Rule Request: trojan_source
Nobody has claimed this yet.
- Dominant language
- Swift
- Stars
- 19.7k
- Forks
- 2.3k
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 11
Description
New Issue Checklist
- Updated SwiftLint to the latest version
- I searched for existing GitHub issues
New rule request
Please describe the rule idea, format
this issue's title as Rule Request: [Rule Name] and describe:
- Why should this rule be added? Share links to existing discussion about what
the community thinks about this.
A recent publication has brought attention to "trojan source" attacks. See discussion and links at https://forums.swift.org/t/is-swift-vulnerable-to-trojan-source-attacks/53205/5
- Provide several examples of what would and wouldn't trigger violations.
Only the characters relevant to the attack would trigger a violation.
- Should the rule be configurable, if so what parameters should be configurable?
No
- Should the rule be opt-in or enabled by default? Why?
See README.md for guidelines on when to mark a rule as opt-in.
Enabled by default. It guards against security vulnerabilities and developers who do want to use these unicode features should be explicit about their intent.
Implementation via custom rule for reference:
custom_rules:
trojan_source:
regex: "[\u202A\u202B\u202D\u202E\u2066\u2067\u2068\u202C\u2069]"
severity: error
message: "Source should not contain characters that may be used in reordering attacks. https://trojansource.codes/trojan-source.pdf"
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the linked Swift Forum discussion and README.md's opt-in-rule guidelines, then review existing SwiftLint rule implementations and tests for the appropriate entry points. Define the rule around the listed bidirectional Unicode characters, ensure it is enabled by default with the stated message and error severity, and verify that intended characters are not reported.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- swift
- Domain
- security, tooling
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 42/100