False Negative:ArrayIndexOutOfBounds.ql
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 45/100
Hướng nghiên cứu
Bắt đầu với Likely Bugs/Collections/ArrayIndexOutOfBounds.ql và so sánh cách nó xử lý việc truy cập mảng trực tiếp với việc truy cập bằng các phương thức trợ giúp, bí danh và chỉ mục được tính toán. Tái tạo các ví dụ Java từ issue, sau đó xác minh rằng query báo cáo mọi lần truy cập vượt giới hạn, bao gồm cả các chỉ mục âm.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Version
codeql 2.23.9
When I detect the code like this using Likely Bugs/Collections/ArrayIndexOutOfBounds.ql, the problem is reported normally:
package scensct.core.pos;
public class PosCase1 {
public static void main(String[] args) {
int[] arr = new int[5];
int index = 10; // Unbounded index, no constraint check before access
int value = arr[index]; // Direct access with potentially out-of-bounds index // [REPORTED LINE]
}
}
However, when I use a mediator variable or call a mediator function, ArrayIndexOutOfBounds.ql fails to detect the problem:
package scensct.var.pos;
public class PosCase1_Var4 {
public static void main(String[] args) {
int[] arr = createArray();
int index = getIndex();
int value = arr[index]; // Access with index from method
}
private static int[] createArray() {
return new int[5];
}
private static int getIndex() {
return 10;
}
}
package scensct.var.pos;
public class PosCase2_Var4 {
public static void main(String[] args) {
int[] arr = new int[5];
int K = 5;
// Introduce an alias reference
int[] alias = arr;
int index = K;
int value = alias[index];
}
}
package scensct.var.pos;
public class PosCase2_Var5 {
private static int getIndex(int k) {
return k;
}
public static void main(String[] args) {
int[] arr = new int[5];
int K = 5;
// Move index computation to a helper method
int index = getIndex(K);
int value = arr[index];
}
}
package scensct.core.pos;
public class PosCase3 {
public static void main(String[] args) {
int[] arr = new int[5];
int K = -1; // Negative bound
int index = K + 0; // Index bounded below by negative K
int value = arr[index]; // Access with potentially negative index
}
}
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 16 giờ
- Pull request đã merge (30 ngày)
- 143
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/codeql
-
agentic-workflows
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
false-positive javascript
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
-
C#: cs/simplifiable-boolean-expression false positive on Nullable<bool> compared with a literal Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
false-positive
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Tất cả issue của github/codeql
Issue tương tự
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
canonical/paas-charm#368 · 1 bình luận ·
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
palladius/rails8-app-on-gcp#142 ·
-
addition to tracking list Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
StevenBlack/hosts#3256 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
corsairdev/corsair#1764 ·
-
oblt-aw/detector/security
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100