Skip to content

Commit af3c341

Browse files
committed
Fixup test case
1 parent 9fb6864 commit af3c341

File tree

3 files changed

+10
-8
lines changed

3 files changed

+10
-8
lines changed

javascript/ql/test/library-tests/TaintTracking/BasicTaintTracking.expected

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ legacyDataFlowDifference
3333
| promise.js:12:20:12:27 | source() | promise.js:13:8:13:23 | resolver.promise | only flow with OLD data flow library |
3434
| sanitizer-guards.js:57:11:57:18 | source() | sanitizer-guards.js:64:8:64:8 | x | only flow with NEW data flow library |
3535
| use-use-after-implicit-read.js:7:17:7:24 | source() | use-use-after-implicit-read.js:8:10:8:17 | captured | only flow with OLD data flow library |
36-
| use-use-after-implicit-read.js:7:17:7:24 | source() | use-use-after-implicit-read.js:13:10:13:10 | x | only flow with NEW data flow library |
36+
| use-use-after-implicit-read.js:7:17:7:24 | source() | use-use-after-implicit-read.js:15:10:15:10 | x | only flow with NEW data flow library |
3737
consistencyIssue
3838
| library-tests/TaintTracking/nested-props.js:20 | expected an alert, but found none | NOT OK - but not found | Consistency |
3939
| library-tests/TaintTracking/stringification-read-steps.js:17 | expected an alert, but found none | NOT OK | Consistency |
@@ -291,7 +291,7 @@ flow
291291
| tst.js:2:13:2:20 | source() | tst.js:48:10:48:22 | new Buffer(x) |
292292
| tst.js:2:13:2:20 | source() | tst.js:51:10:51:31 | seriali ... ript(x) |
293293
| tst.js:2:13:2:20 | source() | tst.js:54:14:54:19 | unsafe |
294-
| use-use-after-implicit-read.js:7:17:7:24 | source() | use-use-after-implicit-read.js:13:10:13:10 | x |
294+
| use-use-after-implicit-read.js:7:17:7:24 | source() | use-use-after-implicit-read.js:15:10:15:10 | x |
295295
| xml.js:5:18:5:25 | source() | xml.js:8:14:8:17 | text |
296296
| xml.js:12:17:12:24 | source() | xml.js:13:14:13:19 | result |
297297
| xml.js:23:18:23:25 | source() | xml.js:20:14:20:17 | attr |

javascript/ql/test/library-tests/TaintTracking/DataFlowTracking.expected

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ legacyDataFlowDifference
2424
| sanitizer-guards.js:57:11:57:18 | source() | sanitizer-guards.js:64:8:64:8 | x | only flow with NEW data flow library |
2525
| tst.js:2:13:2:20 | source() | tst.js:35:14:35:16 | ary | only flow with NEW data flow library |
2626
| tst.js:2:13:2:20 | source() | tst.js:41:14:41:16 | ary | only flow with NEW data flow library |
27-
| use-use-after-implicit-read.js:7:17:7:24 | source() | use-use-after-implicit-read.js:13:10:13:10 | x | only flow with NEW data flow library |
27+
| use-use-after-implicit-read.js:7:17:7:24 | source() | use-use-after-implicit-read.js:15:10:15:10 | x | only flow with NEW data flow library |
2828
flow
2929
| access-path-sanitizer.js:2:18:2:25 | source() | access-path-sanitizer.js:4:8:4:12 | obj.x |
3030
| advanced-callgraph.js:2:13:2:20 | source() | advanced-callgraph.js:6:22:6:22 | v |
@@ -182,4 +182,4 @@ flow
182182
| tst.js:2:13:2:20 | source() | tst.js:35:14:35:16 | ary |
183183
| tst.js:2:13:2:20 | source() | tst.js:41:14:41:16 | ary |
184184
| tst.js:2:13:2:20 | source() | tst.js:54:14:54:19 | unsafe |
185-
| use-use-after-implicit-read.js:7:17:7:24 | source() | use-use-after-implicit-read.js:13:10:13:10 | x |
185+
| use-use-after-implicit-read.js:7:17:7:24 | source() | use-use-after-implicit-read.js:15:10:15:10 | x |

javascript/ql/test/library-tests/TaintTracking/use-use-after-implicit-read.js

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,14 @@
11
import 'dummy';
22

3-
function f() {
3+
function f(x) {
44
let captured;
5-
function inner() { captured = "sdf"; return captured; }
5+
function inner() { captured; captured = "sdf"; }
66

7-
captured = [source(), "safe"];
7+
captured = [source(), "safe", x];
88
sink(captured); // NOT OK [INCONSISTENCY] - no implicit read of ArrayElement
9-
g.apply(undefined, captured);
9+
g.apply(undefined, captured); // with use-use flow the output of an implicit read might flow here
10+
11+
return captured;
1012
}
1113

1214
function g(x, y) {

0 commit comments

Comments
 (0)