Skip to content

cpp: model BDE bdlbb::Blob byte-buffer taint flow - #22455

Open
kumarak wants to merge 1 commit into
github:mainfrom
trail-of-forks:kumarak/cpp-bdlbb-blob-models
Open

cpp: model BDE bdlbb::Blob byte-buffer taint flow#22455
kumarak wants to merge 1 commit into
github:mainfrom
trail-of-forks:kumarak/cpp-bdlbb-blob-models

Conversation

@kumarak

@kumarak kumarak commented Aug 27, 2026

Copy link
Copy Markdown

Add flow summaries for the BDE segmented byte buffer BloombergLP::bdlbb::Blob so taint reaches a blob's payload bytes:

  • Accessor chain: Blob::buffer taints the returned BlobBuffer, and BlobBuffer::data/buffer taint the bytes.
  • bdlbb::BlobUtil::copy and getContiguousRangeOrCopy propagate taint between a blob and a flat buffer in both directions.

This unblocks blob-carried sources such as bmqa::Message::getData, whose payload was previously stranded on the opaque Blob object. Not a duplicate; the bdlbb namespace had no coverage. Verified with a BloombergLP::bdlbb-shaped stub in the dataflow external-models harness.

Add flow summaries for the BDE segmented byte buffer
BloombergLP::bdlbb::Blob so taint reaches a blob's payload bytes:

- Accessor chain: Blob::buffer taints the returned BlobBuffer, and
  BlobBuffer::data/buffer taint the bytes.
- bdlbb::BlobUtil::copy and getContiguousRangeOrCopy propagate taint
  between a blob and a flat buffer in both directions.

This unblocks blob-carried sources such as bmqa::Message::getData, whose
payload was previously stranded on the opaque Blob object. Not a
duplicate; the bdlbb namespace had no coverage. Verified with a
BloombergLP::bdlbb-shaped stub in the dataflow external-models harness.
Copilot AI balanced review requested due to automatic review settings August 27, 2026 19:52
@kumarak
kumarak requested a review from a team as a code owner August 27, 2026 19:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds BDE bdlbb::Blob taint-flow models for payload access and copying.

Changes:

  • Models Blob and BlobBuffer accessors.
  • Models BlobUtil copy operations.
  • Adds external-model tests and release notes.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
cpp/ql/lib/ext/bdlbb.model.yml Defines flow summaries.
cpp/ql/test/library-tests/dataflow/external-models/bdlbb.cpp Adds test stubs and cases.
cpp/ql/test/library-tests/dataflow/external-models/flow.expected Updates expected flow results.
cpp/ql/test/library-tests/dataflow/external-models/steps.expected Updates expected summary steps.
cpp/ql/lib/change-notes/2026-08-27-bdlbb-blob-models.md Documents the analysis improvement.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
# Accessor chain: a tainted blob taints its buffers, and a tainted buffer taints its bytes.
- ["BloombergLP::bdlbb", "Blob", true, "buffer", "", "", "Argument[-1]", "ReturnValue[*]", "taint", "manual"]
- ["BloombergLP::bdlbb", "BlobBuffer", true, "data", "", "", "Argument[-1]", "ReturnValue[*]", "taint", "manual"]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants