Skip to content

Go: Add models for go 1.21 - #22797

Open
owen-mc wants to merge 1 commit into
github:mainfrom
owen-mc:go/model-go1.21-minor-library-changes
Open

owen-mc wants to merge 1 commit into
github:mainfrom
owen-mc:go/model-go1.21-minor-library-changes

Conversation

@owen-mc

@owen-mc owen-mc commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Copilot AI balanced review requested due to automatic review settings October 9, 2026 14:51
@owen-mc
owen-mc requested a review from a team as a code owner October 9, 2026 14:51
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

⚠️ The head of this PR and the base branch were compared for differences in the framework coverage reports. The generated reports are available in the artifacts of this workflow run. The differences will be picked up by the nightly job after the PR gets merged.

Click to show differences in coverage

go

Generated file changes for go

  • Changes to framework-coverage-go.rst:
-    `Standard library <https://pkg.go.dev/std>`_,"````, ``archive/*``, ``bufio``, ``bytes``, ``cmp``, ``compress/*``, ``container/*``, ``context``, ``crypto``, ``crypto/*``, ``database/*``, ``debug/*``, ``embed``, ``encoding``, ``encoding/*``, ``errors``, ``expvar``, ``flag``, ``fmt``, ``go/*``, ``hash``, ``hash/*``, ``html``, ``html/*``, ``image``, ``image/*``, ``index/*``, ``io``, ``io/*``, ``log``, ``log/*``, ``maps``, ``math``, ``math/*``, ``mime``, ``mime/*``, ``net``, ``net/*``, ``os``, ``os/*``, ``path``, ``path/*``, ``plugin``, ``reflect``, ``reflect/*``, ``regexp``, ``regexp/*``, ``slices``, ``sort``, ``strconv``, ``strings``, ``sync``, ``sync/*``, ``syscall``, ``syscall/*``, ``testing``, ``testing/*``, ``text/*``, ``time``, ``time/*``, ``unicode``, ``unicode/*``, ``unsafe``, ``weak``",52,674,127
+    `Standard library <https://pkg.go.dev/std>`_,"````, ``archive/*``, ``bufio``, ``bytes``, ``cmp``, ``compress/*``, ``container/*``, ``context``, ``crypto``, ``crypto/*``, ``database/*``, ``debug/*``, ``embed``, ``encoding``, ``encoding/*``, ``errors``, ``expvar``, ``flag``, ``fmt``, ``go/*``, ``hash``, ``hash/*``, ``html``, ``html/*``, ``image``, ``image/*``, ``index/*``, ``io``, ``io/*``, ``log``, ``log/*``, ``maps``, ``math``, ``math/*``, ``mime``, ``mime/*``, ``net``, ``net/*``, ``os``, ``os/*``, ``path``, ``path/*``, ``plugin``, ``reflect``, ``reflect/*``, ``regexp``, ``regexp/*``, ``slices``, ``sort``, ``strconv``, ``strings``, ``sync``, ``sync/*``, ``syscall``, ``syscall/*``, ``testing``, ``testing/*``, ``text/*``, ``time``, ``time/*``, ``unicode``, ``unicode/*``, ``unsafe``, ``weak``",52,696,127
-    Totals,,690,1134,1580
+    Totals,,690,1156,1580
  • Changes to framework-coverage-go.csv:
- context,,,5,,,,,,,,,,,,,,,,,,,,,,,5,
+ context,,,10,,,,,,,,,,,,,,,,,,,,,,,10,
- crypto,,,10,,,,,,,,,,,,,,,,,,,,,,,10,
+ crypto,,,24,,,,,,,,,,,,,,,,,,,,,,,24,
- io,5,4,34,,,,,,5,,,,,,,,,,,,,,4,,,34,
+ io,5,4,36,,,,,,5,,,,,,,,,,,,,,4,,,36,
- math/big,,,1,,,,,,,,,,,,,,,,,,,,,,,1,
+ math/big,,,2,,,,,,,,,,,,,,,,,,,,,,,2,

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The TLS summaries currently introduce false-positive flows from unused ConnectionState arguments.

4 open findings
What changed in this PR

Adds Go 1.21 standard-library data-flow models and corresponding regression coverage.

Changes:

  • Models new context, crypto/tls, io/fs, and math/big APIs.
  • Adds taint-flow fixtures and a change note.
File Description
go/​ql/​lib/​ext/​context.model.yml Models new context APIs.
go/​ql/​lib/​ext/​crypto.tls.model.yml Models TLS session and QUIC APIs.
go/​ql/​lib/​ext/​io.fs.model.yml Models filesystem formatting functions.
go/​ql/​lib/​ext/​math.big.model.yml Models Int.Float64.
go/​ql/​test/​library-tests/​semmle/​go/​frameworks/​StdlibTaintFlow/​Context.go Tests context summaries.
go/​ql/​test/​library-tests/​semmle/​go/​frameworks/​StdlibTaintFlow/​CryptoTls.go Tests TLS summaries.
go/​ql/​test/​library-tests/​semmle/​go/​frameworks/​StdlibTaintFlow/​IoFs.go Tests filesystem summaries.
go/​ql/​test/​library-tests/​semmle/​go/​frameworks/​StdlibTaintFlow/​MathBig.go Tests Int.Float64.
go/​ql/​src/​change-notes/​2026-09-30-model-go1.21-minor-library-changes.md Documents the analysis improvement.
Files not reviewed (2)
  • go/ql/test/library-tests/semmle/go/frameworks/StdlibTaintFlow/Context.go: Generated file
  • go/ql/test/library-tests/semmle/go/frameworks/StdlibTaintFlow/CryptoTls.go: Generated file

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

- ["crypto/tls", "", False, "Server", "", "", "Argument[0]", "ReturnValue", "taint", "manual"]
- ["crypto/tls", "ClientSessionState", True, "ResumptionState", "", "", "Argument[receiver]", "ReturnValue[0..1]", "taint", "manual"]
- ["crypto/tls", "Config", True, "DecryptTicket", "", "", "Argument[receiver]", "ReturnValue[0]", "taint", "manual"]
- ["crypto/tls", "Config", True, "DecryptTicket", "", "", "Argument[0..1]", "ReturnValue[0]", "taint", "manual"]
Comment on lines +13 to +17
- ["crypto/tls", "ClientSessionState", True, "ResumptionState", "", "", "Argument[receiver]", "ReturnValue[0..1]", "taint", "manual"]
- ["crypto/tls", "Config", True, "DecryptTicket", "", "", "Argument[receiver]", "ReturnValue[0]", "taint", "manual"]
- ["crypto/tls", "Config", True, "DecryptTicket", "", "", "Argument[0..1]", "ReturnValue[0]", "taint", "manual"]
- ["crypto/tls", "Config", True, "EncryptTicket", "", "", "Argument[receiver]", "ReturnValue[0]", "taint", "manual"]
- ["crypto/tls", "Config", True, "EncryptTicket", "", "", "Argument[0..1]", "ReturnValue[0]", "taint", "manual"]

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants