Skip to content

fix(abap): args counts declared parameter surfaces, not call sites (#2824 contract corollary 1) - #2886

Merged
squid-protocol merged 2 commits into
mainfrom
fix/2824-2804-args-rules
Sep 8, 2026
Merged

squid-protocol merged 2 commits into
mainfrom
fix/2824-2804-args-rules

Conversation

@squid-protocol

@squid-protocol squid-protocol commented Sep 8, 2026 •

Copy link
Copy Markdown
Owner

ABAP passes actuals with the same six binding keywords its declarations use (CALL FUNCTION ... EXPORTING/EXCEPTIONS, PERFORM ... CHANGING, RAISE EXCEPTION ... EXPORTING, walk( EXPORTING ... )), so abap's args rule scored call sites as declared parameter lists — corollary 1 of the stated contract (docs/args_rule_contract.md), the same failure shape #2786/#2790 fixed for objective-c/typescript/groovy/apex. abap audited clean in #2773 only because neither corpus then contained a call site using them; the #2806 PERFORM plants exposed it (rosetta abap args 16 vs planted 13).

The fix

The owning statement can start an unbounded distance before the clause and re has no variable-width lookbehind, so the decision cannot live in the rule regex. New abap_declaration_statement scope filter (the #2674 registry mechanism, 4th filter): tokenize statements at unquoted periods (literals/templates/comments skipped), keep only clauses whose statement opens with METHODS/CLASS-METHODS/FORM/FUNCTION/MODULE. The opener/comment skip is plain code, not a regex loop — the first draft's (?:[ \t\r\n]+|...)* was the #631 nested-quantifier ReDoS shape and the strict suite's detonation caught it before it shipped.

Measured

  • crucible: 167 → 121; all 46 drops verified as call sites (the issue's 3% estimate counted statement-level CALL forms only; the functional-method-call form is the bulk in OO abapGit). a/f 1.35 → 0.98.
  • rosetta: abap args 16 → 13 (the planted median) — exactly the three PERFORM ... CHANGING clauses. Per-function args unchanged (1 per FORM, verified via one-file --db-only scan).
  • bless_scope on the re-blessed golden masters: abap files only, Function Parameters + its derived formulas, newly parsed/excluded none.
  • Gauntlet: extraction+core 8106 passed; ruff/mypy/dead-key audits at baseline; audit_check clear; rosetta_audit vs the re-blessed corpus branch 46/46, 0 regressions.

Docs: args_rule_contract.md abap rows updated (fallback family + audit table); how_to_add_a_language.md §17 gains the statement-scope example.

Cross-repo

Corpus PR: squid-protocol/keyword-rosetta#105 (abap args re-bless 16 → 13, ledger entry abap-args-counts-call-site-keywords resolved). Merge order: engine first; the corpus PR goes green when engine main carries this. bias-history.yml re-runs after both.

Also in this wave: #2804 (cobol args) was verified complete on current data and closed — engine half #2830, corpus half keyword-rosetta#97, window fix #2864; both cobol cells in band.

Closes #2824

🤖 Generated with Claude Code

https://claude.ai/code/session_012zPD39y58Bfrr2Q45Z6djL

… statement-scoped filter (#2824 contract corollary 1)

ABAP passes actuals with the same six binding keywords its declarations use,
and the owning statement can start an unbounded distance before the clause,
so the decision cannot live in the rule regex (re has no variable-width
lookbehind). New abap_declaration_statement scope filter (#2674 mechanism):
tokenize statements at unquoted periods, keep clauses owned by
METHODS/CLASS-METHODS/FORM/FUNCTION/MODULE.

Crucible 167 -> 121, all 46 drops verified call sites (CALL FUNCTION ...
EXPORTING/EXCEPTIONS, RAISE EXCEPTION ... EXPORTING, CREATE OBJECT ...
EXPORTING, functional calls -- the bulk #2824's 3% statement-level estimate
missed). Rosetta 16 -> 13: exactly the three PERFORM clauses #2806 planted.
Golden masters re-blessed; bless_scope: abap only, Function Parameters +
derived formulas, newly parsed/excluded none. The opener skip is plain code,
not a regex loop -- the first draft was the #631 nested-quantifier shape and
the strict suite's detonation caught it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zPD39y58Bfrr2Q45Z6djL
@squid-protocol squid-protocol added the rosetta:rebless-owed Intentionally moves keyword-rosetta counts; audit warns, corpus re-blesses after merge label Sep 8, 2026
Comment thread gitgalaxy/core/detector.py Fixed
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

🐦‍⬛ Muninn Security Scan

✅ No security issues found.

🐦‍⬛ Powered by Muninn · Skald Lab

…cktracked exponentially (CodeQL on #2886)

The string-template arm's escape alternative and ordinary-character
alternative could both consume a backslash, so an unterminated template
holding a backslash run had exponentially many parses. The arms are now
disjoint on the backslash; token spans are identical on every real corpus
and crucible abap file (verified), so no re-bless moves.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012zPD39y58Bfrr2Q45Z6djL
@squid-protocol
squid-protocol merged commit f8f59c4 into main Sep 8, 2026
32 checks passed
@squid-protocol
squid-protocol deleted the fix/2824-2804-args-rules branch September 8, 2026 15:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

rosetta:rebless-owed Intentionally moves keyword-rosetta counts; audit warns, corpus re-blesses after merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

abap args counts call-site parameter keywords (CALL FUNCTION ... EXPORTING, PERFORM ... CHANGING) as declared parameters

2 participants