github / github/codeql

[Python] tsg-parser fails to extract generic base class relations

未關閉
#22,298 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
question
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

Working with typed base classes in Python (see #22291) I realised that the toolchain seems to drop generic base classes (e.g. `list[int]` in `class Bar(list[int]):`) at some point. That is, in the example code
```
class Foo(list): pass

class Bar(list[int]): pass
```
CodeQL knows the `Foo` -> `list` relation but not the `Bar` -> `list[int]` relation.

---------

As far as I could trace it, the relation is already lost in the `tsg-python` parser. Using the v2.26.2 toolchain, the source code `class Bar(list): pass` produces the following `tsg-python` output (assignment nodes removed for brevity):
```
node 4
_kind: "Name"
_location: [0, 10, 0, 14]
ctx: "load"
variable: "list"
node 5
_kind: "ClassExpr"
_location: [0, 0, 0, 21]
_location_end: [0, 16]
inner_scope: [graph node 6]
name: "Bar"
edge 5 -> 4
bases: 0
node 6
_kind: "Class"
_location: [0, 0, 0, 21]
_location_end: [0, 16]
name: "Bar"
edge 6 -> 1
body: 0
```
Now if the code is extended for a generic subscription as `class Bar(list[int]): pass` produces the following `tsg-python` output (assignment nodes removed for brevity):
```
node 4
_kind: "Name"
_location: [0, 10, 0, 14]
ctx: "load"
variable: "list"
node 5
_kind: "Name"
_location: [0, 15, 0, 18]
ctx: "load"
variable: "int"
node 6
_kind: "Subscript"
_location: [0, 10, 0, 19]
ctx: "load"
index: [graph node 5]
value: [graph node 4]
node 7
_kind: "ClassExpr"
_location: [0, 0, 0, 26]
_location_end: [0, 21]
inner_scope: [graph node 8]
name: "Bar"
node 8
_kind: "Class"
_location: [0, 0, 0, 26]
_location_end: [0, 21]
name: "Bar"
edge 8 -> 1
body: 0
```
Notice that the type subscription is parsed (nodes `4`, `5`, `6`) but the `edge n -> m` node for the `bases: 0` relation is absent.

貢獻指南

開啟貢獻指南

研究方向

Start by reproducing the v2.26.2 tsg-python output for `class Bar(list[int]): pass`, then trace how the parser handles the `Subscript` node when constructing class bases. Done means the generic base produces a `bases` edge and CodeQL recognizes the `Bar` -> `list[int]` relation, while the existing non-generic case remains intact.

由索引模型根據 Issue 內容生成。

評估

技術堆疊
python
領域
compilers
Issue 類型
缺陷
難度
3/5
預估耗時
1-2 天
活躍度
冷清
描述清晰度
基本清楚
新手友好度
55/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。