github / github/codeql

Add AlertSuppression.ql for Rust (inline // codeql[...] suppression)

未關閉 適合新手
#21,637 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the issue**

Rust is missing an `AlertSuppression.ql` query, which means `// codeql[...]` and `// lgtm[...]` inline suppression comments have no effect on Rust code scanning alerts. Every other supported language (C++, C#, Go, Java, JavaScript, Python, Ruby, Swift) has this query.

All the building blocks already exist in the Rust CodeQL library:

- **Shared suppression module**: [`shared/util/codeql/util/suppression/AlertSuppression.qll`](https://github.com/github/codeql/blob/main/shared/util/codeql/util/suppression/AlertSuppression.qll) — requires `AstNode` (with `hasLocationInfo`) and `SingleLineComment` (with `hasLocationInfo`, `getText`, `toString`)
- **Rust `Comment` class**: [`rust/ql/lib/codeql/rust/elements/Comment.qll`](https://github.com/github/codeql/blob/main/rust/ql/lib/codeql/rust/elements/Comment.qll) — already has `getText()` (raw text including `//`), `getCommentText()` (stripped), `hasLocationInfo` (inherited from `AstNode`/`Token`), and `toString`
- **Rust `AstNode`**: [`rust/ql/lib/codeql/rust/elements/AstNode.qll`](https://github.com/github/codeql/blob/main/rust/ql/lib/codeql/rust/elements/AstNode.qll)

### Proposed implementation

A new file at `rust/ql/src/AlertSuppression.ql`, following the same pattern as [`python/ql/src/AlertSuppression.ql`](https://github.com/github/codeql/blob/main/python/ql/src/AlertSuppression.ql):

```ql
/**
* @name Alert suppression
* @description Generates information about alert suppressions.
* @kind alert-suppression
* @id rust/alert-suppression
*/

private import codeql.util.suppression.AlertSuppression as AS
private import codeql.rust.elements.Comment as C
private import codeql.rust.elements.AstNode as A

class AstNode instanceof A::AstNode {
predicate hasLocationInfo(
string filepath, int startline, int startcolumn, int endline, int endcolumn
) {
super.getLocation().hasLocationInfo(filepath, startline, startcolumn, endline, endcolumn)
}

string toString() { result = super.toString() }
}

class SingleLineComment instanceof C::Comment {
SingleLineComment() {
// Only match single-line comments (// ...), not block comments (/* ... */)
super.getText().matches("//%")
}

predicate hasLocationInfo(
string filepath, int startline, int startcolumn, int endline, int endcolumn
) {
super.getLocation().hasLocationInfo(filepath, startline, startcolumn, endline, endcolumn)
}

string getText() { result = super.getText() }

string toString() { result = super.toString() }
}

import AS::Make
```

The `qlpack.yml` at `rust/ql/src/qlpack.yml` already depends on `codeql/util`, so no dependency changes are needed.

### Motivation

Without this, there is no way to suppress false positives inline for Rust. The only workaround is dismissing alerts via the GitHub API or UI, which doesn't persist reliably across code changes.

貢獻指南

開啟貢獻指南

研究方向

從 python/ql/src/AlertSuppression.ql 中提議的模式開始,然後閱讀 shared/util/codeql/util/suppression/AlertSuppression.qll 以及 Rust Comment.qll 和 AstNode.qll 檔案。新增 rust/ql/src/AlertSuppression.ql,並確認 // codeql[...] 和 // lgtm[...] 註解能夠產生 Rust 警示抑制,而不變更 rust/ql/src/qlpack.yml。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
rust
領域
security
Issue 類型
功能
難度
2/5
預估耗時
1-3 小時
活躍度
冷清
描述清晰度
描述清楚
新手友好度
78/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。