cost_attribution covers 3 of 9 pinned repos, and not the one that actually regressed — the gate that fires and the tool that explains it have different populations #259
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#259
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
CLAUDE.md makes attribution mandatory before a cost bless:
That instruction cannot always be followed, because the two populations differ.
Measured
corpus_costprices seven tier-1 repos.cost_attributionhas three tests:On 2026-09-10 the ratchet fired on rust-ripgrep, python-flask and ts-zod. Only one of those three — rust-ripgrep — can be attributed. The largest and only substantive regression was python-flask
vm_step14 222 433 → 15 070 105 (+6.0%), and there is no way to ask which statement caused it.The failure this produces is quiet: an operator follows the documented procedure, gets
0 passed; 0 filtered out(or, as happened here,running 0 tests … test result: ok), and unless they read past the exit code they conclude the attribution found nothing rather than that it ran nothing.Two smaller edges found at the same time
rust_ripgrep, notrust-ripgrepas the corpus and the CLAUDE.md line spell it. Passing the hyphenated name silently matches zero tests and exits 0.Why this is the repo's own recurring shape
A gate fires over one population and the tool that explains it is drawn from another, smaller one that nobody enumerated — the same structure as
bless_registrybefore it swept,ignored_test_reachabilitybefore it swept, and the release audit that hardcoded two of three packages (fixed today). Each time, the smaller list was written once and then diverged silently.What would close it
Derive the attribution's population from the same manifest the cost gate prices —
tests/corpus/corpus.toml, tier 1 — rather than from three hand-written#[test]fns, and require every priced repo to be attributable. A repo that cannot be attributed should be a declared, written exemption rather than an absence.Anti-vacuity: the count of attributable repos must be asserted against the count of priced repos, so adding an eighth priced repo without an attribution path is RED. A hardcoded
>= 3would rebuild the same trap one number higher — that mistake was made twice today inrelease_gate.rsand both were fixed by deriving instead of bumping.Also worth fixing while there: accept the hyphenated repo name as spelled everywhere else, or make an unmatched filter a refusal instead of a green run over zero tests.