Add AlertSuppression.ql for Rust (inline // codeql[...] suppression)
- Lenguaje dominante
- CodeQL
- Estrellas
- 10.1k
- Forks
- 2.1k
- Merge medio
- 2 d 15 h
- PR fusionados (30 d)
- 141
Descripción
**Description of the issue**
Rust is missing an `AlertSuppression.ql` query, which means `// codeql[...]` and `// lgtm[...]` inline suppression comments have no effect on Rust code scanning alerts. Every other supported language (C++, C#, Go, Java, JavaScript, Python, Ruby, Swift) has this query.
All the building blocks already exist in the Rust CodeQL library:
- **Shared suppression module**: [`shared/util/codeql/util/suppression/AlertSuppression.qll`](https://github.com/github/codeql/blob/main/shared/util/codeql/util/suppression/AlertSuppression.qll) — requires `AstNode` (with `hasLocationInfo`) and `SingleLineComment` (with `hasLocationInfo`, `getText`, `toString`)
- **Rust `Comment` class**: [`rust/ql/lib/codeql/rust/elements/Comment.qll`](https://github.com/github/codeql/blob/main/rust/ql/lib/codeql/rust/elements/Comment.qll) — already has `getText()` (raw text including `//`), `getCommentText()` (stripped), `hasLocationInfo` (inherited from `AstNode`/`Token`), and `toString`
- **Rust `AstNode`**: [`rust/ql/lib/codeql/rust/elements/AstNode.qll`](https://github.com/github/codeql/blob/main/rust/ql/lib/codeql/rust/elements/AstNode.qll)
### Proposed implementation
A new file at `rust/ql/src/AlertSuppression.ql`, following the same pattern as [`python/ql/src/AlertSuppression.ql`](https://github.com/github/codeql/blob/main/python/ql/src/AlertSuppression.ql):
```ql
/**
* @name Alert suppression
* @description Generates information about alert suppressions.
* @kind alert-suppression
* @id rust/alert-suppression
*/
private import codeql.util.suppression.AlertSuppression as AS
private import codeql.rust.elements.Comment as C
private import codeql.rust.elements.AstNode as A
class AstNode instanceof A::AstNode {
predicate hasLocationInfo(
string filepath, int startline, int startcolumn, int endline, int endcolumn
) {
super.getLocation().hasLocationInfo(filepath, startline, startcolumn, endline, endcolumn)
}
string toString() { result = super.toString() }
}
class SingleLineComment instanceof C::Comment {
SingleLineComment() {
// Only match single-line comments (// ...), not block comments (/* ... */)
super.getText().matches("//%")
}
predicate hasLocationInfo(
string filepath, int startline, int startcolumn, int endline, int endcolumn
) {
super.getLocation().hasLocationInfo(filepath, startline, startcolumn, endline, endcolumn)
}
string getText() { result = super.getText() }
string toString() { result = super.toString() }
}
import AS::Make
```
The `qlpack.yml` at `rust/ql/src/qlpack.yml` already depends on `codeql/util`, so no dependency changes are needed.
### Motivation
Without this, there is no way to suppress false positives inline for Rust. The only workaround is dismissing alerts via the GitHub API or UI, which doesn't persist reliably across code changes.
Guía de contribución
Línea de trabajo
Comienza con el patrón propuesto en python/ql/src/AlertSuppression.ql, luego lee shared/util/codeql/util/suppression/AlertSuppression.qll y los archivos Rust Comment.qll y AstNode.qll. Añade rust/ql/src/AlertSuppression.ql y confirma que los comentarios // codeql[...] y // lgtm[...] producen supresiones de alertas de Rust sin cambiar rust/ql/src/qlpack.yml.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- rust
- Área
- security
- Tipo de issue
- Nueva funcionalidad
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Estado de actividad
- Tranquilo
- Claridad
- Bien especificado
- Aptitud para principiantes
- 78/100