github / github/codeql

False positive - go/allocation-size-overflow

Đang mở
#16,368 2 bình luận 0 reaction 0 người được giao Xem trên GitHub
false-positive
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

**Description of the false positive**

This rule fires when you make a slice from the length of another slice and add a small constant size to it. It's literally impossible to overflow MaxInt on a 64 bit machine in today's world in this case.

**Code samples or links to source code**
```go
// simplified for this example
func extend(input []byte) []byte {
return make([]byte, len(input)+1)
}
```

** More Discussion **

In order for this to overflow, the input slice would need to be of size MaxInt. That's approximately 9 million terabytes if we're talking []byte on a 64 bit machine. The largest machine on azure right now has 12 TB of RAM. Even if we assume RAM size doubles every year, no machine will have 9 million terabytes of RAM for at least 20 years. So, you can't have a slice of anything except an empty struct that is anywhere near MaxInt length.

Until that time, it's literally impossible to have a slice of bytes with a length that is MaxInt-1 on a 64 bit machine. You'd run out of memory loooong before you had to worry about overflowing the int in the `make()` call.

Is there a way this check could be changed so that it won't trigger if you're getting the length off some other slice? Or are we worried about 32bit architectures, because that does not seem like something we should worry about at GitHub.

I don't really know much about how CodeQL works or what it can infer, but I'm open to other ways to avoid this check.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Bắt đầu bằng cách xác định truy vấn go/allocation-size-overflow và xem xét cách truy vấn này xử lý len(input)+1 trong ví dụ Go được báo cáo. Xác định xem bước kiểm tra có thể tính đến độ dài của một slice trước khi báo cáo trường hợp này hay không, đồng thời vẫn duy trì phạm vi bao phủ cho các rủi ro overflow thực sự. Hoàn thành có nghĩa là false positive đã được xử lý và hành vi của rule được bao phủ bởi phần xác thực truy vấn liên quan.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
go
Lĩnh vực
devtools, security
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.