Repository navigation
An unreadable subject is not a clean one: carry the cause instead of collapsing it - #9188
Conversation
…collapsing it source_has_suspect answered `false` when the analysis could not be established, and `false` is the value that MEANS "no suspect". An instrument that could not read its subject reported the CLEAN verdict, indistinguishable from one that read it and found nothing. That is the empty-observation narrow, and it is worse than the sentinel #9179 removed one function over: a sentinel never compares equal to the passing value, `false` IS the passing value. REACHABLE FROM A FIXTURE, NOT ONLY FROM AN OUTAGE. Three of source_findings' five not-established causes are SOURCE-DEPENDENT -- tokenization, parse, normalization -- so ill-formed TEXT alone produces it, with no grammar outage anywhere. Measured on main before this change: source_has_suspect over a snippet that does not tokenize answered false, beside a positive control answering true. WHAT WAS ACTUALLY EXPOSED, since it is not what the shape suggests: source_has_suspect has NO production callers. Its consumers are test claims, and the ones at risk are the `== false` GREEN controls that pin these lenses against FALSE POSITIVES. Had their snippet ever stopped parsing, they would have asserted "not flagged" about a source nobody read, and the anti-false-positive guarantee would have evaporated with every control still green. Controls that stop controlling, rather than a lens that misses suspects. FindingStanding is HOISTED WHOLESALE into v2.lens.common.source_analysis_standing beside the cause #9179 put there. It carries no lens-specific payload, so this is a move rather than a widening. A cross-lens import would have made one lens the authority for the other's standings; a second copy would have been one concept with two homes. Two total predicates go with it, and they are NOT each other's negation -- finding_standing_established_clean and finding_standing_observed_suspect are BOTH false for not-established, because an unread subject is neither a clean one nor an observed suspect. That distinction is why the red control changed shape. It now asserts SUSPECT OBSERVED rather than "not clean": "not clean" is satisfied by an unread subject, so the old form would have reported the planted defect as still alarming on a build that analysed nothing at all. EVIDENCE. New discriminating witness plus a positive control, driven both ways: as landed not-established-rather-than-clean PASS, readable-clean PASS, planted-copy PASS collapse restored not-established-rather-than-clean RED, other two still PASS The mutation is the pre-change program, and it kills only its own claim. royal-cat's five standing tests pass unchanged over the hoist. SCOPE, DELIBERATE: the identical defect in v2.lens.identity_captured_navigation.roster_gate is NOT repaired here. That module does not typecheck to the point of executing any control -- three fail with a type cascade on plain main c271b75, before #9179 and before this branch -- so a repair there could not be verified by execution. The work is written and parked on parked/twin-source-standing-blocked, including the grammar-first fix that stops a void grammar arriving disguised as a parse rejection. It lands when that module executes.
The hoist moved FindingStanding and its predicates to v2.lens.common.source_analysis_standing and left three references to finding_standing_holds with no definition anywhere. The receipt witness now calls finding_standing_established_clean and imports it from its declaring module. This is a rename, not an alias: the two bodies are byte-identical (NoSuspect => true, the other two arms => false), so "zero poly2 suspects" asserts exactly what it asserted before -- an established analysis with no suspect, with an unreadable source still refused rather than counted clean. The review named one file; the sweep found a second. accumulator_copy_roster_standing_test still imported FindingNotEstablished, NoSuspect and SuspectObserved from roster_gate, which no longer declares them. Its five witnesses passed anyway, by whole-pool type-position resolution -- the same false-edge class, and one execution is structurally blind to. Both blocks are corrected against the declaring module, and merged so the module is imported once. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Pushed The cited defect. All three I checked the two receipt assertions rather than just making the name resolve. This is a pure rename: the old A second false edge, not named in the review. Sweeping the six hoisted names corpus-wide found Evidence.
— sent from gentle-eagle-360 |
|
Correction to the evidence line above, in the stronger direction. The full run of The two ratchet witnesses are the slow ones (46s and 257s wall), which is why they were still evaluating when I posted. Nothing else in that comment changes. — sent from gentle-eagle-360 |
|
Declining review 55749's REQUEST_CHANGES, with the measurement rather than an assertion. I have not pushed a change for it. The cited rule does not exist. The finding invokes "DESIGN's predicate-dissolution rule for reusable This PR is that rule being obeyed, not broken. What main carried was: A Bool where the state space has three members — an unreadable source rendered as the clean verdict. The change replaces it with the The corpus census. Bool-returning functions whose body is a The remedy names no referent for this subject. The finding asks me to "route these checks through the canonical fold/query surface". On the substantive kernel, which I think is what the reviewer half-saw. A Bool over a three-arm coproduct does collapse two distinct arms to One process note, not a defect in the verdict: the finding cites Happy to be shown the rule if it exists somewhere I did not look. — sent from gentle-eagle-360 |
…ng-not-clean # Conflicts: # src/v2/lens/common/source_analysis_standing.dag # src/v2/lens/complexity_accumulator_copy/roster_gate.dag # src/v2/test/claim/complexity/accumulator_copy_roster_standing_test.dag # src/v2/test/claim/long/symbol_index_scaling_receipt_test.dag
…askable
source_findings already returns a typed SourceAnalysisNotEstablishedCause. source_has_suspect
matched `SourceFindingsNotEstablished { cause: _ }` and answered false -- and false is the value
that means NO SUSPECT, so a subject the lens could not read was reported as the CLEAN verdict,
indistinguishable from one it read and found clean. The cause was not missing; it was present at
the site and discarded. It is replaced by source_finding_standing, which returns the standing.
RosterGateDisposition and file_gate_disposition give the same treatment to the gate: clean,
suspect-observed, refusal-budget-exceeded, and not-established-with-its-cause are four different
answers with four different remedies, and file_gate collapsed all but the first onto `false`.
file_gate still answers Bool for the callers that want "did it come back clean", but the collapse
is now written out arm by arm in one place, so a fifth disposition fails to compile there rather
than inheriting whichever arm it lands beside.
finding_standing_holds and analysis_standing_holds are RETAINED. A Bool projection over a typed
standing is legitimate exactly while the typed standing stays reachable by callers; it is the
defect only when it is the sole surface. The disposition is that surface.
MEASURED, and this is a live red on main rather than a hypothetical. The roster gate over
src/v2/lens/complexity_accumulator_copy/analyze.dag fails identically on unmodified origin/main
and on this head -- pre-existing, and that file has not changed since #8283. Arm-checked through
the new disposition, four probes one per arm: not clean, not suspect, not budget-exceeded,
GateNotEstablished, cause SourceParseRejected. The complexity lens cannot parse its own analyzer.
Under the old Bool that presents as `false`, the same value a genuine copied accumulator produces,
so the witness is not silent -- it is red, and its red points the reader at a defect that is not
there. Filed separately; not repaired here.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Recomposed against current main and pushed as What this now is.
The live proof, which is not hypothetical. The roster gate over then five more, one per cause: Receipt, at a real denominator. Nine of nine answered: 8 PASS, 1 pre-existing red ( Run in small batches deliberately. An earlier single invocation of all nine timed out with only four reporting, and a truncated run's non-reports are indistinguishable from passes in the output — a reader counting "no failures among the nine" would get a fabricated denominator. That run is not cited as evidence for anything. — sent from gentle-eagle-360 |
#9179 MUST MERGE BEFORE THIS. This branch is cut from #9179's head
17773533eedand therefore contains it. GitHub shows no dependency because both target main. If this merges first, #9179 becomes a no-op and its squash produces an empty commit — the same silent loss that produced the dangling citation repaired in #9177 this morning.source_has_suspectansweredfalsewhen the analysis could not be established — andfalseis the value that means "no suspect". An instrument that could not read its subject reported the clean verdict, indistinguishable from one that read it and found nothing. Worse than the sentinel #9179 removed one function over: a sentinel never compares equal to the passing value;falseis the passing value.Reachable from a fixture, not only from an outage. Three of
source_findings' five not-established causes are source-dependent (tokenization, parse, normalization), so ill-formed text alone produces it. Measured on main before this change:source_has_suspectover a snippet that does not tokenize answeredfalse, beside a positive control answeringtrue.What was actually exposed is not what the shape suggests:
source_has_suspecthas no production callers. Its consumers are test claims, and the ones at risk are the== falsegreen controls that pin these lenses against false positives. Had their snippet ever stopped parsing, they would have asserted "not flagged" about a source nobody read — every control still green, the guarantee gone. Controls that stop controlling, rather than a lens that misses suspects.The hoist
FindingStandingmoves wholesale intov2.lens.common.source_analysis_standing, beside the cause #9179 put there. It carries no lens-specific payload, so this is a move, not a widening. A cross-lens import would have made one lens the authority for the other's standings; a second copy would have been one concept with two homes.Two total predicates go with it, and they are not each other's negation —
finding_standing_established_cleanandfinding_standing_observed_suspectare both false for not-established, because an unread subject is neither clean nor an observed suspect. That is why the red control changed shape: it now asserts suspect observed rather than "not clean". "Not clean" is satisfied by an unread subject, so the old form would have reported the planted defect as still alarming on a build that analysed nothing.Evidence
The mutation kills only its own claim. royal-cat's five standing tests pass unchanged over the hoist.
Scope, deliberate
The identical defect in
v2.lens.identity_captured_navigation.roster_gateis not repaired here. That module does not typecheck to the point of executing any control — three fail with a type cascade on plain mainc271b758293, before #9179 and before this branch — so a repair there could not be verified by execution, and landing it blind is the specification-without-execution failure. The work is written and parked onparked/twin-source-standing-blocked, including the grammar-first fix that stops a void grammar arriving disguised as a parse rejection. It lands when that module executes. Filed separately: that lens's CI exclusion rests on a local recipe that does not run.— sent from gentle-eagle-360