Skip to content

Commit f3e6b44

Browse files
committed
unified: Handle explicit .init at call site
1 parent abacde2 commit f3e6b44

3 files changed

Lines changed: 13 additions & 5 deletions

File tree

‎unified/ql/lib/codeql/unified/internal/mad/LegacyMaD.qll‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -77,7 +77,11 @@ private predicate methodCallSelector(CallExpr call, string name, string argLabel
7777

7878
pragma[nomagic]
7979
private predicate constructorCallSelector(CallExpr call, string name, string argLabels) {
80-
name = getQualifiedNameFromExpr(call.getCallee()) and
80+
(
81+
if call.getCallee().(MemberAccessExpr).getMemberName() = "init"
82+
then name = getQualifiedNameFromExpr(call.getCallee().(MemberAccessExpr).getBase())
83+
else name = getQualifiedNameFromExpr(call.getCallee())
84+
) and
8185
argLabels = getArgLabelsFromCall(call)
8286
}
8387

‎unified/ql/test/library-tests/mad/test.expected‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -7,15 +7,19 @@ isSink
77
| test.swift:23:20:23:25 | string | regex-use |
88
| test.swift:24:20:24:25 | string | regex-use |
99
| test.swift:71:37:71:49 | encodedOffset | string-length |
10+
| test.swift:72:42:72:54 | encodedOffset | string-length |
1011
| test.swift:76:24:76:36 | encryptionKey | encryption-key |
1112
| test.swift:77:18:77:24 | fileURL | path-injection |
13+
| test.swift:88:24:88:36 | encryptionKey | encryption-key |
14+
| test.swift:89:18:89:24 | fileURL | path-injection |
1215
| test.swift:100:24:100:36 | encryptionKey | encryption-key |
1316
| test.swift:101:18:101:24 | fileURL | path-injection |
1417
| test.swift:107:23:107:34 | seedFilePath | path-injection |
1518
isSource
1619
| test.swift:4:5:4:27 | String(...) | remote |
1720
| test.swift:5:5:5:44 | String(...) | remote |
1821
| test.swift:6:5:6:48 | String(...) | remote |
22+
| test.swift:7:5:7:32 | ... .init(...) | remote |
1923
| test.swift:9:5:9:34 | String(...) | local |
2024
| test.swift:10:5:12:24 | String(...) | local |
2125
| test.swift:13:5:15:28 | String(...) | local |

‎unified/ql/test/library-tests/mad/test.swift‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ func test(url: URL, string: String) {
44
String(contentsOf: url) // $ isSource=remote
55
String(contentsOf: url, encoding: .utf8) // $ isSource=remote
66
String(contentsOf: url, usedEncoding: .utf8) // $ isSource=remote
7-
String.init(contentsOf: url) // $ MISSING: isSource=remote
7+
String.init(contentsOf: url) // $ isSource=remote
88

99
String(contentsOfFile: string) // $ isSource=local isSink=path-injection
1010
String(
@@ -69,7 +69,7 @@ func testQualifiedConstructors(
6969
seedFilePath: String
7070
) {
7171
_ = String.Index(encodedOffset: encodedOffset) // $ isSink=string-length
72-
_ = String.Index.init(encodedOffset: encodedOffset) // $ MISSING: isSink=string-length
72+
_ = String.Index.init(encodedOffset: encodedOffset) // $ isSink=string-length
7373

7474
_ = Realm.Configuration(
7575
deleteRealmIfMigrationNeeded: false,
@@ -85,8 +85,8 @@ func testQualifiedConstructors(
8585

8686
_ = Realm.Configuration.init(
8787
deleteRealmIfMigrationNeeded: false,
88-
encryptionKey: encryptionKey, // $ MISSING: isSink=encryption-key
89-
fileURL: fileURL, // $ MISSING: isSink=path-injection
88+
encryptionKey: encryptionKey, // $ isSink=encryption-key
89+
fileURL: fileURL, // $ isSink=path-injection
9090
inMemoryIdentifier: nil,
9191
migrationBlock: nil,
9292
objectTypes: nil,

0 commit comments

Comments
 (0)