Skip to content

Commit 1dc8dbc

Browse files
authored
Merge pull request #22653 from owen-mc/go/mad/update-nhooyr-io-websocket
Go: Add new import path for `nhooyr.io/websocket`
2 parents e86d08b + 05ac22b commit 1dc8dbc

11 files changed

Lines changed: 187 additions & 64 deletions

File tree

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
---
2+
category: minorAnalysis
3+
---
4+
* Models for the `nhooyr.io/websocket` package have been updated to also support its new import path `github.com/coder/websocket`.
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
extensions:
2+
- addsTo:
3+
pack: codeql/go-all
4+
extensible: packageGrouping
5+
data:
6+
- ["coder/websocket", "github.com/coder/websocket"]
7+
- ["coder/websocket", "nhooyr.io/websocket"]
8+
- addsTo:
9+
pack: codeql/go-all
10+
extensible: sourceModel
11+
data:
12+
- ["group:coder/websocket", "Conn", True, "Read", "", "", "ReturnValue[1]", "remote", "manual"]
13+
- ["group:coder/websocket", "Conn", True, "Reader", "", "", "ReturnValue[1]", "remote", "manual"]

‎go/ql/lib/ext/nhooyr.io.websocket.model.yml‎

Lines changed: 0 additions & 7 deletions
This file was deleted.

‎go/ql/lib/semmle/go/frameworks/WebSocket.qll‎

Lines changed: 15 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -102,10 +102,10 @@ module WebSocketRequestCall {
102102
/**
103103
* A call to the `Dial` function of the `nhooyr.io/websocket` package.
104104
*/
105-
private class NhooyrWebSocketDialFunc extends Range {
106-
NhooyrWebSocketDialFunc() {
105+
private class CoderWebSocketDialFunc extends Range {
106+
CoderWebSocketDialFunc() {
107107
// func Dial(ctx context.Context, u string, opts *DialOptions) (*Conn, *http.Response, error)
108-
this.getTarget().hasQualifiedName(NhooyrWebSocket::packagePath(), "Dial")
108+
this.getTarget().hasQualifiedName(CoderWebSocket::packagePath(), "Dial")
109109
}
110110

111111
override DataFlow::Node getRequestUrl() { result = this.getArgument(1) }
@@ -188,10 +188,10 @@ module WebSocketReader {
188188
/**
189189
* The `Conn.Read` method of the `nhooyr.io/websocket` package.
190190
*/
191-
private class NhooyrWebSocketRead extends Range, Method {
192-
NhooyrWebSocketRead() {
191+
private class CoderWebSocketRead extends Range, Method {
192+
CoderWebSocketRead() {
193193
// func (c *Conn) Read(ctx context.Context) (MessageType, []byte, error)
194-
this.hasQualifiedName(NhooyrWebSocket::packagePath(), "Conn", "Read")
194+
this.hasQualifiedName(CoderWebSocket::packagePath(), "Conn", "Read")
195195
}
196196

197197
override FunctionOutput getAnOutput() { result.isResult(1) }
@@ -200,10 +200,10 @@ module WebSocketReader {
200200
/**
201201
* The `Conn.Reader` method of the `nhooyr.io/websocket` package.
202202
*/
203-
private class NhooyrWebSocketReader extends Range, Method {
204-
NhooyrWebSocketReader() {
203+
private class CoderWebSocketReader extends Range, Method {
204+
CoderWebSocketReader() {
205205
// func (c *Conn) Reader(ctx context.Context) (MessageType, io.Reader, error)
206-
this.hasQualifiedName(NhooyrWebSocket::packagePath(), "Conn", "Reader")
206+
this.hasQualifiedName(CoderWebSocket::packagePath(), "Conn", "Reader")
207207
}
208208

209209
override FunctionOutput getAnOutput() { result.isResult(1) }
@@ -313,12 +313,14 @@ module GolangOrgXNetWebsocket {
313313
}
314314

315315
/**
316-
* Provides classes for working with the [nhooyr.io/websocket](http://nhooyr.io/websocket)
316+
* Provides classes for working with the [coder/websocket](http://github.com/coder/websocket)
317317
* package.
318318
*/
319-
module NhooyrWebSocket {
320-
/** Gets the package name `nhooyr.io/websocket/`. */
321-
string packagePath() { result = package("nhooyr.io/websocket", "") }
319+
module CoderWebSocket {
320+
/** Gets the package name `github.com/coder/websocket` or `nhooyr.io/websocket`. */
321+
string packagePath() {
322+
result = package(["github.com/coder/websocket", "nhooyr.io/websocket"], "")
323+
}
322324
}
323325

324326
/**

‎go/ql/test/query-tests/Security/CWE-079/CONSISTENCY/DataFlowConsistency.expected‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,4 +18,4 @@ reverseRead
1818
| tst.go:33:15:33:15 | implicit-deref r | Origin of readStep is missing a PostUpdateNode. |
1919
| tst.go:48:14:48:14 | implicit-deref r | Origin of readStep is missing a PostUpdateNode. |
2020
| tst.go:66:15:66:15 | implicit-deref r | Origin of readStep is missing a PostUpdateNode. |
21-
| websocketXss.go:26:9:26:9 | implicit-deref r | Origin of readStep is missing a PostUpdateNode. |
21+
| websocketXss.go:27:9:27:9 | implicit-deref r | Origin of readStep is missing a PostUpdateNode. |

‎go/ql/test/query-tests/Security/CWE-079/ReflectedXss.expected‎

Lines changed: 47 additions & 43 deletions
Large diffs are not rendered by default.

‎go/ql/test/query-tests/Security/CWE-079/go.mod‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@ module codeql-go-tests/CWE-079
33
go 1.24
44

55
require (
6+
github.com/coder/websocket v1.8.5
67
github.com/gobwas/ws v1.0.3
78
github.com/gorilla/websocket v1.4.2
89
golang.org/x/net v0.0.0-20200505041828-1ed23360d12c

‎go/ql/test/query-tests/Security/CWE-079/vendor/github.com/coder/websocket/LICENSE‎

Lines changed: 21 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎go/ql/test/query-tests/Security/CWE-079/vendor/github.com/coder/websocket/stub.go‎

Lines changed: 76 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎go/ql/test/query-tests/Security/CWE-079/vendor/modules.txt‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,6 @@
1+
# github.com/coder/websocket v1.8.5
2+
## explicit
3+
github.com/coder/websocket
14
# github.com/gobwas/ws v1.0.3
25
## explicit
36
github.com/gobwas/ws

0 commit comments

Comments
 (0)