github / github/codeql

False positive: Go x, _ := strconv.ParseUint(,, strconv.IntSize-1); int(x)

Offen
#14,733 3 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
false-positive Go
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

**Description of the false positive**

If I'm not mistaken and making a terribly stupid mistake here I would expect that Go's `strconv.IntSize-1` should cover the positive range of an `int`, regardless of architecture integer size. The actual value range returned by `strconv.ParseUint` in an `uint64` should be correctly castable to an `int` without ambiguities.

Currently, CodeQL scanning reports "Incorrect conversion between integer types". Am I getting this one horribly wrong?

**Code samples or links to source code**

```go
fd, err := strconv.ParseUint(fdInfoEntry.Name(), 10, strconv.IntSize-1)
if err != nil {
continue
}
taptunFd, err := unix.PidfdGetfd(pidfd, int(fd), 0)
```

https://github.com/siemens/ghostwire/pull/29/checks?check_run_id=18520023133

Related: https://github.com/github/codeql/issues/9295 ... but it seems the PR addressing the "old" issue doesn't address this case too.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.