Skip to content

Commit e13f93a

Browse files
authored
fix(capi): use as_ref() null-check idiom for error pointer deref in test (#2404)
Closes CodeQL rust/access-invalid-pointer #35. Before: test asserted `!error.is_null()` then performed raw deref `(*error).message`. CodeQL does not model `assert!` as a guard, flagged invalid-pointer deref. After: `error.as_ref().expect("ffi_boundary must set error").message`. Same semantics (aborts if null), no raw deref, idiom the query understands. Proof: `cargo fmt --check -p bashkit-capi` clean, `cargo clippy -p bashkit-capi --all-targets` 0 warnings, `cargo test -p bashkit-capi` green (1 + 19 passed). Note: alerts #9/#12/#13 (napi struct lines) and the 13 hard-coded-crypto test-key alerts triaged as false positives, no code change.
1 parent 6c3bd44 commit e13f93a

4 files changed

Lines changed: 11 additions & 9 deletions

File tree

‎Cargo.lock‎

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎crates/bashkit-capi/src/lib.rs‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -947,8 +947,10 @@ mod tests {
947947
});
948948

949949
assert_eq!(status, BashkitStatus::InternalError);
950-
assert!(!error.is_null());
951-
assert_eq!((*error).message, b"internal error");
950+
assert_eq!(
951+
error.as_ref().expect("ffi_boundary must set error").message,
952+
b"internal error"
953+
);
952954
bashkit_error_free(error);
953955
}
954956
}

‎crates/bashkit/fuzz/Cargo.lock‎

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎supply-chain/config.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1657,7 +1657,7 @@ version = "1.1.4"
16571657
criteria = "safe-to-deploy"
16581658

16591659
[[exemptions.rustls]]
1660-
version = "0.23.43"
1660+
version = "0.23.45"
16611661
criteria = "safe-to-deploy"
16621662

16631663
[[exemptions.rustls-native-certs]]

0 commit comments

Comments
 (0)