github / github/codeql

[question?] counterintuitive class method behaviour

未關閉
#21,670 9 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

When I write a query like this:
```codeql
class Meow extends Struct {
Field f;
Meow() {
f.getDeclaringType() = this
}
Field getField() { result = f }
}

from Meow m
select m, m.getField(), m.getField()
```
My mental model of this is: "`Meow` is essentially a (struct, struct's field) tuple. `from Meow m` will select all of those tuples. For each of those , `select m, m.getField(), m.getField()` will print their contents."

But that is actually not what happens, because you get results like this:
```
| m | col1 | col2 |
+-----------------------------------+-----------------------------------------------------+-----------------------------------------------------+
// [snip]
| port_io_ops | f_inb | f_outb |
// [snip]
```
Which means that the first `m.getField()` and the second `m.getField()` are operating on different `Meow` objects.

I've been debugging a bug in my query for hours now only to realize that this is what happens. Is this really intended? I read through a non-trivial amount of documentation and did not realize this, I feel like my whole mental model of how codeql works is shattering :S

(If it is really intended, could the documentation be updated to point this out more clearly?)

貢獻指南

開啟貢獻指南

研究方向

Start with the CodeQL query and output shown in the issue, then read the documentation covering class methods and predicate evaluation. Confirm the intended behavior and identify the relevant documentation section; done means the behavior is explained clearly enough to address the reported mental-model gap.

由索引模型根據 Issue 內容生成。

評估

領域
documentation
Issue 類型
文件
難度
4/5
預估耗時
3-5 天
活躍度
冷清
描述清晰度
基本清楚
新手友好度
38/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。