Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

False Negative: ContainsTypeMismatch.ql misses mismatched collection lookups once the receiver is routed through a raw alias.

Ouverte
#21,539 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

Évaluation

Difficulté
3/5
Temps estimé
1-2 jours
Accessibilité débutants
58/100
Type d'issue
Bug
Clarté
Plutôt claire
Activité
Calme
Stack technique
java
Domaine
devtools

Piste de recherche

Commencez par le checker Likely Bugs/Collections/ContainsTypeMismatch.ql et le cas PosCase5_Var5.java décrit dans l’issue. Suivez comment le récepteur Vector est récupéré après son affectation à rawVec, puis ajoutez ou mettez à jour un test de régression afin que rawVec.lastIndexOf(arg) soit signalé comme une incompatibilité entre Byte et Float.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

False Negative: ContainsTypeMismatch.ql misses mismatched collection lookups once the receiver is routed through a raw alias.

Version
codeql 2.24.3

Checker

  • Checker id: Likely Bugs/Collections/ContainsTypeMismatch.ql
  • Checker description: This checker detects calls to Java collection methods where the argument type is incompatible with the collection's element type, such as calling contains with an argument that can never match any element in the collection.

Description of the false negative

The collection still holds Byte values and the lookup still uses a Float. The only change is that the call goes through a raw alias before reaching lastIndexOf(...).

That should not be enough to hide the type mismatch from Likely Bugs/Collections/ContainsTypeMismatch.ql.

Affected test cases

PosCase5_Var5.java

rawVec.lastIndexOf(arg) is still searching a Vector<Byte> with a Float. The raw alias obscures generics, but it does not make the lookup compatible.

// Call lastIndexOf on a Vector<Byte> with an argument of type Float (first argument) should be flagged as incompatible type.
package scensct.var.pos;

import java.util.Vector;

public class PosCase5_Var5 {
    public static void main(String[] args) {
        Vector<? extends Byte> vec = new Vector<Byte>();
        // Wildcard capture: still Vector<Byte> compatible
        Float arg = 3.14f;
        // Raw type manipulation to obscure but preserve generic info
        Vector rawVec = vec;
        // Checker must still detect Byte vs Float incompatibility
        rawVec.lastIndexOf(arg);
    }
}

Cause analysis

This looks like a generic-type recovery gap. Once the receiver is widened to a raw type, the query appears to stop using the element type information from the original collection.

That is too weak for this rule. Raw aliases are common in older Java code, and they do not change the fact that a Float can never match an element from a Vector<Byte>.

References

None known.

Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 16 h
PR mergées (30 j)
143

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de github/codeql

Toutes les issues de github/codeql

Issues similaires

Plus d'issues DevTools

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.