Skip to content

feat: attribute access as taint source for dataflow analysis (GAP-006) - #620

Merged
shivasurya merged 4 commits into
mainfrom
shiva/gap-analysis-reports
Mar 28, 2026
Merged

shivasurya merged 4 commits into
mainfrom
shiva/gap-analysis-reports

Conversation

@shivasurya

Copy link
Copy Markdown
Owner

Summary

  • Add AttributeAccess field to core.Statement to capture full dotted attribute chains on RHS of assignments (e.g., request.url, file.filename, self.config.SECRET)
  • New attribute_matcher IR type and AttributeMatcherExecutor in DSL layer, wired into resolveMatchers() for use inside flows() as source/sink/sanitizer
  • VDG matches AttributeAccess against taint source/sanitizer/sink patterns alongside existing CallTarget matching
  • Python SDK: attribute() matcher function and QueryType.attr() for type-constrained attribute matching
  • Unlocks ~40 detection rules where web frameworks expose user input as properties, not function calls

CVE Verification

Verified end-to-end with Python SDK rules against 3 real CVE patterns:

CVE Pattern Source → Sink Result
GHSA-527m-2xhr-j27g (LLaMA Factory) SSRF request.url → requests.get() Detected
GHSA-ph9w-r52h-28p7 (langflow) Path traversal uploaded.filename → os.path.join() Detected
GHSA-vwmf-pq79-vjvx (langflow) RCE request.data → eval() Detected

Test plan

  • 10 unit tests for extractFullAttributeChain (simple, deep, negative cases)
  • 4 VDG tests for attribute-based taint marking (source, flow, sanitizer, negative)
  • 6 AttributeMatcherExecutor tests (exact, suffix, multi-pattern, nil safety)
  • 1 dataflow integration test (attribute source → call sink end-to-end)
  • 7 Python SDK verification tests (IR serialization, flows integration, QueryType.attr)
  • Full regression: gradle lintGo, buildGo, testGo all pass

🤖 Generated with Claude Code

Enable pure attribute access (x = request.url, name = file.filename) to
be recognized as taint sources in dataflow analysis. Previously only
function call results could be taint sources, causing ~40 detection rules
to miss real CVEs where web frameworks expose user input as properties.

Go engine:
- Add AttributeAccess field to core.Statement, populated by
  extractFullAttributeChain() for RHS attribute nodes
- VDG matches AttributeAccess against source/sanitizer/sink patterns
- New AttributeMatcherIR and AttributeMatcherExecutor in DSL layer
- Wire attribute_matcher and type_constrained_attribute into
  resolveMatchers() for use inside flows()

Python SDK:
- Add attribute() matcher function (parallel to calls())
- Add QueryType.attr() for type-constrained attribute matching
- Update AnyMatcher union and exports

Verified against 3 real CVE patterns:
- GHSA-527m-2xhr-j27g (SSRF via request.url)
- GHSA-ph9w-r52h-28p7 (path traversal via file.filename)
- GHSA-vwmf-pq79-vjvx (RCE via request.data to eval)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@shivasurya shivasurya added enhancement New feature or request go Pull requests that update go code python labels Mar 27, 2026
@shivasurya shivasurya self-assigned this Mar 27, 2026
@shivasurya shivasurya added enhancement New feature or request go Pull requests that update go code python labels Mar 27, 2026
@safedep

safedep Bot commented Mar 27, 2026 •

Copy link
Copy Markdown

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

No dependency changes detected. Nothing to scan.

View complete scan results →

This report is generated by SafeDep Github App

@github-actions

github-actions Bot commented Mar 27, 2026 •

Copy link
Copy Markdown

Code Pathfinder Security Scan

Pass Critical High Medium Low Info

No security issues detected.

Metric Value
Files Scanned 23
Rules 88

Powered by Code Pathfinder

@codecov

codecov Bot commented Mar 27, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 98.09524% with 2 lines in your changes missing coverage. Please review.
✅ Project coverage is 83.84%. Comparing base (4dffef2) to head (9f470ce).
⚠️ Report is 1 commits behind head on main.

Files with missing lines Patch % Lines
...st-engine/graph/callgraph/extraction/statements.go 88.23% 2 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #620      +/-   ##
==========================================
+ Coverage   83.77%   83.84%   +0.06%     
==========================================
  Files         155      156       +1     
  Lines       21298    21397      +99     
==========================================
+ Hits        17843    17940      +97     
- Misses       2801     2803       +2     
  Partials      654      654              

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

shivasurya and others added 3 commits March 27, 2026 00:11
- Remove unnecessary string() conversions in extractFullAttributeChain
- Format query_type.py with black
- Add 17 Python SDK tests for attribute(), QueryType.attr(), IR validation
- Coverage: 97.51% (above 95% threshold)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- Cover attribute_matcher JSON unmarshal error branch
- Cover attribute_matcher validation error branch
- Cover type_constrained_attribute resolveMatchers path with detections
- Cover type_constrained_attribute invalid JSON branch
- Cover validateAttributeMatcherIR empty patterns + empty string
- Cover extractFullAttributeChain nil node edge case
- All patch lines now have count >= 1

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
- sast-engine: 2.0.0 → 2.0.1 (patch: new attribute_matcher IR + executor)
- python-sdk: 1.3.6 → 1.4.0 (minor: new attribute() and QueryType.attr() API)
- Add CHANGELOG entry for python-sdk 1.4.0

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@shivasurya
shivasurya force-pushed the shiva/gap-analysis-reports branch from 5fd23eb to 9f470ce Compare March 28, 2026 02:51
@shivasurya
shivasurya merged commit a05f7f1 into main Mar 28, 2026
8 checks passed
@shivasurya
shivasurya deleted the shiva/gap-analysis-reports branch March 28, 2026 02:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request go Pull requests that update go code python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant