Problem
The shape-expressiveness design (docs/design-plans/2026-06-11-ltm-shape-expressiveness.md, invariant I4 in Architecture section 2) states:
the rows a source contributes per result slot are computed ONLY by read_slice_rows applied to that source's slice. No consumer re-derives rows from from_dims cartesian products.
emit_agg_routed_edges (src/simlin-engine/src/db/analysis.rs, ~lines 805-1010) violates this: it enumerates agg-routed element-edge rows via its own per-source AxisPlan machinery rather than consuming read_slice_rows.
Evidence
During the adversarial review of the Phase-1 proptest extension (commit d26dfc3e on branch ltm-shape-phase1), a mutation experiment proved the independence: widening Reduced.subset to the full extent INSIDE read_slice_rows left the production agg-routed edges correct (deterministic subset-edge tests still passed) while only the proptest's expectation side changed. So the link-score emitters consume read_slice_rows, but the element-graph edge emitter re-derives rows independently -- two parallel enumerations that currently agree but can drift. That is exactly the two-surface-divergence class the design phase exists to eliminate (and a direct instance of epic #488's standing invariant "Two-surface decisions share one predicate").
Silver lining: because the two derivations are independent, the proptest oracle is accidentally differential for subset routing -- a drift WOULD be caught by the generative tests as long as they cover the drifting shape.
Why it matters
No behavioral divergence today, but it is a standing-invariant violation in the design's own terms. Any future change to read_slice_rows (subranges, permutations, broadcasts -- the whole Phase-1 surface) must be mirrored by hand in emit_agg_routed_edges' AxisPlan path or the element graph and the link scores silently disagree about which rows an edge covers.
Component
src/simlin-engine/src/db/analysis.rs (emit_agg_routed_edges), LTM element-graph construction.
Suggested direction
Refactor emit_agg_routed_edges' row planning to consume read_slice_rows per source (or extract one shared row-plan helper that both the element-edge emitter and the link-score emitters consume), preserving byte-identical edge output -- golden-pin the existing element-graph tests before the refactor. Low urgency: no wrong numbers today, and the proptest guards subset/mixed shapes differentially.
Provenance
Found by the adversarial reviewer of the Phase-1 proptest commit (d26dfc3e, branch ltm-shape-phase1) via mutation testing, 2026-06-11. Tracked under epic #488 cluster A.
Problem
The shape-expressiveness design (
docs/design-plans/2026-06-11-ltm-shape-expressiveness.md, invariant I4 in Architecture section 2) states:emit_agg_routed_edges(src/simlin-engine/src/db/analysis.rs, ~lines 805-1010) violates this: it enumerates agg-routed element-edge rows via its own per-sourceAxisPlanmachinery rather than consumingread_slice_rows.Evidence
During the adversarial review of the Phase-1 proptest extension (commit
d26dfc3eon branchltm-shape-phase1), a mutation experiment proved the independence: wideningReduced.subsetto the full extent INSIDEread_slice_rowsleft the production agg-routed edges correct (deterministic subset-edge tests still passed) while only the proptest's expectation side changed. So the link-score emitters consumeread_slice_rows, but the element-graph edge emitter re-derives rows independently -- two parallel enumerations that currently agree but can drift. That is exactly the two-surface-divergence class the design phase exists to eliminate (and a direct instance of epic #488's standing invariant "Two-surface decisions share one predicate").Silver lining: because the two derivations are independent, the proptest oracle is accidentally differential for subset routing -- a drift WOULD be caught by the generative tests as long as they cover the drifting shape.
Why it matters
No behavioral divergence today, but it is a standing-invariant violation in the design's own terms. Any future change to
read_slice_rows(subranges, permutations, broadcasts -- the whole Phase-1 surface) must be mirrored by hand inemit_agg_routed_edges'AxisPlanpath or the element graph and the link scores silently disagree about which rows an edge covers.Component
src/simlin-engine/src/db/analysis.rs(emit_agg_routed_edges), LTM element-graph construction.Suggested direction
Refactor
emit_agg_routed_edges' row planning to consumeread_slice_rowsper source (or extract one shared row-plan helper that both the element-edge emitter and the link-score emitters consume), preserving byte-identical edge output -- golden-pin the existing element-graph tests before the refactor. Low urgency: no wrong numbers today, and the proptest guards subset/mixed shapes differentially.Provenance
Found by the adversarial reviewer of the Phase-1 proptest commit (
d26dfc3e, branchltm-shape-phase1) via mutation testing, 2026-06-11. Tracked under epic #488 cluster A.