github / github/codeql

Java: RawType getASourceSupertype() is not generic type / getting source declaration or supertype is cumbersome

Ouverte
#5,521 2 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
question
Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 15 h
PR mergées (30 j)
141

Description

It appears that for a `RawType` the result of `getASourceSupertype()` will not be the generic type. (This is also described by the `getASourceSupertype()` [documentation](https://codeql.github.com/codeql-standard-libraries/java/semmle/code/java/Type.qll/predicate.Type$RefType$getASourceSupertype.0.html).)

In addition to that there are the following issues:
- CodeQL raw types have a `<>` at the end of their name, therefore a check for the class name such as `getDeclaringType().getASourceSupertype*().hasQualifiedName("java.util", "List")` would not hold due to the trailing `<>`.
- Access of static fields and methods declared on a generic class, but only when explicitly using the declaring class as qualifier, are treated like accesses on a raw type (`fieldAccess.getQualifier().getType()` and `methodAccess.getDeclaringType()` will have a raw type as result).
Whether that is the correct behavior might be a different story (now #5593).

This all combined causes some false negatives for the pattern `getDeclaringType().getASourceSupertype*()` (which is also used a few times in the CodeQL codebase).
Is there a more 'correct' predicate for this task? A workaround might be `getDeclaringType().getASourceSupertype*().getErasure()`.
If there is no alternative currently, would it make sense to change the behavior of `getASourceSupertype()` or introduce a new predicate?

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.