Skip to content

Go: Use shared guards library - #22365

Draft
owen-mc wants to merge 6 commits into
github:mainfrom
owen-mc:go/shared-guards
Draft

owen-mc wants to merge 6 commits into
github:mainfrom
owen-mc:go/shared-guards

Conversation

@owen-mc

@owen-mc owen-mc commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

No description provided.


/** Holds if arguments at position `apos` match parameters at position `ppos`. */
pragma[inline]
predicate parameterMatch(ParameterPosition ppos, ArgumentPosition apos) { ppos = apos }
* idiom.
*/
pragma[inline]
predicate guardEnsures(Expr e, boolean b, BasicBlock bb) { e.(Guard).controls(bb, b) }
Comment thread go/ql/lib/semmle/go/dataflow/internal/DataFlowUtil.qll Fixed

@github-advanced-security github-advanced-security AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CodeQL found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.

@owen-mc
owen-mc force-pushed the go/shared-guards branch 2 times, most recently from def5d61 to 888eae3 Compare August 18, 2026 11:45
private import semmle.go.dataflow.SSA as GoSsa
private import semmle.go.dataflow.SsaImpl as SsaImpl
private import codeql.controlflow.Guards as SharedGuards
private import codeql.controlflow.SuccessorType
))
)
or
caseExpressionBranch(this.(Expr), bb1,
Node g, ControlFlow::ConditionGuardNode guard, Node nd, SsaWithFields ap, P param
) {
guards(g, guard, nd, param) and nd = ap.getAUse()
private predicate guards(Node g, Guard guard, GuardValue value, Node nd, SsaWithFields ap, P param) {
not exists(ControlFlow::ConditionGuardNode innerCond |
isDominatingLengthLEGuard(innerCond, index, array, bb) and
innerCond.getCondition().getParent+() = cond.getCondition()
not exists(Guard innerCond, boolean innerBranch |
) and
// and it is not additionally guarded by a stronger index check
not exists(Index index2, int i, int i2 |
not exists(Index index2, int i, int i2, Guard g2, boolean b2 |
) and
// and it is not additionally guarded by a stronger index check
not exists(Index index2, int i, int i2 |
not exists(Index index2, int i, int i2, Guard g2, boolean b2 |
owen-mc and others added 6 commits October 1, 2026 14:53
Add the complete guard regression suite and fold the shared hooks and Go-specific correctness fixes into the initial adapter.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Move simple data-flow and security consumers to shared guards, including value-aware barriers and the corrected feature-flag semantics.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Explicitly implement the new optional SSA hooks in LogicInput_v3 so its signature members do not conflict with those imported from LogicInput_v2.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants