Skip to content

Add CodeQL query to check for allocations not preceeded by ensure_free#2104

Draft
pguyot wants to merge 2 commits intoatomvm:mainfrom
pguyot:w07/add-codeql-allocation-without-ensure-free
Draft

Add CodeQL query to check for allocations not preceeded by ensure_free#2104
pguyot wants to merge 2 commits intoatomvm:mainfrom
pguyot:w07/add-codeql-allocation-without-ensure-free

Conversation

@pguyot
Copy link
Collaborator

@pguyot pguyot commented Feb 15, 2026

Continuation of

Fix several cases where this happened in nifs. Also add a NOLINT comment
for cases where the query is not smart enough to remove the couple of
false positives.

These changes are made under both the "Apache 2.0" and the "GNU Lesser General
Public License 2.1 or later" license terms (dual license).

SPDX-License-Identifier: Apache-2.0 OR LGPL-2.1-or-later

The query also checks redundant ensure_free calls, i.e. calls
followed by another call with no allocation in between.

Fix errors found by the query:
- Fix an insufficient ensure_free in `enif_make_resource_binary`
- Added a missing ensure_free in esp32 `dac_driver.c`
- Remove nine redundant ensure_free calls followed by `enif_make_resource`
  in `otp_ssl.c` and `otp_socket.c` and esp32 drivers
- Remove a redundant ensure_free call in `nif_erlang_fun_to_list`

Signed-off-by: Paul Guyot <pguyot@kallisys.net>
Fix several cases where this happened in nifs. Also add a NOLINT comment
for cases where the query is not smart enough to remove the couple of
false positives.

Signed-off-by: Paul Guyot <pguyot@kallisys.net>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant