test(plc): add realistic OpenPLC-style traffic-light sample
CI / Check (pull_request) Successful in 5m20s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped

Second demo fixture (public-sample shape) to complement the all-rules
pump_station.st: a timed pedestrian-crossing state machine adapted from
the OpenPLC traffic-light example, extended with a SCADA/Modbus uplink and
a maintenance override. Mostly sound control logic with three planted,
field-realistic defects (hardcoded SCADA password, cleartext Modbus master,
maintenance mode that drops the pedestrian safety permit).

The regression test asserts the scanner surfaces those defects while staying
quiet on the guarded duty-cycle division and the JMP-free CASE machine —
demonstrating low false positives on real-world-shaped code.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Sharang Parnerkar
2026-07-16 10:25:31 +02:00
co-authored by Claude Opus 4.8
parent 5e983d699f
commit f8861419cb
2 changed files with 136 additions and 0 deletions
+44
View File
@@ -153,4 +153,48 @@ mod tests {
.count();
assert_eq!(div0, 1, "only the unguarded division should be flagged");
}
/// The realistic OpenPLC-style traffic-light sample is mostly sound control
/// logic: the scanner must surface its few genuine defects and stay quiet on
/// the timed state machine and the guarded duty-cycle division.
#[test]
fn realistic_sample_flags_only_real_issues() {
let all = analyze_tree(&demo_dir(), "demo-target");
let tl: Vec<_> = all
.iter()
.filter(|f| {
f.file_path
.as_deref()
.is_some_and(|p| p.ends_with("traffic_light.st"))
})
.collect();
assert!(!tl.is_empty(), "traffic_light.st should produce findings");
let rules: HashSet<&str> = tl.iter().filter_map(|f| f.rule_id.as_deref()).collect();
// The three planted defects: hardcoded SCADA password, cleartext Modbus
// master (no auth), and a maintenance mode that drops the PedPermit.
for r in [
"plc-hardcoded-credential",
"plc-insecure-comm",
"plc-safety-bypass",
] {
assert!(rules.contains(r), "expected rule {r}; got {rules:?}");
}
// Modbus/TCP on 502 is also an insecure-protocol port.
assert!(rules.contains("plc-insecure-protocol-port"));
// Low false positives: the guarded `IF LampCount <> 0` division and the
// JMP-free state machine must not trip anything.
assert_eq!(
tl.iter()
.filter(|f| f.rule_id.as_deref() == Some("plc-division-by-zero"))
.count(),
0,
"the guarded duty-cycle division must not be flagged"
);
assert!(
!rules.contains("plc-unstructured-jump"),
"the CASE state machine uses no JMP"
);
}
}