Skip to content

javascript: call-graph engine for the JavaScript front end (tracking) #456

Description

@swapnilpaliwal-sd

JavaScript front end — tracking

A call-graph engine for JavaScript over the parser's js_* IR, on the long-lived javascript-engine branch. Nothing merges to main until the engine is code-complete and evaluated on both a development and a held-out corpus; every mechanism lands on the branch through its own issue.

Shape of the engine

JavaScript declares no types, so the engine is a may-analysis over values rather than a type lookup: every expression, binding, parameter, property and return carries the set of values it may hold — a function, a class, an instance, a prototype, a module surface, an object literal, an array, or the platform — and a call site resolves through the callee's value. An untyped receiver produces nothing: the site is a declared unknown, never a name match.

Ground truth

checker.getResolvedSignature from a ts.Program built with allowJs + checkJs over the project's own files, per site, positions exact on both sides. Sites the compiler types as any (about half) enter no rate.

Layers

  • projections, containment, module graph (CommonJS + ESM, one export surface)
  • value flow: bindings, parameters, this, returns, properties, member writes
  • hierarchy: extends in all its spellings, nearest-declaration member lookup, constructor targets
  • JSDoc types: @param/@type/@returns, import() types, typedef aliases
  • arrays: element flow through literals, push, index writes, map, callbacks, for..of
  • ambient values: the platform reached through bindings and chains classifies the site
  • call chain: seven confidence classes, conservation over every raw site
  • regression suite with compiler-adjudicated goldens
  • development and held-out evaluation with per-site scoring
  • library staging (a dependency parsed from source as --library)

Status (draft PR #466)

Development: exact 0.988, recall 0.996, WRONG 0 over 9,867 sites. Held-out: exact 0.942, recall 0.984, precision 0.999 over 9,649 sites; the gap is width on one project, not misses. Every project solves in ≤ 9 s after #467.

Acceptance for merge to main

  • coverage guard: zero silently dropped sites on every corpus project
  • precision (WRONG rate) at or near zero on both corpora
  • held-out rates reported alongside development rates, with the gap stated

Activity

  1. swapnilpaliwal-sd commented on Sep 14, 2026

    @swapnilpaliwal-sd
    ContributorAuthor

    Edge-case sweep (2026-09-13), synthetic programs scored against both the compiler and execution oracles — nine probe projects covering value flow, classes, async/callbacks, CommonJS and ES module forms, JSDoc, heritage, precision traps and class fields. Two WRONG edges found (#479 superclass by last-segment name, #481 call through a getter); the rest are misses with a known mechanism:

    Module resolution (require of a directory, index.js, package.json#main, .js extension, JSON, circular requires, module.exports = require(), exports.a = exports.b =, conditional exports, spread of a required module) scored 47/50 EXACT with the three misses in the list above.

  2. swapnilpaliwal-sd commented on Sep 14, 2026

    @swapnilpaliwal-sd
    ContributorAuthor

    The engine is on main (21864ff, #472, task #577): 19/19 suite, development 0.985 exact / 0.998 recall / WRONG 0 over 9,867 compiler-decided sites, held-out 0.938 / 0.989 / 0.999 over 9,649, torture 0.982 and real-app 0.980 against execution. What is deliberately not resolved stays listed in #465; the CI gate (#418) and the engine build (#478) are being extended to cover JavaScript and land after the C# engine.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

engineResolution / call-graph engine rulesenhancementNew feature or requestjavascriptJavaScript

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions