Repository navigation
Commit 03c1b0f
docs(audits): census of same-key/per-row-value beforeUpdate rewrites — zero in-repo, guard precision 0/5 (#15301)
* wip(census): static AST enumerator for beforeUpdate handlers [#14744]
* wip(census): seed-propagating classifier + two-directional self-test [#14744]
* wip(census): runtime behavioural probe over the real engine [#14744]
* docs(audits): census of same-key/per-row-value beforeUpdate rewrites [#14744]
Measurement only — implements no guard, changes no write shape, opens no ADR,
and edits neither engine.ts nor multi-update-hook-key-divergence.ts.
Two independent instruments, each with a firing positive control:
- scripts/audits/14744-before-update-per-row-value-census.mjs — static AST
enumeration and taint classification of every in-repo beforeUpdate
registration (--self-test: 10/10, both directions).
- scripts/audits/14744-before-update-per-row-value-probe.mjs — runtime
behavioural probe dispatching the real handlers per row of a genuine
multi: true update on the real engine, reading the actual SET clause.
Result: the in-repo population of same-key / per-row-VALUE rewrites is ZERO
across 23 production registration sites. The candidate provenance guard fires
on 5 of them and none is an instance (precision 0/5): every in-repo pre-image
read decides WHETHER to write, not WHAT to write, and that is already caught by
#14099's key-set refusal.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ARYe3yQTQCUFm5qPYNgKaJ
* tooling(pm): register the census self-test in COMPOUND_ANCHOR_LEDGER
`scripts/audits/14744-before-update-per-row-value-census.mjs` declares
`runSelfTest`, whose name the compound self-test anchor matches, so the
ledger owed it a row and `check:pm-dispatch-gates` was red without one.
Classified `accidental: false` — it is a genuine self-test battery, on the
same evidence the ledger's own docblock uses for the two existing
`runSelfTest` rows it calls genuine: not exported, reached only from the
file's `--self-test` guard, and it spawns no other script's self-test. Its
inline fixture sources SHOULD be masked away, which is what that
classification buys.
⛔ The self-test is not renamed or removed to dodge the anchor — the
ledger's docblock refuses that repair explicitly, and this particular
self-test is the census's own evidence (10/10 both directions, carrying the
firing positive control).
Part of #14744
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ARYe3yQTQCUFm5qPYNgKaJ
---------
Co-authored-by: Claude <noreply@anthropic.com>1 parent 8b54e9d commit 03c1b0f
4 files changed
Lines changed: 1405 additions & 0 deletions
0 commit comments