-
Notifications
You must be signed in to change notification settings - Fork 578
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Fix OpcodeStack to handle propagation of taints properly in case of s…
…tring concatenation in Java 11 and above (#2195) * Test for Issue 2184 * Fix OpcodeStack to handle propagation of taints properly in case of string concatenation in Java 9 and above Instead of using StringBuffer or StringBuilder internally, Java 11 and above uses a dynamic call to makeConcatWithConstants() to append strings. Previously, `OpcodeStackDetector` did not handle the taint propagation properly in case of this dyanamic call which led to false negative such as the one described in issue [#2184](#2184). This PR fixes such issues by adding code to `OpcodeStackDetector` to handle this case as well. * Refactored double negatives Co-authored-by: Kengo TODA <skypencil@gmail.com>
- Loading branch information
Showing
4 changed files
with
132 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
36 changes: 36 additions & 0 deletions
36
spotbugs-tests/src/test/java/edu/umd/cs/findbugs/detect/Issue2184Test.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,36 @@ | ||
package edu.umd.cs.findbugs.detect; | ||
|
||
import org.junit.Before; | ||
import org.junit.Test; | ||
|
||
import edu.umd.cs.findbugs.AbstractIntegrationTest; | ||
import edu.umd.cs.findbugs.test.matcher.BugInstanceMatcher; | ||
import edu.umd.cs.findbugs.test.matcher.BugInstanceMatcherBuilder; | ||
|
||
import static org.junit.Assume.assumeFalse; | ||
import static org.junit.Assume.assumeThat; | ||
import static org.hamcrest.MatcherAssert.assertThat; | ||
import static org.hamcrest.Matchers.hasItem; | ||
import static org.hamcrest.Matchers.is; | ||
import static org.hamcrest.number.OrderingComparison.greaterThanOrEqualTo; | ||
|
||
public class Issue2184Test extends AbstractIntegrationTest { | ||
@Before | ||
public void verifyJavaVersion() { | ||
assumeFalse(System.getProperty("java.specification.version").startsWith("1.")); | ||
int javaVersion = Integer.parseInt(System.getProperty("java.specification.version")); | ||
assumeThat(javaVersion, is(greaterThanOrEqualTo(14))); | ||
} | ||
|
||
@Test | ||
public void test() { | ||
performAnalysis("../java14/ghIssues/Issue2184.class"); | ||
BugInstanceMatcher matcher = new BugInstanceMatcherBuilder() | ||
.bugType("PT_RELATIVE_PATH_TRAVERSAL") | ||
.inClass("Issue2184") | ||
.inMethod("test") | ||
.atLine(17) | ||
.build(); | ||
assertThat(getBugCollection(), hasItem(matcher)); | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,28 @@ | ||
package ghIssues; | ||
|
||
import java.io.BufferedReader; | ||
import java.io.FileReader; | ||
import java.io.IOException; | ||
import java.io.PrintWriter; | ||
|
||
import javax.servlet.ServletException; | ||
import javax.servlet.http.HttpServlet; | ||
import javax.servlet.http.HttpServletRequest; | ||
import javax.servlet.http.HttpServletResponse; | ||
|
||
public class Issue2184 { | ||
public void test(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException { | ||
response.setContentType("text/plain"); | ||
PrintWriter out = response.getWriter(); | ||
String path = request.getParameter("path"); | ||
BufferedReader r = new BufferedReader(new FileReader("data/" + path)); | ||
while (true) { | ||
String txt = r.readLine(); | ||
if (txt == null) | ||
break; | ||
out.println(txt); | ||
} | ||
out.close(); | ||
r.close(); | ||
} | ||
} |