github / github/codeql

Java: `PrimitiveType.getADefaultValue()` is misleading and might not work correctly

未關閉
#6,615 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
acknowledged Java question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

There are several issues with `PrimitiveType.getADefaultValue()`:
- The [documentation says](https://codeql.github.com/codeql-standard-libraries/java/semmle/code/java/Type.qll/predicate.Type$PrimitiveType$getADefaultValue.0.html):
> Gets a default value for this primitive type, as assigned by the compiler for variables that are declared but not initialized explicitly.

This is misleading; unless the source actually contains literals with the default value, the predicate will have no result (except for some `BooleanLiteral`s which are found in the JDK code as part of annotations). For example for this Java code:
```java
class DefaultLiteral {
byte b;
short s;
int i;
long l;
float f;
double d;
boolean bool;
char c;

Object o;
}
```
the following query only finds `BooleanLiteral`s:
```ql
import java

from PrimitiveType t, Literal defaultValue
where
defaultValue = t.getADefaultValue()
select t, defaultValue, defaultValue.getLocation()
```
- The way it matches literals by using `getLiteral()` misses some cases where `getValue()` would actually represent the default value (relates to #6612).

Would it make sense to deprecate the predicate (for removal) and instead adjust the only query using it (`DeadStoreOfLocal.ql`)?
It appears that query actually wants to find out if an assigned literal has a default value; so maybe it should be rewritten to explicitly test that. (Note that adding a predicate `Literal.hasDefaultValue()` might not make much sense because technically for `StringLiteral`s type `String` the default value is `null`; and `NullLiteral` has no type which could occur as field type.)

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。