github / github/codeql

Java: TypeAccess matches implicit access

未關閉
#3,648 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
Java question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the issue**
It appears `TypeAccess` matches implicit (?) access of types, and that even when it has to hold `fromSource()`. This is not documented, and even QL's built-in query [`java/unused-import`](https://github.com/github/codeql/blob/master/java/ql/src/Violations%20of%20Best%20Practice/legacy/UnnecessaryImport.ql) appears to not consider this.
This behavior renders `TypeAccess` useless for certain queries.

Try the query below on the demo projects on https://lgtm.com/query:
```ql
import java
import semmle.code.java.Conversions

from TypeAccess typeAccess, RefType type, Location location, int expectedLength, int startColumn, int actualLength
where
type = typeAccess.getType()
and location = typeAccess.getLocation()
and type = type.getErasure()
and not type instanceof GenericType
and not type.hasAnnotation()
and not typeAccess.hasQualifier()
and expectedLength = type.getName().length()
// Ignore type access spanning multiple lines
and location.getNumberOfLines() = 1
and startColumn = location.getStartColumn()
// + 1 because both are inclusive
and actualLength = location.getEndColumn() - startColumn + 1
and expectedLength != actualLength
select typeAccess, expectedLength, startColumn, actualLength
```

While it does match some actual explicit type access (where the type is fully qualified) it also matches enum constant declarations, complete lambda bodies and probably other non-explicit access.

Possibly related to #3644.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。