github / github/codeql

False positive: Go x, _ := strconv.ParseUint(,, strconv.IntSize-1); int(x)

Aberta
#14,733 3 comentários 0 reações 0 responsáveis Ver no GitHub
false-positive Go
Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 15h
PRs com merge (30d)
141

Descrição

**Description of the false positive**

If I'm not mistaken and making a terribly stupid mistake here I would expect that Go's `strconv.IntSize-1` should cover the positive range of an `int`, regardless of architecture integer size. The actual value range returned by `strconv.ParseUint` in an `uint64` should be correctly castable to an `int` without ambiguities.

Currently, CodeQL scanning reports "Incorrect conversion between integer types". Am I getting this one horribly wrong?

**Code samples or links to source code**

```go
fd, err := strconv.ParseUint(fdInfoEntry.Name(), 10, strconv.IntSize-1)
if err != nil {
continue
}
taptunFd, err := unix.PidfdGetfd(pidfd, int(fd), 0)
```

https://github.com/siemens/ghostwire/pull/29/checks?check_run_id=18520023133

Related: https://github.com/github/codeql/issues/9295 ... but it seems the PR addressing the "old" issue doesn't address this case too.

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Start with the CodeQL query that reports "Incorrect conversion between integer types" for the Go sample, then compare its behavior with related issue #9295. Reproduce the alert using the linked ghostwire pull request and determine whether this conversion should remain flagged; done means the query handles this case consistently without losing relevant findings.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
go
Domínio
security
Tipo de issue
Bug
Dificuldade
4/5
Tempo estimado
3-5 dias
Status de atividade
Estagnada
Clareza
Precisa de esclarecimento
Facilidade para iniciantes
35/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.