Skip to content

fix(jq): indices/index/rindex on null or an object look the key up (#3890) - #3952

Merged
newhoggy merged 5 commits into
mainfrom
issue-3890-jq-path-indices-index-rindex-tracked-input
Oct 7, 2026
Merged

newhoggy merged 5 commits into
mainfrom
issue-3890-jq-path-indices-index-rindex-tracked-input

Conversation

@newhoggy

@newhoggy newhoggy commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Part of #3890 (does not close it; see "Still open").

Summary

jq defines indices($i) as .[$i] for every input but an array and a string, and index/rindex as that followed by .[0] / .[-1:][0]. unsearchable_input answered null for any key on null or an object, on the strength of a comment calling it _strindices's answer. That held for the null and {} it was probed with and nothing else:

input / filter jq 1.7.1 before after
null | indices(true) Cannot index null with boolean null same as jq
{"a":1} | indices("a") 1 null same as jq
{"a":[5,6]} | rindex("a") 6 null same as jq
{"a":1} | index("a") Cannot index number with number null same as jq

In path() the wrong null was the root's own, so [path(indices(true))] on null answered [[]] and del, = and |= ran through it. Those are the 210 ACCEPT_WRONG rows #3890's comments cite for the indices/index/rindex operands. They are 0 now.

unsearchable_input is now index_one (jq's .[$i], lazy), followed for index/rindex by jq's own tail through the evaluator. Under --jq-extensions the YAML route follows jq too (verified: a: [5, 6] gives index("a") = 5, was null).

Still open (why this is a part, not the close)

Tracked array input (path(.a | indices(1)) is ["a",[1]]), a tracked object key (["a","x"]) and a tracked string's index/rindex still refuse, in the safe direction. They need the register-moving .[$i] step (the first/last arm's shape plus its classification predicates), a larger change that wants its own sweep. #3890 stays open for it.

Sweep (scripts/jq-path-register-sweep.py, base vs candidate, the 8 operands, 106,587 rows)

build MATCH ACCEPT_WRONG REFUSE_WRONG DIFF
base 104,645 210 1,712 20
candidate 105,297 0 1,280 10

The script reports FAIL: 14 regression(s). All 14 are one shape and are disclosed in docs/compliance/jq/limitations.md: index("a")/rindex("a") on {"a":[true]} was the wrong null, so del((index("a") and (.a)?) // .a) (and the .a? as $y | try (index("a") and .a) | ... shape) short-circuited and and landed on jq's answer by another road. With jq's own true the right operand runs against a register the resolver does not yet move for index, so it refuses (exit 5, nothing written). The same programs spelled .a[0] still match in base and candidate (checked directly). These close with the tracked-navigation step above.

This is user-visible, so the changelog check is not waived: changelog.d/3890.fixed.md is included.

Test plan

  • By-value oracle matrix (3 builtins x 15 patterns x 14 inputs = 630 rows) against /usr/bin/jq: 0 differences after, the null/object rows differed before.
  • test_indices_family_looks_up_a_null_or_object_input_3890: 36 rows captured live from jq 1.7.1 (values, errors, ? forms, path/del/assign).
  • test_string_search_unsearchable_inputs extended and its wrong rationale corrected.
  • cargo test --features cli,simd,regex,serde --no-fail-fast: 69 binaries, 10,226 passed, 0 failed.
  • cargo clippy --all-targets --all-features -D warnings; cargo clippy --all-targets --features std,simd,serde,cli,regex,bench-runner,large-tests,mmap-tests -D warnings; cargo check --no-default-features; RUSTDOCFLAGS=-D warnings cargo doc; cargo fmt --check.
  • python3 scripts/changelog.py check.
  • CI, review, coverage (below).

@newhoggy

newhoggy commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Review pass on 53abf42 (fresh-context code-review), triaged. Each claim was reproduced before acting.

Fixed in 945ac79

  • yq mode (--jq-extensions) followed yq's lenient indexing (confirmed): a: [1, 2] | indices(1) printed null (jq, and the base commit: Cannot index object with number), and a: 1 | index("a") printed nothing. indices is jq surface even where yq reaches it, so the lookup and its tail now run with JqSemantics. New test_indices_family_looks_up_in_yq_extensions_3890; mutating the lookup back to YqSemantics fails it.
  • Ok(_) => QueryResult::None swallowed a non-single result (confirmed, it was the cause of the empty yq output above): the tail now goes through eval_single and an owned result keeps every output.
  • Container materialised just to take one element: the tail runs lazily on the looked-up document value.
  • Pin for the accepted lost matches: test_index_on_a_tracked_object_register_residual_3890 pins the shape (exit 5 here, {} in jq) beside its .a[0] contrast row, which matches.
  • Object/array patterns on null/objects and yq mode untested: rows added (jq 1.7.1 captures).

Not a regression (verified against the base binary)
The finding that del(indices("a")), index("a") = 5, [path(indices("a"))] and path(first(indices("a"),.b)) now "hard-fail" is a pre-existing refusal: base refused all four too (Invalid path expression with result null), and they are #3890's open part (the tracked .[$i] step), which this PR deliberately leaves open. path(index("a") // .b) is the opposite: base answered ["b"], jq raises Cannot index number with number, and this PR now matches jq.

Re-verified after the rewrite: by-value matrix vs jq 1.7.1, 630 rows, 0 differences; sweep over the eight operands is re-running on the final binary.

@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Coverage

Total: 95.03% ⚪ 0 pp vs main

Comparing 17cd2b2..6761d51 (merge-base → PR head)

No per-file coverage changes vs main.

🔇 0 ignored region(s), 409 tolerated region(s)

ignore removes the lines from both reports; tolerate keeps them in the reported percentage but scores them against the baseline, so a cross-run flip cannot move a delta. Regions are read from each revision's own source.

File Kind Lines Rev Reason
src/bin/succinctly/jq_runner.rs tolerate 1332 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted, for the identical reason run_jq's own analogous fallback (#2395) is tolerated -- see that line's own comment (#2950)
src/bin/succinctly/jq_runner.rs tolerate 1705 both unreachable while the walk and the loader agree on what fails: both resolve with resolve_module_in/resolve_data_file_in, parse with parse_program and name a cycle by canonical file, which the fuzz in #3573 held over thousands of programs; kept so drift prints the loader's failure and not 0 compile errors
src/bin/succinctly/jq_runner.rs tolerate 2422-2434 both unreachable: try_parse_meta_op only fires under ParserMode::Yq (src/jq/parser.rs), and rewrite_namespaced_calls is only reached via ModuleProcessor::process_program, which jq_runner's own jq-mode run is the sole caller of -- so a MetaAssign node can never reach this function (#798)
src/bin/succinctly/jq_runner.rs tolerate 3022 both unreachable by construction: every error this wrapper receives today is a decode or nesting-depth failure the evaluator raised itself, never error(v); kept so a future one is rendered rather than dropped (#2999)
src/bin/succinctly/jq_runner.rs tolerate 3023 both see the arm above (#2999)
src/bin/succinctly/jq_runner.rs tolerate 3442 both unreachable in practice today: def is only None when occurrences.module_def() is None, which (given origin is Some) would require an open run whose innermost frame has no def set at a check point that isn't itself inside a module-level def body -- but every module run is a strict chain of def nodes (the loader's own defs, each wrapping its dependency stubs INSIDE its own body via wrap_defs/dep_stubs_for) terminated by the run's own end marker, so a diagnosable call/var/break site is always reached either inside a module-level def's body (module_def Some) or outside every run (origin None) -- and even when def is Some, self.defs is always ModuleSource::read's own re-parse of the exact same file run_id_for interned this origin's id from, so collect_def_sites always finds the matching (name, arity, ordinal) span. Kept as a defensive fallback rather than a panic/unwrap in case that invariant is ever violated (#3085)
src/bin/succinctly/jq_runner.rs tolerate 3691-3694 both unreachable in a single-process run by construction: run_id_for (the sole source of an origin id) always inserts a run_origins entry for the id it hands back -- from a real load's canonical path, or its own literal-path fallback on a resolve failure -- and a def body only ever gets stamped with an origin after its module loaded successfully, so at always names a file that existed and was readable moments earlier. Reaching this arm needs that same file to vanish (or become unreadable) in the narrow window between that load and this re-read, entirely outside this process's control (#2964)
src/bin/succinctly/jq_runner.rs tolerate 3960 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted -- a newly covered name only wraps an already-successful dedicated parse, and a failing one would have propagated its error in the first parse too, so the retry budget is charged at the identical sites in both (#2395)
src/bin/succinctly/jq_runner.rs tolerate 4606-4642 both unreachable from any query this suite can build since #3457: the path walkers were the sites that panicked at MAX_NESTING_DEPTH here (sort/join/map, path()/paths/setpath/del()/assignment on a deep document), and they now return a decode-failure-tagged error, so a deep document is reported through the ordinary Err arm instead. The panic sites still in the evaluator (lazy.rs cursor_to_owned, owned_identity_recurse_step, owned_from_standard_json_at_depth, the YAML comment-preserving materialization) are not reached by a jq-mode CLI query at 250-500 levels, probed by hand; the catch is kept as the net for them and for a future guard that panics, and nesting_depth_panic_message itself is pinned by a unit test (#3457)
src/bin/succinctly/jq_runner.rs tolerate 9974 both unreachable: this test builds only ResolveError::Call values (#3313)
src/bin/succinctly/jq_runner.rs tolerate 12025 both unreachable in a passing suite by design -- the fixed b\
src/bin/succinctly/main.rs tolerate 1372 both unreachable given clap 4.6's own unknown_argument() error constructor: every ErrorKind::UnknownArgument it builds sets ContextKind::InvalidArg to ContextValue::String(arg) in the same call, so this arm only guards a future clap release changing that invariant
src/bin/succinctly/main.rs tolerate 1541 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_accepted_via_sjq_multicall_alias_3389's '-x' row demonstrably reaches the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1710 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_boundary_characters_3389's '-x'/'-n1'/'--bogus' rows demonstrably reach the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1732 both the CLI suites drive yq through the syq multi-call arm above; this arm is the same call reached only when spelled succinctly yq (#2999)
src/bin/succinctly/yq_runner.rs tolerate 1650 both unreachable: bytes already parsed successfully by every caller (#1350)
src/bin/succinctly/yq_runner.rs tolerate 1752 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1753 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1754 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 3365 both unreachable: path is always the raw output of the path(TARGET) builtin evaluated a few lines up in resolve_one_meta_assign -- path/1 is a jq/yq language invariant that always answers an array of path components (see Expr::Builtin(Builtin::PathNoArg) => Ok(Some(OwnedValue::Array(..))) in eval_generic.rs), never any other shape (#798)
src/bin/succinctly/yq_runner.rs tolerate 3467 both unreachable: resolve_meta_assign_writes runs expr through this before any evaluation begins (see its own doc comment), and Expr::Shared is never constructed by the parser -- only at eval time, by function-call argument substitution (substitute_func_param in eval.rs) -- so a pre-evaluation AST can never contain one here (#798)
src/bin/succinctly/yq_runner.rs tolerate 4123 both unreachable: every arm of the match result { .. } above that assigns docs (L3492-3622) constructs Ok(..) -- none ever produces Err, so this if let's implicit else can't be taken; symmetric to L1625's ? (#798)
src/bin/succinctly/yq_runner.rs tolerate 6936-6938 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 7127-7132 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 7892-7897 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/jq/document.rs tolerate 406 both unreachable: the only caller, eval_generic::embed_at_or_within, is gated on jq semantics, and the YAML cursor (the one implementor without an override) is only ever evaluated under yq semantics (#3179)
src/jq/document.rs tolerate 1096-1100 both unreachable: both implementors (JsonCursor, YamlCursor) override this; the default exists as the conservative-false contract a future implementor inherits (#3222)
src/jq/document.rs tolerate 1275-1282 both unreachable: both implementors (StandardJson, YamlValue) override this to decode once; the default exists as the contract a future implementor inherits, and is deliberately the two-call sequence it replaces (#965)
src/jq/eval.rs tolerate 1217 both unreachable: def is always a collect_alias_groups anchor path, which step_to_expr never fails on (#1351)
src/jq/eval.rs tolerate 1238 both unreachable: redirect_paths with Redirect::SINGLE always contributes exactly one output per input, so a 1-element paths always pops Some (#1351)
src/jq/eval.rs tolerate 1247 both unreachable: a concrete setpath/delpaths path's components are always Field/Index -- step_to_expr never produces another shape (#1351)
src/jq/eval.rs tolerate 1251 both unreachable: the map above never yields None, since it only ever matches Field/Index (#1351)
src/jq/eval.rs tolerate 1785 both unreachable: key_or_parent_root_construct's identical structural match already refused any expr shape that would reach this arm
src/jq/eval.rs tolerate 2357 both unreachable: same invariant as the tolerated line below (#3069)
src/jq/eval.rs tolerate 2358 both unreachable: same invariant as the tolerated line below (#3069)
src/jq/eval.rs tolerate 2360 both unreachable: a bridge document is its source's serialization, so the node at each recorded position is the recorded kind (#3069)
src/jq/eval.rs tolerate 2361 both unreachable: see the debug_assert above (#3069)
src/jq/eval.rs tolerate 2407 both unreachable: a scalar has no children, and node lies inside the subtree the walk is in (#3069)
src/jq/eval.rs tolerate 4971 both unreachable: is_escape() is exactly `Error
src/jq/eval.rs tolerate 4972 both unreachable: see the if let above -- push_owned_values never answers None for an is_escape() result (#2180)
src/jq/eval.rs tolerate 6240 both unreachable today: to_owned's only failures are is_decode_failure()-tagged, and suppresses() answers false for those whatever optional is -- the same defensive-but-dead arm eval_generic's own Builtin::Path materialization documents under #2280 (#2908)
src/jq/eval.rs tolerate 7119 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 8504 both unreachable: optional is never true here. eval_each is entered with a forced true at exactly one site (Expr::Optional over an IndexExpr/SliceExpr), and both of those evaluate their target (eval_index_expr) and their key (eval_each(key, .., false)) with a hardcoded false, so only the final index/slice step ever sees it -- nothing carries it down to an Expr::Object (#2180)
src/jq/eval.rs tolerate 9790 both unreachable: owned_write_door calls this only on a clone of a head write_target already matched, and the two list the same five variants (#3188)
src/jq/eval.rs tolerate 9804 both unreachable: every value path_over_owned hands back is a path() output, which is always an array (#3188)
src/jq/eval.rs tolerate 10088 both unreachable: any_child_witnessed is false for every non-container, checked just above (#3178)
src/jq/eval.rs tolerate 10280 both unreachable: the if above replaces every other state with Owned before this match
src/jq/eval.rs tolerate 10786 both reachable only on a genuine allocation failure: owned_assign_step's single-step arms map every non-allocation error to unreachable_owned_assign_write (provably impossible, see its own doc comment), and its Chain arm's set_path call walks exactly the steps owned_assign_step_child already validated as Field-into-Object/Null or Index-in-[0,len]-into-Array/Null with no mutation in between, so the only way set_path/set_field/set_index/pad_with_nulls can still fail is the same try_reserve-fails-under-OOM branch the codebase already tolerates elsewhere (#2267) (#3138)
src/jq/eval.rs tolerate 10906 both unreachable: owned_assign_shape's only caller (owned_step_shape) gates the call on is_owned_assign(expr), which recognizes exactly Assign/Update/CompoundAssign/AlternativeAssign -- the same four variants this match already has explicit arms for, so expr can never be anything else here (#3138)
src/jq/eval.rs tolerate 11106 both unreachable: both call sites (try_eval_owned_step, gated on is_owned_assign; eval_owned_reindex_free's own Assign
src/jq/eval.rs tolerate 11180 both unreachable: this function's own doc comment states why -- the borrow on state between owned_assign_step_child's check and the single write makes the container changing shape impossible, so debug_assert!(false, ..) can never fire (#3138)
src/jq/eval.rs tolerate 11181 both unreachable: same invariant as the false above -- this message is only ever formatted if that assert fires (#3138)
src/jq/eval.rs tolerate 11183 both unreachable: this function is only called from owned_assign_step's single-step arms, both of which the invariant above already rules out ever calling it for real (#3138)
src/jq/eval.rs tolerate 11184 both unreachable: the whole function body above is provably dead by the same borrow-checker invariant its doc comment states (#3138)
src/jq/eval.rs tolerate 11221 both unreachable: Expr::pipe() (the parser's sole Pipe constructor) collapses a one-element list to the bare inner expr instead of wrapping it, and substitute_vars's substitute_var walk preserves a Pipe's stage count rather than dropping stages -- no other site builds an Expr::Pipe for a parsed assignment path, so a path's top-level Pipe here is never single-element (#3138)
src/jq/eval.rs tolerate 14402 both unreachable: every entry point supplies path context, so path never evaluates without one; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 14535 both unreachable: only ever constructed by builtin_sort_keys's own eval_update_no_vivify call, whose enclosing eval_update_impl already runs to_owned on the whole document up front (#2855) -- a decode failure anywhere raises there, before this filter ever sees a value to re-decode; confirmed live, sort_keys(.a)/sort_keys(..) on a document with a decode-failure subtree both raise from the outer to_owned
src/jq/eval.rs tolerate 14678-14680 both unreachable: builtin_length's sole caller is eval_builtin's Builtin::Length dispatch, and Length is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before this match ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 14901-14903 both unreachable: has_one_key's sole caller is builtin_has (via eval_builtin's Builtin::Has dispatch), and Has is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before builtin_has ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 18188 both unreachable: entry is one of to_entries's already-materialized {key,value} pairs, so its depth here is provably no deeper than whatever earlier check let it exist -- a document-decoded entry is already <256 deep (MAX_NESTING_DEPTH, stricter than this 384 guard), and a filter-constructed one already survived becoming a cursor via its own whole-object reindex, which is strictly deeper than any single field extracted from it could be (unwrapping only reduces depth); confirmed live, {a: (reduce range(400) as $i (0; [.]))}
src/jq/eval.rs tolerate 26102 both unreachable: escape_with_prefix! sets terminal before Demand::Stop; already returned above (#2138)
src/jq/eval.rs tolerate 26198 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval.rs tolerate 26199 both unreachable in a test: see the line above (#1634)
src/jq/eval.rs tolerate 26205-26208 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval.rs tolerate 26223-26228 both unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval.rs tolerate 28307 both unreachable via --eval-all: every document here comes straight from parse_input, whose own MAX_NESTING_DEPTH (256) guard already rejects anything deep enough to reach MAX_VALUE_TREE_DEPTH (384) here -- confirmed live, a 300-level document fails parse_input's guard before ever reaching this reindex (#3261)
src/jq/eval.rs tolerate 28638 both unreachable: eval_assign returns collect_assign for JqSemantics before this point, and yq_prepare_assign_targets is Some for every YqSemantics call (#3448)
src/jq/eval.rs tolerate 30240 both unreachable: eval_compound_assign/eval_alternative_assign return collect_assign for JqSemantics before this point, and yq_prepare_assign_targets is Some for every YqSemantics call (#3448)
src/jq/eval.rs tolerate 30567-30570 both unreachable: a materialization only ever raises a decode failure, which suppresses never swallows -- debug_assert_materialization_error (#2334) asserts exactly that; kept so the one classification rule is applied here as at every sibling to_owned site (#1953, #3448)
src/jq/eval.rs tolerate 30580-30583 both unreachable: assign_pristine is to_owned, which only ever raises a decode failure (#2334's debug_assert_materialization_error), and suppresses never swallows one; kept so the one classification rule is applied here as at every sibling to_owned site (#1953, #3448)
src/jq/eval.rs tolerate 30718 both unreachable: the eager route runs only when the path resolves to at most one path -- needs_path_prepass false is one verbatim path, and true with resolves_to_at_most_one_path is at most one resolved path (#2976) -- so no path is ever followed by another; kept as the loop's own contract (#3448)
src/jq/eval.rs tolerate 31799 both unreachable: descriptor_path_component builds a Verbatim key only from an object (#3300)
src/jq/eval.rs tolerate 32368 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval.rs tolerate 35726 both unreachable: an anchor is always a proper ancestor, so it records at least one step (#3134)
src/jq/eval.rs tolerate 37006 both reachable only on a genuine allocation failure: Vec::try_reserve(1) on a vector that has spare capacity, or can grow, cannot fail -- this is the whole purpose of the branch, converting an OOM into a catchable error rather than an abort (ADR-0018's 'would take the host process down' exception). The pre-#2267 form of the same guard, out.try_reserve(branches.len()) in resolve_index_expr/resolve_slice_expr, was 0-hit for the identical reason (#2267)
src/jq/eval.rs tolerate 37007 both see the line above -- the Demand::Stop half of the same allocation-failure-only branch (#2267)
src/jq/eval.rs tolerate 37013 both reachable only when the try_reserve above failed, i.e. only on a genuine allocation failure (#2267)
src/jq/eval.rs tolerate 39985 both unreachable: owned_value_jq_length's own match only ever constructs OwnedValue::Int or OwnedValue::Float, checked just above this arm (#2744)
src/jq/eval.rs tolerate 40040 both unreachable: owned_value_jq_length's own match only ever constructs OwnedValue::Int or OwnedValue::Float, as in the Reverse arm of builtin_navigation (#3888)
src/jq/eval.rs tolerate 40981 both unreachable: is_primitive admits only Identity/Field/Index/Slice, and of those only a Slice's computed bounds can halt -- all four have their own arm in resolve_node_sink/resolve_node_eager, so none reaches this function. Pre-existing; #2694 only wrapped the return in Some (#2694)
src/jq/eval.rs tolerate 41015 both unreachable, as this arm's own comment above says: indexing or slicing a value yields zero or one result, so is_primitive never produces more than one -- kept as a named error rather than a panic. Pre-existing; #2694 only wrapped the enclosing return in Some (#2694)
src/jq/eval.rs tolerate 41794 both unreachable: a cond that flattens to no stages is . or a pipe of ., which cannot_move_register admits, so it never takes the live route (#3757); the debug_assert where stages is built fails a test build that breaks that
src/jq/eval.rs tolerate 46502 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 48066 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), returned just above (#2872)
src/jq/eval.rs tolerate 48949 both unreachable: every arm of the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 49528 both unreachable: every path through the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 52757 both unreachable in a passing suite by design -- a panic-message format argument for the #682 single-valued-tail pin, evaluated only if that assert's own condition is false (#2190)
src/jq/eval.rs tolerate 52834 both unreachable: the only caller reaches this after classify_static_component answered Field for this same value, which it does only for an object (#2190)
src/jq/eval.rs tolerate 52878 both unreachable: both callers establish the container first -- navigate_static_component_ref via classify_static_component's Index arm, and walk_path's Expr::Iterate arm by matching on the container itself (#2190)
src/jq/eval.rs tolerate 55859 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 57602 both unreachable: stop_with_escape's only write is slot.set(Some(control)) with the control it was handed, which is always the Control::Error built one line above (#2180)
src/jq/eval.rs tolerate 58293 both unreachable: on_update records a step_outcome before every Demand::Stop it answers, and the fallback match runs only when it recorded none (#2872)
src/jq/eval.rs tolerate 58333 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 59260 both unreachable by construction: the per-fork match only ever hands stop_with_downstream a non-Exhausted flow, so terminal can never hold Exhausted (#2899)
src/jq/eval.rs tolerate 61600 both llvm-cov line-attribution artifact, not unreachable: the new gate test above (Builtin::Length as first) demonstrably takes key_or_parent_root_construct(first) == false and falls through to the reindex-bridge route below, passing -- but this closing brace, like the one at #56920 for the same reason, is never itself credited a hit
src/jq/eval.rs tolerate 61614 both unreachable in the current test suite: eval_path_context_pipe_owned itself has zero total call-site coverage today (not just this arm), confirmed by a full-suite eprintln probe across every test binary -- reaching its error arm needs first solving how to reach the function at all, out of scope for #3261's reindex-bridge fix
src/jq/eval.rs tolerate 62688 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 62694 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval.rs tolerate 64814 both pre-existing zero-hit line; #2999 changed only which null constant it names
src/jq/eval.rs tolerate 67231 both ? suppresses mktime's error outside builtin dispatch, so the optional flag is false even for an invalid date (#3083)
src/jq/eval.rs tolerate 67234 both unreachable for mktime's C-int-clamped fields: checked civil-date arithmetic stays within i64; the guard protects other callers of the shared helpers (#3083)
src/jq/eval.rs tolerate 67423 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 67426 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 67471 both optional is never true through either caller of this function -- confirmed live (eprintln! probe): `[1,2,3]
src/jq/eval.rs tolerate 67480 both every array literal written in filter source, and every array-element JSON parses, decodes to NumberLiteral (#1035), not a bare Int -- Int is for internally-synthesized values spliced post-parse; probed a computed element ([1970,(0+0),..]) and it still decoded as NumberLiteral here, so this arm has no known real producer (#3068)
src/jq/eval.rs tolerate 67516 both optional is never true through either caller of this function, same as the array-length check above (#3068)
src/jq/eval.rs tolerate 67580 both unreachable for strftime's C-int-clamped fields and bounded zone offset; shared checked date helpers retain overflow guards for other callers (#3083)
src/jq/eval.rs tolerate 67736 both llvm-cov line-attribution artifact, not unreachable: the call's own argument lines (immediately above) show 3 hits under the #3055 test's three E/O pass-through rows, but this closing-token line is never itself credited -- verified via the raw lcov DA: records
src/jq/eval.rs tolerate 68926 both unreachable: YamlIndex::root always wraps the documents in a virtual root sequence, so the arm above takes every input (#2664)
src/jq/eval.rs tolerate 68927 both unreachable: the same defensive arm as the line above (#2664)
src/jq/eval.rs tolerate 69239 both unreachable from combinations, whose own empty-input return runs first; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 70343 both confirmed live (eprintln! probe): optional is always false in builtin_abs regardless of whether the filter writes abs?, since that suppression happens entirely outside builtin dispatch here -- the same 'optional is never true here' shape eval.rs already documents elsewhere (#2180) (#3041)
src/jq/eval.rs tolerate 72401 both unreachable: the sink is a plain collector that always answers Demand::Continue (#2872)
src/jq/eval.rs tolerate 72511 both unreachable: optional: false makes index_one_owned answer Ok(Some)/Err only (#2872)
src/jq/eval.rs tolerate 72816 both unreachable: pattern_has_computed_key is false for Pattern::Var, so the loop walker above always takes it (#2872)
src/jq/eval.rs tolerate 72864 both unreachable: every caller gates on pattern_has_computed_key being false (#2872)
src/jq/eval.rs tolerate 74560 both unreachable: bind_def_call only calls this for a non-empty params, install_def_calls only builds a DefCall whose args.len() equals params.len(), and the last parameter is never shadowed, so at least one entry is always built (#2560)
src/jq/eval.rs tolerate 75974 both unreachable in a passing suite by design -- this panic only fires if eval_owned_reindex_free declined a shape this loop's own handled table asserts is always answered (#3138)
src/jq/eval.rs tolerate 75983 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a shape this loop's own handled table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 76022 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step handled a shape this loop's own declined table asserts is always declined (#3138)
src/jq/eval.rs tolerate 76043 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a yq shape this loop's own table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 76143 both unreachable in a passing suite by design -- this panic only fires if the tracked \
src/jq/eval.rs tolerate 76145 both unreachable in a passing suite by design -- this panic only fires if state stopped being an Object, which every owned_assign_step write in the loop below preserves (#3138)
src/jq/eval.rs tolerate 76153 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on the single-step shape this loop drives every iteration (#3138)
src/jq/eval.rs tolerate 76158 both unreachable in a passing suite by design -- this arm only fires if state stopped being an Object, which every write in the loop above preserves (#3138)
src/jq/eval.rs tolerate 76196 both unreachable in a passing suite by design -- this panic only fires if the tracked \
src/jq/eval.rs tolerate 76198 both unreachable in a passing suite by design -- this panic only fires if state stopped being an Object, which every owned_assign_step write in the loop below preserves (#3241)
src/jq/eval.rs tolerate 76216 both unreachable in a passing suite by design -- this arm only fires if state stopped being an Object, which every write in the loop above preserves (#3241)
src/jq/eval.rs tolerate 76293 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on the single closed assignment this test drives (#3241)
src/jq/eval.rs tolerate 76308 both unreachable in a passing suite by design -- both values are built as objects above and an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 76353 both unreachable in a passing suite by design -- doc builds an object (#3241)
src/jq/eval.rs tolerate 76361 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on the single closed assignment this test drives (#3241)
src/jq/eval.rs tolerate 76369 both unreachable in a passing suite by design -- an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 76402 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on a closed assignment this table asserts is always answered (#3241)
src/jq/eval.rs tolerate 76405 both unreachable in a passing suite by design -- an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 76449 both unreachable in a passing suite by design -- this panic only fires if fold_step_each reported anything but an escape (not optional) or exhaustion (optional) for a failing owned step (#3241)
src/jq/eval.rs tolerate 76492 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step answered an UPDATE holding an Expr::TrackedVar, which closed_expr_to_owned rejects (#3241)
src/jq/eval.rs tolerate 76520 both unreachable in a passing suite: every row below is a reduce or a foreach (#3329)
