GitNexus/gitnexus/test/integration/cfg/worker-roundtrip.test.ts
Gergő Magyar ed8ab1c246
Some checks are pending
CodeQL / Analyze (python) (push) Waiting to run
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
Gitleaks / gitleaks (push) Waiting to run
Publish / Classify release event (push) Waiting to run
Publish / RC guard (marker + release-PR skip) (push) Blocked by required conditions
Publish / ci (push) Blocked by required conditions
Publish / Publish to npm (push) Blocked by required conditions
Publish / Build & Push RC Docker images (push) Blocked by required conditions
Scorecard / Scorecard analysis (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-cli) (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-web) (push) Waiting to run
fix(scope-resolution): resolve callable reference flows (#2437) (#2522)
* docs(plans): add provider-hook value-refs plan (#2437)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(plans): deepen #2437 plan to USES + property-dispatch design

Design revised after prior-art research (Kythe ref vs ref/call, Joern
METHOD_REF, Feldthaus field-based call graphs, CodeQL impliedReceiverStep):
registration sites emit reference-class USES, invocation is recovered by a
field-based property-dispatch pass synthesizing CALLS at member-call sites.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(scope-resolution): model provider-hook value references (#2437)

Functions referenced as object-literal property values (provider hooks like
emitScopeCaptures: emitCppScopeCaptures) previously produced no edge at all,
so impact/context reported a false-safe 0 upstream dependents.

Two coordinated halves, per prior art (Kythe ref vs ref/call, Joern
METHOD_REF, Feldthaus ICSE'13 field-based call graphs, CodeQL
impliedReceiverStep):

- Registration -> USES: new ReferenceKind 'value-ref'; TS/JS queries capture
  pair values and shorthand properties (with @reference.property-key);
  emitted as a reference-class USES edge, reason 'scope-resolution:
  value-ref'. Resolution is callable-gated so plain values emit nothing.
- Dispatch -> CALLS: new shared pass emitPropertyDispatchCalls synthesizes
  CALLS (reason 'property-dispatch', confidence 0.7, per-key fan-out cap 32
  calibrated on this repo's 16-provider hook tables) from member-call sites
  to every function registered under the same property key.

Deviation from plan: the pass owns value-ref resolution entirely via the
post-finalize findCallableBindingInScope walker — the shared registries only
see pre-finalize local bindings, so imported hooks (the c-cpp.ts case) were
unresolvable through lookupForSite; Reference.propertyKey passthrough
dropped as unnecessary.

SCHEMA_BUMP 13 -> 14: ParsedFile gains value-ref sites + propertyKey.

Verified end-to-end: impact(emitCppScopeCaptures, upstream) now reports 8
impacted / HIGH with extractParsedFile (true dispatch caller) at d=1 via
property-dispatch and the c-cpp.ts registration via USES.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(scope-resolution): cover value-ref registration and property dispatch (#2437)

Integration: same-file/cross-file/aliased/shorthand registrations emit USES;
non-callable and destructuring values emit nothing; dispatch sites gain
property-dispatch CALLS (incl. JS twins and per-language partitioning);
fan-out-capped keys are dropped entirely; factory-call values unchanged.
Unit: capture-shape pins for @reference.value-ref + @reference.property-key.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(scope-resolution): surface dropped property-dispatch keys in stats (#2437)

Review finding: skippedKeys was returned but discarded — a hook table
larger than the fan-out cap silently reopened the #2437 gap for those
keys. Log dropped keys and fold value-ref USES + dispatch CALLS into
referenceEdgesEmitted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(plans): add callable reference-flow implementation plan

* fix(scope-resolution): close property-dispatch review gaps

* feat(scope-resolution): add callable flow facts

* feat(scope-resolution): resolve callable value flow

* feat(scope-resolution): resolve callable references across providers

* fix: harden callable reference flow resolution

* fix(scope-resolution): preserve callable binding semantics

* docs(plans): add pr-2522-review-fixes plan

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(storage): bump INCREMENTAL_SCHEMA_VERSION for callable-value-flow edges

Callable-value-flow CALLS/USES edges (#2437) can connect two files whose
content did not change, but the incremental write set only covers changed
files — a top-up against a pre-v7 index would silently omit the new edges
for every unchanged file pair, indefinitely. Force the one-time full
re-analyze (review finding 1, #2522).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(storage): sanitize callable-flow sites per-site at load, log drops

The load-time validator rejected the WHOLE ParsedFile when one site was
malformed or over-bound, with no logging — and C++ legitimately emits
empty-string parameterTypes entries ('' = unknown, the
ReferenceSite.argumentTypes convention) for cv-only/ERROR-recovered types,
so real repos fell into a permanent, silent warm-cache-miss reparse loop
through the #1983-sensitive main-thread path (review finding 7, #2522).

Now: '' entries are valid in type arrays; a malformed/over-bound site drops
only itself (counted, warned once per load); only non-array garbage —
evidence the serialization itself is untrustworthy — rejects the file.
Deviation from plan §6 wording: validator-side tolerance replaces emit-side
clamps — smaller diff, same asymmetry closed at the single chokepoint.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(scope-resolution): keep declarations in the union for reassigned callable cells

The binding-lookup suppression for fact-constrained cells was wholesale:
reassigning a declared function through its own name (greet = other;
greet()) deferred the call to the solver, which then refused the lexical
lookup that resolves the declaration — an unresolvable RHS yielded zero
CALLS for a call that resolved pre-flow (review finding 8, #2522).

Suppression now applies only to cells bound by FORMAL facts — its actual
purpose (a parameter whose grammar emits no declaration binding must not
adopt a same-named outer function). Copy/alias/store/load destinations keep
their declaration as an inclusion seed (Andersen-style union).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(scope-resolution): count forfeited deferred sites in the budget-bailout warning

On work-budget exhaustion the deferred invoke sites end the run with zero
CALLS — free-call fallback and reference emission already skipped them —
but the warning said 'ordinary graph emission remains untouched', which is
false for exactly those sites. The warning context now carries the
unresolved deferred-site count and the comment states the real cost
(review finding: budget-bailout honesty, #2522).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(scope-resolution): surface dropped property-dispatch keys in stats and warn payload

The over-cap warning carried only a count; the dropped key NAMES were
discarded and RunScopeResolutionStats had no field, so the PR-body claim
'includes them in resolver statistics' was unimplemented (review finding,
#2522; reviewer ask on the fan-out cap). The warn payload now names up to
20 dropped keys and the stats carry propertyDispatchSkippedKeys.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(scope-resolution): drop producer-less ownerQualifiedName from formal sites

No capture emitter anywhere produces @callable-flow.owner-qualified-name —
the solver branch consuming it was unreachable in production, yet the field
was typed, parsed, validated, and unit-tested with hand-built input (review
finding 16, #2522; YAGNI). Re-add with a real producer if C++ qualified
member declarators ever need it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(scope-resolution): drop dead callable-flow knobs

CallableFlowPassingMode 'callable-object' had no producer and no consumer
distinguishing it, and CallableFlowCaptureOptions.extractCallArguments had
no language providing it (unlike its live sibling extractCallCallee) —
review finding 17, #2522 (YAGNI). The invocation-kind 'callable-object'
is a different, live concept and stays.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ingestion): bind subscripted callable cells to the container, not the index

terminalIdentifier iterates children in reverse, so tbl[i] = handler seeded
the INDEX variable's cell (polluting a same-named formal) and tbl[i](7)
looked up the callee under i in a different scope — no join, no CALLS edge
for the classic function-pointer-array dispatch (review finding 12, #2522).
Subscript nodes now recurse into their container field only, in both
bindingIdentifier and terminalIdentifier, across the fielded grammars
(C/C++/JS/TS/Python/Go/Java).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ingestion): make cross-function file-scope callable bindings resolvable

Two stacked gaps killed the canonical C callback-registration pattern
(fp assigned in init(), called in run()) — the exact #2437 false-safe this
PR exists to fix (review finding H1, #2522):

1. isVisibleValueBinding only consulted assignment regions and formals, so
   a call in a function OTHER than the assigning one emitted no invoke
   fact. A declared callable-typed binding is now a value binding wherever
   its declaration is visible (visibleCallableSignature).
2. The C scope query had no @declaration.variable pattern for function-
   pointer declarators — void (*fp)(int); created no scope-tree binding,
   so the seed (init) and invoke (run) cells canonicalized to different
   keys and never joined. Both bare and initialized forms now bind.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(c): detect variadic parameters via the named variadic_parameter node

tree-sitter-c materializes '...' as a named variadic_parameter node; the
anonymous-token checks never matched, so variadic function-pointer
signatures were emitted with a wrong fixed arity and no '...' sentinel
(review finding, #2522). C++ is unaffected ('...' stays an anonymous token
there); the token checks remain for such grammars.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ingestion): emit invoke facts for field-stored callable member calls

The C ops-vtable pattern (o->run = handler; o->run(1)) captured the store
but never the call — the member path in emitCallFacts bailed for languages
without protocol methods, and the value-binding index recorded the member
store under the OBJECT's name ('o'), not the member's ('run') (review
finding 11/M3, #2522). Member destinations now also record their terminal
member name, and a member call whose name-cell has a visible store emits an
indirect invoke — gated on the store so plain accessor calls (map.get)
stay inert.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(cpp): disambiguate (obj->*ptr)() ERROR recovery by token order

tree-sitter-cpp groups the recovered '->*' two ways depending on
error-recovery cost (identifier lengths): [identifier, ERROR '->*m'] or
[ERROR 'obj->*', identifier]. The recovery assumed the first shape, so the
second silently swapped receiver/member and dropped the call site — the
committed test passed only by name luck (review finding H2, #2522). The
identifier's position relative to '->*' inside the ERROR now decides roles.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(cpp): class members are never file-local in hasFileLocalCallableLinkage

The name-keyed file-local set is populated from every static declaration,
so an in-class 'static void make();' (external linkage — in-class static
means no-instance) and any member sharing a name with a static free
function were over-marked, refusing legitimate cross-file
declaration/definition joins (review finding 13/M2, #2522). Method and
Constructor defs now bypass the name-set, per the hook's own linkage-only
contract.

Deviation from plan step 13: the regression is a unit-level contract pin
rather than an end-to-end join test — C++ merges out-of-line member
definitions onto the member node by qualified identity, so the graph shape
cannot discriminate the join refusal for members.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(cpp): classify parameter passing mode from the declarator chain only

A whole-subtree scan for reference_declarator inverted copy vs alias:
void reg(void (*cb)(int& out)) marked the by-value pointer cb as
'reference' because of the NESTED parameter's int&, making the solver
back-propagate formal targets into every caller's argument cell — alias
semantics for a copy (review finding 14/M5, #2522). The chain walk never
descends into nested parameter lists; a reference anywhere ON the chain
(int& x, void (*&cb)(int)) still aliases.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ruby): bare identifiers are calls, not callable references

Ruby parses a receiver-less zero-arg method call identically to a variable
read, so 'action = process' — which CALLS process and stores its return —
seeded action with the callable and minted a wrong CALLS edge from any
dispatch through it, confirmed end-to-end (review finding 15/HIGH, #2522).
New provider knob bareNamesAreCalls: a bare name that is not a provably
local value binding and not an explicit reference form (method(:x),
lambda/proc) emits no flow fact, on both the assignment and argument paths.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(go): pair multi-value := positionally instead of cross-wiring

The shared field fallback took the FIRST LHS identifier and the LAST RHS
identifier of Go's expression_list pair, cross-wiring 'a, b := f, g' and
synthesizing a garbage comma-joined qualified name — the real relationships
were silently dropped (review finding 16, #2522). extractAssignment may now
return multiple pairs; Go pairs list entries positionally and emits nothing
for a length mismatch (multi-return call RHS).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(java): drop get/test from callableProtocolMethods

'get' and 'test' collide with ubiquitous non-functional-interface APIs
(Map/List/Optional/Future.get), so every ordinary container access emitted
a spurious callable-object invoke fact — high-volume misleading graph facts
with a cross-wiring risk on receiver-name reuse (review finding 17, #2522).
Supplier.get/Predicate.test dispatch is deliberately traded away until the
check can gate on the receiver's declared type.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(rust): pin the qualified-name no-degrade guard as a hard invariant

Rust's scoped_identifier callable-reference capture over-includes unit enum
variants and associated constants (Shape::Square seeds as if callable);
they stay edge-free only because resolveSeedCandidates refuses to degrade
an unresolved qualified name to a simple-name lookup (review finding 18,
#2522). Capture-side type filtering would false-negative on tuple-variant
constructors, so the guard IS the contract: documented as a hard invariant
(Go's mis-shaped multi-value forms also rely on it) and pinned end-to-end.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(php): remove nonexistent optional_parameter node type

tree-sitter-php has no 'optional_parameter' — defaults ride on
simple_parameter — so the entry was dead weight the #1920 literal gate
does not cover for capture-option Sets (review finding 19, #2522).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(cobol): detect procedure pointers on fixed-format sources

Two stacked defects made the feature a no-op on classic sequence-numbered
fixed format (review finding 20/H3, #2522):
1. parseDataItemClauses' USAGE alternation knew POINTER but not
   PROCEDURE-POINTER/FUNCTION-POINTER, so the dataItems filter was dead.
2. The raw-line fallback scanned UNCLEANED text, where the sequence number
   satisfied the leading digits and the LEVEL NUMBER got captured as the
   pointer name. It now scans preprocessed lines and requires a letter-
   initial name (COBOL data names must contain a letter).
161 COBOL preprocessor/copy-expander tests stay green; free-format matrix
case unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(cobol): skip comment lines in SET seed/copy scans

A commented-out SET (indicator-column '*'/'/' or free-format '*>')
produced a live seed and a false CALLS edge from dead code (review
finding 21/M1, #2522). The scan now skips indicator-column comment lines
and strips inline '*>' tails before matching.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(architecture): document callable-flow-only mode and skipped-key reporting

The Callable-value flow section omitted scopeResolutionEdgeMode:
'callable-flow-only' — a real emit-pipeline branch that suppresses all
ordinary emission for standalone providers (review finding 22, #2522) —
and predated the skipped-key names/stats surfacing.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(scope-resolution): correct value-ref resolution attribution and stale pdg-gating comments

The value-ref contract comment claimed MethodRegistry resolution — the
mechanism is the post-finalize findCallableBindingInScope walker owned by
emitPropertyDispatchCalls (resolveReferenceSites skips these sites). Three
'only under --pdg' calleeIdSink comments were falsified by the #2437 gating
change (callee-id-sink.ts's header was updated; these copies were missed).
Review finding 23, #2522.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(ingestion): direct unit coverage for synthesizeCallableFlowCaptures

The 1,100-line shared synthesizer had no test naming it — only downstream
consumers were covered (review finding 24, #2522). Pins seed/invoke/
formal/argument emission, subscript container binding, store-gated member
invokes, produced-value guards, and the bareNamesAreCalls knob over a
minimal options object so assertions target the synthesizer's own
semantics.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(resolvers): deepen shallow-language coverage; fix Kotlin/Swift reassignment gaps it exposed

Adds the COBOL SET x TO y copy-branch scenario and conditional-assignment
scenarios for Kotlin, C#, Swift, and Dart (10 languages previously had one
generic case each — review finding 25, #2522). The new scenarios exposed
two real capture gaps, fixed here:
- tree-sitter-kotlin's 'assignment' node is fieldless, so nested
  reassignments (chosen = ::target inside a block) produced no flow facts;
  Kotlin's extractAssignment now decomposes it positionally.
- tree-sitter-swift fields its assignment as target:/result:, neither in
  the shared fallback's field lists; both added.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(infra): literal-validation gate for callable-capture option Sets

The #1920 gate validates query literals and exported configs but not the
module-private *_CALLABLE_CAPTURE_OPTIONS Sets consumed by the shared
synthesizer — a typo'd node type silently captures nothing (PHP shipped a
dead 'optional_parameter'; review finding 26, #2522). Every <key>NodeTypes
Set literal is now validated against its language's grammar; name-carrying
sets (callableProtocolMethods, memberPointerOperators) are deliberately
outside the contract.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(storage): centralize corrupt-fixture casts into makeStoreEntry

The callable-flow store tests scattered 'as unknown as' double-casts per
fixture (review finding 27, #2522; standing no-as-any rule). One typed
helper now owns the single controlled escape hatch for building malformed
serialization-boundary payloads.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore(bench): refresh capture fingerprints after review fixes

python-scope: the committed baseline (8d5c3699) never matched this
branch's code — CI's benchmarks arm was red on the PR head (review
finding 2/HIGH, #2522); regenerated (a99e69ab), scaling 1.04 in budget.
scope-capture: ruby/cpp/swift/java/kotlin drifted from the review-fix
commits (bare-name suppression, passing modes + ->* recovery, assignment
fields, protocol narrowing, positional assignment); all 14 languages
re-verified PASS with ratios <= 1.18 against the 1.5 budget.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore(docs): untrack docs/plans working documents

docs/ is gitignored (local working docs); the plan files were force-added
past the ignore. Untracked from the index only — they stay on disk.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(golden): regenerate captures goldens after callable-flow review fixes

The per-language digest guards (csharp/go/php/python/ruby/rust/swift)
locked the pre-fix capture output; the review-fix series intentionally
changed it — store-gated member invokes, subscript container binding,
Ruby bare-name suppression, Swift assignment fields, positional pairing.
Regenerated with UPDATE_GOLDEN=1; clean verification run 59/59; all other
parity/golden guards (pipeline-graph, spring-route, python parity) pass
untouched at 33/33.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ingestion): prototypes are callees, not callable value cells

The cross-function visibility fix indexed EVERY signature-bearing
declaration as a value binding — including plain function/method
prototypes (void f(int);). Every call to a declared function then became
an indirect invoke, and with emitCanonicalInvokeReference (C/C++) minted a
free-call reference that resolved through the registry, bypassing the
precise passes' two-phase/ambiguity/subobject suppression — eight phantom
CALLS edges in the cpp resolver suite on CI.

Only declarations whose binding identifier sits under a pointer/
parenthesized declarator (callable-typed variables like void (*fp)(int);)
create value cells now. cpp resolver suite 331/331; callable-value-flow +
C/C++ suites 181/181 (the cross-function fp regression still passes); cpp
fingerprint rebaselined, both bench gates PASS.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 17:20:02 +01:00

377 lines
17 KiB
TypeScript

import { createHash } from 'crypto';
import { describe, it, expect } from 'vitest';
import Parser from 'tree-sitter';
import TypeScript from 'tree-sitter-typescript';
import { collectFunctionCfgs } from '../../../src/core/ingestion/cfg/collect.js';
import { computeChunkHash, mapReplacer, mapReviver } from '../../../src/storage/parse-cache.js';
import { getProvider } from '../../../src/core/ingestion/languages/index.js';
import { SupportedLanguages } from '../../../src/config/supported-languages.js';
import type { CfgVisitor } from '../../../src/core/ingestion/cfg/types.js';
import type { SyntaxNode } from '../../../src/core/ingestion/utils/ast-helpers.js';
import { extractParsedFile } from '../../../src/core/ingestion/scope-extractor-bridge.js';
// U3 — the worker→main boundary + cache coherence for the CFG side-channel.
// These pin the contracts that make the disk-store + warm/durable parse cache
// carry the CFG intact across the --pdg flag (R3, R4) WITHOUT spinning a real
// worker pool: the worker simply calls collectFunctionCfgs (tested here) and
// attaches the result as plain data, and the parse-cache key folds the flag.
function tsRoot(code: string): SyntaxNode {
const parser = new Parser();
parser.setLanguage(TypeScript.typescript);
return parser.parse(code).rootNode;
}
const tsVisitor = (): CfgVisitor<SyntaxNode> => {
const v = getProvider(SupportedLanguages.TypeScript).cfgVisitor;
if (!v) throw new Error('typescript provider has no cfgVisitor');
return v;
};
describe('CFG provider gate — a cfgVisitor enables the worker CFG path', () => {
it('TS and JS providers carry a cfgVisitor', () => {
expect(getProvider(SupportedLanguages.TypeScript).cfgVisitor).toBeDefined();
expect(getProvider(SupportedLanguages.JavaScript).cfgVisitor).toBeDefined();
});
it('a non-CFG language (COBOL) has no cfgVisitor ⇒ worker emits no cfgSideChannel', () => {
// `provider.cfgVisitor &&` short-circuits in the worker → no CFG, no field.
// COBOL is the deliberate non-goal of the PDG-language rollout (#2195) —
// every other supported language now carries a cfgVisitor.
expect(getProvider(SupportedLanguages.Cobol).cfgVisitor).toBeUndefined();
});
});
describe('U3 — collectFunctionCfgs', () => {
it('produces one CFG per function with the expected branch edges', () => {
const root = tsRoot(`
function a(x: number) { if (x) { p(); } else { q(); } }
function b() { return 1; }
`);
const { cfgs, skipped } = collectFunctionCfgs(root, tsVisitor(), 'a.ts');
expect(skipped).toEqual({ tooManyLines: 0, tooDeeplyNested: 0, buildError: 0 });
expect(cfgs).toHaveLength(2);
const a = cfgs.find((c) => c.blocks.some((bl) => bl.text.includes('p();')));
expect(a).toBeDefined();
const kinds = new Set(a!.edges.map((e) => e.kind));
expect(kinds.has('cond-true')).toBe(true);
expect(kinds.has('cond-false')).toBe(true);
// every block belongs to its declaring file
for (const c of cfgs) expect(c.filePath).toBe('a.ts');
});
it('a file with no functions yields an empty CFG set (no error)', () => {
const { cfgs, skipped } = collectFunctionCfgs(
tsRoot(`const x = 1; export {};`),
tsVisitor(),
'x.ts',
);
expect(cfgs).toHaveLength(0);
expect(skipped).toEqual({ tooManyLines: 0, tooDeeplyNested: 0, buildError: 0 });
});
it('maxFunctionLines skips an over-cap function and counts the skip', () => {
const big = `function big() {\n${' step();\n'.repeat(20)}}`;
const root = tsRoot(`${big}\nfunction small() { ok(); }`);
const { cfgs, skipped } = collectFunctionCfgs(root, tsVisitor(), 'f.ts', 5);
expect(skipped.tooManyLines).toBe(1); // big() exceeds the 5-line cap
expect(skipped.tooDeeplyNested).toBe(0);
expect(skipped.buildError).toBe(0);
// small() is still built
expect(cfgs.some((c) => c.blocks.some((bl) => bl.text.includes('ok();')))).toBe(true);
expect(cfgs.some((c) => c.blocks.some((bl) => bl.text.includes('step();')))).toBe(false);
});
it('a pathologically deep nest is bailed proactively and counted (#2195)', () => {
// A function nested far past MAX_CFG_NESTING_DEPTH (real code is ≤ ~50 deep).
// The visitor's proactive guard throws CfgNestingDepthError; collect counts
// it under tooDeeplyNested and ISOLATES it — the sibling function still
// builds (the bail must not drop the whole file's CFGs).
const deep = `function deep() { ${'if (c) {'.repeat(1200)} leaf(); ${'}'.repeat(1200)} }`;
const root = tsRoot(`${deep}\nfunction sibling() { ok(); }`);
const { cfgs, skipped } = collectFunctionCfgs(root, tsVisitor(), 'deep.ts');
expect(skipped.tooDeeplyNested).toBe(1);
expect(skipped.tooManyLines).toBe(0);
expect(skipped.buildError).toBe(0);
// sibling() survives the bail
expect(cfgs.some((c) => c.blocks.some((bl) => bl.text.includes('ok();')))).toBe(true);
expect(cfgs.some((c) => c.blocks.some((bl) => bl.text.includes('leaf();')))).toBe(false);
});
it('isolates a generic build error to one function and counts it (buildError, #2195)', () => {
// A non-CfgNestingDepthError throw from buildFunctionCfg used to escape to the
// worker language-group catch and drop EVERY remaining file's CFG. It must now
// be caught per function, counted under buildError, and NOT stop the sibling.
const real = tsVisitor();
const flaky: CfgVisitor<SyntaxNode> = {
isFunction: (n) => real.isFunction(n),
buildFunctionCfg: (n, fp) => {
if (n.text.includes('boom()')) throw new Error('synthetic build failure');
return real.buildFunctionCfg(n, fp);
},
};
const root = tsRoot(`function bad() { boom(); }\nfunction good() { ok(); }`);
const { cfgs, skipped } = collectFunctionCfgs(root, flaky, 'be.ts');
expect(skipped).toEqual({ tooManyLines: 0, tooDeeplyNested: 0, buildError: 1 });
// good() still builds — the throw didn't drop the file's other CFGs
expect(cfgs.some((c) => c.blocks.some((bl) => bl.text.includes('ok();')))).toBe(true);
expect(cfgs.some((c) => c.blocks.some((bl) => bl.text.includes('boom();')))).toBe(false);
});
});
describe('U3 — CFG side-channel JSON round-trip (no AST leakage, no field loss)', () => {
it('serialize → JSON → deserialize yields an identical CFG', () => {
const root = tsRoot(`function f(xs: number[]) {
for (const x of xs) { if (x > 0) { use(x); } else { break; } }
done();
}`);
const { cfgs } = collectFunctionCfgs(root, tsVisitor(), 'rt.ts');
expect(cfgs.length).toBeGreaterThan(0);
// The worker serializes ParsedFile via mapReplacer; the store revives via
// mapReviver. The CFG is plain data, so it must survive byte-for-byte.
const round = JSON.parse(JSON.stringify(cfgs, mapReplacer), mapReviver);
expect(round).toEqual(cfgs);
// No tree-sitter nodes leaked: every value is a primitive/array/plain object.
for (const c of round) {
for (const b of c.blocks) expect(typeof b.text).toBe('string');
for (const e of c.edges) expect(typeof e.from).toBe('number');
}
// M2 (#2082 U1): the binding table + statement facts must survive the
// boundary — a future cache-slimming field list that drops them would
// silently break reaching-defs (the #2038 mergeChunkResults lesson).
for (const c of round) {
expect(Array.isArray(c.bindings)).toBe(true);
expect(c.blocks.every((b: { statements?: unknown }) => Array.isArray(b.statements))).toBe(
true,
);
}
expect(round.some((c: { bindings: unknown[] }) => c.bindings.length > 0)).toBe(true);
});
});
describe('callable-flow ParsedFile round-trip', () => {
it('preserves discriminants, scopes, ranges, indexes, modes, and invocation positions', () => {
const provider = getProvider(SupportedLanguages.TypeScript);
const parsed = extractParsedFile(
provider,
`
function target(): void {}
function invoke(cb: () => void): void { cb(); }
const first = target;
invoke(first);
`,
'callable.ts',
() => {},
);
expect(parsed.callableFlowSites?.map((site) => site.kind)).toEqual([
'formal',
'invoke',
'seed',
'argument',
]);
const round = JSON.parse(JSON.stringify(parsed, mapReplacer), mapReviver);
expect(round.callableFlowSites).toEqual(parsed.callableFlowSites);
expect(round.callableFlowSites[0]).toMatchObject({
kind: 'formal',
parameterIndex: 0,
passingMode: 'value',
