False Negative: ContainsTypeMismatch.ql misses mismatched collection lookups once the receiver is routed through a raw alias.
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 3/5
- Tempo estimado
- 1-2 dias
- Facilidade para iniciantes
- 58/100
Direção de pesquisa
Comece pelo checker Likely Bugs/Collections/ContainsTypeMismatch.ql e pelo caso PosCase5_Var5.java descrito na issue. Rastreie como o receiver Vector é recuperado após a atribuição a rawVec e, em seguida, adicione ou atualize um teste de regressão para que rawVec.lastIndexOf(arg) seja reportado como uma incompatibilidade entre Byte e Float.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
False Negative: ContainsTypeMismatch.ql misses mismatched collection lookups once the receiver is routed through a raw alias.
Version
codeql 2.24.3
Checker
- Checker id:
Likely Bugs/Collections/ContainsTypeMismatch.ql - Checker description: This checker detects calls to Java collection methods where the argument type is incompatible with the collection's element type, such as calling
containswith an argument that can never match any element in the collection.
Description of the false negative
The collection still holds Byte values and the lookup still uses a Float. The only change is that the call goes through a raw alias before reaching lastIndexOf(...).
That should not be enough to hide the type mismatch from Likely Bugs/Collections/ContainsTypeMismatch.ql.
Affected test cases
PosCase5_Var5.java
rawVec.lastIndexOf(arg) is still searching a Vector<Byte> with a Float. The raw alias obscures generics, but it does not make the lookup compatible.
// Call lastIndexOf on a Vector<Byte> with an argument of type Float (first argument) should be flagged as incompatible type.
package scensct.var.pos;
import java.util.Vector;
public class PosCase5_Var5 {
public static void main(String[] args) {
Vector<? extends Byte> vec = new Vector<Byte>();
// Wildcard capture: still Vector<Byte> compatible
Float arg = 3.14f;
// Raw type manipulation to obscure but preserve generic info
Vector rawVec = vec;
// Checker must still detect Byte vs Float incompatibility
rawVec.lastIndexOf(arg);
}
}
Cause analysis
This looks like a generic-type recovery gap. Once the receiver is widened to a raw type, the query appears to stop using the element type information from the original collection.
That is too weak for this rule. Raw aliases are common in older Java code, and they do not change the fact that a Float can never match an element from a Vector<Byte>.
References
None known.
- Linguagem predominante
- CodeQL
- Estrelas
- 10.1k
- Forks
- 2.1k
- Merge médio
- 2d 16h
- PRs com merge (30d)
- 143
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de github/codeql
-
agentic-workflows
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
-
false-positive javascript
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
-
C#: cs/simplifiable-boolean-expression false positive on Nullable<bool> compared with a literal Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 82/100
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
-
false-positive
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
Todas as issues de github/codeql
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
palladius/rails8-app-on-gcp#145 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
elastic/gradle-plugins#156 ·
-
area:workflow bug ready-for-agent
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 75/100
fil-donadoni/tolaria#4409 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 65/100
dotenvx/dotenv-vscode#139 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 70/100
Fission-AI/OpenSpec#1960 ·