Repository navigation
Conversation
f8092fc to
57db4c8
Compare
There was a problem hiding this comment.
CodeQL found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.
def5d61 to
888eae3
Compare
888eae3 to
82e42b4
Compare
c60e983 to
45fd28e
Compare
17bf057 to
e3e1dcb
Compare
e3e1dcb to
05e44c8
Compare
05e44c8 to
bf97136
Compare
bf97136 to
97e898b
Compare
|
"Run QL for QL" is failing for all PRs at the moment. I don't think it is related to this PR. |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The deprecation change note incorrectly states that the legacy class has no instances.
Review effort: Balanced
Findings: 1
What changed in this PR
Migrates Go guard reasoning to the shared control-flow guards library and updates dependent analyses, models, and tests.
Changes:
- Adds the Go
Guard/GuardValueimplementation and shared-library extension points. - Migrates guard consumers and barrier models to the new APIs.
- Deprecates the legacy guard API and expands regression coverage.
| File | Description |
|---|---|
shared/controlflow/codeql/controlflow/Guards.qll |
Extends shared guard capabilities. |
java/ql/lib/semmle/code/java/controlflow/Guards.qll |
Adapts Java to the extended interface. |
go/ql/test/query-tests/Security/CWE-295/DisabledCertificateCheck/main.go |
Adds switch-based flag coverage. |
go/ql/test/query-tests/Security/CWE-209/test.go |
Adds switch-flow coverage. |
go/ql/test/query-tests/Security/CWE-209/StackTraceExposure.expected |
Updates expected findings. |
go/ql/test/library-tests/semmle/go/dataflow/GuardingFunctions/test.go |
Expands wrapper-guard tests. |
go/ql/test/library-tests/semmle/go/controlflow/Guards/Guards.ql |
Adds guard API test queries. |
go/ql/test/library-tests/semmle/go/controlflow/Guards/guards.go |
Adds comprehensive guard fixtures. |
go/ql/test/library-tests/semmle/go/controlflow/Guards/Guards.ext.yml |
Adds barrier-guard models. |
go/ql/test/library-tests/semmle/go/controlflow/Guards/Guards.expected |
Records expected guard results. |
go/ql/test/experimental/CWE-942/CorsMisconfiguration.go |
Adds switch-based CORS coverage. |
go/ql/test/experimental/CWE-942/CorsMisconfiguration.expected |
Updates expected CORS findings. |
go/ql/test/experimental/CWE-942/CONSISTENCY/DataFlowConsistency.expected |
Updates consistency expectations. |
go/ql/src/Security/CWE-327/InsecureTLS.ql |
Uses shared flag-control reasoning. |
go/ql/src/Security/CWE-295/DisabledCertificateCheck.ql |
Uses shared flag-control reasoning. |
go/ql/src/Security/CWE-209/StackTraceExposure.ql |
Migrates debug-flag barriers. |
go/ql/src/Security/CWE-020/IncompleteHostnameRegexp.ql |
Migrates regexp guard reasoning. |
go/ql/src/InconsistentCode/LengthComparisonOffByOne.ql |
Migrates comparison guards. |
go/ql/src/InconsistentCode/ConstantLengthComparison.ql |
Migrates length guards. |
go/ql/src/experimental/IntegerOverflow/RangeAnalysis.qll |
Uses shared range guards. |
go/ql/src/experimental/CWE-942/CorsMisconfiguration.ql |
Migrates CORS guard logic. |
go/ql/src/experimental/CWE-807/SensitiveConditionBypass.ql |
Migrates sensitive-condition guards. |
go/ql/lib/semmle/go/security/InsecureFeatureFlag.qll |
Adds flag-control abstraction. |
go/ql/lib/semmle/go/dataflow/internal/DataFlowUtil.qll |
Migrates barrier-guard infrastructure. |
go/ql/lib/semmle/go/dataflow/internal/DataFlowPrivate.qll |
Migrates unreachable-region guards. |
go/ql/lib/semmle/go/dataflow/ExternalFlow.qll |
Supports all modeled guard values. |
go/ql/lib/semmle/go/controlflow/IR.qll |
Clarifies conditional IR handling. |
go/ql/lib/semmle/go/controlflow/Guards.qll |
Instantiates shared guards for Go. |
go/ql/lib/semmle/go/controlflow/ControlFlowGraph.qll |
Deprecates legacy guard APIs. |
go/ql/lib/change-notes/2026-08-17-shared-guards.md |
Announces the shared guard API. |
go/ql/lib/change-notes/2026-08-17-deprecate-condition-guard-node.md |
Announces legacy API deprecation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Add the complete guard regression suite and fold the shared hooks and Go-specific correctness fixes into the initial adapter. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Move simple data-flow and security consumers to shared guards, including value-aware barriers and the corrected feature-flag semantics. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
fc8d706 to
c05aecb
Compare
|
There seems to be a performance problem which is causing some DCA jobs to time out. I'll investigate on Tuesday. |

Instantiate the shared guards library for Go, port over all uses of the Go-specific
ConditionGuardNodeand deprecate it.Go-specific issues encountered: