farebrother
f94a61cc8a
Remove unneeded rows
2021-09-16 15:23:01 +01:00
Joe Farebrother
b51ffadd27
Improve generated tests
2021-09-16 15:23:01 +01:00
Joe Farebrother
0f2c50f1f5
Explicitly add the of and copyOf methods for ImmutableSorted variants of certain types.
2021-09-16 15:23:01 +01:00
Joe Farebrother
c8e2b027ee
Add fieldFlowBranchLimit to the tests
2021-09-16 15:23:00 +01:00
Joe Farebrother
839c9e35c8
Simplify synthetic table fields
2021-09-16 15:23:00 +01:00
Joe Farebrother
46eec3c8eb
Switch to simpler synthetic field model
2021-09-16 15:23:00 +01:00
Joe Farebrother
6ae11b5b2c
Generate stubs.
...
Some generated stubs were manually adjusted due to minor issues in the stub generator.
In particular, ambiguous references were resolved and references to private classes were removed.
2021-09-16 15:23:00 +01:00
Joe Farebrother
ff733e0334
Fix up issues in generated tests
2021-09-16 15:23:00 +01:00
Joe Farebrother
693d729ec6
Generate tests and fix broken specs
2021-09-16 15:23:00 +01:00
Joe Farebrother
2150c1d58e
Remove <> from flow summaries
2021-09-16 15:23:00 +01:00
Joe Farebrother
1273b063f4
Fix test expectations
2021-09-16 15:23:00 +01:00
Joe Farebrother
a755633405
Add the remaining utility classes
2021-09-16 15:22:59 +01:00
Joe Farebrother
19579f0d9a
Add more utility class models and reorder existing ones
2021-09-16 15:22:59 +01:00
Joe Farebrother
ca583bffd5
Add Lists and Collections2 utilites
2021-09-16 15:22:59 +01:00
Joe Farebrother
5fee6d2d19
Convert Sets utilities
2021-09-16 15:22:59 +01:00
Joe Farebrother
10f0f3038c
Add tables, improve tests, make fixes
2021-09-16 15:22:59 +01:00
Joe Farebrother
73aba09eee
Add create methods
2021-09-16 15:22:59 +01:00
Joe Farebrother
035d655e72
Update guava collection flow steps to CSV
2021-09-16 15:22:59 +01:00
Marcono1234
020aa4d94c
Java: Address feedback and fix test failures
2021-09-16 14:10:48 +01:00
Marcono1234
58d2d5d14e
Java: Replace incorrect usage of Literal.getLiteral()
2021-09-16 14:10:48 +01:00
Tom Hvitved
1c1c46591e
Merge pull request #6708 from hvitved/python/files-folders-drop-columns
...
Python: Drop redundant columns from `files` and `folders` relations
2021-09-16 14:42:15 +02:00
Tom Hvitved
1fd91ab9bd
Merge pull request #295 from github/hvitved/remove-numlines
...
No longer create redundant `numlines` relation
2021-09-16 13:21:20 +02:00
Tom Hvitved
9f10018d48
Address review comment
2021-09-16 13:11:03 +02:00
Taus
783233dfe4
Merge pull request #6696 from yoff/python/copy-multiples-performance-fix-from-ruby
...
Python: Copy performance fix for `multiples` from ruby
2021-09-16 13:01:07 +02:00
Tom Hvitved
464b50231b
DB upgrade script
2021-09-16 12:57:32 +02:00
Tony Torralba
f18c163408
Improve handling of the 'author' word as an exception
2021-09-16 11:57:28 +02:00
Tony Torralba
8022530f34
Merge pull request #5983 from atorralba/atorralba/promote-insecure-basic-auth
...
Java: Promote Insecure Basic Authentication query from experimental
2021-09-16 11:45:30 +02:00
Tom Hvitved
fd04baa9fe
No longer create redundant numlines relation
2021-09-16 11:43:13 +02:00
Anders Schack-Mulligen
28e5dcef52
Java: Add container flow to the local taint flow relation.
2021-09-16 11:14:30 +02:00
Tom Hvitved
37ec83a68b
Python: Upgrade script
2021-09-16 10:51:27 +02:00
Tom Hvitved
94b5c4eada
Python: Drop redundant columns from files and folders relations
2021-09-16 10:51:27 +02:00
Benjamin Muskalla
d3caa80274
Merge pull request #6706 from github/workflow/coverage/update
...
Update CSV framework coverage reports
2021-09-16 09:58:19 +02:00
Tamas Vajk
f015cea590
Merge branch 'main' into feature/service-stack
2021-09-16 09:42:42 +02:00
Tamas Vajk
05dd3fa0e7
Adjust review findings
2021-09-16 09:42:38 +02:00
Erik Krogh Kristensen
0198cf6318
Merge pull request #6704 from erik-krogh/fix-upgrade
...
JS: fix dbsheme upgrade from TypeScript 4.4 PR
2021-09-16 08:34:58 +02:00
Anders Schack-Mulligen
236ffc8972
Merge pull request #6700 from aschackmull/dataflow/subpaths-joinorder
...
Dataflow: Fix bad joinorder in subpaths
2021-09-16 08:22:59 +02:00
github-actions[bot]
563878d28d
Add changed framework coverage reports
2021-09-16 00:08:03 +00:00
Erik Krogh Kristensen
5c73fed83a
fix dbsheme upgrade from TypeScript 4.4 PR
2021-09-15 22:38:27 +02:00
Alex Ford
e89d485bc0
update test output (subpaths)
2021-09-15 20:51:14 +01:00
Alex Ford
773291e4c3
Put exprNodeReturnedFrom predicate in DataFlowDispatch.qll
2021-09-15 20:50:46 +01:00
Alex Ford
e80faa017c
Fix rb/reflected-xss flow from helper method return values
2021-09-15 20:50:46 +01:00
Alex Ford
35da921deb
format
2021-09-15 20:50:46 +01:00
Alex Ford
50b0bb8b36
Restrict rb/reflected-xss instance variable taint edges
2021-09-15 20:50:46 +01:00
Alex Ford
5cfefb1027
Add some more test cases for rb/reflected-xss
2021-09-15 20:50:46 +01:00
Alex Ford
6cc82d46f3
Fix LinkToCallArgumentAsSink matching when link_to is passed a block
2021-09-15 20:50:46 +01:00
Alex Ford
200c8f2493
Add some HTMLEscaping implementations for Rails
2021-09-15 20:50:46 +01:00
Alex Ford
2e65f9b80e
update some comments referencing view components
2021-09-15 20:50:46 +01:00
Alex Ford
98fd0e1c24
Update ql/src/queries/security/cwe-079/ReflectedXSS.qhelp
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-09-15 20:50:46 +01:00
Alex Ford
0689e6095e
make a type more specific
2021-09-15 20:50:46 +01:00
Alex Ford
ed708c1903
Update ql/src/queries/security/cwe-079/ReflectedXSS.qhelp
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-09-15 20:50:46 +01:00
Alex Ford
eed87b3319
Apply suggestions from code review
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-09-15 20:50:46 +01:00
Alex Ford
205b141482
format
2021-09-15 20:50:46 +01:00
Alex Ford
76864a82be
remove an incorrect test case
2021-09-15 20:50:46 +01:00
Alex Ford
3445a6a5e7
fix flow steps from controller instance var assignement to view read access
2021-09-15 20:50:46 +01:00
Alex Ford
b993723595
remove spurious ivar -> locals hash mapping (actionview/controller)
2021-09-15 20:50:46 +01:00
Alex Ford
3430a46440
fix some local variable mappings between view and controller
2021-09-15 20:50:46 +01:00
Alex Ford
b264a05288
Update ql/lib/codeql/ruby/security/ReflectedXSSCustomizations.qll
...
Co-authored-by: Harry Maclean <hmac@github.com >
2021-09-15 20:50:46 +01:00
Alex Ford
dbb239b04e
reorder and format rb/reflected-xss qhelp
2021-09-15 20:50:46 +01:00
Alex Ford
d71dd3f6c7
rb/reflected-xss
2021-09-15 20:50:46 +01:00
Ethan P
080867a390
Add reviewer feedback
2021-09-15 11:19:41 -07:00
Nick Rolfe
f76ce8b33b
Merge pull request #6686 from hvitved/cpp/files-folders-drop-columns
...
C++: Drop redundant columns from `files` and `folders` relations
2021-09-15 18:33:20 +01:00
Mathias Vorreiter Pedersen
33ef634ea8
Merge pull request #6679 from andersfugmann/relax_memberMayBeVarSize
...
Improve precision on OverflowStatic query.
2021-09-15 17:24:10 +01:00
Tony Torralba
21079a1315
Fix conditionControlsMethod predicate
...
Exceptions for throw and return statements were missing the appropriate condition
2021-09-15 17:51:51 +02:00
Tony Torralba
d3cf697b07
QLDoc
2021-09-15 17:32:36 +02:00
Tony Torralba
5ed9949498
Adapt InsecureBasicAuth to the previous commit
2021-09-15 17:20:28 +02:00
Tony Torralba
2e08c5dd2b
Refactored HttpsUrls.ql
2021-09-15 17:20:28 +02:00
Tony Torralba
c3c73377b8
Fix scope issues in the Java example
2021-09-15 17:20:28 +02:00
Tony Torralba
023264660b
Suggestions from code review
2021-09-15 17:20:28 +02:00
mc
0e7cbbfeb8
Update InsecureBasicAuth.qhelp
2021-09-15 17:20:28 +02:00
mc
e58b90ef1c
Added full stops
2021-09-15 17:20:28 +02:00
Tony Torralba
e159351179
Update java/change-notes/2021-06-01-insecure-basic-auth-query.md
...
Co-authored-by: Anders Schack-Mulligen <aschackmull@users.noreply.github.com >
2021-09-15 17:20:27 +02:00
Tony Torralba
30178d4f23
Decouple InsecureBasicAuth.qll to reuse the taint tracking configuration
2021-09-15 17:20:27 +02:00
Tony Torralba
90df3fa94c
Remove CWE reference from qlhelp since it's obtained from metadata
2021-09-15 17:20:27 +02:00
Tony Torralba
49c6a56f97
Add change note
2021-09-15 17:20:27 +02:00
Tony Torralba
148443fae1
Use InlineExpectationsTest
2021-09-15 17:20:27 +02:00
Tony Torralba
2cada386b4
Refactored into InsecureBasicAuth.qll
2021-09-15 17:20:27 +02:00
Tony Torralba
905be67aae
Moved from experimental
2021-09-15 17:20:27 +02:00
Tom Hvitved
d3a1d0a62a
Merge pull request #294 from github/bump-codeql
...
Bump `codeql` submodule
2021-09-15 16:24:04 +02:00
Anders Schack-Mulligen
c0fd44c909
Dataflow: Sync.
2021-09-15 16:10:54 +02:00
Anders Schack-Mulligen
3abe1b4fc6
Dataflow: Fix bad join-order.
2021-09-15 16:10:30 +02:00
Geoffrey White
c4714b55a3
Merge pull request #6588 from ihsinme/ihsinme-patch-069
...
CPP: Add query for CWE-675: Duplicate Operations on Resource
2021-09-15 15:10:03 +01:00
Tom Hvitved
9e67382f06
Bump codeql submodule
2021-09-15 14:59:42 +02:00
Jonas Jensen
65f4ec403f
Merge pull request #6593 from geoffw0/samate-move
...
C++: Add test cases with SAMATE Juliet code snippets to the codeql test suite.
2021-09-15 14:18:08 +02:00
Mathias Vorreiter Pedersen
947ab8a14d
Make the QLDoc on 'getAnSqlParameter' more clear.
2021-09-15 13:15:05 +01:00
Erik Krogh Kristensen
3f736d3eb8
Merge pull request #6694 from erik-krogh/owasp-fixes
...
JS/Java: use the correct cwe tags
2021-09-15 13:46:35 +02:00
CodeQL CI
b228398b87
Merge pull request #6587 from erik-krogh/ts44
...
Approved by asgerf
2021-09-15 04:00:13 -07:00
Rasmus Lerchedahl Petersen
8ea7a28a77
Python: Unexpose fields as suggested.
2021-09-15 12:32:21 +02:00
yoff
758b6bd4dd
Update python/ql/src/semmle/python/functions/ModificationOfParameterWithDefaultCustomizations.qll
...
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com >
2021-09-15 12:25:27 +02:00
Geoffrey White
0e7afb24cf
Merge pull request #6643 from MathiasVP/add-frontend-and-extractor-diagnostic-query
...
C++: Add uninterpreted query for obtaining frontend and extraction time
2021-09-15 11:17:58 +01:00
Geoffrey White
9ad51fbc02
C++: Fix the correct test this time.
2021-09-15 11:03:09 +01:00
Erik Krogh Kristensen
cf149bd8c8
add static_initializer as a stmt_parent
2021-09-15 11:54:30 +02:00
Chris Smowton
03db15af9a
Merge pull request #6685 from smowton/smowton/admin/android-uri-model
...
Java: Add models for android.net.Uri[.Builder]
2021-09-15 10:48:33 +01:00
Erik Krogh Kristensen
0b83d033d7
add @static_initializer in the stats file
2021-09-15 11:33:05 +02:00
Jordy Zomer
0f6e845418
Merge branch 'main' of https://github.com/JordyZomer/codeql into main
2021-09-15 10:41:31 +02:00
Jordy Zomer
01a06d1f5c
Add filter and format the query
2021-09-15 10:37:40 +02:00
Anders Fugmann
e49cd83868
C++: update change note per suggestion from peer review
2021-09-15 10:31:15 +02:00
Anders Schack-Mulligen
8485b6f0b3
Merge pull request #6691 from bmuskalla/moreStringMethods
...
Java: Support String#getChars and #translateEscapes
2021-09-15 10:14:54 +02:00
CodeQL CI
220f2ded85
Merge pull request #6698 from asgerf/js/template-self-assignment
...
Approved by esbena
2021-09-15 01:08:39 -07:00
Anders Schack-Mulligen
3f7d6e6f85
Merge pull request #6136 from smowton/smowton/admin/spring-xss-content-type-sensitivity
...
Spring HTTP: improve content-type sensitivity
2021-09-15 09:50:56 +02:00
Anders Schack-Mulligen
2a9e3da24f
Merge pull request #6697 from github/workflow/coverage/update
...
Update CSV framework coverage reports
2021-09-15 09:35:09 +02:00
Asger Feldthaus
b5db4047a0
JS: Exclude template files in SelfAssignment
2021-09-15 08:59:47 +02:00
github-actions[bot]
baab70bea6
Add changed framework coverage reports
2021-09-15 00:07:57 +00:00
CodeQL CI
b25b19f71b
Merge pull request #6584 from erik-krogh/clipBoard
...
Approved by esbena
2021-09-14 12:41:49 -07:00
Erik Krogh Kristensen
5a7785776c
add upgrade script
2021-09-14 20:43:07 +02:00
Erik Krogh Kristensen
fdbf5f73b1
add JS support for static initializers
2021-09-14 20:40:46 +02:00
Erik Krogh Kristensen
cc0d86403e
revert some type changes that are no longer needed
2021-09-14 20:40:46 +02:00
Erik Krogh Kristensen
48b763c7e9
add qldoc to StaticInitializer::getBody
2021-09-14 20:40:46 +02:00
Erik Krogh Kristensen
7ce87a7118
remove stray import
2021-09-14 20:40:46 +02:00
Erik Krogh Kristensen
c8c7a1f772
remove the body field from StaticInitializer and relax the valuye type on MemberDefinition
2021-09-14 20:40:45 +02:00
Erik Krogh Kristensen
e3ed6c2523
refactor StaticInitializer into it's own class
2021-09-14 20:40:45 +02:00
Erik Krogh Kristensen
23e28ae5d4
fix typo in comment
...
Co-authored-by: Asger F <asgerf@github.com >
2021-09-14 20:40:45 +02:00
Erik Krogh Kristensen
2a03a84315
remove TODO comment
...
Co-authored-by: Asger F <asgerf@github.com >
2021-09-14 20:40:45 +02:00
Erik Krogh Kristensen
68ab210dc8
update TypeScript version info in versions-compilers.rst
2021-09-14 20:40:45 +02:00
Erik Krogh Kristensen
ffd51e725f
add getter for static initializer blocks
2021-09-14 20:40:45 +02:00
Erik Krogh Kristensen
9585481d0b
add support for static initializer blocks in TypeScript
2021-09-14 20:40:45 +02:00
Erik Krogh Kristensen
59f15eb4eb
add tests for TypeScript 4.4 types
2021-09-14 20:40:45 +02:00
Erik Krogh Kristensen
02a0eed8ee
add basic support for TypeScript 4.4
2021-09-14 20:40:45 +02:00
Erik Krogh Kristensen
3b6c8c5191
Merge branch 'main' into clipBoard
2021-09-14 20:21:37 +02:00
CodeQL CI
136d04390d
Merge pull request #6695 from erik-krogh/js-add-cwes
...
Approved by esbena
2021-09-14 11:19:35 -07:00
Nick Rolfe
961674e4a8
Update expected output now we extract the Gemfile
2021-09-14 18:23:57 +01:00
Nick Rolfe
ec13133317
Automatically extract .gemspec and Gemfile files
...
They are just Ruby code, after all.
2021-09-14 18:23:57 +01:00
Nick Rolfe
ebf23d00d1
Don't parse \A and \Z as RegExpConstant
...
Fixes some FPs for the ReDoS queries.
2021-09-14 16:49:35 +01:00
Geoffrey White
8fd848701e
C++: Fix test failure.
2021-09-14 16:38:11 +01:00
Chris Smowton
e5b84fb795
Use InlineFlowTest
2021-09-14 16:37:07 +01:00
Chris Smowton
5d737934c3
Don't inherit models from a final class
...
Co-authored-by: Tony Torralba <atorralba@users.noreply.github.com >
2021-09-14 16:37:07 +01:00
Chris Smowton
367a53dd71
Add models for android.net.Uri[.Builder]
2021-09-14 16:37:07 +01:00
Harry Maclean
12723f0f13
Merge pull request #288 from github/hmac-barrier-guard-checks
...
Make barrier guards more specific
2021-09-14 16:16:20 +01:00
Chris Smowton
ca87768a93
Merge pull request #6692 from bmuskalla/testGeneratorFlowTest
...
Java: Test generator uses `InlineFlowTest`
2021-09-14 15:44:24 +01:00
Arthur Baars
e03fe0fcd4
Add ClassifyFiles.ql
2021-09-14 16:30:34 +02:00
Mathias Vorreiter Pedersen
44dca68463
Merge branch 'main' into promote-sql-pqxx
2021-09-14 15:29:37 +01:00
Chris Smowton
406466de9a
Simplify specifiesContentType predicate
2021-09-14 15:24:46 +01:00
Mathias Vorreiter Pedersen
adbeba291b
Merge pull request #6687 from MathiasVP/fix-fp-in-av-rule-114
...
C++: Exclude uninstantiated templates from AV Rule 114.
2021-09-14 15:24:18 +01:00
Chris Smowton
6cff0d0376
Merge pull request #6393 from luchua-bc/java/xss-jsf
...
Java: CWE-079 Query to detect XSS with JavaServer Faces (JSF)
2021-09-14 15:15:56 +01:00
Anders Fugmann
bc22e0d9aa
C++: Update comments on memberMayBeVarSize
2021-09-14 16:04:39 +02:00
Tony Torralba
4e93330cb9
Improved tests
...
Note that a FN test case was added
2021-09-14 15:51:08 +02:00
Benjamin Muskalla
abd770a027
Avoid empty template in test generator
2021-09-14 15:32:12 +02:00
Chris Smowton
a1ad1ddc10
Deprecated and replace uses of old name ServletWriterSource
2021-09-14 14:21:29 +01:00
Rasmus Lerchedahl Petersen
d37c14880f
Python: Copy performance fix
2021-09-14 15:15:50 +02:00
Erik Krogh Kristensen
b936a04826
add some fitting CWEs to existing queries
2021-09-14 14:59:24 +02:00
Ethan Palm
c62a21e04f
Apply suggestions from code review
...
Co-authored-by: Felicity Chapman <felicitymay@github.com >
2021-09-14 08:55:46 -04:00
Erik Krogh Kristensen
6d12c4aab1
use the correct cwe tags
2021-09-14 14:42:23 +02:00
Anders Schack-Mulligen
26eafcb55a
Merge pull request #6456 from smowton/smowton/admin/flexjson-unsafe-deserialization
...
Java: add unsafe-deserialization support for Flexjson
2021-09-14 14:33:22 +02:00
Tom Hvitved
f4e2c30d86
Merge pull request #291 from github/hvitved/regexp-multiples
...
Speedup `RegExp::multiples`
2021-09-14 14:22:20 +02:00
Tom Hvitved
8ac3dc29e0
Speedup RegExp::multiples
...
Use regexps to perform matching to avoid constructing sub strings.
2021-09-14 13:58:24 +02:00
Tony Torralba
0640b41f00
Adjust tests
2021-09-14 13:44:53 +02:00
Rasmus Wriedt Larsen
8b7fad8595
Merge pull request #6283 from tausbn/python-fix-exceptstmt-gettype
...
Python: Fix `ExceptStmt::getType`
2021-09-14 13:40:33 +02:00
Rasmus Wriedt Larsen
49f5f1e2c2
Merge pull request #6336 from tausbn/python-make-annotated-assignment-a-definitionnode
...
Python: Two fixes regarding annotated assignments
2021-09-14 13:37:53 +02:00
Chris Smowton
6af5c5fc86
Add change note
2021-09-14 12:36:38 +01:00
Chris Smowton
26dbf058c8
Add reverse import from ExternalFlow.qll
2021-09-14 12:35:33 +01:00
Chris Smowton
fcc0f1d5a7
Expand test to exercise all sinks
2021-09-14 12:27:33 +01:00
Chris Smowton
e439b7d7f8
Remove resource-related sources
...
These access application-owned resources AFAICT
2021-09-14 12:24:27 +01:00
Tony Torralba
b740cf9664
Add change note
2021-09-14 13:16:47 +02:00
Tony Torralba
097927226b
Improved heuristics to increase precision
2021-09-14 13:16:47 +02:00
Tony Torralba
f8d1e2ac11
Refactor tests to use InlineExpectationsTest
2021-09-14 13:16:45 +02:00
Tony Torralba
1f7990d6bb
Refactor to use ConditionalBypassQuery.qll
2021-09-14 13:16:09 +02:00
Tony Torralba
a484e9fb06
Use RemoteFlowSource instead of UserInput
2021-09-14 13:16:09 +02:00
Tom Hvitved
b69033f4ff
C++: Upgrade script
2021-09-14 13:14:04 +02:00
Tom Hvitved
6c32b92929
C++: Drop redundant columns from files and folders relations
2021-09-14 13:14:04 +02:00
Tom Hvitved
98a12cef26
Merge pull request #6690 from hvitved/js/files-folders-drop-columns
...
JavaScript: Drop redundant columns from `files` and `folders` relations
2021-09-14 13:13:37 +02:00
Chris Smowton
104873e8ee
Autoformat
2021-09-14 12:07:59 +01:00
Chris Smowton
6811441459
Factor JSF source definitions
2021-09-14 12:07:48 +01:00
Chris Smowton
b7fc068cee
Move JSFRenderer.qll to lib
2021-09-14 11:49:01 +01:00
Chris Smowton
023c533745
Combine Servlet and JSF vulnerable writer flow-tracking
...
JSP and Servlet already shared this logic; might as well add JSF into the same mechanism.
2021-09-14 11:48:34 +01:00
Chris Smowton
cb8096f636
Remove JSF XSS Example
...
Per previous commit, no need for a top-level JSF example
2021-09-14 11:47:37 +01:00
Chris Smowton
cca9ad06b4
Remove JSF example
...
I don't think we need this: there are lots of possible XSS vectors; we don't need to enumerate every one in the qhelp file.
2021-09-14 11:47:36 +01:00
Chris Smowton
76e4077b56
Delete unused classes
2021-09-14 11:47:35 +01:00
luchua-bc
24addd5c10
Query to detect XSS with JavaServer Faces (JSF)
2021-09-14 11:47:32 +01:00
Chris Smowton
e92b9cbe99
Improve getAProducesExpr documentation
2021-09-14 11:16:45 +01:00
Harry Maclean
4763312e55
Merge ConditionBlock and BarrierGuard
2021-09-14 11:11:12 +01:00
Benjamin Muskalla
f9918cc63c
Test generator uses InlineFlowTest
2021-09-14 11:58:56 +02:00
Arthur Baars
c2ec6407f5
Add AlertSuppression.ql
2021-09-14 11:53:53 +02:00
Anders Schack-Mulligen
e71173d953
Merge pull request #6591 from bmuskalla/inlineFlowTest
...
Java: Simplify setup for flow tests using `InlineExpectationsTest`
2021-09-14 10:31:29 +02:00
Tom Hvitved
57b5b2af2e
JavaScript: DB upgrade script
2021-09-14 10:25:53 +02:00
Tom Hvitved
25e1da0150
JavaScript: Update expected test output
2021-09-14 10:25:42 +02:00
Tom Hvitved
63e28c57cd
JavaScript: Drop redundant columns from files and folders relations
2021-09-14 10:25:37 +02:00
Benjamin Muskalla
199e015a06
Support missing String methods
2021-09-14 10:22:22 +02:00
jorgectf
b505662ef9
Fix global test and update .expected
2021-09-14 10:20:50 +02:00
Tamás Vajk
d52616b687
Merge pull request #6683 from tamasvajk/feature/csv-coverage-fix
...
Only leave CSV coverage updater job enabled on github/codeql
2021-09-14 10:13:28 +02:00
Benjamin Muskalla
93f9097b02
Merge pull request #6689 from github/workflow/coverage/update
...
Update CSV framework coverage reports
2021-09-14 09:35:31 +02:00
jorgectf
2ccc6dc092
Merge branch 'main' into jorgectf/python/ldapinsecureauth
2021-09-14 09:32:19 +02:00
ihsinme
8fa3cefb8c
Update DoubleRelease.ql
2021-09-14 10:31:20 +03:00
ihsinme
d150c9a6be
Update DoubleRelease.ql
2021-09-14 08:51:13 +03:00
github-actions[bot]
bf7c26e681
Add changed framework coverage reports
2021-09-14 00:07:57 +00:00
Taus
4d24be04a1
Merge pull request #6688 from RasmusWL/small-fix
...
Python: Fix `globals() == locals()` FP
2021-09-13 21:50:13 +02:00
Erik Krogh Kristensen
b889674486
add change note
2021-09-13 20:45:35 +02:00
Erik Krogh Kristensen
8569d261f7
add test
2021-09-13 20:43:31 +02:00
Erik Krogh Kristensen
8e98dcefb1
add clipboard data as a RemoteFlowSource
2021-09-13 20:43:31 +02:00
Erik Krogh Kristensen
3983aceb48
recognize types of the form "HTML%Element" as dom values
2021-09-13 20:43:31 +02:00
Erik Krogh Kristensen
bac80bf686
delete ClipboardXss.ql experimental query
2021-09-13 20:43:31 +02:00
Rasmus Wriedt Larsen
f402475dd3
Python: Fix globals() == locals() FP
2021-09-13 20:03:11 +02:00
Rasmus Wriedt Larsen
69fe2a36e5
Python: Add globals() == locals() test
2021-09-13 20:02:08 +02:00
Rasmus Wriedt Larsen
ba7cdec2ea
Python: Add some lines in test file
...
These are just empty now, such that it's obvious the tests didn't
change.
2021-09-13 20:00:50 +02:00
Rasmus Wriedt Larsen
a9694bf0ef
Python: Clean whitespace
2021-09-13 19:58:59 +02:00
Mathias Vorreiter Pedersen
a714966e9b
Import 'cpp' and add more description.
2021-09-13 18:43:34 +01:00
Ethan P
930a36df37
Add example step for ending build tracing
2021-09-13 13:40:49 -04:00
Mathias Vorreiter Pedersen
034899367d
C++: Exclude uninstantiated templates from AV Rule 114.
2021-09-13 18:08:51 +01:00
Ethan P
47a543e086
Add reviewer feedback
2021-09-13 12:02:31 -04:00
Tom Hvitved
3bdc92ba8e
Merge pull request #6681 from hvitved/java/files-folders-drop-columns
...
Java: Drop redundant columns from `files` and `folders` relations
2021-09-13 17:43:31 +02:00
Chris Smowton
122ffca049
Merge pull request #6645 from Marcono1234/marcono1234/spurious-javadoc-param-generic-class
...
Java: Detect spurious param Javadoc tag of generic classes
2021-09-13 16:41:06 +01:00
Benjamin Muskalla
24d740b2da
Merge branch 'main' into inlineFlowTest
2021-09-13 17:15:37 +02:00
Benjamin Muskalla
bf5a46f6d8
Simplify inline tests
2021-09-13 17:08:02 +02:00
Taus
b51ce1d2b3
Merge pull request #6640 from yoff/python-add-parameter-default-value-flow-step
...
Python: add parameter default value flow step
2021-09-13 17:05:48 +02:00
Anders Schack-Mulligen
7b764aec92
Merge pull request #6682 from aschackmull/java/callbacks
...
Java: Add support for callback-based library models.
2021-09-13 16:43:03 +02:00
Chris Smowton
3c7b39f089
Add change note
2021-09-13 15:36:26 +01:00
Anders Fugmann
f202ddc5aa
C++: Add changenote
2021-09-13 16:31:06 +02:00
Tamas Vajk
80f5ec29d4
Log stdout and stderr in CSV coverage jobs
2021-09-13 16:16:03 +02:00
Tamas Vajk
1d8fae44cc
Only leave CSV coverage updater job enabled on github/codeql
2021-09-13 16:15:21 +02:00
Tom Hvitved
b60f1cd531
Java: Upgrade script
2021-09-13 16:09:47 +02:00
Tom Hvitved
9fdcacd865
Java: Drop redundant columns from files and folders relations
2021-09-13 16:09:47 +02:00
Anders Schack-Mulligen
ab862276fc
Java: Fix tests.
2021-09-13 16:04:11 +02:00
Anders Schack-Mulligen
12aeaeed56
Java: Address review comment.
2021-09-13 16:03:50 +02:00
Chris Smowton
47b5165f2a
Merge pull request #6653 from smowton/smowton/admin/javascript-unpaired-surrogate-test
...
Java and JS: Add/adapt tests for literals with an unpaired surrogate character
2021-09-13 14:53:23 +01:00
Anders Schack-Mulligen
818e75bb8f
Java: Fix compilation error in telemetry lib.
2021-09-13 15:50:21 +02:00
Geoffrey White
902fa7d44a
C++: Subsection header.
2021-09-13 14:10:17 +01:00
Geoffrey White
acd1acd869
C++: Give it a section header.
2021-09-13 14:08:18 +01:00
Geoffrey White
befd1a7ccc
C++: Rename security tests readme.
2021-09-13 14:06:22 +01:00
Chris Smowton
abdd3a5dbe
Adjust Java tests that check for unpaired surrogate extraction
2021-09-13 14:02:05 +01:00
Erik Krogh Kristensen
05cc6bcf8a
adjust regexp libraries to how unpaired surrogate are parsed now
2021-09-13 14:02:05 +01:00
Chris Smowton
f24d7c4212
Acknowledge new FPs due to the extractor using U+FFFD for unpaired surrogates
...
These were already misinterpreted, but the ReDoS code ignored them as they previously appeared to be `?` characters.
2021-09-13 14:02:05 +01:00
Chris Smowton
487ebdf173
Add test for Javascript literal with an unpaired surrogate character
2021-09-13 14:02:05 +01:00
Anders Schack-Mulligen
89a6cdc711
Java: Add support for callback-based library models.
2021-09-13 14:49:28 +02:00
Ian Lynagh
3404bcf265
Merge pull request #6680 from github/igfoo/java_location
...
Java: Use the standard URL format for Location.toString()
2021-09-13 13:43:32 +01:00
Ian Lynagh
4fbb165dce
Java: Use the standard URL format for Location.toString()
2021-09-13 12:53:50 +01:00
Harry Maclean
6f32401e5c
Add unless x != test to barrier guards
...
This tests that the following call to `foo bar` is guarded:
unless bar != "bar"
foo bar
end
2021-09-13 11:58:17 +01:00
Anders Fugmann
9a35a699cb
C++: Update tests
2021-09-13 12:10:58 +02:00
Chris Smowton
68ed3250e8
Merge pull request #6478 from smowton/smowton/feature/jax-rs-request-filters
...
Java: Add sources for Jax-RS filters
2021-09-13 10:59:17 +01:00
James Fletcher
c86311e879
Merge pull request #6502 from github/dataflow-tutorial
...
Add data flow debugging guide to CodeQL docs
2021-09-13 10:25:19 +01:00
Anders Fugmann
342b2df93f
C++: zero or one byte sized arrays in unions are considered as having the length of the union its a member of
2021-09-13 11:25:04 +02:00
Anders Fugmann
3172d5727a
C++: Relax constraints on Buffer::memberMayBeVarSize
2021-09-13 11:15:33 +02:00
yoff
d0563c80be
Merge pull request #6665 from smowton/smowton/fix/python-redos-invalid-utf16
...
ReDoS: fix unpaired surrogate test
2021-09-13 11:14:45 +02:00
Anders Schack-Mulligen
2db039fb77
Merge pull request #6673 from Marcono1234/marcono1234/clone-method-models
...
Java: Remove duplicate classes modeling Object.clone
2021-09-13 11:13:14 +02:00
Anders Schack-Mulligen
dde07fd2ee
Merge pull request #6672 from Marcono1234/marcono1234/functional-interfaces-test
...
Java: Extend functional interfaces test
2021-09-13 11:13:06 +02:00
Anders Fugmann
4ab9b81a9a
C++: Add tests exposing some FP's for OverflowStatic query
2021-09-13 11:09:56 +02:00
Tom Hvitved
4628f880b4
Merge pull request #6489 from hvitved/csharp/files-folders-drop-columns
...
C#: Drop redundant columns from `files` and `folders` relations
2021-09-13 11:02:13 +02:00
Anders Schack-Mulligen
31739cdae6
Merge pull request #6668 from github/workflow/coverage/update
...
Update CSV framework coverage reports
2021-09-13 09:50:09 +02:00
Tom Hvitved
2730423ab2
C#: Upgrade script
2021-09-13 09:49:10 +02:00
Tom Hvitved
5d048a9518
C#: Drop redundant columns from files and folders relations
2021-09-13 09:49:09 +02:00
Tamás Vajk
cc1374b832
Merge pull request #6646 from tamasvajk/fix/csv-timeseries
...
Fix CSV timeseries script to create DB with scheme from correct git SHA
2021-09-13 09:41:56 +02:00
Tom Hvitved
0abfb00032
Merge pull request #6660 from hvitved/csharp/dotnet-exec-tracing-windows
...
C#: Handle `dotnet exec csc.dll` compiler calls on Windows
2021-09-13 09:07:50 +02:00
github-actions[bot]
26e8e89aca
Add changed framework coverage reports
2021-09-13 00:08:00 +00:00
jorgectf
353c0a9ee7
Add missing comment
2021-09-12 20:44:04 +02:00
jorgectf
3cf28ad6ce
Merge remote-tracking branch 'origin/main' into jorgectf/python/ldapinsecureauth
2021-09-12 20:36:25 +02:00
jorgectf
18b05bc56e
Fix tests and add global option
2021-09-12 20:35:57 +02:00
jorgectf
54012eba23
Optimize getFullHostRegex
2021-09-12 20:13:08 +02:00
Philip Ginsbach
131d63c374
Merge pull request #6592 from github/ginsbach/instanceofDocs
...
language reference entry for non-extending subtypes
2021-09-12 15:21:41 +01:00
Marcono1234
d117593d72
Java: Remove duplicate classes modeling Object.clone
2021-09-12 02:05:57 +02:00
Marcono1234
5009ed618f
Java: Extend functional interfaces test
2021-09-12 01:50:07 +02:00
Andrew Eisenberg
edbaceceb3
Merge pull request #6666 from github/aeisenberg/suites-fix
...
Remove incorrect `suites` directive
2021-09-10 14:15:10 -07:00
Ethan P
fb22931e2d
add indirect build tracing content and example
2021-09-10 16:06:32 -04:00
CodeQL CI
e8fc3c8ead
Merge pull request #5888 from erik-krogh/casting
...
Approved by asgerf
2021-09-10 09:11:39 -07:00
Andrew Eisenberg
9c0f18b88d
Remove incorrect directive
...
This directive should only be in the
pack.
2021-09-10 08:57:37 -07:00
Harry Maclean
800e18349f
Add != to StringConstCompare
...
This means we treat != comparisons against strings as taint tracking guards:
if foo != "A"
foo # still tainted
else
foo # not tainted, because we know foo == "A"
end
2021-09-10 16:42:45 +01:00
Chris Smowton
95046b9bb1
Factor JaxRS models
2021-09-10 16:36:40 +01:00
Chris Smowton
451a46bf0e
Add models for getLanguage, getMediaType
2021-09-10 16:36:38 +01:00
Chris Smowton
5e7a3ca2e6
Model UriInfo.relativize and resolve.
2021-09-10 16:36:37 +01:00
Chris Smowton
62ecab8432
Add change note
2021-09-10 16:36:36 +01:00
Chris Smowton
f1c3a11103
Add sources for Jax-RS filters
2021-09-10 16:36:34 +01:00
Harry Maclean
8f36b0d7fe
Simplify guard in SQL injection tests
...
We don't (yet) properly sanitize taint in cases like this
foo = "A" unless foo == "B"
So for now, use a simpler guard in the SQL injection test.
We can resurrect the old, more idiomatic guard when we can support it.
2021-09-10 16:27:57 +01:00
Chris Smowton
d83ed33252
Make supertype consideration consistent
2021-09-10 16:27:28 +01:00
Chris Smowton
9b488207eb
Add support for the Flexjson framework to the unsafe-deserialization query
2021-09-10 16:27:23 +01:00
Harry Maclean
56983565fe
Update ReDoS length guard
...
Changes to barrier guards in a previous commit mean we need to update
this guard to match.
2021-09-10 16:21:17 +01:00
Chris Smowton
9d31641bb1
Add change note
2021-09-10 16:10:56 +01:00
Chris Smowton
655236c70d
Remove no-longer-needed generic specifiers
2021-09-10 16:10:55 +01:00
Chris Smowton
b47939c737
Note resolved spurious results
2021-09-10 16:10:54 +01:00
Chris Smowton
d940085384
Spring HTTP: inherit produced content-types from surrounding class
2021-09-10 16:10:52 +01:00
Chris Smowton
bdd135dbff
Spring HTTP: mark explicitly content-typed body calls as sinks
...
Previously only the return from the request-handler method constituted a sink, and was filtered by the Produces annotation if any, even though a BodyBuilder could explicitly override.
These sinks are also marked as out-barriers to avoid duplicate paths when the Produces annotation is in agreement.
2021-09-10 16:10:50 +01:00
Chris Smowton
701d0bcdca
Spring content types: recognise constant content-type strings
2021-09-10 16:10:48 +01:00
Chris Smowton
4397371a50
Spring constant media types: recognise constant string versions
...
Previously we only recognised the constant MediaTypes
2021-09-10 16:10:47 +01:00
Chris Smowton
b9b34eb0ee
Move Spring XSS sink definition into SpringHttp.qll
2021-09-10 16:10:45 +01:00
Chris Smowton
3b6cc97557
Sanitize Spring bodies directly associated with an XSS-safe Content-Type
2021-09-10 16:10:44 +01:00
Chris Smowton
0ebbb333ba
Merge pull request #6564 from haby0/java/xxe/new
...
Java: Add XXE sinks
2021-09-10 16:04:27 +01:00
Chris Smowton
38cc9bef02
ReDoS: fix unpaired surrogate test
...
This actually does result in an FP, but this was previously hidden by non-interpretation of '\u' escapes within a raw string.
2021-09-10 15:37:34 +01:00
Chris Smowton
29028c5d46
Update test expectations to account for dataflow subpaths changes
2021-09-10 13:53:41 +01:00
Chris Smowton
2d03840fde
Add experimental variants of java/xxe, incorporating new sinks and a version that uses local sources.
...
Originally authored by @haby0, squashed to clean up a tangled commit history.
2021-09-10 13:49:31 +01:00
Rasmus Lerchedahl Petersen
2eb11731e2
Python: Subpaths in test output
2021-09-10 14:04:57 +02:00
Rasmus Lerchedahl Petersen
02fd63ce20
Merge branch 'main' of github.com:github/codeql into python/port-modification-of-default-value
...
To get the subpaths.
2021-09-10 14:03:02 +02:00
Rasmus Lerchedahl Petersen
5d137ce9c5
Python: Update test expectations
2021-09-10 13:35:49 +02:00
Rasmus Wriedt Larsen
db78e3a7da
Merge pull request #6274 from tausbn/python-api-graphs-import-star
...
Python: Support `import *` in API graphs
2021-09-10 13:25:41 +02:00
Rasmus Wriedt Larsen
b45743b562
Merge pull request #6312 from tausbn/python-deprecate-importnode
...
Python: Deprecate `importNode`
2021-09-10 13:12:56 +02:00
CodeQL CI
27f2d417c1
Merge pull request #6652 from asgerf/js/type-tracking-through-callback
...
Approved by erik-krogh
2021-09-10 04:11:14 -07:00
Rasmus Lerchedahl Petersen
7cfa08abc8
Python: Do not use BarrierGuards
...
They are simply not right for this problem.
We should not even make them available as an extension point.
2021-09-10 12:48:24 +02:00
Tom Hvitved
649c2ce188
Merge pull request #6586 from hvitved/dataflow/stage2-precise-call-ctx-take2
...
Data flow: Add precise call contexts to stage 2
2021-09-10 11:34:35 +02:00
Tom Hvitved
af0b9abab7
C#: Handle dotnet exec csc.dll compiler calls on Windows
2021-09-10 11:26:43 +02:00
CodeQL CI
0673355f31
Merge pull request #6649 from rhysd/discussion-untrusted-inputs
...
Approved by erik-krogh
2021-09-10 01:44:54 -07:00
Rasmus Lerchedahl Petersen
b20232db3c
Python: Simplify guards as suggested
2021-09-10 10:31:48 +02:00
Anders Peter Fugmann
1bbadb57a2
Merge pull request #6568 from andersfugmann/andersfugmann/improve_upper_bound
...
C++: Improve predicate upperBound in SimpleRangeAnalysis
2021-09-10 09:49:48 +02:00
Erik Krogh Kristensen
a756ffa3a6
use the new instanceof syntax for NodeJSClientRequest
2021-09-10 09:30:37 +02:00
Tom Hvitved
296d10fe2a
Data flow: Adjust callMayFlowThroughFwd pragmas
2021-09-10 09:21:24 +02:00
Anders Schack-Mulligen
3e17fdcaa3
Merge pull request #6407 from bmuskalla/charSeqSubSeq
...
Java: Track taint for CharSequence#subSequence
2021-09-10 09:01:29 +02:00
rhysd
97ed9edd32
JS: Detect untrusted inputs in 'discussion' and 'discussion_comment' payloads
2021-09-10 10:42:58 +09:00
Chris Smowton
5b8b27a2aa
Merge pull request #6651 from smowton/smowton/admin/functional-interface-tests
...
Add tests for functional interfaces
2021-09-09 22:02:16 +01:00
Nick Rolfe
b51e741439
Merge pull request #289 from github/rust_warnings
...
Fix 'unused borrow that must be used' warnings.
2021-09-09 17:27:05 +01:00
Nick Rolfe
cf72bada3d
Fix 'unused borrow that must be used' warnings.
...
I don't remember seeing this warning before upgrading to Rust 1.55
2021-09-09 17:03:10 +01:00
Tamás Vajk
ad04099ac2
Merge pull request #6630 from tamasvajk/feature/interface-runtimecallable
...
C# Extend runtime callables to cover interface members with default implementation
2021-09-09 17:24:55 +02:00
Andrew Eisenberg
4c74709019
Merge pull request #6606 from github/aeisenberg/docs
...
Update the docs about qlpacks
2021-09-09 07:42:24 -07:00
Anders Schack-Mulligen
13c4b93d3d
Merge pull request #6648 from aschackmull/java/func-interface
...
Java: Fix FunctionalInterface.
2021-09-09 16:14:14 +02:00
Benjamin Muskalla
9d5e48430e
Merge branch 'main' into charSeqSubSeq
2021-09-09 16:04:36 +02:00
Chris Smowton
a0bf170d02
Add test for functional interfaces
2021-09-09 15:00:42 +01:00
Anders Schack-Mulligen
ec3990c619
Java: Fix FunctionalInterface.
2021-09-09 15:04:22 +02:00
Anders Schack-Mulligen
c4956a4ade
Merge pull request #6376 from bmuskalla/thirdpartyapitelemtry
...
Java: Introduce queries to capture information about 3rd party API usage
2021-09-09 13:55:47 +02:00
Anders Fugmann
270dbd2bf7
C++: Revert peer review suggestion.
...
The suggested change has a severe impact on row counts, as cpp does not cache
the results for `bbDominates`. Since the `getGuardedUpperBound` predicate the
cost of runtime complexity is considered higher than the benefit of this change.
2021-09-09 13:26:42 +02:00
Anders Fugmann
6c44b0e6e7
C++: Add test case where a guarded block has two predecessors which are both in the dominance domain of the guard
2021-09-09 13:18:49 +02:00
Benjamin Muskalla
c0e65e71b4
Revert "Java: Fix external flow perofrmance with future optimiser."
...
This reverts commit be1d4c04f2 .
2021-09-09 13:06:23 +02:00
Benjamin Muskalla
eef044f4d0
Add test to capture expected parameter format
2021-09-09 13:05:15 +02:00
Tamas Vajk
abe6c90829
Update change note
2021-09-09 13:04:47 +02:00
Tamas Vajk
0a17ab9325
Merge branch 'main' into feature/service-stack
2021-09-09 13:01:43 +02:00
Tamas Vajk
cc7471f37d
Fix package separator in timeseries report
2021-09-09 12:53:59 +02:00
Nick Rolfe
6dbf6d7e82
Merge pull request #278 from github/aibaars/revert-hotfix
...
Revert "Use hotfixed version of `codeql/suite-helpers` with workaround for bug in released CLI"
2021-09-09 11:21:20 +01:00
Harry Maclean
b4c29425ea
Make barrier guards more specific
...
Following examples from the other libraries, this change introduces a
member predicate `checks(CfgNode expr, boolean branch)` to
`BarrierGuard`, which holds if the guard validates `expr` for a
particular value of `branch`, which represents the value of the
condition in the guard.
For example, in the following guard...
if foo == "foo"
do_something foo
else
do_something_else foo
end
...the variable `foo` is validated when the condition `foo == "foo"` is
true.
We also introduce the concept that a guard "controls" a code block based
on the value of `branch`. In the example above, the "then" branch of the
if statement is controlled when `branch` is true. The else branch is
not controlled because `foo` can take (almost) any value in that branch.
Based on these concepts, we define a guarded node to be a read of a
validated variable in a controlled block.
In the above example, the `foo` in `do_something foo` is guarded, but
the `foo` in `do_something_else foo` is not.
2021-09-09 11:04:52 +01:00
Tamas Vajk
cbb37f70c4
Change timeseries CSV report to only include dates when values changed
2021-09-09 11:34:38 +02:00
Benjamin Muskalla
a1b7437f8d
Merge branch 'main' into thirdpartyapitelemtry
2021-09-09 11:11:42 +02:00
Tamas Vajk
1fe9e9262f
Fix CSV timeseries script to create DB with scheme from correct git SHA
2021-09-09 10:59:52 +02:00
Marcono1234
a173d9593b
Java: Detect spurious param Javadoc tag of generic classes
2021-09-09 00:11:02 +02:00
Andrew Eisenberg
fb90bb4241
Remove outdated section
...
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com >
2021-09-08 10:45:50 -07:00
Nick Rolfe
2ddca2c0db
Document and test YAML.safe_load
2021-09-08 18:22:31 +01:00
Nick Rolfe
760dbd739d
Add test for rb/unsafe-deserialization
2021-09-08 17:49:23 +01:00
Nick Rolfe
9b9fc18605
Add taint step for Base64.decode64
2021-09-08 17:49:23 +01:00
Nick Rolfe
adceb0a2a1
Add query rb/unsafe-deserialization
2021-09-08 17:49:23 +01:00
Andrew Eisenberg
ec5435befd
Apply suggestions from code review
...
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com >
2021-09-08 08:13:15 -07:00
Philip Ginsbach
55c605998c
Update docs/codeql/ql-language-reference/types.rst
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-09-08 15:35:40 +01:00
Benjamin Muskalla
96a34b6165
Fix value flow for fluent api
2021-09-08 16:12:52 +02:00
Anders Schack-Mulligen
5d58edb3b9
Merge pull request #6641 from aschackmull/dataflow/edges-fasttc
...
Dataflow: Only calculate fastTC for the relevant part of edges.
2021-09-08 15:45:46 +02:00
Mathias Vorreiter Pedersen
44f477d552
C++: Add uninterpreted query for obtaining frontend and extraction time.
2021-09-08 14:32:50 +01:00
Benjamin Muskalla
b47507293a
Minor fixes for fluent apis
2021-09-08 15:32:41 +02:00
Tamas Vajk
9ab6c29cd3
Extend runtime callables to cover interface members with default implementation
2021-09-08 15:07:49 +02:00
Rasmus Lerchedahl Petersen
baca9edbb1
Merge branch 'main' of github.com:github/codeql into python-add-parameter-default-value-flow-step
2021-09-08 14:48:13 +02:00
CodeQL CI
cd26d97dd7
Merge pull request #6549 from erik-krogh/moreDom
...
Approved by asgerf
2021-09-08 05:10:47 -07:00
Chris Smowton
5d37748973
Merge pull request #6631 from github/Claim-Java-16-support
...
Claim Java 16 support
2021-09-08 12:31:28 +01:00
Benjamin Muskalla
67eaa1b735
Fix qldoc
2021-09-08 13:08:28 +02:00
Asger Feldthaus
db1de18cc2
JS: Support transitive callback-passing
2021-09-08 13:08:16 +02:00
Asger Feldthaus
ceaf2b3727
JS: Rename FlowSteps::callback -> exploratoryCallbackStep
2021-09-08 13:08:12 +02:00
Asger Feldthaus
7c94dd94e9
JS: Add type-tracking steps through callback args
2021-09-08 13:08:05 +02:00
Asger Feldthaus
1f6df4e70d
JS: Add callback type tracking test
2021-09-08 13:08:04 +02:00
Anders Schack-Mulligen
1af39f0776
Dataflow: Sync.
2021-09-08 13:02:07 +02:00
Anders Schack-Mulligen
2e9876f58f
Dataflow: Only calculate fastTC for the relevant part of edges.
2021-09-08 13:01:29 +02:00
Anders Fugmann
f91bd91d02
C++: Apply suggested change from code review
2021-09-08 12:38:53 +02:00
Anders Schack-Mulligen
2b7882e6e5
Merge pull request #5032 from aschackmull/dataflow/subpaths
...
Dataflow: Add subpaths query predicate.
2021-09-08 11:52:41 +02:00
Anders Schack-Mulligen
3f5b9d0f54
Merge pull request #6637 from github/alexet/imporve-query
...
Java: Fix performance issues with future versions of codeql.
2021-09-08 11:16:19 +02:00
Anders Fugmann
e93dc0b4c4
C++: Fix comment in getGuardedUpperBound
2021-09-08 11:06:58 +02:00
Rasmus Lerchedahl Petersen
4a5f70e6c8
Python: Reclassify defaultValueFlowStep
...
as a `jumpStep`.
2021-09-08 10:05:31 +02:00
Nick Rolfe
a62aa2b1b2
Merge pull request #269 from github/polynomial_redos
...
Polynomial ReDoS query
2021-09-07 18:31:04 +01:00
jorgectf
4e261c61ae
Optimize concatAndCompareAgainstFullHostRegex
2021-09-07 19:05:03 +02:00
jorgectf
800801177d
Fix taint tracking comment
2021-09-07 19:02:32 +02:00
jorgectf
b802d7903a
Fix OPT_X_TLS_ mandatory options
2021-09-07 19:01:46 +02:00
jorgectf
ee98c0c587
Add start_tls_s() comment and use DataFlow::MethodCallNode instead
2021-09-07 19:00:14 +02:00
Nick Rolfe
414362db8d
Rename .qll to match our naming scheme for other dataflow queries.
2021-09-07 17:38:08 +01:00
Jorge
1bc16fb31e
Apply suggestions from code review
...
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com >
2021-09-07 18:37:33 +02:00
Nick Rolfe
7666d856b7
Merge remote-tracking branch 'origin/main' into polynomial_redos
2021-09-07 17:35:07 +01:00
alexet
81f4822b8d
Java: Fix performance with future optimiser by caching a predicate
2021-09-07 16:38:40 +01:00
alexet
be1d4c04f2
Java: Fix external flow perofrmance with future optimiser.
2021-09-07 16:38:39 +01:00
alexet
726feb3f4d
Java: Fix magic in TC with future optimiser.
2021-09-07 16:38:39 +01:00
Tamás Vajk
f90d1fd70e
Merge pull request #6636 from tamasvajk/fix/stubbing-2
...
C#: Fix member order (yet again) in stubbing
2021-09-07 17:37:29 +02:00
Benjamin Muskalla
9e66ee1da0
Add example to inline flow test docs
2021-09-07 16:47:02 +02:00
Benjamin Muskalla
3641b28c3e
Convert javax-json to InlineFlowTest
2021-09-07 16:47:01 +02:00
Benjamin Muskalla
a6b47208e1
Convert optional to InlineFlowTest
2021-09-07 16:47:01 +02:00
Benjamin Muskalla
2d9b4b33d4
Convert spring to InlineFlowTest
2021-09-07 16:47:01 +02:00
Benjamin Muskalla
da3b7a2b69
Convert json-java to InlineFlowTest
2021-09-07 16:47:00 +02:00
Benjamin Muskalla
ff73e46c95
Convert jackson to InlineFlowTest
2021-09-07 16:47:00 +02:00
Benjamin Muskalla
1ead522705
Convert guava-cache to InlineFlowTest
2021-09-07 16:47:00 +02:00
Benjamin Muskalla
efd5dc94e6
Convert apache-commons-lang3 to InlineFlowTest
2021-09-07 16:47:00 +02:00
Benjamin Muskalla
eba414e31b
Convert apache-collections to InlineFlowTest
2021-09-07 16:46:59 +02:00
Benjamin Muskalla
3bc70f0ce6
Convert containerflow to inline flow test
2021-09-07 16:46:59 +02:00
Benjamin Muskalla
7a0fc6ae61
Migrate jaxson to inline test
2021-09-07 16:46:59 +02:00
Benjamin Muskalla
41891959a3
Fix apache test
2021-09-07 16:46:58 +02:00
Benjamin Muskalla
2d13906e0e
Simplify jaxrs setup
2021-09-07 16:46:58 +02:00
Benjamin Muskalla
24d43689b2
Simplify test setup
2021-09-07 16:46:58 +02:00
Benjamin Muskalla
8830f1531f
Convert some tests to use InlineFlowTest
2021-09-07 16:46:58 +02:00
Benjamin Muskalla
acb055400d
Extract inline flow test
2021-09-07 16:46:57 +02:00
Benjamin Muskalla
d1a1f57e77
Convert taint-format test into inline test
2021-09-07 16:46:56 +02:00
Rasmus Wriedt Larsen
995a8192a9
Merge pull request #6635 from github/RasmusWL/fix-csharp-cwe-tag
...
C#: Fix CWE tag for `cs/insufficient-key-size`
2021-09-07 15:54:42 +02:00
Tom Hvitved
3d4db42da4
Merge pull request #6634 from hvitved/csharp/codeql-manual-build-command
...
C#: Use explicit Code Analysis build command
2021-09-07 15:31:20 +02:00
Tamas Vajk
469993f6d3
C#: Fix member order (yet again) in stubbing
...
With explicit interface implementation, the same member name can show up multiple times in a type declaration. This commit defines an explicit order
for these members.
2021-09-07 15:26:03 +02:00
yoff
43effd2b40
Update python/ql/src/semmle/python/functions/ModificationOfParameterWithDefault.qll
...
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com >
2021-09-07 15:08:50 +02:00
Taus Brock-Nannestad
bea8a457a2
Merge branch 'main' into python-make-annotated-assignment-a-definitionnode
2021-09-07 15:01:01 +02:00
Taus Brock-Nannestad
1ab86892a0
Merge branch 'main' into python-deprecate-importnode
2021-09-07 14:59:12 +02:00
CodeQL CI
5b229e9392
Merge pull request #6574 from asgerf/js/vue-api-graphs
...
Approved by erik-krogh
2021-09-07 05:53:30 -07:00
Taus Brock-Nannestad
79c3ccd56e
Python: Remove import-helper tests
...
As discussed, these are all present in the `ApiGraphs` directory
already (except for the dataflow consistency test, which has been
moved there instead).
2021-09-07 14:50:05 +02:00
Tamás Vajk
d7934865c9
Merge pull request #6628 from tamasvajk/feature/fix-stub-escaping
...
C#: improve stubbing to escape more member names (not just fields)
2021-09-07 14:29:44 +02:00
Benjamin Muskalla
f7ad894495
Fix name of api filter predicate
2021-09-07 14:28:58 +02:00
Taus Brock-Nannestad
5ac32f145f
Merge branch 'main' into python-fix-exceptstmt-gettype
2021-09-07 14:21:13 +02:00
Benjamin Muskalla
22df141761
Rename API name predicate
2021-09-07 14:17:13 +02:00
Taus
51c0ceea38
Python: Update test_import_star.py
...
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com >
2021-09-07 14:15:48 +02:00
Taus Brock-Nannestad
5f5285955b
Merge branch 'main' into python-api-graphs-import-star
2021-09-07 14:13:56 +02:00
Taus
b99c075282
Merge pull request #6460 from yoff/python-regex-parsing-consistency-checks
...
Python: Add regex parsing consistency checks
2021-09-07 13:33:59 +02:00
Nick Rolfe
4d5928ae5a
Add @security-severity tag
2021-09-07 12:15:44 +01:00
Nick Rolfe
8fbe5c0adf
Merge pull request #261 from github/getPrimaryQlClasses
...
Implement getPrimaryQlClasses
2021-09-07 12:02:15 +01:00
Tom Hvitved
8ce7fdc59a
Merge pull request #284 from github/hvitved/instanceof-test
...
Use `instanceof` base classes
2021-09-07 13:01:43 +02:00
Rasmus Wriedt Larsen
8f52089475
C#: Fix CWE tag for cs/insufficient-key-size
...
Since this targets
CWE-326 Inadequate Encryption Strength
> The software stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
> \- https://cwe.mitre.org/data/definitions/326.html
and not
CWE-327: Use of a Broken or Risky Cryptographic Algorithm
> The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information.
> \- https://cwe.mitre.org/data/definitions/327.html
This matches what we do for similar query in Python: https://github.com/github/codeql/blob/main/python/ql/src/Security/CWE-326/WeakCryptoKey.ql
2021-09-07 12:59:10 +02:00
Tamas Vajk
203ca3f91b
C#: improve stubbing to escape more member names (not just fields)
2021-09-07 12:34:23 +02:00
Rasmus Lerchedahl Petersen
fcd346c2af
Python: Add flow from default values
...
to their parameters.
This creates data-flow inconsistencies,
probably because the default values have incorrect enclosing callables
2021-09-07 11:33:09 +02:00
Tom Hvitved
bcaf0658e4
C#: Use explicit Code Analysis build command
2021-09-07 10:58:06 +02:00
Anders Fugmann
ebdda885f9
C++: Update test annotation for OverflowStatic
2021-09-07 10:38:16 +02:00
Rasmus Lerchedahl Petersen
e8644f6f2a
Python: coment out discriminating test
...
The test case has different behaviour between py2/3.
When merging this, we should create an issue to resolve it.
2021-09-07 10:30:38 +02:00
Rasmus Lerchedahl Petersen
b48caaf465
Python: fix reference to PrintNode.qll
2021-09-07 10:19:42 +02:00
Rasmus Lerchedahl Petersen
8729701b66
Merge branch 'main' of github.com:github/codeql into python/port-modification-of-default-value
...
Files have moved around, specifically PrintNode.qll.
2021-09-07 10:13:51 +02:00
Rasmus Lerchedahl Petersen
29cb067769
Python: Remember to update test expectations
2021-09-07 10:13:17 +02:00
Rasmus Lerchedahl Petersen
ae8408bcab
Python: Add missing qldoc
2021-09-07 10:09:02 +02:00
Rasmus Lerchedahl Petersen
4998a48f99
Python: Fix simple guards
2021-09-06 22:40:30 +02:00
Nick Rolfe
060060bc0b
Merge remote-tracking branch 'origin/main' into getPrimaryQlClasses
2021-09-06 19:34:34 +01:00
Chris Smowton
79ff7baaf6
Claim Java 16 support
...
As of https://github.com/github/codeql/pull/6604 we support all new Java 16 features
2021-09-06 17:17:17 +01:00
Tamas Vajk
3a9cf639bd
Change ServiceStack redis sinks to code injection instead of SQL injection
2021-09-06 16:59:31 +02:00
Tamas Vajk
5fa9f16c01
Adjust ServiceStack CSV rows with generic method names
2021-09-06 16:45:21 +02:00
Tom Hvitved
3594794875
Use instanceof base classes in range patterns
2021-09-06 16:15:52 +02:00
Tamas Vajk
f6366e1e1f
Merge branch 'feature/method-name' into feature/service-stack
2021-09-06 15:52:08 +02:00
Tamas Vajk
207d8f6030
Merge branch 'main' into feature/service-stack
2021-09-06 15:46:43 +02:00
Anders Fugmann
9af4d560dd
Merge branch 'main' into andersfugmann/improve_upper_bound
2021-09-06 14:26:58 +02:00
Tamas Vajk
5014ef2337
C#: Add ServiceStack support with CSV data model
2021-09-06 14:06:37 +02:00
Tamas Vajk
43ccc14162
Add ServiceStack stubs and empty test referencing it
2021-09-06 14:05:41 +02:00
Tamas Vajk
e3a49f8213
C#: improve stubbing to escape more member names (not just fields)
2021-09-06 14:02:42 +02:00
Tamas Vajk
270b56af1b
Extend runtime callables to interface members with default implementation
2021-09-06 14:02:42 +02:00
Tamas Vajk
39a88d2e43
Fix dispatch library to handle summarized callables with no runtime target
2021-09-06 14:02:42 +02:00
Erik Krogh Kristensen
85e1c87d14
use the new non-extending-subtypes syntax
2021-09-06 11:19:50 +02:00
Erik Krogh Kristensen
8d4af3ad81
convert field based range pattern to casting based range pattern
2021-09-06 11:05:23 +02:00
Anders Fugmann
ddbaf585ec
Merge branch 'main' into andersfugmann/improve_upper_bound
2021-09-06 10:32:44 +02:00
Anders Fugmann
e4d22ea628
C++: Add comment on why getGuardedUpperBound must have exactly one predecessor
2021-09-06 10:31:32 +02:00
Tom Hvitved
9b3b9a731f
Move instanceof check from charpred in CfgScope
2021-09-06 10:31:16 +02:00
ihsinme
8b0d5a2e7b
Update cpp/ql/src/experimental/Security/CWE/CWE-675/DoubleRelease.qhelp
...
Co-authored-by: Geoffrey White <40627776+geoffw0@users.noreply.github.com >
2021-09-05 22:46:37 +03:00
Andrew Eisenberg
286c102358
Update the docs about qlpacks
...
This is a first pass to fix obvious holes and outdated information, but
we should rethink these docs completely.
2021-09-03 12:50:25 -07:00
Philip Ginsbach
863eede75b
easier second example for instanceof extensions
2021-09-03 16:12:52 +01:00
Calum Grant
51d729a086
Merge pull request #282 from github/add-coc
...
Create CODE_OF_CONDUCT.md
2021-09-03 14:25:44 +01:00
Rasmus Lerchedahl Petersen
913990bc62
Python: Add suggested comments and test case
2021-09-03 14:40:16 +02:00
Harry Maclean
36d5fda400
Merge pull request #260 from github/hmac-url-redirect
...
Add URLRedirect query
2021-09-03 13:36:54 +01:00
Pierre
12c1f43ceb
Create CODE_OF_CONDUCT.md
...
Add COC based on the latest template.
2021-09-03 14:27:04 +02:00
yoff
c6eb795e76
Apply suggestions from code review
...
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com >
2021-09-03 14:23:57 +02:00
Benjamin Muskalla
51475d2fb0
Merge branch 'main' into thirdpartyapitelemtry
2021-09-03 14:23:31 +02:00
Harry Maclean
87253032e2
Add a query for URL redirect vulnerabilities
...
This query finds instances of CWE-601: Redirection to Untrusted Site.
The structure is copied from a query of the same name in the Python
library. We add customisations specific to `ActionController`.
2021-09-03 13:17:14 +01:00
Calum Grant
799c0ff252
Merge pull request #281 from github/add-license
...
Add LICENSE
2021-09-03 13:14:15 +01:00
Benjamin Muskalla
ab5c1d6bdd
Rework filter to exclude simple constructors
2021-09-03 13:38:01 +02:00
Asger Feldthaus
7149ad8ac4
JS: Also mark uses of the exports object as an export in PackageExports
2021-09-03 13:35:30 +02:00
Pierre
bc85a1b825
Add LICENSE file
...
Required step for open-sourcing. This uses the same license at `codeql-ruby`.
2021-09-03 13:10:54 +02:00
Philip Ginsbach
cd646c819d
explain instanceof extensions via charpred instanceof
2021-09-03 10:55:03 +01:00
Benjamin Muskalla
9ed14b438e
Use readble format for APIs
2021-09-03 11:53:18 +02:00
Philip Ginsbach
35b0e83370
simpler first instanceof extension example
2021-09-03 10:52:05 +01:00
Benjamin Muskalla
4b02e266fd
Fix test as we support explicit collection types
2021-09-03 11:37:39 +02:00
Benjamin Muskalla
7d3131ca49
Move usage count into where clause
2021-09-03 11:32:14 +02:00
Benjamin Muskalla
89ce04dcb9
Pull usage count into where clause
2021-09-03 11:26:22 +02:00
Philip Ginsbach
6e025186ab
make clear that instanceof supertypes are not base types
2021-09-03 10:23:58 +01:00
Philip Ginsbach
abaa0633d7
consistently distinguish base types and supertypes
2021-09-03 10:20:14 +01:00
Philip Ginsbach
d2f833d02c
deep implications => implications
2021-09-03 10:13:12 +01:00
Benjamin Muskalla
2edb32f344
Fix naming
2021-09-03 10:59:35 +02:00
Benjamin Muskalla
6ede08e3c9
Remove dead code
2021-09-03 10:53:24 +02:00
james
8c37e90a77
revert a couple of changes
2021-09-03 09:31:54 +01:00
Geoffrey White
f2047ee4d0
C++: Actually fix expected files after layout changes.
2021-09-03 09:13:41 +01:00
Anders Fugmann
d962fc4ce1
C++: Improve predicate upperBound in SimpleRangeAnalysis
...
If an expression has an immediate guardPhi node, this is used as a strict upper bound
2021-09-02 21:46:18 +02:00
Anders Fugmann
c110508b4e
C++: Add tests to expose potential improvements available to SimpleRangeAnalysis
2021-09-02 21:20:33 +02:00
Nick Rolfe
47e5a8fd09
Add test for polynomial ReDoS query
2021-09-02 17:57:56 +01:00
Nick Rolfe
cbe23661ed
Rename exponential ReDoS test directory
2021-09-02 17:57:56 +01:00
Nick Rolfe
d62b41bdf4
Add query for polynomial ReDoS
2021-09-02 17:57:56 +01:00
Geoffrey White
a0b712d44b
C++: Add notice about the SAMATE Juliet tests.
2021-09-02 17:34:48 +01:00
Geoffrey White
d73604d1c5
C++: Fix a few glitches and accept line number changes in expected files.
2021-09-02 17:34:47 +01:00
Geoffrey White
f755659f5d
C++: More directory structure consistency / cleanup.
2021-09-02 17:34:47 +01:00
Geoffrey White
d1ab2d2e8c
C++: Remove some irrelevant macro logic and main functions.
2021-09-02 17:34:46 +01:00
Geoffrey White
fdb4a2acdb
C++: Clean up header comments.
2021-09-02 17:34:46 +01:00
Geoffrey White
75d367a6c5
C++: Add ad-hoc SAMATE Juliet test cases (that were previously internal). Directory structures cleaned up in a few places.
2021-09-02 17:34:45 +01:00
Philip Ginsbach
ee13efbffd
some whitesapce fixes
2021-09-02 17:31:55 +01:00
Philip Ginsbach
dbda1bf5c0
Update docs/codeql/ql-language-reference/types.rst
...
Co-authored-by: Chris Smowton <smowton@github.com >
2021-09-02 17:30:36 +01:00
james
2e995839bb
fix link
2021-09-02 16:46:23 +01:00
james
81a9ce2baa
polish text
2021-09-02 16:40:29 +01:00
Alex Ford
86073776b7
Merge pull request #249 from github/erb-lib
...
Add codeql_ruby.ast.Erb library
2021-09-02 16:26:52 +01:00
Philip Ginsbach
dbc95cadb4
language reference entry for non-extending subtypes
2021-09-02 15:23:39 +01:00
Rasmus Wriedt Larsen
9f590dbf2d
Python: Fix .expected
...
After we now model `db.text()` calls from Flask-SQLAlchemy
2021-09-02 16:04:25 +02:00
Rasmus Wriedt Larsen
414bf12f86
Python: Fix DefaultTextClauseConstruction
2021-09-02 16:03:25 +02:00
Rasmus Wriedt Larsen
88c6d4bb20
Python: Fix .qhelp
2021-09-02 16:02:04 +02:00
Arthur Baars
ab4cc753b0
Revert "Use hotfixed version of codeql/suite-helpers with workaround for bug in released CLI"
...
This reverts commit 9d7b77496e .
2021-09-02 16:01:51 +02:00
Tom Hvitved
b8ec5d7d31
Merge pull request #276 from github/hvitved/api-graphs-comment-typo
...
Fix typo in comment
2021-09-02 12:50:25 +02:00
Rasmus Wriedt Larsen
d55f18f8e3
Python: Add modeling of Flask-SQLAlchemy
2021-09-02 10:48:24 +02:00
Rasmus Wriedt Larsen
f1744890b1
Python: Add tests for Flask-SQLAlchemy
2021-09-02 10:48:15 +02:00
Tom Hvitved
2d0febeb04
Fix typo in comment
2021-09-02 10:24:37 +02:00
Rasmus Wriedt Larsen
c34d6d1162
Python: Add query to handle SQLAlchemy TextClause Injection
...
instead of doing this via taint-steps. See description in code/tests.
2021-09-02 10:19:57 +02:00
Rasmus Wriedt Larsen
81dbe36e99
Python: Promote SQLAlchemy modeling
...
Due to the split between `src/` and `lib/`, I was not really able to do
the next step without having moved the SQLAlchemy modeling over to be in
`lib/` as well.
2021-09-02 10:19:57 +02:00
Rasmus Wriedt Larsen
ba99e21875
Python: Remove modeling of sqlescapy PyPI package
...
I've never seen this being used in real code, and this library doesn't
have a lot of traction, so I would rather not commit to supporting it
(which includes verifying that it actually makes things safe).
Personally I don't think this is the right approach for avoiding SQL
injection either.
2021-09-02 10:19:57 +02:00
Rasmus Wriedt Larsen
91442e100c
Python: Model sessionmaker().begin()
2021-09-02 10:19:57 +02:00
Rasmus Wriedt Larsen
feb2303e1f
Python: Model the underlying DB-API connection
2021-09-02 10:19:57 +02:00
Rasmus Wriedt Larsen
1ab04a7276
Python: Model Connection.execution_options
2021-09-02 10:19:57 +02:00
Rasmus Wriedt Larsen
2acf518037
Python: Model exec_driver_sql
2021-09-02 10:19:57 +02:00
Rasmus Wriedt Larsen
fe143c7dfa
Python: Rewrite most of SQLAlchemy modeling
2021-09-02 10:19:57 +02:00
Rasmus Wriedt Larsen
b39bb24fcf
Python: Add more SQLAlchemy tests
2021-09-02 10:19:57 +02:00
ihsinme
1e88470ad8
Add files via upload
2021-09-02 10:22:49 +03:00
ihsinme
9f4b7255aa
Add files via upload
2021-09-02 10:21:07 +03:00
Tom Hvitved
c3ecae503b
Data flow: Sync files
2021-09-01 19:58:47 +02:00
Tom Hvitved
136c8b5192
Data flow: Improve callMayFlowThroughFwd join order
...
Before:
```
[2021-08-25 09:56:29] (1395s) Tuple counts for DataFlowImpl2::Stage3::callMayFlowThroughFwd#ff/2@111fb3:
15495496 ~5% {5} r1 = SCAN DataFlowImpl2::Stage3::fwdFlowOutFromArg#fffff#reorder_0_2_4_1_3 OUTPUT In.3, In.4, In.2 'config', In.0 'call', In.1
1450611958 ~6335% {5} r2 = JOIN r1 WITH DataFlowImpl2::Stage3::fwdFlow#fffff_03412#join_rhs ON FIRST 3 OUTPUT Lhs.3 'call', Lhs.4, Lhs.2 'config', Rhs.3, Rhs.4
7043648 ~20415% {2} r3 = JOIN r2 WITH DataFlowImpl2::Stage3::fwdFlowIsEntered#fffff#reorder_0_3_4_1_2 ON FIRST 5 OUTPUT Lhs.0 'call', Lhs.2 'config'
return r3
```
After:
```
[2021-08-25 10:57:02] (2652s) Tuple counts for DataFlowImpl2::Stage3::callMayFlowThroughFwd#ff/2@d3e27b:
15495496 ~0% {6} r1 = SCAN DataFlowImpl2::Stage3::fwdFlowOutFromArg#fffff#reorder_0_2_4_1_3 OUTPUT In.0 'call', In.1, In.2 'config', In.3, In.4, In.2 'config'
9236888 ~22% {7} r2 = JOIN r1 WITH DataFlowImpl2::Stage3::fwdFlowIsEntered#fffff#reorder_0_3_4_1_2 ON FIRST 3 OUTPUT Lhs.3, Rhs.3, Rhs.4, Lhs.4, Lhs.5, Lhs.0 'call', Lhs.2 'config'
7043648 ~20415% {2} r3 = JOIN r2 WITH DataFlowImpl2::Stage3::fwdFlow#fffff ON FIRST 5 OUTPUT Lhs.5 'call', Lhs.6 'config'
return r3
```
2021-09-01 19:57:29 +02:00
Tom Hvitved
c176d344ab
Merge pull request #274 from github/hvitved/cfg/may-raise
...
CFG: Model calls that may raise an exception
2021-09-01 17:42:13 +02:00
Tom Hvitved
6e23a9ae7a
Merge pull request #275 from github/hvitved/api-graphs-fix
...
API graphs: Fix bug for resolvable modules
2021-09-01 17:10:27 +02:00
Tom Hvitved
03e91a22bc
API graphs: Performance fixes
2021-09-01 16:57:56 +02:00
Tom Hvitved
ae70af01cd
API graphs: Fix bug for resolvable modules
2021-09-01 16:57:52 +02:00
Tom Hvitved
031a73ff0f
Add API graph test that exhibits a missing edge
2021-09-01 16:56:09 +02:00
Benjamin Muskalla
ee8958ba03
Fix nodes for local taint test
2021-09-01 15:55:59 +02:00
Benjamin Muskalla
c1d34d7d6f
Move Strings to lib
2021-09-01 15:55:39 +02:00
Benjamin Muskalla
190bf90bc8
Replace stringbuilder step with model
2021-09-01 15:41:16 +02:00
Benjamin Muskalla
7ddf7ff211
Track taint from concatenated string
2021-09-01 15:41:16 +02:00
Benjamin Muskalla
d178fe4e5d
Fix failing tests
2021-09-01 15:41:16 +02:00
Benjamin Muskalla
93bc8aa7b2
Fix tests to take trim into account
2021-09-01 15:41:15 +02:00
Benjamin Muskalla
7be179cf6c
Mark String constructor as propagating taint
2021-09-01 15:41:15 +02:00
Benjamin Muskalla
3928ffd30d
Support CharSequence#subSequence
2021-09-01 15:41:15 +02:00
Benjamin Muskalla
b7e608abc9
Model string builder APIs
2021-09-01 15:41:14 +02:00
Benjamin Muskalla
dab626270d
Convert Objects API to csv model
2021-09-01 15:41:14 +02:00
Benjamin Muskalla
5df5805d36
Convert strings to summary model
2021-09-01 15:41:14 +02:00
Benjamin Muskalla
e0d978fd58
Migrate String constructor to model
2021-09-01 15:41:13 +02:00
Tom Hvitved
701eab7b74
Merge pull request #273 from github/hvitved/has-name
...
Add `hasName` predicates
2021-09-01 15:39:39 +02:00
Tom Hvitved
89e6c0e838
CFG: Model calls that may raise an exception
...
In order to avoid dead `rescue`s, we assume that any call that happens in a
`rescue`/`ensure` context may raise an exception.
2021-09-01 14:07:28 +02:00
Tom Hvitved
4eaa31d800
Add hasName predicates
2021-09-01 13:32:19 +02:00
Asger Feldthaus
cc838326e1
JS: Remove old bulk export access getAnExportedModule
2021-09-01 13:28:54 +02:00
Asger Feldthaus
7daa6481e3
JS: Check property name in NodeJSModule.getABulkExportedNode
2021-09-01 13:25:14 +02:00
Asger Feldthaus
4b1f918feb
JS: Extend getABulkExportedNode and use it in PackageExports
2021-09-01 13:24:23 +02:00
Asger Feldthaus
cce3c0256e
JS: Update some comments in Vue
2021-09-01 13:04:40 +02:00
Alex Ford
41e7ef11e6
add missing pragma back
2021-08-31 21:19:56 +01:00
Alex Ford
d47c8ee9a5
format
2021-08-31 21:04:43 +01:00
Tom Hvitved
2d08b0156a
Merge pull request #271 from github/hvitved/cfg/shared
...
Adopt shared CFG library
2021-08-31 19:41:02 +02:00
Alex Ford
20b851a6e0
improve ErbExecutionDirective definition
2021-08-31 17:49:15 +01:00
Alex Ford
df9e0dfcb2
make strictlyBefore a member predicate on Location
2021-08-31 16:24:38 +01:00
Alex Ford
d84731bcc7
Add a library for working with the ERB AST
2021-08-31 16:24:38 +01:00
Harry Maclean
502ad3f9bd
Merge pull request #247 from github/hmac-jump-to-def
...
Jump-to-definition
2021-08-31 16:00:43 +01:00
Harry Maclean
3490e328e1
codeql_ruby -> codeql.ruby
2021-08-31 15:43:02 +01:00
Harry Maclean
d3f683e573
Minor refactor of constantQualifiedName
2021-08-31 15:42:06 +01:00
Harry Maclean
34f02ee622
Fix constantQualifiedName
...
Exclude partial results
Co-authored-by: Alex Ford <alexrford@users.noreply.github.com >
2021-08-31 15:42:06 +01:00
Harry Maclean
91d56cd802
Use dataflow to find method call targets
...
This includes both local and non-local methods, and is also simpler than
the previous definition.
2021-08-31 15:42:06 +01:00
Harry Maclean
cd3192e8f1
Fix ordering for definitionOf
...
Actually select the lexicographically least location, not the greatest.
2021-08-31 15:42:06 +01:00
Harry Maclean
8901eba978
Include constants in jump-to-def query
...
The previous version of this query inadvertently excluded constants
which weren't classes or modules. This version includes them, by
introducing a laxer version of `resolveScopeExpr` that doesn't require
the result to be a `TResolved`.
2021-08-31 15:42:06 +01:00
Harry Maclean
155b385981
Simplify LocalVariable constraint in jump-to-def
2021-08-31 15:42:06 +01:00
Harry Maclean
e72f1399cb
Include class variables in jump-to-def query
2021-08-31 15:42:06 +01:00
Harry Maclean
e84ebe2b94
Include instance variables in jump-to-def query
...
By convention, instance variables are considered to be "defined" in the
`#initialize` method of their containing class. If an instance variable
is written to in `#initialize` and then read elsewhere in the program,
we will point from the read to the write. If it is not written to in
`#initialize` then we won't provide any jump-to-definition information
for it.
2021-08-31 15:42:06 +01:00
Harry Maclean
a16cd8967b
Ignore synthesised reads for jump-to-definition
...
We synthesise variables for things like tuple patterns. For example,
this Ruby code:
a, b = ...
becomes:
__synth__0 = ...
a = __synth__0[0]
b = __synth__0[1]
The `__synth__` variables should be ignored when calculating
jump-to-definition information, since they don't appear in the original
source code.
2021-08-31 15:42:05 +01:00
Harry Maclean
a814010665
Small refactor to constantQualifiedName
2021-08-31 15:42:05 +01:00
Harry Maclean
95e2b8a4a4
Simplify jump-to-def query
...
The expected output format is a tuple (a, b, k) where `a` and `b` are any
`AstNode` subclass and `k` is a string indicating the kind of
definition (e.g. variable, method, ...).
By ensuring that every value in `DefLoc` is a subclass of `Expr` (itself
a subclass of `AstNode`) we can simplify the query by removing all the
use of `getLocation()`.
2021-08-31 15:42:05 +01:00
Harry Maclean
19e135fb6f
Remove redundant imports
2021-08-31 15:42:05 +01:00
Harry Maclean
2fbbabda2d
First draft of a jump-to-definition query
...
TODO: flesh out this message
2021-08-31 15:42:05 +01:00
Nick Rolfe
d1171e08b1
Merge pull request #272 from github/fix_upgrade
...
Fix typo in db upgrade script
2021-08-31 15:34:55 +01:00
Nick Rolfe
ad66f03f90
Fix typo in db upgrade script
2021-08-31 15:23:16 +01:00
Tom Hvitved
eeb68a88b6
Add make target to run tests locally
2021-08-31 14:22:26 +02:00
Tom Hvitved
4677a0832f
Adopt shared CFG library
2021-08-31 13:42:41 +02:00
Tom Hvitved
50158b82c8
Sync shared files
2021-08-31 13:42:25 +02:00
Tom Hvitved
b9745c8e27
Bump codeql submodule
2021-08-31 13:38:52 +02:00
Arthur Baars
60aca018a8
Merge pull request #254 from github/hvitved/drop-files-folders-columns
...
Drop redundant columns from `files` and `folders` relations
2021-08-31 12:30:05 +02:00
Tom Hvitved
c70407ae8c
Update DB stats
2021-08-31 12:19:35 +02:00
Tom Hvitved
652d2a7a72
DB upgrade script
2021-08-31 12:19:35 +02:00
Tom Hvitved
7f03b87142
Drop redundant columns from files and folders relations
2021-08-31 12:16:26 +02:00
Arthur Baars
32253aa868
Merge pull request #266 from github/dbartol/refactor-packs
...
Refactor Ruby into library and query packs
2021-08-31 12:14:00 +02:00
Asger Feldthaus
27f10123c7
JS: Autoformat
2021-08-31 11:19:11 +02:00
Asger Feldthaus
8833ff7854
JS: Use Vue model in Vuex model
2021-08-31 11:19:10 +02:00
Asger Feldthaus
ebf17e10d6
JS: Fixup in getComponentRef()
2021-08-31 11:19:09 +02:00
Asger Feldthaus
607f2d66b8
JS: Rename getASelfRef to getAnInstanceRef
2021-08-31 11:19:08 +02:00
Asger Feldthaus
999f22f548
JS: Fix getOwnOptionsObject
2021-08-31 11:19:08 +02:00
Asger Feldthaus
9f02ae29ec
JS: Autoformat
2021-08-31 11:19:07 +02:00
Asger Feldthaus
7dd65d8ac6
JS: Clean up taint step definitions
...
These are Unit types and so should be kept private as you can't
use them for anything other than getting all taint steps of a certain
type.
Also factors out accesses to 'this'.
2021-08-31 11:19:06 +02:00
Asger Feldthaus
5b0e26c814
JS: Use API graphs a few more places
2021-08-31 11:19:06 +02:00
Asger Feldthaus
4ff135e827
JS: Port class-based components to API graphs
2021-08-31 11:19:05 +02:00
Asger Feldthaus
5cd0996d92
JS: Deprecate getOwnOptionsObject()
2021-08-31 11:19:04 +02:00
Asger Feldthaus
7be4b76abb
JS: Simplify getABoundFunction
2021-08-31 11:19:04 +02:00
Asger Feldthaus
0ee1e8bd97
JS: Rename ExtendedVue to ComponentExtension
2021-08-31 11:19:03 +02:00
Asger Feldthaus
881951368d
JS: Merge VueInstance and ExtendedInstance into one case
2021-08-31 11:19:03 +02:00
Asger Feldthaus
ecda79834d
JS: Remove getOption(name) override subsumed by new implementation
2021-08-31 11:19:02 +02:00
Asger Feldthaus
e4901eda91
JS: Handle .extend called on any component
2021-08-31 11:19:01 +02:00
Asger Feldthaus
2a79817c3b
JS: Add test for "extends"
2021-08-31 11:19:01 +02:00
Asger Feldthaus
4d4443c3cf
JS: Use API graphs in getOption(s)
2021-08-31 11:19:00 +02:00
Asger Feldthaus
f450476b27
JS: Improve handling of default exports in Vue
2021-08-31 11:19:00 +02:00
Asger Feldthaus
cd6a60dc70
JS: Treat default-export from .vue file as entry point
2021-08-31 11:18:59 +02:00
Asger Feldthaus
b223049682
JS: Add getComponentRef()
2021-08-31 11:18:58 +02:00
Asger Feldthaus
b9d1b5584e
JS: Add API-node version of getOwnOptions
2021-08-31 11:18:58 +02:00
Asger Feldthaus
63b7c6a8d9
JS: Use API:: classes for clarity (no semantic change)
2021-08-31 11:18:57 +02:00
Asger Feldthaus
f7f69dc3ab
JS: Make MkExtendedInstance handle cross-module flow
2021-08-31 11:18:56 +02:00
Asger Feldthaus
76c38a564d
JS: Port vue() to API graphs
2021-08-31 11:18:56 +02:00
Tom Hvitved
7fc536db15
Data flow: Add precise call contexts to stage 2
2021-08-31 10:44:33 +02:00
Rasmus Lerchedahl Petersen
a01fca5d48
Merge branch 'main' of github.com:github/codeql into python-regex-parsing-consistency-checks
...
To fix conflicts
2021-08-30 18:40:12 +02:00
yoff
13c5857241
Update python/ql/src/semmle/python/RegexTreeView.qll
...
Co-authored-by: Taus <tausbn@github.com >
2021-08-30 18:38:38 +02:00
Rasmus Lerchedahl Petersen
a855074588
Python: Try to remove py2/3 differences
2021-08-30 15:41:51 +02:00
Rasmus Lerchedahl Petersen
0de621edf9
Python: Add qldoc
2021-08-30 15:03:58 +02:00
Tom Hvitved
789e2e48cf
C#: Remove temporary dispatch restriction
2021-08-30 14:49:04 +02:00
Rasmus Lerchedahl Petersen
1903cb8f82
Python: Add change note
2021-08-30 11:27:55 +02:00
Rasmus Lerchedahl Petersen
a762373ad6
Python: Implement simple barrier guard
...
The one found in the original test case
2021-08-30 11:04:27 +02:00
Erik Krogh Kristensen
81742528a2
add test
2021-08-27 10:04:39 +02:00
Erik Krogh Kristensen
1b6e1dbd13
include property writes in super-classes when reading a property in a sub-class
2021-08-27 10:04:39 +02:00
Erik Krogh Kristensen
285c659541
add src as a potential unsafe DOM property name for js/xss-through-dom
2021-08-27 10:04:39 +02:00
Dave Bartolomeo
42629b969f
Move initial dbscheme
2021-08-26 19:43:06 -04:00
Dave Bartolomeo
593f3b62fe
Fix paths in upgrade script check
2021-08-26 19:26:26 -04:00
Dave Bartolomeo
9c03a02965
Update lock file for hotfix
2021-08-26 19:13:48 -04:00
Dave Bartolomeo
2c1620f25e
Move missed library file
2021-08-26 18:59:58 -04:00
Dave Bartolomeo
9d7b77496e
Use hotfixed version of codeql/suite-helpers with workaround for bug in released CLI
2021-08-26 18:50:04 -04:00
Dave Bartolomeo
11ad664bfb
Updated pack versions and lock files
2021-08-26 18:50:04 -04:00
Dave Bartolomeo
eb412fb31e
Fix PowerShell version of extractor pack script
2021-08-26 18:50:04 -04:00
Dave Bartolomeo
56332a676d
Ignore .codeql output directories
2021-08-26 18:50:04 -04:00
Arthur Baars
ac2c315839
Fix merge conflicts during rebase
2021-08-26 18:48:53 -04:00
Arthur Baars
0afcb9cc86
Workaround for compilation failure
2021-08-26 18:42:06 -04:00
Arthur Baars
817f8747de
Fix build
2021-08-26 18:42:02 -04:00
Arthur Baars
17fc6ab72c
Refactor into separate library and query packs
2021-08-26 18:40:06 -04:00
jorgectf
64b305cf7a
Add .qhelp along with its example
2021-08-26 23:29:45 +02:00
Alex Ford
ee6c809281
Merge pull request #262 from github/action-view-1
...
Start modelling ActionView
2021-08-26 15:22:55 +01:00
Tom Hvitved
348b12c109
Merge pull request #268 from github/hvitved/db-upgrade-pr-check
...
Add DB upgrade script check
2021-08-26 16:06:06 +02:00
Tom Hvitved
42daf5b6d3
Add DB upgrade script check
2021-08-26 15:55:18 +02:00
Alex Ford
9571e7bccc
drop ViewComponent parts from the ActionView library
2021-08-26 14:45:47 +01:00
Alex Ford
a3ae5bcec4
improve ActionControllerHelperMethod doc
2021-08-26 14:12:27 +01:00
Rasmus Lerchedahl Petersen
49ae549e89
Python: Implement modifying syntax
2021-08-26 14:29:18 +02:00
Rasmus Lerchedahl Petersen
097c23e437
Python: add inline expectations test
...
Consider removing the original test
2021-08-26 14:08:52 +02:00
jorgectf
786edb72df
Update .expected
2021-08-26 12:36:34 +02:00
Jorge
d458464e6b
Apply suggestions from code review
...
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com >
2021-08-26 12:20:09 +02:00
Nick Rolfe
4ec30b2a4b
Merge pull request #267 from github/erik-krogh/redosUnicode
...
use toUnicode in ReDoSUtil.qll
2021-08-26 11:08:31 +01:00
Rasmus Lerchedahl Petersen
d834cec9b9
Python: test simple sanitizer
2021-08-26 11:31:20 +02:00
Rasmus Lerchedahl Petersen
8614563b42
Python: More tests of syntactic constructs
2021-08-26 10:56:41 +02:00
Erik Krogh Kristensen
ff27a0c894
use toUnicode in ReDoSUtil.qll
2021-08-26 08:46:51 +00:00
Alex Ford
4a4b2445dc
Clean up how we map between Rails actions and default associated template files
2021-08-26 04:57:15 +01:00
Rasmus Lerchedahl Petersen
5bff5188ac
Python: switch from negative to positive list
...
This should avoid potentially terrible performance.
Also noted the missing syntactic constructs,
as I went through the documnetation.
2021-08-25 23:52:42 +02:00
Nick Rolfe
ffd80fcc88
Merge pull request #263 from github/bump_ts
...
Bump tree-sitter versions to pick up parsing fixes
2021-08-25 16:35:23 +01:00
Harry Maclean
4cbd848497
Merge pull request #264 from github/hmac-dependabot
...
Enable dependabot on the Rust projects
2021-08-25 16:34:29 +01:00
Harry Maclean
0bd7e5914f
Enable dependabot on the Rust projects
...
Add a dependabot.yml file to trigger daily dependabot updates on the
four Rust projects in the codebase:
- `node_types`
- `generator`
- `extractor`
- `autobuilder`
2021-08-25 15:35:31 +01:00
Nick Rolfe
3b0055a7c0
Use published crate for tree-sitter-ruby 0.19
2021-08-25 14:32:01 +01:00
Nick Rolfe
bc06817611
Add ERB comment as regression test for parsing bug
2021-08-25 12:43:33 +01:00
Nick Rolfe
289b59d3b0
Bump tree-sitter versions to pick up parsing fixes
...
Particularly, in tree-siter-embedded-template
2021-08-25 11:58:56 +01:00
Alex Ford
abc283ee8a
remove ErbFile refs
2021-08-24 17:22:35 +01:00
Alex Ford
e403fc77d3
tests
2021-08-24 17:21:22 +01:00
Alex Ford
d628716c42
extend ActionController tests
2021-08-24 17:21:22 +01:00
Alex Ford
41ff10c908
extend modelling of ActionController, and start modelling ActionView
2021-08-24 17:21:22 +01:00
Rasmus Lerchedahl Petersen
e865a290de
Python: straight port of query
...
The old query uses `pointsTo` to limit the sinks
to methods on lists and dictionaries.
That constraint is omitted here which could hurt performance.
2021-08-24 16:35:11 +02:00
Rasmus Lerchedahl Petersen
e3765ced78
Python: Add tests for modification of defaults
2021-08-24 16:35:11 +02:00
Nick Rolfe
5e783e4798
Implement getPrimaryQlClasses
2021-08-24 14:49:56 +01:00
james
18440710b4
fix typos
2021-08-23 14:02:53 +01:00
james
66bdbf4a28
address review comments
2021-08-23 11:35:04 +01:00
james
dbf7487a9b
address review comments
2021-08-23 11:34:48 +01:00
Rasmus Lerchedahl Petersen
34d7772a0d
Python: Move constraints into pranch charpreds
...
For sequences and alternations, we require at least one child.
Otherwise, we wish to represent the term differently.
This avoids multiple representations.
2021-08-23 11:44:00 +02:00
Nick Rolfe
9c17e00645
Merge pull request #256 from github/syncRedos
...
sync ReDoSUtil.qll with python/JS
2021-08-23 10:11:16 +01:00
Rasmus Lerchedahl Petersen
c4554836ca
Python: merge test.py into unittests.py
2021-08-19 10:24:32 +02:00
Rasmus Lerchedahl Petersen
3c647c65bf
Python: update comment
2021-08-19 10:21:19 +02:00
Rasmus Lerchedahl Petersen
21f683d531
Python: clean up stray coments
2021-08-18 16:59:35 +02:00
james
dcbf766217
add new article to toc
2021-08-18 12:14:48 +01:00
james
8443d344a2
correct article name
2021-08-18 11:58:42 +01:00
james
18b8244406
fix link
2021-08-18 11:47:16 +01:00
james
429decd7b6
tweak sojme text
2021-08-18 11:38:03 +01:00
james
ad2850dd5d
add new tutorial
2021-08-18 11:27:53 +01:00
james
babec9bf79
add data flow debugging guide
2021-08-18 11:26:51 +01:00
Harry Maclean
a2115f41e8
Merge pull request #259 from github/hmac-print-ast
...
Don't include desugared nodes in the printed AST
2021-08-18 09:16:36 +01:00
Benjamin Muskalla
99e19e6d59
Fix predicate to only match the current API
2021-08-17 16:26:08 +02:00
Benjamin Muskalla
035f7b57e9
Improve query name
2021-08-17 16:25:49 +02:00
Harry Maclean
e82c21d35d
Don't include desugared nodes in the printed AST
...
The base `PrintAstConfiguration` class already has a predicate for
filtering out desugared nodes - this change just makes use of it in the
query.
This fixes https://github.com/github/codeql-team/issues/408 , which was
caused by including nodes representing the desugaring of
a[b] = c
in the query output. This would result in multiple edges to the same
target node (one from the surface AST and another from the desugared
AST), which the VSCode AST viewer cannot handle.
2021-08-17 15:20:30 +01:00
Arthur Baars
df4fb23f37
Merge pull request #246 from github/aibaars/tweaks
...
Add an example snippet query
2021-08-17 12:42:02 +02:00
Arthur Baars
9b877dc6e1
Add an example snippet query
2021-08-17 11:29:44 +01:00
Rasmus Lerchedahl Petersen
dee5535fbb
Python: condense tests
...
This also avoids potential licensing issues.
2021-08-17 11:24:39 +02:00
Tom Hvitved
50cfd9c318
Merge pull request #257 from github/hvitved/cfg/erb
...
CFG: Allow `erb` top-level scopes
2021-08-17 11:21:44 +02:00
Arthur Baars
115a13f50c
Merge pull request #258 from github/qltest-no-beta
...
Exclude beta releases of code-cli for qltest job
2021-08-17 11:09:53 +02:00
Alex Ford
8427a6bcee
exclude beta releases of code-cli for qltest job
2021-08-17 09:57:52 +01:00
Tom Hvitved
394c27a279
CFG: Allow erb top-level scopes
2021-08-17 10:46:15 +02:00
Benjamin Muskalla
1d3bcdf522
Align tests with new query structure
2021-08-16 21:55:00 +02:00
Benjamin Muskalla
87ef540b52
Split out queries showing supported APIs
2021-08-16 16:38:32 +02:00
Benjamin Muskalla
89f4a35273
Remove filter to see all unsupported APIs
2021-08-16 15:40:53 +02:00
Erik Krogh Kristensen
5e63b0b132
add RegExpSubPattern.getOperand
2021-08-16 12:14:53 +00:00
Erik Krogh Kristensen
8bd663a7ce
sync ReDoSUtil.qll with python/JS
2021-08-16 12:04:22 +00:00
Rasmus Lerchedahl Petersen
6be78d442c
Python: fix compilation
2021-08-16 10:35:33 +02:00
Rasmus Lerchedahl Petersen
2df846ee4b
Merge branch 'python-regex-parsing-consistency-checks' of github.com:yoff/codeql into python-regex-parsing-consistency-checks
2021-08-12 13:34:11 +02:00
Rasmus Lerchedahl Petersen
54e65ce765
Python: Add consistency tests
...
for all the projects that went out of disk as a result of ReDoS
2021-08-12 13:33:44 +02:00
yoff
61bbddeb0c
Apply suggestions from code review
...
Co-authored-by: Erik Krogh Kristensen <erik-krogh@github.com >
2021-08-12 09:39:04 +02:00
Alex Ford
0f6c464d27
Merge pull request #251 from github/aibaars/test
...
Add integration test
2021-08-11 16:54:47 +01:00
Benjamin Muskalla
8aba0b04bc
Add QLDoc for all shared libraries
2021-08-11 16:07:24 +02:00
Benjamin Muskalla
26ffe6c03d
Add tests for telemetry queries
2021-08-11 15:32:09 +02:00
Benjamin Muskalla
6287e6d8e9
Filter unused API callsites
2021-08-11 15:31:56 +02:00
Benjamin Muskalla
ec7f4d18e1
Avoid duplicates and support modular runtime
2021-08-11 15:31:33 +02:00
Rasmus Lerchedahl Petersen
c08f94ec04
Python: Fix parsing of octal escapes
2021-08-11 15:01:26 +02:00
Rasmus Lerchedahl Petersen
34b054ff53
Python: Add consistency checks
2021-08-11 14:58:27 +02:00
Arthur Baars
f26f8c1e05
Add integration test
2021-08-11 12:54:30 +02:00
Tamas Vajk
2437546009
Merge branch 'main' into feature/service-stack
2021-08-10 15:16:17 +02:00
Alex Ford
4d6d6a4016
Merge pull request #236 from github/more-concepts
...
Port some concepts to Concepts.qll
2021-08-10 12:42:40 +01:00
Calum Grant
e29e61fd3e
Merge pull request #250 from github/aibaars-patch-2
...
Use strict 3 digit semantic version number
2021-08-10 11:41:15 +01:00
Benjamin Muskalla
8127f63b1e
Only include APIs without support
2021-08-10 12:05:16 +02:00
Benjamin Muskalla
26d4269071
Use FlowSources for coverage tracking
2021-08-10 12:02:56 +02:00
Arthur Baars
da464511ec
Use strict 3 digit semantic version number
2021-08-10 12:02:54 +02:00
Benjamin Muskalla
c48586ff80
Implement coverage tracking using dataflow nodes
2021-08-10 11:38:01 +02:00
Benjamin Muskalla
5b55a83aaa
Use basename for jars
2021-08-10 11:37:19 +02:00
Aditya Sharad
0b64ef2579
Merge pull request #248 from github/hmakholm/pr/windows-autobuilder
...
attempt to fix Windows autobuilder script
2021-08-09 09:49:17 -07:00
Henning Makholm
d9880075cc
attempt to fix Windows autobuilder script
2021-08-09 18:35:45 +02:00
Tom Hvitved
c0049bf161
Merge pull request #229 from github/hvitved/api-graphs/remove-mk-module
...
API graphs: Remove `MkModule`
2021-08-09 13:10:17 +02:00
Tom Hvitved
ae837d9f7a
API graphs: Remove restriction on top-level constants
2021-08-09 12:59:36 +02:00
Jordy Zomer
a3bacc76f1
Update cpp/ql/src/experimental/Security/CWE/CWE-787/UnsignedToSignedPointerArith.ql
...
Co-authored-by: intrigus-lgtm <60750685+intrigus-lgtm@users.noreply.github.com >
2021-08-05 23:31:12 +02:00
Jordy Zomer
cf40d0ae4d
Fix a typo unsiged -> unsigned
2021-08-05 16:40:49 +02:00
Jordy Zomer
489ac04f86
Remove author tag
2021-08-05 12:34:31 +02:00
Arthur Baars
e8f6cb65b8
Merge pull request #245 from github/aibaars/tweaks
...
Move UseDetect.ql to experimental for now
2021-08-04 16:05:06 +02:00
Arthur Baars
23f423ad66
Merge pull request #242 from github/regex_parsing_fixes
...
Regex parsing fixes
2021-08-04 16:04:54 +02:00
Arthur Baars
9ca0e81953
Move UseDetect to experimental for now
2021-08-04 15:52:48 +02:00
Arthur Baars
8ded688b72
Add queries.xml for legacy tooling
2021-08-04 14:34:20 +02:00
Tom Hvitved
0eaeb3b5a6
Rename moduleImport to getTopLevelMember
2021-08-04 10:57:57 +02:00
Tom Hvitved
8451286754
API graphs: Remove MkModule
2021-08-04 10:28:30 +02:00
Jordy Zomer
19bb8e8c17
Make requested changes
2021-08-03 21:54:04 +02:00
Jordy Zomer
e07516585a
cpp: Add query to detect unsigned integer to signed integer conversions used in pointer arithmetics
2021-08-03 19:08:47 +02:00
Nick Rolfe
78b64dad71
Merge pull request #244 from github/script_cleanup
...
Tidy up shell scripts
2021-08-03 11:27:32 +01:00
Nick Rolfe
52ecc2c152
fix path to create-extractor-pack.sh
2021-08-03 11:14:23 +01:00
Nick Rolfe
f2af68f8cf
Clean up script file locations
2021-08-02 18:21:50 +01:00
Arthur Baars
2c8b1fa6da
Merge pull request #231 from github/aibaars/makefile
...
Add makefile
2021-08-02 18:31:16 +02:00
Arthur Baars
38f82ffc3c
Update Makefile
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-08-02 18:01:59 +02:00
Benjamin Muskalla
60c7003667
Optimize return type check
2021-08-02 17:14:44 +02:00
Benjamin Muskalla
fda394858b
Turn external API query into diagnostics query
...
* Expose (partial) CSV model for the API
* Rework and simplify predicates
2021-08-02 17:14:44 +02:00
Benjamin Muskalla
8595ae71f7
Simplify api coverage detection
...
Fixes a bug that doesn't take super types into account
when computing the usage of a specific API.
2021-08-02 17:14:44 +02:00
Benjamin Muskalla
3365634259
Expose csv parameter format predicate
2021-08-02 17:14:44 +02:00
Benjamin Muskalla
aab633eced
Reformat
2021-08-02 17:14:43 +02:00
Benjamin Muskalla
2064915d3b
Fold JDK API query into external API query
2021-08-02 17:14:43 +02:00
Benjamin Muskalla
0c04c9a2c2
Fix aggregation of jar usages
2021-08-02 17:14:43 +02:00
Benjamin Muskalla
722889e881
Make id unique
2021-08-02 17:14:42 +02:00
Benjamin Muskalla
d9285e78c0
Add query to collect external API calls
2021-08-02 17:14:42 +02:00
Benjamin Muskalla
07303ccbb3
Fix formatting
2021-08-02 17:14:42 +02:00
Benjamin Muskalla
b9f6b60c4d
Introduce query to capture external libraries
2021-08-02 17:14:41 +02:00
Benjamin Muskalla
32f52ac30d
Improve column names
2021-08-02 17:14:41 +02:00
Benjamin Muskalla
18e3763f90
Expose whether APIs are already supported
2021-08-02 17:14:41 +02:00
Benjamin Muskalla
9b6ae9029f
Introduce query for capture JDK API usage
2021-08-02 17:14:40 +02:00
Alex Ford
403dee279d
add Node#getALocalSource predicate
2021-08-02 15:56:36 +01:00
Alex Ford
56139ccf93
port some concepts to Concepts.qll
2021-08-02 15:56:36 +01:00
Arthur Baars
58a6f5a783
Address comments
2021-08-02 16:12:50 +02:00
Arthur Baars
730b6d8e6c
Add makefile
2021-08-02 16:12:50 +02:00
Arthur Baars
2f491a1924
Merge pull request #230 from github/redos-enable-tounicode
...
enable unicode parsing in the ReDoS query
2021-08-02 10:42:09 +02:00
Erik Krogh Kristensen
632ad518f0
enable unicode parsing in the ruby ReDoS query
2021-08-02 07:13:41 +00:00
Arthur Baars
d986bea317
Merge pull request #238 from github/aibaars/extract-erb
...
Extract ERB tags
2021-07-29 19:21:32 +02:00
Arthur Baars
00a0b93172
Add erb file
2021-07-29 19:09:56 +02:00
Nick Rolfe
4007e85991
Incorporate changes from Python PR
2021-07-29 17:25:39 +01:00
Nick Rolfe
3abe047cac
Fix parsing of POSIX bracket expressions.
...
The docs are misleading. [[:alpha:]] is actually a character class
*containing* a POSIX bracket expression, and that means you can have
expressions like [[:alpha:][:digit:]_?!]
2021-07-29 17:24:51 +01:00
Nick Rolfe
5d336d8e1d
Make some predicates/classes/imports private
2021-07-29 17:17:11 +01:00
Nick Rolfe
e757d2e654
Merge pull request #241 from github/fix_yml
...
Fix invalid file-type identifier
2021-07-29 12:05:10 +01:00
Arthur Baars
c568162256
Use a single TrapWriter
...
The output of two distinct TrapWriters should not be written to the
same TRAP file because this causes name clashes between TRAP labels.
2021-07-29 12:50:27 +02:00
Nick Rolfe
4aacdafb38
Fix invalid file-type identifier
...
Upper-case characters are not allowed.
2021-07-29 11:49:22 +01:00
Arthur Baars
cc1bdf1fc3
Add charpred to RubyFile class
2021-07-29 11:48:35 +02:00
Arthur Baars
fcf2d4cbd2
Apply suggestions from code review
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-07-29 09:02:57 +02:00
Arthur Baars
1d245b8d2e
Merge pull request #237 from github/aibaars/rules-sarif
...
Build/Release: create rules.sarif file
2021-07-27 18:49:50 +02:00
Arthur Baars
dacd3f3d19
Update dbscheme stats
2021-07-27 18:43:51 +02:00
Arthur Baars
4d18ec226a
Fix dataset_measure.yml
2021-07-27 18:43:51 +02:00
Arthur Baars
38eb6c112f
Add ERB extraction
2021-07-27 18:43:51 +02:00
Arthur Baars
768a751271
Add upgrade script
2021-07-27 18:43:51 +02:00
Arthur Baars
866ff7b1f6
Replace Generated module with Ruby
2021-07-27 18:43:44 +02:00
Arthur Baars
02bf895a4a
Update dbscheme type references
2021-07-27 18:42:21 +02:00
Arthur Baars
2e10f8f054
Prefix dbscheme entries with language name
2021-07-27 18:17:19 +02:00
Arthur Baars
fe868e4c05
Ruby-Generator: add --dbscheme and --library flags
2021-07-27 18:17:19 +02:00
Arthur Baars
fc8f5919f3
Remove Ruby specific parts from FileSystem.qll
2021-07-27 18:17:15 +02:00
Arthur Baars
58c93bfdca
Build/Release: create rules.sarif file
2021-07-27 12:29:27 +02:00
Jorge
f02b6d60a5
Merge branch 'github:main' into jorgectf/python/ldapinsecureauth
2021-07-22 18:49:51 +02:00
jorgectf
b03e75e3d1
Extend ldap3's start_tls and fix tests
2021-07-22 18:42:41 +02:00
jorgectf
a34d6d390e
Port to ApiGraphs and finish the query
2021-07-22 18:34:57 +02:00
jorgectf
edb273ace5
Merge remote-tracking branch 'origin/jorgectf/python/ldapimproperauth' into jorgectf/python/ldapinsecureauth
2021-07-22 02:51:19 +02:00
Taus
6591a86aad
Python: Add test cases
...
I debated whether to add a
`MISSING: use=moduleImport("builtins").getMember("print").getReturn()`
annotation to the last line.
Ultimately, I decided to add it, as we likely _do_ want this information
to propagate into inner functions (even if the value of `var2` may
change before `func4` is called).
2021-07-20 13:26:35 +00:00
Taus
e53b86fbbc
Python: Apply suggestions from code review
...
Co-authored-by: Rasmus Wriedt Larsen <rasmuswriedtlarsen@gmail.com >
2021-07-20 15:19:45 +02:00
Taus
bbcbcefedc
Python: Add false negative test case.
2021-07-20 12:54:06 +00:00
Taus
233ae5a54b
Python: Fix FP in py/unused-local-variable
...
This is only a temporary fix, as indicated by the TODO comment.
The real underlying issue is the fact that `isUnused` is defined in
terms of the underlying SSA variables (as these are only created
for variables that are actually used), and the fact that annotated
assignments are always considered to redefine their targets, which may
not actually be the case.
Thus, the correct fix would be to change the extractor to _disregard_
mere type annotations for the purposes of figuring out whether an
SSA variable should be created or not.
However, in the short term the present fix is likely sufficient.
2021-07-20 12:13:44 +00:00
Taus
8b3fa789da
Python: Add AnnAssign DefinitionNode
...
This was a source of false positives for the
`py/uninitialized-local-variable` query, as exemplified by the test
case.
2021-07-20 11:57:26 +00:00
Taus
f91e826781
Python: Add test case
2021-07-20 11:57:12 +00:00
Arthur Baars
3790611ca1
Merge pull request #233 from github/tausbn/bump-typetrackingnode-changes
...
Bump `codeql` submodule
2021-07-20 13:24:30 +02:00
Porcuiney Hairs
c6c925d67a
Python : Improve Xpath Injection Query
2021-07-20 03:31:30 +05:30
Nick Rolfe
8d21f95ffc
Merge pull request #235 from github/comment_fix
...
Move comment so it's not treated as part of the precision metadata
2021-07-19 12:39:13 +01:00
Nick Rolfe
ce35d74447
Move comment so it's not treated as part of the precision metadata
2021-07-19 12:29:16 +01:00
Calum Grant
8d71d09b94
Merge pull request #234 from github/calumgrant/security-severities
...
Add security-severity metadata
2021-07-16 15:40:03 +01:00
Calum Grant
46a03795c2
Add security-severity metadata
2021-07-16 14:05:54 +01:00
Taus
4f3f93f267
Python: Autoformat
2021-07-16 12:22:24 +00:00
Taus
3fd0ec74f0
Python: Deprecate importNode
...
Unsurprisingly, the only thing affected by this was the `import-helper`
tests. These have lost all of the results relating to `ImportMember`s,
but apart from that the underlying behaviour should be the same.
I also limited the test to only `CfgNode`s, as a bunch of `EssaNode`s
suddenly appeared when I switched to API graphs.
Finally, I used `API::moduleImport` with a dotted name in the type
tracking tests. This goes against the API graphs interface, but I think
it's more correct for this use case, as these type trackers are doing
the "module attribute lookup" bit manually.
2021-07-16 11:38:30 +00:00
Taus
258f85d6d0
Add defaultImplicitTaintRead
2021-07-15 15:52:59 +00:00
Taus
dc4d353a01
Bump shared dataflow library
2021-07-15 15:08:59 +00:00
Taus
ec645725f0
Bump codeql submodule
...
Syncs up the shared type tracking implementation with Python.
2021-07-15 14:35:33 +00:00
mr-sherman
04940a1105
Create 2021-07-14-service-stack-support.md
2021-07-14 15:54:28 -04:00
Taus
5a9fca48e8
Python: Fix ExceptStmt::getType
...
We were not supporting `except` statements handling multiple exception
types (specified as a tuple) correctly, instead just returning the
tuple itself as the "type" (which makes little sense).
To fix this, we explicitly extract the elements of this node, in the
case where it _is_ a tuple.
This is a change that can potentially affect many queries (as `getType`
is used in quite a few places), so some care should be taken to
ensure that this does not adversely affect performance.
2021-07-14 14:03:49 +00:00
Taus
ec9063b4a5
Python: Add test case for github/codeql#6227
2021-07-14 13:52:32 +00:00
Tom Hvitved
42c06bfde4
Merge pull request #226 from github/hvitved/const-flow
...
Data flow through constants
2021-07-14 13:21:07 +02:00
Tom Hvitved
9463927409
Address review comments
2021-07-14 11:05:55 +02:00
Taus
c3789811c8
Python: Support import * in API graphs
2021-07-13 18:22:51 +00:00
Taus
8b6b4dde69
Python: Refactor built-ins logic
...
This will make it possible to reuse for names defined in `import *`.
2021-07-13 18:20:25 +00:00
Taus
df8a6b984a
Python: Add import * tests
...
Moves the current test out of `test.py`, as otherwise any unknown global
(like, say, `sink`) would _also_ be considered to be something
potentially defined in `unknown`.
2021-07-13 17:46:59 +00:00
Arthur Baars
64a55ba6cf
Merge pull request #232 from github/regexp_test_order
...
Stabilise node ordering for regexp parsing test
2021-07-13 17:36:21 +02:00
Nick Rolfe
1fe5162b67
Stabilise node ordering for regexp parsing test
2021-07-13 16:18:21 +01:00
Tom Hvitved
23447e6d58
Reduce size of lookupMethodOrConst
2021-07-02 14:02:26 +02:00
Tom Hvitved
bf696df788
Data flow through constants
2021-07-02 14:02:26 +02:00
Tom Hvitved
3b6e5881c8
Update constants.rb test
2021-07-02 14:02:26 +02:00
Arthur Baars
0eae89a41b
Merge pull request #228 from github/qhelp
...
QHelp preview
2021-07-02 14:00:51 +02:00
Arthur Baars
5afd3c7846
Merge pull request #213 from github/aibaars/api-graphs2
...
First version of ApiGraphs
2021-07-02 13:58:00 +02:00
Arthur Baars
48ad0aa1ee
Escape file paths
2021-07-02 13:51:22 +02:00
Arthur Baars
b2ba8e664c
Handle .inc.qhelp files
2021-07-02 13:32:43 +02:00
Arthur Baars
20570eb1d1
QHelp preview
2021-07-02 13:10:51 +02:00
Tom Hvitved
703e9e726d
Merge pull request #225 from github/hvitved/private-methods
...
Model private methods and "main objects"
2021-07-02 11:02:41 +02:00
Tom Hvitved
330b33638e
Address review comments
2021-07-02 10:41:10 +02:00
Tom Hvitved
52529d590b
Model private methods and "main objects"
2021-07-02 10:41:06 +02:00
Tom Hvitved
9de4ed4d4d
Add tests for private methods
2021-07-02 10:39:49 +02:00
Tom Hvitved
8de1eedb41
Merge pull request #227 from github/hvitved/expose-call-graph
2021-07-01 18:29:14 +02:00
Tom Hvitved
c3cff3e113
Expose call graph through Call::getATarget()
2021-07-01 16:40:45 +02:00
Nick Rolfe
d99b5510e5
Merge pull request #219 from github/regex
...
Add regexp parser and exponential ReDoS query
2021-06-30 17:23:29 +01:00
Alex Ford
7cc6b3a7b0
Merge pull request #224 from github/sqli-override-fp
...
rb/sql-injection: fix FPs stemming from not accounting for overridden methods
2021-06-30 17:20:14 +01:00
Alex Ford
3f76075fe6
improve some rails framework tests
2021-06-29 13:56:28 +01:00
Alex Ford
31cbf818ab
fix rb/sql-injection FPs due to not accounting for overridden ActiveRecord methods
2021-06-29 13:54:15 +01:00
Nick Rolfe
97ae9ed181
Add more qldoc comments from Python version
...
Co-authored-by: Alex Ford <alexrford@users.noreply.github.com >
2021-06-29 11:22:47 +01:00
Tom Hvitved
20f239fd0a
Improve performance of seqChild/4
...
Gets rid of the following bad join-order
```
[2021-06-29 09:40:44] (5s) Starting to evaluate predicate RegExpTreeView::seqChild#fffff#reorder_0_1_2_4_3/5@i2#fe59dz (iteration 2)
[2021-06-29 09:46:34] (354s) Tuple counts for RegExpTreeView::seqChild#fffff#reorder_0_1_2_4_3/5@i2#fe59dz:
222277 ~0% {5} r1 = SCAN RegExpTreeView::RegExpTerm#ffff#prev_delta OUTPUT In.1 're', In.2 'start', In.3, 0, In.0 'result'
207749 ~3% {4} r2 = JOIN r1 WITH ParseRegExp::RegExp::item_dispred#fff ON FIRST 3 OUTPUT Lhs.0 're', Lhs.1 'start', 0, Lhs.4 'result'
11636 ~2% {5} r3 = JOIN r2 WITH ParseRegExp::RegExp::sequence_dispred#fff ON FIRST 2 OUTPUT 0, Lhs.3 'result', Lhs.0 're', Lhs.1 'start', Rhs.2 'end'
222277 ~0% {4} r4 = SCAN RegExpTreeView::RegExpTerm#ffff#prev_delta OUTPUT In.1 're', In.2 'start', In.3, In.0 'result'
207749 ~0% {3} r5 = JOIN r4 WITH ParseRegExp::RegExp::item_dispred#fff ON FIRST 3 OUTPUT Lhs.1, Lhs.3 'result', Lhs.0 're'
902017671 ~2% {3} r6 = JOIN r5 WITH RegExpTreeView::RegExpTerm#ffff#reorder_3_0_1_2#prev ON FIRST 1 OUTPUT Lhs.2 're', Lhs.1 'result', Rhs.1
1193975963 ~2% {5} r7 = JOIN r6 WITH ParseRegExp::RegExp::sequence_dispred#fff ON FIRST 1 OUTPUT Lhs.0 're', Rhs.1, Rhs.2 'end', Lhs.2, Lhs.1 'result'
0 ~0% {6} r8 = JOIN r7 WITH RegExpTreeView::seqChild#fffff#reorder_0_1_2_4_3#prev ON FIRST 4 OUTPUT Lhs.4 'result', Lhs.0 're', Lhs.1 'start', Lhs.2 'end', Rhs.4 're', (1 + Rhs.4 're')
0 ~0% {6} r9 = SELECT r8 ON In.5 'i' > 0
0 ~0% {5} r10 = SCAN r9 OUTPUT In.5 'i', In.0 'result', In.1 're', In.2 'start', In.3 'end'
11636 ~2% {5} r11 = r3 UNION r10
222277 ~3% {2} r12 = SCAN RegExpTreeView::RegExpTerm#ffff#prev_delta OUTPUT In.3, In.0 'result'
961948702 ~4% {5} r13 = JOIN r12 WITH RegExpTreeView::RegExpTerm#ffff#reorder_2_1_0_3#prev ON FIRST 1 OUTPUT Rhs.1 're', Lhs.0, Rhs.3, Lhs.1, Rhs.2 'result'
902017671 ~0% {3} r14 = JOIN r13 WITH ParseRegExp::RegExp::item_dispred#fff ON FIRST 3 OUTPUT Lhs.0 're', Lhs.3, Lhs.4 'result'
1193975963 ~2% {5} r15 = JOIN r14 WITH ParseRegExp::RegExp::sequence_dispred#fff ON FIRST 1 OUTPUT Lhs.0 're', Rhs.1, Rhs.2 'end', Lhs.1, Lhs.2 'result'
0 ~0% {6} r16 = JOIN r15 WITH RegExpTreeView::seqChild#fffff#reorder_0_1_2_4_3#prev ON FIRST 4 OUTPUT Lhs.4 'result', Lhs.0 're', Lhs.1 'start', Lhs.2 'end', Rhs.4 're', (1 + Rhs.4 're')
0 ~0% {6} r17 = SELECT r16 ON In.5 'i' > 0
0 ~0% {5} r18 = SCAN r17 OUTPUT In.5 'i', In.0 'result', In.1 're', In.2 'start', In.3 'end'
0 ~0% {5} r19 = SCAN RegExpTreeView::seqChild#fffff#reorder_0_1_2_4_3#prev_delta OUTPUT In.0 're', In.1 'start', In.2 'end', In.4, In.3
0 ~0% {6} r20 = JOIN r19 WITH ParseRegExp::RegExp::sequence_dispred#fff ON FIRST 3 OUTPUT Lhs.0 're', Lhs.1 'start', Lhs.2 'end', Lhs.3, Lhs.4, (1 + Lhs.3)
0 ~0% {6} r21 = SELECT r20 ON In.5 'i' > 0
0 ~0% {5} r22 = SCAN r21 OUTPUT In.4, In.0 're', In.1 'start', In.2 'end', In.5 'i'
0 ~0% {5} r23 = JOIN r22 WITH RegExpTreeView::RegExpTerm#ffff#prev ON FIRST 1 OUTPUT Rhs.3, Lhs.1 're', Lhs.2 'start', Lhs.3 'end', Lhs.4 'i'
0 ~0% {7} r24 = JOIN r23 WITH RegExpTreeView::RegExpTerm#ffff#reorder_2_1_0_3#prev ON FIRST 2 OUTPUT Lhs.1 're', Lhs.0, Rhs.3, Lhs.2 'start', Lhs.3 'end', Lhs.4 'i', Rhs.2 'result'
0 ~0% {5} r25 = JOIN r24 WITH ParseRegExp::RegExp::item_dispred#fff ON FIRST 3 OUTPUT Lhs.5 'i', Lhs.6 'result', Lhs.0 're', Lhs.3 'start', Lhs.4 'end'
0 ~0% {5} r26 = r18 UNION r25
11636 ~2% {5} r27 = r11 UNION r26
11636 ~2% {5} r28 = r27 AND NOT RegExpTreeView::seqChild#fffff#reorder_0_1_2_4_3#prev(Lhs.2 're', Lhs.3 'start', Lhs.4 'end', Lhs.1 'result', Lhs.0 'i')
11636 ~0% {5} r29 = SCAN r28 OUTPUT In.2 're', In.3 'start', In.4 'end', In.1 'result', In.0 'i'
return r29
```
2021-06-29 09:57:23 +02:00
Nick Rolfe
ba7021086b
Merge remote-tracking branch 'origin/main' into regex
2021-06-25 15:00:26 +01:00
Nick Rolfe
bee94757dd
Add query test for ReDoS.ql, ported from JS
2021-06-25 12:51:35 +01:00
Nick Rolfe
6142029fdc
Recognise \t as not escaping t
2021-06-25 12:46:25 +01:00
Nick Rolfe
a77e7761fd
Make \h and \H character class escapes
2021-06-25 12:27:39 +01:00
Nick Rolfe
a5dff79e51
Fix locations of regexp nodes in AST viewer
2021-06-25 12:00:38 +01:00
Arthur Baars
fa5e7cb9cc
Merge pull request #223 from github/aibaars/mkdir-p
...
Create parent folders when copying qhelp and sample files
2021-06-25 11:29:27 +02:00
Alex Ford
5179e3e5d6
Merge pull request #209 from github/query-sql-injection
2021-06-25 09:59:50 +01:00
Arthur Baars
efde1f86d9
Fix test case
2021-06-25 10:59:10 +02:00
Arthur Baars
0d77f49f7c
Create parent folders
2021-06-24 22:07:58 +02:00
Alex Ford
2a7d8bbc0a
Apply suggestions from code review
...
Co-authored-by: Tom Hvitved <hvitved@github.com >
2021-06-24 19:43:35 +01:00
Arthur Baars
d4666ab099
Merge pull request #222 from github/aibaars/file-filters
...
Add support for LGTM_INDEX_FILTERS environment variable
2021-06-24 20:09:08 +02:00
Arthur Baars
e3b4e0a9a3
Add missing use statement
2021-06-24 20:00:41 +02:00
Arthur Baars
f92989350a
Update autobuilder/src/main.rs
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-06-24 19:50:32 +02:00
Nick Rolfe
9ec503a3a5
Merge remote-tracking branch 'origin/main' into regex
2021-06-24 18:16:13 +01:00
Alex Ford
a45366e426
remove unnecessary ExprNodes prefix
2021-06-24 18:12:26 +01:00
Alex Ford
b27891b14e
update ActiveRecord test output
2021-06-24 18:12:26 +01:00
Alex Ford
1f5a5181b9
StringInterpolationComponentCfgNode extends ExprNodes::StmtSequenceCfgNode
2021-06-24 18:12:26 +01:00
Alex Ford
a4a8f17a54
Update ql/src/codeql_ruby/dataflow/BarrierGuards.qll
...
Co-authored-by: Tom Hvitved <hvitved@github.com >
2021-06-24 18:12:26 +01:00
Alex Ford
9883a9b606
update SqlInjection tests
2021-06-24 18:12:26 +01:00
Alex Ford
d62f4f5bd4
Address review comments
2021-06-24 18:12:26 +01:00
Alex Ford
bc5a1b86ff
Fix handling of arrays passed to ActiveRecord SQL methods
2021-06-24 18:12:26 +01:00
Alex Ford
fc8db88b66
Apply suggestions from code review
...
Co-authored-by: Tom Hvitved <hvitved@github.com >
2021-06-24 18:12:25 +01:00
Alex Ford
7415503772
update ActiveRecord test output
2021-06-24 18:12:25 +01:00
Alex Ford
12e4c9ee90
update SqlInjection tests
2021-06-24 18:12:25 +01:00
Alex Ford
734fe01867
Support named :conditions parameter to some SQL executing ActiveRecord calls
2021-06-24 18:12:25 +01:00
Alex Ford
91bde8d85d
Support ActiveRecord SQL executing calls where there is a self receiver (implicit or explicit)
2021-06-24 18:12:25 +01:00
Alex Ford
5386c776b3
Implement rb/sql-injection
2021-06-24 18:12:25 +01:00
Alex Ford
957b29b5af
Add more defaultAdditionalTaintSteps
2021-06-24 18:12:25 +01:00
Alex Ford
6e5665da8c
Make ActiveRecord model flag more potentially dangerous SQL executions
2021-06-24 18:12:25 +01:00
Alex Ford
8761873cd1
Implement two common barrier guards
2021-06-24 18:12:25 +01:00
Alex Ford
98313d0a56
Convenience classes for wrapping some Exprs as ExprCfgNodes
2021-06-24 18:12:25 +01:00
Alex Ford
ad1d8420f3
Make BarrierGuard abstract
2021-06-24 18:12:25 +01:00
Alex Ford
adf32e973a
Create Frameworks.qll to act as a container for all framework models
2021-06-24 18:12:25 +01:00
Nick Rolfe
17a59ef824
Add basic test for regex parsing
2021-06-24 18:06:08 +01:00
Arthur Baars
f69c5dc19b
Merge pull request #221 from github/package-depend-on-compile-queries
...
make the package job depend on compile-queries
2021-06-24 19:03:44 +02:00
Arthur Baars
22990a938d
Add support for LGTM_INDEX_FILTERS environment variable
...
* re-implement autobuilder script in Rust
* add additional --include/--exclude flags based on LGTM_INDEX_FILTERS
environment variable
2021-06-24 18:45:31 +02:00
Nick Rolfe
51b0ffdaf8
Fix printAst to support adding edges in AstDesugar test
2021-06-24 17:14:23 +01:00
Nick Rolfe
f7e89f47fd
Comment out temporarily-unused predicates
2021-06-24 17:06:41 +01:00
Alex Ford
58e9b69ea4
make the package job depend on compile-queries
2021-06-24 16:52:22 +01:00
Nick Rolfe
a6dd2fa0a1
Split ReDoS query into .ql and .qll, and add .qhelp
2021-06-24 16:32:45 +01:00
Arthur Baars
7574d1cad7
Merge pull request #220 from github/aibaars/update-build-yml
...
Update build.yml
2021-06-24 16:38:26 +02:00
Arthur Baars
be1d4c3d2c
Address comment
2021-06-24 16:31:24 +02:00
Arthur Baars
ade36691b6
Remove unnecessary qualifier
2021-06-24 16:13:29 +02:00
Arthur Baars
dfc96de4cc
Update build.yml
2021-06-24 16:09:45 +02:00
Arthur Baars
95399b2d0a
Refactor ApiGraphs.qll
2021-06-24 15:58:02 +02:00
Arthur Baars
4f96834711
Add ConstantAccessCfgNode
2021-06-24 15:57:48 +02:00
Arthur Baars
6bed50a86b
Rename predicate with snake cased name
2021-06-24 11:59:13 +02:00
Arthur Baars
b2be1c3b3d
Update ql/src/codeql_ruby/ApiGraphs.qll
...
Co-authored-by: Tom Hvitved <hvitved@github.com >
2021-06-23 20:40:22 +02:00
Tom Hvitved
9438885776
Merge pull request #216 from github/hvitved/synthesis-location
...
AST synthesis: Move location information into a separate predicate
2021-06-23 16:50:17 +02:00
Nick Rolfe
c784e37089
Add regexp parser and exponential ReDoS query
2021-06-23 15:29:49 +01:00
Alex Ford
e5f0206c6d
Merge pull request #208 from github/action-controller-1
...
Model accesses to `ActionController` parameters via `params` method
2021-06-23 14:21:55 +01:00
Alex Ford
0238c19085
remove TODO
2021-06-23 14:11:38 +01:00
Alex Ford
5941eb2be4
model some ActionController user input sources (params)
2021-06-23 14:11:38 +01:00
Alex Ford
9227f3a0c3
Add RemoteFlowSources.qll
2021-06-23 14:11:38 +01:00
Alex Ford
5163514d43
Merge pull request #218 from github/build-yml-debug
...
Fix `compile-queries` job
2021-06-23 14:04:33 +01:00
Alex Ford
8e1f2e6237
try fixing build.yml
2021-06-23 13:41:51 +01:00
Mathias Vorreiter Pedersen
90633b9ce1
C++: Make the new SQL abstract classes extend 'Function' instead. This is more in line with how we model RemoteFlowFunction.
2021-06-23 11:49:51 +02:00
Tom Hvitved
1dde5b8ef9
AST synthesis: Move location information into a separate predicate
2021-06-23 08:46:07 +02:00
Arthur Baars
f18e5030e0
Address comments by @tausbn
2021-06-22 17:25:34 +02:00
Mathias Vorreiter Pedersen
90fe5c5aca
C++: Add change-note.
2021-06-22 17:13:07 +02:00
Mathias Vorreiter Pedersen
2e2673aff6
C++: Delete the experimental SqlPqxxTainted query.
2021-06-22 17:13:07 +02:00
Mathias Vorreiter Pedersen
440793b5ff
C++: Move the example from the experimental CWE-089 query into a test.
2021-06-22 17:13:06 +02:00
Mathias Vorreiter Pedersen
222cd41aa3
C++: Use the new SQL interface in 'Security.qll' and 'SqlTainted.ql'.
2021-06-22 17:13:06 +02:00
Mathias Vorreiter Pedersen
092fbd60d9
C++: Create a new SQL interface.
2021-06-22 17:13:06 +02:00
Alex Ford
dbf1805c8b
Merge pull request #196 from github/active-record-1
...
Start modelling some potential SQL fragment sinks in ActiveRecord
2021-06-22 16:05:26 +01:00
Arthur Baars
bedd790d33
Merge pull request #217 from github/aibaars-patch-2
...
