0.7.1g1G5d: close the final NO_COVERAGE cohort (4 UNREACHABLE) - #465
Conversation
The four frozen NO_COVERAGE identities are all on the suspension protocol of resolveGovernedSuspension() / resolveGovernedIdentity(), neither of which can suspend (0 getCOROUTINE_SUSPENDED, 0 if_acmpne), so the COROUTINE_SUSPENDED exit and the resumed-path throwOnFailure can never execute. 4/4 mapped to exact bytecode PCs; no tests added; no production, authority or test changes. Regression gate: identity-exact campaign at cd46f17 (throwaway 56364ae3) - 918/918 identities, 0 status movements, 0 KILLED regressions, 0 new timeouts.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The substance is an unverifiable-from-source bytecode-reachability adjudication (exact PCs, PIT block/index, UNREACHABLE conclusion) that forms mutation-governance audit authority and warrants human/tooling confirmation.
Review effort: Balanced
Findings: None
What changed in this PR
This documentation-only PR closes the final G5 NO_COVERAGE cohort (task TASK-0.7.1g1G5d) by classifying the four remaining frozen mutation-testing identities as UNREACHABLE. It adds an analysis report and a machine-readable manifest that together record the bytecode-exact mapping (Phase A), the control-flow reachability argument (Phase C), the pair analysis (Phase E), and the regression-campaign reconciliation. No production or test code changes; the artifacts extend the mutation-governance audit trail described in AGENTS.md.
Changes:
- Adds a reachability report arguing all four identities are
UNREACHABLEbecause both suspension-protocol resolvers (resolveGovernedSuspension,resolveGovernedIdentity) contain no suspension point, so theCOROUTINE_SUSPENDEDexits and resumed-paththrowOnFailureinstructions cannot execute. - Adds a four-identity JSON manifest with per-identity bytecode PCs, PIT block/index, mutator, evidence, and a regression-campaign reconciliation (918 population, 0 status movements, 0 regressions).
- Records parent accounting (52 = 36 G5b + 12 G5c + 4 G5d; remainder 0) and documents a mutator label discrepancy (brief's "NonReturningVoidMethodCall" vs frozen
NullReturnValsMutator).
| File | Description |
|---|---|
| docs/roadmap/0.7.0/TASK-0.7.1g1G5d-NO-COVERAGE-REACHABILITY.md | Narrative report: mapping method, per-identity table, UNREACHABLE reasoning, pair analysis, regression gate, and limits. |
| docs/roadmap/0.7.0/TASK-0.7.1g1G5d-NO-COVERAGE-4-MANIFEST.json | Structured manifest of the four identities with PCs, calibration windows, classification proof, totals, and regression reconciliation. |
I verified that the checkable claims are accurate: the JSON is well-formed; population and duration arithmetic (662+132+62+62=918; 17m13s=1033s) and parent accounting are internally consistent; markdown, JSON, and the PR description agree on identities/PCs/block-index; and the cited source coordinates match production at HEAD (suspendToolExecution at line 142, resolveGovernedSuspension() at 145, requestApproval at 73, resolveGovernedIdentity at 82, and GovernedRunScope.resolve is non-suspend at tramai-core/.../GovernedRunScope.kt:64). I found no objective issues to comment on.
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
284faa4
into
epic/0.7.1-control-plane-authority
Base
cd46f176b20ef7e0e0b2b0e251569214dfc90619— the squash merge of #463. Worktree branched directly from it, clean tree.Scope
Exactly the four frozen NO_COVERAGE identities. No widening, no substitution, no production change.
Endpoint
G5D COMPLETE — FINAL G5 NO_COVERAGE COHORT CLOSED. Final classification: 4 UNREACHABLE, 0 KILLED, 0 EQUIVALENT, 0 TOOLING_LIMITATION, 0 UNDETERMINED. Parent accounting: 52 = 36 (G5b) + 12 (G5c) + 4 (G5d). G5 remainder: 0.
564517b2fdabResultKt.throwOnFailure(resumed path)66c311cf4f0aareturnof COROUTINE_SUSPENDED (suspend exit)5a7edac3a982ResultKt.throwOnFailure(resumed path)e52f1c1f6570areturnof COROUTINE_SUSPENDED (suspend exit)Mutator naming: the brief calls the two "NRV" mutants
NonReturningVoidMethodCall; the frozen manifest recordsreturns.NullReturnValsMutator("replaced return value with null"). The frozen identities are authoritative — a label discrepancy, not an identity discrepancy.Phase A — exact mapping method
PIT reports no bytecode offsets, and reconstructing its block/index counter matched only 4 of 36 calibration identities, so that approach was abandoned rather than tuned until it fit. Each identity is instead bracketed:
pitBlockis monotone in pc within a method (verified), and both methods carry in-method calibration points with known pc and known PIT coordinates from the committed G5b/G5c manifests. Every target's block brackets a pc window containing exactly one candidate of the mutated kind.The source line is useless here and was not relied on: line 142 is the
suspendToolExecutionfunction header and line 73 therequestApprovalheader, so every state-machine instruction inherits it.Reachability — UNREACHABLE, structurally
All four sit on the suspension protocol of two calls:
resolveGovernedSuspension()(line 145) andresolveGovernedIdentity(workflowRunId)(line 82). Neither callee can suspend:resolveGovernedSuspension: 50 instructions, 0getCOROUTINE_SUSPENDED, 0if_acmpneresolveGovernedIdentity-jFE5hGw: 32 instructions, 0getCOROUTINE_SUSPENDED, 0if_acmpne; invokes onlyContinuation.getContext, own-package accessors/getters,Intrinsics.areEqual, concat, an exception ctorGovernedRunScope.resolve(context)is a plain non-suspend functionA suspend function returns
COROUTINE_SUSPENDEDonly through the sentinel comparison emitted after a call. With none emitted and no suspending callee, both resolvers always return directly. So the caller's sentinel test is always false and theCOROUTINE_SUSPENDEDexit cannot execute; and the resumed continuation can only be constructed by a real suspension at that call, so the resumed-paththrowOnFailurecannot execute. Nothing else reaches them: no branch or switch entry in either method targets pc194 or pc204.That is control-flow dominance plus callee analysis — not "I could not find a test".
Test evidence
No tests added — tests are permitted only for proven-reachable identities. Making these execute would require changing production semantics or fabricating a coroutine state the runtime cannot produce. A test existing only to move PIT's coverage counter is what this task forbids.
Phase E — pairs
Both pairs are one compiler-generated suspension:
suspendToolExecutionblock 12 (exit) / block 13 (resumed unwrap);requestApprovalblock 10 / block 11. Same construct, different instructions, neither dominating. Whether one test would cover both is moot — neither member is reachable. Block/index adjacency was not used as evidence of equivalence.Diff scope
Tests: none. Production: none. Docs: this report + the four-identity manifest. The measurement narrowing never landed.
Regression gate
Identity-exact campaign running from a fresh worktree at
cd46f176with the proven family-only narrowing; reconciliation (4/4 accounted, 0 identity loss, 0 gain/substitution, 0 new timeouts, 0 regressions of previously KILLED identities, no widening) is appended to the report and manifest on completion.Limits
UNREACHABLEis a statement about this compiled artifact at this base: if either resolver ever gains a suspension point, these instructions become live and these identities must be re-adjudicated rather than inherited.Verification: 4/4 mapped with non-null PCs · no churn ·
spotlessCheck verifyStaticAnalysis verifyChangePolicy -PchangePolicyBase=cd46f176…BUILD SUCCESSFUL. Exact-head CI is the final authority. Not self-merged.