github / github/codeql

[CPP][Questions]No effective API to qeury macro used in function parameter declaration

Aperta
#8,497 4 commenti 0 reazioni 0 assegnatari Vedi su GitHub
C++ question
Lingua principale
CodeQL
Stelle
10.1k
Fork
2.1k
Merge medio
2g 15h
PR unite (30g)
141

Descrizione

Hello all,

Recently I'm interested in writing queries to detect common vulnerability pattern specific for Linux kernel codebase. I find that `__user` marco is used to indicate parameter is user mode pointer, for example
```cpp
#define __user //empty macro body

static int sg_scsi_ioctl(struct request_queue *q, fmode_t mode,
struct scsi_ioctl_command __user *sic) //sic is a user mode pointer
```

I want to write a query to get all user mode pointer defined in function parameter declaration, I tried to find avaliable API defined in `Marco/MacroAccess/MarcoInovation/Function/Function/FunctionDeclarationEntry/ParameterDeclarationEntry`, but I can not find one can be used for my purpose.

I have no way but to query macro used in function parameter declaration by combining `MacroAccess` and `Location`, the following code may be work, but it prone to be false positive and ugly:(

```ql
class UserParameterDeclarationEntry extends ParameterDeclarationEntry{
UserParameterDeclarationEntry(){
exists(MacroAccess m|
m.getMacroName() = "__user"
and m.getFile() = this.getFile()
and m.getLocation().getEndLine() = this.getLocation().getEndLine()
)
}
}
```

So I hope you guys can be kind enougth to help me find a more effective way to query specific macro in function parameter declaration, thank you:)

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.