github-vet / github-vet/rangeloop-pointer-findings
rebujacker/SiestaTime: src/rebugo/tls/handshake_client.go; 35 LoC
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- PR merge metrics
- PR metrics pending
Description
Found a possible issue in [rebujacker/SiestaTime](https://www.github.com/rebujacker/SiestaTime) at [src/rebugo/tls/handshake_client.go](https://github.com/rebujacker/SiestaTime/blob/a2c99b97711969ab3900537e78649654e96167bd/src/rebugo/tls/handshake_client.go#L1159-L1193)
Below is the message reported by the analyzer for this snippet of code. Beware that the analyzer only reports the first issue it finds, so please do not limit your consideration to the contents of the below message.
>
[Click here to see the code in its original context.](https://github.com/rebujacker/SiestaTime/blob/a2c99b97711969ab3900537e78649654e96167bd/src/rebugo/tls/handshake_client.go#L1159-L1193)
Click here to show the 35 line(s) of Go which triggered the analyzer.
```go
for i, chain := range c.config.Certificates {
sigOK := false
for _, alg := range signatureSchemesForCertificate(c.vers, &chain) {
if isSupportedSignatureAlgorithm(alg, cri.SignatureSchemes) {
sigOK = true
break
}
}
if !sigOK {
continue
}
if len(cri.AcceptableCAs) == 0 {
return &chain, nil
}
for j, cert := range chain.Certificate {
x509Cert := chain.Leaf
// Parse the certificate if this isn't the leaf node, or if
// chain.Leaf was nil.
if j != 0 || x509Cert == nil {
var err error
if x509Cert, err = x509.ParseCertificate(cert); err != nil {
c.sendAlert(alertInternalError)
return nil, errors.New("tls: failed to parse configured certificate chain #" + strconv.Itoa(i) + ": " + err.Error())
}
}
for _, ca := range cri.AcceptableCAs {
if bytes.Equal(x509Cert.RawIssuer, ca) {
return &chain, nil
}
}
}
}
```
Click here to show extra information the analyzer produced.
```
No path was found through the callgraph that could lead to a function which writes a pointer argument.
No path was found through the callgraph that could lead to a function which passes a pointer to third-party code.
root signature {signatureSchemesForCertificate 2} was not found in the callgraph; reference was passed directly to third-party code
```
Leave a reaction on this issue to contribute to the project by classifying this instance as a **Bug** :-1:, **Mitigated** :+1:, or **Desirable Behavior** :rocket:
See the descriptions of the classifications [here](https://github.com/github-vet/rangeclosure-findings#how-can-i-help) for more information.
commit ID: a2c99b97711969ab3900537e78649654e96167bd
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.