You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用CodeQL CLI执行数据流查询时遇INVALID_RESULT_PATTERNS错误求助

解决CodeQL CLI路径问题查询的INVALID_RESULT_PATTERNS错误

问题原因

当查询标记为@kind path-problem时,CodeQL CLI要求查询必须返回**路径边(edges)**结果集,用于构建完整的数据流路径展示。VS Code的CodeQL扩展会自动处理路径边的收集逻辑,但CLI需要显式在查询中声明并选择这些边,否则会触发路径问题查询缺少预期结果模式,需至少包含edges结果集的错误。

解决方案

修改查询的from和select部分,加入路径边的查询逻辑,确保CLI能获取到完整的路径信息:

修改后的完整查询

/** 
 * @name Exposure of sensitive information in servlet responses
 * @description Writing sensitive information from exceptions or sensitive file paths to HTTP responses can leak details to users.
 * @kind path-problem
 * @problem.severity warning
 * @id CWE-536
 * @tags security
 *       external/cwe/cwe-536
 * @cwe CWE-536
 */

import java
import semmle.code.java.dataflow.TaintTracking
import semmle.code.java.frameworks.Servlets
import semmle.code.java.dataflow.FlowSources
import semmle.code.java.dataflow.DataFlow
import semmle.code.java.security.SensitiveVariables
import MyFlow::PathGraph

module SensitiveInfoLeakServletConfig implements DataFlow::ConfigSig {

  predicate isSource(DataFlow::Node source) { 
    exists(MethodAccess ma |
      // Sources from exceptions
      ma.getMethod().getDeclaringType().getASupertype*().hasQualifiedName("java.lang", "Throwable") and
      (ma.getMethod().hasName(["getMessage", "getStackTrace", "getStackTraceAsString", "printStackTrace"])) and
      source.asExpr() = ma
    )
    or
    exists(MethodAccess ma |
      // Additional sources: Sensitive file paths
      ma.getMethod().hasName("getAbsolutePath") and
      ma.getMethod().getDeclaringType().hasQualifiedName("java.io", "File") and
      source.asExpr() = ma
    )
    or
    exists(SensitiveVariableExpr sve |
      source.asExpr() = sve
    )
   }
  predicate isSink(DataFlow::Node sink) { 
    exists(MethodAccess ma |
      // Ensuring write is called on servlet response
      ma.getMethod().hasName("write") and
      ma.getQualifier().(MethodAccess).getMethod().hasName("getWriter") and
      ma.getQualifier().(MethodAccess).getQualifier().getType().(RefType).hasQualifiedName("javax.servlet.http", "HttpServletResponse") and
      sink.asExpr() = ma.getAnArgument()
    ) or
    exists(MethodAccess ma |
      // Inferring println on PrintWriter obtained from servlet response, assuming context
      ma.getMethod().hasName("println") and
      ma.getQualifier().getType().(RefType).hasQualifiedName("java.io", "PrintWriter") and
      // Additional context checks might be added here to more directly associate with servlets
      sink.asExpr() = ma.getAnArgument()
    )
  }
}

module MyFlow = DataFlow::Global<SensitiveInfoLeakServletConfig>;

// 新增路径边的查询逻辑
from MyFlow::PathNode source, MyFlow::PathNode sink, MyFlow::PathEdge edge
where MyFlow::flowPath(source, sink) and MyFlow::PathGraph::getPathEdges(source, sink, edge)
select sink, source, edge, "Potential CWE-536: Servlet Runtime Error Message Containing Sensitive Information."

关键修改点

  1. 添加PathEdge到from子句:引入MyFlow::PathEdge edge捕获数据流路径中的每一条边。
  2. 关联路径边与源/ sink:使用MyFlow::PathGraph::getPathEdges(source, sink, edge)确保只获取连接当前source和sink的路径边。
  3. 更新select语句:将edge作为第三个参数返回,满足CLI对path-problem查询的结果集要求。

额外优化建议

  • 删除重复导入的semmle.code.java.dataflow.TaintTracking,减少冗余。
  • 如果不需要展示完整数据流路径,可将查询的@kind改为problem,但会失去路径可视化能力。

内容的提问来源于stack exchange,提问作者Kyler

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 18:26:13