github / github/codeql

Python: Call analysis fails in some scenarios

未關閉
#19,288 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

While trying to use the 'pointsTo' approach for some basic control-flow-based queries (please let me know if there's a better approach to find 'all statements reachable from a function entry-point'), I've noticed that currently, some calls are incorrectly picked up without any value to point to.

MWE:
```python
import sys

def mwe_callable():
print("Hello, World!") # works

def mwe_broken():
if herp := sys.argv[1]:
raise Exception("merp") # broken

mwe_callable() # broken

def mwe_broken2():
if herp := "derp":
print("merp") # broken

mwe_callable() # works

def mwe_works():
if sys.argv[1] == "derp":
raise Exception("merp") # works

mwe_callable() # works

def mwe_works2():
print("merp") # works
mwe_callable() # works
```

Test query:
```codeql
import python

from Function f, Call c, Expr e
where
f.contains(c) and
e = c.getFunc() and
not exists(Value v | e.pointsTo() = v)
select f, c, e
```

Every call I've marked here as 'broken' is returned by the query as not having any Value to point to, whereas the other calls are correctly identified and associated with their target.

I am using:
- CodeQL CLI 2.21.0
- CodeQL VSCode extension 1.17.2
- codeql/python-all@4.0.4
- Python extractor 1.22.1

貢獻指南

開啟貢獻指南

研究方向

Start by running the supplied CodeQL query against the minimal Python example and compare the calls marked as working or broken. Review the Python extractor and pointsTo behavior for assignment expressions and confirm that the query no longer reports calls whose targets have a Value.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
python
領域
devtools
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。