`ReadOfUninitializedMemory`: Improve overall precision and recall

Abierto
#1,079 1 comentario 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
25/100
Tipo de issue
Refactorización
Claridad
Bastante claro
Estado de actividad
Estancado
Stack tecnológico
cpp
Área
devtools

Línea de trabajo

Comienza con la consulta ReadOfUninitializedMemory y compara la implementación actual con el trabajo de la rama referenciada try-use-subobjects-lib-in-rule-11-6-2. Revisa los ejemplos de pruebas unitarias para el falso positivo y el falso negativo reportados, y determina después si la consulta mejorada aumenta la precisión y la exhaustividad, al tiempo que resuelve las decisiones restantes sobre la inicialización de campos y arrays.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Difficulty-High false positive/false negative Impact-Medium
Affected rules
  • RULE-11-6-2
  • RULE-9-1
  • A8-5-0
  • EXP33-C
  • EXP53-CPP
Description

this query makes use of approximations that underrepresent uninitialized variables and over represent definition locations. it is in the idea of only reporting cases where results are more certain, however a potential audit version of the query could be constructed that improves the potential case detection and catch some FPs and FNs that are currently not detected.

work has been done on this effort in this branch.

this improved query has benefits of:

  • reuses more existing modelling
  • models allocated objects in a way that reuses more out of the box library as well
  • increases cases handled that involved subobjects (both potential field analysis and also array analysis)

the current improved query needs more effort on:

  • still uses some approximations around field initialization (see below comment for one such improvement/but still heurisitic)
  • determination on if array subobject cases should be included or not (see below comment as well for potential adjustment to align omission more with current version of query)
Example

one FP case within the unit test that will be improved is:

int *p1 = new int;
  *p1 = 0; // COMPLIANT[FALSE_POSITIVE] -- this is not found bc this is not an
           // lvalue access
  use(p1); // COMPLIANT[FALSE_POSITIVE] -- the pointee of p1 has been
           // initialized

these cases will no longer be found with the improved version of the query

one FN case within the unit test that will be improved is:

  S s1;
  S s2 = {1};

  auto i1 = s1.m1; // NON_COMPLIANT[FALSE_NEGATIVE] - rule currently is not
                   // field sensitive

this cases will be found with the improved version of the query

the examples given are run with the optional additions listed below in the comment

Lenguaje dominante
CodeQL
Estrellas
227
Forks
82
Merge medio
6 d 7 h
PR fusionados (30 d)
9

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de github/codeql-coding-standards

Todos los issues de github/codeql-coding-standards

Issues similares

Más issues de DevTools

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.