feat(gatorwalk-factory): warn when a product CEL reads is not produced on every path (swamp-club #2792) #405

Merged
seth merged 2 commits from cue/2792-gatorwalk-factory-warn into main 2026-10-01 12:00:18 +00:00
Owner

Closes swamp-club #2792.

validate's product-missing-on-path warning now covers products read by CEL: a stage's work.bindings, its cel gates and its human-approval gates' when. It reuses the fixed-reference walker from #2680 (cel_refs.ts).

  • A read the same expression also tests for (has(artifacts.plan), "plan" in artifacts) is exempt. The guard may sit anywhere in the expression, which is generous on purpose.
  • artifacts.x and validations.artifacts.x are one product, reported once per expression, anchored at the expression's path (stages.N.work.bindings.<name>, ...gates.K.config.expr|when).
  • An unguarded read of a missing product throws at run time ("No such key"), so CEL reads are reported even when no path produces the product and even from the stage's own loop, unlike injects and named gates.
  • Bindings are evaluated when the stage is entered, before it records anything, so the stage's own products do not count for them. Gates and when are evaluated at the transition, where they do.
  • Not checked: global transitions, payload field paths, optional access (cel-js 7.6.1 does not parse it).

The bundled examples gain no warnings. DESIGN.md, the README and the skill's authoring table are updated.

Verification: verify-build and verify-reviews passed on 45791db95 (attestation 5a2239f1-492b-4d70-834e-3e19fe6fadbd). Both reviews pass, with low notes only.

🤖 Generated with Claude Code

Closes swamp-club #2792. validate's `product-missing-on-path` warning now covers products read by CEL: a stage's `work.bindings`, its `cel` gates and its human-approval gates' `when`. It reuses the fixed-reference walker from #2680 (`cel_refs.ts`). - A read the same expression also tests for (`has(artifacts.plan)`, `"plan" in artifacts`) is exempt. The guard may sit anywhere in the expression, which is generous on purpose. - `artifacts.x` and `validations.artifacts.x` are one product, reported once per expression, anchored at the expression's path (`stages.N.work.bindings.<name>`, `...gates.K.config.expr|when`). - An unguarded read of a missing product throws at run time ("No such key"), so CEL reads are reported even when no path produces the product and even from the stage's own loop, unlike injects and named gates. - Bindings are evaluated when the stage is entered, before it records anything, so the stage's own products do not count for them. Gates and `when` are evaluated at the transition, where they do. - Not checked: global transitions, payload field paths, optional access (cel-js 7.6.1 does not parse it). The bundled examples gain no warnings. DESIGN.md, the README and the skill's authoring table are updated. Verification: verify-build and verify-reviews passed on 45791db95 (attestation 5a2239f1-492b-4d70-834e-3e19fe6fadbd). Both reviews pass, with low notes only. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
validate's product-missing-on-path pass now also checks the fixed product
references in a stage's work.bindings, cel gates and human-approval when,
using the #2680 walker. A read the same expression tests for (has(),
"x" in artifacts) is exempt. CEL reads are reported even when no path
produces the product and even from the stage's own loop, since an
unguarded read throws at run time. Bindings are judged on entry, so the
stage's own products do not count for them.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
docs(gatorwalk-factory): note what the CEL path warning leaves out (swamp-club #2792)
All checks were successful
CI / Review Integrity (pull_request) Successful in 41s
CI / Validate Attestation (pull_request) Successful in 52s
45791db957
DESIGN.md says global transitions' CEL is not checked and that a binding
read in a loop is judged on the first pass; README re-wraps the graph
validation bullet. From the verify-reviews low findings.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seth merged commit 8d4993426f into main 2026-10-01 12:00:18 +00:00
seth deleted branch cue/2792-gatorwalk-factory-warn 2026-10-01 12:00:18 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
swamp-club/swamp-extensions!405
No description provided.