Skip to content

0.7.1g1G5d: close the final NO_COVERAGE cohort (4 UNREACHABLE) - #464

Closed
GionaGranchelli wants to merge 5 commits into
epic/0.7.1-control-plane-authorityfrom
task/0.7.1g1G5c-survived-adjudication
Closed

GionaGranchelli wants to merge 5 commits into
epic/0.7.1-control-plane-authorityfrom
task/0.7.1g1G5c-survived-adjudication

Conversation

@GionaGranchelli

Copy link
Copy Markdown
Owner

Base

cd46f176b20ef7e0e0b2b0e251569214dfc90619 — the squash merge of #463. Worktree branched directly from it, clean tree.

Scope

Exactly the four frozen NO_COVERAGE identities. No widening, no substitution, no production change.

Endpoint

G5D COMPLETE — FINAL G5 NO_COVERAGE COHORT CLOSED. Final classification: 4 UNREACHABLE, 0 KILLED, 0 EQUIVALENT, 0 TOOLING_LIMITATION, 0 UNDETERMINED. Parent accounting: 52 = 36 (G5b) + 12 (G5c) + 4 (G5d). G5 remainder: 0.

identity owner mutator block/index PC mutated instruction
564517b2fdab suspendToolExecution VoidMethodCall 13/96 pc194 ResultKt.throwOnFailure (resumed path)
66c311cf4f0a suspendToolExecution NullReturnVals 12/78 pc163 areturn of COROUTINE_SUSPENDED (suspend exit)
5a7edac3a982 requestApproval VoidMethodCall 11/92 pc204 ResultKt.throwOnFailure (resumed path)
e52f1c1f6570 requestApproval NullReturnVals 10/72 pc164 areturn of COROUTINE_SUSPENDED (suspend exit)

Mutator naming: the brief calls the two "NRV" mutants NonReturningVoidMethodCall; the frozen manifest records returns.NullReturnValsMutator ("replaced return value with null"). The frozen identities are authoritative — a label discrepancy, not an identity discrepancy.

Phase A — exact mapping method

PIT reports no bytecode offsets, and reconstructing its block/index counter matched only 4 of 36 calibration identities, so that approach was abandoned rather than tuned until it fit. Each identity is instead bracketed: pitBlock is monotone in pc within a method (verified), and both methods carry in-method calibration points with known pc and known PIT coordinates from the committed G5b/G5c manifests. Every target's block brackets a pc window containing exactly one candidate of the mutated kind.

The source line is useless here and was not relied on: line 142 is the suspendToolExecution function header and line 73 the requestApproval header, so every state-machine instruction inherits it.

Reachability — UNREACHABLE, structurally

All four sit on the suspension protocol of two calls: resolveGovernedSuspension() (line 145) and resolveGovernedIdentity(workflowRunId) (line 82). Neither callee can suspend:

  • resolveGovernedSuspension: 50 instructions, 0 getCOROUTINE_SUSPENDED, 0 if_acmpne
  • resolveGovernedIdentity-jFE5hGw: 32 instructions, 0 getCOROUTINE_SUSPENDED, 0 if_acmpne; invokes only Continuation.getContext, own-package accessors/getters, Intrinsics.areEqual, concat, an exception ctor
  • GovernedRunScope.resolve(context) is a plain non-suspend function

A suspend function returns COROUTINE_SUSPENDED only through the sentinel comparison emitted after a call. With none emitted and no suspending callee, both resolvers always return directly. So the caller's sentinel test is always false and the COROUTINE_SUSPENDED exit cannot execute; and the resumed continuation can only be constructed by a real suspension at that call, so the resumed-path throwOnFailure cannot execute. Nothing else reaches them: no branch or switch entry in either method targets pc194 or pc204.

That is control-flow dominance plus callee analysis — not "I could not find a test".

Test evidence

No tests added — tests are permitted only for proven-reachable identities. Making these execute would require changing production semantics or fabricating a coroutine state the runtime cannot produce. A test existing only to move PIT's coverage counter is what this task forbids.

Phase E — pairs

Both pairs are one compiler-generated suspension: suspendToolExecution block 12 (exit) / block 13 (resumed unwrap); requestApproval block 10 / block 11. Same construct, different instructions, neither dominating. Whether one test would cover both is moot — neither member is reachable. Block/index adjacency was not used as evidence of equivalence.

Diff scope

Tests: none. Production: none. Docs: this report + the four-identity manifest. The measurement narrowing never landed.

Regression gate

Identity-exact campaign running from a fresh worktree at cd46f176 with the proven family-only narrowing; reconciliation (4/4 accounted, 0 identity loss, 0 gain/substitution, 0 new timeouts, 0 regressions of previously KILLED identities, no widening) is appended to the report and manifest on completion.

Limits

UNREACHABLE is a statement about this compiled artifact at this base: if either resolver ever gains a suspension point, these instructions become live and these identities must be re-adjudicated rather than inherited.

Verification: 4/4 mapped with non-null PCs · no churn · spotlessCheck verifyStaticAnalysis verifyChangePolicy -PchangePolicyBase=cd46f176… BUILD SUCCESSFUL. Exact-head CI is the final authority. Not self-merged.

…eal failure class

The existing assertions used startsWith("structured-parse-failed"), which is satisfied
both by the authoritative diagnostic (structured-parse-failed: StructuredOutputException)
and by the negated-conditional mutant's output (structured-parse-failed: unknown). The
assertions now pin the full contract, so the diagnostic's class-name component is
observable behaviour rather than an unchecked prefix.
Adjudicates the 12 frozen SURVIVED identities at base 42d9d94: 12/12 EXACT
mappings (the five G5a ambiguities resolved by canonical identity), 1 semantic
KILLED (a9760bea3a92, via an exact diagnostic assertion), 11 instruction-level
EQUIVALENT proofs (6 caller-discard, 2 catch-handler dominance, 1 compiler guard,
2 successor convergence), 0 UNDETERMINED, 0 KILLED regressions.

No production changes; no authority changes.
1. reconciliation.movements[0].identity is the full 64-hex canonical identity
   (was the malformed prefix a9760bea3a92f).
2. The six NullReturnVals rows carry the mutated areturn PCs (161, 100, 244, 341,
   267, 54), each re-verified by javap at the census base against the line table,
   instead of null. Call-site pop PCs remain as supplementary evidence.

No disposition changes: 1 KILLED / 11 EQUIVALENT / 0 UNDETERMINED.
The four frozen NO_COVERAGE identities are all on the suspension protocol of
resolveGovernedSuspension() / resolveGovernedIdentity(), neither of which can
suspend (0 getCOROUTINE_SUSPENDED, 0 if_acmpne), so the COROUTINE_SUSPENDED exit
and the resumed-path throwOnFailure can never execute. 4/4 mapped to exact
bytecode PCs; no tests added (tests are permitted only for proven-reachable
identities); no production, authority or test changes.
Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:57

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The diff includes a test change and the G5c documentation pair that contradict the description's "Tests: none / Docs: two files" scope, indicating the branch is not based on the declared #463 merge and must be reconciled before approval.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

This PR is the final step (G5d) of a mutation-testing adjudication campaign. Its stated goal is to close the last four frozen NO_COVERAGE mutation identities (two in ApprovalSuspensionCoordinator.suspendToolExecution, two in DefaultApprovalGateway.requestApproval) by classifying all four as UNREACHABLE through bytecode-level control-flow and callee-suspension analysis, adding no tests or production code. It fits into the broader 0.7.1g1G5 effort to fully account for the mutation cohort (52 = 36 G5b + 12 G5c + 4 G5d, remainder 0).

Changes:

  • Adds a G5d reachability report and a four-identity JSON manifest documenting the UNREACHABLE classification and its bytecode-bracketing evidence.
  • Also present in the diff: a 2-line test assertion tightening (startsWith → isEqualTo) and the two G5c documentation artifacts — all described as belonging to the already-merged parent #463.

Scope note: The description claims "Tests: none. Production: none. Docs: this report + the four-identity manifest," but the diff additionally modifies a test file and adds the G5c doc pair, indicating the branch is not rooted at the declared base (cd46f176, the #463 squash merge).

File Description
tramai-engine/​.../​ApprovalResumeSuspensionContractTest.kt Tightens two uncertain-reason assertions to isEqualTo(...); correct and matches production, but outside the PR's stated "Tests: none" scope.
docs/​roadmap/​0.7.0/​TASK-0.7.1g1G5d-NO-COVERAGE-REACHABILITY.md New G5d reachability report; internally consistent with the manifest.
docs/​roadmap/​0.7.0/​TASK-0.7.1g1G5d-NO-COVERAGE-4-MANIFEST.json New four-identity manifest; calibration points, windows, and totals are self-consistent.
docs/​roadmap/​0.7.0/​TASK-0.7.1g1G5c-SURVIVED-ADJUDICATION.md G5c adjudication report; described as a #463 artifact yet added here.
docs/​roadmap/​0.7.0/​TASK-0.7.1g1G5c-SURVIVED-12-MANIFEST.json G5c manifest; described as a #463 artifact yet added here.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

assertReachesCaller(thrown, failure)
assertThat(audit.uncertainReasons).hasSize(1)
assertThat(audit.uncertainReasons.single()).startsWith("structured-parse-failed")
assertThat(audit.uncertainReasons.single()).isEqualTo("structured-parse-failed: StructuredOutputException")
Identity-exact campaign at cd46f17 (throwaway 56364ae3, family-only narrowing):
918/918 identities, 0 status movements, 0 KILLED regressions, 0 new timeouts,
all four targets present and NO_COVERAGE, no widening.
@GionaGranchelli

Copy link
Copy Markdown
Owner Author

Superseded by #465. This branch was cut from 42d9d948 (the pre-#463 base). Because #463 was squash-merged, its commits are not ancestors of the new base, so GitHub rendered this PR as a 5-file diff that appeared to re-apply G5c's test and docs.

No content was wrong — the G5c content in this branch is byte-identical to what #463 already merged — but the scope was misleading, and a misleading scope is a custody defect of exactly the kind this track blocks on.

#465 carries the identical artifacts (+425, two files) on a branch cut directly from cd46f176, so its diff is exactly the two G5d documents.

@GionaGranchelli

Copy link
Copy Markdown
Owner Author

Closed as superseded: branch cut from the pre-#463 base, so the diff misrendered. Identical artifacts are in #465, cut from cd46f17.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants