mirror of
https://github.com/github/codeql.git
synced 2025-12-17 01:03:14 +01:00
Java: Improve not closing resource query; add tests
This commit is contained in:
@@ -17,14 +17,14 @@ import CloseType
|
||||
|
||||
predicate readerType(RefType t) {
|
||||
exists(RefType sup | sup = t.getASupertype*() |
|
||||
sup.hasName(["Reader", "InputStream"]) or
|
||||
sup.hasQualifiedName("java.io", ["Reader", "InputStream"]) or
|
||||
sup.hasQualifiedName("java.util.zip", "ZipFile")
|
||||
)
|
||||
}
|
||||
|
||||
predicate safeReaderType(RefType t) {
|
||||
exists(RefType sup | sup = t.getASupertype*() |
|
||||
sup.hasName(["CharArrayReader", "StringReader", "ByteArrayInputStream"])
|
||||
sup.hasQualifiedName("java.io", ["CharArrayReader", "StringReader", "ByteArrayInputStream"])
|
||||
)
|
||||
}
|
||||
|
||||
|
||||
@@ -16,12 +16,14 @@
|
||||
import CloseType
|
||||
|
||||
predicate writerType(RefType t) {
|
||||
exists(RefType sup | sup = t.getASupertype*() | sup.hasName(["Writer", "OutputStream"]))
|
||||
exists(RefType sup | sup = t.getASupertype*() |
|
||||
sup.hasQualifiedName("java.io", ["Writer", "OutputStream"])
|
||||
)
|
||||
}
|
||||
|
||||
predicate safeWriterType(RefType t) {
|
||||
exists(RefType sup | sup = t.getASupertype*() |
|
||||
sup.hasName(["CharArrayWriter", "StringWriter", "ByteArrayOutputStream"])
|
||||
sup.hasQualifiedName("java.io", ["CharArrayWriter", "StringWriter", "ByteArrayOutputStream"])
|
||||
)
|
||||
}
|
||||
|
||||
|
||||
@@ -1,2 +1,4 @@
|
||||
| CloseReader.java:11:42:11:71 | new FileReader(...) | This FileReader is not always closed on method exit. |
|
||||
| CloseReader.java:44:6:44:40 | new FileInputStream(...) | This FileInputStream is not always closed on method exit. |
|
||||
| CloseReader.java:18:42:18:71 | new FileReader(...) | This FileReader is not always closed on method exit. |
|
||||
| CloseReader.java:23:20:23:50 | new FileInputStream(...) | This FileInputStream is not always closed on method exit. |
|
||||
| CloseReader.java:33:6:33:40 | new FileInputStream(...) | This FileInputStream is not always closed on method exit. |
|
||||
| CloseReader.java:43:21:43:43 | new ZipFile(...) | This ZipFile is not always closed on method exit. |
|
||||
|
||||
@@ -1,41 +1,30 @@
|
||||
import java.io.BufferedReader;
|
||||
import java.io.ByteArrayInputStream;
|
||||
import java.io.CharArrayReader;
|
||||
import java.io.Closeable;
|
||||
import java.io.FileInputStream;
|
||||
import java.io.FileNotFoundException;
|
||||
import java.io.FileReader;
|
||||
import java.io.IOException;
|
||||
import java.io.InputStream;
|
||||
import java.io.InputStreamReader;
|
||||
import java.io.IOException;
|
||||
import java.io.Reader;
|
||||
import java.io.StringReader;
|
||||
import java.util.zip.ZipFile;
|
||||
|
||||
class CloseReader {
|
||||
|
||||
public static void test1() throws IOException {
|
||||
void test1() throws IOException {
|
||||
BufferedReader br = new BufferedReader(new FileReader("C:\\test.txt"));
|
||||
System.out.println(br.readLine());
|
||||
}
|
||||
|
||||
public static void test2() throws FileNotFoundException, IOException {
|
||||
BufferedReader br = null;
|
||||
try {
|
||||
br = new BufferedReader(new FileReader("C:\\test.txt"));
|
||||
System.out.println(br.readLine());
|
||||
}
|
||||
finally {
|
||||
if(br != null)
|
||||
br.close(); // 'br' is closed
|
||||
}
|
||||
void test2() throws IOException {
|
||||
InputStream in = new FileInputStream("file.bin");
|
||||
in.read();
|
||||
}
|
||||
|
||||
public static void test3() throws IOException {
|
||||
BufferedReader br = null;
|
||||
try {
|
||||
br = new BufferedReader(new FileReader("C:\\test.txt"));
|
||||
System.out.println(br.readLine());
|
||||
}
|
||||
finally {
|
||||
cleanup(br); // 'br' is closed within a helper method
|
||||
}
|
||||
}
|
||||
|
||||
public static void test4() throws IOException {
|
||||
void test3() throws IOException {
|
||||
InputStreamReader reader = null;
|
||||
try {
|
||||
// InputStreamReader may throw an exception, in which case the ...
|
||||
@@ -50,7 +39,35 @@ class CloseReader {
|
||||
}
|
||||
}
|
||||
|
||||
public static void test5() throws IOException {
|
||||
void test4() throws IOException {
|
||||
ZipFile zipFile = new ZipFile("file.zip");
|
||||
System.out.println(zipFile.getComment());
|
||||
}
|
||||
|
||||
void testCorrect1() throws IOException {
|
||||
BufferedReader br = null;
|
||||
try {
|
||||
br = new BufferedReader(new FileReader("C:\\test.txt"));
|
||||
System.out.println(br.readLine());
|
||||
}
|
||||
finally {
|
||||
if(br != null)
|
||||
br.close(); // 'br' is closed
|
||||
}
|
||||
}
|
||||
|
||||
void testCorrect2() throws IOException {
|
||||
BufferedReader br = null;
|
||||
try {
|
||||
br = new BufferedReader(new FileReader("C:\\test.txt"));
|
||||
System.out.println(br.readLine());
|
||||
}
|
||||
finally {
|
||||
cleanup(br); // 'br' is closed within a helper method
|
||||
}
|
||||
}
|
||||
|
||||
void testCorrect3() throws IOException {
|
||||
FileInputStream fis = null;
|
||||
InputStreamReader reader = null;
|
||||
try {
|
||||
@@ -66,7 +83,7 @@ class CloseReader {
|
||||
}
|
||||
}
|
||||
|
||||
public static void test6() throws IOException {
|
||||
void testCorrect4() throws IOException {
|
||||
BufferedReader br = null;
|
||||
try {
|
||||
br = new BufferedReader(new FileReader("C:\\test.txt"));
|
||||
@@ -77,15 +94,15 @@ class CloseReader {
|
||||
}
|
||||
}
|
||||
|
||||
public static void cleanup(java.io.Closeable... closeables) throws IOException {
|
||||
for (java.io.Closeable c : closeables) {
|
||||
void cleanup(Closeable... closeables) throws IOException {
|
||||
for (Closeable c : closeables) {
|
||||
if (c != null) {
|
||||
c.close();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
public static class LogFile {
|
||||
static class LogFile {
|
||||
private BufferedReader fileRd;
|
||||
LogFile(String path) {
|
||||
FileReader fr = null;
|
||||
@@ -100,9 +117,21 @@ class CloseReader {
|
||||
private void init(InputStreamReader reader) {
|
||||
fileRd = new BufferedReader(reader);
|
||||
}
|
||||
public void readStuff() throws java.io.IOException {
|
||||
public void readStuff() throws IOException {
|
||||
System.out.println(fileRd.readLine());
|
||||
fileRd.close();
|
||||
}
|
||||
}
|
||||
|
||||
// Classes which should be ignored
|
||||
void testIgnore() throws IOException {
|
||||
Reader r1 = new CharArrayReader(new char[] {'a'});
|
||||
r1.read();
|
||||
|
||||
Reader r2 = new StringReader("a");
|
||||
r2.read();
|
||||
|
||||
InputStream i1 = new ByteArrayInputStream(new byte[] {1});
|
||||
i1.read();
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1 +1 @@
|
||||
Likely Bugs/Resource Leaks/CloseReader.ql
|
||||
Likely Bugs/Resource Leaks/CloseReader.ql
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
| CloseWriter.java:17:42:17:71 | new FileWriter(...) | This FileWriter is not always closed on method exit. |
|
||||
| CloseWriter.java:22:22:22:53 | new FileOutputStream(...) | This FileOutputStream is not always closed on method exit. |
|
||||
| CloseWriter.java:32:6:32:41 | new FileOutputStream(...) | This FileOutputStream is not always closed on method exit. |
|
||||
@@ -0,0 +1,131 @@
|
||||
import java.io.BufferedWriter;
|
||||
import java.io.ByteArrayOutputStream;
|
||||
import java.io.CharArrayWriter;
|
||||
import java.io.Closeable;
|
||||
import java.io.FileOutputStream;
|
||||
import java.io.FileWriter;
|
||||
import java.io.IOException;
|
||||
import java.io.OutputStream;
|
||||
import java.io.OutputStreamWriter;
|
||||
import java.io.StringWriter;
|
||||
import java.io.Writer;
|
||||
import java.util.zip.ZipFile;
|
||||
|
||||
class CloseWriter {
|
||||
|
||||
void test1() throws IOException {
|
||||
BufferedWriter bw = new BufferedWriter(new FileWriter("C:\\test.txt"));
|
||||
bw.write("test");
|
||||
}
|
||||
|
||||
void test2() throws IOException {
|
||||
OutputStream out = new FileOutputStream("test.bin");
|
||||
out.write(1);
|
||||
}
|
||||
|
||||
void test3() throws IOException {
|
||||
OutputStreamWriter writer = null;
|
||||
try {
|
||||
// OutputStreamWriter may throw an exception, in which case the ...
|
||||
writer = new OutputStreamWriter(
|
||||
// ... FileOutputStream is not closed by the finally block
|
||||
new FileOutputStream("C:\\test.txt"), "UTF-8");
|
||||
writer.write("test");
|
||||
}
|
||||
finally {
|
||||
if (writer != null)
|
||||
writer.close();
|
||||
}
|
||||
}
|
||||
|
||||
void testCorrect1() throws IOException {
|
||||
BufferedWriter bw = null;
|
||||
try {
|
||||
bw = new BufferedWriter(new FileWriter("C:\\test.txt"));
|
||||
bw.write("test");
|
||||
}
|
||||
finally {
|
||||
if(bw != null)
|
||||
bw.close(); // 'bw' is closed
|
||||
}
|
||||
}
|
||||
|
||||
void testCorrect2() throws IOException {
|
||||
BufferedWriter bw = null;
|
||||
try {
|
||||
bw = new BufferedWriter(new FileWriter("C:\\test.txt"));
|
||||
bw.write("test");
|
||||
}
|
||||
finally {
|
||||
cleanup(bw); // 'bw' is closed within a helper method
|
||||
}
|
||||
}
|
||||
|
||||
void testCorrect3() throws IOException {
|
||||
FileOutputStream fos = null;
|
||||
OutputStreamWriter writer = null;
|
||||
try {
|
||||
fos = new FileOutputStream("C:\\test.txt");
|
||||
writer = new OutputStreamWriter(fos);
|
||||
writer.write("test");
|
||||
}
|
||||
finally {
|
||||
if (fos != null)
|
||||
fos.close(); // 'fos' is closed
|
||||
if (writer != null)
|
||||
writer.close(); // 'writer' is closed
|
||||
}
|
||||
}
|
||||
|
||||
void testCorrect4() throws IOException {
|
||||
BufferedWriter bw = null;
|
||||
try {
|
||||
bw = new BufferedWriter(new FileWriter("C:\\test.txt"));
|
||||
bw.write("test");
|
||||
}
|
||||
finally {
|
||||
cleanup(null, bw); // 'bw' is closed within a varargs helper method, invoked with multiple args
|
||||
}
|
||||
}
|
||||
|
||||
void cleanup(Closeable... closeables) throws IOException {
|
||||
for (Closeable c : closeables) {
|
||||
if (c != null) {
|
||||
c.close();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
static class LogFile {
|
||||
private BufferedWriter fileWr;
|
||||
LogFile(String path) {
|
||||
FileWriter fw = null;
|
||||
try {
|
||||
fw = new FileWriter(path);
|
||||
} catch (IOException e) {
|
||||
System.out.println("Error: File not readable: " + path);
|
||||
System.exit(1);
|
||||
}
|
||||
init(fw);
|
||||
}
|
||||
private void init(OutputStreamWriter writer) {
|
||||
fileWr = new BufferedWriter(writer);
|
||||
}
|
||||
public void writeStuff() throws IOException {
|
||||
fileWr.write("test");
|
||||
fileWr.close();
|
||||
}
|
||||
}
|
||||
|
||||
// Classes which should be ignored
|
||||
void testIgnore() throws IOException {
|
||||
Writer w1 = new CharArrayWriter();
|
||||
w1.write("test");
|
||||
|
||||
Writer w2 = new StringWriter();
|
||||
w2.write("test");
|
||||
|
||||
OutputStream o1 = new ByteArrayOutputStream();
|
||||
o1.write(1);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1 @@
|
||||
Likely Bugs/Resource Leaks/CloseWriter.ql
|
||||
Reference in New Issue
Block a user