refactor(dynamic): enhance framework bindings with SSA receiver type checks, add tests for Laravel, Symfony, Rabbit, Kafka, and Pub/Sub

This commit is contained in:
elipeter 2026-05-23 14:32:48 -05:00
parent aaa1fd7ede
commit 17fa611b63
17 changed files with 1255 additions and 167 deletions

View file

@ -8,6 +8,7 @@
use crate::dynamic::framework::{FrameworkAdapter, FrameworkBinding};
use crate::evidence::EntryKind;
use crate::summary::FuncSummary;
use crate::summary::ssa_summary::SsaFuncSummary;
use crate::symbol::Lang;
pub struct KafkaJavaAdapter;
@ -63,32 +64,64 @@ impl FrameworkAdapter for KafkaJavaAdapter {
fn detect(
&self,
summary: &FuncSummary,
_ast: tree_sitter::Node<'_>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_kafka);
let matches_source = source_imports_kafka(file_bytes);
if matches_call || matches_source {
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_topic(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
} else {
None
}
detect_kafka_java(summary, None, ast, file_bytes)
}
fn detect_with_context(
&self,
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
detect_kafka_java(summary, ssa_summary, ast, file_bytes)
}
}
fn detect_kafka_java(
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
_ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_kafka);
let matches_source = source_imports_kafka(file_bytes);
if !(matches_call || matches_source) {
return None;
}
if !super::typed_receiver_facts_allow(
summary,
ssa_summary,
callee_is_kafka,
typed_container_allows_kafka,
) {
return None;
}
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_topic(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
}
fn typed_container_allows_kafka(container: &str) -> bool {
let lc = container.to_ascii_lowercase();
lc.contains("kafka") || lc.contains("consumer")
}
#[cfg(test)]
mod tests {
use super::*;
use crate::summary::CalleeSite;
fn parse_java(src: &[u8]) -> tree_sitter::Tree {
let mut parser = tree_sitter::Parser::new();
@ -117,4 +150,57 @@ mod tests {
assert_eq!(queue, "orders");
}
}
#[test]
fn ssa_receiver_type_rejects_non_kafka_poll_collision() {
let src: &[u8] = b"import org.springframework.kafka.annotation.KafkaListener;\n\
public class Vuln {\n\
public void onMessage(String body) { timer.poll(); }\n\
}\n";
let tree = parse_java(src);
let mut summary = FuncSummary {
name: "onMessage".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "timer.poll".to_owned(),
receiver: Some("timer".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "Timer".to_owned()));
assert!(
KafkaJavaAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_none()
);
}
#[test]
fn ssa_receiver_type_keeps_kafka_consumer() {
let src: &[u8] = b"import org.apache.kafka.clients.consumer.KafkaConsumer;\n\
public class Vuln {\n\
public void onMessage(String body) { consumer.poll(); }\n\
}\n";
let tree = parse_java(src);
let mut summary = FuncSummary {
name: "onMessage".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "consumer.poll".to_owned(),
receiver: Some("consumer".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers
.push((0, "KafkaConsumer".to_owned()));
assert!(
KafkaJavaAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_some()
);
}
}

View file

@ -11,6 +11,7 @@
use crate::dynamic::framework::{FrameworkAdapter, FrameworkBinding};
use crate::evidence::EntryKind;
use crate::summary::FuncSummary;
use crate::summary::ssa_summary::SsaFuncSummary;
use crate::symbol::Lang;
pub struct KafkaPythonAdapter;
@ -67,32 +68,64 @@ impl FrameworkAdapter for KafkaPythonAdapter {
fn detect(
&self,
summary: &FuncSummary,
_ast: tree_sitter::Node<'_>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_kafka_consumer);
let matches_source = source_imports_kafka(file_bytes);
if matches_call || matches_source {
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_topic_literal(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
} else {
None
}
detect_kafka_python(summary, None, ast, file_bytes)
}
fn detect_with_context(
&self,
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
detect_kafka_python(summary, ssa_summary, ast, file_bytes)
}
}
fn detect_kafka_python(
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
_ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_kafka_consumer);
let matches_source = source_imports_kafka(file_bytes);
if !(matches_call || matches_source) {
return None;
}
if !super::typed_receiver_facts_allow(
summary,
ssa_summary,
callee_is_kafka_consumer,
typed_container_allows_kafka,
) {
return None;
}
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_topic_literal(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
}
fn typed_container_allows_kafka(container: &str) -> bool {
let lc = container.to_ascii_lowercase();
lc.contains("kafka") || lc.contains("consumer")
}
#[cfg(test)]
mod tests {
use super::*;
use crate::summary::CalleeSite;
fn parse_python(src: &[u8]) -> tree_sitter::Tree {
let mut parser = tree_sitter::Parser::new();
@ -135,4 +168,53 @@ mod tests {
.is_none()
);
}
#[test]
fn ssa_receiver_type_rejects_non_kafka_poll_collision() {
let src: &[u8] = b"from kafka import KafkaConsumer\n\
def handler(msg):\n cache.poll(msg)\n";
let tree = parse_python(src);
let mut summary = FuncSummary {
name: "handler".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "cache.poll".to_owned(),
receiver: Some("cache".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "Cache".to_owned()));
assert!(
KafkaPythonAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_none()
);
}
#[test]
fn ssa_receiver_type_keeps_kafka_consumer() {
let src: &[u8] = b"from kafka import KafkaConsumer\n\
def handler(msg):\n consumer.poll()\n";
let tree = parse_python(src);
let mut summary = FuncSummary {
name: "handler".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "consumer.poll".to_owned(),
receiver: Some("consumer".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers
.push((0, "KafkaConsumer".to_owned()));
assert!(
KafkaPythonAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_some()
);
}
}

View file

@ -262,6 +262,40 @@ fn any_callee_matches(
summary.callees.iter().any(|c| predicate(c.name.as_str()))
}
/// Use SSA receiver facts, when available, to reject permissive callee
/// matches whose receiver is known to belong to a different runtime.
///
/// Adapters still accept source-only matches and call sites without typed
/// receiver facts. A typed incompatible receiver is stronger evidence than a
/// broad method name such as `send`, `poll`, `process`, or `receive`.
fn typed_receiver_facts_allow(
summary: &crate::summary::FuncSummary,
ssa_summary: Option<&crate::summary::ssa_summary::SsaFuncSummary>,
callee_pred: impl Fn(&str) -> bool,
container_pred: impl Fn(&str) -> bool,
) -> bool {
let Some(ssa_summary) = ssa_summary else {
return true;
};
for site in &summary.callees {
if !callee_pred(site.name.as_str()) || site.receiver.is_none() {
continue;
}
let Some(container) = ssa_summary
.typed_call_receivers
.iter()
.find(|(ord, _)| *ord == site.ordinal)
.map(|(_, container)| container.as_str())
else {
continue;
};
if !container_pred(container) {
return false;
}
}
true
}
/// True when any callee in `summary.callees` matches `name_pred` AND
/// (its receiver matches `receiver_pred` OR its receiver is `None`).
///

View file

@ -3,6 +3,7 @@
use crate::dynamic::framework::{FrameworkAdapter, FrameworkBinding};
use crate::evidence::EntryKind;
use crate::summary::FuncSummary;
use crate::summary::ssa_summary::SsaFuncSummary;
use crate::symbol::Lang;
pub struct NatsGoAdapter;
@ -49,32 +50,64 @@ impl FrameworkAdapter for NatsGoAdapter {
fn detect(
&self,
summary: &FuncSummary,
_ast: tree_sitter::Node<'_>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_nats);
let matches_source = source_imports_nats(file_bytes);
if matches_call || matches_source {
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_subject(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
} else {
None
}
detect_nats_go(summary, None, ast, file_bytes)
}
fn detect_with_context(
&self,
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
detect_nats_go(summary, ssa_summary, ast, file_bytes)
}
}
fn detect_nats_go(
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
_ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_nats);
let matches_source = source_imports_nats(file_bytes);
if !(matches_call || matches_source) {
return None;
}
if !super::typed_receiver_facts_allow(
summary,
ssa_summary,
callee_is_nats,
typed_container_allows_nats,
) {
return None;
}
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_subject(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
}
fn typed_container_allows_nats(container: &str) -> bool {
let lc = container.to_ascii_lowercase();
lc.contains("nats") || lc.contains("subscription")
}
#[cfg(test)]
mod tests {
use super::*;
use crate::summary::CalleeSite;
fn parse_go(src: &[u8]) -> tree_sitter::Tree {
let mut parser = tree_sitter::Parser::new();
@ -101,4 +134,52 @@ mod tests {
assert_eq!(queue, "events");
}
}
#[test]
fn ssa_receiver_type_rejects_non_nats_publish_collision() {
let src: &[u8] = b"package entry\nimport \"github.com/nats-io/nats.go\"\n\
func OnMessage(msg *nats.Msg) { bus.Publish(msg) }\n";
let tree = parse_go(src);
let mut summary = FuncSummary {
name: "OnMessage".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "bus.Publish".to_owned(),
receiver: Some("bus".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "EventBus".to_owned()));
assert!(
NatsGoAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_none()
);
}
#[test]
fn ssa_receiver_type_keeps_nats_connection() {
let src: &[u8] = b"package entry\nimport \"github.com/nats-io/nats.go\"\n\
func OnMessage(msg *nats.Msg) { nc.Subscribe(\"events\", OnMessage) }\n";
let tree = parse_go(src);
let mut summary = FuncSummary {
name: "OnMessage".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "nc.Subscribe".to_owned(),
receiver: Some("nc".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "nats.Conn".to_owned()));
assert!(
NatsGoAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_some()
);
}
}

View file

@ -4,6 +4,7 @@
use crate::dynamic::framework::{FrameworkAdapter, FrameworkBinding};
use crate::evidence::EntryKind;
use crate::summary::FuncSummary;
use crate::summary::ssa_summary::SsaFuncSummary;
use crate::symbol::Lang;
pub struct PubsubGoAdapter;
@ -54,32 +55,64 @@ impl FrameworkAdapter for PubsubGoAdapter {
fn detect(
&self,
summary: &FuncSummary,
_ast: tree_sitter::Node<'_>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_pubsub);
let matches_source = source_imports_pubsub(file_bytes);
if matches_call || matches_source {
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_topic(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
} else {
None
}
detect_pubsub_go(summary, None, ast, file_bytes)
}
fn detect_with_context(
&self,
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
detect_pubsub_go(summary, ssa_summary, ast, file_bytes)
}
}
fn detect_pubsub_go(
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
_ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_pubsub);
let matches_source = source_imports_pubsub(file_bytes);
if !(matches_call || matches_source) {
return None;
}
if !super::typed_receiver_facts_allow(
summary,
ssa_summary,
callee_is_pubsub,
typed_container_allows_pubsub,
) {
return None;
}
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_topic(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
}
fn typed_container_allows_pubsub(container: &str) -> bool {
let lc = container.to_ascii_lowercase();
lc.contains("pubsub") || lc.contains("subscription") || lc.contains("subscriber")
}
#[cfg(test)]
mod tests {
use super::*;
use crate::summary::CalleeSite;
fn parse_go(src: &[u8]) -> tree_sitter::Tree {
let mut parser = tree_sitter::Parser::new();
@ -105,4 +138,53 @@ mod tests {
assert_eq!(queue, "my-sub");
}
}
#[test]
fn ssa_receiver_type_rejects_non_pubsub_receive_collision() {
let src: &[u8] = b"package entry\nimport \"cloud.google.com/go/pubsub\"\n\
func Handle(msg *pubsub.Message) { inbox.Receive() }\n";
let tree = parse_go(src);
let mut summary = FuncSummary {
name: "Handle".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "inbox.Receive".to_owned(),
receiver: Some("inbox".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "Inbox".to_owned()));
assert!(
PubsubGoAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_none()
);
}
#[test]
fn ssa_receiver_type_keeps_pubsub_subscription() {
let src: &[u8] = b"package entry\nimport \"cloud.google.com/go/pubsub\"\n\
func Handle(msg *pubsub.Message) { sub.Receive(ctx, cb) }\n";
let tree = parse_go(src);
let mut summary = FuncSummary {
name: "Handle".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "sub.Receive".to_owned(),
receiver: Some("sub".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers
.push((0, "pubsub.Subscription".to_owned()));
assert!(
PubsubGoAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_some()
);
}
}

View file

@ -3,6 +3,7 @@
use crate::dynamic::framework::{FrameworkAdapter, FrameworkBinding};
use crate::evidence::EntryKind;
use crate::summary::FuncSummary;
use crate::summary::ssa_summary::SsaFuncSummary;
use crate::symbol::Lang;
pub struct PubsubPythonAdapter;
@ -57,32 +58,64 @@ impl FrameworkAdapter for PubsubPythonAdapter {
fn detect(
&self,
summary: &FuncSummary,
_ast: tree_sitter::Node<'_>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_pubsub);
let matches_source = source_imports_pubsub(file_bytes);
if matches_call || matches_source {
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_topic(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
} else {
None
}
detect_pubsub_python(summary, None, ast, file_bytes)
}
fn detect_with_context(
&self,
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
detect_pubsub_python(summary, ssa_summary, ast, file_bytes)
}
}
fn detect_pubsub_python(
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
_ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_pubsub);
let matches_source = source_imports_pubsub(file_bytes);
if !(matches_call || matches_source) {
return None;
}
if !super::typed_receiver_facts_allow(
summary,
ssa_summary,
callee_is_pubsub,
typed_container_allows_pubsub,
) {
return None;
}
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_topic(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
}
fn typed_container_allows_pubsub(container: &str) -> bool {
let lc = container.to_ascii_lowercase();
lc.contains("pubsub") || lc.contains("subscriber") || lc.contains("subscription")
}
#[cfg(test)]
mod tests {
use super::*;
use crate::summary::CalleeSite;
fn parse_python(src: &[u8]) -> tree_sitter::Tree {
let mut parser = tree_sitter::Parser::new();
@ -109,4 +142,53 @@ mod tests {
assert_eq!(queue, "projects/p/subscriptions/s");
}
}
#[test]
fn ssa_receiver_type_rejects_non_pubsub_callback_collision() {
let src: &[u8] = b"from google.cloud import pubsub_v1\n\
def callback(message):\n timer.callback(message)\n";
let tree = parse_python(src);
let mut summary = FuncSummary {
name: "callback".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "timer.callback".to_owned(),
receiver: Some("timer".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "Timer".to_owned()));
assert!(
PubsubPythonAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_none()
);
}
#[test]
fn ssa_receiver_type_keeps_pubsub_subscriber() {
let src: &[u8] = b"from google.cloud import pubsub_v1\n\
def callback(message):\n sub.subscribe('projects/p/subscriptions/s')\n";
let tree = parse_python(src);
let mut summary = FuncSummary {
name: "callback".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "sub.subscribe".to_owned(),
receiver: Some("sub".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers
.push((0, "PubsubSubscriberClient".to_owned()));
assert!(
PubsubPythonAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_some()
);
}
}

View file

@ -5,6 +5,7 @@
use crate::dynamic::framework::{FrameworkAdapter, FrameworkBinding};
use crate::evidence::EntryKind;
use crate::summary::FuncSummary;
use crate::summary::ssa_summary::SsaFuncSummary;
use crate::symbol::Lang;
pub struct RabbitJavaAdapter;
@ -60,32 +61,64 @@ impl FrameworkAdapter for RabbitJavaAdapter {
fn detect(
&self,
summary: &FuncSummary,
_ast: tree_sitter::Node<'_>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_rabbit);
let matches_source = source_imports_rabbit(file_bytes);
if matches_call || matches_source {
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_queue(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
} else {
None
}
detect_rabbit_java(summary, None, ast, file_bytes)
}
fn detect_with_context(
&self,
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
detect_rabbit_java(summary, ssa_summary, ast, file_bytes)
}
}
fn detect_rabbit_java(
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
_ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_rabbit);
let matches_source = source_imports_rabbit(file_bytes);
if !(matches_call || matches_source) {
return None;
}
if !super::typed_receiver_facts_allow(
summary,
ssa_summary,
callee_is_rabbit,
typed_container_allows_rabbit,
) {
return None;
}
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_queue(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
}
fn typed_container_allows_rabbit(container: &str) -> bool {
let lc = container.to_ascii_lowercase();
lc.contains("rabbit") || lc.contains("amqp") || lc.contains("channel")
}
#[cfg(test)]
mod tests {
use super::*;
use crate::summary::CalleeSite;
fn parse_java(src: &[u8]) -> tree_sitter::Tree {
let mut parser = tree_sitter::Parser::new();
@ -113,4 +146,56 @@ mod tests {
assert_eq!(queue, "work");
}
}
#[test]
fn ssa_receiver_type_rejects_non_rabbit_receive_collision() {
let src: &[u8] = b"import org.springframework.amqp.rabbit.annotation.RabbitListener;\n\
public class Vuln {\n\
public void onMessage(String body) { inbox.receive(); }\n\
}\n";
let tree = parse_java(src);
let mut summary = FuncSummary {
name: "onMessage".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "inbox.receive".to_owned(),
receiver: Some("inbox".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "Inbox".to_owned()));
assert!(
RabbitJavaAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_none()
);
}
#[test]
fn ssa_receiver_type_keeps_rabbit_channel() {
let src: &[u8] = b"import com.rabbitmq.client.Channel;\n\
public class Vuln {\n\
public void onMessage(String body) { channel.basicConsume(\"work\", true, consumer); }\n\
}\n";
let tree = parse_java(src);
let mut summary = FuncSummary {
name: "onMessage".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "channel.basicConsume".to_owned(),
receiver: Some("channel".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "Channel".to_owned()));
assert!(
RabbitJavaAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_some()
);
}
}

View file

@ -4,6 +4,7 @@
use crate::dynamic::framework::{FrameworkAdapter, FrameworkBinding};
use crate::evidence::EntryKind;
use crate::summary::FuncSummary;
use crate::summary::ssa_summary::SsaFuncSummary;
use crate::symbol::Lang;
pub struct RabbitPythonAdapter;
@ -56,32 +57,64 @@ impl FrameworkAdapter for RabbitPythonAdapter {
fn detect(
&self,
summary: &FuncSummary,
_ast: tree_sitter::Node<'_>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_rabbit);
let matches_source = source_imports_rabbit(file_bytes);
if matches_call || matches_source {
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_queue(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
} else {
None
}
detect_rabbit_python(summary, None, ast, file_bytes)
}
fn detect_with_context(
&self,
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
detect_rabbit_python(summary, ssa_summary, ast, file_bytes)
}
}
fn detect_rabbit_python(
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
_ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_rabbit);
let matches_source = source_imports_rabbit(file_bytes);
if !(matches_call || matches_source) {
return None;
}
if !super::typed_receiver_facts_allow(
summary,
ssa_summary,
callee_is_rabbit,
typed_container_allows_rabbit,
) {
return None;
}
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_queue(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
}
fn typed_container_allows_rabbit(container: &str) -> bool {
let lc = container.to_ascii_lowercase();
lc.contains("rabbit") || lc.contains("pika") || lc.contains("amqp") || lc.contains("channel")
}
#[cfg(test)]
mod tests {
use super::*;
use crate::summary::CalleeSite;
fn parse_python(src: &[u8]) -> tree_sitter::Tree {
let mut parser = tree_sitter::Parser::new();
@ -108,4 +141,53 @@ mod tests {
assert_eq!(queue, "work");
}
}
#[test]
fn ssa_receiver_type_rejects_non_rabbit_process_collision() {
let src: &[u8] = b"import pika\n\
def on_message(ch, method, properties, body):\n worker.process(body)\n";
let tree = parse_python(src);
let mut summary = FuncSummary {
name: "on_message".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "worker.process".to_owned(),
receiver: Some("worker".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "Worker".to_owned()));
assert!(
RabbitPythonAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_none()
);
}
#[test]
fn ssa_receiver_type_keeps_rabbit_channel() {
let src: &[u8] = b"import pika\n\
def on_message(ch, method, properties, body):\n channel.basic_consume(queue='work')\n";
let tree = parse_python(src);
let mut summary = FuncSummary {
name: "on_message".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "channel.basic_consume".to_owned(),
receiver: Some("channel".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers
.push((0, "BlockingChannel".to_owned()));
assert!(
RabbitPythonAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_some()
);
}
}

View file

@ -3,6 +3,7 @@
use crate::dynamic::framework::{FrameworkAdapter, FrameworkBinding};
use crate::evidence::EntryKind;
use crate::summary::FuncSummary;
use crate::summary::ssa_summary::SsaFuncSummary;
use crate::symbol::Lang;
pub struct SqsJavaAdapter;
@ -54,32 +55,64 @@ impl FrameworkAdapter for SqsJavaAdapter {
fn detect(
&self,
summary: &FuncSummary,
_ast: tree_sitter::Node<'_>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_sqs);
let matches_source = source_imports_sqs(file_bytes);
if matches_call || matches_source {
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_queue(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
} else {
None
}
detect_sqs_java(summary, None, ast, file_bytes)
}
fn detect_with_context(
&self,
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
detect_sqs_java(summary, ssa_summary, ast, file_bytes)
}
}
fn detect_sqs_java(
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
_ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_sqs);
let matches_source = source_imports_sqs(file_bytes);
if !(matches_call || matches_source) {
return None;
}
if !super::typed_receiver_facts_allow(
summary,
ssa_summary,
callee_is_sqs,
typed_container_allows_sqs,
) {
return None;
}
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_queue(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
}
fn typed_container_allows_sqs(container: &str) -> bool {
let lc = container.to_ascii_lowercase();
lc.contains("sqs") || lc.contains("queue")
}
#[cfg(test)]
mod tests {
use super::*;
use crate::summary::CalleeSite;
fn parse_java(src: &[u8]) -> tree_sitter::Tree {
let mut parser = tree_sitter::Parser::new();
@ -107,4 +140,56 @@ mod tests {
assert_eq!(queue, "jobs");
}
}
#[test]
fn ssa_receiver_type_rejects_non_sqs_handle_collision() {
let src: &[u8] = b"import io.awspring.cloud.sqs.annotation.SqsListener;\n\
public class Vuln {\n\
public void handleMessage(String env) { worker.handleMessage(env); }\n\
}\n";
let tree = parse_java(src);
let mut summary = FuncSummary {
name: "handleMessage".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "worker.handleMessage".to_owned(),
receiver: Some("worker".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "Worker".to_owned()));
assert!(
SqsJavaAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_none()
);
}
#[test]
fn ssa_receiver_type_keeps_sqs_client() {
let src: &[u8] = b"import software.amazon.awssdk.services.sqs.SqsClient;\n\
public class Vuln {\n\
public void handleMessage(String env) { client.receiveMessage(); }\n\
}\n";
let tree = parse_java(src);
let mut summary = FuncSummary {
name: "handleMessage".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "client.receiveMessage".to_owned(),
receiver: Some("client".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "SqsClient".to_owned()));
assert!(
SqsJavaAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_some()
);
}
}

View file

@ -3,6 +3,7 @@
use crate::dynamic::framework::{FrameworkAdapter, FrameworkBinding};
use crate::evidence::EntryKind;
use crate::summary::FuncSummary;
use crate::summary::ssa_summary::SsaFuncSummary;
use crate::symbol::Lang;
pub struct SqsPythonAdapter;
@ -57,32 +58,64 @@ impl FrameworkAdapter for SqsPythonAdapter {
fn detect(
&self,
summary: &FuncSummary,
_ast: tree_sitter::Node<'_>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_sqs);
let matches_source = source_imports_sqs(file_bytes);
if matches_call || matches_source {
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_queue(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
} else {
None
}
detect_sqs_python(summary, None, ast, file_bytes)
}
fn detect_with_context(
&self,
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
detect_sqs_python(summary, ssa_summary, ast, file_bytes)
}
}
fn detect_sqs_python(
summary: &FuncSummary,
ssa_summary: Option<&SsaFuncSummary>,
_ast: tree_sitter::Node<'_>,
file_bytes: &[u8],
) -> Option<FrameworkBinding> {
let matches_call = super::any_callee_matches(summary, callee_is_sqs);
let matches_source = source_imports_sqs(file_bytes);
if !(matches_call || matches_source) {
return None;
}
if !super::typed_receiver_facts_allow(
summary,
ssa_summary,
callee_is_sqs,
typed_container_allows_sqs,
) {
return None;
}
Some(FrameworkBinding {
adapter: ADAPTER_NAME.to_owned(),
kind: EntryKind::MessageHandler {
queue: extract_queue(file_bytes),
message_schema: None,
},
route: None,
request_params: Vec::new(),
response_writer: None,
middleware: Vec::new(),
})
}
fn typed_container_allows_sqs(container: &str) -> bool {
let lc = container.to_ascii_lowercase();
lc.contains("sqs") || lc.contains("queue")
}
#[cfg(test)]
mod tests {
use super::*;
use crate::summary::CalleeSite;
fn parse_python(src: &[u8]) -> tree_sitter::Tree {
let mut parser = tree_sitter::Parser::new();
@ -109,4 +142,54 @@ mod tests {
assert_eq!(queue, "jobs");
}
}
#[test]
fn ssa_receiver_type_rejects_non_sqs_process_collision() {
let src: &[u8] = b"import boto3\n\
boto3.client('sqs')\n\
def handler(envelope):\n cache.process_message(envelope)\n";
let tree = parse_python(src);
let mut summary = FuncSummary {
name: "handler".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "cache.process_message".to_owned(),
receiver: Some("cache".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers.push((0, "Cache".to_owned()));
assert!(
SqsPythonAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_none()
);
}
#[test]
fn ssa_receiver_type_keeps_sqs_queue_receiver() {
let src: &[u8] = b"import boto3\n\
def handler(envelope):\n queue.process_message(envelope)\n";
let tree = parse_python(src);
let mut summary = FuncSummary {
name: "handler".into(),
..Default::default()
};
summary.callees.push(CalleeSite {
name: "queue.process_message".to_owned(),
receiver: Some("queue".to_owned()),
ordinal: 0,
..Default::default()
});
let mut ssa = SsaFuncSummary::default();
ssa.typed_call_receivers
.push((0, "SqsQueueClient".to_owned()));
assert!(
SqsPythonAdapter
.detect_with_context(&summary, Some(&ssa), tree.root_node(), src)
.is_some()
);
}
}