使用joern-slice的--sink-filter参数时触发空指针异常求助
问题:Joern数据流切片触发空指针异常,正则过滤参数问题
问题场景
我需要对下述Node.js代码中的exec(opener + ' "' + escape(target) + '"', callback)语句做数据流切片,执行命令joern-slice data-flow --sink-filter exec\([\S\s]+\) cpg.bin时触发空指针异常:
WARN DataFlowSlicing$: Exception encountered during slicing task java.util.concurrent.ExecutionException: java.lang.NullPointerException: Cannot invoke "java.lang.CharSequence.length()" because "this.text" is null.
我怀疑问题出在--sink-filter参数的正则表达式上,求解决办法。
相关Node.js源码
var exec = require('child_process').exec , path = require('path') ; /** * open a file or uri using the default application for the file type. * * @return {ChildProcess} - the child process object. * @param {string} target - the file/uri to open. * @param {string} appName - (optional) the application to be used to open the * file (for example, "chrome", "firefox") * @param {function(Error)} callback - called with null on success, or * an error object that contains a property 'code' with the exit * code of the process. */ module.exports = open; function open(target, appName, callback) { var opener; if (typeof(appName) === 'function') { callback = appName; appName = null; } switch (process.platform) { case 'darwin': if (appName) { opener = 'open -a "' + escape(appName) + '"'; } else { opener = 'open'; } break; case 'win32': // if the first parameter to start is quoted, it uses that as the title // so we pass a blank title so we can quote the file we are opening if (appName) { opener = 'start "" "' + escape(appName) + '"'; } else { opener = 'start ""'; } break; default: if (appName) { opener = escape(appName); } else { // use Portlands xdg-open everywhere else opener = path.join(__dirname, './xdg-open'); } break; } if (process.env.SUDO_USER) { opener = 'sudo -u ' + process.env.SUDO_USER + ' ' + opener; } return exec(opener + ' "' + escape(target) + '"', callback); } function escape(s) { return s.replace(/"/g, '\\"'); }
解决方法
- 优化正则表达式:原正则
exec\([\S\s]+\)会匹配任意字符(包括可能的空文本节点),改用更精准的exec\([^)]+\),只匹配括号内的非括号字符,避免触发空文本解析问题。 - 修复shell转义:命令行中的正则可能被shell转义破坏,用单引号包裹正则表达式,确保Joern能正确接收:
joern-slice data-flow --sink-filter 'exec\([^)]+\)' cpg.bin - 改用函数名精确匹配:如果只需要定位
exec函数调用,直接用函数名过滤更稳定,无需正则:joern-slice data-flow --sink-filter "name=exec" cpg.bin - 重新生成CPG文件:空指针也可能是CPG生成不完整导致的,重新解析代码生成CPG:
确认生成过程无报错后再执行切片命令。joern-parse your-nodejs-file.js --output cpg.bin
内容的提问来源于stack exchange,提问作者zhanS
相关产品推荐
相关产品推荐

