Rust: Make crate fallback logic more conservative in path resolution library - #22495
Open
hvitved wants to merge 2 commits into
Open
Rust: Make crate fallback logic more conservative in path resolution library#22495hvitved wants to merge 2 commits into
hvitved wants to merge 2 commits into
Conversation
hvitved
force-pushed
the
rust/path-resolution-crate-fallback-uniqueness
branch
from
September 3, 2026 07:06
e35d861 to
1925c20
Compare
hvitved
marked this pull request as ready for review
September 3, 2026 10:49
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Raw string ordering can select the wrong semantic version, and the uniqueness behavior lacks regression coverage.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review tier: Balanced
Findings: 1
New issues introduced by this change (2)
| Severity | Finding |
|---|---|
rust/ql/lib/codeql/rust/internal/PathResolution.qll — ver is a raw Cargo version string, so this ordering is lexicographic rather than semantic: for… |
|
rust/ql/lib/codeql/rust/internal/PathResolution.qll — The existing path-resolution fixture does not contain multiple extracted crate entities sharing the… |
What changed in this PR
Restricts Rust crate dependency fallback to a uniquely identified latest crate version, reducing path-resolution explosions.
Changes:
- Selects the latest crate version for fallback resolution.
- Adds debugging support for crate dependency edges.
| File | Description |
|---|---|
rust/ql/lib/codeql/rust/internal/PathResolution.qll |
Narrows crate fallback resolution and adds debugging support. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
hvitved
force-pushed
the
rust/path-resolution-crate-fallback-uniqueness
branch
from
September 3, 2026 11:08
d432cd5 to
52e2c72
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


When doing a QA run for #21795, I noticed that our fallback logic for crate dependencies can sometimes lead to combinatorial explosions. This PR alleviates this by only applying the fallback logic to crates that have a unique latest version. DCA confirms that this PR resolves the performance issue, most notably on the
reflaxe-rustproject, where thehxrtcrate exists in many test copies (e.g. https://github.com/fullofcaffeine/reflaxe.rust/blob/main/test/snapshot/abstracts_conversions/intended/hxrt/Cargo.toml).