`DCL53-CPP`: Reports non syntactically ambiguous object declarations
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
Research direction
Start with LocalConstructorInitializedObjectHidesIdentifier.ql and its existing test case, then compare the query results for the S1(g1), S1 g2(), S1 g3, S1 g4{}, S1 g5(1), and S1 g6{1} examples. The work is done when the DCL53-CPP query reports the non-compliant declarations without the listed false positives, or the remaining parsing limitation is documented.
Written by the indexing model from the issue text.
Description
Affected rules
DCL53-CPP
Description
LocalConstructorInitializedObjectHidesIdentifier.ql currently identifies variable declarations that call a constructor and hide an outer scope variable. However, this does not fully capture the cases covered by this vexing parsing situation, which is looking for S1(g1).
The following additions to the query could help address this problem:
v.getInitializer().getExpr().(ConstructorCall).getNumberOfArguments() = 0 and
not v.getInitializer().isBraced()
However this would still flag S1 g3; below - as we don't currently have a record of where the brackets were during parsing.
Example
This modification of the test case highlights the problems:
int g1 = 0;
int g2 = 0;
int g3 = 0;
int g4 = 0;
int g5 = 0;
int g6 = 0;
void f1() {
S1(g1); // NON_COMPLIANT
S1 g2(); // NON_COMPLIANT
S1 g3; // COMPLIANT[FALSE_POSITIVE]
S1 g4{}; // COMPLIANT[FALSE_POSITIVE]
S1 g5(1); // COMPLIANT[FALSE_POSITIVE]
S1 g6{1}; // COMPLIANT[FALSE_POSITIVE]
}
- Dominant language
- CodeQL
- Stars
- 227
- Forks
- 82
- Avg merge
- 6d 7h
- Merged PRs (30d)
- 9
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/codeql-coding-standards
-
false positive/false negative Stardard-MISRA-C++
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/codeql-coding-standards#1172 ·
-
Difficulty-Low false positive/false negative false-negative Impact-Low Standard-MISRA-C
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Difficulty-Medium false positive/false negative false-positive Impact-Medium Standard-CERT-C
Difficulty 4/5 3-5 days Newbie friendliness 48/100
github/codeql-coding-standards#1200 ·
-
`RULE-0-0-1`: "unreachable statement" false positives due to over-pruning of the control-flow graph Openfalse positive/false negative
Difficulty 4/5 3-5 days Newbie friendliness 48/100
github/codeql-coding-standards#1190 ·
-
false positive/false negative
Difficulty 3/5 1-2 days Newbie friendliness 65/100
github/codeql-coding-standards#1175 ·
All issues in github/codeql-coding-standards
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
palladius/rails8-app-on-gcp#145 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
elastic/gradle-plugins#156 ·
-
area:workflow bug ready-for-agent
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
fil-donadoni/tolaria#4409 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
dotenvx/dotenv-vscode#139 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Fission-AI/OpenSpec#1960 ·