Part of the #241 epic. Registers C-89.
Problem
test_no_coordinate_value_is_copied_into_this_repo exists because README.md once carried four real coordinate values in a public repository. It has three parts, and they disagree about the one rule that matters: never print the value.
The Python branch prints it. tests/test_env_declaration.py:1065:
copied.append(f"{source.relative_to(_PKG)}:{node.lineno} = {node.value!r}")
The markdown branch, 68 lines below, was rewritten on 2026-08-11 to report "assigns a registry value to {name}" for precisely this reason. _describe_changes was added in the same change with a docstring whose whole subject is that a value must never reach a public log. The invariant was stated, applied to one branch, and left off the other. This fires on exactly the violation the scan exists to catch, and the file's own comment records that this half runs in CI as of 2026-08-10. CI logs are world-readable and are not retroactively redactable.
The rotation proof checks one side. :937:
assert "value:" in changed[canary] and "at-the-pin" not in changed[canary]
Only the pinned value is asserted absent. The freshly rotated value — the more damaging one, and the one the fixture already names "after-rotation" — is never asserted absent. A regression in _describe_changes that digests one side and interpolates the other passes this proof.
Work
- Change the AST branch to report location and coordinate name only, matching the markdown branch's wording. The name is not secret; the value is.
- Extend the rotation proof to assert both fixture values absent from the message.
- Add one guard that asserts the no-print invariant about the test as a whole, not about a branch — e.g. a check that no registry value appears in any message this test can construct, exercised over a synthetic registry with both branches firing. This is the piece whose absence let one branch drift from the other.
Acceptance criteria
Implementation notes
Do this story first. S2 rewrites the matcher; getting the no-print invariant asserted before that moves means S2 cannot reintroduce this.
The "about the whole test" guard is the interesting part and should not be skipped as ceremony — it is the only thing that would have caught this. One approach: factor message construction into a small helper both branches call, and assert over the helper.
Testing
pytest -q tests/test_env_declaration.py, plus the two injections above run and reverted. Use cp backups; never git checkout --, git stash, or git restore.
Labels
story, implementation, testing
Part of the #241 epic. Registers C-89.
Problem
test_no_coordinate_value_is_copied_into_this_repoexists because README.md once carried four real coordinate values in a public repository. It has three parts, and they disagree about the one rule that matters: never print the value.The Python branch prints it.
tests/test_env_declaration.py:1065:The markdown branch, 68 lines below, was rewritten on 2026-08-11 to report
"assigns a registry value to {name}"for precisely this reason._describe_changeswas added in the same change with a docstring whose whole subject is that a value must never reach a public log. The invariant was stated, applied to one branch, and left off the other. This fires on exactly the violation the scan exists to catch, and the file's own comment records that this half runs in CI as of 2026-08-10. CI logs are world-readable and are not retroactively redactable.The rotation proof checks one side.
:937:Only the pinned value is asserted absent. The freshly rotated value — the more damaging one, and the one the fixture already names
"after-rotation"— is never asserted absent. A regression in_describe_changesthat digests one side and interpolates the other passes this proof.Work
Acceptance criteria
.pystring constant fails the scan, and the failure message contains neither the value nor any substring of it."at-the-pin"and"after-rotation"are absent; mutation-proven by interpolating each side raw in turn and watching the proof fail.Implementation notes
Do this story first. S2 rewrites the matcher; getting the no-print invariant asserted before that moves means S2 cannot reintroduce this.
The "about the whole test" guard is the interesting part and should not be skipped as ceremony — it is the only thing that would have caught this. One approach: factor message construction into a small helper both branches call, and assert over the helper.
Testing
pytest -q tests/test_env_declaration.py, plus the two injections above run and reverted. Usecpbackups; nevergit checkout --,git stash, orgit restore.Labels
story,implementation,testing