Skip to content

Sorting out false positives for A0-1-2 and A0-1-4 #181

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 28 commits into from
Feb 22, 2023

Conversation

jeongsoolee09
Copy link
Contributor

@jeongsoolee09 jeongsoolee09 commented Feb 3, 2023

Description

Strengthen query by getting rid of false positive cases for both Autosar A0-1-2: Unused Return Value and A0-1-4: Unused Parameter.

Change request type

  • Release or process automation (GitHub workflows, internal scripts)
  • Internal documentation
  • External documentation
  • Query files (.ql, .qll, .qls or unit tests)
  • External scripts (analysis report or other code shipped as part of a release)

Rules with added or modified queries

  • No rules added
  • Queries have been added for the following rules:
    • rule number here
  • Queries have been modified for the following rules:
    • Autosar A0-1-2
    • Autosar A0-1-4

Release change checklist

A change note (development_handbook.md#change-notes) is required for any pull request which modifies:

  • The structure or layout of the release artifacts.
  • The evaluation performance (memory, execution time) of an existing query.
  • The results of an existing query in any circumstance.

If you are only adding new rule queries, a change note is not required.

Author: Is a change note required?

  • Yes
  • No

🚨🚨🚨
Reviewer: Confirm that format of shared queries (not the .qll file, the
.ql file that imports it) is valid by running them within VS Code.

  • Confirmed

Reviewer: Confirm that either a change note is not required or the change note is required and has been added.

  • Confirmed

Query development review checklist

For PRs that add new queries or modify existing queries, the following checklist should be completed by both the author and reviewer:

Author

  • Have all the relevant rule package description files been checked in?
  • Have you verified that the metadata properties of each new query is set appropriately?
  • Do all the unit tests contain both "COMPLIANT" and "NON_COMPLIANT" cases?
  • Are the alert messages properly formatted and consistent with the style guide?
  • Have you run the queries on OpenPilot and verified that the performance and results are acceptable?
    As a rule of thumb, predicates specific to the query should take no more than 1 minute, and for simple queries be under 10 seconds. If this is not the case, this should be highlighted and agreed in the code review process.
  • Does the query have an appropriate level of in-query comments/documentation?
  • Have you considered/identified possible edge cases?
  • Does the query not reinvent features in the standard library?
  • Can the query be simplified further (not golfed!)

Reviewer

  • Have all the relevant rule package description files been checked in?
  • Have you verified that the metadata properties of each new query is set appropriately?
  • Do all the unit tests contain both "COMPLIANT" and "NON_COMPLIANT" cases?
  • Are the alert messages properly formatted and consistent with the style guide?
  • Have you run the queries on OpenPilot and verified that the performance and results are acceptable?
    As a rule of thumb, predicates specific to the query should take no more than 1 minute, and for simple queries be under 10 seconds. If this is not the case, this should be highlighted and agreed in the code review process.
  • Does the query have an appropriate level of in-query comments/documentation?
  • Have you considered/identified possible edge cases?
  • Does the query not reinvent features in the standard library?
  • Can the query be simplified further (not golfed!)

@jeongsoolee09 jeongsoolee09 marked this pull request as draft February 3, 2023 00:14
@jeongsoolee09 jeongsoolee09 marked this pull request as ready for review February 3, 2023 21:51
@jeongsoolee09
Copy link
Contributor Author

Query performance for A0-1-2 is not good (33.8s):

$ codeql database analyze --format=sarif-latest --output=a0-1-2.sarif --search-path=./ -- ../codeql-coding-standards-release-engineering/data/commaai-openpilot-72d1744d830bc249d8761a1d843a98fb0ced49fe-cpp/ cpp/autosar/src/rules/A0-1-2/UnusedReturnValue.ql

Running queries.
Compiling query plan for .../codeql-coding-standards/cpp/autosar/src/rules/A0-1-2/UnusedReturnValue.ql.
Resolving database upgrade for .../codeql-coding-standards/cpp/autosar/src/rules/A0-1-2/UnusedReturnValue.ql
[1/1 comp 4.1s] Compiled .../codeql-coding-standards/cpp/autosar/src/rules/A0-1-2/UnusedReturnValue.ql.
UnusedReturnValue.ql: [1/1 eval 33.8s] Results written to autosar-cpp-coding-standards/rules/
Shutting down query evaluator.
Interpreting results.

@jeongsoolee09 jeongsoolee09 self-assigned this Feb 6, 2023
Copy link
Collaborator

@lcartey lcartey left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good! Just a few comments on some stylistic details, and some subtleties around casts/conversions.

@github-actions
Copy link

🤖 Beep Boop! Matrix Testing for this PR has been initiated. Please check back later for results.

💡 If you do not hear back from me please check my status! I will report even if this PR does not contain files eligible for matrix testing.

@jeongsoolee09 jeongsoolee09 merged commit c32a12a into main Feb 22, 2023
@jeongsoolee09 jeongsoolee09 deleted the jeongsoolee09/a0-1-2_and_a0-1-4 branch February 22, 2023 15:25
@lcartey
Copy link
Collaborator

lcartey commented Feb 22, 2023

@jeongsoolee09 I just approved this, but noticed we're missing a change note. Can you please raise a separate PR to add a change note as per the developer handbook:
https://github.com/github/codeql-coding-standards/blob/main/docs/development_handbook.md#change-notes
Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Development

Successfully merging this pull request may close these issues.

2 participants