Skip to content

Release 3.4.0: audit fixes - #6

Merged
yankikucuk merged 1 commit into
masterfrom
fix/audit-3-4-0
Sep 8, 2026
Merged

yankikucuk merged 1 commit into
masterfrom
fix/audit-3-4-0

Conversation

@yankikucuk

Copy link
Copy Markdown
Owner

A review pass over the extension. Each finding below was reproduced before it was fixed and is covered by a test.

Defects that produced wrong output

  • Add Type Annotations corrupted lines. VariableSymbol.column came from raw.indexOf(name), which finds the letter inside a keyword: var a = 1 reported column 1, so the command wrote vint ar a = 1, and varip r = 2 became vaint rip r = 2. Columns now come from the tokens. Go to Definition and Rename used the same column and were wrong by the same amount.
  • for counters were typed for. for i = 0 to 10 matched the variable pattern with for as the type, so x = i inside the loop was annotated for x = i. Counters are typed int now, for x in and for [index, element] in declare their names, and all of them are scoped to the loop block instead of the rest of the file.
  • Outline entries pointed at the wrong lines. Fields and enum members were assumed to sit on consecutive lines after the header, so one comment inside a type block shifted every field by one. They now carry the line they are written on.
  • Range formatting compared LF-joined text against a CRLF document, so it never detected "nothing changed".

Performance

The offline checks were quadratic: every symbol rescanned the whole token stream, and shadow detection scanned every function against every variable. One index per document version, built in sourceIndex(), makes both linear.

Document lint before lint after semantic tokens before after
271 lines 5.8 ms 0.51 ms 0.8 ms 0.64 ms
791 lines 33.4 ms 1.80 ms 3.5 ms 0.96 ms
1571 lines 160.3 ms 3.13 ms 12.7 ms 2.00 ms

Median of seven batches. The checks run 300 ms after every keystroke, so the old figure was felt while typing.

Completion was measured too and left alone: building the documentation for every bare built-in costs 0.09 ms, so deferring it would have been noise.

Also

  • Hovering a function parameter shows its declaration and //@param text; it previously showed nothing.
  • The Outline lists top-level declarations only, instead of mixing in variables declared inside blocks.
  • All 107 exported declarations that had no comment now have one.
  • CONTRIBUTING.md covers the modules added in 3.2.0 and 3.3.0 and says where identifier-walking code belongs.

Test plan

  • npm test (329 tests, 7 of them new regression tests)
  • npm run build and vsce package
  • Offline checks over the 98 snippet and fixture sources: zero false errors
  • A v4 script converted and formatted still compiles on the TradingView compiler
  • Corrected output (var int a = 1, for [idx, el] in, an annotated loop body) verified against the compiler

@yankikucuk
yankikucuk merged commit 4b4f372 into master Sep 8, 2026
1 check passed
@yankikucuk
yankikucuk deleted the fix/audit-3-4-0 branch September 8, 2026 16:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant