lockfile_forge_registry is blind TODAY: a doc comment in the one file its anti-vacuity floor names exempts that whole file, so its declared mutation is false as written #180
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#180
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found during the #178 audit and measured, not argued: the mutation below was applied to the tree, the gate was run, and it stayed green. This is the first confirmed instance of #178's class that is failing right now rather than merely capable of failing.
Measured
Mutation applied to
crates/mcp-server/src/main.rs, inside its#[cfg(test)]module — the literal defect this gate exists to catch, a daemon payload forged by interpolating the project root into a hand-written TOML basic string:GREEN. The forge is in the tree, in the file the gate's own floor singles out, and nothing says so.
Control run, same forge, with only the doc-comment token neutered:
So the doc comment is provably the sole cause of the blindness. This is not a reading of the code; it is a two-run experiment with the variable isolated.
Mechanism
crates/daemon/tests/lockfile_forge_registry.rs, insideno_test_forges_a_daemon_payload_by_hand:interpolated_basicis per line.hand_escapedis per file — and it is loop-invariant, which is the tell: it is recomputed on every iteration and depends on nothing the loop varies. One occurrence of that token anywhere in a file blanket-clears every line of that file.The per-line comment skip above it is what makes this counter-intuitive. The gate does strip comments, correctly, from the offender half. It does not strip them from the exemption half, so a comment cannot be flagged but a comment can grant an exemption to everything around it.
And the token that grants it is not exotic.
.replace('\\', "\\\\")is the ordinary path-normalisation idiom in this workspace: 40 files undercrates/carry it and are each wholly exempt.The file it is exempt in is the file the gate names
crates/mcp-server/src/main.rs:1235, inside a///doc comment — the paragraph that explains the original defect:And
lockfile_forge_registry.rs:126-130:The gate asserts that its scan reaches
main.rs, because that is where the motivating defect lived. The scan does reach it. The predicate then exempts all of it. The anti-vacuity floor is passing while certifying membership in a population where nothing can ever be flagged — which is worse than no floor, because it is evidence pointing the wrong way.Note also the deliberate skip immediately above the loop:
The author had already noticed that documentation quoting a pattern defeats a text scan, and handled it for one file by name. The same hazard in the exemption half, one screen down, went unnoticed — a hand-scoped fix where a structural one was needed.
Why the declared mutation does not catch it
lockfile_forge_registry.rs:70-73:"any scanned source" is false today. It holds for the ~140 files without the token and fails for the 40 with it. Whoever ran it picked a file from the majority — an entirely reasonable thing to do, and exactly why this survived.
That is the general shape from #178: the mutation was RUN, it was RED, and it graded the subject (production code) rather than the predicate. A mutation set that never perturbs the predicate cannot discover that the predicate is vacuous.
Suggested fix, and the property it has to have
Scope
hand_escapedthe wayinterpolated_basicis scoped, and strip comments from it:body;Then pair it with a detector test on synthetic input, in the shape this tree already has seven times over (
the_scan_itself_can_fail,the_detector_can_fail): a must-catch corpus holding the offending line next to an unrelated.replace('\\', …)in a comment, and a must-not-catch corpus holding a genuinely escaped forge. Without that arm, the next refactor of the predicate is ungraded again.kind_table_guard(crates/plugin-host/tests/) is the model for why the lexical fix alone is never the whole answer: it countsmodule.imports()on the compiled module and says so — "a text scan for(importwould pass on a module whose import arrived some other way."What must NOT be done
main.rsdoc comment to make the gate work. That paragraph is the record of how the defect propagated, and it is correct. A gate that requires the documentation to stop describing the bug is a worse gate, and this repo has already made the opposite trade deliberately (#178: "do not ban local wrappers").main.rsspecifically, because that is the file with both the token and the history.The portable result, which is the reason this is worth reading past the one bug
Twenty-two registry/population gates were read; eleven were rated vulnerable; five predicate mutations were run; five confirmed, zero refuted. Out of that, one finding generalises further than any individual gate:
That single question — does any declared mutation perturb the predicate itself? — separated the two populations more reliably than reading the code did, and it is cheap enough to ask in review of every new gate.
It was confirmed against a gate written in the same lane, which is the part that convinced me. #169 added
ci_cadence::no_grading_step_is_masked_by_an_earlier_one, a scan over the real workflows. Weakening its predicate so that an unrelatedif: github.event_name == 'push'reads as a run-anyway guard left that scan GREEN — a compliant tree never exercises a weakened predicate — and only the syntheticthe_masking_detector_can_failwent red. A scan over real inputs is structurally incapable of discovering that its own predicate has gone vacuous. The paired synthetic detector is therefore not redundant with the scan; it is the only thing grading the predicate.Two supporting patterns, both cheap to act on:
bless_registryadded — a corpus holding the non-compliant shape that was measured green — appears in only three files (bless_registry,reason_code_registry,generation_policy_registry).generation_policy_registry/reason_code_registrystrip;pool_capability_registry/disclosure_surface_registry/disclosure_derivation_registry/resource_grading_registrydo not.pool_capability_registry's own fix is already written in the adjacent file in the same directory (strip_line_comments(&strip_cfg_test(&src))).The audit is a FLOOR, not a census
Eleven gates were rated vulnerable; five were mutated. Six were rated vulnerable and never mutated, so their status is unknown, not safe — the exact distinction this project insists on everywhere else. The next lane should start from this list rather than re-deriving it. Each is given with the concrete predicate mutation to run:
indexer/tests/production_caller_gate.rsconst _WHY: &str = "cmd_enable calls build::build( here";to a file the module closure reaches — a string literal, whichstrip_line_commentsdoes not touch. (Or a nestedmod _notes { pub mod build { pub fn build() {} } }.)daemon/tests/argument_registry_e2e.rsShapeProbe's named test body, leave/// Superseded. See the notes on fn wire_vintage_probe( in the design record.ShapeProberows are skipped by the behavioural sweep, sosrc.contains(&format!("fn {func}("))is all that stands behind them. This file declares noMUTATION (RUN)block anywhere.mcp-server/tests/ref_kind_stance_registry.rsNOTatdaemon/src/graph.rs:1237. Polarity, not spelling:code.contains("'binding'")cannot tellIN (...)fromNOT IN (...), so the population inverts to exactly the kinds the row declares excluded while every assertion passes. Six sibling sites take the same one-token edit.mcp-server/tests/disclosure_surface_registry.rsproducer: "lang"— a 4-character bare substring matchinglanguage,lang_id,by_lang, or any comment — delete the real disclosure and leave// no language disclosure here.mcp-server/tests/disclosure_derivation_registry.rsrender_link_package_set(one of ~8 renderers), replace the absence branch with// absence used to mint ACTIVATION_UNAVAILABLE here+return Value::Null;. Membership itself is decided byregion.contains("ACTIVATION_UNAVAILABLE")over an un-stripped corpus. The equivalent edit inrender_count_basisis caught by an e2e; this one is not.abi/tests/doc_citation_gate.rs.rsthat is not the gate file:/* fn the_shipped_host_cannot_compile_wasm */. The comment filter is//-only, so a block comment enters bothwrittenanditemsand the gate's own motivating phantom resolves as a declared item. The string-literal hole is disclosed and priced; this one is not mentioned anywhere.Already confirmed by measurement and needing fixes rather than further investigation: this issue's
lockfile_forge_registry, pluspool_capability_registry,resource_grading_registry(the only invariant in the set that no runtime arm can ever back up — a faithful copy-paste shipped the whole file green),exec_copy_registry(a local shadowfn install_executabledoing a barefs::copy, call-site text unchanged), andshipped_binary_registry(code-indexis a proper prefix ofcode-index-daemon, so dropping the primary CLI from all 12INSTALL=lines inrelease.ymlis green).Rated vulnerable but honestly disclosed and braced, so lower priority:
bounding_site_registry,inline_cargo_build_registry,refusal_stage_registry,resolution_percentage_stance— each already declares and runs at least one predicate mutation, which is the profile above, working.Related
#178 (the class, and the audit this came out of), #169 (where the general result was confirmed against a fresh gate), and
bless_registry(the fixed exemplar — note its own declared mutation went stale when its predicate was fixed, which is a third instance of records drifting from mechanisms).🤖 Generated with Claude Code
https://claude.ai/code/session_01K1zj5VcFJvJt3pQxe9259K
The six unmutated gates are now mutated: 6 confirmed, 0 refuted, all six fixed
Second lane on #180, working from
origin/master(a9ba058) in a detached worktree. Every row below is two runs with one variable: the non-compliance held constant, the text token added, RED → GREEN. Exit codes are$?captured directly, never through a pipe.The "floor, not census" list is now empty.
indexer/tests/production_caller_gate.rspromotion::rollback(cli/src/activation.rs:1041), then add one file-scopeconst _WHY: &str = "… promotion::rollback( …";strip_non_code(comments + strings + char literals) +the_scan_reads_code_and_not_textabi/tests/doc_citation_gate.rs/* fn the_shipped_host_cannot_compile_wasm */at file scope ofindexer/src/promotion.rs— a DIFFERENT cratestrip_block_commentsinuniverse+the_universe_reads_code_and_not_block_commentsdaemon/tests/argument_registry_e2e.rsShapeProbecover test away inrpc_e2e.rs, leave a//comment namingfn old_clients_…(declares_test_fn(comment/string-stripped declaration + a#[…test…]attribute) +the_cover_test_scan_reads_declarations_and_not_prosemcp-server/tests/disclosure_surface_registry.rsrow_to_symbol's body into a helper, then add// no language disclosure hereproduces= whole identifier in code or a string literal that IS the token +the_producer_check_reads_code_and_not_prosemcp-server/tests/disclosure_derivation_registry.rsrender_link_package_set's absence arm withreturn Value::Null;, then add// absence used to mint ACTIVATION_UNAVAILABLE heremints_absence_marker(whole word, code only) +the_renderer_definition_reads_code_and_not_commentsmcp-server/tests/ref_kind_stance_registry.rsNOTatdaemon/src/graph.rs:1237(change_impact)kind_polarityreads the OPERATOR and is graded against the row's existingImport/Accessstance, bya_kind_filters_polarity_matches_the_declared_stance+the_polarity_parse_reads_the_operatorThe RED output, per gate
production_caller_gate— control (caller deleted, no string), exit 101:Add one string literal at file scope of the same file:
test result: ok. 5 passed, exit 0. After the fix, the same tree is RED again.doc_citation_gate— control (the gate's own declared MUTATION (RUN)), exit 101:Add
/* fn the_shipped_host_cannot_compile_wasm */tocrates/indexer/src/promotion.rs:9 passed, exit 0. A block comment reaches BOTH tiers —writtenand, via thefn NAMEwindow,items— so a comment mints a declared item, which is a stronger lie than the disclosed-and-priced string-literal tier.argument_registry_e2e— control, exit 101:Add three
//lines naming it:1 passed, exit 0.disclosure_surface_registry— control, exit 101, FIVE rows at once:Add
// no language disclosure here:10 passed, exit 0. Note the mechanism: the comment matches becauselanguagecontainslang.disclosure_derivation_registry— control, exit 101, on TWO gates:Add
// absence used to mint ACTIVATION_UNAVAILABLE here:10 passed, exit 0.ref_kind_stance_registry— control that the gate is otherwise live (NOT IN ('binding','import')→NOT IN ('import')), exit 101:Then the one-token edit — put the kind back, delete
NOT—12 passed, exit 0. The population inverted to exactly the two kinds the row declares excluded:change_impact.resolution_rate_pct, the numberreview_difftests against 30.0 to raiselow_confidence_area, would be computed from binding and import refs alone, andimport: Excludedbecame a lie with every assertion passing.One severity correction to #180, measured
#180 says of the
render_link_package_setedit: "The equivalent edit inrender_count_basisis caught by an e2e; this one is not." Refuted at the tree level.server::routing_tests::two_links_with_different_package_sets_render_differentlydrivesrender_link_package_set(None)and asserts the marker; under the mutation it goes RED (cargo test -p code-index-mcp --bins, exit 101). The gate is confirmed blind — which is what matters, because the gate is what derives the surface set — but the tree was not. Recorded in the fix's own doc.The declared-mutation-profile screen: 4/6 correct, and the two misses are the interesting part
#180 proposed the screen — does any declared mutation perturb the predicate itself? — and asked for a second sample. Here it is, applied per FILE as #180 states it:
argument_registry_e2eref_kind_stance_registryrefs-reading fn (SUBJECT)disclosure_surface_registryannotate_evidence_gapscall (SUBJECT)disclosure_derivation_registryproduction_caller_gatedeclares_a_bin_table, both directions) + 3 subject/datadoc_citation_gatebackticked_spans,classify,rust_sources,universe,doc_body)So the screen has no false positives here and two false negatives, and they share a shape worth naming:
The corrected question for review is therefore: for each helper the gate's verdict passes through, is there a declared mutation of THAT helper?
production_caller_gatewould have failed that question onstrip_line_commentsanddoc_citation_gateonuniverse's comment filter, which is precisely where both were blind.The other #180 result held, six times out of six
Every fix here was verified by weakening the NEW predicate back to its pre-fix form. In all six, the real-tree scan stayed GREEN and only the synthetic paired detector went RED — including
doc_citation_gate, where dropping thestrip_block_commentscall left all nine real-tree gates passing. A scan over compliant inputs is structurally incapable of discovering that its own predicate has gone vacuous, because a compliant tree never contains the shape the predicate would wave through. Recorded as a declaredMUTATION (RUN)on each new detector.One mechanism, not six fixes
Five of the six needed the same Rust lexer, and the first draft wrote it into five files. It now lives once, in
crates/test-support/src/source.rs(scan/strip_non_code/strip_comments/whole_word), reached bycode-index-indexer,code-index-daemonandcode-index-mcp, which already dev-depend on that crate. The sharing is not tidiness: the character-literal arm —'"', a quote as a CHAR — was omitted on the first attempt, anddoc_citation_gatethen reported TWELVE live test names as undeclared phantoms. One copy, one arm, one detector suite.crates/abi/tests/doc_citation_gate.rskeeps a local copy, and the reason is written into it:crates/abi/Cargo.tomldeclares no dependencies at all ("not serde, not thiserror, not xxhash — std only") because #76 requires the crate be fuzzable "without starting a daemon, tree-sitter or SQLite". A dev-dependency ontest-supportwould drag all three into abi's test and fuzz builds. The doctrine wins; the duplication is decided rather than missed.Bounds stated rather than discovered
disclosure_surface_registry'sproducesis still a spelling.fn search_texttakes a FILTER parameter also namedlang, so that one row would survive deletion of its per-hit disclosure — the parameter alone satisfies it. Closing that needs #178's behavioural arm, not a better substring. Written into the fix.kind_polarityclassifies four SQL shapes (IN,NOT IN,= 'k',!= 'k'/<> 'k'). A literal in none of them is left unclassified and asserted about by nothing — 21 of the registry's sites classify today against a floor of 10.Gates
COSI_E2E_LEG=daemon cargo test -p code-index-mcp --no-fail-fastfailed on both runs, on a different test each time, with the same signature:index_coverage_facts_e2e::a_refused_file_is_not_reported_as_indexed_and_currentcoverage_reasons: ["index_reconciling"]activation_offer_e2e::an_unconsultable_store_is_never_rendered_as_nothing_to_activate"state": "reconciling",files: 0,symbols: 0Both pass in isolation (3/3 and 2/2, exit 0), and run 1's victim passed in run 2. That is a fixture-readiness race under parallel load — an e2e asserting against a daemon whose initial reconcile has not finished — and it is unreachable from this diff, which is six registry test files plus one new
test-supportmodule and no production code at all. Reported, not blessed: two distinct victims with one signature suggests the daemon-leg harness needs a steady-state barrier before asserting, not a retry.Corpus ratchets were not run: nothing in this diff is production code, and no protected record is touched.
🤖 Generated with Claude Code
https://claude.ai/code/session_01K1zj5VcFJvJt3pQxe9259K
STAYING OPEN — the titled defect is unchanged on master; the second half is done
Close-out lane, master
552e3a2.The headline defect is live, byte-for-byte
crates/daemon/tests/lockfile_forge_registry.rs:157-159, still verbatim:hand_escapedis still computed over the whole file inside a per-line loop, and comments are stripped from the offender half (t.starts_with("//")) and not from the exemption half. The anti-vacuity assertion at:126-131still singles outmcp-server/src/main.rsby name, andcrates/mcp-server/src/main.rs:1235still carries the token in a///paragraph — so a doc comment exempts every line of the one file the floor names. The file is untouched since09c9be4, which predates this issue.The second half IS done, and should be struck from the scope
The six rated-vulnerable-but-never-mutated gates are complete on master (
0f011cd):crates/test-support/src/source.rsprovidesscan/strip_non_code/strip_comments/whole_word, used byproduction_caller_gate(the_scan_reads_code_and_not_text),argument_registry_e2e,disclosure_surface_registryanddisclosure_derivation_registry;doc_citation_gatehas its ownstrip_block_commentsplusthe_universe_reads_code_and_not_block_comments;ref_kind_stance_registryhaskind_polarityand 14 tests. All green — daemon suites EXIT=0, mcp-server suites EXIT=0, abidoc_citation_gateEXIT=0 (10 passed).Corrected scope
This issue is now only
lockfile_forge_registry: movehand_escapedinside the loop (per-line, like its offender counterpart) and strip comments from it, then run the mutation the issue already specifies — the///line atmain.rs:1235must stop exempting the file.#178 holds the four other registries that were confirmed blind and have no owner; this one is separate because it has this tracker.
Note for whoever takes it
0f011cdand the six-gate work are unpushed — local master is 7 commits ahead oforigin/master(a9ba058). The green cited above is a local green.$minFreeGbassignments with different values, and the gate pinning them matches whole-file so it only ever sees the first — the Windows reclaim can never fire #193release_gate_e2e.rs:102-122still says musl is continue-on-error and that nothing runs the step-13 migration gate — both false since #84 #187FIXED — the titled defect, with the two-run control this issue demanded
Branch
worktree-agent-a9fb463736bf2b59d, based on master1d81180. Not pushed.I took the corrected scope from the close-out comment: only
lockfile_forge_registry.The control run, because "do not close this by re-running the declared mutation on a file without the token"
Two runs, ONE variable — the gate, not the mutation. The forge is the same bytes in both, in
crates/mcp-server/src/main.rs's#[cfg(test)]module (the file that carries the exemption token in a///paragraph and that the anti-vacuity floor names):1d81180(this issue's subject), forge present1 passedin 30.45s — GREEN, as filedThe
main.rsdoc paragraph was NOT touched —md5 6e24db9f1f78a2456042098ad5b4bbdabefore and after, and the working tree at commit time holds three test files and nothing else.The fix is the SCOPE, not the spelling
The token still has 41 legitimate users (I recounted; the issue said 40) and none of them was narrowed. What changed:
code_index_test_support::source— so a comment can no more grant an exemption than it can be an offender;;inside the forged TOML is not a statement end).Per-LINE would have been wrong in the other direction: the one genuinely-escaped forge in this workspace spans nine lines —
crates/cli/tests/plugin_activation_cli.rs,format!on 647,.replaceon 649, statement 644–652.It needed a fix in the shared lexer, and that is the interesting part
Scanpromised line alignment in prose ("newlines inside a removed span are kept, so line structure survives") and the promise was false. The\escape arm consumed a backslash-newline line continuation without emitting its newline intocode, socodelost a line for every continued string literal above the hit.crates/indexer/src/approval.rshas several. Reading the offender off one view and the statement span off another is exactly the thing that promise has to hold for — so the arm is fixed, andsource::tests::every_view_keeps_the_line_structurenow grades it in both views, with both halves mutated (RED atleft: 12 right: 13andleft: 11 right: 13).An unmeasured prose contract in the SHARED module is the same class as this issue, one layer down: five gates were already resting on it.
The paired detector, and what it proved
the_detector_can_failholds a must-catch corpus (bare forge; the #180 doc-comment paragraph verbatim above a real forge; a block comment; an escape in a different statement of the same file) and a must-not corpus (the real nine-line escaped shape;root = {:?};root = '{}').The must-not arms assert the candidate count as well as the offender count, so "not flagged because exempted" cannot be confused with "not flagged because the detector went blind".
Four predicate mutations, all run:
an escape in another statement…,left: [] right: [6]— and GREEN on the real treea BLOCK comment must not exempt either,left: [] right: [4]candidate_forgessee nothing#180's general result reproduced, cleanly. The whole-file mutation leaves the real-tree scan GREEN and reddens only the synthetic detector. A scan over a compliant tree cannot discover that its own predicate has gone vacuous.
A correction to my own first draft, since this issue is about records drifting from mechanisms
I declared mutation 3 as reddening the doc-comment fixture too. It does not, and I only found that by running it: the STATEMENT scope alone already defeats a comment outside the statement, and comment-stripping is what defeats one inside it. Two fixtures, two halves of the repair. The declaration in the file now says what was measured.
New anti-vacuity, on the axis the old floor could not see
The old floor counted FILES — the exact axis blind to #180, since the walk reached every file and the predicate matched nothing in any of them. Added: the workspace must still contain at least one candidate and at least one exemption, so both halves of the predicate run on every push and a predicate that quietly stops matching reddens without a synthetic corpus.
Its bound is written next to it rather than discovered later: these floors do not catch an exemption that is too WIDE — measured, that mutation leaves them both at 1.
The self-exemption stayed, and is now asserted
This file still skips itself by name, because its fixtures spell the broken form on purpose. I tried assembling the needle so the skip could go; the fixtures re-introduce the literal, so the skip is real. It is now disclosed in the module doc and
self_skips == 1is asserted, so it cannot widen.Should this become a general gate? I measured, and no
The root shape here is a loop-invariant whole-file
containsinside a per-line loop. I swept every.rsundercrates/for it (afor … in X.lines()loop whose body callsX.contains(). Positive control: the sweep finds exactlylockfile_forge_registry.rs:158in the pre-fix file. Across the current tree it finds 0. The population of that shape was one, and it is now zero — a standing gate for it would grade nothing, so I did not add one.Gates
The one failure is
code-index-plugins'sextraction_is_linear_for_every_language_and_adversarial_shape— a wall-clock ceiling,rust/comment_runat 8.04x over an 8x ceiling. Isolated re-run: passes, exit 0. The contended run was at load average 21.85 (sibling lanes), and this diff is three test files plus onetest-supportlexer arm — no production code, and nothingcrates/pluginslinks. Reported, not blessed.Corpus ratchets and
precision_gatewere not run: no production code changed and no protected record is touched.Correction to the gate line in the comment above, since the record should say what was measured last rather than first.
I re-ran
cargo test --workspace --no-fail-fastafter committing, on the same tree, on a less contended box (load 15.25 vs 21.85):extraction_scaling_tests::extraction_is_linear_for_every_language_and_adversarial_shapepassed in that run (log line 5411). So the wall-clock ceiling failure reported above was contention, confirmed twice — once isolated, once in a second full run — and not a regression from this diff.Commit:
fd6f753onworktree-agent-a9fb463736bf2b59d, three test files, still unpushed.FIXED, merged as
46f6006.Confirmed live on master first, with the two-run control this issue demanded — the single variable being the gate, not the mutation. Same forge bytes in
crates/mcp-server/src/main.rs's#[cfg(test)]module both times:1d811801 passed, 30.45s — GREEN, exactly as filedcrates/mcp-server/src/main.rs:1378The doc paragraph this issue blamed was not touched (md5 identical before and after). The fix is the scope: both questions are now asked of comment-free text via
code_index_test_support::source, and the exemption is scoped to the statement. Per-line would have been wrong in the other direction — the one correctly-escaped forge spans nine lines (plugin_activation_cli.rs644–652). The token's 41 legitimate users are untouched.A false prose contract found on the way, worth more than the gate
Scanpromised line alignment and did not keep it: the\-escape arm swallowed a backslash-newline line continuation without emitting its newline intocode, socodelost a line per continued string literal above the hit — andcrates/indexer/src/approval.rshas several. Five gates already rested on that promise. Fixed, and now graded byevery_view_keeps_the_line_structureinstead of asserted in prose.A general gate for the root shape was measured and declined
The root shape is a loop-invariant whole-file
containsinside a per-line loop. Every.rsundercrates/was swept: the positive control finds exactlylockfile_forge_registry.rs:158in the pre-fix file, and the current tree yields 0. The population was one, so a standing gate would grade nothing — building it would have been ceremony.Seven mutations run, all RED, including two self-corrections after running them: mutation 3 does not redden the doc-comment fixture (statement scope already defeats a comment outside the statement; comment-stripping defeats one inside), and the first population-floor claim — that it would catch a too-wide exemption — was measured and found false. Both records now say what was measured rather than what was expected.
Closing.
posix_script_gateuses a WHOLE-FILE predicate for a call-scoped hazard: a file that merely quotes a script path beside an unrelatedCommand::newbecomes an offender #244