From c1d4f95f6279d93f60f37abf56d28cdd75bf1728 Mon Sep 17 00:00:00 2001 From: baku-ccron Date: Wed, 16 Sep 2026 11:54:09 +0000 Subject: [PATCH 1/2] audit: record the #76 measurement, which adds no test The five documented claims of #76 were measured rather than assumed. 28 mutants over every behaviour of LibHashNoAlloc: the suite as it stands kills 28/28, and the seven tests the issue proposes, written in their strongest library-calling form and probed alone, kill 23 of those 28 and nothing the suite misses. One of the seven kills nothing because its claim is about the compiler's memory layout and it never calls the library. So no test is added and the scan record is the whole change. The mutants and both probe transcripts are on hash-76-measurement, which is evidence, not a proposal. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01V8ViHcKLVk2YoS2joH4HdN --- audit/mutation-test-scans.json | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/audit/mutation-test-scans.json b/audit/mutation-test-scans.json index ce72913..c264358 100644 --- a/audit/mutation-test-scans.json +++ b/audit/mutation-test-scans.json @@ -21,5 +21,28 @@ "filed": ["#20", "#21", "#22", "#23", "#24", "#25", "#26", "#27"], "notes": "Library code: no miscomputation found; all four functions and HASH_NIL match cast keccak known answers. Survivors were the unasserted no-allocation / memory-safe promise (free memory pointer and zero slot). Filed issues are README/NatSpec/test-harness defects and one security-argument premise (#22, refs #7). testsAfterCommit is the merge commit of PR #19 on main." } + }, + { + "timestamp": "2026-09-16T11:37:04Z", + "commit": "f2a9f5f613a82752761c4a17d70597ece17adb97", + "testsAfterCommit": null, + "publishedTag": "sol-v0.1.25", + "commitsAheadOfTag": 0, + "scope": "src/lib/LibHashNoAlloc.sol, against the five documented claims of #76", + "tool": "mutation-probe (adversarial-mutation-test 4e59ec0c)", + "skillVersion": "0.34.0", + "summary": { + "behaviours": 28, + "mutantsKilledByPreExistingSuite": 28, + "mutantsSurvivedPreExistingSuite": 0, + "mutantsKilledAfter": 28, + "candidates": 0, + "confirmed": 0, + "testsBefore": 77, + "testsAfter": 77, + "coveragePRs": [], + "filed": [], + "notes": "Mutation probe only, no adversarial pass. 28 mutants over every behaviour the library has: the read offset and byte count of hashBytes and of both hashWords overloads, the two scratch writes and the hashed range of combineHashes, the HASH_NIL literal, and the no-allocation promise of all four. All 28 die to the suite as it stands. The seven tests #76 proposes were written and probed against the same 28: between them they kill 23, none of which the suite misses, and they miss the four no-allocation mutants and HASH_NIL. No test added. main moved to 6afa299 after this scan by a README-only commit, so src/ and test/ are byte-identical to the scanned commit." + } } ] From 53f8d7590e944cdd3fc8cedb1323e19648bfc384 Mon Sep 17 00:00:00 2001 From: baku-ccron Date: Wed, 16 Sep 2026 12:01:33 +0000 Subject: [PATCH 2/2] audit: the scan note names main's NatSpec move, not just the README one #114 landed on main after the record was written. It changes only /// lines in LibHashNoAlloc, so no mutated line moved, but "src/ and test/ are byte-identical to the scanned commit" is no longer literally true and the note now says what is. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01V8ViHcKLVk2YoS2joH4HdN --- audit/mutation-test-scans.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/audit/mutation-test-scans.json b/audit/mutation-test-scans.json index c264358..2c9dd30 100644 --- a/audit/mutation-test-scans.json +++ b/audit/mutation-test-scans.json @@ -42,7 +42,7 @@ "testsAfter": 77, "coveragePRs": [], "filed": [], - "notes": "Mutation probe only, no adversarial pass. 28 mutants over every behaviour the library has: the read offset and byte count of hashBytes and of both hashWords overloads, the two scratch writes and the hashed range of combineHashes, the HASH_NIL literal, and the no-allocation promise of all four. All 28 die to the suite as it stands. The seven tests #76 proposes were written and probed against the same 28: between them they kill 23, none of which the suite misses, and they miss the four no-allocation mutants and HASH_NIL. No test added. main moved to 6afa299 after this scan by a README-only commit, so src/ and test/ are byte-identical to the scanned commit." + "notes": "Mutation probe only, no adversarial pass. 28 mutants over every behaviour the library has: the read offset and byte count of hashBytes and of both hashWords overloads, the two scratch writes and the hashed range of combineHashes, the HASH_NIL literal, and the no-allocation promise of all four. All 28 die to the suite as it stands. The seven tests #76 proposes were written and probed against the same 28: between them they kill 23, none of which the suite misses, and they miss the four no-allocation mutants and HASH_NIL. No test added. main has since moved to 092293e by a README-only commit and a NatSpec-only commit: test/ is byte-identical to the scanned commit and src/ differs from it only in /// lines, so every mutated line is unchanged." } } ]