False positive: Go x, _ := strconv.ParseUint(,, strconv.IntSize-1); int(x)
- Linguagem predominante
- CodeQL
- Estrelas
- 10.1k
- Forks
- 2.1k
- Merge médio
- 2d 15h
- PRs com merge (30d)
- 141
Descrição
**Description of the false positive**
If I'm not mistaken and making a terribly stupid mistake here I would expect that Go's `strconv.IntSize-1` should cover the positive range of an `int`, regardless of architecture integer size. The actual value range returned by `strconv.ParseUint` in an `uint64` should be correctly castable to an `int` without ambiguities.
Currently, CodeQL scanning reports "Incorrect conversion between integer types". Am I getting this one horribly wrong?
**Code samples or links to source code**
```go
fd, err := strconv.ParseUint(fdInfoEntry.Name(), 10, strconv.IntSize-1)
if err != nil {
continue
}
taptunFd, err := unix.PidfdGetfd(pidfd, int(fd), 0)
```
https://github.com/siemens/ghostwire/pull/29/checks?check_run_id=18520023133
Related: https://github.com/github/codeql/issues/9295 ... but it seems the PR addressing the "old" issue doesn't address this case too.
Guia de contribuição
Direção de pesquisa
Start with the CodeQL query that reports "Incorrect conversion between integer types" for the Go sample, then compare its behavior with related issue #9295. Reproduce the alert using the linked ghostwire pull request and determine whether this conversion should remain flagged; done means the query handles this case consistently without losing relevant findings.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- go
- Domínio
- security
- Tipo de issue
- Bug
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Status de atividade
- Estagnada
- Clareza
- Precisa de esclarecimento
- Facilidade para iniciantes
- 35/100