`RULE-0-0-1`: "unreachable statement" false positives due to over-pruning of the control-flow graph
還沒有人認領這個 Issue。
評估
研究方向
從 RULE-0-0-1 的自訂 isReachable predicate 開始,追蹤 BasicBlock.getAPredecessor()、possiblePredecessor、potentiallyReturningFunction 和 reachableRecursive。使用 CodeQL CLI 2.26.2,透過自包含的 C++ 範例重現該報告,然後確認 update() 和 run() 中可達的陳述式不再被報告為不可達。
由索引模型根據 Issue 內容生成。
描述
Affected rules
RULE-0-0-1
Description
RULE-0-0-1 reports plainly reachable statements as unreachable. The query does not use the standard reachable predicate; it defines its own reachability walk over BasicBlock.getAPredecessor():
predicate isReachable(BasicBlock bb) {
bb = any(Function f).getEntryPoint()
or
isReachable(bb.getAPredecessor())
or
... // special cases for &&/||, ?:, catch blocks, constexpr if
}
BasicBlock.getAPredecessor() is derived from successors_adapted , One pruning step, possiblePredecessor, removes the control-flow graph edge after a FunctionCall unless the callee is classified as potentiallyReturningFunction. That classification is itself defined recursively in terms of the adapted control-flow graph (reachableRecursive).
When this circular analysis fails to prove that a function returns the edge after the call is dropped, the rest of the function becomes "unreachable", and the function's own exit point is then considered unreachable too. The function is consequently treated as noreturn, so callers have everything after the call flagged as well. The error cascades across the translation unit.
Environment: CodeQL CLI 2.26.2, codeql/misra-cpp-coding-standards 2.62.0 (cpp-all 5.0.0), C++17.
Example
Five false positives on this self-contained file: the if in update() and every statement in run() after the call to update().
#include <unordered_map>
namespace detail {
struct Error {
Error() noexcept = default;
};
template <typename E>
struct unexpected {
E error;
explicit unexpected(E e) noexcept : error(e) {}
};
template <typename T, typename E>
struct expected {
T value_{};
E error_{};
bool has_value_ = true;
expected(T v) noexcept : value_(v), has_value_(true) {}
expected(unexpected<E> u) noexcept : error_(u.error), has_value_(false) {}
explicit operator bool() const noexcept { return has_value_; }
};
} // namespace detail
using Error = detail::Error;
using Unexpected = detail::unexpected<Error>;
template <typename T> using Result = detail::expected<T, Error>;
Result<int> update(const std::unordered_map<int, int>& keys) noexcept {
auto it = keys.find(0);
if (it == keys.end()) { // flagged as unreachable
return Result<int>{Unexpected{Error{}}};
}
return Result<int>{it->second};
}
void run() noexcept {
std::unordered_map<int, int> keys;
auto r = update(keys); // flagged as unreachable
if (r) { // flagged as unreachable
(void)0; // flagged as unreachable
}
int x = 42; // flagged as unreachable
(void)x;
}
- 主要語言
- CodeQL
- 星號
- 227
- 分支
- 82
- 平均合併
- 6 天 7 小時
- 30 天內合併 PR
- 9
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
github/codeql-coding-standards 的其他 Issue
-
false positive/false negative Stardard-MISRA-C++
難度 2/5 1-3 小時 新手友好度 72/100
github/codeql-coding-standards#1172 ·
-
Difficulty-Low false positive/false negative false-negative Impact-Low Standard-MISRA-C
難度 2/5 1-3 小時 新手友好度 68/100
-
Difficulty-Medium false positive/false negative false-positive Impact-Medium Standard-CERT-C
難度 4/5 3-5 天 新手友好度 48/100
github/codeql-coding-standards#1200 ·
-
false positive/false negative
難度 3/5 1-2 天 新手友好度 65/100
github/codeql-coding-standards#1175 ·
-
false positive/false negative Stardard-MISRA-C++
難度 3/5 1-2 天 新手友好度 48/100
github/codeql-coding-standards#1165 ·
查看 github/codeql-coding-standards 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 75/100
palladius/rails8-app-on-gcp#145 ·
-
難度 2/5 1-3 小時 新手友好度 75/100
elastic/gradle-plugins#156 ·
-
area:workflow bug ready-for-agent
難度 2/5 1-3 小時 新手友好度 75/100
fil-donadoni/tolaria#4409 ·
-
難度 2/5 1-3 小時 新手友好度 65/100
dotenvx/dotenv-vscode#139 ·
-
難度 2/5 1-3 小時 新手友好度 70/100
Fission-AI/OpenSpec#1960 ·