github / github/codeql

Weird(?) behavior of `Expr.getType`

Offen
#4,180 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
C++ enhancement
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

Hello,
I'm not sure if this place is relevant to post this topic(I'm sorry if not), but
I can't see what is going on with the below snippet:

```codeql
import cpp

class Set1 extends FunctionCall {
Set1() { this.getNumberOfArguments() >= 1 and exists(Expr e | 1 = 1 | this.getArgument(0) = e) }
}
class Set2 extends FunctionCall {
Set2() { this.getNumberOfArguments() >= 1 and exists(Type t | 1 = 1 | this.getArgument(0).getType() = t) }
}
from FunctionCall fc
where fc instanceof Set1 and (not fc instanceof Set2)
select fc
```

I was writing some simple query, which checks the type of the arguments of a certain sort of function calls.
But I realized that for some reason calling `getType()` narrows the result, regardless of any further operations.
My understanding is that `FunctionCall.getArgument(0)` always returns `Expr` as long as the number of arguments is greater than 0, and that `Expr.getType()` always returns some meaningful instance of `Type`.
Is this assumption wrong? Or is this a bug or something?

I tested the snippet in some projects including [flatbuffers](https://lgtm.com/projects/g/google/flatbuffers/) and [glibc](https://lgtm.com/projects/g/bminor/glibc/). In both, we can see that there are some function calls satisfying the condition(they are mostly calls of struct operator and __builtin_function, but I saw other types of function calls in a confidential project).

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.