github / github/codeql

Weird(?) behavior of `Expr.getType`

Aberta
#4,180 1 comentário 0 reações 0 responsáveis Ver no GitHub
C++ enhancement
Linguagem predominante
CodeQL
Estrelas
10.1k
Forks
2.1k
Merge médio
2d 15h
PRs com merge (30d)
141

Descrição

Hello,
I'm not sure if this place is relevant to post this topic(I'm sorry if not), but
I can't see what is going on with the below snippet:

```codeql
import cpp

class Set1 extends FunctionCall {
Set1() { this.getNumberOfArguments() >= 1 and exists(Expr e | 1 = 1 | this.getArgument(0) = e) }
}
class Set2 extends FunctionCall {
Set2() { this.getNumberOfArguments() >= 1 and exists(Type t | 1 = 1 | this.getArgument(0).getType() = t) }
}
from FunctionCall fc
where fc instanceof Set1 and (not fc instanceof Set2)
select fc
```

I was writing some simple query, which checks the type of the arguments of a certain sort of function calls.
But I realized that for some reason calling `getType()` narrows the result, regardless of any further operations.
My understanding is that `FunctionCall.getArgument(0)` always returns `Expr` as long as the number of arguments is greater than 0, and that `Expr.getType()` always returns some meaningful instance of `Type`.
Is this assumption wrong? Or is this a bug or something?

I tested the snippet in some projects including [flatbuffers](https://lgtm.com/projects/g/google/flatbuffers/) and [glibc](https://lgtm.com/projects/g/bminor/glibc/). In both, we can see that there are some function calls satisfying the condition(they are mostly calls of struct operator and __builtin_function, but I saw other types of function calls in a confidential project).

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.