github / github/codeql

C#: cs/simplifiable-boolean-expression false positive on Nullable<bool> compared with a literal

未關閉 適合新手
#22,556 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the false positive**

`cs/simplifiable-boolean-expression` flags `x == false` and `x == true` when `x` is a `bool?` (`Nullable`), suggesting `!x` / `x`. The suggestion is not equivalent and does not compile: `!x` on a `bool?` is `CS0266`/`CS0023`, and using a `bool?` directly as a condition is `CS0266`. Comparing a nullable bool with a literal is the idiomatic way to write "has a value and it is false", and it is also the form EF Core translates cleanly (`x is false` is not allowed in an expression tree, and `x.HasValue && !x.Value` is what the rule is meant to steer people away from).

`simplifyBinaryExpr` in `SimplifyBoolExpr.ql` only matches on the operator; it never checks the operand's type. Restricting the `==`/`!=`-with-literal cases to operands whose type is `bool` (not `Nullable`) would remove the false positive.

The alert is raised as a Code Quality finding on every PR touching one of these comparisons, and there is no way to filter a rule under Code Quality's default setup, so it recurs.

**Code samples or links to source code**

```csharp
public class Rule
{
public bool? ScanToLocation { get; set; }
public int? LocationId { get; set; }
}

// Flagged: "The expression 'A == false' can be simplified to '!A'."
// !r.ScanToLocation does not compile for a bool?.
var rules = context.Rules
.Where(r => r.ScanToLocation == false && r.LocationId != null)
.ToList();

// Also flagged, same problem
var off = rules.Where(r => r.ScanToLocation == false);
```

Expected: no alert when the operand is `Nullable`.

**URL to the alert on GitHub code scanning (optional)**

Private repository (Code Quality PR comments, CodeQL CLI 2.27.0 with the `code-quality` suite).

貢獻指南

開啟貢獻指南

研究方向

先從 SimplifyBoolExpr.ql 中的 simplifyBinaryExpr 開始,然後檢查 == 和 != 字面量情況如何判定運算元型別。使用 issue 中的 nullable-bool 範例,驗證比較不再產生 alert,同時現有的簡化行為維持不變。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
csharp
領域
devtools
Issue 類型
缺陷
難度
2/5
預估耗時
1-3 小時
活躍度
活躍
描述清晰度
描述清楚
新手友好度
82/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。