github / github/codeql

Clarify that CodeQL `int` `bitShiftLeft`, `bitShiftRight` and `bitShiftRightSigned` only use lowest 5 bits of argument (or adjust behavior)

Đang mở
#13,064 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
question
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

It appears the CodeQL `int` predicates `bitShiftLeft`, `bitShiftRight` and `bitShiftRightSigned` only use the lowest 5 bits of argument. Most likely this is due to CodeQL CLI being written in Java and Java having the [same quirk](https://docs.oracle.com/javase/specs/jls/se17/html/jls-15.html#jls-15.19).

This can be seen with this query:
```codeql
select
1.bitShiftLeft(33) as l, // Expected 0
2.bitShiftRight(33) as r, // Expected 0
2.bitShiftRightSigned(33) as sr // Expected 0
```

The results are:
| l | r | sr |
| -- | -- | -- |
| 2 | 1 | 1 |

(Tested with CodeQL CLI 2.13.1)

If this behavior is intended, please mention it in the documentation of these predicates (and probably the [QL language specification](https://codeql.github.com/docs/ql-language-reference/ql-language-specification/#built-ins-for-int)), or alternatively adjust the behavior of these predicates because the current behavior is not very intuitive.

Similarly it would also be good to define how negative arguments are handled. Currently due to using only the lowest 5 bits a shift distance of -2147483647 seems to be treated as 1, which is not intuitive. Maybe for negative shift distances there should not be any result.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.