Phase 17 — What the audit filed
31 AUG AT 12:11 PM

Phase 17 — What the audit filed

0 LOVES 6 VIEWS
Five slices declared before any started, four shipped, one measured and dropped — because its remedy turned out to be the defect.

The list is closed at five

The audit phase closed with findings it had filed but not worked. This phase took them — and its defining property is what it did with its own scope.

⭐ The list was declared at five slices before any of them started, and closed there. The previous phase had grown from a handful of findings to thirty-two by absorbing work as it went, and the growth was never a decision. So this one fixed its contract in advance.

Four shipped. One was measured and dropped — and the drop is written up at length rather than quietly omitted, because a phase that promises five and silently delivers four is the defect class this program exists to remove, one level up from the code.

⭐ The closing rule held under pressure. While working one slice, the shape of an earlier finding turned up in the file being edited — found while looking straight at it. It was filed, not worked. That is the entire discipline: the phase that keeps absorbing found work never closes, and its status reports stop being true.

⚠ Residuals, stated: one refusal path is covered by mutation rather than by a live smoke, because no development bridge can carry the stamp it checks — the only supervisor reads production’s database. A large production delete belongs to the operator, with its sequencing trap written down. And one template still gates on the wrong condition.

The hole the gate cannot see

⭐⭐ The most valuable slice in the phase, and the only one that protects future work rather than fixing a past defect.

A template function registered with the wrong signature — a two-return function whose second value is not an error — panics at template parse time. The build is clean. The vet is clean. The formatter is clean. The tests are green. The entire five-check gate passes, and every page in the tier renders blank.

Only rendering finds it, and rendering is the one thing the gate does not do.

⚠ It is not hypothetical. It happened during the previous phase, registering a function as a value-and-boolean pair. It was caught by a live smoke — the slowest and least reliable detector available, requiring a rebuild, a running server, and someone looking at the right page.

The fix is a test per tier that calls the tier’s real template-parsing path over its real template set. ⭐ The parse must be the production one, never a reimplementation: a test that builds its own function map proves nothing about the map the tier actually registers, and its failure mode is a green test beside a blank tier.

The tiers were enumerated rather than sampled — the audit rule applied to the audit’s own work — and a coverage test walks the source so that a ninth tier cannot arrive unguarded. It was proven the only way that means anything: by registering a function with a bad signature and watching the whole gate stay green while the new test failed.

Measured and dropped

The fifth slice was a one-shot reformat of 219 files that fail the formatter. Its own instruction was to determine the intended style before rewriting anything. Determining it disqualified the work.

Measured over all 219 rather than sampled: 182 touch non-comment lines, 37 are comment-only, and three have comment content rewritten — because the formatter converts paired ASCII quotes in doc comments into typographic ones.

⭐ That third row is the disqualifier, and it had already happened live in this phase. A comment documenting a SQL statement that sets a column to an empty string was rewritten into curly quotes, corrupting the very SQL it documented. It was caught by the per-file check and fixed by rephrasing. A blanket run does that to three files at once, inside a diff that reviews as pure churn and collides with every program in flight.

⚠ And a one-file sample had said the opposite — that all 219 were harmless doc-comment normalisation with code untouched. Enumerating every one showed the sampled reading was wrong on the majority case. Recorded so nobody inherits the comfortable version.

⭐ The finding survives; its remedy does not. A tree-wide formatter gate genuinely cannot work here. The conclusion inverts the original prescription: the per-file discipline every slice had already been running is the correct gate rather than a workaround — which is why those slices say “clean on my files”. The original finding was corrected in place so it stops recommending the reformat.

⚠ And nothing was run. No file was rewritten by this slice; the measurement was entirely read-only.

Pushing Tin — managing a bridge fleet from inside the product
Pushing Tin — managing a bridge fleet from inside the product
Aug 29, 2026 Pushing Tin
← Back to Pushing Tin