github / github/codeql

[CPP][Questions]No effective API to qeury macro used in function parameter declaration

Open
#8,497 4 comments 0 reactions 0 assignees View on GitHub
C++ question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

Hello all,

Recently I'm interested in writing queries to detect common vulnerability pattern specific for Linux kernel codebase. I find that `__user` marco is used to indicate parameter is user mode pointer, for example
```cpp
#define __user //empty macro body

static int sg_scsi_ioctl(struct request_queue *q, fmode_t mode,
struct scsi_ioctl_command __user *sic) //sic is a user mode pointer
```

I want to write a query to get all user mode pointer defined in function parameter declaration, I tried to find avaliable API defined in `Marco/MacroAccess/MarcoInovation/Function/Function/FunctionDeclarationEntry/ParameterDeclarationEntry`, but I can not find one can be used for my purpose.

I have no way but to query macro used in function parameter declaration by combining `MacroAccess` and `Location`, the following code may be work, but it prone to be false positive and ugly:(

```ql
class UserParameterDeclarationEntry extends ParameterDeclarationEntry{
UserParameterDeclarationEntry(){
exists(MacroAccess m|
m.getMacroName() = "__user"
and m.getFile() = this.getFile()
and m.getLocation().getEndLine() = this.getLocation().getEndLine()
)
}
}
```

So I hope you guys can be kind enougth to help me find a more effective way to query specific macro in function parameter declaration, thank you:)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.