github / github/codeql

Wrong global dataflow analyse in C

Offen
#10,571 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

Hi! I write a small C code, and I want to find if there is a dataflow from `malloc` to `free`.And `malloc` and` free` in different functions.
But I got a wrong result. The result shows that only` malloc` in `test5` has related dataflow, but I think `malloc` in `test4` should in the result...I don't know if my ql code is wrong.
C code :
```
typedef struct{
int a;
char* b;
}test;

typedef struct{
int a;
test* b;
}test_big;

void test4(test_big* p)
{
test* a = malloc(200);
p->b = a;
a->b = malloc(2);
return;
}
void test5(test_big* p)
{
test* a;

a->b = malloc(2);
p->b = a;
return;
}
int main(void)
{
char* a;
test_big* b;
test4(b);
free(b->b->b);
test5(b);
free(b->b->b);
}
```
QL:
```
class TestConfiguration extends DataFlow::Configuration {
TestConfiguration() { this = "TestConfiguration" }

override predicate isSource(DataFlow::Node source) {
exists(FunctionCall fc |
fc.getTarget().hasName("malloc")
and (fc = source.asExpr())
)
}
override predicate isSink(DataFlow::Node sink) {
// sink.asExpr()
exists(FunctionCall fc |
fc.getTarget().hasName("free")
and fc.getAnArgument() = sink.asExpr()
)
}
}

from FunctionCall malloc, TestConfiguration cfg, DataFlow::Node source
where malloc.getTarget().hasName("malloc")
and source.asExpr() = malloc
and exists(Expr expr |
not expr.getEnclosingFunction() = malloc.getEnclosingFunction()
and cfg.hasFlow(source, DataFlow::exprNode(expr)))
```

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.