disclosure_surface_registry grades by SURFACE, not by FIELD, so a field that is correct on one surface and collapsed on another is structurally invisible to it #152
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#152
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found by a disclosure-field trace. The registry is not vacuous — its axis is wrong, which is a failure this project already has a name for ("audits checking the wrong axis").
The live defect it cannot see (A1)
render_offersexists specifically soactivation_availableis never rendered as "nothing to activate" (#86 A2). It has exactly one caller:crates/mcp-server/src/server.rs:8481, theproject_overviewtool.stats_resource(server.rs:19632) re-renders onlyplugin_activationthroughrender_activationand passes everything else through raw.Stats::activation_availablecarries#[serde(default, skip_serializing_if = "Option::is_none")](crates/daemon/src/local_index.rs:1157).So
code-index://statsdrops the field precisely when the store could not be consulted — the exact collapse the whole doctrine exists to prevent, on a shipped surface.project_overview_resourcenever carries it at all.Verified in the tree, not inferred.
Siblings found in the same trace
package_duplicate_idsandpackage_set_consultedship twice in one payload oncode-index://stats: raw at top level and inside the three-state block. The top-level copy hands the reader exactly the collapse the nested one prevents.PathClaim::claimed_by(crates/daemon/src/local_index.rs:1312) is produced atcrates/daemon/src/eligibility.rs:375. Its doc says it "is the field that makes the reply project-scoped rather than a restatement of what the client could have computed alone."Eligibility::from_claims(crates/mcp-server/src/eligibility.rs:262-289) readsc.kind,c.reason,c.path— neverc.claimed_by. The only other read in the tree is a test assertion. 24 B per path on every eligibility batch (changed_symbols,review_diff,index_coverage), zero readers.index_coverage'sclaimed_by: "none"is annotated in its own source (server.rs:11924) as "UNREACHABLE ON EVERY INDEX IN THE WILD" and no test pins it.active_generation_staleis graded only over a stubbed block.plugin_state_unavailableandavailability: "unavailable"are the same bit in the same object at project level.The generic fix
Give the registry a per-field axis: for each disclosure field, enumerate every surface that can carry it, and require the same three-state rendering on all of them. That catches A1 and A2 by construction and every future instance, rather than a fix per field — which is this project's own stated rule.
Fix A1 and A2 by routing both resources through
render_offersand stripping the rawStatsduplicates. Fix A3 by reading the field or deleting it.No opposite-direction shim
Related and worth its own thought: the doctrine is built entirely on "an absent or zero answer must never read as a measured negative" and has no shim for the reverse — a retired reason code arriving from a peer reporting the same version string.
coverage::RETIREDis referenced only by its own unit tests. The trace hit this on its first live call: the installed build returnedcoverage_reasons: ["rules_coverage_absent"]beside acoverage_semanticsstring still defining it — a code the current tree has retired.Trim candidates found in the same pass
The activation family costs 2,932 B on every
project_overview, 75% of it two constant prose strings (activation::SEMANTICS1,177 B +coverage::SEMANTICS1,013 B). Per-rowinfluencecosts 1,850 B/page of an invariant value, retained even inconcise— a page-levelinfluence_scopewould replace it.states_not_derivedis ~630 B per overview describing four states the producer cannot reach. See #111/#120.🤖 Generated with Claude Code
https://claude.ai/code/session_01K1zj5VcFJvJt3pQxe9259K