Skip to content

taint analysis example - #1369

Closed
SamarthBengle wants to merge 9 commits into
soot-oss:developfrom
SamarthBengle:taint-analysis-example
Closed

SamarthBengle wants to merge 9 commits into
soot-oss:developfrom
SamarthBengle:taint-analysis-example

Conversation

@SamarthBengle

Copy link
Copy Markdown

No description provided.

@swissiety swissiety left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ok - please add a step by step guide "tutorial" written in markdown.

  • write tutorial
  • add a new file in docs/ .
  • To include the code example please make use of a plugin that lets you include files so that you can refer to specific lines/code range in the TaintAnalysisTest.java file so that the mentioned lines are included in the markdown rendering (find/configure a mkdocs plugin if necessary) - maybe a mkdocs plugin that lets you specify code regions by a placeholder in a code comment which we could insert into the original source would be really great so the ranges would not changes if someone adds anew line of code.

@swissiety swissiety left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lets make use of a mkdocs plugin to import the sections from a .java file

Comment thread docs/taint-analysis-example.md Outdated
The core analysis logic extends `DefaultJimpleIFDSTabulationProblem`:

```java
static class TaintAnalysisProblem extends DefaultJimpleIFDSTabulationProblem<Object, InterproceduralCFG<Stmt, SootMethod>> {

@swissiety swissiety Sep 19, 2025 •

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

can we break that huge section down into multiple smaller ones + explaination?

@swissiety swissiety changed the title taint analysis example added taint analysis example Sep 30, 2025
Address review of soot-oss#1369:
- docs/taint-analysis-example.md no longer copies code; every Java block is
  included from TaintAnalysisTest.java via named `--8<--` sections, so the
  tutorial always shows compiled and tested code. check_paths fails the docs
  build if a section goes missing.
- Use pymdownx.snippets (already enabled, shipped with mkdocs-material)
  instead of the codeinclude plugin, which the docs CI does not install.
- Remove CodeBlockExtractor and the sync-examples workflow (out of scope).
- Update TaintAnalysisTest to the current SootUp API, propagate taint through
  call sites with a return value (b = id(a)) and assert the expected leak /
  no-leak verdict per scenario instead of swallowing all results.
- Split the tutorial into small sections, each with an explanation; fix the
  dependency snippet.
@swissiety

Copy link
Copy Markdown
Collaborator

integrated into #1629

@swissiety swissiety closed this Sep 24, 2026
swissiety added a commit that referenced this pull request Sep 24, 2026
Moves the tutorial next to the other analysis examples under "How to.."
and keeps base_path/check_paths while adding dedent_subsections.
@codecov

codecov Bot commented Sep 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 72.59%. Comparing base (1001d5f) to head (77bae3c).

Additional details and impacted files
@@              Coverage Diff              @@
##             develop    #1369      +/-   ##
=============================================
- Coverage      72.64%   72.59%   -0.05%     
  Complexity       238      238              
=============================================
  Files            488      488              
  Lines          20820    20820              
  Branches        3400     3400              
=============================================
- Hits           15124    15115       -9     
- Misses          4385     4390       +5     
- Partials        1311     1315       +4     
Components Coverage Δ
core 66.51% <ø> (ø)
java.core 74.04% <ø> (ø)
java.bytecode.frontend 80.46% <ø> (ø)
jimple.frontend 70.70% <ø> (ø)
apk.frontend 76.99% <ø> (-0.37%) ⬇️
interceptors 73.56% <ø> (ø)
callgraph 85.42% <ø> (ø)
codepropertygraph 74.35% <ø> (ø)
analysis.intraprocedural 63.86% <ø> (ø)
analysis.interprocedural 68.26% <ø> (ø)
🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants