Skip to content

Commit b65f822

Browse files
committed
Merge remote-tracking branch 'upstream/main' into SimpleRangeAnalysis-mul-constant
2 parents f79c140 + bc77916 commit b65f822

File tree

58 files changed

+2448
-1725
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

58 files changed

+2448
-1725
lines changed

change-notes/1.26/analysis-cpp.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,6 +14,7 @@ The following changes in version 1.26 affect C/C++ analysis in all applications.
1414
| **Query** | **Expected impact** | **Change** |
1515
|----------------------------|------------------------|------------------------------------------------------------------|
1616
| Inconsistent direction of for loop (`cpp/inconsistent-loop-direction`) | Fewer false positive results | The query now accounts for intentional wrapping of an unsigned loop counter. |
17+
| Overflow in uncontrolled allocation size (`cpp/uncontrolled-allocation-size`) | | The precision of this query has been decreased from "high" to "medium". As a result, the query is still run but results are no longer displayed on LGTM by default. |
1718
| Comparison result is always the same (`cpp/constant-comparison`) | More correct results | Bounds on expressions involving multiplication can now be determined in more cases. |
1819

1920
## Changes to libraries
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
# Improvements to C# analysis
2+
3+
The following changes in version 1.26 affect C# analysis in all applications.
4+
5+
## New queries
6+
7+
| **Query** | **Tags** | **Purpose** |
8+
|-----------------------------|-----------|--------------------------------------------------------------------|
9+
10+
11+
## Changes to existing queries
12+
13+
| **Query** | **Expected impact** | **Change** |
14+
|------------------------------|------------------------|-----------------------------------|
15+
16+
17+
## Removal of old queries
18+
19+
## Changes to code extraction
20+
21+
* Partial method bodies are extracted. Previously, partial method bodies were skipped completely.
22+
23+
## Changes to libraries
24+
25+
## Changes to autobuilder
26+
27+
## Changes to tooling support
28+
29+
* The Abstract Syntax Tree of C# files can be printed in Visual Studio Code.

change-notes/1.26/analysis-javascript.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@
2424

2525
| **Query** | **Expected impact** | **Change** |
2626
|--------------------------------|------------------------------|---------------------------------------------------------------------------|
27+
| Incomplete URL substring sanitization (`js/incomplete-url-substring-sanitization`) | More results | This query now recognizes additional URLs when the substring check is an inclusion check. |
2728

2829

2930
## Changes to libraries
30-

cpp/ql/src/Security/CWE/CWE-190/TaintedAllocationSize.ql

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@
44
* user can result in integer overflow.
55
* @kind path-problem
66
* @problem.severity error
7-
* @precision high
7+
* @precision medium
88
* @id cpp/uncontrolled-allocation-size
99
* @tags reliability
1010
* security
Lines changed: 78 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,78 @@
1+
/**
2+
* EXPERIMENTAL: The API of this module may change without notice.
3+
*
4+
* Provides a class for modeling `Expr`s with a restricted range.
5+
*/
6+
7+
import cpp
8+
import semmle.code.cpp.rangeanalysis.SimpleRangeAnalysis
9+
10+
/**
11+
* EXPERIMENTAL: The API of this class may change without notice.
12+
*
13+
* An expression for which a range can be deduced. Extend this class to add
14+
* functionality to the range analysis library.
15+
*/
16+
abstract class SimpleRangeAnalysisExpr extends Expr {
17+
/**
18+
* Gets the lower bound of the expression.
19+
*
20+
* Implementations of this predicate should use
21+
* `getFullyConvertedLowerBounds` and `getFullyConvertedUpperBounds` for
22+
* recursive calls to get the bounds of their children.
23+
*/
24+
abstract float getLowerBounds();
25+
26+
/**
27+
* Gets the upper bound of the expression.
28+
*
29+
* Implementations of this predicate should use
30+
* `getFullyConvertedLowerBounds` and `getFullyConvertedUpperBounds` for
31+
* recursive calls to get the bounds of their children.
32+
*/
33+
abstract float getUpperBounds();
34+
35+
/**
36+
* Holds if the range this expression depends on the definition `srcDef` for
37+
* StackVariable `srcVar`.
38+
*
39+
* Because this predicate cannot be recursive, most implementations should
40+
* override `dependsOnChild` instead.
41+
*/
42+
predicate dependsOnDef(RangeSsaDefinition srcDef, StackVariable srcVar) { none() }
43+
44+
/**
45+
* Holds if this expression depends on the range of its unconverted
46+
* subexpression `child`. This information is used to inform the range
47+
* analysis about cyclic dependencies. Without this information, range
48+
* analysis might work for simple cases but will go into infinite loops on
49+
* complex code.
50+
*
51+
* For example, when modeling a function call whose return value depends on
52+
* all of its arguments, implement this predicate as
53+
* `child = this.getAnArgument()`.
54+
*/
55+
abstract predicate dependsOnChild(Expr child);
56+
}
57+
58+
import SimpleRangeAnalysisInternal
59+
60+
/**
61+
* This class exists to prevent the QL front end from emitting compile errors
62+
* inside `SimpleRangeAnalysis.qll` about certain conjuncts being empty
63+
* because the overrides of `SimpleRangeAnalysisExpr` that happen to be in
64+
* scope do not make use of every feature it offers.
65+
*/
66+
private class Empty extends SimpleRangeAnalysisExpr {
67+
Empty() {
68+
// This predicate is complicated enough that the QL type checker doesn't
69+
// see it as empty but simple enough that the optimizer should.
70+
this = this and none()
71+
}
72+
73+
override float getLowerBounds() { none() }
74+
75+
override float getUpperBounds() { none() }
76+
77+
override predicate dependsOnChild(Expr child) { none() }
78+
}

0 commit comments

Comments
 (0)