Skip to content

Commit 68f7942

Browse files
committed
Merge branch 'main' into noBin
2 parents bf88c81 + d56a033 commit 68f7942

File tree

223 files changed

+18927
-2895
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

223 files changed

+18927
-2895
lines changed

change-notes/1.26/analysis-cpp.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,12 @@ The following changes in version 1.26 affect C/C++ analysis in all applications.
1414
| **Query** | **Expected impact** | **Change** |
1515
|----------------------------|------------------------|------------------------------------------------------------------|
1616
| Inconsistent direction of for loop (`cpp/inconsistent-loop-direction`) | Fewer false positive results | The query now accounts for intentional wrapping of an unsigned loop counter. |
17+
| Overflow in uncontrolled allocation size (`cpp/uncontrolled-allocation-size`) | | The precision of this query has been decreased from "high" to "medium". As a result, the query is still run but results are no longer displayed on LGTM by default. |
18+
| Comparison result is always the same (`cpp/constant-comparison`) | More correct results | Bounds on expressions involving multiplication can now be determined in more cases. |
1719

1820
## Changes to libraries
1921

22+
* The models library now models some taint flows through `std::array`, `std::vector`, `std::deque`, `std::list` and `std::forward_list`.
23+
* The models library now models many more taint flows through `std::string`.
24+
* The `SimpleRangeAnalysis` library now supports multiplications of the form
25+
`e1 * e2` and `x *= e2` when `e1` and `e2` are unsigned or constant.
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
# Improvements to C# analysis
2+
3+
The following changes in version 1.26 affect C# analysis in all applications.
4+
5+
## New queries
6+
7+
| **Query** | **Tags** | **Purpose** |
8+
|-----------------------------|-----------|--------------------------------------------------------------------|
9+
10+
11+
## Changes to existing queries
12+
13+
| **Query** | **Expected impact** | **Change** |
14+
|------------------------------|------------------------|-----------------------------------|
15+
16+
17+
## Removal of old queries
18+
19+
## Changes to code extraction
20+
21+
* Partial method bodies are extracted. Previously, partial method bodies were skipped completely.
22+
23+
## Changes to libraries
24+
25+
## Changes to autobuilder
26+
27+
## Changes to tooling support
28+
29+
* The Abstract Syntax Tree of C# files can be printed in Visual Studio Code.

change-notes/1.26/analysis-javascript.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,8 @@
1414
- [pretty-format](https://www.npmjs.com/package/pretty-format)
1515
- [stringify-object](https://www.npmjs.com/package/stringify-object)
1616

17+
* Analyzing files with the ".cjs" extension is now supported.
18+
1719
## New queries
1820

1921
| **Query** | **Tags** | **Purpose** |
@@ -24,7 +26,7 @@
2426

2527
| **Query** | **Expected impact** | **Change** |
2628
|--------------------------------|------------------------------|---------------------------------------------------------------------------|
29+
| Incomplete URL substring sanitization (`js/incomplete-url-substring-sanitization`) | More results | This query now recognizes additional URLs when the substring check is an inclusion check. |
2730

2831

2932
## Changes to libraries
30-

cpp/ql/src/Metrics/Files/FNumberOfTests.ql

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,9 @@ Expr getTest() {
1818
or
1919
// boost tests; http://www.boost.org/
2020
result.(FunctionCall).getTarget().hasQualifiedName("boost::unit_test", "make_test_case")
21+
or
22+
// googletest tests; https://github.com/google/googletest/
23+
result.(FunctionCall).getTarget().hasQualifiedName("testing::internal", "MakeAndRegisterTestInfo")
2124
}
2225

2326
from File f, int n

cpp/ql/src/Microsoft/SAL.qll

Lines changed: 42 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,13 @@
1+
/**
2+
* Provides classes for identifying and reasoning about Microsoft source code
3+
* annotation language (SAL) macros.
4+
*/
5+
16
import cpp
27

