pub struct Matcher {Show 20 fields
pub id: String,
pub cwe: u32,
pub title: String,
pub effect: EffectKind,
pub sink_shape: SinkShape,
pub callee_patterns: Vec<CalleePattern>,
pub arg_index: u32,
pub evidence_template: String,
pub import_provenance: Option<String>,
pub enabler: Option<String>,
pub arg_kinds: Option<Vec<SinkArgKind>>,
pub requires_source: bool,
pub requires_source_kinds: Vec<String>,
pub literal_values: Vec<String>,
pub literal_contains: Vec<String>,
pub literal_integers: Vec<i64>,
pub object_properties: Vec<ObjectPropertyPredicate>,
pub object_missing_or_false: Vec<String>,
pub object_missing: Vec<String>,
pub context_keywords: Vec<String>,
}Expand description
A parsed, validated matcher with the sink shape resolved to the typed enum and callee patterns pre-segmented for O(1)-ish matching.
Fields§
§id: String§cwe: u32§title: String§effect: EffectKind§sink_shape: SinkShape§callee_patterns: Vec<CalleePattern>§arg_index: u32§evidence_template: String§import_provenance: Option<String>§enabler: Option<String>Framework enabler package gate (issue #861). None = global row.
Some("pkg") requires an exact dependency match; Some("@scope/")
(trailing slash) requires any dependency under that prefix.
arg_kinds: Option<Vec<SinkArgKind>>Resolved allowlist of admitted argument shapes. None admits any
non-literal shape; Some requires the captured arg_kind to be listed.
requires_source: boolWhether this matcher only fires when the sink argument traces to a configured untrusted source binding.
requires_source_kinds: Vec<String>When non-empty, narrows requires_source to these catalogue source ids
(issue #890): the matched source’s id must be one of these. Empty admits
any matched source.
literal_values: Vec<String>String-literal values admitted by this row.
literal_contains: Vec<String>String fragments admitted by this row.
literal_integers: Vec<i64>Integer literal values admitted by this row.
object_properties: Vec<ObjectPropertyPredicate>Required literal object properties.
object_missing_or_false: Vec<String>Object properties whose absence or boolean false makes the row match.
object_missing: Vec<String>Object keys whose absence makes the row match.
context_keywords: Vec<String>Context-name keywords admitted by this row.
Implementations§
Source§impl Matcher
impl Matcher
Sourcepub fn first_matching_pattern(
&self,
callee_path: &str,
) -> Option<&CalleePattern>
pub fn first_matching_pattern( &self, callee_path: &str, ) -> Option<&CalleePattern>
The first callee pattern that matches the given path, if any. The first match wins, matching the deterministic declaration order.
Sourcepub fn admits_arg_kind(&self, arg_kind: SinkArgKind) -> bool
pub fn admits_arg_kind(&self, arg_kind: SinkArgKind) -> bool
Whether a captured argument shape is admitted by this matcher. None
arg_kinds admits any shape; Some requires the kind to be listed.
Sourcepub fn is_literal_aware(&self) -> bool
pub fn is_literal_aware(&self) -> bool
Whether this row has opted into matching a literal, object-property, or context-only sink that is not covered by the default non-literal model.
Sourcepub fn literal_value_satisfied(
&self,
literal: Option<&SinkLiteralValue>,
) -> bool
pub fn literal_value_satisfied( &self, literal: Option<&SinkLiteralValue>, ) -> bool
Whether captured literal metadata satisfies this row’s literal gates.
Sourcepub fn object_properties_satisfied(
&self,
properties: &[SinkObjectProperty],
) -> bool
pub fn object_properties_satisfied( &self, properties: &[SinkObjectProperty], ) -> bool
Whether captured object-literal metadata satisfies this row’s object property gates.
Sourcepub fn object_missing_satisfied(
&self,
keys: &[String],
keys_complete: bool,
) -> bool
pub fn object_missing_satisfied( &self, keys: &[String], keys_complete: bool, ) -> bool
Whether missing-key predicates are satisfied by complete static object key metadata.
Sourcepub fn context_satisfied(&self, context_names: &[String]) -> bool
pub fn context_satisfied(&self, context_names: &[String]) -> bool
Whether captured context names satisfy this row’s context keyword gate.
Sourcepub fn enabler_satisfied(&self, declared_deps: &FxHashSet<String>) -> bool
pub fn enabler_satisfied(&self, declared_deps: &FxHashSet<String>) -> bool
Whether this matcher’s framework enabler is satisfied by the project’s
declared dependency set (issue #861). None enabler is always satisfied
(a global row). A Some enabler matches by exact package name, or, when
it ends with /, by prefix (@angular/ matches @angular/platform-browser),
mirroring the plugin-system enablers() semantics so framework rows
activate on exactly the dependency universe the plugins do.