Documentation
¶
Overview ¶
Package rustsymreach implements deterministic TIER-2 symbol-level reachability for Rust (crates.io) findings: does first-party Rust source reference the specific vulnerable function an advisory names (RustSec publishes affected functions as fully-qualified "crate::path::func"), not merely import the crate?
It is RAISE-ONLY by construction: it mints a reachable verdict when it can PROVE a reference, and never a not-reachable one. A source scan cannot resolve types, so a method call (`x.foo()`) or a macro-hidden reference cannot be tied to a crate; those are left unknown rather than guessed. A reachable verdict is therefore backed by a qualified path reference ("crate::…::func") or a `use` of the function followed by a call, both of which a reader can check against the source. Because it never suppresses, its worst case is over-prioritizing a finding, never hiding one, so it stays on the safe side of the no-false-positive bar.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Analyzer ¶
type Analyzer struct {
// contains filtered or unexported fields
}
Analyzer implements the reachproof analyzer contract for Rust affected-function reachability.
func (*Analyzer) Analyze ¶
func (a *Analyzer) Analyze(ctx context.Context, dir string, subjects []string) (*reachability.Analysis, error)
Analyze reports, for each affected-function symbol, whether first-party Rust source references it. It returns a reachable verdict only for a proven reference; every other symbol is left Reachable=false, which the raise-only coordinator drops rather than turning into a suppressing not-reachable claim.
func (*Analyzer) Analyzeable ¶
Analyzeable reports the package-URL type this analyzer answers for.