`MEM53-CPP`: False positive due to flow through `realloc`
還沒有人認領這個 Issue。
評估
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 新手友好度
- 30/100
- Issue 類型
- 缺陷
- 描述清晰度
- 基本清楚
- 活躍度
- 停滯
- 技術堆疊
- cpp
- 領域
- devtools, testing-qa
研究方向
先從 MEM53-CPP 測試案例和 taint-tracking 設定的 isSource 定義開始,然後檢視與 realloc 流程變更相關的已連結 pull request。判斷舊的 AST 型函式庫如何處理 realloc,以及受影響的測試情境是否有效;完成的標準是在不接受關於重新配置新配置記憶體的不安全假設下解決 false positive。
由索引模型根據 Issue 內容生成。
描述
Affected rules
MEM53-CPP
Description
In https://github.com/github/codeql/pull/14637 we added taint-flow through the indirection of the pointer passed to realloc to the indirection of the result. That is, flow through the following example:
int* p = ...;
*p = tainted_value;
int* q = (int*)realloc(p, 1024);
sink(*p);
this relies on the new taint-tracking library to distinguish between the result of realloc(...), and the result of what realloc(...) points to. Since the old AST-based taint-tracking library cannot do this this results in a FP in the testcases for MEM53-CPP (that we accepted on the next branch here: https://github.com/github/codeql-coding-standards/pull/419)
The query already tries to rule out realloc cases by excluding them in the definition of the taint-tracking configuration's isSource, but to get this query back to not reporting a FP here a barrier on realloc would have to be inserted.
As @jketema points out the affected test is actually really sketchy since there’s no guarantee that memory allocated with new can safely be realloc'ed. So maybe this scenario should be thought about more carefully by someone on your team.
- 主要語言
- CodeQL
- 星號
- 227
- 分支
- 82
- 平均合併
- 6 天 7 小時
- 30 天內合併 PR
- 9
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
github/codeql-coding-standards 的其他 Issue
-
false positive/false negative Stardard-MISRA-C++
難度 2/5 1-3 小時 新手友好度 72/100
github/codeql-coding-standards#1172 ·
-
Difficulty-Low false positive/false negative false-negative Impact-Low Standard-MISRA-C
難度 2/5 1-3 小時 新手友好度 68/100
-
Difficulty-Medium false positive/false negative false-positive Impact-Medium Standard-CERT-C
難度 4/5 3-5 天 新手友好度 48/100
github/codeql-coding-standards#1200 ·
-
`RULE-0-0-1`: "unreachable statement" false positives due to over-pruning of the control-flow graph 未關閉false positive/false negative
難度 4/5 3-5 天 新手友好度 48/100
github/codeql-coding-standards#1190 ·
-
false positive/false negative
難度 3/5 1-2 天 新手友好度 65/100
github/codeql-coding-standards#1175 ·
查看 github/codeql-coding-standards 的全部 Issue
相似的 Issue
-
kaliscan.com 未關閉N: AdGuard for iOS P3: Medium T: Ads
難度 2/5 1-3 小時 新手友好度 68/100
AdguardTeam/AdguardFilters#242501 ·
-
難度 2/5 1-3 小時 新手友好度 84/100
-
[BUG] createTool tools cannot be registered with Mastra when exactOptionalPropertyTypes is enabled 未關閉customer-eng status: needs triage
難度 2/5 1-3 小時 新手友好度 84/100
-
add-toolnames MCP Toolnames Toolnames checkup
難度 2/5 1-3 小時 新手友好度 68/100
rajbos/ai-engineering-fluency#2190 · 3 則留言 ·
-
enhancement
難度 2/5 1-3 小時 新手友好度 78/100
gajus/eslint-plugin-jsdoc#1776 · 1 個 reaction ·