github / github/codeql

[C++] Fails to detect control flow influence of nested “if”

Open
#18,099 5 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

The `controls` predicate in `GuardCondition` fails to detect a control flow influence from a nested `if`. In the following example the influence from `condition` to `call()` is only revealed in the first `if`, but not in the second.

```cpp
#include

void call()
{
}

void my_fn(bool outer, bool condition)
{

if (condition) // detected
{
throw std::exception();
}

if (outer)
{
if (condition) // not detected
{
throw std::exception();
}
}

call();
}
```

Query I tried:

```ql
import cpp
import semmle.code.cpp.controlflow.IRGuards

from Variable v, VariableAccess va, GuardCondition cond, Call c, int line
where
c.getTarget().getName() = "call" and
va.getTarget() = v and
v.getName() = "condition" and
cond.getAChild*() = va and
cond.controls(c.getBasicBlock(), _) and
line = va.getLocation().getStartLine()
select v, va, cond, c, line
```

Output I received:

```
| v | va | cond | c | line |
+-----------+-----------+-----------+--------------+------+
| condition | condition | condition | call to call | 10 |
```

I expected to also see an influence from line 17, but none is being found.

CodeQL version: 2.19.3

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the supplied C++ example with the query importing semmle.code.cpp.controlflow.IRGuards, then read GuardCondition and its controls predicate. The work is complete when the nested condition access on line 17 is reported as influencing call(), alongside the first condition.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
compilers, devtools
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.