False negative: DoubleCheckedLocking.ql cannot detect scenarios with ternary expressions.
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 141
Mô tả
**Version**
codeql 2.23.9
**Description of the issue**
When I detect the code like this using java/Likely Bugs/Concurrency/DoubleCheckedLocking.ql, the problem is reported normally:
```java
public class PosCase1 {
private Object instance; // Non-volatile field
public Object getInstance() {
if (instance == null) { // First null check
synchronized (this) { // [REPORTED LINE]
if (instance == null) { // Second null check inside synchronized block
instance = new Object(); // Initialization
}
}
}
return instance; // Return after double-checked locking
}
}
```
However, when ternary expressions are introduced into the code, DoubleCheckedLocking.ql fails to detect the problem:
```java
public class PosCase1_Var1 {
private Object instance; // Non-volatile field
public Object getInstance() {
// Use ternary for outer check, but preserve unsafe pattern
return (instance != null) ? instance : createInstance();
}
private Object createInstance() {
synchronized (this) {
if (instance == null) {
instance = new Object();
}
return instance;
}
}
}
```
These two code snippets are semantically identical, only using a ternary expression with some transformations, which is why DoubleCheckedLocking.ql cannot detect the problem.
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu với java/Likely Bugs/Concurrency/DoubleCheckedLocking.ql và tái hiện hai đoạn mã Java từ issue để so sánh kết quả truy vấn. Hoàn thành khi truy vấn báo cáo kịch bản double-checked locking không an toàn dựa trên toán tử ternary, đồng thời tiếp tục báo cáo mẫu trực tiếp hiện có.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- java
- Lĩnh vực
- devtools, security
- Loại issue
- Lỗi
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 38/100