github / github/codeql

False Negative: ContinueInFalseLoop.ql misses `do ... while(false)` loops once `false` is stored in a local.

オープン
#21,540 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
CodeQL
スター
10.1k
フォーク
2.1k
平均マージ
2日 15時間
マージ済み PR(30日)
141

説明

# False Negative: ContinueInFalseLoop.ql misses `do ... while(false)` loops once `false` is stored in a local.

Version
codeql 2.24.3

## Checker
- Checker id: `Likely Bugs/Statements/ContinueInFalseLoop.ql`
- Checker description: This checker detects a 'continue' statement inside a 'do' loop whose condition is always false, meaning the continue will never actually re-run the loop body.

## Description of the false negative
Both samples are still `do` loops whose condition is false and therefore cannot loop back after `continue`. The only difference is that the literal `false` is first assigned to a local variable.

That should still be a direct hit for `Likely Bugs/Statements/ContinueInFalseLoop.ql`.

## Affected test cases
### `PosCase1_Var1.java`
`never` is a constant false value, so the `continue` still cannot re-enter the loop body.

```java
// A do loop with a literal false condition contains a continue statement targeting that same loop should be flagged as a positive case.
package scensct.var.pos;

public class PosCase1_Var1 {
public static void main(String[] args) {
final boolean never = false;
do {
// continue inside do with false condition
continue;
} while (never);
}
}
```

### `PosCase1_Var5.java`
`flag` is initialized from `Boolean.FALSE` and never changed. This is still the same impossible loop-back case.

```java
// A do loop with a literal false condition contains a continue statement targeting that same loop should be flagged as a positive case.
package scensct.var.pos;

public class PosCase1_Var5 {
public static void main(String[] args) {
boolean flag = Boolean.FALSE;
do {
// continue inside do with false condition
continue;
} while (flag);
}
}
```

## Cause analysis
The miss is surprisingly basic. The query appears to require a literal `false` at the loop condition and loses the result as soon as that same value is stored in a local.

For developers, these are the same bug. Whether the condition is written as `while (false)` or `while (never)` should not matter.

## References
None known.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with Likely Bugs/Statements/ContinueInFalseLoop.ql and inspect how it evaluates do-loop conditions when false is stored in a local. Review the affected PosCase1_Var1.java and PosCase1_Var5.java cases, then run the checker tests to confirm both cases are flagged while the existing literal-false behavior remains covered.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
java
領域
devtools
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
静か
明瞭さ
明確に書かれている
初心者へのやさしさ
68/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。