Files
codeql/python/ql/test/query-tests/Security/CWE-022-TarSlip/TarSlip.expected
yoff 408ba6218f Python: switch dataflow library to new (shared) CFG + SSA
Flips the Python dataflow trunk from the legacy CFG (semmle/python/Flow.qll)
and legacy ESSA SSA (semmle/python/essa/*) to the new shared CFG facade
(semmle.python.controlflow.internal.Cfg) and the new SSA adapter
(semmle.python.dataflow.new.internal.SsaImpl), both introduced
additively in the preceding PRs in this stack.

This is the trunk-flip equivalent of the original draft PR #21894 (kept
around as documentation), rebased on top of the four preparatory PRs:

  P1: Remove AstNode.getAFlowNode() and rewrite callers (#21919).
  P2: Qualify Flow.qll's AST references with Py:: prefix (#21920).
  P3: Add new shared-CFG-backed control flow graph (#21921).
  P4: Add new shared-SSA-backed SSA adapter (#21923).

The Python dataflow library (semmle/python/dataflow/new/) now imports
the new CFG facade and SSA adapter. All CFG-typed predicates
(ControlFlowNode, CallNode, BasicBlock, NameNode, AttrNode, ...) are
qualified with the Cfg:: prefix; SSA references switch from
EssaVariable/EssaDefinition to SsaImpl::Definition/SourceVariable.

GuardNode is redesigned to use the new CFG's outcome-node model
(isAfterTrue / isAfterFalse) instead of the legacy ConditionBlock +
flipped indirection. Only BarrierGuard<...> is preserved as public
API.

Framework files (Bottle, FastApi, Django, Tornado, Pyramid, Stdlib,
...) are updated to take CFG nodes from the new facade.

A handful of dataflow consistency tweaks for the new CFG:
- Augmented-assignment targets are treated as both load and store.
- 'from X import *' produces uncertain SSA writes for unknown names.
- CFG nodes are canonicalised so dataflow does not see equivalent
  pre/post-order pairs as distinct nodes.

Two AST tweaks for the new CFG:
- AstNodeImpl: omit PEP 695 type-parameter names from
  FunctionDefExpr / ClassDefExpr children.
- ImportResolution: drop the legacy essa import.

Test churn (~175 files): reblessed library- and query-test .expected
files reflect slightly different CFG granularity, different toString
output, and a handful of true alert deltas in security queries.

Verification: all 367 lib + src + consistency-queries compile clean.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-06-22 13:46:43 +00:00

67 lines
5.7 KiB
Plaintext

edges
| tarslip.py:14:1:14:3 | tar | tarslip.py:15:1:15:3 | tar | provenance | |
| tarslip.py:14:7:14:39 | After Attribute() | tarslip.py:14:1:14:3 | tar | provenance | |
| tarslip.py:18:1:18:3 | tar | tarslip.py:19:5:19:9 | entry | provenance | |
| tarslip.py:18:7:18:39 | After Attribute() | tarslip.py:18:1:18:3 | tar | provenance | |
| tarslip.py:19:5:19:9 | entry | tarslip.py:20:17:20:21 | entry | provenance | |
| tarslip.py:35:1:35:3 | tar | tarslip.py:36:5:36:9 | entry | provenance | |
| tarslip.py:35:7:35:39 | After Attribute() | tarslip.py:35:1:35:3 | tar | provenance | |
| tarslip.py:36:5:36:9 | entry | tarslip.py:39:17:39:21 | entry | provenance | |
| tarslip.py:42:1:42:3 | tar | tarslip.py:43:24:43:26 | tar | provenance | |
| tarslip.py:42:7:42:39 | After Attribute() | tarslip.py:42:1:42:3 | tar | provenance | |
| tarslip.py:58:1:58:3 | tar | tarslip.py:59:5:59:9 | entry | provenance | |
| tarslip.py:58:7:58:39 | After Attribute() | tarslip.py:58:1:58:3 | tar | provenance | |
| tarslip.py:59:5:59:9 | entry | tarslip.py:61:21:61:25 | entry | provenance | |
| tarslip.py:90:1:90:3 | tar | tarslip.py:91:1:91:3 | tar | provenance | |
| tarslip.py:90:7:90:39 | After Attribute() | tarslip.py:90:1:90:3 | tar | provenance | |
| tarslip.py:94:1:94:3 | tar | tarslip.py:95:5:95:9 | entry | provenance | |
| tarslip.py:94:7:94:39 | After Attribute() | tarslip.py:94:1:94:3 | tar | provenance | |
| tarslip.py:95:5:95:9 | entry | tarslip.py:96:17:96:21 | entry | provenance | |
| tarslip.py:109:1:109:3 | tar | tarslip.py:110:1:110:3 | tar | provenance | |
| tarslip.py:109:7:109:39 | After Attribute() | tarslip.py:109:1:109:3 | tar | provenance | |
| tarslip.py:112:1:112:3 | tar | tarslip.py:113:24:113:26 | tar | provenance | |
| tarslip.py:112:7:112:39 | After Attribute() | tarslip.py:112:1:112:3 | tar | provenance | |
nodes
| tarslip.py:14:1:14:3 | tar | semmle.label | tar |
| tarslip.py:14:7:14:39 | After Attribute() | semmle.label | After Attribute() |
| tarslip.py:15:1:15:3 | tar | semmle.label | tar |
| tarslip.py:18:1:18:3 | tar | semmle.label | tar |
| tarslip.py:18:7:18:39 | After Attribute() | semmle.label | After Attribute() |
| tarslip.py:19:5:19:9 | entry | semmle.label | entry |
| tarslip.py:20:17:20:21 | entry | semmle.label | entry |
| tarslip.py:35:1:35:3 | tar | semmle.label | tar |
| tarslip.py:35:7:35:39 | After Attribute() | semmle.label | After Attribute() |
| tarslip.py:36:5:36:9 | entry | semmle.label | entry |
| tarslip.py:39:17:39:21 | entry | semmle.label | entry |
| tarslip.py:42:1:42:3 | tar | semmle.label | tar |
| tarslip.py:42:7:42:39 | After Attribute() | semmle.label | After Attribute() |
| tarslip.py:43:24:43:26 | tar | semmle.label | tar |
| tarslip.py:58:1:58:3 | tar | semmle.label | tar |
| tarslip.py:58:7:58:39 | After Attribute() | semmle.label | After Attribute() |
| tarslip.py:59:5:59:9 | entry | semmle.label | entry |
| tarslip.py:61:21:61:25 | entry | semmle.label | entry |
| tarslip.py:90:1:90:3 | tar | semmle.label | tar |
| tarslip.py:90:7:90:39 | After Attribute() | semmle.label | After Attribute() |
| tarslip.py:91:1:91:3 | tar | semmle.label | tar |
| tarslip.py:94:1:94:3 | tar | semmle.label | tar |
| tarslip.py:94:7:94:39 | After Attribute() | semmle.label | After Attribute() |
| tarslip.py:95:5:95:9 | entry | semmle.label | entry |
| tarslip.py:96:17:96:21 | entry | semmle.label | entry |
| tarslip.py:109:1:109:3 | tar | semmle.label | tar |
| tarslip.py:109:7:109:39 | After Attribute() | semmle.label | After Attribute() |
| tarslip.py:110:1:110:3 | tar | semmle.label | tar |
| tarslip.py:112:1:112:3 | tar | semmle.label | tar |
| tarslip.py:112:7:112:39 | After Attribute() | semmle.label | After Attribute() |
| tarslip.py:113:24:113:26 | tar | semmle.label | tar |
subpaths
#select
| tarslip.py:15:1:15:3 | tar | tarslip.py:14:7:14:39 | After Attribute() | tarslip.py:15:1:15:3 | tar | This file extraction depends on a $@. | tarslip.py:14:7:14:39 | After Attribute() | potentially untrusted source |
| tarslip.py:20:17:20:21 | entry | tarslip.py:18:7:18:39 | After Attribute() | tarslip.py:20:17:20:21 | entry | This file extraction depends on a $@. | tarslip.py:18:7:18:39 | After Attribute() | potentially untrusted source |
| tarslip.py:39:17:39:21 | entry | tarslip.py:35:7:35:39 | After Attribute() | tarslip.py:39:17:39:21 | entry | This file extraction depends on a $@. | tarslip.py:35:7:35:39 | After Attribute() | potentially untrusted source |
| tarslip.py:43:24:43:26 | tar | tarslip.py:42:7:42:39 | After Attribute() | tarslip.py:43:24:43:26 | tar | This file extraction depends on a $@. | tarslip.py:42:7:42:39 | After Attribute() | potentially untrusted source |
| tarslip.py:61:21:61:25 | entry | tarslip.py:58:7:58:39 | After Attribute() | tarslip.py:61:21:61:25 | entry | This file extraction depends on a $@. | tarslip.py:58:7:58:39 | After Attribute() | potentially untrusted source |
| tarslip.py:91:1:91:3 | tar | tarslip.py:90:7:90:39 | After Attribute() | tarslip.py:91:1:91:3 | tar | This file extraction depends on a $@. | tarslip.py:90:7:90:39 | After Attribute() | potentially untrusted source |
| tarslip.py:96:17:96:21 | entry | tarslip.py:94:7:94:39 | After Attribute() | tarslip.py:96:17:96:21 | entry | This file extraction depends on a $@. | tarslip.py:94:7:94:39 | After Attribute() | potentially untrusted source |
| tarslip.py:110:1:110:3 | tar | tarslip.py:109:7:109:39 | After Attribute() | tarslip.py:110:1:110:3 | tar | This file extraction depends on a $@. | tarslip.py:109:7:109:39 | After Attribute() | potentially untrusted source |
| tarslip.py:113:24:113:26 | tar | tarslip.py:112:7:112:39 | After Attribute() | tarslip.py:113:24:113:26 | tar | This file extraction depends on a $@. | tarslip.py:112:7:112:39 | After Attribute() | potentially untrusted source |