Skip to content

fix(jq): let a ?// retry in a slice bound supersede the slice's stash - #3434

Merged
newhoggy merged 10 commits into
mainfrom
issue-3293-slice3-slice-bounds-collected-index
Sep 28, 2026
Merged

newhoggy merged 10 commits into
mainfrom
issue-3293-slice3-slice-bounds-collected-index

Conversation

@newhoggy

@newhoggy newhoggy commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Slice 3 of #3293: a ?// retry inside a slice bound now supersedes the escape that the retried-past alternative left in the slice collector. Fixed in both evaluators: eval_generic::eval_slice_expr (cursor route) and eval::eval_slice_expr (owned route).

filter (on [10,20]) jq 1.7.1 main
.[([[0]] as [$a] ?// [[$a]] | $a):] [10,20] slice indices must be integers, exit 5
.[([[0]] as [$a] ?// $b | $a // empty):] empty, exit 0 same error
.[([[0]] as [$a] ?// $b | $a | if . == null then error("E2") else . end):] E2 the slice error
.[([[0]] as [$a] ?// {k: $b} | $a):] Cannot index array with string "k" the slice error

Both collectors parked a per-pair escape as a finished result: terminal = partial(take(out), control). Nothing could clear it after a retry, and it held the output prefix hostage. The escape now lives in a StashedEscape (#3411), kept apart from out:

  • both bound sinks reset it per invocation;
  • the end drive is settled per start value;
  • the final result folds out in as the Partial prefix only if the stash survived (retry_superseded).

Moving the prefix out of the stash is what lets a superseded escape leave already-produced outputs in place.

The collected computed-index route ([.[G]]), the other slice-3 item on #3293, already matches jq on both routes on current main. I checked the four retry endings under [.[G]], [.[G], 7] and [.[G]] | length.

Review round (/code-review high)

  • Fixed a panic, then its root cause. .[first([[0]] as [$a] ?// [[$a]] | $a):] panicked (exit 101) on both evaluators; jq gives [10,20,30].
    • The first fix treated a stash-less Stopped as completion. The second review showed that only hid the real bug: each_limit and take_at_index (first/nth), plus their generic twins, never cleared outer_stopped, so after a ?// retry they reported a stale Stopped to whatever enclosed them. That's jq: audit other fan-out sinks for #2952's stale-escape-across-a-?//-retry shape #3293's Class 2 shape in the consumers themselves. It cut a following comma short ([.[(first(G), 2):]] gave [[20,30]]; jq gives [[20,30],[30]]) and kept the stale error when a filter dropped the retried value.
    • The flag now resets per invocation, as fix(jq): let a ?// retry supersede verdicts stashed by value-mode fan-out sinks #3411 did for the value-mode sinks. The jq: ?// alternatives re-run once per alternative under a short-circuiting consumer's internal label/break #1519 double answers are unchanged ([first(first(1 as $x ?// $y | 1))] is still [1,1]), and the slice collectors' Stopped arms are back to their strict form.
    • Tests: 15 wrapper rows in the slice table and a new RETRY_ROWS_WRAPPER_STOP_3293 table, both run on both evaluators.
    • Third review: isempty, any/all, IN and generic repeat keep the same stale flag. Reached through a stop-then-continue shape (input), it panicked in the slice collector. isempty, any/all and IN now reset per invocation in both evaluators. The dedicated test has input rows on both routes: six owned-route rows under -n and four cursor-route rows that reach the generic twins.
    • Fourth review: no regression against main across about 5,500 differential cases. A stash-less Stopped in the slice collectors now panics under debug_assertions, so a regressing driver fails the suite, and in a release build it finishes with out. The arm carries region-form coverage markers, which rustfmt can't split off. The repeat reset was reverted: no retry reaches it, and first(repeat(G)) diverges exactly as on main. // doesn't reset its stop flag, but no probe has found it diverging.
  • Fixed: stale terminal comments; end's retry fallback is hoisted out of the per-value closure.
  • Deferred: path mode (resolve_slice_expr_sink under path/del/|=) still lets the abandoned alternative's slice error win. It's the write-direction resolver, so it belongs with jq: audit other fan-out sinks for #2952's stale-escape-across-a-?//-retry shape #3293's path-context slice and its own review; I've listed it there.
  • Not changed: the exit reads the stash with take + partial rather than resume_from_escape, so a stashed nonretryable flag is not cleared at this reclaim. That's unchanged from main's terminal path.

Part of #3293.

Test plan

  • Probe, both routes: 32 slice and collected-index rows go from 16 DIFF to 0 on each route, and 12 prefix/ordering controls match jq on both routes. Everything was checked against /usr/bin/jq 1.7.1.
  • New RETRY_ROWS_SLICE_BOUND_3293 table (38 rows, including 15 wrapper rows, generated from jq 1.7.1), run over a document input and, through the owned-route test, over a -n-built value.
  • cargo test --features cli,simd,regex,serde: 9443 passed (after rebase), 0 failed. cargo test --no-default-features passes.
  • cargo clippy -- -D warnings for all three variants; cargo fmt --check; RUSTDOCFLAGS=-D warnings cargo doc.

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Coverage

Total: 94.32% ⚪ 0 pp vs main

Comparing 9985935..750c4fd (merge-base → PR head)

No per-file coverage changes vs main.

🔇 0 ignored region(s), 280 tolerated region(s)

ignore removes the lines from both reports; tolerate keeps them in the reported percentage but scores them against the baseline, so a cross-run flip cannot move a delta. Regions are read from each revision's own source.

File Kind Lines Rev Reason
src/bin/succinctly/jq_runner.rs tolerate 1094 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted, for the identical reason run_jq's own analogous fallback (#2395) is tolerated -- see that line's own comment (#2950)
src/bin/succinctly/jq_runner.rs tolerate 2148-2160 both unreachable: try_parse_meta_op only fires under ParserMode::Yq (src/jq/parser.rs), and rewrite_namespaced_calls is only reached via ModuleProcessor::process_program, which jq_runner's own jq-mode run is the sole caller of -- so a MetaAssign node can never reach this function (#798)
src/bin/succinctly/jq_runner.rs tolerate 2747 both unreachable by construction: every error this wrapper receives today is a decode or nesting-depth failure the evaluator raised itself, never error(v); kept so a future one is rendered rather than dropped (#2999)
src/bin/succinctly/jq_runner.rs tolerate 2748 both see the arm above (#2999)
src/bin/succinctly/jq_runner.rs tolerate 3164 both unreachable in practice today: def is only None when occurrences.module_def() is None, which (given origin is Some) would require an open run whose innermost frame has no def set at a check point that isn't itself inside a module-level def body -- but every module run is a strict chain of def nodes (the loader's own defs, each wrapping its dependency stubs INSIDE its own body via wrap_defs/dep_stubs_for) terminated by the run's own end marker, so a diagnosable call/var/break site is always reached either inside a module-level def's body (module_def Some) or outside every run (origin None) -- and even when def is Some, self.defs is always ModuleSource::read's own re-parse of the exact same file run_id_for interned this origin's id from, so collect_def_sites always finds the matching (name, arity, ordinal) span. Kept as a defensive fallback rather than a panic/unwrap in case that invariant is ever violated (#3085)
src/bin/succinctly/jq_runner.rs tolerate 3413-3416 both unreachable in a single-process run by construction: run_id_for (the sole source of an origin id) always inserts a run_origins entry for the id it hands back -- from a real load's canonical path, or its own literal-path fallback on a resolve failure -- and a def body only ever gets stamped with an origin after its module loaded successfully, so at always names a file that existed and was readable moments earlier. Reaching this arm needs that same file to vanish (or become unreadable) in the narrow window between that load and this re-read, entirely outside this process's control (#2964)
src/bin/succinctly/jq_runner.rs tolerate 3680 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted -- a newly covered name only wraps an already-successful dedicated parse, and a failing one would have propagated its error in the first parse too, so the retry budget is charged at the identical sites in both (#2395)
src/bin/succinctly/jq_runner.rs tolerate 9419 both unreachable: this test builds only ResolveError::Call values (#3313)
src/bin/succinctly/jq_runner.rs tolerate 11370 both unreachable in a passing suite by design -- the fixed b\
src/bin/succinctly/main.rs tolerate 1356 both unreachable given clap 4.6's own unknown_argument() error constructor: every ErrorKind::UnknownArgument it builds sets ContextKind::InvalidArg to ContextValue::String(arg) in the same call, so this arm only guards a future clap release changing that invariant
src/bin/succinctly/main.rs tolerate 1397 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_accepted_via_sjq_multicall_alias_3389's '-x' row demonstrably reaches the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1559 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_boundary_characters_3389's '-x'/'-n1'/'--bogus' rows demonstrably reach the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1581 both the CLI suites drive yq through the syq multi-call arm above; this arm is the same call reached only when spelled succinctly yq (#2999)
src/bin/succinctly/yq_runner.rs tolerate 1652 both unreachable: bytes already parsed successfully by every caller (#1350)
src/bin/succinctly/yq_runner.rs tolerate 1741 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1742 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1743 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 3330 both unreachable: path is always the raw output of the path(TARGET) builtin evaluated a few lines up in resolve_one_meta_assign -- path/1 is a jq/yq language invariant that always answers an array of path components (see Expr::Builtin(Builtin::PathNoArg) => Ok(Some(OwnedValue::Array(..))) in eval_generic.rs), never any other shape (#798)
src/bin/succinctly/yq_runner.rs tolerate 3430 both unreachable: resolve_meta_assign_writes runs expr through this before any evaluation begins (see its own doc comment), and Expr::Shared is never constructed by the parser -- only at eval time, by function-call argument substitution (substitute_func_param in eval.rs) -- so a pre-evaluation AST can never contain one here (#798)
src/bin/succinctly/yq_runner.rs tolerate 4062 both unreachable: every arm of the match result { .. } above that assigns docs (L3492-3622) constructs Ok(..) -- none ever produces Err, so this if let's implicit else can't be taken; symmetric to L1625's ? (#798)
src/bin/succinctly/yq_runner.rs tolerate 6746-6748 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 6937-6942 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 7695-7700 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/jq/document.rs tolerate 383 both unreachable: the only caller, eval_generic::embed_at_or_within, is gated on jq semantics, and the YAML cursor (the one implementor without an override) is only ever evaluated under yq semantics (#3179)
src/jq/document.rs tolerate 978-982 both unreachable: both implementors (JsonCursor, YamlCursor) override this; the default exists as the conservative-false contract a future implementor inherits (#3222)
src/jq/document.rs tolerate 1157-1164 both unreachable: both implementors (StandardJson, YamlValue) override this to decode once; the default exists as the contract a future implementor inherits, and is deliberately the two-call sequence it replaces (#965)
src/jq/eval.rs tolerate 1163 both unreachable: def is always a collect_alias_groups anchor path, which step_to_expr never fails on (#1351)
src/jq/eval.rs tolerate 1184 both unreachable: redirect_paths with Redirect::SINGLE always contributes exactly one output per input, so a 1-element paths always pops Some (#1351)
src/jq/eval.rs tolerate 1193 both unreachable: a concrete setpath/delpaths path's components are always Field/Index -- step_to_expr never produces another shape (#1351)
src/jq/eval.rs tolerate 1197 both unreachable: the map above never yields None, since it only ever matches Field/Index (#1351)
src/jq/eval.rs tolerate 1731 both unreachable: key_or_parent_root_construct's identical structural match already refused any expr shape that would reach this arm
src/jq/eval.rs tolerate 4677 both unreachable: is_escape() is exactly `Error
src/jq/eval.rs tolerate 4678 both unreachable: see the if let above -- push_owned_values never answers None for an is_escape() result (#2180)
src/jq/eval.rs tolerate 5861 both unreachable today: to_owned's only failures are is_decode_failure()-tagged, and suppresses() answers false for those whatever optional is -- the same defensive-but-dead arm eval_generic's own Builtin::Path materialization documents under #2280 (#2908)
src/jq/eval.rs tolerate 6627 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 7914 both unreachable: optional is never true here. eval_each is entered with a forced true at exactly one site (Expr::Optional over an IndexExpr/SliceExpr), and both of those evaluate their target (eval_index_expr) and their key (eval_each(key, .., false)) with a hardcoded false, so only the final index/slice step ever sees it -- nothing carries it down to an Expr::Object (#2180)
src/jq/eval.rs tolerate 9016 both unreachable: owned_write_door calls this only on a clone of a head write_target already matched, and the two list the same five variants (#3188)
src/jq/eval.rs tolerate 9030 both unreachable: every value path_over_owned hands back is a path() output, which is always an array (#3188)
src/jq/eval.rs tolerate 9309 both unreachable: any_child_witnessed is false for every non-container, checked just above (#3178)
src/jq/eval.rs tolerate 9551 both reachable only on a genuine allocation failure: owned_assign_step's single-step arms map every non-allocation error to unreachable_owned_assign_write (provably impossible, see its own doc comment), and its Chain arm's set_path call walks exactly the steps owned_assign_step_child already validated as Field-into-Object/Null or Index-in-[0,len]-into-Array/Null with no mutation in between, so the only way set_path/set_field/set_index/pad_with_nulls can still fail is the same try_reserve-fails-under-OOM branch the codebase already tolerates elsewhere (#2267) (#3138)
src/jq/eval.rs tolerate 9676 both unreachable: owned_assign_shape's only caller (owned_step_shape) gates the call on is_owned_assign(expr), which recognizes exactly Assign/Update/CompoundAssign/AlternativeAssign -- the same four variants this match already has explicit arms for, so expr can never be anything else here (#3138)
src/jq/eval.rs tolerate 9869 both unreachable: both call sites (try_eval_owned_step, gated on is_owned_assign; eval_owned_reindex_free's own Assign
src/jq/eval.rs tolerate 9943 both unreachable: this function's own doc comment states why -- the borrow on state between owned_assign_step_child's check and the single write makes the container changing shape impossible, so debug_assert!(false, ..) can never fire (#3138)
src/jq/eval.rs tolerate 9944 both unreachable: same invariant as the false above -- this message is only ever formatted if that assert fires (#3138)
src/jq/eval.rs tolerate 9946 both unreachable: this function is only called from owned_assign_step's single-step arms, both of which the invariant above already rules out ever calling it for real (#3138)
src/jq/eval.rs tolerate 9947 both unreachable: the whole function body above is provably dead by the same borrow-checker invariant its doc comment states (#3138)
src/jq/eval.rs tolerate 9984 both unreachable: Expr::pipe() (the parser's sole Pipe constructor) collapses a one-element list to the bare inner expr instead of wrapping it, and substitute_vars's substitute_var walk preserves a Pipe's stage count rather than dropping stages -- no other site builds an Expr::Pipe for a parsed assignment path, so a path's top-level Pipe here is never single-element (#3138)
src/jq/eval.rs tolerate 13034 both unreachable: every entry point supplies path context, so path never evaluates without one; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 13167 both unreachable: only ever constructed by builtin_sort_keys's own eval_update_no_vivify call, whose enclosing eval_update_impl already runs to_owned on the whole document up front (#2855) -- a decode failure anywhere raises there, before this filter ever sees a value to re-decode; confirmed live, sort_keys(.a)/sort_keys(..) on a document with a decode-failure subtree both raise from the outer to_owned
src/jq/eval.rs tolerate 13310-13312 both unreachable: builtin_length's sole caller is eval_builtin's Builtin::Length dispatch, and Length is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before this match ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 13533-13535 both unreachable: has_one_key's sole caller is builtin_has (via eval_builtin's Builtin::Has dispatch), and Has is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before builtin_has ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 16698 both unreachable: entry is one of to_entries's already-materialized {key,value} pairs, so its depth here is provably no deeper than whatever earlier check let it exist -- a document-decoded entry is already <256 deep (MAX_NESTING_DEPTH, stricter than this 384 guard), and a filter-constructed one already survived becoming a cursor via its own whole-object reindex, which is strictly deeper than any single field extracted from it could be (unwrapping only reduces depth); confirmed live, {a: (reduce range(400) as $i (0; [.]))}
src/jq/eval.rs tolerate 24420 both unreachable: escape_with_prefix! sets terminal before Demand::Stop; already returned above (#2138)
src/jq/eval.rs tolerate 24772 base unreachable: escape! sets terminal before Demand::Stop; already returned above (#2546)
src/jq/eval.rs tolerate 24777 head unreachable: a real stop always comes with a stash, returned above (#3293)
src/jq/eval.rs tolerate 24814-24819 head unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval.rs tolerate 26290 both unreachable via --eval-all: every document here comes straight from parse_input, whose own MAX_NESTING_DEPTH (256) guard already rejects anything deep enough to reach MAX_VALUE_TREE_DEPTH (384) here -- confirmed live, a 300-level document fails parse_input's guard before ever reaching this reindex (#3261)
src/jq/eval.rs tolerate 29507 both unreachable: descriptor_path_component builds a Verbatim key only from an object (#3300)
src/jq/eval.rs tolerate 33821 both reachable only on a genuine allocation failure: Vec::try_reserve(1) on a vector that has spare capacity, or can grow, cannot fail -- this is the whole purpose of the branch, converting an OOM into a catchable error rather than an abort (ADR-0018's 'would take the host process down' exception). The pre-#2267 form of the same guard, out.try_reserve(branches.len()) in resolve_index_expr/resolve_slice_expr, was 0-hit for the identical reason (#2267)
src/jq/eval.rs tolerate 33822 both see the line above -- the Demand::Stop half of the same allocation-failure-only branch (#2267)
src/jq/eval.rs tolerate 33828 both reachable only when the try_reserve above failed, i.e. only on a genuine allocation failure (#2267)
src/jq/eval.rs tolerate 36306 both unreachable: owned_value_jq_length's own match only ever constructs OwnedValue::Int or OwnedValue::Float, checked just above this arm (#2744)
src/jq/eval.rs tolerate 36841 both unreachable: is_primitive admits only Identity/Field/Index/Slice, and of those only a Slice's computed bounds can halt -- all four have their own arm in resolve_node_sink/resolve_node_eager, so none reaches this function. Pre-existing; #2694 only wrapped the return in Some (#2694)
src/jq/eval.rs tolerate 36875 both unreachable, as this arm's own comment above says: indexing or slicing a value yields zero or one result, so is_primitive never produces more than one -- kept as a named error rather than a panic. Pre-existing; #2694 only wrapped the enclosing return in Some (#2694)
src/jq/eval.rs tolerate 39734 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 40730 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), returned just above (#2872)
src/jq/eval.rs tolerate 41102 both unreachable: every arm of the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 41640 both unreachable: every path through the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 44366 both unreachable in a passing suite by design -- a panic-message format argument for the #682 single-valued-tail pin, evaluated only if that assert's own condition is false (#2190)
src/jq/eval.rs tolerate 44443 both unreachable: the only caller reaches this after classify_static_component answered Field for this same value, which it does only for an object (#2190)
src/jq/eval.rs tolerate 44487 both unreachable: both callers establish the container first -- navigate_static_component_ref via classify_static_component's Index arm, and walk_path's Expr::Iterate arm by matching on the container itself (#2190)
src/jq/eval.rs tolerate 47248 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 48904 both unreachable: stop_with_escape's only write is slot.set(Some(control)) with the control it was handed, which is always the Control::Error built one line above (#2180)
src/jq/eval.rs tolerate 49404 both unreachable: on_update records a step_outcome before every Demand::Stop it answers, and the fallback match runs only when it recorded none (#2872)
src/jq/eval.rs tolerate 49427 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 49956 both unreachable by construction: the per-fork match only ever hands stop_with_downstream a non-Exhausted flow, so terminal can never hold Exhausted. foreach_forks' identical arm is 0-hit for the same reason and is only unflagged because it predates this diff (#2899)
src/jq/eval.rs tolerate 51874 both llvm-cov line-attribution artifact, not unreachable: the new gate test above (Builtin::Length as first) demonstrably takes key_or_parent_root_construct(first) == false and falls through to the reindex-bridge route below, passing -- but this closing brace, like the one at #56920 for the same reason, is never itself credited a hit
src/jq/eval.rs tolerate 51888 both unreachable in the current test suite: eval_path_context_pipe_owned itself has zero total call-site coverage today (not just this arm), confirmed by a full-suite eprintln probe across every test binary -- reaching its error arm needs first solving how to reach the function at all, out of scope for #3261's reindex-bridge fix
src/jq/eval.rs tolerate 52928 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 55014 both pre-existing zero-hit line; #2999 changed only which null constant it names
src/jq/eval.rs tolerate 57499 both ? suppresses mktime's error outside builtin dispatch, so the optional flag is false even for an invalid date (#3083)
src/jq/eval.rs tolerate 57502 both unreachable for mktime's C-int-clamped fields: checked civil-date arithmetic stays within i64; the guard protects other callers of the shared helpers (#3083)
src/jq/eval.rs tolerate 57723 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 57726 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 57767 both optional is never true through either caller of this function -- confirmed live (eprintln! probe): `[1,2,3]
src/jq/eval.rs tolerate 57776 both every array literal written in filter source, and every array-element JSON parses, decodes to NumberLiteral (#1035), not a bare Int -- Int is for internally-synthesized values spliced post-parse; probed a computed element ([1970,(0+0),..]) and it still decoded as NumberLiteral here, so this arm has no known real producer (#3068)
src/jq/eval.rs tolerate 57797 both optional is never true through either caller of this function, same as the array-length check above (#3068)
src/jq/eval.rs tolerate 57860 both unreachable for strftime's C-int-clamped fields and bounded zone offset; shared checked date helpers retain overflow guards for other callers (#3083)
src/jq/eval.rs tolerate 58016 both llvm-cov line-attribution artifact, not unreachable: the call's own argument lines (immediately above) show 3 hits under the #3055 test's three E/O pass-through rows, but this closing-token line is never itself credited -- verified via the raw lcov DA: records
src/jq/eval.rs tolerate 59631 both unreachable from combinations, whose own empty-input return runs first; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 60731 both confirmed live (eprintln! probe): optional is always false in builtin_abs regardless of whether the filter writes abs?, since that suppression happens entirely outside builtin dispatch here -- the same 'optional is never true here' shape eval.rs already documents elsewhere (#2180) (#3041)
src/jq/eval.rs tolerate 62787 both unreachable: the sink is a plain collector that always answers Demand::Continue (#2872)
src/jq/eval.rs tolerate 62897 both unreachable: optional: false makes index_one_owned answer Ok(Some)/Err only (#2872)
src/jq/eval.rs tolerate 63048 both unreachable: pattern_has_computed_key is false for Pattern::Var, so the loop walker above always takes it (#2872)
src/jq/eval.rs tolerate 63095 both unreachable: every caller gates on pattern_has_computed_key being false (#2872)
src/jq/eval.rs tolerate 64334 both unreachable: bind_def_call only calls this for a non-empty params, install_def_calls only builds a DefCall whose args.len() equals params.len(), and the last parameter is never shadowed, so at least one entry is always built (#2560)
src/jq/eval.rs tolerate 65746 both unreachable in a passing suite by design -- this panic only fires if eval_owned_reindex_free declined a shape this loop's own handled table asserts is always answered (#3138)
src/jq/eval.rs tolerate 65755 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a shape this loop's own handled table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 65794 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step handled a shape this loop's own declined table asserts is always declined (#3138)
src/jq/eval.rs tolerate 65815 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a yq shape this loop's own table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 65914 both unreachable in a passing suite by design -- this panic only fires if the tracked \
src/jq/eval.rs tolerate 65916 both unreachable in a passing suite by design -- this panic only fires if state stopped being an Object, which every owned_assign_step write in the loop below preserves (#3138)
src/jq/eval.rs tolerate 65924 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on the single-step shape this loop drives every iteration (#3138)
src/jq/eval.rs tolerate 65929 both unreachable in a passing suite by design -- this arm only fires if state stopped being an Object, which every write in the loop above preserves (#3138)
src/jq/eval.rs tolerate 66116 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 66138 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 66156 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 66226 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 66244 both substitute_func_param_impl's FuncDef arm always returns FuncDef (#2555)
src/jq/eval.rs tolerate 73755 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval.rs tolerate 73906 both unreachable in a passing suite by design -- this is the failure message for the assertion the test exists to make (#2190)
src/jq/eval.rs tolerate 74876 both unreachable in a passing suite: every source this helper parses starts with def f(n): ...; (#3296)
src/jq/eval.rs tolerate 74933 both unreachable in a passing suite: f(1) under def f(n) always installs as a DefCall, which the assert above has just settled (#3296)
src/jq/eval.rs tolerate 86170 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 86222 both unreachable in a passing suite by design -- this test's own diagnostic (#3102)
src/jq/eval.rs tolerate 87012-87023 both the closure is asserted never called below (on_update_calls stays 0) -- Err(_) with optional=true short-circuits fold_step_each before this sink runs (#3122)
src/jq/eval.rs tolerate 91850 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 96885 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 96896 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 96913 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 96933 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 96941 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 98092 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 99989 both unreachable in a passing suite by design -- check_value_tree_depth's only Err variant is EvalError, and From for EvalEscape always produces EvalEscape::Error (#3275)
src/jq/eval.rs tolerate 105653 both unreachable in a passing suite by design -- every filter this helper is called with parses to an AsPattern (#2649)
src/jq/eval.rs tolerate 105697 both unreachable in a passing suite by design -- a literal-key pattern's walk either completes or refuses with an error (#2872)
src/jq/eval.rs tolerate 105706 both unreachable in a passing suite by design -- every call site passes the origin of a binding this same test already proved carries a marker (#2649)
src/jq/eval.rs tolerate 106034 both unreachable in a passing suite by design -- the assertion above is the test (#2872)
src/jq/eval.rs tolerate 106687 both unreachable in a passing suite by design -- every row here is a shape jq accepts, confirmed live (#2649)
src/jq/eval.rs tolerate 106755 both unreachable in a passing suite by design -- every row here is a shape jq refuses, confirmed live (#2649)
src/jq/eval.rs tolerate 107140 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 107156 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 107183 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 107199 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 107284 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3037)
src/jq/eval.rs tolerate 107362 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3037)
src/jq/eval.rs tolerate 107691 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3135)
src/jq/eval.rs tolerate 107797 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3122)
src/jq/eval.rs tolerate 107815 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3122)
src/jq/eval.rs tolerate 107883 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 107887 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 107927 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 107931 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 109551 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3119)
src/jq/eval.rs tolerate 109606 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3127)
src/jq/eval.rs tolerate 112117 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#2937)
src/jq/eval.rs tolerate 112203 both unreachable in a passing suite by design -- every READERS filter raises a decode failure on every malformed json in this sweep, so this fallback never fires (#3222)
src/jq/eval.rs tolerate 112209 both unreachable in a passing suite by design -- see the concrete match above, same sweep (#3222)
src/jq/eval.rs tolerate 112213-112215 both unreachable in a passing suite by design -- this is the failure-recording line for the assertion below, only reached if a READERS filter fails to raise (#3222)
src/jq/eval.rs tolerate 112271-112273 both unreachable in a passing suite by design -- this is the failure-recording line for the assertion below, only reached if a NON_READERS filter disagrees between the malformed and well-formed document (#3222)
src/jq/eval.rs tolerate 112281 both unreachable in a passing suite by design -- none of NON_READERS ever raises through eval_with_cursor_using, on the malformed document or the well-formed one; kept so a filter that starts erroring is still comparable rather than panicking (#3222)
src/jq/eval.rs tolerate 112287-112289 both unreachable in a passing suite by design -- see the eval failure-recording line above, same assertion (#3222)
src/jq/eval.rs tolerate 112462 both every pinned filter below yields an owned value; kept so a cursor answer still renders rather than panics (#2999)
src/jq/eval.rs tolerate 112463 both unreachable in a passing suite by design -- the failure message for the assertions this helper serves (#2999)
src/jq/eval_generic.rs tolerate 877 both unreachable: validate_cursor, CheckOnly's only instantiation, passes no nested nodes, so the walk never asks (#3179)
src/jq/eval_generic.rs tolerate 3902 both unreachable: the sole remaining caller (retain_truthy_generic's Many arm) runs to_owned on an item before keeping it, so re-converting a kept item here cannot fail; the ManyCursor caller that made this reachable went with the truthiness walk (#2692, re-establishing #2661's premise)
src/jq/eval_generic.rs tolerate 5577 both unreachable: hi is find_close of a container's own open paren, which a built index always matches (#3179)
src/jq/eval_generic.rs tolerate 7914 both unreachable in a passing suite by design -- this is the panic message for the #2368 pin itself, only formatted if the assert's own condition is false (#2368)
src/jq/eval_generic.rs tolerate 7975 both unreachable: this arm's own match guard already evaluated value.as_array().is_some_and(..) as true to be here at all, and as_array() is a pure read of value -- the second call inside the body can never answer None where the guard's own call just answered Some
src/jq/eval_generic.rs tolerate 9869 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 9886 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 11102 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval_generic.rs tolerate 12640 both unreachable: every producer that reaches this empty-exprs tail (each_lazy_keys_iterate_sink's sorted/!sorted arms, each_lazy_index_range_iterate_sink, each_lazy_seq_iterate_sink) yields OneCursorValue/OneCursor/Owned, never a cursorless GenericItem::One -- so cursor is always Some here; kept for exhaustiveness/symmetry with the Some arm (#2103)
src/jq/eval_generic.rs tolerate 14342 both unreachable: each_negate_generic pushes only GenericItem::Owned (arith_negate's result), which converts infallibly (#3410)
src/jq/eval_generic.rs tolerate 15978 both unreachable: escape_generic!/ensure_owned! set terminal before Demand::Stop; already returned above (#2138)
src/jq/eval_generic.rs tolerate 16322 head unreachable: a real stop always comes with a stash, returned above (#3293)
src/jq/eval_generic.rs tolerate 16322 base unreachable: escape! sets terminal before Demand::Stop; already returned above (#2546)
src/jq/eval_generic.rs tolerate 16361-16366 head unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval_generic.rs tolerate 16514-16518 both unreachable: this function's sole caller, slice_one_generic_computed, already runs the identical unreadable_value_error(&target) check on the same target and returns before ever calling here; kept as this function's own contract in case a future literal-bounds caller reaches it directly (#3222)
src/jq/eval_generic.rs tolerate 16971 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 16981 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 17656 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 17689 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 17737 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 17805 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 17821 both unreachable: effective_fields_checked already rejects key_is_malformed, the same decoded_key_str Ok(None) that makes key_display_string return None (#3022)
src/jq/eval_generic.rs tolerate 17944 both unreachable: both callers match Field, Index or Iterate before dispatching here (#3022)
src/jq/eval_generic.rs tolerate 19391 both unreachable: len_checked and SliceBounds::resolve already bound every index in range to [0, len), so get_cursor cannot miss (#2168)
src/jq/eval_generic.rs tolerate 22299 both unreachable by construction: path_context_resolvable admits an any(cond) read only through admits.prefetch, so the rewriter always has one -- the AnyCond arm above carries the identical assertion (#3079)
src/jq/eval_generic.rs tolerate 22303 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 22304 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 22627 both unreachable: the callback records downstream_flow before every Demand::Stop, and that flow is returned above (#3022)
src/jq/eval_generic.rs tolerate 23112 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 23133 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 23492 both unreachable: malformed_object_member above already proved every key stringifies (the None half), and to_owned_cursor on an untagged key decoded_key_str decoded cannot fail (the Err half) (#2785)
src/jq/eval_generic.rs tolerate 23573 both unreachable: map(f) over an array emits exactly one array; kept so a future map shape produces no output rather than a panic (#2785)
src/jq/eval_generic.rs tolerate 23878 both unreachable by design -- eval_single's #2368 debug_assert forbids optional=true on Builtin::Reverse, so length never answers None here (#2730)
src/jq/eval_generic.rs tolerate 24505 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 24511 both see above: the input-queue deferral never fires from the CLI
src/jq/eval_generic.rs tolerate 25956 both unreachable by construction: every shape either guard admits now has an arm above (#2771), and expr_dispatch_catchall_guards_default_conservatively_2549 pins both guards' _ => false defaults directly
src/jq/eval_generic.rs tolerate 26504 both unreachable in a passing suite by design -- owned_identity_rule maps a bare Expr::Var to Bound too (for the static gate, which sees a body before its as substitution runs), but every runtime dispatch that reaches this rule (owned_identity_after_stage/owned_identity_placed_by, from owned_identity_leaving_cursor's Bound arm) only ever sees a stage after eval_owned_identity_as's unconditional substitute_bound_var_from call, which always turns $x into Expr::TrackedVar before recursing -- confirmed by running the full suite with this arm replaced by a hard panic!(), which never fired (#2072)
src/jq/eval_generic.rs tolerate 26522 both unreachable: this Slice rule's own two execution paths both exclude Expr::Slice before ever reaching owned_identity_placed_by -- eval_owned_identity_stages's catch-all only runs a stage owned_identity_nav_supported refused, and owned_identity_leaving_cursor (identity_from_first, eval_generic.rs:10724) only runs a stage path_context_is_navigational refused -- and both predicates admit Expr::Slice (owned_identity_nav_supported/path_context_is_navigational_at each list Expr::Slice { .. } => true), so a bare slice is always resolved by owned_identity_step's own arm first. Kept in owned_identity_rule's match for exhaustiveness/symmetry with the rule table's other entries, the same reason #2072's Bound arm above is kept unreachable-by-construction (#2966's review of #2834)
src/jq/eval_generic.rs tolerate 28016 both optional is never true through this pipe: ? is eval_owned_identity_try, which catches the escape instead, and after #693 only the IndexExpr/SliceExpr special case ever sets it -- kept as any_all_f's scalar_fallback mirror
src/jq/eval_generic.rs tolerate 28017 both optional is never true here, see above
src/jq/eval_generic.rs tolerate 28431 both unreachable in a passing suite by design -- the failure message for the assertion the tests below make (#2999)
src/jq/eval_generic.rs tolerate 28643 both unreachable in a passing suite by design -- the fixture's map(.+1) is always a LazySeq; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 28671 both unreachable in a passing suite by design -- the fixture's only escape is Control::Error; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 28973 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval_generic.rs tolerate 33937 both failure message for the assertion this #3222 test exists to make
src/jq/eval_generic.rs tolerate 39574 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39578 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39581 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39637 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39717 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39732 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39755 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39776 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40188 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40210 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40217 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40295 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40346 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40407 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40443 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40452 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 40453 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 40454 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/lazy.rs tolerate 1474 both failure message for the shape the test asserts
src/jq/parser.rs tolerate 231 both unreachable: parse_join_expr only calls join_expr with two to four arguments (#3046)
src/jq/parser.rs tolerate 253 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 255 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 257 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 264 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 268 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 284 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 9765 both unreachable in a passing suite by design -- this is the panic message for the #3044 pin itself, only formatted if the let-else pattern fails to match (#3044)
src/jq/resolve.rs tolerate 2230 both unreachable by construction: this match is only entered when is_marker (marker.is_some()) is true, and RunMarker has only Begin/End variants -- the None arm exists solely for exhaustiveness against Option's type
src/jq/resolve.rs tolerate 2462 both unreachable in practice today: this arm needs builtin_fallback==None (the name was never a shadow candidate) yet is_jq_builtin==true (a real jq builtin at this arity) -- every implemented builtin's own dedicated parse already lowers that shape to Expr::Builtin before resolve.rs ever runs, and #3042/#3046 closed the once-real 'unimplemented builtin' gap this existed for (see JQ_BUILTIN_ROSTER's own doc comment)
src/jq/resolve.rs tolerate 2464 both unreachable with the current roster: every JQ_BUILTIN_ROSTER entry of arity >= 1 already has a dedicated parser form (a matches_keyword special case or a Libm1/Libm2/Libm3::ALL entry -- confirmed by cross-referencing the full roster against both), so it is parsed straight to Expr::Builtin and never reaches here as a bare FuncCall. This arm exists for a roster name with no dedicated parse yet and a nonzero arity -- there is none today, so the loop body is reached with an empty args on every pinned-suite run (355 hits on the arm's own condition, 0 in the loop) and would only start executing if such a name were added (#2964)
src/jq/share_stats.rs tolerate 97 both process-global env var; exercised by the CLI audit run, not by an in-process test (#2999)
src/jq/value.rs tolerate 365 both unreachable by construction: the slow path is entered only after significant_digit_count found 18+ digits over the same mantissa bytes this loop walks (#2936)
src/jq/value.rs tolerate 389 both unreachable by construction: 18+ significant digits were counted, so at least one nonzero digit was kept (#2936)
src/jq/value.rs tolerate 2800 both unreachable: format_float_with_fraction of a finite double is always RFC 8259 number text, which parse_i64_or_f64 reads (#2936)
src/jq/value.rs tolerate 4861 both unreachable in a passing suite by design -- every caller built the value as an array (#2999)
src/jq/value.rs tolerate 5104 both unreachable in a passing suite by design -- the value was built as this container a few lines above (#2999)
src/jq/value.rs tolerate 5923 both unreachable in a passing suite by design -- the failure message for a malformed oracle table (#2936)
src/jq/value.rs tolerate 6271 both failure message for the assertion the calling test makes
src/jq/value.rs tolerate 6495 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 6501 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 6613 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/jq/value.rs tolerate 7729 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/jq/value.rs tolerate 7747 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/json/light.rs tolerate 2663-2669 both unreachable in practice: UNMEASURED_SPAN only arises when end - text_pos in number_at overflows u32 -- a single number span >= 4 GiB -- which no realistic (or practically constructible) test document approaches (#3222)
src/json/light.rs tolerate 3442 both reachable only through a bare 64-bit hash collision between keys the pairwise scan already proved distinct
src/json/light.rs tolerate 9087 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9169 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9258 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9291 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9320 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9408 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/json/light.rs tolerate 9413 both unreachable in a passing suite by design -- see the assert_eq! format argument above, same sweep (#3222)
src/json/light.rs tolerate 9439 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9450 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9531 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/util/simd/x86.rs tolerate 208-258 both CPU-gated: the avx512f early-return only executes on Zen 4+ / Skylake-X runners, and its absence changes which AMD/Intel branch below executes too (#2449)
src/yaml/index.rs tolerate 1268 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1272 both unreachable: every fixture field_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1283 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1285 both unreachable: every call to field_key_head_foot in this test module passes a key that the fixture's mapping actually has (#798)
src/yaml/index.rs tolerate 1295 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1299 both unreachable: every fixture seq_item_head_foot is called with in this test module is a top-level sequence (#798)
src/yaml/index.rs tolerate 1322 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1341 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1364 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1373 both unreachable: every fixture field_key_head_foot_in_doc is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1384 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1386 both unreachable: every call to field_key_head_foot_in_doc in this test module passes a key that the fixture's document actually has (#798)
src/yaml/index.rs tolerate 1397 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1401 both unreachable: every fixture nested_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1405 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this let-else's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1411 both unreachable: every fixture nested_key_head_foot is called with has a nested mapping under outer (#798)
src/yaml/index.rs tolerate 1422 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1425 both unreachable: every call to nested_key_head_foot in this test module passes an outer.inner pair that the fixture actually has (#798)
src/yaml/light.rs tolerate 3365 both unreachable: an alias target is never None for a built index (#1374)
src/yaml/light.rs tolerate 15669 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 15680 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 15837 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/parser.rs tolerate 1583 both unreachable: every block-sequence open registers a frame at its own depth before any item of it can be parsed (#1079)
src/yaml/parser.rs tolerate 1613 both unreachable: this function's sole caller (record_standalone_comment) only invokes it from inside a match on pending_head_lines.last(), so pending_head_lines is already known non-empty here (#798)
src/yaml/parser.rs tolerate 7999 both unreachable: every byte here already passed the [0-9.eE+-] charset check above, a strict subset of ASCII, so str::from_utf8 can never fail (#2778)

Patch coverage

Patch: 80.39% (41/51 new lines covered)

File Patch Uncovered new lines
src/jq/eval.rs 78.26% (18/23) 24777, 24815-24818
src/jq/eval_generic.rs 82.14% (23/28) 16322, 16362-16365
Uncovered new lines (10)
  • src/jq/eval.rs:24777
  • src/jq/eval.rs:24815
  • src/jq/eval.rs:24816
  • src/jq/eval.rs:24817
  • src/jq/eval.rs:24818
  • src/jq/eval_generic.rs:16322
  • src/jq/eval_generic.rs:16362
  • src/jq/eval_generic.rs:16363
  • src/jq/eval_generic.rs:16364
  • src/jq/eval_generic.rs:16365

📦 Full per-file coverage summary · run summary

newhoggy added a commit that referenced this pull request Sep 28, 2026
… the pull

Review of #3434: a `first`/`limit`/`nth` around a retrying slice bound
reports its own count stop as `Stopped` after the `?//` retry inside it
re-invoked the sink, whose `begin()` had rightly cleared the stash -- a
combination the first version declared unreachable, so `.[first([[0]]
as [$a] ?// [[$a]] | $a):]` on `[10,20,30]` panicked (exit 101) on both
evaluators where jq 1.7.1 answers `[10,20,30]` and main raised.

A `Stopped` with no stash behind it is the bound's wrapper finishing, not
an escape: the inner `end` drive continues and the outer pull completes
with `out`. Also hoist `end`'s retry fallback out of the per-value
closure and drop the comments that still described the removed
`terminal`.

Part of #3293.
newhoggy added a commit that referenced this pull request Sep 28, 2026
Review of #3434: the table had no row with the `?//` inside
`first`/`limit`/`nth`, the shape that reached the panic. Add seven,
captured from jq 1.7.1, run on both evaluators.

Part of #3293.
newhoggy added a commit that referenced this pull request Sep 28, 2026
…a retry

Second review of #3434 found the root of the panic the previous commit
worked around: `each_limit`, `take_at_index` (`first`/`nth`) and their
`eval_generic` twins set `outer_stopped` when the wrapping sink stopped
and never cleared it, so after a `?//` retry inside them re-invoked the
sink they reported a stale `Stopped` to whatever enclosed them -- the
#3293 Class 2 shape in the consumers themselves. The slice collector's
"a stashless Stopped is completion" workaround hid the panic but not
the wrong answers: a comma after the wrapper was cut short
(`[.[(first([[1]] as [$a] ?// [[$a]] | $a), 2):]]` gave `[[20,30]]`
where jq 1.7.1 gives `[[20,30],[30]]`) and a filter dropping the
retried value kept the stale error.

Reset the flag at the top of each invocation, as #3411 did for the
value-mode sinks; the final flag then reflects the last invocation, so
an enclosing consumer that really stopped still makes jq's #1519 second
answer (`[first(first(1 as $x ?// $y | 1))]` is still `[1,1]`). The
slice collectors' `Stopped` arms go back to their strict form: an inner
`Stopped` propagates, and the outer one is unreachable again.

Part of #3293.
newhoggy added a commit that referenced this pull request Sep 28, 2026
Second review of #3434: add the shapes that exposed the stale consumer
stop -- a comma after the wrapper in either slice bound, and a filter
dropping the retried value -- to the slice table, and a
`RETRY_ROWS_WRAPPER_STOP_3293` table pinning the reset outside slices,
including the #1519 double-answer controls. Both run on both evaluators.

Part of #3293.
@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Coverage

Total: 94.41% ⚪ 0 pp vs main

Comparing 9985935..750c4fd (merge-base → PR head)

No per-file coverage changes vs main.

🔇 0 ignored region(s), 279 tolerated region(s)

ignore removes the lines from both reports; tolerate keeps them in the reported percentage but scores them against the baseline, so a cross-run flip cannot move a delta. Regions are read from each revision's own source.

File Kind Lines Rev Reason
src/bin/succinctly/jq_runner.rs tolerate 1094 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted, for the identical reason run_jq's own analogous fallback (#2395) is tolerated -- see that line's own comment (#2950)
src/bin/succinctly/jq_runner.rs tolerate 2148-2160 both unreachable: try_parse_meta_op only fires under ParserMode::Yq (src/jq/parser.rs), and rewrite_namespaced_calls is only reached via ModuleProcessor::process_program, which jq_runner's own jq-mode run is the sole caller of -- so a MetaAssign node can never reach this function (#798)
src/bin/succinctly/jq_runner.rs tolerate 2747 both unreachable by construction: every error this wrapper receives today is a decode or nesting-depth failure the evaluator raised itself, never error(v); kept so a future one is rendered rather than dropped (#2999)
src/bin/succinctly/jq_runner.rs tolerate 2748 both see the arm above (#2999)
src/bin/succinctly/jq_runner.rs tolerate 3164 both unreachable in practice today: def is only None when occurrences.module_def() is None, which (given origin is Some) would require an open run whose innermost frame has no def set at a check point that isn't itself inside a module-level def body -- but every module run is a strict chain of def nodes (the loader's own defs, each wrapping its dependency stubs INSIDE its own body via wrap_defs/dep_stubs_for) terminated by the run's own end marker, so a diagnosable call/var/break site is always reached either inside a module-level def's body (module_def Some) or outside every run (origin None) -- and even when def is Some, self.defs is always ModuleSource::read's own re-parse of the exact same file run_id_for interned this origin's id from, so collect_def_sites always finds the matching (name, arity, ordinal) span. Kept as a defensive fallback rather than a panic/unwrap in case that invariant is ever violated (#3085)
src/bin/succinctly/jq_runner.rs tolerate 3413-3416 both unreachable in a single-process run by construction: run_id_for (the sole source of an origin id) always inserts a run_origins entry for the id it hands back -- from a real load's canonical path, or its own literal-path fallback on a resolve failure -- and a def body only ever gets stamped with an origin after its module loaded successfully, so at always names a file that existed and was readable moments earlier. Reaching this arm needs that same file to vanish (or become unreadable) in the narrow window between that load and this re-read, entirely outside this process's control (#2964)
src/bin/succinctly/jq_runner.rs tolerate 3680 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted -- a newly covered name only wraps an already-successful dedicated parse, and a failing one would have propagated its error in the first parse too, so the retry budget is charged at the identical sites in both (#2395)
src/bin/succinctly/jq_runner.rs tolerate 9419 both unreachable: this test builds only ResolveError::Call values (#3313)
src/bin/succinctly/jq_runner.rs tolerate 11370 both unreachable in a passing suite by design -- the fixed b\
src/bin/succinctly/main.rs tolerate 1356 both unreachable given clap 4.6's own unknown_argument() error constructor: every ErrorKind::UnknownArgument it builds sets ContextKind::InvalidArg to ContextValue::String(arg) in the same call, so this arm only guards a future clap release changing that invariant
src/bin/succinctly/main.rs tolerate 1397 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_accepted_via_sjq_multicall_alias_3389's '-x' row demonstrably reaches the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1559 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_boundary_characters_3389's '-x'/'-n1'/'--bogus' rows demonstrably reach the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1581 both the CLI suites drive yq through the syq multi-call arm above; this arm is the same call reached only when spelled succinctly yq (#2999)
src/bin/succinctly/yq_runner.rs tolerate 1652 both unreachable: bytes already parsed successfully by every caller (#1350)
src/bin/succinctly/yq_runner.rs tolerate 1741 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1742 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1743 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 3330 both unreachable: path is always the raw output of the path(TARGET) builtin evaluated a few lines up in resolve_one_meta_assign -- path/1 is a jq/yq language invariant that always answers an array of path components (see Expr::Builtin(Builtin::PathNoArg) => Ok(Some(OwnedValue::Array(..))) in eval_generic.rs), never any other shape (#798)
src/bin/succinctly/yq_runner.rs tolerate 3430 both unreachable: resolve_meta_assign_writes runs expr through this before any evaluation begins (see its own doc comment), and Expr::Shared is never constructed by the parser -- only at eval time, by function-call argument substitution (substitute_func_param in eval.rs) -- so a pre-evaluation AST can never contain one here (#798)
src/bin/succinctly/yq_runner.rs tolerate 4062 both unreachable: every arm of the match result { .. } above that assigns docs (L3492-3622) constructs Ok(..) -- none ever produces Err, so this if let's implicit else can't be taken; symmetric to L1625's ? (#798)
src/bin/succinctly/yq_runner.rs tolerate 6746-6748 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 6937-6942 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 7695-7700 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/jq/document.rs tolerate 383 both unreachable: the only caller, eval_generic::embed_at_or_within, is gated on jq semantics, and the YAML cursor (the one implementor without an override) is only ever evaluated under yq semantics (#3179)
src/jq/document.rs tolerate 978-982 both unreachable: both implementors (JsonCursor, YamlCursor) override this; the default exists as the conservative-false contract a future implementor inherits (#3222)
src/jq/document.rs tolerate 1157-1164 both unreachable: both implementors (StandardJson, YamlValue) override this to decode once; the default exists as the contract a future implementor inherits, and is deliberately the two-call sequence it replaces (#965)
src/jq/eval.rs tolerate 1163 both unreachable: def is always a collect_alias_groups anchor path, which step_to_expr never fails on (#1351)
src/jq/eval.rs tolerate 1184 both unreachable: redirect_paths with Redirect::SINGLE always contributes exactly one output per input, so a 1-element paths always pops Some (#1351)
src/jq/eval.rs tolerate 1193 both unreachable: a concrete setpath/delpaths path's components are always Field/Index -- step_to_expr never produces another shape (#1351)
src/jq/eval.rs tolerate 1197 both unreachable: the map above never yields None, since it only ever matches Field/Index (#1351)
src/jq/eval.rs tolerate 1731 both unreachable: key_or_parent_root_construct's identical structural match already refused any expr shape that would reach this arm
src/jq/eval.rs tolerate 4677 both unreachable: is_escape() is exactly `Error
src/jq/eval.rs tolerate 4678 both unreachable: see the if let above -- push_owned_values never answers None for an is_escape() result (#2180)
src/jq/eval.rs tolerate 5861 both unreachable today: to_owned's only failures are is_decode_failure()-tagged, and suppresses() answers false for those whatever optional is -- the same defensive-but-dead arm eval_generic's own Builtin::Path materialization documents under #2280 (#2908)
src/jq/eval.rs tolerate 6627 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 7914 both unreachable: optional is never true here. eval_each is entered with a forced true at exactly one site (Expr::Optional over an IndexExpr/SliceExpr), and both of those evaluate their target (eval_index_expr) and their key (eval_each(key, .., false)) with a hardcoded false, so only the final index/slice step ever sees it -- nothing carries it down to an Expr::Object (#2180)
src/jq/eval.rs tolerate 9016 both unreachable: owned_write_door calls this only on a clone of a head write_target already matched, and the two list the same five variants (#3188)
src/jq/eval.rs tolerate 9030 both unreachable: every value path_over_owned hands back is a path() output, which is always an array (#3188)
src/jq/eval.rs tolerate 9309 both unreachable: any_child_witnessed is false for every non-container, checked just above (#3178)
src/jq/eval.rs tolerate 9551 both reachable only on a genuine allocation failure: owned_assign_step's single-step arms map every non-allocation error to unreachable_owned_assign_write (provably impossible, see its own doc comment), and its Chain arm's set_path call walks exactly the steps owned_assign_step_child already validated as Field-into-Object/Null or Index-in-[0,len]-into-Array/Null with no mutation in between, so the only way set_path/set_field/set_index/pad_with_nulls can still fail is the same try_reserve-fails-under-OOM branch the codebase already tolerates elsewhere (#2267) (#3138)
src/jq/eval.rs tolerate 9676 both unreachable: owned_assign_shape's only caller (owned_step_shape) gates the call on is_owned_assign(expr), which recognizes exactly Assign/Update/CompoundAssign/AlternativeAssign -- the same four variants this match already has explicit arms for, so expr can never be anything else here (#3138)
src/jq/eval.rs tolerate 9869 both unreachable: both call sites (try_eval_owned_step, gated on is_owned_assign; eval_owned_reindex_free's own Assign
src/jq/eval.rs tolerate 9943 both unreachable: this function's own doc comment states why -- the borrow on state between owned_assign_step_child's check and the single write makes the container changing shape impossible, so debug_assert!(false, ..) can never fire (#3138)
src/jq/eval.rs tolerate 9944 both unreachable: same invariant as the false above -- this message is only ever formatted if that assert fires (#3138)
src/jq/eval.rs tolerate 9946 both unreachable: this function is only called from owned_assign_step's single-step arms, both of which the invariant above already rules out ever calling it for real (#3138)
src/jq/eval.rs tolerate 9947 both unreachable: the whole function body above is provably dead by the same borrow-checker invariant its doc comment states (#3138)
src/jq/eval.rs tolerate 9984 both unreachable: Expr::pipe() (the parser's sole Pipe constructor) collapses a one-element list to the bare inner expr instead of wrapping it, and substitute_vars's substitute_var walk preserves a Pipe's stage count rather than dropping stages -- no other site builds an Expr::Pipe for a parsed assignment path, so a path's top-level Pipe here is never single-element (#3138)
src/jq/eval.rs tolerate 13034 both unreachable: every entry point supplies path context, so path never evaluates without one; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 13167 both unreachable: only ever constructed by builtin_sort_keys's own eval_update_no_vivify call, whose enclosing eval_update_impl already runs to_owned on the whole document up front (#2855) -- a decode failure anywhere raises there, before this filter ever sees a value to re-decode; confirmed live, sort_keys(.a)/sort_keys(..) on a document with a decode-failure subtree both raise from the outer to_owned
src/jq/eval.rs tolerate 13310-13312 both unreachable: builtin_length's sole caller is eval_builtin's Builtin::Length dispatch, and Length is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before this match ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 13533-13535 both unreachable: has_one_key's sole caller is builtin_has (via eval_builtin's Builtin::Has dispatch), and Has is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before builtin_has ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 16698 both unreachable: entry is one of to_entries's already-materialized {key,value} pairs, so its depth here is provably no deeper than whatever earlier check let it exist -- a document-decoded entry is already <256 deep (MAX_NESTING_DEPTH, stricter than this 384 guard), and a filter-constructed one already survived becoming a cursor via its own whole-object reindex, which is strictly deeper than any single field extracted from it could be (unwrapping only reduces depth); confirmed live, {a: (reduce range(400) as $i (0; [.]))}
src/jq/eval.rs tolerate 24420 both unreachable: escape_with_prefix! sets terminal before Demand::Stop; already returned above (#2138)
src/jq/eval.rs tolerate 24772 base unreachable: escape! sets terminal before Demand::Stop; already returned above (#2546)
src/jq/eval.rs tolerate 24777 head unreachable: a real stop always comes with a stash, returned above (#3293)
src/jq/eval.rs tolerate 24814-24819 head unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval.rs tolerate 26290 both unreachable via --eval-all: every document here comes straight from parse_input, whose own MAX_NESTING_DEPTH (256) guard already rejects anything deep enough to reach MAX_VALUE_TREE_DEPTH (384) here -- confirmed live, a 300-level document fails parse_input's guard before ever reaching this reindex (#3261)
src/jq/eval.rs tolerate 29507 both unreachable: descriptor_path_component builds a Verbatim key only from an object (#3300)
src/jq/eval.rs tolerate 33821 both reachable only on a genuine allocation failure: Vec::try_reserve(1) on a vector that has spare capacity, or can grow, cannot fail -- this is the whole purpose of the branch, converting an OOM into a catchable error rather than an abort (ADR-0018's 'would take the host process down' exception). The pre-#2267 form of the same guard, out.try_reserve(branches.len()) in resolve_index_expr/resolve_slice_expr, was 0-hit for the identical reason (#2267)
src/jq/eval.rs tolerate 33822 both see the line above -- the Demand::Stop half of the same allocation-failure-only branch (#2267)
src/jq/eval.rs tolerate 33828 both reachable only when the try_reserve above failed, i.e. only on a genuine allocation failure (#2267)
src/jq/eval.rs tolerate 36306 both unreachable: owned_value_jq_length's own match only ever constructs OwnedValue::Int or OwnedValue::Float, checked just above this arm (#2744)
src/jq/eval.rs tolerate 36841 both unreachable: is_primitive admits only Identity/Field/Index/Slice, and of those only a Slice's computed bounds can halt -- all four have their own arm in resolve_node_sink/resolve_node_eager, so none reaches this function. Pre-existing; #2694 only wrapped the return in Some (#2694)
src/jq/eval.rs tolerate 36875 both unreachable, as this arm's own comment above says: indexing or slicing a value yields zero or one result, so is_primitive never produces more than one -- kept as a named error rather than a panic. Pre-existing; #2694 only wrapped the enclosing return in Some (#2694)
src/jq/eval.rs tolerate 39734 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 40730 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), returned just above (#2872)
src/jq/eval.rs tolerate 41102 both unreachable: every arm of the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 41640 both unreachable: every path through the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 44366 both unreachable in a passing suite by design -- a panic-message format argument for the #682 single-valued-tail pin, evaluated only if that assert's own condition is false (#2190)
src/jq/eval.rs tolerate 44443 both unreachable: the only caller reaches this after classify_static_component answered Field for this same value, which it does only for an object (#2190)
src/jq/eval.rs tolerate 44487 both unreachable: both callers establish the container first -- navigate_static_component_ref via classify_static_component's Index arm, and walk_path's Expr::Iterate arm by matching on the container itself (#2190)
src/jq/eval.rs tolerate 47248 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 48904 both unreachable: stop_with_escape's only write is slot.set(Some(control)) with the control it was handed, which is always the Control::Error built one line above (#2180)
src/jq/eval.rs tolerate 49404 both unreachable: on_update records a step_outcome before every Demand::Stop it answers, and the fallback match runs only when it recorded none (#2872)
src/jq/eval.rs tolerate 49427 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 49956 both unreachable by construction: the per-fork match only ever hands stop_with_downstream a non-Exhausted flow, so terminal can never hold Exhausted. foreach_forks' identical arm is 0-hit for the same reason and is only unflagged because it predates this diff (#2899)
src/jq/eval.rs tolerate 51874 both llvm-cov line-attribution artifact, not unreachable: the new gate test above (Builtin::Length as first) demonstrably takes key_or_parent_root_construct(first) == false and falls through to the reindex-bridge route below, passing -- but this closing brace, like the one at #56920 for the same reason, is never itself credited a hit
src/jq/eval.rs tolerate 51888 both unreachable in the current test suite: eval_path_context_pipe_owned itself has zero total call-site coverage today (not just this arm), confirmed by a full-suite eprintln probe across every test binary -- reaching its error arm needs first solving how to reach the function at all, out of scope for #3261's reindex-bridge fix
src/jq/eval.rs tolerate 52928 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 55014 both pre-existing zero-hit line; #2999 changed only which null constant it names
src/jq/eval.rs tolerate 57499 both ? suppresses mktime's error outside builtin dispatch, so the optional flag is false even for an invalid date (#3083)
src/jq/eval.rs tolerate 57502 both unreachable for mktime's C-int-clamped fields: checked civil-date arithmetic stays within i64; the guard protects other callers of the shared helpers (#3083)
src/jq/eval.rs tolerate 57723 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 57726 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 57767 both optional is never true through either caller of this function -- confirmed live (eprintln! probe): `[1,2,3]
src/jq/eval.rs tolerate 57776 both every array literal written in filter source, and every array-element JSON parses, decodes to NumberLiteral (#1035), not a bare Int -- Int is for internally-synthesized values spliced post-parse; probed a computed element ([1970,(0+0),..]) and it still decoded as NumberLiteral here, so this arm has no known real producer (#3068)
src/jq/eval.rs tolerate 57797 both optional is never true through either caller of this function, same as the array-length check above (#3068)
src/jq/eval.rs tolerate 57860 both unreachable for strftime's C-int-clamped fields and bounded zone offset; shared checked date helpers retain overflow guards for other callers (#3083)
src/jq/eval.rs tolerate 58016 both llvm-cov line-attribution artifact, not unreachable: the call's own argument lines (immediately above) show 3 hits under the #3055 test's three E/O pass-through rows, but this closing-token line is never itself credited -- verified via the raw lcov DA: records
src/jq/eval.rs tolerate 59631 both unreachable from combinations, whose own empty-input return runs first; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 60731 both confirmed live (eprintln! probe): optional is always false in builtin_abs regardless of whether the filter writes abs?, since that suppression happens entirely outside builtin dispatch here -- the same 'optional is never true here' shape eval.rs already documents elsewhere (#2180) (#3041)
src/jq/eval.rs tolerate 62787 both unreachable: the sink is a plain collector that always answers Demand::Continue (#2872)
src/jq/eval.rs tolerate 62897 both unreachable: optional: false makes index_one_owned answer Ok(Some)/Err only (#2872)
src/jq/eval.rs tolerate 63048 both unreachable: pattern_has_computed_key is false for Pattern::Var, so the loop walker above always takes it (#2872)
src/jq/eval.rs tolerate 63095 both unreachable: every caller gates on pattern_has_computed_key being false (#2872)
src/jq/eval.rs tolerate 64334 both unreachable: bind_def_call only calls this for a non-empty params, install_def_calls only builds a DefCall whose args.len() equals params.len(), and the last parameter is never shadowed, so at least one entry is always built (#2560)
src/jq/eval.rs tolerate 65746 both unreachable in a passing suite by design -- this panic only fires if eval_owned_reindex_free declined a shape this loop's own handled table asserts is always answered (#3138)
src/jq/eval.rs tolerate 65755 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a shape this loop's own handled table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 65794 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step handled a shape this loop's own declined table asserts is always declined (#3138)
src/jq/eval.rs tolerate 65815 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a yq shape this loop's own table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 65914 both unreachable in a passing suite by design -- this panic only fires if the tracked \
src/jq/eval.rs tolerate 65916 both unreachable in a passing suite by design -- this panic only fires if state stopped being an Object, which every owned_assign_step write in the loop below preserves (#3138)
src/jq/eval.rs tolerate 65924 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on the single-step shape this loop drives every iteration (#3138)
src/jq/eval.rs tolerate 65929 both unreachable in a passing suite by design -- this arm only fires if state stopped being an Object, which every write in the loop above preserves (#3138)
src/jq/eval.rs tolerate 66116 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 66138 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 66156 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 66226 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 66244 both substitute_func_param_impl's FuncDef arm always returns FuncDef (#2555)
src/jq/eval.rs tolerate 73755 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval.rs tolerate 73906 both unreachable in a passing suite by design -- this is the failure message for the assertion the test exists to make (#2190)
src/jq/eval.rs tolerate 74876 both unreachable in a passing suite: every source this helper parses starts with def f(n): ...; (#3296)
src/jq/eval.rs tolerate 74933 both unreachable in a passing suite: f(1) under def f(n) always installs as a DefCall, which the assert above has just settled (#3296)
src/jq/eval.rs tolerate 86170 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 86222 both unreachable in a passing suite by design -- this test's own diagnostic (#3102)
src/jq/eval.rs tolerate 87012-87023 both the closure is asserted never called below (on_update_calls stays 0) -- Err(_) with optional=true short-circuits fold_step_each before this sink runs (#3122)
src/jq/eval.rs tolerate 91850 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 96885 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 96896 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 96913 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 96933 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 96941 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 98092 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 99989 both unreachable in a passing suite by design -- check_value_tree_depth's only Err variant is EvalError, and From for EvalEscape always produces EvalEscape::Error (#3275)
src/jq/eval.rs tolerate 105653 both unreachable in a passing suite by design -- every filter this helper is called with parses to an AsPattern (#2649)
src/jq/eval.rs tolerate 105697 both unreachable in a passing suite by design -- a literal-key pattern's walk either completes or refuses with an error (#2872)
src/jq/eval.rs tolerate 105706 both unreachable in a passing suite by design -- every call site passes the origin of a binding this same test already proved carries a marker (#2649)
src/jq/eval.rs tolerate 106034 both unreachable in a passing suite by design -- the assertion above is the test (#2872)
src/jq/eval.rs tolerate 106687 both unreachable in a passing suite by design -- every row here is a shape jq accepts, confirmed live (#2649)
src/jq/eval.rs tolerate 106755 both unreachable in a passing suite by design -- every row here is a shape jq refuses, confirmed live (#2649)
src/jq/eval.rs tolerate 107140 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 107156 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 107183 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 107199 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 107284 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3037)
src/jq/eval.rs tolerate 107362 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3037)
src/jq/eval.rs tolerate 107691 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3135)
src/jq/eval.rs tolerate 107797 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3122)
src/jq/eval.rs tolerate 107815 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3122)
src/jq/eval.rs tolerate 107883 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 107887 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 107927 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 107931 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 109551 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3119)
src/jq/eval.rs tolerate 109606 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3127)
src/jq/eval.rs tolerate 112117 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#2937)
src/jq/eval.rs tolerate 112203 both unreachable in a passing suite by design -- every READERS filter raises a decode failure on every malformed json in this sweep, so this fallback never fires (#3222)
src/jq/eval.rs tolerate 112209 both unreachable in a passing suite by design -- see the concrete match above, same sweep (#3222)
src/jq/eval.rs tolerate 112213-112215 both unreachable in a passing suite by design -- this is the failure-recording line for the assertion below, only reached if a READERS filter fails to raise (#3222)
src/jq/eval.rs tolerate 112271-112273 both unreachable in a passing suite by design -- this is the failure-recording line for the assertion below, only reached if a NON_READERS filter disagrees between the malformed and well-formed document (#3222)
src/jq/eval.rs tolerate 112281 both unreachable in a passing suite by design -- none of NON_READERS ever raises through eval_with_cursor_using, on the malformed document or the well-formed one; kept so a filter that starts erroring is still comparable rather than panicking (#3222)
src/jq/eval.rs tolerate 112287-112289 both unreachable in a passing suite by design -- see the eval failure-recording line above, same assertion (#3222)
src/jq/eval.rs tolerate 112462 both every pinned filter below yields an owned value; kept so a cursor answer still renders rather than panics (#2999)
src/jq/eval.rs tolerate 112463 both unreachable in a passing suite by design -- the failure message for the assertions this helper serves (#2999)
src/jq/eval_generic.rs tolerate 877 both unreachable: validate_cursor, CheckOnly's only instantiation, passes no nested nodes, so the walk never asks (#3179)
src/jq/eval_generic.rs tolerate 3902 both unreachable: the sole remaining caller (retain_truthy_generic's Many arm) runs to_owned on an item before keeping it, so re-converting a kept item here cannot fail; the ManyCursor caller that made this reachable went with the truthiness walk (#2692, re-establishing #2661's premise)
src/jq/eval_generic.rs tolerate 5577 both unreachable: hi is find_close of a container's own open paren, which a built index always matches (#3179)
src/jq/eval_generic.rs tolerate 7914 both unreachable in a passing suite by design -- this is the panic message for the #2368 pin itself, only formatted if the assert's own condition is false (#2368)
src/jq/eval_generic.rs tolerate 7975 both unreachable: this arm's own match guard already evaluated value.as_array().is_some_and(..) as true to be here at all, and as_array() is a pure read of value -- the second call inside the body can never answer None where the guard's own call just answered Some
src/jq/eval_generic.rs tolerate 9869 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 9886 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 11102 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval_generic.rs tolerate 12640 both unreachable: every producer that reaches this empty-exprs tail (each_lazy_keys_iterate_sink's sorted/!sorted arms, each_lazy_index_range_iterate_sink, each_lazy_seq_iterate_sink) yields OneCursorValue/OneCursor/Owned, never a cursorless GenericItem::One -- so cursor is always Some here; kept for exhaustiveness/symmetry with the Some arm (#2103)
src/jq/eval_generic.rs tolerate 14342 both unreachable: each_negate_generic pushes only GenericItem::Owned (arith_negate's result), which converts infallibly (#3410)
src/jq/eval_generic.rs tolerate 15978 both unreachable: escape_generic!/ensure_owned! set terminal before Demand::Stop; already returned above (#2138)
src/jq/eval_generic.rs tolerate 16322 head unreachable: a real stop always comes with a stash, returned above (#3293)
src/jq/eval_generic.rs tolerate 16322 base unreachable: escape! sets terminal before Demand::Stop; already returned above (#2546)
src/jq/eval_generic.rs tolerate 16361-16366 head unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval_generic.rs tolerate 16514-16518 both unreachable: this function's sole caller, slice_one_generic_computed, already runs the identical unreadable_value_error(&target) check on the same target and returns before ever calling here; kept as this function's own contract in case a future literal-bounds caller reaches it directly (#3222)
src/jq/eval_generic.rs tolerate 16971 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 16981 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 17656 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 17689 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 17737 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 17805 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 17821 both unreachable: effective_fields_checked already rejects key_is_malformed, the same decoded_key_str Ok(None) that makes key_display_string return None (#3022)
src/jq/eval_generic.rs tolerate 17944 both unreachable: both callers match Field, Index or Iterate before dispatching here (#3022)
src/jq/eval_generic.rs tolerate 19391 both unreachable: len_checked and SliceBounds::resolve already bound every index in range to [0, len), so get_cursor cannot miss (#2168)
src/jq/eval_generic.rs tolerate 22299 both unreachable by construction: path_context_resolvable admits an any(cond) read only through admits.prefetch, so the rewriter always has one -- the AnyCond arm above carries the identical assertion (#3079)
src/jq/eval_generic.rs tolerate 22303 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 22304 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 22627 both unreachable: the callback records downstream_flow before every Demand::Stop, and that flow is returned above (#3022)
src/jq/eval_generic.rs tolerate 23112 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 23133 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 23492 both unreachable: malformed_object_member above already proved every key stringifies (the None half), and to_owned_cursor on an untagged key decoded_key_str decoded cannot fail (the Err half) (#2785)
src/jq/eval_generic.rs tolerate 23573 both unreachable: map(f) over an array emits exactly one array; kept so a future map shape produces no output rather than a panic (#2785)
src/jq/eval_generic.rs tolerate 23878 both unreachable by design -- eval_single's #2368 debug_assert forbids optional=true on Builtin::Reverse, so length never answers None here (#2730)
src/jq/eval_generic.rs tolerate 24505 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 24511 both see above: the input-queue deferral never fires from the CLI
src/jq/eval_generic.rs tolerate 25956 both unreachable by construction: every shape either guard admits now has an arm above (#2771), and expr_dispatch_catchall_guards_default_conservatively_2549 pins both guards' _ => false defaults directly
src/jq/eval_generic.rs tolerate 26504 both unreachable in a passing suite by design -- owned_identity_rule maps a bare Expr::Var to Bound too (for the static gate, which sees a body before its as substitution runs), but every runtime dispatch that reaches this rule (owned_identity_after_stage/owned_identity_placed_by, from owned_identity_leaving_cursor's Bound arm) only ever sees a stage after eval_owned_identity_as's unconditional substitute_bound_var_from call, which always turns $x into Expr::TrackedVar before recursing -- confirmed by running the full suite with this arm replaced by a hard panic!(), which never fired (#2072)
src/jq/eval_generic.rs tolerate 26522 both unreachable: this Slice rule's own two execution paths both exclude Expr::Slice before ever reaching owned_identity_placed_by -- eval_owned_identity_stages's catch-all only runs a stage owned_identity_nav_supported refused, and owned_identity_leaving_cursor (identity_from_first, eval_generic.rs:10724) only runs a stage path_context_is_navigational refused -- and both predicates admit Expr::Slice (owned_identity_nav_supported/path_context_is_navigational_at each list Expr::Slice { .. } => true), so a bare slice is always resolved by owned_identity_step's own arm first. Kept in owned_identity_rule's match for exhaustiveness/symmetry with the rule table's other entries, the same reason #2072's Bound arm above is kept unreachable-by-construction (#2966's review of #2834)
src/jq/eval_generic.rs tolerate 28016 both optional is never true through this pipe: ? is eval_owned_identity_try, which catches the escape instead, and after #693 only the IndexExpr/SliceExpr special case ever sets it -- kept as any_all_f's scalar_fallback mirror
src/jq/eval_generic.rs tolerate 28017 both optional is never true here, see above
src/jq/eval_generic.rs tolerate 28431 both unreachable in a passing suite by design -- the failure message for the assertion the tests below make (#2999)
src/jq/eval_generic.rs tolerate 28643 both unreachable in a passing suite by design -- the fixture's map(.+1) is always a LazySeq; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 28671 both unreachable in a passing suite by design -- the fixture's only escape is Control::Error; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 28973 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval_generic.rs tolerate 33937 both failure message for the assertion this #3222 test exists to make
src/jq/eval_generic.rs tolerate 39574 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39578 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39581 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39637 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39717 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39732 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39755 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 39776 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40188 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40210 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40217 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40295 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40346 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40407 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40443 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 40452 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 40453 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 40454 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/lazy.rs tolerate 1474 both failure message for the shape the test asserts
src/jq/parser.rs tolerate 231 both unreachable: parse_join_expr only calls join_expr with two to four arguments (#3046)
src/jq/parser.rs tolerate 253 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 255 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 257 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 264 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 268 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 284 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 9765 both unreachable in a passing suite by design -- this is the panic message for the #3044 pin itself, only formatted if the let-else pattern fails to match (#3044)
src/jq/resolve.rs tolerate 2230 both unreachable by construction: this match is only entered when is_marker (marker.is_some()) is true, and RunMarker has only Begin/End variants -- the None arm exists solely for exhaustiveness against Option's type
src/jq/resolve.rs tolerate 2462 both unreachable in practice today: this arm needs builtin_fallback==None (the name was never a shadow candidate) yet is_jq_builtin==true (a real jq builtin at this arity) -- every implemented builtin's own dedicated parse already lowers that shape to Expr::Builtin before resolve.rs ever runs, and #3042/#3046 closed the once-real 'unimplemented builtin' gap this existed for (see JQ_BUILTIN_ROSTER's own doc comment)
src/jq/resolve.rs tolerate 2464 both unreachable with the current roster: every JQ_BUILTIN_ROSTER entry of arity >= 1 already has a dedicated parser form (a matches_keyword special case or a Libm1/Libm2/Libm3::ALL entry -- confirmed by cross-referencing the full roster against both), so it is parsed straight to Expr::Builtin and never reaches here as a bare FuncCall. This arm exists for a roster name with no dedicated parse yet and a nonzero arity -- there is none today, so the loop body is reached with an empty args on every pinned-suite run (355 hits on the arm's own condition, 0 in the loop) and would only start executing if such a name were added (#2964)
src/jq/share_stats.rs tolerate 97 both process-global env var; exercised by the CLI audit run, not by an in-process test (#2999)
src/jq/value.rs tolerate 365 both unreachable by construction: the slow path is entered only after significant_digit_count found 18+ digits over the same mantissa bytes this loop walks (#2936)
src/jq/value.rs tolerate 389 both unreachable by construction: 18+ significant digits were counted, so at least one nonzero digit was kept (#2936)
src/jq/value.rs tolerate 2800 both unreachable: format_float_with_fraction of a finite double is always RFC 8259 number text, which parse_i64_or_f64 reads (#2936)
src/jq/value.rs tolerate 4861 both unreachable in a passing suite by design -- every caller built the value as an array (#2999)
src/jq/value.rs tolerate 5104 both unreachable in a passing suite by design -- the value was built as this container a few lines above (#2999)
src/jq/value.rs tolerate 5923 both unreachable in a passing suite by design -- the failure message for a malformed oracle table (#2936)
src/jq/value.rs tolerate 6271 both failure message for the assertion the calling test makes
src/jq/value.rs tolerate 6495 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 6501 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 6613 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/jq/value.rs tolerate 7729 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/jq/value.rs tolerate 7747 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/json/light.rs tolerate 2663-2669 both unreachable in practice: UNMEASURED_SPAN only arises when end - text_pos in number_at overflows u32 -- a single number span >= 4 GiB -- which no realistic (or practically constructible) test document approaches (#3222)
src/json/light.rs tolerate 3442 both reachable only through a bare 64-bit hash collision between keys the pairwise scan already proved distinct
src/json/light.rs tolerate 9087 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9169 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9258 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9291 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9320 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9408 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/json/light.rs tolerate 9413 both unreachable in a passing suite by design -- see the assert_eq! format argument above, same sweep (#3222)
src/json/light.rs tolerate 9439 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9450 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9531 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/index.rs tolerate 1268 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1272 both unreachable: every fixture field_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1283 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1285 both unreachable: every call to field_key_head_foot in this test module passes a key that the fixture's mapping actually has (#798)
src/yaml/index.rs tolerate 1295 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1299 both unreachable: every fixture seq_item_head_foot is called with in this test module is a top-level sequence (#798)
src/yaml/index.rs tolerate 1322 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1341 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1364 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1373 both unreachable: every fixture field_key_head_foot_in_doc is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1384 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1386 both unreachable: every call to field_key_head_foot_in_doc in this test module passes a key that the fixture's document actually has (#798)
src/yaml/index.rs tolerate 1397 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1401 both unreachable: every fixture nested_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1405 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this let-else's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1411 both unreachable: every fixture nested_key_head_foot is called with has a nested mapping under outer (#798)
src/yaml/index.rs tolerate 1422 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1425 both unreachable: every call to nested_key_head_foot in this test module passes an outer.inner pair that the fixture actually has (#798)
src/yaml/light.rs tolerate 3365 both unreachable: an alias target is never None for a built index (#1374)
src/yaml/light.rs tolerate 15669 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 15680 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 15837 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/parser.rs tolerate 1583 both unreachable: every block-sequence open registers a frame at its own depth before any item of it can be parsed (#1079)
src/yaml/parser.rs tolerate 1613 both unreachable: this function's sole caller (record_standalone_comment) only invokes it from inside a match on pending_head_lines.last(), so pending_head_lines is already known non-empty here (#798)
src/yaml/parser.rs tolerate 7999 both unreachable: every byte here already passed the [0-9.eE+-] charset check above, a strict subset of ASCII, so str::from_utf8 can never fail (#2778)

Patch coverage

Patch: 80.39% (41/51 new lines covered)

File Patch Uncovered new lines
src/jq/eval.rs 78.26% (18/23) 24777, 24815-24818
src/jq/eval_generic.rs 82.14% (23/28) 16322, 16362-16365
Uncovered new lines (10)
  • src/jq/eval.rs:24777
  • src/jq/eval.rs:24815
  • src/jq/eval.rs:24816
  • src/jq/eval.rs:24817
  • src/jq/eval.rs:24818
  • src/jq/eval_generic.rs:16322
  • src/jq/eval_generic.rs:16362
  • src/jq/eval_generic.rs:16363
  • src/jq/eval_generic.rs:16364
  • src/jq/eval_generic.rs:16365

📦 Full per-file coverage summary · run summary

newhoggy added a commit that referenced this pull request Sep 28, 2026
…ry too

Third review of #3434: `isempty`, `any`/`all` (with a generator),
`IN` and generic `repeat` record the wrapping sink's stop exactly as
`first`/`limit`/`nth` did, and never cleared it when a `?//` retry
re-invoked their sink. Reached through a stop-then-continue shape
(`input`), the stale `Stopped` hit the slice collector's restored
`unreachable!` -- `[10,20,30] | [.[(isempty([[1]] as [$a] ?// [[$a]] |
$a) | input):]]` panicked (exit 101) where jq 1.7.1 answers `[[20,30]]`
-- and elsewhere promoted an error the retry had moved past
(`[(isempty(G) | (input | if . == "a" then error("x") else . end)), 9]`
raised on main too; jq answers `[1,9]`). All reset per invocation now,
in both evaluators, with one pointer comment each to `each_limit`.

The slice collectors no longer abort over a stash-less `Stopped`: any
enclosing driver that still reports a stale stop finishes the slice
with what it produced instead of crashing the process.

Part of #3293.
newhoggy added a commit that referenced this pull request Sep 28, 2026
Third review of #3434: six stop-then-continue rows (`input` inside the
consumer's downstream), captured from jq 1.7.1 with `-n`, covering the
slice panic and a comma cut short outside slices.

Part of #3293.
Slice 3 of #3293. Both slice collectors (`eval_generic::eval_slice_expr`
and `eval::eval_slice_expr`) parked a per-pair escape as a finished
`Partial` result -- `terminal = partial(take(out), control)` -- and a
`?//` retry inside either bound could never clear it: `[10,20] |
.[([[0]] as [$a] ?// [[$a]] | $a):]` raised "slice indices must be
integers" after the retry, where jq 1.7.1 answers `[10,20]`; a retry
that produced nothing, raised, or failed to destructure kept the stale
error too.

The escape now lives in a `StashedEscape` apart from `out`: both bound
sinks reset it per invocation, the `end` drive is settled per `start`
value, and the final result folds `out` in as the `Partial` prefix only
if the stash survived (`retry_superseded`). Moving the prefix out of the
stash is what lets a superseded escape leave the outputs already
produced in place.

Part of #3293.
Add a `RETRY_ROWS_SLICE_BOUND_3293` table (every value captured from jq
1.7.1): a retry in either bound that answers, produces nothing, raises
or fails to destructure, plus controls for the output prefix the fix
moved out of the stash -- a prefix before a later bound's error, a
generator in either bound, a slice error with no `?//`, and a
`halt_error` that must not retry. Run it over a document input and,
through the owned-route test, over a value built under `-n`.

Part of #3293.
… the pull

Review of #3434: a `first`/`limit`/`nth` around a retrying slice bound
reports its own count stop as `Stopped` after the `?//` retry inside it
re-invoked the sink, whose `begin()` had rightly cleared the stash -- a
combination the first version declared unreachable, so `.[first([[0]]
as [$a] ?// [[$a]] | $a):]` on `[10,20,30]` panicked (exit 101) on both
evaluators where jq 1.7.1 answers `[10,20,30]` and main raised.

A `Stopped` with no stash behind it is the bound's wrapper finishing, not
an escape: the inner `end` drive continues and the outer pull completes
with `out`. Also hoist `end`'s retry fallback out of the per-value
closure and drop the comments that still described the removed
`terminal`.

Part of #3293.
Review of #3434: the table had no row with the `?//` inside
`first`/`limit`/`nth`, the shape that reached the panic. Add seven,
captured from jq 1.7.1, run on both evaluators.

Part of #3293.
…a retry

Second review of #3434 found the root of the panic the previous commit
worked around: `each_limit`, `take_at_index` (`first`/`nth`) and their
`eval_generic` twins set `outer_stopped` when the wrapping sink stopped
and never cleared it, so after a `?//` retry inside them re-invoked the
sink they reported a stale `Stopped` to whatever enclosed them -- the
#3293 Class 2 shape in the consumers themselves. The slice collector's
"a stashless Stopped is completion" workaround hid the panic but not
the wrong answers: a comma after the wrapper was cut short
(`[.[(first([[1]] as [$a] ?// [[$a]] | $a), 2):]]` gave `[[20,30]]`
where jq 1.7.1 gives `[[20,30],[30]]`) and a filter dropping the
retried value kept the stale error.

Reset the flag at the top of each invocation, as #3411 did for the
value-mode sinks; the final flag then reflects the last invocation, so
an enclosing consumer that really stopped still makes jq's #1519 second
answer (`[first(first(1 as $x ?// $y | 1))]` is still `[1,1]`). The
slice collectors' `Stopped` arms go back to their strict form: an inner
`Stopped` propagates, and the outer one is unreachable again.

Part of #3293.
Second review of #3434: add the shapes that exposed the stale consumer
stop -- a comma after the wrapper in either slice bound, and a filter
dropping the retried value -- to the slice table, and a
`RETRY_ROWS_WRAPPER_STOP_3293` table pinning the reset outside slices,
including the #1519 double-answer controls. Both run on both evaluators.

Part of #3293.
…ry too

Third review of #3434: `isempty`, `any`/`all` (with a generator),
`IN` and generic `repeat` record the wrapping sink's stop exactly as
`first`/`limit`/`nth` did, and never cleared it when a `?//` retry
re-invoked their sink. Reached through a stop-then-continue shape
(`input`), the stale `Stopped` hit the slice collector's restored
`unreachable!` -- `[10,20,30] | [.[(isempty([[1]] as [$a] ?// [[$a]] |
$a) | input):]]` panicked (exit 101) where jq 1.7.1 answers `[[20,30]]`
-- and elsewhere promoted an error the retry had moved past
(`[(isempty(G) | (input | if . == "a" then error("x") else . end)), 9]`
raised on main too; jq answers `[1,9]`). All reset per invocation now,
in both evaluators, with one pointer comment each to `each_limit`.

The slice collectors no longer abort over a stash-less `Stopped`: any
enclosing driver that still reports a stale stop finishes the slice
with what it produced instead of crashing the process.

Part of #3293.
Third review of #3434: six stop-then-continue rows (`input` inside the
consumer's downstream), captured from jq 1.7.1 with `-n`, covering the
slice panic and a comma cut short outside slices.

Part of #3293.
Fourth review of #3434 (no regression found against main or the base
across ~5,500 differential cases, both routes):

- The slice collectors' stash-less `Stopped` arm degraded silently. It
  still finishes with `out` in a release build, but now panics under
  `debug_assertions`, so a driver that regresses into a stale stop fails
  the suite rather than truncating a slice unseen. Region-form coverage
  markers, which rustfmt cannot split off the lines they excuse.
- The consumer test ran only with `-n` (the `eval.rs` route); add the
  cursor-route rows that reach the `eval_generic.rs` twins.
- Revert the `repeat` reset: no `?//` retry reaches that closure, so it
  changed nothing, and `first(repeat(G))` diverges exactly as on main.
- `each_limit`'s comment said every consumer resets its stop; `//` still
  does not (no probe found it diverging) -- say so.

Part of #3293.
@newhoggy
newhoggy force-pushed the issue-3293-slice3-slice-bounds-collected-index branch from b70eb3f to e2f049b Compare September 28, 2026 20:59
The `stash.is_set()` guard returns every real stop before the inner
`end_flow` match, so its `Stopped` arm is reached only by a stale
enclosing driver -- the same by-design-unreachable state as the exit
arm. Say so, and tolerate it in coverage the way the exit arm is.

Part of #3293.
@newhoggy

Copy link
Copy Markdown
Contributor Author

Coverage note: all 10 uncovered patch lines are the slice collectors' stash-less Stopped arms. They're unreachable by design: every consumer that records a wrapping stop now resets it per invocation. They're kept as a debug-build panic with a release fallback, so a regressing driver fails loudly instead of crashing a release build. They carry omni-dev: coverage tolerate markers, and the bot counts tolerated lines in the percentage, so the patch figure can't rise without deleting those defensive arms. No line flipped from covered to uncovered.

@newhoggy
newhoggy added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit e2f8199 Sep 28, 2026
63 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant