Struct SymbolicValue
pub struct SymbolicValue {
pub id: u64,
pub cil_flavor: CilFlavor,
pub source: TaintSource,
pub name: Option<String>,
pub dependencies: Vec<u64>,
}Expand description
A symbolic (unknown) value for partial emulation.
Symbolic values represent unknown or partially-known values during emulation. Each symbolic value has:
- A unique ID for tracking
- A CIL type flavor indicating what kind of value it represents
- A taint source indicating the origin of the value
- Optional constraints collected during execution
§Identity
Each symbolic value has a unique ID. Two symbolic values with different IDs are considered distinct, even if they have the same type and source. This enables precise tracking of data flow.
Fields§
§id: u64Unique identifier for this symbolic value.
cil_flavor: CilFlavorThe CIL type flavor of this symbolic value.
source: TaintSourceThe source/origin of this symbolic value.
name: Option<String>Optional name for debugging (e.g., parameter name).
dependencies: Vec<u64>Dependencies on other symbolic values (for derived values).
Implementations§
§impl SymbolicValue
impl SymbolicValue
pub fn new(cil_flavor: CilFlavor, source: TaintSource) -> Self
pub fn new(cil_flavor: CilFlavor, source: TaintSource) -> Self
Creates a new symbolic value with the given type and source.
§Examples
use dotscope::emulation::{SymbolicValue, TaintSource};
use dotscope::metadata::typesystem::CilFlavor;
let sym = SymbolicValue::new(CilFlavor::I4, TaintSource::Unknown);pub fn parameter(index: u16, cil_flavor: CilFlavor) -> Self
pub fn parameter(index: u16, cil_flavor: CilFlavor) -> Self
Creates a symbolic value representing a method parameter.
§Arguments
index- The parameter index (0-based)cil_flavor- The type of the parameter
§Examples
use dotscope::emulation::SymbolicValue;
use dotscope::metadata::typesystem::CilFlavor;
let param0 = SymbolicValue::parameter(0, CilFlavor::I4);
assert!(matches!(param0.source, dotscope::emulation::TaintSource::Parameter(0)));pub fn local(index: u16, cil_flavor: CilFlavor) -> Self
pub fn local(index: u16, cil_flavor: CilFlavor) -> Self
Creates a symbolic value representing a local variable.
§Arguments
index- The local variable index (0-based)cil_flavor- The type of the local
pub fn field(field_token: u32, cil_flavor: CilFlavor) -> Self
pub fn field(field_token: u32, cil_flavor: CilFlavor) -> Self
Creates a symbolic value representing a field value.
§Arguments
field_token- The metadata token of the fieldcil_flavor- The type of the field
pub fn return_value(method_token: u32, cil_flavor: CilFlavor) -> Self
pub fn return_value(method_token: u32, cil_flavor: CilFlavor) -> Self
Creates a symbolic value representing a method return value.
§Arguments
method_token- The metadata token of the called methodcil_flavor- The return type
pub fn derived(cil_flavor: CilFlavor, source: TaintSource) -> Self
pub fn derived(cil_flavor: CilFlavor, source: TaintSource) -> Self
Creates a symbolic value derived from other values through computation.
§Arguments
cil_flavor- The result typesource- The source type (typicallyTaintSource::Computation)
pub fn derived_from(cil_flavor: CilFlavor, dependencies: Vec<u64>) -> Self
pub fn derived_from(cil_flavor: CilFlavor, dependencies: Vec<u64>) -> Self
Creates a derived symbolic value with explicit dependencies.
§Arguments
cil_flavor- The result typedependencies- IDs of symbolic values this depends on
pub fn user_input(cil_flavor: CilFlavor) -> Self
pub fn user_input(cil_flavor: CilFlavor) -> Self
Creates a symbolic value representing external/user input.
Values from this source should be treated as potentially malicious.
pub fn with_name(self, name: impl Into<String>) -> Self
pub fn with_name(self, name: impl Into<String>) -> Self
Sets a human-readable name for this symbolic value.
pub fn is_tainted(&self) -> bool
pub fn is_tainted(&self) -> bool
Returns true if this value originates from a tainted source.
Tainted sources include user input, external data, and values derived from tainted values.
§Examples
use dotscope::emulation::{SymbolicValue, TaintSource};
use dotscope::metadata::typesystem::CilFlavor;
let user = SymbolicValue::user_input(CilFlavor::I4);
assert!(user.is_tainted());
let param = SymbolicValue::parameter(0, CilFlavor::I4);
assert!(param.is_tainted()); // Parameters are untrusted
let unknown = SymbolicValue::new(CilFlavor::I4, TaintSource::Unknown);
assert!(!unknown.is_tainted());pub fn is_parameter(&self) -> bool
pub fn is_parameter(&self) -> bool
Returns true if this value represents a method parameter.
§Examples
use dotscope::emulation::SymbolicValue;
use dotscope::metadata::typesystem::CilFlavor;
let param = SymbolicValue::parameter(0, CilFlavor::I4);
assert!(param.is_parameter());pub fn is_local(&self) -> bool
pub fn is_local(&self) -> bool
Returns true if this value represents a local variable.
§Examples
use dotscope::emulation::SymbolicValue;
use dotscope::metadata::typesystem::CilFlavor;
let local = SymbolicValue::local(0, CilFlavor::I4);
assert!(local.is_local());pub fn is_computed(&self) -> bool
pub fn is_computed(&self) -> bool
Returns true if this value was derived from computation.
Computed values result from operations on other symbolic values.
pub fn parameter_index(&self) -> Option<u16>
pub fn parameter_index(&self) -> Option<u16>
Returns the parameter index if this is a parameter value.
§Returns
Some(index)if this symbolic value represents a method parameterNoneif this is not a parameter value
pub fn local_index(&self) -> Option<u16>
pub fn local_index(&self) -> Option<u16>
Returns the local variable index if this is a local value.
§Returns
Some(index)if this symbolic value represents a local variableNoneif this is not a local variable value
Trait Implementations§
§impl Clone for SymbolicValue
impl Clone for SymbolicValue
§fn clone(&self) -> SymbolicValue
fn clone(&self) -> SymbolicValue
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more§impl Debug for SymbolicValue
impl Debug for SymbolicValue
Auto Trait Implementations§
impl Freeze for SymbolicValue
impl RefUnwindSafe for SymbolicValue
impl Send for SymbolicValue
impl Sync for SymbolicValue
impl Unpin for SymbolicValue
impl UnsafeUnpin for SymbolicValue
impl UnwindSafe for SymbolicValue
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Downcast for T
impl<T> Downcast for T
impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<F, T> IntoSample<T> for Fwhere
T: FromSample<F>,
impl<F, T> IntoSample<T> for Fwhere
T: FromSample<F>,
fn into_sample(self) -> T
Source§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<SS, SP> SupersetOf<SS> for SPwhere
SS: SubsetOf<SP>,
impl<SS, SP> SupersetOf<SS> for SPwhere
SS: SubsetOf<SP>,
Source§fn to_subset(&self) -> Option<SS>
fn to_subset(&self) -> Option<SS>
self from the equivalent element of its
superset. Read moreSource§fn is_in_subset(&self) -> bool
fn is_in_subset(&self) -> bool
self is actually part of its subset T (and can be converted to it).Source§fn to_subset_unchecked(&self) -> SS
fn to_subset_unchecked(&self) -> SS
self.to_subset but without any property checks. Always succeeds.Source§fn from_subset(element: &SS) -> SP
fn from_subset(element: &SS) -> SP
self to the equivalent element of its superset.Source§impl<T> ToCompactString for Twhere
T: Display,
impl<T> ToCompactString for Twhere
T: Display,
Source§fn try_to_compact_string(&self) -> Result<CompactString, ToCompactStringError>
fn try_to_compact_string(&self) -> Result<CompactString, ToCompactStringError>
ToCompactString::to_compact_string() Read moreSource§fn to_compact_string(&self) -> CompactString
fn to_compact_string(&self) -> CompactString
CompactString. Read more