Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
119 commits
Select commit Hold shift + click to select a range
57661d5
Update expected test results after frontend update
jketema Mar 6, 2025
6abda06
Update MISRA queries and tests after merging location tables
jketema Jun 27, 2025
57c4180
C++: accept new test results after QL changes
IdrissRio Jun 30, 2025
a3d85dd
Comvert ARR37-C to use the new dataflow library
jketema Jul 7, 2025
3f2ae9e
Conver ARR39-C to the new dataflow library
jketema Jul 7, 2025
46af73d
Convert ERR30-C to use the new dataflow library
jketema Jul 7, 2025
e2ac35d
Convert FIO45-C to use the new dataflow library
jketema Jul 7, 2025
43d5bf8
Convert EXP36-C to the new datafow library
jketema Jul 7, 2025
10b9266
Convert MSC33-C to the new dataflow library
jketema Jul 7, 2025
e0b7924
Convert MSC51-CPP to the new dataflow library
jketema Jul 7, 2025
b6c26ee
Convert CTR56-CPP to the new dataflow library
jketema Jul 7, 2025
c478ead
Conver M3-9-3 to use the new dataflow library
jketema Jul 7, 2025
0817197
Convert A9-3-1 to use the new dataflow library
jketema Jul 7, 2025
51295f1
Convert A27-0-4 to use the new dataflow library
jketema Jul 7, 2025
8933de9
Convert A5-0-4 to use the new dataflow library
jketema Jul 7, 2025
aa7d827
Update expected test results for MSC33-C
jketema Jul 7, 2025
f737a94
Create temporary copies of parts of the concurrency library
jketema Jul 7, 2025
f6c3c4c
Convert CON30-C to use the new dataflow library
jketema Jul 7, 2025
9e12e5e
Convert CON34-C to the new dataflow library
jketema Jul 8, 2025
ef96540
Move queries not depending on dataflow over to `ConcurrencyNew`
jketema Jul 8, 2025
cb6ab90
Convert UseOnlyArrayIndexingForPointerArithmetic to use the new dataf…
jketema Jul 8, 2025
30a3635
Convert StringNumberConversionMissingErrorCheck to use the new datafl…
jketema Jul 8, 2025
ce08d1e
Convert FgetsErrorManagement to use the new dataflow library
jketema Jul 8, 2025
88ef34f
Convert RULE-22-3 to use the new dataflow library
jketema Jul 8, 2025
fdf1923
Convert RULE-22-4 to use the new dataflow library
jketema Jul 8, 2025
8ea39d8
Convert A7-5-1 to use the new dataflow library
jketema Jul 8, 2025
b3cffdb
Convert DoNotSubtractPointersAddressingDifferentArrays to use new dat…
jketema Jul 8, 2025
0afdf32
Remove unused dataflow import from IOFstreamMissingPositioning
jketema Jul 8, 2025
241ec63
Convert DanglingCaptureWhenReturningLambdaObject to use new dataflow …
jketema Jul 8, 2025
5887113
Revert "Convert DanglingCaptureWhenReturningLambdaObject to use new d…
jketema Jul 8, 2025
5e3f1dc
Fix FIO40-C regression after incorrectly solving a merge conflict
jketema Jul 10, 2025
d997db1
Conver ARR32-C to use the new dataflow library
jketema Jul 10, 2025
fbb5d04
Convert DCL30-C to the new dataflow library
jketema Jul 10, 2025
6b8b5f5
Convert ERR32-C to use the new dataflow library
jketema Jul 10, 2025
9830abc
Convert ERR33-C to use the new dataflow library
jketema Jul 10, 2025
135cb7a
Convert EXP37-C to the new dataflow library
jketema Jul 10, 2025
bb5e033
Convert EXP40-C to the new dataflow library
jketema Jul 10, 2025
a5a1865
Convert FIO44-C to the new dataflow library
jketema Jul 10, 2025
3e69bf6
Convert MEM35-C to the new dataflow library
jketema Jul 10, 2025
ba281e2
Convert MEM36-C to the new dataflow library
