Skip to content

Commit 547b082

Browse files
committed
C++: Even more test cases.
1 parent 3aa1ba5 commit 547b082

File tree

3 files changed

+34
-12
lines changed

3 files changed

+34
-12
lines changed

cpp/ql/test/query-tests/Security/CWE/CWE-119/semmle/tests/OverflowBuffer.expected

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -100,6 +100,7 @@
100100
| tests.cpp:938:2:938:17 | access to array | This array indexing operation accesses a negative index -1 on the $@. | tests.cpp:906:11:906:12 | xs | array |
101101
| tests.cpp:940:2:940:17 | access to array | This array indexing operation accesses byte offset 399 but the $@ is only 40 bytes. | tests.cpp:906:11:906:12 | xs | array |
102102
| tests.cpp:941:2:941:18 | access to array | This array indexing operation accesses byte offset 403 but the $@ is only 40 bytes. | tests.cpp:906:11:906:12 | xs | array |
103+
| tests.cpp:969:10:969:37 | access to array | This array indexing operation accesses byte offset 43 but the $@ is only 40 bytes. | tests.cpp:959:6:959:11 | values | array |
103104
| tests_restrict.c:12:2:12:7 | call to memcpy | This 'memcpy' operation accesses 2 bytes but the $@ is only 1 byte. | tests_restrict.c:7:6:7:13 | smallbuf | source buffer |
104105
| unions.cpp:26:2:26:7 | call to memset | This 'memset' operation accesses 200 bytes but the $@ is only 100 bytes. | unions.cpp:21:10:21:11 | mu | destination buffer |
105106
| unions.cpp:30:2:30:7 | call to memset | This 'memset' operation accesses 200 bytes but the $@ is only 100 bytes. | unions.cpp:15:7:15:11 | small | destination buffer |

cpp/ql/test/query-tests/Security/CWE/CWE-119/semmle/tests/UnboundedWrite.expected

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,8 @@ edges
2727
| main.cpp:9:29:9:32 | *argv | tests_restrict.c:15:41:15:44 | *argv | provenance | |
2828
| main.cpp:9:29:9:32 | tests_restrict_main output argument | main.cpp:10:20:10:23 | **argv | provenance | |
2929
| main.cpp:9:29:9:32 | tests_restrict_main output argument | main.cpp:10:20:10:23 | *argv | provenance | |
30-
| main.cpp:10:20:10:23 | **argv | tests.cpp:958:32:958:35 | **argv | provenance | |
31-
| main.cpp:10:20:10:23 | *argv | tests.cpp:958:32:958:35 | *argv | provenance | |
30+
| main.cpp:10:20:10:23 | **argv | tests.cpp:978:32:978:35 | **argv | provenance | |
31+
| main.cpp:10:20:10:23 | *argv | tests.cpp:978:32:978:35 | *argv | provenance | |
3232
| overflowdestination.cpp:23:45:23:48 | **argv | overflowdestination.cpp:23:45:23:48 | **argv | provenance | |
3333
| overflowdestination.cpp:23:45:23:48 | **argv | overflowdestination.cpp:23:45:23:48 | *argv | provenance | |
3434
| test_buffer_overrun.cpp:32:46:32:49 | **argv | test_buffer_overrun.cpp:32:46:32:49 | **argv | provenance | |
@@ -41,12 +41,12 @@ edges
4141
| tests.cpp:649:14:649:14 | *s [*home] | tests.cpp:649:14:649:19 | *home | provenance | |
4242
| tests.cpp:649:14:649:14 | *s [*home] | tests.cpp:649:16:649:19 | *home | provenance | |
4343
| tests.cpp:649:16:649:19 | *home | tests.cpp:649:14:649:19 | *home | provenance | |
44-
| tests.cpp:958:32:958:35 | **argv | tests.cpp:983:9:983:15 | *access to array | provenance | |
45-
| tests.cpp:958:32:958:35 | **argv | tests.cpp:984:9:984:15 | *access to array | provenance | |
46-
| tests.cpp:958:32:958:35 | *argv | tests.cpp:983:9:983:15 | *access to array | provenance | |
47-
| tests.cpp:958:32:958:35 | *argv | tests.cpp:984:9:984:15 | *access to array | provenance | |
48-
| tests.cpp:983:9:983:15 | *access to array | tests.cpp:634:19:634:24 | *source | provenance | |
49-
| tests.cpp:984:9:984:15 | *access to array | tests.cpp:643:19:643:24 | *source | provenance | |
44+
| tests.cpp:978:32:978:35 | **argv | tests.cpp:1003:9:1003:15 | *access to array | provenance | |
45+
| tests.cpp:978:32:978:35 | **argv | tests.cpp:1004:9:1004:15 | *access to array | provenance | |
46+
| tests.cpp:978:32:978:35 | *argv | tests.cpp:1003:9:1003:15 | *access to array | provenance | |
47+
| tests.cpp:978:32:978:35 | *argv | tests.cpp:1004:9:1004:15 | *access to array | provenance | |
48+
| tests.cpp:1003:9:1003:15 | *access to array | tests.cpp:634:19:634:24 | *source | provenance | |
49+
| tests.cpp:1004:9:1004:15 | *access to array | tests.cpp:643:19:643:24 | *source | provenance | |
5050
| tests_restrict.c:15:41:15:44 | **argv | tests_restrict.c:15:41:15:44 | **argv | provenance | |
5151
| tests_restrict.c:15:41:15:44 | *argv | tests_restrict.c:15:41:15:44 | *argv | provenance | |
5252
nodes
@@ -80,10 +80,10 @@ nodes
8080
| tests.cpp:649:14:649:14 | *s [*home] | semmle.label | *s [*home] |
8181
| tests.cpp:649:14:649:19 | *home | semmle.label | *home |
8282
| tests.cpp:649:16:649:19 | *home | semmle.label | *home |
83-
| tests.cpp:958:32:958:35 | **argv | semmle.label | **argv |
84-
| tests.cpp:958:32:958:35 | *argv | semmle.label | *argv |
85-
| tests.cpp:983:9:983:15 | *access to array | semmle.label | *access to array |
86-
| tests.cpp:984:9:984:15 | *access to array | semmle.label | *access to array |
83+
| tests.cpp:978:32:978:35 | **argv | semmle.label | **argv |
84+
| tests.cpp:978:32:978:35 | *argv | semmle.label | *argv |
85+
| tests.cpp:1003:9:1003:15 | *access to array | semmle.label | *access to array |
86+
| tests.cpp:1004:9:1004:15 | *access to array | semmle.label | *access to array |
8787
| tests_restrict.c:15:41:15:44 | **argv | semmle.label | **argv |
8888
| tests_restrict.c:15:41:15:44 | **argv | semmle.label | **argv |
8989
| tests_restrict.c:15:41:15:44 | *argv | semmle.label | *argv |

cpp/ql/test/query-tests/Security/CWE/CWE-119/semmle/tests/tests.cpp

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -955,6 +955,26 @@ void test26() {
955955
zs[1][2] = 0; // BAD: overrun write [NOT DETECTED]
956956
}
957957

958+
struct Array10 {
959+
int values[10];
960+
};
961+
962+
void test27(size_t s) {
963+
Array10 arr;
964+
965+
if (s < sizeof(arr.values[10])) { // GOOD (harmless)
966+
// ...
967+
}
968+
969+
if (s < offsetof(Array10, values[10])) { // GOOD (harmless) [FALSE POSITIVE]
970+
// ...
971+
}
972+
973+
if (s < &(arr.values[10]) - &(arr.values[0])) { // GOOD (harmless)
974+
// ...
975+
}
976+
}
977+
958978
int tests_main(int argc, char *argv[])
959979
{
960980
long long arr17[19];
@@ -983,6 +1003,7 @@ int tests_main(int argc, char *argv[])
9831003
test24(argv[0]);
9841004
test25(argv[0]);
9851005
test26();
1006+
test27(argc);
9861007

9871008
return 0;
9881009
}

0 commit comments

Comments
 (0)