github / github/codeql

False positive results of Finding spurious @param tags

未关闭
#4,870 6 条评论 0 个 reaction 已指派 1 人 已被 @yo-h 认领 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

**Description of the issue**

I have found some false positive results of [`Finding spurious @param tags`](https://codeql.github.com/docs/codeql-language-guides/javadoc/#example-finding-spurious-param-tags). For the below query:

```
import java

from Callable c, ParamTag pt
where c.getDoc().getJavadoc() = pt.getParent() and
not c.getAParameter().hasName(pt.getParamName())
select pt, "Spurious @param tag."
```

The query [results](https://lgtm.com/projects/g/apache/maven/snapshot/2e3f49b67b3b4076b9a5a11f6eecd66928a9c26b/files/maven-core/src/main/java/org/apache/maven/project/ReactorModelPool.java?sort=name&dir=ASC&mode=heatmap#L49) of apache/maven are false positive.

![image](https://user-images.githubusercontent.com/12164075/102954811-581c2e80-450f-11eb-9296-d23a01310809.png)

Obviously, the param is alreay stated in the corresponding param tags. The reson is the comma after param. For example, there is a `,` after `groupId` in `@param groupId, never {@code null}`. Hence, the result of `pt.getParamName` is `groupId,` instead of `groupId` which causes the false positive results.

It's common to add comma after param in the param tag. I have searched for param tag with comma for 7 projects. There are 17 results intotal.

```
import java

from ParamTag pt
where pt.getParamName().matches("%,")
select pt
```

![image](https://user-images.githubusercontent.com/12164075/102962074-02e91880-4521-11eb-858a-c59cdd805065.png)

Hence, it's suggested to replace the special characters in the param tag which should not be valid part of param.

I have created two pr(#4871, #4872) for this problem. One is to modify the result of `pt.getParamName()`. The other one is to modify the method of `getParamName()` directly. One of each pr be mereged would be appreciated.

As there may more characters for the param tag which not only limit to `,`. It's suggested to utilize `regexpReplaceAll` to replace more kinds of characters.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。