From f09618a6e0d74f79cfe67cc76a417084c684ca78 Mon Sep 17 00:00:00 2001 From: Tom Hvitved Date: Thu, 1 Oct 2026 09:34:35 +0200 Subject: [PATCH] Unified: Join on both `name` and `namespace` in `derivedStoreReadStep` --- .../ql/lib/codeql/unified/internal/StaticNameBinding.qll | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/unified/ql/lib/codeql/unified/internal/StaticNameBinding.qll b/unified/ql/lib/codeql/unified/internal/StaticNameBinding.qll index b225539526a1..f1773347374e 100644 --- a/unified/ql/lib/codeql/unified/internal/StaticNameBinding.qll +++ b/unified/ql/lib/codeql/unified/internal/StaticNameBinding.qll @@ -335,14 +335,19 @@ module Track { } } +pragma[nomagic] +private predicate derivedStoreReadStep0(NamespaceNode namespace, string name, NameBindingNode node2) { + readStep(namespace.ref(), pragma[only_bind_into](name), node2) +} + /** * Holds if `node1 -> node2` is derived by combining a store and a read step, with zero or more value steps and inheritance steps in-between. */ pragma[nomagic] private predicate derivedStoreReadStep(NameBindingNode node1, NameBindingNode node2) { exists(NamespaceNode namespace, string name | - node1 = namespace.getMember(pragma[only_bind_into](name)) and // getMember() combines a store step with subsequent inheritance steps - readStep(namespace.ref(), pragma[only_bind_into](name), node2) and + node1 = namespace.getMember(name) and // getMember() combines a store step with subsequent inheritance steps + derivedStoreReadStep0(namespace, name, node2) and node1 != node2 ) }