github / github/codeql

C path matching issue

オープン
#20,882 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
acknowledged question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

C language code
```
#include
#include
#include
#include

char buf[32];

int main(int argc, char* argv[], char* envp[]){
if(argc<2){
printf("./fd [输入一个参数]\n");
return 0;
}

int fd = atoi( argv[1] ) - 0x1234;
int len = 0;

len = read(fd, buf, 32);

if(!strcmp("LETMEWIN\n", buf)){
printf("恭喜你!挑战成功!\n");
exit(0);
}

printf("程序结束\n");
return 0;
}
```

This is my rule.
```
/**
* @kind path-problem
* @problem.severity warning
* @id getenv-to-gethostbyname
*/
import cpp
import semmle.code.cpp.dataflow.new.DataFlow
import semmle.code.cpp.dataflow.ExternalFlow

module ReadConfig implements DataFlow::ConfigSig{
predicate isSource(DataFlow::Node source) {
exists(Parameter p, ArrayExpr ae |
p.getFunction().getName() = "main" and
ae.getArrayBase() = p.getAnAccess() and
source.asExpr() = ae
)
}

predicate isSink(DataFlow::Node sink) {
exists(FunctionCall fc |
fc.getTarget().getName() = "read" and
sink.asExpr() = fc.getArgument(0)
)
}

}

module ReadConfigFlow = DataFlow::Global;
import ReadConfigFlow::PathGraph

from ReadConfigFlow::PathNode source, ReadConfigFlow::PathNode sink
where ReadConfigFlow::flowPath(source, sink)
select sink.getNode(), source, sink, "read",
source, "input"
```

The source can match argv[1].

Image

The sink can also match the file descriptor (fd) of the read function.

Image

However, the rule as a whole fails to match the path.

Please help me.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with the supplied C example and the ReadConfig DataFlow configuration, comparing the argv[1] source with the read call's file-descriptor argument. Trace how the fd assignment and read argument are represented in the PathGraph, then determine why the individual matches do not produce a complete path. Done means documenting or reproducing the cause and identifying the expected matching behavior.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
c
領域
security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。