microsoft / microsoft/wil

[prefast:Warning]: C26451 (in 'wil::details::ApiTelemetryLogger::ScheduleFireEventCallback')

Open
#290 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

code-analysis
Dominant language
C++
Stars
3k
Forks
300
Avg merge
19h 12m
Merged PRs (30d)
1

Description

PreFast says 'wil::details::ApiTelemetryLogger::ScheduleFireEventCallback' in include/wil/TraceLogging.h hit issue "Arithmetic overflow: Using operator '' on a 4 byte value and then casting the result to a 8 byte value. Cast the value to the wider type before calling operator '' to avoid overflow (io.2)."
The following appears to be the offending code:

    namespace details
    {
...
        private:
...
            void ScheduleFireEventCallback()
            {
                // do not schedule thread pool timer callback, if process is being terminated and dll is not being unloaded dynamically
                if (m_fireEventThreadPoolTimer && !ProcessShutdownInProgress())
                {
                    // Note this will override any pending scheduled callback
                    FILETIME dueTime;
                    ***reinterpret_cast<PLONGLONG>(&dueTime) = -static_cast<LONGLONG>(m_fireEventDelay * 10000);**
                    SetThreadpoolTimer(m_fireEventThreadPoolTimer.get(), &dueTime, 0, 0);
                }
            }

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in include/wil/TraceLogging.h at wil::details::ApiTelemetryLogger::ScheduleFireEventCallback and inspect the FILETIME due-time calculation reported by PreFast. Verify the change with the relevant Windows build or analysis checks, and consider the issue done when warning C26451 no longer appears for this code.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
operating-systems
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.