Skip to content

fix(parser): #558 — honest-reject removed assume(...); fix misnamed fixture#598

Merged
hyperpolymath merged 3 commits into
mainfrom
fix/558-refinement-honest-reject
Jun 14, 2026
Merged

fix(parser): #558 — honest-reject removed assume(...); fix misnamed fixture#598
hyperpolymath merged 3 commits into
mainfrom
fix/558-refinement-honest-reject

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Context — the premise is stale

#558 reports refinement-type predicates that "parse but are silently not enforced (TRefined)". Investigation shows this is no longer accurate: TRefined does not exist in the AST, and refinement/dependent types (including T where (P) and assume(predicate)) were removed 2026-04-10 (spec.md §711–713, §1849). Refinement syntax parse-errors today — there is no silent-accept / accepts-wrong-program path, so this is not the live soundness hole the issue describes. The genuine residual defects are honesty ones, addressed here where viable.

Changes

  1. assume(...) honest-rejection (lib/parser.mly). The ASSUME keyword token was left dangling (no production) by the 2026-04-10 grammar removal, so assume(...) surfaced a cryptic generic parse error. Add a conflict-free production (ASSUME is a fresh token — zero new LR conflicts; verified 68 s/r + 7 r/r unchanged) that raises a deliberate, named error pointing at the removed feature.
  2. Fix the misnamed fixture. refinement_types.affine contained only generic functions (no refinement, no where) yet produced a green refinement_types test — false coverage. Renamed to generic_functions.affine + test_parse_generic_functions, comment corrected.

Deliberately out of scope

  • T where (P) honest-rejection is non-viable. It cannot be fenced without regressing trait where-clauses: the shared WHERE token forces a shift/reduce decision before the predicate is visible, and menhir resolves it by shifting into the refinement — breaking fn f() -> T where C. It still surfaces a generic parse error.
  • The doc-lies (CAPABILITY-MATRIX.adoc "TRefined parses", STATE/TECH-DEBT CORE-05 rows) are owner-only edits — the strict SPDX-header pre-commit gate on .adoc/.md blocks them. Flagged for manual reconciliation.
  • Dead error codes E0305/W0701 left in place (harmless; removal is churn).

Tests

New E2E Parse cases — generic_functions (parses, honest coverage) and assume() honest-rejection (#558) (deliberate parse error). Full suite 452/452 green.

Refs #558 — recommend reframing the issue from "soundness" to "doc-truthing + hygiene"; the doc reconciliation is the remaining owner-gated step.

🤖 Generated with Claude Code

… fixture

#558's premise is stale. Refinement/dependent types — and the `T where (P)`
and `assume(predicate)` forms — were REMOVED 2026-04-10 (spec.md §711-713,
§1849). `TRefined` does not exist in the AST and refinement syntax
PARSE-ERRORS today; there is no silent-accept / accepts-wrong-program path,
so this is not the live soundness hole the issue describes. The genuine
residual defects are honesty ones:

1. The `ASSUME` keyword token was left dangling (no production) by the grammar
   removal, so `assume(...)` surfaced a cryptic generic parse error. Add a
   conflict-free honest-rejection production (ASSUME is a fresh token — zero
   new LR conflicts, verified: 68 s/r + 7 r/r unchanged) that raises a
   deliberate, named error pointing at the removed feature (CORE-05 deferred).

2. test/e2e/fixtures/refinement_types.affine contained only generic functions
   (no refinement, no `where`) yet produced a green "refinement_types" test —
   false coverage. Rename to generic_functions.affine +
   test_parse_generic_functions, and correct its header comment.

NOT done here (out of scope / non-viable):
- The refinement TYPE form `T where (P)` cannot be honestly fenced without
  regressing trait where-clauses: the shared `WHERE` token forces a
  shift/reduce decision before the predicate is visible (menhir resolves it by
  shifting into the refinement, breaking `fn f() -> T where C`). It still
  surfaces a generic parse error.
- The doc-lies (CAPABILITY-MATRIX.adoc "TRefined parses", STATE/TECH-DEBT
  CORE-05 rows) are owner-only edits (strict SPDX-header pre-commit gate on
  .adoc/.md); flagged for manual reconciliation.
- Dead error codes E0305/W0701 left in place (harmless; removal is churn).

New tests (test/test_e2e.ml, "E2E Parse"):
- generic_functions                → parses (renamed, honest coverage)
- assume() honest-rejection (#558)  → deliberate parse error (negative)

Full suite 452/452 green.

Refs #558

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 40 issues detected

Severity Count
🔴 Critical 2
🟠 High 22
🟡 Medium 16

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action denoland/setup-deno@v2 needs attention",
    "type": "unpinned_action",
    "file": "publish-jsr.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in scorecard-enforcer.yml",
    "type": "scorecard_publish_with_run_step",
    "file": "scorecard-enforcer.yml",
    "action": "split_scorecard_publish_job",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in instant-sync.yml",
    "type": "secret_action_without_presence_gate",
    "file": "instant-sync.yml",
    "action": "peter-evans/repository-dispatch",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Shell execution -- validate input before passing to shell (1 occurrences, CWE-78)",
    "type": "js_exec_sync",
    "file": "/home/runner/work/affinescript/affinescript/packages/affinescript-cli/mod.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "Shell execution -- validate input before passing to shell (2 occurrences, CWE-78)",
    "type": "js_exec_sync",
    "file": "/home/runner/work/affinescript/affinescript/packages/affine-vscode/mod.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "Shell execution -- validate input before passing to shell (1 occurrences, CWE-78)",
    "type": "js_exec_sync",
    "file": "/home/runner/work/affinescript/affinescript/affinescript-vite/src/affine-plugin-improved.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "expect() in hot path (32 occurrences, CWE-754)",
    "type": "expect_in_hot_path",
    "file": "/home/runner/work/affinescript/affinescript/affinescriptiser/src/codegen/wasm_gen.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "expect() in hot path (29 occurrences, CWE-754)",
    "type": "expect_in_hot_path",
    "file": "/home/runner/work/affinescript/affinescript/affinescriptiser/src/codegen/affine_gen.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "unsafe block -- requires SAFETY comment (2 occurrences, CWE-676)",
    "type": "unsafe_block",
    "file": "/home/runner/work/affinescript/affinescript/runtime/src/panic.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "unsafe block -- requires SAFETY comment (1 occurrences, CWE-676)",
    "type": "unsafe_block",
    "file": "/home/runner/work/affinescript/affinescript/runtime/src/alloc.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 40 issues detected

Severity Count
🔴 Critical 2
🟠 High 22
🟡 Medium 16

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action denoland/setup-deno@v2 needs attention",
    "type": "unpinned_action",
    "file": "publish-jsr.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in scorecard-enforcer.yml",
    "type": "scorecard_publish_with_run_step",
    "file": "scorecard-enforcer.yml",
    "action": "split_scorecard_publish_job",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in instant-sync.yml",
    "type": "secret_action_without_presence_gate",
    "file": "instant-sync.yml",
    "action": "peter-evans/repository-dispatch",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Shell execution -- validate input before passing to shell (1 occurrences, CWE-78)",
    "type": "js_exec_sync",
    "file": "/home/runner/work/affinescript/affinescript/packages/affinescript-cli/mod.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "Shell execution -- validate input before passing to shell (2 occurrences, CWE-78)",
    "type": "js_exec_sync",
    "file": "/home/runner/work/affinescript/affinescript/packages/affine-vscode/mod.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "Shell execution -- validate input before passing to shell (1 occurrences, CWE-78)",
    "type": "js_exec_sync",
    "file": "/home/runner/work/affinescript/affinescript/affinescript-vite/src/affine-plugin-improved.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "expect() in hot path (32 occurrences, CWE-754)",
    "type": "expect_in_hot_path",
    "file": "/home/runner/work/affinescript/affinescript/affinescriptiser/src/codegen/wasm_gen.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "expect() in hot path (29 occurrences, CWE-754)",
    "type": "expect_in_hot_path",
    "file": "/home/runner/work/affinescript/affinescript/affinescriptiser/src/codegen/affine_gen.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "unsafe block -- requires SAFETY comment (2 occurrences, CWE-676)",
    "type": "unsafe_block",
    "file": "/home/runner/work/affinescript/affinescript/runtime/src/panic.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "unsafe block -- requires SAFETY comment (1 occurrences, CWE-676)",
    "type": "unsafe_block",
    "file": "/home/runner/work/affinescript/affinescript/runtime/src/alloc.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath hyperpolymath enabled auto-merge (squash) June 14, 2026 16:39
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 40 issues detected

Severity Count
🔴 Critical 2
🟠 High 22
🟡 Medium 16

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action denoland/setup-deno@v2 needs attention",
    "type": "unpinned_action",
    "file": "publish-jsr.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in scorecard-enforcer.yml",
    "type": "scorecard_publish_with_run_step",
    "file": "scorecard-enforcer.yml",
    "action": "split_scorecard_publish_job",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in instant-sync.yml",
    "type": "secret_action_without_presence_gate",
    "file": "instant-sync.yml",
    "action": "peter-evans/repository-dispatch",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Shell execution -- validate input before passing to shell (1 occurrences, CWE-78)",
    "type": "js_exec_sync",
    "file": "/home/runner/work/affinescript/affinescript/packages/affinescript-cli/mod.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "Shell execution -- validate input before passing to shell (2 occurrences, CWE-78)",
    "type": "js_exec_sync",
    "file": "/home/runner/work/affinescript/affinescript/packages/affine-vscode/mod.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "Shell execution -- validate input before passing to shell (1 occurrences, CWE-78)",
    "type": "js_exec_sync",
    "file": "/home/runner/work/affinescript/affinescript/affinescript-vite/src/affine-plugin-improved.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "expect() in hot path (32 occurrences, CWE-754)",
    "type": "expect_in_hot_path",
    "file": "/home/runner/work/affinescript/affinescript/affinescriptiser/src/codegen/wasm_gen.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "expect() in hot path (29 occurrences, CWE-754)",
    "type": "expect_in_hot_path",
    "file": "/home/runner/work/affinescript/affinescript/affinescriptiser/src/codegen/affine_gen.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "unsafe block -- requires SAFETY comment (2 occurrences, CWE-676)",
    "type": "unsafe_block",
    "file": "/home/runner/work/affinescript/affinescript/runtime/src/panic.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "unsafe block -- requires SAFETY comment (1 occurrences, CWE-676)",
    "type": "unsafe_block",
    "file": "/home/runner/work/affinescript/affinescript/runtime/src/alloc.rs",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath hyperpolymath merged commit 58dc2a0 into main Jun 14, 2026
27 checks passed
@hyperpolymath hyperpolymath deleted the fix/558-refinement-honest-reject branch June 14, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant