Rust: False positive for unused variable names
- 主要语言
- CodeQL
- 星标
- 10.1k
- 派生
- 2.1k
- 平均合并
- 2 天 15 小时
- 30 天内合并 PR
- 141
描述
**Description of the false positive**
CodeQL seems to produce false positives for Rust variables in format strings.
**Code samples or links to source code**
On 2026-08-13, the folllowing Rust snippet got [flagged](https://github.com/alltheplaces/osm-diffs/security/code-scanning/30) by CodeQL on https://github.com/alltheplaces/osm-diffs/pull/660. CodeQL posted a notice, claiming `Variable 'name' is not used`. However, the variable _does_ get used in this snippet, via a `format!` macro. We also check for unused variables with clippy, which does not flag an unused variable for this code. So, this looks like a false positive from CodeQL.
```rust
let producers: Vec<_> = sources
.into_iter()
.map(|(name, reader)| {
let tx = tx.clone();
s.spawn(move || -> Result<()> {
for record in reader.iter()? {
let bytes = record?;
let fti = FeatureToIndex::decode(bytes.as_slice()).with_context(|| {
format!("failed to decode a FeatureToIndex record from {name}")
})?;
tx.send(fti)?;
progress_bar.inc(1);
}
Ok(())
})
})
.collect();
```
**URL to the alert on GitHub code scanning (optional)**
https://github.com/alltheplaces/osm-diffs/security/code-scanning/30
贡献指南
调研方向
先从链接的代码扫描警报和 Rust 代码片段开始,然后跟踪 CodeQL Rust 未使用变量查询对 format! 插值的处理方式。完成的标准是:查询不再将 `name` 报告为未使用,同时仍能检测出确实未使用的变量。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- rust
- 领域
- security
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 冷清
- 描述清晰度
- 需要澄清
- 新手友好度
- 38/100