Skip to content

fix(jq): a destructuring ?// bind states its register per result, and a retry after a failed write resumes from null - #3900

Merged
newhoggy merged 2 commits into
mainfrom
issue-3859-jq-a-bind-with-a-failed-first-alternative-and
Oct 6, 2026
Merged

newhoggy merged 2 commits into
mainfrom
issue-3859-jq-a-bind-with-a-failed-first-alternative-and

Conversation

@newhoggy

@newhoggy newhoggy commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

  • A by-value true/false/null body after a destructuring ?// bind whose first alternative fails to destructure now answers jq's valid path: path(.x | (. as [$q] ?// $z | true)) on {"x":true} is ["x"] (was exit 5). The failed destructure is restored by the fork, so the bare-$var alternative that runs leaves the register at the stage's entry; the pipe stage discarded that statement because cannot_move_register is false for any destructuring pattern. stage_states_register_per_result now admits a destructuring AsPattern whose body cannot move the register. A successful destructure navigated and is read as before.
  • Fixes a write bug this widening exposed and that was already there on tracked rows: after a write raises, jq's reduce state is the null its DUPN hands back, so a ?// retry writes the retried alternative's paths onto null. stream_path_writes kept the earlier paths' document. (.x | .. | (. as [$q] ?// $z | $z)) = 9 on {"x":[null],"k":3} kept k on main; jq gives {"x":[9]}.
  • Splits the two residuals into jq: any/all path answers drain the generator before delivery, and a compound body after a destructuring ?// bind still refuses (#3859 split) #3899 (drain order of any/all answers, and a compound body such as (.a?, true)), and updates limitations.md and the producer-contract note.

Fixes #3859

Test plan

  • cargo build --features cli
  • cargo test --features cli,simd,regex,serde (10,146 passed, 0 failed)
  • cargo test --no-default-features --lib, cargo check --no-default-features
  • cargo clippy --all-targets --all-features -- -D warnings
  • cargo clippy --all-targets --features std,simd,serde,cli,regex,bench-runner,large-tests,mmap-tests -- -D warnings
  • RUSTDOCFLAGS="-D warnings" cargo doc --no-deps --features cli
  • Oracle A/B (/usr/bin/jq 1.7.1 vs a main build vs this branch), 49,590 generated rows over entries x binds x bodies x path/del/=/|=: 678 improved, 0 regressed, 0 accept-wrong. The only changed rows that still differ from jq are |= error-to-error message differences with the same exit code (the documented _modify retry quirk).
  • scripts/jq-bind-origin-fuzz.py --destructure-bind-p 1.0 --fold-p 0.3 -n 6000 --baseline <main>: 5,994 agree, 0 fabricate, 0 mismatch; 6 refuse-only rows all reproduced byte-for-byte by the baseline
  • New tests test_destructuring_alt_bind_with_a_failed_first_alternative_states_its_register_3859 and test_destructuring_alt_bind_writes_and_a_retry_resumes_from_null_3859 (every row captured from jq 1.7.1, stdin and -n routes); each pinned row that changes was confirmed to differ on main
  • scripts/jq-path-register-sweep.py, 150k-row seeded sample (result posted as a comment)

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Coverage

Total: 94.88% ⚪ 0 pp vs main

Comparing 299bde7..1f2222d (merge-base → PR head)

No per-file coverage changes vs main.

🔇 0 ignored region(s), 383 tolerated region(s)

ignore removes the lines from both reports; tolerate keeps them in the reported percentage but scores them against the baseline, so a cross-run flip cannot move a delta. Regions are read from each revision's own source.

File Kind Lines Rev Reason
src/bin/succinctly/jq_runner.rs tolerate 1332 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted, for the identical reason run_jq's own analogous fallback (#2395) is tolerated -- see that line's own comment (#2950)
src/bin/succinctly/jq_runner.rs tolerate 1705 both unreachable while the walk and the loader agree on what fails: both resolve with resolve_module_in/resolve_data_file_in, parse with parse_program and name a cycle by canonical file, which the fuzz in #3573 held over thousands of programs; kept so drift prints the loader's failure and not 0 compile errors
src/bin/succinctly/jq_runner.rs tolerate 2422-2434 both unreachable: try_parse_meta_op only fires under ParserMode::Yq (src/jq/parser.rs), and rewrite_namespaced_calls is only reached via ModuleProcessor::process_program, which jq_runner's own jq-mode run is the sole caller of -- so a MetaAssign node can never reach this function (#798)
src/bin/succinctly/jq_runner.rs tolerate 3022 both unreachable by construction: every error this wrapper receives today is a decode or nesting-depth failure the evaluator raised itself, never error(v); kept so a future one is rendered rather than dropped (#2999)
src/bin/succinctly/jq_runner.rs tolerate 3023 both see the arm above (#2999)
src/bin/succinctly/jq_runner.rs tolerate 3442 both unreachable in practice today: def is only None when occurrences.module_def() is None, which (given origin is Some) would require an open run whose innermost frame has no def set at a check point that isn't itself inside a module-level def body -- but every module run is a strict chain of def nodes (the loader's own defs, each wrapping its dependency stubs INSIDE its own body via wrap_defs/dep_stubs_for) terminated by the run's own end marker, so a diagnosable call/var/break site is always reached either inside a module-level def's body (module_def Some) or outside every run (origin None) -- and even when def is Some, self.defs is always ModuleSource::read's own re-parse of the exact same file run_id_for interned this origin's id from, so collect_def_sites always finds the matching (name, arity, ordinal) span. Kept as a defensive fallback rather than a panic/unwrap in case that invariant is ever violated (#3085)
src/bin/succinctly/jq_runner.rs tolerate 3691-3694 both unreachable in a single-process run by construction: run_id_for (the sole source of an origin id) always inserts a run_origins entry for the id it hands back -- from a real load's canonical path, or its own literal-path fallback on a resolve failure -- and a def body only ever gets stamped with an origin after its module loaded successfully, so at always names a file that existed and was readable moments earlier. Reaching this arm needs that same file to vanish (or become unreadable) in the narrow window between that load and this re-read, entirely outside this process's control (#2964)
src/bin/succinctly/jq_runner.rs tolerate 3960 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted -- a newly covered name only wraps an already-successful dedicated parse, and a failing one would have propagated its error in the first parse too, so the retry budget is charged at the identical sites in both (#2395)
src/bin/succinctly/jq_runner.rs tolerate 4551-4587 both unreachable from any query this suite can build since #3457: the path walkers were the sites that panicked at MAX_NESTING_DEPTH here (sort/join/map, path()/paths/setpath/del()/assignment on a deep document), and they now return a decode-failure-tagged error, so a deep document is reported through the ordinary Err arm instead. The panic sites still in the evaluator (lazy.rs cursor_to_owned, owned_identity_recurse_step, owned_from_standard_json_at_depth, the YAML comment-preserving materialization) are not reached by a jq-mode CLI query at 250-500 levels, probed by hand; the catch is kept as the net for them and for a future guard that panics, and nesting_depth_panic_message itself is pinned by a unit test (#3457)
src/bin/succinctly/jq_runner.rs tolerate 9844 both unreachable: this test builds only ResolveError::Call values (#3313)
src/bin/succinctly/jq_runner.rs tolerate 11853 both unreachable in a passing suite by design -- the fixed b\
src/bin/succinctly/main.rs tolerate 1372 both unreachable given clap 4.6's own unknown_argument() error constructor: every ErrorKind::UnknownArgument it builds sets ContextKind::InvalidArg to ContextValue::String(arg) in the same call, so this arm only guards a future clap release changing that invariant
src/bin/succinctly/main.rs tolerate 1541 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_accepted_via_sjq_multicall_alias_3389's '-x' row demonstrably reaches the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1710 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_boundary_characters_3389's '-x'/'-n1'/'--bogus' rows demonstrably reach the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1732 both the CLI suites drive yq through the syq multi-call arm above; this arm is the same call reached only when spelled succinctly yq (#2999)
src/bin/succinctly/yq_runner.rs tolerate 1650 both unreachable: bytes already parsed successfully by every caller (#1350)
src/bin/succinctly/yq_runner.rs tolerate 1752 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1753 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1754 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 3365 both unreachable: path is always the raw output of the path(TARGET) builtin evaluated a few lines up in resolve_one_meta_assign -- path/1 is a jq/yq language invariant that always answers an array of path components (see Expr::Builtin(Builtin::PathNoArg) => Ok(Some(OwnedValue::Array(..))) in eval_generic.rs), never any other shape (#798)
src/bin/succinctly/yq_runner.rs tolerate 3467 both unreachable: resolve_meta_assign_writes runs expr through this before any evaluation begins (see its own doc comment), and Expr::Shared is never constructed by the parser -- only at eval time, by function-call argument substitution (substitute_func_param in eval.rs) -- so a pre-evaluation AST can never contain one here (#798)
src/bin/succinctly/yq_runner.rs tolerate 4123 both unreachable: every arm of the match result { .. } above that assigns docs (L3492-3622) constructs Ok(..) -- none ever produces Err, so this if let's implicit else can't be taken; symmetric to L1625's ? (#798)
src/bin/succinctly/yq_runner.rs tolerate 6936-6938 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 7127-7132 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 7892-7897 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/jq/document.rs tolerate 406 both unreachable: the only caller, eval_generic::embed_at_or_within, is gated on jq semantics, and the YAML cursor (the one implementor without an override) is only ever evaluated under yq semantics (#3179)
src/jq/document.rs tolerate 1096-1100 both unreachable: both implementors (JsonCursor, YamlCursor) override this; the default exists as the conservative-false contract a future implementor inherits (#3222)
src/jq/document.rs tolerate 1275-1282 both unreachable: both implementors (StandardJson, YamlValue) override this to decode once; the default exists as the contract a future implementor inherits, and is deliberately the two-call sequence it replaces (#965)
src/jq/eval.rs tolerate 1217 both unreachable: def is always a collect_alias_groups anchor path, which step_to_expr never fails on (#1351)
src/jq/eval.rs tolerate 1238 both unreachable: redirect_paths with Redirect::SINGLE always contributes exactly one output per input, so a 1-element paths always pops Some (#1351)
src/jq/eval.rs tolerate 1247 both unreachable: a concrete setpath/delpaths path's components are always Field/Index -- step_to_expr never produces another shape (#1351)
src/jq/eval.rs tolerate 1251 both unreachable: the map above never yields None, since it only ever matches Field/Index (#1351)
src/jq/eval.rs tolerate 1785 both unreachable: key_or_parent_root_construct's identical structural match already refused any expr shape that would reach this arm
src/jq/eval.rs tolerate 2357 both unreachable: same invariant as the tolerated line below (#3069)
src/jq/eval.rs tolerate 2358 both unreachable: same invariant as the tolerated line below (#3069)
src/jq/eval.rs tolerate 2360 both unreachable: a bridge document is its source's serialization, so the node at each recorded position is the recorded kind (#3069)
src/jq/eval.rs tolerate 2361 both unreachable: see the debug_assert above (#3069)
src/jq/eval.rs tolerate 2407 both unreachable: a scalar has no children, and node lies inside the subtree the walk is in (#3069)
src/jq/eval.rs tolerate 4955 both unreachable: is_escape() is exactly `Error
src/jq/eval.rs tolerate 4956 both unreachable: see the if let above -- push_owned_values never answers None for an is_escape() result (#2180)
src/jq/eval.rs tolerate 6218 both unreachable today: to_owned's only failures are is_decode_failure()-tagged, and suppresses() answers false for those whatever optional is -- the same defensive-but-dead arm eval_generic's own Builtin::Path materialization documents under #2280 (#2908)
src/jq/eval.rs tolerate 7097 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 8479 both unreachable: optional is never true here. eval_each is entered with a forced true at exactly one site (Expr::Optional over an IndexExpr/SliceExpr), and both of those evaluate their target (eval_index_expr) and their key (eval_each(key, .., false)) with a hardcoded false, so only the final index/slice step ever sees it -- nothing carries it down to an Expr::Object (#2180)
src/jq/eval.rs tolerate 9688 both unreachable: owned_write_door calls this only on a clone of a head write_target already matched, and the two list the same five variants (#3188)
src/jq/eval.rs tolerate 9702 both unreachable: every value path_over_owned hands back is a path() output, which is always an array (#3188)
src/jq/eval.rs tolerate 9981 both unreachable: any_child_witnessed is false for every non-container, checked just above (#3178)
src/jq/eval.rs tolerate 10173 both unreachable: the if above replaces every other state with Owned before this match
src/jq/eval.rs tolerate 10679 both reachable only on a genuine allocation failure: owned_assign_step's single-step arms map every non-allocation error to unreachable_owned_assign_write (provably impossible, see its own doc comment), and its Chain arm's set_path call walks exactly the steps owned_assign_step_child already validated as Field-into-Object/Null or Index-in-[0,len]-into-Array/Null with no mutation in between, so the only way set_path/set_field/set_index/pad_with_nulls can still fail is the same try_reserve-fails-under-OOM branch the codebase already tolerates elsewhere (#2267) (#3138)
src/jq/eval.rs tolerate 10799 both unreachable: owned_assign_shape's only caller (owned_step_shape) gates the call on is_owned_assign(expr), which recognizes exactly Assign/Update/CompoundAssign/AlternativeAssign -- the same four variants this match already has explicit arms for, so expr can never be anything else here (#3138)
src/jq/eval.rs tolerate 10999 both unreachable: both call sites (try_eval_owned_step, gated on is_owned_assign; eval_owned_reindex_free's own Assign
src/jq/eval.rs tolerate 11073 both unreachable: this function's own doc comment states why -- the borrow on state between owned_assign_step_child's check and the single write makes the container changing shape impossible, so debug_assert!(false, ..) can never fire (#3138)
src/jq/eval.rs tolerate 11074 both unreachable: same invariant as the false above -- this message is only ever formatted if that assert fires (#3138)
src/jq/eval.rs tolerate 11076 both unreachable: this function is only called from owned_assign_step's single-step arms, both of which the invariant above already rules out ever calling it for real (#3138)
src/jq/eval.rs tolerate 11077 both unreachable: the whole function body above is provably dead by the same borrow-checker invariant its doc comment states (#3138)
src/jq/eval.rs tolerate 11114 both unreachable: Expr::pipe() (the parser's sole Pipe constructor) collapses a one-element list to the bare inner expr instead of wrapping it, and substitute_vars's substitute_var walk preserves a Pipe's stage count rather than dropping stages -- no other site builds an Expr::Pipe for a parsed assignment path, so a path's top-level Pipe here is never single-element (#3138)
src/jq/eval.rs tolerate 14295 both unreachable: every entry point supplies path context, so path never evaluates without one; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 14428 both unreachable: only ever constructed by builtin_sort_keys's own eval_update_no_vivify call, whose enclosing eval_update_impl already runs to_owned on the whole document up front (#2855) -- a decode failure anywhere raises there, before this filter ever sees a value to re-decode; confirmed live, sort_keys(.a)/sort_keys(..) on a document with a decode-failure subtree both raise from the outer to_owned
src/jq/eval.rs tolerate 14571-14573 both unreachable: builtin_length's sole caller is eval_builtin's Builtin::Length dispatch, and Length is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before this match ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 14794-14796 both unreachable: has_one_key's sole caller is builtin_has (via eval_builtin's Builtin::Has dispatch), and Has is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before builtin_has ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 18081 both unreachable: entry is one of to_entries's already-materialized {key,value} pairs, so its depth here is provably no deeper than whatever earlier check let it exist -- a document-decoded entry is already <256 deep (MAX_NESTING_DEPTH, stricter than this 384 guard), and a filter-constructed one already survived becoming a cursor via its own whole-object reindex, which is strictly deeper than any single field extracted from it could be (unwrapping only reduces depth); confirmed live, {a: (reduce range(400) as $i (0; [.]))}
src/jq/eval.rs tolerate 25962 both unreachable: escape_with_prefix! sets terminal before Demand::Stop; already returned above (#2138)
src/jq/eval.rs tolerate 26058 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval.rs tolerate 26059 both unreachable in a test: see the line above (#1634)
src/jq/eval.rs tolerate 26065-26068 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval.rs tolerate 26083-26088 both unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval.rs tolerate 28167 both unreachable via --eval-all: every document here comes straight from parse_input, whose own MAX_NESTING_DEPTH (256) guard already rejects anything deep enough to reach MAX_VALUE_TREE_DEPTH (384) here -- confirmed live, a 300-level document fails parse_input's guard before ever reaching this reindex (#3261)
src/jq/eval.rs tolerate 28498 both unreachable: eval_assign returns collect_assign for JqSemantics before this point, and yq_prepare_assign_targets is Some for every YqSemantics call (#3448)
src/jq/eval.rs tolerate 30100 both unreachable: eval_compound_assign/eval_alternative_assign return collect_assign for JqSemantics before this point, and yq_prepare_assign_targets is Some for every YqSemantics call (#3448)
src/jq/eval.rs tolerate 30427-30430 both unreachable: a materialization only ever raises a decode failure, which suppresses never swallows -- debug_assert_materialization_error (#2334) asserts exactly that; kept so the one classification rule is applied here as at every sibling to_owned site (#1953, #3448)
src/jq/eval.rs tolerate 30440-30443 both unreachable: assign_pristine is to_owned, which only ever raises a decode failure (#2334's debug_assert_materialization_error), and suppresses never swallows one; kept so the one classification rule is applied here as at every sibling to_owned site (#1953, #3448)
src/jq/eval.rs tolerate 30578 both unreachable: the eager route runs only when the path resolves to at most one path -- needs_path_prepass false is one verbatim path, and true with resolves_to_at_most_one_path is at most one resolved path (#2976) -- so no path is ever followed by another; kept as the loop's own contract (#3448)
src/jq/eval.rs tolerate 31659 both unreachable: descriptor_path_component builds a Verbatim key only from an object (#3300)
src/jq/eval.rs tolerate 32228 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval.rs tolerate 35573 both unreachable: an anchor is always a proper ancestor, so it records at least one step (#3134)
src/jq/eval.rs tolerate 36853 both reachable only on a genuine allocation failure: Vec::try_reserve(1) on a vector that has spare capacity, or can grow, cannot fail -- this is the whole purpose of the branch, converting an OOM into a catchable error rather than an abort (ADR-0018's 'would take the host process down' exception). The pre-#2267 form of the same guard, out.try_reserve(branches.len()) in resolve_index_expr/resolve_slice_expr, was 0-hit for the identical reason (#2267)
src/jq/eval.rs tolerate 36854 both see the line above -- the Demand::Stop half of the same allocation-failure-only branch (#2267)
src/jq/eval.rs tolerate 36860 both reachable only when the try_reserve above failed, i.e. only on a genuine allocation failure (#2267)
src/jq/eval.rs tolerate 39797 both unreachable: owned_value_jq_length's own match only ever constructs OwnedValue::Int or OwnedValue::Float, checked just above this arm (#2744)
src/jq/eval.rs tolerate 40744 both unreachable: is_primitive admits only Identity/Field/Index/Slice, and of those only a Slice's computed bounds can halt -- all four have their own arm in resolve_node_sink/resolve_node_eager, so none reaches this function. Pre-existing; #2694 only wrapped the return in Some (#2694)
src/jq/eval.rs tolerate 40778 both unreachable, as this arm's own comment above says: indexing or slicing a value yields zero or one result, so is_primitive never produces more than one -- kept as a named error rather than a panic. Pre-existing; #2694 only wrapped the enclosing return in Some (#2694)
src/jq/eval.rs tolerate 41531 both unreachable: a cond that flattens to no stages is . or a pipe of ., which cannot_move_register admits, so it never takes the live route (#3757); the debug_assert where stages is built fails a test build that breaks that
src/jq/eval.rs tolerate 46114 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 47632 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), returned just above (#2872)
src/jq/eval.rs tolerate 48423 both unreachable: every arm of the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 48967 both unreachable: every path through the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 52101 both unreachable in a passing suite by design -- a panic-message format argument for the #682 single-valued-tail pin, evaluated only if that assert's own condition is false (#2190)
src/jq/eval.rs tolerate 52178 both unreachable: the only caller reaches this after classify_static_component answered Field for this same value, which it does only for an object (#2190)
src/jq/eval.rs tolerate 52222 both unreachable: both callers establish the container first -- navigate_static_component_ref via classify_static_component's Index arm, and walk_path's Expr::Iterate arm by matching on the container itself (#2190)
src/jq/eval.rs tolerate 55182 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 56890 both unreachable: stop_with_escape's only write is slot.set(Some(control)) with the control it was handed, which is always the Control::Error built one line above (#2180)
src/jq/eval.rs tolerate 57581 both unreachable: on_update records a step_outcome before every Demand::Stop it answers, and the fallback match runs only when it recorded none (#2872)
src/jq/eval.rs tolerate 57621 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 58360 both unreachable by construction: the per-fork match only ever hands stop_with_downstream a non-Exhausted flow, so terminal can never hold Exhausted (#2899)
src/jq/eval.rs tolerate 60689 both llvm-cov line-attribution artifact, not unreachable: the new gate test above (Builtin::Length as first) demonstrably takes key_or_parent_root_construct(first) == false and falls through to the reindex-bridge route below, passing -- but this closing brace, like the one at #56920 for the same reason, is never itself credited a hit
src/jq/eval.rs tolerate 60703 both unreachable in the current test suite: eval_path_context_pipe_owned itself has zero total call-site coverage today (not just this arm), confirmed by a full-suite eprintln probe across every test binary -- reaching its error arm needs first solving how to reach the function at all, out of scope for #3261's reindex-bridge fix
src/jq/eval.rs tolerate 61777 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 61783 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval.rs tolerate 63903 both pre-existing zero-hit line; #2999 changed only which null constant it names
src/jq/eval.rs tolerate 66319 both ? suppresses mktime's error outside builtin dispatch, so the optional flag is false even for an invalid date (#3083)
src/jq/eval.rs tolerate 66322 both unreachable for mktime's C-int-clamped fields: checked civil-date arithmetic stays within i64; the guard protects other callers of the shared helpers (#3083)
src/jq/eval.rs tolerate 66511 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 66514 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 66559 both optional is never true through either caller of this function -- confirmed live (eprintln! probe): `[1,2,3]
src/jq/eval.rs tolerate 66568 both every array literal written in filter source, and every array-element JSON parses, decodes to NumberLiteral (#1035), not a bare Int -- Int is for internally-synthesized values spliced post-parse; probed a computed element ([1970,(0+0),..]) and it still decoded as NumberLiteral here, so this arm has no known real producer (#3068)
src/jq/eval.rs tolerate 66604 both optional is never true through either caller of this function, same as the array-length check above (#3068)
src/jq/eval.rs tolerate 66668 both unreachable for strftime's C-int-clamped fields and bounded zone offset; shared checked date helpers retain overflow guards for other callers (#3083)
src/jq/eval.rs tolerate 66824 both llvm-cov line-attribution artifact, not unreachable: the call's own argument lines (immediately above) show 3 hits under the #3055 test's three E/O pass-through rows, but this closing-token line is never itself credited -- verified via the raw lcov DA: records
src/jq/eval.rs tolerate 68014 both unreachable: YamlIndex::root always wraps the documents in a virtual root sequence, so the arm above takes every input (#2664)
src/jq/eval.rs tolerate 68015 both unreachable: the same defensive arm as the line above (#2664)
src/jq/eval.rs tolerate 68327 both unreachable from combinations, whose own empty-input return runs first; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 69431 both confirmed live (eprintln! probe): optional is always false in builtin_abs regardless of whether the filter writes abs?, since that suppression happens entirely outside builtin dispatch here -- the same 'optional is never true here' shape eval.rs already documents elsewhere (#2180) (#3041)
src/jq/eval.rs tolerate 71489 both unreachable: the sink is a plain collector that always answers Demand::Continue (#2872)
src/jq/eval.rs tolerate 71599 both unreachable: optional: false makes index_one_owned answer Ok(Some)/Err only (#2872)
src/jq/eval.rs tolerate 71904 both unreachable: pattern_has_computed_key is false for Pattern::Var, so the loop walker above always takes it (#2872)
src/jq/eval.rs tolerate 71952 both unreachable: every caller gates on pattern_has_computed_key being false (#2872)
src/jq/eval.rs tolerate 73648 both unreachable: bind_def_call only calls this for a non-empty params, install_def_calls only builds a DefCall whose args.len() equals params.len(), and the last parameter is never shadowed, so at least one entry is always built (#2560)
src/jq/eval.rs tolerate 75062 both unreachable in a passing suite by design -- this panic only fires if eval_owned_reindex_free declined a shape this loop's own handled table asserts is always answered (#3138)
src/jq/eval.rs tolerate 75071 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a shape this loop's own handled table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 75110 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step handled a shape this loop's own declined table asserts is always declined (#3138)
src/jq/eval.rs tolerate 75131 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a yq shape this loop's own table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 75231 both unreachable in a passing suite by design -- this panic only fires if the tracked \
src/jq/eval.rs tolerate 75233 both unreachable in a passing suite by design -- this panic only fires if state stopped being an Object, which every owned_assign_step write in the loop below preserves (#3138)
src/jq/eval.rs tolerate 75241 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on the single-step shape this loop drives every iteration (#3138)
src/jq/eval.rs tolerate 75246 both unreachable in a passing suite by design -- this arm only fires if state stopped being an Object, which every write in the loop above preserves (#3138)
src/jq/eval.rs tolerate 75284 both unreachable in a passing suite by design -- this panic only fires if the tracked \
src/jq/eval.rs tolerate 75286 both unreachable in a passing suite by design -- this panic only fires if state stopped being an Object, which every owned_assign_step write in the loop below preserves (#3241)
src/jq/eval.rs tolerate 75304 both unreachable in a passing suite by design -- this arm only fires if state stopped being an Object, which every write in the loop above preserves (#3241)
src/jq/eval.rs tolerate 75381 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on the single closed assignment this test drives (#3241)
src/jq/eval.rs tolerate 75396 both unreachable in a passing suite by design -- both values are built as objects above and an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 75441 both unreachable in a passing suite by design -- doc builds an object (#3241)
src/jq/eval.rs tolerate 75449 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on the single closed assignment this test drives (#3241)
src/jq/eval.rs tolerate 75457 both unreachable in a passing suite by design -- an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 75490 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on a closed assignment this table asserts is always answered (#3241)
src/jq/eval.rs tolerate 75493 both unreachable in a passing suite by design -- an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 75537 both unreachable in a passing suite by design -- this panic only fires if fold_step_each reported anything but an escape (not optional) or exhaustion (optional) for a failing owned step (#3241)
src/jq/eval.rs tolerate 75580 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step answered an UPDATE holding an Expr::TrackedVar, which closed_expr_to_owned rejects (#3241)
src/jq/eval.rs tolerate 75608 both unreachable in a passing suite: every row below is a reduce or a foreach (#3329)
src/jq/eval.rs tolerate 75937 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 75959 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 75977 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 76047 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 76065 both substitute_func_param_impl's FuncDef arm always returns FuncDef (#2555)
src/jq/eval.rs tolerate 84100 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval.rs tolerate 84259 both unreachable in a passing suite by design -- this is the failure message for the assertion the test exists to make (#2190)
src/jq/eval.rs tolerate 84639 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval.rs tolerate 85298 both unreachable in a passing suite: reports a failed test invariant (#3682)
src/jq/eval.rs tolerate 85513 both the no-std arm: `cfg!(feature = \
src/jq/eval.rs tolerate 86344 both unreachable in a passing suite: every source this helper parses starts with def f(n): ...; (#3296)
src/jq/eval.rs tolerate 86397 both unreachable in a passing suite: f(1) under def f(n) always installs as a DefCall, which the assert above has just settled (#3296)
src/jq/eval.rs tolerate 97869 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 97921 both unreachable in a passing suite by design -- this test's own diagnostic (#3102)
src/jq/eval.rs tolerate 98835-98846 both the closure is asserted never called below (on_update_calls stays 0) -- Err(_) with optional=true short-circuits fold_step_each before this sink runs (#3122)
src/jq/eval.rs tolerate 103625 both unreachable in a passing suite by design -- the door's sink never stops and it never breaks or halts (#3439)
src/jq/eval.rs tolerate 104210 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 109220 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 109231 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 109248 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 109268 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 109276 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 110427 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 112363 both unreachable in a passing suite by design -- check_value_tree_depth's only Err variant is EvalError, and From for EvalEscape always produces EvalEscape::Error (#3275)
src/jq/eval.rs tolerate 112968 both unreachable in a passing suite by design -- the failure message for the shape assertion the test makes (#3471)
src/jq/eval.rs tolerate 116282 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116324 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116329 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116364 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116385 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116488 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116504 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 119981 both unreachable in a passing suite by design -- every filter this helper is called with parses to an AsPattern (#2649)
src/jq/eval.rs tolerate 120025 both unreachable in a passing suite by design -- a literal-key pattern's walk either completes or refuses with an error (#2872)
src/jq/eval.rs tolerate 120034 both unreachable in a passing suite by design -- every call site passes the origin of a binding this same test already proved carries a marker (#2649)
src/jq/eval.rs tolerate 120362 both unreachable in a passing suite by design -- the assertion above is the test (#2872)
src/jq/eval.rs tolerate 121062 both unreachable in a passing suite by design -- every row here is a shape jq accepts, confirmed live (#2649)
src/jq/eval.rs tolerate 121130 both unreachable in a passing suite by design -- every row here is a shape jq refuses, confirmed live (#2649)
src/jq/eval.rs tolerate 121515 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 121531 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 121565 both unreachable in a passing suite by design -- this is the panic message for the #3069 pin itself, only formatted if the let-else pattern fails to match
src/jq/eval.rs tolerate 121582 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 121598 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 121612 both unreachable in a passing suite by design -- this is the panic message for the #3069 pin itself, only formatted if the match doesn't hit the expected arm above
src/jq/eval.rs tolerate 121698 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3037)
src/jq/eval.rs tolerate 121776 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3037)
src/jq/eval.rs tolerate 122552 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3135)
src/jq/eval.rs tolerate 122659 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3122)
src/jq/eval.rs tolerate 122677 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3122)
src/jq/eval.rs tolerate 122745 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 122749 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 122789 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 122793 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 124538 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3119)
src/jq/eval.rs tolerate 124593 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3127)
src/jq/eval.rs tolerate 127287 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#2937)
src/jq/eval.rs tolerate 127374 both unreachable in a passing suite by design -- every READERS filter raises a decode failure on every malformed json in this sweep, so this fallback never fires (#3222)
src/jq/eval.rs tolerate 127380 both unreachable in a passing suite by design -- see the concrete match above, same sweep (#3222)
src/jq/eval.rs tolerate 127386-127388 both unreachable in a passing suite by design -- this is the failure-recording line for the assertion below, only reached if a READERS filter fails to raise (#3222)
src/jq/eval.rs tolerate 127444 both unreachable in a passing suite by design -- none of NON_READERS ever raises through eval_with_cursor_using, on the malformed document or the well-formed one; kept so a filter that starts erroring is still comparable rather than panicking (#3222)
src/jq/eval.rs tolerate 127747 both unreachable in a passing suite by design -- every filter below builds an array (#3191)
src/jq/eval.rs tolerate 127754 both unreachable in a passing suite by design -- each element is built as {k: } (#3191)
src/jq/eval.rs tolerate 127756 both unreachable in a passing suite by design -- each element is built as {k: } (#3191)
src/jq/eval.rs tolerate 127858 both every pinned filter below yields an owned value; kept so a cursor answer still renders rather than panics (#2999)
src/jq/eval.rs tolerate 127859 both unreachable in a passing suite by design -- the failure message for the assertions this helper serves (#2999)
src/jq/eval.rs tolerate 128193 both unreachable in a passing suite: every corpus program starts with a def (#3307)
src/jq/eval.rs tolerate 128318 both unreachable in a passing suite: every corpus program's first node is a def (#3307)
src/jq/eval.rs tolerate 128355 both unreachable in a passing suite: the last def's call is bound (#3307)
src/jq/eval.rs tolerate 128517 both unreachable in a passing suite: every caller passes a def head (#3307)
src/jq/eval.rs tolerate 128593 both unreachable in a passing suite: chain builds a def head (#3307)
src/jq/eval.rs tolerate 128597 both unreachable in a passing suite: a 50-def chain has a second def (#3307)
src/jq/eval.rs tolerate 128693 both unreachable in a passing suite: spine_node builds a def head (#3307)
src/jq/eval.rs tolerate 128754 both unreachable in a passing suite: the loop above builds a def (#3307)
src/jq/eval.rs tolerate 128762 both unreachable in a passing suite: the main filter is a pipe (#3307)
src/jq/eval.rs tolerate 128766 both unreachable in a passing suite: stages 0 and 2 are the spliced arguments (#3307)
src/jq/eval_generic.rs tolerate 1186 both unreachable: validate_cursor, CheckOnly's only instantiation, passes no nested nodes, so the walk never asks (#3179)
src/jq/eval_generic.rs tolerate 5152 both unreachable: the sole remaining caller (retain_truthy_generic's Many arm) runs to_owned on an item before keeping it, so re-converting a kept item here cannot fail; the ManyCursor caller that made this reachable went with the truthiness walk (#2692, re-establishing #2661's premise)
src/jq/eval_generic.rs tolerate 7082 both unreachable: hi is find_close of a container's own open paren, which a built index always matches (#3179)
src/jq/eval_generic.rs tolerate 7960 both unreachable for the one format that claims materializes_members_one_to_one: a JSON object's children always pair key-then-value; kept so an implementor whose mapping could end on a key declines instead of miscounting (#3483)
src/jq/eval_generic.rs tolerate 7977 both unreachable for JSON: a key node always decodes or falls back to its raw spelling, so key_display_string is Some; kept so a format whose key can be non-string declines to the generic walk (#3483)
src/jq/eval_generic.rs tolerate 10511 both unreachable in a passing suite by design -- this is the panic message for the #2368 pin itself, only formatted if the assert's own condition is false (#2368)
src/jq/eval_generic.rs tolerate 10572 both unreachable: this arm's own match guard already evaluated value.as_array().is_some_and(..) as true to be here at all, and as_array() is a pure read of value -- the second call inside the body can never answer None where the guard's own call just answered Some
src/jq/eval_generic.rs tolerate 12532 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 12549 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 13070 both unreachable: a step from a live node emits only live children (#3023)
src/jq/eval_generic.rs tolerate 13986 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval_generic.rs tolerate 15813 both unreachable: every producer that reaches this empty-exprs tail (each_lazy_keys_iterate_sink's sorted/!sorted arms, each_lazy_index_range_iterate_sink, each_lazy_seq_iterate_sink) yields OneCursorValue/OneCursor/Owned, never a cursorless GenericItem::One -- so cursor is always Some here; kept for exhaustiveness/symmetry with the Some arm (#2103)
src/jq/eval_generic.rs tolerate 17627 both unreachable: each_negate_generic pushes only GenericItem::Owned (arith_negate's result), which converts infallibly (#3410)
src/jq/eval_generic.rs tolerate 18230 both unreachable: is_escape() is exactly `Error
src/jq/eval_generic.rs tolerate 18231 both unreachable: see the if let above -- push_generic_owned_values never answers None for an is_escape() result (#2180)
src/jq/eval_generic.rs tolerate 19330 both unreachable: escape_generic!/ensure_owned! set terminal before Demand::Stop; already returned above (#2138)
src/jq/eval_generic.rs tolerate 19456 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval_generic.rs tolerate 19457 both unreachable in a test: see the line above (#1634)
src/jq/eval_generic.rs tolerate 19463-19466 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval_generic.rs tolerate 19482-19487 both unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval_generic.rs tolerate 20022-20026 both unreachable: this function's sole caller, slice_one_generic_computed, already runs the identical unreadable_value_error(&target) check on the same target and returns before ever calling here; kept as this function's own contract in case a future literal-bounds caller reaches it directly (#3222)
src/jq/eval_generic.rs tolerate 20481 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 20491 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 21242 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 21275 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21323 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21391 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21407 both unreachable: effective_fields_checked already rejects key_is_malformed, the same decoded_key_str Ok(None) that makes key_display_string return None (#3022)
src/jq/eval_generic.rs tolerate 21553 both unreachable: both callers match Field, Index or Iterate before dispatching here (#3022)
src/jq/eval_generic.rs tolerate 23128 both unreachable: len_checked and SliceBounds::resolve already bound every index in range to [0, len), so get_cursor cannot miss (#2168)
src/jq/eval_generic.rs tolerate 26524 both unreachable by construction: path_context_resolvable admits an any(cond) read only through admits.prefetch, so the rewriter always has one -- the AnyCond arm above carries the identical assertion (#3079)
src/jq/eval_generic.rs tolerate 26528 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 26529 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 26900 both unreachable: the callback records downstream_flow before every Demand::Stop, and that flow is returned above (#3022)
src/jq/eval_generic.rs tolerate 27398 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 27419 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 27788 both unreachable: malformed_object_member above already proved every key stringifies (the None half), and to_owned_cursor on an untagged key decoded_key_str decoded cannot fail (the Err half) (#2785)
src/jq/eval_generic.rs tolerate 27869 both unreachable: map(f) over an array emits exactly one array; kept so a future map shape produces no output rather than a panic (#2785)
src/jq/eval_generic.rs tolerate 28207 both unreachable by design -- eval_single's #2368 debug_assert forbids optional=true on Builtin::Reverse, so length never answers None here (#2730)
src/jq/eval_generic.rs tolerate 28606 both unreachable: to_owned_with_cursor of a document number literal cannot fail, so the macro's error arms never run (#3191)
src/jq/eval_generic.rs tolerate 28863 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 28869 both see above: the input-queue deferral never fires from the CLI
src/jq/eval_generic.rs tolerate 30358 both unreachable by construction: every shape either guard admits now has an arm above (#2771), and expr_dispatch_catchall_guards_default_conservatively_2549 pins both guards' _ => false defaults directly
src/jq/eval_generic.rs tolerate 31014 both unreachable in a passing suite by design -- owned_identity_rule maps a bare Expr::Var to Bound too (for the static gate, which sees a body before its as substitution runs), but every runtime dispatch that reaches this rule (owned_identity_after_stage/owned_identity_placed_by, from owned_identity_leaving_cursor's Bound arm) only ever sees a stage after eval_owned_identity_as's unconditional substitute_bound_var_from call, which always turns $x into Expr::TrackedVar before recursing -- confirmed by running the full suite with this arm replaced by a hard panic!(), which never fired (#2072)
src/jq/eval_generic.rs tolerate 31032 both unreachable: this Slice rule's own two execution paths both exclude Expr::Slice before ever reaching owned_identity_placed_by -- eval_owned_identity_stages's catch-all only runs a stage owned_identity_nav_supported refused, and owned_identity_leaving_cursor (identity_from_first, eval_generic.rs:10724) only runs a stage path_context_is_navigational refused -- and both predicates admit Expr::Slice (owned_identity_nav_supported/path_context_is_navigational_at each list Expr::Slice { .. } => true), so a bare slice is always resolved by owned_identity_step's own arm first. Kept in owned_identity_rule's match for exhaustiveness/symmetry with the rule table's other entries, the same reason #2072's Bound arm above is kept unreachable-by-construction (#2966's review of #2834)
src/jq/eval_generic.rs tolerate 31128 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval_generic.rs tolerate 31501 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval_generic.rs tolerate 32561 both unreachable: the arm's or-pattern admits Expr::Limit, Builtin::Skip and Builtin::NthStream only, and each has its own arm above (#3610)
src/jq/eval_generic.rs tolerate 32657 both optional is never true through this pipe: ? is eval_owned_identity_try, which catches the escape instead, and after #693 only the IndexExpr/SliceExpr special case ever sets it -- kept as any_all_f's scalar_fallback mirror
src/jq/eval_generic.rs tolerate 32658 both optional is never true here, see above
src/jq/eval_generic.rs tolerate 33082 both unreachable in a passing suite by design -- the failure message for the assertion the tests below make (#2999)
src/jq/eval_generic.rs tolerate 33329 both unreachable in a passing suite by design -- the fixture's map(.+1) is always a LazySeq; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 33358 both unreachable in a passing suite by design -- the fixture's only escape is Control::Error; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 33663 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval_generic.rs tolerate 38709 both failure message for the assertion this #3222 test exists to make
src/jq/eval_generic.rs tolerate 39759 both unreachable in a passing suite by design -- the failure message for the shape assertion the test makes (#3471)
src/jq/eval_generic.rs tolerate 43759 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 44255 both unreachable in a passing suite: reports a failed test invariant (#3477)
src/jq/eval_generic.rs tolerate 44258 both unreachable in a passing suite: reports a failed test invariant (#3477)
src/jq/eval_generic.rs tolerate 44301 both unreachable in a passing suite: reports a failed test invariant (#3815)
src/jq/eval_generic.rs tolerate 44681 both unreachable in a passing suite by design: a panic message, formatted only if the walk's failure were not a plain Error (#3478)
src/jq/eval_generic.rs tolerate 44685 both no document here answers a plain Error since #3478 (the walk is the consumer's); kept so a future eager walk reports its own message instead of falling to the arm below, which swallows it
src/jq/eval_generic.rs tolerate 46337 both unreachable in a passing suite by design -- the failure arm of a #3722 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 46391 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46395 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46398 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46454 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46534 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46549 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46572 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46593 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46759 both unreachable in a passing suite by design -- the failure arm of a #3702 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 46963 both unreachable in a passing suite by design -- the failure arm of a #3702 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47018 both unreachable in a passing suite by design -- the failure arm of a #3839 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47022 both unreachable in a passing suite by design -- the failure arm of a #3839 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47710 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47732 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47739 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47817 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47868 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47929 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47965 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47974 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 47975 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 47976 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 48938 both unreachable in a passing suite by design -- a panic-message format argument for the #3483 differential test's own assertion, evaluated only if that assert's own condition is false (#3483)
src/jq/lazy.rs tolerate 657 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/lazy.rs tolerate 1474 both failure message for the shape the test asserts
src/jq/parser.rs tolerate 246 both unreachable: parse_join_expr only calls join_expr with two to four arguments (#3046)
src/jq/parser.rs tolerate 268 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 270 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 272 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 279 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 283 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 313 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 317 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 326 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 328 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 330 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 345 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 10224 both unreachable in a passing suite by design -- this is the panic message for the #3044 pin itself, only formatted if the let-else pattern fails to match (#3044)
src/jq/resolve.rs tolerate 921 both unreachable by construction: every plain entry was listed under its name when it was pushed
src/jq/resolve.rs tolerate 924 both unreachable by construction: every plain entry was listed under its arity when it was pushed
src/jq/resolve.rs tolerate 974 both unreachable by construction: FnScope::floor only ever names a begin marker
src/jq/resolve.rs tolerate 2679 both unreachable by construction: this match is only entered when is_marker (marker.is_some()) is true, and RunMarker has only Begin/End variants -- the None arm exists solely for exhaustiveness against Option's type
src/jq/resolve.rs tolerate 2949 both unreachable in practice today: this arm needs builtin_fallback==None (the name was never a shadow candidate) yet is_jq_builtin==true (a real jq builtin at this arity) -- every implemented builtin's own dedicated parse already lowers that shape to Expr::Builtin before resolve.rs ever runs, and #3042/#3046 closed the once-real 'unimplemented builtin' gap this existed for (see JQ_BUILTIN_ROSTER's own doc comment)
src/jq/resolve.rs tolerate 2951 both unreachable with the current roster: every JQ_BUILTIN_ROSTER entry of arity >= 1 already has a dedicated parser form (a matches_keyword special case or a Libm1/Libm2/Libm3::ALL entry -- confirmed by cross-referencing the full roster against both), so it is parsed straight to Expr::Builtin and never reaches here as a bare FuncCall. This arm exists for a roster name with no dedicated parse yet and a nonzero arity -- there is none today, so the loop body is reached with an empty args on every pinned-suite run (355 hits on the arm's own condition, 0 in the loop) and would only start executing if such a name were added (#2964)
src/jq/share_stats.rs tolerate 105 both process-global env var; exercised by the CLI audit run, not by an in-process test (#2999)
src/jq/value.rs tolerate 365 both unreachable by construction: the slow path is entered only after significant_digit_count found 18+ digits over the same mantissa bytes this loop walks (#2936)
src/jq/value.rs tolerate 389 both unreachable by construction: 18+ significant digits were counted, so at least one nonzero digit was kept (#2936)
src/jq/value.rs tolerate 2906 both unreachable by construction -- the block above replaces every Shared with Owned before this line (#3191)
src/jq/value.rs tolerate 3278 both unreachable: format_float_with_fraction of a finite double is always RFC 8259 number text, which parse_i64_or_f64 reads (#2936)
src/jq/value.rs tolerate 5976 both unreachable in a passing suite by design -- built as a string on the line above (#3191)
src/jq/value.rs tolerate 5985 both unreachable in a passing suite by design -- built as a number literal on the line above (#3191)
src/jq/value.rs tolerate 6126 both unreachable in a passing suite by design -- every caller built the value as an array (#2999)
src/jq/value.rs tolerate 6369 both unreachable in a passing suite by design -- the value was built as this container a few lines above (#2999)
src/jq/value.rs tolerate 7191 both unreachable in a passing suite by design -- the failure message for a malformed oracle table (#2936)
src/jq/value.rs tolerate 7580 both failure message for the assertion the calling test makes
src/jq/value.rs tolerate 7912 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 7921 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 7929 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 8070 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 8076 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 8188 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/jq/value.rs tolerate 9304 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/jq/value.rs tolerate 9322 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/jq/value.rs tolerate 9855 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make: the two serializers disagreeing on whether a nest is too deep (#3479)
src/jq/walk.rs tolerate 796 both unreachable: ArrayKey is only built from a resolved key at path-resolution time, never parsed, so no rewrite of parsed source meets it (#3506)
src/json/light.rs tolerate 2809-2815 both unreachable in practice: UNMEASURED_SPAN only arises when end - text_pos in number_at overflows u32 -- a single number span >= 4 GiB -- which no realistic (or practically constructible) test document approaches (#3222)
src/json/light.rs tolerate 3588 both reachable only through a bare 64-bit hash collision between keys the pairwise scan already proved distinct
src/json/light.rs tolerate 9263 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9345 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9434 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9467 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9496 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9584 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/json/light.rs tolerate 9589 both unreachable in a passing suite by design -- see the assert_eq! format argument above, same sweep (#3222)
src/json/light.rs tolerate 9615 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9626 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9707 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9731 both unreachable in a passing suite: every caller passes an object (#3180)
src/json/light.rs tolerate 9737 both unreachable in a passing suite: every caller passes an array (#3180)
src/json/light.rs tolerate 9827 both unreachable in a passing suite by design -- panic-message format argument (#3180)
src/util/simd/x86.rs tolerate 208-258 both CPU-gated: the avx512f early-return only executes on Zen 4+ / Skylake-X runners, and its absence changes which AMD/Intel branch below executes too (#2449)
src/yaml/index.rs tolerate 1296 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1300 both unreachable: every fixture field_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1311 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1313 both unreachable: every call to field_key_head_foot in this test module passes a key that the fixture's mapping actually has (#798)
src/yaml/index.rs tolerate 1323 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1327 both unreachable: every fixture seq_item_head_foot is called with in this test module is a top-level sequence (#798)
src/yaml/index.rs tolerate 1350 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1369 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1392 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1401 both unreachable: every fixture field_key_head_foot_in_doc is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1412 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1414 both unreachable: every call to field_key_head_foot_in_doc in this test module passes a key that the fixture's document actually has (#798)
src/yaml/index.rs tolerate 1425 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1429 both unreachable: every fixture nested_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1433 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this let-else's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1439 both unreachable: every fixture nested_key_head_foot is called with has a nested mapping under outer (#798)
src/yaml/index.rs tolerate 1450 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1453 both unreachable: every call to nested_key_head_foot in this test module passes an outer.inner pair that the fixture actually has (#798)
src/yaml/light.rs tolerate 3372 both unreachable: an alias target is never None for a built index (#1374)
src/yaml/light.rs tolerate 15479 both unreachable in a passing suite by design -- the fixture above is a block sequence (#2640)
src/yaml/light.rs tolerate 15506 both unreachable in a passing suite by design -- the fixture above is a block mapping (#2640)
src/yaml/light.rs tolerate 16243 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 16254 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 16411 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/parser.rs tolerate 1583 both unreachable: every block-sequence open registers a frame at its own depth before any item of it can be parsed (#1079)
src/yaml/parser.rs tolerate 1613 both unreachable: this function's sole caller (record_standalone_comment) only invokes it from inside a match on pending_head_lines.last(), so pending_head_lines is already known non-empty here (#798)
src/yaml/parser.rs tolerate 8013 both unreachable: every byte here already passed the [0-9.eE+-] charset check above, a strict subset of ASCII, so str::from_utf8 can never fail (#2778)

Excluded by ignore-filename-regex: 1 file (none of them touched by this diff).

Patch coverage

Patch: 100% (12/12 new lines covered)

File Patch Uncovered new lines
src/jq/eval.rs 100% (12/12) —

📦 Full per-file coverage summary · run summary

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Coverage

Total: 94.97% ⚪ 0 pp vs main

Comparing 299bde7..1f2222d (merge-base → PR head)

No per-file coverage changes vs main.

🔇 0 ignored region(s), 382 tolerated region(s)

ignore removes the lines from both reports; tolerate keeps them in the reported percentage but scores them against the baseline, so a cross-run flip cannot move a delta. Regions are read from each revision's own source.

File Kind Lines Rev Reason
src/bin/succinctly/jq_runner.rs tolerate 1332 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted, for the identical reason run_jq's own analogous fallback (#2395) is tolerated -- see that line's own comment (#2950)
src/bin/succinctly/jq_runner.rs tolerate 1705 both unreachable while the walk and the loader agree on what fails: both resolve with resolve_module_in/resolve_data_file_in, parse with parse_program and name a cycle by canonical file, which the fuzz in #3573 held over thousands of programs; kept so drift prints the loader's failure and not 0 compile errors
src/bin/succinctly/jq_runner.rs tolerate 2422-2434 both unreachable: try_parse_meta_op only fires under ParserMode::Yq (src/jq/parser.rs), and rewrite_namespaced_calls is only reached via ModuleProcessor::process_program, which jq_runner's own jq-mode run is the sole caller of -- so a MetaAssign node can never reach this function (#798)
src/bin/succinctly/jq_runner.rs tolerate 3022 both unreachable by construction: every error this wrapper receives today is a decode or nesting-depth failure the evaluator raised itself, never error(v); kept so a future one is rendered rather than dropped (#2999)
src/bin/succinctly/jq_runner.rs tolerate 3023 both see the arm above (#2999)
src/bin/succinctly/jq_runner.rs tolerate 3442 both unreachable in practice today: def is only None when occurrences.module_def() is None, which (given origin is Some) would require an open run whose innermost frame has no def set at a check point that isn't itself inside a module-level def body -- but every module run is a strict chain of def nodes (the loader's own defs, each wrapping its dependency stubs INSIDE its own body via wrap_defs/dep_stubs_for) terminated by the run's own end marker, so a diagnosable call/var/break site is always reached either inside a module-level def's body (module_def Some) or outside every run (origin None) -- and even when def is Some, self.defs is always ModuleSource::read's own re-parse of the exact same file run_id_for interned this origin's id from, so collect_def_sites always finds the matching (name, arity, ordinal) span. Kept as a defensive fallback rather than a panic/unwrap in case that invariant is ever violated (#3085)
src/bin/succinctly/jq_runner.rs tolerate 3691-3694 both unreachable in a single-process run by construction: run_id_for (the sole source of an origin id) always inserts a run_origins entry for the id it hands back -- from a real load's canonical path, or its own literal-path fallback on a resolve failure -- and a def body only ever gets stamped with an origin after its module loaded successfully, so at always names a file that existed and was readable moments earlier. Reaching this arm needs that same file to vanish (or become unreadable) in the narrow window between that load and this re-read, entirely outside this process's control (#2964)
src/bin/succinctly/jq_runner.rs tolerate 3960 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted -- a newly covered name only wraps an already-successful dedicated parse, and a failing one would have propagated its error in the first parse too, so the retry budget is charged at the identical sites in both (#2395)
src/bin/succinctly/jq_runner.rs tolerate 4551-4587 both unreachable from any query this suite can build since #3457: the path walkers were the sites that panicked at MAX_NESTING_DEPTH here (sort/join/map, path()/paths/setpath/del()/assignment on a deep document), and they now return a decode-failure-tagged error, so a deep document is reported through the ordinary Err arm instead. The panic sites still in the evaluator (lazy.rs cursor_to_owned, owned_identity_recurse_step, owned_from_standard_json_at_depth, the YAML comment-preserving materialization) are not reached by a jq-mode CLI query at 250-500 levels, probed by hand; the catch is kept as the net for them and for a future guard that panics, and nesting_depth_panic_message itself is pinned by a unit test (#3457)
src/bin/succinctly/jq_runner.rs tolerate 9844 both unreachable: this test builds only ResolveError::Call values (#3313)
src/bin/succinctly/jq_runner.rs tolerate 11853 both unreachable in a passing suite by design -- the fixed b\
src/bin/succinctly/main.rs tolerate 1372 both unreachable given clap 4.6's own unknown_argument() error constructor: every ErrorKind::UnknownArgument it builds sets ContextKind::InvalidArg to ContextValue::String(arg) in the same call, so this arm only guards a future clap release changing that invariant
src/bin/succinctly/main.rs tolerate 1541 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_accepted_via_sjq_multicall_alias_3389's '-x' row demonstrably reaches the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1710 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_boundary_characters_3389's '-x'/'-n1'/'--bogus' rows demonstrably reach the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1732 both the CLI suites drive yq through the syq multi-call arm above; this arm is the same call reached only when spelled succinctly yq (#2999)
src/bin/succinctly/yq_runner.rs tolerate 1650 both unreachable: bytes already parsed successfully by every caller (#1350)
src/bin/succinctly/yq_runner.rs tolerate 1752 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1753 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1754 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 3365 both unreachable: path is always the raw output of the path(TARGET) builtin evaluated a few lines up in resolve_one_meta_assign -- path/1 is a jq/yq language invariant that always answers an array of path components (see Expr::Builtin(Builtin::PathNoArg) => Ok(Some(OwnedValue::Array(..))) in eval_generic.rs), never any other shape (#798)
src/bin/succinctly/yq_runner.rs tolerate 3467 both unreachable: resolve_meta_assign_writes runs expr through this before any evaluation begins (see its own doc comment), and Expr::Shared is never constructed by the parser -- only at eval time, by function-call argument substitution (substitute_func_param in eval.rs) -- so a pre-evaluation AST can never contain one here (#798)
src/bin/succinctly/yq_runner.rs tolerate 4123 both unreachable: every arm of the match result { .. } above that assigns docs (L3492-3622) constructs Ok(..) -- none ever produces Err, so this if let's implicit else can't be taken; symmetric to L1625's ? (#798)
src/bin/succinctly/yq_runner.rs tolerate 6936-6938 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 7127-7132 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 7892-7897 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/jq/document.rs tolerate 406 both unreachable: the only caller, eval_generic::embed_at_or_within, is gated on jq semantics, and the YAML cursor (the one implementor without an override) is only ever evaluated under yq semantics (#3179)
src/jq/document.rs tolerate 1096-1100 both unreachable: both implementors (JsonCursor, YamlCursor) override this; the default exists as the conservative-false contract a future implementor inherits (#3222)
src/jq/document.rs tolerate 1275-1282 both unreachable: both implementors (StandardJson, YamlValue) override this to decode once; the default exists as the contract a future implementor inherits, and is deliberately the two-call sequence it replaces (#965)
src/jq/eval.rs tolerate 1217 both unreachable: def is always a collect_alias_groups anchor path, which step_to_expr never fails on (#1351)
src/jq/eval.rs tolerate 1238 both unreachable: redirect_paths with Redirect::SINGLE always contributes exactly one output per input, so a 1-element paths always pops Some (#1351)
src/jq/eval.rs tolerate 1247 both unreachable: a concrete setpath/delpaths path's components are always Field/Index -- step_to_expr never produces another shape (#1351)
src/jq/eval.rs tolerate 1251 both unreachable: the map above never yields None, since it only ever matches Field/Index (#1351)
src/jq/eval.rs tolerate 1785 both unreachable: key_or_parent_root_construct's identical structural match already refused any expr shape that would reach this arm
src/jq/eval.rs tolerate 2357 both unreachable: same invariant as the tolerated line below (#3069)
src/jq/eval.rs tolerate 2358 both unreachable: same invariant as the tolerated line below (#3069)
src/jq/eval.rs tolerate 2360 both unreachable: a bridge document is its source's serialization, so the node at each recorded position is the recorded kind (#3069)
src/jq/eval.rs tolerate 2361 both unreachable: see the debug_assert above (#3069)
src/jq/eval.rs tolerate 2407 both unreachable: a scalar has no children, and node lies inside the subtree the walk is in (#3069)
src/jq/eval.rs tolerate 4955 both unreachable: is_escape() is exactly `Error
src/jq/eval.rs tolerate 4956 both unreachable: see the if let above -- push_owned_values never answers None for an is_escape() result (#2180)
src/jq/eval.rs tolerate 6218 both unreachable today: to_owned's only failures are is_decode_failure()-tagged, and suppresses() answers false for those whatever optional is -- the same defensive-but-dead arm eval_generic's own Builtin::Path materialization documents under #2280 (#2908)
src/jq/eval.rs tolerate 7097 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 8479 both unreachable: optional is never true here. eval_each is entered with a forced true at exactly one site (Expr::Optional over an IndexExpr/SliceExpr), and both of those evaluate their target (eval_index_expr) and their key (eval_each(key, .., false)) with a hardcoded false, so only the final index/slice step ever sees it -- nothing carries it down to an Expr::Object (#2180)
src/jq/eval.rs tolerate 9688 both unreachable: owned_write_door calls this only on a clone of a head write_target already matched, and the two list the same five variants (#3188)
src/jq/eval.rs tolerate 9702 both unreachable: every value path_over_owned hands back is a path() output, which is always an array (#3188)
src/jq/eval.rs tolerate 9981 both unreachable: any_child_witnessed is false for every non-container, checked just above (#3178)
src/jq/eval.rs tolerate 10173 both unreachable: the if above replaces every other state with Owned before this match
src/jq/eval.rs tolerate 10679 both reachable only on a genuine allocation failure: owned_assign_step's single-step arms map every non-allocation error to unreachable_owned_assign_write (provably impossible, see its own doc comment), and its Chain arm's set_path call walks exactly the steps owned_assign_step_child already validated as Field-into-Object/Null or Index-in-[0,len]-into-Array/Null with no mutation in between, so the only way set_path/set_field/set_index/pad_with_nulls can still fail is the same try_reserve-fails-under-OOM branch the codebase already tolerates elsewhere (#2267) (#3138)
src/jq/eval.rs tolerate 10799 both unreachable: owned_assign_shape's only caller (owned_step_shape) gates the call on is_owned_assign(expr), which recognizes exactly Assign/Update/CompoundAssign/AlternativeAssign -- the same four variants this match already has explicit arms for, so expr can never be anything else here (#3138)
src/jq/eval.rs tolerate 10999 both unreachable: both call sites (try_eval_owned_step, gated on is_owned_assign; eval_owned_reindex_free's own Assign
src/jq/eval.rs tolerate 11073 both unreachable: this function's own doc comment states why -- the borrow on state between owned_assign_step_child's check and the single write makes the container changing shape impossible, so debug_assert!(false, ..) can never fire (#3138)
src/jq/eval.rs tolerate 11074 both unreachable: same invariant as the false above -- this message is only ever formatted if that assert fires (#3138)
src/jq/eval.rs tolerate 11076 both unreachable: this function is only called from owned_assign_step's single-step arms, both of which the invariant above already rules out ever calling it for real (#3138)
src/jq/eval.rs tolerate 11077 both unreachable: the whole function body above is provably dead by the same borrow-checker invariant its doc comment states (#3138)
src/jq/eval.rs tolerate 11114 both unreachable: Expr::pipe() (the parser's sole Pipe constructor) collapses a one-element list to the bare inner expr instead of wrapping it, and substitute_vars's substitute_var walk preserves a Pipe's stage count rather than dropping stages -- no other site builds an Expr::Pipe for a parsed assignment path, so a path's top-level Pipe here is never single-element (#3138)
src/jq/eval.rs tolerate 14295 both unreachable: every entry point supplies path context, so path never evaluates without one; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 14428 both unreachable: only ever constructed by builtin_sort_keys's own eval_update_no_vivify call, whose enclosing eval_update_impl already runs to_owned on the whole document up front (#2855) -- a decode failure anywhere raises there, before this filter ever sees a value to re-decode; confirmed live, sort_keys(.a)/sort_keys(..) on a document with a decode-failure subtree both raise from the outer to_owned
src/jq/eval.rs tolerate 14571-14573 both unreachable: builtin_length's sole caller is eval_builtin's Builtin::Length dispatch, and Length is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before this match ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 14794-14796 both unreachable: has_one_key's sole caller is builtin_has (via eval_builtin's Builtin::Has dispatch), and Has is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before builtin_has ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 18081 both unreachable: entry is one of to_entries's already-materialized {key,value} pairs, so its depth here is provably no deeper than whatever earlier check let it exist -- a document-decoded entry is already <256 deep (MAX_NESTING_DEPTH, stricter than this 384 guard), and a filter-constructed one already survived becoming a cursor via its own whole-object reindex, which is strictly deeper than any single field extracted from it could be (unwrapping only reduces depth); confirmed live, {a: (reduce range(400) as $i (0; [.]))}
src/jq/eval.rs tolerate 25962 both unreachable: escape_with_prefix! sets terminal before Demand::Stop; already returned above (#2138)
src/jq/eval.rs tolerate 26058 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval.rs tolerate 26059 both unreachable in a test: see the line above (#1634)
src/jq/eval.rs tolerate 26065-26068 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval.rs tolerate 26083-26088 both unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval.rs tolerate 28167 both unreachable via --eval-all: every document here comes straight from parse_input, whose own MAX_NESTING_DEPTH (256) guard already rejects anything deep enough to reach MAX_VALUE_TREE_DEPTH (384) here -- confirmed live, a 300-level document fails parse_input's guard before ever reaching this reindex (#3261)
src/jq/eval.rs tolerate 28498 both unreachable: eval_assign returns collect_assign for JqSemantics before this point, and yq_prepare_assign_targets is Some for every YqSemantics call (#3448)
src/jq/eval.rs tolerate 30100 both unreachable: eval_compound_assign/eval_alternative_assign return collect_assign for JqSemantics before this point, and yq_prepare_assign_targets is Some for every YqSemantics call (#3448)
src/jq/eval.rs tolerate 30427-30430 both unreachable: a materialization only ever raises a decode failure, which suppresses never swallows -- debug_assert_materialization_error (#2334) asserts exactly that; kept so the one classification rule is applied here as at every sibling to_owned site (#1953, #3448)
src/jq/eval.rs tolerate 30440-30443 both unreachable: assign_pristine is to_owned, which only ever raises a decode failure (#2334's debug_assert_materialization_error), and suppresses never swallows one; kept so the one classification rule is applied here as at every sibling to_owned site (#1953, #3448)
src/jq/eval.rs tolerate 30578 both unreachable: the eager route runs only when the path resolves to at most one path -- needs_path_prepass false is one verbatim path, and true with resolves_to_at_most_one_path is at most one resolved path (#2976) -- so no path is ever followed by another; kept as the loop's own contract (#3448)
src/jq/eval.rs tolerate 31659 both unreachable: descriptor_path_component builds a Verbatim key only from an object (#3300)
src/jq/eval.rs tolerate 32228 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval.rs tolerate 35573 both unreachable: an anchor is always a proper ancestor, so it records at least one step (#3134)
src/jq/eval.rs tolerate 36853 both reachable only on a genuine allocation failure: Vec::try_reserve(1) on a vector that has spare capacity, or can grow, cannot fail -- this is the whole purpose of the branch, converting an OOM into a catchable error rather than an abort (ADR-0018's 'would take the host process down' exception). The pre-#2267 form of the same guard, out.try_reserve(branches.len()) in resolve_index_expr/resolve_slice_expr, was 0-hit for the identical reason (#2267)
src/jq/eval.rs tolerate 36854 both see the line above -- the Demand::Stop half of the same allocation-failure-only branch (#2267)
src/jq/eval.rs tolerate 36860 both reachable only when the try_reserve above failed, i.e. only on a genuine allocation failure (#2267)
src/jq/eval.rs tolerate 39797 both unreachable: owned_value_jq_length's own match only ever constructs OwnedValue::Int or OwnedValue::Float, checked just above this arm (#2744)
src/jq/eval.rs tolerate 40744 both unreachable: is_primitive admits only Identity/Field/Index/Slice, and of those only a Slice's computed bounds can halt -- all four have their own arm in resolve_node_sink/resolve_node_eager, so none reaches this function. Pre-existing; #2694 only wrapped the return in Some (#2694)
src/jq/eval.rs tolerate 40778 both unreachable, as this arm's own comment above says: indexing or slicing a value yields zero or one result, so is_primitive never produces more than one -- kept as a named error rather than a panic. Pre-existing; #2694 only wrapped the enclosing return in Some (#2694)
src/jq/eval.rs tolerate 41531 both unreachable: a cond that flattens to no stages is . or a pipe of ., which cannot_move_register admits, so it never takes the live route (#3757); the debug_assert where stages is built fails a test build that breaks that
src/jq/eval.rs tolerate 46114 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 47632 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), returned just above (#2872)
src/jq/eval.rs tolerate 48423 both unreachable: every arm of the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 48967 both unreachable: every path through the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 52101 both unreachable in a passing suite by design -- a panic-message format argument for the #682 single-valued-tail pin, evaluated only if that assert's own condition is false (#2190)
src/jq/eval.rs tolerate 52178 both unreachable: the only caller reaches this after classify_static_component answered Field for this same value, which it does only for an object (#2190)
src/jq/eval.rs tolerate 52222 both unreachable: both callers establish the container first -- navigate_static_component_ref via classify_static_component's Index arm, and walk_path's Expr::Iterate arm by matching on the container itself (#2190)
src/jq/eval.rs tolerate 55182 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 56890 both unreachable: stop_with_escape's only write is slot.set(Some(control)) with the control it was handed, which is always the Control::Error built one line above (#2180)
src/jq/eval.rs tolerate 57581 both unreachable: on_update records a step_outcome before every Demand::Stop it answers, and the fallback match runs only when it recorded none (#2872)
src/jq/eval.rs tolerate 57621 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 58360 both unreachable by construction: the per-fork match only ever hands stop_with_downstream a non-Exhausted flow, so terminal can never hold Exhausted (#2899)
src/jq/eval.rs tolerate 60689 both llvm-cov line-attribution artifact, not unreachable: the new gate test above (Builtin::Length as first) demonstrably takes key_or_parent_root_construct(first) == false and falls through to the reindex-bridge route below, passing -- but this closing brace, like the one at #56920 for the same reason, is never itself credited a hit
src/jq/eval.rs tolerate 60703 both unreachable in the current test suite: eval_path_context_pipe_owned itself has zero total call-site coverage today (not just this arm), confirmed by a full-suite eprintln probe across every test binary -- reaching its error arm needs first solving how to reach the function at all, out of scope for #3261's reindex-bridge fix
src/jq/eval.rs tolerate 61777 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 61783 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval.rs tolerate 63903 both pre-existing zero-hit line; #2999 changed only which null constant it names
src/jq/eval.rs tolerate 66319 both ? suppresses mktime's error outside builtin dispatch, so the optional flag is false even for an invalid date (#3083)
src/jq/eval.rs tolerate 66322 both unreachable for mktime's C-int-clamped fields: checked civil-date arithmetic stays within i64; the guard protects other callers of the shared helpers (#3083)
src/jq/eval.rs tolerate 66511 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 66514 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 66559 both optional is never true through either caller of this function -- confirmed live (eprintln! probe): `[1,2,3]
src/jq/eval.rs tolerate 66568 both every array literal written in filter source, and every array-element JSON parses, decodes to NumberLiteral (#1035), not a bare Int -- Int is for internally-synthesized values spliced post-parse; probed a computed element ([1970,(0+0),..]) and it still decoded as NumberLiteral here, so this arm has no known real producer (#3068)
src/jq/eval.rs tolerate 66604 both optional is never true through either caller of this function, same as the array-length check above (#3068)
src/jq/eval.rs tolerate 66668 both unreachable for strftime's C-int-clamped fields and bounded zone offset; shared checked date helpers retain overflow guards for other callers (#3083)
src/jq/eval.rs tolerate 66824 both llvm-cov line-attribution artifact, not unreachable: the call's own argument lines (immediately above) show 3 hits under the #3055 test's three E/O pass-through rows, but this closing-token line is never itself credited -- verified via the raw lcov DA: records
src/jq/eval.rs tolerate 68014 both unreachable: YamlIndex::root always wraps the documents in a virtual root sequence, so the arm above takes every input (#2664)
src/jq/eval.rs tolerate 68015 both unreachable: the same defensive arm as the line above (#2664)
src/jq/eval.rs tolerate 68327 both unreachable from combinations, whose own empty-input return runs first; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 69431 both confirmed live (eprintln! probe): optional is always false in builtin_abs regardless of whether the filter writes abs?, since that suppression happens entirely outside builtin dispatch here -- the same 'optional is never true here' shape eval.rs already documents elsewhere (#2180) (#3041)
src/jq/eval.rs tolerate 71489 both unreachable: the sink is a plain collector that always answers Demand::Continue (#2872)
src/jq/eval.rs tolerate 71599 both unreachable: optional: false makes index_one_owned answer Ok(Some)/Err only (#2872)
src/jq/eval.rs tolerate 71904 both unreachable: pattern_has_computed_key is false for Pattern::Var, so the loop walker above always takes it (#2872)
src/jq/eval.rs tolerate 71952 both unreachable: every caller gates on pattern_has_computed_key being false (#2872)
src/jq/eval.rs tolerate 73648 both unreachable: bind_def_call only calls this for a non-empty params, install_def_calls only builds a DefCall whose args.len() equals params.len(), and the last parameter is never shadowed, so at least one entry is always built (#2560)
src/jq/eval.rs tolerate 75062 both unreachable in a passing suite by design -- this panic only fires if eval_owned_reindex_free declined a shape this loop's own handled table asserts is always answered (#3138)
src/jq/eval.rs tolerate 75071 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a shape this loop's own handled table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 75110 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step handled a shape this loop's own declined table asserts is always declined (#3138)
src/jq/eval.rs tolerate 75131 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a yq shape this loop's own table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 75231 both unreachable in a passing suite by design -- this panic only fires if the tracked \
src/jq/eval.rs tolerate 75233 both unreachable in a passing suite by design -- this panic only fires if state stopped being an Object, which every owned_assign_step write in the loop below preserves (#3138)
src/jq/eval.rs tolerate 75241 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on the single-step shape this loop drives every iteration (#3138)
src/jq/eval.rs tolerate 75246 both unreachable in a passing suite by design -- this arm only fires if state stopped being an Object, which every write in the loop above preserves (#3138)
src/jq/eval.rs tolerate 75284 both unreachable in a passing suite by design -- this panic only fires if the tracked \
src/jq/eval.rs tolerate 75286 both unreachable in a passing suite by design -- this panic only fires if state stopped being an Object, which every owned_assign_step write in the loop below preserves (#3241)
src/jq/eval.rs tolerate 75304 both unreachable in a passing suite by design -- this arm only fires if state stopped being an Object, which every write in the loop above preserves (#3241)
src/jq/eval.rs tolerate 75381 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on the single closed assignment this test drives (#3241)
src/jq/eval.rs tolerate 75396 both unreachable in a passing suite by design -- both values are built as objects above and an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 75441 both unreachable in a passing suite by design -- doc builds an object (#3241)
src/jq/eval.rs tolerate 75449 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on the single closed assignment this test drives (#3241)
src/jq/eval.rs tolerate 75457 both unreachable in a passing suite by design -- an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 75490 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on a closed assignment this table asserts is always answered (#3241)
src/jq/eval.rs tolerate 75493 both unreachable in a passing suite by design -- an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 75537 both unreachable in a passing suite by design -- this panic only fires if fold_step_each reported anything but an escape (not optional) or exhaustion (optional) for a failing owned step (#3241)
src/jq/eval.rs tolerate 75580 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step answered an UPDATE holding an Expr::TrackedVar, which closed_expr_to_owned rejects (#3241)
src/jq/eval.rs tolerate 75608 both unreachable in a passing suite: every row below is a reduce or a foreach (#3329)
src/jq/eval.rs tolerate 75937 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 75959 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 75977 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 76047 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 76065 both substitute_func_param_impl's FuncDef arm always returns FuncDef (#2555)
src/jq/eval.rs tolerate 84100 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval.rs tolerate 84259 both unreachable in a passing suite by design -- this is the failure message for the assertion the test exists to make (#2190)
src/jq/eval.rs tolerate 84639 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval.rs tolerate 85298 both unreachable in a passing suite: reports a failed test invariant (#3682)
src/jq/eval.rs tolerate 85513 both the no-std arm: `cfg!(feature = \
src/jq/eval.rs tolerate 86344 both unreachable in a passing suite: every source this helper parses starts with def f(n): ...; (#3296)
src/jq/eval.rs tolerate 86397 both unreachable in a passing suite: f(1) under def f(n) always installs as a DefCall, which the assert above has just settled (#3296)
src/jq/eval.rs tolerate 97869 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 97921 both unreachable in a passing suite by design -- this test's own diagnostic (#3102)
src/jq/eval.rs tolerate 98835-98846 both the closure is asserted never called below (on_update_calls stays 0) -- Err(_) with optional=true short-circuits fold_step_each before this sink runs (#3122)
src/jq/eval.rs tolerate 103625 both unreachable in a passing suite by design -- the door's sink never stops and it never breaks or halts (#3439)
src/jq/eval.rs tolerate 104210 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 109220 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 109231 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 109248 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 109268 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 109276 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 110427 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 112363 both unreachable in a passing suite by design -- check_value_tree_depth's only Err variant is EvalError, and From for EvalEscape always produces EvalEscape::Error (#3275)
src/jq/eval.rs tolerate 112968 both unreachable in a passing suite by design -- the failure message for the shape assertion the test makes (#3471)
src/jq/eval.rs tolerate 116282 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116324 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116329 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116364 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116385 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116488 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 116504 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 119981 both unreachable in a passing suite by design -- every filter this helper is called with parses to an AsPattern (#2649)
src/jq/eval.rs tolerate 120025 both unreachable in a passing suite by design -- a literal-key pattern's walk either completes or refuses with an error (#2872)
src/jq/eval.rs tolerate 120034 both unreachable in a passing suite by design -- every call site passes the origin of a binding this same test already proved carries a marker (#2649)
src/jq/eval.rs tolerate 120362 both unreachable in a passing suite by design -- the assertion above is the test (#2872)
src/jq/eval.rs tolerate 121062 both unreachable in a passing suite by design -- every row here is a shape jq accepts, confirmed live (#2649)
src/jq/eval.rs tolerate 121130 both unreachable in a passing suite by design -- every row here is a shape jq refuses, confirmed live (#2649)
src/jq/eval.rs tolerate 121515 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 121531 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 121565 both unreachable in a passing suite by design -- this is the panic message for the #3069 pin itself, only formatted if the let-else pattern fails to match
src/jq/eval.rs tolerate 121582 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 121598 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 121612 both unreachable in a passing suite by design -- this is the panic message for the #3069 pin itself, only formatted if the match doesn't hit the expected arm above
src/jq/eval.rs tolerate 121698 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3037)
src/jq/eval.rs tolerate 121776 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3037)
src/jq/eval.rs tolerate 122552 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3135)
src/jq/eval.rs tolerate 122659 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3122)
src/jq/eval.rs tolerate 122677 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3122)
src/jq/eval.rs tolerate 122745 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 122749 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 122789 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 122793 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 124538 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3119)
src/jq/eval.rs tolerate 124593 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3127)
src/jq/eval.rs tolerate 127287 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#2937)
src/jq/eval.rs tolerate 127374 both unreachable in a passing suite by design -- every READERS filter raises a decode failure on every malformed json in this sweep, so this fallback never fires (#3222)
src/jq/eval.rs tolerate 127380 both unreachable in a passing suite by design -- see the concrete match above, same sweep (#3222)
src/jq/eval.rs tolerate 127386-127388 both unreachable in a passing suite by design -- this is the failure-recording line for the assertion below, only reached if a READERS filter fails to raise (#3222)
src/jq/eval.rs tolerate 127444 both unreachable in a passing suite by design -- none of NON_READERS ever raises through eval_with_cursor_using, on the malformed document or the well-formed one; kept so a filter that starts erroring is still comparable rather than panicking (#3222)
src/jq/eval.rs tolerate 127747 both unreachable in a passing suite by design -- every filter below builds an array (#3191)
src/jq/eval.rs tolerate 127754 both unreachable in a passing suite by design -- each element is built as {k: } (#3191)
src/jq/eval.rs tolerate 127756 both unreachable in a passing suite by design -- each element is built as {k: } (#3191)
src/jq/eval.rs tolerate 127858 both every pinned filter below yields an owned value; kept so a cursor answer still renders rather than panics (#2999)
src/jq/eval.rs tolerate 127859 both unreachable in a passing suite by design -- the failure message for the assertions this helper serves (#2999)
src/jq/eval.rs tolerate 128193 both unreachable in a passing suite: every corpus program starts with a def (#3307)
src/jq/eval.rs tolerate 128318 both unreachable in a passing suite: every corpus program's first node is a def (#3307)
src/jq/eval.rs tolerate 128355 both unreachable in a passing suite: the last def's call is bound (#3307)
src/jq/eval.rs tolerate 128517 both unreachable in a passing suite: every caller passes a def head (#3307)
src/jq/eval.rs tolerate 128593 both unreachable in a passing suite: chain builds a def head (#3307)
src/jq/eval.rs tolerate 128597 both unreachable in a passing suite: a 50-def chain has a second def (#3307)
src/jq/eval.rs tolerate 128693 both unreachable in a passing suite: spine_node builds a def head (#3307)
src/jq/eval.rs tolerate 128754 both unreachable in a passing suite: the loop above builds a def (#3307)
src/jq/eval.rs tolerate 128762 both unreachable in a passing suite: the main filter is a pipe (#3307)
src/jq/eval.rs tolerate 128766 both unreachable in a passing suite: stages 0 and 2 are the spliced arguments (#3307)
src/jq/eval_generic.rs tolerate 1186 both unreachable: validate_cursor, CheckOnly's only instantiation, passes no nested nodes, so the walk never asks (#3179)
src/jq/eval_generic.rs tolerate 5152 both unreachable: the sole remaining caller (retain_truthy_generic's Many arm) runs to_owned on an item before keeping it, so re-converting a kept item here cannot fail; the ManyCursor caller that made this reachable went with the truthiness walk (#2692, re-establishing #2661's premise)
src/jq/eval_generic.rs tolerate 7082 both unreachable: hi is find_close of a container's own open paren, which a built index always matches (#3179)
src/jq/eval_generic.rs tolerate 7960 both unreachable for the one format that claims materializes_members_one_to_one: a JSON object's children always pair key-then-value; kept so an implementor whose mapping could end on a key declines instead of miscounting (#3483)
src/jq/eval_generic.rs tolerate 7977 both unreachable for JSON: a key node always decodes or falls back to its raw spelling, so key_display_string is Some; kept so a format whose key can be non-string declines to the generic walk (#3483)
src/jq/eval_generic.rs tolerate 10511 both unreachable in a passing suite by design -- this is the panic message for the #2368 pin itself, only formatted if the assert's own condition is false (#2368)
src/jq/eval_generic.rs tolerate 10572 both unreachable: this arm's own match guard already evaluated value.as_array().is_some_and(..) as true to be here at all, and as_array() is a pure read of value -- the second call inside the body can never answer None where the guard's own call just answered Some
src/jq/eval_generic.rs tolerate 12532 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 12549 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 13070 both unreachable: a step from a live node emits only live children (#3023)
src/jq/eval_generic.rs tolerate 13986 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval_generic.rs tolerate 15813 both unreachable: every producer that reaches this empty-exprs tail (each_lazy_keys_iterate_sink's sorted/!sorted arms, each_lazy_index_range_iterate_sink, each_lazy_seq_iterate_sink) yields OneCursorValue/OneCursor/Owned, never a cursorless GenericItem::One -- so cursor is always Some here; kept for exhaustiveness/symmetry with the Some arm (#2103)
src/jq/eval_generic.rs tolerate 17627 both unreachable: each_negate_generic pushes only GenericItem::Owned (arith_negate's result), which converts infallibly (#3410)
src/jq/eval_generic.rs tolerate 18230 both unreachable: is_escape() is exactly `Error
src/jq/eval_generic.rs tolerate 18231 both unreachable: see the if let above -- push_generic_owned_values never answers None for an is_escape() result (#2180)
src/jq/eval_generic.rs tolerate 19330 both unreachable: escape_generic!/ensure_owned! set terminal before Demand::Stop; already returned above (#2138)
src/jq/eval_generic.rs tolerate 19456 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval_generic.rs tolerate 19457 both unreachable in a test: see the line above (#1634)
src/jq/eval_generic.rs tolerate 19463-19466 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval_generic.rs tolerate 19482-19487 both unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval_generic.rs tolerate 20022-20026 both unreachable: this function's sole caller, slice_one_generic_computed, already runs the identical unreadable_value_error(&target) check on the same target and returns before ever calling here; kept as this function's own contract in case a future literal-bounds caller reaches it directly (#3222)
src/jq/eval_generic.rs tolerate 20481 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 20491 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 21242 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 21275 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21323 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21391 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21407 both unreachable: effective_fields_checked already rejects key_is_malformed, the same decoded_key_str Ok(None) that makes key_display_string return None (#3022)
src/jq/eval_generic.rs tolerate 21553 both unreachable: both callers match Field, Index or Iterate before dispatching here (#3022)
src/jq/eval_generic.rs tolerate 23128 both unreachable: len_checked and SliceBounds::resolve already bound every index in range to [0, len), so get_cursor cannot miss (#2168)
src/jq/eval_generic.rs tolerate 26524 both unreachable by construction: path_context_resolvable admits an any(cond) read only through admits.prefetch, so the rewriter always has one -- the AnyCond arm above carries the identical assertion (#3079)
src/jq/eval_generic.rs tolerate 26528 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 26529 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 26900 both unreachable: the callback records downstream_flow before every Demand::Stop, and that flow is returned above (#3022)
src/jq/eval_generic.rs tolerate 27398 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 27419 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 27788 both unreachable: malformed_object_member above already proved every key stringifies (the None half), and to_owned_cursor on an untagged key decoded_key_str decoded cannot fail (the Err half) (#2785)
src/jq/eval_generic.rs tolerate 27869 both unreachable: map(f) over an array emits exactly one array; kept so a future map shape produces no output rather than a panic (#2785)
src/jq/eval_generic.rs tolerate 28207 both unreachable by design -- eval_single's #2368 debug_assert forbids optional=true on Builtin::Reverse, so length never answers None here (#2730)
src/jq/eval_generic.rs tolerate 28606 both unreachable: to_owned_with_cursor of a document number literal cannot fail, so the macro's error arms never run (#3191)
src/jq/eval_generic.rs tolerate 28863 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 28869 both see above: the input-queue deferral never fires from the CLI
src/jq/eval_generic.rs tolerate 30358 both unreachable by construction: every shape either guard admits now has an arm above (#2771), and expr_dispatch_catchall_guards_default_conservatively_2549 pins both guards' _ => false defaults directly
src/jq/eval_generic.rs tolerate 31014 both unreachable in a passing suite by design -- owned_identity_rule maps a bare Expr::Var to Bound too (for the static gate, which sees a body before its as substitution runs), but every runtime dispatch that reaches this rule (owned_identity_after_stage/owned_identity_placed_by, from owned_identity_leaving_cursor's Bound arm) only ever sees a stage after eval_owned_identity_as's unconditional substitute_bound_var_from call, which always turns $x into Expr::TrackedVar before recursing -- confirmed by running the full suite with this arm replaced by a hard panic!(), which never fired (#2072)
src/jq/eval_generic.rs tolerate 31032 both unreachable: this Slice rule's own two execution paths both exclude Expr::Slice before ever reaching owned_identity_placed_by -- eval_owned_identity_stages's catch-all only runs a stage owned_identity_nav_supported refused, and owned_identity_leaving_cursor (identity_from_first, eval_generic.rs:10724) only runs a stage path_context_is_navigational refused -- and both predicates admit Expr::Slice (owned_identity_nav_supported/path_context_is_navigational_at each list Expr::Slice { .. } => true), so a bare slice is always resolved by owned_identity_step's own arm first. Kept in owned_identity_rule's match for exhaustiveness/symmetry with the rule table's other entries, the same reason #2072's Bound arm above is kept unreachable-by-construction (#2966's review of #2834)
src/jq/eval_generic.rs tolerate 31128 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval_generic.rs tolerate 31501 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval_generic.rs tolerate 32561 both unreachable: the arm's or-pattern admits Expr::Limit, Builtin::Skip and Builtin::NthStream only, and each has its own arm above (#3610)
src/jq/eval_generic.rs tolerate 32657 both optional is never true through this pipe: ? is eval_owned_identity_try, which catches the escape instead, and after #693 only the IndexExpr/SliceExpr special case ever sets it -- kept as any_all_f's scalar_fallback mirror
src/jq/eval_generic.rs tolerate 32658 both optional is never true here, see above
src/jq/eval_generic.rs tolerate 33082 both unreachable in a passing suite by design -- the failure message for the assertion the tests below make (#2999)
src/jq/eval_generic.rs tolerate 33329 both unreachable in a passing suite by design -- the fixture's map(.+1) is always a LazySeq; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 33358 both unreachable in a passing suite by design -- the fixture's only escape is Control::Error; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 33663 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval_generic.rs tolerate 38709 both failure message for the assertion this #3222 test exists to make
src/jq/eval_generic.rs tolerate 39759 both unreachable in a passing suite by design -- the failure message for the shape assertion the test makes (#3471)
src/jq/eval_generic.rs tolerate 43759 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 44255 both unreachable in a passing suite: reports a failed test invariant (#3477)
src/jq/eval_generic.rs tolerate 44258 both unreachable in a passing suite: reports a failed test invariant (#3477)
src/jq/eval_generic.rs tolerate 44301 both unreachable in a passing suite: reports a failed test invariant (#3815)
src/jq/eval_generic.rs tolerate 44681 both unreachable in a passing suite by design: a panic message, formatted only if the walk's failure were not a plain Error (#3478)
src/jq/eval_generic.rs tolerate 44685 both no document here answers a plain Error since #3478 (the walk is the consumer's); kept so a future eager walk reports its own message instead of falling to the arm below, which swallows it
src/jq/eval_generic.rs tolerate 46337 both unreachable in a passing suite by design -- the failure arm of a #3722 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 46391 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46395 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46398 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46454 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46534 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46549 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46572 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46593 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 46759 both unreachable in a passing suite by design -- the failure arm of a #3702 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 46963 both unreachable in a passing suite by design -- the failure arm of a #3702 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47018 both unreachable in a passing suite by design -- the failure arm of a #3839 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47022 both unreachable in a passing suite by design -- the failure arm of a #3839 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47710 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47732 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47739 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47817 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47868 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47929 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47965 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47974 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 47975 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 47976 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 48938 both unreachable in a passing suite by design -- a panic-message format argument for the #3483 differential test's own assertion, evaluated only if that assert's own condition is false (#3483)
src/jq/lazy.rs tolerate 657 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/lazy.rs tolerate 1474 both failure message for the shape the test asserts
src/jq/parser.rs tolerate 246 both unreachable: parse_join_expr only calls join_expr with two to four arguments (#3046)
src/jq/parser.rs tolerate 268 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 270 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 272 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 279 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 283 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 313 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 317 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 326 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 328 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 330 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 345 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 10224 both unreachable in a passing suite by design -- this is the panic message for the #3044 pin itself, only formatted if the let-else pattern fails to match (#3044)
src/jq/resolve.rs tolerate 921 both unreachable by construction: every plain entry was listed under its name when it was pushed
src/jq/resolve.rs tolerate 924 both unreachable by construction: every plain entry was listed under its arity when it was pushed
src/jq/resolve.rs tolerate 974 both unreachable by construction: FnScope::floor only ever names a begin marker
src/jq/resolve.rs tolerate 2679 both unreachable by construction: this match is only entered when is_marker (marker.is_some()) is true, and RunMarker has only Begin/End variants -- the None arm exists solely for exhaustiveness against Option's type
src/jq/resolve.rs tolerate 2949 both unreachable in practice today: this arm needs builtin_fallback==None (the name was never a shadow candidate) yet is_jq_builtin==true (a real jq builtin at this arity) -- every implemented builtin's own dedicated parse already lowers that shape to Expr::Builtin before resolve.rs ever runs, and #3042/#3046 closed the once-real 'unimplemented builtin' gap this existed for (see JQ_BUILTIN_ROSTER's own doc comment)
src/jq/resolve.rs tolerate 2951 both unreachable with the current roster: every JQ_BUILTIN_ROSTER entry of arity >= 1 already has a dedicated parser form (a matches_keyword special case or a Libm1/Libm2/Libm3::ALL entry -- confirmed by cross-referencing the full roster against both), so it is parsed straight to Expr::Builtin and never reaches here as a bare FuncCall. This arm exists for a roster name with no dedicated parse yet and a nonzero arity -- there is none today, so the loop body is reached with an empty args on every pinned-suite run (355 hits on the arm's own condition, 0 in the loop) and would only start executing if such a name were added (#2964)
src/jq/share_stats.rs tolerate 105 both process-global env var; exercised by the CLI audit run, not by an in-process test (#2999)
src/jq/value.rs tolerate 365 both unreachable by construction: the slow path is entered only after significant_digit_count found 18+ digits over the same mantissa bytes this loop walks (#2936)
src/jq/value.rs tolerate 389 both unreachable by construction: 18+ significant digits were counted, so at least one nonzero digit was kept (#2936)
src/jq/value.rs tolerate 2906 both unreachable by construction -- the block above replaces every Shared with Owned before this line (#3191)
src/jq/value.rs tolerate 3278 both unreachable: format_float_with_fraction of a finite double is always RFC 8259 number text, which parse_i64_or_f64 reads (#2936)
src/jq/value.rs tolerate 5976 both unreachable in a passing suite by design -- built as a string on the line above (#3191)
src/jq/value.rs tolerate 5985 both unreachable in a passing suite by design -- built as a number literal on the line above (#3191)
src/jq/value.rs tolerate 6126 both unreachable in a passing suite by design -- every caller built the value as an array (#2999)
src/jq/value.rs tolerate 6369 both unreachable in a passing suite by design -- the value was built as this container a few lines above (#2999)
src/jq/value.rs tolerate 7191 both unreachable in a passing suite by design -- the failure message for a malformed oracle table (#2936)
src/jq/value.rs tolerate 7580 both failure message for the assertion the calling test makes
src/jq/value.rs tolerate 7912 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 7921 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 7929 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 8070 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 8076 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 8188 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/jq/value.rs tolerate 9304 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/jq/value.rs tolerate 9322 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/jq/value.rs tolerate 9855 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make: the two serializers disagreeing on whether a nest is too deep (#3479)
src/jq/walk.rs tolerate 796 both unreachable: ArrayKey is only built from a resolved key at path-resolution time, never parsed, so no rewrite of parsed source meets it (#3506)
src/json/light.rs tolerate 2809-2815 both unreachable in practice: UNMEASURED_SPAN only arises when end - text_pos in number_at overflows u32 -- a single number span >= 4 GiB -- which no realistic (or practically constructible) test document approaches (#3222)
src/json/light.rs tolerate 3588 both reachable only through a bare 64-bit hash collision between keys the pairwise scan already proved distinct
src/json/light.rs tolerate 9263 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9345 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9434 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9467 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9496 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9584 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/json/light.rs tolerate 9589 both unreachable in a passing suite by design -- see the assert_eq! format argument above, same sweep (#3222)
src/json/light.rs tolerate 9615 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9626 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9707 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9731 both unreachable in a passing suite: every caller passes an object (#3180)
src/json/light.rs tolerate 9737 both unreachable in a passing suite: every caller passes an array (#3180)
src/json/light.rs tolerate 9827 both unreachable in a passing suite by design -- panic-message format argument (#3180)
src/yaml/index.rs tolerate 1296 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1300 both unreachable: every fixture field_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1311 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1313 both unreachable: every call to field_key_head_foot in this test module passes a key that the fixture's mapping actually has (#798)
src/yaml/index.rs tolerate 1323 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1327 both unreachable: every fixture seq_item_head_foot is called with in this test module is a top-level sequence (#798)
src/yaml/index.rs tolerate 1350 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1369 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1392 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1401 both unreachable: every fixture field_key_head_foot_in_doc is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1412 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1414 both unreachable: every call to field_key_head_foot_in_doc in this test module passes a key that the fixture's document actually has (#798)
src/yaml/index.rs tolerate 1425 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1429 both unreachable: every fixture nested_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1433 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this let-else's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1439 both unreachable: every fixture nested_key_head_foot is called with has a nested mapping under outer (#798)
src/yaml/index.rs tolerate 1450 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1453 both unreachable: every call to nested_key_head_foot in this test module passes an outer.inner pair that the fixture actually has (#798)
src/yaml/light.rs tolerate 3372 both unreachable: an alias target is never None for a built index (#1374)
src/yaml/light.rs tolerate 15479 both unreachable in a passing suite by design -- the fixture above is a block sequence (#2640)
src/yaml/light.rs tolerate 15506 both unreachable in a passing suite by design -- the fixture above is a block mapping (#2640)
src/yaml/light.rs tolerate 16243 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 16254 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 16411 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/parser.rs tolerate 1583 both unreachable: every block-sequence open registers a frame at its own depth before any item of it can be parsed (#1079)
src/yaml/parser.rs tolerate 1613 both unreachable: this function's sole caller (record_standalone_comment) only invokes it from inside a match on pending_head_lines.last(), so pending_head_lines is already known non-empty here (#798)
src/yaml/parser.rs tolerate 8013 both unreachable: every byte here already passed the [0-9.eE+-] charset check above, a strict subset of ASCII, so str::from_utf8 can never fail (#2778)

Excluded by ignore-filename-regex: 1 file (none of them touched by this diff).

Patch coverage

Patch: 100% (12/12 new lines covered)

File Patch Uncovered new lines
src/jq/eval.rs 100% (12/12) —

📦 Full per-file coverage summary · run summary

@newhoggy

newhoggy commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Sweep result: scripts/jq-path-register-sweep.py, seeded 150,027-row sample (seed 3859) vs a main build: 0 regressions, 0 other flips (both builds 147,215 MATCH / 45 ACCEPT_WRONG / 2,745 REFUSE_WRONG / 22 DIFF, identical). That grid does not generate a destructuring ?// bind with a by-value body, so it is silence, not evidence for this change; the evidence is the targeted oracle A/B (49,590 rows, 678 improved, 0 regressed) and the destructure-weighted bind-origin fuzz (5,994 agree, 0 fabricate, 0 mismatch) in the PR description.

… a retry after a failed write resumes from null (#3859)

A by-value true/false/null body after a destructuring ?// bind whose first
alternative failed to destructure refused where jq answers a valid path:
path(.x | (. as [$q] ?// $z | true)) on {"x":true} is ["x"]. The failed
destructure is restored by the fork, so the bare-$var alternative that runs
leaves the register at the stage's entry and states Unmoved, but the pipe
stage discarded it because cannot_move_register is false for any
destructuring pattern (a successful one moves it).

stage_states_register_per_result now admits a destructuring AsPattern whose
body cannot move the register. A successful destructure navigated and is read
as before; only a result that navigated nothing is trusted.

That widening exposed a write bug that was already there: after a write
raises, jq's reduce state is the null its DUPN hands back, so a ?// retry
writes the retried alternative's paths onto null. stream_path_writes kept the
earlier paths' document instead, so (.x | .. | (. as [$q] ?// $z | $z)) = 9
on {"x":[null],"k":3} kept k where jq's result is {"x":[9]}.

Gated against /usr/bin/jq 1.7.1 and a main build: 49,590 generated rows, 678
improved, 0 regressed, 0 accept-wrong.
@newhoggy
newhoggy force-pushed the issue-3859-jq-a-bind-with-a-failed-first-alternative-and branch from 36efd58 to 1f2222d Compare October 6, 2026 19:15
@newhoggy
newhoggy added this pull request to the merge queue Oct 6, 2026
Merged via the queue into main with commit 3be2e2e Oct 6, 2026
48 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

jq: a ?// bind with a failed first alternative and a by-value true/false body refuses a register-identical path (#3858 split)

1 participant