cpp: model BDE bdlbb::Blob byte-buffer taint flow - #22455
Conversation
There was a problem hiding this comment.
Pull request overview
Adds BDE bdlbb::Blob taint-flow models for payload access and copying.
Changes:
- Models Blob and BlobBuffer accessors.
- Models BlobUtil copy operations.
- Adds external-model tests and release notes.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
cpp/ql/lib/ext/bdlbb.model.yml |
Defines flow summaries. |
cpp/ql/test/library-tests/dataflow/external-models/bdlbb.cpp |
Adds test stubs and cases. |
cpp/ql/test/library-tests/dataflow/external-models/flow.expected |
Updates expected flow results. |
cpp/ql/test/library-tests/dataflow/external-models/steps.expected |
Updates expected summary steps. |
cpp/ql/lib/change-notes/2026-08-27-bdlbb-blob-models.md |
Documents the analysis improvement. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance | ||
| # Accessor chain: a tainted blob taints its buffers, and a tainted buffer taints its bytes. | ||
| - ["BloombergLP::bdlbb", "Blob", true, "buffer", "", "", "Argument[-1]", "ReturnValue[*]", "taint", "manual"] | ||
| - ["BloombergLP::bdlbb", "BlobBuffer", true, "data", "", "", "Argument[-1]", "ReturnValue[*]", "taint", "manual"] |
There was a problem hiding this comment.
I think we at least want to add BlobBuffer::buffer() here. bsl::shared_ptr<char> seems out-of-scope.
jketema
left a comment
There was a problem hiding this comment.
Again only looked at this briefly.
Add flow summaries for the BDE segmented byte buffer BloombergLP::bdlbb::Blob so taint reaches a blob's payload bytes: - Accessor chain: Blob::buffer taints the returned BlobBuffer, and BlobBuffer::data/buffer taint the bytes. - bdlbb::BlobUtil::copy and getContiguousRangeOrCopy propagate taint between a blob and a flat buffer in both directions. This unblocks blob-carried sources such as bmqa::Message::getData, whose payload was previously stranded on the opaque Blob object. Not a duplicate; the bdlbb namespace had no coverage. Verified with a BloombergLP::bdlbb-shaped stub in the dataflow external-models harness.
420d1c1 to
8701ce9
Compare
jketema
left a comment
There was a problem hiding this comment.
I would again reduce the amount of comments. Otherwise this LGTM.
Address review feedback on the bdlbb::Blob models: - Add a summary for BlobBuffer::buffer(), which returns the bsl::shared_ptr<char> that owns the bytes. No shared_ptr rows are needed: SmartPointer.qll already covers bsl::shared_ptr::get(). - Add a harness case that reads through blob.buffer(0).buffer().get(). - Shorten the section comments in bdlbb.model.yml and the change note.
jketema
left a comment
There was a problem hiding this comment.
LGTM. I'm running some more (internal) testing before merging this.
|
I'm seeing the following test failure: |
|
Internal testing showed nothing out of the ordinary. So if you fix the test, then this can be merged. |
jketema
left a comment
There was a problem hiding this comment.
LGTM. Going to fix the broken test afterwards to just get this in. Thanks for the contribution!
Add flow summaries for the BDE segmented byte buffer BloombergLP::bdlbb::Blob so taint reaches a blob's payload bytes:
This unblocks blob-carried sources such as bmqa::Message::getData, whose payload was previously stranded on the opaque Blob object. Not a duplicate; the bdlbb namespace had no coverage. Verified with a BloombergLP::bdlbb-shaped stub in the dataflow external-models harness.