github / github/codeql

Wrong global dataflow analyse in C

Aperta
#10,571 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub
question
Lingua principale
CodeQL
Stelle
10.1k
Fork
2.1k
Merge medio
2g 15h
PR unite (30g)
141

Descrizione

Hi! I write a small C code, and I want to find if there is a dataflow from `malloc` to `free`.And `malloc` and` free` in different functions.
But I got a wrong result. The result shows that only` malloc` in `test5` has related dataflow, but I think `malloc` in `test4` should in the result...I don't know if my ql code is wrong.
C code :
```
typedef struct{
int a;
char* b;
}test;

typedef struct{
int a;
test* b;
}test_big;

void test4(test_big* p)
{
test* a = malloc(200);
p->b = a;
a->b = malloc(2);
return;
}
void test5(test_big* p)
{
test* a;

a->b = malloc(2);
p->b = a;
return;
}
int main(void)
{
char* a;
test_big* b;
test4(b);
free(b->b->b);
test5(b);
free(b->b->b);
}
```
QL:
```
class TestConfiguration extends DataFlow::Configuration {
TestConfiguration() { this = "TestConfiguration" }

override predicate isSource(DataFlow::Node source) {
exists(FunctionCall fc |
fc.getTarget().hasName("malloc")
and (fc = source.asExpr())
)
}
override predicate isSink(DataFlow::Node sink) {
// sink.asExpr()
exists(FunctionCall fc |
fc.getTarget().hasName("free")
and fc.getAnArgument() = sink.asExpr()
)
}
}

from FunctionCall malloc, TestConfiguration cfg, DataFlow::Node source
where malloc.getTarget().hasName("malloc")
and source.asExpr() = malloc
and exists(Expr expr |
not expr.getEnclosingFunction() = malloc.getEnclosingFunction()
and cfg.hasFlow(source, DataFlow::exprNode(expr)))
```

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.