github / github/codeql

Using "Value::named" search for call to "os.path.join" not working

オープン
#3,261 コメント 3 件 リアクション 0 件 担当者 0 名 GitHub で見る
Python question
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

CodeQL version 2.1.0
```
from rest_framework.viewsets import ModelViewSet
from rest_framework.exceptions import ValidationError
import os
from rest_framework.decorators import list_route

def func1():
pass

def preprocess(request):
pass

class TestViewSet(ModelViewSet):
base = "111111"
@list_route(methods=['post'])
def upload(self, request):
try:
var1 = func1()
except:
raise ValidationError({'message': [_('1,1')]})
if var1['1']:
raise ValidationError({'message': [_('1,1')]})

(upload_file, file_name) = preprocess(request)
path1 = base.RELATED_DIR['11111111']
if not os.path.exists(path1):
os.makedirs(path1)
path2 = os.path.join(path1, file_name)
```

Query:
```
import python
from ControlFlowNode c
where Value::named("os.path.join").getACall() = c
select c
```

Expect result:
Can find the call to "os.path.join" on the last line

Actual result:
Just show 2 call in the python lib

Is this a bug or am I doing this in the wrong way?

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。