Review round 3, both reviewers, NOT-MERGEABLE. Nothing needed rework — the code path
was found sound and mutation-sensitive (a 17-mutation battery caught every mutation with
the semantically correct test). What was left were tripwires and prose.
TRIPWIRES
- `assert need > 20` was the tightest live-corpus assertion left in the blocking job:
it reds after 16 over-ceiling additions, while `flags_minority` — the property #688
exists to protect — survives to 36. An arbitrary threshold on a live order statistic is
the ratchet wearing a different hat. Removed; the measured headroom lives in prose,
where being out of date costs a doc fix rather than someone else's red build. This also
removes an unbounded `while` loop that HUNG the suite rather than failing it when the
ratio could not reach the cap.
- test_main_reports_ceiling_drift hardcoded ceiling 999, which is not guaranteed above
p95: ten valid 1000-line records make 999 calibrated and silently delete the test's only
assertion. Now derived as max+1, off the tail by definition.
- test_main_actually_REPORTS_the_ceiling_and_the_trend required >=1 over-ceiling record.
The ceiling is ALLOWED to go green (test_oversized_records_can_go_green says so), so
that would red the blocking job the day someone consolidates the last offender —
punishing exactly the work the warning asks for. Restated as an IFF.
- test_no_budget_flag_means_no_retirement_warning asserted no bare "RETIRED" in stderr; a
legitimate stale record whose TITLE contains the word reds it. Matched precisely now.
- Added the >100-record vacuity guard its siblings carry to the derived-ceiling test.
NUMBERS — all three were mine, and two are the failure mode this repo calls worse than
no note at all (a confident claim that was never measured):
- "the lengths above the ceiling ran 60, 61, 62, 63 then jumped to 81" is FABRICATED. No
record of 61, 62 or 63 lines exists at origin/main, at the #672 sha, or at the #706 sha.
Measured, the sequence is 59, 59, 60, 60 then 81 — a 21-line jump, so the conclusion was
if anything understated. Corrected in all three places it was repeated, including the
canonical v4 row of docs.corpus-size-signal.
- The crosscheck record called `decisions-guard` a REQUIRED check — introduced by the
previous commit in the sentence rewritten to fix an overclaim. Verified against Gitea
branch protection: `main` requires exactly `Build & test (.NET)`, `EF migration
integrity` and `review-verdict/h10`. NEITHER script-tests NOR decisions-guard is
required; the record now says so.
- docs.corpus-size-signal said 37 additions "to reach" the cap two paragraphs above 38
"below the cap" — a same-document numeric inconsistency of exactly the class this change
set out to remove. Both now state 38 to BREACH, noting 37 lands on 0.25 and passes.
- Also: the old bound's accepted range is 39..229 (not 43..229 — 43 is the NEW bound's
lower edge); "95% over the ceiling" was 100%; `oversized_records` said the #620
distribution began at 0 lines where the record itself says 2.
Verification: 428 scripts/tests pass; ruff at baseline parity (47); validator exits 0 with
no drift notice; corpus at p90=60, 18/183 over the ceiling, record trimmed to 60 lines so
main ships calibrated.
Decisions-Edit: yes
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>