Skip to content

Fix sanctifier-core build/clippy failures; add constant folding, gas exhaustion rule, and CFG-based taint analysis - #1065

Merged
Gbangbolaoluwagbemiga merged 1 commit into
HyperSafeD:mainfrom
devsimze:fix/cfg-taint-gas-exhaustion-and-build
Jun 28, 2026
Merged

Gbangbolaoluwagbemiga merged 1 commit into
HyperSafeD:mainfrom
devsimze:fix/cfg-taint-gas-exhaustion-and-build

Conversation

@devsimze

Copy link
Copy Markdown
Contributor

Summary

  • CI: Fix sanctifier-core build errors (EventVisitor missing, unwind safety bound) #490 — Fixes the sanctifier-core build/clippy failures blocking make lint and cargo build: removed an unused Spanned import in contract_discovery.rs, added #[derive(Debug)] to parser::ParsedSource (required by .unwrap_err() in tests), and fixed a clippy::len_zero lint in sep41_tests.rs. Verified clean under cargo build -p sanctifier-core --all-features, cargo clippy --workspace --all-targets --all-features -- -D warnings, and cargo test -p sanctifier-core --all-features.
  • [engine] Constant Folding and Propagation to reduce false positives in arithmetic #402 — Adds a constant-folding pass (constant_folding.rs) that evaluates literal-only arithmetic at analysis time, so trivial expressions like 1000 + 500 are no longer flagged by the S003 arithmetic-overflow rule.
  • [engine] Rule: Detect unbounded loop iterations mapping to target inputs (Gas Exhaustion/DoS) #403 — Adds rule S031: Gas Exhaustion Risk (rules/gas_exhaustion.rs), detecting for/while loops whose bound traces back to an unbounded user-controlled parameter (Vec, Map, Bytes, or raw integers) without a clamp (.min(), .take(), etc.). Note: the issue text requested code S012, but that code is already assigned to SEP41_INTERFACE_DEVIATION, so the next free code S031 was used instead.
  • [engine] Implement Data Flow and Taint Analysis for precise variable tracking #401 — Adds an intra-procedural CFG builder (cfg.rs) and a fixed-point taint dataflow engine (taint_engine.rs), replacing the single-pass AST walker in the S026 taint_propagation rule. This fixes a real gap where the old rule never visited loop bodies at all, so taint introduced inside a for/while loop, or in only one branch of an if, was invisible. Intra-procedural only, as scoped by the issue.

Test plan

  • cargo build -p sanctifier-core --all-features
  • cargo clippy --workspace --all-targets --all-features -- -D warnings
  • cargo test -p sanctifier-core --all-features (342 lib tests + all integration/snapshot tests pass)
  • New regression tests for each rule/module (constant folding, gas exhaustion, CFG construction, taint engine, loop/branch taint propagation)

Closes #490
Closes #402
Closes #403
Closes #401

…exhaustion rule, and CFG-based taint analysis

Fixes the unused-import and missing-Debug-derive clippy failures blocking
`make lint`/`cargo build` on sanctifier-core, suppresses trivial constant-folded
arithmetic warnings (e.g. 1000 + 500), adds the S031 Gas Exhaustion Risk rule
for unbounded user-controlled loops, and replaces the single-pass AST taint
walker with an intra-procedural CFG and fixed-point taint dataflow engine so
taint introduced inside loop bodies or only one if-branch is no longer missed.

Closes #490
Closes #402
Closes #403
Closes #401

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@vercel

vercel Bot commented Jun 28, 2026

Copy link
Copy Markdown

@devsimze is attempting to deploy a commit to the gbangbolaoluwagbemiga's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Jun 28, 2026

Copy link
Copy Markdown

@devsimze Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@Gbangbolaoluwagbemiga
Gbangbolaoluwagbemiga merged commit d419eb7 into HyperSafeD:main Jun 28, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment