github / github/codeql

Java: Record components (and their annotations) are not extracted

Ouverte
#7,727 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
Java
Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 15 h
PR mergées (30 j)
141

Description

The components of a Record class are currently not modeled by CodeQL, and their annotations are not extracted. Therefore it is not possible to test for annotations which only use `ElementType.RECORD_COMPONENT`, or for annotations with `ElementType.METHOD` which only exist in source but not in the class file because the corresponding accessor method is overridden.

The backing private field as well as the implicit accessor method are extracted.

Example:
```java
import static java.lang.annotation.RetentionPolicy.RUNTIME;

import java.lang.annotation.ElementType;
import java.lang.annotation.Retention;
import java.lang.annotation.Target;

record RecordTest(
@RecordComponentAnnotation
int i
) {
@Retention(RUNTIME)
@Target(ElementType.RECORD_COMPONENT)
@interface RecordComponentAnnotation { }
}
```

The following query does not find any usage of `@RecordComponentAnnotation`, and does not have any element modeling the Record component as result:
```ql
import java

from Top t
where t.getLocation().getFile().getBaseName().matches("RecordTest%")
select t, t.getLocation().getStartLine(), t.getPrimaryQlClasses()
```

Interestingly CodeQL reports a `FieldDeclaration` at the location of the component.
This issue might be solvable by modeling the component using the internal field (pretending the field is also the component), but this can cause inaccuracies for annotations, e.g.:
- In the byte code (and accessible through reflection) an annotation with `ElementType.RECORD_COMPONENT` is only present on the component, and `ElementType.FIELD` is only present on the internal field. With this approach both would be present on the field.
- It would not be possible to model an annotation with `ElementType.METHOD` on the component, or it would at least be weird that a `Field` has a method annotation

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.