Sitelet https://web.archive.org/web/20260605070903/https://github.com/github/codeql/pull/12539
Skip to content

Java/C#: Re-factor model generator taint tracking configurations to use the new API#12539

Merged
michaelnebel merged 4 commits into
github:mainfrom
michaelnebel:modelgenerator/configuration
Mar 23, 2023
Merged

Java/C#: Re-factor model generator taint tracking configurations to use the new API#12539
michaelnebel merged 4 commits into
github:mainfrom
michaelnebel:modelgenerator/configuration

Conversation

@michaelnebel
Copy link
Copy Markdown
Contributor

No description provided.

@michaelnebel michaelnebel force-pushed the modelgenerator/configuration branch from 06ad562 to f08280e Compare March 16, 2023 13:26
@michaelnebel michaelnebel changed the title Modelgenerator/configuration Java/C#: Re-factor model generator taint tracking configurations to use the new API Mar 17, 2023
@michaelnebel michaelnebel force-pushed the modelgenerator/configuration branch from f08280e to 9e772aa Compare March 17, 2023 09:30
@michaelnebel michaelnebel force-pushed the modelgenerator/configuration branch from 9e772aa to 8816c54 Compare March 17, 2023 09:51
@michaelnebel michaelnebel marked this pull request as ready for review March 17, 2023 12:09
@michaelnebel michaelnebel requested review from a team as code owners March 17, 2023 12:09
@michaelnebel michaelnebel added the no-change-note-required This PR does not need a change note label Mar 17, 2023
@michaelnebel
Copy link
Copy Markdown
Contributor Author

michaelnebel commented Mar 20, 2023 •

A couple of remarks for DCA.
The appears to be an increase in cache size around 10%.
Also there is a performance regression (around 5% for C# - a bit more for Java, but that could be variance as the queries are executed on a small project).

For C# DCA reports a minor discrepancy between the generated models.
AFAIK after the new API was introduced some results could be missing when using the "old" taint tracking configuration.
Manually inspecting the reported difference in summaries supports this. The .NET runtime models have not been updated since the new API was introduced and most of the models reported as a difference was generated before the introduction of the new API (they have disappeared, but now they are back again).
However, there are a couple of extra models being generated, but they look sound:

System.Reflection.Emit;EnumBuilder;false;get_AssemblyQualifiedName;();;Argument[this];ReturnValue;taint;generated
System.Reflection.Emit;EnumBuilder;false;get_FullName;();;Argument[this];ReturnValue;taint;generated
System.Reflection.Emit;TypeBuilder;false;ToString;();;Argument[this];ReturnValue;taint;generated
System.Reflection.Emit;TypeBuilder;false;get_AssemblyQualifiedName;();;Argument[this];ReturnValue;taint;generated
System.Reflection.Emit;TypeBuilder;false;get_FullName;();;Argument[this];ReturnValue;taint;generated

@michaelnebel michaelnebel force-pushed the modelgenerator/configuration branch from 8816c54 to 643f929 Compare March 21, 2023 10:27
Comment thread java/ql/src/utils/modelgenerator/internal/CaptureModels.qll Fixed
Comment thread java/ql/src/utils/modelgenerator/internal/CaptureModels.qll Fixed
Comment thread csharp/ql/src/utils/modelgenerator/internal/CaptureModels.qll Fixed
Comment thread csharp/ql/src/utils/modelgenerator/internal/CaptureModels.qll Fixed
Comment thread csharp/ql/src/utils/modelgenerator/internal/CaptureModels.qll Fixed
Comment thread java/ql/src/utils/modelgenerator/internal/CaptureModels.qll Fixed
@michaelnebel michaelnebel force-pushed the modelgenerator/configuration branch from 1618e3c to 06af32b Compare March 22, 2023 09:06
Comment thread csharp/ql/src/utils/modelgenerator/internal/CaptureSummaryFlowQuery.qll Outdated
Comment thread csharp/ql/src/utils/modelgenerator/internal/CaptureSinkModelsQuery.qll Outdated
Comment thread java/ql/src/utils/modelgenerator/internal/CaptureSinkModelsQuery.qll Outdated
@michaelnebel michaelnebel force-pushed the modelgenerator/configuration branch from 06af32b to d258a1c Compare March 23, 2023 09:27
@michaelnebel
Copy link
Copy Markdown
Contributor Author

DCA looks similar to the first execution.
Merging.

@michaelnebel michaelnebel merged commit 79cd761 into github:main Mar 23, 2023
@michaelnebel michaelnebel deleted the modelgenerator/configuration branch March 23, 2023 11:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

C# Java no-change-note-required This PR does not need a change note

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants