Open jallen89 opened 6 months ago
cc @alexkassil this question could use a Pysa expert
Hi @jallen89, thanks for reaching out.
First of, make sure that you have defined a rule for flows of CustomUserControlled
into CodeExecution
.
Then, if the problem persists, could you please do the following:
pyre_dump()
inside testFunction()
(anywhere). This will enable verbose logging for testFunction
.pyre -n analyze
and send us the output.
Hello, I have a question about Pysa's tainting.
Currently I am trying to test a small example that considers
os.environ
a source andexec
as a sink (shown below). I expected Pysa to return that it found a dataflow fromos.environ
toexec
. However, after runningpyre analyze
the results returns is an empty list (no dataflows). Is there any additional information I need to provide to Pysa so that it can track this dataflow?My
source_sinks.pysa
file has the following models.So far I have looked at the callgraph, and it identifies both the calls to
os._Environ.__getitem__
and the call toexec
. Do you all have any recommendations on what I should check next.