Reviewed By: sblackshear Differential Revision: D3054009 fbshipit-source-id: 6f6a20amaster
parent
b7b31982ee
commit
f37ed66888
@ -0,0 +1,22 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (c) 2015 - present Facebook, Inc.
|
||||||
|
* All rights reserved.
|
||||||
|
*
|
||||||
|
* This source code is licensed under the BSD style license found in the
|
||||||
|
* LICENSE file in the root directory of this source tree. An additional grant
|
||||||
|
* of patent rights can be found in the PATENTS file in the same directory.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#import <Foundation/NSObject.h>
|
||||||
|
#import <Foundation/NSString.h>
|
||||||
|
|
||||||
|
@interface NSHTTPCookie : NSObject
|
||||||
|
@property(readonly, copy) NSString* value;
|
||||||
|
@end
|
||||||
|
|
||||||
|
@implementation NSHTTPCookie
|
||||||
|
@synthesize value;
|
||||||
|
- (NSString*)value {
|
||||||
|
return value;
|
||||||
|
}
|
||||||
|
@end
|
@ -0,0 +1,44 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (c) 2016 - present Facebook, Inc.
|
||||||
|
* All rights reserved.
|
||||||
|
*
|
||||||
|
* This source code is licensed under the BSD style license found in the
|
||||||
|
* LICENSE file in the root directory of this source tree. An additional grant
|
||||||
|
* of patent rights can be found in the PATENTS file in the same directory.
|
||||||
|
*/
|
||||||
|
|
||||||
|
#import <Foundation/NSObject.h>
|
||||||
|
#import <Foundation/NSString.h>
|
||||||
|
#import <Foundation/NSHTTPCookie.h>
|
||||||
|
|
||||||
|
void testNSHTTPCookie1() {
|
||||||
|
|
||||||
|
NSHTTPCookie* c = [NSHTTPCookie new];
|
||||||
|
NSString* s = c.value;
|
||||||
|
|
||||||
|
[NSString stringWithFormat:@"Test taint %@: ", s];
|
||||||
|
}
|
||||||
|
|
||||||
|
void testNSHTTPCookie2() {
|
||||||
|
|
||||||
|
NSHTTPCookie* c = [NSHTTPCookie new];
|
||||||
|
NSString* s = c.value;
|
||||||
|
|
||||||
|
[NSString localizedStringWithFormat:@"Test taint %@: ", s];
|
||||||
|
}
|
||||||
|
|
||||||
|
void testNSHTTPCookie3() {
|
||||||
|
|
||||||
|
NSHTTPCookie* c = [NSHTTPCookie new];
|
||||||
|
NSString* s = c.value;
|
||||||
|
|
||||||
|
[[NSString alloc] initWithFormat:@"Test taint %@", s];
|
||||||
|
}
|
||||||
|
|
||||||
|
void testNSHTTPCookie4() {
|
||||||
|
|
||||||
|
NSHTTPCookie* c = [NSHTTPCookie new];
|
||||||
|
NSString* s = c.value;
|
||||||
|
|
||||||
|
[NSString stringWithString:s];
|
||||||
|
}
|
@ -0,0 +1,72 @@
|
|||||||
|
/*
|
||||||
|
* Copyright (c) 2013 - present Facebook, Inc.
|
||||||
|
* All rights reserved.
|
||||||
|
*
|
||||||
|
* This source code is licensed under the BSD style license found in the
|
||||||
|
* LICENSE file in the root directory of this source tree. An additional grant
|
||||||
|
* of patent rights can be found in the PATENTS file in the same directory.
|
||||||
|
*/
|
||||||
|
|
||||||
|
package endtoend.objc;
|
||||||
|
|
||||||
|
import static org.hamcrest.MatcherAssert.assertThat;
|
||||||
|
import static utils.matchers.ResultContainsExactly.containsExactly;
|
||||||
|
|
||||||
|
import com.google.common.collect.ImmutableList;
|
||||||
|
|
||||||
|
import org.junit.BeforeClass;
|
||||||
|
import org.junit.ClassRule;
|
||||||
|
import org.junit.Test;
|
||||||
|
|
||||||
|
import java.io.IOException;
|
||||||
|
|
||||||
|
import utils.DebuggableTemporaryFolder;
|
||||||
|
import utils.InferException;
|
||||||
|
import utils.InferResults;
|
||||||
|
import utils.InferRunner;
|
||||||
|
|
||||||
|
public class Taint2Test {
|
||||||
|
|
||||||
|
public static final String TaintFile =
|
||||||
|
"infer/tests/codetoanalyze/objc/errors/taint/sources.m";
|
||||||
|
|
||||||
|
public static final String TAINTED_VALUE = "TAINTED_VALUE_REACHING_SENSITIVE_FUNCTION";
|
||||||
|
|
||||||
|
private static ImmutableList<String> inferCmd;
|
||||||
|
|
||||||
|
@ClassRule
|
||||||
|
public static DebuggableTemporaryFolder folder = new DebuggableTemporaryFolder();
|
||||||
|
|
||||||
|
|
||||||
|
@BeforeClass
|
||||||
|
public static void runInfer() throws InterruptedException, IOException {
|
||||||
|
inferCmd = InferRunner.createObjCInferCommandWithMLBuckets(
|
||||||
|
folder,
|
||||||
|
TaintFile,
|
||||||
|
"cf",
|
||||||
|
false);
|
||||||
|
}
|
||||||
|
|
||||||
|
@Test
|
||||||
|
public void whenInferRunsOnTaintFileErrorFound()
|
||||||
|
throws InterruptedException, IOException, InferException {
|
||||||
|
InferResults inferResults = InferRunner.runInferObjC(inferCmd);
|
||||||
|
String[] methods = {
|
||||||
|
"testNSHTTPCookie1",
|
||||||
|
"testNSHTTPCookie2",
|
||||||
|
"testNSHTTPCookie3",
|
||||||
|
"testNSHTTPCookie4"
|
||||||
|
};
|
||||||
|
|
||||||
|
assertThat(
|
||||||
|
"Results should contain tainted value reaching sensitive function.",
|
||||||
|
inferResults,
|
||||||
|
containsExactly(
|
||||||
|
TAINTED_VALUE,
|
||||||
|
TaintFile,
|
||||||
|
methods
|
||||||
|
)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
}
|
Loading…
Reference in new issue