Python: Call analysis fails in some scenarios

未关闭
#19,288 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
35/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
停滞
技术栈
python
领域
devtools

调研方向

首先,针对最小 Python 示例运行提供的 CodeQL 查询,并比较标记为正常工作或已损坏的调用。检查 Python extractor 和赋值表达式的 pointsTo 行为,并确认该查询不再报告目标具有 Value 的调用。

由索引模型根据 Issue 内容生成。

描述

question

While trying to use the 'pointsTo' approach for some basic control-flow-based queries (please let me know if there's a better approach to find 'all statements reachable from a function entry-point'), I've noticed that currently, some calls are incorrectly picked up without any value to point to.

MWE:

import sys

def mwe_callable():
    print("Hello, World!") # works

def mwe_broken():
    if herp := sys.argv[1]:
        raise Exception("merp") # broken
    
    mwe_callable() # broken

def mwe_broken2():
    if herp := "derp":
        print("merp") # broken
    
    mwe_callable() # works

def mwe_works():
    if sys.argv[1] == "derp":
        raise Exception("merp") # works
    
    mwe_callable() # works

def mwe_works2():
    print("merp") # works
    mwe_callable() # works

Test query:

import python

from Function f, Call c, Expr e
where
  f.contains(c) and
  e = c.getFunc() and
  not exists(Value v | e.pointsTo() = v)
select f, c, e

Every call I've marked here as 'broken' is returned by the query as not having any Value to point to, whereas the other calls are correctly identified and associated with their target.

I am using:

  • CodeQL CLI 2.21.0
  • CodeQL VSCode extension 1.17.2
  • codeql/python-all@4.0.4
  • Python extractor 1.22.1
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 10 小时
30 天内合并 PR
134

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/codeql 的其他 Issue

查看 github/codeql 的全部 Issue

相似的 Issue

更多 DevTools Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。