github / github/codeql

Using "Value::named" search for call to "os.path.join" not working

未關閉
#3,261 3 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
Python question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

CodeQL version 2.1.0
```
from rest_framework.viewsets import ModelViewSet
from rest_framework.exceptions import ValidationError
import os
from rest_framework.decorators import list_route

def func1():
pass

def preprocess(request):
pass

class TestViewSet(ModelViewSet):
base = "111111"
@list_route(methods=['post'])
def upload(self, request):
try:
var1 = func1()
except:
raise ValidationError({'message': [_('1,1')]})
if var1['1']:
raise ValidationError({'message': [_('1,1')]})

(upload_file, file_name) = preprocess(request)
path1 = base.RELATED_DIR['11111111']
if not os.path.exists(path1):
os.makedirs(path1)
path2 = os.path.join(path1, file_name)
```

Query:
```
import python
from ControlFlowNode c
where Value::named("os.path.join").getACall() = c
select c
```

Expect result:
Can find the call to "os.path.join" on the last line

Actual result:
Just show 2 call in the python lib

Is this a bug or am I doing this in the wrong way?

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。