Skip to content

fix(auditor): an import manifest is not a packed payload (#3583) - #3627

Merged
squid-protocol merged 1 commit into
mainfrom
claude/festive-fermat-kojuy7
Sep 25, 2026
Merged

squid-protocol merged 1 commit into
mainfrom
claude/festive-fermat-kojuy7

Conversation

@squid-protocol

Copy link
Copy Markdown
Owner

Summary

Fixes #3583.

The statistical auditor's Packed Payload Guard relegates any file of 30+ lines averaging more than 3 signal hits per line. It is meant for minified, obfuscated or packed code. A re-export barrel is that dense by construction:

  • flask's src/flask/__init__.py is 39 lines of from .app import Flask as Flask;
  • each line is one import plus three from/import/as structural boundaries, so it averages 3.95 hits per line.

It was dropped from the scan. So:

  • no import edge could land on the package root;
  • any view of the scanned files read src/flask/ as a source root. That made the import-accuracy tool expect import typing to mean src/flask/typing.py, which accounted for most of Python's misses.

Fix. A payload is the opposite shape: few, long lines. New StatisticalAuditor._is_import_manifest treats a file as an import manifest, and keeps it, when both hold:

  • at least 80% of its code lines are import statements;
  • its average line length is ≤ 120 characters.

An import-dense file on packed lines is still relegated; a test covers exactly that.

Measured

import_graph_accuracy.py python (httpx, fastapi, flask): recall 98.9 → 100.0 (misses 22 → 1), precision 99.9. Baseline regenerated; the other 19 languages are unchanged.

Type of change

  • Bug fix
  • New feature / language support
  • Parsing or engine logic
  • Docs, tooling, or CI only
  • Other

CI checklist

  • tests/security_auditing/test_statistical_auditor.py: 14 passed. New tests: a manifest is kept; import-dense packed lines are still relegated.
  • crucible_check.py: both fixtures pass on the rebased head (reblessed; scope below).
  • ground_truth_ledger.py check: ledger clean. pytest tests/cobol_mainframe/ with the pinned corpora: 481 passed, 1 skipped.
  • import_graph_accuracy.py --ci: OK, 20 languages.

Golden-master scope

The guard excluded exactly one language-crucible file: javascript/threejs/Nodes.js, which is an export { default as X } from './x.js' barrel. It is now scanned again. Every other difference is an aggregate that counts it:

  • verified_files 3220 → 3221, total_loc +140;
  • the javascript composition and threejs directory group;
  • unparsable_files −1;
  • plus coordinate ripple.

Verification

$ pytest tests/security_auditing/test_statistical_auditor.py -q         -- 14 passed
$ python tests/tools/import_graph_accuracy.py python                   -- python 99.9 / 100.0
$ python tests/tools/crucible_check.py                                 -- full_precision PASS, zero_dependency PASS
$ python tests/tools/ground_truth_ledger.py check                      -- Ledger clean.
$ pytest tests/cobol_mainframe/                                        -- 481 passed, 1 skipped

🤖 Generated with Claude Code

https://claude.ai/code/session_01YAtpBfGGyBGGovitSVaM5Q


Generated by Claude Code

The Packed Payload Guard relegated any file of 30+ lines averaging more than
3 signal hits per line. A re-export barrel is exactly that dense by
construction -- flask's src/flask/__init__.py is 39 lines of
`from .app import Flask as Flask`: one import plus three
from/import/as boundaries per line (3.95 hits/line). It was dropped from
the scan, so no edge could land on the package root, and a scanned-files
view read src/flask/ as a source root.

A payload is the opposite shape: few, long lines. A file whose code lines
are >= 80% import statements at an average line length <= 120 characters is
an import manifest and keeps its place; an import-dense file on packed
lines is still relegated.

import_graph_accuracy python: recall 98.9 -> 100.0 (misses 22 -> 1; the
flask `typing` misses were the dropped __init__.py). Baseline regenerated.
Golden masters: three.js's Nodes.js (an `export ... from` barrel, the one
crucible file this guard excluded) is scanned again, with the aggregates
that include it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YAtpBfGGyBGGovitSVaM5Q
@github-actions

Copy link
Copy Markdown
Contributor

🐦‍⬛ Muninn Security Scan

✅ No security issues found.

🐦‍⬛ Powered by Muninn · Skald Lab

@squid-protocol
squid-protocol merged commit c2d1f1b into main Sep 25, 2026
31 checks passed
@squid-protocol
squid-protocol deleted the claude/festive-fermat-kojuy7 branch September 25, 2026 14:53
squid-protocol pushed a commit that referenced this pull request Sep 25, 2026
 follow-up)

#3627 stopped the Packed Payload Guard relegating import manifests, so the
crucible's three.js barrel `threejs/Nodes.js` (166 lines, 139 of them
`export ... from`) is scanned again: files_scanned 18 -> 19. It declares no
functions or classes, so every other count is unchanged. main's
tree-sitter-accuracy-audit has been red on this since #3627 merged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YAtpBfGGyBGGovitSVaM5Q
squid-protocol added a commit that referenced this pull request Sep 25, 2026
…eceiver (#3608) (#3629)

* fix(kotlin): extract extension functions with a generic or nullable receiver (#3608)

`func_start` and `args` only accepted a plain `[\w.]+` receiver, so
`fun Collection<CodeBlock>.joinToCode(...)`, `fun <T> List<T>.b()` and
`fun String?.d()` were not extracted at all. Both now share a `_RECEIVER`
fragment that takes a bounded, one-level-nested generic argument list and
an optional `?`.

kotlinpoet vs tree-sitter function_declaration: recall 96.4% -> 99.0%
(+56 functions, 0 new false positives). Golden masters unchanged (the
crucible's Kotlin samples have no generic receivers).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YAtpBfGGyBGGovitSVaM5Q

* test(tree-sitter): javascript baseline scans threejs/Nodes.js now (#3627 follow-up)

#3627 stopped the Packed Payload Guard relegating import manifests, so the
crucible's three.js barrel `threejs/Nodes.js` (166 lines, 139 of them
`export ... from`) is scanned again: files_scanned 18 -> 19. It declares no
functions or classes, so every other count is unchanged. main's
tree-sitter-accuracy-audit has been red on this since #3627 merged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YAtpBfGGyBGGovitSVaM5Q

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Statistical auditor's Packed Payload Guard drops re-export __init__.py files from the scan (flask's package root vanishes)

2 participants