Skip to content

0.7.1g1G5d: close the final NO_COVERAGE cohort (4 UNREACHABLE) - #465

Merged
GionaGranchelli merged 1 commit into
epic/0.7.1-control-plane-authorityfrom
task/0.7.1g1G5d-no-coverage-reachability
Sep 30, 2026
Merged

GionaGranchelli merged 1 commit into
epic/0.7.1-control-plane-authorityfrom
task/0.7.1g1G5d-no-coverage-reachability

Conversation

@GionaGranchelli

Copy link
Copy Markdown
Owner

Base

cd46f176b20ef7e0e0b2b0e251569214dfc90619 — the squash merge of #463. Worktree branched directly from it, clean tree.

Scope

Exactly the four frozen NO_COVERAGE identities. No widening, no substitution, no production change.

Endpoint

G5D COMPLETE — FINAL G5 NO_COVERAGE COHORT CLOSED. Final classification: 4 UNREACHABLE, 0 KILLED, 0 EQUIVALENT, 0 TOOLING_LIMITATION, 0 UNDETERMINED. Parent accounting: 52 = 36 (G5b) + 12 (G5c) + 4 (G5d). G5 remainder: 0.

identity owner mutator block/index PC mutated instruction
564517b2fdab suspendToolExecution VoidMethodCall 13/96 pc194 ResultKt.throwOnFailure (resumed path)
66c311cf4f0a suspendToolExecution NullReturnVals 12/78 pc163 areturn of COROUTINE_SUSPENDED (suspend exit)
5a7edac3a982 requestApproval VoidMethodCall 11/92 pc204 ResultKt.throwOnFailure (resumed path)
e52f1c1f6570 requestApproval NullReturnVals 10/72 pc164 areturn of COROUTINE_SUSPENDED (suspend exit)

Mutator naming: the brief calls the two "NRV" mutants NonReturningVoidMethodCall; the frozen manifest records returns.NullReturnValsMutator ("replaced return value with null"). The frozen identities are authoritative — a label discrepancy, not an identity discrepancy.

Phase A — exact mapping method

PIT reports no bytecode offsets, and reconstructing its block/index counter matched only 4 of 36 calibration identities, so that approach was abandoned rather than tuned until it fit. Each identity is instead bracketed: pitBlock is monotone in pc within a method (verified), and both methods carry in-method calibration points with known pc and known PIT coordinates from the committed G5b/G5c manifests. Every target's block brackets a pc window containing exactly one candidate of the mutated kind.

The source line is useless here and was not relied on: line 142 is the suspendToolExecution function header and line 73 the requestApproval header, so every state-machine instruction inherits it.

Reachability — UNREACHABLE, structurally

All four sit on the suspension protocol of two calls: resolveGovernedSuspension() (line 145) and resolveGovernedIdentity(workflowRunId) (line 82). Neither callee can suspend:

  • resolveGovernedSuspension: 50 instructions, 0 getCOROUTINE_SUSPENDED, 0 if_acmpne
  • resolveGovernedIdentity-jFE5hGw: 32 instructions, 0 getCOROUTINE_SUSPENDED, 0 if_acmpne; invokes only Continuation.getContext, own-package accessors/getters, Intrinsics.areEqual, concat, an exception ctor
  • GovernedRunScope.resolve(context) is a plain non-suspend function

A suspend function returns COROUTINE_SUSPENDED only through the sentinel comparison emitted after a call. With none emitted and no suspending callee, both resolvers always return directly. So the caller's sentinel test is always false and the COROUTINE_SUSPENDED exit cannot execute; and the resumed continuation can only be constructed by a real suspension at that call, so the resumed-path throwOnFailure cannot execute. Nothing else reaches them: no branch or switch entry in either method targets pc194 or pc204.

That is control-flow dominance plus callee analysis — not "I could not find a test".

Test evidence

No tests added — tests are permitted only for proven-reachable identities. Making these execute would require changing production semantics or fabricating a coroutine state the runtime cannot produce. A test existing only to move PIT's coverage counter is what this task forbids.

Phase E — pairs

Both pairs are one compiler-generated suspension: suspendToolExecution block 12 (exit) / block 13 (resumed unwrap); requestApproval block 10 / block 11. Same construct, different instructions, neither dominating. Whether one test would cover both is moot — neither member is reachable. Block/index adjacency was not used as evidence of equivalence.

Diff scope

Tests: none. Production: none. Docs: this report + the four-identity manifest. The measurement narrowing never landed.

Regression gate

Identity-exact campaign running from a fresh worktree at cd46f176 with the proven family-only narrowing; reconciliation (4/4 accounted, 0 identity loss, 0 gain/substitution, 0 new timeouts, 0 regressions of previously KILLED identities, no widening) is appended to the report and manifest on completion.

Limits

UNREACHABLE is a statement about this compiled artifact at this base: if either resolver ever gains a suspension point, these instructions become live and these identities must be re-adjudicated rather than inherited.

Verification: 4/4 mapped with non-null PCs · no churn · spotlessCheck verifyStaticAnalysis verifyChangePolicy -PchangePolicyBase=cd46f176… BUILD SUCCESSFUL. Exact-head CI is the final authority. Not self-merged.

The four frozen NO_COVERAGE identities are all on the suspension protocol of
resolveGovernedSuspension() / resolveGovernedIdentity(), neither of which can
suspend (0 getCOROUTINE_SUSPENDED, 0 if_acmpne), so the COROUTINE_SUSPENDED exit
and the resumed-path throwOnFailure can never execute. 4/4 mapped to exact
bytecode PCs; no tests added; no production, authority or test changes.

Regression gate: identity-exact campaign at cd46f17 (throwaway 56364ae3) -
918/918 identities, 0 status movements, 0 KILLED regressions, 0 new timeouts.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The substance is an unverifiable-from-source bytecode-reachability adjudication (exact PCs, PIT block/index, UNREACHABLE conclusion) that forms mutation-governance audit authority and warrants human/tooling confirmation.

Review effort: Balanced
Findings: None

What changed in this PR

This documentation-only PR closes the final G5 NO_COVERAGE cohort (task TASK-0.7.1g1G5d) by classifying the four remaining frozen mutation-testing identities as UNREACHABLE. It adds an analysis report and a machine-readable manifest that together record the bytecode-exact mapping (Phase A), the control-flow reachability argument (Phase C), the pair analysis (Phase E), and the regression-campaign reconciliation. No production or test code changes; the artifacts extend the mutation-governance audit trail described in AGENTS.md.

Changes:

  • Adds a reachability report arguing all four identities are UNREACHABLE because both suspension-protocol resolvers (resolveGovernedSuspension, resolveGovernedIdentity) contain no suspension point, so the COROUTINE_SUSPENDED exits and resumed-path throwOnFailure instructions cannot execute.
  • Adds a four-identity JSON manifest with per-identity bytecode PCs, PIT block/index, mutator, evidence, and a regression-campaign reconciliation (918 population, 0 status movements, 0 regressions).
  • Records parent accounting (52 = 36 G5b + 12 G5c + 4 G5d; remainder 0) and documents a mutator label discrepancy (brief's "NonReturningVoidMethodCall" vs frozen NullReturnValsMutator).
File Description
docs/​roadmap/​0.7.0/​TASK-0.7.1g1G5d-NO-COVERAGE-REACHABILITY.md Narrative report: mapping method, per-identity table, UNREACHABLE reasoning, pair analysis, regression gate, and limits.
docs/​roadmap/​0.7.0/​TASK-0.7.1g1G5d-NO-COVERAGE-4-MANIFEST.json Structured manifest of the four identities with PCs, calibration windows, classification proof, totals, and regression reconciliation.

I verified that the checkable claims are accurate: the JSON is well-formed; population and duration arithmetic (662+132+62+62=918; 17m13s=1033s) and parent accounting are internally consistent; markdown, JSON, and the PR description agree on identities/PCs/block-index; and the cited source coordinates match production at HEAD (suspendToolExecution at line 142, resolveGovernedSuspension() at 145, requestApproval at 73, resolveGovernedIdentity at 82, and GovernedRunScope.resolve is non-suspend at tramai-core/.../GovernedRunScope.kt:64). I found no objective issues to comment on.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@GionaGranchelli
GionaGranchelli merged commit 284faa4 into epic/0.7.1-control-plane-authority Sep 30, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants