Skip to content

Commit 01920ee

Browse files
fix(assail): retain AffineScript deserialization checks (#186)
Restores JSON.parseExn detection for canonical .affine and legacy .aff inputs after those files begin reaching the AffineScript analyzer. The existing positive-control test now proves both the DSL analyzer path and UnsafeDeserialization coverage. This keeps VeriSimDB classification keys semantically exercised after its .res to .affine migration. Verified with cargo test analyze_affinescript_extension_reaches_dsl_analyzer and git diff --check.
1 parent 3d261eb commit 01920ee

1 file changed

Lines changed: 27 additions & 1 deletion

File tree

‎src/assail/analyzer.rs‎

Lines changed: 27 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4998,6 +4998,25 @@ impl Analyzer {
49984998
});
49994999
}
50005000

5001+
// AffineScript uses ReScript-compatible JSON bindings. Preserve the
5002+
// unsafe-deserialization coverage that canonical `.affine` sources
5003+
// received when they were historically scanned as ReScript files.
5004+
if (file_path.ends_with(".aff") || file_path.ends_with(".affine"))
5005+
&& content.contains("JSON.parseExn")
5006+
{
5007+
weak_points.push(WeakPoint {
5008+
file: None,
5009+
line: None,
5010+
category: WeakPointCategory::UnsafeDeserialization,
5011+
location: Some(file_path.to_string()),
5012+
severity: Severity::High,
5013+
description: format!("JSON.parseExn in {}", file_path),
5014+
recommended_attack: vec![AttackAxis::Memory],
5015+
suppressed: false,
5016+
test_context: None,
5017+
});
5018+
}
5019+
50015020
// Resource budgets (Eclexia-specific)
50025021
if file_path.ends_with(".ecl") {
50035022
stats.allocation_sites += content.matches("budget").count();
@@ -6567,7 +6586,7 @@ mod tests {
65676586
let affine_file = tmp.path().join("ffi_boundary.affine");
65686587
fs::write(
65696588
&affine_file,
6570-
"external one\nexternal two\nexternal three\nexternal four\n",
6589+
"external one\nexternal two\nexternal three\nexternal four\nJSON.parseExn(input)\n",
65716590
)
65726591
.unwrap();
65736592

@@ -6584,6 +6603,13 @@ mod tests {
65846603
.any(|point| point.category == WeakPointCategory::UnsafeFFI),
65856604
".affine files must reach the AffineScript analyzer, not Unknown"
65866605
);
6606+
assert!(
6607+
report
6608+
.weak_points
6609+
.iter()
6610+
.any(|point| point.category == WeakPointCategory::UnsafeDeserialization),
6611+
".affine files must retain JSON.parseExn detection"
6612+
);
65876613
}
65886614

65896615
// ---------------------------------------------------------------

0 commit comments

Comments
 (0)