forcedotcom / forcedotcom/code-analyzer

[BUG][code-analyzer] sfge: Decimal.setScale() — and every other unmodelled numeric method — aborts the entry point

Ouverte
#2,092 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
TypeScript
Étoiles
240
Forks
52
Merge moyen
1 j 23 h
PR mergées (30 j)
5

Description

### Have you tried to resolve this issue yourself first?

- [x] I confirm I have gone through the above steps and still have an issue to report.

### Bug Description

**Engine:** `sfge` (Salesforce Graph Engine) · **Rule:** `ApexFlsViolation` (DevPreview) · **Selector:** `--rule-selector sfge`

`ApexSimpleValue.apply` is an unconditional `throw new UnexpectedException(vertex);` (`ApexSimpleValue.java:55`). `ApexStringValue` and `ApexNumberValue` override it, but `ApexNumberValue` handles only `format()` and `intValue()` before delegating back to `super.apply`:

```java
// ApexNumberValue.java:41-43
} else {
return super.apply(vertex, symbols); // -> ApexSimpleValue.apply -> throw
}
```

So every other `Decimal`/`Integer`/`Double`/`Long` method — `setScale`, `round`, `divide`, `pow`, `abs`, `stripTrailingZeros`, … — aborts the entry point. `ApexBooleanValue` has no override at all.

```apex
Decimal v = value;
a.AnnualRevenue = v.setScale(2);
```

### Output / Logs

```shell
UnexpectedException: MethodCallExpressionVertex{fullMethodName=v.setScale, ... MethodName=setScale}:
com.salesforce.graph.symbols.apex.ApexSimpleValue.apply(ApexSimpleValue.java:55);
com.salesforce.graph.symbols.apex.ApexNumberValue.apply(ApexNumberValue.java:42);
com.salesforce.graph.symbols.apex.ApexDecimalValue.apply(ApexDecimalValue.java:49); ...
```

### Steps To Reproduce

1. Create an empty SFDX project (`sfdx-project.json` with a single `force-app` package directory).
2. Add `force-app/main/default/classes/DecimalSetScale.cls` with the class shown below, plus a standard `DecimalSetScale.cls-meta.xml` (apiVersion 62.0).
3. Add `code-analyzer.yml`:
```yaml
engines:
sfge:
java_thread_timeout: 900000
java_thread_count: 4
```
4. Run:
```
sf code-analyzer run --rule-selector sfge --workspace . --config-file code-analyzer.yml
```
5. The run reports an `InternalExecutionError` for the entry point instead of analysing it. That entry point yields no `ApexFlsViolation` findings at all, and nothing in the summary indicates coverage was lost.

```apex
public with sharing class DecimalSetScale {
@AuraEnabled
public static void run(Decimal value) {
Decimal v = value;
Account a = new Account();
a.AnnualRevenue = v.setScale(2);
insert a;
}
}
```

### Expected Behavior

An unmodelled method on a scalar should degrade to an indeterminate value of the appropriate type, not abort the entry point. Changing `ApexSimpleValue.apply` to return an indeterminate value instead of throwing would cover the whole family at once, including the `ApexBooleanValue` gap.

### Operating System

macOS 26.5.2

### Salesforce CLI Version

@salesforce/cli/2.147.7 darwin-arm64 node-v24.5.0

### Code Analyzer Plugin (code-analyzer) Version

code-analyzer 5.15.0

### Node Version

v24.5.0

### Java Version

openjdk version "11.0.32" 2026-07-21

### Python Version

N/A

### Additional Context (Screenshots, Files, etc)

Previously reported as #1409 (`Decimal.valueOf(...).setScale(scale)`), closed NOT_PLANNED as a duplicate in 2024. Still reproduces on 5.15.0.

This one is broad rather than frequent — it is one signature in our codebase, but it covers every unmodelled numeric method, so the surface is large.

### Workaround

Avoid the method call on the path to a DML operation, or compute the value in a helper whose result sfge treats as indeterminate. Neither is a real fix.

### Urgency

Moderate

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par com.salesforce.graph.symbols.apex.ApexSimpleValue.java:55, puis comparez les chemins de délégation dans ApexNumberValue.java et ApexDecimalValue.java. Reproduisez l’exemple DecimalSetScale avec la commande sfge fournie et vérifiez qu’une méthode scalaire non modélisée n’interrompt plus le point d’entrée et que l’analyse peut signaler des résultats.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
java
Domaine
devtools, security
Type d'issue
Bug
Difficulté
3/5
Temps estimé
1-2 jours
Activité
Active
Clarté
Clairement spécifiée
Accessibilité débutants
74/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.