github / github/codeql

Java: CompilationUnit elements in Module are `.class` files instead of `.java` files

Offen
#5,556 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Java not security question
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

There are two predicates for matching `CompilationUnit` to corresponding `Module`, [`Module.getACompilationUnit()`](https://codeql.github.com/codeql-standard-libraries/java/semmle/code/java/Modules.qll/predicate.Modules$Module$getACompilationUnit.0.html) and [`CompilationUnit.getModule()`](https://codeql.github.com/codeql-standard-libraries/java/semmle/code/java/CompilationUnit.qll/predicate.CompilationUnit$CompilationUnit$getModule.0.html) (both using the database predicate `cumodule(@file, @module)`).
The issue is that the reported compilation units appear to always be the `.class` files instead of the source `.java` files, even when the `module-info.java` file was part of the source.

For example the following query against OpenJDK has no results:
```ql
import java

from Module m, RefType t
where
t.fromSource()
and t.getCompilationUnit().getModule() = m
select m, t
```
[Query Console link](https://lgtm.com/query/2379112509629488370/)

However, if you manually try to match `.class` compilation units with `.java` compilation units, you will get the desired results:
```ql
import java

predicate areProbablySame(CompilationUnit classComp, CompilationUnit sourceComp) {
classComp.getPackage() = sourceComp.getPackage()
and classComp.getName() = sourceComp.getName()
}

from Module m, TopLevelType t, CompilationUnit classComp, CompilationUnit sourceComp
where
t.fromSource()
and sourceComp = t.getCompilationUnit()
and classComp = m.getACompilationUnit()
and areProbablySame(classComp, sourceComp)
select m, t, classComp.getRelativePath(), sourceComp.getRelativePath()
```
[Query Console link](https://lgtm.com/query/8137102133532318116/)

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.