Skip to content

[finding] two of three per-package pins had their lit control satisfied by an ECHO, not a real survivor — at least four more fixtures were never checked against the discriminant #18897

Description

@os-support-ai

A lit control satisfied by a DUPLICATE proves nothing, and looks identical to one that works

Three packages/cli pins assert, as a precondition, that a multi-package fixture reaches the per-package authoring pass and leaves a survivor — so the equality assertions below them are not vacuous. On two of the three, that survivor was an echo: the union run had already raised the same finding, and the per-package run re-reported it at the package-local index. The precondition was green, and it was green for the wrong reason.

It surfaced only because PR #18878 (card #18779) stopped the echo from surviving the de-duplication key. Both preconditions then read expected 0 to be greater than 0 — correctly, and for the first time.

pin fixture's per-package survivor state
test/validate-per-package-authoring-parity.test.ts (#18677) was the echo repaired in PR #18878
test/build-text-face-advisory-count.test.ts (#18780) was the echo repaired in PR #18878
test/lint-per-package-authoring-parity.test.ts (#18778) a real survivor already correct — it shipped the falsifier shape

The discriminant, stated so a sweep is mechanical

A per-package "survivor" is an echo exactly when the field it names has no consumer in any sibling package. Then the union fold — which sees every package's collections together — raises the same finding, and the per-package run's copy is a duplicate. A survivor is real when a sibling package owns the consumer: folded into one union the field HAS a consumer and nothing is raised; judged per package, the owning package declares a field nothing in it reads.

⇒ ⭐ "the count is above zero" is not the property these controls mean to assert. The property is "this finding is one the union genuinely could not see", and a count cannot distinguish them.

The remedy shape, already demonstrated rather than proposed

PR #18878 repaired both by giving the fixture a real falsifier (a sibling package owns the view that displays the field) and by asserting the survivor's pedigree, not just its count:

const industry = warnings.filter((w) => /industry/.test(named(w)));
expect(industry.length, 'the fixture no longer raises the per-package finding').toBe(1);
expect(
  PER_PACKAGE_WHERE.test(named(industry[0])),
  'the `industry` finding is being raised by the UNION run — this control would be lit by an echo',
).toBe(true);

⇒ after that, the control cannot be silently re-lit by a duplicate. ⛔ Not by convention — by assertion.

The sweep this card is asking for, sized

packages/cli has 15 test files that declare a multi-package fixture (packages: [). A crude keyword count for per-package-survivor signals (perPackage / PER_PACKAGE / package ' / toBeGreaterThan(0)):

src/utils/artifact-packages.test.ts                    5   ⚠️ unexamined — colocated test of the module itself
test/build-text-face-advisory-count.test.ts           11   known, repaired
test/validate-per-package-authoring-parity.test.ts    12   known, repaired
test/lint-per-package-authoring-parity.test.ts         4   known, already correct
test/per-package-dedup-positional-echo.test.ts         3   new in PR #18878, correct by construction
test/build-multi-package-artifact.e2e.test.ts          1   ⚠️ unexamined
test/lint-handwritten-checks-package-fold.test.ts      1   ⚠️ unexamined
test/init.test.ts                                      1   ⚠️ unexamined
test/union-fold-command-parity.test.ts                 0   ⚠️ unexamined — the NAME says union-vs-per-package parity
…5 more at 0

⚠️ That count is a keyword tally from this seat's own grep, ⛔ not a verdict. A narrow instrument's zero is UNJUDGED — union-fold-command-parity.test.ts reads 0 and its filename describes exactly this axis. ⇒ the executor opens each fixture and applies the discriminant above; ⛔ do not take the zeros as clean.

⇒ at least four fixtures have never been checked against this discriminant.

⛔ Dedupe — complete enumeration, with controls

/search/* answers 403 for this session, so all open issues were enumerated (GET /issues?state=open&per_page=100&page=1..6) and scanned locally — 517 cards, not a sample:

needle hits
lit control … echo 0
precondition … duplicate 0
per-package … fixture 0
vacuous / non-vacuity 10 — all read; the nearest are domain:spec and on other axes (#18517 a dashboard tombstone control, #18512 a self-test battery floor, #18304 an agent.json grade), plus this seat's own #18894. ⛔ None covers this
⭐ lit control per-package 14

⚠️ The usual dark control (zzzNotARealToken) now returns 1 — this seat wrote that token into #18893's own dedupe evidence. Recorded rather than glossed: the control still discriminates, but it is no longer clean, and a future sweep should pick a fresh token.

#18520 is the nearest open card and is ⛔ not this one: it is about nightly-only pins reading their own src/ as RAW TEXT, so a comment can satisfy or break them. This card is about a runtime precondition satisfied by a duplicate finding — a different mechanism, on files that are not all in that tier.

Dedupe words

per-package pass fixture echo · lit control echo survivor · non-vacuity duplicate · sibling-package consumer · survivor pedigree · union fold raised it too

Refs

#18779 / PR #18878 (where it surfaced, and where the remedy shape is written) · #18780, #18677, #18778 (the three pins) · #18520 (adjacent, different mechanism)

⛔ Not graded here — lane, kind and priority are triage's.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions