False positive - Unused static function
- Langage dominant
- CodeQL
- Étoiles
- 10.1k
- Forks
- 2.1k
- Merge moyen
- 2 j 15 h
- PR mergées (30 j)
- 141
Description
In a project using CodeQL scanning, all 4 "Unused static function" complaints look like false positives.
The easier two are:
https://github.com/andyhhp/xtf/security/code-scanning/51
https://github.com/andyhhp/xtf/security/code-scanning/52
Where the caller is the subsequent function.
Two others are also false positives, but the analysis might be suffering from weak functions.
https://github.com/andyhhp/xtf/security/code-scanning/47
https://github.com/andyhhp/xtf/security/code-scanning/48
In these two examples, there is a weak form of `arch_fmt_pointer()` which doesn't call `x86_decode_exinfo()` that could be interfering with analysis.
In reality, compilers are fairly hot on warnings about unused static functions,and this project is -Wall/-Werror on both GCC and Clang
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Start with the four linked code-scanning alerts (47, 48, 51, and 52) and trace the unused-static-function analysis that reports them. Compare the cases where the caller is the subsequent function with those involving the weak arch_fmt_pointer() form. Done means the analysis no longer reports these valid callers as unused while still detecting genuinely unused static functions.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- c
- Domaine
- devtools, security
- Type d'issue
- Bug
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- À l'abandon
- Clarté
- À clarifier
- Accessibilité débutants
- 25/100