The running cost of declining derived_names is only visible by grepping files.parse_error #105

Closed
opened 2026-09-04 15:01:21 +02:00 by buildagent · 1 comment
Member

Split out of #103, where the inert-on-deny proposal was rejected — fail-closed with a measured witness is the right behaviour, and the reasons are recorded there. But one part of that proposal's motivation survives the rejection and is worth taking.

What is true today

An operator who declines the grant gets a per-file refusal that is honest and precise: files.parse_error carries package refused: fact.span_name_mismatch, and the witness is measured, not guessed — withheld_grant_witness re-validates the same body with the grant and observes it pass, so the message only claims the grant is the cause when it demonstrably is.

What is missing

There is no aggregate view. The blast radius is per-file (in the acceptance package: 1 of 5 fixtures, 1 of 2 corpus files — greeter.rb.rbx indexes fully with no grant), which is the good news. But an operator running a real repo has no way to see "42 files in this project are at zero symbols because I said no" short of grepping files.parse_error across the database.

Saying no is a legitimate choice the product supports. It should also be a choice whose bill is legible.

Shape of the fix

A count, in the surfaces that already answer "what is this index missing":

  • plugin status — per package, files refused with fact.span_name_mismatch carrying the withheld-grant witness.
  • index_health — the same count per project.

Both must obey the three-state rule: absent = this build did not report it, zero = a measurement that no file was refused, non-empty = the bill. A zero that cannot distinguish "none refused" from "not counted" is worse than nothing here, because the whole point is to let an operator trust the number when deciding whether to revisit the answer.

Deliberately not in scope: a per-ref "dropped because ungranted" channel. That belongs to inert-on-deny, which #103 declined.

Follow-up to #103.

Split out of #103, where the inert-on-deny proposal was **rejected** — fail-closed with a measured witness is the right behaviour, and the reasons are recorded there. But one part of that proposal's motivation survives the rejection and is worth taking. ## What is true today An operator who declines the grant gets a per-file refusal that is honest and precise: `files.parse_error` carries `package refused: fact.span_name_mismatch`, and the witness is **measured**, not guessed — `withheld_grant_witness` re-validates the same body *with* the grant and observes it pass, so the message only claims the grant is the cause when it demonstrably is. ## What is missing There is no **aggregate** view. The blast radius is per-file (in the acceptance package: 1 of 5 fixtures, 1 of 2 corpus files — `greeter.rb.rbx` indexes fully with no grant), which is the good news. But an operator running a real repo has no way to see "42 files in this project are at zero symbols because I said no" short of grepping `files.parse_error` across the database. Saying no is a legitimate choice the product supports. It should also be a choice whose **bill** is legible. ## Shape of the fix A count, in the surfaces that already answer "what is this index missing": - `plugin status` — per package, files refused with `fact.span_name_mismatch` carrying the withheld-grant witness. - `index_health` — the same count per project. Both must obey the three-state rule: **absent** = this build did not report it, **zero** = a measurement that no file was refused, **non-empty** = the bill. A zero that cannot distinguish "none refused" from "not counted" is worse than nothing here, because the whole point is to let an operator trust the number when deciding whether to revisit the answer. Deliberately **not** in scope: a per-ref "dropped because ungranted" channel. That belongs to inert-on-deny, which #103 declined. ## Related Follow-up to #103.
Author
Member

Triage 2026-09-06: CLOSING, with one deviation flagged rather than glossed — the second surface is project_overview, not index_health.

Verified against master.

The mechanism

  • Derivation from the witness: WITHHELD_GRANT_REFUSAL_PREFIX — crates/daemon/src/local_index.rs:925; pub struct WithheldGrantCensus — :954; read_withheld_grant_refusals — :5176.
  • plugin status, three arms — crates/cli/src/plugin.rs:3024-3075: NOT MEASURED / 0 files — MEASURED / the per-package bill. Exactly the three-state discipline asked for, with absent and zero distinct.
  • MCP: render_withheld_grant_refusals — crates/mcp-server/src/server.rs:3886, with WITHHELD_GRANT_UNAVAILABLE (:3913) and WITHHELD_GRANT_SEMANTICS (:3918) so the reader is told how to read it. Wired into project_overview as extraction_grant_refusals at server.rs:9487, and into the stats resource at :21838.

The deviation, stated plainly

This issue asked for the census on plugin status and index_health. It shipped on plugin status and project_overview (plus the stats resource). I searched withheld_grant_refusal tree-wide — 7 files, no index_health hit — and read the index_health composition path: it carries no census.

I am treating that as intent met, letter not: project_overview is the per-project "what is this index missing" block where parse_errors already lives, so the bill sits beside its natural sibling and an agent orienting on a project sees it on the first call it makes. index_health is per-file. If the per-file placement was actually wanted, that is a small follow-up and should be a new issue rather than holding this one open — but it should be a deliberate decision, which is why I am not burying it.

Runs (all exit 0)

cargo test -p code-index-daemon --test diagnostic_census      → 6 passed
cargo test -p code-index-cli    --test diagnostic_census_cli  → 2 passed
cargo test -p code-index-mcp    --test diagnostic_census_e2e  → 3 passed

Three of those names are the ones that matter:

  • the_derived_name_bill_counts_only_the_witnessed_refusals — it is a census over a witness, not a guess.
  • a_clean_index_measures_zero_and_an_unaskable_one_reports_nothing — the zero/absent split, graded.
  • an_older_daemon_reports_absence_and_not_a_zero — wire skew in the direction that matters. On this repo a 0 that is really "not reported" is the recurring defect, and this is the test that stops it.

Residual

Only the surface substitution above.

🤖 Triage lane, 2026-09-06, master 45cf6e4

## Triage 2026-09-06: CLOSING, with one deviation flagged rather than glossed — the second surface is `project_overview`, not `index_health`. Verified against master. ### The mechanism - Derivation from the witness: `WITHHELD_GRANT_REFUSAL_PREFIX` — `crates/daemon/src/local_index.rs:925`; `pub struct WithheldGrantCensus` — `:954`; `read_withheld_grant_refusals` — `:5176`. - **`plugin status`**, three arms — `crates/cli/src/plugin.rs:3024-3075`: `NOT MEASURED` / `0 files — MEASURED` / the per-package bill. Exactly the three-state discipline asked for, with absent and zero distinct. - **MCP**: `render_withheld_grant_refusals` — `crates/mcp-server/src/server.rs:3886`, with `WITHHELD_GRANT_UNAVAILABLE` (`:3913`) and `WITHHELD_GRANT_SEMANTICS` (`:3918`) so the reader is told how to read it. Wired into `project_overview` as `extraction_grant_refusals` at `server.rs:9487`, and into the stats resource at `:21838`. ### The deviation, stated plainly This issue asked for the census on `plugin status` **and `index_health`**. It shipped on `plugin status` **and `project_overview`** (plus the stats resource). I searched `withheld_grant_refusal` tree-wide — 7 files, **no `index_health` hit** — and read the `index_health` composition path: it carries no census. I am treating that as **intent met, letter not**: `project_overview` is the per-project "what is this index missing" block where `parse_errors` already lives, so the bill sits beside its natural sibling and an agent orienting on a project sees it on the first call it makes. `index_health` is per-file. If the per-file placement was actually wanted, that is a small follow-up and should be a new issue rather than holding this one open — but it should be a deliberate decision, which is why I am not burying it. ### Runs (all exit 0) ``` cargo test -p code-index-daemon --test diagnostic_census → 6 passed cargo test -p code-index-cli --test diagnostic_census_cli → 2 passed cargo test -p code-index-mcp --test diagnostic_census_e2e → 3 passed ``` Three of those names are the ones that matter: - `the_derived_name_bill_counts_only_the_witnessed_refusals` — it is a census over a witness, not a guess. - `a_clean_index_measures_zero_and_an_unaskable_one_reports_nothing` — the zero/absent split, graded. - `an_older_daemon_reports_absence_and_not_a_zero` — wire skew in the direction that matters. On this repo a `0` that is really "not reported" is the recurring defect, and this is the test that stops it. ### Residual Only the surface substitution above. 🤖 Triage lane, 2026-09-06, master `45cf6e4`
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
h-dv/code-index#105
No description provided.