Derive the source census from tracked Git paths - #18
Conversation
|
Reviewer: please run the full code-review and gap-analysis cycle at exact head This closes the five nonblocking residuals recorded from PR #14: Git-derived tracked population, a separate nonignored-untracked scan, an ignored proptest-regression control, explicit root and per-area populations, self-locating census failures, and corrected successor/scenario-label prose. Please specifically scrutinize whether the Git ceiling makes both the scratch-repository positive control and true non-repository refusal falsifiable, whether ignored generated files are excluded without hiding ordinary untracked sources, and whether the per-area counts reject compensating cross-area swaps. Full local |
Independent review — PR #18, "Derive the source census from tracked Git paths"Head reviewed: This was a read-only review. No builds, no ❌ BLOCKED — one highTS18-01: the census reaches 42 of 107 tracked paths, while Everything else is clearing work. 20 findings: 1 high, 8 medium, 11 low. The four residuals other than TS14R3-02 are closed, and the central mechanism — the thing this PR exists to change — is correct. What I verified myself before accepting either laneI reimplemented
This is the first head in this family where I have not had to correct a census figure. Across four rounds and three repositories the stated population was wrong in tl-rewrite twice, in tl-mltl once and in tl-syntax once; here the total, the per-area breakdown and the exclusion set all reconcile against the index. Two structural points deserve credit, both confirmed by that recomputation:
I also confirmed the two claims the lanes turn on. Code and test laneScope: Findings
TS18-01 (high). TS18-02 (medium). TS18-03 (medium). TS18-04 (medium). The scope predicate accepts a root-level path only by exact name ( The author's three scrutiny requests1. "whether the Git ceiling makes both the scratch-repository positive control and true non-repository refusal falsifiable" — No; the ceiling makes neither falsifiable, though both controls are falsifiable with respect to the refusal itself. See TS18-02 for the mechanism and the two read-only probes. To separate the two claims cleanly: the refusal is properly pinned — replace the 2. "whether ignored generated files are excluded without hiding ordinary untracked sources" — Yes. This is the strongest part of the change and the companion control the residual asked for is present. The fixture at 3. "whether the per-area counts reject compensating cross-area swaps" — Yes for cross-area; no for within-area, and no for anything involving the 65 out-of-scope tracked paths. TS14R3-04, self-locating failurePartly closed. The area assertion at What holds
Specification, records and gap laneReviewed read-only at head Residual adjudication
Findings
TS18-R01 (medium). TS18-R02 (medium). TS18-R03 (medium). TS18-R04 (medium). The new TS18-R05 (medium). What holds
Claims I could not verify. "full local Gap analysis
|
|
Reviewer: please re-run the full code-review and gap-analysis cycle at exact head SR-020 maps all 20 findings from the review at Key changes to scrutinize:
Full local |
Independent re-review — PR #18, "Derive the source census from tracked Git paths"Head reviewed: This was a read-only review. No builds, no ✅ MERGEABLEThe round-1 high is closed. All 20 findings from the review at What I verified myself before accepting either laneThe round-1 high, TS18-01, was that the census reached 42 of 107 tracked paths behind a directory-and-extension allowlist while The allowlist is gone.
Every one of the 25 paths I named is now in scope: all 14 I also confirmed the two records claims the lanes turn on. The two things I would still fixNeither blocks, and both are the same shape: a control that cannot fail, described as one that can.
Code and test laneScope: Round-1 code findings adjudication
New findings
TS18R2-01 (medium). The forbidden-reference scan runs on the live tree in exactly one place, TS18R2-02 (medium). At What holds
Specification, records and gap laneHead reviewed: This was a read-only review. No builds, no Round-1 records findings adjudication
Round-1 records lane: 0 high, 5 medium, 6 low → 0 open, 8 fixed, 2 deferred-tracked, 1 partial/deferred-tracked. The two flagged as most important (TS14R3-02 / New findings
TS18R2-R01 (medium). TS18R2-R02 (medium). The PR note asserts the head gate passed "outside the documented Node child-process sandbox", and What holds
Claims I could not verify. "Full local Gap analysis
|
Closes #17
Summary
Independent review response
99dde202Verification
make ci CARGO_TARGET_DIR=target/cargo-reviewpassed at exact head5861efce28c65d9fb72207f638317cba49878196outside the documented Node child-process sandboxSUITE-008 declares the existing local Rust test command and Git premise, but is explicitly not a structured producer or Quoin attestation. This change adds no local runner, evidence collector, Make parser, evidence envelope, identity registry, or retention layer.