github / github/codeql

False positive - go/allocation-size-overflow

Aberta
#16,368 2 comentários 0 reações 0 responsáveis Ver no GitHub
false-positive
Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 15h
PRs com merge (30d)
141

Descrição

**Description of the false positive**

This rule fires when you make a slice from the length of another slice and add a small constant size to it. It's literally impossible to overflow MaxInt on a 64 bit machine in today's world in this case.

**Code samples or links to source code**
```go
// simplified for this example
func extend(input []byte) []byte {
return make([]byte, len(input)+1)
}
```

** More Discussion **

In order for this to overflow, the input slice would need to be of size MaxInt. That's approximately 9 million terabytes if we're talking []byte on a 64 bit machine. The largest machine on azure right now has 12 TB of RAM. Even if we assume RAM size doubles every year, no machine will have 9 million terabytes of RAM for at least 20 years. So, you can't have a slice of anything except an empty struct that is anywhere near MaxInt length.

Until that time, it's literally impossible to have a slice of bytes with a length that is MaxInt-1 on a 64 bit machine. You'd run out of memory loooong before you had to worry about overflowing the int in the `make()` call.

Is there a way this check could be changed so that it won't trigger if you're getting the length off some other slice? Or are we worried about 32bit architectures, because that does not seem like something we should worry about at GitHub.

I don't really know much about how CodeQL works or what it can infer, but I'm open to other ways to avoid this check.

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Start by locating the go/allocation-size-overflow query and reviewing how it handles len(input)+1 in the reported Go example. Determine whether the check can account for a slice length before reporting this case, while preserving coverage for genuine overflow risks. Done means the false positive is addressed and the rule's behavior is covered by its relevant query validation.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
go
Domínio
devtools, security
Tipo de issue
Bug
Dificuldade
4/5
Tempo estimado
3-5 dias
Status de atividade
Estagnada
Clareza
Razoavelmente clara
Facilidade para iniciantes
35/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.