You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

IssuePublisherTest.java 12KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289
  1. /*
  2. * SonarQube
  3. * Copyright (C) 2009-2023 SonarSource SA
  4. * mailto:info AT sonarsource DOT com
  5. *
  6. * This program is free software; you can redistribute it and/or
  7. * modify it under the terms of the GNU Lesser General Public
  8. * License as published by the Free Software Foundation; either
  9. * version 3 of the License, or (at your option) any later version.
  10. *
  11. * This program is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * Lesser General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU Lesser General Public License
  17. * along with this program; if not, write to the Free Software Foundation,
  18. * Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.
  19. */
  20. package org.sonar.scanner.issue;
  21. import java.io.IOException;
  22. import java.util.Collections;
  23. import java.util.HashSet;
  24. import java.util.List;
  25. import org.junit.Before;
  26. import org.junit.Rule;
  27. import org.junit.Test;
  28. import org.junit.rules.TemporaryFolder;
  29. import org.junit.runner.RunWith;
  30. import org.mockito.ArgumentCaptor;
  31. import org.mockito.junit.MockitoJUnitRunner;
  32. import org.sonar.api.batch.bootstrap.ProjectDefinition;
  33. import org.sonar.api.batch.fs.InputComponent;
  34. import org.sonar.api.batch.fs.internal.DefaultInputFile;
  35. import org.sonar.api.batch.fs.internal.DefaultInputProject;
  36. import org.sonar.api.batch.fs.internal.TestInputFileBuilder;
  37. import org.sonar.api.batch.rule.internal.ActiveRulesBuilder;
  38. import org.sonar.api.batch.rule.internal.NewActiveRule;
  39. import org.sonar.api.batch.sensor.issue.NewIssue;
  40. import org.sonar.api.batch.sensor.issue.internal.DefaultExternalIssue;
  41. import org.sonar.api.batch.sensor.issue.internal.DefaultIssue;
  42. import org.sonar.api.batch.sensor.issue.internal.DefaultIssueLocation;
  43. import org.sonar.api.batch.sensor.issue.internal.DefaultMessageFormatting;
  44. import org.sonar.api.issue.impact.SoftwareQuality;
  45. import org.sonar.api.rule.RuleKey;
  46. import org.sonar.api.rule.Severity;
  47. import org.sonar.api.rules.RuleType;
  48. import org.sonar.scanner.protocol.output.ScannerReport;
  49. import org.sonar.scanner.protocol.output.ScannerReport.FlowType;
  50. import org.sonar.scanner.report.ReportPublisher;
  51. import static org.assertj.core.api.Assertions.assertThat;
  52. import static org.assertj.core.api.Assertions.tuple;
  53. import static org.mockito.ArgumentMatchers.any;
  54. import static org.mockito.ArgumentMatchers.eq;
  55. import static org.mockito.Mockito.RETURNS_DEEP_STUBS;
  56. import static org.mockito.Mockito.mock;
  57. import static org.mockito.Mockito.verify;
  58. import static org.mockito.Mockito.verifyNoInteractions;
  59. import static org.mockito.Mockito.when;
  60. import static org.sonar.api.batch.sensor.issue.MessageFormatting.Type.CODE;
  61. import static org.sonar.api.issue.impact.SoftwareQuality.*;
  62. @RunWith(MockitoJUnitRunner.class)
  63. public class IssuePublisherTest {
  64. private static final RuleKey JAVA_RULE_KEY = RuleKey.of("java", "AvoidCycle");
  65. private static final RuleKey NOSONAR_RULE_KEY = RuleKey.of("java", "NoSonarCheck");
  66. private DefaultInputProject project;
  67. @Rule
  68. public TemporaryFolder temp = new TemporaryFolder();
  69. public IssueFilters filters = mock(IssueFilters.class);
  70. private final ActiveRulesBuilder activeRulesBuilder = new ActiveRulesBuilder();
  71. private IssuePublisher moduleIssues;
  72. private final DefaultInputFile file = new TestInputFileBuilder("foo", "src/Foo.php").initMetadata("Foo\nBar\nBiz\n").build();
  73. private final ReportPublisher reportPublisher = mock(ReportPublisher.class, RETURNS_DEEP_STUBS);
  74. @Before
  75. public void prepare() throws IOException {
  76. project = new DefaultInputProject(ProjectDefinition.create()
  77. .setKey("foo")
  78. .setBaseDir(temp.newFolder())
  79. .setWorkDir(temp.newFolder()));
  80. activeRulesBuilder.addRule(new NewActiveRule.Builder()
  81. .setRuleKey(JAVA_RULE_KEY)
  82. .setSeverity(Severity.INFO)
  83. .setQProfileKey("qp-1")
  84. .build());
  85. initModuleIssues();
  86. }
  87. @Test
  88. public void ignore_null_active_rule() {
  89. RuleKey INACTIVE_RULE_KEY = RuleKey.of("repo", "inactive");
  90. initModuleIssues();
  91. DefaultIssue issue = new DefaultIssue(project)
  92. .at(new DefaultIssueLocation().on(file).at(file.selectLine(3)).message("Foo"))
  93. .forRule(INACTIVE_RULE_KEY);
  94. boolean added = moduleIssues.initAndAddIssue(issue);
  95. assertThat(added).isFalse();
  96. verifyNoInteractions(reportPublisher);
  97. }
  98. @Test
  99. public void ignore_null_rule_of_active_rule() {
  100. initModuleIssues();
  101. DefaultIssue issue = new DefaultIssue(project)
  102. .at(new DefaultIssueLocation().on(file).at(file.selectLine(3)).message("Foo"))
  103. .forRule(JAVA_RULE_KEY);
  104. boolean added = moduleIssues.initAndAddIssue(issue);
  105. assertThat(added).isFalse();
  106. verifyNoInteractions(reportPublisher);
  107. }
  108. @Test
  109. public void add_issue_to_cache() {
  110. initModuleIssues();
  111. final String ruleDescriptionContextKey = "spring";
  112. DefaultIssue issue = new DefaultIssue(project)
  113. .at(new DefaultIssueLocation().on(file).at(file.selectLine(3)).message("Foo"))
  114. .forRule(JAVA_RULE_KEY)
  115. .overrideSeverity(org.sonar.api.batch.rule.Severity.CRITICAL)
  116. .setQuickFixAvailable(true)
  117. .setRuleDescriptionContextKey(ruleDescriptionContextKey)
  118. .setCodeVariants(List.of("variant1", "variant2"))
  119. .overrideImpact(MAINTAINABILITY, org.sonar.api.issue.impact.Severity.HIGH)
  120. .overrideImpact(RELIABILITY, org.sonar.api.issue.impact.Severity.LOW);
  121. when(filters.accept(any(InputComponent.class), any(ScannerReport.Issue.class))).thenReturn(true);
  122. boolean added = moduleIssues.initAndAddIssue(issue);
  123. assertThat(added).isTrue();
  124. ArgumentCaptor<ScannerReport.Issue> argument = ArgumentCaptor.forClass(ScannerReport.Issue.class);
  125. verify(reportPublisher.getWriter()).appendComponentIssue(eq(file.scannerId()), argument.capture());
  126. assertThat(argument.getValue().getSeverity()).isEqualTo(org.sonar.scanner.protocol.Constants.Severity.CRITICAL);
  127. assertThat(argument.getValue().getQuickFixAvailable()).isTrue();
  128. assertThat(argument.getValue().getRuleDescriptionContextKey()).isEqualTo(ruleDescriptionContextKey);
  129. assertThat(argument.getValue().getCodeVariantsList()).containsExactly("variant1", "variant2");
  130. ScannerReport.Impact impact1 = ScannerReport.Impact.newBuilder().setSoftwareQuality(MAINTAINABILITY.name()).setSeverity("HIGH").build();
  131. ScannerReport.Impact impact2 = ScannerReport.Impact.newBuilder().setSoftwareQuality(RELIABILITY.name()).setSeverity("LOW").build();
  132. assertThat(argument.getValue().getOverridenImpactsList()).containsExactly(impact1, impact2);
  133. }
  134. @Test
  135. public void add_issue_flows_to_cache() {
  136. initModuleIssues();
  137. DefaultMessageFormatting messageFormatting = new DefaultMessageFormatting().start(0).end(4).type(CODE);
  138. DefaultIssue issue = new DefaultIssue(project)
  139. .at(new DefaultIssueLocation().on(file))
  140. // Flow without type
  141. .addFlow(List.of(new DefaultIssueLocation().on(file).at(file.selectLine(1)).message("Foo1", List.of(messageFormatting)),
  142. new DefaultIssueLocation().on(file).at(file.selectLine(2)).message("Foo2")))
  143. // Flow with type and description
  144. .addFlow(List.of(new DefaultIssueLocation().on(file)), NewIssue.FlowType.DATA, "description")
  145. // Flow with execution type and no description
  146. .addFlow(List.of(new DefaultIssueLocation().on(file)), NewIssue.FlowType.EXECUTION, null)
  147. .forRule(JAVA_RULE_KEY);
  148. when(filters.accept(any(InputComponent.class), any(ScannerReport.Issue.class))).thenReturn(true);
  149. moduleIssues.initAndAddIssue(issue);
  150. ArgumentCaptor<ScannerReport.Issue> argument = ArgumentCaptor.forClass(ScannerReport.Issue.class);
  151. verify(reportPublisher.getWriter()).appendComponentIssue(eq(file.scannerId()), argument.capture());
  152. List<ScannerReport.Flow> writtenFlows = argument.getValue().getFlowList();
  153. assertThat(writtenFlows)
  154. .extracting(ScannerReport.Flow::getDescription, ScannerReport.Flow::getType)
  155. .containsExactly(tuple("", FlowType.UNDEFINED), tuple("description", FlowType.DATA), tuple("", FlowType.EXECUTION));
  156. assertThat(writtenFlows.get(0).getLocationCount()).isEqualTo(2);
  157. assertThat(writtenFlows.get(0).getLocationList()).containsExactly(
  158. ScannerReport.IssueLocation.newBuilder()
  159. .setComponentRef(file.scannerId())
  160. .setMsg("Foo1")
  161. .addMsgFormatting(ScannerReport.MessageFormatting.newBuilder().setStart(0).setEnd(4).setType(ScannerReport.MessageFormattingType.CODE).build())
  162. .setTextRange(ScannerReport.TextRange.newBuilder().setStartLine(1).setEndLine(1).setEndOffset(3).build())
  163. .build(),
  164. ScannerReport.IssueLocation.newBuilder()
  165. .setComponentRef(file.scannerId())
  166. .setMsg("Foo2")
  167. .setTextRange(ScannerReport.TextRange.newBuilder().setStartLine(2).setEndLine(2).setEndOffset(3).build())
  168. .build());
  169. }
  170. @Test
  171. public void add_external_issue_to_cache() {
  172. initModuleIssues();
  173. DefaultExternalIssue issue = new DefaultExternalIssue(project)
  174. .at(new DefaultIssueLocation().on(file).at(file.selectLine(3)).message("Foo"))
  175. .type(RuleType.BUG)
  176. .forRule(JAVA_RULE_KEY)
  177. .severity(org.sonar.api.batch.rule.Severity.CRITICAL);
  178. moduleIssues.initAndAddExternalIssue(issue);
  179. ArgumentCaptor<ScannerReport.ExternalIssue> argument = ArgumentCaptor.forClass(ScannerReport.ExternalIssue.class);
  180. verify(reportPublisher.getWriter()).appendComponentExternalIssue(eq(file.scannerId()), argument.capture());
  181. assertThat(argument.getValue().getSeverity()).isEqualTo(org.sonar.scanner.protocol.Constants.Severity.CRITICAL);
  182. }
  183. @Test
  184. public void use_severity_from_active_rule_if_no_severity_on_issue() {
  185. initModuleIssues();
  186. DefaultIssue issue = new DefaultIssue(project)
  187. .at(new DefaultIssueLocation().on(file).at(file.selectLine(3)).message("Foo"))
  188. .forRule(JAVA_RULE_KEY);
  189. when(filters.accept(any(InputComponent.class), any(ScannerReport.Issue.class))).thenReturn(true);
  190. moduleIssues.initAndAddIssue(issue);
  191. ArgumentCaptor<ScannerReport.Issue> argument = ArgumentCaptor.forClass(ScannerReport.Issue.class);
  192. verify(reportPublisher.getWriter()).appendComponentIssue(eq(file.scannerId()), argument.capture());
  193. assertThat(argument.getValue().getSeverity()).isEqualTo(org.sonar.scanner.protocol.Constants.Severity.INFO);
  194. }
  195. @Test
  196. public void filter_issue() {
  197. DefaultIssue issue = new DefaultIssue(project)
  198. .at(new DefaultIssueLocation().on(file).at(file.selectLine(3)).message(""))
  199. .forRule(JAVA_RULE_KEY);
  200. when(filters.accept(any(InputComponent.class), any(ScannerReport.Issue.class))).thenReturn(false);
  201. boolean added = moduleIssues.initAndAddIssue(issue);
  202. assertThat(added).isFalse();
  203. verifyNoInteractions(reportPublisher);
  204. }
  205. @Test
  206. public void should_ignore_lines_commented_with_nosonar() {
  207. initModuleIssues();
  208. DefaultIssue issue = new DefaultIssue(project)
  209. .at(new DefaultIssueLocation().on(file).at(file.selectLine(3)).message(""))
  210. .forRule(JAVA_RULE_KEY);
  211. file.noSonarAt(new HashSet<>(Collections.singletonList(3)));
  212. boolean added = moduleIssues.initAndAddIssue(issue);
  213. assertThat(added).isFalse();
  214. verifyNoInteractions(reportPublisher);
  215. }
  216. @Test
  217. public void should_accept_issues_on_no_sonar_rules() {
  218. // The "No Sonar" rule logs violations on the lines that are flagged with "NOSONAR" !!
  219. activeRulesBuilder.addRule(new NewActiveRule.Builder()
  220. .setRuleKey(NOSONAR_RULE_KEY)
  221. .setSeverity(Severity.INFO)
  222. .setQProfileKey("qp-1")
  223. .build());
  224. initModuleIssues();
  225. file.noSonarAt(new HashSet<>(Collections.singletonList(3)));
  226. DefaultIssue issue = new DefaultIssue(project)
  227. .at(new DefaultIssueLocation().on(file).at(file.selectLine(3)).message(""))
  228. .forRule(NOSONAR_RULE_KEY);
  229. when(filters.accept(any(InputComponent.class), any(ScannerReport.Issue.class))).thenReturn(true);
  230. boolean added = moduleIssues.initAndAddIssue(issue);
  231. assertThat(added).isTrue();
  232. verify(reportPublisher.getWriter()).appendComponentIssue(eq(file.scannerId()), any());
  233. }
  234. /**
  235. * Every rules and active rules has to be added in builders before creating IssuePublisher
  236. */
  237. private void initModuleIssues() {
  238. moduleIssues = new IssuePublisher(activeRulesBuilder.build(), filters, reportPublisher);
  239. }
  240. }