From 31378970c2d5b87e9ed048e2a0839b31f89ded65 Mon Sep 17 00:00:00 2001 From: Asger F Date: Fri, 2 Oct 2026 11:29:22 +0200 Subject: [PATCH 01/11] unified: Add test showing spurious SSA flow --- .../ql/test/library-tests/dataflow/test.expected | 16 ++++++++++++++++ .../ql/test/library-tests/dataflow/test.swift | 9 +++++++++ 2 files changed, 25 insertions(+) diff --git a/unified/ql/test/library-tests/dataflow/test.expected b/unified/ql/test/library-tests/dataflow/test.expected index 7ae6ed5e6691..9ec3c9eb2890 100644 --- a/unified/ql/test/library-tests/dataflow/test.expected +++ b/unified/ql/test/library-tests/dataflow/test.expected @@ -178,6 +178,12 @@ edges | test.swift:175:25:175:39 | source(...) | test.swift:175:15:175:39 | ... + ... | provenance | | | test.swift:175:42:175:66 | ... + ... | test.swift:175:14:175:67 | TupleExpr [1] | provenance | | | test.swift:175:52:175:66 | source(...) | test.swift:175:42:175:66 | ... + ... | provenance | | +| test.swift:182:9:182:9 | x | test.swift:185:10:185:10 | x | provenance | | +| test.swift:182:9:182:9 | x | test.swift:186:10:186:10 | y | provenance | | +| test.swift:182:13:182:27 | source(...) | test.swift:182:9:182:9 | x | provenance | | +| test.swift:183:9:183:9 | y | test.swift:185:10:185:10 | x | provenance | | +| test.swift:183:9:183:9 | y | test.swift:186:10:186:10 | y | provenance | | +| test.swift:183:13:183:27 | source(...) | test.swift:183:9:183:9 | y | provenance | | nodes | calls.swift:7:19:7:19 | x | semmle.label | x | | calls.swift:8:14:8:14 | x | semmle.label | x | @@ -407,6 +413,12 @@ nodes | test.swift:175:52:175:66 | source(...) | semmle.label | source(...) | | test.swift:176:10:176:10 | a | semmle.label | a | | test.swift:177:10:177:10 | b | semmle.label | b | +| test.swift:182:9:182:9 | x | semmle.label | x | +| test.swift:182:13:182:27 | source(...) | semmle.label | source(...) | +| test.swift:183:9:183:9 | y | semmle.label | y | +| test.swift:183:13:183:27 | source(...) | semmle.label | source(...) | +| test.swift:185:10:185:10 | x | semmle.label | x | +| test.swift:186:10:186:10 | y | semmle.label | y | subpaths | calls.swift:31:17:31:30 | source(...) | calls.swift:28:19:28:19 | x | calls.swift:29:16:29:24 | ... + ... | calls.swift:31:10:31:31 | target(...) | | calls.swift:32:17:32:30 | source(...) | calls.swift:28:19:28:19 | x | calls.swift:29:16:29:24 | ... + ... | calls.swift:32:10:32:31 | target(...) | @@ -476,3 +488,7 @@ testFailures | test.swift:168:10:168:12 | ... .0 | test.swift:167:29:167:43 | source(...) | test.swift:168:10:168:12 | ... .0 | $@ | test.swift:167:29:167:43 | source(...) | source(...) | | test.swift:176:10:176:10 | a | test.swift:175:25:175:39 | source(...) | test.swift:176:10:176:10 | a | $@ | test.swift:175:25:175:39 | source(...) | source(...) | | test.swift:177:10:177:10 | b | test.swift:175:52:175:66 | source(...) | test.swift:177:10:177:10 | b | $@ | test.swift:175:52:175:66 | source(...) | source(...) | +| test.swift:185:10:185:10 | x | test.swift:182:13:182:27 | source(...) | test.swift:185:10:185:10 | x | $@ | test.swift:182:13:182:27 | source(...) | source(...) | +| test.swift:185:10:185:10 | x | test.swift:183:13:183:27 | source(...) | test.swift:185:10:185:10 | x | $@ | test.swift:183:13:183:27 | source(...) | source(...) | +| test.swift:186:10:186:10 | y | test.swift:182:13:182:27 | source(...) | test.swift:186:10:186:10 | y | $@ | test.swift:182:13:182:27 | source(...) | source(...) | +| test.swift:186:10:186:10 | y | test.swift:183:13:183:27 | source(...) | test.swift:186:10:186:10 | y | $@ | test.swift:183:13:183:27 | source(...) | source(...) | diff --git a/unified/ql/test/library-tests/dataflow/test.swift b/unified/ql/test/library-tests/dataflow/test.swift index a7fa42ee6100..36c3babdf8de 100644 --- a/unified/ql/test/library-tests/dataflow/test.swift +++ b/unified/ql/test/library-tests/dataflow/test.swift @@ -176,3 +176,12 @@ func t19() { sink(a) // $ hasTaintFlow=t19.1 sink(b) // $ hasTaintFlow=t19.2 } + +func t20() { + func foo(x: String, y: String) -> String { return x } + var x = source("t20.1") + var y = source("t20.2") + foo(x: x, y: y) + sink(x) // $ hasValueFlow=t20.1 SPURIOUS: hasValueFlow=t20.2 + sink(y) // $ hasValueFlow=t20.2 SPURIOUS: hasValueFlow=t20.1 +} From f906f8dc55fd7509092e5b042a20efac07871c40 Mon Sep 17 00:00:00 2001 From: Asger F Date: Fri, 2 Oct 2026 11:51:36 +0200 Subject: [PATCH 02/11] Ssa: Add consistency check for ambiguous read --- shared/ssa/codeql/ssa/Ssa.qll | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/shared/ssa/codeql/ssa/Ssa.qll b/shared/ssa/codeql/ssa/Ssa.qll index a0c295c5d27d..151728da5466 100644 --- a/shared/ssa/codeql/ssa/Ssa.qll +++ b/shared/ssa/codeql/ssa/Ssa.qll @@ -2144,6 +2144,17 @@ module Make< ) } } + + /** Provides consistency checks that depend on the DataFlowIntegration inputs. */ + module DfConsistency { + /** + * The given `read` reads multiple variables at once. `var` is bound to one of them. + */ + query predicate ambiguousReadNode(ReadNode read, SourceVariable var) { + strictcount(SourceVariable v | read.readsAt(_, _, v)) > 1 and + read.readsAt(_, _, var) + } + } } /** From 9d8f5e615a2583bd28f753affb10242c45267e36 Mon Sep 17 00:00:00 2001 From: Asger F Date: Fri, 2 Oct 2026 11:59:58 +0200 Subject: [PATCH 03/11] unified: Add consistency check --- .../LocalSsaConsistency.ql | 1 + .../CONSISTENCY/LocalSsaConsistency.expected | 25 ++ .../CONSISTENCY/LocalSsaConsistency.expected | 5 + .../CONSISTENCY/LocalSsaConsistency.expected | 0 .../CONSISTENCY/LocalSsaConsistency.expected | 5 + .../CONSISTENCY/LocalSsaConsistency.expected | 18 + .../CONSISTENCY/LocalSsaConsistency.expected | 41 +++ .../CONSISTENCY/LocalSsaConsistency.expected | 347 ++++++++++++++++++ 8 files changed, 442 insertions(+) create mode 100644 unified/ql/test/library-tests/BasicTest/CONSISTENCY/LocalSsaConsistency.expected create mode 100644 unified/ql/test/library-tests/constructors/CONSISTENCY/LocalSsaConsistency.expected create mode 100644 unified/ql/test/library-tests/controlflow/CONSISTENCY/LocalSsaConsistency.expected create mode 100644 unified/ql/test/library-tests/dataflow/CONSISTENCY/LocalSsaConsistency.expected create mode 100644 unified/ql/test/library-tests/mad/CONSISTENCY/LocalSsaConsistency.expected create mode 100644 unified/ql/test/library-tests/type-inference/CONSISTENCY/LocalSsaConsistency.expected create mode 100644 unified/ql/test/query-tests/security/CWE-022/PathInjection/CONSISTENCY/LocalSsaConsistency.expected diff --git a/unified/ql/consistency-queries/LocalSsaConsistency.ql b/unified/ql/consistency-queries/LocalSsaConsistency.ql index 209adfca340a..ca0d9550ad20 100644 --- a/unified/ql/consistency-queries/LocalSsaConsistency.ql +++ b/unified/ql/consistency-queries/LocalSsaConsistency.ql @@ -1,3 +1,4 @@ private import unified private import codeql.unified.internal.dataflow.LocalSsa import LocalSsaOutput::Consistency +import LocalSsaDataFlowOutput::DfConsistency diff --git a/unified/ql/test/library-tests/BasicTest/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/BasicTest/CONSISTENCY/LocalSsaConsistency.expected new file mode 100644 index 000000000000..32f5189788a0 --- /dev/null +++ b/unified/ql/test/library-tests/BasicTest/CONSISTENCY/LocalSsaConsistency.expected @@ -0,0 +1,25 @@ +ambiguousReadNode +| test.swift:8:9:8:26 | [variable post-update] item | test.swift:7:5:9:5 | self | +| test.swift:8:9:8:26 | [variable post-update] item | test.swift:7:25:7:28 | item | +| test.swift:8:9:8:26 | [variable post-update] self | test.swift:7:5:9:5 | self | +| test.swift:8:9:8:26 | [variable post-update] self | test.swift:7:25:7:28 | item | +| test.swift:12:16:12:35 | [variable post-update] item | test.swift:11:5:13:5 | self | +| test.swift:12:16:12:35 | [variable post-update] item | test.swift:11:21:11:24 | item | +| test.swift:12:16:12:35 | [variable post-update] self | test.swift:11:5:13:5 | self | +| test.swift:12:16:12:35 | [variable post-update] self | test.swift:11:21:11:24 | item | +| test.swift:27:13:27:33 | [variable post-update] item | test.swift:25:9:25:14 | result | +| test.swift:27:13:27:33 | [variable post-update] item | test.swift:26:9:26:12 | item | +| test.swift:27:13:27:33 | [variable post-update] result | test.swift:25:9:25:14 | result | +| test.swift:27:13:27:33 | [variable post-update] result | test.swift:26:9:26:12 | item | +| test.swift:28:13:28:31 | [variable post-update] item | test.swift:25:9:25:14 | result | +| test.swift:28:13:28:31 | [variable post-update] item | test.swift:26:9:26:12 | item | +| test.swift:28:13:28:31 | [variable post-update] result | test.swift:25:9:25:14 | result | +| test.swift:28:13:28:31 | [variable post-update] result | test.swift:26:9:26:12 | item | +| test.swift:49:16:49:26 | [variable post-update] index | test.swift:47:5:50:5 | self | +| test.swift:49:16:49:26 | [variable post-update] index | test.swift:47:18:47:22 | index | +| test.swift:49:16:49:26 | [variable post-update] self | test.swift:47:5:50:5 | self | +| test.swift:49:16:49:26 | [variable post-update] self | test.swift:47:18:47:22 | index | +| test.swift:53:9:53:25 | [variable post-update] item | test.swift:52:5:54:5 | self | +| test.swift:53:9:53:25 | [variable post-update] item | test.swift:52:16:52:19 | item | +| test.swift:53:9:53:25 | [variable post-update] self | test.swift:52:5:54:5 | self | +| test.swift:53:9:53:25 | [variable post-update] self | test.swift:52:16:52:19 | item | diff --git a/unified/ql/test/library-tests/constructors/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/constructors/CONSISTENCY/LocalSsaConsistency.expected new file mode 100644 index 000000000000..bbb75f55a047 --- /dev/null +++ b/unified/ql/test/library-tests/constructors/CONSISTENCY/LocalSsaConsistency.expected @@ -0,0 +1,5 @@ +ambiguousReadNode +| constructors.swift:35:9:35:29 | [variable post-update] self | constructors.swift:34:5:36:5 | self | +| constructors.swift:35:9:35:29 | [variable post-update] self | constructors.swift:34:22:34:22 | x | +| constructors.swift:35:9:35:29 | [variable post-update] x | constructors.swift:34:5:36:5 | self | +| constructors.swift:35:9:35:29 | [variable post-update] x | constructors.swift:34:22:34:22 | x | diff --git a/unified/ql/test/library-tests/controlflow/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/controlflow/CONSISTENCY/LocalSsaConsistency.expected new file mode 100644 index 000000000000..e69de29bb2d1 diff --git a/unified/ql/test/library-tests/dataflow/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/dataflow/CONSISTENCY/LocalSsaConsistency.expected new file mode 100644 index 000000000000..cc9c71d9b150 --- /dev/null +++ b/unified/ql/test/library-tests/dataflow/CONSISTENCY/LocalSsaConsistency.expected @@ -0,0 +1,5 @@ +ambiguousReadNode +| test.swift:184:5:184:19 | [variable post-update] x | test.swift:182:9:182:9 | x | +| test.swift:184:5:184:19 | [variable post-update] x | test.swift:183:9:183:9 | y | +| test.swift:184:5:184:19 | [variable post-update] y | test.swift:182:9:182:9 | x | +| test.swift:184:5:184:19 | [variable post-update] y | test.swift:183:9:183:9 | y | diff --git a/unified/ql/test/library-tests/mad/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/mad/CONSISTENCY/LocalSsaConsistency.expected new file mode 100644 index 000000000000..6a0d83888e90 --- /dev/null +++ b/unified/ql/test/library-tests/mad/CONSISTENCY/LocalSsaConsistency.expected @@ -0,0 +1,18 @@ +ambiguousReadNode +| test.swift:74:9:84:31 | [variable post-update] encryptionKey | test.swift:67:5:67:17 | encryptionKey | +| test.swift:74:9:84:31 | [variable post-update] encryptionKey | test.swift:68:5:68:11 | fileURL | +| test.swift:74:9:84:31 | [variable post-update] fileURL | test.swift:67:5:67:17 | encryptionKey | +| test.swift:74:9:84:31 | [variable post-update] fileURL | test.swift:68:5:68:11 | fileURL | +| test.swift:86:9:96:31 | [variable post-update] encryptionKey | test.swift:67:5:67:17 | encryptionKey | +| test.swift:86:9:96:31 | [variable post-update] encryptionKey | test.swift:68:5:68:11 | fileURL | +| test.swift:86:9:96:31 | [variable post-update] fileURL | test.swift:67:5:67:17 | encryptionKey | +| test.swift:86:9:96:31 | [variable post-update] fileURL | test.swift:68:5:68:11 | fileURL | +| test.swift:98:9:109:31 | [variable post-update] encryptionKey | test.swift:67:5:67:17 | encryptionKey | +| test.swift:98:9:109:31 | [variable post-update] encryptionKey | test.swift:68:5:68:11 | fileURL | +| test.swift:98:9:109:31 | [variable post-update] encryptionKey | test.swift:69:5:69:16 | seedFilePath | +| test.swift:98:9:109:31 | [variable post-update] fileURL | test.swift:67:5:67:17 | encryptionKey | +| test.swift:98:9:109:31 | [variable post-update] fileURL | test.swift:68:5:68:11 | fileURL | +| test.swift:98:9:109:31 | [variable post-update] fileURL | test.swift:69:5:69:16 | seedFilePath | +| test.swift:98:9:109:31 | [variable post-update] seedFilePath | test.swift:67:5:67:17 | encryptionKey | +| test.swift:98:9:109:31 | [variable post-update] seedFilePath | test.swift:68:5:68:11 | fileURL | +| test.swift:98:9:109:31 | [variable post-update] seedFilePath | test.swift:69:5:69:16 | seedFilePath | diff --git a/unified/ql/test/library-tests/type-inference/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/type-inference/CONSISTENCY/LocalSsaConsistency.expected new file mode 100644 index 000000000000..b48e15341459 --- /dev/null +++ b/unified/ql/test/library-tests/type-inference/CONSISTENCY/LocalSsaConsistency.expected @@ -0,0 +1,41 @@ +ambiguousReadNode +| closures.swift:47:9:47:21 | [variable post-update] self | closures.swift:45:5:49:5 | self | +| closures.swift:47:9:47:21 | [variable post-update] self | closures.swift:45:24:45:28 | value | +| closures.swift:47:9:47:21 | [variable post-update] value | closures.swift:45:5:49:5 | self | +| closures.swift:47:9:47:21 | [variable post-update] value | closures.swift:45:24:45:28 | value | +| closures.swift:48:16:48:29 | [variable post-update] self | closures.swift:45:5:49:5 | self | +| closures.swift:48:16:48:29 | [variable post-update] self | closures.swift:45:24:45:28 | value | +| closures.swift:48:16:48:29 | [variable post-update] value | closures.swift:45:5:49:5 | self | +| closures.swift:48:16:48:29 | [variable post-update] value | closures.swift:45:24:45:28 | value | +| generics.swift:156:5:156:22 | [variable post-update] v1 | generics.swift:155:10:155:11 | v1 | +| generics.swift:156:5:156:22 | [variable post-update] v1 | generics.swift:155:20:155:21 | v2 | +| generics.swift:156:5:156:22 | [variable post-update] v2 | generics.swift:155:10:155:11 | v1 | +| generics.swift:156:5:156:22 | [variable post-update] v2 | generics.swift:155:20:155:21 | v2 | +| key_paths.swift:44:14:44:35 | [variable post-update] e | key_paths.swift:42:7:42:7 | s | +| key_paths.swift:44:14:44:35 | [variable post-update] e | key_paths.swift:43:7:43:7 | e | +| key_paths.swift:44:14:44:35 | [variable post-update] s | key_paths.swift:42:7:42:7 | s | +| key_paths.swift:44:14:44:35 | [variable post-update] s | key_paths.swift:43:7:43:7 | e | +| key_paths.swift:142:18:142:45 | [variable post-update] kpStart | key_paths.swift:140:7:140:13 | kpStart | +| key_paths.swift:142:18:142:45 | [variable post-update] kpStart | key_paths.swift:141:7:141:9 | kpX | +| key_paths.swift:142:18:142:45 | [variable post-update] kpX | key_paths.swift:140:7:140:13 | kpStart | +| key_paths.swift:142:18:142:45 | [variable post-update] kpX | key_paths.swift:141:7:141:9 | kpX | +| key_paths.swift:146:14:146:35 | [variable post-update] e | key_paths.swift:144:7:144:7 | s | +| key_paths.swift:146:14:146:35 | [variable post-update] e | key_paths.swift:145:7:145:7 | e | +| key_paths.swift:146:14:146:35 | [variable post-update] s | key_paths.swift:144:7:144:7 | s | +| key_paths.swift:146:14:146:35 | [variable post-update] s | key_paths.swift:145:7:145:7 | e | +| overload_resolution.swift:371:5:371:34 | [variable post-update] name | overload_resolution.swift:370:3:372:3 | self | +| overload_resolution.swift:371:5:371:34 | [variable post-update] name | overload_resolution.swift:370:20:370:23 | name | +| overload_resolution.swift:371:5:371:34 | [variable post-update] self | overload_resolution.swift:370:3:372:3 | self | +| overload_resolution.swift:371:5:371:34 | [variable post-update] self | overload_resolution.swift:370:20:370:23 | name | +| overload_resolution.swift:375:5:375:42 | [variable post-update] self | overload_resolution.swift:374:3:376:3 | self | +| overload_resolution.swift:375:5:375:42 | [variable post-update] self | overload_resolution.swift:374:20:374:23 | size | +| overload_resolution.swift:375:5:375:42 | [variable post-update] size | overload_resolution.swift:374:3:376:3 | self | +| overload_resolution.swift:375:5:375:42 | [variable post-update] size | overload_resolution.swift:374:20:374:23 | size | +| overload_resolution.swift:415:12:415:22 | [variable post-update] index | overload_resolution.swift:414:3:416:3 | self | +| overload_resolution.swift:415:12:415:22 | [variable post-update] index | overload_resolution.swift:414:14:414:18 | index | +| overload_resolution.swift:415:12:415:22 | [variable post-update] self | overload_resolution.swift:414:3:416:3 | self | +| overload_resolution.swift:415:12:415:22 | [variable post-update] self | overload_resolution.swift:414:14:414:18 | index | +| overload_resolution.swift:419:12:419:20 | [variable post-update] key | overload_resolution.swift:418:3:420:3 | self | +| overload_resolution.swift:419:12:419:20 | [variable post-update] key | overload_resolution.swift:418:14:418:16 | key | +| overload_resolution.swift:419:12:419:20 | [variable post-update] self | overload_resolution.swift:418:3:420:3 | self | +| overload_resolution.swift:419:12:419:20 | [variable post-update] self | overload_resolution.swift:418:14:418:16 | key | diff --git a/unified/ql/test/query-tests/security/CWE-022/PathInjection/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/query-tests/security/CWE-022/PathInjection/CONSISTENCY/LocalSsaConsistency.expected new file mode 100644 index 000000000000..173907e3ef5a --- /dev/null +++ b/unified/ql/test/query-tests/security/CWE-022/PathInjection/CONSISTENCY/LocalSsaConsistency.expected @@ -0,0 +1,347 @@ +ambiguousReadNode +| testPathInjection.swift:43:9:43:23 | [variable post-update] data | testPathInjection.swift:41:5:44:5 | self | +| testPathInjection.swift:43:9:43:23 | [variable post-update] data | testPathInjection.swift:42:13:42:16 | data | +| testPathInjection.swift:43:9:43:23 | [variable post-update] self | testPathInjection.swift:41:5:44:5 | self | +| testPathInjection.swift:43:9:43:23 | [variable post-update] self | testPathInjection.swift:42:13:42:16 | data | +| testPathInjection.swift:244:9:244:49 | [variable post-update] ascending | testPathInjection.swift:243:5:245:5 | self | +| testPathInjection.swift:244:9:244:49 | [variable post-update] ascending | testPathInjection.swift:243:66:243:74 | ascending | +| testPathInjection.swift:244:9:244:49 | [variable post-update] self | testPathInjection.swift:243:5:245:5 | self | +| testPathInjection.swift:244:9:244:49 | [variable post-update] self | testPathInjection.swift:243:66:243:74 | ascending | +| testPathInjection.swift:349:13:349:58 | [variable post-update] nsData | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:349:13:349:58 | [variable post-update] nsData | testPathInjection.swift:348:9:348:14 | nsData | +| testPathInjection.swift:349:13:349:58 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:349:13:349:58 | [variable post-update] remoteUrl | testPathInjection.swift:348:9:348:14 | nsData | +| testPathInjection.swift:350:5:350:44 | [variable post-update] nsData | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:350:5:350:44 | [variable post-update] nsData | testPathInjection.swift:348:9:348:14 | nsData | +| testPathInjection.swift:350:5:350:44 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:350:5:350:44 | [variable post-update] remoteUrl | testPathInjection.swift:348:9:348:14 | nsData | +| testPathInjection.swift:351:13:351:65 | [variable post-update] nsData | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:351:13:351:65 | [variable post-update] nsData | testPathInjection.swift:348:9:348:14 | nsData | +| testPathInjection.swift:351:13:351:65 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:351:13:351:65 | [variable post-update] remoteString | testPathInjection.swift:348:9:348:14 | nsData | +| testPathInjection.swift:352:5:352:51 | [variable post-update] nsData | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:352:5:352:51 | [variable post-update] nsData | testPathInjection.swift:348:9:348:14 | nsData | +| testPathInjection.swift:352:5:352:51 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:352:5:352:51 | [variable post-update] remoteString | testPathInjection.swift:348:9:348:14 | nsData | +| testPathInjection.swift:355:13:355:94 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:355:13:355:94 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:355:13:355:94 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:355:13:355:94 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:356:13:356:56 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:356:13:356:56 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:356:13:356:56 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:356:13:356:56 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:357:13:358:86 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:357:13:358:86 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:357:13:358:86 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:357:13:358:86 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:359:13:359:47 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:359:13:359:47 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:359:13:359:47 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:359:13:359:47 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:360:13:360:56 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:360:13:360:56 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:360:13:360:56 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:360:13:360:56 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:361:13:361:45 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:361:13:361:45 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:361:13:361:45 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:361:13:361:45 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:362:5:362:90 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:362:5:362:90 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:362:5:362:90 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:362:5:362:90 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:363:13:363:69 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:363:13:363:69 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:363:13:363:69 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:363:13:363:69 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:364:13:364:79 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:364:13:364:79 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:364:13:364:79 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:364:13:364:79 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:365:5:365:32 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:365:5:365:32 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:365:5:365:32 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:365:5:365:32 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:366:5:366:39 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:366:5:366:39 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:366:5:366:39 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:366:5:366:39 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:367:5:367:94 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:367:5:367:94 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:367:5:367:94 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:367:5:367:94 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:368:13:368:94 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:368:13:368:94 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:368:13:368:94 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:368:13:368:94 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:368:13:368:94 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:368:13:368:94 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:368:13:368:94 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:368:13:368:94 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:368:13:368:94 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:369:13:369:94 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:369:13:369:94 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:369:13:369:94 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:369:13:369:94 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:369:13:369:94 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:369:13:369:94 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:369:13:369:94 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:369:13:369:94 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:369:13:369:94 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:370:5:372:70 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:370:5:372:70 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:370:5:372:70 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:370:5:372:70 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:370:5:372:70 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:370:5:372:70 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:370:5:372:70 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:370:5:372:70 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:370:5:372:70 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:373:5:375:70 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:373:5:375:70 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:373:5:375:70 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:373:5:375:70 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:373:5:375:70 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:373:5:375:70 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:373:5:375:70 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:373:5:375:70 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:373:5:375:70 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:376:5:376:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:376:5:376:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:376:5:376:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:376:5:376:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:376:5:376:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:376:5:376:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:376:5:376:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:376:5:376:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:376:5:376:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:377:5:377:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:377:5:377:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:377:5:377:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:377:5:377:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:377:5:377:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:377:5:377:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:377:5:377:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:377:5:377:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:377:5:377:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:378:5:378:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:378:5:378:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:378:5:378:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:378:5:378:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:379:5:379:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:379:5:379:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:379:5:379:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:379:5:379:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:380:5:380:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:380:5:380:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:380:5:380:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:380:5:380:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:380:5:380:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:380:5:380:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:380:5:380:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:380:5:380:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:380:5:380:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:381:5:381:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:381:5:381:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:381:5:381:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:381:5:381:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:381:5:381:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:381:5:381:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:381:5:381:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:381:5:381:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:381:5:381:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:382:5:382:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:382:5:382:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:382:5:382:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:382:5:382:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:383:5:383:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:383:5:383:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:383:5:383:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:383:5:383:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:384:5:384:69 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:384:5:384:69 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:384:5:384:69 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:384:5:384:69 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:384:5:384:69 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:384:5:384:69 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:384:5:384:69 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:384:5:384:69 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:384:5:384:69 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:385:5:385:69 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:385:5:385:69 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:385:5:385:69 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:385:5:385:69 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:385:5:385:69 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:385:5:385:69 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:385:5:385:69 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:385:5:385:69 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:385:5:385:69 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:386:5:386:72 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:386:5:386:72 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:386:5:386:72 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:386:5:386:72 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:387:5:387:72 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:387:5:387:72 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:387:5:387:72 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:387:5:387:72 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:388:5:388:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:388:5:388:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:388:5:388:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:388:5:388:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:388:5:388:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:388:5:388:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:388:5:388:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:388:5:388:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:388:5:388:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:389:5:389:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:389:5:389:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:389:5:389:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:389:5:389:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:389:5:389:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:389:5:389:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:389:5:389:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:389:5:389:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | +| testPathInjection.swift:389:5:389:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:390:5:390:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:390:5:390:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:390:5:390:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:390:5:390:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:391:5:391:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:391:5:391:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:391:5:391:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:391:5:391:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:392:13:392:62 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:392:13:392:62 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:392:13:392:62 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:392:13:392:62 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:393:13:393:47 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:393:13:393:47 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:393:13:393:47 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:393:13:393:47 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:394:13:395:94 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:394:13:395:94 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:394:13:395:94 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:394:13:395:94 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:396:5:396:53 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:396:5:396:53 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:396:5:396:53 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:396:5:396:53 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:397:13:397:45 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:397:13:397:45 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:397:13:397:45 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:397:13:397:45 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:398:13:398:63 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:398:13:398:63 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:398:13:398:63 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:398:13:398:63 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:399:13:399:63 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:399:13:399:63 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:399:13:399:63 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:399:13:399:63 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:400:13:400:55 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:400:13:400:55 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:400:13:400:55 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:400:13:400:55 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:401:13:401:85 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:401:13:401:85 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:401:13:401:85 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | +| testPathInjection.swift:401:13:401:85 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:403:13:403:62 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:403:13:403:62 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:403:13:403:62 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:403:13:403:62 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:404:13:404:54 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:404:13:404:54 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:404:13:404:54 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:404:13:404:54 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:405:13:405:69 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:405:13:405:69 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:405:13:405:69 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:405:13:405:69 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:406:13:406:72 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:406:13:406:72 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:406:13:406:72 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:406:13:406:72 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:407:13:407:72 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:407:13:407:72 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:407:13:407:72 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:407:13:407:72 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:408:13:408:62 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:408:13:408:62 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:408:13:408:62 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | +| testPathInjection.swift:408:13:408:62 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:409:13:410:97 | [variable post-update] fm | testPathInjection.swift:342:9:342:19 | remoteNsUrl | +| testPathInjection.swift:409:13:410:97 | [variable post-update] fm | testPathInjection.swift:344:9:344:17 | safeNsUrl | +| testPathInjection.swift:409:13:410:97 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:409:13:410:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:342:9:342:19 | remoteNsUrl | +| testPathInjection.swift:409:13:410:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:344:9:344:17 | safeNsUrl | +| testPathInjection.swift:409:13:410:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:409:13:410:97 | [variable post-update] safeNsUrl | testPathInjection.swift:342:9:342:19 | remoteNsUrl | +| testPathInjection.swift:409:13:410:97 | [variable post-update] safeNsUrl | testPathInjection.swift:344:9:344:17 | safeNsUrl | +| testPathInjection.swift:409:13:410:97 | [variable post-update] safeNsUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:411:13:412:97 | [variable post-update] fm | testPathInjection.swift:342:9:342:19 | remoteNsUrl | +| testPathInjection.swift:411:13:412:97 | [variable post-update] fm | testPathInjection.swift:344:9:344:17 | safeNsUrl | +| testPathInjection.swift:411:13:412:97 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:411:13:412:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:342:9:342:19 | remoteNsUrl | +| testPathInjection.swift:411:13:412:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:344:9:344:17 | safeNsUrl | +| testPathInjection.swift:411:13:412:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:411:13:412:97 | [variable post-update] safeNsUrl | testPathInjection.swift:342:9:342:19 | remoteNsUrl | +| testPathInjection.swift:411:13:412:97 | [variable post-update] safeNsUrl | testPathInjection.swift:344:9:344:17 | safeNsUrl | +| testPathInjection.swift:411:13:412:97 | [variable post-update] safeNsUrl | testPathInjection.swift:354:9:354:10 | fm | +| testPathInjection.swift:478:5:478:60 | [variable post-update] buffer1 | testPathInjection.swift:339:11:339:17 | buffer1 | +| testPathInjection.swift:478:5:478:60 | [variable post-update] buffer1 | testPathInjection.swift:476:9:476:17 | localData | +| testPathInjection.swift:478:5:478:60 | [variable post-update] localData | testPathInjection.swift:339:11:339:17 | buffer1 | +| testPathInjection.swift:478:5:478:60 | [variable post-update] localData | testPathInjection.swift:339:11:339:17 | buffer1 | +| testPathInjection.swift:478:5:478:60 | [variable post-update] localData | testPathInjection.swift:476:9:476:17 | localData | +| testPathInjection.swift:478:5:478:60 | [variable post-update] localData | testPathInjection.swift:476:9:476:17 | localData | +| testPathInjection.swift:479:5:479:62 | [variable post-update] buffer2 | testPathInjection.swift:339:49:339:55 | buffer2 | +| testPathInjection.swift:479:5:479:62 | [variable post-update] buffer2 | testPathInjection.swift:477:9:477:18 | remoteData | +| testPathInjection.swift:479:5:479:62 | [variable post-update] remoteData | testPathInjection.swift:339:49:339:55 | buffer2 | +| testPathInjection.swift:479:5:479:62 | [variable post-update] remoteData | testPathInjection.swift:339:49:339:55 | buffer2 | +| testPathInjection.swift:479:5:479:62 | [variable post-update] remoteData | testPathInjection.swift:477:9:477:18 | remoteData | +| testPathInjection.swift:479:5:479:62 | [variable post-update] remoteData | testPathInjection.swift:477:9:477:18 | remoteData | +| testPathInjection.swift:510:17:510:49 | [variable post-update] fm | testPathInjection.swift:504:9:504:20 | remoteString | +| testPathInjection.swift:510:17:510:49 | [variable post-update] fm | testPathInjection.swift:506:9:506:10 | fm | +| testPathInjection.swift:510:17:510:49 | [variable post-update] remoteString | testPathInjection.swift:504:9:504:20 | remoteString | +| testPathInjection.swift:510:17:510:49 | [variable post-update] remoteString | testPathInjection.swift:506:9:506:10 | fm | +| testPathInjection.swift:512:13:512:45 | [variable post-update] fm | testPathInjection.swift:504:9:504:20 | remoteString | +| testPathInjection.swift:512:13:512:45 | [variable post-update] fm | testPathInjection.swift:506:9:506:10 | fm | +| testPathInjection.swift:512:13:512:45 | [variable post-update] remoteString | testPathInjection.swift:504:9:504:20 | remoteString | +| testPathInjection.swift:512:13:512:45 | [variable post-update] remoteString | testPathInjection.swift:506:9:506:10 | fm | +| testPathInjection.swift:524:28:524:66 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:524:28:524:66 | [variable post-update] remoteString | testPathInjection.swift:521:9:521:10 | u1 | +| testPathInjection.swift:524:28:524:66 | [variable post-update] u1 | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:524:28:524:66 | [variable post-update] u1 | testPathInjection.swift:521:9:521:10 | u1 | +| testPathInjection.swift:525:28:525:66 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:525:28:525:66 | [variable post-update] remoteString | testPathInjection.swift:521:9:521:10 | u1 | +| testPathInjection.swift:525:28:525:66 | [variable post-update] u1 | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:525:28:525:66 | [variable post-update] u1 | testPathInjection.swift:521:9:521:10 | u1 | +| testPathInjection.swift:526:5:526:40 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:526:5:526:40 | [variable post-update] remoteString | testPathInjection.swift:521:9:521:10 | u1 | +| testPathInjection.swift:526:5:526:40 | [variable post-update] u1 | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:526:5:526:40 | [variable post-update] u1 | testPathInjection.swift:521:9:521:10 | u1 | +| testPathInjection.swift:535:24:535:62 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:535:24:535:62 | [variable post-update] remoteString | testPathInjection.swift:532:9:532:10 | u3 | +| testPathInjection.swift:535:24:535:62 | [variable post-update] u3 | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:535:24:535:62 | [variable post-update] u3 | testPathInjection.swift:532:9:532:10 | u3 | +| testPathInjection.swift:554:9:555:75 | [variable post-update] remoteString | testPathInjection.swift:517:5:517:6 | s3 | +| testPathInjection.swift:554:9:555:75 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:554:9:555:75 | [variable post-update] s3 | testPathInjection.swift:517:5:517:6 | s3 | +| testPathInjection.swift:554:9:555:75 | [variable post-update] s3 | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:559:9:559:67 | [variable post-update] fm | testPathInjection.swift:517:39:517:40 | fm | +| testPathInjection.swift:559:9:559:67 | [variable post-update] fm | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:559:9:559:67 | [variable post-update] remoteString | testPathInjection.swift:517:39:517:40 | fm | +| testPathInjection.swift:559:9:559:67 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:560:13:560:53 | [variable post-update] fm | testPathInjection.swift:517:39:517:40 | fm | +| testPathInjection.swift:560:13:560:53 | [variable post-update] fm | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:560:13:560:53 | [variable post-update] remoteString | testPathInjection.swift:517:39:517:40 | fm | +| testPathInjection.swift:560:13:560:53 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | +| testPathInjection.swift:587:5:587:41 | [variable post-update] mc | testPathInjection.swift:580:9:580:20 | remoteString | +| testPathInjection.swift:587:5:587:41 | [variable post-update] mc | testPathInjection.swift:586:9:586:10 | mc | +| testPathInjection.swift:587:5:587:41 | [variable post-update] remoteString | testPathInjection.swift:580:9:580:20 | remoteString | +| testPathInjection.swift:587:5:587:41 | [variable post-update] remoteString | testPathInjection.swift:586:9:586:10 | mc | +| testPathInjection.swift:588:5:588:34 | [variable post-update] mc | testPathInjection.swift:580:9:580:20 | remoteString | +| testPathInjection.swift:588:5:588:34 | [variable post-update] mc | testPathInjection.swift:586:9:586:10 | mc | +| testPathInjection.swift:588:5:588:34 | [variable post-update] remoteString | testPathInjection.swift:580:9:580:20 | remoteString | +| testPathInjection.swift:588:5:588:34 | [variable post-update] remoteString | testPathInjection.swift:586:9:586:10 | mc | From b1b2b2008c61872085b2bf1a7e760e557cb94adc Mon Sep 17 00:00:00 2001 From: Asger F Date: Fri, 2 Oct 2026 13:08:04 +0200 Subject: [PATCH 04/11] ssa: Expose new consistency check from VariableCapture.qll --- csharp/ql/consistency-queries/SsaConsistency.ql | 1 + java/ql/consistency-queries/SsaConsistency.ql | 1 + ruby/ql/consistency-queries/SsaConsistency.ql | 1 + rust/ql/consistency-queries/SsaConsistency.ql | 1 + shared/dataflow/codeql/dataflow/VariableCapture.qll | 2 ++ 5 files changed, 6 insertions(+) diff --git a/csharp/ql/consistency-queries/SsaConsistency.ql b/csharp/ql/consistency-queries/SsaConsistency.ql index 6b3f4510e487..152258220a7f 100644 --- a/csharp/ql/consistency-queries/SsaConsistency.ql +++ b/csharp/ql/consistency-queries/SsaConsistency.ql @@ -1,6 +1,7 @@ import csharp import semmle.code.csharp.dataflow.internal.SsaImpl as Impl import Impl::Consistency +import Impl::DataFlowIntegration::DfConsistency import Ssa query predicate localDeclWithSsaDef(LocalVariableDeclExpr d) { diff --git a/java/ql/consistency-queries/SsaConsistency.ql b/java/ql/consistency-queries/SsaConsistency.ql index b62db63ac5ba..2ea5604d5b7e 100644 --- a/java/ql/consistency-queries/SsaConsistency.ql +++ b/java/ql/consistency-queries/SsaConsistency.ql @@ -1,3 +1,4 @@ import java import semmle.code.java.dataflow.internal.SsaImpl import Impl::Consistency +import DataFlowIntegration::DfConsistency diff --git a/ruby/ql/consistency-queries/SsaConsistency.ql b/ruby/ql/consistency-queries/SsaConsistency.ql index 235eac263442..a0f1cb23cfef 100644 --- a/ruby/ql/consistency-queries/SsaConsistency.ql +++ b/ruby/ql/consistency-queries/SsaConsistency.ql @@ -1,3 +1,4 @@ import codeql.ruby.dataflow.SSA import codeql.ruby.dataflow.internal.SsaImpl import Consistency +import DataFlowIntegration::DfConsistency diff --git a/rust/ql/consistency-queries/SsaConsistency.ql b/rust/ql/consistency-queries/SsaConsistency.ql index 1774f269749c..4cbce78c5207 100644 --- a/rust/ql/consistency-queries/SsaConsistency.ql +++ b/rust/ql/consistency-queries/SsaConsistency.ql @@ -8,3 +8,4 @@ import codeql.rust.dataflow.Ssa import codeql.rust.dataflow.internal.SsaImpl import Consistency +import DataFlowIntegration::DfConsistency diff --git a/shared/dataflow/codeql/dataflow/VariableCapture.qll b/shared/dataflow/codeql/dataflow/VariableCapture.qll index 0ba44be5ea1f..ab798b02cf2d 100644 --- a/shared/dataflow/codeql/dataflow/VariableCapture.qll +++ b/shared/dataflow/codeql/dataflow/VariableCapture.qll @@ -389,6 +389,8 @@ module Flow< msg = "Callable has multiple locations" and 2 <= strictcount(c.getLocation()) } + import SsaFlow::DfConsistency + query predicate consistencyOverview(string msg, int n) { uniqueToString(msg, n) or n = strictcount(BasicBlock bb | uniqueEnclosingCallable(bb, msg)) or From b2f9e09f2cd9e320bbf43454aea4883ad8ea2567 Mon Sep 17 00:00:00 2001 From: Asger F Date: Fri, 2 Oct 2026 15:35:03 +0200 Subject: [PATCH 05/11] ssa: Record ambiguousReadNode errors from VariableCapture These consistency violations originate from the VariableCapture instantation in C#, JS, Python, and Ruby. --- .../VariableCaptureConsistency.expected | 39 +++++++++ .../VariableCaptureConsistency.expected | 17 ++++ .../VariableCaptureConsistency.expected | 23 +++++ .../VariableCaptureConsistency.expected | 5 ++ .../VariableCaptureConsistency.expected | 3 + .../VariableCaptureConsistency.expected | 9 ++ .../FlowSummary/CaptureConsistency.expected | 1 + .../dataflow-capture-consistency.expected | 29 +++++++ .../CONSISTENCY/VariablesConsistency.expected | 27 ++++++ .../CONSISTENCY/VariablesConsistency.expected | 11 +++ .../CONSISTENCY/VariablesConsistency.expected | 15 ++++ .../CONSISTENCY/VariablesConsistency.expected | 3 + .../CONSISTENCY/VariablesConsistency.expected | 5 ++ .../CONSISTENCY/VariablesConsistency.expected | 3 + .../CONSISTENCY/VariablesConsistency.expected | 3 + .../CONSISTENCY/VariablesConsistency.expected | 85 +++++++++++++++++++ .../CONSISTENCY/VariablesConsistency.expected | 3 + .../CONSISTENCY/VariablesConsistency.expected | 3 + .../CONSISTENCY/VariablesConsistency.expected | 6 ++ .../CONSISTENCY/VariablesConsistency.expected | 3 + .../CONSISTENCY/VariablesConsistency.expected | 3 + .../CONSISTENCY/VariablesConsistency.expected | 15 ++++ .../CONSISTENCY/VariablesConsistency.expected | 3 + .../CONSISTENCY/VariablesConsistency.expected | 5 ++ .../CONSISTENCY/VariablesConsistency.expected | 5 ++ .../CONSISTENCY/VariablesConsistency.expected | 5 ++ .../CONSISTENCY/VariablesConsistency.expected | 3 + .../VariableCaptureConsistency.expected | 3 + .../VariableCaptureConsistency.expected | 17 ++++ 29 files changed, 352 insertions(+) create mode 100644 csharp/ql/test/library-tests/dataflow/global/CONSISTENCY/VariableCaptureConsistency.expected create mode 100644 csharp/ql/test/library-tests/dataflow/local/CONSISTENCY/VariableCaptureConsistency.expected create mode 100644 csharp/ql/test/library-tests/dataflow/ssa/CONSISTENCY/VariableCaptureConsistency.expected create mode 100644 csharp/ql/test/query-tests/Likely Bugs/ThreadUnsafeICryptoTransformLambda/CONSISTENCY/VariableCaptureConsistency.expected create mode 100644 csharp/ql/test/query-tests/Nullness/CONSISTENCY/VariableCaptureConsistency.expected create mode 100644 csharp/ql/test/query-tests/standalone/Language Abuse/SimplifyBoolExpr/CONSISTENCY/VariableCaptureConsistency.expected create mode 100644 ruby/ql/test/library-tests/ast/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/ast/calls/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/ast/control/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/ast/erb/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/controlflow/graph/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/dataflow/array-flow/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/dataflow/call-sensitivity/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/dataflow/global/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/dataflow/local/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/frameworks/action_view/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/frameworks/rack/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/frameworks/sinatra/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/modules/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/library-tests/variables/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/query-tests/experimental/InsecureRandomness/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/query-tests/experimental/improper-memoization/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/query-tests/security/cwe-079/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/query-tests/variables/DeadStoreOfLocal/CONSISTENCY/VariablesConsistency.expected create mode 100644 ruby/ql/test/query-tests/variables/UninitializedLocal/CONSISTENCY/VariablesConsistency.expected create mode 100644 rust/ql/test/library-tests/controlflow/CONSISTENCY/VariableCaptureConsistency.expected create mode 100644 rust/ql/test/query-tests/security/CWE-825/CONSISTENCY/VariableCaptureConsistency.expected diff --git a/csharp/ql/test/library-tests/dataflow/global/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/library-tests/dataflow/global/CONSISTENCY/VariableCaptureConsistency.expected new file mode 100644 index 000000000000..938ee32c47d1 --- /dev/null +++ b/csharp/ql/test/library-tests/dataflow/global/CONSISTENCY/VariableCaptureConsistency.expected @@ -0,0 +1,39 @@ +ambiguousReadNode +| Capture.cs:16:9:24:9 | CaptureIn2(...) | Capture.cs:7:10:7:11 | this in In | +| Capture.cs:16:9:24:9 | CaptureIn2(...) | Capture.cs:7:20:7:26 | tainted | +| Capture.cs:25:9:25:18 | access to local function CaptureIn2 | Capture.cs:7:10:7:11 | this in In | +| Capture.cs:25:9:25:18 | access to local function CaptureIn2 | Capture.cs:7:20:7:26 | tainted | +| Capture.cs:52:23:59:13 | (...) => ... | Capture.cs:50:33:50:40 | nonSink0 | +| Capture.cs:52:23:59:13 | (...) => ... | Capture.cs:50:50:50:55 | sink39 | +| Capture.cs:75:9:82:9 | CaptureOut2(...) | Capture.cs:64:10:64:12 | this in Out | +| Capture.cs:75:9:82:9 | CaptureOut2(...) | Capture.cs:74:16:74:21 | sink31 | +| Capture.cs:83:9:83:19 | access to local function CaptureOut2 | Capture.cs:64:10:64:12 | this in Out | +| Capture.cs:83:9:83:19 | access to local function CaptureOut2 | Capture.cs:74:16:74:21 | sink31 | +| Capture.cs:112:9:122:9 | CaptureOutMultipleLambdas(...) | Capture.cs:95:16:95:23 | nonSink0 | +| Capture.cs:112:9:122:9 | CaptureOutMultipleLambdas(...) | Capture.cs:111:16:111:21 | sink40 | +| Capture.cs:123:9:123:33 | access to local function CaptureOutMultipleLambdas | Capture.cs:95:16:95:23 | nonSink0 | +| Capture.cs:123:9:123:33 | access to local function CaptureOutMultipleLambdas | Capture.cs:111:16:111:21 | sink40 | +| Capture.cs:130:9:133:9 | CaptureThrough1(...) | Capture.cs:127:25:127:31 | tainted | +| Capture.cs:130:9:133:9 | CaptureThrough1(...) | Capture.cs:129:16:129:21 | sink33 | +| Capture.cs:134:9:134:23 | access to local function CaptureThrough1 | Capture.cs:127:25:127:31 | tainted | +| Capture.cs:134:9:134:23 | access to local function CaptureThrough1 | Capture.cs:129:16:129:21 | sink33 | +| Capture.cs:138:9:145:9 | CaptureThrough2(...) | Capture.cs:127:10:127:16 | this in Through | +| Capture.cs:138:9:145:9 | CaptureThrough2(...) | Capture.cs:127:25:127:31 | tainted | +| Capture.cs:138:9:145:9 | CaptureThrough2(...) | Capture.cs:137:16:137:21 | sink34 | +| Capture.cs:146:9:146:23 | access to local function CaptureThrough2 | Capture.cs:127:10:127:16 | this in Through | +| Capture.cs:146:9:146:23 | access to local function CaptureThrough2 | Capture.cs:127:25:127:31 | tainted | +| Capture.cs:146:9:146:23 | access to local function CaptureThrough2 | Capture.cs:137:16:137:21 | sink34 | +| Capture.cs:150:48:154:9 | (...) => ... | Capture.cs:127:25:127:31 | tainted | +| Capture.cs:150:48:154:9 | (...) => ... | Capture.cs:149:16:149:21 | sink35 | +| Capture.cs:155:30:155:44 | access to local variable captureThrough3 | Capture.cs:127:25:127:31 | tainted | +| Capture.cs:155:30:155:44 | access to local variable captureThrough3 | Capture.cs:149:16:149:21 | sink35 | +| Capture.cs:174:9:177:9 | CaptureThrough1NotCalled(...) | Capture.cs:127:25:127:31 | tainted | +| Capture.cs:174:9:177:9 | CaptureThrough1NotCalled(...) | Capture.cs:173:16:173:23 | nonSink0 | +| Capture.cs:180:9:186:9 | CaptureThrough2NotCalled(...) | Capture.cs:127:25:127:31 | tainted | +| Capture.cs:180:9:186:9 | CaptureThrough2NotCalled(...) | Capture.cs:173:16:173:23 | nonSink0 | +| Capture.cs:187:9:187:32 | access to local function CaptureThrough2NotCalled | Capture.cs:127:25:127:31 | tainted | +| Capture.cs:187:9:187:32 | access to local function CaptureThrough2NotCalled | Capture.cs:173:16:173:23 | nonSink0 | +| Capture.cs:332:9:332:65 | CapturingLocalFunction(...) | Capture.cs:326:10:326:12 | this in M12 | +| Capture.cs:332:9:332:65 | CapturingLocalFunction(...) | Capture.cs:328:13:328:13 | x | +| Capture.cs:334:9:334:30 | access to local function CapturingLocalFunction | Capture.cs:326:10:326:12 | this in M12 | +| Capture.cs:334:9:334:30 | access to local function CapturingLocalFunction | Capture.cs:328:13:328:13 | x | diff --git a/csharp/ql/test/library-tests/dataflow/local/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/library-tests/dataflow/local/CONSISTENCY/VariableCaptureConsistency.expected new file mode 100644 index 000000000000..b790fa24b23f --- /dev/null +++ b/csharp/ql/test/library-tests/dataflow/local/CONSISTENCY/VariableCaptureConsistency.expected @@ -0,0 +1,17 @@ +ambiguousReadNode +| Capture.cs:15:9:22:9 | CapIn2(...) | Capture.cs:5:17:5:17 | this in M | +| Capture.cs:15:9:22:9 | CapIn2(...) | Capture.cs:7:13:7:13 | i | +| Capture.cs:23:9:23:14 | access to local function CapIn2 | Capture.cs:5:17:5:17 | this in M | +| Capture.cs:23:9:23:14 | access to local function CapIn2 | Capture.cs:7:13:7:13 | i | +| Capture.cs:25:9:33:9 | CapIn4(...) | Capture.cs:5:17:5:17 | this in M | +| Capture.cs:25:9:33:9 | CapIn4(...) | Capture.cs:7:13:7:13 | i | +| Capture.cs:34:9:34:14 | access to local function CapIn4 | Capture.cs:5:17:5:17 | this in M | +| Capture.cs:34:9:34:14 | access to local function CapIn4 | Capture.cs:7:13:7:13 | i | +| Capture.cs:43:9:50:9 | CapOut2(...) | Capture.cs:5:17:5:17 | this in M | +| Capture.cs:43:9:50:9 | CapOut2(...) | Capture.cs:7:13:7:13 | i | +| Capture.cs:51:9:51:15 | access to local function CapOut2 | Capture.cs:5:17:5:17 | this in M | +| Capture.cs:51:9:51:15 | access to local function CapOut2 | Capture.cs:7:13:7:13 | i | +| Capture.cs:54:9:62:9 | CapOut4(...) | Capture.cs:5:17:5:17 | this in M | +| Capture.cs:54:9:62:9 | CapOut4(...) | Capture.cs:7:13:7:13 | i | +| Capture.cs:63:9:63:15 | access to local function CapOut4 | Capture.cs:5:17:5:17 | this in M | +| Capture.cs:63:9:63:15 | access to local function CapOut4 | Capture.cs:7:13:7:13 | i | diff --git a/csharp/ql/test/library-tests/dataflow/ssa/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/library-tests/dataflow/ssa/CONSISTENCY/VariableCaptureConsistency.expected new file mode 100644 index 000000000000..f3c4bb63106d --- /dev/null +++ b/csharp/ql/test/library-tests/dataflow/ssa/CONSISTENCY/VariableCaptureConsistency.expected @@ -0,0 +1,23 @@ +ambiguousReadNode +| Capture.cs:10:20:27:9 | (...) => ... | Capture.cs:6:16:6:16 | i | +| Capture.cs:10:20:27:9 | (...) => ... | Capture.cs:8:13:8:13 | x | +| Capture.cs:19:24:23:13 | (...) => ... | Capture.cs:10:20:27:9 | this | +| Capture.cs:19:24:23:13 | (...) => ... | Capture.cs:17:17:17:17 | y | +| Capture.cs:25:13:25:13 | access to local variable b | Capture.cs:10:20:27:9 | this | +| Capture.cs:25:13:25:13 | access to local variable b | Capture.cs:17:17:17:17 | y | +| Capture.cs:38:9:38:9 | access to local variable a | Capture.cs:6:16:6:16 | i | +| Capture.cs:38:9:38:9 | access to local variable a | Capture.cs:8:13:8:13 | x | +| Capture.cs:46:12:46:12 | access to local variable a | Capture.cs:6:16:6:16 | i | +| Capture.cs:46:12:46:12 | access to local variable a | Capture.cs:8:13:8:13 | x | +| Capture.cs:169:9:178:9 | M8(...) | Capture.cs:112:10:112:28 | this in NestedFunctionsTest | +| Capture.cs:169:9:178:9 | M8(...) | Capture.cs:168:13:168:13 | h | +| Capture.cs:248:9:252:9 | CaptureAndRef(...) | Capture.cs:240:10:240:11 | this in M2 | +| Capture.cs:248:9:252:9 | CaptureAndRef(...) | Capture.cs:242:13:242:13 | i | +| Capture.cs:254:9:254:21 | access to local function CaptureAndRef | Capture.cs:240:10:240:11 | this in M2 | +| Capture.cs:254:9:254:21 | access to local function CaptureAndRef | Capture.cs:242:13:242:13 | i | +| Consistency.cs:39:20:39:43 | (...) => ... | Consistency.cs:36:10:36:27 | this in CapturedDeclNoInit | +| Consistency.cs:39:20:39:43 | (...) => ... | Consistency.cs:38:13:38:13 | i | +| Fields.cs:81:9:81:9 | access to local variable a | Fields.cs:77:13:77:13 | f | +| Fields.cs:81:9:81:9 | access to local variable a | Fields.cs:78:23:78:23 | a | +| Properties.cs:77:9:77:9 | access to local variable a | Properties.cs:73:13:73:13 | f | +| Properties.cs:77:9:77:9 | access to local variable a | Properties.cs:74:23:74:23 | a | diff --git a/csharp/ql/test/query-tests/Likely Bugs/ThreadUnsafeICryptoTransformLambda/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/query-tests/Likely Bugs/ThreadUnsafeICryptoTransformLambda/CONSISTENCY/VariableCaptureConsistency.expected new file mode 100644 index 000000000000..becc963c0fe5 --- /dev/null +++ b/csharp/ql/test/query-tests/Likely Bugs/ThreadUnsafeICryptoTransformLambda/CONSISTENCY/VariableCaptureConsistency.expected @@ -0,0 +1,5 @@ +ambiguousReadNode +| ThreadUnsafeICryptoTransformLambda.cs:16:24:22:9 | (...) => ... | ThreadUnsafeICryptoTransformLambda.cs:10:32:10:34 | max | +| ThreadUnsafeICryptoTransformLambda.cs:16:24:22:9 | (...) => ... | ThreadUnsafeICryptoTransformLambda.cs:15:13:15:16 | sha1 | +| ThreadUnsafeICryptoTransformLambda.cs:80:24:86:9 | (...) => ... | ThreadUnsafeICryptoTransformLambda.cs:73:32:73:34 | max | +| ThreadUnsafeICryptoTransformLambda.cs:80:24:86:9 | (...) => ... | ThreadUnsafeICryptoTransformLambda.cs:77:13:77:16 | sha1 | diff --git a/csharp/ql/test/query-tests/Nullness/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/query-tests/Nullness/CONSISTENCY/VariableCaptureConsistency.expected new file mode 100644 index 000000000000..4bbdd3f461de --- /dev/null +++ b/csharp/ql/test/query-tests/Nullness/CONSISTENCY/VariableCaptureConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| A.cs:61:31:61:45 | (...) => ... | A.cs:61:26:61:26 | e | +| A.cs:61:31:61:45 | (...) => ... | A.cs:61:26:61:45 | this | diff --git a/csharp/ql/test/query-tests/standalone/Language Abuse/SimplifyBoolExpr/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/query-tests/standalone/Language Abuse/SimplifyBoolExpr/CONSISTENCY/VariableCaptureConsistency.expected new file mode 100644 index 000000000000..bc7a35a116b4 --- /dev/null +++ b/csharp/ql/test/query-tests/standalone/Language Abuse/SimplifyBoolExpr/CONSISTENCY/VariableCaptureConsistency.expected @@ -0,0 +1,9 @@ +ambiguousReadNode +| SimplifyBoolExpr.cs:53:29:53:50 | (...) => ... | SimplifyBoolExpr.cs:50:65:50:68 | left | +| SimplifyBoolExpr.cs:53:29:53:50 | (...) => ... | SimplifyBoolExpr.cs:50:100:50:104 | right | +| SimplifyBoolExpr.cs:56:9:56:41 | Local(...) | SimplifyBoolExpr.cs:50:65:50:68 | left | +| SimplifyBoolExpr.cs:56:9:56:41 | Local(...) | SimplifyBoolExpr.cs:50:100:50:104 | right | +| SimplifyBoolExpr.cs:58:16:58:21 | access to local variable lambda | SimplifyBoolExpr.cs:50:65:50:68 | left | +| SimplifyBoolExpr.cs:58:16:58:21 | access to local variable lambda | SimplifyBoolExpr.cs:50:100:50:104 | right | +| SimplifyBoolExpr.cs:58:28:58:32 | access to local function Local | SimplifyBoolExpr.cs:50:65:50:68 | left | +| SimplifyBoolExpr.cs:58:28:58:32 | access to local function Local | SimplifyBoolExpr.cs:50:100:50:104 | right | diff --git a/javascript/ql/test/library-tests/FlowSummary/CaptureConsistency.expected b/javascript/ql/test/library-tests/FlowSummary/CaptureConsistency.expected index 35f4edcf1fb9..e331f0ddde45 100644 --- a/javascript/ql/test/library-tests/FlowSummary/CaptureConsistency.expected +++ b/javascript/ql/test/library-tests/FlowSummary/CaptureConsistency.expected @@ -15,3 +15,4 @@ closureAliasMustBeInSameScope variableAccessAstNesting uniqueCallableLocation consistencyOverview +ambiguousReadNode diff --git a/python/ql/test/library-tests/dataflow/variable-capture/dataflow-capture-consistency.expected b/python/ql/test/library-tests/dataflow/variable-capture/dataflow-capture-consistency.expected index 35f4edcf1fb9..2837533cd483 100644 --- a/python/ql/test/library-tests/dataflow/variable-capture/dataflow-capture-consistency.expected +++ b/python/ql/test/library-tests/dataflow/variable-capture/dataflow-capture-consistency.expected @@ -15,3 +15,32 @@ closureAliasMustBeInSameScope variableAccessAstNesting uniqueCallableLocation consistencyOverview +ambiguousReadNode +| dict.py:67:5:67:22 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable sinkO1 | +| dict.py:67:5:67:22 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable tainted | +| dict.py:69:5:69:15 | ControlFlowNode for captureOut1 | dict.py:65:1:65:21 | Local Variable sinkO1 | +| dict.py:69:5:69:15 | ControlFlowNode for captureOut1 | dict.py:65:1:65:21 | Local Variable tainted | +| dict.py:73:5:73:22 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable sinkO2 | +| dict.py:73:5:73:22 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable tainted | +| dict.py:77:5:77:15 | ControlFlowNode for captureOut2 | dict.py:65:1:65:21 | Local Variable sinkO2 | +| dict.py:77:5:77:15 | ControlFlowNode for captureOut2 | dict.py:65:1:65:21 | Local Variable tainted | +| dict.py:81:5:81:31 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable nonSink1 | +| dict.py:81:5:81:31 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable tainted | +| dict.py:86:5:86:31 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable nonSink2 | +| dict.py:86:5:86:31 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable tainted | +| dict.py:90:5:90:24 | ControlFlowNode for captureOut2NotCalled | dict.py:65:1:65:21 | Local Variable nonSink2 | +| dict.py:90:5:90:24 | ControlFlowNode for captureOut2NotCalled | dict.py:65:1:65:21 | Local Variable tainted | +| nonlocal.py:73:5:73:22 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable sinkO1 | +| nonlocal.py:73:5:73:22 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable tainted | +| nonlocal.py:76:5:76:15 | ControlFlowNode for captureOut1 | nonlocal.py:71:1:71:21 | Local Variable sinkO1 | +| nonlocal.py:76:5:76:15 | ControlFlowNode for captureOut1 | nonlocal.py:71:1:71:21 | Local Variable tainted | +| nonlocal.py:80:5:80:22 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable sinkO2 | +| nonlocal.py:80:5:80:22 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable tainted | +| nonlocal.py:85:5:85:15 | ControlFlowNode for captureOut2 | nonlocal.py:71:1:71:21 | Local Variable sinkO2 | +| nonlocal.py:85:5:85:15 | ControlFlowNode for captureOut2 | nonlocal.py:71:1:71:21 | Local Variable tainted | +| nonlocal.py:89:5:89:31 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable nonSink1 | +| nonlocal.py:89:5:89:31 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable tainted | +| nonlocal.py:95:5:95:31 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable nonSink2 | +| nonlocal.py:95:5:95:31 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable tainted | +| nonlocal.py:100:5:100:24 | ControlFlowNode for captureOut2NotCalled | nonlocal.py:71:1:71:21 | Local Variable nonSink2 | +| nonlocal.py:100:5:100:24 | ControlFlowNode for captureOut2NotCalled | nonlocal.py:71:1:71:21 | Local Variable tainted | diff --git a/ruby/ql/test/library-tests/ast/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/ast/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..9b218f507380 --- /dev/null +++ b/ruby/ql/test/library-tests/ast/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,27 @@ +ambiguousReadNode +| calls/calls.rb:223:1:225:3 | { ... } | calls/calls.rb:1:1:367:24 | self | +| calls/calls.rb:223:1:225:3 | { ... } | calls/calls.rb:223:5:223:5 | x | +| calls/calls.rb:343:1:345:3 | { ... } | calls/calls.rb:1:1:367:24 | self | +| calls/calls.rb:343:1:345:3 | { ... } | calls/calls.rb:223:5:223:5 | x | +| calls/calls.rb:343:1:345:3 | { ... } | calls/calls.rb:343:8:343:8 | y | +| calls/calls.rb:343:1:345:3 | { ... } | calls/calls.rb:343:11:343:11 | z | +| calls/calls.rb:357:1:361:3 | ... = ... | calls/calls.rb:1:1:367:24 | self | +| calls/calls.rb:357:1:361:3 | ... = ... | calls/calls.rb:343:8:343:8 | y | +| calls/calls.rb:357:5:361:3 | -> { ... } | calls/calls.rb:1:1:367:24 | self | +| calls/calls.rb:357:5:361:3 | -> { ... } | calls/calls.rb:343:8:343:8 | y | +| control/loops.rb:9:1:12:3 | { ... } | control/loops.rb:2:1:2:3 | foo | +| control/loops.rb:9:1:12:3 | { ... } | control/loops.rb:3:1:3:3 | sum | +| control/loops.rb:9:1:12:3 | { ... } | control/loops.rb:9:5:9:5 | n | +| control/loops.rb:16:1:19:3 | { ... } | control/loops.rb:2:1:2:3 | foo | +| control/loops.rb:16:1:19:3 | { ... } | control/loops.rb:3:1:3:3 | sum | +| control/loops.rb:16:1:19:3 | { ... } | control/loops.rb:9:5:9:5 | n | +| control/loops.rb:22:1:25:3 | { ... } | control/loops.rb:2:1:2:3 | foo | +| control/loops.rb:22:1:25:3 | { ... } | control/loops.rb:3:1:3:3 | sum | +| control/loops.rb:22:1:25:3 | { ... } | control/loops.rb:22:5:22:7 | key | +| control/loops.rb:22:1:25:3 | { ... } | control/loops.rb:22:10:22:14 | value | +| control/loops.rb:28:1:32:3 | { ... } | control/loops.rb:2:1:2:3 | foo | +| control/loops.rb:28:1:32:3 | { ... } | control/loops.rb:3:1:3:3 | sum | +| control/loops.rb:28:1:32:3 | { ... } | control/loops.rb:22:5:22:7 | key | +| control/loops.rb:28:1:32:3 | { ... } | control/loops.rb:22:10:22:14 | value | +| erb/template.html.erb:27:6:31:8 | { ... } | erb/template.html.erb:25:4:25:5 | xs | +| erb/template.html.erb:27:6:31:8 | { ... } | erb/template.html.erb:27:10:27:10 | x | diff --git a/ruby/ql/test/library-tests/ast/calls/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/ast/calls/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..7440cff458c8 --- /dev/null +++ b/ruby/ql/test/library-tests/ast/calls/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,11 @@ +ambiguousReadNode +| calls.rb:223:1:225:3 | { ... } | calls.rb:1:1:367:24 | self | +| calls.rb:223:1:225:3 | { ... } | calls.rb:223:5:223:5 | x | +| calls.rb:343:1:345:3 | { ... } | calls.rb:1:1:367:24 | self | +| calls.rb:343:1:345:3 | { ... } | calls.rb:223:5:223:5 | x | +| calls.rb:343:1:345:3 | { ... } | calls.rb:343:8:343:8 | y | +| calls.rb:343:1:345:3 | { ... } | calls.rb:343:11:343:11 | z | +| calls.rb:357:1:361:3 | ... = ... | calls.rb:1:1:367:24 | self | +| calls.rb:357:1:361:3 | ... = ... | calls.rb:343:8:343:8 | y | +| calls.rb:357:5:361:3 | -> { ... } | calls.rb:1:1:367:24 | self | +| calls.rb:357:5:361:3 | -> { ... } | calls.rb:343:8:343:8 | y | diff --git a/ruby/ql/test/library-tests/ast/control/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/ast/control/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..366b4928e753 --- /dev/null +++ b/ruby/ql/test/library-tests/ast/control/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,15 @@ +ambiguousReadNode +| loops.rb:9:1:12:3 | { ... } | loops.rb:2:1:2:3 | foo | +| loops.rb:9:1:12:3 | { ... } | loops.rb:3:1:3:3 | sum | +| loops.rb:9:1:12:3 | { ... } | loops.rb:9:5:9:5 | n | +| loops.rb:16:1:19:3 | { ... } | loops.rb:2:1:2:3 | foo | +| loops.rb:16:1:19:3 | { ... } | loops.rb:3:1:3:3 | sum | +| loops.rb:16:1:19:3 | { ... } | loops.rb:9:5:9:5 | n | +| loops.rb:22:1:25:3 | { ... } | loops.rb:2:1:2:3 | foo | +| loops.rb:22:1:25:3 | { ... } | loops.rb:3:1:3:3 | sum | +| loops.rb:22:1:25:3 | { ... } | loops.rb:22:5:22:7 | key | +| loops.rb:22:1:25:3 | { ... } | loops.rb:22:10:22:14 | value | +| loops.rb:28:1:32:3 | { ... } | loops.rb:2:1:2:3 | foo | +| loops.rb:28:1:32:3 | { ... } | loops.rb:3:1:3:3 | sum | +| loops.rb:28:1:32:3 | { ... } | loops.rb:22:5:22:7 | key | +| loops.rb:28:1:32:3 | { ... } | loops.rb:22:10:22:14 | value | diff --git a/ruby/ql/test/library-tests/ast/erb/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/ast/erb/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..636387e9a992 --- /dev/null +++ b/ruby/ql/test/library-tests/ast/erb/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| template.html.erb:27:6:31:8 | { ... } | template.html.erb:25:4:25:5 | xs | +| template.html.erb:27:6:31:8 | { ... } | template.html.erb:27:10:27:10 | x | diff --git a/ruby/ql/test/library-tests/controlflow/graph/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/controlflow/graph/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..1fe0734c92df --- /dev/null +++ b/ruby/ql/test/library-tests/controlflow/graph/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,5 @@ +ambiguousReadNode +| cfg.rb:90:1:93:3 | { ... } | cfg.rb:1:1:221:1 | self | +| cfg.rb:90:1:93:3 | { ... } | cfg.rb:74:1:74:1 | x | +| raise.rb:155:16:155:50 | { ... } | raise.rb:154:1:156:3 | self | +| raise.rb:155:16:155:50 | { ... } | raise.rb:154:9:154:15 | element | diff --git a/ruby/ql/test/library-tests/dataflow/array-flow/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/dataflow/array-flow/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..2af36de73337 --- /dev/null +++ b/ruby/ql/test/library-tests/dataflow/array-flow/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| array_flow.rb:404:9:406:7 | { ... } | array_flow.rb:402:1:409:3 | self | +| array_flow.rb:404:9:406:7 | { ... } | array_flow.rb:404:13:404:13 | x | diff --git a/ruby/ql/test/library-tests/dataflow/call-sensitivity/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/dataflow/call-sensitivity/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..8861088fef5b --- /dev/null +++ b/ruby/ql/test/library-tests/dataflow/call-sensitivity/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| call_sensitivity.rb:75:20:77:7 | do ... end | call_sensitivity.rb:74:15:74:15 | x | +| call_sensitivity.rb:75:20:77:7 | do ... end | call_sensitivity.rb:74:18:74:18 | y | diff --git a/ruby/ql/test/library-tests/dataflow/global/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/dataflow/global/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..b454f80cd36f --- /dev/null +++ b/ruby/ql/test/library-tests/dataflow/global/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,85 @@ +ambiguousReadNode +| captured_variables.rb:10:5:10:23 | ... = ... | captured_variables.rb:9:1:12:3 | self | +| captured_variables.rb:10:5:10:23 | ... = ... | captured_variables.rb:9:24:9:24 | x | +| captured_variables.rb:10:10:10:23 | -> { ... } | captured_variables.rb:9:1:12:3 | self | +| captured_variables.rb:10:10:10:23 | -> { ... } | captured_variables.rb:9:24:9:24 | x | +| captured_variables.rb:11:5:11:6 | fn | captured_variables.rb:9:1:12:3 | self | +| captured_variables.rb:11:5:11:6 | fn | captured_variables.rb:9:24:9:24 | x | +| captured_variables.rb:16:5:18:5 | -> { ... } | captured_variables.rb:15:1:19:3 | self | +| captured_variables.rb:16:5:18:5 | -> { ... } | captured_variables.rb:15:28:15:28 | x | +| captured_variables.rb:16:5:18:5 | ... | captured_variables.rb:15:1:19:3 | self | +| captured_variables.rb:16:5:18:5 | ... | captured_variables.rb:15:28:15:28 | x | +| captured_variables.rb:23:5:25:5 | -> { ... } | captured_variables.rb:22:1:26:3 | self | +| captured_variables.rb:23:5:25:5 | -> { ... } | captured_variables.rb:22:28:22:28 | x | +| captured_variables.rb:23:5:25:5 | ... | captured_variables.rb:22:1:26:3 | self | +| captured_variables.rb:23:5:25:5 | ... | captured_variables.rb:22:28:22:28 | x | +| captured_variables.rb:30:5:32:5 | ... = ... | captured_variables.rb:29:1:34:3 | self | +| captured_variables.rb:30:5:32:5 | ... = ... | captured_variables.rb:29:33:29:33 | x | +| captured_variables.rb:30:10:32:5 | -> { ... } | captured_variables.rb:29:1:34:3 | self | +| captured_variables.rb:30:10:32:5 | -> { ... } | captured_variables.rb:29:33:29:33 | x | +| captured_variables.rb:33:29:33:30 | fn | captured_variables.rb:29:1:34:3 | self | +| captured_variables.rb:33:29:33:30 | fn | captured_variables.rb:29:33:29:33 | x | +| captured_variables.rb:41:5:43:5 | ... = ... | captured_variables.rb:40:1:45:3 | self | +| captured_variables.rb:41:5:43:5 | ... = ... | captured_variables.rb:40:31:40:31 | x | +| captured_variables.rb:41:10:43:5 | -> { ... } | captured_variables.rb:40:1:45:3 | self | +| captured_variables.rb:41:10:43:5 | -> { ... } | captured_variables.rb:40:31:40:31 | x | +| captured_variables.rb:44:13:44:14 | fn | captured_variables.rb:40:1:45:3 | self | +| captured_variables.rb:44:13:44:14 | fn | captured_variables.rb:40:31:40:31 | x | +| captured_variables.rb:49:16:52:3 | do ... end | captured_variables.rb:1:1:244:2 | self | +| captured_variables.rb:49:16:52:3 | do ... end | captured_variables.rb:48:1:48:1 | x | +| captured_variables.rb:67:16:70:3 | do ... end | captured_variables.rb:1:1:244:2 | self | +| captured_variables.rb:67:16:70:3 | do ... end | captured_variables.rb:65:1:65:3 | foo | +| captured_variables.rb:78:20:80:7 | do ... end | captured_variables.rb:1:1:244:2 | self | +| captured_variables.rb:78:20:80:7 | do ... end | captured_variables.rb:65:1:65:3 | foo | +| captured_variables.rb:86:1:89:1 | ... = ... | captured_variables.rb:1:1:244:2 | self | +| captured_variables.rb:86:1:89:1 | ... = ... | captured_variables.rb:85:1:85:1 | y | +| captured_variables.rb:86:6:89:1 | -> { ... } | captured_variables.rb:1:1:244:2 | self | +| captured_variables.rb:86:6:89:1 | -> { ... } | captured_variables.rb:85:1:85:1 | y | +| captured_variables.rb:90:1:90:2 | fn | captured_variables.rb:1:1:244:2 | self | +| captured_variables.rb:90:1:90:2 | fn | captured_variables.rb:85:1:85:1 | y | +| captured_variables.rb:94:5:96:5 | -> { ... } | captured_variables.rb:93:1:97:3 | self | +| captured_variables.rb:94:5:96:5 | -> { ... } | captured_variables.rb:93:17:93:17 | x | +| captured_variables.rb:94:5:96:5 | ... | captured_variables.rb:93:1:97:3 | self | +| captured_variables.rb:94:5:96:5 | ... | captured_variables.rb:93:17:93:17 | x | +| captured_variables.rb:110:5:116:5 | ... = ... | captured_variables.rb:108:1:119:3 | self | +| captured_variables.rb:110:5:116:5 | ... = ... | captured_variables.rb:109:5:109:5 | x | +| captured_variables.rb:110:14:116:5 | -> { ... } | captured_variables.rb:108:1:119:3 | self | +| captured_variables.rb:110:14:116:5 | -> { ... } | captured_variables.rb:109:5:109:5 | x | +| captured_variables.rb:117:5:117:10 | middle | captured_variables.rb:108:1:119:3 | self | +| captured_variables.rb:117:5:117:10 | middle | captured_variables.rb:109:5:109:5 | x | +| captured_variables.rb:125:5:127:5 | ... = ... | captured_variables.rb:122:1:142:3 | self | +| captured_variables.rb:125:5:127:5 | ... = ... | captured_variables.rb:123:5:123:5 | x | +| captured_variables.rb:125:11:127:5 | -> { ... } | captured_variables.rb:122:1:142:3 | self | +| captured_variables.rb:125:11:127:5 | -> { ... } | captured_variables.rb:123:5:123:5 | x | +| captured_variables.rb:129:5:137:5 | ... = ... | captured_variables.rb:122:1:142:3 | self | +| captured_variables.rb:129:5:137:5 | ... = ... | captured_variables.rb:123:5:123:5 | x | +| captured_variables.rb:129:11:137:5 | -> { ... } | captured_variables.rb:122:1:142:3 | self | +| captured_variables.rb:129:11:137:5 | -> { ... } | captured_variables.rb:123:5:123:5 | x | +| captured_variables.rb:130:9:136:11 | ... | captured_variables.rb:129:11:137:5 | this | +| captured_variables.rb:130:9:136:11 | ... | captured_variables.rb:130:9:130:9 | y | +| captured_variables.rb:132:9:134:9 | ... = ... | captured_variables.rb:129:11:137:5 | this | +| captured_variables.rb:132:9:134:9 | ... = ... | captured_variables.rb:130:9:130:9 | y | +| captured_variables.rb:132:15:134:9 | -> { ... } | captured_variables.rb:129:11:137:5 | this | +| captured_variables.rb:132:15:134:9 | -> { ... } | captured_variables.rb:130:9:130:9 | y | +| captured_variables.rb:139:11:139:13 | fn3 | captured_variables.rb:122:1:142:3 | self | +| captured_variables.rb:139:11:139:13 | fn3 | captured_variables.rb:123:5:123:5 | x | +| captured_variables.rb:141:5:141:7 | fn1 | captured_variables.rb:122:1:142:3 | self | +| captured_variables.rb:141:5:141:7 | fn1 | captured_variables.rb:123:5:123:5 | x | +| captured_variables.rb:205:5:213:5 | ... = ... | captured_variables.rb:196:1:216:3 | self | +| captured_variables.rb:205:5:213:5 | ... = ... | captured_variables.rb:197:5:197:5 | x | +| captured_variables.rb:205:10:213:5 | -> { ... } | captured_variables.rb:196:1:216:3 | self | +| captured_variables.rb:205:10:213:5 | -> { ... } | captured_variables.rb:197:5:197:5 | x | +| captured_variables.rb:215:5:215:6 | fn | captured_variables.rb:196:1:216:3 | self | +| captured_variables.rb:215:5:215:6 | fn | captured_variables.rb:197:5:197:5 | x | +| captured_variables.rb:222:5:224:5 | ... = ... | captured_variables.rb:219:5:219:5 | x | +| captured_variables.rb:222:5:224:5 | ... = ... | captured_variables.rb:220:5:220:5 | y | +| captured_variables.rb:222:11:224:5 | -> { ... } | captured_variables.rb:219:5:219:5 | x | +| captured_variables.rb:222:11:224:5 | -> { ... } | captured_variables.rb:220:5:220:5 | y | +| captured_variables.rb:226:5:226:7 | fn1 | captured_variables.rb:219:5:219:5 | x | +| captured_variables.rb:226:5:226:7 | fn1 | captured_variables.rb:220:5:220:5 | y | +| captured_variables.rb:235:5:237:5 | ... = ... | captured_variables.rb:232:1:242:3 | self | +| captured_variables.rb:235:5:237:5 | ... = ... | captured_variables.rb:233:5:233:5 | x | +| captured_variables.rb:235:11:237:5 | -> { ... } | captured_variables.rb:232:1:242:3 | self | +| captured_variables.rb:235:11:237:5 | -> { ... } | captured_variables.rb:233:5:233:5 | x | +| captured_variables.rb:241:5:241:7 | fn1 | captured_variables.rb:232:1:242:3 | self | +| captured_variables.rb:241:5:241:7 | fn1 | captured_variables.rb:233:5:233:5 | x | diff --git a/ruby/ql/test/library-tests/dataflow/local/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/dataflow/local/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..7a65959a07bb --- /dev/null +++ b/ruby/ql/test/library-tests/dataflow/local/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| local_dataflow.rb:10:5:13:3 | { ... } | local_dataflow.rb:1:1:174:4 | self | +| local_dataflow.rb:10:5:13:3 | { ... } | local_dataflow.rb:10:9:10:9 | x | diff --git a/ruby/ql/test/library-tests/frameworks/action_view/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/frameworks/action_view/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..df37e38d506f --- /dev/null +++ b/ruby/ql/test/library-tests/frameworks/action_view/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| app/views/foo/bars/show.html.erb:10:37:12:6 | do ... end | app/views/foo/bars/show.html.erb:1:14:33:43 | self | +| app/views/foo/bars/show.html.erb:10:37:12:6 | do ... end | app/views/foo/bars/show.html.erb:6:4:6:6 | key | diff --git a/ruby/ql/test/library-tests/frameworks/rack/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/frameworks/rack/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..8fd7077be5e1 --- /dev/null +++ b/ruby/ql/test/library-tests/frameworks/rack/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,6 @@ +ambiguousReadNode +| rack.rb:34:32:34:69 | { ... } | rack.rb:30:3:36:5 | self | +| rack.rb:34:32:34:69 | { ... } | rack.rb:30:12:30:14 | env | +| rack.rb:34:32:34:69 | { ... } | rack.rb:31:5:31:12 | began_at | +| rack.rb:34:32:34:69 | { ... } | rack.rb:32:5:32:10 | status | +| rack.rb:34:32:34:69 | { ... } | rack.rb:32:13:32:18 | header | diff --git a/ruby/ql/test/library-tests/frameworks/sinatra/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/frameworks/sinatra/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..528b95a4a187 --- /dev/null +++ b/ruby/ql/test/library-tests/frameworks/sinatra/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| app.rb:64:41:64:57 | { ... } | app.rb:64:21:64:59 | this | +| app.rb:64:41:64:57 | { ... } | app.rb:64:24:64:28 | value | diff --git a/ruby/ql/test/library-tests/modules/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/modules/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..fa3f6afe3fad --- /dev/null +++ b/ruby/ql/test/library-tests/modules/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| calls.rb:492:35:494:11 | do ... end | calls.rb:491:18:495:7 | this | +| calls.rb:492:35:494:11 | do ... end | calls.rb:491:22:491:22 | i | diff --git a/ruby/ql/test/library-tests/variables/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/variables/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..6c2cca383f88 --- /dev/null +++ b/ruby/ql/test/library-tests/variables/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,15 @@ +ambiguousReadNode +| nested_scopes.rb:18:23:18:36 | { ... } | nested_scopes.rb:16:21:19:15 | this | +| nested_scopes.rb:18:23:18:36 | { ... } | nested_scopes.rb:16:29:16:29 | a | +| parameters.rb:54:9:57:3 | do ... end | parameters.rb:1:1:62:1 | self | +| parameters.rb:54:9:57:3 | do ... end | parameters.rb:53:1:53:1 | x | +| scopes.rb:9:9:18:3 | do ... end | scopes.rb:1:1:89:4 | self | +| scopes.rb:9:9:18:3 | do ... end | scopes.rb:7:1:7:1 | a | +| ssa.rb:26:3:28:5 | { ... } | ssa.rb:25:1:30:3 | self | +| ssa.rb:26:3:28:5 | { ... } | ssa.rb:26:7:26:10 | elem | +| ssa.rb:66:11:70:5 | do ... end | ssa.rb:64:1:72:3 | self | +| ssa.rb:66:11:70:5 | do ... end | ssa.rb:65:3:65:10 | captured | +| ssa.rb:76:7:78:5 | do ... end | ssa.rb:74:1:79:3 | self | +| ssa.rb:76:7:78:5 | do ... end | ssa.rb:75:3:75:10 | captured | +| ssa.rb:83:7:87:5 | do ... end | ssa.rb:81:1:88:3 | self | +| ssa.rb:83:7:87:5 | do ... end | ssa.rb:82:3:82:10 | captured | diff --git a/ruby/ql/test/query-tests/experimental/InsecureRandomness/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/query-tests/experimental/InsecureRandomness/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..bc17a7c2a860 --- /dev/null +++ b/ruby/ql/test/query-tests/experimental/InsecureRandomness/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| InsecureRandomness.rb:6:34:6:60 | { ... } | InsecureRandomness.rb:3:1:7:3 | self | +| InsecureRandomness.rb:6:34:6:60 | { ... } | InsecureRandomness.rb:4:3:4:7 | chars | diff --git a/ruby/ql/test/query-tests/experimental/improper-memoization/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/query-tests/experimental/improper-memoization/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..19f2d36a5fd6 --- /dev/null +++ b/ruby/ql/test/query-tests/experimental/improper-memoization/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,5 @@ +ambiguousReadNode +| improper_memoization.rb:42:25:44:7 | do ... end | improper_memoization.rb:41:20:45:5 | this | +| improper_memoization.rb:42:25:44:7 | do ... end | improper_memoization.rb:41:28:41:31 | arg1 | +| improper_memoization.rb:83:21:85:5 | do ... end | improper_memoization.rb:82:1:87:3 | self | +| improper_memoization.rb:83:21:85:5 | do ... end | improper_memoization.rb:82:15:82:18 | arg2 | diff --git a/ruby/ql/test/query-tests/security/cwe-079/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/query-tests/security/cwe-079/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..f595abd76408 --- /dev/null +++ b/ruby/ql/test/query-tests/security/cwe-079/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,5 @@ +ambiguousReadNode +| app/views/foo/bars/show.html.erb:15:4:18:6 | { ... } | app/views/foo/bars/show.html.erb:2:14:89:48 | self | +| app/views/foo/bars/show.html.erb:15:4:18:6 | { ... } | app/views/foo/bars/show.html.erb:10:4:10:6 | key | +| app/views/foo/stores/show.html.erb:12:4:15:6 | { ... } | app/views/foo/stores/show.html.erb:2:5:90:48 | self | +| app/views/foo/stores/show.html.erb:12:4:15:6 | { ... } | app/views/foo/stores/show.html.erb:7:4:7:6 | key | diff --git a/ruby/ql/test/query-tests/variables/DeadStoreOfLocal/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/query-tests/variables/DeadStoreOfLocal/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..e9dd3ea8adfe --- /dev/null +++ b/ruby/ql/test/query-tests/variables/DeadStoreOfLocal/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,5 @@ +ambiguousReadNode +| DeadStoreOfLocal.rb:44:14:47:7 | do ... end | DeadStoreOfLocal.rb:43:1:48:3 | self | +| DeadStoreOfLocal.rb:44:14:47:7 | do ... end | DeadStoreOfLocal.rb:43:20:43:20 | x | +| DeadStoreOfLocal.rb:57:16:65:7 | do ... end | DeadStoreOfLocal.rb:56:1:66:3 | self | +| DeadStoreOfLocal.rb:57:16:65:7 | do ... end | DeadStoreOfLocal.rb:56:17:56:17 | x | diff --git a/ruby/ql/test/query-tests/variables/UninitializedLocal/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/query-tests/variables/UninitializedLocal/CONSISTENCY/VariablesConsistency.expected new file mode 100644 index 000000000000..4193d87746f6 --- /dev/null +++ b/ruby/ql/test/query-tests/variables/UninitializedLocal/CONSISTENCY/VariablesConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| UninitializedLocal.rb:73:5:75:7 | { ... } | UninitializedLocal.rb:72:1:77:3 | self | +| UninitializedLocal.rb:73:5:75:7 | { ... } | UninitializedLocal.rb:73:9:73:9 | i | diff --git a/rust/ql/test/library-tests/controlflow/CONSISTENCY/VariableCaptureConsistency.expected b/rust/ql/test/library-tests/controlflow/CONSISTENCY/VariableCaptureConsistency.expected new file mode 100644 index 000000000000..87bc24d5e5a6 --- /dev/null +++ b/rust/ql/test/library-tests/controlflow/CONSISTENCY/VariableCaptureConsistency.expected @@ -0,0 +1,3 @@ +ambiguousReadNode +| test.rs:511:28:516:9 | { ... } | test.rs:511:22:516:9 | this | +| test.rs:511:28:516:9 | { ... } | test.rs:511:23:511:25 | foo | diff --git a/rust/ql/test/query-tests/security/CWE-825/CONSISTENCY/VariableCaptureConsistency.expected b/rust/ql/test/query-tests/security/CWE-825/CONSISTENCY/VariableCaptureConsistency.expected new file mode 100644 index 000000000000..b8abfaf72c0e --- /dev/null +++ b/rust/ql/test/query-tests/security/CWE-825/CONSISTENCY/VariableCaptureConsistency.expected @@ -0,0 +1,17 @@ +ambiguousReadNode +| lifetime.rs:514:2:527:2 | return ... | lifetime.rs:509:16:509:17 | p3 | +| lifetime.rs:514:2:527:2 | return ... | lifetime.rs:509:32:509:33 | p4 | +| lifetime.rs:514:2:527:2 | return ... | lifetime.rs:511:6:511:14 | my_local2 | +| lifetime.rs:514:2:527:2 | return ... | lifetime.rs:512:6:512:7 | p1 | +| lifetime.rs:514:9:527:2 | \|...\| ... | lifetime.rs:509:16:509:17 | p3 | +| lifetime.rs:514:9:527:2 | \|...\| ... | lifetime.rs:509:32:509:33 | p4 | +| lifetime.rs:514:9:527:2 | \|...\| ... | lifetime.rs:511:6:511:14 | my_local2 | +| lifetime.rs:514:9:527:2 | \|...\| ... | lifetime.rs:512:6:512:7 | p1 | +| lifetime.rs:567:2:580:2 | return ... | lifetime.rs:562:22:562:23 | p3 | +| lifetime.rs:567:2:580:2 | return ... | lifetime.rs:562:38:562:39 | p4 | +| lifetime.rs:567:2:580:2 | return ... | lifetime.rs:564:6:564:14 | my_local2 | +| lifetime.rs:567:2:580:2 | return ... | lifetime.rs:565:6:565:7 | p1 | +| lifetime.rs:567:9:580:2 | { ... } | lifetime.rs:562:22:562:23 | p3 | +| lifetime.rs:567:9:580:2 | { ... } | lifetime.rs:562:38:562:39 | p4 | +| lifetime.rs:567:9:580:2 | { ... } | lifetime.rs:564:6:564:14 | my_local2 | +| lifetime.rs:567:9:580:2 | { ... } | lifetime.rs:565:6:565:7 | p1 | From 8957cdae1a4aad59ab3597ebaa6c6d3fc02e9280 Mon Sep 17 00:00:00 2001 From: Asger F Date: Fri, 2 Oct 2026 12:47:30 +0200 Subject: [PATCH 06/11] ssa: Associate ExprNode with a variable --- shared/ssa/codeql/ssa/Ssa.qll | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/shared/ssa/codeql/ssa/Ssa.qll b/shared/ssa/codeql/ssa/Ssa.qll index 151728da5466..7f05e5c006a1 100644 --- a/shared/ssa/codeql/ssa/Ssa.qll +++ b/shared/ssa/codeql/ssa/Ssa.qll @@ -1680,7 +1680,12 @@ module Make< cached private newtype TNode = TWriteDefSource(WriteDefinition def) { DfInput::ssaDefHasSource(def) } or - TExprNode(DfInput::Expr e, Boolean isPost) { e = DfInput::getARead(_) } or + TExprNode(DfInput::Expr e, SourceVariable v, Boolean isPost) { + exists(Definition def | + def.getSourceVariable() = v and + e = DfInput::getARead(def) + ) + } or TSsaDefinitionNode(DefinitionExt def) { not phiHasUniqNextNode(def) and if DfInput::includeWriteDefsInFlowStep() @@ -1730,8 +1735,9 @@ module Make< abstract private class ExprNodePreOrPostImpl extends NodeImpl, TExprNode { DfInput::Expr e; boolean isPost; + SourceVariable v_; - ExprNodePreOrPostImpl() { this = TExprNode(e, isPost) } + ExprNodePreOrPostImpl() { this = TExprNode(e, v_, isPost) } /** Gets the underlying expression. */ DfInput::Expr getExpr() { result = e } @@ -1742,6 +1748,9 @@ module Make< result = bb.getNode(i).getLocation() ) } + + /** Gets the variable accessed at this expression. */ + SourceVariable getSourceVariable() { result = v_ } } final class ExprNodePreOrPost = ExprNodePreOrPostImpl; @@ -1760,7 +1769,7 @@ module Make< ExprPostUpdateNodeImpl() { isPost = true } /** Gets the pre-update expression node. */ - ExprNode getPreUpdateNode() { result = TExprNode(e, false) } + ExprNode getPreUpdateNode() { result = TExprNode(e, _, false) } override string toString() { result = e.toString() + " [postupdate]" } } @@ -1770,7 +1779,6 @@ module Make< private class ReadNodeImpl extends ExprNodeImpl { private BasicBlock bb_; private int i_; - private SourceVariable v_; ReadNodeImpl() { variableRead(bb_, i_, v_, true) and From c0847078f27d4c1fad89aeb69fe21ad686e16488 Mon Sep 17 00:00:00 2001 From: Asger F Date: Fri, 2 Oct 2026 16:13:11 +0200 Subject: [PATCH 07/11] ssa: Record absense of ambiguousReadNode errors The previously-added consistency errors are gone. --- .../VariableCaptureConsistency.expected | 39 --------- .../VariableCaptureConsistency.expected | 17 ---- .../VariableCaptureConsistency.expected | 23 ----- .../VariableCaptureConsistency.expected | 5 -- .../VariableCaptureConsistency.expected | 3 - .../VariableCaptureConsistency.expected | 9 -- .../dataflow-capture-consistency.expected | 28 ------ .../CONSISTENCY/VariablesConsistency.expected | 27 ------ .../CONSISTENCY/VariablesConsistency.expected | 11 --- .../CONSISTENCY/VariablesConsistency.expected | 15 ---- .../CONSISTENCY/VariablesConsistency.expected | 3 - .../CONSISTENCY/VariablesConsistency.expected | 5 -- .../CONSISTENCY/VariablesConsistency.expected | 3 - .../CONSISTENCY/VariablesConsistency.expected | 3 - .../CONSISTENCY/VariablesConsistency.expected | 85 ------------------- .../CONSISTENCY/VariablesConsistency.expected | 3 - .../CONSISTENCY/VariablesConsistency.expected | 3 - .../CONSISTENCY/VariablesConsistency.expected | 6 -- .../CONSISTENCY/VariablesConsistency.expected | 3 - .../CONSISTENCY/VariablesConsistency.expected | 3 - .../CONSISTENCY/VariablesConsistency.expected | 15 ---- .../CONSISTENCY/VariablesConsistency.expected | 3 - .../CONSISTENCY/VariablesConsistency.expected | 5 -- .../CONSISTENCY/VariablesConsistency.expected | 5 -- .../CONSISTENCY/VariablesConsistency.expected | 5 -- .../CONSISTENCY/VariablesConsistency.expected | 3 - .../VariableCaptureConsistency.expected | 3 - .../VariableCaptureConsistency.expected | 17 ---- 28 files changed, 350 deletions(-) delete mode 100644 csharp/ql/test/library-tests/dataflow/global/CONSISTENCY/VariableCaptureConsistency.expected delete mode 100644 csharp/ql/test/library-tests/dataflow/local/CONSISTENCY/VariableCaptureConsistency.expected delete mode 100644 csharp/ql/test/library-tests/dataflow/ssa/CONSISTENCY/VariableCaptureConsistency.expected delete mode 100644 csharp/ql/test/query-tests/Likely Bugs/ThreadUnsafeICryptoTransformLambda/CONSISTENCY/VariableCaptureConsistency.expected delete mode 100644 csharp/ql/test/query-tests/Nullness/CONSISTENCY/VariableCaptureConsistency.expected delete mode 100644 csharp/ql/test/query-tests/standalone/Language Abuse/SimplifyBoolExpr/CONSISTENCY/VariableCaptureConsistency.expected delete mode 100644 ruby/ql/test/library-tests/ast/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/ast/calls/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/ast/control/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/ast/erb/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/controlflow/graph/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/dataflow/array-flow/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/dataflow/call-sensitivity/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/dataflow/global/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/dataflow/local/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/frameworks/action_view/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/frameworks/rack/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/frameworks/sinatra/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/modules/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/library-tests/variables/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/query-tests/experimental/InsecureRandomness/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/query-tests/experimental/improper-memoization/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/query-tests/security/cwe-079/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/query-tests/variables/DeadStoreOfLocal/CONSISTENCY/VariablesConsistency.expected delete mode 100644 ruby/ql/test/query-tests/variables/UninitializedLocal/CONSISTENCY/VariablesConsistency.expected delete mode 100644 rust/ql/test/library-tests/controlflow/CONSISTENCY/VariableCaptureConsistency.expected delete mode 100644 rust/ql/test/query-tests/security/CWE-825/CONSISTENCY/VariableCaptureConsistency.expected diff --git a/csharp/ql/test/library-tests/dataflow/global/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/library-tests/dataflow/global/CONSISTENCY/VariableCaptureConsistency.expected deleted file mode 100644 index 938ee32c47d1..000000000000 --- a/csharp/ql/test/library-tests/dataflow/global/CONSISTENCY/VariableCaptureConsistency.expected +++ /dev/null @@ -1,39 +0,0 @@ -ambiguousReadNode -| Capture.cs:16:9:24:9 | CaptureIn2(...) | Capture.cs:7:10:7:11 | this in In | -| Capture.cs:16:9:24:9 | CaptureIn2(...) | Capture.cs:7:20:7:26 | tainted | -| Capture.cs:25:9:25:18 | access to local function CaptureIn2 | Capture.cs:7:10:7:11 | this in In | -| Capture.cs:25:9:25:18 | access to local function CaptureIn2 | Capture.cs:7:20:7:26 | tainted | -| Capture.cs:52:23:59:13 | (...) => ... | Capture.cs:50:33:50:40 | nonSink0 | -| Capture.cs:52:23:59:13 | (...) => ... | Capture.cs:50:50:50:55 | sink39 | -| Capture.cs:75:9:82:9 | CaptureOut2(...) | Capture.cs:64:10:64:12 | this in Out | -| Capture.cs:75:9:82:9 | CaptureOut2(...) | Capture.cs:74:16:74:21 | sink31 | -| Capture.cs:83:9:83:19 | access to local function CaptureOut2 | Capture.cs:64:10:64:12 | this in Out | -| Capture.cs:83:9:83:19 | access to local function CaptureOut2 | Capture.cs:74:16:74:21 | sink31 | -| Capture.cs:112:9:122:9 | CaptureOutMultipleLambdas(...) | Capture.cs:95:16:95:23 | nonSink0 | -| Capture.cs:112:9:122:9 | CaptureOutMultipleLambdas(...) | Capture.cs:111:16:111:21 | sink40 | -| Capture.cs:123:9:123:33 | access to local function CaptureOutMultipleLambdas | Capture.cs:95:16:95:23 | nonSink0 | -| Capture.cs:123:9:123:33 | access to local function CaptureOutMultipleLambdas | Capture.cs:111:16:111:21 | sink40 | -| Capture.cs:130:9:133:9 | CaptureThrough1(...) | Capture.cs:127:25:127:31 | tainted | -| Capture.cs:130:9:133:9 | CaptureThrough1(...) | Capture.cs:129:16:129:21 | sink33 | -| Capture.cs:134:9:134:23 | access to local function CaptureThrough1 | Capture.cs:127:25:127:31 | tainted | -| Capture.cs:134:9:134:23 | access to local function CaptureThrough1 | Capture.cs:129:16:129:21 | sink33 | -| Capture.cs:138:9:145:9 | CaptureThrough2(...) | Capture.cs:127:10:127:16 | this in Through | -| Capture.cs:138:9:145:9 | CaptureThrough2(...) | Capture.cs:127:25:127:31 | tainted | -| Capture.cs:138:9:145:9 | CaptureThrough2(...) | Capture.cs:137:16:137:21 | sink34 | -| Capture.cs:146:9:146:23 | access to local function CaptureThrough2 | Capture.cs:127:10:127:16 | this in Through | -| Capture.cs:146:9:146:23 | access to local function CaptureThrough2 | Capture.cs:127:25:127:31 | tainted | -| Capture.cs:146:9:146:23 | access to local function CaptureThrough2 | Capture.cs:137:16:137:21 | sink34 | -| Capture.cs:150:48:154:9 | (...) => ... | Capture.cs:127:25:127:31 | tainted | -| Capture.cs:150:48:154:9 | (...) => ... | Capture.cs:149:16:149:21 | sink35 | -| Capture.cs:155:30:155:44 | access to local variable captureThrough3 | Capture.cs:127:25:127:31 | tainted | -| Capture.cs:155:30:155:44 | access to local variable captureThrough3 | Capture.cs:149:16:149:21 | sink35 | -| Capture.cs:174:9:177:9 | CaptureThrough1NotCalled(...) | Capture.cs:127:25:127:31 | tainted | -| Capture.cs:174:9:177:9 | CaptureThrough1NotCalled(...) | Capture.cs:173:16:173:23 | nonSink0 | -| Capture.cs:180:9:186:9 | CaptureThrough2NotCalled(...) | Capture.cs:127:25:127:31 | tainted | -| Capture.cs:180:9:186:9 | CaptureThrough2NotCalled(...) | Capture.cs:173:16:173:23 | nonSink0 | -| Capture.cs:187:9:187:32 | access to local function CaptureThrough2NotCalled | Capture.cs:127:25:127:31 | tainted | -| Capture.cs:187:9:187:32 | access to local function CaptureThrough2NotCalled | Capture.cs:173:16:173:23 | nonSink0 | -| Capture.cs:332:9:332:65 | CapturingLocalFunction(...) | Capture.cs:326:10:326:12 | this in M12 | -| Capture.cs:332:9:332:65 | CapturingLocalFunction(...) | Capture.cs:328:13:328:13 | x | -| Capture.cs:334:9:334:30 | access to local function CapturingLocalFunction | Capture.cs:326:10:326:12 | this in M12 | -| Capture.cs:334:9:334:30 | access to local function CapturingLocalFunction | Capture.cs:328:13:328:13 | x | diff --git a/csharp/ql/test/library-tests/dataflow/local/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/library-tests/dataflow/local/CONSISTENCY/VariableCaptureConsistency.expected deleted file mode 100644 index b790fa24b23f..000000000000 --- a/csharp/ql/test/library-tests/dataflow/local/CONSISTENCY/VariableCaptureConsistency.expected +++ /dev/null @@ -1,17 +0,0 @@ -ambiguousReadNode -| Capture.cs:15:9:22:9 | CapIn2(...) | Capture.cs:5:17:5:17 | this in M | -| Capture.cs:15:9:22:9 | CapIn2(...) | Capture.cs:7:13:7:13 | i | -| Capture.cs:23:9:23:14 | access to local function CapIn2 | Capture.cs:5:17:5:17 | this in M | -| Capture.cs:23:9:23:14 | access to local function CapIn2 | Capture.cs:7:13:7:13 | i | -| Capture.cs:25:9:33:9 | CapIn4(...) | Capture.cs:5:17:5:17 | this in M | -| Capture.cs:25:9:33:9 | CapIn4(...) | Capture.cs:7:13:7:13 | i | -| Capture.cs:34:9:34:14 | access to local function CapIn4 | Capture.cs:5:17:5:17 | this in M | -| Capture.cs:34:9:34:14 | access to local function CapIn4 | Capture.cs:7:13:7:13 | i | -| Capture.cs:43:9:50:9 | CapOut2(...) | Capture.cs:5:17:5:17 | this in M | -| Capture.cs:43:9:50:9 | CapOut2(...) | Capture.cs:7:13:7:13 | i | -| Capture.cs:51:9:51:15 | access to local function CapOut2 | Capture.cs:5:17:5:17 | this in M | -| Capture.cs:51:9:51:15 | access to local function CapOut2 | Capture.cs:7:13:7:13 | i | -| Capture.cs:54:9:62:9 | CapOut4(...) | Capture.cs:5:17:5:17 | this in M | -| Capture.cs:54:9:62:9 | CapOut4(...) | Capture.cs:7:13:7:13 | i | -| Capture.cs:63:9:63:15 | access to local function CapOut4 | Capture.cs:5:17:5:17 | this in M | -| Capture.cs:63:9:63:15 | access to local function CapOut4 | Capture.cs:7:13:7:13 | i | diff --git a/csharp/ql/test/library-tests/dataflow/ssa/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/library-tests/dataflow/ssa/CONSISTENCY/VariableCaptureConsistency.expected deleted file mode 100644 index f3c4bb63106d..000000000000 --- a/csharp/ql/test/library-tests/dataflow/ssa/CONSISTENCY/VariableCaptureConsistency.expected +++ /dev/null @@ -1,23 +0,0 @@ -ambiguousReadNode -| Capture.cs:10:20:27:9 | (...) => ... | Capture.cs:6:16:6:16 | i | -| Capture.cs:10:20:27:9 | (...) => ... | Capture.cs:8:13:8:13 | x | -| Capture.cs:19:24:23:13 | (...) => ... | Capture.cs:10:20:27:9 | this | -| Capture.cs:19:24:23:13 | (...) => ... | Capture.cs:17:17:17:17 | y | -| Capture.cs:25:13:25:13 | access to local variable b | Capture.cs:10:20:27:9 | this | -| Capture.cs:25:13:25:13 | access to local variable b | Capture.cs:17:17:17:17 | y | -| Capture.cs:38:9:38:9 | access to local variable a | Capture.cs:6:16:6:16 | i | -| Capture.cs:38:9:38:9 | access to local variable a | Capture.cs:8:13:8:13 | x | -| Capture.cs:46:12:46:12 | access to local variable a | Capture.cs:6:16:6:16 | i | -| Capture.cs:46:12:46:12 | access to local variable a | Capture.cs:8:13:8:13 | x | -| Capture.cs:169:9:178:9 | M8(...) | Capture.cs:112:10:112:28 | this in NestedFunctionsTest | -| Capture.cs:169:9:178:9 | M8(...) | Capture.cs:168:13:168:13 | h | -| Capture.cs:248:9:252:9 | CaptureAndRef(...) | Capture.cs:240:10:240:11 | this in M2 | -| Capture.cs:248:9:252:9 | CaptureAndRef(...) | Capture.cs:242:13:242:13 | i | -| Capture.cs:254:9:254:21 | access to local function CaptureAndRef | Capture.cs:240:10:240:11 | this in M2 | -| Capture.cs:254:9:254:21 | access to local function CaptureAndRef | Capture.cs:242:13:242:13 | i | -| Consistency.cs:39:20:39:43 | (...) => ... | Consistency.cs:36:10:36:27 | this in CapturedDeclNoInit | -| Consistency.cs:39:20:39:43 | (...) => ... | Consistency.cs:38:13:38:13 | i | -| Fields.cs:81:9:81:9 | access to local variable a | Fields.cs:77:13:77:13 | f | -| Fields.cs:81:9:81:9 | access to local variable a | Fields.cs:78:23:78:23 | a | -| Properties.cs:77:9:77:9 | access to local variable a | Properties.cs:73:13:73:13 | f | -| Properties.cs:77:9:77:9 | access to local variable a | Properties.cs:74:23:74:23 | a | diff --git a/csharp/ql/test/query-tests/Likely Bugs/ThreadUnsafeICryptoTransformLambda/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/query-tests/Likely Bugs/ThreadUnsafeICryptoTransformLambda/CONSISTENCY/VariableCaptureConsistency.expected deleted file mode 100644 index becc963c0fe5..000000000000 --- a/csharp/ql/test/query-tests/Likely Bugs/ThreadUnsafeICryptoTransformLambda/CONSISTENCY/VariableCaptureConsistency.expected +++ /dev/null @@ -1,5 +0,0 @@ -ambiguousReadNode -| ThreadUnsafeICryptoTransformLambda.cs:16:24:22:9 | (...) => ... | ThreadUnsafeICryptoTransformLambda.cs:10:32:10:34 | max | -| ThreadUnsafeICryptoTransformLambda.cs:16:24:22:9 | (...) => ... | ThreadUnsafeICryptoTransformLambda.cs:15:13:15:16 | sha1 | -| ThreadUnsafeICryptoTransformLambda.cs:80:24:86:9 | (...) => ... | ThreadUnsafeICryptoTransformLambda.cs:73:32:73:34 | max | -| ThreadUnsafeICryptoTransformLambda.cs:80:24:86:9 | (...) => ... | ThreadUnsafeICryptoTransformLambda.cs:77:13:77:16 | sha1 | diff --git a/csharp/ql/test/query-tests/Nullness/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/query-tests/Nullness/CONSISTENCY/VariableCaptureConsistency.expected deleted file mode 100644 index 4bbdd3f461de..000000000000 --- a/csharp/ql/test/query-tests/Nullness/CONSISTENCY/VariableCaptureConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| A.cs:61:31:61:45 | (...) => ... | A.cs:61:26:61:26 | e | -| A.cs:61:31:61:45 | (...) => ... | A.cs:61:26:61:45 | this | diff --git a/csharp/ql/test/query-tests/standalone/Language Abuse/SimplifyBoolExpr/CONSISTENCY/VariableCaptureConsistency.expected b/csharp/ql/test/query-tests/standalone/Language Abuse/SimplifyBoolExpr/CONSISTENCY/VariableCaptureConsistency.expected deleted file mode 100644 index bc7a35a116b4..000000000000 --- a/csharp/ql/test/query-tests/standalone/Language Abuse/SimplifyBoolExpr/CONSISTENCY/VariableCaptureConsistency.expected +++ /dev/null @@ -1,9 +0,0 @@ -ambiguousReadNode -| SimplifyBoolExpr.cs:53:29:53:50 | (...) => ... | SimplifyBoolExpr.cs:50:65:50:68 | left | -| SimplifyBoolExpr.cs:53:29:53:50 | (...) => ... | SimplifyBoolExpr.cs:50:100:50:104 | right | -| SimplifyBoolExpr.cs:56:9:56:41 | Local(...) | SimplifyBoolExpr.cs:50:65:50:68 | left | -| SimplifyBoolExpr.cs:56:9:56:41 | Local(...) | SimplifyBoolExpr.cs:50:100:50:104 | right | -| SimplifyBoolExpr.cs:58:16:58:21 | access to local variable lambda | SimplifyBoolExpr.cs:50:65:50:68 | left | -| SimplifyBoolExpr.cs:58:16:58:21 | access to local variable lambda | SimplifyBoolExpr.cs:50:100:50:104 | right | -| SimplifyBoolExpr.cs:58:28:58:32 | access to local function Local | SimplifyBoolExpr.cs:50:65:50:68 | left | -| SimplifyBoolExpr.cs:58:28:58:32 | access to local function Local | SimplifyBoolExpr.cs:50:100:50:104 | right | diff --git a/python/ql/test/library-tests/dataflow/variable-capture/dataflow-capture-consistency.expected b/python/ql/test/library-tests/dataflow/variable-capture/dataflow-capture-consistency.expected index 2837533cd483..e331f0ddde45 100644 --- a/python/ql/test/library-tests/dataflow/variable-capture/dataflow-capture-consistency.expected +++ b/python/ql/test/library-tests/dataflow/variable-capture/dataflow-capture-consistency.expected @@ -16,31 +16,3 @@ variableAccessAstNesting uniqueCallableLocation consistencyOverview ambiguousReadNode -| dict.py:67:5:67:22 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable sinkO1 | -| dict.py:67:5:67:22 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable tainted | -| dict.py:69:5:69:15 | ControlFlowNode for captureOut1 | dict.py:65:1:65:21 | Local Variable sinkO1 | -| dict.py:69:5:69:15 | ControlFlowNode for captureOut1 | dict.py:65:1:65:21 | Local Variable tainted | -| dict.py:73:5:73:22 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable sinkO2 | -| dict.py:73:5:73:22 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable tainted | -| dict.py:77:5:77:15 | ControlFlowNode for captureOut2 | dict.py:65:1:65:21 | Local Variable sinkO2 | -| dict.py:77:5:77:15 | ControlFlowNode for captureOut2 | dict.py:65:1:65:21 | Local Variable tainted | -| dict.py:81:5:81:31 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable nonSink1 | -| dict.py:81:5:81:31 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable tainted | -| dict.py:86:5:86:31 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable nonSink2 | -| dict.py:86:5:86:31 | ControlFlowNode for FunctionExpr | dict.py:65:1:65:21 | Local Variable tainted | -| dict.py:90:5:90:24 | ControlFlowNode for captureOut2NotCalled | dict.py:65:1:65:21 | Local Variable nonSink2 | -| dict.py:90:5:90:24 | ControlFlowNode for captureOut2NotCalled | dict.py:65:1:65:21 | Local Variable tainted | -| nonlocal.py:73:5:73:22 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable sinkO1 | -| nonlocal.py:73:5:73:22 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable tainted | -| nonlocal.py:76:5:76:15 | ControlFlowNode for captureOut1 | nonlocal.py:71:1:71:21 | Local Variable sinkO1 | -| nonlocal.py:76:5:76:15 | ControlFlowNode for captureOut1 | nonlocal.py:71:1:71:21 | Local Variable tainted | -| nonlocal.py:80:5:80:22 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable sinkO2 | -| nonlocal.py:80:5:80:22 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable tainted | -| nonlocal.py:85:5:85:15 | ControlFlowNode for captureOut2 | nonlocal.py:71:1:71:21 | Local Variable sinkO2 | -| nonlocal.py:85:5:85:15 | ControlFlowNode for captureOut2 | nonlocal.py:71:1:71:21 | Local Variable tainted | -| nonlocal.py:89:5:89:31 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable nonSink1 | -| nonlocal.py:89:5:89:31 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable tainted | -| nonlocal.py:95:5:95:31 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable nonSink2 | -| nonlocal.py:95:5:95:31 | ControlFlowNode for FunctionExpr | nonlocal.py:71:1:71:21 | Local Variable tainted | -| nonlocal.py:100:5:100:24 | ControlFlowNode for captureOut2NotCalled | nonlocal.py:71:1:71:21 | Local Variable nonSink2 | -| nonlocal.py:100:5:100:24 | ControlFlowNode for captureOut2NotCalled | nonlocal.py:71:1:71:21 | Local Variable tainted | diff --git a/ruby/ql/test/library-tests/ast/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/ast/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 9b218f507380..000000000000 --- a/ruby/ql/test/library-tests/ast/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,27 +0,0 @@ -ambiguousReadNode -| calls/calls.rb:223:1:225:3 | { ... } | calls/calls.rb:1:1:367:24 | self | -| calls/calls.rb:223:1:225:3 | { ... } | calls/calls.rb:223:5:223:5 | x | -| calls/calls.rb:343:1:345:3 | { ... } | calls/calls.rb:1:1:367:24 | self | -| calls/calls.rb:343:1:345:3 | { ... } | calls/calls.rb:223:5:223:5 | x | -| calls/calls.rb:343:1:345:3 | { ... } | calls/calls.rb:343:8:343:8 | y | -| calls/calls.rb:343:1:345:3 | { ... } | calls/calls.rb:343:11:343:11 | z | -| calls/calls.rb:357:1:361:3 | ... = ... | calls/calls.rb:1:1:367:24 | self | -| calls/calls.rb:357:1:361:3 | ... = ... | calls/calls.rb:343:8:343:8 | y | -| calls/calls.rb:357:5:361:3 | -> { ... } | calls/calls.rb:1:1:367:24 | self | -| calls/calls.rb:357:5:361:3 | -> { ... } | calls/calls.rb:343:8:343:8 | y | -| control/loops.rb:9:1:12:3 | { ... } | control/loops.rb:2:1:2:3 | foo | -| control/loops.rb:9:1:12:3 | { ... } | control/loops.rb:3:1:3:3 | sum | -| control/loops.rb:9:1:12:3 | { ... } | control/loops.rb:9:5:9:5 | n | -| control/loops.rb:16:1:19:3 | { ... } | control/loops.rb:2:1:2:3 | foo | -| control/loops.rb:16:1:19:3 | { ... } | control/loops.rb:3:1:3:3 | sum | -| control/loops.rb:16:1:19:3 | { ... } | control/loops.rb:9:5:9:5 | n | -| control/loops.rb:22:1:25:3 | { ... } | control/loops.rb:2:1:2:3 | foo | -| control/loops.rb:22:1:25:3 | { ... } | control/loops.rb:3:1:3:3 | sum | -| control/loops.rb:22:1:25:3 | { ... } | control/loops.rb:22:5:22:7 | key | -| control/loops.rb:22:1:25:3 | { ... } | control/loops.rb:22:10:22:14 | value | -| control/loops.rb:28:1:32:3 | { ... } | control/loops.rb:2:1:2:3 | foo | -| control/loops.rb:28:1:32:3 | { ... } | control/loops.rb:3:1:3:3 | sum | -| control/loops.rb:28:1:32:3 | { ... } | control/loops.rb:22:5:22:7 | key | -| control/loops.rb:28:1:32:3 | { ... } | control/loops.rb:22:10:22:14 | value | -| erb/template.html.erb:27:6:31:8 | { ... } | erb/template.html.erb:25:4:25:5 | xs | -| erb/template.html.erb:27:6:31:8 | { ... } | erb/template.html.erb:27:10:27:10 | x | diff --git a/ruby/ql/test/library-tests/ast/calls/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/ast/calls/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 7440cff458c8..000000000000 --- a/ruby/ql/test/library-tests/ast/calls/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,11 +0,0 @@ -ambiguousReadNode -| calls.rb:223:1:225:3 | { ... } | calls.rb:1:1:367:24 | self | -| calls.rb:223:1:225:3 | { ... } | calls.rb:223:5:223:5 | x | -| calls.rb:343:1:345:3 | { ... } | calls.rb:1:1:367:24 | self | -| calls.rb:343:1:345:3 | { ... } | calls.rb:223:5:223:5 | x | -| calls.rb:343:1:345:3 | { ... } | calls.rb:343:8:343:8 | y | -| calls.rb:343:1:345:3 | { ... } | calls.rb:343:11:343:11 | z | -| calls.rb:357:1:361:3 | ... = ... | calls.rb:1:1:367:24 | self | -| calls.rb:357:1:361:3 | ... = ... | calls.rb:343:8:343:8 | y | -| calls.rb:357:5:361:3 | -> { ... } | calls.rb:1:1:367:24 | self | -| calls.rb:357:5:361:3 | -> { ... } | calls.rb:343:8:343:8 | y | diff --git a/ruby/ql/test/library-tests/ast/control/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/ast/control/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 366b4928e753..000000000000 --- a/ruby/ql/test/library-tests/ast/control/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,15 +0,0 @@ -ambiguousReadNode -| loops.rb:9:1:12:3 | { ... } | loops.rb:2:1:2:3 | foo | -| loops.rb:9:1:12:3 | { ... } | loops.rb:3:1:3:3 | sum | -| loops.rb:9:1:12:3 | { ... } | loops.rb:9:5:9:5 | n | -| loops.rb:16:1:19:3 | { ... } | loops.rb:2:1:2:3 | foo | -| loops.rb:16:1:19:3 | { ... } | loops.rb:3:1:3:3 | sum | -| loops.rb:16:1:19:3 | { ... } | loops.rb:9:5:9:5 | n | -| loops.rb:22:1:25:3 | { ... } | loops.rb:2:1:2:3 | foo | -| loops.rb:22:1:25:3 | { ... } | loops.rb:3:1:3:3 | sum | -| loops.rb:22:1:25:3 | { ... } | loops.rb:22:5:22:7 | key | -| loops.rb:22:1:25:3 | { ... } | loops.rb:22:10:22:14 | value | -| loops.rb:28:1:32:3 | { ... } | loops.rb:2:1:2:3 | foo | -| loops.rb:28:1:32:3 | { ... } | loops.rb:3:1:3:3 | sum | -| loops.rb:28:1:32:3 | { ... } | loops.rb:22:5:22:7 | key | -| loops.rb:28:1:32:3 | { ... } | loops.rb:22:10:22:14 | value | diff --git a/ruby/ql/test/library-tests/ast/erb/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/ast/erb/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 636387e9a992..000000000000 --- a/ruby/ql/test/library-tests/ast/erb/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| template.html.erb:27:6:31:8 | { ... } | template.html.erb:25:4:25:5 | xs | -| template.html.erb:27:6:31:8 | { ... } | template.html.erb:27:10:27:10 | x | diff --git a/ruby/ql/test/library-tests/controlflow/graph/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/controlflow/graph/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 1fe0734c92df..000000000000 --- a/ruby/ql/test/library-tests/controlflow/graph/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,5 +0,0 @@ -ambiguousReadNode -| cfg.rb:90:1:93:3 | { ... } | cfg.rb:1:1:221:1 | self | -| cfg.rb:90:1:93:3 | { ... } | cfg.rb:74:1:74:1 | x | -| raise.rb:155:16:155:50 | { ... } | raise.rb:154:1:156:3 | self | -| raise.rb:155:16:155:50 | { ... } | raise.rb:154:9:154:15 | element | diff --git a/ruby/ql/test/library-tests/dataflow/array-flow/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/dataflow/array-flow/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 2af36de73337..000000000000 --- a/ruby/ql/test/library-tests/dataflow/array-flow/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| array_flow.rb:404:9:406:7 | { ... } | array_flow.rb:402:1:409:3 | self | -| array_flow.rb:404:9:406:7 | { ... } | array_flow.rb:404:13:404:13 | x | diff --git a/ruby/ql/test/library-tests/dataflow/call-sensitivity/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/dataflow/call-sensitivity/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 8861088fef5b..000000000000 --- a/ruby/ql/test/library-tests/dataflow/call-sensitivity/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| call_sensitivity.rb:75:20:77:7 | do ... end | call_sensitivity.rb:74:15:74:15 | x | -| call_sensitivity.rb:75:20:77:7 | do ... end | call_sensitivity.rb:74:18:74:18 | y | diff --git a/ruby/ql/test/library-tests/dataflow/global/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/dataflow/global/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index b454f80cd36f..000000000000 --- a/ruby/ql/test/library-tests/dataflow/global/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,85 +0,0 @@ -ambiguousReadNode -| captured_variables.rb:10:5:10:23 | ... = ... | captured_variables.rb:9:1:12:3 | self | -| captured_variables.rb:10:5:10:23 | ... = ... | captured_variables.rb:9:24:9:24 | x | -| captured_variables.rb:10:10:10:23 | -> { ... } | captured_variables.rb:9:1:12:3 | self | -| captured_variables.rb:10:10:10:23 | -> { ... } | captured_variables.rb:9:24:9:24 | x | -| captured_variables.rb:11:5:11:6 | fn | captured_variables.rb:9:1:12:3 | self | -| captured_variables.rb:11:5:11:6 | fn | captured_variables.rb:9:24:9:24 | x | -| captured_variables.rb:16:5:18:5 | -> { ... } | captured_variables.rb:15:1:19:3 | self | -| captured_variables.rb:16:5:18:5 | -> { ... } | captured_variables.rb:15:28:15:28 | x | -| captured_variables.rb:16:5:18:5 | ... | captured_variables.rb:15:1:19:3 | self | -| captured_variables.rb:16:5:18:5 | ... | captured_variables.rb:15:28:15:28 | x | -| captured_variables.rb:23:5:25:5 | -> { ... } | captured_variables.rb:22:1:26:3 | self | -| captured_variables.rb:23:5:25:5 | -> { ... } | captured_variables.rb:22:28:22:28 | x | -| captured_variables.rb:23:5:25:5 | ... | captured_variables.rb:22:1:26:3 | self | -| captured_variables.rb:23:5:25:5 | ... | captured_variables.rb:22:28:22:28 | x | -| captured_variables.rb:30:5:32:5 | ... = ... | captured_variables.rb:29:1:34:3 | self | -| captured_variables.rb:30:5:32:5 | ... = ... | captured_variables.rb:29:33:29:33 | x | -| captured_variables.rb:30:10:32:5 | -> { ... } | captured_variables.rb:29:1:34:3 | self | -| captured_variables.rb:30:10:32:5 | -> { ... } | captured_variables.rb:29:33:29:33 | x | -| captured_variables.rb:33:29:33:30 | fn | captured_variables.rb:29:1:34:3 | self | -| captured_variables.rb:33:29:33:30 | fn | captured_variables.rb:29:33:29:33 | x | -| captured_variables.rb:41:5:43:5 | ... = ... | captured_variables.rb:40:1:45:3 | self | -| captured_variables.rb:41:5:43:5 | ... = ... | captured_variables.rb:40:31:40:31 | x | -| captured_variables.rb:41:10:43:5 | -> { ... } | captured_variables.rb:40:1:45:3 | self | -| captured_variables.rb:41:10:43:5 | -> { ... } | captured_variables.rb:40:31:40:31 | x | -| captured_variables.rb:44:13:44:14 | fn | captured_variables.rb:40:1:45:3 | self | -| captured_variables.rb:44:13:44:14 | fn | captured_variables.rb:40:31:40:31 | x | -| captured_variables.rb:49:16:52:3 | do ... end | captured_variables.rb:1:1:244:2 | self | -| captured_variables.rb:49:16:52:3 | do ... end | captured_variables.rb:48:1:48:1 | x | -| captured_variables.rb:67:16:70:3 | do ... end | captured_variables.rb:1:1:244:2 | self | -| captured_variables.rb:67:16:70:3 | do ... end | captured_variables.rb:65:1:65:3 | foo | -| captured_variables.rb:78:20:80:7 | do ... end | captured_variables.rb:1:1:244:2 | self | -| captured_variables.rb:78:20:80:7 | do ... end | captured_variables.rb:65:1:65:3 | foo | -| captured_variables.rb:86:1:89:1 | ... = ... | captured_variables.rb:1:1:244:2 | self | -| captured_variables.rb:86:1:89:1 | ... = ... | captured_variables.rb:85:1:85:1 | y | -| captured_variables.rb:86:6:89:1 | -> { ... } | captured_variables.rb:1:1:244:2 | self | -| captured_variables.rb:86:6:89:1 | -> { ... } | captured_variables.rb:85:1:85:1 | y | -| captured_variables.rb:90:1:90:2 | fn | captured_variables.rb:1:1:244:2 | self | -| captured_variables.rb:90:1:90:2 | fn | captured_variables.rb:85:1:85:1 | y | -| captured_variables.rb:94:5:96:5 | -> { ... } | captured_variables.rb:93:1:97:3 | self | -| captured_variables.rb:94:5:96:5 | -> { ... } | captured_variables.rb:93:17:93:17 | x | -| captured_variables.rb:94:5:96:5 | ... | captured_variables.rb:93:1:97:3 | self | -| captured_variables.rb:94:5:96:5 | ... | captured_variables.rb:93:17:93:17 | x | -| captured_variables.rb:110:5:116:5 | ... = ... | captured_variables.rb:108:1:119:3 | self | -| captured_variables.rb:110:5:116:5 | ... = ... | captured_variables.rb:109:5:109:5 | x | -| captured_variables.rb:110:14:116:5 | -> { ... } | captured_variables.rb:108:1:119:3 | self | -| captured_variables.rb:110:14:116:5 | -> { ... } | captured_variables.rb:109:5:109:5 | x | -| captured_variables.rb:117:5:117:10 | middle | captured_variables.rb:108:1:119:3 | self | -| captured_variables.rb:117:5:117:10 | middle | captured_variables.rb:109:5:109:5 | x | -| captured_variables.rb:125:5:127:5 | ... = ... | captured_variables.rb:122:1:142:3 | self | -| captured_variables.rb:125:5:127:5 | ... = ... | captured_variables.rb:123:5:123:5 | x | -| captured_variables.rb:125:11:127:5 | -> { ... } | captured_variables.rb:122:1:142:3 | self | -| captured_variables.rb:125:11:127:5 | -> { ... } | captured_variables.rb:123:5:123:5 | x | -| captured_variables.rb:129:5:137:5 | ... = ... | captured_variables.rb:122:1:142:3 | self | -| captured_variables.rb:129:5:137:5 | ... = ... | captured_variables.rb:123:5:123:5 | x | -| captured_variables.rb:129:11:137:5 | -> { ... } | captured_variables.rb:122:1:142:3 | self | -| captured_variables.rb:129:11:137:5 | -> { ... } | captured_variables.rb:123:5:123:5 | x | -| captured_variables.rb:130:9:136:11 | ... | captured_variables.rb:129:11:137:5 | this | -| captured_variables.rb:130:9:136:11 | ... | captured_variables.rb:130:9:130:9 | y | -| captured_variables.rb:132:9:134:9 | ... = ... | captured_variables.rb:129:11:137:5 | this | -| captured_variables.rb:132:9:134:9 | ... = ... | captured_variables.rb:130:9:130:9 | y | -| captured_variables.rb:132:15:134:9 | -> { ... } | captured_variables.rb:129:11:137:5 | this | -| captured_variables.rb:132:15:134:9 | -> { ... } | captured_variables.rb:130:9:130:9 | y | -| captured_variables.rb:139:11:139:13 | fn3 | captured_variables.rb:122:1:142:3 | self | -| captured_variables.rb:139:11:139:13 | fn3 | captured_variables.rb:123:5:123:5 | x | -| captured_variables.rb:141:5:141:7 | fn1 | captured_variables.rb:122:1:142:3 | self | -| captured_variables.rb:141:5:141:7 | fn1 | captured_variables.rb:123:5:123:5 | x | -| captured_variables.rb:205:5:213:5 | ... = ... | captured_variables.rb:196:1:216:3 | self | -| captured_variables.rb:205:5:213:5 | ... = ... | captured_variables.rb:197:5:197:5 | x | -| captured_variables.rb:205:10:213:5 | -> { ... } | captured_variables.rb:196:1:216:3 | self | -| captured_variables.rb:205:10:213:5 | -> { ... } | captured_variables.rb:197:5:197:5 | x | -| captured_variables.rb:215:5:215:6 | fn | captured_variables.rb:196:1:216:3 | self | -| captured_variables.rb:215:5:215:6 | fn | captured_variables.rb:197:5:197:5 | x | -| captured_variables.rb:222:5:224:5 | ... = ... | captured_variables.rb:219:5:219:5 | x | -| captured_variables.rb:222:5:224:5 | ... = ... | captured_variables.rb:220:5:220:5 | y | -| captured_variables.rb:222:11:224:5 | -> { ... } | captured_variables.rb:219:5:219:5 | x | -| captured_variables.rb:222:11:224:5 | -> { ... } | captured_variables.rb:220:5:220:5 | y | -| captured_variables.rb:226:5:226:7 | fn1 | captured_variables.rb:219:5:219:5 | x | -| captured_variables.rb:226:5:226:7 | fn1 | captured_variables.rb:220:5:220:5 | y | -| captured_variables.rb:235:5:237:5 | ... = ... | captured_variables.rb:232:1:242:3 | self | -| captured_variables.rb:235:5:237:5 | ... = ... | captured_variables.rb:233:5:233:5 | x | -| captured_variables.rb:235:11:237:5 | -> { ... } | captured_variables.rb:232:1:242:3 | self | -| captured_variables.rb:235:11:237:5 | -> { ... } | captured_variables.rb:233:5:233:5 | x | -| captured_variables.rb:241:5:241:7 | fn1 | captured_variables.rb:232:1:242:3 | self | -| captured_variables.rb:241:5:241:7 | fn1 | captured_variables.rb:233:5:233:5 | x | diff --git a/ruby/ql/test/library-tests/dataflow/local/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/dataflow/local/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 7a65959a07bb..000000000000 --- a/ruby/ql/test/library-tests/dataflow/local/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| local_dataflow.rb:10:5:13:3 | { ... } | local_dataflow.rb:1:1:174:4 | self | -| local_dataflow.rb:10:5:13:3 | { ... } | local_dataflow.rb:10:9:10:9 | x | diff --git a/ruby/ql/test/library-tests/frameworks/action_view/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/frameworks/action_view/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index df37e38d506f..000000000000 --- a/ruby/ql/test/library-tests/frameworks/action_view/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| app/views/foo/bars/show.html.erb:10:37:12:6 | do ... end | app/views/foo/bars/show.html.erb:1:14:33:43 | self | -| app/views/foo/bars/show.html.erb:10:37:12:6 | do ... end | app/views/foo/bars/show.html.erb:6:4:6:6 | key | diff --git a/ruby/ql/test/library-tests/frameworks/rack/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/frameworks/rack/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 8fd7077be5e1..000000000000 --- a/ruby/ql/test/library-tests/frameworks/rack/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,6 +0,0 @@ -ambiguousReadNode -| rack.rb:34:32:34:69 | { ... } | rack.rb:30:3:36:5 | self | -| rack.rb:34:32:34:69 | { ... } | rack.rb:30:12:30:14 | env | -| rack.rb:34:32:34:69 | { ... } | rack.rb:31:5:31:12 | began_at | -| rack.rb:34:32:34:69 | { ... } | rack.rb:32:5:32:10 | status | -| rack.rb:34:32:34:69 | { ... } | rack.rb:32:13:32:18 | header | diff --git a/ruby/ql/test/library-tests/frameworks/sinatra/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/frameworks/sinatra/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 528b95a4a187..000000000000 --- a/ruby/ql/test/library-tests/frameworks/sinatra/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| app.rb:64:41:64:57 | { ... } | app.rb:64:21:64:59 | this | -| app.rb:64:41:64:57 | { ... } | app.rb:64:24:64:28 | value | diff --git a/ruby/ql/test/library-tests/modules/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/modules/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index fa3f6afe3fad..000000000000 --- a/ruby/ql/test/library-tests/modules/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| calls.rb:492:35:494:11 | do ... end | calls.rb:491:18:495:7 | this | -| calls.rb:492:35:494:11 | do ... end | calls.rb:491:22:491:22 | i | diff --git a/ruby/ql/test/library-tests/variables/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/library-tests/variables/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 6c2cca383f88..000000000000 --- a/ruby/ql/test/library-tests/variables/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,15 +0,0 @@ -ambiguousReadNode -| nested_scopes.rb:18:23:18:36 | { ... } | nested_scopes.rb:16:21:19:15 | this | -| nested_scopes.rb:18:23:18:36 | { ... } | nested_scopes.rb:16:29:16:29 | a | -| parameters.rb:54:9:57:3 | do ... end | parameters.rb:1:1:62:1 | self | -| parameters.rb:54:9:57:3 | do ... end | parameters.rb:53:1:53:1 | x | -| scopes.rb:9:9:18:3 | do ... end | scopes.rb:1:1:89:4 | self | -| scopes.rb:9:9:18:3 | do ... end | scopes.rb:7:1:7:1 | a | -| ssa.rb:26:3:28:5 | { ... } | ssa.rb:25:1:30:3 | self | -| ssa.rb:26:3:28:5 | { ... } | ssa.rb:26:7:26:10 | elem | -| ssa.rb:66:11:70:5 | do ... end | ssa.rb:64:1:72:3 | self | -| ssa.rb:66:11:70:5 | do ... end | ssa.rb:65:3:65:10 | captured | -| ssa.rb:76:7:78:5 | do ... end | ssa.rb:74:1:79:3 | self | -| ssa.rb:76:7:78:5 | do ... end | ssa.rb:75:3:75:10 | captured | -| ssa.rb:83:7:87:5 | do ... end | ssa.rb:81:1:88:3 | self | -| ssa.rb:83:7:87:5 | do ... end | ssa.rb:82:3:82:10 | captured | diff --git a/ruby/ql/test/query-tests/experimental/InsecureRandomness/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/query-tests/experimental/InsecureRandomness/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index bc17a7c2a860..000000000000 --- a/ruby/ql/test/query-tests/experimental/InsecureRandomness/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| InsecureRandomness.rb:6:34:6:60 | { ... } | InsecureRandomness.rb:3:1:7:3 | self | -| InsecureRandomness.rb:6:34:6:60 | { ... } | InsecureRandomness.rb:4:3:4:7 | chars | diff --git a/ruby/ql/test/query-tests/experimental/improper-memoization/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/query-tests/experimental/improper-memoization/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 19f2d36a5fd6..000000000000 --- a/ruby/ql/test/query-tests/experimental/improper-memoization/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,5 +0,0 @@ -ambiguousReadNode -| improper_memoization.rb:42:25:44:7 | do ... end | improper_memoization.rb:41:20:45:5 | this | -| improper_memoization.rb:42:25:44:7 | do ... end | improper_memoization.rb:41:28:41:31 | arg1 | -| improper_memoization.rb:83:21:85:5 | do ... end | improper_memoization.rb:82:1:87:3 | self | -| improper_memoization.rb:83:21:85:5 | do ... end | improper_memoization.rb:82:15:82:18 | arg2 | diff --git a/ruby/ql/test/query-tests/security/cwe-079/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/query-tests/security/cwe-079/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index f595abd76408..000000000000 --- a/ruby/ql/test/query-tests/security/cwe-079/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,5 +0,0 @@ -ambiguousReadNode -| app/views/foo/bars/show.html.erb:15:4:18:6 | { ... } | app/views/foo/bars/show.html.erb:2:14:89:48 | self | -| app/views/foo/bars/show.html.erb:15:4:18:6 | { ... } | app/views/foo/bars/show.html.erb:10:4:10:6 | key | -| app/views/foo/stores/show.html.erb:12:4:15:6 | { ... } | app/views/foo/stores/show.html.erb:2:5:90:48 | self | -| app/views/foo/stores/show.html.erb:12:4:15:6 | { ... } | app/views/foo/stores/show.html.erb:7:4:7:6 | key | diff --git a/ruby/ql/test/query-tests/variables/DeadStoreOfLocal/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/query-tests/variables/DeadStoreOfLocal/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index e9dd3ea8adfe..000000000000 --- a/ruby/ql/test/query-tests/variables/DeadStoreOfLocal/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,5 +0,0 @@ -ambiguousReadNode -| DeadStoreOfLocal.rb:44:14:47:7 | do ... end | DeadStoreOfLocal.rb:43:1:48:3 | self | -| DeadStoreOfLocal.rb:44:14:47:7 | do ... end | DeadStoreOfLocal.rb:43:20:43:20 | x | -| DeadStoreOfLocal.rb:57:16:65:7 | do ... end | DeadStoreOfLocal.rb:56:1:66:3 | self | -| DeadStoreOfLocal.rb:57:16:65:7 | do ... end | DeadStoreOfLocal.rb:56:17:56:17 | x | diff --git a/ruby/ql/test/query-tests/variables/UninitializedLocal/CONSISTENCY/VariablesConsistency.expected b/ruby/ql/test/query-tests/variables/UninitializedLocal/CONSISTENCY/VariablesConsistency.expected deleted file mode 100644 index 4193d87746f6..000000000000 --- a/ruby/ql/test/query-tests/variables/UninitializedLocal/CONSISTENCY/VariablesConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| UninitializedLocal.rb:73:5:75:7 | { ... } | UninitializedLocal.rb:72:1:77:3 | self | -| UninitializedLocal.rb:73:5:75:7 | { ... } | UninitializedLocal.rb:73:9:73:9 | i | diff --git a/rust/ql/test/library-tests/controlflow/CONSISTENCY/VariableCaptureConsistency.expected b/rust/ql/test/library-tests/controlflow/CONSISTENCY/VariableCaptureConsistency.expected deleted file mode 100644 index 87bc24d5e5a6..000000000000 --- a/rust/ql/test/library-tests/controlflow/CONSISTENCY/VariableCaptureConsistency.expected +++ /dev/null @@ -1,3 +0,0 @@ -ambiguousReadNode -| test.rs:511:28:516:9 | { ... } | test.rs:511:22:516:9 | this | -| test.rs:511:28:516:9 | { ... } | test.rs:511:23:511:25 | foo | diff --git a/rust/ql/test/query-tests/security/CWE-825/CONSISTENCY/VariableCaptureConsistency.expected b/rust/ql/test/query-tests/security/CWE-825/CONSISTENCY/VariableCaptureConsistency.expected deleted file mode 100644 index b8abfaf72c0e..000000000000 --- a/rust/ql/test/query-tests/security/CWE-825/CONSISTENCY/VariableCaptureConsistency.expected +++ /dev/null @@ -1,17 +0,0 @@ -ambiguousReadNode -| lifetime.rs:514:2:527:2 | return ... | lifetime.rs:509:16:509:17 | p3 | -| lifetime.rs:514:2:527:2 | return ... | lifetime.rs:509:32:509:33 | p4 | -| lifetime.rs:514:2:527:2 | return ... | lifetime.rs:511:6:511:14 | my_local2 | -| lifetime.rs:514:2:527:2 | return ... | lifetime.rs:512:6:512:7 | p1 | -| lifetime.rs:514:9:527:2 | \|...\| ... | lifetime.rs:509:16:509:17 | p3 | -| lifetime.rs:514:9:527:2 | \|...\| ... | lifetime.rs:509:32:509:33 | p4 | -| lifetime.rs:514:9:527:2 | \|...\| ... | lifetime.rs:511:6:511:14 | my_local2 | -| lifetime.rs:514:9:527:2 | \|...\| ... | lifetime.rs:512:6:512:7 | p1 | -| lifetime.rs:567:2:580:2 | return ... | lifetime.rs:562:22:562:23 | p3 | -| lifetime.rs:567:2:580:2 | return ... | lifetime.rs:562:38:562:39 | p4 | -| lifetime.rs:567:2:580:2 | return ... | lifetime.rs:564:6:564:14 | my_local2 | -| lifetime.rs:567:2:580:2 | return ... | lifetime.rs:565:6:565:7 | p1 | -| lifetime.rs:567:9:580:2 | { ... } | lifetime.rs:562:22:562:23 | p3 | -| lifetime.rs:567:9:580:2 | { ... } | lifetime.rs:562:38:562:39 | p4 | -| lifetime.rs:567:9:580:2 | { ... } | lifetime.rs:564:6:564:14 | my_local2 | -| lifetime.rs:567:9:580:2 | { ... } | lifetime.rs:565:6:565:7 | p1 | From 649e8ccca8d85303f6df4e56c979c073b66f4363 Mon Sep 17 00:00:00 2001 From: Asger F Date: Fri, 2 Oct 2026 16:16:44 +0200 Subject: [PATCH 08/11] unified: Update local SSA consistency output Unified also had consistency errors from its LocalSSA instantiation, due to its use of synthetic read nodes to represent post-update positions. Many variables can have a post-update at the same CFG node. --- .../CONSISTENCY/LocalSsaConsistency.expected | 25 -- .../CONSISTENCY/LocalSsaConsistency.expected | 5 - .../CONSISTENCY/LocalSsaConsistency.expected | 5 - .../CONSISTENCY/LocalSsaConsistency.expected | 18 - .../CONSISTENCY/LocalSsaConsistency.expected | 41 --- .../CONSISTENCY/LocalSsaConsistency.expected | 347 ------------------ 6 files changed, 441 deletions(-) diff --git a/unified/ql/test/library-tests/BasicTest/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/BasicTest/CONSISTENCY/LocalSsaConsistency.expected index 32f5189788a0..e69de29bb2d1 100644 --- a/unified/ql/test/library-tests/BasicTest/CONSISTENCY/LocalSsaConsistency.expected +++ b/unified/ql/test/library-tests/BasicTest/CONSISTENCY/LocalSsaConsistency.expected @@ -1,25 +0,0 @@ -ambiguousReadNode -| test.swift:8:9:8:26 | [variable post-update] item | test.swift:7:5:9:5 | self | -| test.swift:8:9:8:26 | [variable post-update] item | test.swift:7:25:7:28 | item | -| test.swift:8:9:8:26 | [variable post-update] self | test.swift:7:5:9:5 | self | -| test.swift:8:9:8:26 | [variable post-update] self | test.swift:7:25:7:28 | item | -| test.swift:12:16:12:35 | [variable post-update] item | test.swift:11:5:13:5 | self | -| test.swift:12:16:12:35 | [variable post-update] item | test.swift:11:21:11:24 | item | -| test.swift:12:16:12:35 | [variable post-update] self | test.swift:11:5:13:5 | self | -| test.swift:12:16:12:35 | [variable post-update] self | test.swift:11:21:11:24 | item | -| test.swift:27:13:27:33 | [variable post-update] item | test.swift:25:9:25:14 | result | -| test.swift:27:13:27:33 | [variable post-update] item | test.swift:26:9:26:12 | item | -| test.swift:27:13:27:33 | [variable post-update] result | test.swift:25:9:25:14 | result | -| test.swift:27:13:27:33 | [variable post-update] result | test.swift:26:9:26:12 | item | -| test.swift:28:13:28:31 | [variable post-update] item | test.swift:25:9:25:14 | result | -| test.swift:28:13:28:31 | [variable post-update] item | test.swift:26:9:26:12 | item | -| test.swift:28:13:28:31 | [variable post-update] result | test.swift:25:9:25:14 | result | -| test.swift:28:13:28:31 | [variable post-update] result | test.swift:26:9:26:12 | item | -| test.swift:49:16:49:26 | [variable post-update] index | test.swift:47:5:50:5 | self | -| test.swift:49:16:49:26 | [variable post-update] index | test.swift:47:18:47:22 | index | -| test.swift:49:16:49:26 | [variable post-update] self | test.swift:47:5:50:5 | self | -| test.swift:49:16:49:26 | [variable post-update] self | test.swift:47:18:47:22 | index | -| test.swift:53:9:53:25 | [variable post-update] item | test.swift:52:5:54:5 | self | -| test.swift:53:9:53:25 | [variable post-update] item | test.swift:52:16:52:19 | item | -| test.swift:53:9:53:25 | [variable post-update] self | test.swift:52:5:54:5 | self | -| test.swift:53:9:53:25 | [variable post-update] self | test.swift:52:16:52:19 | item | diff --git a/unified/ql/test/library-tests/constructors/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/constructors/CONSISTENCY/LocalSsaConsistency.expected index bbb75f55a047..e69de29bb2d1 100644 --- a/unified/ql/test/library-tests/constructors/CONSISTENCY/LocalSsaConsistency.expected +++ b/unified/ql/test/library-tests/constructors/CONSISTENCY/LocalSsaConsistency.expected @@ -1,5 +0,0 @@ -ambiguousReadNode -| constructors.swift:35:9:35:29 | [variable post-update] self | constructors.swift:34:5:36:5 | self | -| constructors.swift:35:9:35:29 | [variable post-update] self | constructors.swift:34:22:34:22 | x | -| constructors.swift:35:9:35:29 | [variable post-update] x | constructors.swift:34:5:36:5 | self | -| constructors.swift:35:9:35:29 | [variable post-update] x | constructors.swift:34:22:34:22 | x | diff --git a/unified/ql/test/library-tests/dataflow/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/dataflow/CONSISTENCY/LocalSsaConsistency.expected index cc9c71d9b150..e69de29bb2d1 100644 --- a/unified/ql/test/library-tests/dataflow/CONSISTENCY/LocalSsaConsistency.expected +++ b/unified/ql/test/library-tests/dataflow/CONSISTENCY/LocalSsaConsistency.expected @@ -1,5 +0,0 @@ -ambiguousReadNode -| test.swift:184:5:184:19 | [variable post-update] x | test.swift:182:9:182:9 | x | -| test.swift:184:5:184:19 | [variable post-update] x | test.swift:183:9:183:9 | y | -| test.swift:184:5:184:19 | [variable post-update] y | test.swift:182:9:182:9 | x | -| test.swift:184:5:184:19 | [variable post-update] y | test.swift:183:9:183:9 | y | diff --git a/unified/ql/test/library-tests/mad/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/mad/CONSISTENCY/LocalSsaConsistency.expected index 6a0d83888e90..e69de29bb2d1 100644 --- a/unified/ql/test/library-tests/mad/CONSISTENCY/LocalSsaConsistency.expected +++ b/unified/ql/test/library-tests/mad/CONSISTENCY/LocalSsaConsistency.expected @@ -1,18 +0,0 @@ -ambiguousReadNode -| test.swift:74:9:84:31 | [variable post-update] encryptionKey | test.swift:67:5:67:17 | encryptionKey | -| test.swift:74:9:84:31 | [variable post-update] encryptionKey | test.swift:68:5:68:11 | fileURL | -| test.swift:74:9:84:31 | [variable post-update] fileURL | test.swift:67:5:67:17 | encryptionKey | -| test.swift:74:9:84:31 | [variable post-update] fileURL | test.swift:68:5:68:11 | fileURL | -| test.swift:86:9:96:31 | [variable post-update] encryptionKey | test.swift:67:5:67:17 | encryptionKey | -| test.swift:86:9:96:31 | [variable post-update] encryptionKey | test.swift:68:5:68:11 | fileURL | -| test.swift:86:9:96:31 | [variable post-update] fileURL | test.swift:67:5:67:17 | encryptionKey | -| test.swift:86:9:96:31 | [variable post-update] fileURL | test.swift:68:5:68:11 | fileURL | -| test.swift:98:9:109:31 | [variable post-update] encryptionKey | test.swift:67:5:67:17 | encryptionKey | -| test.swift:98:9:109:31 | [variable post-update] encryptionKey | test.swift:68:5:68:11 | fileURL | -| test.swift:98:9:109:31 | [variable post-update] encryptionKey | test.swift:69:5:69:16 | seedFilePath | -| test.swift:98:9:109:31 | [variable post-update] fileURL | test.swift:67:5:67:17 | encryptionKey | -| test.swift:98:9:109:31 | [variable post-update] fileURL | test.swift:68:5:68:11 | fileURL | -| test.swift:98:9:109:31 | [variable post-update] fileURL | test.swift:69:5:69:16 | seedFilePath | -| test.swift:98:9:109:31 | [variable post-update] seedFilePath | test.swift:67:5:67:17 | encryptionKey | -| test.swift:98:9:109:31 | [variable post-update] seedFilePath | test.swift:68:5:68:11 | fileURL | -| test.swift:98:9:109:31 | [variable post-update] seedFilePath | test.swift:69:5:69:16 | seedFilePath | diff --git a/unified/ql/test/library-tests/type-inference/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/library-tests/type-inference/CONSISTENCY/LocalSsaConsistency.expected index b48e15341459..e69de29bb2d1 100644 --- a/unified/ql/test/library-tests/type-inference/CONSISTENCY/LocalSsaConsistency.expected +++ b/unified/ql/test/library-tests/type-inference/CONSISTENCY/LocalSsaConsistency.expected @@ -1,41 +0,0 @@ -ambiguousReadNode -| closures.swift:47:9:47:21 | [variable post-update] self | closures.swift:45:5:49:5 | self | -| closures.swift:47:9:47:21 | [variable post-update] self | closures.swift:45:24:45:28 | value | -| closures.swift:47:9:47:21 | [variable post-update] value | closures.swift:45:5:49:5 | self | -| closures.swift:47:9:47:21 | [variable post-update] value | closures.swift:45:24:45:28 | value | -| closures.swift:48:16:48:29 | [variable post-update] self | closures.swift:45:5:49:5 | self | -| closures.swift:48:16:48:29 | [variable post-update] self | closures.swift:45:24:45:28 | value | -| closures.swift:48:16:48:29 | [variable post-update] value | closures.swift:45:5:49:5 | self | -| closures.swift:48:16:48:29 | [variable post-update] value | closures.swift:45:24:45:28 | value | -| generics.swift:156:5:156:22 | [variable post-update] v1 | generics.swift:155:10:155:11 | v1 | -| generics.swift:156:5:156:22 | [variable post-update] v1 | generics.swift:155:20:155:21 | v2 | -| generics.swift:156:5:156:22 | [variable post-update] v2 | generics.swift:155:10:155:11 | v1 | -| generics.swift:156:5:156:22 | [variable post-update] v2 | generics.swift:155:20:155:21 | v2 | -| key_paths.swift:44:14:44:35 | [variable post-update] e | key_paths.swift:42:7:42:7 | s | -| key_paths.swift:44:14:44:35 | [variable post-update] e | key_paths.swift:43:7:43:7 | e | -| key_paths.swift:44:14:44:35 | [variable post-update] s | key_paths.swift:42:7:42:7 | s | -| key_paths.swift:44:14:44:35 | [variable post-update] s | key_paths.swift:43:7:43:7 | e | -| key_paths.swift:142:18:142:45 | [variable post-update] kpStart | key_paths.swift:140:7:140:13 | kpStart | -| key_paths.swift:142:18:142:45 | [variable post-update] kpStart | key_paths.swift:141:7:141:9 | kpX | -| key_paths.swift:142:18:142:45 | [variable post-update] kpX | key_paths.swift:140:7:140:13 | kpStart | -| key_paths.swift:142:18:142:45 | [variable post-update] kpX | key_paths.swift:141:7:141:9 | kpX | -| key_paths.swift:146:14:146:35 | [variable post-update] e | key_paths.swift:144:7:144:7 | s | -| key_paths.swift:146:14:146:35 | [variable post-update] e | key_paths.swift:145:7:145:7 | e | -| key_paths.swift:146:14:146:35 | [variable post-update] s | key_paths.swift:144:7:144:7 | s | -| key_paths.swift:146:14:146:35 | [variable post-update] s | key_paths.swift:145:7:145:7 | e | -| overload_resolution.swift:371:5:371:34 | [variable post-update] name | overload_resolution.swift:370:3:372:3 | self | -| overload_resolution.swift:371:5:371:34 | [variable post-update] name | overload_resolution.swift:370:20:370:23 | name | -| overload_resolution.swift:371:5:371:34 | [variable post-update] self | overload_resolution.swift:370:3:372:3 | self | -| overload_resolution.swift:371:5:371:34 | [variable post-update] self | overload_resolution.swift:370:20:370:23 | name | -| overload_resolution.swift:375:5:375:42 | [variable post-update] self | overload_resolution.swift:374:3:376:3 | self | -| overload_resolution.swift:375:5:375:42 | [variable post-update] self | overload_resolution.swift:374:20:374:23 | size | -| overload_resolution.swift:375:5:375:42 | [variable post-update] size | overload_resolution.swift:374:3:376:3 | self | -| overload_resolution.swift:375:5:375:42 | [variable post-update] size | overload_resolution.swift:374:20:374:23 | size | -| overload_resolution.swift:415:12:415:22 | [variable post-update] index | overload_resolution.swift:414:3:416:3 | self | -| overload_resolution.swift:415:12:415:22 | [variable post-update] index | overload_resolution.swift:414:14:414:18 | index | -| overload_resolution.swift:415:12:415:22 | [variable post-update] self | overload_resolution.swift:414:3:416:3 | self | -| overload_resolution.swift:415:12:415:22 | [variable post-update] self | overload_resolution.swift:414:14:414:18 | index | -| overload_resolution.swift:419:12:419:20 | [variable post-update] key | overload_resolution.swift:418:3:420:3 | self | -| overload_resolution.swift:419:12:419:20 | [variable post-update] key | overload_resolution.swift:418:14:418:16 | key | -| overload_resolution.swift:419:12:419:20 | [variable post-update] self | overload_resolution.swift:418:3:420:3 | self | -| overload_resolution.swift:419:12:419:20 | [variable post-update] self | overload_resolution.swift:418:14:418:16 | key | diff --git a/unified/ql/test/query-tests/security/CWE-022/PathInjection/CONSISTENCY/LocalSsaConsistency.expected b/unified/ql/test/query-tests/security/CWE-022/PathInjection/CONSISTENCY/LocalSsaConsistency.expected index 173907e3ef5a..e69de29bb2d1 100644 --- a/unified/ql/test/query-tests/security/CWE-022/PathInjection/CONSISTENCY/LocalSsaConsistency.expected +++ b/unified/ql/test/query-tests/security/CWE-022/PathInjection/CONSISTENCY/LocalSsaConsistency.expected @@ -1,347 +0,0 @@ -ambiguousReadNode -| testPathInjection.swift:43:9:43:23 | [variable post-update] data | testPathInjection.swift:41:5:44:5 | self | -| testPathInjection.swift:43:9:43:23 | [variable post-update] data | testPathInjection.swift:42:13:42:16 | data | -| testPathInjection.swift:43:9:43:23 | [variable post-update] self | testPathInjection.swift:41:5:44:5 | self | -| testPathInjection.swift:43:9:43:23 | [variable post-update] self | testPathInjection.swift:42:13:42:16 | data | -| testPathInjection.swift:244:9:244:49 | [variable post-update] ascending | testPathInjection.swift:243:5:245:5 | self | -| testPathInjection.swift:244:9:244:49 | [variable post-update] ascending | testPathInjection.swift:243:66:243:74 | ascending | -| testPathInjection.swift:244:9:244:49 | [variable post-update] self | testPathInjection.swift:243:5:245:5 | self | -| testPathInjection.swift:244:9:244:49 | [variable post-update] self | testPathInjection.swift:243:66:243:74 | ascending | -| testPathInjection.swift:349:13:349:58 | [variable post-update] nsData | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:349:13:349:58 | [variable post-update] nsData | testPathInjection.swift:348:9:348:14 | nsData | -| testPathInjection.swift:349:13:349:58 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:349:13:349:58 | [variable post-update] remoteUrl | testPathInjection.swift:348:9:348:14 | nsData | -| testPathInjection.swift:350:5:350:44 | [variable post-update] nsData | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:350:5:350:44 | [variable post-update] nsData | testPathInjection.swift:348:9:348:14 | nsData | -| testPathInjection.swift:350:5:350:44 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:350:5:350:44 | [variable post-update] remoteUrl | testPathInjection.swift:348:9:348:14 | nsData | -| testPathInjection.swift:351:13:351:65 | [variable post-update] nsData | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:351:13:351:65 | [variable post-update] nsData | testPathInjection.swift:348:9:348:14 | nsData | -| testPathInjection.swift:351:13:351:65 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:351:13:351:65 | [variable post-update] remoteString | testPathInjection.swift:348:9:348:14 | nsData | -| testPathInjection.swift:352:5:352:51 | [variable post-update] nsData | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:352:5:352:51 | [variable post-update] nsData | testPathInjection.swift:348:9:348:14 | nsData | -| testPathInjection.swift:352:5:352:51 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:352:5:352:51 | [variable post-update] remoteString | testPathInjection.swift:348:9:348:14 | nsData | -| testPathInjection.swift:355:13:355:94 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:355:13:355:94 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:355:13:355:94 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:355:13:355:94 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:356:13:356:56 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:356:13:356:56 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:356:13:356:56 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:356:13:356:56 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:357:13:358:86 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:357:13:358:86 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:357:13:358:86 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:357:13:358:86 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:359:13:359:47 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:359:13:359:47 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:359:13:359:47 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:359:13:359:47 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:360:13:360:56 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:360:13:360:56 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:360:13:360:56 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:360:13:360:56 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:361:13:361:45 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:361:13:361:45 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:361:13:361:45 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:361:13:361:45 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:362:5:362:90 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:362:5:362:90 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:362:5:362:90 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:362:5:362:90 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:363:13:363:69 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:363:13:363:69 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:363:13:363:69 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:363:13:363:69 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:364:13:364:79 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:364:13:364:79 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:364:13:364:79 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:364:13:364:79 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:365:5:365:32 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:365:5:365:32 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:365:5:365:32 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:365:5:365:32 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:366:5:366:39 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:366:5:366:39 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:366:5:366:39 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:366:5:366:39 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:367:5:367:94 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:367:5:367:94 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:367:5:367:94 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:367:5:367:94 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:368:13:368:94 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:368:13:368:94 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:368:13:368:94 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:368:13:368:94 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:368:13:368:94 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:368:13:368:94 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:368:13:368:94 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:368:13:368:94 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:368:13:368:94 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:369:13:369:94 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:369:13:369:94 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:369:13:369:94 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:369:13:369:94 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:369:13:369:94 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:369:13:369:94 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:369:13:369:94 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:369:13:369:94 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:369:13:369:94 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:370:5:372:70 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:370:5:372:70 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:370:5:372:70 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:370:5:372:70 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:370:5:372:70 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:370:5:372:70 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:370:5:372:70 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:370:5:372:70 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:370:5:372:70 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:373:5:375:70 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:373:5:375:70 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:373:5:375:70 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:373:5:375:70 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:373:5:375:70 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:373:5:375:70 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:373:5:375:70 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:373:5:375:70 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:373:5:375:70 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:376:5:376:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:376:5:376:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:376:5:376:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:376:5:376:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:376:5:376:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:376:5:376:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:376:5:376:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:376:5:376:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:376:5:376:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:377:5:377:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:377:5:377:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:377:5:377:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:377:5:377:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:377:5:377:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:377:5:377:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:377:5:377:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:377:5:377:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:377:5:377:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:378:5:378:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:378:5:378:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:378:5:378:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:378:5:378:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:379:5:379:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:379:5:379:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:379:5:379:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:379:5:379:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:380:5:380:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:380:5:380:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:380:5:380:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:380:5:380:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:380:5:380:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:380:5:380:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:380:5:380:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:380:5:380:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:380:5:380:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:381:5:381:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:381:5:381:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:381:5:381:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:381:5:381:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:381:5:381:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:381:5:381:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:381:5:381:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:381:5:381:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:381:5:381:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:382:5:382:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:382:5:382:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:382:5:382:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:382:5:382:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:383:5:383:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:383:5:383:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:383:5:383:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:383:5:383:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:384:5:384:69 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:384:5:384:69 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:384:5:384:69 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:384:5:384:69 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:384:5:384:69 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:384:5:384:69 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:384:5:384:69 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:384:5:384:69 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:384:5:384:69 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:385:5:385:69 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:385:5:385:69 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:385:5:385:69 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:385:5:385:69 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:385:5:385:69 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:385:5:385:69 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:385:5:385:69 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:385:5:385:69 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:385:5:385:69 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:386:5:386:72 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:386:5:386:72 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:386:5:386:72 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:386:5:386:72 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:387:5:387:72 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:387:5:387:72 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:387:5:387:72 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:387:5:387:72 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:388:5:388:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:388:5:388:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:388:5:388:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:388:5:388:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:388:5:388:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:388:5:388:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:388:5:388:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:388:5:388:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:388:5:388:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:389:5:389:43 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:389:5:389:43 | [variable post-update] fm | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:389:5:389:43 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:389:5:389:43 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:389:5:389:43 | [variable post-update] remoteUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:389:5:389:43 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:389:5:389:43 | [variable post-update] safeUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:389:5:389:43 | [variable post-update] safeUrl | testPathInjection.swift:343:9:343:15 | safeUrl | -| testPathInjection.swift:389:5:389:43 | [variable post-update] safeUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:390:5:390:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:390:5:390:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:390:5:390:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:390:5:390:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:391:5:391:49 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:391:5:391:49 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:391:5:391:49 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:391:5:391:49 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:392:13:392:62 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:392:13:392:62 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:392:13:392:62 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:392:13:392:62 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:393:13:393:47 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:393:13:393:47 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:393:13:393:47 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:393:13:393:47 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:394:13:395:94 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:394:13:395:94 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:394:13:395:94 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:394:13:395:94 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:396:5:396:53 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:396:5:396:53 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:396:5:396:53 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:396:5:396:53 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:397:13:397:45 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:397:13:397:45 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:397:13:397:45 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:397:13:397:45 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:398:13:398:63 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:398:13:398:63 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:398:13:398:63 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:398:13:398:63 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:399:13:399:63 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:399:13:399:63 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:399:13:399:63 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:399:13:399:63 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:400:13:400:55 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:400:13:400:55 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:400:13:400:55 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:400:13:400:55 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:401:13:401:85 | [variable post-update] fm | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:401:13:401:85 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:401:13:401:85 | [variable post-update] remoteUrl | testPathInjection.swift:341:9:341:17 | remoteUrl | -| testPathInjection.swift:401:13:401:85 | [variable post-update] remoteUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:403:13:403:62 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:403:13:403:62 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:403:13:403:62 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:403:13:403:62 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:404:13:404:54 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:404:13:404:54 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:404:13:404:54 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:404:13:404:54 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:405:13:405:69 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:405:13:405:69 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:405:13:405:69 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:405:13:405:69 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:406:13:406:72 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:406:13:406:72 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:406:13:406:72 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:406:13:406:72 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:407:13:407:72 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:407:13:407:72 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:407:13:407:72 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:407:13:407:72 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:408:13:408:62 | [variable post-update] fm | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:408:13:408:62 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:408:13:408:62 | [variable post-update] remoteString | testPathInjection.swift:340:9:340:20 | remoteString | -| testPathInjection.swift:408:13:408:62 | [variable post-update] remoteString | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:409:13:410:97 | [variable post-update] fm | testPathInjection.swift:342:9:342:19 | remoteNsUrl | -| testPathInjection.swift:409:13:410:97 | [variable post-update] fm | testPathInjection.swift:344:9:344:17 | safeNsUrl | -| testPathInjection.swift:409:13:410:97 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:409:13:410:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:342:9:342:19 | remoteNsUrl | -| testPathInjection.swift:409:13:410:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:344:9:344:17 | safeNsUrl | -| testPathInjection.swift:409:13:410:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:409:13:410:97 | [variable post-update] safeNsUrl | testPathInjection.swift:342:9:342:19 | remoteNsUrl | -| testPathInjection.swift:409:13:410:97 | [variable post-update] safeNsUrl | testPathInjection.swift:344:9:344:17 | safeNsUrl | -| testPathInjection.swift:409:13:410:97 | [variable post-update] safeNsUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:411:13:412:97 | [variable post-update] fm | testPathInjection.swift:342:9:342:19 | remoteNsUrl | -| testPathInjection.swift:411:13:412:97 | [variable post-update] fm | testPathInjection.swift:344:9:344:17 | safeNsUrl | -| testPathInjection.swift:411:13:412:97 | [variable post-update] fm | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:411:13:412:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:342:9:342:19 | remoteNsUrl | -| testPathInjection.swift:411:13:412:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:344:9:344:17 | safeNsUrl | -| testPathInjection.swift:411:13:412:97 | [variable post-update] remoteNsUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:411:13:412:97 | [variable post-update] safeNsUrl | testPathInjection.swift:342:9:342:19 | remoteNsUrl | -| testPathInjection.swift:411:13:412:97 | [variable post-update] safeNsUrl | testPathInjection.swift:344:9:344:17 | safeNsUrl | -| testPathInjection.swift:411:13:412:97 | [variable post-update] safeNsUrl | testPathInjection.swift:354:9:354:10 | fm | -| testPathInjection.swift:478:5:478:60 | [variable post-update] buffer1 | testPathInjection.swift:339:11:339:17 | buffer1 | -| testPathInjection.swift:478:5:478:60 | [variable post-update] buffer1 | testPathInjection.swift:476:9:476:17 | localData | -| testPathInjection.swift:478:5:478:60 | [variable post-update] localData | testPathInjection.swift:339:11:339:17 | buffer1 | -| testPathInjection.swift:478:5:478:60 | [variable post-update] localData | testPathInjection.swift:339:11:339:17 | buffer1 | -| testPathInjection.swift:478:5:478:60 | [variable post-update] localData | testPathInjection.swift:476:9:476:17 | localData | -| testPathInjection.swift:478:5:478:60 | [variable post-update] localData | testPathInjection.swift:476:9:476:17 | localData | -| testPathInjection.swift:479:5:479:62 | [variable post-update] buffer2 | testPathInjection.swift:339:49:339:55 | buffer2 | -| testPathInjection.swift:479:5:479:62 | [variable post-update] buffer2 | testPathInjection.swift:477:9:477:18 | remoteData | -| testPathInjection.swift:479:5:479:62 | [variable post-update] remoteData | testPathInjection.swift:339:49:339:55 | buffer2 | -| testPathInjection.swift:479:5:479:62 | [variable post-update] remoteData | testPathInjection.swift:339:49:339:55 | buffer2 | -| testPathInjection.swift:479:5:479:62 | [variable post-update] remoteData | testPathInjection.swift:477:9:477:18 | remoteData | -| testPathInjection.swift:479:5:479:62 | [variable post-update] remoteData | testPathInjection.swift:477:9:477:18 | remoteData | -| testPathInjection.swift:510:17:510:49 | [variable post-update] fm | testPathInjection.swift:504:9:504:20 | remoteString | -| testPathInjection.swift:510:17:510:49 | [variable post-update] fm | testPathInjection.swift:506:9:506:10 | fm | -| testPathInjection.swift:510:17:510:49 | [variable post-update] remoteString | testPathInjection.swift:504:9:504:20 | remoteString | -| testPathInjection.swift:510:17:510:49 | [variable post-update] remoteString | testPathInjection.swift:506:9:506:10 | fm | -| testPathInjection.swift:512:13:512:45 | [variable post-update] fm | testPathInjection.swift:504:9:504:20 | remoteString | -| testPathInjection.swift:512:13:512:45 | [variable post-update] fm | testPathInjection.swift:506:9:506:10 | fm | -| testPathInjection.swift:512:13:512:45 | [variable post-update] remoteString | testPathInjection.swift:504:9:504:20 | remoteString | -| testPathInjection.swift:512:13:512:45 | [variable post-update] remoteString | testPathInjection.swift:506:9:506:10 | fm | -| testPathInjection.swift:524:28:524:66 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:524:28:524:66 | [variable post-update] remoteString | testPathInjection.swift:521:9:521:10 | u1 | -| testPathInjection.swift:524:28:524:66 | [variable post-update] u1 | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:524:28:524:66 | [variable post-update] u1 | testPathInjection.swift:521:9:521:10 | u1 | -| testPathInjection.swift:525:28:525:66 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:525:28:525:66 | [variable post-update] remoteString | testPathInjection.swift:521:9:521:10 | u1 | -| testPathInjection.swift:525:28:525:66 | [variable post-update] u1 | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:525:28:525:66 | [variable post-update] u1 | testPathInjection.swift:521:9:521:10 | u1 | -| testPathInjection.swift:526:5:526:40 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:526:5:526:40 | [variable post-update] remoteString | testPathInjection.swift:521:9:521:10 | u1 | -| testPathInjection.swift:526:5:526:40 | [variable post-update] u1 | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:526:5:526:40 | [variable post-update] u1 | testPathInjection.swift:521:9:521:10 | u1 | -| testPathInjection.swift:535:24:535:62 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:535:24:535:62 | [variable post-update] remoteString | testPathInjection.swift:532:9:532:10 | u3 | -| testPathInjection.swift:535:24:535:62 | [variable post-update] u3 | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:535:24:535:62 | [variable post-update] u3 | testPathInjection.swift:532:9:532:10 | u3 | -| testPathInjection.swift:554:9:555:75 | [variable post-update] remoteString | testPathInjection.swift:517:5:517:6 | s3 | -| testPathInjection.swift:554:9:555:75 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:554:9:555:75 | [variable post-update] s3 | testPathInjection.swift:517:5:517:6 | s3 | -| testPathInjection.swift:554:9:555:75 | [variable post-update] s3 | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:559:9:559:67 | [variable post-update] fm | testPathInjection.swift:517:39:517:40 | fm | -| testPathInjection.swift:559:9:559:67 | [variable post-update] fm | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:559:9:559:67 | [variable post-update] remoteString | testPathInjection.swift:517:39:517:40 | fm | -| testPathInjection.swift:559:9:559:67 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:560:13:560:53 | [variable post-update] fm | testPathInjection.swift:517:39:517:40 | fm | -| testPathInjection.swift:560:13:560:53 | [variable post-update] fm | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:560:13:560:53 | [variable post-update] remoteString | testPathInjection.swift:517:39:517:40 | fm | -| testPathInjection.swift:560:13:560:53 | [variable post-update] remoteString | testPathInjection.swift:519:9:519:20 | remoteString | -| testPathInjection.swift:587:5:587:41 | [variable post-update] mc | testPathInjection.swift:580:9:580:20 | remoteString | -| testPathInjection.swift:587:5:587:41 | [variable post-update] mc | testPathInjection.swift:586:9:586:10 | mc | -| testPathInjection.swift:587:5:587:41 | [variable post-update] remoteString | testPathInjection.swift:580:9:580:20 | remoteString | -| testPathInjection.swift:587:5:587:41 | [variable post-update] remoteString | testPathInjection.swift:586:9:586:10 | mc | -| testPathInjection.swift:588:5:588:34 | [variable post-update] mc | testPathInjection.swift:580:9:580:20 | remoteString | -| testPathInjection.swift:588:5:588:34 | [variable post-update] mc | testPathInjection.swift:586:9:586:10 | mc | -| testPathInjection.swift:588:5:588:34 | [variable post-update] remoteString | testPathInjection.swift:580:9:580:20 | remoteString | -| testPathInjection.swift:588:5:588:34 | [variable post-update] remoteString | testPathInjection.swift:586:9:586:10 | mc | From 0164aff6a85e21897d324408721905650f005287 Mon Sep 17 00:00:00 2001 From: Asger F Date: Fri, 2 Oct 2026 12:48:03 +0200 Subject: [PATCH 09/11] unified: Update unit test output --- unified/ql/test/library-tests/dataflow/test.expected | 4 ---- unified/ql/test/library-tests/dataflow/test.swift | 4 ++-- 2 files changed, 2 insertions(+), 6 deletions(-) diff --git a/unified/ql/test/library-tests/dataflow/test.expected b/unified/ql/test/library-tests/dataflow/test.expected index 9ec3c9eb2890..478e0e3edfa3 100644 --- a/unified/ql/test/library-tests/dataflow/test.expected +++ b/unified/ql/test/library-tests/dataflow/test.expected @@ -179,9 +179,7 @@ edges | test.swift:175:42:175:66 | ... + ... | test.swift:175:14:175:67 | TupleExpr [1] | provenance | | | test.swift:175:52:175:66 | source(...) | test.swift:175:42:175:66 | ... + ... | provenance | | | test.swift:182:9:182:9 | x | test.swift:185:10:185:10 | x | provenance | | -| test.swift:182:9:182:9 | x | test.swift:186:10:186:10 | y | provenance | | | test.swift:182:13:182:27 | source(...) | test.swift:182:9:182:9 | x | provenance | | -| test.swift:183:9:183:9 | y | test.swift:185:10:185:10 | x | provenance | | | test.swift:183:9:183:9 | y | test.swift:186:10:186:10 | y | provenance | | | test.swift:183:13:183:27 | source(...) | test.swift:183:9:183:9 | y | provenance | | nodes @@ -489,6 +487,4 @@ testFailures | test.swift:176:10:176:10 | a | test.swift:175:25:175:39 | source(...) | test.swift:176:10:176:10 | a | $@ | test.swift:175:25:175:39 | source(...) | source(...) | | test.swift:177:10:177:10 | b | test.swift:175:52:175:66 | source(...) | test.swift:177:10:177:10 | b | $@ | test.swift:175:52:175:66 | source(...) | source(...) | | test.swift:185:10:185:10 | x | test.swift:182:13:182:27 | source(...) | test.swift:185:10:185:10 | x | $@ | test.swift:182:13:182:27 | source(...) | source(...) | -| test.swift:185:10:185:10 | x | test.swift:183:13:183:27 | source(...) | test.swift:185:10:185:10 | x | $@ | test.swift:183:13:183:27 | source(...) | source(...) | -| test.swift:186:10:186:10 | y | test.swift:182:13:182:27 | source(...) | test.swift:186:10:186:10 | y | $@ | test.swift:182:13:182:27 | source(...) | source(...) | | test.swift:186:10:186:10 | y | test.swift:183:13:183:27 | source(...) | test.swift:186:10:186:10 | y | $@ | test.swift:183:13:183:27 | source(...) | source(...) | diff --git a/unified/ql/test/library-tests/dataflow/test.swift b/unified/ql/test/library-tests/dataflow/test.swift index 36c3babdf8de..b817497a1e57 100644 --- a/unified/ql/test/library-tests/dataflow/test.swift +++ b/unified/ql/test/library-tests/dataflow/test.swift @@ -182,6 +182,6 @@ func t20() { var x = source("t20.1") var y = source("t20.2") foo(x: x, y: y) - sink(x) // $ hasValueFlow=t20.1 SPURIOUS: hasValueFlow=t20.2 - sink(y) // $ hasValueFlow=t20.2 SPURIOUS: hasValueFlow=t20.1 + sink(x) // $ hasValueFlow=t20.1 + sink(y) // $ hasValueFlow=t20.2 } From ee7fc863fd60984eba2d6d8cb8399569786afa98 Mon Sep 17 00:00:00 2001 From: Asger F Date: Fri, 2 Oct 2026 16:45:55 +0200 Subject: [PATCH 10/11] unified: Update path-injection output Many tests passed for the wrong reasons, due to the SSA bug. We need more library/operator modelling to actually find these flows. --- .../PathInjection/PathInjectionTest.expected | 114 ------------------ .../PathInjection/testPathInjection.swift | 46 +++---- 2 files changed, 23 insertions(+), 137 deletions(-) diff --git a/unified/ql/test/query-tests/security/CWE-022/PathInjection/PathInjectionTest.expected b/unified/ql/test/query-tests/security/CWE-022/PathInjection/PathInjectionTest.expected index 3e90894e5b86..90cd69557490 100644 --- a/unified/ql/test/query-tests/security/CWE-022/PathInjection/PathInjectionTest.expected +++ b/unified/ql/test/query-tests/security/CWE-022/PathInjection/PathInjectionTest.expected @@ -5,41 +5,15 @@ | testPathInjection.swift:359:35:359:46 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:359:35:359:46 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:360:44:360:55 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:360:44:360:55 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:361:33:361:44 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:361:33:361:44 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:362:28:362:36 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:362:28:362:36 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:363:40:363:51 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:363:40:363:51 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:364:35:364:46 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:364:35:364:46 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:365:23:365:31 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:365:23:365:31 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:366:27:366:38 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:366:27:366:38 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:367:22:367:30 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:367:22:367:30 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:368:30:368:38 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:368:30:368:38 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:369:30:369:36 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:369:30:369:36 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:369:51:369:59 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:369:51:369:59 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:371:13:371:21 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:371:13:371:21 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:371:36:371:42 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:371:36:371:42 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:374:13:374:19 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:374:13:374:19 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:374:34:374:42 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:374:34:374:42 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:376:21:376:29 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:376:21:376:29 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:376:36:376:42 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:376:36:376:42 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:377:21:377:27 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:377:21:377:27 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:377:34:377:42 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:377:34:377:42 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:378:25:378:36 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:378:25:378:36 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:379:37:379:48 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:379:37:379:48 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:380:21:380:29 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:380:21:380:29 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:380:36:380:42 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:380:36:380:42 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:381:21:381:27 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:381:21:381:27 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:381:34:381:42 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:381:34:381:42 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:382:25:382:36 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:382:25:382:36 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:383:37:383:48 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:383:37:383:48 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:384:31:384:39 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:384:31:384:39 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:384:62:384:68 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:384:62:384:68 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:385:31:385:37 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:385:31:385:37 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:385:60:385:68 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:385:60:385:68 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:386:35:386:46 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:386:35:386:46 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:387:60:387:71 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:387:60:387:71 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:388:21:388:29 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:388:21:388:29 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:388:36:388:42 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:388:36:388:42 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:389:21:389:27 | safeUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:389:21:389:27 | safeUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:389:34:389:42 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:389:34:389:42 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:390:25:390:36 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:390:25:390:36 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:391:37:391:48 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:391:37:391:48 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:392:50:392:61 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:392:50:392:61 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | @@ -50,24 +24,19 @@ | testPathInjection.swift:398:38:398:49 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:398:38:398:49 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:399:51:399:62 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:399:51:399:62 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:400:43:400:54 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:400:43:400:54 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:401:34:401:42 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:401:34:401:42 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:403:50:403:61 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:403:50:403:61 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:404:42:404:53 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:404:42:404:53 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:405:40:405:51 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:405:40:405:51 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:406:43:406:54 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:406:43:406:54 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:407:60:407:71 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:407:60:407:71 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:408:50:408:61 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:408:50:408:61 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:412:26:412:34 | safeNsUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:412:26:412:34 | safeNsUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:412:52:412:62 | remoteNsUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:412:52:412:62 | remoteNsUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:415:41:415:52 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:415:41:415:52 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:416:41:416:52 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:416:41:416:52 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:417:41:417:52 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:417:41:417:52 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:419:43:419:54 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:419:43:419:54 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:420:43:420:54 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:420:43:420:54 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:421:26:421:34 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:421:26:421:34 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:422:30:422:41 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:422:30:422:41 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:424:59:424:70 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:424:59:424:70 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:436:25:436:33 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:436:25:436:33 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:437:26:437:37 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:437:26:437:37 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:441:28:441:39 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:441:28:441:39 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:443:32:443:43 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:443:32:443:43 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | @@ -75,13 +44,10 @@ | testPathInjection.swift:447:40:447:51 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:447:40:447:51 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:456:15:456:26 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:456:15:456:26 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:482:22:482:33 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:482:22:482:33 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | -| testPathInjection.swift:484:24:484:30 | buffer2 | testPathInjection.swift:477:22:477:87 | Data(...) | testPathInjection.swift:484:24:484:30 | buffer2 | This path depends on a $@. | testPathInjection.swift:477:22:477:87 | Data(...) | user-provided value | | testPathInjection.swift:486:25:486:36 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:486:25:486:36 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:498:49:498:60 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:498:49:498:60 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:510:37:510:48 | remoteString | testPathInjection.swift:504:24:504:78 | String(...) | testPathInjection.swift:510:37:510:48 | remoteString | This path depends on a $@. | testPathInjection.swift:504:24:504:78 | String(...) | user-provided value | | testPathInjection.swift:512:33:512:44 | remoteString | testPathInjection.swift:504:24:504:78 | String(...) | testPathInjection.swift:512:33:512:44 | remoteString | This path depends on a $@. | testPathInjection.swift:504:24:504:78 | String(...) | user-provided value | -| testPathInjection.swift:525:28:525:93 | ... .appendingPathComponent(...) | testPathInjection.swift:519:24:519:78 | String(...) | testPathInjection.swift:525:28:525:93 | ... .appendingPathComponent(...) | This path depends on a $@. | testPathInjection.swift:519:24:519:78 | String(...) | user-provided value | -| testPathInjection.swift:527:28:527:29 | u1 | testPathInjection.swift:519:24:519:78 | String(...) | testPathInjection.swift:527:28:527:29 | u1 | This path depends on a $@. | testPathInjection.swift:519:24:519:78 | String(...) | user-provided value | | testPathInjection.swift:529:28:529:39 | remoteString | testPathInjection.swift:519:24:519:78 | String(...) | testPathInjection.swift:529:28:529:39 | remoteString | This path depends on a $@. | testPathInjection.swift:519:24:519:78 | String(...) | user-provided value | | testPathInjection.swift:541:32:541:43 | remoteString | testPathInjection.swift:519:24:519:78 | String(...) | testPathInjection.swift:541:32:541:43 | remoteString | This path depends on a $@. | testPathInjection.swift:519:24:519:78 | String(...) | user-provided value | | testPathInjection.swift:542:38:542:49 | remoteString | testPathInjection.swift:519:24:519:78 | String(...) | testPathInjection.swift:542:38:542:49 | remoteString | This path depends on a $@. | testPathInjection.swift:519:24:519:78 | String(...) | user-provided value | @@ -100,41 +66,15 @@ edges | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:359:35:359:46 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:360:44:360:55 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:361:33:361:44 | remoteString | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:362:28:362:36 | remoteUrl | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:363:40:363:51 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:364:35:364:46 | remoteString | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:365:23:365:31 | remoteUrl | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:366:27:366:38 | remoteString | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:367:22:367:30 | remoteUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:368:30:368:38 | remoteUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:369:30:369:36 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:369:51:369:59 | remoteUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:371:13:371:21 | remoteUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:371:36:371:42 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:374:13:374:19 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:374:34:374:42 | remoteUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:376:21:376:29 | remoteUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:376:36:376:42 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:377:21:377:27 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:377:34:377:42 | remoteUrl | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:378:25:378:36 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:379:37:379:48 | remoteString | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:380:21:380:29 | remoteUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:380:36:380:42 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:381:21:381:27 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:381:34:381:42 | remoteUrl | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:382:25:382:36 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:383:37:383:48 | remoteString | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:384:31:384:39 | remoteUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:384:62:384:68 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:385:31:385:37 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:385:60:385:68 | remoteUrl | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:386:35:386:46 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:387:60:387:71 | remoteString | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:388:21:388:29 | remoteUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:388:36:388:42 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:389:21:389:27 | safeUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:389:34:389:42 | remoteUrl | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:390:25:390:36 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:391:37:391:48 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:392:50:392:61 | remoteString | provenance | | @@ -145,24 +85,19 @@ edges | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:398:38:398:49 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:399:51:399:62 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:400:43:400:54 | remoteString | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:401:34:401:42 | remoteUrl | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:403:50:403:61 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:404:42:404:53 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:405:40:405:51 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:406:43:406:54 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:407:60:407:71 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:408:50:408:61 | remoteString | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:412:26:412:34 | safeNsUrl | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:412:52:412:62 | remoteNsUrl | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:415:41:415:52 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:416:41:416:52 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:417:41:417:52 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:419:43:419:54 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:420:43:420:54 | remoteString | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:421:26:421:34 | remoteUrl | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:422:30:422:41 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:424:59:424:70 | remoteString | provenance | | -| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:436:25:436:33 | remoteUrl | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:437:26:437:37 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:441:28:441:39 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:443:32:443:43 | remoteString | provenance | | @@ -173,13 +108,9 @@ edges | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:486:25:486:36 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:498:49:498:60 | remoteString | provenance | | | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:340:9:340:20 | remoteString | provenance | | -| testPathInjection.swift:477:9:477:18 | remoteData | testPathInjection.swift:484:24:484:30 | buffer2 | provenance | | -| testPathInjection.swift:477:22:477:87 | Data(...) | testPathInjection.swift:477:9:477:18 | remoteData | provenance | | | testPathInjection.swift:504:9:504:20 | remoteString | testPathInjection.swift:510:37:510:48 | remoteString | provenance | | | testPathInjection.swift:504:9:504:20 | remoteString | testPathInjection.swift:512:33:512:44 | remoteString | provenance | | | testPathInjection.swift:504:24:504:78 | String(...) | testPathInjection.swift:504:9:504:20 | remoteString | provenance | | -| testPathInjection.swift:519:9:519:20 | remoteString | testPathInjection.swift:525:28:525:29 | u1 | provenance | | -| testPathInjection.swift:519:9:519:20 | remoteString | testPathInjection.swift:527:28:527:29 | u1 | provenance | | | testPathInjection.swift:519:9:519:20 | remoteString | testPathInjection.swift:529:28:529:39 | remoteString | provenance | | | testPathInjection.swift:519:9:519:20 | remoteString | testPathInjection.swift:541:32:541:43 | remoteString | provenance | | | testPathInjection.swift:519:9:519:20 | remoteString | testPathInjection.swift:542:38:542:49 | remoteString | provenance | | @@ -188,10 +119,6 @@ edges | testPathInjection.swift:519:9:519:20 | remoteString | testPathInjection.swift:559:35:559:46 | remoteString | provenance | | | testPathInjection.swift:519:9:519:20 | remoteString | testPathInjection.swift:560:41:560:52 | remoteString | provenance | | | testPathInjection.swift:519:24:519:78 | String(...) | testPathInjection.swift:519:9:519:20 | remoteString | provenance | | -| testPathInjection.swift:525:28:525:29 | u1 | testPathInjection.swift:16:74:16:77 | self | provenance | | -| testPathInjection.swift:525:28:525:29 | u1 | testPathInjection.swift:525:28:525:66 | ... .appendingPathComponent(...) | provenance | | -| testPathInjection.swift:525:28:525:66 | ... .appendingPathComponent(...) | testPathInjection.swift:16:74:16:77 | self | provenance | | -| testPathInjection.swift:525:28:525:66 | ... .appendingPathComponent(...) | testPathInjection.swift:525:28:525:93 | ... .appendingPathComponent(...) | provenance | | | testPathInjection.swift:546:5:546:6 | [post] s1 [pointee] | testPathInjection.swift:547:32:547:33 | s1 [pointee] | provenance | | | testPathInjection.swift:546:5:546:14 | ... .pointee | testPathInjection.swift:546:5:546:6 | [post] s1 [pointee] | provenance | | | testPathInjection.swift:546:18:546:29 | remoteString | testPathInjection.swift:546:5:546:14 | ... .pointee | provenance | | @@ -202,7 +129,6 @@ edges | testPathInjection.swift:580:9:580:20 | remoteString | testPathInjection.swift:588:22:588:33 | remoteString | provenance | | | testPathInjection.swift:580:24:580:78 | String(...) | testPathInjection.swift:580:9:580:20 | remoteString | provenance | | nodes -| testPathInjection.swift:16:74:16:77 | self | semmle.label | self | | testPathInjection.swift:340:9:340:20 | remoteString | semmle.label | remoteString | | testPathInjection.swift:340:24:340:78 | String(...) | semmle.label | String(...) | | testPathInjection.swift:351:34:351:45 | remoteString | semmle.label | remoteString | @@ -211,41 +137,15 @@ nodes | testPathInjection.swift:359:35:359:46 | remoteString | semmle.label | remoteString | | testPathInjection.swift:360:44:360:55 | remoteString | semmle.label | remoteString | | testPathInjection.swift:361:33:361:44 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:362:28:362:36 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:363:40:363:51 | remoteString | semmle.label | remoteString | | testPathInjection.swift:364:35:364:46 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:365:23:365:31 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:366:27:366:38 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:367:22:367:30 | remoteUrl | semmle.label | remoteUrl | -| testPathInjection.swift:368:30:368:38 | remoteUrl | semmle.label | remoteUrl | -| testPathInjection.swift:369:30:369:36 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:369:51:369:59 | remoteUrl | semmle.label | remoteUrl | -| testPathInjection.swift:371:13:371:21 | remoteUrl | semmle.label | remoteUrl | -| testPathInjection.swift:371:36:371:42 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:374:13:374:19 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:374:34:374:42 | remoteUrl | semmle.label | remoteUrl | -| testPathInjection.swift:376:21:376:29 | remoteUrl | semmle.label | remoteUrl | -| testPathInjection.swift:376:36:376:42 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:377:21:377:27 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:377:34:377:42 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:378:25:378:36 | remoteString | semmle.label | remoteString | | testPathInjection.swift:379:37:379:48 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:380:21:380:29 | remoteUrl | semmle.label | remoteUrl | -| testPathInjection.swift:380:36:380:42 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:381:21:381:27 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:381:34:381:42 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:382:25:382:36 | remoteString | semmle.label | remoteString | | testPathInjection.swift:383:37:383:48 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:384:31:384:39 | remoteUrl | semmle.label | remoteUrl | -| testPathInjection.swift:384:62:384:68 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:385:31:385:37 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:385:60:385:68 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:386:35:386:46 | remoteString | semmle.label | remoteString | | testPathInjection.swift:387:60:387:71 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:388:21:388:29 | remoteUrl | semmle.label | remoteUrl | -| testPathInjection.swift:388:36:388:42 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:389:21:389:27 | safeUrl | semmle.label | safeUrl | -| testPathInjection.swift:389:34:389:42 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:390:25:390:36 | remoteString | semmle.label | remoteString | | testPathInjection.swift:391:37:391:48 | remoteString | semmle.label | remoteString | | testPathInjection.swift:392:50:392:61 | remoteString | semmle.label | remoteString | @@ -256,34 +156,26 @@ nodes | testPathInjection.swift:398:38:398:49 | remoteString | semmle.label | remoteString | | testPathInjection.swift:399:51:399:62 | remoteString | semmle.label | remoteString | | testPathInjection.swift:400:43:400:54 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:401:34:401:42 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:403:50:403:61 | remoteString | semmle.label | remoteString | | testPathInjection.swift:404:42:404:53 | remoteString | semmle.label | remoteString | | testPathInjection.swift:405:40:405:51 | remoteString | semmle.label | remoteString | | testPathInjection.swift:406:43:406:54 | remoteString | semmle.label | remoteString | | testPathInjection.swift:407:60:407:71 | remoteString | semmle.label | remoteString | | testPathInjection.swift:408:50:408:61 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:412:26:412:34 | safeNsUrl | semmle.label | safeNsUrl | -| testPathInjection.swift:412:52:412:62 | remoteNsUrl | semmle.label | remoteNsUrl | | testPathInjection.swift:415:41:415:52 | remoteString | semmle.label | remoteString | | testPathInjection.swift:416:41:416:52 | remoteString | semmle.label | remoteString | | testPathInjection.swift:417:41:417:52 | remoteString | semmle.label | remoteString | | testPathInjection.swift:419:43:419:54 | remoteString | semmle.label | remoteString | | testPathInjection.swift:420:43:420:54 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:421:26:421:34 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:422:30:422:41 | remoteString | semmle.label | remoteString | | testPathInjection.swift:424:59:424:70 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:436:25:436:33 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:437:26:437:37 | remoteString | semmle.label | remoteString | | testPathInjection.swift:441:28:441:39 | remoteString | semmle.label | remoteString | | testPathInjection.swift:443:32:443:43 | remoteString | semmle.label | remoteString | | testPathInjection.swift:445:33:445:44 | remoteString | semmle.label | remoteString | | testPathInjection.swift:447:40:447:51 | remoteString | semmle.label | remoteString | | testPathInjection.swift:456:15:456:26 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:477:9:477:18 | remoteData | semmle.label | remoteData | -| testPathInjection.swift:477:22:477:87 | Data(...) | semmle.label | Data(...) | | testPathInjection.swift:482:22:482:33 | remoteString | semmle.label | remoteString | -| testPathInjection.swift:484:24:484:30 | buffer2 | semmle.label | buffer2 | | testPathInjection.swift:486:25:486:36 | remoteString | semmle.label | remoteString | | testPathInjection.swift:498:49:498:60 | remoteString | semmle.label | remoteString | | testPathInjection.swift:504:9:504:20 | remoteString | semmle.label | remoteString | @@ -292,10 +184,6 @@ nodes | testPathInjection.swift:512:33:512:44 | remoteString | semmle.label | remoteString | | testPathInjection.swift:519:9:519:20 | remoteString | semmle.label | remoteString | | testPathInjection.swift:519:24:519:78 | String(...) | semmle.label | String(...) | -| testPathInjection.swift:525:28:525:29 | u1 | semmle.label | u1 | -| testPathInjection.swift:525:28:525:66 | ... .appendingPathComponent(...) | semmle.label | ... .appendingPathComponent(...) | -| testPathInjection.swift:525:28:525:93 | ... .appendingPathComponent(...) | semmle.label | ... .appendingPathComponent(...) | -| testPathInjection.swift:527:28:527:29 | u1 | semmle.label | u1 | | testPathInjection.swift:529:28:529:39 | remoteString | semmle.label | remoteString | | testPathInjection.swift:541:32:541:43 | remoteString | semmle.label | remoteString | | testPathInjection.swift:542:38:542:49 | remoteString | semmle.label | remoteString | @@ -314,5 +202,3 @@ nodes | testPathInjection.swift:586:38:586:49 | remoteString | semmle.label | remoteString | | testPathInjection.swift:588:22:588:33 | remoteString | semmle.label | remoteString | subpaths -| testPathInjection.swift:525:28:525:29 | u1 | testPathInjection.swift:16:74:16:77 | self | testPathInjection.swift:16:74:16:77 | self | testPathInjection.swift:525:28:525:66 | ... .appendingPathComponent(...) | -| testPathInjection.swift:525:28:525:66 | ... .appendingPathComponent(...) | testPathInjection.swift:16:74:16:77 | self | testPathInjection.swift:16:74:16:77 | self | testPathInjection.swift:525:28:525:93 | ... .appendingPathComponent(...) | diff --git a/unified/ql/test/query-tests/security/CWE-022/PathInjection/testPathInjection.swift b/unified/ql/test/query-tests/security/CWE-022/PathInjection/testPathInjection.swift index 9cc20d430bdc..e21c3b994bab 100644 --- a/unified/ql/test/query-tests/security/CWE-022/PathInjection/testPathInjection.swift +++ b/unified/ql/test/query-tests/security/CWE-022/PathInjection/testPathInjection.swift @@ -359,34 +359,34 @@ func test(buffer1: UnsafeMutablePointer, buffer2: UnsafeMutablePointer()) // $ Alert - let _ = fm.replaceItemAt(remoteUrl, withItemAt: safeUrl, backupItemName: nil, options: []) // $ Alert - let _ = fm.replaceItemAt(safeUrl, withItemAt: remoteUrl, backupItemName: nil, options: []) // $ Alert + fm.trashItem(at: remoteUrl, resultingItemURL: AutoreleasingUnsafeMutablePointer()) // $ MISSING: Alert + let _ = fm.replaceItemAt(remoteUrl, withItemAt: safeUrl, backupItemName: nil, options: []) // $ MISSING: Alert + let _ = fm.replaceItemAt(safeUrl, withItemAt: remoteUrl, backupItemName: nil, options: []) // $ MISSING: Alert fm.replaceItem( - at: remoteUrl, withItemAt: safeUrl, backupItemName: nil, options: [], // $ SPURIOUS: Alert + at: remoteUrl, withItemAt: safeUrl, backupItemName: nil, options: [], resultingItemURL: AutoreleasingUnsafeMutablePointer()) // $ MISSING: Alert fm.replaceItem( - at: safeUrl, withItemAt: remoteUrl, backupItemName: nil, options: [], // $ SPURIOUS: Alert + at: safeUrl, withItemAt: remoteUrl, backupItemName: nil, options: [], resultingItemURL: AutoreleasingUnsafeMutablePointer()) // $ MISSING: Alert - fm.copyItem(at: remoteUrl, to: safeUrl) // $ Alert - fm.copyItem(at: safeUrl, to: remoteUrl) // $ Alert + fm.copyItem(at: remoteUrl, to: safeUrl) // $ MISSING: Alert + fm.copyItem(at: safeUrl, to: remoteUrl) // $ MISSING: Alert fm.copyItem(atPath: remoteString, toPath: "") // $ Alert fm.copyItem(atPath: "", toPath: remoteString) // $ Alert - fm.moveItem(at: remoteUrl, to: safeUrl) // $ Alert - fm.moveItem(at: safeUrl, to: remoteUrl) // $ Alert + fm.moveItem(at: remoteUrl, to: safeUrl) // $ MISSING: Alert + fm.moveItem(at: safeUrl, to: remoteUrl) // $ MISSING: Alert fm.moveItem(atPath: remoteString, toPath: "") // $ Alert fm.moveItem(atPath: "", toPath: remoteString) // $ Alert - fm.createSymbolicLink(at: remoteUrl, withDestinationURL: safeUrl) // $ Alert - fm.createSymbolicLink(at: safeUrl, withDestinationURL: remoteUrl) // $ Alert + fm.createSymbolicLink(at: remoteUrl, withDestinationURL: safeUrl) // $ MISSING: Alert + fm.createSymbolicLink(at: safeUrl, withDestinationURL: remoteUrl) // $ MISSING: Alert fm.createSymbolicLink(atPath: remoteString, withDestinationPath: "") // $ Alert fm.createSymbolicLink(atPath: "", withDestinationPath: remoteString) // $ Alert - fm.linkItem(at: remoteUrl, to: safeUrl) // $ Alert - fm.linkItem(at: safeUrl, to: remoteUrl) // $ Alert + fm.linkItem(at: remoteUrl, to: safeUrl) // $ MISSING: Alert + fm.linkItem(at: safeUrl, to: remoteUrl) // $ MISSING: Alert fm.linkItem(atPath: remoteString, toPath: "") // $ Alert fm.linkItem(atPath: "", toPath: remoteString) // $ Alert let _ = fm.destinationOfSymbolicLink(atPath: remoteString) // $ Alert @@ -398,7 +398,7 @@ func test(buffer1: UnsafeMutablePointer, buffer2: UnsafeMutablePointer, buffer2: UnsafeMutablePointer, buffer2: UnsafeMutablePointer, buffer2: UnsafeMutablePointer, buffer2: UnsafeMutablePointer Date: Fri, 2 Oct 2026 12:06:50 +0200 Subject: [PATCH 11/11] unified: Mostly restore path-injection results Switched to TaintTracking and adds some very ad-hoc steps to recover most of the results. Some more tests pass and others fail; these are now consistent with what we actually model. --- .../internal/dataflow/DataFlowPluginSwift.qll | 16 ++++ .../queries/security/CWE-022/PathInjection.ql | 2 +- .../PathInjection/PathInjectionTest.expected | 83 +++++++++++++++++++ .../PathInjection/testPathInjection.swift | 50 +++++------ 4 files changed, 125 insertions(+), 26 deletions(-) diff --git a/unified/ql/lib/codeql/unified/internal/dataflow/DataFlowPluginSwift.qll b/unified/ql/lib/codeql/unified/internal/dataflow/DataFlowPluginSwift.qll index ec03bf1536d3..fdabcc6eee71 100644 --- a/unified/ql/lib/codeql/unified/internal/dataflow/DataFlowPluginSwift.qll +++ b/unified/ql/lib/codeql/unified/internal/dataflow/DataFlowPluginSwift.qll @@ -25,5 +25,21 @@ private class SwiftDataFlowPlugin extends DataFlowPlugin { step.value() and node2.isResultValue(call) ) + or + // Taint flow through unary "!" (TODO: model as a read of Optional.some, possibly with implicit taint read) + exists(UnaryExpr expr | + expr.getOperator().(PostfixOperator).getValue() = "!" and + node1.isResultValue(expr.getOperand()) and + step.taint() and + node2.isResultValue(expr) + ) + or + // Taint flow through URL(string: x). TODO: Model with MaD and flow summaries + exists(CallExpr call | + call.getCallee().(Identifier).getValue() = ["URL", "NSURL"] and + node1.isResultValue(call.getNamedArgument("string")) and + step.taint() and + node2.isResultValue(call) + ) } } diff --git a/unified/ql/src/queries/security/CWE-022/PathInjection.ql b/unified/ql/src/queries/security/CWE-022/PathInjection.ql index 3ae09d533f1e..ecdd2ba3600f 100644 --- a/unified/ql/src/queries/security/CWE-022/PathInjection.ql +++ b/unified/ql/src/queries/security/CWE-022/PathInjection.ql @@ -54,7 +54,7 @@ module PathInjectionConfig implements DataFlow::ConfigSig { } } -module PathInjectionFlow = DataFlow::Global; +module PathInjectionFlow = TaintTracking::Global; import PathInjectionFlow::PathGraph diff --git a/unified/ql/test/query-tests/security/CWE-022/PathInjection/PathInjectionTest.expected b/unified/ql/test/query-tests/security/CWE-022/PathInjection/PathInjectionTest.expected index 90cd69557490..f80c567968ce 100644 --- a/unified/ql/test/query-tests/security/CWE-022/PathInjection/PathInjectionTest.expected +++ b/unified/ql/test/query-tests/security/CWE-022/PathInjection/PathInjectionTest.expected @@ -1,19 +1,39 @@ #select +| testPathInjection.swift:346:24:346:32 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:346:24:346:32 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:349:30:349:38 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:349:30:349:38 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:350:22:350:30 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:350:22:350:30 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:351:34:351:45 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:351:34:351:45 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:352:26:352:37 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:352:26:352:37 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:355:40:355:48 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:355:40:355:48 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:356:44:356:55 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:356:44:356:55 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:358:13:358:21 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:358:13:358:21 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:359:35:359:46 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:359:35:359:46 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:360:44:360:55 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:360:44:360:55 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:361:33:361:44 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:361:33:361:44 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:362:28:362:36 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:362:28:362:36 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:363:40:363:51 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:363:40:363:51 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:364:35:364:46 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:364:35:364:46 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:365:23:365:31 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:365:23:365:31 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:366:27:366:38 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:366:27:366:38 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:367:22:367:30 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:367:22:367:30 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:368:30:368:38 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:368:30:368:38 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:369:51:369:59 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:369:51:369:59 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:371:13:371:21 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:371:13:371:21 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:374:34:374:42 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:374:34:374:42 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:376:21:376:29 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:376:21:376:29 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:377:34:377:42 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:377:34:377:42 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:378:25:378:36 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:378:25:378:36 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:379:37:379:48 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:379:37:379:48 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:380:21:380:29 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:380:21:380:29 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:381:34:381:42 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:381:34:381:42 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:382:25:382:36 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:382:25:382:36 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:383:37:383:48 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:383:37:383:48 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:384:31:384:39 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:384:31:384:39 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:385:60:385:68 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:385:60:385:68 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:386:35:386:46 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:386:35:386:46 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:387:60:387:71 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:387:60:387:71 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:388:21:388:29 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:388:21:388:29 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:389:34:389:42 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:389:34:389:42 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:390:25:390:36 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:390:25:390:36 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:391:37:391:48 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:391:37:391:48 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:392:50:392:61 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:392:50:392:61 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | @@ -24,19 +44,24 @@ | testPathInjection.swift:398:38:398:49 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:398:38:398:49 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:399:51:399:62 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:399:51:399:62 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:400:43:400:54 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:400:43:400:54 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:401:34:401:42 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:401:34:401:42 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:403:50:403:61 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:403:50:403:61 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:404:42:404:53 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:404:42:404:53 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:405:40:405:51 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:405:40:405:51 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:406:43:406:54 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:406:43:406:54 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:407:60:407:71 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:407:60:407:71 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:408:50:408:61 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:408:50:408:61 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:410:26:410:36 | remoteNsUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:410:26:410:36 | remoteNsUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:412:52:412:62 | remoteNsUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:412:52:412:62 | remoteNsUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:415:41:415:52 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:415:41:415:52 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:416:41:416:52 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:416:41:416:52 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:417:41:417:52 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:417:41:417:52 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:419:43:419:54 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:419:43:419:54 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:420:43:420:54 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:420:43:420:54 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:421:26:421:34 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:421:26:421:34 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:422:30:422:41 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:422:30:422:41 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:424:59:424:70 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:424:59:424:70 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | +| testPathInjection.swift:436:25:436:33 | remoteUrl | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:436:25:436:33 | remoteUrl | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:437:26:437:37 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:437:26:437:37 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:441:28:441:39 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:441:28:441:39 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | | testPathInjection.swift:443:32:443:43 | remoteString | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:443:32:443:43 | remoteString | This path depends on a $@. | testPathInjection.swift:340:24:340:78 | String(...) | user-provided value | @@ -60,6 +85,8 @@ | testPathInjection.swift:586:38:586:49 | remoteString | testPathInjection.swift:580:24:580:78 | String(...) | testPathInjection.swift:586:38:586:49 | remoteString | This path depends on a $@. | testPathInjection.swift:580:24:580:78 | String(...) | user-provided value | | testPathInjection.swift:588:22:588:33 | remoteString | testPathInjection.swift:580:24:580:78 | String(...) | testPathInjection.swift:588:22:588:33 | remoteString | This path depends on a $@. | testPathInjection.swift:580:24:580:78 | String(...) | user-provided value | edges +| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:341:33:341:44 | remoteString | provenance | | +| testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:342:37:342:48 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:351:34:351:45 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:352:26:352:37 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:356:44:356:55 | remoteString | provenance | | @@ -108,6 +135,33 @@ edges | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:486:25:486:36 | remoteString | provenance | | | testPathInjection.swift:340:9:340:20 | remoteString | testPathInjection.swift:498:49:498:60 | remoteString | provenance | | | testPathInjection.swift:340:24:340:78 | String(...) | testPathInjection.swift:340:9:340:20 | remoteString | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:346:24:346:32 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:349:30:349:38 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:350:22:350:30 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:355:40:355:48 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:358:13:358:21 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:362:28:362:36 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:365:23:365:31 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:367:22:367:30 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:368:30:368:38 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:369:51:369:59 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:371:13:371:21 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:374:34:374:42 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:376:21:376:29 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:377:34:377:42 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:380:21:380:29 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:381:34:381:42 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:384:31:384:39 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:385:60:385:68 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:388:21:388:29 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:389:34:389:42 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:401:34:401:42 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:421:26:421:34 | remoteUrl | provenance | | +| testPathInjection.swift:341:9:341:17 | remoteUrl | testPathInjection.swift:436:25:436:33 | remoteUrl | provenance | | +| testPathInjection.swift:341:33:341:44 | remoteString | testPathInjection.swift:341:9:341:17 | remoteUrl | provenance | | +| testPathInjection.swift:342:9:342:19 | remoteNsUrl | testPathInjection.swift:410:26:410:36 | remoteNsUrl | provenance | | +| testPathInjection.swift:342:9:342:19 | remoteNsUrl | testPathInjection.swift:412:52:412:62 | remoteNsUrl | provenance | | +| testPathInjection.swift:342:37:342:48 | remoteString | testPathInjection.swift:342:9:342:19 | remoteNsUrl | provenance | | | testPathInjection.swift:504:9:504:20 | remoteString | testPathInjection.swift:510:37:510:48 | remoteString | provenance | | | testPathInjection.swift:504:9:504:20 | remoteString | testPathInjection.swift:512:33:512:44 | remoteString | provenance | | | testPathInjection.swift:504:24:504:78 | String(...) | testPathInjection.swift:504:9:504:20 | remoteString | provenance | | @@ -131,21 +185,45 @@ edges nodes | testPathInjection.swift:340:9:340:20 | remoteString | semmle.label | remoteString | | testPathInjection.swift:340:24:340:78 | String(...) | semmle.label | String(...) | +| testPathInjection.swift:341:9:341:17 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:341:33:341:44 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:342:9:342:19 | remoteNsUrl | semmle.label | remoteNsUrl | +| testPathInjection.swift:342:37:342:48 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:346:24:346:32 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:349:30:349:38 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:350:22:350:30 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:351:34:351:45 | remoteString | semmle.label | remoteString | | testPathInjection.swift:352:26:352:37 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:355:40:355:48 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:356:44:356:55 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:358:13:358:21 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:359:35:359:46 | remoteString | semmle.label | remoteString | | testPathInjection.swift:360:44:360:55 | remoteString | semmle.label | remoteString | | testPathInjection.swift:361:33:361:44 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:362:28:362:36 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:363:40:363:51 | remoteString | semmle.label | remoteString | | testPathInjection.swift:364:35:364:46 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:365:23:365:31 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:366:27:366:38 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:367:22:367:30 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:368:30:368:38 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:369:51:369:59 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:371:13:371:21 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:374:34:374:42 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:376:21:376:29 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:377:34:377:42 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:378:25:378:36 | remoteString | semmle.label | remoteString | | testPathInjection.swift:379:37:379:48 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:380:21:380:29 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:381:34:381:42 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:382:25:382:36 | remoteString | semmle.label | remoteString | | testPathInjection.swift:383:37:383:48 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:384:31:384:39 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:385:60:385:68 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:386:35:386:46 | remoteString | semmle.label | remoteString | | testPathInjection.swift:387:60:387:71 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:388:21:388:29 | remoteUrl | semmle.label | remoteUrl | +| testPathInjection.swift:389:34:389:42 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:390:25:390:36 | remoteString | semmle.label | remoteString | | testPathInjection.swift:391:37:391:48 | remoteString | semmle.label | remoteString | | testPathInjection.swift:392:50:392:61 | remoteString | semmle.label | remoteString | @@ -156,19 +234,24 @@ nodes | testPathInjection.swift:398:38:398:49 | remoteString | semmle.label | remoteString | | testPathInjection.swift:399:51:399:62 | remoteString | semmle.label | remoteString | | testPathInjection.swift:400:43:400:54 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:401:34:401:42 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:403:50:403:61 | remoteString | semmle.label | remoteString | | testPathInjection.swift:404:42:404:53 | remoteString | semmle.label | remoteString | | testPathInjection.swift:405:40:405:51 | remoteString | semmle.label | remoteString | | testPathInjection.swift:406:43:406:54 | remoteString | semmle.label | remoteString | | testPathInjection.swift:407:60:407:71 | remoteString | semmle.label | remoteString | | testPathInjection.swift:408:50:408:61 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:410:26:410:36 | remoteNsUrl | semmle.label | remoteNsUrl | +| testPathInjection.swift:412:52:412:62 | remoteNsUrl | semmle.label | remoteNsUrl | | testPathInjection.swift:415:41:415:52 | remoteString | semmle.label | remoteString | | testPathInjection.swift:416:41:416:52 | remoteString | semmle.label | remoteString | | testPathInjection.swift:417:41:417:52 | remoteString | semmle.label | remoteString | | testPathInjection.swift:419:43:419:54 | remoteString | semmle.label | remoteString | | testPathInjection.swift:420:43:420:54 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:421:26:421:34 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:422:30:422:41 | remoteString | semmle.label | remoteString | | testPathInjection.swift:424:59:424:70 | remoteString | semmle.label | remoteString | +| testPathInjection.swift:436:25:436:33 | remoteUrl | semmle.label | remoteUrl | | testPathInjection.swift:437:26:437:37 | remoteString | semmle.label | remoteString | | testPathInjection.swift:441:28:441:39 | remoteString | semmle.label | remoteString | | testPathInjection.swift:443:32:443:43 | remoteString | semmle.label | remoteString | diff --git a/unified/ql/test/query-tests/security/CWE-022/PathInjection/testPathInjection.swift b/unified/ql/test/query-tests/security/CWE-022/PathInjection/testPathInjection.swift index e21c3b994bab..9ada50020f56 100644 --- a/unified/ql/test/query-tests/security/CWE-022/PathInjection/testPathInjection.swift +++ b/unified/ql/test/query-tests/security/CWE-022/PathInjection/testPathInjection.swift @@ -343,50 +343,50 @@ func test(buffer1: UnsafeMutablePointer, buffer2: UnsafeMutablePointer()) // $ MISSING: Alert - let _ = fm.replaceItemAt(remoteUrl, withItemAt: safeUrl, backupItemName: nil, options: []) // $ MISSING: Alert - let _ = fm.replaceItemAt(safeUrl, withItemAt: remoteUrl, backupItemName: nil, options: []) // $ MISSING: Alert + fm.trashItem(at: remoteUrl, resultingItemURL: AutoreleasingUnsafeMutablePointer()) // $ Alert + let _ = fm.replaceItemAt(remoteUrl, withItemAt: safeUrl, backupItemName: nil, options: []) // $ Alert + let _ = fm.replaceItemAt(safeUrl, withItemAt: remoteUrl, backupItemName: nil, options: []) // $ Alert fm.replaceItem( - at: remoteUrl, withItemAt: safeUrl, backupItemName: nil, options: [], + at: remoteUrl, withItemAt: safeUrl, backupItemName: nil, options: [], // $ SPURIOUS: Alert resultingItemURL: AutoreleasingUnsafeMutablePointer()) // $ MISSING: Alert fm.replaceItem( - at: safeUrl, withItemAt: remoteUrl, backupItemName: nil, options: [], + at: safeUrl, withItemAt: remoteUrl, backupItemName: nil, options: [], // $ SPURIOUS: Alert resultingItemURL: AutoreleasingUnsafeMutablePointer()) // $ MISSING: Alert - fm.copyItem(at: remoteUrl, to: safeUrl) // $ MISSING: Alert - fm.copyItem(at: safeUrl, to: remoteUrl) // $ MISSING: Alert + fm.copyItem(at: remoteUrl, to: safeUrl) // $ Alert + fm.copyItem(at: safeUrl, to: remoteUrl) // $ Alert fm.copyItem(atPath: remoteString, toPath: "") // $ Alert fm.copyItem(atPath: "", toPath: remoteString) // $ Alert - fm.moveItem(at: remoteUrl, to: safeUrl) // $ MISSING: Alert - fm.moveItem(at: safeUrl, to: remoteUrl) // $ MISSING: Alert + fm.moveItem(at: remoteUrl, to: safeUrl) // $ Alert + fm.moveItem(at: safeUrl, to: remoteUrl) // $ Alert fm.moveItem(atPath: remoteString, toPath: "") // $ Alert fm.moveItem(atPath: "", toPath: remoteString) // $ Alert - fm.createSymbolicLink(at: remoteUrl, withDestinationURL: safeUrl) // $ MISSING: Alert - fm.createSymbolicLink(at: safeUrl, withDestinationURL: remoteUrl) // $ MISSING: Alert + fm.createSymbolicLink(at: remoteUrl, withDestinationURL: safeUrl) // $ Alert + fm.createSymbolicLink(at: safeUrl, withDestinationURL: remoteUrl) // $ Alert fm.createSymbolicLink(atPath: remoteString, withDestinationPath: "") // $ Alert fm.createSymbolicLink(atPath: "", withDestinationPath: remoteString) // $ Alert - fm.linkItem(at: remoteUrl, to: safeUrl) // $ MISSING: Alert - fm.linkItem(at: safeUrl, to: remoteUrl) // $ MISSING: Alert + fm.linkItem(at: remoteUrl, to: safeUrl) // $ Alert + fm.linkItem(at: safeUrl, to: remoteUrl) // $ Alert fm.linkItem(atPath: remoteString, toPath: "") // $ Alert fm.linkItem(atPath: "", toPath: remoteString) // $ Alert let _ = fm.destinationOfSymbolicLink(atPath: remoteString) // $ Alert @@ -398,7 +398,7 @@ func test(buffer1: UnsafeMutablePointer, buffer2: UnsafeMutablePointer, buffer2: UnsafeMutablePointer, buffer2: UnsafeMutablePointer, buffer2: UnsafeMutablePointer