Skip to content

fix: Fix passing partial fingerprints generation option - #11

Merged
seqradev merged 1 commit into
mainfrom
seqradev/fix-partial-fingerprints
Jan 29, 2026
Merged

fix: Fix passing partial fingerprints generation option#11
seqradev merged 1 commit into
mainfrom
seqradev/fix-partial-fingerprints

Conversation

@seqradev

Copy link
Copy Markdown
Member

No description provided.

@seqradev
seqradev merged commit d9b7f46 into main Jan 29, 2026
5 checks passed
@seqradev
seqradev deleted the seqradev/fix-partial-fingerprints branch January 29, 2026 15:48
misonijnik pushed a commit that referenced this pull request Mar 19, 2026
misonijnik pushed a commit that referenced this pull request Mar 19, 2026
misonijnik pushed a commit that referenced this pull request Mar 19, 2026
Saloed added a commit that referenced this pull request Jun 29, 2026
Engine (opentaint-go-dataflow):
- #1 typed field-read source no longer crashes: thread GoFieldSignature.receiverType,
  allow This as a field-source condition base (taint target stays Result-only).
- #2 TypeUtils.matchesType matches interface implementations (method-set check,
  pointer/value rules, graceful fallback).
- #7 GoFunctionSignature.pkgName (declared package clause name) + candidates() branch
  so bare rand.* matches math/rand/v2.
- #11 GoConditionResolver.resolveWithType descends a single-element GoIRTupleType
  (single-return result) before a Field/Element modifier, so a result-field source
  taint action (cookie .Value) resolves and seeds field-sensitively. No whole-value taint.
- #12 GoCallExpr peels the receiver for DIRECT concrete pointer-receiver methods from the
  static target signature (fixes *sql.DB.Query arg indexing); no go-ssa-server change.
- #6 GoTaintConfiguration.matchPackage is exact for slash-qualified matchers.

Querylang (opentaint-go-querylang):
- #3 typed metavar in argument position parses to ParamCondition.TypeIs(Argument).
- #6 new GoImportRewriter pre-pass resolves package qualifiers from in-pattern imports.

Ruleset (rules/ruleset/go):
- #6 import-qualified package names across lib/security rules (bare where a local
  test-stub / ambiguous package / typed-receiver method pattern requires it).
- #7 weak-random drops the v2.* block.
- #11 http-sources cookies source taints [$I].Value.

Tooling: #10 restore scan --entry-point flag; re-point fn_investigate.py to
test rule reachability.

Gates: engine units 1300/1300; GoSampleBasedTest 95 (3 intentional skips);
rules/test/go detection harness 197/197.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant