FazBrowse GitHub Viewer
|
Trending
|
URL:
|
Home
Tools:
[Download Repo ZIP]
[View Raw Code]
[Original HTTPS Page]
codeql/cpp/ql/src/Critical/DeadCodeCondition.ql at codeql-cli/latest · github/codeql · GitHub
Uh oh!
There was an error while loading.
Please reload this page
.
github
/
codeql
Public
Notifications
You must be signed in to change notification settings
Fork
2.1k
Star
10k
Code
Issues
997
Pull requests
459
Discussions
Actions
Projects
Security and quality
0
Insights
Additional navigation options
Code
Issues
Pull requests
Discussions
Actions
Projects
Security and quality
Insights
Expand file tree
Breadcrumbs
codeql
/
cpp
/
ql
/
src
/
Critical
/
DeadCodeCondition.ql
Copy path
More file actions
More file actions
Latest commit
History
History
History
68 lines (62 loc) · 1.98 KB
Breadcrumbs
codeql
/
cpp
/
ql
/
src
/
Critical
/
DeadCodeCondition.ql
Copy path
File metadata and controls
68 lines (62 loc) · 1.98 KB
Raw
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
/**
* @name Branching condition always evaluates to same value
* @description The condition of the branching statement always evaluates to the same value. This means that only one branch will ever be executed.
* @kind problem
* @id cpp/dead-code-condition
* @problem.severity warning
* @tags reliability
* external/cwe/cwe-561
*/
import
cpp
predicate
testAndBranch
(
Expr
e
,
Stmt
branch
)
{
exists
(
IfStmt
ifstmt
|
ifstmt
.
getCondition
(
)
=
e
and
(
ifstmt
.
getThen
(
)
=
branch
or
ifstmt
.
getElse
(
)
=
branch
)
)
or
exists
(
WhileStmt
while
|
while
.
getCondition
(
)
=
e
and
while
.
getStmt
(
)
=
branch
)
}
predicate
choice
(
StackVariable
v
,
Stmt
branch
,
string
value
)
{
exists
(
AnalysedExpr
e
|
testAndBranch
(
e
,
branch
)
and
(
e
.
getNullSuccessor
(
v
)
=
branch
and
value
=
"null"
or
e
.
getNonNullSuccessor
(
v
)
=
branch
and
value
=
"non-null"
)
)
}
predicate
guarded
(
StackVariable
v
,
Stmt
loopstart
,
AnalysedExpr
child
)
{
choice
(
v
,
loopstart
,
_
)
and
loopstart
.
getChildStmt
*
(
)
=
child
.
getEnclosingStmt
(
)
and
(
definition
(
v
,
child
)
or
exists
(
child
.
getNullSuccessor
(
v
)
)
)
}
predicate
addressLeak
(
Variable
v
,
Stmt
leak
)
{
exists
(
VariableAccess
access
|
v
.
getAnAccess
(
)
=
access
and
access
.
getEnclosingStmt
(
)
=
leak
and
access
.
isAddressOfAccess
(
)
)
}
from
StackVariable
v
,
Stmt
branch
,
AnalysedExpr
cond
,
string
context
,
string
test
,
string
testresult
where
choice
(
v
,
branch
,
context
)
and
forall
(
ControlFlowNode
def
|
definition
(
v
,
def
)
and
definitionReaches
(
def
,
cond
)
|
not
guarded
(
v
,
branch
,
def
)
)
and
not
cond
.
isDef
(
v
)
and
guarded
(
v
,
branch
,
cond
)
and
exists
(
cond
.
getNullSuccessor
(
v
)
)
and
not
addressLeak
(
v
,
branch
.
getChildStmt
*
(
)
)
and
(
cond
.
isNullCheck
(
v
)
and
test
=
"null"
or
cond
.
isValidCheck
(
v
)
and
test
=
"non-null"
)
and
(
if
context
=
test
then
testresult
=
"succeed"
else
testresult
=
"fail"
)
select
cond
,
"Variable '"
+
v
.
getName
(
)
+
"' is always "
+
context
+
", this check will always "
+
testresult
+
"."
Back
|
FazBrowse Home
|
New Git URL