github / github/codeql

Clarify that CodeQL `int` `bitShiftLeft`, `bitShiftRight` and `bitShiftRightSigned` only use lowest 5 bits of argument (or adjust behavior)

未关闭
#13,064 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

It appears the CodeQL `int` predicates `bitShiftLeft`, `bitShiftRight` and `bitShiftRightSigned` only use the lowest 5 bits of argument. Most likely this is due to CodeQL CLI being written in Java and Java having the [same quirk](https://docs.oracle.com/javase/specs/jls/se17/html/jls-15.html#jls-15.19).

This can be seen with this query:
```codeql
select
1.bitShiftLeft(33) as l, // Expected 0
2.bitShiftRight(33) as r, // Expected 0
2.bitShiftRightSigned(33) as sr // Expected 0
```

The results are:
| l | r | sr |
| -- | -- | -- |
| 2 | 1 | 1 |

(Tested with CodeQL CLI 2.13.1)

If this behavior is intended, please mention it in the documentation of these predicates (and probably the [QL language specification](https://codeql.github.com/docs/ql-language-reference/ql-language-specification/#built-ins-for-int)), or alternatively adjust the behavior of these predicates because the current behavior is not very intuitive.

Similarly it would also be good to define how negative arguments are handled. Currently due to using only the lowest 5 bits a shift distance of -2147483647 seems to be treated as 1, which is not intuitive. Maybe for negative shift distances there should not be any result.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。