Conversation
There was a problem hiding this comment.
🟢 Approval recommended
The summaries match the referenced API signatures and are comprehensively validated within the stated scope.
Pull request overview
Adds C++ taint summaries for BDE Base64 and hexadecimal pointer-buffer conversions.
Changes:
- Models both
convertoverloads across four BDE converter classes. - Adds positive, negative, inheritance, and overload coverage.
- Documents the new analysis support.
File summaries
| File | Description |
|---|---|
cpp/ql/lib/ext/bdlde.model.yml |
Defines conversion summaries. |
cpp/ql/lib/change-notes/2026-09-14-bdlde-conversion-models.md |
Adds the change note. |
cpp/ql/test/library-tests/dataflow/bdlde/bdlde.h |
Declares test API fixtures. |
cpp/ql/test/library-tests/dataflow/bdlde/test.cpp |
Exercises modeled behavior. |
cpp/ql/test/library-tests/dataflow/bdlde/flow.ql |
Configures taint-flow testing. |
cpp/ql/test/library-tests/dataflow/bdlde/flow.expected |
Records expected test output. |
cpp/ql/test/library-tests/dataflow/external-models/validatemodels.expected |
Updates model-validation expectations. |
Review details
- Files reviewed: 6/7 changed files
- Comments generated: 0
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
geoffw0
left a comment
There was a problem hiding this comment.
Looks good, couple of questions...
| template <class OUT, class IN> | ||
| int Base64Encoder::convert(OUT out, IN begin, IN end) { | ||
| *out = *begin; | ||
| return 0; |
There was a problem hiding this comment.
I'm not clear why these convert functions need to have bodies, since you've modelled the flow in QL (BdldePointerConversion)?
| template <class OUTPUT_ITERATOR, class INPUT_ITERATOR> | ||
| int convert(OUTPUT_ITERATOR out, int *numOut, int *numIn, | ||
| INPUT_ITERATOR begin, INPUT_ITERATOR end, int maxNumOut = -1); | ||
| }; |
There was a problem hiding this comment.
I appreciate the effort to construct test cases with all the necessary library stubs here. Have you confirmed at your end that the models are equally effective in real world code, that uses the actual libraries instead of stubs?
|
See questions above. There may well be no changes needed, but I'll wait for your answers. |
Adds taint summaries for both convert overloads of BDE bdlde
Base64Encoder,Base64Decoder,HexEncoder, andHexDecoder, propagating input bytes to the output buffer. The models match the member templates by signature and use subtypes: false, so hiding methods in derived classes do not inherit the summary.API evidence: BDE bdlde headers at ec310b87e008199ecbdbc00a0b0264a53d806a0a under Apache 2.0.
Scope is limited to direct pointer-buffer conversion; stateful flows and endConvert are left for follow-up work.
Validation covers all four classes, overloads, const/mutable inputs, inheritance/hiding behavior, and external-model validation.