Skip to content

Go: model maps package (skipping functions that involve iterating over a function) - #22722

Closed
owen-mc wants to merge 1 commit into
mainfrom
go/mad/model-maps-package
Closed

owen-mc wants to merge 1 commit into
mainfrom
go/mad/model-maps-package

Conversation

@owen-mc

@owen-mc owen-mc commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Follows the pattern established in #18108 (which modeled the slices package) to add value-flow models for the Go standard library maps package.

Summary

Adds a MaD (models-as-data) summary model for maps in go/ql/lib/ext/maps.model.yml, covering the functions that do not involve the iter package (which CodeQL cannot yet model):

  • Clone — Argument[0].MapKey/MapValue → ReturnValue.MapKey/MapValue (value flow)
  • Copy — Argument[1].MapKey/MapValue (src) → Argument[0].MapKey/MapValue (dst) (value flow)

The remaining functions are intentionally left unmodeled, with comments explaining why:

  • All, Collect, Insert, Keys, Values — involve iter.Seq/iter.Seq2; should be modeled once iterator modeling is supported.
  • DeleteFunc — only removes entries in place and returns nothing, so no new flow path is introduced.
  • Equal, EqualFunc — return a bool, so there is no value flow to model.

Testing

Added go/ql/test/library-tests/semmle/go/frameworks/StdlibTaintFlow/Maps.go with taint-flow tests for Clone and Copy, covering both map keys and map values, following the same RunAllTaints_* pattern used for slices in Slices.go.

Also added a change note under go/ql/src/change-notes/.

…ver a function)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 12:11
@owen-mc
owen-mc requested a review from a team as a code owner October 1, 2026 12:11

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The models follow existing conventions and are covered by focused flow tests.

Review effort: Balanced
Findings: None

What changed in this PR

Adds Go standard-library value-flow models for maps, following the established slices modeling pattern.

Changes:

  • Models key and value flow through maps.Clone and maps.Copy.
  • Documents intentionally unsupported APIs.
  • Adds taint-flow coverage and a change note.
File Description
go/​ql/​lib/​ext/​maps.model.yml Defines maps summary models.
go/​ql/​test/​library-tests/​semmle/​go/​frameworks/​StdlibTaintFlow/​Maps.go Tests key and value propagation.
go/​ql/​src/​change-notes/​2026-10-01-model-maps-package.md Announces the new models.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

⚠️ The head of this PR and the base branch were compared for differences in the framework coverage reports. The generated reports are available in the artifacts of this workflow run. The differences will be picked up by the nightly job after the PR gets merged.

Click to show differences in coverage

go

Generated file changes for go

  • Changes to framework-coverage-go.rst:
-    `Standard library <https://pkg.go.dev/std>`_,"````, ``archive/*``, ``bufio``, ``bytes``, ``cmp``, ``compress/*``, ``container/*``, ``context``, ``crypto``, ``crypto/*``, ``database/*``, ``debug/*``, ``embed``, ``encoding``, ``encoding/*``, ``errors``, ``expvar``, ``flag``, ``fmt``, ``go/*``, ``hash``, ``hash/*``, ``html``, ``html/*``, ``image``, ``image/*``, ``index/*``, ``io``, ``io/*``, ``log``, ``log/*``, ``maps``, ``math``, ``math/*``, ``mime``, ``mime/*``, ``net``, ``net/*``, ``os``, ``os/*``, ``path``, ``path/*``, ``plugin``, ``reflect``, ``reflect/*``, ``regexp``, ``regexp/*``, ``slices``, ``sort``, ``strconv``, ``strings``, ``sync``, ``sync/*``, ``syscall``, ``syscall/*``, ``testing``, ``testing/*``, ``text/*``, ``time``, ``time/*``, ``unicode``, ``unicode/*``, ``unsafe``, ``weak``",52,674,127
+    `Standard library <https://pkg.go.dev/std>`_,"````, ``archive/*``, ``bufio``, ``bytes``, ``cmp``, ``compress/*``, ``container/*``, ``context``, ``crypto``, ``crypto/*``, ``database/*``, ``debug/*``, ``embed``, ``encoding``, ``encoding/*``, ``errors``, ``expvar``, ``flag``, ``fmt``, ``go/*``, ``hash``, ``hash/*``, ``html``, ``html/*``, ``image``, ``image/*``, ``index/*``, ``io``, ``io/*``, ``log``, ``log/*``, ``maps``, ``math``, ``math/*``, ``mime``, ``mime/*``, ``net``, ``net/*``, ``os``, ``os/*``, ``path``, ``path/*``, ``plugin``, ``reflect``, ``reflect/*``, ``regexp``, ``regexp/*``, ``slices``, ``sort``, ``strconv``, ``strings``, ``sync``, ``sync/*``, ``syscall``, ``syscall/*``, ``testing``, ``testing/*``, ``text/*``, ``time``, ``time/*``, ``unicode``, ``unicode/*``, ``unsafe``, ``weak``",52,678,127
-    Totals,,690,1134,1580
+    Totals,,690,1138,1580
  • Changes to framework-coverage-go.csv:
+ maps,,,4,,,,,,,,,,,,,,,,,,,,,,,,4

@owen-mc
owen-mc requested a review from a team October 1, 2026 18:35
@owen-mc

owen-mc commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Duplicate of #22709

@owen-mc owen-mc marked this as a duplicate of #22709 Oct 1, 2026
@owen-mc owen-mc closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants