Skip to content

cpp: model BDE bdlbb::Blob byte-buffer taint flow - #22455

Open
kumarak wants to merge 1 commit into
github:mainfrom
trail-of-forks:kumarak/cpp-bdlbb-blob-models
Open

cpp: model BDE bdlbb::Blob byte-buffer taint flow#22455
kumarak wants to merge 1 commit into
github:mainfrom
trail-of-forks:kumarak/cpp-bdlbb-blob-models

Conversation

@kumarak

@kumarak kumarak commented Aug 27, 2026

Copy link
Copy Markdown
Contributor

Add flow summaries for the BDE segmented byte buffer BloombergLP::bdlbb::Blob so taint reaches a blob's payload bytes:

  • Accessor chain: Blob::buffer taints the returned BlobBuffer, and BlobBuffer::data/buffer taint the bytes.
  • bdlbb::BlobUtil::copy and getContiguousRangeOrCopy propagate taint between a blob and a flat buffer in both directions.

This unblocks blob-carried sources such as bmqa::Message::getData, whose payload was previously stranded on the opaque Blob object. Not a duplicate; the bdlbb namespace had no coverage. Verified with a BloombergLP::bdlbb-shaped stub in the dataflow external-models harness.

Copilot AI balanced review requested due to automatic review settings August 27, 2026 19:52
@kumarak
kumarak requested a review from a team as a code owner August 27, 2026 19:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds BDE bdlbb::Blob taint-flow models for payload access and copying.

Changes:

  • Models Blob and BlobBuffer accessors.
  • Models BlobUtil copy operations.
  • Adds external-model tests and release notes.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.

Show a summary per file
File Description
cpp/ql/lib/ext/bdlbb.model.yml Defines flow summaries.
cpp/ql/test/library-tests/dataflow/external-models/bdlbb.cpp Adds test stubs and cases.
cpp/ql/test/library-tests/dataflow/external-models/flow.expected Updates expected flow results.
cpp/ql/test/library-tests/dataflow/external-models/steps.expected Updates expected summary steps.
cpp/ql/lib/change-notes/2026-08-27-bdlbb-blob-models.md Documents the analysis improvement.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
# Accessor chain: a tainted blob taints its buffers, and a tainted buffer taints its bytes.
- ["BloombergLP::bdlbb", "Blob", true, "buffer", "", "", "Argument[-1]", "ReturnValue[*]", "taint", "manual"]
- ["BloombergLP::bdlbb", "BlobBuffer", true, "data", "", "", "Argument[-1]", "ReturnValue[*]", "taint", "manual"]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we at least want to add BlobBuffer::buffer() here. bsl::shared_ptr<char> seems out-of-scope.

@jketema jketema left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again only looked at this briefly.

Comment thread cpp/ql/lib/ext/bdlbb.model.yml Outdated
- ["BloombergLP::bdlbb", "BlobBuffer", true, "data", "", "", "Argument[-1]", "ReturnValue[*]", "taint", "manual"]
# BlobUtil read-out: the source blob (Argument[*1]) taints the destination buffer (and the
# returned contiguous range).
- ["BloombergLP::bdlbb", "BlobUtil", true, "copy", "", "", "Argument[*1]", "Argument[*0]", "taint", "manual"]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Like in the case of the protobuf PR. I think you need to be more specific here, as there seem to be three variants of copy and the input argument can either be argument 1 or argument 2.

Add flow summaries for the BDE segmented byte buffer
BloombergLP::bdlbb::Blob so taint reaches a blob's payload bytes:

- Accessor chain: Blob::buffer taints the returned BlobBuffer, and
  BlobBuffer::data/buffer taint the bytes.
- bdlbb::BlobUtil::copy and getContiguousRangeOrCopy propagate taint
  between a blob and a flat buffer in both directions.

This unblocks blob-carried sources such as bmqa::Message::getData, whose
payload was previously stranded on the opaque Blob object. Not a
duplicate; the bdlbb namespace had no coverage. Verified with a
BloombergLP::bdlbb-shaped stub in the dataflow external-models harness.
@kumarak
kumarak force-pushed the kumarak/cpp-bdlbb-blob-models branch from 420d1c1 to 8701ce9 Compare August 30, 2026 21:04

@jketema jketema left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would again reduce the amount of comments. Otherwise this LGTM.

pack: codeql/cpp-all
extensible: summaryModel
data: # namespace, type, subtypes, name, signature, ext, input, output, kind, provenance
# Accessor chain: a tainted blob taints its buffers, and a tainted buffer taints its bytes.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
# Accessor chain: a tainted blob taints its buffers, and a tainted buffer taints its bytes.
# Accessor chain

Comment on lines +11 to +12
# BlobUtil read-out: the source blob (Argument[*1]) taints the destination buffer (and the
# returned contiguous range).

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
# BlobUtil read-out: the source blob (Argument[*1]) taints the destination buffer (and the
# returned contiguous range).
# BlobUtil read-out

Comment on lines +16 to +18
# BlobUtil write-in: the source (Argument[*2]) taints the destination blob. `copy` has two
# write-in overloads, one taking a raw byte buffer and one taking another blob as the source;
# each row pins the exact signature so the int offset/length arguments are never tainted.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
# BlobUtil write-in: the source (Argument[*2]) taints the destination blob. `copy` has two
# write-in overloads, one taking a raw byte buffer and one taking another blob as the source;
# each row pins the exact signature so the int offset/length arguments are never tainted.
# BlobUtil write-in

---
category: minorAnalysis
---
* Added flow summaries for the BDE `bdlbb::Blob` segmented byte buffer (`BloombergLP::bdlbb`). Taint now flows from a blob to its bytes through the `Blob::buffer`/`BlobBuffer::data` accessor chain and through the `bdlbb::BlobUtil::copy` and `getContiguousRangeOrCopy` helpers, so a blob populated from untrusted input (for example a BlazingMQ message body read via `bmqa::Message::getData`) is tracked into the payload bytes.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I would again shorten this.

Suggested change
* Added flow summaries for the BDE `bdlbb::Blob` segmented byte buffer (`BloombergLP::bdlbb`). Taint now flows from a blob to its bytes through the `Blob::buffer`/`BlobBuffer::data` accessor chain and through the `bdlbb::BlobUtil::copy` and `getContiguousRangeOrCopy` helpers, so a blob populated from untrusted input (for example a BlazingMQ message body read via `bmqa::Message::getData`) is tracked into the payload bytes.
* Added flow summaries for the BDE `BloombergLP::bdlbb::Blob` segmented byte buffer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants