Skip to content

Lang support - #99

Merged
sshaaf merged 6 commits into
mainfrom
lang-support
Sep 30, 2026
Merged

sshaaf merged 6 commits into
mainfrom
lang-support

Conversation

@sshaaf

@sshaaf sshaaf commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Add support for puppet
Groovy
Kotlin
Config and build files
reshape docs.

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
…to avoid symbol-index collisions)

  • Fixture call profile::helpers::ok() so Calls resolve (no global Calls stubbing)
  • Puppet naming in ast_skeleton so cpg ast matches CFG hosts

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
…, span-faithful config keys, Java/C# → config links,

  and Kantra providers that use those nodes — without dual-emitting config soup or blowing Gate A.

  Ingest routing

  • IngestRoute: Manifest | Config | Workflow | Ignore
  • Basename rules: pom.xml, Cargo.toml, package.json, go.mod, build.gradle(.kts) → Manifest only
  • Lockfiles and non-allowlisted XML → Ignore

  Manifests → Dependency + DependsOn

  • Maven, Cargo, npm, Go, Gradle (best-effort)
  • Declared deps only (no lockfile / transitive resolution)

  Config → ConfigKey with real spans

  • Properties, YAML (marked-yaml), TOML (toml_edit), JSON, allowlisted XML
  • Line/col fidelity; no line-0 keys

  Code → config

  • Java: @value, @ConfigProperty, env/getProperty literals → UsesConfig
  • C#: Configuration[...] / GetValue / GetSection
  • No stub ConfigKeys for missing keys

  Kantra

  • java.dependency / go.dependency against Dependency nodes
  • builtin.xml / builtin.json via on-demand reparse (no DOM in .rgctl/)

  Docs / gates

  • Honesty notes in docs/build-and-config-honesty.md
  • Gate A: linux cold 146.9s (pass); ecommerce-java: Dependency/ConfigKey/UsesConfig deltas recorded
  • Optional CLI dependencies/config list deferred — use GQL

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
  New language crates (rgctl-lang-kotlin, rgctl-lang-groovy) with tree-sitter plugins (kotlin-ng 1.1.0, groovy 0.1.2), AST
  coverage manifests, workspace/languages.toml registration, and Manifest-first routing so build.gradle / build.gradle.kts
  stay Dependency-only.

  Analysis (Layers B/C/F): CFG profiles (when for Kotlin), def-use (Kotlin navigation_expression field writes), taint
  patterns, field-write locals + golden tests, constructor CFG naming for Kotlin.

  Fixtures & gates: langfeatures/CFG/taint tests; ecommerce-kotlin / ecommerce-groovy; dashboard + GQL verify scripts; Gate
  B fetch (example/kotlin sparse JetBrains/kotlin, example/groovy = gradle) with baselines 10s / 5s.

  Docs: honesty guides, language pages, parity/profile/AGENTS/example README updates.

  Measured (this machine): default cold K/G ~9s / ~4s; --full ~91s / ~14s; Linux Gate A 141s (pass).

Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
Signed-off-by: Shaaf Syed <474256+sshaaf@users.noreply.github.com>
@sshaaf
sshaaf merged commit 886fa0e into main Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant