Repository navigation
fix(auditor): an import manifest is not a packed payload (#3583) - #3627
Merged
Merged
Conversation
The Packed Payload Guard relegated any file of 30+ lines averaging more than 3 signal hits per line. A re-export barrel is exactly that dense by construction -- flask's src/flask/__init__.py is 39 lines of `from .app import Flask as Flask`: one import plus three from/import/as boundaries per line (3.95 hits/line). It was dropped from the scan, so no edge could land on the package root, and a scanned-files view read src/flask/ as a source root. A payload is the opposite shape: few, long lines. A file whose code lines are >= 80% import statements at an average line length <= 120 characters is an import manifest and keeps its place; an import-dense file on packed lines is still relegated. import_graph_accuracy python: recall 98.9 -> 100.0 (misses 22 -> 1; the flask `typing` misses were the dropped __init__.py). Baseline regenerated. Golden masters: three.js's Nodes.js (an `export ... from` barrel, the one crucible file this guard excluded) is scanned again, with the aggregates that include it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YAtpBfGGyBGGovitSVaM5Q
Contributor
squid-protocol
pushed a commit
that referenced
this pull request
Sep 25, 2026
follow-up) #3627 stopped the Packed Payload Guard relegating import manifests, so the crucible's three.js barrel `threejs/Nodes.js` (166 lines, 139 of them `export ... from`) is scanned again: files_scanned 18 -> 19. It declares no functions or classes, so every other count is unchanged. main's tree-sitter-accuracy-audit has been red on this since #3627 merged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YAtpBfGGyBGGovitSVaM5Q
squid-protocol
added a commit
that referenced
this pull request
Sep 25, 2026
…eceiver (#3608) (#3629) * fix(kotlin): extract extension functions with a generic or nullable receiver (#3608) `func_start` and `args` only accepted a plain `[\w.]+` receiver, so `fun Collection<CodeBlock>.joinToCode(...)`, `fun <T> List<T>.b()` and `fun String?.d()` were not extracted at all. Both now share a `_RECEIVER` fragment that takes a bounded, one-level-nested generic argument list and an optional `?`. kotlinpoet vs tree-sitter function_declaration: recall 96.4% -> 99.0% (+56 functions, 0 new false positives). Golden masters unchanged (the crucible's Kotlin samples have no generic receivers). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YAtpBfGGyBGGovitSVaM5Q * test(tree-sitter): javascript baseline scans threejs/Nodes.js now (#3627 follow-up) #3627 stopped the Packed Payload Guard relegating import manifests, so the crucible's three.js barrel `threejs/Nodes.js` (166 lines, 139 of them `export ... from`) is scanned again: files_scanned 18 -> 19. It declares no functions or classes, so every other count is unchanged. main's tree-sitter-accuracy-audit has been red on this since #3627 merged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YAtpBfGGyBGGovitSVaM5Q --------- Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #3583.
The statistical auditor's Packed Payload Guard relegates any file of 30+ lines averaging more than 3 signal hits per line. It is meant for minified, obfuscated or packed code. A re-export barrel is that dense by construction:
src/flask/__init__.pyis 39 lines offrom .app import Flask as Flask;importplus threefrom/import/asstructural boundaries, so it averages 3.95 hits per line.It was dropped from the scan. So:
src/flask/as a source root. That made the import-accuracy tool expectimport typingto meansrc/flask/typing.py, which accounted for most of Python's misses.Fix. A payload is the opposite shape: few, long lines. New
StatisticalAuditor._is_import_manifesttreats a file as an import manifest, and keeps it, when both hold:An import-dense file on packed lines is still relegated; a test covers exactly that.
Measured
import_graph_accuracy.py python(httpx, fastapi, flask): recall 98.9 → 100.0 (misses 22 → 1), precision 99.9. Baseline regenerated; the other 19 languages are unchanged.Type of change
CI checklist
tests/security_auditing/test_statistical_auditor.py: 14 passed. New tests: a manifest is kept; import-dense packed lines are still relegated.crucible_check.py: both fixtures pass on the rebased head (reblessed; scope below).ground_truth_ledger.py check: ledger clean.pytest tests/cobol_mainframe/with the pinned corpora: 481 passed, 1 skipped.import_graph_accuracy.py --ci: OK, 20 languages.Golden-master scope
The guard excluded exactly one language-crucible file:
javascript/threejs/Nodes.js, which is anexport { default as X } from './x.js'barrel. It is now scanned again. Every other difference is an aggregate that counts it:verified_files3220 → 3221,total_loc+140;unparsable_files−1;Verification
🤖 Generated with Claude Code
https://claude.ai/code/session_01YAtpBfGGyBGGovitSVaM5Q
Generated by Claude Code