Codex was unavailable for this round (usage quota), so the cross-family reviewer was
replaced by a same-family agent doing one mechanical job: enumerate every security-bearing
clause the diff adds, disarm each, and run the WHOLE suite per mutant. 60 mutants, 40 red,
20 survivors — a yield no per-finding review in this series came close to, because a review
looks at what the diff says it does and a sweep looks at what the tests actually pin.
## Proved (nine)
- the description type test in the RECONCILIATION `buried` filter — exact twin of the
post-write one, which had a proof; without it a numeric description hard-errors
`startswith`, the count comes back unusable, and the genuine verdict on the next row is
lost with it;
- the `.status` / `.description` / `.id` type tests, parametrised over all four consumed
fields so a fifth cannot be added without a case (`.creator`'s was the only one proved);
- both retry loops — the combined read and `repair_status_to`'s second POST. Against a stub
that fails EVERY attempt a retrying reader and a one-shot reader are indistinguishable,
which is how a retry ships unexercised; the fixtures now fail only the first attempt;
- the mid-run guard's self-exemption, which is what stops a sentinel-writing run abstaining
on the row it was about to replace with an equivalent one;
- both repair-write failure paths (the repair and the post-POST replacement), reachable only
with a stub that lets the FIRST post through and fails the rest — with every post failing
the job dies on its own classification write and never reaches them;
- the two `state=pending` updates after a repair. The first is load-bearing beyond tidiness:
without it a repaired head re-enters the post-POST check and, on a retarget it then
observes, replaces `$REPAIR_DESC` with the weaker reconcilable sentinel — the same ordering
inversion the floor beside it exists to prevent, reached by another route.
## Declared unreachable (six), enumerated rather than counted
The path-predicate failure branch; the empty-`row` refusal; page 2's non-numeric length; the
`$witness` normalisation; and the two unusable-count arms. Each is defence in depth behind a
filter that makes its input well-formed for every case a fixture can pose — the same standing
exception the post-write unusable-count arm already carried.
That set has gone two -> five -> six across three rounds as the sweep widened. Naming them is
the point: an inventory that undercounts reads as a checked claim and talks the next reader
out of verifying, which is the same defect as inventing coverage — and this branch has
already had to correct that twice.
refs #849
Decisions-Edit: yes
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019T79beF1Ufid3dXju4yqkF