github / github/codeql

Python: Dataflow fails when Class attributes are accessed as Instance attributes.

未关闭
#16,501 3 条评论 0 个 reaction 已指派 1 人 已指派给 @RasmusWL 在 GitHub 查看
Python question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

I'm testing out dataflow and taint tracking analysis on Python and I've run into a example where the dataflow analysis should find a path, but fails because a class variable is accessed as an instance variable.

Here is the dataflow query
```
/**
* @name Testing
* @kind path-problem
* @id test
*/

import python
import semmle.python.Concepts
import semmle.python.dataflow.new.DataFlow
import semmle.python.dataflow.new.TaintTracking
import semmle.python.ApiGraphs

module MyFlowConfiguration implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
source = API::builtin("input").getACall().getReturn().asSource()
}

predicate isSink(DataFlow::Node sink) {
sink = API::builtin("print").getACall().getAParameter().asSink()
}
}

module MyFlow = DataFlow::Global;
import MyFlow::PathGraph

from MyFlow::PathNode source, MyFlow::PathNode sink
where MyFlow::flowPath(source,sink)
select sink.getNode(), source, sink, "This path depends on a $@.", source.getNode(),
"user-provided value"
```

The query correctly identfies the path from `input()` to `print()` in this snippet:
```
class Test():
def __init__(self):
self.one = input()

class Test2():
t = Test
def func(self):
test = Test2.t()
print(test.one)

Test2().func()
```

But it fails for this snippet:
```
class Test():
def __init__(self):
self.one = input()

class Test2():
t = Test
def func(self):
test = self.t()
print(test.one)

Test2().func()
```

The only difference is that the first example uses `test = Test2.t()` and the second example uses `test = self.t()` in the function `func` defined in `Test2`

This seems related to #14842, #14899 and https://github.com/github/codeql/discussions/9684

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。