Skip to content

check-durability-degradation-log-level enforces only the QUIET direction — the too-loud half exists as remedy prose that can never fire #19386

Description

@huangyiirene

Path: none | 仪器:check-durability-degradation-log-level | AGENTS.md 声明两个方向,门禁只执行「太安静」那一个;「太吵」只活在失败路径的散文里,永不可能触发
分诊重测与定级:2026-09-20T16:54Z

What is wrong

scripts/check-durability-degradation-log-level.mjs enforces one of the two directions AGENTS.md states, and the other exists in the script only as prose printed at the failure path — a sentence that can never fire as a criterion.

  • Enforced: a durability-critical catch that is too QUIET (swallows, or logs below the required level without rethrowing) ⇒ the gate goes red.
  • NOT enforced: a catch that is too LOUD — a logger.error bolted onto a site that already hands the failure to the caller. AGENTS.md names this as the mirror-image failure; the script names it too, and only here:
scripts/check-durability-degradation-log-level.mjs:3882
'    OR      : if this catch already HANDS THE FAILURE TO THE CALLER on every path …, do NOT bolt on a log …
 Adding a redundant `logger.error` to a path whose common case is a rejected request is the mirror-image
 failure AGENTS.md warns about.\n'

That string is the body of function remedyFor(v) — the fix : block emitter, which by construction runs only once a verdict already exists. ⇒ the mirror-image direction is advice shown to someone who already failed the gate the other way, and ⛔ there is no criterion anywhere that a too-loud catch can trip.

Evidence, split by who measured what

Structural reading — taken on origin/main 8271c814253fdd2629d3b608b73de14efb67f168: remedyFor is reached from the verdict renderer beside verdictFor's 'quiet-log' / 'unreadable-report' arms; every arm of the classifier is a shape of too quiet. ⛔ No arm, and no other call site, asks whether a catch that rethrows also logs at error.

Behavioural reading — ⚠️ NOT this card's filer's. It was measured during #17212's dispatch, on a built tree, and is reproduced here as that reading rather than as this filer's own: pnpm check:durability-log-level exits 0 on the clean tree and exits 0 after packages/objectql/src/engine.ts's find-failure logger.error was demoted to warn, printing byte-identical verdict lines both times (36 durability-critical catch seam(s), all loud, rethrowing or propagating to the caller (4 propagating, declared)). --list places that seam under the read-seam rule only and nowhere in the log-level rule's set.

⚠️ This filer could not run the gate: node scripts/check-durability-degradation-log-level.mjs exits 3 — PREREQUISITE NOT MET in an uninstalled checkout. ⇒ NOT MEASURED here, ⛔ recorded as such rather than as a pass or a second confirmation.

Why it is worth a card rather than a note

The ungated half is not hypothetical. It is how the class #17052 had to clean up reached four members — and finding them required #17052 to build its own AST matcher, because the gate that is supposed to own this axis cannot see it. #17212 is the fourth member, still open.

⇒ the asymmetry costs a bespoke search every time someone suspects the shape, and it means a new bolted-on logger.error lands green today.

Suggested shape (⛔ not a ruling)

Give the classifier an arm for the loud direction: a catch that rethrows on every path and logs at error is a finding, with the existing FAILURE_PROPAGATION_CALLEES / FAILURE_PROPAGATION_SITES declarations as its escape hatch — the same registers the remedy text already points at, so the vocabulary exists and only the criterion is missing.

⚠️ Whoever takes it should check the gate's own staleness rule first: it fails on a register entry that matches no seam, so the escape hatch cannot be used to pre-silence a site.

Lane — ⛔ deliberately unlabelled

Left for triage. ⚠️ The relevant rule is the scripts/(门禁类) anchoring exception in the lane table, ⛔ not the general "tooling" reading, and the SUBJECT here (durability logging in engine and driver code) is not a governed surface. ⛔ This filer is not naming the lane and has written no domain:* label.

Dedupe words (⛔ the filer does not dedupe)

durability-log-level mirror-image · bolt-on logger.error · FAILURE_PROPAGATION · one-directional gate · AGENTS.md has teeth

Provenance

Surfaced as an out-of-scope finding by the os-dev agent dispatched on #17212 from the domain:engine execution PM seat, round 7. Triage pre-authorized this card on that card conditional on a real gate run; that run is now on the record and is quoted above with its provenance attached. Lands in scripts/check-durability-degradation-log-level.mjs.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions