Skip to content

Statistical auditor's Packed Payload Guard drops re-export __init__.py files from the scan (flask's package root vanishes) #3583

Description

@squid-protocol

Problem

pallets/flask's src/flask/__init__.py is 2 KB of plain re-exports (from .app import Flask as Flask, ×60). It is parsed, then removed from the scan output:

[GalaxyScope.statistical_auditor] [python] Excluded: '__init__.py' stripped to unparsable.
Reason: Packed Payload Guard (Impossible Density: 3.95 hits/line)

It is absent from file_data, so:

  • no import edge can land on it: every from flask import X and from . import X inside the package loses its target;
  • anything that asks "is this directory a package" from the scanned files reads src/flask/ as a source root. import_graph_accuracy.py's ground truth does this, so it expects import typing in blueprints.py, cli.py, config.py … to resolve to src/flask/typing.py. Those ~7 Python "misses" are artifacts of the dropped file.

Why it trips

A re-export barrel has several signal hits on every line (import, the as alias, named tokens), so hits per line sits near 4. That's the same density profile the guard uses to spot minified or packed payloads, but this file is ordinary, human-written code.

Repro

cd <checkout of pallets/flask>
GITGALAXY_DISABLE_GIT_HISTORY=1 python -m gitgalaxy.galaxyscope . --db-only --debug --output /tmp/o.json
grep "Packed Payload Guard" <log>
sqlite3 /tmp/*_master.db "select count(*) from file_data where file_path='src/flask/__init__.py'"   # 0

Fix direction

Exempt a file whose lines are overwhelmingly import/re-export statements from the density guard. Short, one-statement-per-line barrels are the opposite of a packed payload, which is long lines with few newlines. Or base the guard on line length or entropy rather than hits per line alone. Measure the effect with tests/tools/import_graph_accuracy.py python.

Found while working on import-graph precision (the Python from . import name fix).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugUnintended behavior or logic failure in the enginecore-engineModifications to the central physics and parsing engine

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions