first commit
This commit is contained in:
@@ -0,0 +1,63 @@
|
||||
"""AST-level boundary error injection for JavaScript using esprima."""
|
||||
|
||||
from typing import Optional
|
||||
|
||||
import esprima
|
||||
|
||||
from app.dataset.rules.base import Mutation, MutationRule
|
||||
|
||||
|
||||
class JSBoundaryErrorRule(MutationRule):
|
||||
"""Mutate array length boundary from `<` to `<=`.
|
||||
|
||||
Uses `esprima` to locate a binary expression comparing against `.length`
|
||||
and flips the operator.
|
||||
"""
|
||||
|
||||
name = "js_boundary_error"
|
||||
language = "javascript"
|
||||
defect_type = "boundary_condition_error"
|
||||
|
||||
def detect_and_mutate(self, source: str, filename: str = "") -> Optional[Mutation]:
|
||||
# Modern JS is usually ESM: try module grammar first, then script.
|
||||
try:
|
||||
tree = esprima.parseModule(source, loc=True)
|
||||
except Exception:
|
||||
try:
|
||||
tree = esprima.parseScript(source, loc=True)
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
for node in self._walk(tree):
|
||||
if node.type != "BinaryExpression" or node.operator != "<":
|
||||
continue
|
||||
right = node.right
|
||||
if right.type == "MemberExpression" and getattr(right.property, "name", None) == "length":
|
||||
line_no = node.loc.start.line
|
||||
lines = source.splitlines(keepends=True)
|
||||
line = lines[line_no - 1]
|
||||
mutated_line = line.replace("<", "<=", 1)
|
||||
if mutated_line == line:
|
||||
continue
|
||||
mutated = "".join(lines[:line_no - 1] + [mutated_line] + lines[line_no:])
|
||||
return Mutation(
|
||||
defect_type=self.defect_type,
|
||||
language=self.language,
|
||||
line_start=line_no,
|
||||
line_end=line_no,
|
||||
mutated_source=mutated,
|
||||
reference_fix="Use strict `< length` to avoid out-of-bounds access.",
|
||||
description="Changed array boundary check to off-by-one (<= length).",
|
||||
)
|
||||
return None
|
||||
|
||||
def _walk(self, node):
|
||||
yield node
|
||||
for key in getattr(node, "__dict__", {}):
|
||||
child = getattr(node, key)
|
||||
if isinstance(child, list):
|
||||
for item in child:
|
||||
if hasattr(item, "type"):
|
||||
yield from self._walk(item)
|
||||
elif hasattr(child, "type"):
|
||||
yield from self._walk(child)
|
||||
@@ -0,0 +1,60 @@
|
||||
"""AST-level concurrency issue injection for JavaScript using esprima."""
|
||||
|
||||
from typing import Optional
|
||||
|
||||
import esprima
|
||||
|
||||
from app.dataset.rules.base import Mutation, MutationRule
|
||||
|
||||
|
||||
class JSConcurrencyRule(MutationRule):
|
||||
"""Remove an `await mutex.acquire()` / `mutex.release()` pair.
|
||||
|
||||
Uses `esprima` to locate a try block followed by a finally that releases a
|
||||
mutex and removes the finally/release, exposing a race.
|
||||
"""
|
||||
|
||||
name = "js_concurrency"
|
||||
language = "javascript"
|
||||
defect_type = "concurrency_issue"
|
||||
|
||||
def detect_and_mutate(self, source: str, filename: str = "") -> Optional[Mutation]:
|
||||
# Modern JS is usually ESM: try module grammar first, then script.
|
||||
try:
|
||||
tree = esprima.parseModule(source, loc=True)
|
||||
except Exception:
|
||||
try:
|
||||
tree = esprima.parseScript(source, loc=True)
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
def walk(node):
|
||||
yield node
|
||||
for key in node.__dict__:
|
||||
child = getattr(node, key)
|
||||
if isinstance(child, list):
|
||||
for item in child:
|
||||
if hasattr(item, "type"):
|
||||
yield from walk(item)
|
||||
elif hasattr(child, "type"):
|
||||
yield from walk(child)
|
||||
|
||||
for node in walk(tree):
|
||||
if node.type != "TryStatement" or not node.finalizer:
|
||||
continue
|
||||
start = node.loc.start.line
|
||||
end = node.finalizer.loc.end.line
|
||||
lines = source.splitlines(keepends=True)
|
||||
# Drop the entire finally block; the try block ends on the same line as finally starts
|
||||
finally_start = node.finalizer.loc.start.line - 1
|
||||
mutated = "".join(lines[:finally_start] + [" }\n"] + lines[end:])
|
||||
return Mutation(
|
||||
defect_type=self.defect_type,
|
||||
language=self.language,
|
||||
line_start=start,
|
||||
line_end=end,
|
||||
mutated_source=mutated,
|
||||
reference_fix="Restore mutex release in finally to protect the critical section.",
|
||||
description="Removed mutex release, exposing a race condition.",
|
||||
)
|
||||
return None
|
||||
@@ -0,0 +1,61 @@
|
||||
"""AST-level logical operator misuse injection for JavaScript using esprima."""
|
||||
|
||||
from typing import Optional
|
||||
|
||||
import esprima
|
||||
|
||||
from app.dataset.rules.base import Mutation, MutationRule
|
||||
|
||||
|
||||
class JSLogicOperatorRule(MutationRule):
|
||||
"""Swap `&&` with `||` in a boolean expression.
|
||||
|
||||
Uses `esprima` to locate a LogicalExpression using `&&` and replaces the
|
||||
operator with `||`.
|
||||
"""
|
||||
|
||||
name = "js_logic_operator"
|
||||
language = "javascript"
|
||||
defect_type = "logic_operator_misuse"
|
||||
|
||||
def detect_and_mutate(self, source: str, filename: str = "") -> Optional[Mutation]:
|
||||
# Modern JS is usually ESM: try module grammar first, then script.
|
||||
try:
|
||||
tree = esprima.parseModule(source, loc=True)
|
||||
except Exception:
|
||||
try:
|
||||
tree = esprima.parseScript(source, loc=True)
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
for node in self._walk(tree):
|
||||
if node.type != "LogicalExpression" or node.operator != "&&":
|
||||
continue
|
||||
line_no = node.loc.start.line
|
||||
lines = source.splitlines(keepends=True)
|
||||
line = lines[line_no - 1]
|
||||
mutated_line = line.replace("&&", "||", 1)
|
||||
if mutated_line == line:
|
||||
continue
|
||||
mutated = "".join(lines[:line_no - 1] + [mutated_line] + lines[line_no:])
|
||||
return Mutation(
|
||||
defect_type=self.defect_type,
|
||||
language=self.language,
|
||||
line_start=line_no,
|
||||
line_end=line_no,
|
||||
mutated_source=mutated,
|
||||
reference_fix="Restore `&&` for correct short-circuit logic.",
|
||||
description="Replaced boolean `&&` with `||`.",
|
||||
)
|
||||
return None
|
||||
|
||||
def _walk(self, node):
|
||||
yield node
|
||||
for key in getattr(node, "__dict__", {}):
|
||||
child = getattr(node, key)
|
||||
if isinstance(child, list):
|
||||
for item in child:
|
||||
if hasattr(item, "type"):
|
||||
yield from self._walk(item)
|
||||
elif hasattr(child, "type"):
|
||||
yield from self._walk(child)
|
||||
@@ -0,0 +1,76 @@
|
||||
"""AST-level null-pointer injection for JavaScript using esprima."""
|
||||
|
||||
from typing import Optional
|
||||
|
||||
import esprima
|
||||
|
||||
from app.dataset.rules.base import Mutation, MutationRule
|
||||
|
||||
|
||||
class JSNoneReferenceRule(MutationRule):
|
||||
"""Remove a `if (x !== null)` guard in JavaScript.
|
||||
|
||||
Uses the Python port of `esprima` to locate the guard statement and
|
||||
replaces it with the body, leaving a potential null dereference.
|
||||
"""
|
||||
|
||||
name = "js_none_reference"
|
||||
language = "javascript"
|
||||
defect_type = "null_pointer"
|
||||
|
||||
def detect_and_mutate(self, source: str, filename: str = "") -> Optional[Mutation]:
|
||||
# Modern JS is usually ESM: try module grammar first, then script.
|
||||
try:
|
||||
tree = esprima.parseModule(source, loc=True)
|
||||
except Exception:
|
||||
try:
|
||||
tree = esprima.parseScript(source, loc=True)
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
def walk(node):
|
||||
yield node
|
||||
for key in node.__dict__:
|
||||
child = getattr(node, key)
|
||||
if isinstance(child, list):
|
||||
for item in child:
|
||||
if hasattr(item, "type"):
|
||||
yield from walk(item)
|
||||
elif hasattr(child, "type"):
|
||||
yield from walk(child)
|
||||
|
||||
for node in walk(tree):
|
||||
if node.type != "IfStatement":
|
||||
continue
|
||||
cond = node.test
|
||||
if (
|
||||
cond.type == "BinaryExpression"
|
||||
and cond.operator == "!=="
|
||||
and cond.right.type == "Literal"
|
||||
and cond.right.value is None
|
||||
):
|
||||
var_name = getattr(cond.left, "name", str(cond.left))
|
||||
start = node.loc.start.line
|
||||
end = node.consequent.loc.end.line
|
||||
lines = source.splitlines(keepends=True)
|
||||
# Drop guard header and closing brace, keep body (1-based -> 0-based)
|
||||
body_start = node.consequent.loc.start.line
|
||||
body_end = node.consequent.loc.end.line - 1
|
||||
body_lines = lines[body_start:body_end]
|
||||
dedented = []
|
||||
for line in body_lines:
|
||||
if line.startswith(" "):
|
||||
dedented.append(line[4:])
|
||||
else:
|
||||
dedented.append(line)
|
||||
mutated = "".join(lines[: start - 1] + dedented + lines[end:])
|
||||
return Mutation(
|
||||
defect_type=self.defect_type,
|
||||
language=self.language,
|
||||
line_start=start,
|
||||
line_end=end,
|
||||
mutated_source=mutated,
|
||||
reference_fix=f"Add `if ({var_name} !== null)` guard before dereferencing.",
|
||||
description=f"Removed null-check guard for '{var_name}'.",
|
||||
)
|
||||
return None
|
||||
@@ -0,0 +1,60 @@
|
||||
"""AST-level resource leak injection for JavaScript using esprima."""
|
||||
|
||||
from typing import Optional
|
||||
|
||||
import esprima
|
||||
|
||||
from app.dataset.rules.base import Mutation, MutationRule
|
||||
|
||||
|
||||
class JSResourceLeakRule(MutationRule):
|
||||
"""Remove a fetch Response body close/usage, leaking the reader.
|
||||
|
||||
Uses `esprima` to locate a `try/finally` that closes a reader and removes
|
||||
the finally block.
|
||||
"""
|
||||
|
||||
name = "js_resource_leak"
|
||||
language = "javascript"
|
||||
defect_type = "resource_not_closed"
|
||||
|
||||
def detect_and_mutate(self, source: str, filename: str = "") -> Optional[Mutation]:
|
||||
# Modern JS is usually ESM: try module grammar first, then script.
|
||||
try:
|
||||
tree = esprima.parseModule(source, loc=True)
|
||||
except Exception:
|
||||
try:
|
||||
tree = esprima.parseScript(source, loc=True)
|
||||
except Exception:
|
||||
return None
|
||||
|
||||
def walk(node):
|
||||
yield node
|
||||
for key in node.__dict__:
|
||||
child = getattr(node, key)
|
||||
if isinstance(child, list):
|
||||
for item in child:
|
||||
if hasattr(item, "type"):
|
||||
yield from walk(item)
|
||||
elif hasattr(child, "type"):
|
||||
yield from walk(child)
|
||||
|
||||
for node in walk(tree):
|
||||
if node.type != "TryStatement" or not node.finalizer:
|
||||
continue
|
||||
start = node.loc.start.line
|
||||
end = node.finalizer.loc.end.line
|
||||
lines = source.splitlines(keepends=True)
|
||||
# Drop the finally block entirely, close the try block
|
||||
finally_start = node.finalizer.loc.start.line - 1
|
||||
mutated = "".join(lines[:finally_start] + [" }\n"] + lines[end:])
|
||||
return Mutation(
|
||||
defect_type=self.defect_type,
|
||||
language=self.language,
|
||||
line_start=start,
|
||||
line_end=end,
|
||||
mutated_source=mutated,
|
||||
reference_fix="Restore finally block to close/release resources.",
|
||||
description="Removed finally block, leaving resource unreleased.",
|
||||
)
|
||||
return None
|
||||
Reference in New Issue
Block a user