github / github/codeql

Java: `MemberRefExpr.asMethod()` uses parameter types of referenced callable instead of types of functional method

未关闭
#5,706 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement Java
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

### Description
Relates to #3605

`MemberRefExpr.asMethod()` uses the parameter types of the referenced callable instead of the parameter types of the functional method it implements. For example using `void consumeObject(Object)` as referenced method for an `IntConsumer` will cause `asMethod()` to report that the signature is `consume(Object)` instead of `consume(int)`.

This prevents detecting any conversions, e.g. boxing or unboxing, which happen when the referenced callable would be called.
As workaround it is possible to check for the overridden method (because interestingly CodeQL at least claims that `consume(Object)` overrides `consume(int)`).

### Example
Java source:
```java
import java.util.function.*;

class MemberRefExprTest {
void consumeLong(long l) {
}

void consumeFloat(float f) {
}

void consumeObject(Object o) {
}

void test() {
// asMethod(): consume(long)
IntConsumer m1 = this::consumeLong;
// asMethod(): consume(float)
IntConsumer m2 = this::consumeFloat;
// asMethod(): consume(Object)
IntConsumer m3 = this::consumeObject;

// asMethod(): consume(Object)
Consumer m4 = this::consumeObject;
}
}
```

CodeQL query:
```ql
import java

from MemberRefExpr m, Method asMethod, Method overridden
where
asMethod = m.asMethod()
and asMethod.overrides(overridden)
select m, m.getReferencedCallable().getStringSignature() as referencedSig, asMethod.getStringSignature() as methodSig,
overridden.getStringSignature() as overriddenSig
```

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。