Files
trailofbits-skills/plugins/c-review/prompts/general/use-after-free-finder.md
T
Paweł Płatek 870955f1af C review (#156)
* init c review

* lsp

* agents -> prompts

* wip

* add windows, update judges

* improve

* upgrade

* size update

* rm toon format, improve workflow, cluster agents/prompts by issue type, improve prompt cache

* improve general workflow, fix bugs

* sarif via script, cluster manifest

* fix bugs

* fix workflow2

* workflow updates

* more fixes

* more fixes

* improvements

* update readme

* update codeowners

* update codeowners2

* fix small inconsistencies

* Address review feedback on c-review plugin

Critical:
- Move SKILL.md into named skill subdirectory (plugins/c-review/skills/c-review/)
  so plugin discovery and the Codex validator find it; add .codex/skills/c-review
  symlink.
- Convert allowed-tools in SKILL.md from YAML list to space-delimited string
  (spec compliance per #139).
- Fix parse_scalar in generate_sarif.py to respect quoted strings when splitting
  inline lists; ["a,b", c] no longer corrupts to ['"a', 'b"', 'c'].
- Fix location_parts trailing-colon handling so 'src/foo.c:' resolves to
  ('src/foo.c', 1) instead of keeping the colon in the filename.

Important:
- Convert agent tools: from YAML list to comma-separated string in worker,
  dedup-judge, fp-judge.
- Refactor build_run_plan.py main() (131 → 77 lines) by extracting
  _validate_run_inputs / _render_workers / _print_summary helpers.
- Fix ty possibly-missing-attribute warning by typing workers list explicitly.
- Add PEP 723 inline metadata + plugins/c-review/scripts/pyproject.toml.
- Rewrite SKILL.md description as scenario-based; add When to Use /
  When NOT to Use section headers.
- Add Usage section to README.
- Resolve Tier 2 contradiction in dedup-judge: unparseable/multi findings
  now skip Tier 2 and go straight to Tier 3.
- Standardize placeholder convention in fp-judge ({var} not <var>).
- Fix "Widthness Overflows" → "Width Truncation" in integer-overflow-finder.
- Standardize "Bug Patterns to Find" heading in signal-handler and
  thread-safety finders.
- Replace ls -1 glob in worker shard-write with find for shell portability.
- Bump version 1.1.0 → 1.1.1 in plugin.json + marketplace.json.

Verification: codex validator passes (73 plugin skills); ruff + ty clean;
main() 77 lines (limit 100); SARIF generator runtime tests pass; end-to-end
build_run_plan.py produces all 11 clusters with cache primer.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* Address claude[bot] review feedback on c-review

- Phase 1 is_posix/is_windows probes in SKILL.md now include C++ extensions
  (.cpp, .cxx, .cc, .hpp, .hh) in their --include lists. A pure C++ POSIX
  daemon was silently dropping ~17 POSIX-gated passes plus all is_windows
  clusters because pthread.h / windows.h includes only in .cpp/.hpp files
  failed both --include='*.c' --include='*.h' filters.
- generate_sarif.py informationUri points at trailofbits/skills (the actual
  repo) instead of trailofbits/tob-skills (404).
- CODEOWNERS: add @dguido co-owner to /plugins/c-review/ and move it to the
  top of the c* alphabetical group (- < l < o < u under ASCII collation).
- README.md: move c-review row after burpsuite-project-parser (b < c).
- Bump version 1.1.1 → 1.1.2.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Dan Guido <dan@trailofbits.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-03 15:59:55 -04:00

2.1 KiB

name, description
name description
use-after-free-finder Detects use-after-free and double-free bugs

Finding ID Prefix: UAF (e.g., UAF-001, UAF-002)

Bug Patterns to Find:

  1. Classic Use-After-Free

    • Memory freed, then accessed through stale pointer
    • Multiple shared_ptr to same object with incorrect refcount
  2. Use After Scope (Dangling Pointers)

    • Heap structures storing pointers to stack variables
    • Returning pointer to local variable
    • Capturing local by reference in escaping lambda
  3. Use After Return

    • return string("").c_str() - buffer destroyed on return
    • Returning pointer to temporary object
  4. Use After Close

    • File descriptor reused after close
    • Handle accessed after release
  5. Double Free

    • Same pointer freed twice
    • Freeing in destructor and manually
  6. Arbitrary Pointer Free

    • Freeing non-heap memory
    • Freeing uninitialized pointer
  7. Incorrect Refcounts

    • Refcount incremented incorrectly
    • Object not freed when refcount hits zero
  8. Partial Free

    • Struct field freed but struct not
    • Container freed but elements not
  9. Library Function Misuse

    • OpenSSL BN_CTX_start without BN_CTX_end
    • Other allocator/deallocator mismatches

Common False Positives to Avoid:

  • Pointer reassigned before use: If pointer is set to new allocation after free, not UAF
  • Pointer set to NULL after free: Defensive coding; subsequent NULL check prevents use
  • Smart pointer managed lifetime: unique_ptr and properly used shared_ptr handle lifetime
  • Pool allocators: Object returned to pool, then same memory reused - intentional, not UAF
  • Realloc success path: ptr = realloc(ptr, size) - old ptr invalid only if realloc succeeds
  • Static/global lifetime: Pointers to static storage don't become dangling at scope exit
  • Reference counting verified: If refcount is checked and correct, not a real UAF

Search Patterns:

free\s*\(|delete\s+|delete\s*\[
shared_ptr|unique_ptr|weak_ptr
->|\.get\(\)|\.release\(\)
return.*\.c_str\(\)|return.*\.data\(\)
close\s*\(|fclose\s*\(