Overview
The current scanner treats each .sol file as an isolated unit. In real Solidity projects, contracts are deeply interconnected via inheritance (is), interface implementation, and library imports. Vulnerabilities that cross file boundaries — particularly in inherited functions and overridden modifiers — are entirely invisible to the current scanner.
Problem
// BaseVault.sol
contract BaseVault {
function _authorizeUpgrade(address) internal virtual {} // no protection
}
// UpgradeableVault.sol
import "./BaseVault.sol";
contract UpgradeableVault is BaseVault, UUPSUpgradeable {
// inherits unprotected _authorizeUpgrade — anyone can upgrade
}
Scanning UpgradeableVault.sol alone will not detect the vulnerability because the dangerous function body is in BaseVault.sol.
Proposed Solution
Phase 1: Import Graph Construction
- Parse
import statements from each file's AST to build a dependency graph
- Resolve relative and node_modules paths to absolute file paths
- Build a topological ordering of the import graph for processing order
Phase 2: Inheritance-Aware Analysis
- When analyzing a contract
C, collect all ancestor contracts via the inheritance chain
- Merge function definitions, modifiers, and state variable declarations from ancestors
- Apply rules against the merged contract view, not just the leaf contract
- Tag findings with the origin file (
definedIn: string) so reports point to the correct source location
Phase 3: Cross-File Dataflow
- Track state variables defined in parent contracts
- Track modifier definitions from parent contracts and apply them correctly when checking function guards in child contracts
New Fields on Finding
interface Finding {
// ... existing fields
definedIn?: string; // File where the vulnerable code is defined
inheritedBy?: string; // File of the contract that inherits the vulnerability
importPath?: string[]; // Resolved import chain
}
Acceptance Criteria
Overview
The current scanner treats each
.solfile as an isolated unit. In real Solidity projects, contracts are deeply interconnected via inheritance (is), interface implementation, and library imports. Vulnerabilities that cross file boundaries — particularly in inherited functions and overridden modifiers — are entirely invisible to the current scanner.Problem
Scanning
UpgradeableVault.solalone will not detect the vulnerability because the dangerous function body is inBaseVault.sol.Proposed Solution
Phase 1: Import Graph Construction
importstatements from each file's AST to build a dependency graphPhase 2: Inheritance-Aware Analysis
C, collect all ancestor contracts via the inheritance chaindefinedIn: string) so reports point to the correct source locationPhase 3: Cross-File Dataflow
New Fields on Finding
Acceptance Criteria
packages/core/src/ast/import-graph.tsdefinedInandinheritedByfields added toFindingtypeexamples/contracts/multi-file/