Rust: False positive for unused variable names
还没有人认领这个 Issue。
评估
调研方向
先从链接的代码扫描警报和 Rust 代码片段开始,然后跟踪 CodeQL Rust 未使用变量查询对 format! 插值的处理方式。完成的标准是:查询不再将 name 报告为未使用,同时仍能检测出确实未使用的变量。
由索引模型根据 Issue 内容生成。
描述
Description of the false positive
CodeQL seems to produce false positives for Rust variables in format strings.
Code samples or links to source code
On 2026-08-13, the folllowing Rust snippet got flagged by CodeQL on https://github.com/alltheplaces/osm-diffs/pull/660. CodeQL posted a notice, claiming Variable 'name' is not used. However, the variable does get used in this snippet, via a format! macro. We also check for unused variables with clippy, which does not flag an unused variable for this code. So, this looks like a false positive from CodeQL.
let producers: Vec<_> = sources
.into_iter()
.map(|(name, reader)| {
let tx = tx.clone();
s.spawn(move || -> Result<()> {
for record in reader.iter()? {
let bytes = record?;
let fti = FeatureToIndex::decode(bytes.as_slice()).with_context(|| {
format!("failed to decode a FeatureToIndex record from {name}")
})?;
tx.send(fti)?;
progress_bar.inc(1);
}
Ok(())
})
})
.collect();
URL to the alert on GitHub code scanning (optional)
https://github.com/alltheplaces/osm-diffs/security/code-scanning/30
- 主要语言
- CodeQL
- 星标
- 10.1k
- 派生
- 2.1k
- 平均合并
- 2 天 11 小时
- 30 天内合并 PR
- 129
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/codeql 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 84/100
-
难度 2/5 1-3 小时 新手友好度 82/100
-
难度 2/5 1-3 小时 新手友好度 78/100
-
false-positive
难度 2/5 1-3 小时 新手友好度 70/100
-
false-positive
难度 3/5 1-2 天 新手友好度 68/100
相似的 Issue
-
enhancement
难度 2/5 1-3 小时 新手友好度 76/100
TheManticoreProject/Manticore#1383 ·
-
难度 2/5 1-3 小时 新手友好度 75/100
dotnet/arcade-skills#51 ·
-
难度 2/5 1-3 小时 新手友好度 84/100
ethereum-optimism/factory#64 ·
-
难度 2/5 1-3 小时 新手友好度 82/100
zitadel/zitadel-go#628 ·
-
难度 2/5 1-3 小时 新手友好度 84/100
phoenixframework/phoenix#6847 ·