Five role-model comments describe the pre-CB-501 rule, and two of them say an unconfigured pane is the primary #759
Open
opened 2026-10-05 10:12:17 +02:00 by ltms
·
3 comments
No Branch/Tag Specified
main
worker/759-authz-comment-and-role-list-e3f0e5-5
worker/756-758-observer-pane-discovery-7e6ffd-1
worker/759-role-model-comments-5d8409-3
worker/743-pane-discovery-ad5b75-5
worker/743-observer-send-4706db-6
worker/749-edge-baseline-28d1a0-3
worker/748-dead-comment-refs-f42ac5-4
worker/737-9c61d3-4
worker/737-a263f3-3
worker/737-20d1d9-1
worker/737-b038f7-2
worker/726-unit2-75cb13-4
worker/737-owner-key-ff061f-10
worker/736-presence-forget-f35144-9
worker/705-observer-14c258-6
worker/722-024c34-5
worker/726-ea34a0-2
worker/726-10cbf0-1
worker/729-5961c6-3
worker/727-ee14ed-3
worker/719-bdd95e-4
worker/702-4f5c7f-2
worker/715-5c43fc-1
worker/721-70f9ea-5
worker/718-99362b-2
worker/task-15-af0d10-12
worker/task-16-50a702-13
worker/task-12-4d0479-9
worker/task-13-823ce2-10
worker/705-ticket-owner-af9928-8
worker/703-list-collaborators-9c06c2-7
worker/669-example-truth-0b303d-6
worker/669-collab-deliverability-9ba859-3
worker/669-collab-reload-report-2a21bd-4
worker/669-7e80a6-1
worker/669-unit-d-efbbd7-1
worker/669-1b786a-1
worker/669-1d1d9f-1
worker/692-4afb9d-2
worker/689-02fced-13
worker/693-cf23fa-14
worker/677-fix-lead-collision-f69073-12
worker/638-fix-overmask-dbb1bf-11
worker/675-5b7478-4
worker/669-unit-a-70cc8f-3
worker/677-8cdaaf-5
worker/638-a7b391-1
worker/683-4536d6-2
worker/651-a75bbe-8
worker/680-20607d-7
worker/664-c12e95-3
worker/668-08534d-4
worker/672-0f2469-2
worker/670-7d1022-1
worker/661-ac7c28-2
worker/664-37fb9b-3
worker/663-remove-3arg-read-3f6783-1
worker/659-remove-dead-backcompat-ba5e6f-1
worker/637-revision-60a488-23
worker/656-redact-regression-tests-892903-19
worker/637-context-gauge-threshold-466eb5-16
worker/639-redact-line-numbers-de4ac4-17
worker/641-set-reformat-guard-6f96a4-18
worker/642-herdr-guard-scope-5de0e4-15
worker/650-javadoc-scope-95f3b3-14
worker/612-01e9f7-13
worker/612-a-r4-quarantine-outage-7ab0e8-5
worker/612-a-r9-r11-capacity-coverage-peers-cfcc79-7
worker/612-a-r10-loophealth-ccc872-8
worker/612-a-r12-turnregistrar-9e3bb7-9
worker/612-a-r5-leadconfigdir-9e70cf-6
lead/config-edit-redact-anchor-wording
worker/config-edit-seam-ca8dc1-1
worker/612-r67-630-lifecycle-290b8d-3
worker/629-625-ports-seams-da7d5d-4
worker/612-r12-exhaustion-f37cd7-1
worker/612-r38-amqp-24b083-2
worker/fleetd-612-unita-87807e-1
worker/612-b3-mcpwirings-da2b58-3
worker/612-b2-cb185-176d3a-2
worker/612-b1-completion-457459-1
worker/612-agaps-73a926-2
worker/608-sleeps-3a64ff-3
worker/621-b4520b-1
worker/618-b83894-2
worker/fleetd-615-e05481-5
worker/lead-autocompact-5f1ab2-3
worker/fleetd-613-f85deb-3
worker/fleetd-608-flaky-nudge-test-d0c2d1-3
worker/lead-context-gauge-ad404f-1
worker/gauge-wiring-9158c1-4
worker/redeploy-slowstart-ead0e5-5
worker/charter-bytes-13668c-6
worker/rollover-outcome-291483-2
worker/589-f64303-2
worker/593-1a8025-5
worker/589-fcd2aa-1
worker/568-9fdaa2-3
worker/571-attempted-outcome-5739f7-2
worker/581-completionresolver-cas-sites-0542b7-6
worker/562-loop-health-wiring-test-99611c-5
worker/562-surface-loop-health-7df5cc-4
worker/575-waiter-cleanup-sites-62ad80-1
worker/572-answer-lock-release-46a9ae-5
worker/567-probe-channel-leak-a38fc5-6
worker/551-record-before-send-7cbf56-1
worker/561-listener-fanout-survives-a-throw-61d538-2
worker/555-redeploy-main-flow-seam-65c2f5-2
worker/556-injector-owns-registration-e027a5-1
worker/552-post-restart-mktemp-abort-bc2672-4
worker/553-onstatus-completion-leak-0da881-2
worker/550-shasum-linux-196132-1
worker/538-loop-dies-on-error-4a5eeb-6
worker/426-health-coverage-ef1fd4-4
worker/504-failed-reported-clean-3cfd66-3
worker/537-capturedlog-close-e4c437-2
worker/459-broken-link-targets-cadc17-5
worker/535-appender-leak-fe74c1-1
worker/512-part2-shutdown-detection-434701-9
worker/529-logger-level-sweep-2a5533-8
worker/528-drain-gate-call-site-5de83d-7
charter/forge-mcp-vs-token
worker/521-swap-guard-unpinned-28e931-5
worker/519-probe-test-harness-d25ab8-4
worker/525-logger-level-leak-1b4eb0-6
worker/518-fleetmcp-resolver-wiring-8ef96c-1
worker/512-drain-complete-line-7edd71-3
worker/517-abort-branch-and-jar-id-41b641-2
worker/500-9e52c9-3
worker/509-4912f4-2
worker/511-9a4b23-1
worker/493-479f45-2
worker/505-03f8b2-1
worker/492-followup-detect-unclear
worker/501-a31fa0-7
worker/498-451d1c-5
worker/494-1015ce-2
worker/492-209647-1
worker/489-001902-2
worker/480-relative-handover-path-906323-1
worker/480-b-handover-skill-45bf1f-5
worker/474-followup-source-pin-f54a55-17
worker/474-charter-check-on-reload-f54a55-17
worker/466-quarantine-repeatcount-report
worker/393-opencode-skill-seeding-71854b-13
worker/469-canonical-tool-names-2a472a-16
worker/466-quarantine-escalation-5ae9c1-15
worker/446-hot-exhausted-pattern-0af580-6
worker/464-charter-tool-name-guard-a85635-12
worker/463-listfleet-default-fails-open-f1c76c-11
worker/458-invariant-5-by-purpose-862f9a-10
worker/439-coordinator-row-gate-bc032a-8
worker/449-herdr-protocol-576015-4
worker/450-abstract-spawn-599e1c-5
worker/437-ack-refuses-177d91-1
worker/444-placement-window-feb56a-2
worker/440-helddurable-derived-d462d7-13
worker/425-rework-placement-resolve-c58ba1-9
worker/421-lead-peek-held-msgs-cdbad2-10
worker/435-fixed-policy-cap-fe11de-12
worker/422-gate-state-observability-9e79d6-11
worker/431-memberregistry-live-readers-cdbad2-10
worker/424-architect-slot-hot-038b41-7
worker/422-model-gate-spawn-c29f48-6
worker/425-default-profile-live-f55534-8
worker/415-coverage-wording-2cbf9c-5
worker/416-3ad1da-1
worker/418-588283-3
worker/deterministic-stamp-race-409-3cb7b6-10
worker/armed-reads-live-config-404-ed931f-9
worker/reply-peer-refusal-391-5a34bd-7
worker/models-allowlist-aa9e9b-3
worker/ttl-stamp-race-399-f1122f-8
worker/scrub-receipt-400-316b3e-5
worker/exhaustion-detection-395-105105-6
worker/scrub-abort-394-316b3e-5
fix/scrub-uid-abort
worker/task-scrub-517574-2
worker/t386-clock-bd5b78-4
worker/t384-scrub-813790-5
worker/t381-cc-748314-2
worker/t373-336973-2
worker/t365-3920c5-3
worker/t358-6e989b-1
worker/t355-8b321c-1
worker/fleetd-369-hermetic-git-tests-e8b19a-3
worker/fleetd-368-stale-lead-binding-f5682e-2
worker/fleetd-360-deploy-units-0d3793-1
worker/359-dead-lead-tabs-f1253b-4
worker/362-worktree-skills-c03e51-3
worker/361-coord-visibility-655144-1
362-plugin-visibility-and-drift
worker/errscan-bed2ca-2
worker/amqp-log-identity-bed2ca-2
worker/withdefaults-guard-561704
worker/sleepguard-82076d-1
worker/fd334-9ee1b6-5
worker/fd348-f1ab27-4
worker/fd335-a71c35-1
worker/fd342-174a17-2
worker/fd345-490d0f-3
worker/fleetd-337-5ec7d4-21
worker/fleetd-341-af5a6b-24
worker/fleetd-339-5ca0a2-23
worker/fleetd-338-83a4a1-22
worker/fleetd-333-281f46-18
worker/fleetd-329-11bdbb-16
worker/fleetd-330-2770fb-17
worker/fix-326-50506e-15
worker/fix-324-3e9bbf-14
worker/fix-323-b8287d-13
worker/fix-316b-bd0860-11
worker/fix-318-76ca36-9
worker/fix-317-486aec-8
worker/fix-315-ce47c5-6
worker/fix-307-275890-6
worker/fix-308-b4f664-7
worker/fix-309-ec3939-8
worker/fix-310-7a3974-9
worker/fix-302-52ad0e-9
worker/fix-298-ce1acb-8
worker/fix-297-66bd11-7
worker/fix-296-104622-6
worker/fix-293-bare-closetab-eb22b5-3
worker/fix-280-gone-ask-lapse-bca98e-2
worker/fix-290-reapidle-guard-coverage-9b0dd1-1
worker/fix-285-trust-seed-8f3565-10
worker/fix-284-backend-error-seat-85912c-11
worker/fix-282-chained-ask-e6d0bb-8
worker/fix-283-teardown-leaks-f40dfa-9
worker/fix-281-pin-handler-actions-4921ac-7
worker/audit-rendezvous-lifecycle-d072ae-2
worker/audit-health-placement-1a2476-6
worker/audit-teardown-exits-e207a5-3
worker/audit-launcher-asymmetry-27e370-4
worker/audit-rest-authz-6ca53c-5
worker/investigate-275-abandon-asking-fdef52-8
worker/fix-274-worktree-leak-b0095d-7
worker/fix-273-exhausted-pattern-9665b5-6
worker/fleetd-267-model-check-bd8068-1
worker/fleetd-131-archunit-18b834-7
worker/fleetd-266-sshagent-rename-a014ff-6
worker/fleetd-184-uid-claim-8e1f31-4
worker/fleetd-184-warn-b381ee-10
worker/fleetd-184-docs-be1d12-9
worker/fleetd-257-9bf010-7
worker/fleetd-103-23a113-6
worker/fleetd-247-342356-5
worker/fleetd-116-04dea8-4
worker/fleetd-252-a830e0-3
worker/fleetd-111-7e8673-9
worker/fleetd-155c-f8ef4b-8
worker/fleetd-176-b928ca-3
worker/fleetd-249-7a7878-2
worker/cb248-composition-root-b-9acdf7-15
worker/cb148-envrc-default-fa6c82-12
worker/cb201-unit5-wiring-6c12e6-8
worker/cb241-fallback-echo-1175e9-11
worker/cb149-trust-dialog-2392a5-9
worker/cb134-148-overlay-visible-c9b986-10
worker/cb234-session-id-keyed-04e1fc-1
worker/cb201-unit3-nudge-abdf5c-6
worker/cb201-unit2-policy-c1102c-5
worker/cb201-unit4-outcome-a13bfa-7
worker/cb201-unit1-classifier-91b9b1-4
worker/cb201-227-refine-831980-3
worker/cb175-model-readback-0f085f-1
worker/cb222-charter-tmpdir-17f013-1
worker/cb226-architect-slot-race-cd3aa8-3
worker/cb224-worktree-root-group-024523-2
worker/cb-123-role-demotion-c600f7-2
worker/cb-219-opencode-roots-1f677e-1
worker/cb214-claude-session-id-b9eab4-4
worker/cb213-zdotdir-wrong-process-dd6de4-3
worker/cb211-exhaustion-classification-9546e0-2
worker/cb137-ambiguous-task-4df3d8-4
worker/cb209-agentsessionid-4dfdb6-2
worker/cb185-hostenvnames-2692b5-3
worker/cb206-opencode-sqlite-128718-2
worker/cb185-worktree-group-fc0c99-1
worker/cb-137-ask-ticket-e7760c-2
worker/cb-172-broker-uri-d36ae4-4
worker/cb-175-model-readback-76ead6-3
worker/cb-161-pane-ancestry-293510-1
worker/cb-164-rebase-885863-8
worker/cb-164-empty-scrape-false-success-1a80af-3
fix/cb-197-ticket-ttl-from-completion
worker/cb-189-remote-url-coverage-4692f3-1
worker/cb-185-blockers-027756-4
worker/cb-192-gap-log-11b631-2
worker/cb-633-fix-5f4396-3
worker/cb185-router-d6436d-3
worker/cb185-router-routing-gaps-9e9d33-3
worker/cb185-paneids-992586-2
worker/cb-633-allow-list-union-ed374b-1
worker/cb-157-credential-in-remote-url-496e44-2
worker/cb-641-health-herdr-evidence-8f1f54-6
worker/cb-640-health-msg-evidence-99c9cd-1
worker/cb-642-fleets-status-skill-bbbc40-5
cb-634-ide-mcp
worker/lead-comms-wiring-c014b9-7
worker/lead-mailbox-c19577-6
worker/autocompact-window-82bc2f-5
worker/cb-634-probe-18056f-4
worker/cb635-broker-urienv
worker/cb-632-config-retry-8e0efa-7
lead/cb-622e-claude-md
lead/cb-622-followup
worker/cb-622a-165dff-1
lead/cb-622d-opencode-mount
worker/cb-622b-717c67-2
worker/cb-622c-ab7759-3
worker/cb-617b2-20ca4b-3
worker/cb-617a-5c2f4a-1
worker/cb596-4e49ef-3
worker/cb586-10500c-1
worker/cb-606-b9343a-25
worker/cb604-1445f8-24
worker/cb582-477374-21
worker/cb584-8c2281-22
worker/cb600-e6b9a9-20
worker/cb602-ce257f-19
worker/cb601-b42837-18
worker/cb598-6c7ba7-17
worker/cb599-740fe4-16
worker/cb597-282224-15
worker/cb590fix-185e9a-10
worker/cb528-recovery-race
worker/cb594-96bead-8
worker/cb590-916766-2
worker/cb527-997d99-3
worker/cb592-env-leak-3cbf9c-1
worker/cb588-async-ticket-nudge-3218f7-5
worker/cb578b-9dcb13-6
worker/cb581-d24826-5
worker/m2-u5-ef8c42-15
worker/cb578a-516499-2
worker/cb576-01a04b-17
worker/cb579-lead-tab-acba06-20
worker/cb580-terminal-health-ed6058-21
worker/cb577-f36fdc-18
worker/cb573b-3db06f-16
worker/cb568c-f36fdc-18
worker/cb568-drop-cause-c3ac1c
worker/cb575-cancelled-notification-c3ac1c
worker/m4-sol-a2cbec-3
worker/cb574-async-ask-c3ac1c
worker/cb573-health-model-8ca857-14
worker/cb572-unknown-target-7f2e35-13
worker/u4-700706-9
worker/u3-b9fcb6-6
worker/u2-ef5b68-4
worker/u1-469dce-1-clean
worker/u1-469dce-1
worker/cb-564-health-events-70cf7e-2
worker/cb-565-recycle-drops-role-98e58f-3
worker/cb-563-missing-reply-df2866-1
worker/cb-562-readiness-gate-silent-6c23c9-3
worker/cb-560-architect-presence-da8155-1
worker/cb-561-architect-silent-off-a71cab-2
worker/cb-548-bind-architect-slot-fe1b8c-1
worker/parity-overlay-settings-5fb711-1
secrets-central-store
cb-559-hot-key-correction
cb-557-fleet-role-pools
worker/cb-553-maxload-explicit-spawn-305ee3-6
worker/cb-551-idle-lead-heartbeat-f1633c-1
worker/cb-544-drain-preserves-worktree-925fad-3
worker/cb-552-docs-sync-1cb9cf-4
worker/cb-548-rendezvous-guard-rebased
worker/cb-548-rendezvous-guard-116b53-10
worker/cb-548-authz-v2-586df6-8
worker/cb-548-authz-264363-5
salvage/cb-528b-codex-home
salvage/cb-528a-codex-launcher
CB-518-primary-flow
feature/peer-launcher-spi
cb-103-injector
v1.1.0
v1.0.0
Labels
Clear labels
blocked
needs-live-proof
ready-to-delegate
silent-default
Cannot start until something else lands. The body says what.
Merged and green, but never shown working on the running daemon. Not the same as done.
Scope, files and acceptance criteria are written. A worker can be briefed from the body alone.
A feature that compiles, passes tests, and ships turned off. Nine recurrences and counting.
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: fleet/fleetd#759
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
A
huntersweep for comments that over-claim what their code does. Five findings, all five confirmed by me against the code, not taken on the worker's word. The sweep carried a working positive probe: its pattern matched the known seed atFleetMcp.java:827-832, so a zero elsewhere would have been a real zero.They are one family.
Role.PRIMARYused to be reached by failing every other check — "anything that is not a worker is the primary". CB-501 inverted that, CB-548 added architects, #703 added collaborators and #743 added observers. The code moved each time; these five comments did not.1.
auth/Role.java:15— says an unconfigured pane is the primaryCallerResolver.resolve:300opens withif (c.terminal() != null), and every path inside that block returns: a spawned member, a lead, an architect slot, a collaborator, elsePrincipal.observer(...)at:346. The loopback-trust promotion to primary is at:357, reachable only whenc.terminal() == null.So a loopback caller that is a pane but not a worker is an observer — never the primary. The comment states the opposite, and in the escalation direction: a reader would conclude an unconfigured tab may spawn, stop and drain. Highest severity of the five.
The same class javadoc already describes the inversion correctly two paragraphs up ("
ANONYMOUSis the fallback, andPRIMARYmust be established"). The enum constant's own comment contradicts its class's.2.
mcp/ConnectionIdentity.java:6-10and:89-92— the same wrong rule, second placeThe hunter reported this as a
null-handling inaccuracy. It is more than that. Line 90-92:That parenthesis is finding 1 again, written where a reader of the identity layer will meet it.
resolve:84returnslookup.terminal()for any agent pane herdr maps — a lead's, an architect's, a collaborator's, an observer's. So "not a known on-host worker" does not imply a null terminal, and a null terminal does not imply the primary.The class javadoc at
:6-10carries the same premise ("yielding the caller's workerterminal_id").3.
inject/MemberPresence.java:12-13— presence is not worker-onlyFleetMcp.markTrackedCallerPresent:888:isSpawnedMember()coversWORKERandARCHITECT. So architects and observer panes enrol too.markTrackedCallerPresent's own javadoc states this correctly — "a worker, an architect, or the unconfigured-pane floor" — so the rule is written twice and the two copies disagree.This one is load-bearing right now: #757 is about presence, and anyone reading
MemberPresencefirst would conclude observer panes never enrol, which is the opposite of the mechanism #743 depends on.4.
mcp/FleetMcp.java:524-525—fleet_replyis not worker-onlyAuthz:162iscase REPLY, ASK -> caller.ownsSession(targetSession);, andPrincipal.ownsSession:145isterminal != null && terminal.equals(sessionId). Any peer with a terminal may answer for its own pane.Authz's own comment above that line says so explicitly and names CB-532 as the widening. A reader would wrongly withholdfleet_replyfrom a lead, architect, collaborator or observer that the gate accepts.5.
mcp/FleetMcp.java:2727— thefleet_listtool description omitshunterMemberRoledeclaresARCHITECT, DEV, HUNTER, REVIEWER(peer/MemberRole.java:35-61), the spawn schema accepts hunter, and the row writess.role().wireName(). Lowest harm of the five, but it reaches furthest: this is the live MCP schema, whichCLAUDE.mdnames as the tool reference, so every agent on the bus reads it.The pattern worth naming
Four of the five are one rule written in two places, where one copy was updated and the other was not.
Rolevs its own class javadoc;ConnectionIdentityvsCallerResolver;MemberPresencevsmarkTrackedCallerPresent;FleetMcp:524vsAuthz:155-162. In each pair the copy nearest the enforcing line is right and the distant one is stale.That is exactly what
CLAUDE.md's "one fact, one place" rule predicts, and no build check sees it: rules 1, 2 and 3 check for tickets, dates, length and test-class names, never whether a sentence is true. The honest answer is that this family needs a sweep now and then, not a gate.Sequencing
Findings 4 and 5 are in
FleetMcp.java, which #756/#758 is editing right now. They must wait for that PR to merge, or the two changes collide. Findings 1, 2 and 3 are inRole.java,ConnectionIdentity.javaandMemberPresence.javaand can go immediately.Findings 1–3 are fixed —
mainat39accf7PR #760 plus one follow-up commit of mine.
MVN_EXIT=0, surefire XML sumtests=2137 failures=0 errors=0 skipped=0, same as baremain— the right outcome for a comment-only change. Merged tree hash matched the tree I built, so the tested bytes are the shipped bytes.A fourth copy existed, and my brief missed it
I named two places in
ConnectionIdentityand there were three. TheCallerrecord's own javadoc carried the same claim:The worker found it, left it alone as out of scope, and reported it — which is exactly right. I fixed it in the follow-up commit. So the count for this file was three, not two, and the wrong rule was written in four places overall, not three.
Worth recording why: I built the brief from the hunter's report, and the hunter cited the two spots its pattern matched. I treated its citation list as the extent of the defect instead of as the extent of its search. One grep answers "where did this pattern match", never "where else does this rule appear". For a defect whose whole shape is the same sentence copied around, the enumeration has to be mine and it has to be exhaustive before the brief goes out.
Two more instances, still open
Both in
mcp/ConnectionIdentity.java, both reported by the #760 worker and correctly not touched:Caller#resolved's javadoc — carriesfleetd #317,#305, and a narrative of what drifted and why the method was deliberately not widened for#505. Rule 1 bans tickets and history in comments; that reasoning belongs in the commit message or adocs/page.isLoopback's javadoc — notebook-style: "used to say", a measurement date, and#305 removed the second copy.These are rule-1 violations rather than false statements, so they are lower priority than findings 1–3 were. They are also a judgement call: the
resolved()block explains a real two-states-one-sentinel trap that cost a ticket, and that knowledge is load-bearing. Rule 2's prescription applies — move it todocs/, never delete it. Whoever takes this should propose where it goes rather than cut it.Findings 4 and 5 — unblocked soon
Both are in
FleetMcp.java, which the #756/#758 worker still holds. They land once that PR merges. Finding 5 (fleet_list's tool description omittinghunter) is the one that reaches furthest, sinceCLAUDE.mdnames the live MCP schema as the tool reference.Finding 6 — three
{@link}references point at symbols that do not existFound while reading
HerdrPeerLauncherfor #763. All three are in that one file:{@link #place}place(member in the file{@link #defaultProfileFor}{@link #BLOCKED_GITEA_ACCESS_TOKEN}BLOCKED_CREDENTIAL_SENTINEL; this is its pre-rename nameThis is rule 3's mechanism, one layer out. Rule 3 bans naming a test class in a main-source comment because the name is invisible to the compiler and rots in silence. The same is true of a
{@link #X}to a renamed member:javacnever looks inside a doc comment, andmvn clean installhere does not run the javadoc tool, so all three have compiled green for as long as they have been wrong.#BLOCKED_GITEA_ACCESS_TOKENis the one that actually misleads. Its sentence says the marker "survives the login shell that wipesBLOCKED_GITEA_ACCESS_TOKEN" — but the thing the login shell wipes is the sentinel value, written over the variableGITEA_ACCESS_TOKEN. A reader chasing that link finds nothing and cannot tell which of the two the sentence means.Fix
Point each link at the symbol that exists, or drop the link and name the thing in plain text.
#placeand#defaultProfileForneed a look at what line 595 was trying to say — both names are gone, so the sentence may need rewriting rather than relinking.How I measured it, and the number I nearly published
Worth recording, because my first three attempts all gave a different answer:
NAME,.enum AuthorizationMode { ENFORCED, UNENFORCED }is all on one line. Six of those nine were live symbols.#place, because place is an ordinary English word and appears in the prose of a nearby comment.The answer is 3, from a declaration-shape check run with six controls — three names that must resolve (
MEMBER_MARKER,BLOCKED_CREDENTIAL_SENTINEL,baseEnv) and the three above that must not. All six came out as expected, in both directions.A single-direction check would have passed at step 3 as well. The negative controls are what caught the English-word hole.
The sweep this belongs to
Three in one file is not a codebase sweep. A
hunterpass should widen it in two directions this check does not cover:{@link Other#member}across files, and{@code X#method}which is plain text and resolves nothing by construction. The right long-term fix is a build check, so a rename cannot leave a dead link behind again — the same reasoning that gave rules 1, 2, 3 and 5 their gates.Not in the running worker's scope: findings 4 and 5 only.
Findings 4 and 5 fixed and merged —
mainat2289e94, PR #764. Verification is on that PR; one result from it belongs here instead.The description fix is not pinned by any test
I mutated the shipped fix, putting the stale
"architect/dev/reviewer"literal back intofleet_list's description, and ranFleetMcp*Test,MemberRoleTest: 185 tests, 0 failures, BUILD SUCCESS. The mutation survives.MemberRole.wireNames()itself is pinned —MemberRoleTest.parseRejectsAnUnknownRoleAndListsTheValidOnesasserts the joined string, so that test now transitively proves the description would containhunterif the description calls the method. Nothing proves it still calls it.So the hole that lost
hunteris still open in the same direction: a future author can type a literal back in and the build stays green.listTool()isprivate static, so closing it means either widening it for a test — which is what code-quality rule 4 exists to prevent — or standing the MCP server up in a test. That is a design decision, so I am not deciding it inside a comment-fix ticket. It belongs with the remaining #748 build-gate work, where there is already a precedent to copy:McpContractDocTestreadsFleetTool.wireNames()and carries its own positive control ("returned only N tool(s); the server registers eleven").Status of this ticket's findings
0f2ec7aConnectionIdentity'sCallerrecord, which my brief missed39accf7fleet_replyauthz comment named the wrong predicate2289e94fleet_list's description omittedhunter2289e94— not pinned, see above{@link}refs inHerdrPeerLauncherCaller#resolvedandisLoopbackjavadoc: tickets, dates, "used to say"docs/, never delete itLeaving this ticket open for finding 6 and the two javadoc blocks.