Improve CERT DCL30-C stack return analysis - #1188
JeewoongKim wants to merge 1 commit into
Conversation
|
Hi @JeewoongKim ! Thank you for sending! My first thought is that I'd rather solve this while still using the C Objects API. It makes sense that However, in general, this project would probably benefit from using the ir more often, so from that standpoint I really like your approach. I'd like to triage the differences this shows in practice before deciding the next direction. I'm wondering if the Thank you again! |
|
The concrete false negative I verified was the I also wanted to cover field-address returns such as So |
Description
Fixes #495.
This updates the CERT C
DCL30-Cfunction-return query to use the stack-return analysisfrom
cpp/return-stack-allocated-memory.The previous implementation used the legacy local data-flow API and missed some stack-derived
pointer returns. (e.g.,
char a[2] ; return a + 1;)The changes include:
MustFlowanalysisThe function-return query now focuses on return values. Stack-address escapes through output
parameters are still covered by the separate
AppropriateStorageDurationsStackAdressEscapequery.Tested locally:
codeql test run --show-extractor-output c/cert/test/rules/DCL30-Cpython scripts/validate-rule-package.py c/Declarations8Change request type
.ql,.qll,.qlsor unit tests)Rules with added or modified queries
Release change checklist
Author: Is a change note required?
Query development review checklist
Author
As a rule of thumb, predicates specific to the query should take no more than 1 minute, and for simple queries be under 10 seconds. If this is not the case, this should be highlighted and agreed in the code review process.