Commit b4bb293
Take the ABAP call graph across the whole tree, bounded by ABAP's own visibility
The per-artefact graph answered nothing about class-based code. Measured on
sample_data/abap_src, every method parameter came back `no_caller` — a class's
callers live in other files by construction, and class-based ABAP is most modern
ABAP. So the graph now spans the scanned tree.
SEEING THE TREE IS NOT PERMISSION TO CLEAR A METHOD, and that is the part worth
reading. Who may call a procedure is decided by the language:
FORM file-local in every codebase anyone writes
PRIVATE only from inside its class — one artefact holds every caller
PROTECTED its class and its subclasses, which need the whole tree
PUBLIC anything that imports the class, including code never exported
FUNCTION another system entirely, if it carries the RFC flag
`by_public_literal` and `priv_literal` in the new fixture are the pair that makes
this a rule rather than a convenience: identical evidence — every call in the
whole tree passes a literal — and only the private one is downgraded.
RESOLUTION HAD TO BECOME CLASS-QUALIFIED FIRST. `run`, `execute` and `get_data`
are each defined dozens of times in a real custom-code base; resolving a call by
bare name across a tree would make almost every method ambiguous, and the tree
graph would have answered LESS than the per-artefact one it replaced. Receivers
are typed from TYPE REF TO, NEW, me-> and zcl_x=>. A receiver that cannot be
typed leaves the call unqualified, and an unqualified call may add taint to every
method of that name and may never clear any of them.
Local variable types are per artefact and never carried between files: `lo_worker`
in two files is two variables, and carrying a type across would resolve one
file's call against another file's declaration.
THE TRACE POINTED AT THE WRONG FILE. A cross-file call step carrying only
"line 20" sends the reader to line 20 of the artefact they are already reading,
which is an unrelated statement. The step now carries the caller's file, the
caller's own statement, and the variable the caller actually passed —
`iv_user_input`, not the callee's `iv_where`, which does not appear on that line.
The console ignored the new key and would have reproduced exactly that
misdirection on screen, so FindingDetail renders it.
Across every ABAP fixture, over the two commits: 11 confirmed / 0 tentative
became 17 / 4, with 7 traces crossing a call boundary and 1 reaching into another
artefact. The tree pass costs about 16% on a 120-file synthetic tree.
Still not interprocedural data-flow analysis, and docs/CVA_MERGE_PLAN.md's "not
claim interprocedural analysis" still holds: no fixpoint, and a non-literal
actual is treated as tainted rather than proven to be. It decides where the walk
starts; it does not trace a value through a procedure.
Eight mutations against the backend tests and two against the frontend one. All
ten fail them.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>1 parent 5f1e5b9 commit b4bb293
11 files changed
Lines changed: 964 additions & 114 deletions
File tree
- frontend/src/routes
- modules
- tests
- fixtures
- abap_tree
- exposure
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
717 | 717 | | |
718 | 718 | | |
719 | 719 | | |
720 | | - | |
| 720 | + | |
721 | 721 | | |
722 | 722 | | |
723 | 723 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
392 | 392 | | |
393 | 393 | | |
394 | 394 | | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
395 | 401 | | |
396 | 402 | | |
397 | | - | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
398 | 407 | | |
399 | 408 | | |
400 | 409 | | |
| |||
0 commit comments