The running cost of declining derived_names is only visible by grepping files.parse_error #105
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#105
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Split out of #103, where the inert-on-deny proposal was rejected — fail-closed with a measured witness is the right behaviour, and the reasons are recorded there. But one part of that proposal's motivation survives the rejection and is worth taking.
What is true today
An operator who declines the grant gets a per-file refusal that is honest and precise:
files.parse_errorcarriespackage refused: fact.span_name_mismatch, and the witness is measured, not guessed —withheld_grant_witnessre-validates the same body with the grant and observes it pass, so the message only claims the grant is the cause when it demonstrably is.What is missing
There is no aggregate view. The blast radius is per-file (in the acceptance package: 1 of 5 fixtures, 1 of 2 corpus files —
greeter.rb.rbxindexes fully with no grant), which is the good news. But an operator running a real repo has no way to see "42 files in this project are at zero symbols because I said no" short of greppingfiles.parse_erroracross the database.Saying no is a legitimate choice the product supports. It should also be a choice whose bill is legible.
Shape of the fix
A count, in the surfaces that already answer "what is this index missing":
plugin status— per package, files refused withfact.span_name_mismatchcarrying the withheld-grant witness.index_health— the same count per project.Both must obey the three-state rule: absent = this build did not report it, zero = a measurement that no file was refused, non-empty = the bill. A zero that cannot distinguish "none refused" from "not counted" is worse than nothing here, because the whole point is to let an operator trust the number when deciding whether to revisit the answer.
Deliberately not in scope: a per-ref "dropped because ungranted" channel. That belongs to inert-on-deny, which #103 declined.
Related
Follow-up to #103.
plugin_addtool cannot grantderived_names, so an agent can never add a package that needs it #106Triage 2026-09-06: CLOSING, with one deviation flagged rather than glossed — the second surface is
project_overview, notindex_health.Verified against master.
The mechanism
WITHHELD_GRANT_REFUSAL_PREFIX—crates/daemon/src/local_index.rs:925;pub struct WithheldGrantCensus—:954;read_withheld_grant_refusals—:5176.plugin status, three arms —crates/cli/src/plugin.rs:3024-3075:NOT MEASURED/0 files — MEASURED/ the per-package bill. Exactly the three-state discipline asked for, with absent and zero distinct.render_withheld_grant_refusals—crates/mcp-server/src/server.rs:3886, withWITHHELD_GRANT_UNAVAILABLE(:3913) andWITHHELD_GRANT_SEMANTICS(:3918) so the reader is told how to read it. Wired intoproject_overviewasextraction_grant_refusalsatserver.rs:9487, and into the stats resource at:21838.The deviation, stated plainly
This issue asked for the census on
plugin statusandindex_health. It shipped onplugin statusandproject_overview(plus the stats resource). I searchedwithheld_grant_refusaltree-wide — 7 files, noindex_healthhit — and read theindex_healthcomposition path: it carries no census.I am treating that as intent met, letter not:
project_overviewis the per-project "what is this index missing" block whereparse_errorsalready lives, so the bill sits beside its natural sibling and an agent orienting on a project sees it on the first call it makes.index_healthis per-file. If the per-file placement was actually wanted, that is a small follow-up and should be a new issue rather than holding this one open — but it should be a deliberate decision, which is why I am not burying it.Runs (all exit 0)
Three of those names are the ones that matter:
the_derived_name_bill_counts_only_the_witnessed_refusals— it is a census over a witness, not a guess.a_clean_index_measures_zero_and_an_unaskable_one_reports_nothing— the zero/absent split, graded.an_older_daemon_reports_absence_and_not_a_zero— wire skew in the direction that matters. On this repo a0that is really "not reported" is the recurring defect, and this is the test that stops it.Residual
Only the surface substitution above.
🤖 Triage lane, 2026-09-06, master
45cf6e4