Home | History | Annotate | Download | only in Checkers

Lines Matching refs:taint

9 // This checker defines the attack surface for generic taint propagation.
11 // The taint information produced by it might be useful to other checkers. For
17 #include "Taint.h"
38 using namespace taint;
141 /// Catch taint related bugs. Check if tainted data is passed to a
146 /// Add taint sources on a pre-visit. Returns true on matching.
155 /// Propagate taint generated at pre-visit. Returns true on matching.
212 /// A struct used to specify taint propagation rules for a function.
214 /// If any of the possible taint source arguments is tainted, all of the
216 /// src list to specify that all of the arguments can introduce taint. Use
225 /// List of arguments which can be taint sources and should be checked.
279 /// Pre-process a function which propagates taint according to the
280 /// taint rule.
629 // Clear up the taint info from the state.
684 // Check for taint in arguments.
695 // Check for taint in variadic arguments.
747 // If argument 0(protocol domain) is network, the return value should get taint.
822 // Check for taint.
884 // If yes, should taint be a global setting?