Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

False Negative : CloseSql.ql cannot detect bugs in the Try-Catch block.

未關閉
#21,393 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

評估

難度
4/5
預估耗時
3-5 天
新手友好度
48/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
停滯
技術堆疊
java
領域
security

研究方向

首先閱讀 CloseSql.ql 中的 Java 資源洩漏查詢,並將其對直接 createStatement 情況的處理與 Supplier 範例的 try-catch 區塊進行比較。完成的標準是:查詢回報由 supplier.get() 建立但遭捨棄的 Statement,同時保留現有的偵測功能。

由索引模型根據 Issue 內容生成。

描述

question

Version
codeql 2.23.9
Description of the issue
When I used java/Likely Bugs/Resource Leaks/CloseSql.ql to check the following code, it correctly reported an issue of improper use of createStatement.


import java.sql.Connection;
import java.sql.DriverManager;
import java.sql.SQLException;
import java.sql.Statement;
public class PosCase3 {
    public void test() throws SQLException {
        // Scenario 3: Primary resource assigned
        Connection conn = DriverManager.getConnection("url", "user", "pass");
        // Secondary created from primary, not assigned, not closed
        conn.createStatement(); // [REPORTED LINE]
        // Secondary Statement leak -> Positive detection.
    }
}

However, when using CloseSql.ql to detect the following code, no bug were detected and no bug were reported.

import java.sql.Connection;
import java.sql.DriverManager;
import java.sql.SQLException;
import java.sql.Statement;
import java.util.function.Supplier;
public class PosCase3_Var3 {
    public void test() throws SQLException {
        // Variant 3: Use Supplier to defer creation, then discard
        Connection conn = DriverManager.getConnection("url", "user", "pass");
        Supplier<Statement> supplier = () -> {
            try {
                return conn.createStatement();
            } catch (SQLException e) {
                throw new RuntimeException(e);
            }
        };
        supplier.get();  // Statement created and leaked
    }
}

主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 16 小時
30 天內合併 PR
143

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

github/codeql 的其他 Issue

查看 github/codeql 的全部 Issue

相似的 Issue

更多 Security Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。