github / github/codeql

Java: RawType getASourceSupertype() is not generic type / getting source declaration or supertype is cumbersome

未關閉
#5,521 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

It appears that for a `RawType` the result of `getASourceSupertype()` will not be the generic type. (This is also described by the `getASourceSupertype()` [documentation](https://codeql.github.com/codeql-standard-libraries/java/semmle/code/java/Type.qll/predicate.Type$RefType$getASourceSupertype.0.html).)

In addition to that there are the following issues:
- CodeQL raw types have a `<>` at the end of their name, therefore a check for the class name such as `getDeclaringType().getASourceSupertype*().hasQualifiedName("java.util", "List")` would not hold due to the trailing `<>`.
- Access of static fields and methods declared on a generic class, but only when explicitly using the declaring class as qualifier, are treated like accesses on a raw type (`fieldAccess.getQualifier().getType()` and `methodAccess.getDeclaringType()` will have a raw type as result).
Whether that is the correct behavior might be a different story (now #5593).

This all combined causes some false negatives for the pattern `getDeclaringType().getASourceSupertype*()` (which is also used a few times in the CodeQL codebase).
Is there a more 'correct' predicate for this task? A workaround might be `getDeclaringType().getASourceSupertype*().getErasure()`.
If there is no alternative currently, would it make sense to change the behavior of `getASourceSupertype()` or introduce a new predicate?

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。