274 add json schema for mole taint model format (#275)

Added JSON schema to validate taint model
This commit is contained in:
Damian Pfammatter
2026-07-16 08:51:15 +02:00
committed by GitHub
parent 8b41a13909
commit a2c83d37fe
4 changed files with 145 additions and 2 deletions
+1
View File
@@ -24,6 +24,7 @@ mole/conf/*.yml.bak
!mole/conf/003-libc.yml !mole/conf/003-libc.yml
mole/conf/*.json mole/conf/*.json
mole/conf/*.json.bak mole/conf/*.json.bak
!mole/conf/taint_model_schema.json
!mole/conf/001-settings.json !mole/conf/001-settings.json
!mole/conf/003-libc.json !mole/conf/003-libc.json
+1 -1
View File
@@ -30,7 +30,7 @@ The taint model, and the corresponding functions, is backed by **JSON files** lo
You can add your own functions either by creating a custom JSON file (e.g., `conf/004-yourlib.json`) or by adding them manually through Binary Ninja's UI. For more details on how to do this and the expected format, refer to the next subsections. You can add your own functions either by creating a custom JSON file (e.g., `conf/004-yourlib.json`) or by adding them manually through Binary Ninja's UI. For more details on how to do this and the expected format, refer to the next subsections.
#### Configure Functions via JSON Files #### Configure Functions via JSON Files
To define your own functions - such as those belonging to a custom third-party library - you can use [`conf/003-libc.json`](../mole/conf/003-libc.json) as a template. First, duplicate and rename this file (e.g., to `conf/004-yourlib.json`), then add your custom function definitions to it. The expected format is described below: To define your own functions - such as those belonging to a custom third-party library - you can use [`conf/003-libc.json`](../mole/conf/003-libc.json) as a template. First, duplicate and rename this file (e.g., to `conf/004-yourlib.json`), then add your custom function definitions to it. The expected format is described below and can be validated using the JSON schema at [`conf/taint_model_schema.json`](../mole/conf/taint_model_schema.json):
```JSON ```JSON
{ {
+138
View File
@@ -0,0 +1,138 @@
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://raw.githubusercontent.com/cyber-defence-campus/mole/refs/heads/main/mole/conf/taint_model_schema.json",
"title": "Mole Taint Model",
"description": "JSON schema for Mole static-taint-analysis models",
"type": "object",
"required": ["taint_model"],
"properties": {
"taint_model": {
"$ref": "#/$defs/taint_model"
}
},
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": false,
"$defs": {
"taint_model" : {
"description": "Taint model",
"type": "object",
"minProperties": 0,
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": {
"$ref": "#/$defs/library"
}
},
"library": {
"description": "Library (e.g. \"libc\") (grouping level 1)",
"type": "object",
"minProperties": 0,
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": {
"$ref": "#/$defs/category"
}
},
"category": {
"description": "Category (e.g. \"Memory Copy\") (grouping level 2)",
"type": "object",
"minProperties": 0,
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": {
"$ref": "#/$defs/function"
}
},
"function": {
"description": "Function (e.g. \"memcpy\")",
"type": "object",
"required": ["aliases", "synopsis", "roles"],
"properties": {
"aliases": {
"description": "Alternative function names (e.g. [\"_memcpy\", \"__builtin_memcpy\"])",
"type": "array",
"items": {
"type": "string",
"minLength": 1
},
"minItems": 0,
"uniqueItems": true
},
"synopsis": {
"description": "Function type signature (e.g. \"void* memcpy(void* to, const void* from, size_t size)\")",
"type": "string",
"minLength": 1
},
"roles": {
"description": "Roles assigned to the function (e.g. source, sink and/or fixer)",
"type": "object",
"minProperties": 0,
"properties": {
"source": {
"$ref": "#/$defs/role"
},
"sink": {
"$ref": "#/$defs/role"
},
"fixer": {
"$ref": "#/$defs/role"
}
},
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": false
}
},
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": false
},
"role": {
"description": "Function role",
"type": "object",
"properties": {
"enabled": {
"description": "Flag stating whether the function has the role assigned by default (e.g. true)",
"type": "boolean"
},
"par_slice": {
"description": "Expression stating which function parameter(s) should propagate taint (e.g. \"i == 1 or i == 3\")",
"type": "string",
"minLength": 1
}
},
"patternProperties": {
"^_comment": {
"type": "string",
"minLength": 1
}
},
"additionalProperties": false
}
}
}
+5 -1
View File
@@ -250,7 +250,11 @@ class ConfigService:
config_files = sorted(os.listdir(self._config_path)) config_files = sorted(os.listdir(self._config_path))
for config_file in config_files: for config_file in config_files:
# Filter configuration files # Filter configuration files
if not fn.fnmatch(config_file, "*.json") or config_file == "000-mole.json": if (
not fn.fnmatch(config_file, "*.json")
or config_file == "000-mole.json"
or config_file == "taint_model_schema.json"
):
continue continue
# Load configuration file # Load configuration file
custom_config = self.import_config( custom_config = self.import_config(