8+
/**
9+
* A SAL macro defined in `sal.h` or a similar header file.
10+
*/
311
class SALMacro extends Macro {
412
SALMacro() {
513
exists(string filename | filename = this.getFile().getBaseName() |
@@ -20,27 +28,34 @@ class SALMacro extends Macro {
2028
}
2129

2230
pragma[noinline]
23-
predicate isTopLevelMacroAccess(MacroAccess ma) { not exists(ma.getParentInvocation()) }
31+
private predicate isTopLevelMacroAccess(MacroAccess ma) { not exists(ma.getParentInvocation()) }
2432

33+
/**
34+
* An invocation of a SAL macro (excluding invocations inside other macros).
35+
*/
2536
class SALAnnotation extends MacroInvocation {
2637
SALAnnotation() {
2738
this.getMacro() instanceof SALMacro and
2839
isTopLevelMacroAccess(this)
2940
}
3041

31-
/** Returns the `Declaration` annotated by `this`. */
42+
/** Gets the `Declaration` annotated by `this`. */
3243
Declaration getDeclaration() {
3344
annotatesAt(this, result.getADeclarationEntry(), _, _) and
3445
not result instanceof Type // exclude typedefs
3546
}
3647

37-
/** Returns the `DeclarationEntry` annotated by `this`. */
48+
/** Gets the `DeclarationEntry` annotated by `this`. */
3849
DeclarationEntry getDeclarationEntry() {
3950
annotatesAt(this, result, _, _) and
4051
not result instanceof TypeDeclarationEntry // exclude typedefs
4152
}
4253
}
4354

55+
/**
56+
* A SAL macro indicating that the return value of a function should always be
57+
* checked.
58+
*/
4459
class SALCheckReturn extends SALAnnotation {
4560
SALCheckReturn() {
4661
exists(SALMacro m | m = this.getMacro() |
@@ -50,6 +65,10 @@ class SALCheckReturn extends SALAnnotation {
5065
}
5166
}
5267

68+
/**
69+
* A SAL macro indicating that a pointer variable or return value should not be
70+
* `NULL`.
71+
*/
5372
class SALNotNull extends SALAnnotation {
5473
SALNotNull() {
5574
exists(SALMacro m | m = this.getMacro() |
@@ -69,6 +88,9 @@ class SALNotNull extends SALAnnotation {
6988
}
7089
}
7190

91+
/**
92+
* A SAL macro indicating that a value may be `NULL`.
93+
*/
7294
class SALMaybeNull extends SALAnnotation {
7395
SALMaybeNull() {
7496
exists(SALMacro m | m = this.getMacro() |
@@ -79,13 +101,29 @@ class SALMaybeNull extends SALAnnotation {
79101
}
80102
}
81103

104+
/**
105+
* A parameter annotated by one or more SAL annotations.
106+
*/
107+
class SALParameter extends Parameter {
108+
/** One of this parameter's annotations. */
109+
SALAnnotation a;
110+
111+
SALParameter() { annotatesAt(a, this.getADeclarationEntry(), _, _) }
112+
113+
predicate isIn() { a.getMacroName().toLowerCase().matches("%\\_in%") }
114+
115+
predicate isOut() { a.getMacroName().toLowerCase().matches("%\\_out%") }
116+
117+
predicate isInOut() { a.getMacroName().toLowerCase().matches("%\\_inout%") }
118+
}
119+
82120
///////////////////////////////////////////////////////////////////////////////
83121
// Implementation details
84122
/**
85123
* Holds if `a` annotates the declaration entry `d` and
86124
* its start position is the `idx`th position in `file` that holds a SAL element.
87125
*/
88-
predicate annotatesAt(SALAnnotation a, DeclarationEntry d, File file, int idx) {
126+
private predicate annotatesAt(SALAnnotation a, DeclarationEntry d, File file, int idx) {
89127
annotatesAtPosition(a.(SALElement).getStartPosition(), d, file, idx)
90128
}
91129

@@ -109,22 +147,6 @@ private predicate annotatesAtPosition(SALPosition pos, DeclarationEntry d, File
109147
)
110148
}
111149

112-
/**
113-
* A parameter annotated by one or more SAL annotations.
114-
*/
115-
class SALParameter extends Parameter {
116-
/** One of this parameter's annotations. */
117-
SALAnnotation a;
118-
119-
SALParameter() { annotatesAt(a, this.getADeclarationEntry(), _, _) }
120-
121-
predicate isIn() { a.getMacroName().toLowerCase().matches("%\\_in%") }
122-
123-
predicate isOut() { a.getMacroName().toLowerCase().matches("%\\_out%") }
124-
125-
predicate isInOut() { a.getMacroName().toLowerCase().matches("%\\_inout%") }
126-
}
127-
128150
/**
129151
* A SAL element, that is, a SAL annotation or a declaration entry
130152
* that may have SAL annotations.

cpp/ql/src/Security/CWE/CWE-190/TaintedAllocationSize.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* user can result in integer overflow.
55
* @kind path-problem
66
* @problem.severity error
7-
* @precision high
7+
* @precision medium
88
* @id cpp/uncontrolled-allocation-size
99
* @tags reliability
1010
* security
Lines changed: 78 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,78 @@
1+
/**
2+
* EXPERIMENTAL: The API of this module may change without notice.
3+
*
4+
* Provides a class for modeling `Expr`s with a restricted range.
5+
*/
6+
7+
import cpp
8+
import semmle.code.cpp.rangeanalysis.SimpleRangeAnalysis
9+
10+
/**
11+
* EXPERIMENTAL: The API of this class may change without notice.
12+
*
13+
* An expression for which a range can be deduced. Extend this class to add
14+
* functionality to the range analysis library.
15+
*/
16+
abstract class SimpleRangeAnalysisExpr extends Expr {
17+
/**
18+
* Gets the lower bound of the expression.
19+
*
20+
* Implementations of this predicate should use
21+
* `getFullyConvertedLowerBounds` and `getFullyConvertedUpperBounds` for
22+
* recursive calls to get the bounds of their children.
23+
*/
24+
abstract float getLowerBounds();
25+
26+
/**
27+
* Gets the upper bound of the expression.
28+
*
29+
* Implementations of this predicate should use
30+
* `getFullyConvertedLowerBounds` and `getFullyConvertedUpperBounds` for
31+
* recursive calls to get the bounds of their children.
32+
*/
33+
abstract float getUpperBounds();
34+
35+
/**
36+
* Holds if the range this expression depends on the definition `srcDef` for
37+
* StackVariable `srcVar`.
38+
*
39+
* Because this predicate cannot be recursive, most implementations should
40+
* override `dependsOnChild` instead.
41+
*/
42+
predicate dependsOnDef(RangeSsaDefinition srcDef, StackVariable srcVar) { none() }
43+
44+
/**
45+
* Holds if this expression depends on the range of its unconverted
46+
* subexpression `child`. This information is used to inform the range
47+
* analysis about cyclic dependencies. Without this information, range
48+
* analysis might work for simple cases but will go into infinite loops on
49+
* complex code.
50+
*
51+
* For example, when modeling a function call whose return value depends on
52+
* all of its arguments, implement this predicate as
53+
* `child = this.getAnArgument()`.
54+
*/
55+
abstract predicate dependsOnChild(Expr child);
56+
}
57+
58+
import SimpleRangeAnalysisInternal
59+
60+
/**
61+
* This class exists to prevent the QL front end from emitting compile errors
62+
* inside `SimpleRangeAnalysis.qll` about certain conjuncts being empty
63+
* because the overrides of `SimpleRangeAnalysisExpr` that happen to be in
64+
* scope do not make use of every feature it offers.
65+
*/
66+
private class Empty extends SimpleRangeAnalysisExpr {
67+
Empty() {
68+
// This predicate is complicated enough that the QL type checker doesn't
69+
// see it as empty but simple enough that the optimizer should.
70+
this = this and none()
71+
}
72+
73+
override float getLowerBounds() { none() }
74+
75+
override float getUpperBounds() { none() }
76+
77+
override predicate dependsOnChild(Expr child) { none() }
78+
}

0 commit comments

Comments
 (0)