Skip to content

Unexpected error "Rule parse error dart-dynamic-system-commands" #25

Description

@ericcornelissen

I'm running this ruleset in CI as:

git clone https://github.com/apiiro/malicious-code-ruleset.git ../malicious-code-ruleset
semgrep --config ../malicious-code-ruleset

which worked fine until today when I started getting the following error (note that this project has no Dart source code):


METRICS: Using configs from the Registry (like --config=p/ci) reports pseudonymous rule metrics to semgrep.dev.
To disable Registry rule metrics, use "--metrics=off".
When using configs only from local files (like --config=xyz.yml) metrics are sent only when the user is logged in.

More information: https://semgrep.dev/docs/metrics

               
               
┌─────────────┐
│ Scan Status │
└─────────────┘
  Scanning 94 files tracked by git with 101 Code rules:
                                                                                                                        
  Language   Rules   Files          Origin   Rules                                                                      
 ──────────────────────────        ────────────────                                                                     
  js            14      32          Custom     101                                                                      
  ts            14       3                                                                                              
  bash           6       3                                                                                              
                                                                                                                        
Error: [ERROR] Rule parse error in rule malicious-code-ruleset.dynamic_execution.dart.dart-dynamic-system-commands:
 Invalid pattern for Dart: Stdlib.Parsing.Parse_error
----- pattern -----
$P = Process;
...
$P.$RUN('dart', ['-e', ...]);

----- end pattern -----

                
                
┌──────────────┐
│ Scan Summary │
└──────────────┘
✅ Scan completed successfully.
 • Findings: 0 (0 blocking)
 • Rules run: 17
 • Targets scanned: 38
 • Parsed lines: ~100.0%
 • Scan skipped: 
   ◦ Files matching .semgrepignore patterns: 184
 • Scan was limited to files tracked by git
 • For a detailed list of skipped files and lines, run semgrep with the --verbose flag
Ran 17 rules on 38 files: 0 findings.

Activity

  1. Matan-Giladi commented on Jun 5, 2025

    @Matan-Giladi
    Collaborator

    Thanks for reporting. I didn't manage to reproduce the error. Which Semgrep version are you using?

  2. ericcornelissen commented on Jun 5, 2025

    @ericcornelissen
    Author
  3. Matan-Giladi commented on Jun 5, 2025

    @Matan-Giladi
    Collaborator

    I didn't manage to reproduce the error using the latest version, including on Dart files. It could be a sub-dependency issue, caused by another component. You'd have to either debug more or fork and delete the problematic rule or the Dart folder.

  4. ericcornelissen commented on Jun 6, 2025

    @ericcornelissen
    Author

    The following reproduces the problem for me locally:

    git clone git@github.com:ericcornelissen/shescape.git
    cd shescape
    docker run -it --rm --volume $PWD:/src --entrypoint sh docker.io/semgrep/semgrep@sha256:3947ff700c40fdad4d9431875d649279f162eeb3b6b7a16ba7ba911b4a88358f
    git clone https://github.com/apiiro/malicious-code-ruleset.git ../malicious-code-ruleset
    semgrep --config ../malicious-code-ruleset
    echo $?

    This fetches a21246b and outputs:

    Cloning into 'shescape'...
    remote: Enumerating objects: 10508, done.
    remote: Counting objects: 100% (767/767), done.
    remote: Compressing objects: 100% (243/243), done.
    remote: Total 10508 (delta 700), reused 525 (delta 524), pack-reused 9741 (from 3)
    Receiving objects: 100% (10508/10508), 4.94 MiB | 7.24 MiB/s, done.
    Resolving deltas: 100% (8108/8108), done.
    
    Unable to find image 'semgrep/semgrep@sha256:3947ff700c40fdad4d9431875d649279f162eeb3b6b7a16ba7ba911b4a88358f' locally
    docker.io/semgrep/semgrep@sha256:3947ff700c40fdad4d9431875d649279f162eeb3b6b7a16ba7ba911b4a88358f: Pulling from semgrep/semgrep
    f18232174bc9: Already exists 
    4ee519377a42: Pull complete 
    c664c0851505: Pull complete 
    a74de1fcaf7d: Pull complete 
    3891236cd1e7: Pull complete 
    008357ddee58: Pull complete 
    dc157545c5dc: Pull complete 
    bd9ddc54bea9: Pull complete 
    31897fa8222b: Pull complete 
    c00b04c13604: Pull complete 
    efbef319e03c: Pull complete 
    0bfdf99913cf: Pull complete 
    c54f7b18d269: Pull complete 
    46ca3a2adf7e: Pull complete 
    eeb01d8565aa: Pull complete 
    c1f1769fbf95: Pull complete 
    167ed7fc3bb0: Pull complete 
    1515f2876841: Pull complete 
    Digest: sha256:3947ff700c40fdad4d9431875d649279f162eeb3b6b7a16ba7ba911b4a88358f
    Status: Downloaded newer image for semgrep/semgrep@sha256:3947ff700c40fdad4d9431875d649279f162eeb3b6b7a16ba7ba911b4a88358f
    
    Cloning into '../malicious-code-ruleset'...
    remote: Enumerating objects: 758, done.
    remote: Counting objects: 100% (758/758), done.
    remote: Compressing objects: 100% (389/389), done.
    remote: Total 758 (delta 504), reused 609 (delta 359), pack-reused 0 (from 0)
    Receiving objects: 100% (758/758), 106.87 KiB | 7.12 MiB/s, done.
    Resolving deltas: 100% (504/504), done.
    
    ┌──── ○○○ ────┐
    │ Semgrep CLI │
    └─────────────┘
    
    METRICS: Using configs from the Registry (like --config=p/ci) reports pseudonymous rule metrics to semgrep.dev.
    To disable Registry rule metrics, use "--metrics=off".
    When using configs only from local files (like --config=xyz.yml) metrics are sent only when the user is logged in.
    
    More information: https://semgrep.dev/docs/metrics
    
                                                                                                                            
    Scanning 94 files (only git-tracked) with 101 Code rules:
                
      CODE RULES
                                                                                                                            
      Language   Rules   Files          Origin   Rules                                                                      
     ──────────────────────────        ────────────────                                                                     
      js            14      32          Custom     101                                                                      
      ts            14       3                                                                                              
      bash           6       3                                                                                              
                                                                                                                            
                        
      SUPPLY CHAIN RULES
                      
      No rules to run.
                      
              
      PROGRESS
       
      ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% 0:00:00                                                                                                                        
    [ERROR] Rule parse error in rule malicious-code-ruleset.dynamic_execution.dart.dart-dynamic-system-commands:
     Invalid pattern for Dart: Stdlib.Parsing.Parse_error
    ----- pattern -----
    $P = Process;
    ...
    $P.$RUN('dart', ['-e', ...]);
    
    ----- end pattern -----
    
                    
                    
    ┌──────────────┐
    │ Scan Summary │
    └──────────────┘
    ✅ Scan completed successfully.
     • Findings: 0 (0 blocking)
     • Rules run: 17
     • Targets scanned: 38
     • Parsed lines: ~100.0%
     • Scan skipped: 
       ◦ Files matching .semgrepignore patterns: 184
     • Scan was limited to files tracked by git
     • For a detailed list of skipped files and lines, run semgrep with the --verbose flag
    Ran 17 rules on 38 files: 0 findings.
    
    2
    
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions