github / github/codeql

Java: Record components (and their annotations) are not extracted

未关闭
#7,727 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
Java
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

The components of a Record class are currently not modeled by CodeQL, and their annotations are not extracted. Therefore it is not possible to test for annotations which only use `ElementType.RECORD_COMPONENT`, or for annotations with `ElementType.METHOD` which only exist in source but not in the class file because the corresponding accessor method is overridden.

The backing private field as well as the implicit accessor method are extracted.

Example:
```java
import static java.lang.annotation.RetentionPolicy.RUNTIME;

import java.lang.annotation.ElementType;
import java.lang.annotation.Retention;
import java.lang.annotation.Target;

record RecordTest(
@RecordComponentAnnotation
int i
) {
@Retention(RUNTIME)
@Target(ElementType.RECORD_COMPONENT)
@interface RecordComponentAnnotation { }
}
```

The following query does not find any usage of `@RecordComponentAnnotation`, and does not have any element modeling the Record component as result:
```ql
import java

from Top t
where t.getLocation().getFile().getBaseName().matches("RecordTest%")
select t, t.getLocation().getStartLine(), t.getPrimaryQlClasses()
```

Interestingly CodeQL reports a `FieldDeclaration` at the location of the component.
This issue might be solvable by modeling the component using the internal field (pretending the field is also the component), but this can cause inaccuracies for annotations, e.g.:
- In the byte code (and accessible through reflection) an annotation with `ElementType.RECORD_COMPONENT` is only present on the component, and `ElementType.FIELD` is only present on the internal field. With this approach both would be present on the field.
- It would not be possible to model an annotation with `ElementType.METHOD` on the component, or it would at least be weird that a `Field` has a method annotation

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。