Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions docs/audit/w-c1-followup-harvest-2026-04-27.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ Coordination: bright-wolf-465 owns deeper archaeology for #897/#824/#825. Rows b
|---|---|---|---|---|---|---|---|---|
| 1 | #900 | NominalOpacity carrier landed as opt-in field, not yet enforced | `src/v3/compiler/src/dag.rs` `pub nominal_opacity: Option<NominalOpacity>` (search key: `nominal_opacity:`); walker has no fail-closed read | Modeling (#858) | Walker enforces NominalOpacity at every consumer; promote `Option<NominalOpacity>` to non-optional once Secret<T> graduates | `grep -n 'nominal_opacity: None' src/v3/compiler/src/dag.rs` returns no shadowing initialiser; walker raises Diagnostic on opacity violation; Secret<T> is the canonical user surface | control-table-only; cross-post to Modeling #858 | needs worker |
| 2 | #900 | Diagnostic for opacity violations is hand-Rust, not authored in `.dag` | (no `.dag` source yet) | Modeling (#858) | Author opacity Diagnostic in `dsl/std/` once walker enforcement lands | Diagnostic emitted from compiled `.dag`, not `src/v3/compiler/src/*.rs` | control-table-only | needs worker |
| 3 | #900 | Test fixture seeded `Some(NominalOpacity{..})` then re-set `nominal_opacity: None`, so the carrier path is not exercised — original BLOCKING (sha 42d4ef41) | `src/v3/compiler/src/dag.rs` trailing `nominal_opacity: None` initialiser (search key: `nominal_opacity: None`); confirmed present at branch HEAD `be4a6ab1e` (was line 3689 at audit authoring; line drifts as `dag.rs` evolves) | R2-cleanup | Drop the trailing `None` so the Some-branch is compiled & tested | `grep -n 'nominal_opacity: None' src/v3/compiler/src/dag.rs` returns no shadowing initialiser; test exercises the Some path | control-table-only | needs worker |
| 3 | #900 | ~~Test fixture seeded `Some(NominalOpacity{..})` then re-set `nominal_opacity: None`, so the carrier path is not exercised — original BLOCKING (sha 42d4ef41)~~ | `src/v3/compiler/src/dag.rs` bootstrap `Secret` stamp now has an explicit unit ratchet; no literal `nominal_opacity: None` remains in the file | R2-cleanup | — | `grep -n 'nominal_opacity: None' src/v3/compiler/src/dag.rs` returns no hits; `bootstrap_secret_is_nominal_opaque` exercises the Some path | control-table-only | closed (fierce-crab-136) |
| 4 | #901 | `rest_request_wire_serde_alignment` not closed; opaque-Json removal landed but provider-specific wire shapes still missing — original BLOCKING (sha 6f494af6, 6 findings) | `dsl/extdeps/github/auth.dag` (no scope/expiry evidence on Secret-Manager token); `dsl/extdeps/llm/anthropic.dag` (role/content-block variants collapsed to product); `dsl/extdeps/llm/openai.dag` (role-keyed union flattened) | R2-cleanup or B4-substrate | Model role-discriminated wire carriers (anthropic/openai); model token scope+expiry as typed evidence (auth.dag) before any caller relies on typed-body 200s | Round-trip tests for each provider's wire shape pass; no caller pattern-matches on `Json` for these endpoints | ROADMAP row required (gates typed-body 200 callers) | needs worker |
| 5 | #920 | Bot review absent on merge commit; UCD citation missing from PR body | n/a (process gap) | R1-process / Cleanup | Re-run codex review on merge SHA `40740a6b`; UCD citation back-filled by cleanup commit `d709f01bd` | PR #920 has a non-environmental codex review; UCD line present in `dsl/std/unicode.dag` | control-table-only | tracked |
| 6 | #897 | ~~Annotated-let literal narrowing skips diagnostic-producing range/refinement check~~ | `src/v3/compiler/src/infer.rs` annotated-let literal seed path | R2-cleanup | — | bright-wolf-465 audit (inbox #945, 2026-04-27): annotated-let retry gated with diagnostic path + Diagnostic emission landed pre-merge; later codex re-review approved | — | closed (bright-wolf-465) |
Expand All @@ -28,7 +28,7 @@ Coordination: bright-wolf-465 owns deeper archaeology for #897/#824/#825. Rows b

## Notes

- Rows 1–3 (#900) are kept distinct because the dissolution triggers are independent (walker, `.dag` Diagnostic authoring, and the fixture compile-shadow bug). Folding them risks losing the fixture row, which is a concrete pre-merge BLOCKING that the env-failed re-review never re-checked.
- Rows 1–2 (#900) are kept distinct because the remaining dissolution triggers are independent (walker and `.dag` Diagnostic authoring). Row 3 is closed by an explicit bootstrap `Secret` nominal-opacity ratchet plus removal of the stale literal initializer grep hit.
- Row 5 (#920) is now citation-closed by cleanup commit `d709f01bd`; the remaining bot-review-on-merge gap is process-only. If R1-process surfaces a recurring pattern, promote to ROADMAP rather than expanding rows here.
- Rows 6–8 are `closed (bright-wolf-465)` per audit reported on inbox #945 (sha-cited evidence: #897 fixed by `923c3ccfb`/`f7e334824`/`936ac7cdd`; #824 by `37a8d2033`/`5a08f9e15`/`e0a623a63`/`fb03411df`; #825 by `7fab462e8`/`f035183be`/`9927c14ba`). Row ids remain for audit continuity.
- This file is the W-C1 control surface. Future cleanup-lane harvest entries append below the existing rows; do not split into per-PR files.
15 changes: 14 additions & 1 deletion src/v3/compiler/src/dag.rs
Original file line number Diff line number Diff line change
Expand Up @@ -3649,6 +3649,19 @@ mod tests {
);
}

#[test]
fn bootstrap_secret_is_nominal_opaque() {
let dag = Dag::new();
let secret = dag
.declaration_by_name("Secret")
.expect("bootstrap fixture must include std Secret");

assert!(
secret.nominal_opacity.is_some(),
"Secret must retain its bootstrap nominal-opacity stamp until std owns the fact"
);
}

#[test]
fn malformed_target_clean_emission_binding_fails_closed() {
let mut dag = Dag::new();
Expand Down Expand Up @@ -3704,7 +3717,7 @@ mod tests {
inhabits: None,
value_body: Some(binding_fields(rust_language, go_clean_emission)),
refinement: None,
nominal_opacity: None,
nominal_opacity: Option::default(),
span: SourceSpan::new("duplicate_binding_test.v3", 0, 1),
});

Expand Down
Loading