-
Notifications
You must be signed in to change notification settings - Fork 0
feat(sast): detect bearer DNS validation TOCTOU #1080
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
seonghobae
wants to merge
105
commits into
develop
Choose a base branch
from
sentinel/detect-bearer-dns-toctou-892
base: develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
105 commits
Select commit
Hold shift + click to select a range
0e7191b
test(ssrf): preserve bearer DNS TOCTOU vulnerable oracle
seonghobae 0530f8a
test(ssrf): preserve pinned HTTPS fixed oracle
seonghobae ba480e2
feat(ssrf): detect bearer DNS validation TOCTOU
seonghobae 785119a
test(ssrf): exercise bearer DNS TOCTOU detector
seonghobae 9fcafb7
docs(changelog): record bearer DNS TOCTOU detector
seonghobae 1274a13
docs(traceability): map bearer DNS TOCTOU detector evidence
seonghobae 3fb319e
test(ssrf): isolate DNS pinning repair boundary
seonghobae a99b02a
test(ssrf): preserve protected pinned HTTPS repair
seonghobae d61cc18
test(ssrf): bound DNS TOCTOU executable path
seonghobae 2a7403c
fix(ssrf): require executable DNS TOCTOU flow
seonghobae ad7d083
test(ssrf): replay historical bearer push path
seonghobae 2836857
fix(sast): cover ordinary urllib TOCTOU layouts
seonghobae 9314528
test(sast): lock urllib TOCTOU layout boundaries
seonghobae 2181145
fix(sast): cover bearer header syntax variants
seonghobae 62dd979
test(sast): lock bearer syntax variants
seonghobae da21c97
docs(security): record bearer TOCTOU syntax boundaries
seonghobae 33b3033
test(ssrf): cover assigned and replaced bearer dispatch
seonghobae e7a84fb
fix(ssrf): bind bearer dispatch to live request flow
seonghobae 0782bab
test(ssrf): preserve unsafe self-derived reassignments
seonghobae d02e064
fix(ssrf): preserve unsafe self-derived bearer flow
seonghobae 41d5833
test(sast): preserve bearer DNS TOCTOU flow boundaries
seonghobae e23bc99
fix(sast): ignore quoted names in TOCTOU reassignment flow
seonghobae 17c89c7
docs: record TOCTOU reassignment provenance boundary
seonghobae 0472b40
fix(sast): preserve credential and conditional TOCTOU flow boundaries
seonghobae 664fba5
test(sast): cover TOCTOU credential and nested-dispatch edges
seonghobae ab02ca3
fix(sast): tighten bearer DNS TOCTOU provenance
seonghobae 2374813
fix(sast): repair TOCTOU regression corpus
seonghobae c3ccac7
docs(security): record bearer TOCTOU provenance boundaries
seonghobae 7558633
fix(sast): detect restored bearer credentials after preflight
seonghobae 39aeaa9
test(sast): preserve bearer restoration TOCTOU boundaries
seonghobae ab5c7e1
fix(sast): bound restored bearer DNS flow
seonghobae 99e7ddb
test(sast): cover restored bearer flow barriers
seonghobae 63dd65c
docs: trace restored bearer provenance boundaries
seonghobae 3ba1eaa
fix(sast): bind restored bearer headers to Request
seonghobae 09f0e95
fix(sast): derive restored bearer credential at mutation
seonghobae dde31d5
test(sast): prove late bearer restoration supplies credential
seonghobae 5c9e86a
docs: clarify restored bearer credential provenance
seonghobae 1db03cf
fix(sast): bind bearer headers and nested request flow
seonghobae 495319f
test(sast): lock request-header and branch replacement boundaries
seonghobae d3f682b
docs: trace request header and branch replacement boundaries
seonghobae 3f38342
fix(sast): model bearer header mutations as a unique subrule
seonghobae d93c218
test(sast): cover direct and restored bearer mutations
seonghobae 01c3fa2
fix(sast): preserve POST and nested replacement flow boundaries
seonghobae fa2f791
test(sast): lock latest bearer TOCTOU review boundaries
seonghobae 8878601
docs(security): reconcile bearer TOCTOU detector family
seonghobae f7830e4
fix(sast): make bearer credential sources exclusive
seonghobae eb3d970
test(sast): enforce one bearer TOCTOU family finding
seonghobae db69ba0
fix(sast): preserve direct bearer spacing boundary
seonghobae 4f7ff69
test(sast): cover spaced one-line bearer overlap
seonghobae eaea642
test(sast): cover one-line bearer Request kwargs
seonghobae 661eded
fix(sast): detect one-line bearer Request kwargs
seonghobae ee0b750
test(sast): keep bearer removal branch-local
seonghobae 7e61153
fix(sast): keep bearer restore evidence branch-local
seonghobae 3bdf6a4
test(sast): cover nested bearer mutation paths
seonghobae 04c59f2
fix(sast): follow reachable nested bearer dispatches
seonghobae 4564fef
ci: verify packaged rules on Python 3.12
seonghobae 40da1f5
fix(sast): track final bearer credential state
seonghobae 46bdbcd
fix(sast): close primary bearer provenance gaps
seonghobae 831725e
fix(sast): detect multiline Bearer TOCTOU syntax
seonghobae 81e8912
test(sast): cover multiline Bearer TOCTOU syntax
seonghobae 28bc627
fix(sast): preserve multiline DNS TOCTOU flow barriers
seonghobae 1815b30
test(sast): cover multiline DNS TOCTOU barriers
seonghobae c8620cc
docs(security): trace multiline DNS TOCTOU rules
seonghobae fc5cdad
fix(sast): cover fully multiline Bearer mutations
seonghobae a06ddce
test(sast): cover fully multiline Bearer mutation flows
seonghobae 3960226
docs(security): clarify multiline endpoint barrier
seonghobae 5a8ea1b
test(sast): cover request state mutation boundaries
seonghobae abb0e0b
fix(sast): track request destination and credential mutation
seonghobae ffeed61
feat(sast): detect provable dynamic Bearer replacement
seonghobae 2d34e41
docs(security): record request-state provenance boundaries
seonghobae a4421d7
test(sast): assert dynamic Bearer rule packaging
seonghobae c7cbe1d
fix(sast): compile dynamic bearer replacement detector
seonghobae 4126fb2
test(sast): require compiled dynamic bearer detector
seonghobae 8a81dd0
fix(sast): carry request-state barriers into multiline bearer rules
seonghobae 427d4f2
test(sast): cover multiline request-state barriers
seonghobae e228625
test(sast): cover dynamic Bearer reviewed opener
seonghobae 331f04c
fix(sast): detect dynamic Bearer reviewed opener
seonghobae e41dac0
fix(sast): restore compiled dynamic bearer detector
seonghobae 311062c
fix(sast): track unredirected bearer credential store
seonghobae f18367a
test(sast): cover unredirected bearer persistence
seonghobae f3ea510
fix(sast): compile dynamic bearer detector in canonical rule
seonghobae a84d5bb
chore(sast): keep one canonical dynamic bearer rule
seonghobae b952c82
docs(security): trace urllib credential-store provenance
seonghobae e2c8fcc
docs(security): record unredirected bearer persistence
seonghobae 2fc31ea
test(sast): enforce unredirected family ownership
seonghobae f12c99c
fix(sast): bind dynamic bearer Request destination
seonghobae 2fbae8d
fix(sast): model urllib header-store precedence
seonghobae 58eb981
test(sast): verify urllib header precedence and destination binding
seonghobae 196a3c5
test(sast): enforce dynamic Request destination binding
seonghobae 45c1bd4
docs(security): correct urllib credential precedence
seonghobae 44ba203
docs(security): correct unredirected header precedence
seonghobae 5c91e61
test(sast): lock dynamic destination provenance regressions
seonghobae eff3743
fix(sast): terminate stale dynamic destination provenance
seonghobae 1b073fa
test(sast): preserve self-derived validated-url provenance
seonghobae 9f1cb8b
test(sast): lock inverse-condition bearer path compatibility
seonghobae 217e90e
fix(sast): reject inverse-guard bearer branch joins
seonghobae b03e452
fix(sast): reject inverse-guard multiline branch joins
seonghobae b231d6a
docs(traceability): record inverse-guard path boundary
seonghobae 037b8be
docs(changelog): record path-provenance detector repairs
seonghobae 75526a4
test(ssrf): lock dynamic and unredirected provenance barriers
seonghobae 38be651
fix(ssrf): track dynamic bearer state before mutation
seonghobae fd7e764
fix(ssrf): invalidate stale unredirected request provenance
seonghobae 865b0e1
test(sast): lock exhaustive Bearer branch boundaries
seonghobae 678c77d
fix(sast): model exhaustive Bearer branch state
seonghobae 0a752c0
test(sast): lock one-branch sanitizer reachability
seonghobae File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -16,7 +16,7 @@ jobs: | |
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| python-version: ['3.11', '3.13'] | ||
| python-version: ['3.11', '3.12', '3.13'] | ||
|
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. |
||
| steps: | ||
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | ||
| with: | ||
|
|
||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| ## Security | ||
|
|
||
| - Add the HIGH built-in Bearer DNS-rebinding TOCTOU detector family for Python `urllib` flows that validate a URL before dispatch but allow the network client to make a second DNS decision. The source-backed regression corpus preserves the pre-PR #898 vulnerable flow and the protected DNS-pinned HTTPS repair for security issue #892. | ||
| - Track post-construction request state instead of treating the original constructor as permanently authoritative: opaque/dynamic Authorization replacement, header mapping replacement/clearing, and unrelated `Request.full_url` mutation terminate stale credential or destination provenance when those operations affect the active credential/destination. A narrowly scoped companion rule keeps provably Bearer-valued variable replacements detectable, while self-derived destination mutations remain positive. All companion rules bind the validated endpoint only when it is the actual first positional Request URL or `url=...`, not when it merely appears in another argument. | ||
| - Preserve pre-Request destination and bounded control-flow provenance: unrelated reassignment of the validated URL or its derived endpoint breaks the dynamic-Bearer path, while self-derived transformations remain detectable; a Bearer mutation under `if flag:` cannot donate credential state to a resolver-backed dispatch nested under a later `if not flag:`, while direct fallthrough from that guarded mutation to an outer dispatch remains positive. | ||
| - Model urllib credential storage and precedence precisely for `add_unredirected_header`: a Bearer value in `unredirected_hdrs` survives ordinary `req.headers.clear()`, empty-map replacement, or Authorization pop, but a same-name normal Authorization entry overrides it in `Request.header_items()` at dispatch. `remove_header("Authorization")` removes both stores. Production scanner regressions and runtime `urllib.request.Request` assertions preserve clear/pop re-exposure, normal-header override, direct/multiline positives, destination-binding negatives, and the universal-removal negative. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📝 Info: Python 3.12 receives full unit tests
The added matrix entry runs ordinary tests on Python 3.12. The specialized coverage gate remains intentionally confined to Python 3.13.
Was this helpful? React with 👍 or 👎 to provide feedback.