-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Add a PR check to ensure query IDs are unique #11574
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
da1cdde to
9f10956
Compare
9f10956 to
2627632
Compare
|
QHelp previews: java/ql/src/experimental/Security/CWE/CWE-400/LocalThreadResourceAbuse.qhelpUncontrolled thread resource consumption from local input sourceThe RecommendationTo guard against this attack, consider specifying an upper range of allowed sleep time or adopting the producer/consumer design pattern with ExampleThe following example shows a bad situation and a good situation respectively. In the bad situation, a thread sleep time comes directly from user input. In the good situation, an upper range check on the maximum sleep time allowed is enforced. class SleepTest {
public void test(int userSuppliedWaitTime) throws Exception {
// BAD: no boundary check on wait time
Thread.sleep(userSuppliedWaitTime);
// GOOD: enforce an upper limit on wait time
if (userSuppliedWaitTime > 0 && userSuppliedWaitTime < 5000) {
Thread.sleep(userSuppliedWaitTime);
}
}
}References
|
|
@github/codeql-python The QHelp changes are failing for This seems genuine since the examples don't exist. Do we have some other examples we can use here? |
|
@tausbn I've renamed the Qhelp file as you suggested |
tausbn
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Python looks reasonable to me. 👍
aschackmull
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Java 👍
|
Thanks both! |
We distinguish queries in Code scanning by their ID, so it's important that each query has a unique ID. This PR adds a PR check to ensure that query IDs are unique, and fixes up duplicate query IDs for Java and Python.
For now, we limit our scope to just the duplicate IDs in
srcdirectories, which correspond to query packs. In the future, we may want to extend this to eliminate duplicate IDs in test packs too, but the changes involved there are more widespread, so let's break that out into a separate PR.