github / github/codeql

False positive: Go x, _ := strconv.ParseUint(,, strconv.IntSize-1); int(x)

オープン
#14,733 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る
false-positive Go
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

**Description of the false positive**

If I'm not mistaken and making a terribly stupid mistake here I would expect that Go's `strconv.IntSize-1` should cover the positive range of an `int`, regardless of architecture integer size. The actual value range returned by `strconv.ParseUint` in an `uint64` should be correctly castable to an `int` without ambiguities.

Currently, CodeQL scanning reports "Incorrect conversion between integer types". Am I getting this one horribly wrong?

**Code samples or links to source code**

```go
fd, err := strconv.ParseUint(fdInfoEntry.Name(), 10, strconv.IntSize-1)
if err != nil {
continue
}
taptunFd, err := unix.PidfdGetfd(pidfd, int(fd), 0)
```

https://github.com/siemens/ghostwire/pull/29/checks?check_run_id=18520023133

Related: https://github.com/github/codeql/issues/9295 ... but it seems the PR addressing the "old" issue doesn't address this case too.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。