github / github/codeql

Python: Mixing implicit/explicit returns false positive

オープン
#18,521 コメント 2 件 リアクション 1 件 担当者 0 名 GitHub で見る
false-positive
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

**Description of the false positive**

I am seeing an ` Mixing implicit and explicit returns may indicate an error as implicit returns always return None.` alert where the code actually always has a return.
In my interpretation of the alert it seems that the issue is that CodeQL isn't considering the `case _:` in a match to be acting as a default case so it believes that there should be a `return None` outside of the `match`.

**Code samples or links to source code**

I had to slightly redact the code but I believe that this is the same:
(ironically this is in a piece of code that processes codeql alerts, don't get confused 😄)

```python
def codeql_severity_conversion(self, security_severity, severity):
match (security_severity, severity):
case ("critical", _) | ("high", _) | ("low", _):
return security_severity
case ("medium", _):
return "moderate"
case (None, "error"):
return "high"
case (None, "warning"):
return "moderate"
case (None, "note") | (None, "none"):
return "low"
case _:
return "high"
```

**URL to the alert on GitHub code scanning (optional)**

I'd rather not share the link outside the enterprise. The link to the rule in the alert is https://github.com/github/codeql/blob/d42788844f7ec0a6b9832140313cc2318e513987/python/ql/src/Functions/ConsistentReturns.ql

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start by reading python/ql/src/Functions/ConsistentReturns.ql and compare its return-flow handling with the supplied Python match example. Reproduce the alert if possible; done means a function with a case _ default return is no longer reported as mixing implicit and explicit returns.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
python
領域
security
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
38/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。