github / github/codeql

Java: Generic Class Methods not connected when type parameter is unknown (build-mode=none)

Open
#19,538 4 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

The introduction of `build-mode=none` has been very helpful for us. This allows us to create (partial) CodeQL databases, without being forced to fully resolve (maven) dependencies. Sometimes this is convenient because some dependencies might not be easily resolvable.

That said, we also see many examples of Generic Classes and Methods in our codebases. Unfortunately, we cannot analyse (calls to) Generic Methods that are instantiated with type parameters that are unknown.

Note that, while the code of the type parameter `T` is unavailable, the code of the `GenericClass` *is* available.

## Example pseudo code
```
class GenericClass {
public method() { ... };
};

GenericClass i1 = new GenericClass<>();
i1.method(); // not connected
GenericClass i2 = new GenericClass<>();
i2.method(); // connected
```

See attached [codeql_issue.zip](https://github.com/user-attachments/files/20345107/codeql_issue.zip) zip file for a more thorough analysis of the issue.

Contributor guide

Open the contributing guide

Research direction

Start by unpacking the attached codeql_issue.zip and comparing the connected Boolean instantiation with the unconnected unknown-type instantiation under build-mode=none. The issue names no source files or tests, so trace the relevant Java analysis entry point from the reproduction. Done means calls to GenericClass.method() are connected like calls with a known type parameter.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
devtools
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.