github / github/codeql

So many false positives that I doubt it actually works

Aperta
#18,359 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub
false-positive
Lingua principale
CodeQL
Stelle
10.1k
Fork
2.1k
Merge medio
2g 15h
PR unite (30g)
141

Descrizione

**Description of the false positive**

I am constantly getting the following in my Java project.

```
Useless parameter
The parameter '' is never used.
```

```
Unread local variable
Variable '
' is never read.
```

This is so frequente that I am at a point that I am seriously doubting the capacity of this tool of really working for whatever it proposes itself to do.

All parameters and variables it points as being useless or unread are always read, sometimes in the literal next line.

**Code samples or links to source code**

https://github.com/Scoppio/mekhq/blob/79a0f780ba5b70b46deea320962b9f6a4d8bdb19/MekHQ/src/mekhq/campaign/autoresolve/acar/handler/StandardUnitAttackHandler.java#L173

```Java
private int[] calculateDamage(
Formation attacker, // CodeQL - Useless parameter
StandardUnitAttack attack, // CodeQL - Useless parameter
SBFUnit attackingUnit, Formation target) {
int bonusDamage = 0; // CodeQL - Unread local variable
if (attack.getManeuverResult().equals(StandardUnitAttack.ManeuverResult.SUCCESS)) {
bonusDamage += 1;
}

var damage = attackingUnit.getElements().stream().mapToInt(e -> e.getStandardDamage().getDamage(attack.getRange()).damage).toArray();
return processDamageByEngagementControl(attacker, target, bonusDamage, damage);
}
```

As you can see, attacker parameter is used as parameter for processDamageByEngagementControl (it uses attacker inside), attack parameter is used when accessing `attack.getRange()`, and the variable bonusDamage is also used being passed as a parameter to processDamageByEngagementControl which then consumes it.

This is just a sample of my common experience with CodeQL, I often from 12 to 20 false positives sauing a parameter is useless or a variable is never read in all my pull requests.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start with the linked Java sample and the calculateDamage method, then reproduce the reported diagnostics for the parameter and local variable. Trace the CodeQL query that emits them and add regression coverage so valid uses like these are no longer reported.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
java
Ambito
security, tooling
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Ferma
Chiarezza
Da chiarire
Idoneità per principianti
25/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.