github / github/codeql

Java: `MemberRefExpr.asMethod()` uses parameter types of referenced callable instead of types of functional method

Abierto
#5,706 0 comentarios 0 reacciones 0 asignados Ver en GitHub
enhancement Java
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

### Description
Relates to #3605

`MemberRefExpr.asMethod()` uses the parameter types of the referenced callable instead of the parameter types of the functional method it implements. For example using `void consumeObject(Object)` as referenced method for an `IntConsumer` will cause `asMethod()` to report that the signature is `consume(Object)` instead of `consume(int)`.

This prevents detecting any conversions, e.g. boxing or unboxing, which happen when the referenced callable would be called.
As workaround it is possible to check for the overridden method (because interestingly CodeQL at least claims that `consume(Object)` overrides `consume(int)`).

### Example
Java source:
```java
import java.util.function.*;

class MemberRefExprTest {
void consumeLong(long l) {
}

void consumeFloat(float f) {
}

void consumeObject(Object o) {
}

void test() {
// asMethod(): consume(long)
IntConsumer m1 = this::consumeLong;
// asMethod(): consume(float)
IntConsumer m2 = this::consumeFloat;
// asMethod(): consume(Object)
IntConsumer m3 = this::consumeObject;

// asMethod(): consume(Object)
Consumer m4 = this::consumeObject;
}
}
```

CodeQL query:
```ql
import java

from MemberRefExpr m, Method asMethod, Method overridden
where
asMethod = m.asMethod()
and asMethod.overrides(overridden)
select m, m.getReferencedCallable().getStringSignature() as referencedSig, asMethod.getStringSignature() as methodSig,
overridden.getStringSignature() as overriddenSig
```

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.