github-vet / github-vet/rangeloop-pointer-findings

openeuler-mirror/cve-manager: taskhandler/cve.go; 25 LoC

Open
#18,021 0 comments 0 reactions 0 assignees View on GitHub
fresh small
Dominant language
No language data
Stars
0
Forks
0
PR merge metrics
PR metrics pending

Description

Found a possible issue in [openeuler-mirror/cve-manager](https://www.github.com/openeuler-mirror/cve-manager) at [taskhandler/cve.go](https://github.com/openeuler-mirror/cve-manager/blob/7fc60d65bb2c999ed3658c526614a8836e3862d7/taskhandler/cve.go#L1746-L1770)

Below is the message reported by the analyzer for this snippet of code. Beware that the analyzer only reports the first issue it finds, so please do not limit your consideration to the contents of the below message.

> range-loop variable cveOrg used in defer or goroutine at line 1766

[Click here to see the code in its original context.](https://github.com/openeuler-mirror/cve-manager/blob/7fc60d65bb2c999ed3658c526614a8836e3862d7/taskhandler/cve.go#L1746-L1770)

Click here to show the 25 line(s) of Go which triggered the analyzer.

```go
for i, cveOrg := range gs {
count = count + 1
logs.Info("当前正常解析第: ", count, "条数据,i:", i, ", cvenum: ", cveOrg.IssueId)
// add mutex
lockOk := models.LockUpdateCveIssueStatus(15, cveOrg.Id)
if !lockOk {
logs.Error("Data is being processed, id: ", cveOrg.Id, ",cveOrg: ", cveOrg)
ch <- i
continue
}
if cveOrg.CveNumber == "" || len(cveOrg.CveNumber) == 0 {
logs.Error("数据异常, 不处理, cveData: ", cveOrg)
models.UpdateCveIssueStatusById(3, cveOrg.Id)
ch <- i
continue
}
go func(idx int, cveData models.GiteOriginIssue) {
ok, err := GenCveVulerByIssue(cveData, cveRef, openeulernum, owner)
if !ok {
logs.Error("GenCveVulerByIssue, cveData: ", cveData, "处理失败, err: ", err)
models.UpdateCveIssueStatusById(3, cveOrg.Id)
}
ch <- idx
}(i, cveOrg)
}

```

Leave a reaction on this issue to contribute to the project by classifying this instance as a **Bug** :-1:, **Mitigated** :+1:, or **Desirable Behavior** :rocket:
See the descriptions of the classifications [here](https://github.com/github-vet/rangeclosure-findings#how-can-i-help) for more information.

commit ID: 7fc60d65bb2c999ed3658c526614a8836e3862d7

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with taskhandler/cve.go lines 1746-1770 at commit 7fc60d65bb2c999ed3658c526614a8836e3862d7, then inspect the goroutine's error path and GenCveVulerByIssue call. Confirm whether the analyzer finding affects behavior; done means the finding is resolved or explicitly classified with supporting evidence.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
backend
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
50/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.