packages.rs:4478-4480 says the wire has no bit for is_extension, contradicting record.rs:18 and a comment fifteen lines above it in the same expression #185
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#185
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found by dogfooding during the 2026-09-06 triage session, while verifying #86's four ABI gaps. One file, one expression, two opposite claims — sitting exactly where a reader goes to decide whether #86 gap 3 is possible.
Measured
crates/indexer/src/packages.rs:4478-4480:Both halves of that are contradicted by the tree:
TAG_SYMBOL_IS_EXTENSION = 0x8002—crates/abi/src/record.rs:18packages.rs:4462-4473— which correctly says "Its ABI half is closed too."So the file disagrees with itself within a single expression, and with the ABI crate.
Why it matters more than a stale sentence
This is the comment that explains why
packages.rs:4481writes a literalis_extension: falsefor every packaged symbol. The real reason is good and is stated correctly in the upper comment: wiring it through would falsifypool_capability_registry'sNeverDynamic("s.is_extension = 1")stance and admit a package to the C# extension pool with no grant — a #77 capability decision, deliberately not taken.The lower sentence replaces that reasoning with a false one. A reader who finds it first concludes the ABI work is undone and either duplicates
TAG_SYMBOL_IS_EXTENSION, or files gap 3 as an ABI gap when it is a capability decision. #86's own body already made a version of that mistake about a neighbouring tag (it claimsfacts_to_extracthardcodesattr_start_line: None; the mapping is live atpackages.rs:4475).This repo's recorded rule is that issue text goes stale in both directions — and so does in-tree prose. The difference is that a wrong comment is read at the moment of a decision.
Repro
Read
crates/indexer/src/packages.rs:4460-4485top to bottom. The upper comment says the ABI half is closed; the lower says the wire has no bit.crates/abi/src/record.rs:18settles it.Why existing gates miss it
Nothing grades a comment against the constant it describes. The
readme_security_claims/platform_support_claimspattern (crates/daemon/tests/support/claims.rs) does exactly this for shipped documents — deriving thresholds fromNetworkDenial::Enforced.encode()andNETWORK_FILTER_SUPPORTED's owncfg!rather than from copied spellings — and it caught a claim shipping from two places nobody had looked at. No equivalent exists for source comments that assert the presence or absence of an ABI tag.What must NOT be done
is_extensionthrough. That is #86 gap 3 and is an unmade #77 capability decision — doing it as a side effect of a comment repair would admit a package to the C# extension pool with no grant.crates/abi/src/record.rs's tag constants, in the shapeclaims.rsalready uses.Related
attr_start_linepremise (see the triage comment there).🤖 Filed by the triage lane, 2026-09-06, found while verifying #86.
CONFIRMED and FIXED. The claim is corrected, the reasoning is kept, and the fact now points at the row that grades it.
Lane worktree:
/tmp/cosi-lane-docdrift, detached at master552e3a2. Staged by path, not pushed.Verified before touching anything
Both halves of the contradiction reproduce exactly as filed:
pub const TAG_SYMBOL_IS_EXTENSION: u16 = 0x8002;—crates/abi/src/record.rs:77, and the module header at:18names it as one of the two optional tags #86 addedThe tag is not merely declared, it is live on both sides: encoded at
record.rs:1328, decoded at:1082, emitted by the guest atcrates/guest/src/encode.rs:351, and round-tripped bycrates/guest/tests/wire_parity.rs:832.The fix
crates/indexer/src/packages.rs:4477-4499(was 4478-4480). The sentence is corrected, not deleted — per the issue's first "must not". What changed:falseis the structural justification cited bypool_capability_registry'sNeverDynamic("s.is_extension = 1")row, and the comment points there rather than restating the fact in prose. That is the small mechanism available here — the fact already had a graded home, and the comment was competing with it.On the gate this issue asks for — REFUSED, with the measurement
The issue proposes a narrow
claims.rs-shaped check: a comment asserting a wire tag is absent should be checkable againstrecord.rs's tag constants. I measured the population before building it, and it does not support the gate.The claim family has to be found by vocabulary, and over the 152,986 comment lines in
crates/:no bit forthe wire has nohas no tagthere is nodoes not existno suchThe true family is a single line; the phrases broad enough to catch a differently worded future instance return hundreds of hits that are overwhelmingly runtime conditions (
if the file does not exist). A gate keyed on "the wire has no bit" catches this exact sentence and nothing else — a fix-per-case wearing a gate's clothes — and one keyed broadly enough to generalise would be suppressed within a week.The denominator is also small on the other side:
record.rsdeclares 7 tags, of which 2 are optional. A registry over two rows is not where this earns its keep.crates/abi/tests/doc_citation_gate.rs's own header already reached this conclusion with its own numbers, and drew the line in the right place: name resolution is mechanical, a claim about a state is not. "TAG_SYMBOL_IS_EXTENSIONexists" is checkable; "the wire has no bit for it" is a proposition, and there is no computable relation from that sentence to that constant without a vocabulary that does not survive contact with a paraphrase.Full reasoning, and the two other refusals it rests on, in the #187 comment.
🤖 Doc-drift lane, 2026-09-06, master
552e3a2disclosure_derivation_registry.rscalls #137 an open blind spot in its header while its own body says the gap is closed and inside the gate #186release_gate_e2e.rs:102-122still says musl is continue-on-error and that nothing runs the step-13 migration gate — both false since #84 #187release_gate_e2e.rs:102-122still says musl is continue-on-error and that nothing runs the step-13 migration gate — both false since #84 #187