github / github/codeql

CPP: Flow Into Barrier Guards

未關閉
#10,011 15 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

I'm looking for general assistance on how to properly use codeql with barrier guards when the guard condition may not be computed in the guard itself, but instead also data traces into a guard:

Consider these two cases, where `use(x)` is a sink, but if it is guarded by `MyGuard(x)` it is considered safe. The first case is the easy case where BarrierGuard (or SanitizerGuard) can be used fairly easily, and the latter case seems to require yet another dataflow:

```
//Easy case
if(MyGuard(x))
use(x);

//harder case
res = MyGuard(x)
if(res)
use(x);
```

For the latter/harder case, what is the CodeQL paradigm to associate the guard to `x` such that I know use(x) is safe? Seems to me, out of the box, there is no flow from `x` to res. I could add an additional step, in a dataflow/taint analysis, but that would still not let me define barrier guard check conditions to associate that value with the originating variable. Perhaps there is a way to pass around misc. metadata too that will feed into a BarrierGuard check in these cases?

貢獻指南

開啟貢獻指南

研究方向

Start with the CodeQL BarrierGuard and SanitizerGuard concepts named in the issue, then compare them with the two guard examples in the report. Determine whether a computed guard result can be associated with the original value through dataflow or metadata, and document the supported pattern or limitation as the outcome.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
cpp
領域
security
Issue 類型
文件
難度
5/5
預估耗時
一週以上
活躍度
停滯
描述清晰度
需要釐清
新手友好度
20/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。