@@ -139,7 +139,30 @@ private predicate sourceModelCsv(string row) {
139139 "javax.servlet.http;Cookie;false;getComment;();;ReturnValue;remote" ,
140140 // ApacheHttp*
141141 "org.apache.http;HttpMessage;false;getParams;();;ReturnValue;remote" ,
142- "org.apache.http;HttpEntity;false;getContent;();;ReturnValue;remote"
142+ "org.apache.http;HttpEntity;false;getContent;();;ReturnValue;remote" ,
143+ // In the setting of Android we assume that XML has been transmitted over
144+ // the network, so may be tainted.
145+ // XmlPullGetMethod
146+ "org.xmlpull.v1;XmlPullParser;false;getName;();;ReturnValue;remote" ,
147+ "org.xmlpull.v1;XmlPullParser;false;getNamespace;();;ReturnValue;remote" ,
148+ "org.xmlpull.v1;XmlPullParser;false;getText;();;ReturnValue;remote" ,
149+ // XmlAttrSetGetMethod
150+ "android.util;AttributeSet;false;getAttributeBooleanValue;;;ReturnValue;remote" ,
151+ "android.util;AttributeSet;false;getAttributeCount;;;ReturnValue;remote" ,
152+ "android.util;AttributeSet;false;getAttributeFloatValue;;;ReturnValue;remote" ,
153+ "android.util;AttributeSet;false;getAttributeIntValue;;;ReturnValue;remote" ,
154+ "android.util;AttributeSet;false;getAttributeListValue;;;ReturnValue;remote" ,
155+ "android.util;AttributeSet;false;getAttributeName;;;ReturnValue;remote" ,
156+ "android.util;AttributeSet;false;getAttributeNameResource;;;ReturnValue;remote" ,
157+ "android.util;AttributeSet;false;getAttributeNamespace;;;ReturnValue;remote" ,
158+ "android.util;AttributeSet;false;getAttributeResourceValue;;;ReturnValue;remote" ,
159+ "android.util;AttributeSet;false;getAttributeUnsignedIntValue;;;ReturnValue;remote" ,
160+ "android.util;AttributeSet;false;getAttributeValue;;;ReturnValue;remote" ,
161+ "android.util;AttributeSet;false;getClassAttribute;;;ReturnValue;remote" ,
162+ "android.util;AttributeSet;false;getIdAttribute;;;ReturnValue;remote" ,
163+ "android.util;AttributeSet;false;getIdAttributeResourceValue;;;ReturnValue;remote" ,
164+ "android.util;AttributeSet;false;getPositionDescription;;;ReturnValue;remote" ,
165+ "android.util;AttributeSet;false;getStyleAttribute;;;ReturnValue;remote"
143166 ]
144167}
145168
0 commit comments