False positive "Comparison result is always the same" because of incorrect sizeof evaluation
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the false positive**
CodeQL complains "Comparison is always true because i <= 1. "
However, it is really a loop over 4 elements.
I suspect the problem is that
```c
struct foo
{
...
unsigned long (*fnptr_array[4])(void);
...
};
```
describes an array of 4 function pointers, but that CodeQL isn't evaluating `sizeof` correctly on the type.
**Code samples or links to source code**
https://github.com/andyhhp/xtf/blob/f503efe8e5cf8858ec0704f1aaa82d0bf50891a5/tests/swint-emulation/main.c#L162-L162
but I've done a simpler example in https://godbolt.org/z/9fGr51r68 if that helps
**URL to the alert on GitHub code scanning (optional)**
https://github.com/andyhhp/xtf/security/code-scanning/55
貢獻指南
評估
這個 Issue 還沒有評估資料。