`ReadOfUninitializedMemory`: Improve overall precision and recall
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Anfängerfreundlichkeit
- 25/100
Rechercherichtung
Beginne mit der ReadOfUninitializedMemory-Abfrage und vergleiche die aktuelle Implementierung mit der Arbeit im referenzierten try-use-subobjects-lib-in-rule-11-6-2-Branch. Überprüfe die Unit-Test-Beispiele für den gemeldeten False Positive und False Negative und ermittle anschließend, ob die verbesserte Abfrage die Präzision und den Recall erhöht und gleichzeitig die verbleibenden Entscheidungen zur Initialisierung von Feldern und Arrays löst.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Affected rules
- RULE-11-6-2
- RULE-9-1
- A8-5-0
- EXP33-C
- EXP53-CPP
Description
this query makes use of approximations that underrepresent uninitialized variables and over represent definition locations. it is in the idea of only reporting cases where results are more certain, however a potential audit version of the query could be constructed that improves the potential case detection and catch some FPs and FNs that are currently not detected.
work has been done on this effort in this branch.
this improved query has benefits of:
- reuses more existing modelling
- models allocated objects in a way that reuses more out of the box library as well
- increases cases handled that involved subobjects (both potential field analysis and also array analysis)
the current improved query needs more effort on:
- still uses some approximations around field initialization (see below comment for one such improvement/but still heurisitic)
- determination on if array subobject cases should be included or not (see below comment as well for potential adjustment to align omission more with current version of query)
Example
one FP case within the unit test that will be improved is:
int *p1 = new int;
*p1 = 0; // COMPLIANT[FALSE_POSITIVE] -- this is not found bc this is not an
// lvalue access
use(p1); // COMPLIANT[FALSE_POSITIVE] -- the pointee of p1 has been
// initialized
these cases will no longer be found with the improved version of the query
one FN case within the unit test that will be improved is:
S s1;
S s2 = {1};
auto i1 = s1.m1; // NON_COMPLIANT[FALSE_NEGATIVE] - rule currently is not
// field sensitive
this cases will be found with the improved version of the query
the examples given are run with the optional additions listed below in the comment
- Vorherrschende Sprache
- CodeQL
- Sterne
- 227
- Forks
- 82
- Ø Merge
- 6 T. 7 Std.
- Gemergte PRs (30 T.)
- 9
Beitragsleitfaden
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus github/codeql-coding-standards
-
false positive/false negative Stardard-MISRA-C++
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
github/codeql-coding-standards#1172 ·
-
Difficulty-Low false positive/false negative false-negative Impact-Low Standard-MISRA-C
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 68/100
-
Difficulty-Medium false positive/false negative false-positive Impact-Medium Standard-CERT-C
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 48/100
github/codeql-coding-standards#1200 ·
-
`RULE-0-0-1`: "unreachable statement" false positives due to over-pruning of the control-flow graph Offenfalse positive/false negative
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 48/100
github/codeql-coding-standards#1190 ·
-
false positive/false negative
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 65/100
github/codeql-coding-standards#1175 ·
Alle Issues in github/codeql-coding-standards
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
-
enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
OpenwaterHealth/openmotion-bloodflow-app#604 · 1 Kommentar ·
-
good first issue
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 90/100
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
rust-bitcoin/rust-bitcoin#6930 · 1 Kommentar ·
-
Solved site promotion gate fails on runner PHP patch drift (expects 8.2.33, runner installs 8.2.34) Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
Automattic/blocks-engine#2161 ·