github / github/codeql

Python: Mixing implicit/explicit returns false positive

Open
#18,521 2 comments 1 reaction 0 assignees View on GitHub
false-positive
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

**Description of the false positive**

I am seeing an ` Mixing implicit and explicit returns may indicate an error as implicit returns always return None.` alert where the code actually always has a return.
In my interpretation of the alert it seems that the issue is that CodeQL isn't considering the `case _:` in a match to be acting as a default case so it believes that there should be a `return None` outside of the `match`.

**Code samples or links to source code**

I had to slightly redact the code but I believe that this is the same:
(ironically this is in a piece of code that processes codeql alerts, don't get confused 😄)

```python
def codeql_severity_conversion(self, security_severity, severity):
match (security_severity, severity):
case ("critical", _) | ("high", _) | ("low", _):
return security_severity
case ("medium", _):
return "moderate"
case (None, "error"):
return "high"
case (None, "warning"):
return "moderate"
case (None, "note") | (None, "none"):
return "low"
case _:
return "high"
```

**URL to the alert on GitHub code scanning (optional)**

I'd rather not share the link outside the enterprise. The link to the rule in the alert is https://github.com/github/codeql/blob/d42788844f7ec0a6b9832140313cc2318e513987/python/ql/src/Functions/ConsistentReturns.ql

Contributor guide

Open the contributing guide

Research direction

Start by reading python/ql/src/Functions/ConsistentReturns.ql and compare its return-flow handling with the supplied Python match example. Reproduce the alert if possible; done means a function with a case _ default return is no longer reported as mixing implicit and explicit returns.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.