Skip to content

JS: Improve support for NodeJS pipe callbacks - #22765

Draft
MathiasVP wants to merge 4 commits into
github:mainfrom
MathiasVP:js-better-nodejs-callback-support
Draft

MathiasVP wants to merge 4 commits into
github:mainfrom
MathiasVP:js-better-nodejs-callback-support

Conversation

@MathiasVP

Copy link
Copy Markdown
Contributor

Somewhat vibe-coded, but I think it looks reasonable (after lots of cleanup).

@MathiasVP MathiasVP added the JS label Oct 6, 2026
@MathiasVP
MathiasVP force-pushed the js-better-nodejs-callback-support branch from 28aa544 to 620f2a8 Compare October 7, 2026 10:25
@MathiasVP
MathiasVP marked this pull request as ready for review October 7, 2026 10:30
@MathiasVP
MathiasVP requested a review from a team as a code owner October 7, 2026 10:30
Copilot AI balanced review requested due to automatic review settings October 7, 2026 10:30

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Standard writable hooks and several supported stream inputs or filesystem variants are not modeled correctly.

Review effort: Balanced
Findings: 5 Medium severity

Open (5)
What changed in this PR

Adds Node.js stream data-flow modeling for Readable.from() and piped destinations.

Changes:

  • Models readable stream factories, fluent methods, and implicit pipe writes.
  • Adds stream pipe flow tests.
  • Documents the analysis improvement.
File Description
NodeJSLib.qll Adds stream and pipe flow modeling.
StreamPipeDataFlow.ql Defines inline flow assertions.
StreamPipeDataFlow.expected Stores expected test results.
stream-pipe.js Provides stream flow test cases.
2026-10-07-nodejs-stream-pipe.md Adds the change note.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

private EarlyStageNode getAStreamModuleNode() { BuiltinModule<isStream/1>::builtinModule(result) }

overlay[local?]
private predicate isFs(string name) { name = "fs" }
Comment on lines +788 to +789
streamConstructor(base) and
memberRead(base, "fromWeb", node)
DataFlow::Node pred, DataFlow::ContentSet contents, DataFlow::Node succ
) {
exists(ReadableFromCall call |
pred = call.getArgument(0).flow() and
Comment on lines +981 to +983
override string getCalleeName() { result = "write" }

override string getMethodName() { result = "write" }

module StreamPipeConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
source.getFile().getBaseName() = ["stream-pipe.js", "stream-pipe.mjs"] and
@MathiasVP
MathiasVP marked this pull request as draft October 7, 2026 10:42

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants