Skip to content

fix(javascript): retain unbound CommonJS semantic imports - #1799

Merged
N0zoM1z0 merged 1 commit into
mainfrom
fix/javascript-unbound-require-20261011
Oct 11, 2026
Merged

N0zoM1z0 merged 1 commit into
mainfrom
fix/javascript-unbound-require-20261011

Conversation

@N0zoM1z0

Copy link
Copy Markdown
Collaborator

Summary

Unbound literal CommonJS calls now contribute semantic module dependencies and the source module's import count. Existing static asset references remain available.

Fixes #1793.

Problem and expected behavior

With main.cjs containing require("./dependency.cjs");, main 3ad5782d returns one static require asset edge but zero semantic require module edges and import_relationships: 0. An equivalent side-effect ESM import has a semantic module edge. The fixed CLI and stdio MCP return one semantic require edge and import_relationships: 1, with the dependency path resolved and the original source digest/range retained.

Change and scope

Collect unbound calls at the existing semantic projection owner. Its existing parser still decides whether a call is an unshadowed literal require. Keep the exact call node private to analysis and mark calls already represented by a binding or CommonJS export in a WeakSet. This avoids extra links for bound calls while retaining distinct nested calls, empty destructures, assignments and other unbound expressions.

Binding names remain null where no binding is known. Dynamic specifiers and shadowed calls remain excluded; dynamic member paths keep unknown binding provenance. Existing alias, empty-key and re-export precision is preserved. Move the existing alias/assignment case into the focused require module and update two goldens to retain dependencies without inventing dynamic bindings.

Contract and boundary impact

  • Semantic owner and earliest changed stage: JavaScript semantic require origin and module-link collection.
  • CLI and MCP/tool-catalog contract: unchanged schemas; semantic edges and import counts now include these source facts.
  • Provider, bridge, target-format, or platform compatibility: shared JavaScript analysis; no provider adapter changes.
  • Evidence, artifact, provenance, or reconstruction contract: preserve both static asset references and semantic module relationships, source identity/ranges and uncertainty.
  • Process execution, authorization, cleanup, or containment impact: none.
  • Generated metadata, package, or installation impact: none.

Evidence and regression coverage

  • Executed reproduction: a 101-byte, three-file target through freshly compiled public CLI and real SDK stdio MCP, on both latest merged main and the fixed branch. Native Node resolves the dependency without executing the fixture. Complete Evidence envelopes authenticate; normalized CLI/MCP results match, MCP text/structured content matches, and a subsequent ping succeeds.

  • Regression coverage: 19 new semantic cases and two compiled public journeys; existing binding/provenance coverage retained, including deep members and empty keys. The initial source/public regression run fails 15 cases on the affected producer and passes six controls.

  • Remaining proof gaps: Linux verification only; no real Ghidra, IDA, Hopper or browser workflow is involved.

  • Observed, derived, and inferred claims remain distinguishable.

  • Artifact identity, source provenance, and failed attempts remain preserved.

  • Unsupported, incomplete, unavailable, or uncertain outcomes remain visible.

Validation performed

Node 24.18.0 / npm 11.16.0, two CPUs, supervised 2 GiB process-family RSS limit:

  • npm run compile -- --singleThreaded — passed on exact head 92e2ddfd2359209e36f1f528db48ee87dd96a160, based on merged main 3ad5782d.
  • Flameox-supervised Vitest source runs, --maxWorkers=1 — 50 semantic/composition files with 890 passing cases, and 19 application/cancellation files with 297 passing cases.
  • Exact integrated-head Vitest run — eight files, 79 passing cases, including both compiled CLI/MCP journeys. This overlaps the broader source runs.
  • Separate complete public CLI/MCP reproduction — passed on the exact integrated runtime.
  • npm run typecheck -- --singleThreaded with GOMEMLIMIT=768MiB, npm run lint (including module boundaries), changed-file oxfmt --check, npm run verify:architecture-guards, and git diff --check — all passed.

Flameox capture workload exits and payload digests were checked; the profiles cover the Vitest launcher, so they establish neither child-worker CPU nor allocation improvements. The threaded aggregate hooks were bypassed with HUSKY=0; the checks above ran explicitly within the resource budget. Full CI remains required before merge.

Compatibility, safety, and release

  • Breaking changes or migration steps: none; additional semantic dependencies correct an omission.
  • Real Hopper/Ghidra, browser, or OS coverage: Linux CLI/MCP only, as described above.
  • Package or release metadata impact: none.
  • Security, privacy, process, or containment review: AST call identity stays private to analysis and never enters the IR or Evidence; no new execution or cleanup authority.

Review checklist

  • This PR addresses a concrete problem or an agreed enhancement.
  • The PR has one focused outcome and the title follows type(scope): outcome.
  • Related issue is linked.
  • Tests cover changed observable behavior and meaningful failure paths.
  • Owning docs, contracts, and generated metadata are updated where needed; none require regeneration here.
  • User-visible CLI/MCP changes include representative output.
  • I checked the final diff for secrets, unrelated cleanup, and unsupported claims.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-11T11:06:51.914467Z 92e2ddf PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@N0zoM1z0
N0zoM1z0 merged commit 3a17882 into main Oct 11, 2026
28 checks passed
@N0zoM1z0
N0zoM1z0 deleted the fix/javascript-unbound-require-20261011 branch October 11, 2026 11:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Unbound CommonJS require calls lack semantic module edges and report zero import relationships

1 participant