Repository navigation
Conversation
| * idiom. | ||
| */ | ||
| pragma[inline] | ||
| predicate guardEnsures(Expr e, boolean b, BasicBlock bb) { e.(Guard).controls(bb, b) } |
owen-mc
force-pushed
the
go/shared-guards
branch
from
August 17, 2026 19:16
f8092fc to
57db4c8
Compare
Contributor
There was a problem hiding this comment.
CodeQL found more than 20 potential problems in the proposed changes. Check the Files changed tab for more details.
owen-mc
force-pushed
the
go/shared-guards
branch
2 times, most recently
from
August 18, 2026 11:45
def5d61 to
888eae3
Compare
owen-mc
force-pushed
the
go/shared-guards
branch
from
September 20, 2026 22:01
888eae3 to
82e42b4
Compare
owen-mc
force-pushed
the
go/shared-guards
branch
from
September 22, 2026 15:40
c60e983 to
45fd28e
Compare
owen-mc
force-pushed
the
go/shared-guards
branch
from
September 30, 2026 22:46
17bf057 to
e3e1dcb
Compare
owen-mc
force-pushed
the
go/shared-guards
branch
from
October 1, 2026 13:53
e3e1dcb to
05e44c8
Compare
owen-mc
force-pushed
the
go/shared-guards
branch
from
October 6, 2026 14:46
05e44c8 to
bf97136
Compare
Add the complete guard regression suite and fold the shared hooks and Go-specific correctness fixes into the initial adapter. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Move simple data-flow and security consumers to shared guards, including value-aware barriers and the corrected feature-flag semantics. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
owen-mc
force-pushed
the
go/shared-guards
branch
from
October 6, 2026 15:42
bf97136 to
97e898b
Compare
Contributor
Author
|
"Run QL for QL" is failing for all PRs at the moment. I don't think it is related to this PR. |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The deprecation change note incorrectly states that the legacy class has no instances.
Review effort: Balanced
Findings: 1
What changed in this PR
Migrates Go guard reasoning to the shared control-flow guards library and updates dependent analyses, models, and tests.
Changes:
- Adds the Go
Guard/GuardValueimplementation and shared-library extension points. - Migrates guard consumers and barrier models to the new APIs.
- Deprecates the legacy guard API and expands regression coverage.
| File | Description |
|---|---|
shared/controlflow/codeql/controlflow/Guards.qll |
Extends shared guard capabilities. |
java/ql/lib/semmle/code/java/controlflow/Guards.qll |
Adapts Java to the extended interface. |
go/ql/test/query-tests/Security/CWE-295/DisabledCertificateCheck/main.go |
Adds switch-based flag coverage. |
go/ql/test/query-tests/Security/CWE-209/test.go |
Adds switch-flow coverage. |
go/ql/test/query-tests/Security/CWE-209/StackTraceExposure.expected |
Updates expected findings. |
go/ql/test/library-tests/semmle/go/dataflow/GuardingFunctions/test.go |
Expands wrapper-guard tests. |
go/ql/test/library-tests/semmle/go/controlflow/Guards/Guards.ql |
Adds guard API test queries. |
go/ql/test/library-tests/semmle/go/controlflow/Guards/guards.go |
Adds comprehensive guard fixtures. |
go/ql/test/library-tests/semmle/go/controlflow/Guards/Guards.ext.yml |
Adds barrier-guard models. |
go/ql/test/library-tests/semmle/go/controlflow/Guards/Guards.expected |
Records expected guard results. |
go/ql/test/experimental/CWE-942/CorsMisconfiguration.go |
Adds switch-based CORS coverage. |
go/ql/test/experimental/CWE-942/CorsMisconfiguration.expected |
Updates expected CORS findings. |
go/ql/test/experimental/CWE-942/CONSISTENCY/DataFlowConsistency.expected |
Updates consistency expectations. |
go/ql/src/Security/CWE-327/InsecureTLS.ql |
Uses shared flag-control reasoning. |
go/ql/src/Security/CWE-295/DisabledCertificateCheck.ql |
Uses shared flag-control reasoning. |
go/ql/src/Security/CWE-209/StackTraceExposure.ql |
Migrates debug-flag barriers. |
go/ql/src/Security/CWE-020/IncompleteHostnameRegexp.ql |
Migrates regexp guard reasoning. |
go/ql/src/InconsistentCode/LengthComparisonOffByOne.ql |
Migrates comparison guards. |
go/ql/src/InconsistentCode/ConstantLengthComparison.ql |
Migrates length guards. |
go/ql/src/experimental/IntegerOverflow/RangeAnalysis.qll |
Uses shared range guards. |
go/ql/src/experimental/CWE-942/CorsMisconfiguration.ql |
Migrates CORS guard logic. |
go/ql/src/experimental/CWE-807/SensitiveConditionBypass.ql |
Migrates sensitive-condition guards. |
go/ql/lib/semmle/go/security/InsecureFeatureFlag.qll |
Adds flag-control abstraction. |
go/ql/lib/semmle/go/dataflow/internal/DataFlowUtil.qll |
Migrates barrier-guard infrastructure. |
go/ql/lib/semmle/go/dataflow/internal/DataFlowPrivate.qll |
Migrates unreachable-region guards. |
go/ql/lib/semmle/go/dataflow/ExternalFlow.qll |
Supports all modeled guard values. |
go/ql/lib/semmle/go/controlflow/IR.qll |
Clarifies conditional IR handling. |
go/ql/lib/semmle/go/controlflow/Guards.qll |
Instantiates shared guards for Go. |
go/ql/lib/semmle/go/controlflow/ControlFlowGraph.qll |
Deprecates legacy guard APIs. |
go/ql/lib/change-notes/2026-08-17-shared-guards.md |
Announces the shared guard API. |
go/ql/lib/change-notes/2026-08-17-deprecate-condition-guard-node.md |
Announces legacy API deprecation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| --- | ||
| category: deprecated | ||
| --- | ||
| * `ControlFlow::ConditionGuardNode` is now deprecated and has no instances. Use the API from `semmle.go.controlflow.Guards` instead. No newline at end of file |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

No description provided.