Skip to content

Commit f549f7a

Browse files
mbaludaCopilot
andcommitted
Update dataflow library
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent 1274407 commit f549f7a

46 files changed

Lines changed: 250 additions & 242 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎c/cert/src/rules/EXP30-C/DependenceOnOrderOfFunctionArgumentsForSideEffects.ql‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
import cpp
2020
import codingstandards.c.cert
2121
import codingstandards.cpp.SideEffect
22-
import semmle.code.cpp.dataflow.TaintTracking
22+
import semmle.code.cpp.dataflow.new.TaintTracking
2323
import semmle.code.cpp.valuenumbering.GlobalValueNumbering
2424

2525
/** Holds if the function's return value is derived from the `AliasParamter` p. */

‎c/cert/test/rules/ARR30-C/DoNotFormOutOfBoundsPointersOrArraySubscripts.expected‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,13 @@
55
| test.c:45:17:45:30 | ... + ... | Buffer may access up to offset 101*1 which is greater than the fixed size 100 of the $@. | test.c:45:17:45:22 | buffer | buffer |
66
| test.c:55:5:55:13 | ... - ... | Buffer access may be to a negative index in the buffer. | test.c:55:5:55:9 | ptr16 | buffer |
77
| test.c:57:5:57:14 | ... + ... | Buffer accesses offset 22 which is greater than the fixed size 20 of the $@. | test.c:57:5:57:9 | ptr16 | buffer |
8+
| test.c:58:5:58:14 | ... - ... | Buffer access may be to a negative index in the buffer. | test.c:55:5:55:9 | ptr16 | buffer |
9+
| test.c:58:5:58:14 | ... - ... | Buffer access may be to a negative index in the buffer. | test.c:56:5:56:9 | ptr16 | buffer |
10+
| test.c:58:5:58:14 | ... - ... | Buffer access may be to a negative index in the buffer. | test.c:57:5:57:9 | ptr16 | buffer |
811
| test.c:58:5:58:14 | ... - ... | Buffer access may be to a negative index in the buffer. | test.c:58:5:58:9 | ptr16 | buffer |
912
| test.c:63:3:63:9 | access to array | Buffer access may be to a negative index in the buffer. | test.c:63:3:63:5 | arr | buffer |
1013
| test.c:65:3:65:9 | access to array | Buffer accesses offset 44 which is greater than the fixed size 40 of the $@. | test.c:65:3:65:5 | arr | buffer |
14+
| test.c:66:3:66:10 | access to array | Buffer access may be to a negative index in the buffer. | test.c:63:3:63:5 | arr | buffer |
15+
| test.c:66:3:66:10 | access to array | Buffer access may be to a negative index in the buffer. | test.c:64:3:64:5 | arr | buffer |
16+
| test.c:66:3:66:10 | access to array | Buffer access may be to a negative index in the buffer. | test.c:65:3:65:5 | arr | buffer |
1117
| test.c:66:3:66:10 | access to array | Buffer access may be to a negative index in the buffer. | test.c:66:3:66:5 | arr | buffer |
Lines changed: 0 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -1,25 +1 @@
1-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:28,31-39)
2-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:28,59-67)
3-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:31,33-41)
4-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:31,57-65)
5-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:35,33-41)
6-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:35,59-67)
7-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:44,5-13)
8-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:44,25-33)
9-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:44,53-61)
10-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:47,31-39)
11-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:47,57-65)
12-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:56,31-39)
13-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:56,55-63)
14-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:63,31-39)
15-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:63,57-65)
16-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:75,31-39)
17-
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:75,55-63)
18-
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:28,5-18)
19-
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:31,7-20)
20-
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:35,7-20)
21-
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:47,5-18)
22-
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:56,5-18)
23-
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:63,5-18)
24-
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:75,5-18)
251
| test.c:20:3:20:4 | call to f1 | Depending on the order of evaluation for the arguments $@ and $@ for side effects on shared state is unspecified and can result in unexpected behavior. | test.c:20:6:20:7 | call to f2 | call to f2 | test.c:20:12:20:13 | call to f3 | call to f3 |

‎c/common/src/codingstandards/c/OutOfBounds.qll‎

Lines changed: 45 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,6 @@ import codingstandards.cpp.Allocations
1111
import codingstandards.cpp.Overflow
1212
import codingstandards.cpp.PossiblyUnsafeStringOperation
1313
import codingstandards.cpp.SimpleRangeAnalysisCustomizations
14-
private import semmle.code.cpp.dataflow.DataFlow
1514
import semmle.code.cpp.valuenumbering.GlobalValueNumbering
1615

1716
module OOB {
@@ -380,8 +379,13 @@ module OOB {
380379
StrncatLibraryFunction() { this.getName() = getNameOrInternalName(["strncat", "wcsncat"]) }
381380

382381
override predicate getALengthParameterIndex(int i) {
383-
// `strncat` and `wcsncat` exclude the size of a null terminator
384-
i = 2
382+
// The source need not contain a null terminator within the first `n` characters.
383+
none()
384+
}
385+
386+
override predicate getANullTerminatedParameterIndex(int i) {
387+
// The destination must be null-terminated.
388+
i = 0
385389
}
386390
}
387391

@@ -645,42 +649,46 @@ module OOB {
645649
}
646650

647651
/**
648-
* A class for reasoning about the offset of a variable from the original value flowing to it
649-
* as a result of arithmetic or pointer arithmetic expressions.
652+
* Gets the offset of `expr` from `underlyingBase` due to arithmetic or pointer arithmetic.
653+
*
654+
* `underlyingBase` may be the arithmetic operand's base expression or `expr` itself, allowing
655+
* callers to use whichever dataflow node is available.
650656
*/
651657
bindingset[expr]
652-
private int getArithmeticOffsetValue(Expr expr, Expr base) {
653-
result = getMinStatedValue(expr.(PointerArithmeticExpr).getOperand()) and
654-
base = expr.(PointerArithmeticExpr).getPointer()
655-
or
656-
// &(array[index]) expressions
657-
result =
658-
getMinStatedValue(expr.(AddressOfExpr).getOperand().(PointerArithmeticExpr).getOperand()) and
659-
base = expr.(AddressOfExpr).getOperand().(PointerArithmeticExpr).getPointer()
660-
or
661-
result = getMinStatedValue(expr.(AddExpr).getRightOperand()) and
662-
base = expr.(AddExpr).getLeftOperand()
663-
or
664-
result = -getMinStatedValue(expr.(SubExpr).getRightOperand()) and
665-
base = expr.(SubExpr).getLeftOperand()
666-
or
667-
expr instanceof IncrementOperation and
668-
result = 1 and
669-
base = expr.(IncrementOperation).getOperand()
670-
or
671-
expr instanceof DecrementOperation and
672-
result = -1 and
673-
base = expr.(DecrementOperation).getOperand()
674-
or
675-
// fall-back if `expr` is not an arithmetic or pointer arithmetic expression
676-
not expr instanceof PointerArithmeticExpr and
677-
not expr.(AddressOfExpr).getOperand() instanceof PointerArithmeticExpr and
678-
not expr instanceof AddExpr and
679-
not expr instanceof SubExpr and
680-
not expr instanceof IncrementOperation and
681-
not expr instanceof DecrementOperation and
682-
base = expr and
683-
result = 0
658+
private int getArithmeticOffsetValue(Expr expr, Expr underlyingBase) {
659+
exists(Expr base | underlyingBase = [base, expr] |
660+
result = getMinStatedValue(expr.(PointerArithmeticExpr).getOperand()) and
661+
base = expr.(PointerArithmeticExpr).getPointer()
662+
or
663+
// &(array[index]) expressions
664+
result =
665+
getMinStatedValue(expr.(AddressOfExpr).getOperand().(PointerArithmeticExpr).getOperand()) and
666+
base = expr.(AddressOfExpr).getOperand().(PointerArithmeticExpr).getPointer()
667+
or
668+
result = getMinStatedValue(expr.(AddExpr).getRightOperand()) and
669+
base = expr.(AddExpr).getLeftOperand()
670+
or
671+
result = -getMinStatedValue(expr.(SubExpr).getRightOperand()) and
672+
base = expr.(SubExpr).getLeftOperand()
673+
or
674+
expr instanceof IncrementOperation and
675+
result = 1 and
676+
base = expr.(IncrementOperation).getOperand()
677+
or
678+
expr instanceof DecrementOperation and
679+
result = -1 and
680+
base = expr.(DecrementOperation).getOperand()
681+
or
682+
// fall-back if `expr` is not an arithmetic or pointer arithmetic expression
683+
not expr instanceof PointerArithmeticExpr and
684+
not expr.(AddressOfExpr).getOperand() instanceof PointerArithmeticExpr and
685+
not expr instanceof AddExpr and
686+
not expr instanceof SubExpr and
687+
not expr instanceof IncrementOperation and
688+
not expr instanceof DecrementOperation and
689+
base = expr and
690+
result = 0
691+
)
684692
}
685693

686694
private int constOrZero(Expr e) {

‎c/common/test/rules/constlikereturnvalue/ConstLikeReturnValue.expected‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
11
problems
2-
| test.c:11:7:11:12 | * ... | test.c:18:16:18:21 | call to getenv | test.c:11:7:11:12 | * ... | The object returned by the function getenv should not be modified. |
32
| test.c:11:8:11:12 | c_str | test.c:18:16:18:21 | call to getenv | test.c:11:7:11:12 | * ... | The object returned by the function getenv should not be modified. |
43
| test.c:67:5:67:9 | conv4 | test.c:64:11:64:20 | call to localeconv | test.c:67:5:67:9 | conv4 | The object returned by the function localeconv should not be modified. |
54
| test.c:76:5:76:8 | conv | test.c:72:25:72:34 | call to localeconv | test.c:76:5:76:8 | conv | The object returned by the function localeconv should not be modified. |

‎c/misra/src/rules/RULE-14-3/ControllingExprInvariant.ql‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,9 @@ where
4040
conditionAlwaysFalse(expr) and
4141
not (
4242
getEssentialTypeCategory(getEssentialType(expr)) instanceof EssentiallyBooleanType and
43-
expr.getValue() = "0"
43+
expr.getValue() = "0" and
44+
// Only apply to expressions that do not reference variables.
45+
not exists(VariableAccess va | va = expr.getAChild*())
4446
)
4547
or
4648
conditionAlwaysTrue(expr) and

‎c/misra/test/rules/RULE-14-3/ControllingExprInvariant.expected‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@
33
| test.c:16:9:16:13 | ... > ... | Controlling expression in if statement has an invariant value. |
44
| test.c:20:20:20:24 | ... < ... | Controlling expression in loop statement has an invariant value. |
55
| test.c:27:10:27:14 | ... < ... | Controlling expression in loop statement has an invariant value. |
6-
| test.c:37:3:37:6 | 1 | Controlling expression in conditional statement has an invariant value. |
7-
| test.c:38:3:38:3 | 1 | Controlling expression in conditional statement has an invariant value. |
8-
| test.c:45:10:45:26 | ... && ... | Controlling expression in loop statement has an invariant value. |
6+
| test.c:35:12:35:12 | 0 | Controlling expression in loop statement has an invariant value. |
7+
| test.c:39:3:39:6 | 1 | Controlling expression in conditional statement has an invariant value. |
8+
| test.c:40:3:40:3 | 1 | Controlling expression in conditional statement has an invariant value. |
9+
| test.c:47:10:47:26 | ... && ... | Controlling expression in loop statement has an invariant value. |
10+
| test.c:49:10:49:21 | ... && ... | Controlling expression in loop statement has an invariant value. |

‎c/misra/test/rules/RULE-14-3/test.c‎

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,8 @@ void f1(int p1) {
1313

1414
void f2() {
1515
while (20 > 10) { // NON_COMPLIANT
16-
if (1 > 2) {
17-
} // NON_COMPLIANT
16+
if (1 > 2) { // NON_COMPLIANT
17+
}
1818
}
1919

2020
for (int i = 10; i < 5; i++) { // NON_COMPLIANT
@@ -31,6 +31,8 @@ void f3() {
3131
void f4() {
3232
do {
3333
} while (0u == 1u); // COMPLIANT - by exception 2
34+
do {
35+
} while (0); // NON_COMPLIANT - a bare literal `0` is not essentially Boolean
3436
}
3537

3638
void f5(bool b1) {
@@ -44,4 +46,6 @@ void f6(int p1) {
4446
}
4547
while (1 == 0 && p1 > 12) { // NON_COMPLIANT
4648
}
49+
while (0 && p1 > 12) { // NON_COMPLIANT
50+
}
4751
}

‎c/misra/test/rules/RULE-21-18/test.c‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -103,4 +103,10 @@ void test(void) {
103103
strxfrm(buf + 1, buf2,
104104
sizeof(buf) - 1); // NON_COMPLIANT - not null-terminated
105105
}
106-
}
106+
}
107+
108+
void test_strncat_bounded_source(void) {
109+
char destination[2] = {0};
110+
char source[1] = {'x'};
111+
strncat(destination, source, 1); // COMPLIANT
112+
}
Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
- `ENV30-C`, `RULE-21-19`, `RULE-25-5-2`: removed duplicate alerts for the same modification of a
2+
pointer returned by an environment or locale function.
3+
- `RULE-14-3`: loop controlling expressions with an invariant false value are now reported when
4+
they use the integer literal `0`, including within compound expressions.
5+
- `ARR30-C`: negative out-of-bounds accesses may now produce a result for each reaching buffer
6+
expression.
7+
- `ARR38-C`, `RULE-21-17`, `RULE-21-18`, `RULE-8-7-1`: corrected the modeling of `strncat` and
8+
`wcsncat`. Their destination must be null-terminated, while their source does not need a null
9+
terminator within the specified character limit.

0 commit comments

Comments
 (0)