Skip to content

feat(analyzers): custom Roslyn analyzers CX001-CX004 with violation fixes - #66

Closed
mcpolo99 wants to merge 27 commits into
developfrom
feat/custom-roslyn-analyzers
Closed

mcpolo99 wants to merge 27 commits into
developfrom
feat/custom-roslyn-analyzers

Conversation

@mcpolo99

Copy link
Copy Markdown
Owner

Fixes #49

Custom Analyzers (Confuser.Analyzers project)

ID Severity Pattern Prevents
CX001 Error module.Import(typeof(X).GetMethod(...)) — host runtime import Wrong mscorlib version
CX002 Warning ResolveTypeDef()/ResolveMethodDef() result used without null check Crashes on external assemblies
CX003 Info ResolveThrow/ResolveTypeDefThrow usage audit Awareness of crash-on-failure points
CX004 Warning Assembly.GetTypes() without ReflectionTypeLoadException catch Plugin/packer load crashes

Violations Fixed

CX004:

  • PluginDiscovery.cs — catch ReflectionTypeLoadException, continue with loaded types
  • ComponentDiscovery.cs — same fix for GUI discovery

CX002:

  • VTableAnalyzer.cs:355-356 — null guard on two unprotected ResolveTypeDef() calls

CX001: Already fixed by PR #31 (Utils.Import resolves via CorLib). Analyzer prevents regressions.

Integration

  • New Confuser.Analyzers project (netstandard2.0) added to solution
  • Wired into all projects via ConfuserEx.Common.targets ProjectReference with OutputItemType=Analyzer
  • Excluded from self-analysis via MSBuildProjectName condition

mcpolo99 and others added 23 commits June 7, 2026 18:55
Co-authored-by: RandomCrocodile <mawi@polosab.com>
* fix WPF relative resource renaming

* Update Confuser.Renamer/Analyzers/WPFAnalyzer.cs

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

---------

Co-authored-by: Ryan <smbserv@qq.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* Add types in referencing assembly to netstandard DLL.

Types defined in AssemblyRefs of netstandard (e.g. mscorlib) will be moved to netstandard. Therefore, subsequence ModuleDef.Find will return AssemblyRef to netstandard. As a result, the confused module will only reference to netstandard.

* Remove AssemblyAttributes.PA_NoPlatform from assembly.

Net standard project may refer to NuGet package (e.g. System.ComponentModel.Composition) in order to use the Framework libraries. However, DLL in NuGet may have this attribute set but the actual Framework DLL does not. As a result, dnlib treats them as different assemblies and confused DLL will reference to two identical assemblies.

* Fix assembly reference to assemblies that hidden by netstandard assembly.

TargetModule.GetAssemblyRef returns null if type is defined in assembly hidden by netstandard. This change searches assemblies hidden by netstandard and returns the fixed type reference.

* Returns the method from CorLib of module to be confused instead from runtime.

MSBuild may runs on .net framework and runtime help will reference to mscorlib instead of netstandard. This change try resolve it from CorLib before from runtime type.

---------

Co-authored-by: KC Ip <kamchuen.ip@hidglobal.com>
) (#32)

Co-authored-by: RandomCrocodile <mawi@polosab.com>
… (#33)

When preserveGenericParams is true but name is null or empty,
ParseGenericName would crash. Add a null/empty guard to prevent this.

Cherry-pick of mkaring#516.

Co-authored-by: RandomCrocodile <mawi@polosab.com>
注意到 mkaring 在 1.4.0版本中对控制流保护做出了误操作(272行)
将src => statementLast.Contains(src),错误修改成了src => !statementLast.Contains(src),导致了保护后的程序出现了错误的循环,这里特此做出修复!

Co-authored-by: wujiayang2007 <52036257+wujiayang2007@users.noreply.github.com>
) (#35)

Cherry-pick of mkaring#481 — allows using wildcards like
*.dll in module paths to batch-load modules from the base directory.

The Load method now accepts an optional baseDirRoot parameter to
resolve relative base directory paths. New internal helpers AddModule,
IsWildcard, and BatchLoadModules handle wildcard expansion using
Directory.GetFiles with TopDirectoryOnly search.

Co-authored-by: RandomCrocodile <mawi@polosab.com>
…ttributed types and members (#38)

Detect serialization-related attributes and exclude decorated types and
members from renaming to prevent WCF/DataContract serialization breakage
at runtime.

Attributes now checked:
- DataContractAttribute on types
- DataMemberAttribute on fields and properties
- EnumMemberAttribute on enum fields

Fixes mcpolo99/private-ConfuserEx#9
Upstream: mkaring#147

Co-authored-by: RandomCrocodile <mawi@polosab.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…serialization (#39)

Co-authored-by: RandomCrocodile <mawi@polosab.com>
Co-authored-by: RandomCrocodile <mawi@polosab.com>
Co-authored-by: RandomCrocodile <mawi@polosab.com>
…for external types (#42)

Co-authored-by: RandomCrocodile <mawi@polosab.com>
…portedException (#43)

Co-authored-by: RandomCrocodile <mawi@polosab.com>
#44)

Co-authored-by: RandomCrocodile <mawi@polosab.com>
…#45)

Co-authored-by: RandomCrocodile <mawi@polosab.com>
Co-authored-by: RandomCrocodile <mawi@polosab.com>
…erage (#51)

Co-authored-by: RandomCrocodile <mawi@polosab.com>
Co-authored-by: RandomCrocodile <mawi@polosab.com>
) (#56)

Co-authored-by: RandomCrocodile <mawi@polosab.com>
…odernize (#57)

Co-authored-by: RandomCrocodile <mawi@polosab.com>
#58)

Co-authored-by: RandomCrocodile <mawi@polosab.com>
@mcpolo99 mcpolo99 added the enhancement New feature or request label Jun 10, 2026
@mcpolo99 mcpolo99 closed this Jun 11, 2026
@mcpolo99
mcpolo99 deleted the feat/custom-roslyn-analyzers branch June 11, 2026 09:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant