[sergo] Sergo Report: STABLE-73 Reconcile + Never-Audited Backlog Exhaustion - 2026-09-26 #63552
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by Sergo - Serena Go Expert. A newer discussion is available at Discussion #63769. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Overview
Run R78 (workflow run 36215881512). Registry held steady at 73 analyzers (no new linter since R74). All 13 pre-run open sergo issues were reconciled and confirmed still open, with zero reverse-phantom flips for the first time since R73 - a quiet run on the reconcile side. New-exploration work solo-audited the final 6 never-before-audited linters, exhausting that backlog, and turned up 2 new confirmed bugs in the well-established
paren_unwrap_gappattern class.Key Findings
extractStatusLiteraland the switch-case branch ofrunboth use a bare*ast.BasicLitassertion on the literal side with noastutil.UnwrapParenExprcall, soresp.StatusCode == (404)orcase (404):silently escapes detection. Confirmed CI-enforced in both native and wasm custom-linter runs.isBoolTruemisses parenthesized(true), causing false negatives (issue filed, temp id aw_sg78a2). Same missing-unwrap shape, but here it is the inverse direction of the usual pattern: a parenthesizedtruevalue makes a genuinely set-shapedmap[string]boolinvisible to the linter instead of causing a false positive. Affects both call sites of the helper. Not currently CI-enforced.ioutildeprecatedandssljsonaudited clean this run;errormessageandmapclearloopeach have only a very weak, unrealistic paren-wrap shape not worth filing. Every linter in the registry has now had at least one solo bug-focused audit pass.Strategy Split (50/50)
Generated Issues (2)
Full evidence and recommendations
httpstatuscode (pkg/linters/httpstatuscode/httpstatuscode.go):
extractStatusLiteral(163-171) doesexpr.X.(*ast.BasicLit)/expr.Y.(*ast.BasicLit), and the switch-case handling inrun(126) doescaseExpr.(*ast.BasicLit)- both without unwrappingast.ParenExprfirst. Fix: callastutil.UnwrapParenExprbefore each assertion, matching the idiom already used inwalkfuncerrshadow.go,mapdeletecheck.go, andtypeassertionokdiscarded.go.seenmapbool (pkg/linters/seenmapbool/seenmapbool.go):
isBoolTrue(248-251) does a bareexpr.(*ast.Ident)assertion for the identifiertrue. Both call sites -findNonSetMaps(191) andmarkIfNonSetLiteral(223) - rely on this to decide whether a write is a true-set-write; a parenthesized(true)fails the assertion and gets treated as a non-set write, suppressing a valid finding for that map variable.Metrics
Historical Context
This is the second run (after R73) with zero reverse-phantom flips on reconcile, suggesting either team attention has shifted elsewhere or the backlog of easy auto-expiring issues has thinned. The
paren_unwrap_gappattern class now has confirmed instances across 9+ linters and 2 shared helpers (astutil.StringLitValue/IsStringLiteral), making it the single most productive recurring vein this project has found. This run also produced the first known false-negative-direction instance of the class (seenmapbool), broadening its documented shape.Next-Run Focus
The never-solo-audited linter backlog is now empty. R79 should either (a) re-probe already-audited-clean linters for bug classes distinct from whichever one they were originally checked against, or (b) wait for the registry to grow past 73 and audit any new linter fresh. Also worth periodically pruning the oldest
tool_change_RXXentries in the tools-list cache file, which has grown to roughly 96 KB across memory files.References:
All reactions