fallow_extract/cache/types.rs
1//! Serialization types for the incremental parse cache.
2//!
3//! All types use bitcode `Encode`/`Decode` for fast binary serialization.
4
5use bitcode::{Decode, Encode};
6
7use crate::MemberKind;
8
9/// Cache version, bump when the cache format or cached extraction semantics change.
10///
11/// Bumped to 89 for issue #475: extraction now strips a leading UTF-8 BOM
12/// before hashing and computing line offsets, so pre-fix entries whose source
13/// included a BOM carry hashes over the wrong byte sequence and would
14/// fast-path into stale `member_accesses` / `exports` for any BOM-bearing
15/// file. The bump invalidates user caches once on upgrade; subsequent runs
16/// are warm.
17///
18/// Bumped to 90 for issue #540: CSS Modules class extraction now strips
19/// `@layer` and `@import` at-rule preludes before scanning class names, so
20/// pre-fix entries for `.module.css` files using nested cascade-layer syntax
21/// (`@layer foo.bar { ... }`) carry phantom `bar` / `baz` exports that the
22/// new scanner no longer produces.
23///
24/// Bumped to 91 for issue #549: CSS Modules class extraction now records a
25/// real `Span` pointing at each class's declaration position in the source.
26/// Pre-fix cache entries for `.module.css` / `.module.scss` files carry
27/// `Span::default()` (start=0, end=0) on every export, which renders every
28/// finding at line:1 col:0; the new scanner produces real offsets.
29///
30/// Bumped to 92 for issue #563: feature flag extraction recognizes additional
31/// built-in SDK providers (PostHog, Vercel Flags, Optimizely, Eppo, plus more
32/// ConfigCat surfaces) and Vercel `flag({ key: "..." })` object arguments, so
33/// pre-fix entries can carry stale `flag_uses`.
34///
35/// Bumped to 93 for issue #589: Node `module.register()` loader calls now
36/// emit `DynamicImportInfo.destructured_names` populated with the loader-hook
37/// allowlist (current `initialize` / `resolve` / `load` / `globalPreload`
38/// plus legacy `getFormat` / `getSource` / `transformSource`) for every
39/// relative or `file:` specifier, including specifiers bound via
40/// `new URL(..., import.meta.url)`. Pre-fix entries carry empty
41/// `destructured_names` for the same source, so they would silently miss
42/// the named-export credit until the file is touched.
43///
44/// Bumped to 94 for issue #586: Playwright helper fixture extraction recognizes
45/// helpers with local setup before the final `return base.extend<T>(...)`, so
46/// pre-fix entries can miss fixture definition sentinels.
47///
48/// Bumped to 95 for the Glimmer `<template>` scanner: imported-binding usage
49/// and `MemberAccess { object: "this", member }` records for `{{this.foo}}`
50/// template references are now folded into the extractor before
51/// `into_module_info`. Pre-fix entries for `.gts` / `.gjs` files omit both,
52/// so template-only imports surface as `unused-import` and template-only
53/// class members as `unused-class-member` until the cache is re-extracted.
54///
55/// Bumped to 96 for issue #640: generic JSX `<script src>` and
56/// `<link rel="stylesheet|modulepreload" href>` attributes no longer emit
57/// synthetic `SideEffect` imports, so pre-fix entries can carry stale JSX
58/// resource edges that surface as false `unresolved-imports`.
59///
60/// Bumped to 97 for issue #639: MDX import/export extraction now skips
61/// fenced Markdown code blocks, so pre-fix entries can carry stale example
62/// imports that surface as false `unresolved-imports`.
63///
64/// Bumped to 98 for issue #638: statically resolvable `child_process.fork()`
65/// targets now emit `DynamicImportInfo` entries for local runner files.
66/// Pre-fix entries omit those dynamic imports, so forked script files can be
67/// reported as unused until the file is re-extracted.
68///
69/// Bumped to 99 for issue #605: methods reached via `new Class(...).method()`
70/// receivers (direct and fluent-chain) now emit member accesses crediting the
71/// constructed class. Pre-fix entries lack those accesses, so such methods can
72/// be reported as unused class members until the file is re-extracted.
73///
74/// Bumped to 100 for issue #608: static Iconify icon strings (`icon="jam:github"`,
75/// `name="ic:round-home"`) in markup now populate `iconify_prefixes` so the
76/// `@iconify-json/<prefix>` package is credited. Pre-fix entries omit the field,
77/// so icon-set packages can be reported as unused until the file is re-extracted.
78///
79/// Bumped to 101 for issue #704: SFC template tags that match no import now
80/// populate `auto_import_candidates` for convention auto-import resolution.
81/// Pre-fix entries omit the field, so Nuxt components consumed only via template
82/// tags are not edge-credited until the file is re-extracted.
83///
84/// Bumped to 102 for issue #742: `FunctionComplexity` now carries an
85/// `Option<String> source_hash` (content digest of the function's full-span
86/// source slice) so runtime-coverage baselines survive line moves. Pre-fix
87/// cache entries lack the field, so the hash is absent until re-extraction.
88///
89/// Bumped to 103 for issue #752: typed destructure bindings
90/// (`let { resultState }: Props = $props()`, `function f({ x }: Props)`) now
91/// populate `binding_target_names`, which changes the `member_accesses` emitted
92/// for those files. Pre-fix cache entries lack the additional member accesses.
93///
94/// Bumped to 104 for issue #445: MDX, Astro, Vue/Svelte SFC, and CSS/SCSS
95/// container extraction now remaps source-authored spans back to the original
96/// file byte offsets. Pre-fix entries can carry synthetic extracted-buffer
97/// positions, so diagnostics can point at line 1 or compacted MDX lines until
98/// the file is re-extracted.
99///
100/// Bumped to 105 for issue #739: JS/TS and Vue/Svelte SFC script extraction
101/// now populates `auto_import_candidates` from unresolved value references.
102/// Pre-fix entries omit these candidates, so convention script auto-imports
103/// are not edge-credited until the file is re-extracted.
104///
105/// Bumped to 106 for `fallow security`: JS/TS extraction now stores file-level
106/// directives (`"use client"`, `"use server"`) in the parse cache so client
107/// boundary detection does not depend on stale cached module info.
108///
109/// Bumped to 107 for issue #835: Svelte `<script src>` references no longer
110/// emit synthetic imports because they are runtime markup, not bundled SFC
111/// script modules. Pre-fix entries can carry stale root-relative imports that
112/// surface as false `unresolved-imports`.
113///
114/// Bumped to 108 for three extraction-semantics changes shipping together:
115/// - issue #839: `declare` ambient class properties are no longer extracted as
116/// class members (they emit no JS and cannot be value-referenced), so pre-fix
117/// entries carry phantom members that surface as false `unused-class-member`.
118/// - issue #840: extensionless `new URL(specifier, import.meta.url)` dynamic
119/// imports now persist `is_speculative = true` so a directory target
120/// (`new URL('./services', import.meta.url)`) is silently dropped when the
121/// resolver finds no module; pre-fix entries carry `is_speculative = false`
122/// and surface as false `unresolved-imports`.
123/// - issue #845: a method call on an `instanceof`-narrowed value now emits a
124/// member access against the narrowed class, changing the persisted
125/// `member_accesses`; pre-fix entries miss the credit and surface as false
126/// `unused-class-member`.
127///
128/// Bumped to 109 for the data-driven security matcher catalogue: JS/TS
129/// extraction now captures non-literal sink sites into `security_sinks`, each
130/// carrying an `arg_kind` discriminator (template-with-substitution, concat,
131/// object, call, other) so the catalogue can require unsafe SQL shapes and
132/// exclude safely-parameterized `` sql`${x}` `` templates and object-form
133/// `.execute({ sql, args })` arguments. Pre-109 entries lack the field, so their
134/// sink sites do not feed the catalogue until the file is re-extracted.
135///
136/// Bumped to 110 for issue #844: `const svc = useMemo(() => new Svc())` now
137/// binds the non-destructured identifier to the constructed class, so method
138/// calls on it emit member accesses crediting the class. This changes the
139/// persisted `member_accesses` for files using the useMemo factory shape;
140/// pre-fix entries miss the credit and surface as false `unused-class-member`.
141///
142/// Bumped to 111 for issue #859 (untrusted-source modeling): `SinkSite` now
143/// carries `arg_idents` (identifiers referenced in the sink argument) and
144/// `ModuleInfo`/`CachedModule` carry `tainted_bindings` (local bindings tied to
145/// the member-access path they were sourced from), so the security
146/// `tainted_sink` detector can back-trace a sink argument to a known untrusted
147/// source. Pre-111 entries lack both, so source-to-sink association is unset
148/// until the file is re-extracted.
149///
150/// Bumped to 112 for issue #863 (sanitizer-aware security sinks):
151/// `ModuleInfo`/`CachedModule` now carry direct sanitized sink arguments, so
152/// the security `tainted_sink` detector can suppress high-confidence
153/// DOMPurify-backed HTML sink candidates. Pre-112 entries lack sanitizer
154/// metadata until the file is re-extracted.
155///
156/// Bumped to 113 for issue #863 follow-up: sanitizer metadata gained URL and
157/// path domains plus guarded path backpatching. Pre-113 entries may lack those
158/// sanitizer domains until the file is re-extracted.
159///
160/// Bumped to 114 for issue #911: Angular component properties initialized with
161/// named-import `inject(Service)` now populate `ClassHeritageInfo.instance_bindings`
162/// so external templates can credit service member access through the property.
163/// Pre-114 entries miss the binding and can surface false `unused-class-member`
164/// findings until the component file is re-extracted.
165///
166/// Bumped to 115 for issue #910: local typed function calls now credit concrete
167/// class members when a direct `new Class()` argument or constructor-bound
168/// identifier flows into a structurally typed parameter. Pre-115 entries can
169/// miss those synthetic `member_accesses` and surface false
170/// `unused-class-member` findings.
171///
172/// Bumped to 117 for issue #955: Vue SFC script-side Nuxt UI icon strings now
173/// populate `iconify_icon_names`, allowing declared `@iconify-json/*`
174/// collections used through values like `icon: 'i-simple-icons-github'` to be
175/// credited. Pre-116 entries omit those names and can surface false
176/// `unused-dependency` findings until the file is re-extracted.
177///
178/// Bumped to 118 for issue #954: JS/TS extraction now records static
179/// `pino({ transport: { target: "pkg" } })` target packages as synthetic
180/// dynamic imports so runtime transport dependencies are credited. Pre-118
181/// entries can surface false `unused-dependency` findings until the file is
182/// re-extracted.
183///
184/// Bumped to 119 for issue #952: JS/TS extraction now records static package
185/// path resolution references so packages consumed via package-root and
186/// `pkg/package.json` lookups are credited as dependency usage. Pre-119
187/// entries omit those references and can surface false `unused-dependency`
188/// findings until the file is re-extracted.
189///
190/// Bumped to 120 for issue #953: instance methods annotated with TypeScript's
191/// `this` return type now count as self-returning for constructor-rooted
192/// fluent chains. Pre-120 entries can miss those self-returning flags and
193/// surface false `unused-class-member` findings until the file is re-extracted.
194///
195/// Bumped to 121 for issue #883: framework template HTML injection sinks now
196/// flow into `ModuleInfo.security_sinks` for Svelte `{@html ...}`, Vue
197/// `v-html`, and Angular `[innerHTML]`. Pre-121 entries omit those sink sites
198/// until the file is re-extracted.
199///
200/// Bumped to 122: `FunctionComplexity` now carries a `contributions` vector
201/// (per-decision-point complexity breakdown) and `RequireCallInfo` carries
202/// `source_span` (the specifier string-literal span so an `unresolved-import`
203/// squiggly anchors under the `'./x'` specifier rather than the `require`
204/// keyword). Pre-122 entries lack the breakdown (empty under
205/// `health --complexity-breakdown`) and carry `Span::default()` for the
206/// require specifier until the file is re-extracted.
207///
208/// Bumped to 123 for PR #1010: JSDoc import-type extraction now ignores prose
209/// examples, including examples that contain ordinary JavaScript brace groups.
210/// Pre-123 entries can carry stale type-only imports that surface as false
211/// `unresolved-imports` until the file is re-extracted.
212///
213/// Bumped to 124 for issue #877: static `import.meta.env.SECRET` reads now
214/// populate `member_accesses` as `import.meta.env` source reads for the
215/// opt-in client/server security candidate detector. Pre-124 entries omit the
216/// source and would miss Vite env reads until the file is re-extracted.
217///
218/// Bumped to 125 for issue #875: `SinkSite` now carries literal argument and
219/// object-literal option metadata, allowing security catalogue rows to match
220/// deterministic literal sinks such as wildcard postMessage origins,
221/// permissive CORS, insecure cookie options, weak crypto algorithms, and
222/// alg:none JWT options. Pre-125 entries lack that metadata until the file is
223/// re-extracted.
224///
225/// Bumped to 126 for issue #876: `SinkSite` now carries flattened source paths
226/// referenced inside sink arguments, so source-backed logging candidates can
227/// match direct expressions such as `process.env.SECRET` without requiring a
228/// temporary local binding. Pre-126 entries lack those paths until the file is
229/// re-extracted.
230///
231/// Bumped to 127 for issue #898: `SinkSite` now carries complete top-level
232/// object-key metadata so missing-option security rows can distinguish absent
233/// keys from non-literal option values. Pre-127 entries lack that metadata until
234/// the file is re-extracted.
235///
236/// Bumped to 128 for issue #895: JS/TS extraction now captures the exact
237/// `process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0"` literal assignment as a
238/// security sink site. Pre-128 entries omit that sink until the file is
239/// re-extracted.
240///
241/// Bumped to 129 for issue #901: JS/TS extraction now captures cleartext
242/// request URL literals and `new WebSocket("ws://...")` as security sink sites.
243/// Pre-129 entries omit those sinks until the file is re-extracted.
244///
245/// Bumped to 130 for issue #892: JS/TS extraction now captures static string
246/// literals assigned to secret-shaped identifiers or known provider credential
247/// prefixes as opt-in hardcoded-secret candidates.
248/// Pre-130 entries omit those candidates until the file is re-extracted.
249///
250/// Bumped to 131 for issue #879: JS/TS extraction now records synthetic
251/// source bindings for recognizable framework handler parameters. Pre-131
252/// entries omit those bindings and cannot source-rank direct handler params.
253///
254/// Bumped to 132 for issue #878: JS/TS extraction now records one-hop
255/// same-module helper calls that return source-backed expressions as tainted
256/// bindings. Pre-132 entries miss the ranking signal until re-extracted.
257///
258/// Bumped to 133 for issue #901: `SinkSite` now carries integer literal
259/// values and nested static object property paths for additional literal-tier
260/// security rows. Pre-133 entries omit that metadata until the file is
261/// re-extracted.
262///
263/// Bumped to 134 for issue #928: JS/TS extraction now captures risky literal
264/// regex application sites in `security_sinks` so `fallow security` can report
265/// source-backed ReDoS candidates. Pre-134 entries omit those sink sites until
266/// the file is re-extracted.
267///
268/// Bumped to 135 for issue #929: JS/TS extraction now skips directly clamped
269/// resource-amplification size arguments before catalogue matching. Pre-135
270/// entries may retain stale clamped amplification sink candidates until the
271/// file is re-extracted.
272///
273/// Bumped to 136 for issue #899: JS/TS extraction now emits GraphQL resolver
274/// args, tRPC procedure input, and exact member source paths for local tainted
275/// bindings. Pre-136 entries may miss those source-backed ranking signals until
276/// the file is re-extracted.
277///
278/// Bumped to 137 for issue #888: JS/TS extraction now records defensive
279/// security control sites for the attack-surface inventory. Pre-137 entries
280/// omit those controls until the file is re-extracted.
281///
282/// Bumped to 138 for issue #890: `SinkSite` now carries the arg-0 URL literal
283/// (`url_arg_literal`) for the secret-to-network destination signal, `import.meta.env`
284/// reads are modeled as a source via the new `flatten_member_path` MetaProperty
285/// arm, and public-by-convention env vars (`NEXT_PUBLIC_`, `VITE_`, ...) are no
286/// longer recorded as secret sources. Pre-138 entries omit the URL signal and may
287/// retain stale public-env source bindings until the file is re-extracted.
288///
289/// Bumped to 139 for issue #1095: JS/TS extraction now records source-backed
290/// local bindings when template literals, string concatenation, or object
291/// literals embed an untrusted source. Pre-139 entries miss those ranking
292/// signals until the file is re-extracted.
293///
294/// Bumped to 140 for issue #1094: JS/TS extraction now records declarative
295/// framework validation boundary controls for security surface output. Pre-140
296/// entries can miss route-level validation control sites until re-extracted.
297///
298/// Bumped to 141 for issue #1093: `TaintedBinding` gains `source_span_start`
299/// (the byte offset of the source read) so the analyze layer can anchor a taint
300/// trace's source node at the real read line; pre-141 entries lack the offset.
301/// Bumped to 142 for issue #1134: JS/TS extraction now stores compact
302/// diagnostics for security sink-shaped callees that could not be flattened, so
303/// warm-cache `fallow security` runs can report the same blind-spot metadata as
304/// cold extraction.
305///
306/// Bumped to 143 for issue #1138: JS/TS extraction now propagates simple
307/// module-scope literal constants into security sink argument metadata and
308/// filters public CI metadata env vars before source matching.
309///
310/// Bumped to 144 for issue #1136: JS/TS sanitizer metadata now recognizes
311/// proven local HTML escape helpers, renderer helpers, and SQL identifier
312/// quoting helpers. Pre-144 entries can lack those sanitizer domains until the
313/// file is re-extracted.
314///
315/// Bumped to 145 for issue #1137: `SinkSite` now carries URL construction shape
316/// metadata for fixed-origin and dynamic-origin URL sink candidates.
317///
318/// Bumped to 146 for issue #1146: JS/TS extraction now chains tainted local
319/// bindings through up to three same-module hops, so warm caches written
320/// before the bump lack the chained `tainted_bindings` records.
321///
322/// Bumped to 147 for issue #1147: JS/TS extraction now captures deduped
323/// statically flattenable callee paths (`callee_uses`) for the
324/// `boundaries.calls.forbidden` detector, so warm caches written before the
325/// bump would report zero forbidden-call findings.
326///
327/// Bumped to 148 for issue #1190: JS/TS extraction now records nested
328/// Playwright fixture type-alias bindings in `member_accesses`, so warm caches
329/// written before the bump can miss fixture members reached through imported
330/// object type aliases.
331///
332/// Bumped to 149 for issue #1180: cached inline suppressions now preserve
333/// scoped rule-pack policy tokens (`policy-violation:<pack>/<rule-id>`).
334/// Pre-149 entries only store a broad `IssueKind` discriminant and cannot
335/// round-trip scoped policy suppressions.
336///
337/// Bumped to 150 for issue #1210: JS/TS extraction now records Playwright
338/// fixture wrapper aliases in `member_accesses`, so warm caches written before
339/// the bump can miss fixture members reached through `mergeTests` or chained
340/// wrapper `.extend(...)` calls.
341///
342/// Bumped to 151 for the server-only-import security candidate: JS/TS extraction
343/// now records `next/dynamic(..., { ssr: false })` dynamic-import spans on
344/// `client_only_dynamic_import_spans`, so warm caches written before the bump
345/// miss the ssr:false client-only escape hatch the `client-server-leak` BFS uses
346/// to exclude that edge.
347///
348/// Bumped to 152 for the `misplaced-directive` detector: JS/TS extraction now
349/// records `"use client"` / `"use server"` directive strings written as
350/// expression statements in `program.body` (misplaced) on
351/// `misplaced_directives`, so warm caches written before the bump would report
352/// zero misplaced-directive findings.
353///
354/// Bumped to 154 for the `unprovided-inject` detector: JS/TS and SFC extraction
355/// now record Vue `provide`/`inject` and Svelte `setContext`/`getContext` call
356/// sites on `di_key_sites` plus a `has_dynamic_provide` flag, so warm caches
357/// written before the bump would report zero unprovided-inject findings.
358///
359/// Bumped to 155 because `di_key_sites` now drops keys bound to a module-scope
360/// string-literal const (string identity, not a symbol), so a warm cache from
361/// 154 would carry those dropped sites and false-flag a string-keyed inject.
362///
363/// Bumped to 156 because SFC markup asset references (`<img src="./logo.png">`,
364/// `<source>`, `<video poster>`) now emit `SideEffect` imports, so a warm cache
365/// from 155 would miss the new `unresolved-import` findings on missing assets.
366///
367/// Bumped to 157 because the Vue `<template>` body extractor now matches the
368/// root `</template>` with nesting depth tracking instead of the first
369/// `</template>`. A Vue SFC whose root template contains a nested `<template
370/// #slot>` no longer has its body truncated, so component tags rendered after
371/// the first nested slot are now credited; a warm cache from 156 would carry the
372/// truncated template-usage set and false-flag those components / their imports.
373///
374/// Bumped to 158 for the `unused-component-prop` detector: Vue `<script setup>`
375/// extraction now records `defineProps` declared props on `component_props`
376/// (with `used_in_script` / `used_in_template`) plus the
377/// `has_props_attrs_fallthrough` / `has_define_expose` / `has_define_model` /
378/// `has_unharvestable_props` abstain flags, so a warm cache from 157 would
379/// report zero unused-component-prop findings.
380///
381/// Bumped to 159 because `ComponentProp` gained a `local` field (the destructure
382/// alias for a renamed prop), changing the cached wire shape; a warm 158 cache
383/// would bitcode-misread it.
384///
385/// Bumped to 160 for the `unused-component-emit` detector: Vue `<script setup>`
386/// extraction now records `defineEmits` declared events on `component_emits`
387/// (with `used`) plus the `has_unharvestable_emits` / `has_dynamic_emit` /
388/// `has_emit_whole_object_use` abstain flags, so a warm cache from 159 would
389/// report zero unused-component-emit findings.
390///
391/// Bumped to 162 for `unused-load-data-key` Primitive A: a destructure off the
392/// SvelteKit `data` prop local (`const { user } = data`) now emits `data.<key>`
393/// member accesses (rest element records a whole-object use). A warm cache from
394/// 161 lacks those accesses, so the cross-file load-data-key join would miss the
395/// consumed keys.
396///
397/// Bumped to 163 for `unused-load-data-key` Primitive B: a SvelteKit route
398/// component (`+page.svelte` / `+layout.svelte`) now credits the `data` prop as
399/// a template-visible root, so `{data.x}` / `{#each data.items as i}` markup
400/// reads emit `data.<key>` member accesses. A warm cache from 162 lacks those
401/// template-side accesses, so the cross-file load-data-key join would miss keys
402/// consumed only in markup.
403///
404/// Bumped to 164 for `unused-load-data-key` Primitive C: a SvelteKit global
405/// page-store read in a template (`{$page.data.KEY}` / `{page.data.KEY}`) now
406/// recovers the nested `page.data.<key>` member access (the template scanner
407/// previously dropped the key, keeping only `page.data`). A warm cache from 163
408/// lacks those project-wide global-store accesses.
409///
410/// Bumped (origin/main) for the `unused-load-data-key` detector: SvelteKit
411/// page-load producers now harvest `load_return_keys` + `has_unharvestable_load`,
412/// and every file records `has_load_data_whole_use` (the FP-1 whole-`data` pass
413/// signal). A warm cache from 164 lacks all three.
414///
415/// Bumped (origin/main) for the typed-`data` template fix: a SvelteKit route
416/// component whose `data` prop is typed (`export let data: PageData`) no longer
417/// remaps its template `data.<key>` accesses onto the generated `$types` alias,
418/// keeping them keyed on `data` for the load-data join. A warm cache carries the
419/// remapped (`PageData.<key>`) accesses and would miss real consumer reads.
420///
421/// Bumped (origin/main) for #550: CSS Module class extraction now derives its
422/// class set from a real CSS AST (lightningcss) for standard CSS, so warm caches
423/// written by the regex-only extractor can differ on escaped class names and
424/// malformed at-rule preludes.
425///
426/// Bumped (feat/react-health) for React/JSX structural extraction (Phase 0
427/// foundation): `.jsx`/`.tsx` files now record `component_functions`,
428/// `react_props`, `hook_uses`, and `render_edges`, so a warm cache lacks the
429/// React IR the later React-health phases consume.
430///
431/// Bumped (feat/react-health) for the React `unused-component-prop` arm
432/// (Phase 1): each `ComponentProp` gained a `component` field (the enclosing
433/// React component name) and `react_props[].used_in_script` is now populated
434/// from a used-in-body pass, so a warm cache carries props with an empty
435/// `component` and always-false usage.
436///
437/// Bumped (feat/react-health) for React-aware complexity (Phase 2):
438/// `FunctionComplexity` now carries `react_hook_count`, `react_jsx_max_depth`,
439/// and `react_prop_count` descriptive fields, and the cognitive metric folds
440/// deep JSX nesting, hook density, and prop count (recorded as `JsxDepth` /
441/// `HookDensity` / `PropCount` contributions). A warm cache carries the pre-fold
442/// cognitive scores and lacks the React descriptive counts until re-extraction.
443///
444/// Bumped (feat/react-health) for the prop-drilling forward signal (Phase 3):
445/// `RenderEdge` gained `attr_value_roots` / `has_complex_forward`,
446/// `ComponentFunction` gained `uses_clone_element` / `renders_provider` /
447/// `has_children_as_function`, and `ComponentProp` gained `used_outside_forward`.
448/// A warm cache lacks the per-render attribute-value roots and the
449/// per-component / per-prop forward classification the prop-drilling detector
450/// consumes.
451///
452/// Bumped to 170: `ComponentFunction` gained `is_pure_passthrough` (the
453/// thin-wrapper extraction flag), a new bitcode field on a cached struct
454/// persisted via `ModuleInfo`.
455pub(super) const CACHE_VERSION: u32 = 170;
456
457/// Duplication token cache version. Bump when duplicate tokenization,
458/// normalization, or the on-disk token cache schema changes.
459///
460/// Bumped to 6 for issue #1225: `ignoreImports` now excludes re-export barrels
461/// and top-level static CommonJS require binding declarations.
462pub const DUPES_CACHE_VERSION: u32 = 6;
463
464/// Default maximum cache size (256 MB). Overridable per-project via
465/// `cache.maxSizeMb` in the config file or `FALLOW_CACHE_MAX_SIZE` env var.
466/// Also used as the hard ceiling on load-time deserialization as a defence
467/// against pathological on-disk files.
468pub const DEFAULT_CACHE_MAX_SIZE: usize = 256 * 1024 * 1024;
469
470/// Trigger LRU eviction when the serialized cache exceeds 80% of the cap.
471/// Basis points (1/100 of a percent) for integer arithmetic without floats.
472pub(super) const EVICTION_TRIGGER_BPS: usize = 8000;
473
474/// Evict down to 60% of the cap so subsequent saves leave headroom.
475pub(super) const EVICTION_TARGET_BPS: usize = 6000;
476
477/// Promote the eviction log from `debug!` to `info!` when at least 25% of
478/// entries are removed in a single save. Default-noise concerns mean
479/// small-turnover saves should not be visible without `RUST_LOG=debug`.
480pub(super) const EVICTION_SIGNIFICANT_BPS: usize = 2500;
481
482/// Import kind discriminant for `CachedImport`:
483/// 0 = Named, 1 = Default, 2 = Namespace, 3 = `SideEffect`.
484pub(super) const IMPORT_KIND_NAMED: u8 = 0;
485pub(super) const IMPORT_KIND_DEFAULT: u8 = 1;
486pub(super) const IMPORT_KIND_NAMESPACE: u8 = 2;
487pub(super) const IMPORT_KIND_SIDE_EFFECT: u8 = 3;
488
489macro_rules! assert_cached_type_size {
490 ($ty:ty, $size:expr) => {
491 const _: () = assert!(
492 std::mem::size_of::<$ty>() == $size,
493 concat!(
494 stringify!($ty),
495 " size changed; bump CACHE_VERSION if the cached wire shape or extraction semantics changed, then update this assertion"
496 )
497 );
498 };
499}
500
501assert_cached_type_size!(CachedModule, 1056);
502assert_cached_type_size!(CachedNamespaceObjectAlias, 72);
503assert_cached_type_size!(CachedLocalTypeDeclaration, 32);
504assert_cached_type_size!(CachedPublicSignatureTypeReference, 56);
505assert_cached_type_size!(CachedSuppression, 64);
506assert_cached_type_size!(CachedUnknownSuppressionKind, 32);
507assert_cached_type_size!(CachedExport, 112);
508assert_cached_type_size!(CachedImport, 96);
509assert_cached_type_size!(CachedDynamicImport, 88);
510assert_cached_type_size!(CachedRequireCall, 88);
511assert_cached_type_size!(CachedReExport, 88);
512assert_cached_type_size!(CachedMember, 64);
513assert_cached_type_size!(CachedDynamicImportPattern, 56);
514assert_cached_type_size!(crate::MemberAccess, 48);
515assert_cached_type_size!(fallow_types::extract::CalleeUse, 32);
516assert_cached_type_size!(fallow_types::extract::MisplacedDirectiveSite, 8);
517assert_cached_type_size!(fallow_types::extract::SinkSite, 216);
518assert_cached_type_size!(fallow_types::extract::FunctionComplexity, 96);
519assert_cached_type_size!(fallow_types::extract::ComplexityContribution, 16);
520assert_cached_type_size!(fallow_types::extract::FlagUse, 80);
521assert_cached_type_size!(fallow_types::extract::ClassHeritageInfo, 96);
522assert_cached_type_size!(fallow_types::extract::LoadReturnKey, 32);
523
524/// Cached data for a single module.
525#[derive(Debug, Clone, Encode, Decode)]
526pub struct CachedModule {
527 /// xxh3 hash of the file content.
528 pub content_hash: u64,
529 /// File modification time (seconds since epoch) for fast cache validation.
530 /// When mtime+size match the on-disk file, we skip reading file content entirely.
531 pub mtime_secs: u64,
532 /// File size in bytes for fast cache validation.
533 pub file_size: u64,
534 /// Seconds-since-epoch at the time this entry was last WRITTEN
535 /// (first parse or content-change refresh). NOT updated on cache-hit
536 /// reads: `update_cache` already iterates every in-scope file every run,
537 /// so refreshing on read would collapse the LRU to "last run this file
538 /// was discovered" for every retained entry. With write-only refresh,
539 /// the LRU genuinely targets stale (in-scope-but-unchanged-for-many-runs)
540 /// entries. Used by `CacheStore::save` for write-time eviction ordering.
541 pub last_access_secs: u64,
542 /// Exported symbols.
543 pub exports: Vec<CachedExport>,
544 /// Import specifiers.
545 pub imports: Vec<CachedImport>,
546 /// Re-export specifiers.
547 pub re_exports: Vec<CachedReExport>,
548 /// Dynamic import specifiers.
549 pub dynamic_imports: Vec<CachedDynamicImport>,
550 /// `require()` specifiers.
551 pub require_calls: Vec<CachedRequireCall>,
552 /// Package names statically referenced through package path resolution.
553 pub package_path_references: Vec<String>,
554 /// Static member accesses (e.g., `Status.Active`).
555 pub member_accesses: Vec<crate::MemberAccess>,
556 /// Identifiers used as whole objects (Object.values, for..in, spread, etc.).
557 pub whole_object_uses: Vec<String>,
558 /// Dynamic import patterns with partial static resolution.
559 pub dynamic_import_patterns: Vec<CachedDynamicImportPattern>,
560 /// Whether this module uses CJS exports.
561 pub has_cjs_exports: bool,
562 /// Whether this module declares at least one Angular `@Component({
563 /// templateUrl: ... })` decorator. Mirrors `ModuleInfo.has_angular_component_template_url`
564 /// so the CRAP-inherit walker's gate survives a warm-cache load.
565 pub has_angular_component_template_url: bool,
566 /// Local names of import bindings that are never referenced in this file.
567 pub unused_import_bindings: Vec<String>,
568 /// Local import bindings referenced from type positions.
569 pub type_referenced_import_bindings: Vec<String>,
570 /// Local import bindings referenced from value positions.
571 pub value_referenced_import_bindings: Vec<String>,
572 /// Inline suppression directives.
573 pub suppressions: Vec<CachedSuppression>,
574 /// Suppression tokens that did not parse to any known `IssueKind`. See #449.
575 pub unknown_suppression_kinds: Vec<CachedUnknownSuppressionKind>,
576 /// Pre-computed line-start byte offsets for O(log N) byte-to-line/col conversion.
577 pub line_offsets: Vec<u32>,
578 /// Per-function complexity metrics.
579 pub complexity: Vec<fallow_types::extract::FunctionComplexity>,
580 /// Feature flag use sites.
581 pub flag_uses: Vec<fallow_types::extract::FlagUse>,
582 /// Heritage metadata for exported classes.
583 pub class_heritage: Vec<fallow_types::extract::ClassHeritageInfo>,
584 /// Angular `InjectionToken<Interface>` `(token, interface)` pairs (#920).
585 pub injection_tokens: Vec<(String, String)>,
586 /// Local type-capable declarations.
587 pub local_type_declarations: Vec<CachedLocalTypeDeclaration>,
588 /// Type references from exported public signatures.
589 pub public_signature_type_references: Vec<CachedPublicSignatureTypeReference>,
590 /// Namespace-import aliases re-exported through an object literal
591 /// (`export const API = { foo }` where `foo` is `import * as foo from './bar'`).
592 pub namespace_object_aliases: Vec<CachedNamespaceObjectAlias>,
593 /// Iconify collection prefixes found in static icon props (issue #608).
594 pub iconify_prefixes: Vec<String>,
595 /// Nuxt UI icon class suffixes found in static script-side icon properties
596 /// (issue #955).
597 pub iconify_icon_names: Vec<String>,
598 /// Bare identifier names that are candidates for convention auto-import
599 /// resolution (issue #704). Content-local, so they round-trip through the
600 /// cache; resolution against the plugin table happens at graph-build time.
601 pub auto_import_candidates: Vec<String>,
602 /// File-level string directives (`"use client"`, `"use server"`). Content-local,
603 /// round-trips through the cache so the security `client-server-leak` detector
604 /// sees directives on warm-cache loads.
605 pub directives: Vec<String>,
606 /// Byte-offset starts of `next/dynamic(..., { ssr: false })` dynamic imports.
607 /// Content-local, round-trips so the security `client-server-leak` BFS sees
608 /// the ssr:false client-only escape hatch on warm-cache loads.
609 pub client_only_dynamic_import_spans: Vec<u32>,
610 /// Captured security sink sites (category-blind). Round-trips through the
611 /// cache so the catalogue-driven `tainted_sink` detector sees sinks on
612 /// warm-cache loads.
613 pub security_sinks: Vec<fallow_types::extract::SinkSite>,
614 /// Count of sink-shaped nodes whose callee could not be flattened to a
615 /// static path. Round-trips so the in-band blind-spot count is stable.
616 pub security_sinks_skipped: u32,
617 /// Span-level diagnostics for skipped security sink callees.
618 pub security_unresolved_callee_sites: Vec<fallow_types::extract::SkippedSecurityCalleeSite>,
619 /// Local bindings tied to the member-access path they were sourced from.
620 /// Round-trips so the security `tainted_sink` source-to-sink association
621 /// sees source-tainted bindings on warm-cache loads.
