Skip to content

C++: Add a predicate for getting dataflow nodes whose value has been constant folded #13895

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 3 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -195,6 +195,44 @@ class Node extends TIRDataFlowNode {
*/
Expr asExpr() { result = this.(ExprNode).getExpr() }

/**
* Gets a constant that is used to compute this node's constant value.
*
* For example, `node.asFoldedConstant() = "1"` holds for the `node` that
* reprents the value `1 | MY_VALUE` in
* ```cpp
* enum Masks { MY_VALUE = 0x10 };
* ...
* int value = 1 | MY_VALUE;
* ```
*
* This predicate is useful when doing taint-tracking from all literal
* expressions with a specific value. If one were to use
* ```ql
* node.asExpr().getValue() = "1"
* ````
* in the above example to mark `1` as the source in a taint-tracking
* configuration, no node would be selected as a source because the value
* `1` has been folded into a constant that represents the value
* `1 | MY_VALUE`. However, using `node.asFoldedConstant() = "1"` would pick
* select the node for `1 | MY_VALUE` because a constant with the value `1`
* was part of the expression that was used to compute the value for the
* constant `1 | MY_VALUE`.
*
* Note: This predicate should not be used for _dataflow_ configurations
* since the the value returned by this predicate will not represent the
* runtime value of the underlying expression (since the expression has been
* constant folded). For such cases `node.asExpr().getValue()` should be used
* instead.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There's no (general) way to tell what operations were done to combine the constants at present, right? i.e. the | in 1 | MYVALUE.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not at the moment, no. We could of course do something more clever instead of using .getAChild*() (i.e., traverse the AST to find the set of operations and construct some useful type that gives this information), but I haven't yet seen a good reason to do this yet.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm happy to start with the simple solution that solves the problem. 👍

*/
string asFoldedConstant() {
this.asInstruction()
.(IntegerConstantInstruction)
.getUnconvertedResultExpression()
.getAChild*()
.getValue() = result
}

/**
* Gets the non-conversion expression that's indirectly tracked by this node
* under `index` number of indirections.
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
failures
testFailures
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
import TestUtilities.dataflow.FlowTestCommon
private import semmle.code.cpp.ir.IR
private import semmle.code.cpp.ir.dataflow.TaintTracking

/** Common data flow configuration to be used by tests. */
module TestFoldedConstantConfig implements DataFlow::ConfigSig {
predicate isSource(DataFlow::Node source) {
source.asFoldedConstant() = any(MacroInvocation mi).getExpr().getValue()
}

predicate isSink(DataFlow::Node sink) {
exists(FunctionCall call |
call.getTarget().getName() = "sink" and
sink.asExpr() = call.getAnArgument()
)
}
}

module TestFoldedConstant = TaintTracking::Global<TestFoldedConstantConfig>;

import MakeTest<IRFlowTest<TestFoldedConstant>>
28 changes: 28 additions & 0 deletions cpp/ql/test/library-tests/dataflow/folded-constant/test.cpp
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
enum Constants
{
ONE = 1,
TWO = 2,
LARGE = 0xff00,
};

#define SOURCE 1

void sink(int x);

void test_constants() {
sink(SOURCE | ONE); // $ ir
sink(SOURCE | TWO); // $ ir
sink(SOURCE | LARGE); // $ ir

int x1 = SOURCE | TWO;
sink(x1); // $ ir

int x2 = TWO | SOURCE;
sink(x2); // $ ir

int x3 = TWO | LARGE;
sink(x3); // clean

int x4 = ((SOURCE | ONE) | TWO) | LARGE;
sink(x4); // $ ir
}