`ReadOfUninitializedMemory`: Improve overall precision and recall
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 5/5
- Tempo estimado
- Mais de uma semana
- Facilidade para iniciantes
- 25/100
Direção de pesquisa
Comece pela consulta ReadOfUninitializedMemory e compare a implementação atual com o trabalho na branch referenciada try-use-subobjects-lib-in-rule-11-6-2. Revise os exemplos de testes unitários para o falso positivo e o falso negativo relatados e, em seguida, determine se a consulta aprimorada aumenta a precisão e o recall enquanto resolve as decisões restantes sobre a inicialização de campos e arrays.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Affected rules
- RULE-11-6-2
- RULE-9-1
- A8-5-0
- EXP33-C
- EXP53-CPP
Description
this query makes use of approximations that underrepresent uninitialized variables and over represent definition locations. it is in the idea of only reporting cases where results are more certain, however a potential audit version of the query could be constructed that improves the potential case detection and catch some FPs and FNs that are currently not detected.
work has been done on this effort in this branch.
this improved query has benefits of:
- reuses more existing modelling
- models allocated objects in a way that reuses more out of the box library as well
- increases cases handled that involved subobjects (both potential field analysis and also array analysis)
the current improved query needs more effort on:
- still uses some approximations around field initialization (see below comment for one such improvement/but still heurisitic)
- determination on if array subobject cases should be included or not (see below comment as well for potential adjustment to align omission more with current version of query)
Example
one FP case within the unit test that will be improved is:
int *p1 = new int;
*p1 = 0; // COMPLIANT[FALSE_POSITIVE] -- this is not found bc this is not an
// lvalue access
use(p1); // COMPLIANT[FALSE_POSITIVE] -- the pointee of p1 has been
// initialized
these cases will no longer be found with the improved version of the query
one FN case within the unit test that will be improved is:
S s1;
S s2 = {1};
auto i1 = s1.m1; // NON_COMPLIANT[FALSE_NEGATIVE] - rule currently is not
// field sensitive
this cases will be found with the improved version of the query
the examples given are run with the optional additions listed below in the comment
- Linguagem predominante
- CodeQL
- Estrelas
- 227
- Forks
- 82
- Merge médio
- 6d 7h
- PRs com merge (30d)
- 9
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de github/codeql-coding-standards
-
false positive/false negative Stardard-MISRA-C++
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
github/codeql-coding-standards#1172 ·
-
Difficulty-Low false positive/false negative false-negative Impact-Low Standard-MISRA-C
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
-
Difficulty-Medium false positive/false negative false-positive Impact-Medium Standard-CERT-C
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 48/100
github/codeql-coding-standards#1200 ·
-
`RULE-0-0-1`: "unreachable statement" false positives due to over-pruning of the control-flow graph Abertafalse positive/false negative
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 48/100
github/codeql-coding-standards#1190 ·
-
false positive/false negative
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 65/100
github/codeql-coding-standards#1175 ·
Todas as issues de github/codeql-coding-standards
Issues semelhantes
-
area: harness bug status: needs-triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
Human-Agent-Society/reef#625 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
vercel-labs/just-bash#464 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100