Skip to content

feat: deep call chain resolution for VDG taint analysis (GAP-004) - #623

Merged
shivasurya merged 6 commits into
mainfrom
shiva/deep-call-chain-gap-004
Mar 28, 2026
Merged

shivasurya merged 6 commits into
mainfrom
shiva/deep-call-chain-gap-004

Conversation

@shivasurya

Copy link
Copy Markdown
Owner

Summary

  • Add CallChain field to Statement storing full dotted attribute chain for method calls (e.g., "request.args.get" instead of just "get")
  • Modify extractCallTarget to return both bare method name and full chain in extraction and CFG builder
  • Thread CallChain through VDG Build() and FindTaintFlows() for precise source/sink/sanitizer matching
  • Enables rules like calls("request.args.get") and calls("*.config.get") to match precisely without false positives from dict.get(), list.get(), etc.

Test plan

  • 10 extraction tests for CallChain (simple, 2-level, 3-level, 6-level, bare call, method call, subscript-on-call)
  • 3 CFG builder tests for CallChain (method call, three-level, simple call)
  • 6 VDG tests (precise source match, wildcard suffix, no false positive, sink match, sanitizer match, backward compat)
  • E2E scan: calls("*.config.get") matches self.pyload.config.get() — 1 finding
  • E2E scan: calls("request.args.get") matches precisely — 1 finding
  • E2E scan: calls("*.get") backward compat — still works
  • gradle lintGo — 0 issues
  • gradle buildGo — BUILD SUCCESSFUL
  • gradle testGo — 368 Python + 29 Go packages passed

🤖 Generated with Claude Code

shivasurya and others added 4 commits March 28, 2026 14:17
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
… (GAP-004)

Change extractCallTarget to return (target, chain) where target is the
bare method name and chain is the full dotted path. Thread CallChain
through extractCall and extractAssignment (including subscript-on-call).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…n (GAP-004)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@shivasurya shivasurya added enhancement New feature or request go Pull requests that update go code labels Mar 28, 2026
@shivasurya shivasurya self-assigned this Mar 28, 2026
@safedep

safedep Bot commented Mar 28, 2026 •

Copy link
Copy Markdown

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

No dependency changes detected. Nothing to scan.

View complete scan results: 🔗 Here

This report is generated by SafeDep Github App

@github-actions

github-actions Bot commented Mar 28, 2026 •

Copy link
Copy Markdown

Code Pathfinder Security Scan

Pass Critical High Medium Low Info

No security issues detected.

Metric Value
Files Scanned 8
Rules 88

Powered by Code Pathfinder

@codecov

codecov Bot commented Mar 28, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 88.57143% with 4 lines in your changes missing coverage. Please review.
✅ Project coverage is 84.04%. Comparing base (cd5ec14) to head (bab3b03).
⚠️ Report is 1 commits behind head on main.

Files with missing lines Patch % Lines
sast-engine/graph/callgraph/cfg/builder.go 85.71% 2 Missing ⚠️
...st-engine/graph/callgraph/extraction/statements.go 85.71% 2 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #623      +/-   ##
==========================================
+ Coverage   83.91%   84.04%   +0.12%     
==========================================
  Files         156      156              
  Lines       21454    21474      +20     
==========================================
+ Hits        18003    18047      +44     
+ Misses       2802     2779      -23     
+ Partials      649      648       -1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

shivasurya and others added 2 commits March 28, 2026 15:09
Add tests for augmented assignment, bare call with chain, and lambda
call expressions to cover previously untested code paths.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Parameters with identical Line values caused non-deterministic sort
order in getParamNamesForFQN, making the tracked param index mapping
random. Give params distinct line numbers for stable ordering.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@shivasurya
shivasurya merged commit f00f440 into main Mar 28, 2026
8 checks passed
@shivasurya
shivasurya deleted the shiva/deep-call-chain-gap-004 branch March 28, 2026 19:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant