Skip to content

Commit 05ac22b

Browse files
authored
Merge branch 'main' into go/mad/update-nhooyr-io-websocket
2 parents 2505d14 + e86d08b commit 05ac22b

244 files changed

Lines changed: 14166 additions & 1920 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/label-external-contributions.yml‎

Lines changed: 42 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,9 +20,21 @@ jobs:
2020
pull-requests: write
2121

2222
steps:
23+
- name: Create organization membership token
24+
id: membership-token
25+
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
26+
with:
27+
client-id: ${{ vars.CODEQL_ORG_MEMBERS_APP_CLIENT_ID }}
28+
private-key: ${{ secrets.CODEQL_ORG_MEMBERS_APP_PRIVATE_KEY }}
29+
owner: ${{ github.repository_owner }}
30+
permission-members: read
31+
2332
- name: Label external contributions
2433
env:
34+
API_URL: ${{ github.api_url }}
2535
GH_TOKEN: ${{ github.token }}
36+
MEMBERS_TOKEN: ${{ steps.membership-token.outputs.token }}
37+
ORG: ${{ github.repository_owner }}
2638
REPO: ${{ github.repository }}
2739
run: |
2840
set -euo pipefail
@@ -46,13 +58,13 @@ jobs:
4658
(.head.repo.full_name | type == "string") and
4759
.head.repo.full_name != $repo and
4860
.user.type == "User" and
49-
.author_association != "MEMBER" and
50-
.author_association != "OWNER" and
61+
(.user.login | type == "string" and length > 0) and
5162
(any(.labels[]?; .name == $label) | not)' \
5263
>/dev/null <<<"$pr_json"; then
5364
continue
5465
fi
5566
67+
author=$(jq -r '.user.login' <<<"$pr_json")
5668
events=$(gh api --paginate \
5769
"repos/$REPO/issues/$pr_number/events?per_page=100" |
5870
jq -cs 'add')
@@ -63,6 +75,34 @@ jobs:
6375
continue
6476
fi
6577
78+
if ! membership_status=$(curl \
79+
--silent \
80+
--show-error \
81+
--output /dev/null \
82+
--write-out '%{http_code}' \
83+
--connect-timeout 10 \
84+
--max-time 30 \
85+
--header "Accept: application/vnd.github+json" \
86+
--header "Authorization: Bearer $MEMBERS_TOKEN" \
87+
--header "X-GitHub-Api-Version: 2022-11-28" \
88+
"$API_URL/orgs/$ORG/members/$author"); then
89+
echo "::error::Membership check failed for pull request #$pr_number."
90+
exit 1
91+
fi
92+
93+
case "$membership_status" in
94+
204)
95+
echo "Pull request #$pr_number was opened by an organization member; skipping."
96+
continue
97+
;;
98+
404)
99+
;;
100+
*)
101+
echo "::error::Membership check for pull request #$pr_number returned HTTP $membership_status."
102+
exit 1
103+
;;
104+
esac
105+
66106
jq -n --arg label "$label" '{labels: [$label]}' |
67107
gh api --method POST \
68108
"repos/$REPO/issues/$pr_number/labels" \

‎CONTRIBUTING.md‎

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -16,15 +16,17 @@ If you have an idea for a query that you would like to share with other CodeQL u
1616

1717
1. **Directory structure**
1818

19-
There are eight language-specific query directories in this repository:
19+
There are ten language-specific query directories in this repository:
2020

21+
* Actions: `actions/ql/src`
2122
* C/C++: `cpp/ql/src`
2223
* C#: `csharp/ql/src`
2324
* Go: `go/ql/src`
2425
* Java/Kotlin: `java/ql/src`
2526
* JavaScript: `javascript/ql/src`
2627
* Python: `python/ql/src`
2728
* Ruby: `ruby/ql/src`
29+
* Rust: `rust/ql/src`
2830
* Swift: `swift/ql/src`
2931

3032
Each language-specific directory contains further subdirectories that group queries based on their `@tags` or purpose.
@@ -75,7 +77,3 @@ After the experimental query is merged, we welcome pull requests to improve it.
7577
If you contribute to this project, we will record your name and email address (as provided by you with your contributions) as part of the code repositories, which are public. We might also use this information to contact you in relation to your contributions, as well as in the normal course of software development. We also store records of CLA agreements signed in the past, but no longer require contributors to sign a CLA. Under GDPR legislation, we do this on the basis of our legitimate interest in creating the CodeQL product.
7678

7779
Please do get in touch (privacy@github.com) if you have any questions about this or our data protection policies.
78-
79-
## Bazel
80-
Please notice that any bazel targets and definitions in this repository are currently experimental
81-
and for internal use only.

‎MODULE.bazel‎

Lines changed: 22 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ bazel_dep(name = "rules_kotlin", version = "2.2.2-codeql.1")
3030
bazel_dep(name = "gazelle", version = "0.50.0")
3131
bazel_dep(name = "rules_dotnet", version = "0.21.5-codeql.1")
3232
bazel_dep(name = "googletest", version = "1.17.0.bcr.2")
33-
bazel_dep(name = "rules_rust", version = "0.73.0")
33+
bazel_dep(name = "rules_rust", version = "0.74.0")
3434
bazel_dep(name = "rules_swift", version = "4.0.0-rc5-codeql.2")
3535
bazel_dep(name = "swift-syntax", version = "603.0.2")
3636
bazel_dep(name = "zstd", version = "1.5.7.bcr.1")
@@ -45,7 +45,7 @@ RUST_EDITION = "2024"
4545
# a nightly toolchain is required to enable experimental_use_cc_common_link, which we require internally
4646
# we prefer to run the same version as internally, even if experimental_use_cc_common_link is not really
4747
# required in this repo
48-
RUST_VERSION = "nightly/2026-07-15"
48+
RUST_VERSION = "nightly/2026-09-03"
4949

5050
rust = use_extension("@rules_rust//rust:extensions.bzl", "rust")
5151
rust.toolchain(
@@ -57,26 +57,26 @@ rust.toolchain(
5757
],
5858
# generated by buildutils-internal/scripts/fill-rust-sha256s.py (internal repo)
5959
sha256s = {
60-
"2026-07-15/rustc-nightly-x86_64-unknown-linux-gnu.tar.xz": "dad49ece98c6d0e5f3bfd7c532b5111f55319a0e2a880ef1a87379643348cf8e",
61-
"2026-07-15/rustc-nightly-x86_64-apple-darwin.tar.xz": "54fe056dd41fd0ae2e74e8a941ee207af21e9b86700636fa254f11f0f1fa0783",
62-
"2026-07-15/rustc-nightly-aarch64-apple-darwin.tar.xz": "0e8c44436fefd06850a343e244236bf8e2b7eadaee447c53a91bc4e17e6710d1",
63-
"2026-07-15/rustc-nightly-x86_64-pc-windows-msvc.tar.xz": "a55c3933faf617a47a10545a072bae1de03aa3fe7363d0779baad35bed2cf259",
64-
"2026-07-15/clippy-nightly-x86_64-unknown-linux-gnu.tar.xz": "49425e37f45e428b569098174a28985aae3102965dfa7434ca8472d1b3e58b5e",
65-
"2026-07-15/clippy-nightly-x86_64-apple-darwin.tar.xz": "2b1ca2938c8d3d35f9c26badd696d575db876260569900684c766cf8319960a7",
66-
"2026-07-15/clippy-nightly-aarch64-apple-darwin.tar.xz": "7c95556525376e0250dcdfb9c36725e8c0c131c1c6ac3b7e5872279e040852fb",
67-
"2026-07-15/clippy-nightly-x86_64-pc-windows-msvc.tar.xz": "e737590737fdf81e08af55c7cbc3e7f4883d5f68cbec4bd572ccb7af44fc15d8",
68-
"2026-07-15/cargo-nightly-x86_64-unknown-linux-gnu.tar.xz": "4df5b9f2ad9b597d272fa9500d650561f22c8543233485078a13a64693e567c3",
69-
"2026-07-15/cargo-nightly-x86_64-apple-darwin.tar.xz": "e45a0ab75df0e61a3429ab450e35551ca920b138be39dc5cf8af824dd36fcb15",
70-
"2026-07-15/cargo-nightly-aarch64-apple-darwin.tar.xz": "81e1469252cd4630fdf221f9390cdb4604472c0ef6774e6162370864e5adc3e0",
71-
"2026-07-15/cargo-nightly-x86_64-pc-windows-msvc.tar.xz": "077cf2ad9811cba2596faab7b5763f8430791263ab7f3961fa31f23aaa3d741d",
72-
"2026-07-15/llvm-tools-nightly-x86_64-unknown-linux-gnu.tar.xz": "25823477ba51d4aba12beb19cb7d2c46d453357a4b6d1c301102fc06d0c5db28",
73-
"2026-07-15/llvm-tools-nightly-x86_64-apple-darwin.tar.xz": "168f79a128b34c88a8cef03af0ced8986a99c52df4016e5d111cba3c4638e4e3",
74-
"2026-07-15/llvm-tools-nightly-aarch64-apple-darwin.tar.xz": "f95a27de3a30e6ba3d36548663b434e625cd1bbbfb015eadd90f67d80f657c5a",
75-
"2026-07-15/llvm-tools-nightly-x86_64-pc-windows-msvc.tar.xz": "1d48b7b8f511a23f270e9380f729ee414db918abbc88535fe419dd53aa0d5429",
76-
"2026-07-15/rust-std-nightly-x86_64-unknown-linux-gnu.tar.xz": "4c1a2f508b6791a1059924e6369d813b46888215add0a5906af95266b33219b2",
77-
"2026-07-15/rust-std-nightly-x86_64-apple-darwin.tar.xz": "a2438da77f7eb292f80a5cab3de1aa2e8deb718b89c0ba6e26ef5c76299cc048",
78-
"2026-07-15/rust-std-nightly-aarch64-apple-darwin.tar.xz": "02c36fc7728dc17376062e7a0f3bf26439e1317317971ba9339b3a3a34dee2fa",
79-
"2026-07-15/rust-std-nightly-x86_64-pc-windows-msvc.tar.xz": "5e724d34d34ec4ed34161bb890452640ddda11fd9ef64f6a74e47541d5b02583",
60+
"2026-09-03/rustc-nightly-x86_64-unknown-linux-gnu.tar.xz": "bd1f0986150596835e808635d81786c60ab9da3981687dfb00918329925e837a",
61+
"2026-09-03/rustc-nightly-x86_64-apple-darwin.tar.xz": "8f3da4fcdaf5c8574f723ee0dab80c0e47e59e97fb55c1b84a1dc96dc2b90f6b",
62+
"2026-09-03/rustc-nightly-aarch64-apple-darwin.tar.xz": "ef4e9dda67ee052fb60b506f76a5dbd2f1c45822aec878b31b98c2fe75ab6f84",
63+
"2026-09-03/rustc-nightly-x86_64-pc-windows-msvc.tar.xz": "b2feb930850f69c40c4fc4658a054676de9a3c263b6e1afbdad86b61ab0940ef",
64+
"2026-09-03/clippy-nightly-x86_64-unknown-linux-gnu.tar.xz": "9715b53a8e80261f85eeddc6096e82e6038218ddd81e9fd8d7d5d558d076191b",
65+
"2026-09-03/clippy-nightly-x86_64-apple-darwin.tar.xz": "83b26f9becd27e65b822a70d2f0ca1b676e0bad3d7a99597adf65326692744bb",
66+
"2026-09-03/clippy-nightly-aarch64-apple-darwin.tar.xz": "51708a4c7399d2a71e5fcaa491a9e233e63c98f67dcad7bbe11fd164ba604690",
67+
"2026-09-03/clippy-nightly-x86_64-pc-windows-msvc.tar.xz": "2990517d181ffe467505070d8842ae63089b781addedffa296100d018b746979",
68+
"2026-09-03/cargo-nightly-x86_64-unknown-linux-gnu.tar.xz": "a60615509715996b8d4d54b30a7db8a1cd62400d06206dbeeb20b223ad1e6b34",
69+
"2026-09-03/cargo-nightly-x86_64-apple-darwin.tar.xz": "1650d406de2cef5d7b0d573fa131937a09559c33b03766380fb3b97eb30b2493",
70+
"2026-09-03/cargo-nightly-aarch64-apple-darwin.tar.xz": "058ced0d2b26cde728a0553a572c0895cbbc5bdaaf23dc995649737cb2dd043d",
71+
"2026-09-03/cargo-nightly-x86_64-pc-windows-msvc.tar.xz": "1ce268af2f3e143b4a4aa114cfcead7091659af7b36660b007652b1f34329dff",
72+
"2026-09-03/llvm-tools-nightly-x86_64-unknown-linux-gnu.tar.xz": "c4557aaddd0b4a65593bd1f8474322fe3d91e5cc41a0221f383a8780256ad102",
73+
"2026-09-03/llvm-tools-nightly-x86_64-apple-darwin.tar.xz": "47d0e8184d270c223c298a227b0485afcfa5dc70429f5454b472a8b69ca03e9c",
74+
"2026-09-03/llvm-tools-nightly-aarch64-apple-darwin.tar.xz": "141b1f097db3a292f8641fe6e4ec1e48edb758154a2defa2dbd4a088af72caf7",
75+
"2026-09-03/llvm-tools-nightly-x86_64-pc-windows-msvc.tar.xz": "f6bb9e1cabc5b790bd419b7fe18c7ff132a40d0ff2db794efd2d5f4c0b535ba0",
76+
"2026-09-03/rust-std-nightly-x86_64-unknown-linux-gnu.tar.xz": "7bfd37eda0920b04ef50b4785475c5fa2cea8df19c24f3879d0b5cac6e4dcdbc",
77+
"2026-09-03/rust-std-nightly-x86_64-apple-darwin.tar.xz": "462e83115594799aff5d77a221b29a59d5e166435773c8eae37d047a8a5f39e1",
78+
"2026-09-03/rust-std-nightly-aarch64-apple-darwin.tar.xz": "79f676f8265e332ece71eea226a3a9b124506c9460e758ca1f669f80e0336eb0",
79+
"2026-09-03/rust-std-nightly-x86_64-pc-windows-msvc.tar.xz": "075661d74da5a65b8d5c8adb9375a868fea80d5b0e5c131af6f4cd059d6b3113",
8080
},
8181
versions = [RUST_VERSION],
8282
)
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
---
2+
category: minorAnalysis
3+
---
4+
* Added taint flow summaries for the BDE `bslx` byte-stream deserializers `BloombergLP::bslx::ByteInStream`, `BloombergLP::bslx::GenericInStream`, and `BloombergLP::bslx::InStreamFunctions::bdexStreamIn`.
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
---
2+
category: minorAnalysis
3+
---
4+
* Added flow summaries for the BDE codecs `BloombergLP::balber::BerDecoder`/`BerEncoder`, `BloombergLP::baljsn::Decoder`/`Encoder` and `BloombergLP::balxml::Decoder`/`Encoder`.
Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
---
2+
category: minorAnalysis
3+
---
4+
* Added SQL-injection sink models for the Comdb2 C API functions `cdb2_run_statement` and `cdb2_run_statement_typed`.

‎cpp/ql/lib/ext/Comdb2.model.yml‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
# Partial model of the Comdb2 C API.
2+
# https://bloomberg.github.io/comdb2/c_api.html
3+
extensions:
4+
- addsTo:
5+
pack: codeql/cpp-all
6+
extensible: sinkModel
7+
data: # namespace, type, subtypes, name, signature, ext, input, kind, provenance
8+
# Both functions interpret the second argument as SQL. The typed variant
9+
# specifies result-column types; bound parameter values are passed separately.
10+
- ["", "", False, "cdb2_run_statement", "", "", "Argument[*1]", "sql-injection", "manual"]
11+
- ["", "", False, "cdb2_run_statement_typed", "", "", "Argument[*1]", "sql-injection", "manual"]

‎cpp/ql/lib/ext/balber.model.yml‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
# Model of the BDE balber BER codec (BloombergLP::balber).
2+
# All overloads take the stream at argument 0 and the object at argument 1 and return int.
3+
extensions:
4+
- addsTo:
5+
pack: codeql/cpp-all
6+
extensible: summaryModel
7+
data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
8+
# Decoding: stream -> object
9+
- ["BloombergLP::balber", "BerDecoder", true, "decode", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
10+
- ["BloombergLP::balber", "BerDecoder", true, "decodeAny", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
11+
# Encoding: object -> stream
12+
- ["BloombergLP::balber", "BerEncoder", true, "encode", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
13+
- ["BloombergLP::balber", "BerEncoder", true, "encodeAny", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]

‎cpp/ql/lib/ext/baljsn.model.yml‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
# Model of the BDE baljsn JSON codec (BloombergLP::baljsn).
2+
# All overloads, including those taking DecoderOptions/EncoderOptions, take the stream at
3+
# argument 0 and the object at argument 1 and return int.
4+
extensions:
5+
- addsTo:
6+
pack: codeql/cpp-all
7+
extensible: summaryModel
8+
data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
9+
# Decoding: stream -> object
10+
- ["BloombergLP::baljsn", "Decoder", true, "decode", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
11+
- ["BloombergLP::baljsn", "Decoder", true, "decodeAny", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
12+
# Encoding: object -> stream
13+
- ["BloombergLP::baljsn", "Encoder", true, "encode", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
14+
- ["BloombergLP::baljsn", "Encoder", true, "encodeAny", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]

‎cpp/ql/lib/ext/balxml.model.yml‎

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
# Model of the BDE balxml XML codec (BloombergLP::balxml).
2+
# Rows name their overload where the overloads differ in argument layout. Not modelled:
3+
# decode(const char *filename, TYPE *), the two-step open() + decode(TYPE *) form, and the
4+
# Formatter overloads.
5+
extensions:
6+
- addsTo:
7+
pack: codeql/cpp-all
8+
extensible: summaryModel
9+
data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
10+
# Decoding: stream -> object; the istream overloads also return the stream
11+
- ["BloombergLP::balxml", "Decoder", true, "decode<TYPE>", "(istream &,TYPE *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
12+
- ["BloombergLP::balxml", "Decoder", true, "decode<TYPE>", "(istream &,TYPE *,const char *)", "", "Argument[*0]", "ReturnValue[*]", "taint", "manual"]
13+
- ["BloombergLP::balxml", "Decoder", true, "decode<TYPE>", "(streambuf *,TYPE *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
14+
- ["BloombergLP::balxml", "Decoder", true, "decode<TYPE>", "(const char *,size_t,TYPE *,const char *)", "", "Argument[*0]", "Argument[*2]", "taint", "manual"]
15+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny<TYPE>", "(istream &,TYPE *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
16+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny<TYPE>", "(istream &,TYPE *,const char *)", "", "Argument[*0]", "ReturnValue[*]", "taint", "manual"]
17+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny<TYPE>", "(streambuf *,TYPE *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
18+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny", "(istream &,AnyRef *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
19+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny", "(istream &,AnyRef *,const char *)", "", "Argument[*0]", "ReturnValue[*]", "taint", "manual"]
20+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny", "(streambuf *,AnyRef *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
21+
# Encoding: object -> stream; the ostream overloads also return the stream
22+
- ["BloombergLP::balxml", "Encoder", true, "encode<TYPE>", "(streambuf *,const TYPE &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
23+
- ["BloombergLP::balxml", "Encoder", true, "encode<TYPE>", "(ostream &,const TYPE &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
24+
- ["BloombergLP::balxml", "Encoder", true, "encode<TYPE>", "(ostream &,const TYPE &)", "", "Argument[*0..1]", "ReturnValue[*]", "taint", "manual"]
25+
- ["BloombergLP::balxml", "Encoder", true, "encodeToStream", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
26+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny<TYPE>", "(streambuf *,const TYPE &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
27+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny<TYPE>", "(ostream &,const TYPE &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
28+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny<TYPE>", "(ostream &,const TYPE &)", "", "Argument[*0..1]", "ReturnValue[*]", "taint", "manual"]
29+
- ["BloombergLP::balxml", "Encoder", true, "encodeAnyToStream", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
30+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny", "(streambuf *,const AnyConstRef &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
31+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny", "(ostream &,const AnyConstRef &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
32+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny", "(ostream &,const AnyConstRef &)", "", "Argument[*0..1]", "ReturnValue[*]", "taint", "manual"]

0 commit comments

Comments
 (0)