Skip to content

feat(scan): support custom models with one selected analyzer - #68

Merged
picatz merged 6 commits into
mainfrom
feat/scan-custom-models-20261009
Oct 9, 2026
Merged

picatz merged 6 commits into
mainfrom
feat/scan-custom-models-20261009

Conversation

@picatz

@picatz picatz commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Add additive YAML file/directory models to whole-program taint scan through the shared loader and detector options.
  • Require exactly one unique selected analyzer whenever -models is supplied (including an explicit empty value). Model kind labels remain informational; findings retain the selected analyzer's identity.
  • Validate paths/YAML before loading Go packages. Relative model paths resolve under -C, without process-wide chdir.
  • Preserve selected occurrence scope, body budgets, deterministic output ordering, and default behavior.

Regression coverage

Synthetic tests cover file/directory/absolute/relative paths, flag order, empty/missing/malformed/schema-invalid models, all six analyzer identities, source/sink/sanitizer/summary controls, built-in additive findings, model isolation between runs, exact same-module limits, selected dependency occurrence boundaries, and text/JSON/SARIF output. Process smoke checks verify exits 0/1/3 for all formats.

Validation

  • Focused regression suites pass on official Go 1.27.2 and Go 1.26.9. Independent review and independent focused rerun found no blockers; final build/workflow amendments were reviewed too.
  • All 15 existing pinned precision snapshots match; no snapshot changes. Final evaluated analyzer source, module files, runtime, and targets are unchanged by the later lint-only workflow edit.
  • Go 1.27.2 govulncheck passes with zero called vulnerabilities; Staticcheck v0.8.1 passes on Go 1.26.9.
  • Final head 319ee537 passed all eight hosted checks. Terminal logs confirm full suites on Go 1.26.9/1.27.2, root/callgraph race on Go 1.27.2 (222 groups), and wholeprogram/CLI race on Go 1.27.2 (53 groups). CI run.

Inherited CI compatibility repairs

The old preferred Go 1.27.1 toolchain triggers newly published standard-library advisories. Bump only the preferred toolchain to Go 1.27.2; minimum Go 1.26.0 and dependencies stay unchanged.

Released Staticcheck v0.8.1 cannot decode Go 1.27.2 export data. Run that unchanged version on patched Go 1.26.9 with GOTOOLCHAIN=local. Only check_go127_test.go and sink_paths_go127_test.go are excluded from this lint pass; Go 1.27 tests/race/vet still cover them. No production source is excluded by this version selection, and security checks remain on the patched preferred toolchain.

No new real-target cases or model semantics redesign.

The full-suite matrix and wholeprogram/CLI race explicitly pin the patched versions: floating setup-go aliases were observed resolving to older patches despite check-latest. Test commands, assertions, and coverage are unchanged.

@picatz
picatz marked this pull request as ready for review October 9, 2026 01:31
@picatz
picatz merged commit f7be227 into main Oct 9, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant