From 9c8a8f168574a1cd72cb8a0c26067ba9e4dbaae9 Mon Sep 17 00:00:00 2001 From: Simon Keimer Date: Sat, 19 Sep 2026 14:21:43 +0200 Subject: [PATCH] fix(trace): REQ-PTT-04 was born scope-bound; bind its CLI half (#1405) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit One `// VERIFIES: REQ-PTT-04` in openpulse-cli. Reachability 281/363 (0.77) -> 363/363 (1.00). I INTRODUCED THE DEFECT I HAD JUST BEEN FIXING. REQ-PTT-04 shipped yesterday (#1412) with three bindings — ardop, kiss, daemon — none of whose test binaries can link openpulse-cli. So cli/radio.rs and cli/commands/calibrate.rs, 82 of its 363 mutants, were unreachable by construction: a fresh instance of #1405, created in the same week #1405 was filed. Re-measuring the enforced set after the merge is what surfaced it, not review. The binding target was checked for vacuity first: the_cli_never_keys_the_rig_by_ hand is a source scan over include_str!'d CLI sources, and its sibling the_scan_actually_covers_the_files_that_key validates that scan against a PLANTED bare `.assert_ptt(` call, so it cannot go vacuous. It is also the acceptance method REQ-PTT-04's own registered text names. A LIMIT OF THE METRIC, demonstrated by this very change: the ratio reached 1.00 while the kill-power of those 82 mutants did not meaningfully change. A source scan makes mutants LINKABLE, not KILLABLE — a mutation of calibrate.rs's logic does not introduce a bare `.assert_ptt(`. Reachability is necessary for a mutation verdict to mean anything and not sufficient for it to be strong; #1405's check reports the necessary condition only and should say so. Implements: REQ-PTT-04 Review: none — applying #1405's own triage pattern to a requirement added two commits ago; the binding target was read and its planted-violation control confirmed before binding. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_0188ATCj6DZ9aRVQ2vSirua6 --- .../tests/ptt_goes_through_shared_ptt.rs | 13 ++++++++++ docs/dev/project/traceability.md | 26 +++++++++++++++++++ 2 files changed, 39 insertions(+) diff --git a/crates/openpulse-cli/tests/ptt_goes_through_shared_ptt.rs b/crates/openpulse-cli/tests/ptt_goes_through_shared_ptt.rs index f2f68990..c3842542 100644 --- a/crates/openpulse-cli/tests/ptt_goes_through_shared_ptt.rs +++ b/crates/openpulse-cli/tests/ptt_goes_through_shared_ptt.rs @@ -60,6 +60,19 @@ fn hits(src: &str) -> Vec { .collect() } +// VERIFIES: REQ-PTT-04 +// +// The CLI half of the requirement, and the reason it needs its own binding: REQ-PTT-04's other +// three bindings live in ardop/kiss/daemon, none of whose test binaries can link `openpulse-cli`, +// so `cli/radio.rs` and `cli/commands/calibrate.rs` — 82 of the requirement's 363 mutants — were +// unreachable by construction (#1405). +// +// This is the acceptance method the requirement's own text names — a source scan requiring every +// keying site to sit inside the helper, validated against a planted bare call by the sibling test +// below. Note what that does and does not buy: it makes those mutants LINKABLE, not killable. A +// mutation of `calibrate.rs`'s logic does not introduce a bare `.assert_ptt(`, so the scan will not +// catch it. Reachability is necessary for a mutation verdict to mean anything and is not +// sufficient for it to be strong. #[test] fn the_cli_never_keys_the_rig_by_hand() { let files = sources(); diff --git a/docs/dev/project/traceability.md b/docs/dev/project/traceability.md index b8362bfa..a2f4dc7f 100644 --- a/docs/dev/project/traceability.md +++ b/docs/dev/project/traceability.md @@ -15,6 +15,32 @@ and the actually-observed results per change. --- +## 2026-09-19 — REQ-PTT-04 was born scope-bound; bound its CLI half; #1405 + +**Change.** One `// VERIFIES: REQ-PTT-04` in `openpulse-cli`. Reachability **281/363 (0.77) -> +363/363 (1.00)**. + +**I introduced the defect I had just been fixing.** REQ-PTT-04 shipped yesterday (#1412) with three +bindings — ardop, kiss, daemon — none of whose test binaries can link `openpulse-cli`. So +`cli/radio.rs` and `cli/commands/calibrate.rs`, 82 of its 363 mutants, were unreachable by +construction: a fresh instance of #1405, created in the same week #1405 was filed. Re-measuring the +enforced set after the merge is what surfaced it, not review. + +**The binding target was checked for vacuity first**, per the rule that caught +`tampered_fragment_fails_verification`: `the_cli_never_keys_the_rig_by_hand` is a source scan over +`include_str!`'d CLI sources, and its sibling `the_scan_actually_covers_the_files_that_key` +validates that scan against a **planted** bare `.assert_ptt(` call — so it cannot go vacuous. It is +also literally the acceptance method REQ-PTT-04's own registered text names. + +**A limit of the reachability metric, worth recording because this change demonstrates it.** The +ratio went to 1.00, and the kill-power of those 82 mutants did not meaningfully change: a source +scan makes mutants **linkable**, not **killable** — a mutation of `calibrate.rs`'s logic does not +introduce a bare `.assert_ptt(`, so the scan will not catch it. **Reachability is necessary for a +mutation verdict to mean anything, and not sufficient for it to be strong.** #1405's check, if it is +ever built, reports the necessary condition only, and should say so. + +--- + ## 2026-09-19 — a gate verdict from ANY commit counted as run-status evidence; #1413 **Change.** `trace.py` compares the stored verdict's `commit` against HEAD, degrading to the same