github / github/codeql

Java: CompilationUnit elements in Module are `.class` files instead of `.java` files

Open
#5,556 1 comment 0 reactions 0 assignees View on GitHub
Java not security question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

There are two predicates for matching `CompilationUnit` to corresponding `Module`, [`Module.getACompilationUnit()`](https://codeql.github.com/codeql-standard-libraries/java/semmle/code/java/Modules.qll/predicate.Modules$Module$getACompilationUnit.0.html) and [`CompilationUnit.getModule()`](https://codeql.github.com/codeql-standard-libraries/java/semmle/code/java/CompilationUnit.qll/predicate.CompilationUnit$CompilationUnit$getModule.0.html) (both using the database predicate `cumodule(@file, @module)`).
The issue is that the reported compilation units appear to always be the `.class` files instead of the source `.java` files, even when the `module-info.java` file was part of the source.

For example the following query against OpenJDK has no results:
```ql
import java

from Module m, RefType t
where
t.fromSource()
and t.getCompilationUnit().getModule() = m
select m, t
```
[Query Console link](https://lgtm.com/query/2379112509629488370/)

However, if you manually try to match `.class` compilation units with `.java` compilation units, you will get the desired results:
```ql
import java

predicate areProbablySame(CompilationUnit classComp, CompilationUnit sourceComp) {
classComp.getPackage() = sourceComp.getPackage()
and classComp.getName() = sourceComp.getName()
}

from Module m, TopLevelType t, CompilationUnit classComp, CompilationUnit sourceComp
where
t.fromSource()
and sourceComp = t.getCompilationUnit()
and classComp = m.getACompilationUnit()
and areProbablySame(classComp, sourceComp)
select m, t, classComp.getRelativePath(), sourceComp.getRelativePath()
```
[Query Console link](https://lgtm.com/query/8137102133532318116/)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.