Remove ad-hoc entries from query suite
2021-06-22 15:48:22 +02:00
Arthur Baars
f7eee915da
Remove ad-hoc queries
2021-06-22 15:35:30 +02:00
Arthur Baars
cdfe74959f
Remove methodName field
2021-06-22 10:32:44 +02:00
Arthur Baars
7c3c1db462
Use ApiGraphs in WeakFilePermissions query
2021-06-22 10:25:56 +02:00
Arthur Baars
65d9327951
Add CallNode class
2021-06-22 10:25:56 +02:00
Arthur Baars
57d8ba649f
Use flowsTo
2021-06-21 19:37:41 +02:00
Arthur Baars
d2e2901128
First version of ApiGraphs
2021-06-21 19:37:41 +02:00
Arthur Baars
f0c83288a7
Add test case for ApiGraph
2021-06-21 19:37:41 +02:00
Arthur Baars
4fa093048c
Add inline expectations test framework
2021-06-21 19:37:41 +02:00
Arthur Baars
33c5312842
Merge pull request #215 from github/bump-codeql
...
Bump `codeql` submodule
2021-06-21 16:18:04 +02:00
Tom Hvitved
992d8faa06
Bump codeql submodule
2021-06-21 16:06:45 +02:00
Tom Hvitved
abe5e3d953
Merge pull request #210 from github/hvitved/dataflow/consistency
...
Data flow: Add consistency queries
2021-06-21 14:42:55 +02:00
Nick Rolfe
35eb4a3af4
Merge pull request #214 from github/regexp_naming
...
Use RegExp prefix instead of Regex, for consistency with other languages.
2021-06-21 11:06:19 +01:00
Tom Hvitved
b820f3f20d
Merge pull request #212 from github/hvitved/ssa/assigns-pred
...
Add `Ssa::WriteDefinition::assigns/1` predicate
2021-06-21 10:46:48 +02:00
Nick Rolfe
65aa97c07c
Use RegExp prefix instead of Regex, for consistency with other languages.
2021-06-18 15:56:19 +01:00
Tom Hvitved
7cc02e6d00
Add Ssa::WriteDefinition::assigns/1 predicate
2021-06-18 10:42:32 +02:00
Nick Rolfe
78db1bf045
Merge pull request #211 from github/smaller_trap
...
Tweaks to reduce size of TRAP output
2021-06-17 17:09:14 +01:00
Nick Rolfe
ab72b4e9e7
Use hexadecimal encoding for TRAP labels
2021-06-17 16:16:32 +01:00
Nick Rolfe
ed93233917
Remove unnecessary spaces in TRAP output
2021-06-17 16:16:06 +01:00
Alex Ford
7439ab5635
remove recvCls field from ActiveRecordModelClassMethodCall
2021-06-17 14:42:42 +01:00
Alex Ford
214532516b
try to avoid a future merge conflict
2021-06-17 14:41:51 +01:00
Alex Ford
762656ee60
Add QLDoc to ActiveRecord.qll
2021-06-17 14:41:51 +01:00
Alex Ford
12a0af1d28
Tidy up PotentiallyUnsafeSqlExecutingMethodCall characteristic predicate
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-06-17 14:39:40 +01:00
Tom Hvitved
41ed9f3e1b
Data flow: Fix inconsistencies
2021-06-17 10:48:32 +02:00
Tom Hvitved
00e544189e
Data flow: Add consistency queries
2021-06-17 10:26:56 +02:00
Tom Hvitved
ad54f2e1f4
Bump codeql submodule
2021-06-17 10:24:19 +02:00
Tom Hvitved
872c7edfc8
Merge pull request #207 from github/bump-codeql
...
Bump `codeql` submodule
2021-06-16 12:33:40 +02:00
Tom Hvitved
84d79ccae9
Bump codeql submodule
2021-06-16 11:55:38 +02:00
Alex Ford
bf43a77df5
Include some more types of expressions as possible active record SQL sink arguments
2021-06-15 12:41:42 +01:00
Alex Ford
ea21c591af
remove accidentally unbound variable
2021-06-15 11:39:48 +01:00
Alex Ford
c1b9952517
account for chained method calls when constructing ActiveRecord SQL queries
2021-06-15 11:39:48 +01:00
Alex Ford
f8a77b9854
format QL
2021-06-15 11:39:48 +01:00
Alex Ford
57c04266e3
rename SqlExecutingMethodCall as PotentiallyUnsafeSqlExecutingMethodCall
2021-06-15 11:39:48 +01:00
Alex Ford
2d4bb61789
limit SqlExecutingMethodCall to those that are called with a StringlikeLiteral argument
2021-06-15 11:39:48 +01:00
Alex Ford
2c15b60998
add ActiveRecord find_by_sql as an SQL executing method call
2021-06-15 11:39:48 +01:00
Alex Ford
c641d12259
add shell ActiveRecord library tests
2021-06-15 11:39:48 +01:00
Alex Ford
5b7df8578a
cleanup ActiveRecord.qll
2021-06-15 11:39:48 +01:00
Alex Ford
7488d072d8
Model some SQL fragment sinks in ActiveRecord model classes
2021-06-15 11:39:48 +01:00
Alex Ford
743deee9ce
add a class to represent ActiveRecord models
2021-06-15 11:39:48 +01:00
Alex Ford
7d3eaf40ff
add base SqlExecution concepts
2021-06-15 11:39:48 +01:00
Tom Hvitved
3a37e321d5
Merge pull request #205 from github/hvitved/taint-tracking
...
Initial taint-tracking library
2021-06-15 09:30:59 +02:00
Tom Hvitved
5a9521372b
Merge pull request #206 from github/tausbn/fix-identical-files
2021-06-15 07:31:07 +02:00
Taus
2bbcbb2200
Bump submodule pointer
2021-06-14 19:04:22 +00:00
Tom Hvitved
302b485f4c
Merge pull request #204 from github/hvitved/cfg-nodes-perf
...
Improve performance of `ExprChildMapping::reachesBasicBlock()`
2021-06-14 20:14:17 +02:00
Taus
068b980517
Update identical-files.json
...
As of https://github.com/github/codeql/pull/6063 we have now started using the shared type tracking library in Python as well. 🎉
2021-06-14 19:01:24 +02:00
Tom Hvitved
8aa337ab01
Initial taint-tracking library
2021-06-14 14:19:34 +02:00
Tom Hvitved
b154c936c3
Improve performance of ExprChildMapping::reachesBasicBlock()
...
Since all expressions are now post-order, the logic of `reachesBasicBlock` can
be simplified, and performance can be improved as well.
2021-06-14 11:58:24 +02:00
Arthur Baars
88fb3c7097
Merge pull request #203 from github/aibaars/pack-qhelp-samples
...
Query pack: include .rb and .erb sample files from queries directory
2021-06-11 13:50:17 +02:00
Arthur Baars
909e6d5a62
Query pack: include .rb and .erb sample files from queries directory
...
These are required by the qhelp files.
2021-06-11 13:42:43 +02:00
Arthur Baars
78a6ed43c3
Merge pull request #202 from github/aibaars-patch-2
...
HardCodedCredentials: fix query metadata comment
2021-06-11 12:05:44 +02:00
Arthur Baars
661d6e8e38
HardCodedCredentials: fix query metadata comment
2021-06-11 11:59:46 +02:00
Tom Hvitved
8860b8adf0
Merge pull request #198 from github/hvitved/desugar-compound-assignment
2021-06-10 19:39:54 +02:00
Alex Ford
f74dff560b
Merge pull request #187 from github/hardcoded-credentials
...
Add rb/hardcoded-credentials query
2021-06-10 16:12:32 +01:00
Alex Ford
8839d4c584
limit additional flow steps in rb/hardcoded-credentials to string concatenation
2021-06-10 14:59:28 +01:00
Alex Ford
fe45dadd55
set precision to high for rb/hardcoded-credentials
2021-06-10 14:52:26 +01:00
Alex Ford
e26afe91b5
move rb/hardcoded-credential alert location to the source
2021-06-07 14:53:04 +01:00
Alex Ford
5d79a8cec0
account for keyword args in rb/hardcoded-credentials and simplify query
2021-06-07 14:49:49 +01:00
Tom Hvitved
962768e7c0
Disambiguate toStrings for nested synthetic local variables
2021-06-04 19:20:11 +02:00
Tom Hvitved
82fbc03889
Merge pull request #200 from github/hvitved/dataflow/call-sensitivity
...
Data flow: Call-sensitive resolution of lambda/block calls
2021-06-04 16:25:13 +02:00
Alex Ford
ec326bfcb7
Merge pull request #201 from github/perm-file-report-source
...
Report rb/weak-file-permission alerts at source rather than sink and improve alert message
2021-06-04 14:52:48 +01:00
Alex Ford
8a3ffb6dca
add missing toString
2021-06-04 13:25:03 +01:00
Alex Ford
b2d36babc4
report rb/weak-file-permission alerts at source rather than sink and improve alert message
2021-06-04 13:10:18 +01:00
Nick Rolfe
523a0b1f12
Merge pull request #197 from github/upgrade-pack
2021-06-04 13:03:39 +01:00
Nick Rolfe
6203c9019a
Remove reference to deleted upgrades qlpack from manifest
2021-06-04 12:15:36 +01:00
Tom Hvitved
61e35ddae1
Data flow: Call-sensitive resolution of lambda/block calls
2021-06-04 12:58:38 +02:00
Tom Hvitved
77146e4e04
Data flow: Reduce caching
...
These predicates are now cached in the shared implementation.
2021-06-04 12:53:47 +02:00
Tom Hvitved
f9eecfb59f
Bump codeql submodule
2021-06-04 12:52:05 +02:00
Tom Hvitved
6678ac0347
Desugar compound assignments
2021-06-04 10:39:06 +02:00
Tom Hvitved
da9adfbab4
Improve performance of desugaring transformations
2021-06-04 10:34:00 +02:00
Tom Hvitved
57eee0368d
Add CFG tests for compound assignments
2021-06-04 10:34:00 +02:00
Tom Hvitved
dfcf4c90ab
Merge pull request #199 from github/hvitved/splat-expr
...
Rename `(Hash)SplatArgument` to `(Hash)SplatExpr` and make them `UnaryOperation`s
2021-06-04 10:33:42 +02:00
Tom Hvitved
1007f2aaff
Rename (Hash)SplatArgument to (Hash)SplatExpr and make them UnaryOperations
2021-06-04 10:04:06 +02:00
Tom Hvitved
372f8645a9
Add (hash)splat AST tests
2021-06-04 09:53:14 +02:00
Nick Rolfe
8b987757c6
Merge upgrades qlpack into ql/src
2021-06-03 18:28:20 +01:00
Tom Hvitved
2094aa983a
Merge pull request #194 from github/hvitved/desugar-child
2021-06-03 18:07:33 +02:00
Arthur Baars
03ef1261d3
Merge pull request #192 from github/aibaars/release-workflow
...
Build workflow: create release
2021-06-03 16:52:50 +02:00
Tom Hvitved
908e9ff3b5
Include desugared node in AstDesugar.ql
2021-06-03 14:46:32 +02:00
Arthur Baars
63475dc692
Merge pull request #195 from github/escape_field_name
...
Escape field names with table storage
2021-06-01 14:55:46 +02:00
Nick Rolfe
1388d82f1d
Escape field names with table storage
2021-06-01 13:32:13 +01:00
Nick Rolfe
9c199b6c2a
Merge pull request #193 from github/tausbn/autogenerate-qldoc
...
Autogenerate QLDoc for `TreeSitter.qll`
2021-06-01 13:31:32 +01:00
Tom Hvitved
5bafc0c708
Merge pull request #183 from github/hvitved/assign-op-desugar
...
Desugar setter assignments
2021-06-01 14:00:04 +02:00
Alex Ford
f27dd45e4c
run formatter
2021-06-01 12:29:45 +01:00
Alex Ford
907bb9b556
add a comment
2021-06-01 12:22:04 +01:00
Alex Ford
1f931d6f76
rb/hardcoded-credentials: fix bad bracketing
2021-06-01 12:22:04 +01:00
Alex Ford
fdd4f7f616
attempt to use typetracker in rb/hardcoded-credentials
2021-06-01 12:22:04 +01:00
Alex Ford
c530ba5b11
format ql
2021-06-01 12:22:04 +01:00
Alex Ford
f1303e0ced
remove WIP files
2021-06-01 12:22:04 +01:00
Alex Ford
10175e1398
remove WIP files
2021-06-01 12:22:04 +01:00
Alex Ford
4fdd072603
WIP: HardcodedCredentials query
2021-06-01 12:22:04 +01:00
Taus
53b7492aa3
Generate QLDoc for getChild
2021-06-01 10:57:39 +00:00
Taus
6cf7a12c8c
Undo field name escaping
2021-06-01 10:56:45 +00:00
Taus
d38520dc73
Escape field names correctly
...
This should make `field('unique', $.whatever)` valid again.
2021-05-31 20:56:29 +00:00
Taus
64090b086c
Autogenerate QLDoc for TreeSitter.qll
...
It's not quite perfect, as there's still some QLDoc missing on the
various `getChild` methods, but it wasn't immediately clear to me how
to get this working (especially since the QLDoc would ideally be
different depending on whether there was a child index or not).
Then again, `getChild` probably has a pretty intuitive meaning...
2021-05-31 20:54:10 +00:00
Tom Hvitved
3ffef634d7
More synthesis refactoring
...
- Join `TElementReferenceSynth` and `TMethodCallSynth`.
- Move arity and setter information into `MethodCallKind`.
- Add `Synthesis::methodCall` for specifying which method calls need synthesis.
2021-05-31 16:29:41 +02:00
mr-sherman
ec48d0ac29
Merge remote-tracking branch 'upstream/main' into service-stack-remote-sink
...
merging from main because it fell way behind.
2021-05-28 10:30:29 -04:00
Tom Hvitved
e8841e6482
Simplify getSynthChild
2021-05-27 10:20:31 +02:00
Tom Hvitved
f8b99291a7
Improve desugaring of setter assignments
2021-05-26 18:41:21 +02:00
Arthur Baars
af6f050d06
Merge pull request #189 from github/aibaars/fix-lgtm-suite
...
Fix LGTM suites
2021-05-26 16:02:14 +02:00
Arthur Baars
3f210865b2
Build workflow: create release
2021-05-26 15:55:34 +02:00
Arthur Baars
ec905e0866
Merge pull request #168 from github/aibaars/typetrack-method
...
Call graph
2021-05-26 14:19:21 +02:00
Arthur Baars
4dc182d4a4
Merge pull request #191 from github/fixCap
...
fix snake_casing of camelCased identifiers
2021-05-26 13:39:52 +02:00
Arthur Baars
bacbd5e997
Address comments
2021-05-26 13:35:45 +02:00
Erik Krogh Kristensen
9c1b237e3b
fix snake_casing of camelCased identifiers
2021-05-26 11:16:05 +00:00
Arthur Baars
a044f41aad
Merge pull request #188 from github/aibaars/qlpack
...
Build Ruby bundle
2021-05-26 12:18:51 +02:00
Tom Hvitved
abcabeef06
Remove *Real predicates and enable recursive desugaring
2021-05-25 21:27:39 +02:00
Tom Hvitved
3f412e4fad
Desugar setter assignment operations
2021-05-25 21:27:39 +02:00
Tom Hvitved
b173cc332a
Desugar setter assignments
2021-05-25 21:27:39 +02:00
Tom Hvitved
b812012b71
Add CFG setter assignment test
2021-05-25 21:27:39 +02:00
Tom Hvitved
e85677a040
Adjust locations of synthesized AST nodes
2021-05-25 21:27:34 +02:00
Arthur Baars
aea0c6fc64
Merge pull request #190 from github/aibaars/fix-heredoc-parent
...
Fix Scope::parentOf for HeredocBody nodes
2021-05-25 11:58:21 +02:00
Arthur Baars
ce23ae33e7
Fix Scope::parentOf for HereDocBody
2021-05-25 11:27:45 +02:00
Arthur Baars
bb62564c9e
Add test for heredoc with variables
2021-05-25 11:16:55 +02:00
Arthur Baars
86d57d3e26
Fix LGTM suites
2021-05-25 10:41:07 +02:00
Arthur Baars
73aae5dfd9
Use num_cpus-1 threads by default
2021-05-25 09:28:49 +02:00
Arthur Baars
4f404e9b11
Temporarily include some queries in the code scanning suite
...
This should be reverted once we have a decent set of default queries.
2021-05-25 09:21:40 +02:00
Arthur Baars
a02cfd27c9
Compile query packs with previous CodeQL versions too
2021-05-24 17:48:49 +02:00
Arthur Baars
78d9191526
Build query pack
2021-05-24 13:27:50 +02:00
Tom Hvitved
423a1b39e1
Improve call graph performance by forcing non-linear joins first
2021-05-20 14:36:56 +02:00
Tom Hvitved
492f41d399
Fix performance
2021-05-20 14:27:13 +02:00
Arthur Baars
0ccca47b01
Dataflow for implicit self argument of methods
2021-05-20 14:27:13 +02:00
Arthur Baars
eb8b2558da
Add types of lambdas and methods
2021-05-20 14:27:13 +02:00
Arthur Baars
e787d99cd1
Resolve yield calls to blocks
2021-05-20 14:27:13 +02:00
Arthur Baars
66b2c39985
More tests
2021-05-20 14:27:13 +02:00
Arthur Baars
578b94453d
Flow for captured local variables
2021-05-20 14:27:13 +02:00
Arthur Baars
e46755021b
Add data flow steps for optional parameter values
2021-05-20 14:27:13 +02:00
Arthur Baars
da88661746
Add SSA flow step for parameters
2021-05-20 14:27:13 +02:00
Arthur Baars
84da0cb2f3
Track type of Classes/Modules and and self in singleton methods
2021-05-20 14:27:13 +02:00
Arthur Baars
f157f1f359
Fix superclass of Class
2021-05-20 14:27:13 +02:00
Arthur Baars
1ba94beb01
Fix types of true/false
2021-05-20 14:27:13 +02:00
Tom Hvitved
f63f5aba15
Fix performance
2021-05-20 14:27:13 +02:00
Arthur Baars
af19cc5fae
Add test cases
2021-05-20 14:27:13 +02:00
Arthur Baars
a9806719f9
Toplevel 'self'
2021-05-20 14:27:13 +02:00
Arthur Baars
1a739b2fbf
Resolve super calls
2021-05-20 14:27:13 +02:00
Arthur Baars
7f520e7899
Add types of literals
2021-05-20 14:27:13 +02:00
Arthur Baars
4951b7d378
Treat methods defined in a singleton class similar to single methods
2021-05-20 14:27:13 +02:00
Arthur Baars
8815bb7dbe
Track calls to singleton methods
2021-05-20 14:27:13 +02:00
Arthur Baars
b13bae6a4e
Resolve instance method calls
2021-05-20 14:27:13 +02:00
Arthur Baars
3c80b32ba0
Merge pull request #186 from github/bump-codeql
...
Bump `codeql` sub module
2021-05-20 14:26:24 +02:00
Tom Hvitved
16d34c7cd4
Sync files
2021-05-20 14:15:54 +02:00
Tom Hvitved
c73e6ff390
Bump codeql sub module
2021-05-20 14:15:33 +02:00
Tom Hvitved
1509584e27
Merge pull request #185 from github/hvitved/resolve-expr-perf
...
Improve performance of `internal/Module.qll`
2021-05-19 14:53:46 +02:00
Tom Hvitved
6b6aeb10c7
Improve performance of internal/Module.qll
2021-05-19 14:33:52 +02:00
Tom Hvitved
4798a1a008
Merge pull request #184 from github/cfg/singleton-method-abnormal
...
CFG: Add missing `propagatesAbnormal` overrides
2021-05-19 12:45:59 +02:00
Tom Hvitved
c866f88410
CFG: Add missing propagatesAbnormal overrides
2021-05-18 20:39:46 +02:00
Tom Hvitved
9871698cee
Add more CFG tests
2021-05-18 20:39:08 +02:00
Nick Rolfe
b9b6ffe53e
Merge pull request #178 from github/cfg_cleanup
...
Clean up CFG implementation
2021-05-18 10:53:44 +01:00
Nick Rolfe
778de741d0
Merge remote-tracking branch 'origin/main' into cfg_cleanup
2021-05-17 16:26:28 +01:00
Nick Rolfe
f3d831c25e
Remove unnecessary superclass prefix
2021-05-17 15:26:53 +01:00
Nick Rolfe
9a2523e2f9
Make EndBlockTree extend StmtSequenceTree
2021-05-17 15:24:20 +01:00
Nick Rolfe
6d395230d4
Make BraceBlockTree extend StmtSequenceTree
2021-05-17 14:54:11 +01:00
Tom Hvitved
ad036f8af1
Merge pull request #179 from github/hvitved/synth-framework-take2
...
AST synthesis framework (take 2)
2021-05-17 15:36:56 +02:00
Tom Hvitved
25f226e9dc
Add comment to getVariableReal
2021-05-17 15:02:40 +02:00
Tom Hvitved
b434d42d05
Rename ParenthesizedExprSynth to StmtSequenceSynth
2021-05-17 13:39:44 +02:00
Alex Ford
ca046c9af5
Merge pull request #182 from github/loc-query-tag
2021-05-14 17:42:21 +01:00
Alex Ford
1ba491a956
add lines-of-code tag to rb/summary/lines-of-code
2021-05-14 17:06:49 +01:00
Alex Ford
3c0f20cec8
Merge pull request #170 from github/weak-file-permissions
...
Add `rb/overly-permissive-file` query
2021-05-14 17:04:15 +01:00
Arthur Baars
6c382ccd4b
Merge pull request #169 from github/aibaars/codespace
...
Add CodeSpace container
2021-05-14 18:00:51 +02:00
Alex Ford
e9090cec70
Merge pull request #181 from github/loc-description-improvements
...
LOC summary query improvements
2021-05-14 16:13:42 +01:00
Alex Ford
65b0ce204d
restrict rb/summary/lines-of-code to the source root
2021-05-14 16:00:55 +01:00
Alex Ford
71234155b8
improve rb/summary/lines-of-code description
2021-05-14 15:59:07 +01:00
Alex Ford
7ff2ca4ffe
improve rb/summary/lines-of-user-code name and description
2021-05-14 15:56:59 +01:00
Alex Ford
6bd2e4e4b7
Merge pull request #175 from github/loc-summary-queries-1
...
Summary queries for total LOC and user-code LOC
2021-05-14 15:51:45 +01:00
Arthur Baars
66bf13e77a
Setup a CodeSpace
2021-05-13 21:03:40 +02:00
Arthur Baars
3547980f5b
Update reference to tree-sitter-embedded-template
2021-05-13 21:03:40 +02:00
Arthur Baars
498e760b21
Add consistency queries to codeqlmanifest
2021-05-13 21:03:40 +02:00
Nick Rolfe
a46f45440a
Create NamespaceTree to reduce duplication
2021-05-13 17:52:20 +01:00
Nick Rolfe
5e6dddad3e
Replace count(getReceiver()) with 1
2021-05-13 16:59:05 +01:00
Alex Ford
11949c6b77
Merge pull request #176 from github/diagnostics-entries
...
Start writing diagnostics to the DB, and some basic summary/diagnostics queries
2021-05-13 14:31:01 +01:00
Alex Ford
15712df717
update ruby.dbscheme.stats
2021-05-13 13:50:53 +01:00
Alex Ford
dc3c5926f5
add a db upgrade for the diagnostics table
2021-05-13 13:45:02 +01:00
Alex Ford
277a6a020a
diagnostics: use debug rather than hidden terminology, and leave gaps for other severities
2021-05-13 13:44:10 +01:00
Alex Ford
b2f2f786ac
allow the WeakFilePermissions access predicate to return multiple values
2021-05-13 13:22:14 +01:00
Alex Ford
0d1c4a1290
document that the WeakFilePermissions access predicate should return at most one value
2021-05-13 13:06:45 +01:00
Alex Ford
89be8d8710
Apply suggestions from code review
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2021-05-13 12:59:16 +01:00
Tom Hvitved
ff06e724b1
AST synthesis framework
2021-05-12 19:58:52 +02:00
Alex Ford
acdbd9859e
simplify ExtractionError class defn
2021-05-12 16:45:31 +01:00
Alex Ford
11376bc411
note that severity 3 corresponds to an error diagnostic level
2021-05-12 16:39:51 +01:00
Alex Ford
0dad1a4779
use a case-split for diagnostic severity levels
2021-05-12 16:38:37 +01:00
Tom Hvitved
ea1c7b51ef
Add more operator assignment tests
2021-05-12 17:24:11 +02:00
Alex Ford
0016146e11
limit summary queries to files from within the source directory
2021-05-11 21:07:08 +01:00
Alex Ford
49d9bb798c
revamp the diagnostics tests
2021-05-11 19:53:00 +01:00
Alex Ford
9b115129fe
move diagnostics queries to match other languages more closely
2021-05-11 19:53:00 +01:00
Alex Ford
1381d8d076
tidy up Diagnostics library
2021-05-11 19:28:31 +01:00
Alex Ford
9663b74e12
use severity level 3 to indicate an extraction error for a file
2021-05-11 19:23:05 +01:00
Alex Ford
d1d8cff915
tests for some more diagnostics queries
2021-05-11 19:14:22 +01:00
Alex Ford
de497dd1ba
tests for NumberOfFiles* summary queries
2021-05-11 19:14:22 +01:00
Nick Rolfe
004147984b
Simplify CFG classes for StmtSequences
2021-05-11 18:27:11 +01:00
Alex Ford
8ab95324eb
dedupe some error reporting code
2021-05-11 14:09:10 +01:00
Alex Ford
0f3168f293
record more parse errors
2021-05-10 21:23:24 +01:00
Alex Ford
2154b7df30
add doc for IntegerLiteral.getValue
2021-05-10 11:02:48 +01:00
Alex Ford
48add9ffbc
remove internal import in rb/overly-permissive-file
2021-05-10 11:00:59 +01:00
Alex Ford
269ae8331b
record 'unknown table type' extraction errors
2021-05-07 17:56:50 +01:00
Nick Rolfe
94ceb3f237
Remove unused class
2021-05-07 17:20:51 +01:00
Nick Rolfe
9def7c2dfe
Make CFG for TEnsure post-order
2021-05-07 17:15:10 +01:00
Nick Rolfe
7f6805c82f
Make CFG for TDo post-order
2021-05-07 17:00:30 +01:00
Nick Rolfe
46c9f858c4
Make CFG for TElse post-order
2021-05-07 16:47:19 +01:00
Nick Rolfe
2569bf257f
Make CFG for TThen post-order
2021-05-07 15:40:50 +01:00
Alex Ford
a7873f9023
rb/summary/number-of-files-extracted-with-errors
2021-05-07 00:24:13 +01:00
Alex Ford
31b8913ffd
rb/summary/number-of-successfully-extracted-files FIXUP
2021-05-07 00:23:56 +01:00
Alex Ford
804198cd37
rb/summary/number-of-successfully-extracted-files
2021-05-07 00:22:22 +01:00
Alex Ford
e7285babf0
rb/diagnostics/successfully-extracted-files
2021-05-07 00:17:58 +01:00
Alex Ford
54266eca33
rb/diagnostics/files-extracted-with-errors
2021-05-07 00:17:12 +01:00
Alex Ford
d223851429
add Diagnostics.qll
2021-05-07 00:15:09 +01:00
Alex Ford
272aec27f2
clean up the parse_error writing code
2021-05-07 00:15:09 +01:00
Alex Ford
3a1dff1c95
start writing diagnostics entries for parse errors
2021-05-06 23:09:43 +01:00
Alex Ford
c38453305f
add diagnostics table to dbscheme
2021-05-06 22:58:01 +01:00
Alex Ford
e5896047d8
summary LOC query tests
2021-05-06 19:54:23 +01:00
Alex Ford
98a4f4c5b9
rb/summary/lines-of-user-code
2021-05-06 19:54:23 +01:00
Alex Ford
f6c8b07f4f
rb/summary/lines-of-code
2021-05-06 19:54:23 +01:00
Nick Rolfe
4e80b548c1
Make BeginBlock CFG post-order
2021-05-06 16:45:27 +01:00
Nick Rolfe
2c7f1e0c11
Remove unused class
2021-05-06 16:28:36 +01:00
Nick Rolfe
9185a93312
Make SingletonClassDeclarationTree post-order
2021-05-06 16:20:50 +01:00
Nick Rolfe
fd3d50f340
Make ModuleDeclarationTree post-order
2021-05-06 15:54:11 +01:00
Nick Rolfe
d623f47ba0
Make ClassDeclarationTree post-order
2021-05-06 15:36:25 +01:00
Arthur Baars
07c059cb2e
Merge pull request #166 from github/type_tracking
...
Minimal implementation of shared type-tracking library
2021-05-06 10:59:45 +02:00
Nick Rolfe
a0084b7732
Simplify CFG tree classes for calls
2021-05-05 17:18:44 +01:00
Nick Rolfe
569063ca73
Make YieldCallTree post-order
2021-05-05 17:14:32 +01:00
Nick Rolfe
3a3586f14b
Restrict type to MethodCallCfgNode
2021-05-05 14:49:24 +01:00
Arthur Baars
73b5699f32
Merge pull request #174 from github/escape_file_keys
...
Escape keys for files and folders
2021-05-05 15:02:04 +02:00
Nick Rolfe
c37f390efc
Reserve more capacity for escaped key
2021-05-05 13:21:16 +01:00
Nick Rolfe
99ae17de03
Avoid copying key when it doesn't need escaping
2021-05-05 12:54:23 +01:00
Nick Rolfe
b16b95e2f7
Fix type-tracking load/store steps
2021-05-05 12:12:45 +01:00
Nick Rolfe
d2d5f31599
Escape keys for files and folders
2021-05-04 16:52:35 +01:00
Nick Rolfe
647c108c0b
Merge remote-tracking branch 'origin/main' into type_tracking
2021-05-04 12:38:16 +01:00
Arthur Baars
1a94fb47b6
Merge pull request #172 from github/update-testoutput
...
Update expected test output
2021-05-04 13:37:37 +02:00
Arthur Baars
27538cb11d
Update expected test output
2021-05-04 12:43:43 +02:00
Nick Rolfe
53deede8ab
Remove unnecessary local flow inside type-tracking store step
2021-05-04 11:32:57 +01:00
Nick Rolfe
35ee62c689
Use splitting-aware nodes for type-tracking store/load steps
2021-05-04 11:31:03 +01:00
Arthur Baars
6adff6f195
Merge pull request #171 from github/self_nodes
...
Create synthetic `self` nodes for calls without explicit receivers
2021-05-03 12:59:11 +02:00
Nick Rolfe
5dc910d0db
Move track predicate to LocalSourceNode
2021-04-30 15:05:12 +01:00
Nick Rolfe
37c8d8a252
Rename getCallable to getTarget
2021-04-30 14:41:50 +01:00
Nick Rolfe
fdccd5da7e
Add AstNode::isSynthesized()
2021-04-30 11:58:54 +01:00
Alex Ford
2c8a4f833f
make rb/overly-permissive-file a proper path-problem
2021-04-29 19:11:39 +01:00
Nick Rolfe
e87bf57bc5
Avoid recursion in IPA construction
2021-04-29 18:04:15 +01:00
Alex Ford
4375452866
more IntegerLiteral.getValue improvements
2021-04-29 17:08:33 +01:00
Alex Ford
05adfec03d
account for more patterns in IntegerLiteral.getValue
2021-04-29 17:02:54 +01:00
Alex Ford
35d5bae10e
run formatter
2021-04-29 16:16:09 +01:00
Alex Ford
efa323c304
rb/overly-permissive-file use QL bitwise operators
2021-04-29 16:08:42 +01:00
Alex Ford
46a14b2826
move parseInt logic into getValue method predicate on IntegerLiteral
2021-04-29 15:54:22 +01:00
Alex Ford
1c89bbe188
fix select format of rb/overly-permissive-file
2021-04-29 15:44:54 +01:00
Nick Rolfe
bd6fe41388
Merge IPA branches for implicit self
2021-04-29 15:38:58 +01:00
Alex Ford
2c0fc7d193
parse integer permission args as ints instead of using regex matches
2021-04-29 15:34:10 +01:00
Nick Rolfe
59c83b7b8f
Add clarifying comment
2021-04-29 14:00:27 +01:00
Nick Rolfe
9540125771
Remove fromGeneratedInclSynth predicate
2021-04-29 13:58:16 +01:00
Arthur Baars
300a54384f
Add TypeTracker to identical-files.json
2021-04-29 12:20:14 +02:00
Arthur Baars
f07c58ee07
Update codeql submodule
2021-04-29 12:13:11 +02:00
Nick Rolfe
96ddd55191
Apply suggestions from code review
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2021-04-29 12:07:32 +02:00
Nick Rolfe
c1c437f020
Minimal implementation of shared type-tracking library
2021-04-29 12:07:32 +02:00
Nick Rolfe
f3852f9b56
Create synthetic self nodes for calls without explicit receivers
2021-04-28 16:43:40 +01:00
Alex Ford
0a6dc6f150
update WeakFilePermissions.expected
2021-04-28 16:31:07 +01:00
Alex Ford
7a72d8ec2f
add qhelp for rb/overly-permissive-file
2021-04-28 15:51:08 +01:00
Alex Ford
e3d393b7c1
use full dataflow for permission args in rb/overly-permissive-file
2021-04-28 15:40:58 +01:00
Alex Ford
e5862a942f
WIP rb/overly-permissive-file query
2021-04-27 21:22:17 +01:00
Arthur Baars
bc6aec7a99
Merge pull request #167 from github/alexrford/numlines
...