622 pub tainted_bindings: Vec<fallow_types::extract::TaintedBinding>,
623 /// Direct sink arguments recognized as sanitizer calls.
624 pub sanitized_sink_args: Vec<fallow_types::extract::SanitizedSinkArg>,
625 /// Defensive control call sites for security surface output.
626 pub security_control_sites: Vec<fallow_types::extract::SecurityControlSite>,
627 /// Deduped statically flattenable callee paths. Round-trips so the
628 /// `boundaries.calls.forbidden` detector sees call sites on warm-cache
629 /// loads.
630 pub callee_uses: Vec<fallow_types::extract::CalleeUse>,
631 /// Misplaced `"use client"` / `"use server"` directive sites.
632 /// Round-trips so the `misplaced-directive` detector sees them on
633 /// warm-cache loads.
634 pub misplaced_directives: Vec<fallow_types::extract::MisplacedDirectiveSite>,
635 /// Vue `provide`/`inject` and Svelte `setContext`/`getContext` key sites.
636 /// Round-trips so the `unprovided-inject` detector sees them on warm-cache
637 /// loads.
638 pub di_key_sites: Vec<fallow_types::extract::DiKeySite>,
639 /// Whether the module had an unknowable-key provide. Round-trips so the
640 /// `unprovided-inject` project-wide abstain holds on warm-cache loads.
641 pub has_dynamic_provide: bool,
642 /// Vue `<script setup>` `defineProps` declared props. Round-trips so the
643 /// `unused-component-prop` detector sees them on warm-cache loads.
644 pub component_props: Vec<fallow_types::extract::ComponentProp>,
645 /// Whether the template spreads `$attrs`/`$props`/`props` or the
646 /// `defineProps` return is rest-destructured. Round-trips for the abstain.
647 pub has_props_attrs_fallthrough: bool,
648 /// Whether the SFC calls `defineExpose(...)`. Round-trips for the abstain.
649 pub has_define_expose: bool,
650 /// Whether the SFC calls `defineModel(...)`. Round-trips for the abstain.
651 pub has_define_model: bool,
652 /// Whether `defineProps` had an unharvestable type-reference argument.
653 /// Round-trips for the abstain.
654 pub has_unharvestable_props: bool,
655 /// Vue `<script setup>` `defineEmits` declared events. Round-trips so the
656 /// `unused-component-emit` detector sees them on warm-cache loads.
657 pub component_emits: Vec<fallow_types::extract::ComponentEmit>,
658 /// Whether `defineEmits` had an unharvestable argument. Round-trips for the
659 /// abstain.
660 pub has_unharvestable_emits: bool,
661 /// Whether an `emit(<nonLiteral>)` call was seen. Round-trips for the abstain.
662 pub has_dynamic_emit: bool,
663 /// Whether the emit binding was used as a whole value. Round-trips for the
664 /// abstain.
665 pub has_emit_whole_object_use: bool,
666 /// SvelteKit `load()` return-object keys. Round-trips so the
667 /// `unused-load-data-key` detector sees them on warm-cache loads.
668 pub load_return_keys: Vec<fallow_types::extract::LoadReturnKey>,
669 /// Whether this file's `load()` body could not be harvested safely.
670 /// Round-trips for the abstain.
671 pub has_unharvestable_load: bool,
672 /// Whether this file passes the whole `data` object opaquely. Round-trips
673 /// for the `unused-load-data-key` abstain.
674 pub has_load_data_whole_use: bool,
675 /// React/JSX component definitions. Round-trips so the React-health phases
676 /// see them on warm-cache loads.
677 pub component_functions: Vec<fallow_types::extract::ComponentFunction>,
678 /// React component props. Round-trips so the React `unused-component-prop`
679 /// arm sees them on warm-cache loads.
680 pub react_props: Vec<fallow_types::extract::ComponentProp>,
681 /// React hook call sites. Round-trips for the complexity-fold phase.
682 pub hook_uses: Vec<fallow_types::extract::HookUse>,
683 /// React render edges (child name captured; resolution deferred to graph
684 /// build). Round-trips so the render graph survives a warm cache.
685 pub render_edges: Vec<fallow_types::extract::RenderEdge>,
686}
687
688/// Cached namespace-object alias.
689#[derive(Debug, Clone, Encode, Decode)]
690pub struct CachedNamespaceObjectAlias {
691 /// Canonical export name on this module.
692 pub via_export_name: String,
693 /// Dotted suffix of the property path relative to the export.
694 pub suffix: String,
695 /// Local name of the namespace import on this module.
696 pub namespace_local: String,
697}
698
699/// Cached local type declaration.
700#[derive(Debug, Clone, Encode, Decode)]
701pub struct CachedLocalTypeDeclaration {
702 /// Local declaration name.
703 pub name: String,
704 /// Byte offset of the declaration span start.
705 pub span_start: u32,
706 /// Byte offset of the declaration span end.
707 pub span_end: u32,
708}
709
710/// Cached public signature type reference.
711#[derive(Debug, Clone, Encode, Decode)]
712pub struct CachedPublicSignatureTypeReference {
713 /// Exported symbol whose signature contains the reference.
714 pub export_name: String,
715 /// Referenced type name.
716 pub type_name: String,
717 /// Byte offset of the reference span start.
718 pub span_start: u32,
719 /// Byte offset of the reference span end.
720 pub span_end: u32,
721}
722
723/// Cached suppression directive.
724#[derive(Debug, Clone, Encode, Decode)]
725pub struct CachedSuppression {
726 /// 1-based line this suppression applies to. 0 = file-wide.
727 pub line: u32,
728 /// 1-based line where the comment itself appears.
729 pub comment_line: u32,
730 /// 0 = suppress all, otherwise `IssueKind` discriminant.
731 pub kind: u8,
732 /// Rule-pack name for scoped policy suppressions. Empty for all other
733 /// suppression targets.
734 pub policy_pack: String,
735 /// Rule id for scoped policy suppressions. Empty for all other suppression
736 /// targets.
737 pub policy_rule_id: String,
738}
739
740/// Cached unknown suppression kind token (see #449).
741#[derive(Debug, Clone, Encode, Decode)]
742pub struct CachedUnknownSuppressionKind {
743 /// 1-based line where the comment itself appears.
744 pub comment_line: u32,
745 /// True when the marker was `fallow-ignore-file`.
746 pub is_file_level: bool,
747 /// The verbatim token that did not parse.
748 pub token: String,
749}
750
751/// Cached export data for a single export declaration.
752#[derive(Debug, Clone, Encode, Decode)]
753pub struct CachedExport {
754 /// Export name (or "default" for default exports).
755 pub name: String,
756 /// Whether this is a default export.
757 pub is_default: bool,
758 /// Whether this is a type-only export.
759 pub is_type_only: bool,
760 /// Whether this export is registered through a runtime side effect at
761 /// module load time (Lit `@customElement` decorator or
762 /// `customElements.define` call). Persisted so warm-cache runs continue
763 /// to skip unused-export reporting for these classes.
764 pub is_side_effect_used: bool,
765 /// Visibility tag discriminant (0=None, 1=Public, 2=Internal, 3=Beta, 4=Alpha).
766 pub visibility: u8,
767 /// The local binding name, if different.
768 pub local_name: Option<String>,
769 /// Byte offset of the export span start.
770 pub span_start: u32,
771 /// Byte offset of the export span end.
772 pub span_end: u32,
773 /// Members of this export (for enums and classes).
774 pub members: Vec<CachedMember>,
775 /// The local name of the parent class from `extends` clause, if any.
776 pub super_class: Option<String>,
777}
778
779/// Cached import data for a single import declaration.
780#[derive(Debug, Clone, Encode, Decode)]
781pub struct CachedImport {
782 /// The import specifier.
783 pub source: String,
784 /// For Named imports, the imported symbol name. Empty for other kinds.
785 pub imported_name: String,
786 /// The local binding name.
787 pub local_name: String,
788 /// Whether this is a type-only import.
789 pub is_type_only: bool,
790 /// Whether this import originated from an SFC `<style>` block / `<style src>` (CSS context).
791 pub from_style: bool,
792 /// Import kind: 0=Named, 1=Default, 2=Namespace, 3=SideEffect.
793 pub kind: u8,
794 /// Byte offset of the import span start.
795 pub span_start: u32,
796 /// Byte offset of the import span end.
797 pub span_end: u32,
798 /// Byte offset of the source string literal span start.
799 pub source_span_start: u32,
800 /// Byte offset of the source string literal span end.
801 pub source_span_end: u32,
802}
803
804/// Cached dynamic import data.
805#[derive(Debug, Clone, Encode, Decode)]
806pub struct CachedDynamicImport {
807 /// The import specifier.
808 pub source: String,
809 /// Byte offset of the span start.
810 pub span_start: u32,
811 /// Byte offset of the span end.
812 pub span_end: u32,
813 /// Names destructured from the import result.
814 pub destructured_names: Vec<String>,
815 /// Local variable name for namespace imports.
816 pub local_name: Option<String>,
817 /// True when this dynamic import was synthesised by fallow (see
818 /// `DynamicImportInfo::is_speculative`).
819 pub is_speculative: bool,
820}
821
822/// Cached `require()` call data.
823#[derive(Debug, Clone, Encode, Decode)]
824pub struct CachedRequireCall {
825 /// The require specifier.
826 pub source: String,
827 /// Byte offset of the span start.
828 pub span_start: u32,
829 /// Byte offset of the span end.
830 pub span_end: u32,
831 /// Byte offset of the specifier string-literal span start.
832 pub source_span_start: u32,
833 /// Byte offset of the specifier string-literal span end.
834 pub source_span_end: u32,
835 /// Names destructured from the require result.
836 pub destructured_names: Vec<String>,
837 /// Local variable name for namespace requires.
838 pub local_name: Option<String>,
839}
840
841/// Cached re-export data.
842#[derive(Debug, Clone, Encode, Decode)]
843pub struct CachedReExport {
844 /// The module being re-exported from.
845 pub source: String,
846 /// Name imported from the source.
847 pub imported_name: String,
848 /// Name exported from this module.
849 pub exported_name: String,
850 /// Whether this is a type-only re-export.
851 pub is_type_only: bool,
852 /// Byte offset of the re-export span start (for line-number reporting).
853 pub span_start: u32,
854 /// Byte offset of the re-export span end.
855 pub span_end: u32,
856}
857
858/// Cached enum or class member data.
859#[derive(Debug, Clone, Encode, Decode)]
860pub struct CachedMember {
861 /// Member name.
862 pub name: String,
863 /// Member kind (enum, method, or property).
864 pub kind: MemberKind,
865 /// Byte offset of the span start.
866 pub span_start: u32,
867 /// Byte offset of the span end.
868 pub span_end: u32,
869 /// Whether this member has decorators.
870 pub has_decorator: bool,
871 /// Full dotted path of each decorator (e.g. `step`, `ns.foo`).
872 /// Empty for undecorated members and decorators with non-identifier
873 /// expressions.
874 pub decorator_names: Vec<String>,
875 /// True when this is a static method that returns a fresh instance of
876 /// the class: body returns `new this()` / `new <SameClassName>()`, or the
877 /// declared return type matches the class name. Treated as a factory.
878 /// See issues #346, #387.
879 pub is_instance_returning_static: bool,
880 /// True when this instance method's call result is an instance of the
881 /// same class (declared return type matches the class name, or body's
882 /// last statement is `return this`). Drives fluent-chain credit. See
883 /// issue #387.
884 pub is_self_returning: bool,
885}
886
887/// Cached dynamic import pattern data (template literals, `import.meta.glob`).
888#[derive(Debug, Clone, Encode, Decode)]
889pub struct CachedDynamicImportPattern {
890 /// Static prefix of the import path.
891 pub prefix: String,
892 /// Static suffix, if any.
893 pub suffix: Option<String>,
894 /// Byte offset of the span start.
895 pub span_start: u32,
896 /// Byte offset of the span end.
897 pub span_end: u32,
898}