Goal: Get the 56,105 engine rules from vendor/codeql/cpp to evaluate successfully.
Deliverables:
- Engine evaluates 56K rules against basic.c without stratification error
- Class characteristic predicates (
Function#char,Element#char) produce correct tuples - Regression test:
qlpack_probe.rsevaluation phase succeeds
Tasks:
- Add a "skip-cycles" mode to the engine stratifier that drops rules involved in negation cycles
- Evaluate the remaining rules and verify core predicates work
- Implement proper fix: inline double-negation patterns in MIR (
forall/implies→ direct AntiJoin without auxiliary predicate) - Re-run full evaluation and measure how many predicates produce results
Testable Milestones:
- Engine evaluates with cycle-skipping, >90% of rules execute
-
Function#charrelation has 3 rows when run against basic.c - Proper fix: 0 false negation cycles on vendor/codeql
Goal: Member calls on subclass-typed variables resolve to parent class methods. Transitive closure works.
Deliverables:
f.getName()wheref : SubClassfindsParentClass#getNameedges+(a, b)generates recursive transitive closure predicatex in [1, 2, 3]creates proper disjunction- Regression tests for all three
Tasks:
- Dispatch predicates: After lowering all files, build a map of
method_name → [Class#method_name]. For each method name, generate a dispatch predicate:method_name(this, args...) :- Class1#method_name(this, args...); ... - Closure operators: When
ClosureOp::Plusis present on a call, generate a recursive predicate:_tc_P(a, b) :- P(a, b). _tc_P(a, b) :- P(a, c), _tc_P(c, b). - SetLiteral fix: Generate disjunction for
[a, b, c].
Testable Milestones:
- E2E test:
from SubClass f select f.parentMethod()returns correct results - E2E test:
edges+(a, b)returns transitive closure - E2E test:
x in [1, 2, 3]matches all three values - Existing 34 E2E tests still pass
Goal: Our C++ extractor schema matches what vendor library classes expect. String methods work.
Deliverables:
- Audit of which database tables vendor library classes reference vs what our extractor produces
- Engine built-in predicates for string methods (
toString,regexpMatch,matches) - Mapping layer between our schema column names and CodeQL schema column names
Tasks:
- Schema audit: Compare
semmlecode.cpp.dbschemetables with ourcpp_schema(). List missing tables and column mismatches. - String builtins: Add engine support for
string.toString(),int.toString(),string.length(),string.matches(pattern). - Table name mapping: If our extractor uses different table/column names than the vendor schema, add a translation layer.
Testable Milestones:
- Document listing all table mismatches between schemas
- Engine test:
"hello".length() = 5evaluates correctly - Engine test:
42.toString() = "42"evaluates correctly - Schema coverage report: X/Y tables from vendor schema are populated by our extractor