github / github/codeql

Java: Generic Class Methods not connected when type parameter is unknown (build-mode=none)

未关闭
#19,538 4 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

The introduction of `build-mode=none` has been very helpful for us. This allows us to create (partial) CodeQL databases, without being forced to fully resolve (maven) dependencies. Sometimes this is convenient because some dependencies might not be easily resolvable.

That said, we also see many examples of Generic Classes and Methods in our codebases. Unfortunately, we cannot analyse (calls to) Generic Methods that are instantiated with type parameters that are unknown.

Note that, while the code of the type parameter `T` is unavailable, the code of the `GenericClass` *is* available.

## Example pseudo code
```
class GenericClass {
public method() { ... };
};

GenericClass i1 = new GenericClass<>();
i1.method(); // not connected
GenericClass i2 = new GenericClass<>();
i2.method(); // connected
```

See attached [codeql_issue.zip](https://github.com/user-attachments/files/20345107/codeql_issue.zip) zip file for a more thorough analysis of the issue.

贡献指南

打开贡献指南

调研方向

Start by unpacking the attached codeql_issue.zip and comparing the connected Boolean instantiation with the unconnected unknown-type instantiation under build-mode=none. The issue names no source files or tests, so trace the relevant Java analysis entry point from the reproduction. Done means calls to GenericClass.method() are connected like calls with a known type parameter.

由索引模型根据 Issue 内容生成。

评估

技术栈
java
领域
devtools
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。