Repository navigation
fix(policy): declare the third ported mutation, and drop two numbers that drift - #813
Conversation
CLOUD-1302 PR #794 shipped a `ported` arm with no declared mutation and two stale numbers in landed prose — and three governed defects reported as unlandable
Why CLOUD-1268 landed the 1. A third
|
| where | says | is |
|---|---|---|
:146 |
"667.4s corpus" | 660.5s (main retired six suites) |
:157 |
"session-start, 97.8s" |
6.8s warm; the row's own cold figure is 135.9s |
The second is worse than staleness — 97.8s matches no measurement that exists. It was asserted rather than derived, which is CLOUD-1166 arm 4, and CLOUD-1268's own top-of-row correction is about exactly that class. Prefer deleting the corpus denominator to updating it: an ungated count in prose drifts by construction (CLOUD-770's rule).
3. Three governed defects reported as unlandable — the reasoning error
mise-tasks/replay.sh and mise-tasks/config-lint.sh were each reported as carrying a fix that could not land, with "the file is governed" as the reason. That inverts the rule. .claude/rules/toolchain.md: "A plan that says 'this row edits foo.sh' has not found a blocked row — it has found a row whose §1 is written in the wrong shape. Re-scope it to a retirement." A governed path is the one place a fix is guaranteed a route, because the campaign is the route.
The config-lint instance is the expensive one: the defect is real (see CLOUD-841), and it is what admitted PR #794's own config smell. It was filed and left standing.
The memories state the correct rules and neither states the inference that trips over them, which is why reading them did not stop it. That is the third deliverable.
Refinement — Ready
Refinement gate: Definition of Ready & Done. This body carries only specializations.
- **Authority boundary (§1). **
policy/shell-retirement.rego(one#MUTANTrow),crates/batten/tests/it/shell_retirement.rs(one case),policy/suite-subject-retirable.rego(header prose), and the two memoriestoolchain-and-hooksandworkflow/board-states. Nomise-tasks/program and no.batsis edited — the config-lint retirement is CLOUD-841's and is not this row. - Computable predicate (§2). A mutation of
V-PORT-SUBJECT-RETIRED's dying-subject conjunct reddens a named case in the declared#MUTANT-SUITE, and survives without it. The case discriminates becausetests/helpers.bashis neither a.batsnor undermise-tasks/, sogoverned_when_deleteddoes not select it and its deletion owes no arm — leaving this arm the only one that can fire. - Shown able to fail (§2). Run the declared mutation and watch the new case go red; drop the case and watch the same mutation report
SURVIVED. - Deliberately not in scope (§2). Retiring
config-lint.sh(CLOUD-841) orreplay.sh(no defect — see CLOUD-1272). Re-opening CLOUD-1268's landed mechanism. - **Effect (§3). **
read. - Output and exit (§5). Unchanged — this adds a declaration and a case, not a verdict.
- **Commit / bump (§6). **
fix(policy)— patch (0.0.x). - Test obligation (§7). The case above, in the declared suite, over the compiled binary.
mise run policy-testand the mutation sweep both green. - Blockers (§8). None.
relatedToCLOUD-1268 (whose PR shipped 1 and 2), CLOUD-1267 (whose mechanism 1 lands against), CLOUD-1166 (the asserted-not-derived class 2 is an instance of), CLOUD-841 and CLOUD-1272 (the two rows 3 mis-scoped).
Acceptance
V-PORT-SUBJECT-RETIREDcarries a#MUTANTrow naming a case incrates/batten/tests/it/shell_retirement.rs, and that case exists and discriminates.- Neither stale number survives in
suite-subject-retirable.rego, and the corpus denominator is gone rather than refreshed. mem:toolchain-and-hooksstates that a defect in a governed program is a retirement row, never a block, with the three measured instances.mem:workflow/board-statesstates that an In Review row is landed, not occupied, so its open acceptance bullets are pullable.
Found by auditing CLOUD-1268's own deferrals after it landed, rather than by a gate — which is the fourth finding and has no remedy here.
CLOUD-1303 `judge_pending` demands an admission for a protected write made THROUGH its owning surface, and the admission's precondition then cannot be answered truthfully
CANCELED 2026-09-01 — the finding is real and lives on CLOUD-1278, where the mechanism does
Nothing here is withdrawn on the merits. The defect stands, verbatim, as a comment on CLOUD-1278: judge_admissions demands an admission for a protected write made THROUGH its owning surface, and V-PROTECTED-MUTATION's precondition and rejected-route questions then cannot be answered truthfully about such a write. crates/batten/src/commit.rs is CLOUD-1278's §1 and the clause is what that row built, so that is where it belongs.
What was wrong is that it was a row. filed-over-own-diff refused the branch that filed it, alongside filed-unrefined — a new row opened over its author's own diff and stored unready, which prices a home opened instead of a fix (CLOUD-514's second half). Both arms were correct.
That refusal has no prose remedy by design: fix it here, comment on the row that owns it, file it after landing from a clean tree, or spend a declared override. The second is not the cheapest of the four — it is the right one, and filing separately was the mistake.
A note for whoever reads this row next, because the first cancellation did not clear the refusal either. That body quoted the gate's own output — its list of refused paths — and the overlap is computed from the row's body at READ time against the branch's delta. Quoting a refusal re-created the very overlap the cancellation was resolving, and the second run reported nine findings where the first reported six. This body names none of them, which is the third declared exemption: a row whose body names none of the diff.
Superseded by the comment on CLOUD-1278. Not a duplicate and not refuted: the same finding, in the durable home it should have had.
ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Free Run ID: 📒 Files selected for processing (5)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe change adds integration and mutation coverage for rejecting Merge Risk: ⚪ Minimal · up to This PR makes localized policy, test, and documentation updates, with verification reported as passing; no actionable merge-blocking risk remains beyond normal checks and review. Note 🎁 Summarized by CodeRabbit FreeYour organization is on the Free plan. CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please upgrade your subscription to CodeRabbit Essentials by visiting https://app.coderabbit.ai/settings/billing. Comment |
…rator
`#MUTANT` rows are pipe-delimited, and the expression I wrote to kill
`V-PORT-SUBJECT-RETIRED`'s dying-subject conjunct contained a Rego set
comprehension — `{gone | some gone in delta.deleted}`. The `|` inside it read
as a field separator, so the declaration parsed as four fields where three are
wanted and the sweep reported it `malformed-row`: could-not-look, not a pass.
That is the gate discriminating rather than a nuisance. A row this shape would
have sat in the file looking like coverage while never applying a mutation —
the exact failure CLOUD-1302 exists to close, reproduced one level up in the
fix for it.
Anchored on the line prefix instead, which is how `shell-subject-alive-unchecked`
already spells the same problem: replace `\tsubject in ` with `\tfalse #`, so the
remainder of the line becomes a comment and no `|` appears in the expression.
`^\t` keeps it off the two neighbouring `some subject in` and `not subject in`
lines, which carry the same comprehension and must not move.
Refs: CLOUD-1302
Admits: 72ebe3172dea00a954c21a74d6bc2a0fa6183424c25d36d415a7672367092507
Admits-rule: protected-mutation
Admits-verdict: V-PROTECTED-MUTATION
Admits-subject: policy/shell-retirement.rego
Admits-head: 1c4f445
Admits-epoch: 71bf7f9f4f378e71c73ceeea5eb44c0217d75bdca1c242d0f9cdfb31f03c5117
Admits-author: alec@wenzowski.com
Admits-prev: d90a5f385ccca5b96d4a1196cc70273e2ec067f27aad9e66ba8c93fc13ff929a
Admits-answer-lost: The row stays malformed and the sweep keeps reporting 'port-subject-retired-unchecked malformed-row (4 fields, want 3)' — could-not-look, not a pass. The pipe inside the Rego comprehension {gone | some gone in delta.deleted} is read as the #MUTANT field separator, so the declaration parses as four fields and the mutation is never applied. V-PORT-SUBJECT-RETIRED would remain the one arm of three with no mutation actually exercised, which is the whole point of CLOUD-1302.
Admits-answer-precondition: A registered .rego module has no owning surface that can write it: batten offers no verb that edits a #MUTANT declaration, and the row must sit beside the predicate it mutates. This is a one-line repair to the row added in 1c4f445 on this same branch, landing in draft PR #813 against CLOUD-1302.
Admits-answer-rejected-route: R-USE-THE-OWNING-SURFACE. There is no owning surface: #MUTANT rows are read from the module source and batten exposes no verb that writes one. R-RESTORE-IT is the wrong direction — restoring the file would restore the malformed row this repairs.
4be41a6 to
9c6f4b2
Compare
…rator
`#MUTANT` rows are pipe-delimited, and the expression I wrote to kill
`V-PORT-SUBJECT-RETIRED`'s dying-subject conjunct contained a Rego set
comprehension — `{gone | some gone in delta.deleted}`. The `|` inside it read
as a field separator, so the declaration parsed as four fields where three are
wanted and the sweep reported it `malformed-row`: could-not-look, not a pass.
That is the gate discriminating rather than a nuisance. A row this shape would
have sat in the file looking like coverage while never applying a mutation —
the exact failure CLOUD-1302 exists to close, reproduced one level up in the
fix for it.
Anchored on the line prefix instead, which is how `shell-subject-alive-unchecked`
already spells the same problem: replace `\tsubject in ` with `\tfalse #`, so the
remainder of the line becomes a comment and no `|` appears in the expression.
`^\t` keeps it off the two neighbouring `some subject in` and `not subject in`
lines, which carry the same comprehension and must not move.
Refs: CLOUD-1302
Admits: 72ebe3172dea00a954c21a74d6bc2a0fa6183424c25d36d415a7672367092507
Admits-rule: protected-mutation
Admits-verdict: V-PROTECTED-MUTATION
Admits-subject: policy/shell-retirement.rego
Admits-head: 1c4f445
Admits-epoch: 71bf7f9f4f378e71c73ceeea5eb44c0217d75bdca1c242d0f9cdfb31f03c5117
Admits-author: alec@wenzowski.com
Admits-prev: d90a5f385ccca5b96d4a1196cc70273e2ec067f27aad9e66ba8c93fc13ff929a
Admits-answer-lost: The row stays malformed and the sweep keeps reporting 'port-subject-retired-unchecked malformed-row (4 fields, want 3)' — could-not-look, not a pass. The pipe inside the Rego comprehension {gone | some gone in delta.deleted} is read as the #MUTANT field separator, so the declaration parses as four fields and the mutation is never applied. V-PORT-SUBJECT-RETIRED would remain the one arm of three with no mutation actually exercised, which is the whole point of CLOUD-1302.
Admits-answer-precondition: A registered .rego module has no owning surface that can write it: batten offers no verb that edits a #MUTANT declaration, and the row must sit beside the predicate it mutates. This is a one-line repair to the row added in 1c4f445 on this same branch, landing in draft PR #813 against CLOUD-1302.
Admits-answer-rejected-route: R-USE-THE-OWNING-SURFACE. There is no owning surface: #MUTANT rows are read from the module source and batten exposes no verb that writes one. R-RESTORE-IT is the wrong direction — restoring the file would restore the malformed row this repairs.
…that drift PR #794 landed three `V-PORT-SUBJECT-*` verdicts and declared mutations for two of them. `V-PORT-SUBJECT-RETIRED` had none, and the gap was two-deep: the suite `#MUTANT-SUITE` names carried no case for that arm either. The load-time tier pinned the predicate and `ratchet.rs` pinned the case granularity, but neither is the declared suite, so a mutation of this arm had nothing to redden and could only ever have been reported as a survivor. `a_port_over_a_subject_that_died_is_refused` is that case. It discriminates because `tests/helpers.bash` is neither a `.bats` nor under `mise-tasks/`, so `governed_when_deleted` does not select it and its own deletion owes no arm — leaving the dying-subject arm the only one that can fire. Two numbers in `suite-subject-retirable.rego`'s header also came from that PR and were wrong. The corpus denominator is DELETED rather than refreshed: it moves every time a suite retires, so restating one is a number that goes stale silently. `session-start`'s seconds are removed for a different reason — 97.8s matched no measurement that exists, and the suite is the corpus's second-largest on a cold container and unremarkable on a warm one, so the honest place for a number is the row that owns both readings. Both memories gain the inference their own rules did not state. A defect in a governed program is a RETIREMENT row, never a block — "leave it alone" is the shape for a file needing no change, not an answer to one that does. And an In Review row is landed, not occupied, so its declared still-open acceptance bullets are pullable work. Refs: CLOUD-1302 Admits: d90a5f385ccca5b96d4a1196cc70273e2ec067f27aad9e66ba8c93fc13ff929a Admits-rule: protected-mutation Admits-verdict: V-PROTECTED-MUTATION Admits-subject: policy/shell-retirement.rego Admits-head: 6063049 Admits-epoch: 71bf7f9f4f378e71c73ceeea5eb44c0217d75bdca1c242d0f9cdfb31f03c5117 Admits-author: alec@wenzowski.com Admits-prev: - Admits-answer-lost: V-PORT-SUBJECT-RETIRED keeps its status as the one arm of three shipped by PR #794 whose mutation was never declared, so nothing proves its compiled-binary case discriminates. That leaves a predicate that can silently stop refusing, in exactly the class CLOUD-1267 withdrew 32 exemptions to close. Admits-answer-precondition: A registered .rego module has no owning surface that can write it: batten offers no verb that adds a #MUTANT declaration line, and the declaration must sit beside the predicate it mutates. This write is a two-line addition to policy/shell-retirement.rego landing in a reviewed PR against CLOUD-1302. Admits-answer-rejected-route: R-USE-THE-OWNING-SURFACE. There is no owning surface: #MUTANT rows are read from the module source itself and batten exposes no verb that writes one. R-RESTORE-IT does not apply either, since the file is not damaged; the change is a declaration that was missing from the start. Admits: b5eec5a0af1a244a95e0e372de28dcdb199ebb1df5ce9b7f4fa259785a8dda01 Admits-rule: protected-mutation Admits-verdict: V-PROTECTED-MUTATION Admits-subject: policy/suite-subject-retirable.rego Admits-head: 6063049 Admits-epoch: 71bf7f9f4f378e71c73ceeea5eb44c0217d75bdca1c242d0f9cdfb31f03c5117 Admits-author: alec@wenzowski.com Admits-prev: - Admits-answer-lost: Two numbers PR #794 landed stay wrong in the tree. ':147' states a 667.4s corpus that is now 660.5s, and ':158' states session-start at 97.8s, which matches no measurement that exists — the row's cold figure is 135.9s and the warm one is 6.8s. A reader classifying the exemption table is calibrated by both. Admits-answer-precondition: A registered .rego module has no owning surface that can write its header prose: batten offers no verb that edits a module comment. The write is a comment-only change to policy/suite-subject-retirable.rego landing in a reviewed PR against CLOUD-1302, and the predicate below it is untouched. Admits-answer-rejected-route: R-USE-THE-OWNING-SURFACE. There is no owning surface for a module's header comment; the prose is read from the module source. R-RESTORE-IT does not apply — restoring the file would restore the wrong numbers, which are what this change removes. Admits: e96e3aa4ccf27e2460fde52e56d0b5357d2e80a2ff4f775a8c8ff2c12bcfa36f Admits-rule: protected-mutation Admits-verdict: V-PROTECTED-MUTATION Admits-subject: .serena/memories/toolchain-and-hooks.md Admits-head: 6063049 Admits-epoch: 71bf7f9f4f378e71c73ceeea5eb44c0217d75bdca1c242d0f9cdfb31f03c5117 Admits-author: alec@wenzowski.com Admits-prev: - Admits-answer-lost: Both memories keep stating a correct rule while omitting the inference that trips over it. mem:toolchain-and-hooks names the two landable shapes for a governed file and never says which applies when you find a BUG in one — read as 'leave it alone', it makes every defect in that layer permanent. mem:workflow/board-states says In Review means merged and never says the consequence: such a row is landed, not occupied, so its open acceptance bullets are pullable. Both misreadings were measured this session. Admits-answer-precondition: NOT the usual one, and stated plainly rather than fitted to the question. The owning surface CAN express this change and WAS used: both files were written with Serena's edit_memory, and the mediated-call gate allowed those writes. What demands this block is the commit-level half (commit.rs judge_pending), which requires an articulation for every protected path a commit touches, whether or not the write needed an override. The write is a two-paragraph addition to each memory, landing in a reviewed PR against CLOUD-1302. Admits-answer-rejected-route: Neither route was rejected; R-USE-THE-OWNING-SURFACE was TAKEN, which is why this articulation does not fit the question. R-RESTORE-IT does not apply — nothing is damaged. The gate's question set presumes the write bypassed a surface; for .serena/memories/** written through Serena it cannot be answered as asked, and that contradiction is filed rather than papered over. Admits: 14eb1973fd24f18fe1092e42014b0cac84beef053e935f202b0aab519cb80b01 Admits-rule: protected-mutation Admits-verdict: V-PROTECTED-MUTATION Admits-subject: .serena/memories/workflow/board-states.md Admits-head: 6063049 Admits-epoch: 71bf7f9f4f378e71c73ceeea5eb44c0217d75bdca1c242d0f9cdfb31f03c5117 Admits-author: alec@wenzowski.com Admits-prev: - Admits-answer-lost: mem:workflow/board-states keeps saying In Review means already merged while never drawing the consequence a reader needs: such a row is LANDED, not OCCUPIED, so its declared still-open acceptance bullets are pullable work and its attached PRs are evidence of landed work rather than of a competitor. Measured this session on CLOUD-1218, which was declined on exactly that misreading. Admits-answer-precondition: NOT the usual one, and stated plainly rather than fitted to the question. The owning surface CAN express this change and WAS used: this file was written with Serena's edit_memory, and the mediated-call gate allowed the write. What demands this block is the commit-level half (commit.rs judge_pending), which requires an articulation for every protected path a commit touches, whether or not the write needed an override. The write adds one numbered entry to the memory's own 'three things that trip agents up' section, landing in a reviewed PR against CLOUD-1302. Admits-answer-rejected-route: Neither route was rejected; R-USE-THE-OWNING-SURFACE was TAKEN, which is why this articulation does not fit the question. R-RESTORE-IT does not apply — nothing is damaged. The gate's question set presumes the write bypassed a surface; for .serena/memories/** written through Serena it cannot be answered as asked, and that contradiction is filed rather than papered over.
…rator
`#MUTANT` rows are pipe-delimited, and the expression I wrote to kill
`V-PORT-SUBJECT-RETIRED`'s dying-subject conjunct contained a Rego set
comprehension — `{gone | some gone in delta.deleted}`. The `|` inside it read
as a field separator, so the declaration parsed as four fields where three are
wanted and the sweep reported it `malformed-row`: could-not-look, not a pass.
That is the gate discriminating rather than a nuisance. A row this shape would
have sat in the file looking like coverage while never applying a mutation —
the exact failure CLOUD-1302 exists to close, reproduced one level up in the
fix for it.
Anchored on the line prefix instead, which is how `shell-subject-alive-unchecked`
already spells the same problem: replace `\tsubject in ` with `\tfalse #`, so the
remainder of the line becomes a comment and no `|` appears in the expression.
`^\t` keeps it off the two neighbouring `some subject in` and `not subject in`
lines, which carry the same comprehension and must not move.
Refs: CLOUD-1302
Admits: 72ebe3172dea00a954c21a74d6bc2a0fa6183424c25d36d415a7672367092507
Admits-rule: protected-mutation
Admits-verdict: V-PROTECTED-MUTATION
Admits-subject: policy/shell-retirement.rego
Admits-head: 1c4f445
Admits-epoch: 71bf7f9f4f378e71c73ceeea5eb44c0217d75bdca1c242d0f9cdfb31f03c5117
Admits-author: alec@wenzowski.com
Admits-prev: d90a5f385ccca5b96d4a1196cc70273e2ec067f27aad9e66ba8c93fc13ff929a
Admits-answer-lost: The row stays malformed and the sweep keeps reporting 'port-subject-retired-unchecked malformed-row (4 fields, want 3)' — could-not-look, not a pass. The pipe inside the Rego comprehension {gone | some gone in delta.deleted} is read as the #MUTANT field separator, so the declaration parses as four fields and the mutation is never applied. V-PORT-SUBJECT-RETIRED would remain the one arm of three with no mutation actually exercised, which is the whole point of CLOUD-1302.
Admits-answer-precondition: A registered .rego module has no owning surface that can write it: batten offers no verb that edits a #MUTANT declaration, and the row must sit beside the predicate it mutates. This is a one-line repair to the row added in 1c4f445 on this same branch, landing in draft PR #813 against CLOUD-1302.
Admits-answer-rejected-route: R-USE-THE-OWNING-SURFACE. There is no owning surface: #MUTANT rows are read from the module source and batten exposes no verb that writes one. R-RESTORE-IT is the wrong direction — restoring the file would restore the malformed row this repairs.
9c6f4b2 to
be5a33c
Compare
|
❌ The last analysis has failed. |
|
/fast-forward |
Closes CLOUD-1302.
Found by auditing what PR #794 (CLOUD-1268) deferred, after it landed. Two of the four deferrals were shipped defects; one reasoning error produced three of them.
The missing mutation
#794 landed three
V-PORT-SUBJECT-*verdicts and declared#MUTANTrows for two.V-PORT-SUBJECT-RETIREDhad none, and the gap was two-deep: the suite#MUTANT-SUITEnames carried no case for that arm either. The load-time tier pinned the predicate andratchet.rspinned the case granularity, but neither is the declared suite, so a mutation of this arm had nothing to redden and could only ever have been reported as a survivor.That lands against CLOUD-1267's grain: it withdrew 32 of 32
#MUTANT-EXEMPTs so a module could name the tier that actually drives the engine, and the next module to grow a predicate grew one outside it.a_port_over_a_subject_that_died_is_refusedis the case. It discriminates rather than surviving behind a conjunct some other arm excludes: the dying subject is neither a.batsnor undermise-tasks/, sogoverned_when_deleteddoes not select it and its own deletion owes no arm — leaving the dying-subject arm the only one that can fire.The sweep caught a defect in the fix for the defect. My first row spelled the mutation with a Rego set comprehension, whose
|read as the#MUTANTfield separator: four fields where three are wanted, reportedmalformed-row— could-not-look, not a pass. A row that shape sits in the file looking like coverage while never applying a mutation, which is this PR's own subject one level up. Anchored on the line prefix instead, the wayshell-subject-alive-uncheckedalready spells it.Measured before and after: 14 declared mutations not caught → 13, with the row gone from the list. The 13 remaining all carry a
#MUTANT-OWNERfrom another row and are main's standing baseline.Two numbers that were wrong
Both landed by #794 in the exemption header of the retirable module:
session-start, 97.8s"The corpus denominator is deleted rather than refreshed — it moves every time a suite retires, so restating one is a number that goes stale silently.
session-start's figure is removed for a different reason: the suite is the corpus's second-largest on a cold container and unremarkable on a warm one, and CLOUD-1271 records that the generated results file is not reproducible and anchors no conditions. The honest home for a number about it is CLOUD-1273, which owns both readings.The 97.8s was asserted rather than derived, which is CLOUD-1166 arm 4 — the same class CLOUD-1268's own top-of-row correction was about.
The reasoning error, and where it went
Two governed shell programs were each reported as carrying an unlandable fix because the file is governed. That inverts the rule: a defect in a governed program is a retirement row. Both memories stated the correct rule and neither stated the inference that trips over it, which is why reading them did not help.
mem:toolchain-and-hooksnow says a bug in a governed program is a retirement, never a block — "leave it alone" is the shape for a file needing no change.mem:workflow/board-statesnow says an In Review row is landed, not occupied, so its declared open acceptance bullets are pullable and its attached PRs are evidence of landed work.Dispositions for the rows that error touched: CLOUD-1272 narrowed — the
portedhalf was not a defect, since onlycarriedcases are differentially replayed by design, leaving one real drift finding. CLOUD-841 needed nothing from me: already In Progress as PR #809 and scoped correctly as a retirement, which has since landed. CLOUD-1273 was ungroomed for want of a two-minute measurement this PR's own bench run produced.Four admissions, and what the filed-here gate taught
The two module edits spend
V-PROTECTED-MUTATIONadmissions — a registered module is protected by derivation. Expected.The two memory edits also demanded one, and they were written through Serena's
edit_memory, the surface the config prescribes.judge_admissionshas no condition on how a write was made, so the admission'spreconditionandrejected-routequestions cannot be answered truthfully for a compliant write. Both blocks say so in their own text rather than fitting the answer to the question. That finding is CLOUD-1303, and also a comment on CLOUD-1278 whose §1 is the file the clause lives in. This PR does not fix it and does not close it.Getting that row past
filed-heretook three attempts and each failure was mine:filed-over-own-diff×5 plusfiled-unrefined.closesexemption then could not fire at all, because its record is minted by a recorder on agh pr viewbody fetch and this PR was created through the GitHub MCP tools, so no such call had ever happened. Fetching the body through the boundary minted it — and the first fetch recordedcloses 0, because I redirected stdout to a file and the recorder feeds the captured stdout to its extractor.filed-unrefineddeclares no override route, which is the design working: it wants the row groomed, not excused. So the row is groomed, and its §1 names only the two engine files a fix touches — neither in this diff, which earns thecites_onlyexemption rather than arguing for it.Verification
mise run policy-testgreen.mise run filed-here-checkgreen. The mutation sweep confirms the new row is applied and killed by its named case.verifyand CI run before this leaves draft.