Skip to content

fix(extract): clear false file provenance from rescued imports - #4159

Draft
rileydev wants to merge 1 commit into
Graphify-Labs:v8from
rileydev:codex/fix-rescued-import-provenance
Draft

rileydev wants to merge 1 commit into
Graphify-Labs:v8from
rileydev:codex/fix-rescued-import-provenance

Conversation

@rileydev

@rileydev rileydev commented Oct 6, 2026

Copy link
Copy Markdown

fix(extract): keep unresolved rescued imports free of false file provenance

Regex-rescued imports can emit unresolved package names, missing relative files, and browser import URLs as node source_file values. Downstream consumers then treat references such as unknown-package or /node_modules/.vite/deps/react.js as real source files.

Mark only stubs emitted by the unresolved-target branch and clear their file claim after the existing ID canonicalization pass. Keep the specifier label and importing-file edge evidence. Delaying the clearing preserves portable IDs for unresolved relative imports; the existing Astro portability regression remains unchanged.

Validation: 86 focused tests and five language subcases pass, including JS, TS, Svelte, Astro, Vue, resolved local imports, portable IDs and warm AST cache reuse. The new regression fails before the repair. Isolated full-corpus CLI builds on 0.9.49 and 0.9.77 pass cold and retained source-path validation and querying while preserving every node ID and edge. Installed runtimes were not modified. Full upstream validation also ran in a disposable, credential-free environment: uv run --frozen --no-sync pytest tests/ -q reported 6,439 passed, 44 failed, 106 skipped and 5 subtests passed. The same 44 failures reproduced on the unchanged base: missing optional parser/OpenAI dependencies, absent historical Git objects in the source archive, and temporary-path assumptions. uv run --frozen --no-sync ruff check . --no-cache passed. uv run --frozen --no-sync pyright reported the same 637 errors and 4 warnings on candidate and base, with no added diagnostics. Full pytest and Pyright are not green; this PR remains a draft. The existing version-based AST cache namespace must advance with the upstream release; this is not a same-version hot patch.

Prepared with OpenAI Codex. No private repository contents or credentials are included in this patch.

Keep unresolved import paths through ID canonicalization, then remove the
source_file claim without changing IDs, import edges, or specifier labels.
Cover five syntax families, real-file resolution and retained AST caches.

Co-Authored-By: Codex <noreply@openai.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Thanks for the pull request, @rileydev. A maintainer will review it soon.

Want to talk it through while it is in review? Come join us on our Discord server. For longer-form discussion there is also GitHub Discussions.

A couple of things that speed up review: make sure the test suite passes on Python 3.10 and 3.13, and that the change keeps extraction deterministic.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant