Skip to content

[engine] Implement Data Flow and Taint Analysis for precise variable tracking #401

Description

@Gbangbolaoluwagbemiga

Context

Currently, Sanctifier uses AST-based pattern matching. This fails if variables are passed through intermediate functions or aliased.

What to build

Implement an intra-procedural Control Flow Graph (CFG) and taint analysis pass.

  1. Identify "sources" (untrusted user input).
  2. Identify "sinks" (privileged operations).
  3. Trace data flow between them.

Acceptance Criteria

  • CFG generation module in sanctifier-core.
  • Taint engine tracks variable assignments.

Activity

  1. Emoji-dot commented on Jun 28, 2026

    @Emoji-dot

    @Emoji-dot has applied to work on this issue as part of the Stellar Wave Program's 6th wave.

    I would like to work on this issue

    ℹ️ Repo Maintainers: To accept this application, review their application or assign @Emoji-dot to this issue.

  2. Unclebaffa commented on Jun 28, 2026

    @Unclebaffa

    @Unclebaffa has applied to work on this issue as part of the Stellar Wave Program's 6th wave.

    Hi Maintainer,
    I’m interested in contributing to this issue and believe I can deliver a clean, well-tested solution that aligns with the project’s standards. Kindly assign me please
    Thank you

    ETA 6hrs

    ℹ️ Repo Maintainers: To accept this application, review their application or assign @Unclebaffa to this issue.

  3. devsimze commented on Jun 28, 2026

    @devsimze
    Contributor

    @devsimze has applied to work on this issue as part of the Stellar Wave Program's 6th wave.

    Hi I'd like to work on this issue

    ℹ️ Repo Maintainers: To accept this application, review their application or assign @devsimze to this issue.

  4. drips-wave commented on Jun 28, 2026

    @drips-wave

    Congratulations, @devsimze! 🎉 Your application was accepted by the repo's maintainers, and the issue is due on June 30, 2026.

    🧑‍💻 @devsimze: Please resolve the issue such that the repo's maintainers have enough time to review your contribution before the due date. You'll earn Points for completing the issue on-time, which will make you eligible for a share of the Stellar Wave Program's reward pool.

    Warning

    When opening a PR, please link it to this issue to ensure it gets tracked accurately. Points are awarded when this issue is marked as completed by the maintainer.

    🤠 Repo maintainers: Please keep an eye on the contributor's progress and review their work before the due date. You can manage this issue, including adjusting its complexity and points, here.

    🌊 Happy Wave 🌊

  5. deleted a comment from Gozirimdev on Jun 28, 2026
  6. drips-wave commented on Jun 28, 2026

    @drips-wave

    This issue has been completed by @devsimze as part of the Stellar Wave Program's 6th Wave 🥳

    😎 @devsimze: You earned 200 Points for completing this issue! After the current Wave ends, you'll be eligible for a percentage of the Wave's reward pool based on the percentage of total points you've earned. Learn more here. You can also Leave a review to share your experience working on this issue.

    🧑‍💻 Repo maintainers: How'd the contributor do? Leave a review to share your experience working with them.

  7. added a commit that references this issue on Jun 28, 2026
    9dce074
  8. added 3 commits that reference this issue on Jul 19, 2026
    fbf35c4
    c45c061
    50899d8
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions