rustsymreach

package
v0.2.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package rustsymreach implements deterministic TIER-2 symbol-level reachability for Rust (crates.io) findings: does first-party Rust source reference the specific vulnerable function an advisory names (RustSec publishes affected functions as fully-qualified "crate::path::func"), not merely import the crate?

It is RAISE-ONLY by construction: it mints a reachable verdict when it can PROVE a reference, and never a not-reachable one. A source scan cannot resolve types, so a method call (`x.foo()`) or a macro-hidden reference cannot be tied to a crate; those are left unknown rather than guessed. A reachable verdict is therefore backed by a qualified path reference ("crate::…::func") or a `use` of the function followed by a call, both of which a reader can check against the source. Because it never suppresses, its worst case is over-prioritizing a finding, never hiding one, so it stays on the safe side of the no-false-positive bar.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Analyzer

type Analyzer struct {
	// contains filtered or unexported fields
}

Analyzer implements the reachproof analyzer contract for Rust affected-function reachability.

func New

func New(scanner symbolScanner) (*Analyzer, error)

New returns a Rust symbol-reachability analyzer. A nil scanner is a programming error.

func (*Analyzer) Analyze

func (a *Analyzer) Analyze(ctx context.Context, dir string, subjects []string) (*reachability.Analysis, error)

Analyze reports, for each affected-function symbol, whether first-party Rust source references it. It returns a reachable verdict only for a proven reference; every other symbol is left Reachable=false, which the raise-only coordinator drops rather than turning into a suppressing not-reachable claim.

func (*Analyzer) Analyzeable

func (a *Analyzer) Analyzeable() string

Analyzeable reports the package-URL type this analyzer answers for.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL