Go: go/comparison-of-identical-expressions false positive when a variable is reassigned in a range loop (go-all 8.0.0)
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Anfängerfreundlichkeit
- 54/100
- Issue-Typ
- Bug
- Klarheit
- Klar beschrieben
- Aktivitätsstatus
- Aktiv
- Tech-Stack
- go
- Bereich
- testing-qa
Rechercherichtung
Start by reproducing the false positive with the Go samples in the issue and the two versions of CompareIdenticalValues.ql; compare results with go-all 7.3.2 and 8.0.0. Investigate how the range-loop CFG handles assignments that flow past the loop, and check whether related data-flow queries are affected. Done when the range-loop comparison is no longer reported while the issue’s other cases behave as expected.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Description of the false positive
Since codeql/go-queries 1.6.12 (with codeql/go-all 8.0.0), go/comparison-of-identical-expressions reports a comparison between a variable and the value it was initialised from, even though the variable may be reassigned inside a range loop between the two. With codeql/go-queries 1.6.11 (codeql/go-all 7.3.2), the same database gives no result.
The trigger is the range loop. The same assignment in a plain if or in a three-clause for loop is not reported. It looks related to the CFG rewrite in go-all 8.0.0, whose changelog mentions range statements. If assignments in a range body don't reach the code after the loop, other data-flow queries might be affected as well. I have only checked this query.
Code samples or links to source code
package repro
// Reported (line "if n == c"): n may be raised inside the range loop.
func Settle(c int, xs []int) int {
for {
n := c
for _, x := range xs {
if x > n {
n = x
}
}
if n == c { // <- "This expression compares an expression to itself."
break
}
c = n
}
return c
}
// Also reported: unconditional assignment in a range loop.
func VariantD(c int, xs []int) int {
n := c
for _, x := range xs {
n = x
}
if n == c { // <- reported
return 0
}
return n
}
// Not reported: the same assignment in a three-clause loop.
func VariantB(c int, xs []int) int {
n := c
for i := 0; i < len(xs); i++ {
if xs[i] > n {
n = xs[i]
}
}
if n == c {
return 0
}
return n
}
To reproduce (CodeQL CLI 2.27.1, macOS arm64, Go 1.25.13). --no-tracing is used only because this machine has no Rosetta for the tracer.
codeql database create db --language=go --source-root src --build-mode=autobuild --no-tracing
codeql database analyze db codeql/[email protected]:RedundantCode/CompareIdenticalValues.ql --format=sarif-latest --output=a.sarif --rerun
codeql database analyze db codeql/[email protected]:RedundantCode/CompareIdenticalValues.ql --format=sarif-latest --output=b.sarif --rerun
a.sarif, go-queries 1.6.11 / go-all 7.3.2: 0 results.b.sarif, go-queries 1.6.12 / go-all 8.0.0: 3 results:Settle,VariantD, and a third range-loop variant without the outer loop.
Without --rerun, the second command silently reuses the first command's cached results: its SARIF reports go-queries 1.6.11 and 0 results. This may be worth a look separately.
The same comparison is reported in real code here: https://github.com/gomaja/go-asn1/blob/2e83d89af0dc815fc1e0a589691032aa069153bc/runtime/ber/named_bit_size.go#L43. In that code, next starts as candidate and can be raised inside the range loop over the permitted intervals.
- Vorherrschende Sprache
- CodeQL
- Sterne
- 10.2k
- Forks
- 2.1k
- Ø Merge
- 2 T. 13 Std.
- Gemergte PRs (30 T.)
- 144
Entwicklungsumgebung
Startet den Dev-Container des Projekts im Browser, mit Ihrem eigenen GitHub-Konto.
- Kein Dockerfile und keine Docker-Compose-Datei
- Keine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus github/codeql
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 66/100
github/codeql#22766 · 3 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
Python: trailing comma in a PEP 695 type parameter list causes a parse errorEvtl. vergeben @jketema hat das vor 6 Tagen übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
github/codeql#22739 · 1 Kommentar · 1 Reaktion ·
Maintainer antworten meist innerhalb von 1 Tag
-
false-positive javascript
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
github/codeql#22632 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Add AlertSuppression.ql for Rust (inline // codeql[...] suppression)Evtl. vergeben @cnuss hat das vor 189 Tagen übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
github/codeql#21637 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
false-positive
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
github/codeql#21076 · 3 Kommentare · 3 Reaktionen ·
Maintainer antworten meist innerhalb von 1 Tag
Ähnliche Issues
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
-
hipRTC lit tests compile against /opt/rocm's LLVM instead of the ROCm under test (ci/ hardcodes LLVM_PATH)Evtl. vergeben @bernardogv hat das heute übernommen. Offen
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 82/100
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
Maintainer antworten meist innerhalb von 1 Tag
-
pending triage
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 76/100
nuxt/test-utils#1842 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 86/100
FinanceFlash/unvibecode#206 ·
Maintainer antworten meist innerhalb von 1 Tag