Skip to content

Commit 327133b

Browse files
committed
C++: Model BDE bal codec taint flow
Add flow summaries for the balber, baljsn and balxml codecs. decode and decodeAny move taint from the stream into the decoded object; encode and encodeAny move it from the object into the stream. balber and baljsn have a uniform argument layout across overloads and return an int status, so their rows carry no signature. balxml overloads differ in layout and two of them return the stream they were given, so each balxml row names its overload and the istream/ostream forms also get ReturnValue[*] rows. Not modelled: balxml::Decoder::decode(const char *filename, TYPE *), the two-step open() + decode(TYPE *) form, and the Formatter overloads of balxml::Encoder.
1 parent 401a516 commit 327133b

8 files changed

Lines changed: 1273 additions & 70 deletions

File tree

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,4 @@
1+
---
2+
category: minorAnalysis
3+
---
4+
* Added flow summaries for the BDE codecs `BloombergLP::balber::BerDecoder`/`BerEncoder`, `BloombergLP::baljsn::Decoder`/`Encoder` and `BloombergLP::balxml::Decoder`/`Encoder`.

‎cpp/ql/lib/ext/balber.model.yml‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
# Model of the BDE balber BER (X.690) codec (BloombergLP::balber).
2+
# Decoding moves taint from the byte stream into the decoded object; encoding moves it from
3+
# the object into the byte stream. Every overload of these members takes the stream at
4+
# argument 0 and the object at argument 1 and returns an int status, so the rows need no
5+
# signature and there are no fluent ReturnValue rows.
6+
extensions:
7+
- addsTo:
8+
pack: codeql/cpp-all
9+
extensible: summaryModel
10+
data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
11+
- ["BloombergLP::balber", "BerDecoder", true, "decode", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
12+
- ["BloombergLP::balber", "BerDecoder", true, "decodeAny", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
13+
- ["BloombergLP::balber", "BerEncoder", true, "encode", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
14+
- ["BloombergLP::balber", "BerEncoder", true, "encodeAny", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]

‎cpp/ql/lib/ext/baljsn.model.yml‎

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# Model of the BDE baljsn JSON codec (BloombergLP::baljsn).
2+
# Decoding moves taint from the byte stream into the decoded object; encoding moves it from
3+
# the object into the byte stream. Every overload of these members, including the ones that
4+
# take a trailing DecoderOptions/EncoderOptions, has the stream at argument 0 and the object
5+
# at argument 1 and returns an int status, so the rows need no signature and there are no
6+
# fluent ReturnValue rows.
7+
extensions:
8+
- addsTo:
9+
pack: codeql/cpp-all
10+
extensible: summaryModel
11+
data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
12+
- ["BloombergLP::baljsn", "Decoder", true, "decode", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
13+
- ["BloombergLP::baljsn", "Decoder", true, "decodeAny", "", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
14+
- ["BloombergLP::baljsn", "Encoder", true, "encode", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
15+
- ["BloombergLP::baljsn", "Encoder", true, "encodeAny", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]

‎cpp/ql/lib/ext/balxml.model.yml‎

Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
# Model of the BDE balxml XML codec (BloombergLP::balxml).
2+
# Decoding moves taint from the byte stream into the decoded object; encoding moves it from
3+
# the object into the byte stream. Unlike balber and baljsn, the overloads here differ in
4+
# argument layout, so every row names its overload. The istream/ostream overloads of
5+
# decode/decodeAny/encode/encodeAny return the stream they were given, which is modelled
6+
# with ReturnValue[*] rows.
7+
#
8+
# Not modelled: decode(const char *filename, TYPE *) (its input is a path, not data);
9+
# the two-step open(...) followed by decode(TYPE *) / decodeAny(TYPE *) form, which would
10+
# require stashing taint on the decoder; and the encode/encodeAny(Formatter &, ...) overloads.
11+
extensions:
12+
- addsTo:
13+
pack: codeql/cpp-all
14+
extensible: summaryModel
15+
data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
16+
# Decoder: stream -> object
17+
- ["BloombergLP::balxml", "Decoder", true, "decode<TYPE>", "(istream &,TYPE *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
18+
- ["BloombergLP::balxml", "Decoder", true, "decode<TYPE>", "(istream &,TYPE *,const char *)", "", "Argument[*0]", "ReturnValue[*]", "taint", "manual"]
19+
- ["BloombergLP::balxml", "Decoder", true, "decode<TYPE>", "(streambuf *,TYPE *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
20+
- ["BloombergLP::balxml", "Decoder", true, "decode<TYPE>", "(const char *,size_t,TYPE *,const char *)", "", "Argument[*0]", "Argument[*2]", "taint", "manual"]
21+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny<TYPE>", "(istream &,TYPE *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
22+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny<TYPE>", "(istream &,TYPE *,const char *)", "", "Argument[*0]", "ReturnValue[*]", "taint", "manual"]
23+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny<TYPE>", "(streambuf *,TYPE *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
24+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny", "(istream &,AnyRef *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
25+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny", "(istream &,AnyRef *,const char *)", "", "Argument[*0]", "ReturnValue[*]", "taint", "manual"]
26+
- ["BloombergLP::balxml", "Decoder", true, "decodeAny", "(streambuf *,AnyRef *,const char *)", "", "Argument[*0]", "Argument[*1]", "taint", "manual"]
27+
# Encoder: object -> stream
28+
- ["BloombergLP::balxml", "Encoder", true, "encode<TYPE>", "(streambuf *,const TYPE &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
29+
- ["BloombergLP::balxml", "Encoder", true, "encode<TYPE>", "(ostream &,const TYPE &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
30+
- ["BloombergLP::balxml", "Encoder", true, "encode<TYPE>", "(ostream &,const TYPE &)", "", "Argument[*0..1]", "ReturnValue[*]", "taint", "manual"]
31+
- ["BloombergLP::balxml", "Encoder", true, "encodeToStream<TYPE>", "(ostream &,const TYPE &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
32+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny<TYPE>", "(streambuf *,const TYPE &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
33+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny<TYPE>", "(ostream &,const TYPE &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
34+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny<TYPE>", "(ostream &,const TYPE &)", "", "Argument[*0..1]", "ReturnValue[*]", "taint", "manual"]
35+
- ["BloombergLP::balxml", "Encoder", true, "encodeAnyToStream<TYPE>", "(ostream &,const TYPE &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
36+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny", "(streambuf *,const AnyConstRef &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
37+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny", "(ostream &,const AnyConstRef &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]
38+
- ["BloombergLP::balxml", "Encoder", true, "encodeAny", "(ostream &,const AnyConstRef &)", "", "Argument[*0..1]", "ReturnValue[*]", "taint", "manual"]
39+
- ["BloombergLP::balxml", "Encoder", true, "encodeAnyToStream", "(ostream &,const AnyConstRef &)", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]

0 commit comments

Comments
 (0)