github / github/codeql

Java: `PrimitiveType.getADefaultValue()` is misleading and might not work correctly

Ouverte
#6,615 2 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
acknowledged Java question
Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 15 h
PR mergées (30 j)
141

Description

There are several issues with `PrimitiveType.getADefaultValue()`:
- The [documentation says](https://codeql.github.com/codeql-standard-libraries/java/semmle/code/java/Type.qll/predicate.Type$PrimitiveType$getADefaultValue.0.html):
> Gets a default value for this primitive type, as assigned by the compiler for variables that are declared but not initialized explicitly.

This is misleading; unless the source actually contains literals with the default value, the predicate will have no result (except for some `BooleanLiteral`s which are found in the JDK code as part of annotations). For example for this Java code:
```java
class DefaultLiteral {
byte b;
short s;
int i;
long l;
float f;
double d;
boolean bool;
char c;

Object o;
}
```
the following query only finds `BooleanLiteral`s:
```ql
import java

from PrimitiveType t, Literal defaultValue
where
defaultValue = t.getADefaultValue()
select t, defaultValue, defaultValue.getLocation()
```
- The way it matches literals by using `getLiteral()` misses some cases where `getValue()` would actually represent the default value (relates to #6612).

Would it make sense to deprecate the predicate (for removal) and instead adjust the only query using it (`DeadStoreOfLocal.ql`)?
It appears that query actually wants to find out if an assigned literal has a default value; so maybe it should be rewritten to explicitly test that. (Note that adding a predicate `Literal.hasDefaultValue()` might not make much sense because technically for `StringLiteral`s type `String` the default value is `null`; and `NullLiteral` has no type which could occur as field type.)

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.