Rust: False positive for unused variable names
- Vorherrschende Sprache
- CodeQL
- Sterne
- 10.1k
- Forks
- 2.1k
- Ø Merge
- 2 T. 15 Std.
- Gemergte PRs (30 T.)
- 141
Beschreibung
**Description of the false positive**
CodeQL seems to produce false positives for Rust variables in format strings.
**Code samples or links to source code**
On 2026-08-13, the folllowing Rust snippet got [flagged](https://github.com/alltheplaces/osm-diffs/security/code-scanning/30) by CodeQL on https://github.com/alltheplaces/osm-diffs/pull/660. CodeQL posted a notice, claiming `Variable 'name' is not used`. However, the variable _does_ get used in this snippet, via a `format!` macro. We also check for unused variables with clippy, which does not flag an unused variable for this code. So, this looks like a false positive from CodeQL.
```rust
let producers: Vec<_> = sources
.into_iter()
.map(|(name, reader)| {
let tx = tx.clone();
s.spawn(move || -> Result<()> {
for record in reader.iter()? {
let bytes = record?;
let fti = FeatureToIndex::decode(bytes.as_slice()).with_context(|| {
format!("failed to decode a FeatureToIndex record from {name}")
})?;
tx.send(fti)?;
progress_bar.inc(1);
}
Ok(())
})
})
.collect();
```
**URL to the alert on GitHub code scanning (optional)**
https://github.com/alltheplaces/osm-diffs/security/code-scanning/30
Beitragsleitfaden
Rechercherichtung
Start with the linked code-scanning alert and the Rust snippet, then trace the CodeQL Rust unused-variable query's handling of format! interpolation. Done means the query no longer reports `name` as unused while still detecting genuinely unused variables.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- rust
- Bereich
- security
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Ruhig
- Klarheit
- Muss geklärt werden
- Anfängerfreundlichkeit
- 38/100