github / github/codeql

Python: Dataflow fails when Class attributes are accessed as Instance attributes.

未關閉
#16,501 3 則留言 0 個 reaction 已指派 1 人 已指派給 @RasmusWL 在 GitHub 檢視
Python question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

I'm testing out dataflow and taint tracking analysis on Python and I've run into a example where the dataflow analysis should find a path, but fails because a class variable is accessed as an instance variable.

Here is the dataflow query
```
/**
* @name Testing
* @kind path-problem
* @id test
*/

import python
import semmle.python.Concepts
import semmle.python.dataflow.new.DataFlow
import semmle.python.dataflow.new.TaintTracking
import semmle.python.ApiGraphs

module MyFlowConfiguration implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
source = API::builtin("input").getACall().getReturn().asSource()
}

predicate isSink(DataFlow::Node sink) {
sink = API::builtin("print").getACall().getAParameter().asSink()
}
}

module MyFlow = DataFlow::Global;
import MyFlow::PathGraph

from MyFlow::PathNode source, MyFlow::PathNode sink
where MyFlow::flowPath(source,sink)
select sink.getNode(), source, sink, "This path depends on a $@.", source.getNode(),
"user-provided value"
```

The query correctly identfies the path from `input()` to `print()` in this snippet:
```
class Test():
def __init__(self):
self.one = input()

class Test2():
t = Test
def func(self):
test = Test2.t()
print(test.one)

Test2().func()
```

But it fails for this snippet:
```
class Test():
def __init__(self):
self.one = input()

class Test2():
t = Test
def func(self):
test = self.t()
print(test.one)

Test2().func()
```

The only difference is that the first example uses `test = Test2.t()` and the second example uses `test = self.t()` in the function `func` defined in `Test2`

This seems related to #14842, #14899 and https://github.com/github/codeql/discussions/9684

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。