Sitelet https://web.archive.org/web/20240111220311/https://github.com/github/codeql/issues/14899
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

General issue Python:Unable to recognize calling a method through an instance member of a class #14899

Open
luke10481 opened this issue Nov 23, 2023 · 5 comments
Labels
acknowledged GitHub staff acknowledges this issue Python question Further information is requested

Comments

@luke10481
Copy link

luke10481 commented Nov 23, 2023 •

when evaluate """private API::Node connection()""", the query result should find """self.orm.connection()""".But the query result is none

private API::Node dbClient() {
    result = API::moduleImport("dbutils").getMember("pooled_db").getMember("PooledDB").getReturn()
  }

  private API::Node connection() {
    result = dbClient().getMember("connection").getReturn()
  }

python demo here

import flask
import pymysql
from flask import request
from dbutils.pooled_db import PooledDB

app = flask.Flask(__name__)

class Database:
    def __init__(self):
        self.orm = self.dbpool()

    def dbpool(self):
        pool = PooledDB(
            creator=pymysql
        )
        return pool

    def conn(self):
        self.orm.connection()

@app.route('/search')
def search():
    query = request.args.get('query')
    database = Database()
    database.conn()
    database.orm.connection()
    return f"Search query: {query}"

if __name__ == '__main__':
    app.run()
@luke10481 luke10481 added the question Further information is requested label Nov 23, 2023
@luke10481 luke10481 changed the title General issue Unable to recognize calling a method through an instance member of a class General issue Python:Unable to recognize calling a method through an instance member of a class Nov 23, 2023
@MathiasVP
Copy link
Contributor

Hi @luke10481,

Can you quick-eval any of the sub-expressions to figure out where you lose your result? Here is a couple of questions I'd ask if I were to debug this:

  • Does quick-evaluation of the dbClient predicate give any results?
    • If yes: Does dbClient().getMember("connection") give any results?
    • If no: Does quick-evaluation of API::moduleImport("dbutils") give any results?

By quick-eval'ing iteratively larger sub expressions you can investigate which expression is causing the full evaluation to give no results.

@luke10481
Copy link
Author

Hi @luke10481,

Can you quick-eval any of the sub-expressions to figure out where you lose your result? Here is a couple of questions I'd ask if I were to debug this:

  • Does quick-evaluation of the dbClient predicate give any results?

    • If yes: Does dbClient().getMember("connection") give any results?
    • If no: Does quick-evaluation of API::moduleImport("dbutils") give any results?

By quick-eval'ing iteratively larger sub expressions you can investigate which expression is causing the full evaluation to give no results.

My test result is here.After I run quick evaluation:connection.It should display three result.But just one result.
image

image

If the connection() is in function,but not in class.That's no problem.
image

@MathiasVP
Copy link
Contributor

Thanks for those screenshots 🙇.

I talked with the Python team, and they said that they will investigate this issue more closely.

Will make sure to keep you updated!

@luke10481
Copy link
Author

Can this problem be solved through the API of codeql-python now? Do I need to wait for you to fix it? This problem will lead to some vulnerabilities that cannot be discovered.

@sidshank
Copy link
Contributor

sidshank commented Jan 2, 2024

Hi @luke10481 👋 My apologies for the delayed response. The issue you have encountered here is a known limitation in Python CodeQL analysis. We will take your report into account as we prioritize and act on this gap. I am not aware of any workarounds you could employ, but now that we've had some time to consider the issue, I'll check again with the team and get back to you here.

@sidshank sidshank added the acknowledged GitHub staff acknowledges this issue label Jan 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
acknowledged GitHub staff acknowledges this issue Python question Further information is requested
Projects
None yet
Development

No branches or pull requests

6 participants
@RasmusWL @sidshank @MathiasVP @luke10481 and others