Implement FLines metrics queries
2021-04-21 14:42:18 +02:00
Alex Ford
240f0abf27
drop @tags from metrics queries
2021-04-21 13:00:48 +01:00
Alex Ford
15289dba34
simplify File.getNumberOfLines
2021-04-21 12:59:25 +01:00
Alex Ford
cc5bbfce0b
Get -> Gets
2021-04-21 12:57:55 +01:00
Alex Ford
5a191692df
Update ql/src/queries/metrics/FLinesOfComments.ql
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2021-04-21 12:57:12 +01:00
Alex Ford
4e119cc085
consider empty files (no ruby tokens) to have 0 lines
2021-04-21 11:29:55 +01:00
Alex Ford
a8597025aa
fixed logic for line counting
2021-04-21 11:29:09 +01:00
Alex Ford
bcc1be05de
use explicit this prefixes in FileSystem.qll
2021-04-21 10:51:28 +01:00
Alex Ford
85ecacd858
make helper predicates private
2021-04-21 10:50:00 +01:00
Alex Ford
9d117d10b8
drop MetricFile class
2021-04-21 10:45:42 +01:00
Alex Ford
c6b6a83501
extend FLines* tests
2021-04-21 10:42:53 +01:00
Alex Ford
a1c91e28da
move FLines* tests to a common directory
2021-04-21 10:34:58 +01:00
Alex Ford
fcd46025fe
update metadata for FLines* queries
2021-04-21 10:28:20 +01:00
Arthur Baars
abb37e212a
Merge pull request #165 from github/aibaars/methods
...
Implement method lookup
2021-04-21 11:24:20 +02:00
Arthur Baars
549e5ab9d6
Revert "Rename Method -> MethodDeclaration"
...
This reverts commit d361ef37af .
2021-04-21 10:50:47 +02:00
Arthur Baars
1245674df8
Add missing @id properties
2021-04-21 10:50:47 +02:00
Alex Ford
50a0f282bf
add basic tests for FLines queries
2021-04-20 17:36:16 +01:00
Alex Ford
f0d1498c8c
Revert "WIP: populate numlines table"
...
This reverts commit 62bf58b289 .
2021-04-20 17:36:16 +01:00
Alex Ford
37cce23c26
add FLines.ql, FLinesOfComments.ql
2021-04-20 17:36:16 +01:00
Alex Ford
d6c7846089
put logic for determining line counts into MetricFile
2021-04-20 17:36:16 +01:00
Arthur Baars
122315db3f
Remove 'Method' class
2021-04-20 13:41:11 +02:00
Alex Ford
28e46c8915
add FLinesOfCode.ql metric query
2021-04-20 10:12:52 +01:00
Alex Ford
7bfc61789d
line count MetricFile predicates
2021-04-19 18:08:01 +01:00
Alex Ford
62bf58b289
WIP: populate numlines table
2021-04-19 18:06:35 +01:00
Arthur Baars
bf4f91e038
Address comments
2021-04-16 16:37:42 +02:00
Arthur Baars
07726fd979
Add some module and method tests
2021-04-16 11:07:57 +02:00
Arthur Baars
bf556a2b53
Implement method lookup
2021-04-15 11:32:43 +02:00
Arthur Baars
5837af0936
Add MethodBase::getMethod
2021-04-15 11:32:43 +02:00
Arthur Baars
d361ef37af
Rename Method -> MethodDeclaration
2021-04-15 11:32:43 +02:00
Arthur Baars
3590a2c2ac
Merge pull request #164 from github/aibaars/fix-modules
...
Improve module/class resolution
2021-04-15 11:32:28 +02:00
Arthur Baars
24bb11b20a
Improve module/class resolution
2021-04-14 17:14:38 +02:00
Arthur Baars
12ee957331
Add test cases
2021-04-14 17:12:39 +02:00
Arthur Baars
3b73d41cc4
Merge pull request #163 from github/aibaars/modules-2
...
Ignore include/prepend statements in blocks
2021-04-14 17:09:34 +02:00
Arthur Baars
9afda342bc
Address comments
2021-04-14 09:57:49 +02:00
Arthur Baars
754bfdd136
Ignore include/prepend statements in blocks
...
Include and prepend statements are rarely used in block in normal code and when
used in normal code they tend to be in blocks that are passed to methods like
`module_eval` which is a builtin method that evaluates a block in the context
of some other module (typically created with Module.new). We currently don't attempt
to track such "dynamically" constructed modules, and ignoring such modules
and the `module_eval` calls on them seems fine for now.
Another, much more frequent use of include/prepend statements in blocks is in Rspec.describe and
Rspec.context method calls in tests. Rspec also evaluates those blocks in the context of some
special Rspec class. Precisely tracking such calls during the initial construction of the module/class
hierarchy would be really hard and there would be little benefit because the interesting modules and classes of
an application are not defined in test files.
2021-04-14 09:53:19 +02:00
Arthur Baars
280fe73063
Add test case with 'module_eval' call with block containing 'prepend' statement
2021-04-14 09:53:19 +02:00
Arthur Baars
caef2c36c7
Merge pull request #162 from github/aibaars/modules
...
Basic implementation of module resolution
2021-04-09 20:50:54 +02:00
Arthur Baars
cdfabbc95d
Make Cached module private
2021-04-09 16:47:02 +02:00
Arthur Baars
a247544fc5
Add comments
2021-04-09 16:35:23 +02:00
Arthur Baars
7bc5be93ff
Module: make main predicates cached
2021-04-09 13:29:27 +02:00
Arthur Baars
2db999d0da
Improve module resolution
2021-04-09 09:51:24 +02:00
Arthur Baars
ceb2eb21d8
Address comments
2021-04-08 15:11:57 +02:00
Arthur Baars
039e8b36a5
Add some include/prepend tests
2021-04-07 17:27:33 +02:00
Arthur Baars
84f6e902ea
AST: move some scope related methods to AstNode
2021-04-07 17:16:10 +02:00
Arthur Baars
063b085078
Address comments
2021-04-07 15:57:13 +02:00
Arthur Baars
50b8b6b257
Also resolve constants with respect to the ancestors
...
of the enclosing module.
2021-04-06 15:47:13 +02:00
Arthur Baars
f12e6ea8ea
Avoid 'Object::' prefixes
2021-03-30 16:14:21 +02:00
Arthur Baars
b2c7185664
Add tests
2021-03-30 15:49:41 +02:00
Arthur Baars
201c1e4b81
Basic module resolution
2021-03-30 15:40:03 +02:00
Arthur Baars
ea9afcd4e1
AST: make some classes instance of Scope
2021-03-30 15:40:03 +02:00
Arthur Baars
eebbc7e505
AST: rename Class/Module to ClassDefinition/ModuleDefinition
2021-03-30 15:40:01 +02:00
mr-sherman
bf2d7b3a16
Added IRestClientAsync methods to external location sink. Removed import from
...
Remote.qll, as it is un-necessary now.
2021-03-29 14:37:51 -04:00
mr-sherman
13997caa32
feedback from code review
2021-03-26 16:29:14 -04:00
Tom Hvitved
aad5d133d0
Merge pull request #161 from github/hvitved/cfg-remove-is-hidden
...
CFG: Remove `isHidden()` predicate
2021-03-25 15:08:17 +01:00
Tom Hvitved
0bb5007103
Reintroduce hidden then/else/do in AST; include all in CFG
2021-03-25 14:22:35 +01:00
Tom Hvitved
58ecd771d3
AST: Exclude empty then/else/do statements
2021-03-25 09:53:55 +01:00
Tom Hvitved
ca7c0584c7
CFG: Remove isHidden() predicate
2021-03-24 17:22:05 +01:00
Tom Hvitved
9472cef492
Merge pull request #160 from github/bump-codeql
...
Bump `codeql` sub module and implement new data-flow stubs
2021-03-24 15:34:42 +01:00
Tom Hvitved
6c00e66272
Update ql/src/codeql_ruby/dataflow/internal/DataFlowPrivate.qll
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-03-24 15:02:30 +01:00
Tom Hvitved
b8f65fb756
Bump codeql sub module and implement new data-flow stubs
2021-03-24 14:00:21 +01:00
mr-sherman
3e889c398e
updated document formatting
2021-03-23 10:09:30 -04:00
Arthur Baars
d103acb04f
Merge pull request #158 from github/hvitved/vscode-hide-codeql-submodule
...
Hide `codeql` sub module in VS Code workspace
2021-03-23 10:41:32 +01:00
Arthur Baars
6a26483fc7
Merge pull request #159 from github/hvitved/herdoc-body-rank-performance
...
Improve performance of `HereDoc::getBody()`
2021-03-23 10:40:28 +01:00
Tom Hvitved
2891d94f99
Improve performance of HereDoc::getBody()
...
Gets rid of
```
[2021-03-23 10:07:49] (138s) Tuple counts for Literal::HereDoc::getBody_dispred#ff#shared#1/4@1cc5b9:
11294 ~0% {1} r1 = SCAN AST::Cached::THereDoc#ff@staged_ext OUTPUT In.0
11294 ~388% {1} r2 = JOIN r1 WITH Literal::HereDoc::getBody_dispred#ff#join_rhs ON FIRST 1 OUTPUT Rhs.1 'arg1'
95514613 ~2080% {4} r3 = JOIN r2 WITH locations_default_1023#join_rhs ON FIRST 1 OUTPUT Rhs.1 'arg0', Lhs.0 'arg1', Rhs.2 'arg2', Rhs.3 'arg3'
```
2021-03-23 10:31:48 +01:00
Tom Hvitved
1004363131
Hide codeql sub module in VS Code workspace
2021-03-23 09:55:56 +01:00
mr-sherman
858c0e67a1
added support for remote flow sinks in the form of parameters to the function
...
ServiceStack.IRestClient.Get()
2021-03-22 19:27:49 -04:00
Nick Rolfe
b293522710
Merge pull request #150 from github/parent_child
...
Create `ast_node_parent` relation
2021-03-22 15:06:50 +00:00
Nick Rolfe
e7f1ae8c96
Merge remote-tracking branch 'origin/main' into parent_child
2021-03-22 14:58:33 +00:00
Nick Rolfe
3284a3fc1f
Merge pull request #157 from github/cfg_impl
...
Port CFG implementation to public AST interface
2021-03-22 14:57:43 +00:00
Nick Rolfe
cf7ce911bc
Combine CfgScope classes for BodyStmt ∩ Callable
2021-03-19 16:08:43 +00:00
Nick Rolfe
7667606b89
Replace some uses of Generated types
2021-03-19 14:31:17 +00:00
Nick Rolfe
21192bf43c
Remove outdated comment
2021-03-19 14:28:26 +00:00
Nick Rolfe
f37c862c92
Rename MandatoryParameterTree to NonDefaultValueParameterTree
2021-03-19 14:27:29 +00:00
Nick Rolfe
c6958f64e4
Make CFG for AssignExpr visit left operand before right
2021-03-19 14:25:38 +00:00
Nick Rolfe
f381f94bc2
Rename ProgramScope to ToplevelScope
2021-03-19 14:02:54 +00:00
Nick Rolfe
5cedf7ee86
Remove unused import
2021-03-19 13:59:02 +00:00
Tom Hvitved
e175513293
Remove duplicate tuple patterns
2021-03-19 10:52:29 +01:00
jorgectf
957b3e1e85
Precision warn
2021-03-18 20:39:53 +01:00
jorgectf
3ce0a9c8c0
Move to experimental folder
2021-03-18 20:20:04 +01:00
Nick Rolfe
c0636bef29
Make CfgScope extend Scope
2021-03-18 19:08:51 +00:00
Nick Rolfe
6bcc433af3
Uncomment empty class and module in CFG test
2021-03-18 19:02:32 +00:00
Nick Rolfe
9493997e9d
Make space in CFG test for two new lines in the middle
...
Commented out to make it easier to ignore the noise from line number
changes.
2021-03-18 19:01:11 +00:00
Nick Rolfe
37435764a0
Fix control-flow for empty classes and modules
2021-03-18 18:58:40 +00:00
jorgectf
7de9214c99
Upload LDAP Insecure authentication query and tests
2021-03-18 17:41:34 +01:00
Nick Rolfe
434d9e54a1
Fix complex symbols having multiple ControlFlowTree implementations
2021-03-18 14:48:08 +00:00
Nick Rolfe
4ce7faf868
Fix erroneous flow from 'raise' call to StmtSequence
2021-03-18 13:01:27 +00:00
Nick Rolfe
ceda7c8fd2
Generalise splitting of parenthesized exprs to all statement sequences
2021-03-18 11:21:11 +00:00
Nick Rolfe
c8eab42c1d
Minor comment fixes
2021-03-18 11:09:21 +00:00
Tom Hvitved
3bb2c529a5
CFG: Revert change to mandatory parameters
2021-03-18 10:43:10 +01:00
Arthur Baars
d4030c66d8
Update Consistency.qll
2021-03-18 09:54:44 +01:00
Tom Hvitved
c761ab6882
Merge pull request #156 from github/hvitved/ipa-ast
...
Make external `AstNode` an IPA type
2021-03-17 22:23:05 +01:00
Nick Rolfe
32e2b257bf
Port CFG implementation to public AST interface
2021-03-17 20:28:47 +00:00
Nick Rolfe
26c251f080
Order CFG nodes by column as well
2021-03-17 19:07:52 +00:00
Tom Hvitved
39aa2c6e53
Rework IPA injectors for constant accesses
2021-03-17 14:27:21 +01:00
Tom Hvitved
eb7610c55f
Rename (to|from)TreeSitter to (to|from)Generated
2021-03-17 09:28:23 +01:00
Tom Hvitved
5724112513
Address review comments
2021-03-17 09:28:18 +01:00
Tom Hvitved
7eaf02a0bf
Make external AstNode an IPA type
2021-03-16 12:50:20 +01:00
Arthur Baars
c672169621
Merge pull request #155 from github/aibaars/order-ast-test
...
AST: order edges by target node
2021-03-15 10:43:34 +01:00
Arthur Baars
d54db292f7
Move semmle.order property to printAst.qll
2021-03-15 10:33:10 +01:00
Arthur Baars
3e5ff1d042
AST: order edges by target node
...
When printing a tree CodeQL iterates over the nodes and
for each node prints the successor edges as children. If the
the successor edges are ordered by target node then the children
printe in the right order in the expected output.
2021-03-12 16:52:34 +01:00
Arthur Baars
cde496cc4c
Merge pull request #152 from github/aibaars/fix-vars
...
Fix VariableRead/WriteAcess for instance and class variables
2021-03-11 17:05:56 +01:00
Calum Grant
bf873c8ad1
Merge pull request #147 from github/calumgrant/use-detect
...
Ruby: New query UseDetect
2021-03-10 14:39:37 +00:00
Calum Grant
cb977cb290
Ruby: Use getAUniqueRead TC
2021-03-10 10:56:33 +00:00
Arthur Baars
3966de6b2b
Merge pull request #151 from github/aibaars/scopes-refactor
...
Add Scopes.qll and remove VariableScopes IPA type
2021-03-09 20:55:18 +01:00
Arthur Baars
6a284378d6
Update ql/src/codeql_ruby/ast/Scope.qll
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-03-09 18:57:24 +01:00
Arthur Baars
f28071ceb6
Fix VariableRead/WriteAcess for instance and class variables
2021-03-09 13:55:55 +01:00
Arthur Baars
600d9c66ae
Remove VariableScope
2021-03-09 11:56:17 +01:00
Arthur Baars
86a89ab1fe
Remove VariableScope IPA type
2021-03-09 11:48:18 +01:00
Calum Grant
855d190800
Ruby: Test local data flow
2021-03-09 10:25:24 +00:00
Calum Grant
5b4bf584a1
Ruby: Update qltest output for new select format
2021-03-09 10:20:23 +00:00
Calum Grant
0f829476f4
Ruby: Refactor EndCall to reduce number of classes
2021-03-09 10:13:07 +00:00
Arthur Baars
00260db58f
Add Scope.qll
2021-03-09 09:46:42 +01:00
Nick Rolfe
56e03d7ed4
Remove old upgrades
2021-03-08 18:28:23 +00:00
Nick Rolfe
be102e24f6
Update stats
2021-03-08 18:25:37 +00:00
Nick Rolfe
f691ec9e2a
Remove overrides of getParent[Index]
2021-03-08 18:25:37 +00:00
Nick Rolfe
9b96bc32cc
Add ast_node_parent relation
2021-03-08 18:25:37 +00:00
Nick Rolfe
61b3aa8f27
Merge pull request #149 from github/manual_stats_workflow
...
Enable manual dispatch of stats workflow
2021-03-08 14:28:27 +00:00
Nick Rolfe
df8f7a30d7
Enable manual dispatch of stats workflow
2021-03-08 14:10:37 +00:00
Nick Rolfe
1818b68ea2
Merge pull request #148 from github/calumgrant/readme-qltest
...
Update README.md
2021-03-04 19:36:42 +00:00
Calum Grant
67416a6440
Update README.md
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-03-04 17:19:34 +00:00
Calum Grant
0be5c529ee
Update README.md
2021-03-04 16:03:23 +00:00
Calum Grant
20a62d169a
Ruby: Update query description
2021-03-04 15:48:09 +00:00
Calum Grant
ca497479c2
Ruby: Finish the test for UseDetect
2021-03-04 15:44:05 +00:00
Calum Grant
522bcff79d
Ruby: Initial test case
2021-03-04 15:38:09 +00:00
Calum Grant
5854b831f3
Ruby: rb/use-detect query
2021-03-04 13:43:59 +00:00
Arthur Baars
ce69c912fd
Merge pull request #145 from github/aibaars/fix
...
Fix regression in rb/unused-parameter
2021-03-01 12:26:47 +01:00
Arthur Baars
c9f86743bd
Merge pull request #143 from github/aibaars/ast-test
...
AST: add printAST test case
2021-02-26 19:41:56 +01:00
Arthur Baars
b2fbeee794
CFG: hide all non-AstNodes
2021-02-26 19:04:33 +01:00
Arthur Baars
5f32b822e2
Remove use of AstNodes
2021-02-26 19:03:55 +01:00
Arthur Baars
dd4f297c37
Remove duplicate clause
2021-02-26 17:51:04 +01:00
Arthur Baars
39181ec871
AST: printAST: show all primary classes and method names
2021-02-25 15:25:49 +01:00
Arthur Baars
e2b2a450ac
AST: add printAST test case
2021-02-25 15:25:49 +01:00
Arthur Baars
75883b94cd
QLTest: ignore *.testproj folders
2021-02-25 15:25:42 +01:00
Arthur Baars
7ab147a7b8
Merge pull request #144 from github/aibaars/missing
...
AST: add missing getAPrimaryQlClass predicate
2021-02-25 15:18:29 +01:00
Arthur Baars
a6bb34c86d
AST: add missing getAPrimaryQlClass predicate
2021-02-25 14:59:39 +01:00
Arthur Baars
fa7adee245
Merge pull request #142 from github/aibaars/clean-up
...
Remove as many references to TreeSitter::Generated
2021-02-25 14:28:09 +01:00
Arthur Baars
9800e3f930
Add some TODO comments
2021-02-25 13:43:36 +01:00
Arthur Baars
f3d1c804be
Update test data
2021-02-25 12:57:18 +01:00
Arthur Baars
7c0ea7b3bc
CFG: add AstNode for @in
2021-02-25 12:57:18 +01:00
Arthur Baars
b16d6bf5b4
CFG: make isValidFor work for hidden nodes
2021-02-25 12:57:18 +01:00
Arthur Baars
9fc5c43412
Clean-up Completion.qll
2021-02-25 12:57:18 +01:00
Arthur Baars
999b82ca73
Remove imports of TreeSitter
2021-02-25 12:57:18 +01:00
Arthur Baars
d30912611b
Merge pull request #136 from github/aibaars/child-parent
...
Finish AST and add consistency query
2021-02-25 12:54:45 +01:00
Arthur Baars
27a2310840
CFG: sort expected output by file path and line
2021-02-25 12:27:11 +01:00
Arthur Baars
87b2c142bc
Update qldoc
2021-02-25 10:23:29 +01:00
Arthur Baars
4ba0f3088a
Use strictcount
2021-02-25 10:21:07 +01:00
Arthur Baars
0f940349ba
AST: rename getExpr predicates to more meaningful names
2021-02-25 10:11:29 +01:00
Arthur Baars
1a73cf6cc4
AST: add ArgumentList
2021-02-24 19:07:16 +01:00
Arthur Baars
336b310668
AST: improve AST for special parameters
2021-02-24 19:07:16 +01:00
Arthur Baars
8913810bf0
AST: change return type of Assignment LHS to Pattern
2021-02-24 19:07:16 +01:00
Arthur Baars
190978cc56
AST: add consistency query
2021-02-24 19:07:16 +01:00
Arthur Baars
cb21e8edda
CFG: hide nodes that are not proper AstNodes
2021-02-24 19:07:16 +01:00
Arthur Baars
14474d660b
AST: change types to Stmt
2021-02-24 19:07:16 +01:00
Arthur Baars
3288070279
Merge pull request #131 from github/aibaars/pattern
...
AST: split method call into normal and setter calls
2021-02-24 19:03:55 +01:00
Arthur Baars
a7408dd262
Merge pull request #140 from github/aibaars/namespace
...
AST: introduce 'Namespace' as super class of Class/Module
2021-02-24 13:22:02 +01:00
Arthur Baars
242481c701
Apply suggestions from code review
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-02-24 13:13:47 +01:00
Arthur Baars
d6c0049a7e
AST: make SetterMethodCall instance of MethodCall
2021-02-24 13:06:54 +01:00
Arthur Baars
7ae20f3b5b
AST: add SetterMethodCall as instance of LhsExpr
2021-02-24 13:06:54 +01:00
Arthur Baars
79bb20b31f
AST: add MethodCall as a subclass of Call
2021-02-24 13:06:53 +01:00
Arthur Baars
5fe7bd57fa
AST: calls without method name
2021-02-24 13:02:22 +01:00
Arthur Baars
eaeabf19bf
Merge pull request #141 from github/bump_ts
...
Add support for multiple statements in interpolations
2021-02-24 11:29:26 +01:00
Nick Rolfe
37253fd1f1
Update stats for dbscheme change to interpolation_child
2021-02-23 16:08:24 +00:00
Nick Rolfe
6c84f2c3dc
Add test case for multiple statements in interpolation
2021-02-23 15:52:11 +00:00
Nick Rolfe
672148e5b4
Add support for multiple statements in interpolations
2021-02-23 15:36:14 +00:00
Arthur Baars
a7ddd642ea
AST: introduce 'Namespace' as super class of Class/Module
2021-02-19 13:34:34 +01:00
Arthur Baars
098e0ac142
Merge pull request #139 from github/printast
...
printAst: use the user-facing AST library
2021-02-19 09:46:27 +01:00
Nick Rolfe
d52e439547
printAst: use the user-facing AST library
2021-02-18 18:25:57 +00:00
Arthur Baars
370135fab7
Merge pull request #138 from github/aibaars/part-1
...
AST: getChild/getParent
2021-02-18 19:00:08 +01:00
Arthur Baars
1c8a76f44a
AST: make Assignment::getLeftOperand a Pattern again
2021-02-18 18:14:55 +01:00
Arthur Baars
c877eb4642
AST: add additional token-types to variable patterns
2021-02-18 14:37:58 +01:00
Arthur Baars
3ee83870b6
AST: add begin expressions
2021-02-18 14:37:58 +01:00
Arthur Baars
5659388ec0
AST: implement AstNode::child
2021-02-18 14:37:58 +01:00
Arthur Baars
c0b5ac760a
AST: rename getLhs/getRhs to getLeftOperand/getRightOperand
2021-02-18 14:37:58 +01:00
Arthur Baars
095eb803b3
AST: improve type of getDefaultValue
2021-02-18 14:37:58 +01:00
Arthur Baars
e42d1ff936
Change Expr to LhsExpr for getVariableExpr
2021-02-18 14:37:58 +01:00
Arthur Baars
214f113016
AST: add getChild/getParent method
2021-02-18 14:37:53 +01:00
Nick Rolfe
ac3da22158
Merge pull request #137 from github/scope_tostring
...
Include file/class/method/module names in VariableScope::toString
2021-02-17 19:24:36 +00:00
Nick Rolfe
b8bbbe92f3
Include file/class/method/module names in VariableScope::toString
2021-02-17 18:10:03 +00:00
Nick Rolfe
aedf093e72
Merge pull request #135 from github/aibaars/heredoc
...
AST: HereDoc
2021-02-17 17:18:38 +00:00
Arthur Baars
cabe6df820
Add missing heredoc end token
2021-02-17 15:58:13 +01:00
Arthur Baars
e1047fad2c
CFG: remove intermediate HeredocBody nodes
2021-02-17 13:10:18 +01:00
Arthur Baars
167574d82f
AST: HereDoc
2021-02-17 13:10:18 +01:00
Arthur Baars
1e19904342
Merge pull request #134 from github/literals
...
Add and expand AST classes for literals
2021-02-17 13:09:02 +01:00
Nick Rolfe
c019da83f3
Address feedback on StringInterpolationComponent::getStmt
2021-02-17 10:57:01 +00:00
Nick Rolfe
97654eb338
Simplify bash script
2021-02-17 10:48:17 +00:00
Arthur Baars
4f5b1c06ac
Merge branch 'main' into literals
2021-02-16 19:30:03 +01:00
Arthur Baars
3f4b4b360e
Merge pull request #133 from github/aibaars/pattern-0
...
AST: RestAssignment and LhsExpr
2021-02-16 19:29:15 +01:00
Nick Rolfe
3978d6387e
Update tree-sitter-ruby revision used
2021-02-16 16:49:59 +00:00
Nick Rolfe
4537e5d6f8
Update expected test output to match truncation of long strings
2021-02-16 16:21:49 +00:00
Nick Rolfe
02f853b8fd
Add r suffix to RationalLiteral::getValueText()
2021-02-16 16:21:28 +00:00
Nick Rolfe
cd38b980a8
Update dbscheme stats
2021-02-16 16:13:00 +00:00
Nick Rolfe
fff5dad702
Truncate long strings in StringlikeLiteral::toString()
2021-02-16 16:11:41 +00:00
Arthur Baars
7dd429c945
Format Expr.qll
2021-02-16 15:41:44 +00:00
Nick Rolfe
1c869f6d85
Make merge_stats.py work in python3
2021-02-16 15:41:44 +00:00
Nick Rolfe
5e6ef5c8b5
Upgrade script for dbscheme changes to range_*
2021-02-16 15:41:44 +00:00
Nick Rolfe
2eb8757285
Update expected test output for toString changes
2021-02-16 15:41:05 +00:00
Nick Rolfe
f56f81f555
Add and expand AST classes for literals
2021-02-16 15:41:05 +00:00
Arthur Baars
c4b3c8bc28
More QLDoc for LhsExpr
2021-02-16 16:09:56 +01:00
Arthur Baars
e3cf226679
AST: make ConstantWriteAccess extend LhsExpr
2021-02-16 13:03:04 +01:00
Arthur Baars
9d449a90c2
AST: add LhsExpr
2021-02-16 13:02:02 +01:00
Arthur Baars
7778f1c21f
AST: make Pattern:Range abstract
2021-02-16 13:01:00 +01:00
Arthur Baars
9c5da197ed
AST: add Pattern::getRestIndex
2021-02-16 12:56:06 +01:00
Arthur Baars
eee12eecc9
Merge pull request #132 from github/rescue_naming
...
Rename {Rescue,RescueExpr} to {RescueExpr,RescueModifierExpr}
2021-02-16 12:54:19 +01:00
Nick Rolfe
04ad1f805a
Update rust auto-formatting for 1.50
2021-02-16 11:47:24 +00:00
Nick Rolfe
0fc19ea7a9
Rename RescueExpr to RescueClause
2021-02-16 11:46:30 +00:00
Nick Rolfe
cf50006d68
Rename {Rescue,RescueExpr} to {RescueExpr,RescueModifierExpr}
2021-02-16 11:09:25 +00:00
Arthur Baars
90f59de589
Merge pull request #130 from github/aibaars/ast-5
...
AST: add ElementReference as call
2021-02-15 14:59:34 +01:00
Arthur Baars
ad6c916f01
Merge pull request #129 from github/aibaars/ast-4
...
AST: rescue modifier
2021-02-15 14:59:22 +01:00
Arthur Baars
c6c39ad04d
Merge pull request #128 from github/aibaars/ast-3
...
AST: undef and alias
2021-02-15 14:59:12 +01:00
Arthur Baars
5b8c74eb5b
AST: add SingletonMethod::getObject
2021-02-15 13:53:50 +01:00
Arthur Baars
e3f54411d8
AST: add ElementReference
2021-02-15 13:51:16 +01:00
Arthur Baars
d69a1731f9
Fix QL doc
2021-02-15 12:53:13 +01:00
Arthur Baars
ddea74265d
AST: rescue modifier
2021-02-15 12:50:00 +01:00
Arthur Baars
9cb58be5cf
AST: avoid multivalued results for MethodName::getValueText
2021-02-15 10:39:21 +01:00
Arthur Baars
8a4f27c052
Add test case
2021-02-12 19:23:13 +01:00
Arthur Baars
5f1907efc4
AST: undef and alias
2021-02-12 19:22:51 +01:00
Arthur Baars
392af7fe76
Merge pull request #127 from github/aibaars/ast-2
...
Some more AST
2021-02-12 18:40:24 +01:00
Arthur Baars
c0c155361f
Address comments
2021-02-12 18:31:44 +01:00
Arthur Baars
874ac121d9
AST: Toplevel and BEGIN/ END blocks
2021-02-12 15:26:30 +01:00
Arthur Baars
015b581f57
AST: add redo, retry, empty-statement
2021-02-12 15:18:28 +01:00
Arthur Baars
64cba18c41
AST: add Self class
2021-02-12 14:09:00 +01:00
Arthur Baars
ce824f4adb
Merge pull request #126 from github/aibaars/rescue
...
AST: rescue clauses
2021-02-12 14:08:31 +01:00
Arthur Baars
63f67aa04e
AST: rename getVariable to getVariableExpr
2021-02-12 13:35:17 +01:00
Tom Hvitved
1aaebeea76
Merge pull request #125 from github/hvitved/cfg-to-string
...
CFG: Reintroduce `toString()`s
2021-02-11 18:46:26 +01:00
Arthur Baars
43b238f729
AST: rescue clauses
2021-02-11 18:40:29 +01:00
Tom Hvitved
c4ee79ed27
CFG: Reintroduce toString()s
2021-02-11 18:37:18 +01:00
Nick Rolfe
307db73c9c
Merge pull request #124 from github/aibaars/ast-stmt-expr
...
AST: make Expr extend Stmt and change ExprSequence to StmtSequence
2021-02-11 17:00:21 +00:00
Arthur Baars
f9e9dc2304
Address comment
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-02-11 17:53:28 +01:00
Arthur Baars
c4e2c87d82
AST: some statement tests
2021-02-11 17:20:11 +01:00
Arthur Baars
d42b6b651e
AST: rename ExprSequence to StmtSequence
2021-02-11 17:20:10 +01:00
Arthur Baars
fd6aeba9f5
AST: make Expr extend Stmt
2021-02-11 17:20:10 +01:00
Arthur Baars
f02d4a977d
AST: some statement tests
2021-02-11 17:20:10 +01:00
Arthur Baars
d02d359c51
Merge pull request #122 from github/constants_scopes
...
Rework handling of scope resolution nodes, and add `ConstantAccess` class
2021-02-11 17:19:47 +01:00
Arthur Baars
ada652b6f0
Merge branch 'main' into constants_scopes
2021-02-11 17:00:50 +01:00
Nick Rolfe
885137dca2
Simplify representation of calls that use scope resolution operator.
...
Now, `Foo::bar` is a call where the receiver expr is `Foo`.
2021-02-11 15:29:42 +00:00
Arthur Baars
f8ce7276a3
Merge pull request #123 from github/aibaars/ast-ensure
...
AST: ensure and else blocks
2021-02-11 15:17:30 +01:00
Arthur Baars
a908f2fe86
Merge pull request #121 from github/aibaars/dataflow-2
...
Dataflow: identify ReturnNodes
2021-02-11 15:10:27 +01:00
Arthur Baars
426bf30822
AST: ensure and else blocks
2021-02-11 14:27:23 +01:00
Arthur Baars
4f3412fff9
Address comments
2021-02-11 13:46:34 +01:00
Nick Rolfe
23998e5f99
Accept CFG test changes
...
Some generated ScopeResolution nodes are no longer represented in the
user-facing AST. These should go away when we port the CFG to the
user-facing AST.
2021-02-11 12:38:13 +00:00
Nick Rolfe
6ff0ebb94a
Add ConstantAccess class
2021-02-11 12:29:25 +00:00
Nick Rolfe
452a343e86
Remove ScopeResolution from AST
...
Now we handle it specially in calls and class/module names, so they have
predicate to get the scope expr.
2021-02-10 17:53:25 +00:00
Arthur Baars
0f6854301e
Dataflow: identify ReturnNodes
2021-02-10 18:26:11 +01:00
Arthur Baars
d69aa96f23
More tests
2021-02-10 18:26:11 +01:00
Arthur Baars
6c63bd2586
Merge pull request #120 from github/aibaars/ast
...
AST: lambda and block bodies
2021-02-10 18:25:37 +01:00
Arthur Baars
635b6fb45b
AST: lambda and brace block bodies
2021-02-10 14:45:14 +01:00
Arthur Baars
d4ebcbf18f
Merge pull request #118 from github/aibaars/dataflow
...
More dataflow steps
2021-02-09 20:36:28 +01:00
Tom Hvitved
9cfc08319d
Use Generated::AstNode in ExprChildMapping
2021-02-09 19:32:41 +01:00
Arthur Baars
1e64b264ba
Fix compilation errors after merge
2021-02-09 18:50:30 +01:00
Arthur Baars
3e0b7c491a
Merge remote-tracking branch 'origin/main' into aibaars/dataflow
2021-02-09 18:49:53 +01:00
Tom Hvitved
248f5cd648
Merge pull request #119 from github/hvitved/ast-range
...
Rangify `AstNode`
2021-02-09 16:47:50 +01:00
Tom Hvitved
85c13a1190
Make entries in RemoveWhenFullCoverage explicit
2021-02-09 16:34:25 +01:00
Arthur Baars
daa7bd7fd4
Move ReturningStmt::getValue implementation to internal library
2021-02-09 14:01:08 +01:00
Arthur Baars
e398837bdc
Rename Statement to Stmt
2021-02-09 13:55:06 +01:00
Arthur Baars
bb89e134c4
Address comments
2021-02-09 13:54:46 +01:00
Tom Hvitved
32daf28b34
Rangify AstNode
2021-02-09 12:17:21 +01:00
Arthur Baars
a752491c5f
Add flow steps for loop 'return' values
2021-02-08 19:06:07 +01:00
Arthur Baars
adb88df638
Add flow steps for conditional and case expressions
2021-02-08 19:00:47 +01:00
Arthur Baars
c991d550cd
AST: add Statement and ReturningStatement
2021-02-08 19:00:47 +01:00
Arthur Baars
bde04d48a2
Merge pull request #116 from github/aibaars/cfg-loop-post-order
...
CFG: make loop expressions post order
2021-02-08 09:53:25 +01:00
Arthur Baars
f2a6f3aadc
Update comments
2021-02-08 09:47:33 +01:00
Arthur Baars
37c4e6cbdf
Merge pull request #98 from github/aibaars/erb-extractor
...
Quick and dirty ERB extraction
2021-02-05 18:45:47 +01:00
Arthur Baars
b553eb6964
CFG: make 'for .. in' post-order
...
Use the 'in' as the intermediate node that checks whether the Enumerable
has more elements.
2021-02-05 18:23:31 +01:00
Arthur Baars
4ae55a718a
CFG: make 'while' post-order
2021-02-05 18:23:31 +01:00
Arthur Baars
5bb32b983c
Merge pull request #115 from github/aibaars/dataflow
...
My first dataflow step
2021-02-05 14:13:38 +01:00
Arthur Baars
846173732b
Add newline at the end of each code region in an ERB file
2021-02-05 09:49:25 +01:00
Arthur Baars
9d974bd56d
Extract ERB files
2021-02-05 09:48:54 +01:00
Arthur Baars
bc55fa861e
Merge pull request #114 from github/aibaars/fix-scopes
...
Correct the scope of class/method names etc.
2021-02-04 17:22:25 +01:00
Arthur Baars
83bcd26244
Add dataflow step tests
2021-02-04 16:09:50 +01:00
Arthur Baars
62802d53c8
Ensure module/class/methods and their headers belong to the right CfgScope
2021-02-04 15:32:20 +01:00
Arthur Baars
bfc5ee3149
Correct the scope of class/method names etc.
2021-02-04 15:30:58 +01:00
Arthur Baars
a998879897
Add local flow step for parenthesized expressions
2021-02-04 14:06:58 +01:00
Arthur Baars
f8cca01e6f
Restrict assigment flow to normal assignments only
2021-02-04 14:04:58 +01:00
Arthur Baars
8368a39f00
QLDoc updates
2021-02-04 13:40:06 +01:00
Arthur Baars
da565875df
Merge pull request #112 from github/hvitved/ssa/shared-sync
...
SSA: Sync with latest changes
2021-02-04 13:39:32 +01:00
Arthur Baars
8cec8699a7
Merge pull request #113 from github/aibaars/parenthesized-expr
...
AST: add ParenthesizedExpr
2021-02-04 13:36:47 +01:00
Arthur Baars
2035bc4d3a
AST: add ParenthesizedExpr
2021-02-04 11:51:05 +01:00
Nick Rolfe
61d9669655
Merge pull request #110 from github/class_ast
...
Add AST classes for classes and modules
2021-02-03 19:32:55 +00:00
Tom Hvitved
16c4faef6a
SSA: Sync with latest changes
...
Now that the shared SSA library supports uncertain/pseudo reads, we can simplify
the Ruby implementation.
2021-02-03 20:31:36 +01:00
Nick Rolfe
c5fca0cb6b
Add ModuleBase base class and combine class/module tests
2021-02-03 16:13:59 +00:00
Arthur Baars
3c0f822369
Merge pull request #111 from github/hvitved/dataflow
...
Initial data flow library
2021-02-03 13:43:08 +01:00
Tom Hvitved
de77a7f96d
Initial data-flow files
2021-02-03 10:57:14 +01:00
Nick Rolfe
8976cc556a
Update test to match removal of Module::getAClass()
2021-02-02 18:02:16 +00:00
Nick Rolfe
ee03e84d7f
Rename Class.qll to Module.qll
2021-02-02 18:00:29 +00:00
Nick Rolfe
645b8c2a8a
Apply suggestions from code review
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2021-02-02 17:54:00 +00:00
Tom Hvitved
f71505c29c
Data flow: Sync files
2021-02-02 13:03:42 +01:00
Nick Rolfe
6331a33b23
Update dbscheme stats
2021-02-01 14:41:00 +00:00
Nick Rolfe
c667791bde
Update expected test output to match toString() for classes and modules
2021-02-01 14:23:47 +00:00
Nick Rolfe
0649e6c3b0
Update CFG to handle separate superclass node
2021-02-01 14:23:47 +00:00
Nick Rolfe
fbc1c5e8c0
Add test for Module
2021-02-01 14:23:47 +00:00
Nick Rolfe
86bb8a246b
Add test for Class and SingletonClass
2021-02-01 14:23:47 +00:00
Nick Rolfe
d26822ad23
Add upgrade script moving superclass exprs to own table
2021-02-01 14:23:47 +00:00
Nick Rolfe
443a992a90
Add AST classes for classes and modules
2021-02-01 14:23:41 +00:00
Arthur Baars
2770b4fef8
Merge pull request #104 from github/aibaars/variables
...
Simple implementation of class and instance variables
2021-01-29 18:28:25 +01:00
Arthur Baars
c33c3a1124
Address comments
2021-01-29 17:45:48 +01:00
Arthur Baars
6a7e3bfc10
Address comments
2021-01-29 17:45:48 +01:00
Arthur Baars
2921f72473
Implement class variables
2021-01-29 17:45:48 +01:00
Arthur Baars
a07e0fb0f7
Class variables boilerplate code
2021-01-29 17:45:44 +01:00
Arthur Baars
341bc5c888
Implement instance variables
2021-01-29 16:09:44 +01:00
Arthur Baars
e36795c82e
Instance variables boilerplate code
2021-01-29 15:41:23 +01:00
Arthur Baars
184d42efe0
Remove unnecessary clause
2021-01-29 15:39:31 +01:00
Arthur Baars
b04391636d
Fix qldoc comment
2021-01-29 15:39:31 +01:00
Tom Hvitved
f8790c81a8
Merge pull request #108 from github/hvitved/ssa
...
Add SSA library
2021-01-29 15:12:14 +01:00
Nick Rolfe
623ee59410
Merge pull request #106 from github/self
2021-01-28 20:16:48 +00:00
Nick Rolfe
30804f74e2
Remove redundant instanceof expression
2021-01-28 17:48:16 +00:00
Tom Hvitved
47fdee4bbe
Sync SsaImplCommon.qll with C# implementation
2021-01-28 09:09:37 +01:00
Tom Hvitved
05b8a6c27b
Apply suggestions from code review
...
Co-authored-by: Nick Rolfe <nickrolfe@github.com >
2021-01-28 08:49:42 +01:00
Nick Rolfe
640092352b
RegularSuperCallRange::getReceiver() never holds
2021-01-27 18:49:37 +00:00
Nick Rolfe
743e627a8d
Test calls to methods named 'super'
2021-01-27 18:45:08 +00:00
Nick Rolfe
70bbeaac3b
Simplify, since super tokens are never variable accesses
2021-01-27 18:28:01 +00:00
Tom Hvitved
b9b4325b84
Add initial mapping of CFG nodes to AST nodes
2021-01-27 15:38:49 +01:00
Tom Hvitved
edc6e7eba8
Add UnusedParameter.ql query
2021-01-27 10:47:42 +01:00
Tom Hvitved
9dfea8006d
Add UninitializedLocal.ql query
2021-01-27 10:44:49 +01:00
Tom Hvitved
8abedaee8a
Add DeadStoreOfLocal.ql query
2021-01-27 10:42:02 +01:00
Tom Hvitved
2077ba4a1f
Add SSA library
2021-01-27 10:39:19 +01:00
Nick Rolfe
6423ea3219
Merge pull request #107 from github/hvitved/index-files-working-dir
...
Add `--working-dir=.` to `index-files` call
2021-01-26 19:19:20 +00:00
Tom Hvitved
735eb24a33
Add --working-dir=. to index-files call
2021-01-26 19:31:16 +01:00
Nick Rolfe
7ac46bf8f8
Add SuperCall class for calls to super
2021-01-26 18:08:46 +00:00
Tom Hvitved
d19053deda
Merge pull request #105 from github/hvitved/vcall
2021-01-25 18:41:36 +01:00
Tom Hvitved
2c6b9eceda
Move vcall into internal/Variable.qll
2021-01-25 16:26:11 +01:00
Tom Hvitved
ce74208317
Merge pull request #97 from github/hvitved/var-access-categorization
...
Categorize variable accesses into reads and (implicit or explicit) writes
2021-01-25 16:25:35 +01:00
Tom Hvitved
979da623ed
Merge pull request #103 from github/hvitved/cfg/params
...
CFG: Replace special parameters with their identifiers
2021-01-25 16:24:10 +01:00
Tom Hvitved
3a0c9a8104
CFG: Replace special parameters with their identifiers
...
For example, instead of including `**kwargs` in the CFG, we include `kwargs`.
This means that all variable accesses belonging to parameter definitions will
be included in the CFG.
2021-01-25 10:02:21 +01:00
Nick Rolfe
12fc0b914b
Merge pull request #102 from github/hvitved/blocks-no-params
...
Recognize blocks without parameters
2021-01-22 15:44:14 +00:00
Tom Hvitved
586885f066
Recognize blocks without parameters
2021-01-22 16:16:01 +01:00
Tom Hvitved
0f3a4a1a60
Merge pull request #101 from github/stats
...
Update stats
2021-01-22 16:05:47 +01:00
Nick Rolfe
216b1de2dd
Update stats
2021-01-22 14:35:43 +00:00
Nick Rolfe
858ca0b3bc
Merge pull request #100 from github/call_ast
...
Add AST classes and tests for method calls
2021-01-22 14:33:10 +00:00
Nick Rolfe
243dfde72e
Create ComplexSymbolRange class to deduplicate some predicates
2021-01-22 14:21:39 +00:00
Tom Hvitved
7e374c416a
Categorize variable accesses into reads and (implicit or explicit) writes
2021-01-22 13:17:26 +01:00
Nick Rolfe
3939008fd5
Small tweaks based on PR feedback
2021-01-22 12:17:17 +00:00
Nick Rolfe
ccd8a2aae6
Merge remote-tracking branch 'origin/main' into call_ast
2021-01-22 11:48:32 +00:00
Tom Hvitved
08c655e4e3
Merge pull request #99 from github/hvitved/cfg/to-string
...
CFG: Use manual `toString()`s for `AstCfgNode` when available
2021-01-21 14:10:16 +01:00
Nick Rolfe
2e8d154f2b
Add AST classes and tests for method calls
2021-01-20 18:34:25 +00:00
Tom Hvitved
bf7eb022a0
CFG: Use manual toString()s for AstCfgNode when available
2021-01-20 19:15:03 +01:00
Arthur Baars
78771ba4c2
Merge pull request #96 from github/hvitved/codeql-submodule-sync
...
Add `github/codeql` submodule and functionality for synchronizing files
2021-01-19 11:16:38 +01:00
Tom Hvitved
c11df1fe8c
Add sync-identical-files.py
2021-01-18 17:34:51 +01:00
Tom Hvitved
a41eea4fd7
Merge pull request #95 from github/hvitved/cfg/not-bug
...
CFG: Fix bug in `LogicalNotTree`
2021-01-18 16:05:39 +01:00
Tom Hvitved
e9a8afe284
Add github/codeql as a sub module
2021-01-18 15:54:39 +01:00
Tom Hvitved
34fe416a85
CFG: Fix bug in LogicalNotTree
2021-01-18 15:03:58 +01:00
Tom Hvitved
3f31775252
CFG: Add test for constant condition
2021-01-18 15:01:41 +01:00
Arthur Baars
03d407e50d
Merge pull request #82 from github/more_exprs
...
Add AST library for control expressions (conditionals and loops)
2021-01-11 10:35:37 +01:00
Nick Rolfe
6d7efab820
Add ConditionalLoop base class
2021-01-08 12:20:08 +00:00
Arthur Baars
c68f6a7f2e
Merge pull request #84 from github/aibaars/codeql-threads
...
Actions: apply CODEQL_THREADS to all steps
2021-01-08 13:19:01 +01:00
Nick Rolfe
6465c90a16
Rename IfOrElsifExpr to IfExpr; remove child classes
2021-01-08 11:53:15 +00:00
Nick Rolfe
15785b4535
Add db base type for CaseExpr::Range
2021-01-08 11:31:43 +00:00
Arthur Baars
4ef4053385
Actions: apply CODEQL_THREADS to all steps
2021-01-08 10:25:25 +01:00
Nick Rolfe
6efebf1e36
Merge remote-tracking branch 'origin/main' into more_exprs
2021-01-07 19:02:50 +00:00
Nick Rolfe
6c0804c1af
Address feedback on CFG change
2021-01-07 19:02:37 +00:00
Nick Rolfe
8cb8ead48e
Address more feedback on ExprSequence
2021-01-07 19:02:14 +00:00
Nick Rolfe
19a4e63ac6
Move comment about getCondition from class to predicate
2021-01-07 18:01:38 +00:00
Nick Rolfe
9a71bdc993
Improvements from feedback on case/when classes.
2021-01-07 17:48:51 +00:00
Nick Rolfe
36c7d3fe5b
Replace ConditionalExpr::get{Then,Else} with getBranch(boolean cond).
2021-01-07 17:32:41 +00:00
Nick Rolfe
e245382057
Merge pull request #83 from github/threads
...
Parallelize extraction
2021-01-07 17:14:41 +00:00
Nick Rolfe
f4abe7f4a1
Remove ThenExpr, ElseExpr, and DoExpr from public API
2021-01-07 15:56:31 +00:00
Nick Rolfe
83a28786a0
Use 4 threads for extraction and TRAP import in stats job
2021-01-07 11:17:07 +00:00
Nick Rolfe
1d3f06aca1
Simplify propagation of errors
2021-01-07 11:11:15 +00:00
Nick Rolfe
92c78e2b2d
Simplify num_codeql_threads function slightly
2021-01-07 11:10:43 +00:00
Nick Rolfe
bb2bdc01b5
Have the extract function create the TS parser object
2021-01-07 10:56:23 +00:00
Nick Rolfe
bf4eac5113
Parallelize extraction
...
Use the Rayon library to do parallel iteration over the file list. The
number of threads used respects the CODEQL_THREADS environment variable.
2021-01-06 18:22:27 +00:00
Nick Rolfe
f484b573f2
update stats for dbscheme change
2021-01-05 16:25:46 +00:00
Nick Rolfe
7c503120ae
Add AST library for control expressions (conditionals and loops)
2021-01-05 16:08:33 +00:00
Arthur Baars
c35283cefb
Merge pull request #77 from github/aibaars/global-variables
...
Add global variables
2020-12-21 12:15:31 +01:00
Arthur Baars
f0ddeaa9f2
Merge pull request #81 from github/aibaars/revert-dup-code
...
Update ruby.dbscheme.stats
2020-12-21 12:15:10 +01:00
Arthur Baars
ad1782b620
Address comments
2020-12-21 11:01:46 +01:00
Arthur Baars
8469bd3688
Uncomment getAPrimaryQlClass()
2020-12-21 11:01:46 +01:00
Arthur Baars
dc0de9132e
Add GlobalVariable
2020-12-21 11:01:46 +01:00
Arthur Baars
1ada9feda7
Make VariableAccess "abstract"
2020-12-21 11:01:46 +01:00
Arthur Baars
ebacec41d5
Update ruby.dbscheme.stats
2020-12-21 10:58:25 +01:00
Nick Rolfe
b1b2815c26
Merge pull request #80 from github/aibaars/revert-dup-code
...
Updates after CodeQL upgrade to 2.4.1
2020-12-21 09:57:59 +00:00
Arthur Baars
d4874641a3
Revert "Add duplicate code tables to dbscheme"
...
This reverts commit 4c699fcb32 .
2020-12-21 10:45:59 +01:00
Arthur Baars
bf232f0582
Update formatting for CodeQL 2.4.1
2020-12-21 10:45:59 +01:00
Arthur Baars
ff8ea6d44f
Merge pull request #79 from github/test_checks
...
Add all the TRAP check flags in qltest workflow
2020-12-21 10:20:47 +01:00
yo-h
402ed04189
Merge pull request #4844 from johnlugton/servicestack
...
Add provisional support for ServiceStack framework to feature branch
2020-12-18 16:24:27 -05:00
Nick Rolfe
5a54026bcc
Add all the TRAP check flags in qltest workflow
2020-12-18 17:25:28 +00:00
John Lugton
059d6b0e0f
Fix warning in ServiceStack.qll
2020-12-18 08:34:06 -08:00
John Lugton
563dc62c33
Improve qldoc for ServiceStack.qll
2020-12-18 08:23:27 -08:00
Arthur Baars
dddf0a66d9
Merge pull request #78 from github/typo
...
fix typo in comment
2020-12-18 13:50:58 +01:00
Nick Rolfe
72319b538f
fix typo in comment
2020-12-18 12:47:31 +00:00
Arthur Baars
8f1c916242
Merge pull request #66 from github/aibaars/cfg-2
...
CFG: make all simple nodes instance of StandardLeftToRight{Pre,Post}Tree
2020-12-18 13:26:05 +01:00
Nick Rolfe
c4ca537574
Merge pull request #75 from github/stmts_exprs
...
Add AST classes and tests for operations
2020-12-18 10:40:27 +00:00
Nick Rolfe
6c828214f7
Make import private
2020-12-18 10:23:19 +00:00
Nick Rolfe
53fbfc369d
Make params test pass for now
...
- some toString improvements
- comment out getAPrimaryQlClass predicates that cause the test to fail
2020-12-18 10:13:13 +00:00
Nick Rolfe
4718de08b2
Address review feedback
2020-12-18 10:08:45 +00:00
John Lugton
3f1f83f667
remove experimental
2020-12-17 16:24:52 -08:00
John Lugton
6d5f9035e6
Minor fixes to XSS:
...
Only want returns in request methods
Also care about non-string 1st args to HttpResult e.g. streams
2020-12-17 16:17:26 -08:00
John Lugton
7d47bffd53
Tidy up ServiceStack.qll
...
Use fully qualified names for classes
Make util predicate private
Make naming more consistent with rest of ql libs
2020-12-17 16:17:26 -08:00
Chelsea Boling
d4acccb13c
Update sink
2020-12-17 16:17:26 -08:00
Chelsea Boling
0a7e4b6840
Update sink based on feedback
2020-12-17 16:17:26 -08:00
Chelsea Boling
4e0f3a30ee
Update sink based on feedback
2020-12-17 16:17:25 -08:00
Chelsea Boling
ba46eaa143
Refactor sink
2020-12-17 16:17:25 -08:00
Chelsea Boling
3c493511e9
Update file
2020-12-17 16:17:25 -08:00
Chelsea Boling
12e8107492
Add example
2020-12-17 16:17:25 -08:00
Chelsea Boling
5c7dedffb3
Update sinks
2020-12-17 16:17:25 -08:00
Chelsea Boling
71a08c3237
Update servicestack lib
2020-12-17 16:17:25 -08:00
John Lugton
d408ae7e10
Split ServiceStack into modules and incorporate into main lib
2020-12-17 16:17:25 -08:00
John Lugton
386eb2d56b
move ServiceStack out of microsoft
2020-12-17 16:17:25 -08:00
Chelsea Boling
a2615339f7
Delete ServiceStack.qll
2020-12-17 16:17:24 -08:00
Chelsea Boling
cae6f91729
Create ServiceStack.qll
2020-12-17 16:17:24 -08:00
Chelsea Boling
dbe0170249
Add files via upload
2020-12-17 16:17:24 -08:00
Chelsea Boling
188dbde2d6
Create SQLInjection.ql
2020-12-17 16:17:24 -08:00
Chelsea Boling
96d11b7966
Create ServiceStack.qll
2020-12-17 16:17:24 -08:00
Nick Rolfe
a87fe410af
Simplify examples for unary plus/minus
2020-12-17 18:35:01 +00:00
Nick Rolfe
8b7af665b4
Simplify imports
2020-12-17 18:33:49 +00:00
Tom Hvitved
6893f57978
Merge pull request #74 from github/hvitved/cfg/fix-join-order
...
CFG: Fix bad join-order
2020-12-17 16:58:23 +01:00
Tom Hvitved
07c464b753
CFG: Fix bad join-order
...
Before:
```
[2020-12-17 11:33:46] (211s) Tuple counts for ControlFlowGraphImpl::Trees::RescueEnsureBlockTree::nestedEnsure_dispred#ff/2@2ea588:
11409019 ~0% {2} r1 = SCAN ControlFlowGraphImpl::getScope#ff AS I OUTPUT I.<1>, I.<0> 'this'
3714296409 ~0% {3} r2 = JOIN r1 WITH ControlFlowGraphImpl::Trees::getAChildInScope#fff_102#join_rhs AS R ON FIRST 1 OUTPUT r1.<1> 'this', R.<1>, R.<2>
2359 ~0% {2} r3 = JOIN r2 WITH ControlFlowGraphImpl::Trees::RescueEnsureBlockTree::getAnEnsureDescendant#ff AS R ON FIRST 2 OUTPUT r2.<2>, r2.<0> 'this'
1 ~0% {2} r4 = JOIN r3 WITH ControlFlowGraphImpl::Trees::RescueEnsureBlockTree::getEnsure_dispred#ff_10#join_rhs AS R ON FIRST 1 OUTPUT r3.<1> 'this', R.<1> 'innerBlock'
return r4
```
After:
```
[2020-12-17 15:20:37] (51s) Tuple counts for ControlFlowGraphImpl::Trees::RescueEnsureBlockTree::nestedEnsure_dispred#ff/2@c4f57d:
635 ~1% {3} r1 = JOIN ControlFlowGraphImpl::Trees::RescueEnsureBlockTree::getEnsure_dispred#ff_10#join_rhs AS L WITH ControlFlowGraphImpl::Trees::getAChildInScope#fff_201#join_rhs AS R ON FIRST 1 OUTPUT R.<1>, L.<1> 'innerBlock', R.<2>
1 ~0% {3} r2 = JOIN r1 WITH ControlFlowGraphImpl::Trees::RescueEnsureBlockTree::getAnEnsureDescendant#ff_10#join_rhs AS R ON FIRST 1 OUTPUT R.<1> 'this', r1.<2>, r1.<1> 'innerBlock'
1 ~0% {2} r3 = JOIN r2 WITH ControlFlowGraphImpl::getScope#ff AS R ON FIRST 2 OUTPUT r2.<0> 'this', r2.<2> 'innerBlock'
return r3
```
2020-12-17 16:46:03 +01:00
Arthur Baars
ff751b97d2
CFG: make all simple nodes instance of StandardLeftToRight{Pre,Post}Tree
2020-12-17 16:39:54 +01:00
Arthur Baars
a15a066414
Merge pull request #72 from github/aibaars/fix-cfg
...
CFG improvements
2020-12-17 16:39:19 +01:00
Arthur Baars
b676c95218
Address comments
2020-12-17 16:35:51 +01:00
Nick Rolfe
73798312b9
Add classes and tests for operations
2020-12-17 15:16:37 +00:00
Tom Hvitved
46fc17da58
CFG: Fix multiple abnormal successors
2020-12-17 11:15:17 +01:00
Tom Hvitved
1033b8610a
CFG: Add more tests
2020-12-17 11:14:10 +01:00
Arthur Baars
91ae237434
Use latest CodeQL for CI
2020-12-17 11:04:57 +01:00
Arthur Baars
dd954ea943
CFG: correct flow for lambda bodies
...
Lambda bodies are parsed as nested do-blocks or normal blocks.
This is actually incorrect, as the body of a lambda can't have
parameters. However, we can "inline" such blocks to get the
desired control flow.
2020-12-17 10:04:01 +01:00
Arthur Baars
eafec4331b
CFG: add nodes for block arguments
2020-12-17 10:04:01 +01:00
Arthur Baars
d016e3cae0
CFG: methods are evaluated before their arguments
2020-12-17 10:04:01 +01:00
Arthur Baars
81c907a87a
CFG: fix BEGIN and END blocks
2020-12-17 10:04:01 +01:00
Arthur Baars
f2fd1c7931
CFG: make def nodes visible
2020-12-17 10:04:01 +01:00
Arthur Baars
f2effce786
CFG: improve handling of block and lambda
2020-12-17 10:04:01 +01:00
Arthur Baars
30895e634c
CFG: refactor CfgScope
2020-12-17 10:04:01 +01:00
Arthur Baars
bc47338b52
CFG: add test-case for conditional method declarations
2020-12-17 10:04:01 +01:00
Arthur Baars
69de81bdd5
CFG: have alternative flow for the definition and call of methods etc.
2020-12-17 10:04:01 +01:00
Arthur Baars
fd14770542
CFG: drop getObject from flow of singleton method
2020-12-17 09:59:30 +01:00
Arthur Baars
8501e30b6a
CFG: fix linking heredoc start to heredoc body
2020-12-17 09:59:30 +01:00
Arthur Baars
edbd997f15
Merge pull request #71 from github/kinds
...
Create disjoint db types for different operators
2020-12-17 09:58:52 +01:00
Nick Rolfe
282d20d766
Remove redundant field on ChildNode struct
2020-12-16 20:57:06 +00:00
Nick Rolfe
a873cb9f3d
Update dbscheme stats
2020-12-16 20:53:41 +00:00
Nick Rolfe
d1a9572b0e
Merge remote-tracking branch 'origin/main' into kinds
2020-12-16 17:55:20 +00:00
Nick Rolfe
f5282edfc1
Simplifications based on PR feedback
2020-12-16 17:54:40 +00:00
Arthur Baars
381d6aafaa
Merge pull request #73 from github/calls
...
Update tree-sitter-ruby to pick up improvements to calls
2020-12-16 14:00:53 +01:00
Nick Rolfe
0518d51b51
Update CFG: call receiers are evaluated before arguments
2020-12-16 12:40:57 +00:00
Nick Rolfe
e98a84c8b5
Update CFG to match changes to Call/MethodCall
2020-12-16 12:01:30 +00:00
Nick Rolfe
aa0c1491a6
Update tree-sitter-ruby to pick up improvements to calls
2020-12-16 10:13:45 +00:00
Arthur Baars
7971b243f1
Merge pull request #69 from github/hvitved/cfg/post-order-cond
...
CFG: Model `IfElsifAstNode` in post-order
2020-12-15 19:22:16 +01:00
Nick Rolfe
ddb71790e9
Fix formatting
2020-12-15 16:01:13 +00:00
Tom Hvitved
9aadeedeb9
CFG: Model IfElsifAstNode in post-order
2020-12-15 17:00:12 +01:00
Tom Hvitved
bb88858633
CFG: Add test for nested ifs
2020-12-15 16:46:55 +01:00
Nick Rolfe
3f5eab04b5
Create disjoint db types for different operators
2020-12-15 15:22:33 +00:00
Arthur Baars
ac9f439935
Merge pull request #70 from github/hvitved/cfg/rescue-part2
...
CFG: More adjustments for `rescue`/`ensure`
2020-12-15 16:06:26 +01:00
Tom Hvitved
16c25f2a4c
CFG: Handle ensure blocks without body/rescues
2020-12-15 13:49:14 +01:00
Tom Hvitved
489b406e2a
CFG: Change column order in succExit/hasExitScope
2020-12-15 13:45:22 +01:00
Tom Hvitved
e784640cca
CFG: Add more test cases
2020-12-15 13:45:22 +01:00
Arthur Baars
5108b369e1
Merge pull request #64 from github/hvitved/cfg/rescue
...
Implement CFG logic for `rescue-ensure`
2020-12-15 11:43:14 +01:00
Tom Hvitved
a76e6848c7
CFG: Address more review comments
2020-12-14 20:45:57 +01:00
Tom Hvitved
ec4ead2117
Apply suggestions from code review
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2020-12-14 14:53:35 +01:00
Nick Rolfe
b76f97d337
Merge pull request #68 from github/bump_ts
...
Bump tree-sitter-ruby revision to get operator_assignment field
2020-12-14 12:40:36 +00:00
Tom Hvitved
89fb2f8498
CFG: Add @kind graph to Cfg.ql, and remove labels from ordinary successor edges
2020-12-14 11:00:26 +01:00
Nick Rolfe
6bacac7598
Bump tree-sitter-ruby revision to get operator_assignment field
2020-12-08 18:28:54 +00:00
Tom Hvitved
b14a889f5f
CFG: Use MatchingCompletion for parameters with default values
2020-12-08 13:47:32 +01:00
Tom Hvitved
80a59a81ed
CFG: Use MatchingCompletion for patterns
2020-12-08 13:47:32 +01:00
Tom Hvitved
31b8d33a7c
CFG: Mark redo edges out of for loops
2020-12-08 13:47:32 +01:00
Tom Hvitved
b6ea5c5eab
CFG: Implement logic for rescue-ensure blocks
2020-12-08 13:47:32 +01:00
Nick Rolfe
53a1cbc492
Merge pull request #67 from github/getAPrimaryQlClass
...
Rename describeQlClass to getAPrimaryQlClass
2020-12-08 12:16:18 +00:00
Nick Rolfe
3145b3dde7
Rename describeQlClass to getAPrimaryQlClass
2020-12-08 11:09:18 +00:00
Tom Hvitved
5a0376f67e
CFG: More tests
2020-12-08 11:06:15 +01:00
Arthur Baars
990ed34c02
Merge pull request #55 from github/aibaars/cfg
...
Control flow graph
2020-12-07 16:51:33 +01:00
Arthur Baars
9390cf0401
CFG: add test case for if-in-case
2020-12-07 16:46:52 +01:00
Arthur Baars
86e73afc74
CFG: extract HeredocBeginning::getName predicate
2020-12-07 16:31:17 +01:00
Arthur Baars
9883d7124e
CFG: improve handling of redo
2020-12-07 16:20:42 +01:00
Arthur Baars
003f7230b2
Apply suggestions from code review
...
Co-authored-by: Tom Hvitved <hvitved@github.com >
2020-12-07 16:02:19 +01:00
Arthur Baars
024150b04b
CFG: hide 'begin'
2020-12-07 16:02:19 +01:00
Arthur Baars
87451fd999
CFG: specialise return type instead of instanceof check
2020-12-07 15:36:09 +01:00
Arthur Baars
6aea3eff3e
CFG: rename getBody{=>Node} and getCondition{=>Node}
2020-12-07 15:30:57 +01:00
Arthur Baars
6d12bcc2fe
Make ConditionalSuccessor not abstract
2020-12-07 15:19:14 +01:00
Arthur Baars
044d14c8b4
Use private imports in generated code
2020-12-07 15:14:34 +01:00
Arthur Baars
ed3b102ecc
Improve formatting
2020-12-07 15:12:43 +01:00
Arthur Baars
d25835c7d2
Merge pull request #61 from github/aibaars/code-nav
...
Add basic code navigation queries
2020-12-07 14:47:43 +01:00
Arthur Baars
2394b26636
CFG: skip Uninterpreted nodes
2020-12-07 13:11:21 +01:00
Arthur Baars
36f5a63c18
Improve handling of class, module, block and method
2020-12-07 13:11:21 +01:00
Arthur Baars
2124247d5e
CFG: add samples of all syntactical constructs to cfg.rb
2020-12-07 13:11:21 +01:00
Arthur Baars
ebf3a31224
CFG: don't handle rescue, else, ensure for now
2020-12-07 13:11:21 +01:00
Arthur Baars
97d0220ffd
CFG: Model nodes with simple flow
2020-12-07 13:11:21 +01:00
Arthur Baars
3807e1be38
CFG: flow for rescue-modifier
2020-12-07 13:11:21 +01:00
Arthur Baars
d619bdd8f9
CFG: Completions: fix definition of boolean constants
2020-12-07 13:11:21 +01:00
Arthur Baars
6c579ff608
CFG: link heredoc start to its body
2020-12-07 13:11:21 +01:00
Arthur Baars
49d11b1e09
CFG: don't hide Class and Module nodes
2020-12-07 13:11:21 +01:00
Arthur Baars
0852068bcd
CFG: make lambda a CFG entry point
2020-12-07 13:11:21 +01:00
Arthur Baars
01066ea3bb
CFG: case expression
2020-12-07 13:11:21 +01:00
Arthur Baars
2f238280dc
CFG: model if-modifier and unless
2020-12-07 13:11:21 +01:00
Arthur Baars
5d6e77be28
CFG: model while, until and variants
2020-12-07 13:11:21 +01:00
Arthur Baars
6660cb4417
CFG: for-in loop
2020-12-07 13:11:21 +01:00
Arthur Baars
165b2b37dc
Treat for variables and exception variables as declarations
2020-12-07 13:11:21 +01:00
Arthur Baars
b60ea74e8a
Treat conditional expressions as if-then-else
2020-12-07 13:11:21 +01:00
Arthur Baars
97fab0d18b
Assignments evaluate right-hand-side first
2020-12-07 13:11:21 +01:00
Arthur Baars
465c266b8a
Classes and module are not CfgScopes
2020-12-07 13:11:21 +01:00
Arthur Baars
0959a4675f
Merge pull request #65 from github/aibaars/dup-code
...
Add duplicate code tables to dbscheme
2020-12-07 13:10:52 +01:00
Arthur Baars
4c699fcb32
Add duplicate code tables to dbscheme
2020-12-07 13:06:26 +01:00
Arthur Baars
0a38d6801c
Address review comments
2020-12-07 12:53:45 +01:00
Arthur Baars
d92d635103
Add basic code navigation queries
2020-12-04 15:01:43 +01:00
Arthur Baars
1d502cb40d
Merge pull request #63 from github/aibaars/fix-warnings
...
Fix warnings and make imports private
2020-12-04 10:43:01 +01:00
Arthur Baars
c1f1efb16b
Merge pull request #62 from github/aibaars/update-grammar
...
Update tree-sitter grammar
2020-12-03 19:14:13 +01:00
Arthur Baars
22fd8908c5
Use private imports
...
No need to have everyting re-export the entire AST
2020-12-03 19:13:05 +01:00
Arthur Baars
582b00ef07
Fix warnings
2020-12-03 19:05:49 +01:00
Arthur Baars
dd3f94a3e2
Update tree-sitter grammar
2020-12-03 18:50:47 +01:00
Nick Rolfe
b0227a7ee1
Merge pull request #60 from github/aibaars/osx-gnutar
...
Workaround for broken cache on OSX
2020-12-03 16:10:10 +00:00
Arthur Baars
c69f64fb4f
Workaround for broken cache on OSX
2020-12-03 16:40:37 +01:00
Nick Rolfe
492f7d1987
Merge pull request #59 from github/bump_ts
...
Bump to latest tree-sitter-ruby revision
2020-12-02 20:04:12 +00:00
Nick Rolfe
d7c1231020
Bump to latest tree-sitter-ruby revision
2020-12-02 16:11:07 +00:00
Tom Hvitved
86a2cbc773
Merge pull request #58 from github/hvitved/pattern-get-a-variable
...
Add `Pattern::getAVariable()` and use `self` range field throughout
2020-12-02 12:57:52 +01:00
Tom Hvitved
9129e886b2
Update ql/src/codeql_ruby/ast/Parameter.qll
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2020-12-02 12:07:13 +01:00
Tom Hvitved
77129e473a
Adhere to ::Range pattern
2020-12-02 11:27:00 +01:00
Tom Hvitved
b2483069e0
Add Pattern::getAVariable() and use self range field througout
2020-12-02 10:36:33 +01:00
Arthur Baars
59263650b1
Merge pull request #57 from github/hvitved/rename-generated-qll
...
Move `Generated.qll` to `ast/internal/TreeSitter.qll`
2020-12-02 10:32:38 +01:00
Tom Hvitved
a370cd8bdf
Move Generated.qll to ast/internal/TreeSitter.qll
2020-12-01 20:53:41 +01:00
Tom Hvitved
ba7a42328d
Merge pull request #56 from github/hvitved/parameter-get-a-variable
...
Introduce `Parameter::getAVariable()`
2020-12-01 18:32:34 +01:00
Tom Hvitved
d50f5cc785
Address review comments
2020-12-01 15:14:14 +01:00
Tom Hvitved
9820dcb363
Generate VariableAccesses also for defining accesses
2020-12-01 14:39:41 +01:00
Tom Hvitved
bde9f59e0e
Introduce Parameter::getAVariable()
2020-12-01 13:18:06 +01:00
Tom Hvitved
965b351cde
Merge pull request #54 from github/hvitved/ast-final
...
Mark more AST predicates as `final`
2020-12-01 12:38:28 +01:00
Tom Hvitved
311a0b6b20
Mark more AST predicates as final
2020-12-01 10:24:33 +01:00
Tom Hvitved
11927a930f
Merge pull request #53 from github/user-facing
...
Add some user-facing AST classes
2020-12-01 10:23:37 +01:00
Nick Rolfe
baf29ae56b
Add qldoc comment and isOptional predicate to KeywordParameter
2020-11-30 13:42:02 +00:00
Tom Hvitved
c0dd89122c
Handle parameters with overlapping names
2020-11-28 19:23:08 +01:00
Tom Hvitved
58baa33a3f
Various changes to user-facing library
...
- Remove `abstract` classes from public API.
- Align `Variable.qll` with rest of library.
- Introduce `Callable` class.
- Make `Pattern` class cover everything that can be on the LHS of an assignment
and in a pattern (except special parameters such as `**param`).
2020-11-27 17:07:03 +01:00
Tom Hvitved
59d45de118
Move AST files into ast folder
2020-11-27 14:45:15 +01:00
Tom Hvitved
00f3daabfe
Rename Variables.qll to Variable.qll
2020-11-27 14:39:20 +01:00
Nick Rolfe
38b401f04f
Fix import
2020-11-26 16:04:46 +00:00
Arthur Baars
f9c7ae78fe
Merge pull request #52 from github/aibaars/db-stats
...
Collect database stats
2020-11-26 17:03:34 +01:00
Nick Rolfe
399170fd58
Add getParent(Index) to user-facing AstNode
2020-11-26 15:33:50 +00:00
Arthur Baars
c7986442d0
Update ruby.dbscheme.stats
2020-11-26 15:07:13 +01:00
Arthur Baars
49c97bd157
Collect database stats
2020-11-26 14:53:30 +01:00
Nick Rolfe
c598dc6b5c
Initial work on user-facing AST library
2020-11-26 13:45:45 +00:00
Arthur Baars
2082171bdf
Merge pull request #51 from github/aibaars/cfg-scopes
...
CFG: add more CfgScopeRanges
2020-11-26 12:13:53 +01:00
Tom Hvitved
8632cbec71
CFG: Do not descend into nested scopes
2020-11-26 10:58:23 +01:00
Arthur Baars
30cb2cc3e0
CFG: add more CfgScopeRanges
2020-11-26 10:58:23 +01:00
Arthur Baars
e181666a37
Merge pull request #49 from github/aibaars/parent
...
Add parent ref and parent_index fields to all AstNodes
2020-11-25 18:25:03 +01:00
Arthur Baars
083672744e
Remove @file from @astnode
2020-11-25 17:37:58 +01:00
Arthur Baars
735aec9d34
Ensure top-level nodes have distinct parent_index values
2020-11-25 13:48:25 +01:00
Arthur Baars
00015b0022
Add #keyset[parent, parent_index]
2020-11-25 13:48:25 +01:00
Arthur Baars
89953fd87c
Add parent_index field to @astnode
2020-11-25 13:48:25 +01:00
Arthur Baars
b72db8b6f1
Add parent field to AstNode
2020-11-25 13:48:25 +01:00
Arthur Baars
c7b07b7821
Merge pull request #47 from github/aibaars/name-resolution
...
Name resolution: handle the different types of parameters better
2020-11-25 13:44:42 +01:00
Arthur Baars
64ebf5b909
Address comments
2020-11-25 12:55:53 +01:00
Arthur Baars
7a13e8549b
Merge pull request #50 from github/pin_ts_rev
...
Pin tree-sitter-ruby revision
2020-11-24 20:46:53 +01:00
Nick Rolfe
f612e05b34
Pin tree-sitter-ruby revision
2020-11-24 19:22:30 +00:00
Arthur Baars
bc5d7a3b74
Change modelling of Parameters
2020-11-24 19:22:40 +01:00
Arthur Baars
c745978ebb
Fix inconsistent variable references
2020-11-24 19:22:40 +01:00
Arthur Baars
290d3decc8
Add consistency query for Variables
...
Test that VariableAccess.getVariable returns a unique Variable
2020-11-24 19:19:15 +01:00
Tom Hvitved
0616040f3c
Merge pull request #48 from github/hvitved/ci-check-queries
...
Check query compilation and formatting in `qltest.yml`
2020-11-24 11:51:54 +01:00
Tom Hvitved
eceeb6a5fd
Break up QL CI tests into separatly named steps
2020-11-24 11:47:59 +01:00
Tom Hvitved
966e1cdcd0
Apply old formatter to make CI check pass
2020-11-24 11:26:47 +01:00
Tom Hvitved
74f0a8fdb7
Check query compilation and formatting in qltest.yml
2020-11-24 11:20:16 +01:00
Tom Hvitved
d5582f3f48
Merge pull request #46 from github/hvitved/unique-parent
...
Add `unique` wrapper to `AstNode::getParent()`
2020-11-23 16:16:02 +01:00
Tom Hvitved
8132c4cafb
Update generator/src/ql.rs
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2020-11-23 16:12:31 +01:00
Tom Hvitved
d0257dda36
Add unique wrapper to AstNode::getParent()
2020-11-23 15:23:21 +01:00
Arthur Baars
41a76eeb01
Merge pull request #42 from github/aibaars/name-resolution
...
Local variable binding
2020-11-23 15:22:43 +01:00
Arthur Baars
3ea6cb40f8
Merge pull request #45 from github/hvitved/name-resolution-suggestions
...
Suggested changes to Variables.qll
2020-11-23 13:28:40 +01:00
Tom Hvitved
59624454d1
Suggested changes to Variables.qll
...
- Remove `abstract` predicates from public API.
- Cache core computations.
- Redefine `VariableScope::get[A]Variable` to only include variables declared
directly in the scope.
2020-11-23 10:33:34 +01:00
Arthur Baars
bc423000ca
Add variable to varaccess tests
2020-11-23 09:58:31 +01:00
Arthur Baars
49f1143133
Make Variable an IPA type and speed things up on large databases
2020-11-23 09:58:31 +01:00
Tom Hvitved
bb06c1ffeb
Various minor changes to Variables.qll
2020-11-23 09:58:31 +01:00
Arthur Baars
c16a2e77d8
Model local variables
2020-11-23 09:58:31 +01:00
Arthur Baars
6bd476ff30
Add AstNode::getParent
2020-11-23 09:58:31 +01:00
Nick Rolfe
10411ef49e
Merge pull request #43 from github/hvitved/unbreak-print-ast
...
Unbreak PrintAST query
2020-11-19 13:58:43 +00:00
Tom Hvitved
7716d53552
Unbreak PrintAST query
2020-11-19 14:48:14 +01:00
Tom Hvitved
100daacb94
Merge pull request #39 from github/hvitved/cfg-skeleton
...
Initial CFG skeleton code
2020-11-19 14:41:16 +01:00
Tom Hvitved
06a6a3feb0
Address review comments
2020-11-19 14:31:08 +01:00
Tom Hvitved
4626168969
CFG: Separate scope for method blocks
2020-11-19 09:29:15 +01:00
Tom Hvitved
4dd4373b53
Initial CFG skeleton code
2020-11-18 20:12:42 +01:00
Arthur Baars
f9c1bbd8f9
Merge pull request #41 from github/gitignore
...
Update .gitignore
2020-11-17 18:31:35 +01:00
Nick Rolfe
9d1eec8fe8
Update .gitignore
2020-11-17 16:45:10 +00:00
Nick Rolfe
12d4224e8e
Merge pull request #40 from github/refactor
...
Move all naming decisions to shared library
2020-11-17 11:19:18 +00:00
Nick Rolfe
1a9663ff7d
Replace single-branch match with if let
2020-11-16 18:43:54 +00:00
Nick Rolfe
68c97a2d13
Use .. to ignore fields
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2020-11-16 18:41:18 +00:00
Nick Rolfe
ad61f7a0a6
Use references instead of owned strings in generator
2020-11-16 17:54:16 +00:00
Nick Rolfe
bbe7c70d34
more refactoring of names
2020-11-16 17:54:16 +00:00
Nick Rolfe
83a0e5fea6
Refactor to move naming decisions to shared library
2020-11-16 17:54:14 +00:00
Nick Rolfe
505d5c04d8
Merge pull request #31 from github/aibaars/drop-classes
...
Simplify generated QL classes
2020-11-16 14:16:02 +00:00
Arthur Baars
043c3fd2eb
Simplify generated QL classes
2020-11-13 12:59:22 +01:00
Arthur Baars
f57d20f5c6
Merge pull request #36 from github/readme-build-dbs
...
Add README instructions for building databases
2020-11-13 12:57:09 +01:00
Nick Rolfe
c16390fd05
Merge remote-tracking branch 'origin/main' into readme-build-dbs
2020-11-13 11:37:28 +00:00
Nick Rolfe
8d46151a10
Merge pull request #37 from github/aibaars-patch-1
...
Change cache key
2020-11-13 11:33:31 +00:00
Arthur Baars
5fe3bf138c
Change cache key
2020-11-12 19:11:04 +01:00
Arthur Baars
402c348e37
Merge pull request #33 from github/aibaars/qltest
...
Add QL test support
2020-11-12 15:10:39 +01:00
Nick Rolfe
0e1b54f061
Add instructions for building databases
2020-11-12 13:33:32 +00:00
Nick Rolfe
bb1d6f3bb8
Merge pull request #34 from github/aibaars/osx-fmt
...
Remove cargo fmt workaround on OSX
2020-11-12 13:03:41 +00:00
Nick Rolfe
056879eb97
Merge pull request #35 from github/aibaars/cargo-update
...
Run: cargo update
2020-11-12 10:34:50 +00:00
Arthur Baars
8d1ed4bf89
Run: cargo update
...
This pulls in improvements to the tree-sitter-ruby repository.
2020-11-12 10:25:40 +01:00
Arthur Baars
557d990a0d
Remove cargo fmt workaround on OSX
...
The `fmt` component is now installed by default on OSX.
2020-11-12 09:29:26 +01:00
Arthur Baars
44150600ab
Add QLTest workflow
2020-11-11 21:57:50 +01:00
Arthur Baars
080c56c9eb
Add QL test support
2020-11-11 16:32:44 +01:00
Arthur Baars
db35abdf17
Merge pull request #32 from github/getFileBySourceArchiveName
...
Replace getEncodedFile with getFileBySourceArchiveName predicate
2020-11-11 13:46:10 +01:00
Nick Rolfe
5771e4790e
Replace getEncodedFile with getFileBySourceArchiveName predicate
...
While also making it work with paths for databases created on Windows.
2020-11-10 16:50:10 +00:00
Arthur Baars
5f1e373355
Merge pull request #30 from github/string_contents
...
Get latest fixes from tree-sitter-ruby repo
2020-11-09 15:05:50 +01:00
Arthur Baars
81ceb22b14
Restore cache before running cargo fmt
...
It appears cargo fmt also downloads the git dependencies which takes quite a while. The cache should contain a copy of the cloned repo, so restoring the cache early should speed things up.
2020-11-09 14:25:54 +01:00
Nick Rolfe
6f72ba106e
Get latest fixes from tree-sitter-ruby repo
2020-11-06 17:15:22 +00:00
Nick Rolfe
aec99746d6
Merge pull request #29 from github/aibaars/dedup
...
Deduplicate and sort union members
2020-11-05 18:00:07 +00:00
Arthur Baars
222af90790
Deduplicate and sort union members
2020-11-05 18:50:12 +01:00
Arthur Baars
f514655231
Merge pull request #28 from github/token_classes
...
Add classes for token kinds
2020-11-05 17:27:22 +01:00
Nick Rolfe
510621f018
Don't add 'Token' prefix to token subclass names
2020-11-05 16:21:33 +00:00
Nick Rolfe
4bda204118
Add classes for token kinds
2020-11-05 13:06:46 +00:00
Arthur Baars
296d4d0f47
Merge pull request #26 from github/aibaars/tokens
...
Store tokens into separate table
2020-11-05 14:03:26 +01:00
Arthur Baars
c565f323f6
Don't register extra tokens as children of the parent node
2020-11-05 12:53:58 +01:00
Arthur Baars
180df8a63d
Make classes non-abstract
2020-11-04 18:18:45 +01:00
Nick Rolfe
69b1d7c0dc
Make union-wrapping classes abstract to fix results for toString/describeQlClass
2020-11-04 16:01:51 +00:00
Arthur Baars
86aa05e3cb
Address comments
2020-11-04 14:49:47 +01:00
Arthur Baars
c3e8d85f0b
Tolerate tokens containing invalid UTF-8
2020-11-04 14:46:31 +01:00
Arthur Baars
8056186c3c
Hide disconnected tokens
2020-11-04 13:35:24 +01:00
Arthur Baars
96423d2e8e
Remove describeQlClass from union types
...
The descriptions of the underlying types are more interesting.
2020-11-04 13:35:24 +01:00
Arthur Baars
053c9f60a4
Store tokens in a separate table
2020-11-04 13:35:24 +01:00
Nick Rolfe
9e49991859
Merge pull request #27 from github/extractor-pack-script
...
Add scripts to create extractor pack locally
2020-11-04 12:20:45 +00:00
Nick Rolfe
b16588f058
Add powershell script to create extractor pack locally
2020-11-04 12:09:52 +00:00
Nick Rolfe
a83ac24652
Add bash script to create extractor pack locally
2020-11-04 11:59:17 +00:00
Arthur Baars
b92d789598
Merge pull request #25 from github/printAST
...
Implement basic `printAst` query
2020-11-03 19:13:44 +01:00
Nick Rolfe
41dcb19cd5
Implement basic printAst query
2020-11-03 13:47:54 +00:00
Arthur Baars
65c1f2c359
Merge pull request #20 from github/aibaars/extract-extra
...
Extract 'extra' nodes and their subtrees
2020-11-03 13:45:33 +01:00
Arthur Baars
d7e9178cda
Merge pull request #24 from github/gzip
...
Add buffered writing and gzip compression for trap files
2020-11-03 13:45:19 +01:00
Arthur Baars
bfc05539ec
Update library and dbscheme
2020-11-03 10:07:05 +01:00
Arthur Baars
25205a09a3
Update tree-sitter-ruby
2020-11-03 10:06:59 +01:00
Arthur Baars
dc3459de8e
Extract 'extra' nodes and their subtrees
2020-11-03 10:03:11 +01:00
Nick Rolfe
27c3c88b3c
Add buffered writing and gzip compression for trap files
2020-11-02 16:14:19 +00:00
Arthur Baars
0156de12ea
Merge pull request #22 from github/aibaars/trapwriter
...
Add a TrapWriter
2020-11-02 15:00:38 +01:00
Arthur Baars
0ccd97639b
Address comments
2020-11-02 13:30:46 +01:00
Arthur Baars
0ecab93d09
Merge pull request #23 from github/aibaars/locations-lib
...
Add Locations.qll and import FileSystem and Locations libraries in generated AST
2020-11-02 13:08:15 +01:00
Arthur Baars
f94b5ae412
Update QL code generator
2020-10-31 14:03:26 +01:00
Arthur Baars
1b502c161e
Add Locations library and move language independent files to 'codeql'
2020-10-31 11:51:01 +01:00
Arthur Baars
63ca8212f6
Limit string sizes to 1MB
2020-10-31 11:36:01 +01:00
Arthur Baars
f265ccef59
TrapWriter: add global ID caching and populate folders
2020-10-31 11:35:57 +01:00
Arthur Baars
0de8b0c069
Add TrapWriter::comment
2020-10-31 11:35:22 +01:00
Arthur Baars
748dee64ae
Escape label keys
2020-10-31 11:35:22 +01:00
Arthur Baars
57842e8a87
Add TrapWriter
2020-10-31 11:35:16 +01:00
Nick Rolfe
83667ab89a
Merge pull request #19 from github/locations
...
Fix location handling to match common db schema requirements
2020-10-30 16:56:34 +00:00
Arthur Baars
c2c197dba5
Merge pull request #21 from github/aibaars/files-qll
...
Basic FileSystem.qll
2020-10-30 17:50:54 +01:00
Nick Rolfe
075c72e6ef
Iterate through path components to 'normalize' paths on windows
2020-10-30 15:26:46 +00:00
Arthur Baars
3e12aa457f
Basic FileSystem.qll
2020-10-30 15:40:29 +01:00
Nick Rolfe
e73500ef7c
Cope with empty filenames/extensions
2020-10-30 14:38:24 +00:00
Nick Rolfe
0a754334cf
Don't generate the QL File class
2020-10-30 13:41:27 +00:00
Nick Rolfe
35cb379db7
Fix name of table for locations
2020-10-30 13:24:16 +00:00
Nick Rolfe
a54f923a73
Normalize the absolute path in the files table
2020-10-30 13:22:58 +00:00
Nick Rolfe
4b8bbd101c
Give locations full ids matching the common spec
2020-10-30 13:06:21 +00:00
Nick Rolfe
79d15051be
Fix full ids for files to match common spec
2020-10-30 12:45:23 +00:00
Nick Rolfe
7f03206b52
Use a key id for file entities
2020-10-30 11:29:04 +00:00
Nick Rolfe
826b4571a0
Canonicalize source file paths in main
2020-10-30 11:21:51 +00:00
Nick Rolfe
d47bd32b58
Now that we also generate conjunctions, use parentheses in disjunctions
2020-10-30 10:34:42 +00:00
Nick Rolfe
f198dc530f
Use fromSource = 1
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2020-10-30 10:25:09 +00:00
Nick Rolfe
2232700428
Correct comment
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2020-10-30 10:24:24 +00:00
Nick Rolfe
4d5d80c749
Fix location handling to match common db schema requirements
2020-10-29 19:44:16 +00:00
Nick Rolfe
556507cec7
Merge pull request #18 from github/optional_fields
...
Don't generate an index for optional fields that occur at most once
2020-10-29 15:35:27 +00:00
Nick Rolfe
547d12ca58
Add more info to error message
2020-10-29 15:13:04 +00:00
Nick Rolfe
11c9c18de4
Don't generate an index for optional fields that occur at most once
2020-10-29 13:04:26 +00:00
Arthur Baars
fbb075b477
Merge pull request #17 from github/aibaars/locations-2
...
TRAP locations: always fix-up empty ranges
2020-10-29 12:15:52 +01:00
Arthur Baars
3350d9d3d4
TRAP locations: always fix-up empty ranges
2020-10-29 10:45:07 +01:00
Arthur Baars
ca91e15a4b
Merge pull request #16 from github/aibaars/locations
...
Fix locations in the
2020-10-28 18:09:58 +01:00
Arthur Baars
4c04b8bb15
Add comment
2020-10-28 17:40:01 +01:00
Arthur Baars
d2f42552f6
Adjust source locations
...
Tree-sitter row and column numbers are 0-based while CodeQL expects 1-based.
In addition tree-sitter location ranges end-points are exclusive while
CodeQL's ranges are inclusive.
2020-10-28 17:30:03 +01:00
Nick Rolfe
743eca7992
Merge pull request #15 from github/aibaars/ql-folder
...
Add QL folder structure
2020-10-28 13:11:50 +00:00
Arthur Baars
638fd91e50
Update generator to write the ast.qll file directly into ql/src
2020-10-28 14:04:36 +01:00
Arthur Baars
28a99cfe83
Update path of generated dbscheme
2020-10-28 14:04:36 +01:00
Arthur Baars
88acbc883c
Copy dbscheme stats into extractor pack
2020-10-28 14:04:36 +01:00
Arthur Baars
030d957535
Update stats with values measured on bunch of ruby databases
2020-10-28 14:04:36 +01:00
Arthur Baars
5d3f2de685
Add dbscheme to QL folder
2020-10-28 14:04:36 +01:00
Arthur Baars
2e102b8cdf
Add folder structure for QL code
2020-10-28 14:04:36 +01:00
Arthur Baars
553e1ab465
Merge pull request #13 from github/aibaars/improve-workflow
...
Check formatting and cache builds
2020-10-28 14:04:05 +01:00
Arthur Baars
7e6c30b121
Check formatting and cache builds
2020-10-28 13:55:52 +01:00
Nick Rolfe
29899485c7
Merge pull request #11 from github/ql_gen
...
Generate QL classes
2020-10-28 12:25:53 +00:00
Nick Rolfe
e03d5da8cd
Rename a field to avoid using raw identifiers
2020-10-28 12:14:54 +00:00
Nick Rolfe
f4b9c0c71a
Merge remote-tracking branch 'origin/main' into ql_gen
2020-10-28 11:41:18 +00:00
Nick Rolfe
24b4586ddd
Merge pull request #14 from github/aibaars/remove-storage-index
...
Extractor: fix child index values
2020-10-28 11:37:38 +00:00
Nick Rolfe
11152583d5
Add get_name() method to simplify logic in field handling
2020-10-28 11:30:50 +00:00
Nick Rolfe
53de99e6af
Regenerate QL with fix to Top::getAFieldOrChild
2020-10-28 11:22:21 +00:00
Nick Rolfe
7b51030dd4
Merge remote-tracking branch 'origin/ql_gen' into ql_gen
2020-10-28 11:20:58 +00:00
Nick Rolfe
b4f9599dd9
Simplify hashmap insertion
2020-10-28 11:20:47 +00:00
Nick Rolfe
679ca6d0f1
Update Actions workflow to generate ruby_ast.qll
2020-10-28 11:04:09 +00:00
Nick Rolfe
17820e017c
Fix Top::getAFieldOrChild() so it doesn't take an index arg
...
Co-authored-by: Arthur Baars <aibaars@github.com >
2020-10-28 11:02:42 +00:00
Nick Rolfe
bc22631c32
Simplify QL model following review feedback
2020-10-28 11:00:40 +00:00
Nick Rolfe
77fdafdc95
Simplify error handling with if let
2020-10-28 10:35:33 +00:00
Nick Rolfe
59580d51bb
Merge remote-tracking branch 'origin/main' into ql_gen
2020-10-28 10:30:36 +00:00
Arthur Baars
fe1d8ec15f
Extractor: fix child index values
2020-10-27 22:32:53 +01:00
Arthur Baars
0c15783f2b
Merge pull request #12 from github/crates-language
...
Use tree-sitter-ruby crate instead of vendoring it
2020-10-27 20:53:48 +01:00
Nick Rolfe
a41c3e36f9
Give node_types a static lifetime.
2020-10-27 19:11:05 +00:00
Nick Rolfe
5484ff3dcf
Use tree_sitter_ruby crate in generator
2020-10-27 18:13:40 +00:00
Douglas Creager
2663de86fb
Don't clone submodules in Actions workflow
...
Since we don't have any submodules anymore!
2020-10-27 14:02:15 -04:00
Nick Rolfe
ce8de3feba
Update generator binary name in Actions workflow
2020-10-27 17:56:37 +00:00
Douglas Creager
5f985be2d9
Use tree-sitter-ruby crate instead of vendoring it
2020-10-27 13:54:56 -04:00
Nick Rolfe
e05bcf9fb7
Generate QL classes
2020-10-27 17:46:11 +00:00
Arthur Baars
3e1c378aba
Merge pull request #8 from github/aibaars/actions
...
Improve extractor build and add GitHub Actions configuration
2020-10-27 18:21:20 +01:00
Arthur Baars
4b46a75c24
Merge pull request #10 from github/github/aibaars/escape-uppercase
...
DB scheme: convert uppercase to lowercase + underscore
2020-10-27 18:21:00 +01:00
Arthur Baars
bb2e7d841f
DB scheme: convert uppercase to lowercase + underscore
2020-10-27 18:15:48 +01:00
Arthur Baars
53b97ff0fa
Use release builds for the CodeQL package
2020-10-27 17:48:11 +01:00
Arthur Baars
bdff1fe9f4
Merge pull request #9 from github/aibaars/escape-column-names
...
DB scheme generator: escape column names
2020-10-27 17:44:39 +01:00
Arthur Baars
e3a1d426b8
DB scheme generator: escape column names
2020-10-27 17:31:10 +01:00
Arthur Baars
9e6ccf558e
Preserve permissions of Linux and OSX binaries
...
The {upload,download}-artifact actions do not preserve
file permissions, so we need to patch things up.
2020-10-27 17:17:44 +01:00
Arthur Baars
048f19edc1
Build a CodeQL extractor pack
2020-10-27 17:02:08 +01:00
Arthur Baars
73a090501a
Add GitHub actions configuration
2020-10-27 16:34:17 +01:00
Arthur Baars
7555141246
Extractor: include contents node-types.json as constant
2020-10-27 16:34:17 +01:00
Arthur Baars
74dd4dcc2c
Build parser.c and scanner.cc separately
2020-10-27 16:34:17 +01:00
Arthur Baars
74e9829609
Merge pull request #7 from github/aibaars/refactor
...
Refactor dbscheme generator to use intermediate representation
2020-10-27 14:12:05 +01:00
Arthur Baars
1fd6fdd652
Address review comment from earlier pull-request
2020-10-27 13:43:59 +01:00
Arthur Baars
a50f79b401
Add logging to dbscheme generator
2020-10-27 13:36:58 +01:00
Arthur Baars
0439d4f674
Refactor dbscheme generator to use intermediate representation
...
* merge extractor/node_types.rs into node-types/lib.rs
* use intermediate representation in dbscheme generator
* move dbscheme naming and escaping functions to node-types so they can be shared
2020-10-27 13:27:45 +01:00
Arthur Baars
4c1682ef2e
Merge pull request #5 from github/aibaars/logger
...
Add logging based on the tracing library
2020-10-27 13:24:34 +01:00
Nick Rolfe
63282eac60
Merge pull request #6 from github/windows_paths
...
Handle Windows path prefixes
2020-10-27 12:20:54 +00:00
Nick Rolfe
c02b735eec
Handle Windows path prefixes
2020-10-27 12:09:46 +00:00
Arthur Baars
52035ef672
Add tracing logger
2020-10-27 11:29:21 +01:00
Arthur Baars
9c534209f7
Add tracing:0.1
2020-10-27 11:26:35 +01:00
Arthur Baars
467e32ade4
Merge pull request #2 from github/aibaars/extractor-rust
...
Rewrite extractor in rust
2020-10-27 10:16:58 +01:00
Arthur Baars
0f576fe29a
Address review comments
2020-10-26 19:10:44 +01:00
Arthur Baars
1d36b5085a
Do not recurse into 'extra' nodes for now
2020-10-26 18:39:10 +01:00
Arthur Baars
fd39524c5e
Improve error messages
...
Include file path and line number and emit better descriptions
2020-10-26 18:37:29 +01:00
Arthur Baars
47ccc33ab3
Initial version of extractor based on tree-sitter grammar
2020-10-24 13:22:39 +02:00
Arthur Baars
d00c956028
Build with clang for non-windows platforms
2020-10-24 13:22:39 +02:00
Arthur Baars
f6292e437e
Merge pull request #4 from github/shared_lib
...
Add library package for shared code
2020-10-23 14:18:42 +02:00
Nick Rolfe
849e109583
Add library package for shared code
2020-10-23 13:01:17 +01:00
Arthur Baars
305fd566a8
Merge pull request #3 from github/aibaars/codeql-extractor-yaml
...
Basic CodeQL extractor configuration and autobuild scripts
2020-10-22 22:23:44 +02:00
Arthur Baars
e16b85e511
Add codeql-extractor config
2020-10-22 18:30:57 +02:00
Nick Rolfe
12571dbe42
Merge pull request #1 from github/dbscheme
...
Basic dbscheme generation from `node-types.json`
2020-10-22 12:29:44 +01:00
Nick Rolfe
36823d7804
Move deserialization to node_types module; propagate errors to caller
2020-10-22 11:10:05 +01:00
Nick Rolfe
e018f3f20b
Use if let instead of iterating over Option
2020-10-21 12:51:10 +01:00
Nick Rolfe
5e3544fcc3
Use fmt::Display trait for writing dbscheme
2020-10-21 12:45:54 +01:00
Nick Rolfe
a7a18b8b0f
Gather all hard-coded Ruby-specific names/paths in one struct.
2020-10-21 11:29:25 +01:00
Nick Rolfe
47c8a3d6fb
Simplify to std::io::Result
2020-10-21 11:26:23 +01:00
Nick Rolfe
fd1f8b22e2
Simplify keysets to Option<Vec<String>>
2020-10-21 11:06:53 +01:00
Nick Rolfe
97181d1c21
Basic dbscheme generation from node-types.json
2020-10-20 17:49:55 +01:00
Nick Rolfe
735fde7a22
Add README
2020-10-15 13:26:13 +01:00
Nick Rolfe
a837c65bc4
Add VSCode build task for cargo build
2020-10-15 13:21:12 +01:00
Nick Rolfe
ffbb57a8e2
Make VSCode default to unix line endings
2020-10-15 13:20:37 +01:00
Nick Rolfe
6c697bf9b5
Split into generator and extractor packages
2020-10-15 13:20:11 +01:00
Nick Rolfe
b677a91fea
Add VSCode workspace
2020-10-14 11:16:28 +01:00
Nick Rolfe
89959b2e0d
Add tree-sitter-ruby submodule
2020-10-14 11:15:59 +01:00
Nick Rolfe
d3ccb49273
Initial commit: cargo-generated boilerplate
2020-10-13 18:42:13 +01:00