Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: github/codeql
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 5187e9a
Choose a base ref
...
head repository: github/codeql
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 8178a8d
Choose a head ref
  • 1 commit
  • 247 files changed
  • 1 contributor

Commits on Jun 1, 2026

  1. Python: switch dataflow library to new (shared) CFG + SSA

    Flips the Python dataflow trunk from the legacy CFG (semmle/python/Flow.qll)
    and legacy ESSA SSA (semmle/python/essa/*) to the new shared CFG facade
    (semmle.python.controlflow.internal.Cfg) and the new SSA adapter
    (semmle.python.dataflow.new.internal.SsaImpl), both introduced
    additively in the preceding PRs in this stack.
    
    This is the trunk-flip equivalent of the original draft PR #21894 (kept
    around as documentation), rebased on top of the four preparatory PRs:
    
      P1: Remove AstNode.getAFlowNode() and rewrite callers (#21919).
      P2: Qualify Flow.qll's AST references with Py:: prefix (#21920).
      P3: Add new shared-CFG-backed control flow graph (#21921).
      P4: Add new shared-SSA-backed SSA adapter (#21923).
    
    The Python dataflow library (semmle/python/dataflow/new/) now imports
    the new CFG facade and SSA adapter. All CFG-typed predicates
    (ControlFlowNode, CallNode, BasicBlock, NameNode, AttrNode, ...) are
    qualified with the Cfg:: prefix; SSA references switch from
    EssaVariable/EssaDefinition to SsaImpl::Definition/SourceVariable.
    
    GuardNode is redesigned to use the new CFG's outcome-node model
    (isAfterTrue / isAfterFalse) instead of the legacy ConditionBlock +
    flipped indirection. Only BarrierGuard<...> is preserved as public
    API.
    
    Framework files (Bottle, FastApi, Django, Tornado, Pyramid, Stdlib,
    ...) are updated to take CFG nodes from the new facade.
    
    A handful of dataflow consistency tweaks for the new CFG:
    - Augmented-assignment targets are treated as both load and store.
    - 'from X import *' produces uncertain SSA writes for unknown names.
    - CFG nodes are canonicalised so dataflow does not see equivalent
      pre/post-order pairs as distinct nodes.
    
    Two AST tweaks for the new CFG:
    - AstNodeImpl: omit PEP 695 type-parameter names from
      FunctionDefExpr / ClassDefExpr children.
    - ImportResolution: drop the legacy essa import.
    
    Test churn (~175 files): reblessed library- and query-test .expected
    files reflect slightly different CFG granularity, different toString
    output, and a handful of true alert deltas in security queries.
    
    Verification: all 367 lib + src + consistency-queries compile clean.
    
    Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
    Copilot authored and yoff committed Jun 1, 2026
    Configuration menu
    Copy the full SHA
    8178a8d View commit details
    Browse the repository at this point in the history
Loading