[sergo] Sergo Report: STABLE-73 Reverse-Phantom Double-Refile - 2026-09-23 #62863
Closed
Replies: 1 comment
|
This discussion was automatically closed because it expired on 2026-09-24T03:56:15.996Z.
|
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Overview
Run §35815762269 (R75 in Sergo history). Linter registry held STABLE at 73 analyzers (no new linter since R74s uncheckedsliceindex). Reconcile found 2 of the 14 pre-run open sergo issues had auto-expired (closed/not_planned) without any code change landing, so both were refiled with fresh code citations. A cached-vein follow-up confirmed a known root-cause bug extends further into the newest linter, but that finding was folded into an existing open issue instead of a duplicate filing.
Key metrics
grep -c Analyzer, pkg/linters/registry.go= 73, unchanged since R74)activate_projectOK for go/typescript/bash, no approval promptsStrategy: 50/50 split
Cached component (reconcile-driven, ~50%): Re-verify all pre-run open issues against current code before deciding whether new findings are needed. Two issues had flipped to closed/not_planned since the last run:
internal/nolintspace-prefix directive bug (originally internal/nolint: HasDirectiveForLinter ignores space-prefixed nolint directives #59122, refiled internal/nolint: space-prefixed "// nolint:" directive still silently ignored (issue 59122 auto-expired, bug unfixed) #61023, both auto-expired) - re-readnolint.go:59-60and confirmedstrings.TrimPrefix(comment.Text, "//")still leaves a leading space for the common// nolint:xspelling, which then failsstrings.HasPrefix(text, "nolint:"). Byte-for-byte unchanged. Refiled.blankassigncommaidiom-reflag (originally blankassigncomma (71st linter): flags 14+ production sites that are deliberate idiomatic error-discards #61024) - re-readblankassigncomma.go:52-57and confirmed no allow-list or comment-aware exception was added; the same 14+ production_, _ = f()sites (the codebases manual substitute for a disabled errcheck exclude-list) are still re-flagged. Refiled.New-exploration component (~50%): Followed up on last runs suggested next step - whether
uncheckedsliceindex.goshasTerminatingGuardBefore/invalidBounds/writesObjectsfunctions share thesameExprIdent-only root cause already filed as #62540. Confirmed they do (same helper, same limitation, lines 325/356/359/466). Since this strengthens rather than duplicates an already-open issue, no new issue was filed from it - it is logged as a candidate follow-up comment on #62540 if that issue stays open.Findings this run
Finding 1: internal/nolint space-prefix directive bug (4th reverse-phantom)
pkg/linters/internal/nolint/nolint.go:59-60treats// nolint:linter(with the gofmt-normal single space after//) as a non-directive plain comment, becauseTrimPrefix(comment.Text, "//")leaves the leading space attached and the subsequentHasPrefix(text, "nolint:")check then fails. This is shared infrastructure used by every one of the 73 registered linters, so any contributor using the spaced style gets silently unsuppressed diagnostics. This is the 4th time this exact bug has been filed and auto-expired without a fix landing.Finding 2: blankassigncomma re-flags established codebase idiom (2nd reverse-phantom)
pkg/linters/blankassigncomma/blankassigncomma.go:52-57still has no allow-list or comment-aware exception, so it continues to flag 14+ production sites where_, _ = f()is the deliberate, already-adopted workaround for.golangci.yml:37s disabled errcheck exclude-functions mechanism (e.g.hash.Hash.Write, which never errors in practice). Not yet CI-enforced, but the underlying design gap is unchanged from the first audit.Finding 3 (no new issue): uncheckedsliceindex early-return guard shares the same root cause as #62540
hasTerminatingGuardBefore,invalidBounds, andwritesObjectsall call the samesameExprhelper (Ident-only equality) already diagnosed in #62540s selector-base blind spot. A single fix tosameExprwould resolve both the previously-filed bounds-check gap and this early-return-guard gap at once. Logged for a follow-up comment rather than a duplicate issue.Tasks generated (2)
nolint:prefix check ininternal/nolint/nolint.go, add a spaced-directive testdata fixture.blankassigncommabefore considering it for CI enforcement.Historical context
This run continues a long-running pattern: several sergo-filed bugs get auto-expired (closed/not_planned) by repository automation without the underlying code changing. This is the 8th confirmed instance of that pattern across different bug lineages, and the 4th generation specifically for the nolint space-prefix bug. Total across all 75 runs: 477 findings, 131 tasks generated, average success score 8.8/10.
Recommendations
internal/nolintspace-prefix fix: it is shared infrastructure affecting every linters suppression mechanism, the highest-leverage open item in the backlog.Next-run focus (R76)
Re-verify #62541, #62540, #62304, #62115, #62114, #61948, #61947, #61715, #61714, #61519, #61518, #61265 plus this runs sg75a1/sg75a2. If the registry grows to 74 analyzers, audit the new linter fresh. If #62540 is still open, add a follow-up comment citing this runs
hasTerminatingGuardBeforeconfirmation rather than filing a new issue.References:
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
api.anthropic.comTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.
All reactions