Rust: False positive for unused variable names
- 主要言語
- CodeQL
- スター
- 10.1k
- フォーク
- 2.1k
- 平均マージ
- 2日 15時間
- マージ済み PR(30日)
- 141
説明
**Description of the false positive**
CodeQL seems to produce false positives for Rust variables in format strings.
**Code samples or links to source code**
On 2026-08-13, the folllowing Rust snippet got [flagged](https://github.com/alltheplaces/osm-diffs/security/code-scanning/30) by CodeQL on https://github.com/alltheplaces/osm-diffs/pull/660. CodeQL posted a notice, claiming `Variable 'name' is not used`. However, the variable _does_ get used in this snippet, via a `format!` macro. We also check for unused variables with clippy, which does not flag an unused variable for this code. So, this looks like a false positive from CodeQL.
```rust
let producers: Vec<_> = sources
.into_iter()
.map(|(name, reader)| {
let tx = tx.clone();
s.spawn(move || -> Result<()> {
for record in reader.iter()? {
let bytes = record?;
let fti = FeatureToIndex::decode(bytes.as_slice()).with_context(|| {
format!("failed to decode a FeatureToIndex record from {name}")
})?;
tx.send(fti)?;
progress_bar.inc(1);
}
Ok(())
})
})
.collect();
```
**URL to the alert on GitHub code scanning (optional)**
https://github.com/alltheplaces/osm-diffs/security/code-scanning/30
コントリビューションガイド
調査の方向性
Start with the linked code-scanning alert and the Rust snippet, then trace the CodeQL Rust unused-variable query's handling of format! interpolation. Done means the query no longer reports `name` as unused while still detecting genuinely unused variables.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- rust
- 領域
- security
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- 説明が足りない
- 初心者へのやさしさ
- 38/100