[lua2cpg] Add Lua 5.1 bytecode analysis frontend - #6119
prankster009 wants to merge 105 commits into
Conversation
8eeb8c8 to
e81be43
Compare
|
This PR brings Lua analysis capability to Joern. It is derived from the Lua analysis component of our security research, FirmCross: Detecting Taint-style Vulnerabilities in Modern C-Lua Hybrid Web Services of Linux-based Firmware, which was validated on real-world Lua services and identified 610 previously unknown vulnerabilities. Rather than importing the complete FirmCross system, this PR ports its reusable Lua analysis capability into Joern as a self-contained Lua 5.1 frontend. It supports workflows starting from either Lua source code or raw Lua 5.1 bytecode input, with semantic analysis performed on the bytecode, including CPG generation and interprocedural taint analysis. To keep the PR focused and easier to review, reproducible reports and other generated intermediate artifacts have been removed from the Git history, while the implementation, fixtures, tests, and reproduction commands remain self-contained. We plan to continue improving the precision and coverage of Lua analysis in Joern through follow-up contributions. |
|
Hi @prankster009, thank you for the substantial effort that clearly went into this. A full (bytecode-decoding) frontend with tests, fixtures, and evidence export is a lot of work, and we appreciate the contribution. That said, we've decided not to merge this PR at this time. Taking on a new language frontend is a long-term maintenance commitment for the core team. Keeping it working as the CPG schema evolves, handling bug reports, reviewing follow-up changes, and supporting users. We don't currently feel able to take on that responsibility for lua2cpg. This is a question of our maintenance capacity, not a judgment on the quality of your work. One separate but important note, since it would block any future merge as well: this PR commits compiled Lua bytecode files as test fixtures. We don't accept binary files into the repository, even as test fixtures — binaries can't be meaningfully reviewed, diffed, or audited, and they permanently bloat the git history for every clone. Fixtures like these should be generated at test time from checked-in source instead (e.g., compile .lua sources with luac5.1 as part of the test setup) or fetched from an external artifact store. You're very welcome to keep developing and distributing this on a fork of the project under the existing license, and to maintain it as an external frontend. If it matures there and there is sustained community interest, we'd be open to revisiting the discussion in the future. Thanks again for the contribution and for your understanding. |
Summary
resolution, and interprocedural argument and return flow.
and vulnerability reports.
luac5.1.Usage
Build the frontend: