Skip to content

fix(python/sast): Fix module variable reassignment contamination and var: placeholder leaking - #515

Merged
shivasurya merged 1 commit into
mainfrom
fix/bug-03-module-variable-inference-gaps
Feb 9, 2026
Merged

shivasurya merged 1 commit into
mainfrom
fix/bug-03-module-variable-inference-gaps

Conversation

@shivasurya

Copy link
Copy Markdown
Owner

Summary

  • Change FunctionScope.Variables from map[string]*VariableBinding to map[string][]*VariableBinding for per-assignment tracking, fixing reassignment contamination where reassigned module variables (val = ""; val = 5) always returned the last assignment's type
  • Add GetVariableAtLine(varName, line) method to retrieve the binding at a specific source line, and update GetModuleVariableType() to accept a line uint32 parameter for line-aware lookups
  • Add ResolveReturnVariableReferences() pipeline step that resolves var:varName placeholders in return types by looking up the variable's concrete type in the function's scope — fixes return result patterns leaking var:result to MCP output
  • Add var: prefix filter in GetModuleVariableType() as a safety net alongside the existing call: filter

Before

// Issue A: Both lines return the SAME (wrong) type
{"fqn": "main.val", "line": 15, "inferred_type": "builtins.int", "confidence": 1}
{"fqn": "main.val", "line": 16, "inferred_type": "builtins.int", "confidence": 1}

// Issue B: var: placeholder leaks to output
{"fqn": "main.sum_result", "inferred_type": "var:result"}

After

// Issue A: Each line returns the CORRECT type
{"fqn": "main.val", "line": 15, "inferred_type": "builtins.str", "confidence": 1}
{"fqn": "main.val", "line": 16, "inferred_type": "builtins.int", "confidence": 1}

// Issue B: Resolved to concrete type
{"fqn": "main.sum_result", "inferred_type": "builtins.int", "confidence": 0.855}

Test plan

  • 4 new test cases: TestGetModuleVariableType_Reassignment, TestGetModuleVariableType_VarPlaceholder, TestResolveReturnVariableReferences, TestResolveReturnVariableReferences_Unresolved
  • All ~25 variable extraction test accesses updated for sliced Variables type
  • All ~30 inference test writes/reads updated for sliced Variables type
  • ModuleVariableProvider interface updated with line uint32 parameter; mock updated
  • gradle buildGo passes
  • All 26 test packages pass (go test ./...)

🤖 Generated with Claude Code

…var: placeholder leaking (#BUG-03)

Change FunctionScope.Variables from map[string]*VariableBinding to map[string][]*VariableBinding
to support per-assignment tracking. This fixes two issues:

- Issue A: Reassigned module variables (e.g., val="" then val=5) now return the correct type
  for each assignment line instead of always returning the last assignment's type.
- Issue B: Functions returning a named variable (return result) no longer leak var:result
  placeholders to MCP output. A new ResolveReturnVariableReferences() pipeline step resolves
  these to concrete types, with a safety filter in GetModuleVariableType().

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@shivasurya shivasurya added bug Something isn't working go Pull requests that update go code labels Feb 9, 2026
@shivasurya shivasurya self-assigned this Feb 9, 2026
@safedep

safedep Bot commented Feb 9, 2026 •

Copy link
Copy Markdown

SafeDep Report Summary

Green Malicious Packages Badge Green Vulnerable Packages Badge Green Risky License Badge

No dependency changes detected. Nothing to scan.

This report is generated by SafeDep Github App

@github-actions

github-actions Bot commented Feb 9, 2026

Copy link
Copy Markdown

Code Pathfinder Security Scan

Pass Critical High Medium Low Info

No security issues detected.

Metric Value
Files Scanned 10
Rules 38

Powered by Code Pathfinder

@codecov

codecov Bot commented Feb 9, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 86.20690% with 8 lines in your changes missing coverage. Please review.
✅ Project coverage is 82.54%. Comparing base (0fd8ebb) to head (e645635).
⚠️ Report is 1 commits behind head on main.

Files with missing lines Patch % Lines
...ast-engine/graph/callgraph/resolution/inference.go 83.78% 3 Missing and 3 partials ⚠️
sast-engine/graph/callgraph/builder/builder.go 66.66% 1 Missing ⚠️
sast-engine/graph/callgraph/resolution/types.go 92.85% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main     #515      +/-   ##
==========================================
- Coverage   82.54%   82.54%   -0.01%     
==========================================
  Files         122      122              
  Lines       14059    14097      +38     
==========================================
+ Hits        11605    11636      +31     
- Misses       2012     2016       +4     
- Partials      442      445       +3     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@shivasurya
shivasurya merged commit 4955bdd into main Feb 9, 2026
7 checks passed
@shivasurya
shivasurya deleted the fix/bug-03-module-variable-inference-gaps branch February 9, 2026 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant