github / github/codeql

Java: RawType getASourceSupertype() is not generic type / getting source declaration or supertype is cumbersome

未关闭
#5,521 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

It appears that for a `RawType` the result of `getASourceSupertype()` will not be the generic type. (This is also described by the `getASourceSupertype()` [documentation](https://codeql.github.com/codeql-standard-libraries/java/semmle/code/java/Type.qll/predicate.Type$RefType$getASourceSupertype.0.html).)

In addition to that there are the following issues:
- CodeQL raw types have a `<>` at the end of their name, therefore a check for the class name such as `getDeclaringType().getASourceSupertype*().hasQualifiedName("java.util", "List")` would not hold due to the trailing `<>`.
- Access of static fields and methods declared on a generic class, but only when explicitly using the declaring class as qualifier, are treated like accesses on a raw type (`fieldAccess.getQualifier().getType()` and `methodAccess.getDeclaringType()` will have a raw type as result).
Whether that is the correct behavior might be a different story (now #5593).

This all combined causes some false negatives for the pattern `getDeclaringType().getASourceSupertype*()` (which is also used a few times in the CodeQL codebase).
Is there a more 'correct' predicate for this task? A workaround might be `getDeclaringType().getASourceSupertype*().getErasure()`.
If there is no alternative currently, would it make sense to change the behavior of `getASourceSupertype()` or introduce a new predicate?

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。