Sitelet https://web.archive.org/web/20260101090226/https://github.com/github/codeql/pull/6098
Skip to content

Conversation

@atorralba
Copy link
Contributor

@atorralba atorralba commented Jun 17, 2021 •

This PR adds an additional taint step between remote source Parameter types (e.g. parameters of a JAX-RS resource method) and field reads on said types (either directly or through getters).

Credits to @pwntester for the solution proposal.

@github-actions github-actions bot added the Java label Jun 17, 2021
@atorralba atorralba marked this pull request as ready for review June 17, 2021 14:50
@atorralba atorralba requested a review from a team as a code owner June 17, 2021 14:50
@atorralba atorralba requested a review from aschackmull July 21, 2021 09:48
Copy link
Contributor

@aschackmull aschackmull left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks reasonable, but adds quite a number of new steps, so we should check for performance impact.

@aschackmull
Copy link
Contributor

aschackmull commented Aug 4, 2021 •

@atorralba atorralba force-pushed the atorralba/entrypoint-field-steps branch from a58d4cc to 217d14f Compare October 18, 2021 15:16
@atorralba
Copy link
Contributor Author

Force-pushed to fix conflicts. @aschackmull did the performance evaluation work out?

@aschackmull
Copy link
Contributor

Looks like we need a rebase to enable a dca run.

@owen-mc owen-mc changed the title Preserve taint on field-read-steps on entrypoint types Java: Preserve taint on field-read-steps on entrypoint types Dec 7, 2021
@atorralba atorralba force-pushed the atorralba/entrypoint-field-steps branch 3 times, most recently from 3c45d9f to 27f4554 Compare December 9, 2021 10:24
@atorralba atorralba force-pushed the atorralba/entrypoint-field-steps branch from 27f4554 to c1e4c05 Compare December 15, 2021 12:08
@atorralba
Copy link
Contributor Author

DCA experiment looks good. I force-pushed to adapt the change note to the new format.

@atorralba atorralba merged commit 7e644d8 into github:main Dec 15, 2021
@atorralba atorralba deleted the atorralba/entrypoint-field-steps branch December 15, 2021 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants