From c002b1151d3dfcd029c0cbfcadd6641592bca0ac Mon Sep 17 00:00:00 2001 From: ChargingFoxSec Date: Sat, 6 Jun 2026 07:39:33 +0000 Subject: [PATCH] fix: suppress side-effect-free strict equality reports --- .../statements/incorrect_strict_equality.py | 11 ++++++ ...35_incorrect_equality_view_pure_sol__0.txt | 3 ++ .../0.8.35/incorrect_equality_view_pure.sol | 32 ++++++++++++++++++ ...ncorrect_equality_view_pure.sol-0.8.35.zip | Bin 0 -> 4185 bytes tests/e2e/detectors/test_detectors.py | 5 +++ 5 files changed, 51 insertions(+) create mode 100644 tests/e2e/detectors/snapshots/detectors__detector_IncorrectStrictEquality_0_8_35_incorrect_equality_view_pure_sol__0.txt create mode 100644 tests/e2e/detectors/test_data/incorrect-equality/0.8.35/incorrect_equality_view_pure.sol create mode 100644 tests/e2e/detectors/test_data/incorrect-equality/0.8.35/incorrect_equality_view_pure.sol-0.8.35.zip diff --git a/slither/detectors/statements/incorrect_strict_equality.py b/slither/detectors/statements/incorrect_strict_equality.py index 85b3b1195a..f1e2dcd7a5 100644 --- a/slither/detectors/statements/incorrect_strict_equality.py +++ b/slither/detectors/statements/incorrect_strict_equality.py @@ -105,6 +105,15 @@ def is_any_tainted( is_dependent_ssa(var, taint, function.contract) for var in variables for taint in taints ) + @staticmethod + def is_side_effect_free_view_or_pure(func: Function) -> bool: + if not (func.view or func.pure): + return False + + return not any( + not (caller.view or caller.pure) for caller in func.all_reachable_from_functions + ) + def taint_balance_equalities( self, functions: list[FunctionContract | Any] ) -> list[LocalIRVariable | TemporaryVariableSSA | Any]: @@ -148,6 +157,8 @@ def tainted_equality_nodes( # Disable the detector on top level function until we have good taint on those if isinstance(func, FunctionTopLevel): continue + if self.is_side_effect_free_view_or_pure(func): + continue for node in func.nodes: for ir in node.irs_ssa: # Filter to only tainted equality (==) comparisons diff --git a/tests/e2e/detectors/snapshots/detectors__detector_IncorrectStrictEquality_0_8_35_incorrect_equality_view_pure_sol__0.txt b/tests/e2e/detectors/snapshots/detectors__detector_IncorrectStrictEquality_0_8_35_incorrect_equality_view_pure_sol__0.txt new file mode 100644 index 0000000000..135e821f56 --- /dev/null +++ b/tests/e2e/detectors/snapshots/detectors__detector_IncorrectStrictEquality_0_8_35_incorrect_equality_view_pure_sol__0.txt @@ -0,0 +1,3 @@ +ViewPureStrictEquality._isDeadline() (tests/e2e/detectors/test_data/incorrect-equality/0.8.35/incorrect_equality_view_pure.sol#23-25) uses a dangerous strict equality: + - block.timestamp == deadline (tests/e2e/detectors/test_data/incorrect-equality/0.8.35/incorrect_equality_view_pure.sol#24) + diff --git a/tests/e2e/detectors/test_data/incorrect-equality/0.8.35/incorrect_equality_view_pure.sol b/tests/e2e/detectors/test_data/incorrect-equality/0.8.35/incorrect_equality_view_pure.sol new file mode 100644 index 0000000000..4ccb0e1bcd --- /dev/null +++ b/tests/e2e/detectors/test_data/incorrect-equality/0.8.35/incorrect_equality_view_pure.sol @@ -0,0 +1,32 @@ +contract ViewPureStrictEquality { + uint256 public immutable deployBlock; + uint256 public deadline; + uint256 public releases; + + constructor(uint256 deadline_) { + deployBlock = block.number; + deadline = deadline_; + } + + function isDeployBlockExternal() external view returns (bool) { + return block.number == deployBlock; + } + + function isDeployBlockPublic() public view returns (bool) { + return block.number == deployBlock; + } + + function isZeroPure(uint256 value) public pure returns (bool) { + return value == 0; + } + + function _isDeadline() internal view returns (bool) { + return block.timestamp == deadline; + } + + function releaseIfDeadline() external { + if (_isDeadline()) { + releases += 1; + } + } +} diff --git a/tests/e2e/detectors/test_data/incorrect-equality/0.8.35/incorrect_equality_view_pure.sol-0.8.35.zip b/tests/e2e/detectors/test_data/incorrect-equality/0.8.35/incorrect_equality_view_pure.sol-0.8.35.zip new file mode 100644 index 0000000000000000000000000000000000000000..8a1ee9d7dfe84ce4acb4062a1393351afa0949e0 GIT binary patch literal 4185 zcmbW5*CQJa!-b;}t4gU+wQEy*RViu{TWo%2V(*wm)n2uVnl)>Wn6*c2RZ8qlRYb+! z^ZUKu{d@DCbMaiAKj1mqU?8px;1PfX5F$2cCWzAZr;WXX50uZ*%gvP#7X&Z|073wO zx6#pd!neX61ykeAl2395TpifD86rOEzL4e}pE3StWfY$kY_5X)fHlQG<1dR2;j$f{ zoVO?MmiLJFC+l60(Ler<>`m5Dao5*nc*PMgL56AR(s*Fz^=lC}gW=5_TltAt6yu}q zpNB{D3*72iWj)<9o+V8f?rD$|-E6;ts3VRJz0ZGVB6t$M%kcwSd(J!Y0xN5ekAO0y z?Dv`{=ilA4hMqa^PmseR@1(zT1#N=bTELR+g!f>Yu-;B4_o{D4xfV*$<+AD)&N>i>#EBo^l z^l_{ZbtiS;A!yE;rDE?ne?iS$RA?e+jMuL~`X?3b091EX-I30A{8ld!*HKRabJ6;; zNc4NS9Kd9A#rBJjkTw?6|JpY(B|j=SE^(I$gGu{2Y0$i7M|fdZV?SQ>hNvRibncCj zN%+_H@P;@+HcMv?sF1PZts{V^$aEAKgV4p{qY!#`q@3@L5NjFJr9RlUYY_#)woGJ< z2u=g-K&@YgWIlz)dBE<8rfA63YAWjJ`_neKWhU0V>ax-c)mfWQMODe9raQ9o_2e;i zT2t;8(M>sHb!5*kJI&8UAHR95qKIV7pMDV_omaeX!SonSFO*ubFtaGJ(4Ur`3u#Op z{K(x!85U7FlLr*rXa6nToj&VHW(;X;l3J)Qf1lNmZgjXlwo5m=_Q!0h)1iYUN2wEZ zV};y=$mFDcDWAakeG(EspSwjxfMfPO0lP{71EG~l2n;gSO zjtHX64JSNmguy_gB|13Eod+!>4eiOeks@rYRC0CzRj+Hqz&fnCS<#BiyB zF_a=8h^sRs(T-(LVy_Zssur0WIO!D0V$TihV)EXoTfBaQ3wRAvygmvX|;8U4BlHc zY4UzXfG;C3u{BG{utPk1G&O(@Im2jD7_JH|XTMj}*}O`4SKeRk6I5lvifCb~c*L@1 zGxm}_0fARf;nZboD;MNqt&$%E$?bI>ZmX&5EdLCT`<1r-UG9!&vN2qf#x+9zn(C{K zfZQoCJ+R3d7kZ2((!rsQ!IEcL0G9i+%o;JT)D3>%Vz4;SEc#XD11?h96)EpI6}H3h zK`K!4sRVY!w_wA9?&goiJ_aOVQ#TRm#jN)S3}iCD4MFI0q#V6 z!L!^5wQfdMov8W|=FfT3!hOf;BzI}EaA!Ok)Entta~5yauuLoC=G^IR1rG6ha9*c! zO-`QZHd8(^>UZG|eFWP2ypF(E|Ft)ddcK;AcQvtP?(-Gj!MPOb1^N0Q_)q?y&3=cT z>&sZ%P-V5_SnDeZLcM5KQQzhR!s4!Ex*h@-jzW(1KzVB%g$!ssGNL~iU9!Q4<#2j1 zOv_x97jKE^M$3K{_~%dEZPFDrHutN*$8#sbyFRd_5|vN2M>I2wbs^LkX{HH1 zwr4B$G%m@%E6a|#tv!G4&b|KqWQob`@Qt^}vLZYGH0n@`Ju|;9K&jY_QFv+@a{bsv9!YIl1P1jkmNK;y;L|BD)`{sBHMkaTRS) z#@;Zh6=$-XF9FslRBlUPbivPz93OFg!VOCcNFNLx8t^*MWLa`a`1r=0fL~gq__;aP zZH?WvmQRLV3)Fp{yv3d_6vz2BkZ%y|cK9yw)^5PY-AZvzh}V-)TX6%ci-379gV5b8^`WHOG&i zQ{@ZJ?ZM#W{RMv#<=wgiFJzMagr-IZgs2=oU%9^bu7h9DWg=v-tW|L_IkW0Mp5=tGQaIstCgpS{L0>#DwO-p_ zQQ&A3nz&r^_Vc72DB~Ez*!_3qJ~$Vsp2f2lc?~5$^09u#K;%}PCCgXvc(`|!zFlxI zChIZWQ^+)QWO#?3UsD?dfvDSL`$_Q{$!Q}fn+;qHMc>Nv_Y;*~pn;`_+?s`auhj{= zu4kU?e6ST$C{T4=_{dZN8@%RMD>-cYY!?WS&&@oC*UK!d9i|8qTfSfQ4Bc4<{hoFx z%)LKXx7lt`_yfXfkHcN0G2E3VnA)4n3*EKv${{XPDIC!Q;$%^rZ*d6_jktgT!3&-5 z-o+bg*5!W#u%4f;ANg!#_KV(Y5NHf?;+mDC$Miw)Hox$IR@R&(taz&c@Ha z(waQn{CNHg>QT+^f{9Rj7hy^K7*h57$Xr^>wrcSvGS>~FmBZ6<2hJW18lkI^g(F&K zJN#E-em@%G4Y|h(7zTf2^}pi`vtLSgZjIHfUgKlC@4x+0T8|eqDOPv9WK=lG9NXly z)q$xM)f)jRQVi1@U5pIJtqhYL1Mz_gjH2bl_vRl6)P03#C{l+uDy%yHNijpUH;SV_ zn4X$QUn=#hq8?x8im5`%i9~s6Lo?STNy~T^ql0+Y0*U(&KIE^V0jk2`s0GF|F|R9@ z09U#nnqI$FMxdc6FqckgEp6p-4^IIG;&S+V_}8QAvW#)|f%k})e3E1uwHE?+=M5lp zL$GDop_WkZT(DRS72Uz0P%A!SQP-ZL^JouOLULV{)2G zZgan^6hY%4cFcHyC(eQF)it}l^GHZCt1_FQ3lb@d+^EfDM z5=m5}^1>8c^AL6x~mymx-~~ zXo9^dpV0lr1TCVJpFK%s;`#;F4qsw$GUe%|uq~Do)oP-HuKME=WXLB*#gfi{iw}1n zn2-(N^tPM*Io*GJ$M%BoS%epdju8*`9tciwHNh)qz$G$21xLB2B^hJ(I6ADq<4pgM z#>_MQot51({=3Ihs*A~Tr{jOU?q{})gmbyp<~u1|`bT>TJ*$*9dC!WYVfh9hKVj=I zpGij$!A8j)o5DNo)@T~g)GZV9y5DiNp=K@ZqAQEV&-Tl`)wDwtu)#e;{Yo`aq(-0X zDYN)B_$Jv6@M+jDC8TJlrhuW=-GBqb@Aq~N?10a3f*Q9)ro>BMW%~BP`&`Y)5{-=6 zNKYrG8Voi6DE`^5)1$oTJXs_VJdmm%0fv!KeTx+n40_atBZ(8|)#arBB_RIT3yw#y-FD$DLDq`B(mpILgA z>9T)vdG~byHaI#;-LKr)1BudVUW^_V2f%gl?7W!nzZREg^00@a4{UB2ic7@L*lp@S z*w<;@Xs@R)YEykxhT7a6IvNjIkT@chKDPeO_GBu(wo#|q)cYL_NX+7z=r{ar?M$KU