Skip to content

Python qualified names can produce false inheritance and import-call edges #421

Description

@DivyamTalwar

Problem

Reducing requests.Session to Session can link a class to itself or to an unrelated local class. Separately, treating the leaf of unaliased import pkg.util as a bound name can invent a util.helper() call relationship.

Observed on upstream ce30de7ca94115cb73fa991538c6d2595ac2622a.

Focused correction

Keep plain dotted base names qualified and unresolved instead of guessing a local match. Do not create a leaf namespace binding for an unaliased dotted import; retain module import edges and supported explicit aliases. Native extractor-to-snapshot tests cover both false-edge cases and valid local/aliased controls.

Validation

The repository-native focused tests report 8 failures and 18 passing controls on unchanged production source; the prepared correction passes all 26 focused tests. The final commit is independently validated by the full Node 22/Linux suite with coverage, typecheck, build, duplication guard and critical-only bundle audit. The workflow enforces zero failed and zero skipped tests.

Prepared commit: 056df2b02716f8ff9adcbbb816a865a0f5d43b3e. Exact validation job and logs.

I am taking the implementation because the regression is reproducible and the change can remain focused. I will link the corresponding pull request.

Scope

Qualified-base resolution and general Python evaluation are not implemented. Dynamic base expressions remain unresolved, and unaliased dotted imports do not gain new inferred top-package bindings. PR #270 touches pushNode for node deduplication; this fix changes qualification handling rather than duplicating that work.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions