github / github/codeql

False Negative: ContainsTypeMismatch.ql misses mismatched collection lookups once the receiver is routed through a raw alias.

未關閉
#21,539 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

# False Negative: ContainsTypeMismatch.ql misses mismatched collection lookups once the receiver is routed through a raw alias.

Version
codeql 2.24.3

## Checker
- Checker id: `Likely Bugs/Collections/ContainsTypeMismatch.ql`
- Checker description: This checker detects calls to Java collection methods where the argument type is incompatible with the collection's element type, such as calling `contains` with an argument that can never match any element in the collection.

## Description of the false negative
The collection still holds `Byte` values and the lookup still uses a `Float`. The only change is that the call goes through a raw alias before reaching `lastIndexOf(...)`.

That should not be enough to hide the type mismatch from `Likely Bugs/Collections/ContainsTypeMismatch.ql`.

## Affected test cases
### `PosCase5_Var5.java`
`rawVec.lastIndexOf(arg)` is still searching a `Vector` with a `Float`. The raw alias obscures generics, but it does not make the lookup compatible.

```java
// Call lastIndexOf on a Vector with an argument of type Float (first argument) should be flagged as incompatible type.
package scensct.var.pos;

import java.util.Vector;

public class PosCase5_Var5 {
public static void main(String[] args) {
Vector vec = new Vector();
// Wildcard capture: still Vector compatible
Float arg = 3.14f;
// Raw type manipulation to obscure but preserve generic info
Vector rawVec = vec;
// Checker must still detect Byte vs Float incompatibility
rawVec.lastIndexOf(arg);
}
}
```

## Cause analysis
This looks like a generic-type recovery gap. Once the receiver is widened to a raw type, the query appears to stop using the element type information from the original collection.

That is too weak for this rule. Raw aliases are common in older Java code, and they do not change the fact that a `Float` can never match an element from a `Vector`.

## References
None known.

貢獻指南

開啟貢獻指南

研究方向

Start with the Likely Bugs/Collections/ContainsTypeMismatch.ql checker and the PosCase5_Var5.java case described in the issue. Trace how the Vector receiver is recovered after assignment to rawVec, then add or update a regression test so rawVec.lastIndexOf(arg) is reported as a Byte-versus-Float mismatch.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
java
領域
devtools
Issue 類型
缺陷
難度
3/5
預估耗時
1-2 天
活躍度
冷清
描述清晰度
基本清楚
新手友好度
58/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。