github / github/codeql

Wrong global dataflow analyse in C

未关闭
#10,571 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

Hi! I write a small C code, and I want to find if there is a dataflow from `malloc` to `free`.And `malloc` and` free` in different functions.
But I got a wrong result. The result shows that only` malloc` in `test5` has related dataflow, but I think `malloc` in `test4` should in the result...I don't know if my ql code is wrong.
C code :
```
typedef struct{
int a;
char* b;
}test;

typedef struct{
int a;
test* b;
}test_big;

void test4(test_big* p)
{
test* a = malloc(200);
p->b = a;
a->b = malloc(2);
return;
}
void test5(test_big* p)
{
test* a;

a->b = malloc(2);
p->b = a;
return;
}
int main(void)
{
char* a;
test_big* b;
test4(b);
free(b->b->b);
test5(b);
free(b->b->b);
}
```
QL:
```
class TestConfiguration extends DataFlow::Configuration {
TestConfiguration() { this = "TestConfiguration" }

override predicate isSource(DataFlow::Node source) {
exists(FunctionCall fc |
fc.getTarget().hasName("malloc")
and (fc = source.asExpr())
)
}
override predicate isSink(DataFlow::Node sink) {
// sink.asExpr()
exists(FunctionCall fc |
fc.getTarget().hasName("free")
and fc.getAnArgument() = sink.asExpr()
)
}
}

from FunctionCall malloc, TestConfiguration cfg, DataFlow::Node source
where malloc.getTarget().hasName("malloc")
and source.asExpr() = malloc
and exists(Expr expr |
not expr.getEnclosingFunction() = malloc.getEnclosingFunction()
and cfg.hasFlow(source, DataFlow::exprNode(expr)))
```

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。