Commit 5f0d283
committed
Merge remote-tracking branch 'upstream/master' into dataflow-indirect-args
The conflicts came from how `this` is now a parameter but not a
`Parameter` on `master`.
Conflicts:
cpp/ql/src/semmle/code/cpp/ir/dataflow/internal/DataFlowUtil.qll
cpp/ql/test/library-tests/dataflow/DefaultTaintTracking/defaulttainttracking.cpp
cpp/ql/test/library-tests/dataflow/DefaultTaintTracking/tainted.expected
cpp/ql/test/library-tests/dataflow/DefaultTaintTracking/test_diff.expected
cpp/ql/test/library-tests/dataflow/dataflow-tests/dataflow-ir-consistency.expected
cpp/ql/test/library-tests/dataflow/fields/ir-flow.expected
cpp/ql/test/library-tests/syntax-zoo/dataflow-ir-consistency.expected803 files changed
Lines changed: 25363 additions & 13582 deletions
File tree
- .devcontainer
- change-notes/1.25
- cpp
- ql
- src
- Likely Bugs/Underspecified Functions
- Metrics/History
- experimental/semmle/code/cpp/rangeanalysis
- external
- tests
- filters
- semmle/code/cpp
- commons/unix
- controlflow
- dataflow/internal
- tainttracking1
- tainttracking2
- exprs
- ir
- dataflow
- internal
- tainttracking1
- tainttracking2
- implementation
- aliased_ssa
- internal
- internal
- raw
- internal
- unaliased_ssa
- internal
- internal
- models
- implementations
- interfaces
- rangeanalysis
- security
- test
- examples/expressions
- experimental/library-tests/rangeanalysis
- arraylengthanalysis
- inboundsptr
- header-variant-tests/deduplication
- library-tests
- allocators
- blocks/cpp
- builtins
- edg
- type_traits
- classes/variadic
- conditions
- controlflow
- guards-ir
- primitives
- conversions
- dataflow
- DefaultTaintTracking
- dataflow-tests
- fields
- partialdefinitions
- taint-tests
- defuse
- functions/functions
- ir
- constant_func
- escape
- ir
- ssa
- lambdas/captures
- literals/uuidof
- range_based_for
- sideEffects/exprs
- static_cast
- synchronization
- syntax-zoo
- templates
- instantiations_functions
- isfromtemplateinstantiation
- typename
- usings
- valuenumbering
- GlobalValueNumbering
- HashCons
- query-tests/Security/CWE/CWE-190/semmle
- TaintedAllocationSize
- extreme
- upgrades/2074f1cc7a3659ad555465a8025a8f2b7687896b
- csharp
- extractor/Semmle.Extraction.CSharp/Entities/Expressions
- ql
- src
- API Abuse
- experimental/CWE-099
- semmle/code/csharp
- controlflow
- dataflow
- flowsources
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- exprs
- frameworks
- ir
- implementation
- internal
- raw
- internal
- common
- desugar
- internal
- unaliased_ssa
- internal
- internal
- rangeanalysis
- test
- library-tests
- controlflow/graph
- csharp6
- dataflow/types
- ir/ir
- overrides
- standalone/controlflow
- unification
- query-tests/API Abuse
- FormatInvalid
- FormatMissingArgument
- FormatUnusedArgument
- docs/language
- learn-ql
- java
- writing-queries
- ql-spec
- ql-training/java
- support
- javascript
- extractor
- lib/typescript
- src/com/semmle/js/parser
- ql
- src
- AngularJS
- DOM
- Declarations
- Expressions
- JSDoc
- LanguageFeatures
- NodeJS
- Security
- CWE-020
- CWE-078
- examples
- CWE-079/examples
- CWE-089/examples
- CWE-116
- examples
- CWE-134/examples
- CWE-327/examples
- CWE-352/examples
- CWE-400
- CWE-502/examples
- CWE-601/examples
- CWE-611/examples
- CWE-776/examples
- CWE-798/examples
- CWE-843/examples
- CWE-916/examples
- CWE-918/examples
- Statements
- external
- semmle/javascript
- dataflow
- internal
- explore
- frameworks
- heuristics
- security/dataflow
- test
- library-tests
- AMD
- DataFlow
- DefUse
- Flow
- GlobalAccessPaths
- InterProceduralFlow
- LocalObjects
- ModuleImportNodes
- Modules
- NodeJS
- PackageExports
- lib1
- sublib
- Promises
- PropWrite
- TaintBarriers
- TaintTracking
- TypeScript
- CallResolution
- CallSignatureTypes
- frameworks
- AngularJS/scopes
- Electron
- Express
- src
- NodeJSLib
- SQL
- connect
- fastify
- src
- hapi
- koa
- restify
- query-tests
- Declarations/UnusedProperty
- Security
- CWE-020
- CWE-022/ZipSlip
- CWE-078
- lib
- subLib
- CWE-079
- CWE-089/untyped
- CWE-094/CodeInjection
- CWE-116/IncompleteSanitization
- CWE-338
- CWE-400
- PrototypePollutionUtility
- CWE-601/ClientSideUrlRedirect
- Statements/UselessConditional
- java/ql
- src
- experimental
- CWE-532
- CWE-939
- Security/CWE
- CWE-016
- CWE-074
- semmle/code/java/frameworks
- spring
- semmle/code
- java
- controlflow/internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- dispatch
- xml
- test
- experimental
- query-tests/security
- CWE-016
- CWE-074
- stubs
- shiro-core-1.5.2/org/apache/shiro/jndi
- spring-ldap-2.3.2/org/springframework/ldap
- core
- filter
- query
- support
- springframework-5.2.3/org/springframework
- beans/factory
- boot/actuate/autoconfigure/security/servlet
- jndi
- web/bind/annotation
- library-tests
- dataflow/switchexpr
- ssa
- query-tests
- Nullness
- RangeAnalysis
- python/ql
- examples/snippets
- src
- Classes
- Functions
- Security
- CWE-022
- CWE-312
- CWE-798
- Variables
- semmle/python
- dataflow
- objects
- security
- injection
- strings
- types
- web
- bottle
- cherrypy
- django
- falcon
- flask
- pyramid
- stdlib
- tornado
- turbogears
- twisted
- webob
- xml
- test
- 3
- library-tests/taint/unpacking
- query-tests/Classes/equals-attr
- library-tests
- PointsTo/calls
- examples/custom-sanitizer
- taint
- collections
- config
- example
- extensions
- flowpath_regression
- general
- namedtuple
- strings
- unpacking
- web
- flask
- stdlib
- query-tests
- Classes/equals-hash
- Functions/general
- Security/CWE-327
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | | - | |
| 3 | + | |
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
21 | 24 | | |
22 | 25 | | |
23 | 26 | | |
24 | | - | |
| 27 | + | |
25 | 28 | | |
26 | 29 | | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
27 | 53 | | |
28 | 54 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
6 | 10 | | |
7 | 11 | | |
8 | 12 | | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
9 | 28 | | |
10 | 29 | | |
11 | 30 | | |
12 | 31 | | |
13 | 32 | | |
14 | 33 | | |
15 | 34 | | |
| 35 | + | |
| 36 | + | |
16 | 37 | | |
17 | 38 | | |
18 | 39 | | |
19 | 40 | | |
20 | 41 | | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
21 | 47 | | |
22 | | - | |
| 48 | + | |
23 | 49 | | |
24 | | - | |
25 | | - | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
26 | 77 | | |
27 | 78 | | |
28 | 79 | | |
| 80 | + | |
29 | 81 | | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
Lines changed: 27 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
10 | 23 | | |
11 | 24 | | |
12 | | - | |
| 25 | + | |
13 | 26 | | |
14 | 27 | | |
15 | 28 | | |
16 | | - | |
| 29 | + | |
17 | 30 | | |
18 | 31 | | |
19 | 32 | | |
20 | 33 | | |
21 | 34 | | |
22 | 35 | | |
| 36 | + | |
23 | 37 | | |
24 | 38 | | |
25 | 39 | | |
26 | 40 | | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
27 | 44 | | |
28 | 45 | | |
29 | | - | |
30 | | - | |
31 | | - | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
32 | 53 | | |
33 | 54 | | |
34 | 55 | | |
This file was deleted.
This file was deleted.
This file was deleted.
0 commit comments