test: DAEMON_READERS is a hand-list with a summed floor, so an unregistered daemon reader is invisible to the generation-gate scan #129
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#129
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Split out of #78. Gate hardening, not a live bug — verified 2026-09-04 that no escapee exists today.
The registry and its own doc
crates/indexer/tests/generation_build.rs:1354-1366:The doc argues the hand-list is better than a glob. It is the opposite: a glob is what makes an unregistered reader visible; the hand-list is what makes it invisible. The comment states the exact risk and then chooses it.
The gate
every_daemon_row_read_is_generation_gated,generation_build.rs:1906-1952. It loopsfor rel in DAEMON_READERS, accumulatessites += n, then:83 is the census in the comment above it (47 in
local_index.rs, 19 ingraph.rs, 16 inrefactor.rs, 1 inhandle.rs); 70 is a deliberately slack floor.Why that hides a new reader
The floor is a
>=on a sum over the four registered files only. A newcrates/daemon/src/whatever.rswith an ungatedFROM symbolsis never opened by the scan, so it contributes 0 ungated and 0 sites; the sum stays ~83 and the assertion passes. Nothing in the workspace enumeratescrates/daemon/srcand cross-checks it againstDAEMON_READERS.The sum also hides per-file collapse:
handle.rscontributes 1 site, so it could stop being scanned entirely (renamed, split) and the sum would still clear 70.Checked for a live escapee — there is none. Every daemon source containing
FROM/JOINonsymbols|refs|importsis one of the four (local_index.rs59 raw,graph.rs19,refactor.rs17,handle.rs3; raw counts include test halves).The backstop is off the shelf — this repo has the pattern twice
crates/mcp-server/tests/bounding_site_registry.rsdiscovers crate dirs byread_dirand walks every*.rs, withthe_walk_reaches_every_crate_and_the_files_that_hid_capsas the discovery anchor (including a "the walk did not reach{anchor}" assertion).crates/mcp-server/tests/reason_code_registry.rs'sproduction_sources()does the same walk overcrates/*/src, with anti-vacuity floors on how many sources were scanned.RPC_METHODS/rpc_coverage_e2e.rs, which asserts set equality between what is exercised and what production declares, rather than a floor.So:
read_dirovercrates/daemon/src, collect every file whose production half matches the same six needlesscan_daemon_readsuses, and assert that set equalsDAEMON_READERS∪ a registered-exception list. That turns "a new reader" from invisible into a red test naming the file. A per-file floor beside the sum would close the collapse half.Triage 2026-09-06 at
f6a878a: CLOSING. The hand-list is now aread_dirset equality with a per-file floor, and the four isolating mutations were run.Verified against master and by re-running the test myself, not from a lane report.
What landed
the_daemon_reader_registry_names_every_daemon_source_that_reads_a_row—crates/indexer/tests/generation_build.rs:3089. It walkscrates/daemon/srcand asserts set equality againstDAEMON_READERS∪DAEMON_READER_EXCEPTIONS, so a new daemon source that reads a row is a build failure rather than an invisible omission.DAEMON_READER_EXCEPTIONS—generation_build.rs:3032, and it is currently empty. That matters: the gate went green on its first run with nothing waived, which is the outcome that distinguishes "the list was already right" from "the list was made right by exempting the awkward files".PER_FILE_FLOOR—generation_build.rs:3093. This is the half the issue actually turned on: a summed floor lets one file's many hits cover another file's zero. A per-file floor cannot.scanned >= 15atgeneration_build.rs:3126, so a brokenread_dirfails loudly instead of passing over an empty scan. (This repo has been bitten by exactly that: a gate whose population collapsed to nothing and stayed green.)../daemon/src/ref_aggregate.rs,generation_build.rs:1498-1512.generation_build.rs:3059-3086, each with its isolating pair — RED under the new gate, GREEN under the old summed one. That pairing is what proves the new gate is the thing catching them, and it is exactly the evidence this issue asked for.The run
(run together with #128's storage test; both green)
Residual
None. The exception list is empty, so there is no waiver to keep true, and the floor is per-file rather than summed, which is the whole complaint.
🤖 Triage lane, 2026-09-06, master
f6a878a