Skip to content

Go: Use shared guards library - #22365

Open
owen-mc wants to merge 6 commits into
github:mainfrom
owen-mc:go/shared-guards
Open

owen-mc wants to merge 6 commits into
github:mainfrom
owen-mc:go/shared-guards

Conversation

@owen-mc

@owen-mc owen-mc commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

No description provided.

Comment thread go/ql/lib/semmle/go/controlflow/Guards.qll Fixed
* idiom.
*/
pragma[inline]
predicate guardEnsures(Expr e, boolean b, BasicBlock bb) { e.(Guard).controls(bb, b) }
Comment thread go/ql/lib/semmle/go/dataflow/internal/DataFlowUtil.qll Fixed

@github-advanced-security github-advanced-security AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CodeQL found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.

@owen-mc
owen-mc force-pushed the go/shared-guards branch 2 times, most recently from def5d61 to 888eae3 Compare August 18, 2026 11:45
Comment thread go/ql/lib/semmle/go/controlflow/Guards.qll Fixed
Comment thread go/ql/lib/semmle/go/controlflow/Guards.qll Fixed
Comment thread go/ql/lib/semmle/go/dataflow/internal/DataFlowUtil.qll Fixed
Comment thread go/ql/src/InconsistentCode/LengthComparisonOffByOne.ql Fixed
Comment thread go/ql/src/InconsistentCode/LengthComparisonOffByOne.ql Fixed
Comment thread go/ql/src/InconsistentCode/LengthComparisonOffByOne.ql Fixed
Comment thread go/ql/lib/semmle/go/controlflow/Guards.qll
owen-mc and others added 6 commits October 6, 2026 16:41
Add the complete guard regression suite and fold the shared hooks and Go-specific correctness fixes into the initial adapter.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Move simple data-flow and security consumers to shared guards, including value-aware barriers and the corrected feature-flag semantics.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@owen-mc

owen-mc commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor Author

"Run QL for QL" is failing for all PRs at the moment. I don't think it is related to this PR.

@owen-mc
owen-mc marked this pull request as ready for review October 6, 2026 16:28
Copilot AI balanced review requested due to automatic review settings October 6, 2026 16:28
@owen-mc
owen-mc requested review from a team as code owners October 6, 2026 16:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The deprecation change note incorrectly states that the legacy class has no instances.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Migrates Go guard reasoning to the shared control-flow guards library and updates dependent analyses, models, and tests.

Changes:

  • Adds the Go Guard/GuardValue implementation and shared-library extension points.
  • Migrates guard consumers and barrier models to the new APIs.
  • Deprecates the legacy guard API and expands regression coverage.
File Description
shared/​controlflow/​codeql/​controlflow/​Guards.qll Extends shared guard capabilities.
java/​ql/​lib/​semmle/​code/​java/​controlflow/​Guards.qll Adapts Java to the extended interface.
go/​ql/​test/​query-tests/​Security/​CWE-295/​DisabledCertificateCheck/​main.go Adds switch-based flag coverage.
go/​ql/​test/​query-tests/​Security/​CWE-209/​test.go Adds switch-flow coverage.
go/​ql/​test/​query-tests/​Security/​CWE-209/​StackTraceExposure.expected Updates expected findings.
go/​ql/​test/​library-tests/​semmle/​go/​dataflow/​GuardingFunctions/​test.go Expands wrapper-guard tests.
go/​ql/​test/​library-tests/​semmle/​go/​controlflow/​Guards/​Guards.ql Adds guard API test queries.
go/​ql/​test/​library-tests/​semmle/​go/​controlflow/​Guards/​guards.go Adds comprehensive guard fixtures.
go/​ql/​test/​library-tests/​semmle/​go/​controlflow/​Guards/​Guards.ext.yml Adds barrier-guard models.
go/​ql/​test/​library-tests/​semmle/​go/​controlflow/​Guards/​Guards.expected Records expected guard results.
go/​ql/​test/​experimental/​CWE-942/​CorsMisconfiguration.go Adds switch-based CORS coverage.
go/​ql/​test/​experimental/​CWE-942/​CorsMisconfiguration.expected Updates expected CORS findings.
go/​ql/​test/​experimental/​CWE-942/​CONSISTENCY/​DataFlowConsistency.expected Updates consistency expectations.
go/​ql/​src/​Security/​CWE-327/​InsecureTLS.ql Uses shared flag-control reasoning.
go/​ql/​src/​Security/​CWE-295/​DisabledCertificateCheck.ql Uses shared flag-control reasoning.
go/​ql/​src/​Security/​CWE-209/​StackTraceExposure.ql Migrates debug-flag barriers.
go/​ql/​src/​Security/​CWE-020/​IncompleteHostnameRegexp.ql Migrates regexp guard reasoning.
go/​ql/​src/​InconsistentCode/​LengthComparisonOffByOne.ql Migrates comparison guards.
go/​ql/​src/​InconsistentCode/​ConstantLengthComparison.ql Migrates length guards.
go/​ql/​src/​experimental/​IntegerOverflow/​RangeAnalysis.qll Uses shared range guards.
go/​ql/​src/​experimental/​CWE-942/​CorsMisconfiguration.ql Migrates CORS guard logic.
go/​ql/​src/​experimental/​CWE-807/​SensitiveConditionBypass.ql Migrates sensitive-condition guards.
go/​ql/​lib/​semmle/​go/​security/​InsecureFeatureFlag.qll Adds flag-control abstraction.
go/​ql/​lib/​semmle/​go/​dataflow/​internal/​DataFlowUtil.qll Migrates barrier-guard infrastructure.
go/​ql/​lib/​semmle/​go/​dataflow/​internal/​DataFlowPrivate.qll Migrates unreachable-region guards.
go/​ql/​lib/​semmle/​go/​dataflow/​ExternalFlow.qll Supports all modeled guard values.
go/​ql/​lib/​semmle/​go/​controlflow/​IR.qll Clarifies conditional IR handling.
go/​ql/​lib/​semmle/​go/​controlflow/​Guards.qll Instantiates shared guards for Go.
go/​ql/​lib/​semmle/​go/​controlflow/​ControlFlowGraph.qll Deprecates legacy guard APIs.
go/​ql/​lib/​change-notes/​2026-08-17-shared-guards.md Announces the shared guard API.
go/​ql/​lib/​change-notes/​2026-08-17-deprecate-condition-guard-node.md Announces legacy API deprecation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

---
category: deprecated
---
* `ControlFlow::ConditionGuardNode` is now deprecated and has no instances. Use the API from `semmle.go.controlflow.Guards` instead. No newline at end of file

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants