Affected rules
Description
RULE-0-0-1 reports plainly reachable statements as unreachable. The query does not use the standard reachable predicate; it defines its own reachability walk over BasicBlock.getAPredecessor():
predicate isReachable(BasicBlock bb) {
bb = any(Function f).getEntryPoint()
or
isReachable(bb.getAPredecessor())
or
... // special cases for &&/||, ?:, catch blocks, constexpr if
}
BasicBlock.getAPredecessor() is derived from successors_adapted , One pruning step, possiblePredecessor, removes the control-flow graph edge after a FunctionCall unless the callee is classified as potentiallyReturningFunction. That classification is itself defined recursively in terms of the adapted control-flow graph (reachableRecursive).
When this circular analysis fails to prove that a function returns the edge after the call is dropped, the rest of the function becomes "unreachable", and the function's own exit point is then considered unreachable too. The function is consequently treated as noreturn, so callers have everything after the call flagged as well. The error cascades across the translation unit.
Environment: CodeQL CLI 2.26.2, codeql/misra-cpp-coding-standards 2.62.0 (cpp-all 5.0.0), C++17.
Example
Five false positives on this self-contained file: the if in update() and every statement in run() after the call to update().
#include <unordered_map>
namespace detail {
struct Error {
Error() noexcept = default;
};
template <typename E>
struct unexpected {
E error;
explicit unexpected(E e) noexcept : error(e) {}
};
template <typename T, typename E>
struct expected {
T value_{};
E error_{};
bool has_value_ = true;
expected(T v) noexcept : value_(v), has_value_(true) {}
expected(unexpected<E> u) noexcept : error_(u.error), has_value_(false) {}
explicit operator bool() const noexcept { return has_value_; }
};
} // namespace detail
using Error = detail::Error;
using Unexpected = detail::unexpected<Error>;
template <typename T> using Result = detail::expected<T, Error>;
Result<int> update(const std::unordered_map<int, int>& keys) noexcept {
auto it = keys.find(0);
if (it == keys.end()) { // flagged as unreachable
return Result<int>{Unexpected{Error{}}};
}
return Result<int>{it->second};
}
void run() noexcept {
std::unordered_map<int, int> keys;
auto r = update(keys); // flagged as unreachable
if (r) { // flagged as unreachable
(void)0; // flagged as unreachable
}
int x = 42; // flagged as unreachable
(void)x;
}
Affected rules
RULE-0-0-1Description
RULE-0-0-1reports plainly reachable statements as unreachable. The query does not use the standardreachablepredicate; it defines its own reachability walk overBasicBlock.getAPredecessor():BasicBlock.getAPredecessor()is derived fromsuccessors_adapted, One pruning step,possiblePredecessor, removes the control-flow graph edge after aFunctionCallunless the callee is classified aspotentiallyReturningFunction. That classification is itself defined recursively in terms of the adapted control-flow graph (reachableRecursive).When this circular analysis fails to prove that a function returns the edge after the call is dropped, the rest of the function becomes "unreachable", and the function's own exit point is then considered unreachable too. The function is consequently treated as
noreturn, so callers have everything after the call flagged as well. The error cascades across the translation unit.Environment: CodeQL CLI 2.26.2,
codeql/misra-cpp-coding-standards2.62.0 (cpp-all5.0.0), C++17.Example
Five false positives on this self-contained file: the
ifinupdate()and every statement inrun()after the call toupdate().