зеркало из https://github.com/github/codeql.git
C++: Add tests to 'cpp/overrun-write'.
This commit is contained in:
Родитель
f761e57365
Коммит
51758aa928
|
@ -1,6 +1,7 @@
|
|||
edges
|
||||
| test.cpp:16:11:16:21 | VariableAddress indirection [string] | test.cpp:24:21:24:31 | Call indirection [string] |
|
||||
| test.cpp:16:11:16:21 | VariableAddress indirection [string] | test.cpp:34:21:34:31 | Call indirection [string] |
|
||||
| test.cpp:16:11:16:21 | VariableAddress indirection [string] | test.cpp:39:21:39:31 | Call indirection [string] |
|
||||
| test.cpp:18:5:18:30 | Store | test.cpp:18:10:18:15 | Load indirection [post update] [string] |
|
||||
| test.cpp:18:10:18:15 | Load indirection [post update] [string] | test.cpp:16:11:16:21 | VariableAddress indirection [string] |
|
||||
| test.cpp:18:19:18:24 | call to malloc | test.cpp:18:5:18:30 | Store |
|
||||
|
@ -12,6 +13,94 @@ edges
|
|||
| test.cpp:30:18:30:23 | FieldAddress indirection | test.cpp:30:18:30:23 | Load |
|
||||
| test.cpp:34:21:34:31 | Call indirection [string] | test.cpp:35:21:35:23 | str indirection [string] |
|
||||
| test.cpp:35:21:35:23 | str indirection [string] | test.cpp:29:32:29:34 | str indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:41:13:41:15 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:42:13:42:15 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:44:13:44:15 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:45:13:45:15 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:48:17:48:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:52:17:52:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:56:17:56:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:60:17:60:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:64:17:64:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:68:17:68:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:72:17:72:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:76:17:76:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:80:17:80:19 | Load indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | test.cpp:84:17:84:19 | Load indirection [string] |
|
||||
| test.cpp:41:13:41:15 | Load indirection [string] | test.cpp:41:18:41:23 | FieldAddress indirection |
|
||||
| test.cpp:41:18:41:23 | FieldAddress indirection | test.cpp:41:18:41:23 | Load |
|
||||
| test.cpp:42:13:42:15 | Load indirection [string] | test.cpp:42:18:42:23 | FieldAddress indirection |
|
||||
| test.cpp:42:18:42:23 | FieldAddress indirection | test.cpp:42:18:42:23 | Load |
|
||||
| test.cpp:44:13:44:15 | Load indirection [string] | test.cpp:44:18:44:23 | FieldAddress indirection |
|
||||
| test.cpp:44:18:44:23 | FieldAddress indirection | test.cpp:44:18:44:23 | Load |
|
||||
| test.cpp:45:13:45:15 | Load indirection [string] | test.cpp:45:18:45:23 | FieldAddress indirection |
|
||||
| test.cpp:45:18:45:23 | FieldAddress indirection | test.cpp:45:18:45:23 | Load |
|
||||
| test.cpp:48:17:48:19 | Load indirection [string] | test.cpp:48:22:48:27 | FieldAddress indirection |
|
||||
| test.cpp:48:22:48:27 | FieldAddress indirection | test.cpp:48:22:48:27 | Load |
|
||||
| test.cpp:52:17:52:19 | Load indirection [string] | test.cpp:52:22:52:27 | FieldAddress indirection |
|
||||
| test.cpp:52:22:52:27 | FieldAddress indirection | test.cpp:52:22:52:27 | Load |
|
||||
| test.cpp:56:17:56:19 | Load indirection [string] | test.cpp:56:22:56:27 | FieldAddress indirection |
|
||||
| test.cpp:56:22:56:27 | FieldAddress indirection | test.cpp:56:22:56:27 | Load |
|
||||
| test.cpp:60:17:60:19 | Load indirection [string] | test.cpp:60:22:60:27 | FieldAddress indirection |
|
||||
| test.cpp:60:22:60:27 | FieldAddress indirection | test.cpp:60:22:60:27 | Load |
|
||||
| test.cpp:64:17:64:19 | Load indirection [string] | test.cpp:64:22:64:27 | FieldAddress indirection |
|
||||
| test.cpp:64:22:64:27 | FieldAddress indirection | test.cpp:64:22:64:27 | Load |
|
||||
| test.cpp:68:17:68:19 | Load indirection [string] | test.cpp:68:22:68:27 | FieldAddress indirection |
|
||||
| test.cpp:68:22:68:27 | FieldAddress indirection | test.cpp:68:22:68:27 | Load |
|
||||
| test.cpp:72:17:72:19 | Load indirection [string] | test.cpp:72:22:72:27 | FieldAddress indirection |
|
||||
| test.cpp:72:22:72:27 | FieldAddress indirection | test.cpp:72:22:72:27 | Load |
|
||||
| test.cpp:76:17:76:19 | Load indirection [string] | test.cpp:76:22:76:27 | FieldAddress indirection |
|
||||
| test.cpp:76:22:76:27 | FieldAddress indirection | test.cpp:76:22:76:27 | Load |
|
||||
| test.cpp:80:17:80:19 | Load indirection [string] | test.cpp:80:22:80:27 | FieldAddress indirection |
|
||||
| test.cpp:80:22:80:27 | FieldAddress indirection | test.cpp:80:22:80:27 | Load |
|
||||
| test.cpp:84:17:84:19 | Load indirection [string] | test.cpp:84:22:84:27 | FieldAddress indirection |
|
||||
| test.cpp:84:22:84:27 | FieldAddress indirection | test.cpp:84:22:84:27 | Load |
|
||||
| test.cpp:88:11:88:30 | VariableAddress indirection [string] | test.cpp:96:21:96:40 | Call indirection [string] |
|
||||
| test.cpp:90:5:90:34 | Store | test.cpp:90:10:90:15 | Load indirection [post update] [string] |
|
||||
| test.cpp:90:10:90:15 | Load indirection [post update] [string] | test.cpp:88:11:88:30 | VariableAddress indirection [string] |
|
||||
| test.cpp:90:19:90:24 | call to malloc | test.cpp:90:5:90:34 | Store |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:98:13:98:15 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:99:13:99:15 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:101:13:101:15 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:102:13:102:15 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:105:17:105:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:109:17:109:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:113:17:113:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:117:17:117:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:121:17:121:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:125:17:125:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:129:17:129:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:133:17:133:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:137:17:137:19 | Load indirection [string] |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | test.cpp:141:17:141:19 | Load indirection [string] |
|
||||
| test.cpp:98:13:98:15 | Load indirection [string] | test.cpp:98:18:98:23 | FieldAddress indirection |
|
||||
| test.cpp:98:18:98:23 | FieldAddress indirection | test.cpp:98:18:98:23 | Load |
|
||||
| test.cpp:99:13:99:15 | Load indirection [string] | test.cpp:99:18:99:23 | FieldAddress indirection |
|
||||
| test.cpp:99:18:99:23 | FieldAddress indirection | test.cpp:99:18:99:23 | Load |
|
||||
| test.cpp:101:13:101:15 | Load indirection [string] | test.cpp:101:18:101:23 | FieldAddress indirection |
|
||||
| test.cpp:101:18:101:23 | FieldAddress indirection | test.cpp:101:18:101:23 | Load |
|
||||
| test.cpp:102:13:102:15 | Load indirection [string] | test.cpp:102:18:102:23 | FieldAddress indirection |
|
||||
| test.cpp:102:18:102:23 | FieldAddress indirection | test.cpp:102:18:102:23 | Load |
|
||||
| test.cpp:105:17:105:19 | Load indirection [string] | test.cpp:105:22:105:27 | FieldAddress indirection |
|
||||
| test.cpp:105:22:105:27 | FieldAddress indirection | test.cpp:105:22:105:27 | Load |
|
||||
| test.cpp:109:17:109:19 | Load indirection [string] | test.cpp:109:22:109:27 | FieldAddress indirection |
|
||||
| test.cpp:109:22:109:27 | FieldAddress indirection | test.cpp:109:22:109:27 | Load |
|
||||
| test.cpp:113:17:113:19 | Load indirection [string] | test.cpp:113:22:113:27 | FieldAddress indirection |
|
||||
| test.cpp:113:22:113:27 | FieldAddress indirection | test.cpp:113:22:113:27 | Load |
|
||||
| test.cpp:117:17:117:19 | Load indirection [string] | test.cpp:117:22:117:27 | FieldAddress indirection |
|
||||
| test.cpp:117:22:117:27 | FieldAddress indirection | test.cpp:117:22:117:27 | Load |
|
||||
| test.cpp:121:17:121:19 | Load indirection [string] | test.cpp:121:22:121:27 | FieldAddress indirection |
|
||||
| test.cpp:121:22:121:27 | FieldAddress indirection | test.cpp:121:22:121:27 | Load |
|
||||
| test.cpp:125:17:125:19 | Load indirection [string] | test.cpp:125:22:125:27 | FieldAddress indirection |
|
||||
| test.cpp:125:22:125:27 | FieldAddress indirection | test.cpp:125:22:125:27 | Load |
|
||||
| test.cpp:129:17:129:19 | Load indirection [string] | test.cpp:129:22:129:27 | FieldAddress indirection |
|
||||
| test.cpp:129:22:129:27 | FieldAddress indirection | test.cpp:129:22:129:27 | Load |
|
||||
| test.cpp:133:17:133:19 | Load indirection [string] | test.cpp:133:22:133:27 | FieldAddress indirection |
|
||||
| test.cpp:133:22:133:27 | FieldAddress indirection | test.cpp:133:22:133:27 | Load |
|
||||
| test.cpp:137:17:137:19 | Load indirection [string] | test.cpp:137:22:137:27 | FieldAddress indirection |
|
||||
| test.cpp:137:22:137:27 | FieldAddress indirection | test.cpp:137:22:137:27 | Load |
|
||||
| test.cpp:141:17:141:19 | Load indirection [string] | test.cpp:141:22:141:27 | FieldAddress indirection |
|
||||
| test.cpp:141:22:141:27 | FieldAddress indirection | test.cpp:141:22:141:27 | Load |
|
||||
nodes
|
||||
| test.cpp:16:11:16:21 | VariableAddress indirection [string] | semmle.label | VariableAddress indirection [string] |
|
||||
| test.cpp:18:5:18:30 | Store | semmle.label | Store |
|
||||
|
@ -27,7 +116,98 @@ nodes
|
|||
| test.cpp:30:18:30:23 | Load | semmle.label | Load |
|
||||
| test.cpp:34:21:34:31 | Call indirection [string] | semmle.label | Call indirection [string] |
|
||||
| test.cpp:35:21:35:23 | str indirection [string] | semmle.label | str indirection [string] |
|
||||
| test.cpp:39:21:39:31 | Call indirection [string] | semmle.label | Call indirection [string] |
|
||||
| test.cpp:41:13:41:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:41:18:41:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:41:18:41:23 | Load | semmle.label | Load |
|
||||
| test.cpp:42:13:42:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:42:18:42:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:42:18:42:23 | Load | semmle.label | Load |
|
||||
| test.cpp:44:13:44:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:44:18:44:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:44:18:44:23 | Load | semmle.label | Load |
|
||||
| test.cpp:45:13:45:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:45:18:45:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:45:18:45:23 | Load | semmle.label | Load |
|
||||
| test.cpp:48:17:48:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:48:22:48:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:48:22:48:27 | Load | semmle.label | Load |
|
||||
| test.cpp:52:17:52:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:52:22:52:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:52:22:52:27 | Load | semmle.label | Load |
|
||||
| test.cpp:56:17:56:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:56:22:56:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:56:22:56:27 | Load | semmle.label | Load |
|
||||
| test.cpp:60:17:60:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:60:22:60:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:60:22:60:27 | Load | semmle.label | Load |
|
||||
| test.cpp:64:17:64:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:64:22:64:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:64:22:64:27 | Load | semmle.label | Load |
|
||||
| test.cpp:68:17:68:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:68:22:68:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:68:22:68:27 | Load | semmle.label | Load |
|
||||
| test.cpp:72:17:72:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:72:22:72:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:72:22:72:27 | Load | semmle.label | Load |
|
||||
| test.cpp:76:17:76:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:76:22:76:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:76:22:76:27 | Load | semmle.label | Load |
|
||||
| test.cpp:80:17:80:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:80:22:80:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:80:22:80:27 | Load | semmle.label | Load |
|
||||
| test.cpp:84:17:84:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:84:22:84:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:84:22:84:27 | Load | semmle.label | Load |
|
||||
| test.cpp:88:11:88:30 | VariableAddress indirection [string] | semmle.label | VariableAddress indirection [string] |
|
||||
| test.cpp:90:5:90:34 | Store | semmle.label | Store |
|
||||
| test.cpp:90:10:90:15 | Load indirection [post update] [string] | semmle.label | Load indirection [post update] [string] |
|
||||
| test.cpp:90:19:90:24 | call to malloc | semmle.label | call to malloc |
|
||||
| test.cpp:96:21:96:40 | Call indirection [string] | semmle.label | Call indirection [string] |
|
||||
| test.cpp:98:13:98:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:98:18:98:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:98:18:98:23 | Load | semmle.label | Load |
|
||||
| test.cpp:99:13:99:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:99:18:99:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:99:18:99:23 | Load | semmle.label | Load |
|
||||
| test.cpp:101:13:101:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:101:18:101:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:101:18:101:23 | Load | semmle.label | Load |
|
||||
| test.cpp:102:13:102:15 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:102:18:102:23 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:102:18:102:23 | Load | semmle.label | Load |
|
||||
| test.cpp:105:17:105:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:105:22:105:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:105:22:105:27 | Load | semmle.label | Load |
|
||||
| test.cpp:109:17:109:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:109:22:109:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:109:22:109:27 | Load | semmle.label | Load |
|
||||
| test.cpp:113:17:113:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:113:22:113:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:113:22:113:27 | Load | semmle.label | Load |
|
||||
| test.cpp:117:17:117:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:117:22:117:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:117:22:117:27 | Load | semmle.label | Load |
|
||||
| test.cpp:121:17:121:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:121:22:121:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:121:22:121:27 | Load | semmle.label | Load |
|
||||
| test.cpp:125:17:125:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:125:22:125:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:125:22:125:27 | Load | semmle.label | Load |
|
||||
| test.cpp:129:17:129:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:129:22:129:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:129:22:129:27 | Load | semmle.label | Load |
|
||||
| test.cpp:133:17:133:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:133:22:133:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:133:22:133:27 | Load | semmle.label | Load |
|
||||
| test.cpp:137:17:137:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:137:22:137:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:137:22:137:27 | Load | semmle.label | Load |
|
||||
| test.cpp:141:17:141:19 | Load indirection [string] | semmle.label | Load indirection [string] |
|
||||
| test.cpp:141:22:141:27 | FieldAddress indirection | semmle.label | FieldAddress indirection |
|
||||
| test.cpp:141:22:141:27 | Load | semmle.label | Load |
|
||||
subpaths
|
||||
#select
|
||||
| test.cpp:26:18:26:23 | Load | test.cpp:18:19:18:24 | call to malloc | test.cpp:26:18:26:23 | Load | Overrunning write allocated at $@ bounded by $@. | test.cpp:18:19:18:24 | call to malloc | call to malloc | test.cpp:26:31:26:39 | Convert | Convert |
|
||||
| test.cpp:30:18:30:23 | Load | test.cpp:18:19:18:24 | call to malloc | test.cpp:30:18:30:23 | Load | Overrunning write allocated at $@ bounded by $@. | test.cpp:18:19:18:24 | call to malloc | call to malloc | test.cpp:30:31:30:39 | Convert | Convert |
|
||||
| test.cpp:26:18:26:23 | Load | test.cpp:18:19:18:24 | call to malloc | test.cpp:26:18:26:23 | Load | Overrunning write allocated at $@ bounded by $@. | test.cpp:18:19:18:24 | call to malloc | call to malloc | test.cpp:26:36:26:39 | Load | Load |
|
||||
| test.cpp:30:18:30:23 | Load | test.cpp:18:19:18:24 | call to malloc | test.cpp:30:18:30:23 | Load | Overrunning write allocated at $@ bounded by $@. | test.cpp:18:19:18:24 | call to malloc | call to malloc | test.cpp:30:36:30:39 | Load | Load |
|
||||
| test.cpp:41:18:41:23 | Load | test.cpp:18:19:18:24 | call to malloc | test.cpp:41:18:41:23 | Load | Overrunning write allocated at $@ bounded by $@. | test.cpp:18:19:18:24 | call to malloc | call to malloc | test.cpp:41:36:41:39 | Load | Load |
|
||||
|
|
|
@ -1,5 +1,5 @@
|
|||
|
||||
typedef unsigned long long size_t;
|
||||
typedef unsigned size_t;
|
||||
int sprintf(char *s, const char *format, ...);
|
||||
int snprintf(char *s, size_t n, const char *format, ...);
|
||||
int scanf(const char *format, ...);
|
||||
|
@ -10,7 +10,7 @@ char *strncpy(char *dst, const char *src, size_t n);
|
|||
typedef struct
|
||||
{
|
||||
char *string;
|
||||
int size;
|
||||
unsigned size;
|
||||
} string_t;
|
||||
|
||||
string_t *mk_string_t(int size) {
|
||||
|
@ -23,11 +23,11 @@ string_t *mk_string_t(int size) {
|
|||
void test1(int size, char *buf) {
|
||||
string_t *str = mk_string_t(size);
|
||||
|
||||
strncpy(str->string, buf, str->size);
|
||||
strncpy(str->string, buf, str->size); // GOOD [FALSE POSITIVE]
|
||||
}
|
||||
|
||||
void strncpy_wrapper(string_t *str, char *buf) {
|
||||
strncpy(str->string, buf, str->size);
|
||||
strncpy(str->string, buf, str->size); // GOOD [FALSE POSITIVE]
|
||||
}
|
||||
|
||||
void test2(int size, char *buf) {
|
||||
|
@ -35,3 +35,110 @@ void test2(int size, char *buf) {
|
|||
strncpy_wrapper(str, buf);
|
||||
}
|
||||
|
||||
void test3(unsigned size, char *buf, unsigned anotherSize) {
|
||||
string_t *str = mk_string_t(size);
|
||||
|
||||
strncpy(str->string, buf, str->size); // GOOD [FALSE POSITIVE]
|
||||
strncpy(str->string, buf, str->size + 1); // BAD [NOT DETECTED]
|
||||
|
||||
strncpy(str->string, buf, size); // GOOD
|
||||
strncpy(str->string, buf, size + 1); // BAD [NOT DETECTED]
|
||||
|
||||
if(anotherSize < str->size) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize < size) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize <= str->size) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize <= size) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize < str->size + 1) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize < size + 1) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize <= str->size + 1) {
|
||||
strncpy(str->string, buf, anotherSize); // BAD [NOT DETECTED]
|
||||
}
|
||||
|
||||
if(anotherSize <= size + 1) {
|
||||
strncpy(str->string, buf, anotherSize); // BAD [NOT DETECTED]
|
||||
}
|
||||
|
||||
if(anotherSize <= str->size + 2) {
|
||||
strncpy(str->string, buf, anotherSize); // BAD [NOT DETECTED]
|
||||
}
|
||||
|
||||
if(anotherSize <= size + 2) {
|
||||
strncpy(str->string, buf, anotherSize); // BAD [NOT DETECTED]
|
||||
}
|
||||
}
|
||||
|
||||
string_t *mk_string_t_plus_one(int size) {
|
||||
string_t *str = (string_t *) malloc(sizeof(string_t));
|
||||
str->string = malloc(size + 1);
|
||||
str->size = size + 1;
|
||||
return str;
|
||||
}
|
||||
|
||||
void test4(unsigned size, char *buf, unsigned anotherSize) {
|
||||
string_t *str = mk_string_t_plus_one(size);
|
||||
|
||||
strncpy(str->string, buf, str->size); // GOOD
|
||||
strncpy(str->string, buf, str->size + 1); // BAD [NOT DETECTED]
|
||||
|
||||
strncpy(str->string, buf, size); // GOOD
|
||||
strncpy(str->string, buf, size + 1); // GOOD
|
||||
|
||||
if(anotherSize < str->size) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize < size) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize <= str->size) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize <= size) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize < str->size + 1) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize < size + 1) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize <= str->size + 1) {
|
||||
strncpy(str->string, buf, anotherSize); // BAD [NOT DETECTED]
|
||||
}
|
||||
|
||||
if(anotherSize <= size + 1) {
|
||||
strncpy(str->string, buf, anotherSize); // GOOD
|
||||
}
|
||||
|
||||
if(anotherSize <= str->size + 2) {
|
||||
strncpy(str->string, buf, anotherSize); // BAD [NOT DETECTED]
|
||||
}
|
||||
|
||||
if(anotherSize <= size + 2) {
|
||||
strncpy(str->string, buf, anotherSize); // BAD [NOT DETECTED]
|
||||
}
|
||||
}
|
||||
|
||||
|
|
Загрузка…
Ссылка в новой задаче