66 lines
2.5 KiB
Python
66 lines
2.5 KiB
Python
"""AST-level null-pointer / None-reference injection for Python."""
|
|
|
|
import ast
|
|
from typing import Optional
|
|
|
|
from app.dataset.rules.base import Mutation, MutationRule
|
|
|
|
|
|
class NoneReferenceRule(MutationRule):
|
|
"""Replace a checked variable access with an unchecked None dereference.
|
|
|
|
This rule uses the standard library `ast` module to precisely locate a
|
|
variable that is used after an `if x is not None:` guard, then removes the
|
|
guard. The mutation position is derived from AST line numbers so it is
|
|
exact and reproducible.
|
|
"""
|
|
|
|
name = "none_reference"
|
|
language = "python"
|
|
defect_type = "null_pointer"
|
|
|
|
def detect_and_mutate(self, source: str, filename: str = "") -> Optional[Mutation]:
|
|
try:
|
|
tree = ast.parse(source)
|
|
except SyntaxError:
|
|
return None
|
|
|
|
for node in ast.walk(tree):
|
|
if not isinstance(node, ast.If):
|
|
continue
|
|
test = node.test
|
|
# Match: if x is not None:
|
|
if (
|
|
isinstance(test, ast.Compare)
|
|
and isinstance(test.left, ast.Name)
|
|
and len(test.ops) == 1
|
|
and isinstance(test.ops[0], ast.IsNot)
|
|
and len(test.comparators) == 1
|
|
and isinstance(test.comparators[0], ast.Constant)
|
|
and test.comparators[0].value is None
|
|
):
|
|
var_name = test.left.id
|
|
lines = source.splitlines(keepends=True)
|
|
start = node.lineno
|
|
end = getattr(node, "end_lineno", node.lineno) or node.lineno
|
|
body_lines = lines[start:end]
|
|
dedented = []
|
|
for line in body_lines[1:]:
|
|
if line.startswith(" "):
|
|
dedented.append(line[4:])
|
|
elif line.startswith("\t"):
|
|
dedented.append(line[1:])
|
|
else:
|
|
dedented.append(line)
|
|
mutated = "".join(lines[: start - 1] + dedented + lines[end:])
|
|
return Mutation(
|
|
defect_type=self.defect_type,
|
|
language=self.language,
|
|
line_start=start,
|
|
line_end=end,
|
|
mutated_source=mutated,
|
|
reference_fix=f"Add `if {var_name} is not None:` guard before use.",
|
|
description=f"Removed None-check guard for variable '{var_name}'.",
|
|
)
|
|
return None
|