Skip to content

[lua2cpg] Add Lua 5.1 bytecode analysis frontend - #6119

Closed
prankster009 wants to merge 105 commits into
joernio:masterfrom
prankster009:lua-full-capability-upstream-pr-sanitized
Closed

prankster009 wants to merge 105 commits into
joernio:masterfrom
prankster009:lua-full-capability-upstream-pr-sanitized

Conversation

@prankster009

Copy link
Copy Markdown

Summary

  • Add a Lua 5.1 frontend based on bytecode decoding and CPG generation.
  • Model prototypes, instructions, calls, reaching definitions, module
    resolution, and interprocedural argument and return flow.
  • Provide source/sink matching, sanitizer classification, taint paths,
    and vulnerability reports.
  • Support Lua source analysis by compiling source files with luac5.1.
  • Include self-contained Lua 5.1 fixtures and reviewer-visible JSON evidence.

Usage

Build the frontend:

sbt 'lua2cpg/stage'
                                                                                                                                     
Analyze Lua 5.1 bytecode:
                                                                
joern-cli/frontends/lua2cpg/target/universal/stage/bin/lua2cpg \
/path/to/lua-bytecode \                                   
--output /tmp/lua.cpg.bin

Detailed usage, CPG traversals, evidence export, and reviewer commands are
documented in joern-cli/frontends/lua2cpg/README.md.


## Validation                 
                                                                
- sbt scalafmtCheck Test/scalafmtCheck: passed
- sbt 'lua2cpg/test': 14/14 tests passed          
- sbt 'lua2cpg/stage': passed                                     
- Staged CLI help: passed       
- Self-contained corpus: 42/42 bytecode inputs decoded, 0 diagnostics                                                                  
- Analysis evidence: 164 sources, 94 sinks, 20 taint paths, 20 reports                                                                 
- Secret scan of the final commits: 0 findings                    
                                                                
## Scope                                                          
                                                                
- Lua version: Lua 5.1                                            
- Analysis core: Lua 5.1 bytecode
- Lua source is analyzed after compilation with luac5.1           
- JSON evidence export is optional; the primary output is the CPG         

@prankster009
prankster009 marked this pull request as ready for review July 18, 2026 07:54
@prankster009
prankster009 force-pushed the lua-full-capability-upstream-pr-sanitized branch from 8eeb8c8 to e81be43 Compare July 22, 2026 07:38
@prankster009

Copy link
Copy Markdown
Author

This PR brings Lua analysis capability to Joern. It is derived from the Lua analysis component of our security research, FirmCross: Detecting Taint-style Vulnerabilities in Modern C-Lua Hybrid Web Services of Linux-based Firmware, which was validated on real-world Lua services and identified 610 previously unknown vulnerabilities.

Rather than importing the complete FirmCross system, this PR ports its reusable Lua analysis capability into Joern as a self-contained Lua 5.1 frontend. It supports workflows starting from either Lua source code or raw Lua 5.1 bytecode input, with semantic analysis performed on the bytecode, including CPG generation and interprocedural taint analysis.

To keep the PR focused and easier to review, reproducible reports and other generated intermediate artifacts have been removed from the Git history, while the implementation, fixtures, tests, and reproduction commands remain self-contained. We plan to continue improving the precision and coverage of Lua analysis in Joern through follow-up contributions.

@max-leuthaeuser

Copy link
Copy Markdown
Contributor

Hi @prankster009, thank you for the substantial effort that clearly went into this. A full (bytecode-decoding) frontend with tests, fixtures, and evidence export is a lot of work, and we appreciate the contribution.

That said, we've decided not to merge this PR at this time. Taking on a new language frontend is a long-term maintenance commitment for the core team. Keeping it working as the CPG schema evolves, handling bug reports, reviewing follow-up changes, and supporting users. We don't currently feel able to take on that responsibility for lua2cpg. This is a question of our maintenance capacity, not a judgment on the quality of your work.

One separate but important note, since it would block any future merge as well: this PR commits compiled Lua bytecode files as test fixtures. We don't accept binary files into the repository, even as test fixtures — binaries can't be meaningfully reviewed, diffed, or audited, and they permanently bloat the git history for every clone. Fixtures like these should be generated at test time from checked-in source instead (e.g., compile .lua sources with luac5.1 as part of the test setup) or fetched from an external artifact store.

You're very welcome to keep developing and distributing this on a fork of the project under the existing license, and to maintain it as an external frontend. If it matures there and there is sustained community interest, we'd be open to revisiting the discussion in the future.

Thanks again for the contribution and for your understanding.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants