github / github/codeql

[C++] Control Flow Influence not detected interprocedurally

Ouverte
#18,100 5 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
question
Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 15 h
PR mergées (30 j)
141

Description

The `controls` predicate from `GuardCondition` does not detect influence across function boundaries. Is this intended behavior?

Here is the code for my example. Influence from `condition` in line 23 is detected but not from line 14.

Similarly the influence on `call()` in line 30 is detected but not on line 8.

```cpp
#include

void call()
{
}

void call_wrapper()
{
call(); // not detected as controlled
}

void check_condition(bool condition)
{
if (condition) // not detected as controlling
{
throw std::exception();
}
}

void my_fn(bool outer, bool condition)
{

if (condition) // detected as controlling
{
throw std::exception();
}

check_condition(condition);

call(); // detected as controlled

call_wrapper();
}
```

```ql
import cpp
import semmle.code.cpp.controlflow.IRGuards

from Variable v, VariableAccess va, GuardCondition cond, Call c, int line
where
c.getTarget().getName() = "call" and
va.getTarget() = v and
v.getName() = "condition" and
cond.getAChild*() = va and
cond.controls(c.getBasicBlock(), _) and
line = va.getLocation().getStartLine()
select v, va, cond, c, line

```

```
| v | va | cond | c | line |
+-----------+-----------+-----------+--------------+------+
| condition | condition | condition | call to call | 23 |
```

CodeQL version: 2.19.3

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Reproduce the example query and inspect semmle.code.cpp.controlflow.IRGuards, especially GuardCondition.controls and its interprocedural behavior. Compare the reported results at the marked call and condition lines, then check existing control-flow tests. Done means the intended behavior is established and covered by an appropriate regression test or documented as unsupported.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
cpp
Domaine
devtools
Type d'issue
Bug
Difficulté
4/5
Temps estimé
3-5 jours
Activité
À l'abandon
Clarté
Plutôt claire
Accessibilité débutants
35/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.