Skip to content

Rust: Model futures-io, rustls, futures-rustls #19626

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 10 commits into from
Jun 10, 2025
Merged

Conversation

geoffw0
Copy link
Contributor

@geoffw0 geoffw0 commented May 29, 2025

Add models for futures-io (traits, part of futures-rs), and for rustls + futures-rustls (which uses the traits and includes what seem like high value sources).

Most of these work well, but the models for poll_read and poll_fill_buf aren't working reliably. I haven't been able to figure out what's wrong and I suspect it isn't an issue with the models themselves.

There's also a fix of the test sink recognition logic that allows the test to find sinks in sources/web_frameworks.rs, which also gives us a few results in sources/web_frameworks.rs that we should have been finding all along.

@Copilot Copilot AI review requested due to automatic review settings May 29, 2025 16:03
@geoffw0 geoffw0 requested a review from a team as a code owner May 29, 2025 16:03
@geoffw0 geoffw0 added no-change-note-required This PR does not need a change note Rust Pull requests that update Rust code labels May 29, 2025
Copy link
Contributor

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR adds CodeQL models and tests to improve taint-tracking for asynchronous I/O in Rust, covering futures-io, rustls, and futures-rustls. It also fixes test sink recognition in the web_frameworks suite.

  • Introduce test_futures_io.rs and test_rustls in test.rs to exercise AsyncRead/AsyncBufRead patterns over TLS streams.
  • Add dependency entries for rustls, futures-rustls, and async-std in options.yml.
  • Provide new model YAMLs (rustls.model.yml, futures.model.yml, async-rs.model.yml) to define taint sources and summaries for the relevant crates.

Reviewed Changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
rust/ql/test/library-tests/dataflow/sources/web_frameworks.rs Update expected sink annotations from $ MISSING to $ hasTaintFlow.
rust/ql/test/library-tests/dataflow/sources/test_futures_io.rs New tests covering AsyncRead/AsyncBufRead over TLS streams.
rust/ql/test/library-tests/dataflow/sources/test.rs Add test_rustls function and invoke it from main.
rust/ql/test/library-tests/dataflow/sources/options.yml Add rustls, futures-rustls, and async-std dependencies.
rust/ql/test/library-tests/dataflow/sources/TaintSources.expected Update expected taint alerts for new connection and args sources.
rust/ql/test/library-tests/dataflow/sources/InlineFlow.ql Broaden sink matching predicate to %::sink.
rust/ql/lib/codeql/rust/frameworks/rustls.model.yml Add source/summary model entries for rustls and futures-rustls.
rust/ql/lib/codeql/rust/frameworks/futures.model.yml Add summary model entries for futures-util I/O and streams.
rust/ql/lib/codeql/rust/frameworks/async-rs.model.yml Add source model entry for async-std TCP connect.

extensible: summaryModel
data:
- ["repo:https://github.com/quininer/futures-rustls:futures-rustls", "<crate::TlsConnector>::connect", "Argument[1]", "ReturnValue.Future.Field[crate::result::Result::Ok(0)]", "taint", "manual"]
- ["repo:https://github.com/quininer/futures-rustls:futures-rustls", "<crate::client::TlsStream as crate::if_std::AsyncRead>::poll_read", "Argument[self].Reference", "Argument[1].Reference", "taint", "manual"]
Copy link
Preview

Copilot AI May 29, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add a summaryModel entry for <crate::client::TlsStream as crate::if_std::AsyncBufRead>::poll_fill_buf so that taint is correctly propagated through buffered reads, mirroring the existing poll_read rule.

Suggested change
- ["repo:https://github.com/quininer/futures-rustls:futures-rustls", "<crate::client::TlsStream as crate::if_std::AsyncRead>::poll_read", "Argument[self].Reference", "Argument[1].Reference", "taint", "manual"]
- ["repo:https://github.com/quininer/futures-rustls:futures-rustls", "<crate::client::TlsStream as crate::if_std::AsyncRead>::poll_read", "Argument[self].Reference", "Argument[1].Reference", "taint", "manual"]
- ["repo:https://github.com/quininer/futures-rustls:futures-rustls", "<crate::client::TlsStream as crate::if_std::AsyncBufRead>::poll_fill_buf", "Argument[self].Reference", "ReturnValue.Reference", "taint", "manual"]

Copilot uses AI. Check for mistakes.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice try, but it doesn't help. Hopefully when we have support for MaD trait models, we can clean this stuff up.

Comment on lines +8 to +15
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncReadExt::read", "Argument[self]", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncReadExt::read", "Argument[self].Reference", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncReadExt::read_to_end", "Argument[self]", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncReadExt::read_to_end", "Argument[self].Reference", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncBufReadExt::read_line", "Argument[self]", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncBufReadExt::read_line", "Argument[self].Reference", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncBufReadExt::read_until", "Argument[self]", "Argument[1].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncBufReadExt::read_until", "Argument[self].Reference", "Argument[1].Reference", "taint", "manual"]
Copy link
Preview

Copilot AI May 29, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nitpick] These two read rules only differ by .Reference. Consider consolidating into a single pattern (e.g., match Argument[self]) to reduce duplication and maintenance overhead.

Suggested change
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncReadExt::read", "Argument[self]", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncReadExt::read", "Argument[self].Reference", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncReadExt::read_to_end", "Argument[self]", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncReadExt::read_to_end", "Argument[self].Reference", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncBufReadExt::read_line", "Argument[self]", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncBufReadExt::read_line", "Argument[self].Reference", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncBufReadExt::read_until", "Argument[self]", "Argument[1].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncBufReadExt::read_until", "Argument[self].Reference", "Argument[1].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncReadExt::read", "Argument[self].*", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncReadExt::read_to_end", "Argument[self].*", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncBufReadExt::read_line", "Argument[self].*", "Argument[0].Reference", "taint", "manual"]
- ["repo:https://github.com/rust-lang/futures-rs:futures-util", "crate::io::AsyncBufReadExt::read_until", "Argument[self].*", "Argument[1].Reference", "taint", "manual"]

Copilot uses AI. Check for mistakes.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There's missing data flow through certain implicit dereferences, when that's fixed we can get rid of the duplicate models.

paldepind
paldepind previously approved these changes Jun 10, 2025
Copy link
Contributor

@paldepind paldepind left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me. I've created an internal issue for the problem about the same model not working for both function calls and method calls.

In reader.read(&mut buffer2) there is an implicit borrow of reader, so this is equivalent to (&reader).read(&mut buffer2). Therefore I think that the model that we actually want is the ones from 4d51a15 with Argument[self].Reference and not the ones with Argument[self].

@geoffw0
Copy link
Contributor Author

geoffw0 commented Jun 10, 2025

I've created an internal issue for the problem about the same model not working for both function calls and method calls.

Thanks, that's fantastic.

I've just merged in a recent main, it looks that will make the consistency check failure go away...

@geoffw0
Copy link
Contributor Author

geoffw0 commented Jun 10, 2025

It turns out I needed an even more recent main than my first attempt. The consistency check failure / merge conflict is now fixed.

Ready for re-approval and merge.

@geoffw0
Copy link
Contributor Author

geoffw0 commented Jun 10, 2025

Thanks!

@geoffw0 geoffw0 merged commit 652d32d into github:main Jun 10, 2025
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
no-change-note-required This PR does not need a change note Rust Pull requests that update Rust code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants