Reviewed By: sblackshear Differential Revision: D2739191 fb-gh-sync-id: 5c66a48master
parent
c6b8682dd6
commit
c8b80f2435
@ -0,0 +1,94 @@
|
||||
/*
|
||||
* Copyright (c) 2015 - present Facebook, Inc.
|
||||
* All rights reserved.
|
||||
*
|
||||
* This source code is licensed under the BSD style license found in the
|
||||
* LICENSE file in the root directory of this source tree. An additional grant
|
||||
* of patent rights can be found in the PATENTS file in the same directory.
|
||||
*/
|
||||
|
||||
#import <Foundation/Foundation.h>
|
||||
#import <UIKit/UIKit.h>
|
||||
|
||||
BOOL ExampleSanitizer(NSURL * u, int f)
|
||||
{
|
||||
if (f) __set_untaint_attribute(u);
|
||||
return f;
|
||||
}
|
||||
|
||||
@interface ExampleViewController : NSObject
|
||||
- (void)loadURL:(NSURL *)URL
|
||||
trackingCodes:(NSArray *)trackingCodes;
|
||||
@end
|
||||
|
||||
@implementation ExampleViewController
|
||||
- (void) dealloc
|
||||
{
|
||||
[self dealloc];
|
||||
}
|
||||
- (void)loadURL:(NSURL *)URL
|
||||
trackingCodes: (NSArray *)trackingCodes
|
||||
{
|
||||
// Require untainted URL
|
||||
};
|
||||
@end
|
||||
|
||||
@interface B : NSObject
|
||||
- (void) another_url_pass: (NSURL *) u;
|
||||
@end
|
||||
|
||||
@implementation B
|
||||
- (void) dealloc
|
||||
{
|
||||
[self dealloc];
|
||||
}
|
||||
- (void) another_url_pass: (NSURL *) u
|
||||
{
|
||||
ExampleViewController *vc = [[ExampleViewController alloc] init];
|
||||
[vc loadURL:u trackingCodes:nil];
|
||||
[vc dealloc];
|
||||
}
|
||||
@end
|
||||
|
||||
@interface A : NSObject
|
||||
- (void) pass_url_arond:(NSURL *) u;
|
||||
@end
|
||||
|
||||
@implementation A
|
||||
- (void) dealloc
|
||||
{
|
||||
[self dealloc];
|
||||
}
|
||||
- (void) pass_url_arond: (NSURL *) u
|
||||
{
|
||||
B* b = [[B alloc] init];
|
||||
[b another_url_pass:u];
|
||||
[b dealloc];
|
||||
}
|
||||
@end
|
||||
|
||||
@interface ExampleDelegate : NSObject
|
||||
- (BOOL)application: (UIApplication *)application
|
||||
openURL: (NSURL *)URL
|
||||
sourceApplication: (NSString *)sourceApplication
|
||||
annotation: (id)annotation;
|
||||
@end
|
||||
|
||||
@implementation ExampleDelegate
|
||||
- (BOOL)application: (UIApplication *)application
|
||||
openURL: (NSURL *)URL
|
||||
sourceApplication: (NSString *)sourceApplication
|
||||
annotation: (id)annotation
|
||||
{
|
||||
// Assume tainted URL;
|
||||
A* a = [[A alloc] init];
|
||||
if (!ExampleSanitizer(URL, 0 )) {
|
||||
[a pass_url_arond:URL]; // report taint
|
||||
}
|
||||
if (!ExampleSanitizer(URL, 1 )) {
|
||||
[a pass_url_arond:URL]; // No taint
|
||||
}
|
||||
[a dealloc];
|
||||
return YES;
|
||||
}
|
||||
@end
|
@ -0,0 +1,67 @@
|
||||
/*
|
||||
* Copyright (c) 2013 - present Facebook, Inc.
|
||||
* All rights reserved.
|
||||
*
|
||||
* This source code is licensed under the BSD style license found in the
|
||||
* LICENSE file in the root directory of this source tree. An additional grant
|
||||
* of patent rights can be found in the PATENTS file in the same directory.
|
||||
*/
|
||||
|
||||
package endtoend.objc;
|
||||
|
||||
import static org.hamcrest.MatcherAssert.assertThat;
|
||||
import static utils.matchers.ResultContainsExactly.containsExactly;
|
||||
|
||||
import com.google.common.collect.ImmutableList;
|
||||
|
||||
import org.junit.BeforeClass;
|
||||
import org.junit.ClassRule;
|
||||
import org.junit.Test;
|
||||
|
||||
import java.io.IOException;
|
||||
|
||||
import utils.DebuggableTemporaryFolder;
|
||||
import utils.InferException;
|
||||
import utils.InferResults;
|
||||
import utils.InferRunner;
|
||||
|
||||
public class TaintTest {
|
||||
|
||||
public static final String TaintFile =
|
||||
"infer/tests/codetoanalyze/objc/errors/taint/viewController.m";
|
||||
|
||||
public static final String TAINTED_VALUE = "TAINTED_VALUE_REACHING_SENSITIVE_FUNCTION";
|
||||
|
||||
private static ImmutableList<String> inferCmd;
|
||||
|
||||
@ClassRule
|
||||
public static DebuggableTemporaryFolder folder = new DebuggableTemporaryFolder();
|
||||
|
||||
|
||||
@BeforeClass
|
||||
public static void runInfer() throws InterruptedException, IOException {
|
||||
inferCmd = InferRunner.createObjCInferCommand(
|
||||
folder,
|
||||
TaintFile);
|
||||
}
|
||||
|
||||
@Test
|
||||
public void whenInferRunsOnTaintFileErrorFound()
|
||||
throws InterruptedException, IOException, InferException {
|
||||
InferResults inferResults = InferRunner.runInferObjC(inferCmd);
|
||||
String[] methods = {
|
||||
"application:openURL:sourceApplication:annotation:"
|
||||
};
|
||||
|
||||
assertThat(
|
||||
"Results should contain tainted value reaching sensitive function.",
|
||||
inferResults,
|
||||
containsExactly(
|
||||
TAINTED_VALUE,
|
||||
TaintFile,
|
||||
methods
|
||||
)
|
||||
);
|
||||
}
|
||||
|
||||
}
|
Loading…
Reference in new issue