From 1382e6dafa33de6871799ccb652feb441124e3a6 Mon Sep 17 00:00:00 2001 From: Alec Wenzowski Date: Tue, 25 Aug 2026 00:04:30 +0000 Subject: [PATCH] ci(gates): two mutation rows that have never discriminated anything MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `mise run mutant` names both, and neither gate's logic or suite changes — only the declarations were wrong. ntia-check/receipt-failure-decides-conformance was UNAPPLIABLE. The pattern escaped the braces as `\{ … \}`, which is the BRE interval quantifier, so sed rejected the whole expression (`Invalid content of \{\}`) and the mutation never ran. Literal braces are the unescaped ones. This is the row with the most to lose: its own comment says the mutation "restores the shipped defect — a failed record deciding conformance — which is the false verdict CI reported", so the one row guarding a bug that already reached CI was inert. release-tracking-check/refresh-order-ignored NAMED NO CASE. Field 3 is a bats --filter, a case-sensitive regex, not a description. It said "a tag refresh AFTER the resolver does not satisfy the rule"; the case is "a tag refresh after the resolver is a violation", so `AFTER` selected nothing and the mutation was never judged. The suite already carried the right case. Both spellings now carry the reason beside them, because the unescaped braces read like a typo and tidying them back is how this recurs. This is CLOUD-941's class on two gates it did not cover. It can recur because `mutant-census` checks that declarations EXIST and `mutant` checks that they DISCRIMINATE, and only the first is on the landing path (hk.pkl:239-244) — so a broken declaration reaches main and stays until someone runs `mutant` by hand. Verified: 255 declared mutations across 111 gates, every one caught, exit 0. Closes CLOUD-1034 --- mise-tasks/ntia-check.sh | 6 +++++- mise-tasks/release-tracking-check.sh | 6 +++++- 2 files changed, 10 insertions(+), 2 deletions(-) diff --git a/mise-tasks/ntia-check.sh b/mise-tasks/ntia-check.sh index 4d63184f8..650763366 100755 --- a/mise-tasks/ntia-check.sh +++ b/mise-tasks/ntia-check.sh @@ -62,7 +62,11 @@ #MUTANT precondition-guesses-an-absent-spec|s/^\tif \[\[ -z "\$doc_version" \]\]; then$/\tif false; then/|a document declaring no spdxVersion is could-not-look, never a pass # And the receipt's demotion to advisory. The mutation restores the shipped defect # — a failed record deciding conformance — which is the false verdict CI reported. -#MUTANT receipt-failure-decides-conformance|s@^\techo "ntia-check: \$\{spdx##\*/\} conforms, but the replay receipt.*$@\texit 1@|a receipt that cannot be written is reported, never a nonconformance +# The braces are LITERAL and therefore UNESCAPED (CLOUD-1034). `\{ … \}` is the +# BRE interval quantifier, so the escaped spelling made sed reject the whole +# expression — `Invalid content of \{\}` — and this row never applied at all, on +# the one mutation guarding a defect that already reached CI. +#MUTANT receipt-failure-decides-conformance|s@^\techo "ntia-check: \${spdx##\*/} conforms, but the replay receipt.*$@\texit 1@|a receipt that cannot be written is reported, never a nonconformance set -euo pipefail # Resolved BEFORE the cd: `$0` may be relative, and moving first would leave this diff --git a/mise-tasks/release-tracking-check.sh b/mise-tasks/release-tracking-check.sh index acdf0f3af..602189bc0 100755 --- a/mise-tasks/release-tracking-check.sh +++ b/mise-tasks/release-tracking-check.sh @@ -90,7 +90,11 @@ # The ORDER is the whole of the second defect. Drop the comparison and a refresh # placed AFTER the resolver satisfies the rule — which is the workflow that ran 32 # times and recorded nothing, wearing a passing gate. -#MUTANT refresh-order-ignored|s/\[\[ "\$refresh_line" -lt "\$resolver_line" \]\]/true/|a tag refresh AFTER the resolver does not satisfy the rule +# Field 3 is a bats --filter, a case-sensitive regex, NOT a description +# (CLOUD-1034). It read "a tag refresh AFTER the resolver does not satisfy the +# rule", which matches no case — the suite's is "a tag refresh after the resolver +# is a violation" — so this row selected nothing and judged nothing. +#MUTANT refresh-order-ignored|s/\[\[ "\$refresh_line" -lt "\$resolver_line" \]\]/true/|a tag refresh after the resolver set -euo pipefail