Six gates were rated vulnerable and never mutated — their status is UNKNOWN, not safe (the #180 audit residual) #204
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#204
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Carried out of #180, which is now closed on its own defect. That issue's audit ended with a sentence worth keeping: "The audit is a FLOOR, not a census. Eleven gates were rated vulnerable; five were mutated. Six were rated vulnerable and never mutated, so their status is UNKNOWN, not SAFE."
That distinction is the one this project insists on everywhere else, so it gets its own number rather than dying with the issue that produced it.
The portable result this rests on
That single question — does any declared mutation perturb the predicate itself? — separated the two populations more reliably than reading the code did, and is cheap enough to ask in review of every new gate.
It was confirmed against a gate written in the same lane, which is the convincing part: weakening
ci_cadence::no_grading_step_is_masked_by_an_earlier_one's predicate left the scan over real workflows GREEN — a compliant tree never exercises a weakened predicate — and only the synthetic detector went red. A scan over real inputs is structurally incapable of discovering that its own predicate has gone vacuous.The six, with the mutation to run on each
indexer/tests/production_caller_gate.rsconst _WHY: &str = "cmd_enable calls build::build( here";to a file the module closure reaches — a string literal, whichstrip_line_commentsdoes not touch.daemon/tests/argument_registry_e2e.rsShapeProbe's named test body, leave a doc comment mentioningfn wire_vintage_probe(.ShapeProberows are skipped by the behavioural sweep, sosrc.contains(&format!("fn {func}("))is all that stands behind them. This file declares noMUTATION (RUN)block anywhere.mcp-server/tests/ref_kind_stance_registry.rsNOTatdaemon/src/graph.rs:1237. Polarity, not spelling:code.contains("'binding'")cannot tellIN (...)fromNOT IN (...), so the population inverts to exactly the kinds the row declares excluded while every assertion passes. Six sibling sites take the same one-token edit.mcp-server/tests/disclosure_surface_registry.rsproducer: "lang"— a 4-character bare substring matchinglanguage,lang_id,by_lang, or any comment — delete the real disclosure and leave// no language disclosure here.mcp-server/tests/disclosure_derivation_registry.rsrender_link_package_set, replace the absence branch with a comment plusreturn Value::Null;. Membership is decided byregion.contains("ACTIVATION_UNAVAILABLE")over an un-stripped corpus. The equivalent edit inrender_count_basisis caught by an e2e; this one is not.abi/tests/doc_citation_gate.rs.rsthat is not the gate file:/* fn the_shipped_host_cannot_compile_wasm */. The comment filter is//-only, so a block comment enters bothwrittenanditemsand the gate's own motivating phantom resolves as a declared item. The string-literal hole is disclosed and priced; this one is not mentioned anywhere.Two supporting patterns, cheap to act on
bless_registryadded — a corpus holding the non-compliant shape, measured green — appears in only three files.generation_policy_registry/reason_code_registrystrip;pool_capability_registry/disclosure_surface_registry/disclosure_derivation_registry/resource_grading_registrydo not.pool_capability_registry's own fix is already written in an adjacent file in the same directory.Acceptance
For each of the six: run the stated mutation and paste the real result. A green one is the finding — it means the gate is vacuous and needs its predicate scoped, in the shape #180's fix used (ask both halves of a predicate of comment-free text, and scope the exemption to the same unit as the detection). A red one is also a result: it retires the row honestly, and that is a legitimate outcome — #180's own general-gate proposal was measured and declined because the population turned out to be one.
What must NOT be done
ci_cadenceresult above shows a scan over real inputs cannot grade its own predicate.Related
#180 (the confirmed instance, fixed), #178 (the class), #169 (where the general result was confirmed against a fresh gate).
Closed on
masteratee1d9c8. All six are RED. A seventh was found outside the six and it was the vacuous one.The six — verdicts
Every mutation re-measured from scratch rather than trusted from a prior commit message.
indexer/tests/production_caller_gate.rsbuild::build(call site, then added the string-literal decoybuild::build( has NO production caller compiled into any shipped binarydaemon/tests/argument_registry_e2e.rsShapeProbecover test, then named the old fn in//linescovered_by names …, but no such test function exists theremcp-server/tests/ref_kind_stance_registry.rsNOTatgraph.rs:1237, then at each of the three sibling sitesnames 'import' in an INCLUDING clause while declaring Import::Excludedmcp-server/tests/disclosure_surface_registry.rs//; thenlet _languagebindingsmcp-server/tests/disclosure_derivation_registry.rsreturn Value::Null, then the rescuing commentthese surfaces are declared and call NO renderer any more: ["link_summary"]abi/tests/doc_citation_gate.rs/* */decoy1 doc comment(s) cite a name NOTHING in this workspace declaresThis issue's premise is stale.
0f011cd(2026-09-06 12:07) already confirmed and fixed all six — twelve hours before this issue was filed on 2026-09-07 00:37. The re-measurement was still worth doing: it is what turned up the seventh.The seventh — the one that mattered, and I reproduced it myself
evidence_semantics_registry.rs::the_partial_sources_clause_still_cites_the_field_it_sends_the_reader_to— the anti-vacuity floor under G3 — asserted over RAW source:A
//comment is inside that body. So a comment could hold the floor up while the sentence was gone from the wire.I did not take this from the lane's report. One variable, two runs, both by me on the merged tree — the phrase removed from the shipped string literal and left only in a comment inside the function body:
The new failure says why:
The fix is the right shape:
clause_prosereads the contents of the function's string literals, so the question becomes "does a client receive these words", not "is this spelled somewhere in the source". #216's defect, one level up — the gate against the disclosure had the disclosure's own failure mode.A methodology note on my own first attempt, because it is instructive. My first run put the decoy comment before the
fnand the old gate went RED — which would have read as "the lane's finding is refuted". It was not:item_bodyscans from thefnmarker, so a comment above it is outside the body being searched. The mutation only reproduces with the comment inside. A mutation placed one line off tests a different thing and looks like a refutation.Confirming this issue's portable result — twice, on gates it was not derived from
With the stripper weakened to pre-#180 and the mutation left in place:
Both real-tree scans went GREEN on a tree that had lost the thing they grade; only the synthetic detector saw it. That reproduces the
ci_cadenceresult on two more gates — and extends it: the compliant-corpus detector is blind too, not only the real-tree scan.The standing check — NOT built, refused with numbers
The per-predicate form would police 387 non-test helper fns across 31 gate-shaped files, of which 48 are named in a declared
MUTATIONline — 339 sites on day one, most false (workspace_root,brace_delta,connare not predicates), and a helper graded inside a named detector test is already covered. The narrower screen — "reads Rust source andcontainses over it with no stripper in the file" — flags 9 of 26, and ≥4 of those read YAML, CLI stderr or TOML rather than Rust.It did find the seventh. So did reading the same 26-row list by hand. Not cheap enough to be mechanical — keep it as the review question, which is what this issue itself proposes. Recording the refusal with its measurement rather than leaving it as unbuilt scope.
Three corrections to this issue's text
render_count_basisis caught by an e2e; this one is not" — wrong. With the absence arm replaced and the rescuing comment in place,server::routing_tests::two_links_with_different_package_sets_render_differentlyFAILED, exit 101. The gate was blind; the tree was not.0f011cd~1,production_caller_gatedeclared 5MUTATION (RUN)blocks anddoc_citation_gatedeclared 17 — including predicate mutations ofbackticked_spans,classify,universe,doc_body. Both read SAFE by the screen; both were vulnerable. The failure is systematic: they mutated the interesting predicates and left the boring text stripper underneath ungraded. The rule is per predicate, not per file. (The claim aboutargument_registry_e2e, which declared 0, was accurate.)NOTdeletion does not reconcile with the tree: 4 exact-spelling sites ingraph.rs(756, 1237, 1896, 1968), 8NOT IN ('binding'occurrences workspace-wide. All four graph.rs sites tested RED individually.Verification on the merged tree
fmt --checkandclippy --workspace --all-targets -D warningsboth exit 0; workspace suite 3563 passed / 0 failed;tests/corpus/baseline.jsonuntouched. All seven gates re-run by me after merge:evidence_semantics_registry4,production_caller_gate6,doc_citation_gate10,disclosure_surface_registry11,disclosure_derivation_registry11,ref_kind_stance_registry14,argument_registry_e2e8 — every one EXIT=0.The six moved from UNKNOWN to measured, which was the ask. The seventh is why the ask was worth honouring even though the answer to it was "already fixed".
.claude/, which is permanently unindexable #238posix_script_gateuses a WHOLE-FILE predicate for a call-scoped hazard: a file that merely quotes a script path beside an unrelatedCommand::newbecomes an offender #244