Skip to content

Commit 2a14640

Browse files
committed
Adjust tests
1 parent 1d2a51c commit 2a14640

File tree

6 files changed

+22
-533
lines changed

6 files changed

+22
-533
lines changed

java/ql/src/experimental/Security/CWE/CWE-073/FilePathInjection.ql

Lines changed: 0 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -16,10 +16,7 @@ import java
1616
import semmle.code.java.dataflow.TaintTracking
1717
import semmle.code.java.dataflow.ExternalFlow
1818
import semmle.code.java.dataflow.FlowSources
19-
<<<<<<< HEAD
20-
=======
2119
import semmle.code.java.security.TaintedPathQuery
22-
>>>>>>> 9e469c9c32 (Migrate path injection sinks to MaD)
2320
import JFinalController
2421
import semmle.code.java.security.PathSanitizer
2522
private import semmle.code.java.security.Sanitizers
@@ -56,11 +53,7 @@ module InjectFilePathConfig implements DataFlow::ConfigSig {
5653
predicate isSource(DataFlow::Node source) { source instanceof ThreatModelFlowSource }
5754

5855
predicate isSink(DataFlow::Node sink) {
59-
<<<<<<< HEAD
60-
sinkNode(sink, "path-injection") and
61-
=======
6256
sink instanceof TaintedPathSink and
63-
>>>>>>> 9e469c9c32 (Migrate path injection sinks to MaD)
6457
not sink instanceof NormalizedPathNode
6558
}
6659

java/ql/test/experimental/query-tests/security/CWE-073/FilePathInjection.expected

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,6 @@ edges
33
| FilePathInjection.java:64:21:64:34 | getPara(...) : String | FilePathInjection.java:72:47:72:59 | finalFilePath |
44
| FilePathInjection.java:87:21:87:34 | getPara(...) : String | FilePathInjection.java:95:47:95:59 | finalFilePath |
55
| FilePathInjection.java:177:50:177:58 | file : File | FilePathInjection.java:182:30:182:33 | file |
6-
| FilePathInjection.java:205:17:205:44 | getParameter(...) : String | FilePathInjection.java:209:24:209:31 | filePath |
76
| FilePathInjection.java:205:17:205:44 | getParameter(...) : String | FilePathInjection.java:209:24:209:31 | filePath : String |
87
| FilePathInjection.java:209:15:209:32 | new File(...) : File | FilePathInjection.java:217:19:217:22 | file : File |
98
| FilePathInjection.java:209:24:209:31 | filePath : String | FilePathInjection.java:209:15:209:32 | new File(...) : File |
@@ -19,7 +18,6 @@ nodes
1918
| FilePathInjection.java:182:30:182:33 | file | semmle.label | file |
2019
| FilePathInjection.java:205:17:205:44 | getParameter(...) : String | semmle.label | getParameter(...) : String |
2120
| FilePathInjection.java:209:15:209:32 | new File(...) : File | semmle.label | new File(...) : File |
22-
| FilePathInjection.java:209:24:209:31 | filePath | semmle.label | filePath |
2321
| FilePathInjection.java:209:24:209:31 | filePath : String | semmle.label | filePath : String |
2422
| FilePathInjection.java:217:19:217:22 | file : File | semmle.label | file : File |
2523
subpaths
@@ -28,4 +26,3 @@ subpaths
2826
| FilePathInjection.java:72:47:72:59 | finalFilePath | FilePathInjection.java:64:21:64:34 | getPara(...) : String | FilePathInjection.java:72:47:72:59 | finalFilePath | External control of file name or path due to $@. | FilePathInjection.java:64:21:64:34 | getPara(...) | user-provided value |
2927
| FilePathInjection.java:95:47:95:59 | finalFilePath | FilePathInjection.java:87:21:87:34 | getPara(...) : String | FilePathInjection.java:95:47:95:59 | finalFilePath | External control of file name or path due to $@. | FilePathInjection.java:87:21:87:34 | getPara(...) | user-provided value |
3028
| FilePathInjection.java:182:30:182:33 | file | FilePathInjection.java:205:17:205:44 | getParameter(...) : String | FilePathInjection.java:182:30:182:33 | file | External control of file name or path due to $@. | FilePathInjection.java:205:17:205:44 | getParameter(...) | user-provided value |
31-
| FilePathInjection.java:209:24:209:31 | filePath | FilePathInjection.java:205:17:205:44 | getParameter(...) : String | FilePathInjection.java:209:24:209:31 | filePath | External control of file name or path due to $@. | FilePathInjection.java:205:17:205:44 | getParameter(...) | user-provided value |

0 commit comments

Comments
 (0)