CodeQL Python query runs extremely slow on medium-sized project using TaintTracking::Global
- 主要语言
- CodeQL
- 星标
- 10.1k
- 派生
- 2.1k
- 平均合并
- 2 天 15 小时
- 30 天内合并 PR
- 141
描述
I'm experiencing very slow performance when running a CodeQL query on a Python project using `TaintTracking::Global`. The analysis never finishes, even after more than **2 hours**, on a project that I believe is not very large. Below are some details:
* **CVE project**: CVE-2024-23637
* **Python files**: 263
* **Total lines**: \~88,981
* **Sources**: < 200
* **Sinks**: < 200
* **Tracking config**: `TaintTracking::Global`
My query looks like this:
```ql
module RemoteToFileConfiguration implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
MySources::isSource(source)
}
predicate isSink(DataFlow::Node sink) {
MySinks::isMySink(sink)
}
}
module Flow = TaintTracking::Global;
import Flow::PathGraph
from Flow::PathNode source, Flow::PathNode sink
where Flow::flowPath(source, sink)
select sink.getNode(), source, sink, "Flow path from source to sink"
```
I defined sinks or sources like this (simplified):
```ql
module MySinks {
class Sink extends DataFlow::Node {
Sink() {
exists(FunctionValue func, Call call |
func.getQualifiedName() = "run_code" or
func.getQualifiedName() = "check_syntax_error" or
...
call.getFunc().pointsTo(func) and
this = DataFlow::exprNode(call.getAnArg())
)
}
}
predicate isMySink(DataFlow::Node sink) {
exists(Sink s | s = sink)
}
}
```
### My questions:
1. Why is the performance so slow in this case?
2. Are there any best practices for optimizing `TaintTracking::Global` on Python?
3. I tried using `func.getQualifiedName()` with a full path like `"Module xml.etree.ElementInclude.Function default_loader"`, but it didn’t work in VSCode (the function wasn't found). Is there a correct way to define sinks using fully qualified names for Python?
Thank you very much for any guidance or suggestions!
贡献指南
调研方向
未指定任何仓库文件或测试。首先针对 CVE-2024-23637 项目复现所示的 TaintTracking::Global 查询,然后检查 source 和 sink 的定义,包括 VSCode 中对 getQualifiedName 的使用。完成标准是记录性能原因或优化指导,以及正确的 Python sink 命名方法。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- python, vscode
- 领域
- devtools, security
- Issue 类型
- 缺陷
- 难度
- 5/5
- 预计耗时
- 一周以上
- 活跃度
- 停滞
- 描述清晰度
- 需要澄清
- 新手友好度
- 25/100