binding: { name: 'cb', addressOf: false, indirection: 0 },
});
expect(round.callableFlowSites[1]).toMatchObject({
kind: 'invoke',
callee: { name: 'cb' },
callSite: { startLine: 3 },
});
expect(round.callableFlowSites[3]).toMatchObject({
kind: 'argument',
directCalleeName: 'invoke',
parameterIndex: 0,
});
});
});
describe('U3 — parse-cache key folds the --pdg flag (R4, #2038-class guard)', () => {
const entries = [
{ filePath: 'b.ts', contentHash: 'h2' },
{ filePath: 'a.ts', contentHash: 'h1' },
];
it('pdg-on and pdg-off produce DIFFERENT chunk keys', () => {
expect(computeChunkHash(entries, false)).not.toBe(computeChunkHash(entries, true));
});
it('the same flag value is stable and order-independent', () => {
const reordered = [...entries].reverse();
expect(computeChunkHash(entries, true)).toBe(computeChunkHash(reordered, true));
expect(computeChunkHash(entries, false)).toBe(computeChunkHash(reordered, false));
});
it('default (no flag arg) equals the explicit pdg-off key — warm caches survive the change', () => {
expect(computeChunkHash(entries)).toBe(computeChunkHash(entries, false));
});
it('the boolean form equals the object form with the same flag (back-compat)', () => {
expect(computeChunkHash(entries, true)).toBe(computeChunkHash(entries, { pdg: true }));
expect(computeChunkHash(entries, false)).toBe(computeChunkHash(entries, { pdg: false }));
});
it('the worker-side line cap is folded into the key — a different maxFunctionLines re-dispatches', () => {
// Guards the #2038-class trap for the WORKER-visible cap: a warm chunk
// built under one maxFunctionLines must NOT be served to a --pdg run with
// a different cap (the cached cfgSideChannel differs — the worker skips
// different functions). Different cap value ⇒ different key.
const base = computeChunkHash(entries, { pdg: true });
expect(computeChunkHash(entries, { pdg: true, maxFunctionLines: 500 })).not.toBe(base);
// Same cap values ⇒ same key (deterministic, order-independent).
const reordered = [...entries].reverse();
expect(computeChunkHash(entries, { pdg: true, maxFunctionLines: 500 })).toBe(
computeChunkHash(reordered, { pdg: true, maxFunctionLines: 500 }),
);
});
it('the EMIT-time edge cap does NOT perturb the key — cached worker output is identical across it (#2099 F3)', () => {
// pdgMaxEdgesPerFunction is applied in scope-resolution on the main
// thread; the worker never sees it, so the cached shard is byte-identical
// across cap values. Folding it in (a prior review round did) only forced
// a spurious full re-parse + durable-store rewrite on every cap change.
const base = computeChunkHash(entries, { pdg: true });
expect(
computeChunkHash(entries, {
pdg: true,
maxEdgesPerFunction: 100,
} as Parameters<typeof computeChunkHash>[1]),
).toBe(base);
});
});
describe('#2082 M2 — the REACHING_DEF emit cap does NOT perturb the chunk key', () => {
const entries = [
{ filePath: 'b.ts', contentHash: 'h2' },
{ filePath: 'a.ts', contentHash: 'h1' },
];
it('pdgMaxReachingDefEdgesPerFunction is emit-time-only — same key across values (F3 discipline)', () => {
// The worker never sees the REACHING_DEF edge cap (solve + emit happen in
// scope-resolution on the main thread), so the cached shard is identical
// across cap values. Folding it in would be the #2099-F3 over-correction:
// a spurious full re-parse on every cap change. PdgCacheKey simply has no
// field for it — this test pins that the key API surface stays that way
// (the object form ignores unknown extras rather than hashing them).
const base = computeChunkHash(entries, { pdg: true });
const withExtra = computeChunkHash(entries, {
pdg: true,
// @ts-expect-error — deliberately passing an unknown field: the key must ignore it
maxReachingDefEdgesPerFunction: 1,
});
expect(withExtra).toBe(base);
});
});
describe('#2083 M3 U1 — taint sites cross the worker/store boundary intact', () => {
const siteSource = `function handler(req, x) {
const cp = require('child_process');
const b = req.body;
cp.exec(escape(x), b);
sql\`select \${x}\`;
run(...b);
}`;
function siteCfgs() {
const { cfgs } = collectFunctionCfgs(tsRoot(siteSource), tsVisitor(), 'sites.ts');
expect(cfgs).toHaveLength(1);
return cfgs;
}
function allSites(cfgs: readonly { blocks: readonly { statements?: readonly unknown[] }[] }[]) {
return cfgs.flatMap((c) =>
c.blocks.flatMap((b) =>
(b.statements ?? []).flatMap((s) => (s as { sites?: unknown[] }).sites ?? []),
),
);
}
it('sites survive the worker JSON boundary (mapReplacer/mapReviver) byte-equal', () => {
const cfgs = siteCfgs();
expect(allSites(cfgs).length).toBeGreaterThan(0);
const round = JSON.parse(JSON.stringify(cfgs, mapReplacer), mapReviver);
expect(round).toEqual(cfgs);
expect(allSites(round)).toEqual(allSites(cfgs));
});
it('sites survive a frozen re-wrap + the DURABLE store interning reviver (no nodeId-dedup loss)', async () => {
const { makeInterningReviver } = await import('../../../src/storage/parsedfile-store.js');
const cfgs = siteCfgs();
// The pipeline deep-freezes ParsedFiles and re-wraps via spread — the CFG
// payload itself rides by reference and must tolerate being frozen.
const deepFreeze = (o: unknown): unknown => {
if (o && typeof o === 'object') {
for (const v of Object.values(o)) deepFreeze(v);
Object.freeze(o);
}
return o;
};
const frozen = (deepFreeze(cfgs) as typeof cfgs).map((c) => ({ ...c }));
const raw = JSON.stringify(frozen, mapReplacer);
// The durable parsedfile-cache revives with the interning reviver, which
// DEDUPS any object carrying a string `nodeId` field — SiteRecord must
// never trip it (the KTD2 "no field named nodeId" obligation).
const revived = JSON.parse(raw, makeInterningReviver(new Map(), new Map()));
expect(revived).toEqual(frozen);
expect(allSites(revived)).toEqual(allSites(cfgs));
});
});
describe('#2083 M3 U1 — pdg chunk-key namespace version (flag-off keys untouched)', () => {
const entries = [
{ filePath: 'b.ts', contentHash: 'h2' },
{ filePath: 'a.ts', contentHash: 'h1' },
];
it('flag-off chunk keys are BYTE-IDENTICAL across the M3 namespace bump (pinned hash)', () => {
// Independent reconstruction of the pre-namespace key format: pdg-off
// keys are sha256 over the sorted filePath:contentHash lines and NOTHING
// else. This pin fails if the version token ever leaks into non-pdg keys
// (which would force a cold re-parse on every flag-off user).
const expected = createHash('sha256').update(Buffer.from('a.ts:h1\nb.ts:h2')).digest('hex');
expect(computeChunkHash(entries, false)).toBe(expected);
expect(computeChunkHash(entries)).toBe(expected);
});
it('pdg-mode keys CHANGED from the M2-era namespace (v1 chunks invalidate on upgrade)', () => {
// The M2-era pdg namespace was `pdg:1;maxFn=<v>` — an M3 binary must not
// serve a v1 chunk (its cfgSideChannel lacks `sites`, so taint would
// silently no-op on warm caches).
const joined = 'a.ts:h1\nb.ts:h2';
const m2Key = createHash('sha256')
.update(Buffer.from(`pdg:1;maxFn=def\n${joined}`))
.digest('hex');
expect(computeChunkHash(entries, { pdg: true })).not.toBe(m2Key);
// and the v2 key is still deterministic + order-independent
expect(computeChunkHash([...entries].reverse(), { pdg: true })).toBe(
computeChunkHash(entries, { pdg: true }),
);
});
it('pdg-mode keys CHANGED from prior namespaces AND pin the current pdg:5 (FU-C BindingEntry.formalIndex)', () => {
// The pdg namespace bumps whenever the worker `cfgSideChannel` SHAPE changes:
// U1 added `SiteRecord.at` (pdg:2→3), U4 added the Rust struct-literal
// `kind:'new'` site (pdg:3→4), and the FU-C call-summary soundness fix added
// `BindingEntry.formalIndex` on param bindings (pdg:4→5) so return-flow keys on
// the enclosing formal position, not the flattened binding ordinal. A stale
// prior shard lacks the new field, so the call-summary harvest would route to
// its conservative empty-summary fallback on a warm cache. Assert prior chunks
// are NOT served, and PIN the current pdg:5 namespace so an accidental revert
// of the token re-introduces the stale-shape bug.
const joined = 'a.ts:h1\nb.ts:h2';
const keyOf = (token: string) =>
createHash('sha256')
.update(Buffer.from(`${token};maxFn=def\n${joined}`))
.digest('hex');
const current = computeChunkHash(entries, { pdg: true });
expect(current).not.toBe(keyOf('pdg:2'));
expect(current).not.toBe(keyOf('pdg:3'));
expect(current).not.toBe(keyOf('pdg:4'));
expect(current).toBe(keyOf('pdg:5'));
});
});