github / github/codeql

[C++] Control Flow Influence not detected interprocedurally

未關閉
#18,100 5 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

The `controls` predicate from `GuardCondition` does not detect influence across function boundaries. Is this intended behavior?

Here is the code for my example. Influence from `condition` in line 23 is detected but not from line 14.

Similarly the influence on `call()` in line 30 is detected but not on line 8.

```cpp
#include

void call()
{
}

void call_wrapper()
{
call(); // not detected as controlled
}

void check_condition(bool condition)
{
if (condition) // not detected as controlling
{
throw std::exception();
}
}

void my_fn(bool outer, bool condition)
{

if (condition) // detected as controlling
{
throw std::exception();
}

check_condition(condition);

call(); // detected as controlled

call_wrapper();
}
```

```ql
import cpp
import semmle.code.cpp.controlflow.IRGuards

from Variable v, VariableAccess va, GuardCondition cond, Call c, int line
where
c.getTarget().getName() = "call" and
va.getTarget() = v and
v.getName() = "condition" and
cond.getAChild*() = va and
cond.controls(c.getBasicBlock(), _) and
line = va.getLocation().getStartLine()
select v, va, cond, c, line

```

```
| v | va | cond | c | line |
+-----------+-----------+-----------+--------------+------+
| condition | condition | condition | call to call | 23 |
```

CodeQL version: 2.19.3

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。