github / github/codeql

False positive results of Finding spurious @param tags

未關閉
#4,870 6 則留言 0 個 reaction 已指派 1 人 已被 @yo-h 認領 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the issue**

I have found some false positive results of [`Finding spurious @param tags`](https://codeql.github.com/docs/codeql-language-guides/javadoc/#example-finding-spurious-param-tags). For the below query:

```
import java

from Callable c, ParamTag pt
where c.getDoc().getJavadoc() = pt.getParent() and
not c.getAParameter().hasName(pt.getParamName())
select pt, "Spurious @param tag."
```

The query [results](https://lgtm.com/projects/g/apache/maven/snapshot/2e3f49b67b3b4076b9a5a11f6eecd66928a9c26b/files/maven-core/src/main/java/org/apache/maven/project/ReactorModelPool.java?sort=name&dir=ASC&mode=heatmap#L49) of apache/maven are false positive.

![image](https://user-images.githubusercontent.com/12164075/102954811-581c2e80-450f-11eb-9296-d23a01310809.png)

Obviously, the param is alreay stated in the corresponding param tags. The reson is the comma after param. For example, there is a `,` after `groupId` in `@param groupId, never {@code null}`. Hence, the result of `pt.getParamName` is `groupId,` instead of `groupId` which causes the false positive results.

It's common to add comma after param in the param tag. I have searched for param tag with comma for 7 projects. There are 17 results intotal.

```
import java

from ParamTag pt
where pt.getParamName().matches("%,")
select pt
```

![image](https://user-images.githubusercontent.com/12164075/102962074-02e91880-4521-11eb-858a-c59cdd805065.png)

Hence, it's suggested to replace the special characters in the param tag which should not be valid part of param.

I have created two pr(#4871, #4872) for this problem. One is to modify the result of `pt.getParamName()`. The other one is to modify the method of `getParamName()` directly. One of each pr be mereged would be appreciated.

As there may more characters for the param tag which not only limit to `,`. It's suggested to utilize `regexpReplaceAll` to replace more kinds of characters.

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。