test(prune): $OWN_DIR protection has no pressure-pass coverage #26

Closed
opened 2026-09-22 16:08:53 +00:00 by claude · 0 comments
Collaborator

Problem

$OWN_DIR protection — the guard that stops a running job's own cache being evicted mid-build — has no test covering the pressure pass. Verified by mutation: moving the $OWN_DIR check out of protected_reason (scripts/prune-cache.sh:221) into the pass-1-only predicate leaves all 64 assertions green on main after PR #25, and all 61 green before it. The gap is pre-existing, not introduced by #25.

Why it hid

Scenario 9 ("own cache never evicted by a sibling pass", scripts/prune-cache-selftest.sh:177-178) runs after scenario 3's under-pressure run. Pass 3's self-clear does rm -rf "$OWN_DIR"; mkdir -p "$OWN_DIR" (prune-cache.sh:639-640), recreating the directory regardless of what happened to it — and assert_kept tests existence only. So the directory is there whether or not the guard worked, and the assertion passes either way.

That is the vacuous-test shape this repo's own selftest header warns about: "a scenario that always passes proves nothing."

Why it matters more now than it did

PR #25 removed one of two independent guards on a publisher's target dir during its own run. It previously had the protected_ns entry and $OWN_DIR/lock; it now has $OWN_DIR plus the lock. The remaining guard carries more weight than before, and it is the one with no pressure-pass coverage.

Acceptance criteria

  1. A selftest scenario fails if $OWN_DIR protection is removed from the pressure pass specifically. Red-prove it with that exact mutation — the one described above, which currently leaves the suite green.
  2. The assertion tests directory contents, not existence, or scenario 9 gets its own under-pressure run_prune so pass 3's recreate cannot mask the result.
  3. bash scripts/selftest.sh green.

Notes

  • Surfaced by PR #25's final review, which recorded it as a follow-up rather than a blocker: the guard is correct in the code as written, it is the test that is missing. That judgement looks right — but the mutation result means a future refactor of protected_reason would be unguarded, which is exactly when it would matter.
  • Two other findings from that review: a comment-drift entry recorded on the standing docs-drift catalog, and a lowest-severity nit about an incomplete causal account at prune-cache.sh:76-79 (it names publish-snapshot.sh's unshare where the seed side calls the same unshare_mutable_paths; nothing false, not worth a round).
## Problem `$OWN_DIR` protection — the guard that stops a running job's own cache being evicted mid-build — has **no test covering the pressure pass**. Verified by mutation: moving the `$OWN_DIR` check out of `protected_reason` (`scripts/prune-cache.sh:221`) into the pass-1-only predicate leaves **all 64 assertions green** on `main` after PR #25, and all 61 green before it. The gap is pre-existing, not introduced by #25. ## Why it hid Scenario 9 ("own cache never evicted by a sibling pass", `scripts/prune-cache-selftest.sh:177-178`) runs *after* scenario 3's under-pressure run. Pass 3's self-clear does `rm -rf "$OWN_DIR"; mkdir -p "$OWN_DIR"` (`prune-cache.sh:639-640`), recreating the directory regardless of what happened to it — and `assert_kept` tests **existence only**. So the directory is there whether or not the guard worked, and the assertion passes either way. That is the vacuous-test shape this repo's own selftest header warns about: *"a scenario that always passes proves nothing."* ## Why it matters more now than it did PR #25 removed one of two independent guards on a publisher's target dir during its own run. It previously had the `protected_ns` entry **and** `$OWN_DIR`/lock; it now has `$OWN_DIR` plus the lock. The remaining guard carries more weight than before, and it is the one with no pressure-pass coverage. ## Acceptance criteria 1. A selftest scenario fails if `$OWN_DIR` protection is removed from the pressure pass specifically. Red-prove it with that exact mutation — the one described above, which currently leaves the suite green. 2. The assertion tests directory **contents**, not existence, or scenario 9 gets its own under-pressure `run_prune` so pass 3's recreate cannot mask the result. 3. `bash scripts/selftest.sh` green. ## Notes - Surfaced by PR #25's final review, which recorded it as a follow-up rather than a blocker: the guard is correct in the code as written, it is the *test* that is missing. That judgement looks right — but the mutation result means a future refactor of `protected_reason` would be unguarded, which is exactly when it would matter. - Two other findings from that review: a comment-drift entry recorded on the standing docs-drift catalog, and a lowest-severity nit about an incomplete causal account at `prune-cache.sh:76-79` (it names `publish-snapshot.sh`'s unshare where the seed side calls the same `unshare_mutable_paths`; nothing false, not worth a round).
claude added the bug label 2026-09-22 16:08:53 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: daniel/gitdan-actions#26