github-vet / github-vet/rangeloop-pointer-findings
boz/circumspect: resolver/kube/service.go; 34 LoC
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- PR merge metrics
- PR metrics pending
Description
Found a possible issue in [boz/circumspect](https://www.github.com/boz/circumspect) at [resolver/kube/service.go](https://github.com/boz/circumspect/blob/c2f5324ad7d01012f6ea9e6a85b3b64be9cd97a0/resolver/kube/service.go#L311-L344)
Below is the message reported by the analyzer for this snippet of code. Beware that the analyzer only reports the first issue it finds, so please do not limit your consideration to the contents of the below message.
> function call at line 340 may store a reference to cs
[Click here to see the code in its original context.](https://github.com/boz/circumspect/blob/c2f5324ad7d01012f6ea9e6a85b3b64be9cd97a0/resolver/kube/service.go#L311-L344)
Click here to show the 34 line(s) of Go which triggered the analyzer.
```go
for _, cs := range pod.Status.ContainerStatuses {
// todo: check container state
if cs.Name == qp.containerName {
switch {
case cs.ContainerID == "":
// container not populated in kube yet.
log.Debug("empty container id")
return nil, false, nil
case cs.ContainerID != containerIdPrefix+qp.containerID:
log.
WithField("kube.container-id", cs.ContainerID).
WithField("docker.container-id", qp.containerID).
Warn("mismatched container id")
return nil, false, ErrInvalidContainerID
default:
log.
WithField("kube-ns", pod.Namespace).
WithField("kube-pod", pod.Name).
WithField("kube-container", cs.Name).
WithField("docker-container", cs.ContainerID).
Debug("container found")
return newProps(pod, &cs), true, nil
}
}
}
```
Click here to show extra information the analyzer produced.
```
The following graphviz dot graph describes paths through the callgraph that could lead to a function which writes a pointer argument:
digraph G {
"(newProps, 2)" -> {}
}
No path was found through the callgraph that could lead to a function which passes a pointer to third-party code.
```
Leave a reaction on this issue to contribute to the project by classifying this instance as a **Bug** :-1:, **Mitigated** :+1:, or **Desirable Behavior** :rocket:
See the descriptions of the classifications [here](https://github.com/github-vet/rangeclosure-findings#how-can-i-help) for more information.
commit ID: c2f5324ad7d01012f6ea9e6a85b3b64be9cd97a0
Contributor guide
No contributing guide indexed for this repository
Research direction
Read resolver/kube/service.go around lines 311-344, beginning with the range over pod.Status.ContainerStatuses and the call to newProps. Check the analyzer's concern about the reference to cs against the surrounding Kubernetes resolver behavior. When the finding is understood, classify it by reacting with Bug, Mitigated, or Desirable Behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, kubernetes
- Domain
- devops
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 35/100