Repository navigation
0.7.1g1G5d: close the final NO_COVERAGE cohort (4 UNREACHABLE) - #464
GionaGranchelli wants to merge 5 commits into
Conversation
…eal failure class
The existing assertions used startsWith("structured-parse-failed"), which is satisfied
both by the authoritative diagnostic (structured-parse-failed: StructuredOutputException)
and by the negated-conditional mutant's output (structured-parse-failed: unknown). The
assertions now pin the full contract, so the diagnostic's class-name component is
observable behaviour rather than an unchecked prefix.
Adjudicates the 12 frozen SURVIVED identities at base 42d9d94: 12/12 EXACT mappings (the five G5a ambiguities resolved by canonical identity), 1 semantic KILLED (a9760bea3a92, via an exact diagnostic assertion), 11 instruction-level EQUIVALENT proofs (6 caller-discard, 2 catch-handler dominance, 1 compiler guard, 2 successor convergence), 0 UNDETERMINED, 0 KILLED regressions. No production changes; no authority changes.
1. reconciliation.movements[0].identity is the full 64-hex canonical identity (was the malformed prefix a9760bea3a92f). 2. The six NullReturnVals rows carry the mutated areturn PCs (161, 100, 244, 341, 267, 54), each re-verified by javap at the census base against the line table, instead of null. Call-site pop PCs remain as supplementary evidence. No disposition changes: 1 KILLED / 11 EQUIVALENT / 0 UNDETERMINED.
The four frozen NO_COVERAGE identities are all on the suspension protocol of resolveGovernedSuspension() / resolveGovernedIdentity(), neither of which can suspend (0 getCOROUTINE_SUSPENDED, 0 if_acmpne), so the COROUTINE_SUSPENDED exit and the resumed-path throwOnFailure can never execute. 4/4 mapped to exact bytecode PCs; no tests added (tests are permitted only for proven-reachable identities); no production, authority or test changes.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The diff includes a test change and the G5c documentation pair that contradict the description's "Tests: none / Docs: two files" scope, indicating the branch is not based on the declared #463 merge and must be reconciled before approval.
Review effort: Balanced
Findings: 1
What changed in this PR
This PR is the final step (G5d) of a mutation-testing adjudication campaign. Its stated goal is to close the last four frozen NO_COVERAGE mutation identities (two in ApprovalSuspensionCoordinator.suspendToolExecution, two in DefaultApprovalGateway.requestApproval) by classifying all four as UNREACHABLE through bytecode-level control-flow and callee-suspension analysis, adding no tests or production code. It fits into the broader 0.7.1g1G5 effort to fully account for the mutation cohort (52 = 36 G5b + 12 G5c + 4 G5d, remainder 0).
Changes:
- Adds a G5d reachability report and a four-identity JSON manifest documenting the UNREACHABLE classification and its bytecode-bracketing evidence.
- Also present in the diff: a 2-line test assertion tightening (
startsWith→isEqualTo) and the two G5c documentation artifacts — all described as belonging to the already-merged parent #463.
Scope note: The description claims "Tests: none. Production: none. Docs: this report + the four-identity manifest," but the diff additionally modifies a test file and adds the G5c doc pair, indicating the branch is not rooted at the declared base (cd46f176, the #463 squash merge).
| File | Description |
|---|---|
tramai-engine/.../ApprovalResumeSuspensionContractTest.kt |
Tightens two uncertain-reason assertions to isEqualTo(...); correct and matches production, but outside the PR's stated "Tests: none" scope. |
docs/roadmap/0.7.0/TASK-0.7.1g1G5d-NO-COVERAGE-REACHABILITY.md |
New G5d reachability report; internally consistent with the manifest. |
docs/roadmap/0.7.0/TASK-0.7.1g1G5d-NO-COVERAGE-4-MANIFEST.json |
New four-identity manifest; calibration points, windows, and totals are self-consistent. |
docs/roadmap/0.7.0/TASK-0.7.1g1G5c-SURVIVED-ADJUDICATION.md |
G5c adjudication report; described as a #463 artifact yet added here. |
docs/roadmap/0.7.0/TASK-0.7.1g1G5c-SURVIVED-12-MANIFEST.json |
G5c manifest; described as a #463 artifact yet added here. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| assertReachesCaller(thrown, failure) | ||
| assertThat(audit.uncertainReasons).hasSize(1) | ||
| assertThat(audit.uncertainReasons.single()).startsWith("structured-parse-failed") | ||
| assertThat(audit.uncertainReasons.single()).isEqualTo("structured-parse-failed: StructuredOutputException") |
Identity-exact campaign at cd46f17 (throwaway 56364ae3, family-only narrowing): 918/918 identities, 0 status movements, 0 KILLED regressions, 0 new timeouts, all four targets present and NO_COVERAGE, no widening.
|
Superseded by #465. This branch was cut from No content was wrong — the G5c content in this branch is byte-identical to what #463 already merged — but the scope was misleading, and a misleading scope is a custody defect of exactly the kind this track blocks on. #465 carries the identical artifacts (+425, two files) on a branch cut directly from |

Base
cd46f176b20ef7e0e0b2b0e251569214dfc90619— the squash merge of #463. Worktree branched directly from it, clean tree.Scope
Exactly the four frozen NO_COVERAGE identities. No widening, no substitution, no production change.
Endpoint
G5D COMPLETE — FINAL G5 NO_COVERAGE COHORT CLOSED. Final classification: 4 UNREACHABLE, 0 KILLED, 0 EQUIVALENT, 0 TOOLING_LIMITATION, 0 UNDETERMINED. Parent accounting: 52 = 36 (G5b) + 12 (G5c) + 4 (G5d). G5 remainder: 0.
564517b2fdabResultKt.throwOnFailure(resumed path)66c311cf4f0aareturnof COROUTINE_SUSPENDED (suspend exit)5a7edac3a982ResultKt.throwOnFailure(resumed path)e52f1c1f6570areturnof COROUTINE_SUSPENDED (suspend exit)Mutator naming: the brief calls the two "NRV" mutants
NonReturningVoidMethodCall; the frozen manifest recordsreturns.NullReturnValsMutator("replaced return value with null"). The frozen identities are authoritative — a label discrepancy, not an identity discrepancy.Phase A — exact mapping method
PIT reports no bytecode offsets, and reconstructing its block/index counter matched only 4 of 36 calibration identities, so that approach was abandoned rather than tuned until it fit. Each identity is instead bracketed:
pitBlockis monotone in pc within a method (verified), and both methods carry in-method calibration points with known pc and known PIT coordinates from the committed G5b/G5c manifests. Every target's block brackets a pc window containing exactly one candidate of the mutated kind.The source line is useless here and was not relied on: line 142 is the
suspendToolExecutionfunction header and line 73 therequestApprovalheader, so every state-machine instruction inherits it.Reachability — UNREACHABLE, structurally
All four sit on the suspension protocol of two calls:
resolveGovernedSuspension()(line 145) andresolveGovernedIdentity(workflowRunId)(line 82). Neither callee can suspend:resolveGovernedSuspension: 50 instructions, 0getCOROUTINE_SUSPENDED, 0if_acmpneresolveGovernedIdentity-jFE5hGw: 32 instructions, 0getCOROUTINE_SUSPENDED, 0if_acmpne; invokes onlyContinuation.getContext, own-package accessors/getters,Intrinsics.areEqual, concat, an exception ctorGovernedRunScope.resolve(context)is a plain non-suspend functionA suspend function returns
COROUTINE_SUSPENDEDonly through the sentinel comparison emitted after a call. With none emitted and no suspending callee, both resolvers always return directly. So the caller's sentinel test is always false and theCOROUTINE_SUSPENDEDexit cannot execute; and the resumed continuation can only be constructed by a real suspension at that call, so the resumed-paththrowOnFailurecannot execute. Nothing else reaches them: no branch or switch entry in either method targets pc194 or pc204.That is control-flow dominance plus callee analysis — not "I could not find a test".
Test evidence
No tests added — tests are permitted only for proven-reachable identities. Making these execute would require changing production semantics or fabricating a coroutine state the runtime cannot produce. A test existing only to move PIT's coverage counter is what this task forbids.
Phase E — pairs
Both pairs are one compiler-generated suspension:
suspendToolExecutionblock 12 (exit) / block 13 (resumed unwrap);requestApprovalblock 10 / block 11. Same construct, different instructions, neither dominating. Whether one test would cover both is moot — neither member is reachable. Block/index adjacency was not used as evidence of equivalence.Diff scope
Tests: none. Production: none. Docs: this report + the four-identity manifest. The measurement narrowing never landed.
Regression gate
Identity-exact campaign running from a fresh worktree at
cd46f176with the proven family-only narrowing; reconciliation (4/4 accounted, 0 identity loss, 0 gain/substitution, 0 new timeouts, 0 regressions of previously KILLED identities, no widening) is appended to the report and manifest on completion.Limits
UNREACHABLEis a statement about this compiled artifact at this base: if either resolver ever gains a suspension point, these instructions become live and these identities must be re-adjudicated rather than inherited.Verification: 4/4 mapped with non-null PCs · no churn ·
spotlessCheck verifyStaticAnalysis verifyChangePolicy -PchangePolicyBase=cd46f176…BUILD SUCCESSFUL. Exact-head CI is the final authority. Not self-merged.