Skip to content

Unified: Data flow through enum constructors and operators - #22751

Open
asgerf wants to merge 18 commits into
github:mainfrom
asgerf:unified/more-data-flow
Open

asgerf wants to merge 18 commits into
github:mainfrom
asgerf:unified/more-data-flow

Conversation

@asgerf

@asgerf asgerf commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor
  • Adds flow through enum constructors: we store into a field at a constructor call, and read fields at constructor patterns.
  • Also adds flow through try, try?, try!, as, as?, as!, and await operators.
  • Adds flow through array literals and for..in loops.

@asgerf asgerf added the no-change-note-required This PR does not need a change note label Oct 5, 2026
Comment on lines +1 to +3
/**
* Provides data-flow modelling of constructor patterns / enum-case constructors.
*/
@asgerf
asgerf force-pushed the unified/more-data-flow branch 3 times, most recently from 1c464b7 to 65f475f Compare October 8, 2026 09:13
@asgerf
asgerf requested a balanced review from Copilot October 8, 2026 10:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Enum content identity, optional try? flattening, and guard-pattern flow have unresolved correctness issues.

5 open findings
What changed in this PR

Adds unified Swift data flow for enum associated values, operators, array literals, and for-in loops.

Changes:

  • Models enum constructor storage and pattern extraction.
  • Propagates flow through Swift casts, error-handling, async, and array operations.
  • Extends path-injection models and regression coverage.
File Description
unified/​ql/​test/​query-tests/​security/​CWE-022/​PathInjection/​testPathInjection.swift Updates cast-flow alert annotations.
unified/​ql/​test/​query-tests/​security/​CWE-022/​PathInjection/​PathInjectionTest.expected Regenerates path-injection results.
unified/​ql/​test/​library-tests/​dataflow/​test.swift Adds operator and array-flow tests.
unified/​ql/​test/​library-tests/​dataflow/​test.expected Regenerates data-flow expectations.
unified/​ql/​test/​library-tests/​dataflow/​enums.swift Adds enum associated-value tests.
unified/​ql/​test/​library-tests/​dataflow/​CONSISTENCY/​CfgConsistency.expected Records CFG consistency output.
unified/​ql/​test/​library-tests/​controlflow/​CONSISTENCY/​DataFlowConsistency.expected Updates consistency expectations.
unified/​ql/​src/​queries/​security/​CWE-022/​PathInjection.ql Adds flow through path properties.
unified/​ql/​lib/​ext/​legacy-swift.model.yml Models one-argument Data(contentsOf:).
unified/​ql/​lib/​codeql/​unified/​internal/​dataflow/​Step.qll Adds array-content step helpers.
unified/​ql/​lib/​codeql/​unified/​internal/​dataflow/​DataFlowPluginSwift.qll Models Swift operators and casts.
unified/​ql/​lib/​codeql/​unified/​internal/​dataflow/​DataFlowInstantiation.qll Hides expression-pattern value nodes.
unified/​ql/​lib/​codeql/​unified/​internal/​dataflow/​DataFlowGraph.qll Adds enum, pattern, and array edges.
unified/​ql/​lib/​codeql/​unified/​internal/​dataflow/​Content.qll Defines array and enum content keys.
unified/​ql/​lib/​codeql/​unified/​internal/​dataflow/​ConstructorPatterns.qll Resolves enum constructor patterns.
unified/​ql/​lib/​codeql/​unified/​internal/​dataflow/​AllDataFlow.qll Imports constructor-pattern support.
unified/​ql/​consistency-queries/​DataFlowConsistency.ql Excludes plugin reads from reverse-read checks.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread unified/ql/lib/codeql/unified/internal/dataflow/DataFlowGraph.qll
Comment thread unified/ql/lib/ext/legacy-swift.model.yml
Comment on lines +49 to +53
predicate isAdditionalFlowStep(DataFlow::Node node1, DataFlow::Node node2) {
exists(MemberAccessExpr expr |
expr.getMemberName() = "path" and
node1.isResultValue(expr.getBase()) and
node2.isResultValue(expr)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm OK with this for now

@asgerf
asgerf marked this pull request as ready for review October 8, 2026 12:38
@asgerf
asgerf requested a review from a team as a code owner October 8, 2026 12:38
@asgerf
asgerf force-pushed the unified/more-data-flow branch from 60bdcac to b8a4f66 Compare October 8, 2026 14:33
asgerf added 4 commits October 8, 2026 16:51
The file now passes 'swiftc -typecheck' without errors
This change happened after rebasing onto the SSA changes, which had significant impact for unified data flow
@asgerf
asgerf force-pushed the unified/more-data-flow branch from b8a4f66 to 9211707 Compare October 8, 2026 15:10

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-change-note-required This PR does not need a change note Unified

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants