| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [View Raw Code] [Original HTTPS Page] |
The following changes in version 1.24 affect C/C++ analysis in all applications.
You can now suppress alerts using either single-line block comments (/* ... */) or line comments (// ...).
| Query | Tags | Purpose |
|---|---|---|
| Implicit function declarations (cpp/Likely Bugs/Underspecified Functions/ImplicitFunctionDeclaration.ql) | correctness, maintainability | This query finds calls to undeclared functions that are compiled by a C compiler. Results are shown on LGTM by default. |
A new taint-tracking library is used by all the security queries that track tainted values (cpp/path-injection, cpp/cgi-xss, cpp/sql-injection, cpp/uncontrolled-process-operation, cpp/unbounded-write, cpp/tainted-format-string, cpp/tainted-format-string-through-global, cpp/uncontrolled-arithmetic, cpp/uncontrolled-allocation-size, cpp/user-controlled-bypass, cpp/cleartext-storage-buffer, cpp/tainted-permissions-check). These queries now have more precise results and also offer path explanations so you can explore the results easily. There is a performance cost to this, and the LGTM query suite will overall run slower than before.
| Query | Expected impact | Change |
|---|---|---|
| Boost_asio TLS Settings Misconfiguration (cpp/boost/tls-settings-misconfiguration) | Query id change | The identifier was updated to use dashes in place of underscores (previous identifier cpp/boost/tls_settings_misconfiguration). |
| Buffer not sufficient for string (cpp/overflow-calculated) | More true positive results | This query now identifies a wider variety of buffer allocations using the semmle.code.cpp.models.interfaces.Allocation library. |
| Hard-coded Japanese era start date (cpp/japanese-era/exact-era-date) | This query is no longer run on LGTM. | |
| Memory is never freed (cpp/memory-never-freed) | More true positive results | This query now identifies a wider variety of buffer allocations using the semmle.code.cpp.models.interfaces.Allocation library. |
| Memory may not be freed (cpp/memory-may-not-be-freed) | More true positive results | This query now identifies a wider variety of buffer allocations using the semmle.code.cpp.models.interfaces.Allocation library. |
| Mismatching new/free or malloc/delete (cpp/new-free-mismatch) | Fewer false positive results | Improved handling of template code gives greater precision. |
| Missing return statement (cpp/missing-return) | Fewer false positive results and more accurate locations | Functions containing asm statements are no longer highlighted by this query. The locations reported by this query are now more accurate in some cases. |
| No space for zero terminator (cpp/no-space-for-terminator) | More results with greater precision | The query gives more precise results for a wider variety of buffer allocations. String arguments to formatting functions are now (usually) expected to be null terminated strings. Use of the semmle.code.cpp.models.interfaces.Allocation library identifies problems with a wider variety of buffer allocations. This query is also more conservative when identifying which pointers point to null-terminated strings. |
| Overflow in uncontrolled allocation size (cpp/uncontrolled-allocation-size) | Fewer false positive results | The query now produces fewer, more accurate results. Cases where the tainted allocation size is range checked are more reliably excluded. |
| Overloaded assignment does not return 'this' (cpp/assignment-does-not-return-this) | Fewer false positive results | This query no longer reports incorrect results in template classes. |
| Pointer overflow check (cpp/pointer-overflow-check), Possibly wrong buffer size in string copy (cpp/bad-strncpy-size), Signed overflow check (cpp/signed-overflow-check) |
More correct results | A new library is used for determining which expressions have identical value, giving more precise results. There is a performance cost to this, and the LGTM suite will overall run slower than before. |
| Unsafe array for days of the year (cpp/leap-year/unsafe-array-for-days-of-the-year) | This query is no longer run on LGTM. | |
| Unsigned comparison to zero (cpp/unsigned-comparison-zero) | More correct results | This query now also looks for comparisons of the form 0 <= x. |
| Back | FazBrowse Home | New Git URL |