Skip to content

Python: Model bytearray construction and take_bytes - #22746

Merged
tausbn merged 1 commit into
mainfrom
tausbn/python315-model-bytearray-and-take-bytes
Oct 8, 2026
Merged

tausbn merged 1 commit into
mainfrom
tausbn/python315-model-bytearray-and-take-bytes

Conversation

@tausbn

@tausbn tausbn commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

We model these as string-like taint preserving steps.

We model these as string-like taint preserving steps.
@tausbn
tausbn marked this pull request as ready for review October 2, 2026 13:37
@tausbn
tausbn requested a review from a team as a code owner October 2, 2026 13:37
Copilot AI balanced review requested due to automatic review settings October 2, 2026 13:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation matches the documented behavior and includes comprehensive focused tests.

Review effort: Balanced
Findings: None

What changed in this PR

Adds taint-preserving models for Python byte-array construction and extraction.

Changes:

  • Models taint flow through bytearray(...) and bytearray.take_bytes.
  • Adds coverage for bound, unbound, aliased, partial, and consuming calls.
  • Documents the analysis improvement.
File Description
TaintTrackingPrivate.qll Implements byte-array taint steps.
test_bytearray.py Tests supported flows and known imprecision.
2026-09-22-python315-take-bytes.md Adds the change note.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@geoffw0 geoffw0 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. I encourage you to consider modelling .clear() as that seems like a straightforward improvement.

buffer = bytearray(b"abc")
taint(buffer)
buffer.clear()
ensure_not_tainted(buffer) # $ SPURIOUS: tainted

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This could be fixed easily with a barrier model, right?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think you're right. I'll add this as a follow-up PR.

@tausbn
tausbn merged commit 1874e77 into main Oct 8, 2026
21 checks passed
@tausbn
tausbn deleted the tausbn/python315-model-bytearray-and-take-bytes branch October 8, 2026 11:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants