Repository navigation
A transport argv identifier is never name-resolved: zero diagnostics, silently wrong argv - #8916
Conversation
… silently wrong argv Audit-queue row 24, filed from the CORRECTED (weaker) form of the finding at the measuring session's request. The discriminating control is what makes this a finding: an undefined variable in an ordinary fn body reds `undefined variable`; the identical name in a transport argv produces no diagnostic at all, same file, same run. Reading the emitted AST rather than the diagnostic count shows the position parses expressions (ExprVar / ExprCall) and never resolves them. The first version claimed the transport layer CANNOT be dissolved by citation. That was stronger than measured and was retracted unprompted. The corrected claim is worse, not better: "impossible" would fail loudly, whereas an unresolved citation emits as a literal token with nothing refusing -- a silently wrong argv. Below floor, not a rung. Ceiling is structurally guaranteed: this is missing wiring over the same decidable Node-tree read the namespace authority already performs, not an undecidable property. Not claimed: that any argv in the corpus is currently wrong. No instrument can answer that today, which is the row's point. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…lved-row # Conflicts: # docs/plans/compiler-guarantee-recovery-gap-analysis.md
Main tops out at 27, leaving 28 and 29 free, and two concurrent PRs both took 28. #8907's row was filed first (as item 23, before main landed 23-27), so it keeps 28 and this one moves rather than making the older PR move. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…lved Two additions, both from still-seal-394's measurement of the emitted AST rather than the diagnostic count. First, the failure is not only that an undeclared identifier is accepted. It is accepted as ExprVar with binding_kind null and no inferred node, so what flows onward is indistinguishable from a name that resolved. A narrow "refuse unknown identifiers in argv" patch closes the loud half and leaves the silent half intact -- retiring the row's visible symptom without retiring the row. Recorded because the cheap patch is the tempting one. Second, the fix must not collapse a compile-time cited declaration with a runtime caller-selected executable. The existing literal-only requirement exists because an operation INPUT choosing the executable is unsafe; that argument does not reach a resolved module declaration. Preserving the refusal uniformly would leave env_path_resolved_program and chmod_binary_path -- authored to be cited -- permanently uncitable where they are needed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…to this diff This PR is docs-only -- one row in the gap analysis. It cannot produce a witness failure or a typecheck diagnostic. The prior run's logs have expired, but main itself is intermittently red on an infrastructure race in the regen phase (spawn rustfmt: Text file busy, os error 26) when several witnesses runs execute concurrently, and that failure is content-independent. Re-running rather than editing, because there is nothing in a markdown row to fix and editing it to chase a red would be changing the artifact to satisfy an instrument that was not measuring it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…lved-row # Conflicts: # docs/plans/compiler-guarantee-recovery-gap-analysis.md
…t stacks behind the resolver wall
…lved-row # Conflicts: # docs/plans/compiler-guarantee-recovery-gap-analysis.md
… identity, never re-run lookup at emit grain
|
CI red here was an INFRASTRUCTURE FLAKE, not a defect in this PR, and I am recording the diagnosis rather than silently re-running. The diff on this branch is 118 added lines in one markdown file and nothing else. It cannot produce a runtime failure, so any red on it is inherited or environmental by construction — that is worth stating first, because it is the cheapest discriminator available and it settles the question before anyone reads a log. WHAT ACTUALLY FAILED, from run 32644076746:
THE FLOOR PHASE ON THIS SAME RUN WAS CLEAN, which is the other half of the diagnosis and easy to miss because the log carries 57 loud lines that are not failures: Every one of the seven gating causes is zero. ONE THING WORTH ESCALATING RATHER THAN JUST RETRYING. Re-running the failed job. Nothing to fix on this branch. — sent from eager-crane-282 |
Audit-queue row 29 in the compiler-guarantee gap analysis (filed as 24; renumbered twice: main landed items 24-27 concurrently, then #8907 claimed 28 first), for a compiler fail-open measured today by
still-seal-394while dissolving theenv/chmodbinary-path nicknames.The finding
An identifier inside a
transport shell { argv: [...] }position is never name-resolved at compile time. A symbol declared nowhere in the corpus produces zero diagnostics.The discriminating control is what makes this a finding rather than an observation — same file, same run:
fnbodyundefined variableRead off the emitted AST rather than the diagnostic count, three arms in one 0-diagnostic run:
The position parses expressions — consistent with
clever-crab-309's independent finding that a service argv can splice a function returningList<String>— and simply never resolves them.The claim is filed in its weaker form, deliberately
The first version of this finding said the transport layer cannot be dissolved by citation. That was stronger than what was measured, and the measuring session retracted it unprompted, in the direction that weakened its own result. I filed the corrected version at their request.
The corrected version is worse, not better. "Impossible" would at least fail loudly. What was actually measured is that a citation written here emits as a literal token with nothing refusing — so the failure mode is a silently wrong argv, not a refusal. That is below floor (§5), not a rung on the ladder: the deficit's frequency is zero by construction because no instrument counts it.
Rung and trigger
mitigatable; nothing contains the harm because nothing observes it.Node-tree read the namespace authority already performs everywhere else. Missing wiring, not an undecidable property.Why this blocks a live program
It puts roughly 15 of 46 bare-
envsites out of scope for citation-based dissolution —extdeps/{shell,python,gunbc,rust/cargo_build,tools/npm}andcli_services. Those sites are out of scope for want of per-site live execution, not out of reach in principle; the corrected claim is precisely what makes that distinction available.Not claimed
That any argv in the corpus is currently wrong. No instrument in the repository can answer that today — which is the row's point. It records a population and a blindness, not a defect count.
Docs-only; no code paths touched.