使用CodeQL CLI执行数据流查询时遇INVALID_RESULT_PATTERNS错误求助
解决CodeQL CLI路径问题查询的
INVALID_RESULT_PATTERNS错误 问题原因
当查询标记为@kind path-problem时,CodeQL CLI要求查询必须返回**路径边(edges)**结果集,用于构建完整的数据流路径展示。VS Code的CodeQL扩展会自动处理路径边的收集逻辑,但CLI需要显式在查询中声明并选择这些边,否则会触发路径问题查询缺少预期结果模式,需至少包含edges结果集的错误。
解决方案
修改查询的from和select部分,加入路径边的查询逻辑,确保CLI能获取到完整的路径信息:
修改后的完整查询
/** * @name Exposure of sensitive information in servlet responses * @description Writing sensitive information from exceptions or sensitive file paths to HTTP responses can leak details to users. * @kind path-problem * @problem.severity warning * @id CWE-536 * @tags security * external/cwe/cwe-536 * @cwe CWE-536 */ import java import semmle.code.java.dataflow.TaintTracking import semmle.code.java.frameworks.Servlets import semmle.code.java.dataflow.FlowSources import semmle.code.java.dataflow.DataFlow import semmle.code.java.security.SensitiveVariables import MyFlow::PathGraph module SensitiveInfoLeakServletConfig implements DataFlow::ConfigSig { predicate isSource(DataFlow::Node source) { exists(MethodAccess ma | // Sources from exceptions ma.getMethod().getDeclaringType().getASupertype*().hasQualifiedName("java.lang", "Throwable") and (ma.getMethod().hasName(["getMessage", "getStackTrace", "getStackTraceAsString", "printStackTrace"])) and source.asExpr() = ma ) or exists(MethodAccess ma | // Additional sources: Sensitive file paths ma.getMethod().hasName("getAbsolutePath") and ma.getMethod().getDeclaringType().hasQualifiedName("java.io", "File") and source.asExpr() = ma ) or exists(SensitiveVariableExpr sve | source.asExpr() = sve ) } predicate isSink(DataFlow::Node sink) { exists(MethodAccess ma | // Ensuring write is called on servlet response ma.getMethod().hasName("write") and ma.getQualifier().(MethodAccess).getMethod().hasName("getWriter") and ma.getQualifier().(MethodAccess).getQualifier().getType().(RefType).hasQualifiedName("javax.servlet.http", "HttpServletResponse") and sink.asExpr() = ma.getAnArgument() ) or exists(MethodAccess ma | // Inferring println on PrintWriter obtained from servlet response, assuming context ma.getMethod().hasName("println") and ma.getQualifier().getType().(RefType).hasQualifiedName("java.io", "PrintWriter") and // Additional context checks might be added here to more directly associate with servlets sink.asExpr() = ma.getAnArgument() ) } } module MyFlow = DataFlow::Global<SensitiveInfoLeakServletConfig>; // 新增路径边的查询逻辑 from MyFlow::PathNode source, MyFlow::PathNode sink, MyFlow::PathEdge edge where MyFlow::flowPath(source, sink) and MyFlow::PathGraph::getPathEdges(source, sink, edge) select sink, source, edge, "Potential CWE-536: Servlet Runtime Error Message Containing Sensitive Information."
关键修改点
- 添加PathEdge到from子句:引入
MyFlow::PathEdge edge捕获数据流路径中的每一条边。 - 关联路径边与源/ sink:使用
MyFlow::PathGraph::getPathEdges(source, sink, edge)确保只获取连接当前source和sink的路径边。 - 更新select语句:将
edge作为第三个参数返回,满足CLI对path-problem查询的结果集要求。
额外优化建议
- 删除重复导入的
semmle.code.java.dataflow.TaintTracking,减少冗余。 - 如果不需要展示完整数据流路径,可将查询的
@kind改为problem,但会失去路径可视化能力。
内容的提问来源于stack exchange,提问作者Kyler
相关产品推荐
相关产品推荐

