Rust: False positive for unused variable names
還沒有人認領這個 Issue。
評估
研究方向
先從連結的程式碼掃描警示和 Rust 程式碼片段開始,然後追蹤 CodeQL Rust 未使用變數查詢如何處理 format! 插值。完成的標準是:查詢不再將 name 回報為未使用,同時仍能偵測出確實未使用的變數。
由索引模型根據 Issue 內容生成。
描述
Description of the false positive
CodeQL seems to produce false positives for Rust variables in format strings.
Code samples or links to source code
On 2026-08-13, the folllowing Rust snippet got flagged by CodeQL on https://github.com/alltheplaces/osm-diffs/pull/660. CodeQL posted a notice, claiming Variable 'name' is not used. However, the variable does get used in this snippet, via a format! macro. We also check for unused variables with clippy, which does not flag an unused variable for this code. So, this looks like a false positive from CodeQL.
let producers: Vec<_> = sources
.into_iter()
.map(|(name, reader)| {
let tx = tx.clone();
s.spawn(move || -> Result<()> {
for record in reader.iter()? {
let bytes = record?;
let fti = FeatureToIndex::decode(bytes.as_slice()).with_context(|| {
format!("failed to decode a FeatureToIndex record from {name}")
})?;
tx.send(fti)?;
progress_bar.inc(1);
}
Ok(())
})
})
.collect();
URL to the alert on GitHub code scanning (optional)
https://github.com/alltheplaces/osm-diffs/security/code-scanning/30
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 10 小時
- 30 天內合併 PR
- 134
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
github/codeql 的其他 Issue
-
難度 2/5 1-3 小時 新手友好度 84/100
-
難度 2/5 1-3 小時 新手友好度 82/100
-
難度 2/5 1-3 小時 新手友好度 78/100
-
false-positive
難度 2/5 1-3 小時 新手友好度 70/100
-
false-positive
難度 3/5 1-2 天 新手友好度 68/100
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 78/100
-
難度 2/5 1-3 小時 新手友好度 88/100
sipyourdrink-ltd/bernstein#6191 ·
-
security severity:low track:open-source
難度 2/5 1-3 小時 新手友好度 78/100
-
難度 2/5 1-3 小時 新手友好度 72/100
gwen001/offsectools_www#2055 ·
-
難度 2/5 1-3 小時 新手友好度 78/100
WalletConnect/actions#112 ·