Go: go/comparison-of-identical-expressions false positive when a variable is reassigned in a range loop (go-all 8.0.0)
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 54/100
- Tipo de issue
- Bug
- Clareza
- Claramente especificada
- Status de atividade
- Ativa
- Stack de tecnologia
- go
- Domínio
- testing-qa
Direção de pesquisa
Start by reproducing the false positive with the Go samples in the issue and the two versions of CompareIdenticalValues.ql; compare results with go-all 7.3.2 and 8.0.0. Investigate how the range-loop CFG handles assignments that flow past the loop, and check whether related data-flow queries are affected. Done when the range-loop comparison is no longer reported while the issue’s other cases behave as expected.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Description of the false positive
Since codeql/go-queries 1.6.12 (with codeql/go-all 8.0.0), go/comparison-of-identical-expressions reports a comparison between a variable and the value it was initialised from, even though the variable may be reassigned inside a range loop between the two. With codeql/go-queries 1.6.11 (codeql/go-all 7.3.2), the same database gives no result.
The trigger is the range loop. The same assignment in a plain if or in a three-clause for loop is not reported. It looks related to the CFG rewrite in go-all 8.0.0, whose changelog mentions range statements. If assignments in a range body don't reach the code after the loop, other data-flow queries might be affected as well. I have only checked this query.
Code samples or links to source code
package repro
// Reported (line "if n == c"): n may be raised inside the range loop.
func Settle(c int, xs []int) int {
for {
n := c
for _, x := range xs {
if x > n {
n = x
}
}
if n == c { // <- "This expression compares an expression to itself."
break
}
c = n
}
return c
}
// Also reported: unconditional assignment in a range loop.
func VariantD(c int, xs []int) int {
n := c
for _, x := range xs {
n = x
}
if n == c { // <- reported
return 0
}
return n
}
// Not reported: the same assignment in a three-clause loop.
func VariantB(c int, xs []int) int {
n := c
for i := 0; i < len(xs); i++ {
if xs[i] > n {
n = xs[i]
}
}
if n == c {
return 0
}
return n
}
To reproduce (CodeQL CLI 2.27.1, macOS arm64, Go 1.25.13). --no-tracing is used only because this machine has no Rosetta for the tracer.
codeql database create db --language=go --source-root src --build-mode=autobuild --no-tracing
codeql database analyze db codeql/[email protected]:RedundantCode/CompareIdenticalValues.ql --format=sarif-latest --output=a.sarif --rerun
codeql database analyze db codeql/[email protected]:RedundantCode/CompareIdenticalValues.ql --format=sarif-latest --output=b.sarif --rerun
a.sarif, go-queries 1.6.11 / go-all 7.3.2: 0 results.b.sarif, go-queries 1.6.12 / go-all 8.0.0: 3 results:Settle,VariantD, and a third range-loop variant without the outer loop.
Without --rerun, the second command silently reuses the first command's cached results: its SARIF reports go-queries 1.6.11 and 0 results. This may be worth a look separately.
The same comparison is reported in real code here: https://github.com/gomaja/go-asn1/blob/2e83d89af0dc815fc1e0a589691032aa069153bc/runtime/ber/named_bit_size.go#L43. In that code, next starts as candidate and can be raised inside the range loop over the permitted intervals.
- Linguagem predominante
- CodeQL
- Estrelas
- 10.2k
- Forks
- 2.1k
- Merge médio
- 2d 10h
- PRs com merge (30d)
- 153
Preparar o ambiente
Inicia o contêiner de desenvolvimento do projeto no navegador, com a sua própria conta do GitHub.
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de github/codeql
-
Python: trailing comma in a PEP 695 type parameter list causes a parse errorTalvez já em andamento @jketema assumiu há 7 dias. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
github/codeql#22739 · 1 comentário · 1 reação ·
Mantenedores costumam responder em até 1 dia
-
false-positive javascript
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
github/codeql#22632 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Add AlertSuppression.ql for Rust (inline // codeql[...] suppression)Talvez já em andamento @cnuss assumiu há 190 dias. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
github/codeql#21637 · 2 comentários ·
Mantenedores costumam responder em até 1 dia
-
false-positive
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
github/codeql#21076 · 3 comentários · 3 reações ·
Mantenedores costumam responder em até 1 dia
-
Actions: `uses: $/…` self-repository references are not resolved to local reusable workflows or composite actions (false positives and downgraded severity)Talvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Aberta
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 62/100
github/codeql#22755 · 1 comentário · 1 reação ·
Mantenedores costumam responder em até 1 dia
Todas as issues de github/codeql
Issues semelhantes
-
Tests that cannot fail, and the erddapy-3-1 job's file selectionTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
eeholmes/xpublish-erddap#111 ·
Mantenedores costumam responder em até 1 dia
-
bug
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
yonatangross/orchestkit#4697 ·
Mantenedores costumam responder em até 1 dia
-
area:rules good first issue
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
good first issue Priority-P3 T2
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
Mantenedores costumam responder em até 1 dia
-
agentic-workflows automation code-quality cookie improvement quick-win task-mining testing
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
Mantenedores costumam responder em até 1 dia