jketema Jul 10, 2025
d385a76
Convert SIG30-C to the new dataflow library
jketema Jul 10, 2025
099f358
Convert SIG35-C to the new dataflow library
jketema Jul 10, 2025
2a8277c
Convert Signal library to the new data flow library
jketema Jul 10, 2025
69c6bf7
Convert RULE-13-2 to the new dataflow library
jketema Jul 11, 2025
9e8e429
Convert RULE-21-14 to the new dataflow library
jketema Jul 11, 2025
cee7cef
Convert RULE-22-7 to the new dataflow library
jketema Jul 11, 2025
fcbb620
Convert A13-1-3 to the new dataflow library
jketema Jul 11, 2025
def97cc
Convert A13-2-1 to the new dataflow library
jketema Jul 11, 2025
3b6a124
Convert A15-1-3 to the new dataflow library
jketema Jul 11, 2025
c06f22a
Address review comment
jketema Jul 11, 2025
1d15367
C++: Accept path changes caused by codeql#20040.
MathiasVP Jul 14, 2025
de0357a
Convert RULE-17-5 to the new dataflow library
jketema Jul 15, 2025
8a2f016
Convert A15-2-2 to use the new dataflow library
jketema Jul 15, 2025
bebac73
Convert A18-9-4 to use the new dataflow library
jketema Jul 15, 2025
c12d294
Convert A20-8-4 to use the new dataflow library
jketema Jul 15, 2025
2c4414d
Convert A5-1-7 to use the new dataflow library
jketema Jul 15, 2025
8dc6dcf
Convert A8-4-12 to use the new dataflow library
jketema Jul 15, 2025
447a3bb
Convert CTR52-CPP to the new dataflow library
jketema Jul 15, 2025
04da91f
Convert CTR53-CPP to the new dataflow library
jketema Jul 15, 2025
cc0d1c8
C++: Block flow into thread-specific storage creating functions (i.e.…
MathiasVP Jul 25, 2025
3a7a99b
C++: Accept test changes to another query.
MathiasVP Jul 25, 2025
88d909e
Convert `ThrowingOperatorNewReturnsNull` to the new dataflow library
jketema Aug 15, 2025
65cf74d
Convert `PredicateFunctionObjectsShouldNotBeMutable` to the new dataf…
jketema Aug 15, 2025
01841f3
Remove redundant dataflow import
jketema Aug 15, 2025
15eef22
Convert `OnlyFreeMemoryAllocatedDynamicallyShared` to the new dataflo…
jketema Aug 15, 2025
68956c9
Convert `InvalidatedEnvStringPointers` to the new dataflow library
jketema Aug 15, 2025
635eca0
Convert `FunctionErroneousReturnValueNotTested` to the new dataflow l…
jketema Aug 18, 2025
76642a8
Update `DoNotPassAliasedPointerToRestrictQualifiedParamShared` to the…
jketema Aug 18, 2025
6edece6
Convert M9-3-1 to the new dataflow library
jketema Aug 19, 2025
5b03559
Convert A8-4-9 to the new dataflow library
jketema Aug 19, 2025
aa1c3af
Conver A8-4-11 to the new dataflow library
jketema Aug 19, 2025
0ae0087
Convert STR31-C to the new dataflow library
jketema Aug 19, 2025
d3dbc96
Convert `FileStreams.qll` to the new dataflow library
jketema Aug 19, 2025
404692b
Convert `DoNotAccessAClosedFile` to the new dataflow library
jketema Aug 19, 2025
8d8cedc
Update `OwnedPointerValueStoredInUnrelatedSmartPointer` to the new da…
jketema Aug 21, 2025
75c5263
Update `MovedFromObjectsUnspecifiedState` to the new dataflow library
jketema Aug 21, 2025
6fc0b5e
Update `DoNotUseRelationalOperatorsWithDifferingArrays` to the new da…
jketema Aug 21, 2025
b6d3b33
Convert `DanglingCaptureWhenReturningLambdaObject` to the new dataflo…
jketema Aug 21, 2025
890ee51
Update `DanglingCaptureWhenMovingLambdaObject` to the new dataflow li…
jketema Aug 21, 2025
318498a
Update `ConstLikeReturnValue` to the new dataflow library
jketema Aug 21, 2025
35fbfad
Remove redundant dataflow import
jketema Aug 21, 2025
90496ba
Convert `BasicStringMayNotBeNullTerminated` to the new dataflow library
jketema Aug 21, 2025
a9c527a
C++: Fix up queries after github/codeql#20485.
MathiasVP Sep 18, 2025
e30f5e7
C++: Fix queries I forgot after merging github/codeql#20485.
MathiasVP Oct 2, 2025
164d2f4
C++: Accept line number changes in .expected file.
MathiasVP Oct 2, 2025
01898e9
Update expected test results
jketema Nov 8, 2025
bee8bd0
Update expected test results after frontend update
jketema Nov 27, 2025
22438a2
Fix test formatting
jketema Jan 8, 2026
cad5be0
Floating point decimal support has been removed from CodeQL
jketema Jan 6, 2026
e92d9c5
C++: Accept test changes after github/codeql#21313.
MathiasVP Feb 11, 2026
7f71c7b
C++: Fix Copilot comments.
MathiasVP Feb 11, 2026
d77616e
Revert "C++: Accept test changes after github/codeql#21313."
paldepind Feb 16, 2026
a79c12d
Update test expectations after switch to SoftFloat library in the ext…
jketema Feb 17, 2026
e116488
Revert "Merge pull request #1042 from jketema/jketema/softfloat"
jketema Feb 24, 2026
b318aa6
Update expected test results
jketema Mar 30, 2026
d483765
Reapply "Merge pull request #1042 from jketema/jketema/softfloat"
jketema Apr 24, 2026
aab3b2d
Update expected test results
jketema May 19, 2026
e2495c8
Update references to deprecated classes
jketema May 19, 2026
a42dd07
Update references to deprecated classes
jketema May 26, 2026
d66ec8d
Use the new dataflow module without affecting any tested behavior (#1…
mbaluda Jun 30, 2026
57a9833
Merge branch 'main' into mbaluda-next-merge
mbaluda Aug 17, 2026
e939643
Update CodeQL to 2.23.9
mbaluda Aug 17, 2026
d73042f
Update CodeQL dependencies to latest versions across multiple modules
mbaluda Aug 17, 2026
2521132
Update CodeQL dependencies to latest versions in multiple lock files
mbaluda Aug 17, 2026
46bc06d
Update SsaInternals usage in PointerArithmeticFormsAnInvalidPointer
mbaluda Aug 17, 2026
b8ba0ec
Fix PossibleDataRaceBetweenThreadsConfig
mbaluda Aug 17, 2026
2a14a02
Fix VariableLengthArraySizeNotInValidRange
mbaluda Aug 18, 2026
aaa8702
Add change note for ARR32-C query update
Copilot Aug 18, 2026
95ef81f
Update expected results for various tests
mbaluda Aug 18, 2026
5c60c39
Fix test formatting
mbaluda Aug 18, 2026
cbb457c
Address review comments
mbaluda Aug 28, 2026
782f8b0
Fix formatting
mbaluda Aug 28, 2026
50333b2
Merge branch 'main' into mbaluda-next-merge
mbaluda Aug 28, 2026
5e33e2d
Remove outdated change notes for ARR32-C and CPP upgrade regressions
mbaluda Aug 28, 2026
97181ce
Add change notes for recent rule fixes and false positive/negative co…
mbaluda Aug 28, 2026
3e41b11
Update change notes to reflect CodeQL upgrade
mbaluda Aug 28, 2026
d2c78ab
Merge branch 'main' into mbaluda-next-merge
mbaluda Sep 2, 2026
aaabfc3
Merge branch 'main' into mbaluda-next-merge
mbaluda Sep 21, 2026
cd36b7f
fix OutOfBounds behavior with new dataflow
mbaluda Sep 23, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@
import cpp
import codingstandards.c.cert
import codingstandards.cpp.SideEffect
import semmle.code.cpp.dataflow.TaintTracking
import semmle.code.cpp.dataflow.new.TaintTracking
import semmle.code.cpp.valuenumbering.GlobalValueNumbering

/** Holds if the function's return value is derived from the `AliasParamter` p. */
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,13 @@
| test.c:45:17:45:30 | ... + ... | Buffer may access up to offset 101*1 which is greater than the fixed size 100 of the $@. | test.c:45:17:45:22 | buffer | buffer |
| test.c:55:5:55:13 | ... - ... | Buffer access may be to a negative index in the buffer. | test.c:55:5:55:9 | ptr16 | buffer |
| test.c:57:5:57:14 | ... + ... | Buffer accesses offset 22 which is greater than the fixed size 20 of the $@. | test.c:57:5:57:9 | ptr16 | buffer |
| test.c:58:5:58:14 | ... - ... | Buffer access may be to a negative index in the buffer. | test.c:55:5:55:9 | ptr16 | buffer |
| test.c:58:5:58:14 | ... - ... | Buffer access may be to a negative index in the buffer. | test.c:56:5:56:9 | ptr16 | buffer |
| test.c:58:5:58:14 | ... - ... | Buffer access may be to a negative index in the buffer. | test.c:57:5:57:9 | ptr16 | buffer |
| test.c:58:5:58:14 | ... - ... | Buffer access may be to a negative index in the buffer. | test.c:58:5:58:9 | ptr16 | buffer |
| test.c:63:3:63:9 | access to array | Buffer access may be to a negative index in the buffer. | test.c:63:3:63:5 | arr | buffer |
| test.c:65:3:65:9 | access to array | Buffer accesses offset 44 which is greater than the fixed size 40 of the $@. | test.c:65:3:65:5 | arr | buffer |
| test.c:66:3:66:10 | access to array | Buffer access may be to a negative index in the buffer. | test.c:63:3:63:5 | arr | buffer |
| test.c:66:3:66:10 | access to array | Buffer access may be to a negative index in the buffer. | test.c:64:3:64:5 | arr | buffer |
| test.c:66:3:66:10 | access to array | Buffer access may be to a negative index in the buffer. | test.c:65:3:65:5 | arr | buffer |
| test.c:66:3:66:10 | access to array | Buffer access may be to a negative index in the buffer. | test.c:66:3:66:5 | arr | buffer |
Original file line number Diff line number Diff line change
@@ -1,25 +1 @@
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:28,31-39)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:28,59-67)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:31,33-41)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:31,57-65)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:35,33-41)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:35,59-67)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:44,5-13)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:44,25-33)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:44,53-61)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:47,31-39)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:47,57-65)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:56,31-39)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:56,55-63)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:63,31-39)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:63,57-65)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:75,31-39)
WARNING: module 'DataFlow' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:75,55-63)
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:28,5-18)
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:31,7-20)
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:35,7-20)
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:47,5-18)
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:56,5-18)
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:63,5-18)
WARNING: module 'TaintTracking' has been deprecated and may be removed in future (DependenceOnOrderOfFunctionArgumentsForSideEffects.ql:75,5-18)
| test.c:20:3:20:4 | call to f1 | Depending on the order of evaluation for the arguments $@ and $@ for side effects on shared state is unspecified and can result in unexpected behavior. | test.c:20:6:20:7 | call to f2 | call to f2 | test.c:20:12:20:13 | call to f3 | call to f3 |
82 changes: 45 additions & 37 deletions c/common/src/codingstandards/c/OutOfBounds.qll
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,6 @@ import codingstandards.cpp.Allocations
import codingstandards.cpp.Overflow
import codingstandards.cpp.PossiblyUnsafeStringOperation
import codingstandards.cpp.SimpleRangeAnalysisCustomizations
private import semmle.code.cpp.dataflow.DataFlow
import semmle.code.cpp.valuenumbering.GlobalValueNumbering

module OOB {
Expand Down Expand Up @@ -380,8 +379,13 @@ module OOB {
StrncatLibraryFunction() { this.getName() = getNameOrInternalName(["strncat", "wcsncat"]) }

override predicate getALengthParameterIndex(int i) {
// `strncat` and `wcsncat` exclude the size of a null terminator
i = 2
// The source need not contain a null terminator within the first `n` characters.
none()
}

override predicate getANullTerminatedParameterIndex(int i) {
// The destination must be null-terminated.
i = 0
}
}

Expand Down Expand Up @@ -645,42 +649,46 @@ module OOB {
}

/**
* A class for reasoning about the offset of a variable from the original value flowing to it
* as a result of arithmetic or pointer arithmetic expressions.
* Gets the offset of `expr` from `underlyingBase` due to arithmetic or pointer arithmetic.
*
* `underlyingBase` may be the arithmetic operand's base expression or `expr` itself, allowing
* callers to use whichever dataflow node is available.
*/
bindingset[expr]
private int getArithmeticOffsetValue(Expr expr, Expr base) {
result = getMinStatedValue(expr.(PointerArithmeticExpr).getOperand()) and
base = expr.(PointerArithmeticExpr).getPointer()
or
// &(array[index]) expressions
result =
getMinStatedValue(expr.(AddressOfExpr).getOperand().(PointerArithmeticExpr).getOperand()) and
base = expr.(AddressOfExpr).getOperand().(PointerArithmeticExpr).getPointer()
or
result = getMinStatedValue(expr.(AddExpr).getRightOperand()) and
base = expr.(AddExpr).getLeftOperand()
or
result = -getMinStatedValue(expr.(SubExpr).getRightOperand()) and
base = expr.(SubExpr).getLeftOperand()
or
expr instanceof IncrementOperation and
result = 1 and
base = expr.(IncrementOperation).getOperand()
or
expr instanceof DecrementOperation and
result = -1 and
base = expr.(DecrementOperation).getOperand()
or
// fall-back if `expr` is not an arithmetic or pointer arithmetic expression
not expr instanceof PointerArithmeticExpr and
not expr.(AddressOfExpr).getOperand() instanceof PointerArithmeticExpr and
not expr instanceof AddExpr and
not expr instanceof SubExpr and
not expr instanceof IncrementOperation and
not expr instanceof DecrementOperation and
base = expr and
result = 0
private int getArithmeticOffsetValue(Expr expr, Expr underlyingBase) {
exists(Expr base | underlyingBase = [base, expr] |
result = getMinStatedValue(expr.(PointerArithmeticExpr).getOperand()) and
base = expr.(PointerArithmeticExpr).getPointer()
or
// &(array[index]) expressions
result =
getMinStatedValue(expr.(AddressOfExpr).getOperand().(PointerArithmeticExpr).getOperand()) and
base = expr.(AddressOfExpr).getOperand().(PointerArithmeticExpr).getPointer()
or
result = getMinStatedValue(expr.(AddExpr).getRightOperand()) and
base = expr.(AddExpr).getLeftOperand()
or
result = -getMinStatedValue(expr.(SubExpr).getRightOperand()) and
base = expr.(SubExpr).getLeftOperand()
or
expr instanceof IncrementOperation and
result = 1 and
base = expr.(IncrementOperation).getOperand()
or
expr instanceof DecrementOperation and
result = -1 and
base = expr.(DecrementOperation).getOperand()
or
// fall-back if `expr` is not an arithmetic or pointer arithmetic expression
not expr instanceof PointerArithmeticExpr and
not expr.(AddressOfExpr).getOperand() instanceof PointerArithmeticExpr and
not expr instanceof AddExpr and
not expr instanceof SubExpr and
not expr instanceof IncrementOperation and
not expr instanceof DecrementOperation and
base = expr and
result = 0
)
}

private int constOrZero(Expr e) {
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
problems
| test.c:11:7:11:12 | * ... | test.c:18:16:18:21 | call to getenv | test.c:11:7:11:12 | * ... | The object returned by the function getenv should not be modified. |
| test.c:11:8:11:12 | c_str | test.c:18:16:18:21 | call to getenv | test.c:11:7:11:12 | * ... | The object returned by the function getenv should not be modified. |
| test.c:67:5:67:9 | conv4 | test.c:64:11:64:20 | call to localeconv | test.c:67:5:67:9 | conv4 | The object returned by the function localeconv should not be modified. |
| test.c:76:5:76:8 | conv | test.c:72:25:72:34 | call to localeconv | test.c:76:5:76:8 | conv | The object returned by the function localeconv should not be modified. |
Expand Down
4 changes: 3 additions & 1 deletion c/misra/src/rules/RULE-14-3/ControllingExprInvariant.ql
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,9 @@ where
conditionAlwaysFalse(expr) and
not (
getEssentialTypeCategory(getEssentialType(expr)) instanceof EssentiallyBooleanType and
expr.getValue() = "0"
expr.getValue() = "0" and
// Only apply to expressions that do not reference variables.
not exists(VariableAccess va | va = expr.getAChild*())
)
or
conditionAlwaysTrue(expr) and
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,8 @@
| test.c:16:9:16:13 | ... > ... | Controlling expression in if statement has an invariant value. |
| test.c:20:20:20:24 | ... < ... | Controlling expression in loop statement has an invariant value. |
| test.c:27:10:27:14 | ... < ... | Controlling expression in loop statement has an invariant value. |
| test.c:37:3:37:6 | 1 | Controlling expression in conditional statement has an invariant value. |
| test.c:38:3:38:3 | 1 | Controlling expression in conditional statement has an invariant value. |
| test.c:45:10:45:26 | ... && ... | Controlling expression in loop statement has an invariant value. |
| test.c:35:12:35:12 | 0 | Controlling expression in loop statement has an invariant value. |
| test.c:39:3:39:6 | 1 | Controlling expression in conditional statement has an invariant value. |
| test.c:40:3:40:3 | 1 | Controlling expression in conditional statement has an invariant value. |
| test.c:47:10:47:26 | ... && ... | Controlling expression in loop statement has an invariant value. |
| test.c:49:10:49:21 | ... && ... | Controlling expression in loop statement has an invariant value. |
4 changes: 4 additions & 0 deletions c/misra/test/rules/RULE-14-3/test.c
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,8 @@ void f3() {
void f4() {
do {
} while (0u == 1u); // COMPLIANT - by exception 2
do {
} while (0); // NON_COMPLIANT - a bare literal `0` is not essentially Boolean
}

void f5(bool b1) {
Expand All @@ -44,4 +46,6 @@ void f6(int p1) {
}
while (1 == 0 && p1 > 12) { // NON_COMPLIANT
}
while (0 && p1 > 12) { // NON_COMPLIANT
}
}
8 changes: 7 additions & 1 deletion c/misra/test/rules/RULE-21-18/test.c
Original file line number Diff line number Diff line change
Expand Up @@ -103,4 +103,10 @@ void test(void) {
strxfrm(buf + 1, buf2,
sizeof(buf) - 1); // NON_COMPLIANT - not null-terminated
}
}
}

void test_strncat_bounded_source(void) {
char destination[2] = {0};
char source[1] = {'x'};
strncat(destination, source, 1); // COMPLIANT
}
9 changes: 9 additions & 0 deletions change_notes/2026-08-28-cpp-all-upgrade-result-changes.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
- Upgraded CodeQL to v2.23.9, updating `codeql/cpp-all` and related dependencies.
- `RULE-1-2` - `LanguageExtensionsShouldNotBeUsed.ql`: fixed a false negative where `_Decimal32`,
`_Decimal64` and `_Decimal128` declarations were no longer reported as compiler extensions.
- `ENV30-C`, `RULE-21-19`, `RULE-25-5-2`: fixed a duplicate alert reported for the same pointer
write.
- `INT31-C` - `IntegerConversionCausesDataLoss.ql`: fixed a false positive on the standard-permitted
`(time_t)-1` conversion.
- `RULE-14-3` - `ControllingExprInvariant.ql`: fixed a false negative where a loop's compound
controlling expression that always evaluates to false was incorrectly permitted.
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,6 @@
import cpp
import codingstandards.cpp.cert
import codingstandards.cpp.SideEffect
import semmle.code.cpp.dataflow.DataFlow
import semmle.code.cpp.dataflow.TaintTracking
import semmle.code.cpp.valuenumbering.GlobalValueNumbering

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
import cpp
import codingstandards.cpp.cert
import semmle.code.cpp.controlflow.Guards
import semmle.code.cpp.dataflow.DataFlow
import semmle.code.cpp.dataflow.new.DataFlow
import codingstandards.cpp.exceptions.ExceptionSpecifications

/**
Expand Down
Loading
Loading