79 import cycles across 27 modules, held open by deferred imports #248
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#248
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Run on 2026-09-16 with the CodeQL CLI 2.27.0 (the toolchain the VS Code extension ships), pack
codeql/python-queries@1.8.10, suitepython-security-and-quality, overmainat23c742c7f. 131 results, 354 source files.py/cyclic-importaccounts for 79 of the 131 results, spread over 27 modules. Every oneof them is a real cycle in the module graph, and every one is held open by an import that
was moved inside a function to stop it closing at import time.
The worst of it:
notifications/transport.pycore/mail_auth.pycore/phone_numbers.pyplugins/policy.pyplugins/registry.pyresume/translating.pycore/mail.pydocuments/rendering.pycore/channels.py,resume/forms.py,plugins/models.py,core/models.pynotifications/transport.pyalone defers ten imports:postulo.plugins.registry,postulo.core.site(four separate times, in four functions),postulo.accounts.recovery,postulo.core.phone_numbers,postulo.core.models,postulo.accounts.modelsandpostulo.plugins.installing.This is not a bug and nothing is broken today. It is filed because the deferred import is
load-bearing: it is the only thing keeping the cycle from being an
ImportError, it isinvisible at the top of the file where a reader looks for dependencies, and moving any one
of them back to module scope breaks startup in a way that no test names.
core/channels.pyand
notifications/transport.pyimport each other; so doplugins/base.pyandplugins/installing.py, andplugins/fetching.pyandplugins/base.py.Worth deciding, rather than fixing file by file:
core/siteshould be a leaf that nothing incoreimports back, since six of thedeferrals point at it;
pluginspackage needs a layer belowbase.pyfor the thingsbase,installingandfetchingall want;notifications/transport.pyis doing too much, given it reaches intoplugins,accountsandcore.A
TYPE_CHECKINGguard covers the deferrals that exist only for annotations; the rest aregenuine runtime dependencies and need the graph changed, not the import moved.
Full SARIF is reproducible with: