Argument level granularity in data-flow tracking to calls
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 30/100
Research direction
Start by reproducing the supplied C/C++ example and Scala query, focusing on whether cpg.call.name("memcpy").argument(3) constrains reachableByFlows. Trace the argument handling in the data-flow implementation and add coverage showing that only the b_n path reaches memcpy's third argument.
Written by the indexing model from the issue text.
Description
I was trying to get data-flow to a specific argument to a function call.
For example, considering the following snippet of code:
#include <stdio.h>
#include <stdint.h>
#include <string.h>
#include <arpa/inet.h>
int main() {
uint32_t a = 28;
uint32_t b = 42;
uint32_t a_n = ntohl(a);
uint32_t b_n = ntohl(b);
char *buf;
uint32_t offset = a_n + 5;
memcpy(buf + offset, buf, b_n);
}
I want to get the dataflow from calls to ntohl, to the size argument of memcpy. So in the example, I would expect the flow b_n = ntohl(a) -> ... -> memcpy(buf + offset, buf, b_n).
My query is:
def networkToMemcpy() = {
val source = cpg.call.name("ntoh(s|l|ll)")
val sink = cpg.call.name("memcpy").argument(3)
val paths = sink.reachableByFlows(source)
paths.l.map(
l => l.elements.map(
call => (
call.asInstanceOf[Call].name,
call.asInstanceOf[Call].code,
call.location.filename,
call.location.lineNumber match {
case Some(n) => n.toString
case None => "n/a"
}
)
)
)
}
The problem is, apart from the expected flow, I am also getting the flow of identifier a_n -> memcpy(buf + offset) which is the first argument of memcpy.
joern> networkToMemcpy
res100: List[List[(String, String, String, String)]] = List(
List(
("ntohl", "ntohl(b)", "/mnt/c/wd/tmp/t/a.c", "10"),
("<operator>.assignment", "b_n = ntohl(b)", "/mnt/c/wd/tmp/t/a.c", "10"),
("memcpy", "memcpy(buf + offset, buf, b_n)", "/mnt/c/wd/tmp/t/a.c", "15")
),
List(
("ntohl", "ntohl(a)", "/mnt/c/wd/tmp/t/a.c", "9"),
("<operator>.assignment", "a_n = ntohl(a)", "/mnt/c/wd/tmp/t/a.c", "9"),
("<operator>.addition", "a_n + 5", "/mnt/c/wd/tmp/t/a.c", "13"),
("<operator>.assignment", "offset = a_n + 5", "/mnt/c/wd/tmp/t/a.c", "13"),
("<operator>.addition", "buf + offset", "/mnt/c/wd/tmp/t/a.c", "15"),
("memcpy", "memcpy(buf + offset, buf, b_n)", "/mnt/c/wd/tmp/t/a.c", "15")
)
)
It seems that argument in val sink = cpg.call.name("memcpy").argument(3) doesn't change the result.
Is there currently a way of getting data-flow for just one argument of a call?
- Dominant language
- Scala
- Stars
- 603
- Forks
- 84
- Avg merge
- 5h 31m
- Merged PRs (30d)
- 4
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from ShiftLeftSecurity/codepropertygraph
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
-
Difficulty 3/5 1-2 days Newbie friendliness 25/100
ShiftLeftSecurity/codepropertygraph#1760 · 3 comments ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
ShiftLeftSecurity/codepropertygraph#1272 · 2 comments ·
-
Difficulty 5/5 Over a week Newbie friendliness 20/100
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
ShiftLeftSecurity/codepropertygraph#1082 · 1 comment ·
All issues in ShiftLeftSecurity/codepropertygraph
Similar issues
-
scope:security type:aquasec
Difficulty 1/5 Under an hour Newbie friendliness 90/100
AbsaOSS/StatusBoard#69 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 82/100
Maintainers usually reply within 1 day
-
A-consensus C-question
Difficulty 1/5 Under an hour Newbie friendliness 74/100
ergoplatform/ergo#2624 ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
[Rust][Flaky Test] multiple_deadlines_fire_in_order asserts a wall-clock gap instead of firing orderOpenCI/CD ⚒️ Flaky-tests 🐦
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
valkey-io/valkey-glide#7255 ·
Maintainers usually reply within 3 days