How can I pick out "Dubious Null Check" by both the caller and the called function (not what DubiousNullCheck.ql means to)?
- Dominant language
- CodeQL
- Stars
- 10.1k
- Forks
- 2.1k
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 141
Description
For example, null check for both the argument `pi` and the parameter `p`:
```cpp
#include
int func(int *p) {
if (p = NULL) return 0;
return *p;
}
int main() {
int i = 9, *pi = &i;
//if (pi != NULL)
printf("%d\n", func(pi));
}
```
I've tried to write some ql, as below, but failed to complete it.
What troubles me the most now is: how to connect the parameter with the argument?
```codeql
import cpp
VariableAccess modify(LocalVariable variable) {
result = variable.getAnAccess() and
result.isModified()
}
from LocalVariable variable, FunctionCall call
where
variable.getType() instanceof PointerType
and exists(call.getTarget().getAParameter())
and call.getEnclosingFunction() = variable.getFunction()
and variable.getAnAccess().getLocation().getStartLine() = call.getLocation().getStartLine()
and not modify(variable).getLocation().getStartLine() = call.getLocation().getStartLine()
and not (call.getTarget().isMember() and call.getTarget().getDeclaringType() = variable.getType().stripType())
select variable, call
```
Contributor guide
Research direction
Start with the provided C++ example and the DubiousNullCheck.ql query referenced in the title. Trace the FunctionCall, its target parameter, and the argument access in the shown CodeQL code. Done means the query can identify the relevant null checks at both the caller argument and called-function parameter without relying on undocumented assumptions.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- devtools, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100