Skip to content

feat: TypeConstrainedAttribute for Statements + DataflowIR.Language - #635

Merged
shivasurya merged 1 commit into
mainfrom
shiva/pr-06-type-attr-language
Apr 3, 2026
Merged

shivasurya merged 1 commit into
mainfrom
shiva/pr-06-type-attr-language

Conversation

@shivasurya

Copy link
Copy Markdown
Owner

Summary

Enables GoHTTPRequest.attr("URL.Path") matching against Go statements and adds language scoping so Go rules only analyze Go functions.

Stacked on: #634 (PR-05: type enrichment)

Changes

  • ir_types.go — DataflowIR.Language field ("go", "python", "" for any). Plural ReceiverTypes/AttributeNames on TypeConstrainedAttributeIR with getReceiverTypes()/getAttributeNames() helpers for backward compatibility.
  • type_constrained_executor.go — Execute() now scans both CallGraph.CallSites (Python) and CallGraph.Statements (Go). Matches enriched stmt.AttributeAccess like "net/http.Request.URL.Path" against (receiverType, attrName) combinations. matchesAttributeAccess updated to use plural helpers.
  • dataflow_executor.go — Language filter in findFunctionsWithSourcesAndSinks: when DataflowIR.Language is set, only functions with matching graph.Node.Language are analyzed.

Test plan

  • 6 Statement scanning tests: basic match, no match, singular IR, empty, prefix match, nil
  • 3 language filter tests: Go only, Python only, no filter
  • Full DSL package: go test ./dsl/ -count=1
  • Full builder package: go test ./graph/callgraph/builder/ -count=1
  • Lint clean: golangci-lint run ./dsl/

🤖 Generated with Claude Code

@shivasurya shivasurya added enhancement New feature or request go Pull requests that update go code labels Apr 2, 2026
@shivasurya shivasurya self-assigned this Apr 2, 2026
@safedep

safedep Bot commented Apr 2, 2026 •

Copy link
Copy Markdown

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

No dependency changes detected. Nothing to scan.

View complete scan results →

This report is generated by SafeDep Github App

@github-actions

github-actions Bot commented Apr 2, 2026

Copy link
Copy Markdown

Code Pathfinder Security Scan

Pass Critical High Medium Low Info

No security issues detected.

Metric Value
Files Scanned 5
Rules 205

Powered by Code Pathfinder

@codecov

codecov Bot commented Apr 2, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 98.36066% with 1 line in your changes missing coverage. Please review.
✅ Project coverage is 84.26%. Comparing base (f84045f) to head (479192f).
⚠️ Report is 1 commits behind head on main.

Files with missing lines Patch % Lines
sast-engine/dsl/ir_types.go 91.66% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #635      +/-   ##
==========================================
+ Coverage   84.22%   84.26%   +0.03%     
==========================================
  Files         160      160              
  Lines       22529    22571      +42     
==========================================
+ Hits        18976    19019      +43     
  Misses       2857     2857              
+ Partials      696      695       -1     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

shivasurya commented Apr 3, 2026 •

Copy link
Copy Markdown
Owner Author

Merge activity

  • Apr 3, 5:27 PM UTC: A user started a stack merge that includes this pull request via Graphite.
  • Apr 3, 5:36 PM UTC: Graphite rebased this pull request as part of a merge.
  • Apr 3, 5:37 PM UTC: @shivasurya merged this pull request with Graphite.

@shivasurya
shivasurya changed the base branch from shiva/pr-05-type-enrichment to graphite-base/635 April 3, 2026 17:34
@shivasurya
shivasurya changed the base branch from graphite-base/635 to main April 3, 2026 17:35
Extends TypeConstrainedAttributeExecutor to scan CallGraph.Statements
for enriched AttributeAccess (Go struct field access). After PR-05
type enrichment, "net/http.Request.URL.Path" in Statements is matched
by GoHTTPRequest.attr("URL.Path").

Also adds DataflowIR.Language field and language filter in
findFunctionsWithSourcesAndSinks — Go rules only analyze Go functions.

Changes:
- ir_types.go: DataflowIR.Language, plural ReceiverTypes/AttributeNames
  on TypeConstrainedAttributeIR with getReceiverTypes/getAttributeNames
- type_constrained_executor.go: Execute() scans Statements + CallSites,
  matchesAttributeAccess uses plural helpers
- dataflow_executor.go: language filter in findFunctionsWithSourcesAndSinks

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@shivasurya
shivasurya force-pushed the shiva/pr-06-type-attr-language branch from 32d425e to 479192f Compare April 3, 2026 17:36
@shivasurya
shivasurya merged commit 683f7d7 into main Apr 3, 2026
5 checks passed
@shivasurya
shivasurya deleted the shiva/pr-06-type-attr-language branch April 3, 2026 17:37
shivasurya added a commit that referenced this pull request Apr 3, 2026
## Summary

Enables Go security rule authoring via the Python SDK. Rule authors write type-first rules with no variable names — pure type contracts.

**Stacked on:** #635 (PR-06: TypeConstrainedAttribute + Language filter)

### New files

- **`codepathfinder/go_rule.py`** — 14 Go QueryType classes: GoHTTPRequest, GoHTTPClient, GoHTTPResponseWriter, GoSQLDB, GoOS, GoOSExec, GoFmt, GoIO, GoFilepath, GoStrconv, GoJSON, GoTemplate, GoContext, GoCrypto
- **`rules/go_decorators.py`** — `@go_rule` decorator mirroring `@python_rule`. Injects `language="go"` into DataflowIR matcher dict for language scoping.
- **`rules/go_ir.py`** — `compile_go_rules()` JSON IR compiler mirroring `python_ir.py`

### Design for multi-language scalability

Each language follows the same pattern: `{lang}_decorators.py` + `{lang}_ir.py` + `codepathfinder/{lang}_rule.py`. Adding Java would create `java_decorators.py`, `java_ir.py`, `codepathfinder/java_rule.py` with `JavaServletRequest`, `JavaJDBCStatement` etc.

### Example rule

```python
@go_rule(id="GO-SQLI-TAINT", severity="CRITICAL", cwe="CWE-89")
def detect_sqli():
    return flows(
        from_sources=[GoHTTPRequest.method("FormValue"), GoHTTPRequest.attr("URL.Path")],
        to_sinks=[GoSQLDB.method("Query", "Exec").tracks(0)],
        propagates_through=PropagationPresets.standard(),
        scope="global",
    )
```

## Test plan
- [x] 13 tests: QueryType IR output, decorator metadata, language injection, non-dataflow matcher, IR compilation, JSON serialization
- [x] 100% coverage on `go_rule.py`
- [x] Full SDK suite: `python3 -m pytest tests/ -v` (381 passed)

🤖 Generated with [Claude Code](https://claude.ai/code)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant