Skip to content

Report the taint flows a plugin connects to a sink from a node without location - #12082

Open
danog wants to merge 2 commits into
vimeo:masterfrom
danog:taint-locationless-predecessor
Open

danog wants to merge 2 commits into
vimeo:masterfrom
danog:taint-locationless-predecessor

Conversation

@danog

@danog danog commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

Found while connecting Twig templates to the taint analysis from a plugin (see psalm/psalm-plugin-symfony#390).

A taint flow was only reported if the node it reaches a sink from has a location: getChildNodes() skipped the sink, and reportTaintedFlowOnce() returned early, when that node had none. Yet the issue is reported at the sink's location whenever the sink is in a file whose issues are reported, so the predecessor's location is only needed as a fallback.

Psalm's own nodes never reach a sink from a node without location, but a plugin can. A template engine plugin joins the PHP code and a template through location-less nodes (a template's variables, its output), and sends the output into a sink: every such flow was silently dropped, with no issue and no error.

A flow is now reported when either the sink or the node it reaches the sink from has a location: at the sink if its issues are reported, else at that node.

Test: LocationlessNodeTest, with a plugin passing what is given to relay() to a sink at deliver() through a location-less node. It fails without this change. TaintTest passes, apart from taintedExecuteQueryMethod, which fails on master too (fixed in #12081), and the plugin event handler tests pass.

@danog

danog commented Oct 4, 2026

Copy link
Copy Markdown
Collaborator Author

bugbot review

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 312f31d. Configure here.

@danog danog added the release:fix The PR will be included in 'Fixes' section of the release notes label Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release:fix The PR will be included in 'Fixes' section of the release notes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant