forcedotcom / forcedotcom/code-analyzer

[BUG][code-analyzer] sfge: Decimal.setScale() — and every other unmodelled numeric method — aborts the entry point

Aperta
#2,092 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
TypeScript
Stelle
240
Fork
52
Merge medio
1g 23h
PR unite (30g)
5

Descrizione

### Have you tried to resolve this issue yourself first?

- [x] I confirm I have gone through the above steps and still have an issue to report.

### Bug Description

**Engine:** `sfge` (Salesforce Graph Engine) · **Rule:** `ApexFlsViolation` (DevPreview) · **Selector:** `--rule-selector sfge`

`ApexSimpleValue.apply` is an unconditional `throw new UnexpectedException(vertex);` (`ApexSimpleValue.java:55`). `ApexStringValue` and `ApexNumberValue` override it, but `ApexNumberValue` handles only `format()` and `intValue()` before delegating back to `super.apply`:

```java
// ApexNumberValue.java:41-43
} else {
return super.apply(vertex, symbols); // -> ApexSimpleValue.apply -> throw
}
```

So every other `Decimal`/`Integer`/`Double`/`Long` method — `setScale`, `round`, `divide`, `pow`, `abs`, `stripTrailingZeros`, … — aborts the entry point. `ApexBooleanValue` has no override at all.

```apex
Decimal v = value;
a.AnnualRevenue = v.setScale(2);
```

### Output / Logs

```shell
UnexpectedException: MethodCallExpressionVertex{fullMethodName=v.setScale, ... MethodName=setScale}:
com.salesforce.graph.symbols.apex.ApexSimpleValue.apply(ApexSimpleValue.java:55);
com.salesforce.graph.symbols.apex.ApexNumberValue.apply(ApexNumberValue.java:42);
com.salesforce.graph.symbols.apex.ApexDecimalValue.apply(ApexDecimalValue.java:49); ...
```

### Steps To Reproduce

1. Create an empty SFDX project (`sfdx-project.json` with a single `force-app` package directory).
2. Add `force-app/main/default/classes/DecimalSetScale.cls` with the class shown below, plus a standard `DecimalSetScale.cls-meta.xml` (apiVersion 62.0).
3. Add `code-analyzer.yml`:
```yaml
engines:
sfge:
java_thread_timeout: 900000
java_thread_count: 4
```
4. Run:
```
sf code-analyzer run --rule-selector sfge --workspace . --config-file code-analyzer.yml
```
5. The run reports an `InternalExecutionError` for the entry point instead of analysing it. That entry point yields no `ApexFlsViolation` findings at all, and nothing in the summary indicates coverage was lost.

```apex
public with sharing class DecimalSetScale {
@AuraEnabled
public static void run(Decimal value) {
Decimal v = value;
Account a = new Account();
a.AnnualRevenue = v.setScale(2);
insert a;
}
}
```

### Expected Behavior

An unmodelled method on a scalar should degrade to an indeterminate value of the appropriate type, not abort the entry point. Changing `ApexSimpleValue.apply` to return an indeterminate value instead of throwing would cover the whole family at once, including the `ApexBooleanValue` gap.

### Operating System

macOS 26.5.2

### Salesforce CLI Version

@salesforce/cli/2.147.7 darwin-arm64 node-v24.5.0

### Code Analyzer Plugin (code-analyzer) Version

code-analyzer 5.15.0

### Node Version

v24.5.0

### Java Version

openjdk version "11.0.32" 2026-07-21

### Python Version

N/A

### Additional Context (Screenshots, Files, etc)

Previously reported as #1409 (`Decimal.valueOf(...).setScale(scale)`), closed NOT_PLANNED as a duplicate in 2024. Still reproduces on 5.15.0.

This one is broad rather than frequent — it is one signature in our codebase, but it covers every unmodelled numeric method, so the surface is large.

### Workaround

Avoid the method call on the path to a DML operation, or compute the value in a helper whose result sfge treats as indeterminate. Neither is a real fix.

### Urgency

Moderate

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start with com.salesforce.graph.symbols.apex.ApexSimpleValue.java:55, then compare the delegation paths in ApexNumberValue.java and ApexDecimalValue.java. Reproduce the DecimalSetScale example with the supplied sfge command and verify that an unmodelled scalar method no longer aborts the entry point and that analysis can report findings.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
java
Ambito
devtools, security
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Attiva
Chiarezza
Specificata chiaramente
Idoneità per principianti
74/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.