Ruby require paths match by bare segment, so rack/protection/base makes lib/sinatra/base.rb reachable — which blocks treating autoload as the dependency it is #297
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#297
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
From the same Ruby dogfood as #294 (§3.3 of the report):
get_dependenciesonauth.rbmissedlib/zammad_mcp.rb, which loads it withautoload :Auth, "zammad_mcp/auth".The fix for that is one line, and it was measured and reverted
autoloadloads a file exactly asrequiredoes, just later. The extractor'semit_requirealready takes the first STRING argument, which forautoloadskips the constant's symbol and lands on the path, so dispatchingautoloadthere records the right dependency. A test pinned it and its mutation ran red.Measured on ruby-sinatra (22
autoloadcalls inrack-protection/lib/rack/protection.rb): imports 231 -> 251, and 17 binds changed, every one a phantom, all tier 3 (import boost):Line 37's
useisRack::Builder#use(the block isRack::Builder.new do … end); line 31'sfetchisHash#fetch. Neither is in this repository. So autoload was reverted — the same bar #294 held every encoding to.Why: a Ruby require path is matched by segment runs
autoload :Base, 'rack/protection/base'produces the importrequire 'rack/protection/base'would. The import-key machinery (import_run_candidatesand the tier-3 reachability joins) offers anchored segment RUNS of the specifier.protectionnames a project file, so it anchors the runbase, and the file keybasematchesrack/protection/base.rbandlib/sinatra/base.rb.Sinatra::useis then the onlyusein a reachable file, and tier 3 takes it.This is not autoload-specific: every
require 'x/y/base'in the corpus already widens reachability the same way. Autoload only made it visible by adding twenty such imports in one file.What would close it
A Ruby
require/require_relativepath names a FILE by its load-path-relative path:'rack/protection/base'is some<load path>/rack/protection/base.rb. So a Ruby import should reach files whose path ENDS with the whole specifier (/rack/protection/base.rb), not any file sharing one segment — the structural factrequireitself obeys.require_relativealready resolves relatively viatemp.import_rel).require-driven phantoms to FALL, which is itself the evidence this is right, and read every lost bind at source.autoloadtoemit_requirein both extractors (builtin and thede.h-dv.rubyguest, forruby_package_parity), and re-measure — the 17 above must not come back.Related: #294, #194, I023 (why same-directory and import keys are Ruby's only locality signals).
#!/usr/bin/env rubyshebang is indexed as text only, because every language claim is path-based #298