274 add json schema for mole taint model format (#275)

Added JSON schema to validate taint model
This commit is contained in:
Damian Pfammatter
2026-07-16 08:51:15 +02:00
committed by GitHub
parent 8b41a13909
commit a2c83d37fe
4 changed files with 145 additions and 2 deletions
+1
View File
@@ -24,6 +24,7 @@ mole/conf/*.yml.bak
!mole/conf/003-libc.yml
mole/conf/*.json
mole/conf/*.json.bak
!mole/conf/taint_model_schema.json
!mole/conf/001-settings.json
!mole/conf/003-libc.json
+1 -1
View File
@@ -30,7 +30,7 @@ The taint model, and the corresponding functions, is backed by **JSON files** lo
You can add your own functions either by creating a custom JSON file (e.g., `conf/004-yourlib.json`) or by adding them manually through Binary Ninja's UI. For more details on how to do this and the expected format, refer to the next subsections.
#### Configure Functions via JSON Files
To define your own functions - such as those belonging to a custom third-party library - you can use [`conf/003-libc.json`](../mole/conf/003-libc.json) as a template. First, duplicate and rename this file (e.g., to `conf/004-yourlib.json`), then add your custom function definitions to it. The expected format is described below:
To define your own functions - such as those belonging to a custom third-party library - you can use [`conf/003-libc.json`](../mole/conf/003-libc.json) as a template. First, duplicate and rename this file (e.g., to `conf/004-yourlib.json`), then add your custom function definitions to it. The expected format is described below and can be validated using the JSON schema at [`conf/taint_model_schema.json`](../mole/conf/taint_model_schema.json):
```JSON
{
+138
View File
@@ -0,0 +1,138 @@
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://raw.githubusercontent.com/cyber-defence-campus/mole/refs/heads/main/mole/conf/taint_model_schema.json",
"title": "Mole Taint Model",
"description": "JSON schema for Mole static-taint-analysis models",
"type": "object",
"required": ["taint_model"],
"properties": {
"taint_model": {
"$ref": "#/$defs/taint_model"
}
},
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": false,
"$defs": {
"taint_model" : {
"description": "Taint model",
"type": "object",
"minProperties": 0,
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": {
"$ref": "#/$defs/library"
}
},
"library": {
"description": "Library (e.g. \"libc\") (grouping level 1)",
"type": "object",
"minProperties": 0,
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": {
"$ref": "#/$defs/category"
}
},
"category": {
"description": "Category (e.g. \"Memory Copy\") (grouping level 2)",
"type": "object",
"minProperties": 0,
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": {
"$ref": "#/$defs/function"
}
},
"function": {
"description": "Function (e.g. \"memcpy\")",
"type": "object",
"required": ["aliases", "synopsis", "roles"],
"properties": {
"aliases": {
"description": "Alternative function names (e.g. [\"_memcpy\", \"__builtin_memcpy\"])",
"type": "array",
"items": {
"type": "string",
"minLength": 1
},
"minItems": 0,
"uniqueItems": true
},
"synopsis": {
"description": "Function type signature (e.g. \"void* memcpy(void* to, const void* from, size_t size)\")",
"type": "string",
"minLength": 1
},
"roles": {
"description": "Roles assigned to the function (e.g. source, sink and/or fixer)",
"type": "object",
"minProperties": 0,
"properties": {
"source": {
"$ref": "#/$defs/role"
},
"sink": {
"$ref": "#/$defs/role"
},
"fixer": {
"$ref": "#/$defs/role"
}
},
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": false
}
},
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": false
},
"role": {
"description": "Function role",
"type": "object",
"properties": {
"enabled": {
"description": "Flag stating whether the function has the role assigned by default (e.g. true)",
"type": "boolean"
},
"par_slice": {
"description": "Expression stating which function parameter(s) should propagate taint (e.g. \"i == 1 or i == 3\")",
"type": "string",
"minLength": 1
}
},
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": false
}
}
}
+5 -1
View File
@@ -250,7 +250,11 @@ class ConfigService:
config_files = sorted(os.listdir(self._config_path))
for config_file in config_files:
# Filter configuration files
if not fn.fnmatch(config_file, "*.json") or config_file == "000-mole.json":
if (
not fn.fnmatch(config_file, "*.json")
or config_file == "000-mole.json"
or config_file == "taint_model_schema.json"
):
continue
# Load configuration file
custom_config = self.import_config(