github / github/codeql

[C++] Assigning to function pointer in a function appears to defeat dispatch analysis

Aberta
#18,103 2 comentários 0 reações 0 responsáveis Ver no GitHub
question
Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 15h
PRs com merge (30d)
141

Descrição

Assigning to a function pointer in a function appears to defeat the points-to analysis used to resolve the dispatch of function pointers.

In the following example I would have expected to see two flows from `source()` to `target()` but only the second one from the direct assignment of the function pointer is reported.

```cpp
int source()
{
return 2;
}

int a_function()
{
return source();
}

int target(int source)
{
return source;
}

void set(int (**ptr)(), int (*ptr2)())
{
*ptr = ptr2;
}

int main(int argv, char **argc)
{
int (*fptr)();

set(&fptr, a_function);

target(fptr()); // not detected as source

fptr = a_function;

target(fptr()); // detected

return 0;
}
```

This is the complete query

```ql
import cpp
import semmle.code.cpp.dataflow.new.TaintTracking

module SourceSinkCallConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
source.asExpr().(FunctionCall).getTarget().getName() = "source"
}

predicate isSink(DataFlow::Node sink) {
exists(Call call |
call.getTarget().getName() = "target" and
call.getArgument(0) = sink.asExpr()
)
}
}

module SourceSinkCallTaint = TaintTracking::Global;

from DataFlow::Node source, DataFlow::Node sink, int source_line, int sink_line
where
SourceSinkCallTaint::flow(source, sink) and
source_line = source.getLocation().getStartLine() and
sink_line = sink.getLocation().getStartLine()
select source, source_line, sink, sink_line

```

This is the output. I would have expected to also see a flow to line 28.

```
| source | source_line | sink | sink_line |
+----------------+-------------+--------------------+-----------+
| call to source | 9 | call to expression | 32 |
```

CodeQL version: 2.19.3

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Start by running the complete query from the issue against the supplied C++ example on CodeQL 2.19.3. Read the C++ data-flow and points-to behavior behind the imported TaintTracking library, then verify that the indirect assignment through set() is resolved. Done means the query reports the expected additional flow to line 28.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
cpp
Domínio
devtools
Tipo de issue
Bug
Dificuldade
4/5
Tempo estimado
3-5 dias
Status de atividade
Estagnada
Clareza
Razoavelmente clara
Facilidade para iniciantes
42/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.