Skip to content

fix: track local map range keys and values precisely - #69

Merged
picatz merged 3 commits into
mainfrom
fix/local-map-range-components
Oct 9, 2026
Merged

picatz merged 3 commits into
mainfrom
fix/local-map-range-components

Conversation

@picatz

@picatz picatz commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

Follow map iterator keys and values separately at each Next; status stays untainted. Local reaching definitions preserve entry-specific overwrite/delete/clear behavior, scalar copies, loop-carried writes, and map identity across Phi reexecution.

The implementation uses finite CFG worklists and query-local scratch storage. Direct local pointee reads have a closed-use guard; unknown aliases and helper effects retain the existing limitations. Existing map-lookup behavior, package/model scope, dependencies, and precision expectations are unchanged.

Validation

Final head: 41e8c08e1c28c39508aa9c6d5d242173a759a807.

  • All eight hosted checks passed: full build/tests on Go 1.26.9 and 1.27.2; root/callgraph and whole-program/CLI race; vet, fmt, compatible Staticcheck, and govulncheck.
  • All 15 precision snapshots unchanged; fresh scoreboard remains 8 TP / 5 known FN / 0 FP. No snapshots or ground-truth expectations were updated.
  • Original 32-case synthetic probe: 29 supported cases now pass, recovering 13 missed findings. Three inherited helper-map misses remain explicit.
  • 128 supported regressions cover tuple isolation, aliases, dynamic/interface/NaN keys, nested loops, local pointers, generic maps, source/sink positions, and deterministic evidence. Four inherited pointee misses are characterized separately.
  • Fresh SQL CLI and whole-program legacy/selected scans find the formerly missed annotated key/value sinks while preserving the clean control.
  • Independent adversarial review passed, including same-Phi clean kills and loop reexecution positives.

Cost and limits

48 benchmark shapes/sizes passed, with SSA construction excluded. Seven existing Linear/StringRange workloads retain identical median B/op and allocs/op. Isolated 1024-read allocation fell from about 623 MB in the initial implementation to 17.2 MB after scratch reuse. Timings were measured under concurrent load and do not support a speedup claim.

Work is O(W 脳 (I + E)) per read, plus alias/indexing/type-comparison costs. Repeated reads still repeat this work; no whole-analyzer linearity claim is made. Helper map summaries, general pointee aliases, and iteration-order/key correlations remain limited and may cause misses or conservative reports. See map-range scope and cost.

One redundant local aggregate root run was OS-killed under shared-runner load. Duplicate local work was canceled after the exact-source hosted gates passed; the hosted full logs are the integration evidence.

@picatz
picatz marked this pull request as ready for review October 9, 2026 02:57
@picatz
picatz merged commit 1000e4b into main Oct 9, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant