Skip to main content

Matcher

Struct Matcher 

Source
pub struct Matcher {
Show 20 fields pub id: String, pub cwe: u32, pub title: String, pub effect: EffectKind, pub sink_shape: SinkShape, pub callee_patterns: Vec<CalleePattern>, pub arg_index: u32, pub evidence_template: String, pub import_provenance: Option<String>, pub enabler: Option<String>, pub arg_kinds: Option<Vec<SinkArgKind>>, pub requires_source: bool, pub requires_source_kinds: Vec<String>, pub literal_values: Vec<String>, pub literal_contains: Vec<String>, pub literal_integers: Vec<i64>, pub object_properties: Vec<ObjectPropertyPredicate>, pub object_missing_or_false: Vec<String>, pub object_missing: Vec<String>, pub context_keywords: Vec<String>,
}
Expand description

A parsed, validated matcher with the sink shape resolved to the typed enum and callee patterns pre-segmented for O(1)-ish matching.

Fields§

§id: String§cwe: u32§title: String§effect: EffectKind§sink_shape: SinkShape§callee_patterns: Vec<CalleePattern>§arg_index: u32§evidence_template: String§import_provenance: Option<String>§enabler: Option<String>

Framework enabler package gate (issue #861). None = global row. Some("pkg") requires an exact dependency match; Some("@scope/") (trailing slash) requires any dependency under that prefix.

§arg_kinds: Option<Vec<SinkArgKind>>

Resolved allowlist of admitted argument shapes. None admits any non-literal shape; Some requires the captured arg_kind to be listed.

§requires_source: bool

Whether this matcher only fires when the sink argument traces to a configured untrusted source binding.

§requires_source_kinds: Vec<String>

When non-empty, narrows requires_source to these catalogue source ids (issue #890): the matched source’s id must be one of these. Empty admits any matched source.

§literal_values: Vec<String>

String-literal values admitted by this row.

§literal_contains: Vec<String>

String fragments admitted by this row.

§literal_integers: Vec<i64>

Integer literal values admitted by this row.

§object_properties: Vec<ObjectPropertyPredicate>

Required literal object properties.

§object_missing_or_false: Vec<String>

Object properties whose absence or boolean false makes the row match.

§object_missing: Vec<String>

Object keys whose absence makes the row match.

§context_keywords: Vec<String>

Context-name keywords admitted by this row.

Implementations§

Source§

impl Matcher

Source

pub fn first_matching_pattern( &self, callee_path: &str, ) -> Option<&CalleePattern>

The first callee pattern that matches the given path, if any. The first match wins, matching the deterministic declaration order.

Source

pub fn admits_arg_kind(&self, arg_kind: SinkArgKind) -> bool

Whether a captured argument shape is admitted by this matcher. None arg_kinds admits any shape; Some requires the kind to be listed.

Source

pub fn is_literal_aware(&self) -> bool

Whether this row has opted into matching a literal, object-property, or context-only sink that is not covered by the default non-literal model.

Source

pub fn literal_value_satisfied( &self, literal: Option<&SinkLiteralValue>, ) -> bool

Whether captured literal metadata satisfies this row’s literal gates.

Source

pub fn object_properties_satisfied( &self, properties: &[SinkObjectProperty], ) -> bool

Whether captured object-literal metadata satisfies this row’s object property gates.

Source

pub fn object_missing_satisfied( &self, keys: &[String], keys_complete: bool, ) -> bool

Whether missing-key predicates are satisfied by complete static object key metadata.

Source

pub fn context_satisfied(&self, context_names: &[String]) -> bool

Whether captured context names satisfy this row’s context keyword gate.

Source

pub fn enabler_satisfied(&self, declared_deps: &FxHashSet<String>) -> bool

Whether this matcher’s framework enabler is satisfied by the project’s declared dependency set (issue #861). None enabler is always satisfied (a global row). A Some enabler matches by exact package name, or, when it ends with /, by prefix (@angular/ matches @angular/platform-browser), mirroring the plugin-system enablers() semantics so framework rows activate on exactly the dependency universe the plugins do.

Trait Implementations§

Source§

impl Clone for Matcher

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Matcher

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<'a, T> FromIn<'a, T> for T

Source§

fn from_in(t: T, _: &'a Allocator) -> T

Converts to this type from the input type within the given allocator.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<'a, T, U> IntoIn<'a, U> for T
where U: FromIn<'a, T>,

Source§

fn into_in(self, allocator: &'a Allocator) -> U

Converts this type into the (usually inferred) input type within the given allocator.
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more