Rust: False positive for unused variable names
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the false positive**
CodeQL seems to produce false positives for Rust variables in format strings.
**Code samples or links to source code**
On 2026-08-13, the folllowing Rust snippet got [flagged](https://github.com/alltheplaces/osm-diffs/security/code-scanning/30) by CodeQL on https://github.com/alltheplaces/osm-diffs/pull/660. CodeQL posted a notice, claiming `Variable 'name' is not used`. However, the variable _does_ get used in this snippet, via a `format!` macro. We also check for unused variables with clippy, which does not flag an unused variable for this code. So, this looks like a false positive from CodeQL.
```rust
let producers: Vec<_> = sources
.into_iter()
.map(|(name, reader)| {
let tx = tx.clone();
s.spawn(move || -> Result<()> {
for record in reader.iter()? {
let bytes = record?;
let fti = FeatureToIndex::decode(bytes.as_slice()).with_context(|| {
format!("failed to decode a FeatureToIndex record from {name}")
})?;
tx.send(fti)?;
progress_bar.inc(1);
}
Ok(())
})
})
.collect();
```
**URL to the alert on GitHub code scanning (optional)**
https://github.com/alltheplaces/osm-diffs/security/code-scanning/30
貢獻指南
研究方向
先從連結的程式碼掃描警示和 Rust 程式碼片段開始,然後追蹤 CodeQL Rust 未使用變數查詢如何處理 format! 插值。完成的標準是:查詢不再將 `name` 回報為未使用,同時仍能偵測出確實未使用的變數。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- rust
- 領域
- security
- Issue 類型
- 缺陷
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 活躍度
- 冷清
- 描述清晰度
- 需要釐清
- 新手友好度
- 38/100