src/jq/eval.rs tolerate 76595 both unreachable in a passing suite: every row below is a reduce or a foreach (#3896)
src/jq/eval.rs tolerate 76916 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 76938 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 76956 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 77026 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 77044 both substitute_func_param_impl's FuncDef arm always returns FuncDef (#2555)
src/jq/eval.rs tolerate 85102 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval.rs tolerate 85261 both unreachable in a passing suite by design -- this is the failure message for the assertion the test exists to make (#2190)
src/jq/eval.rs tolerate 85641 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval.rs tolerate 86300 both unreachable in a passing suite: reports a failed test invariant (#3682)
src/jq/eval.rs tolerate 86515 both the no-std arm: `cfg!(feature = \
src/jq/eval.rs tolerate 87373 both unreachable in a passing suite: every source this helper parses starts with def f(n): ...; (#3296)
src/jq/eval.rs tolerate 87426 both unreachable in a passing suite: f(1) under def f(n) always installs as a DefCall, which the assert above has just settled (#3296)
src/jq/eval.rs tolerate 98894 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 98946 both unreachable in a passing suite by design -- this test's own diagnostic (#3102)
src/jq/eval.rs tolerate 99860-99871 both the closure is asserted never called below (on_update_calls stays 0) -- Err(_) with optional=true short-circuits fold_step_each before this sink runs (#3122)
src/jq/eval.rs tolerate 104712 both unreachable in a passing suite by design -- the door's sink never stops and it never breaks or halts (#3439)
src/jq/eval.rs tolerate 105410 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 107961 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval.rs tolerate 107970 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval.rs tolerate 107990 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval.rs tolerate 110482 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 110493 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 110510 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 110530 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 110538 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 111689 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 113625 both unreachable in a passing suite by design -- check_value_tree_depth's only Err variant is EvalError, and From for EvalEscape always produces EvalEscape::Error (#3275)
src/jq/eval.rs tolerate 114230 both unreachable in a passing suite by design -- the failure message for the shape assertion the test makes (#3471)
src/jq/eval.rs tolerate 117734 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117776 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117781 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117816 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117837 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117940 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117956 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 121492 both unreachable in a passing suite by design -- every filter this helper is called with parses to an AsPattern (#2649)
src/jq/eval.rs tolerate 121536 both unreachable in a passing suite by design -- a literal-key pattern's walk either completes or refuses with an error (#2872)
src/jq/eval.rs tolerate 121545 both unreachable in a passing suite by design -- every call site passes the origin of a binding this same test already proved carries a marker (#2649)
src/jq/eval.rs tolerate 121873 both unreachable in a passing suite by design -- the assertion above is the test (#2872)
src/jq/eval.rs tolerate 122573 both unreachable in a passing suite by design -- every row here is a shape jq accepts, confirmed live (#2649)
src/jq/eval.rs tolerate 122641 both unreachable in a passing suite by design -- every row here is a shape jq refuses, confirmed live (#2649)
src/jq/eval.rs tolerate 123026 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 123042 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 123076 both unreachable in a passing suite by design -- this is the panic message for the #3069 pin itself, only formatted if the let-else pattern fails to match
src/jq/eval.rs tolerate 123093 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 123109 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 123126 both unreachable in a passing suite by design -- this is the panic message for the #3069 pin itself, only formatted if the match doesn't hit the expected arm above
src/jq/eval.rs tolerate 123212 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3037)
src/jq/eval.rs tolerate 123290 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3037)
src/jq/eval.rs tolerate 124174 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3135)
src/jq/eval.rs tolerate 124281 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3122)
src/jq/eval.rs tolerate 124299 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3122)
src/jq/eval.rs tolerate 124367 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 124371 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 124411 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 124415 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 126153 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3119)
src/jq/eval.rs tolerate 126208 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3127)
src/jq/eval.rs tolerate 128902 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#2937)
src/jq/eval.rs tolerate 128989 both unreachable in a passing suite by design -- every READERS filter raises a decode failure on every malformed json in this sweep, so this fallback never fires (#3222)
src/jq/eval.rs tolerate 128995 both unreachable in a passing suite by design -- see the concrete match above, same sweep (#3222)
src/jq/eval.rs tolerate 129001-129003 both unreachable in a passing suite by design -- this is the failure-recording line for the assertion below, only reached if a READERS filter fails to raise (#3222)
src/jq/eval.rs tolerate 129059 both unreachable in a passing suite by design -- none of NON_READERS ever raises through eval_with_cursor_using, on the malformed document or the well-formed one; kept so a filter that starts erroring is still comparable rather than panicking (#3222)
src/jq/eval.rs tolerate 129365 both unreachable in a passing suite by design -- every filter below builds an array (#3191)
src/jq/eval.rs tolerate 129372 both unreachable in a passing suite by design -- each element is built as {k: } (#3191)
src/jq/eval.rs tolerate 129374 both unreachable in a passing suite by design -- each element is built as {k: } (#3191)
src/jq/eval.rs tolerate 129476 both every pinned filter below yields an owned value; kept so a cursor answer still renders rather than panics (#2999)
src/jq/eval.rs tolerate 129477 both unreachable in a passing suite by design -- the failure message for the assertions this helper serves (#2999)
src/jq/eval.rs tolerate 129811 both unreachable in a passing suite: every corpus program starts with a def (#3307)
src/jq/eval.rs tolerate 129936 both unreachable in a passing suite: every corpus program's first node is a def (#3307)
src/jq/eval.rs tolerate 129973 both unreachable in a passing suite: the last def's call is bound (#3307)
src/jq/eval.rs tolerate 130135 both unreachable in a passing suite: every caller passes a def head (#3307)
src/jq/eval.rs tolerate 130211 both unreachable in a passing suite: chain builds a def head (#3307)
src/jq/eval.rs tolerate 130215 both unreachable in a passing suite: a 50-def chain has a second def (#3307)
src/jq/eval.rs tolerate 130311 both unreachable in a passing suite: spine_node builds a def head (#3307)
src/jq/eval.rs tolerate 130372 both unreachable in a passing suite: the loop above builds a def (#3307)
src/jq/eval.rs tolerate 130380 both unreachable in a passing suite: the main filter is a pipe (#3307)
src/jq/eval.rs tolerate 130384 both unreachable in a passing suite: stages 0 and 2 are the spliced arguments (#3307)
src/jq/eval_generic.rs tolerate 1241 both unreachable: validate_cursor, CheckOnly's only instantiation, passes no nested nodes, so the walk never asks (#3179)
src/jq/eval_generic.rs tolerate 4634 both unreachable: the decode above replaced every cursor with an owned value, or returned an error that skips this block (#3856)
src/jq/eval_generic.rs tolerate 5165 both unreachable: the sole remaining caller (retain_truthy_generic's Many arm) runs to_owned on an item before keeping it, so re-converting a kept item here cannot fail; the ManyCursor caller that made this reachable went with the truthiness walk (#2692, re-establishing #2661's premise)
src/jq/eval_generic.rs tolerate 7217 both unreachable: hi is find_close of a container's own open paren, which a built index always matches (#3179)
src/jq/eval_generic.rs tolerate 8149 both unreachable for the one format that claims materializes_members_one_to_one: a JSON object's children always pair key-then-value; kept so an implementor whose mapping could end on a key declines instead of miscounting (#3483)
src/jq/eval_generic.rs tolerate 8166 both unreachable for JSON: a key node always decodes or falls back to its raw spelling, so key_display_string is Some; kept so a format whose key can be non-string declines to the generic walk (#3483)
src/jq/eval_generic.rs tolerate 8377 both unreachable: the climb starts at a container (embed_at_or_within's is_container gate) and only ever moves to a parent, which is a container too, and a key is a leaf -- no node on the climb can be a key; kept as a refusal rather than a panic (#3897)
src/jq/eval_generic.rs tolerate 8406 both unreachable: materializes_members_one_to_one holds, so the value held for a node is an array exactly when the node is a sequence and an object exactly when it is a mapping, and the step the climb recorded is an index for the first and a string key for the second; kept as a refusal rather than a panic (#3897)
src/jq/eval_generic.rs tolerate 10309 both unreachable: this loop is entered only with a LazyKeys/LazyIndexRange/LazySeq head, and every fold_lazy_*_stage answers OneCursor, Owned, ManyOwned or a lazy marker (eval_on_owned never returns One); kept so a stage that did return One hands off by value instead of falling to the eager fold (#1565, #3886)
src/jq/eval_generic.rs tolerate 10828 both unreachable in a passing suite by design -- this is the panic message for the #2368 pin itself, only formatted if the assert's own condition is false (#2368)
src/jq/eval_generic.rs tolerate 10889 both unreachable: this arm's own match guard already evaluated value.as_array().is_some_and(..) as true to be here at all, and as_array() is a pure read of value -- the second call inside the body can never answer None where the guard's own call just answered Some
src/jq/eval_generic.rs tolerate 12800 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 12817 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 13376 both unreachable: a step from a live node emits only live children (#3023)
src/jq/eval_generic.rs tolerate 14292 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval_generic.rs tolerate 16118 both unreachable: every producer that reaches this empty-exprs tail (each_lazy_keys_iterate_sink's sorted/!sorted arms, each_lazy_index_range_iterate_sink, each_lazy_seq_iterate_sink) yields OneCursorValue/OneCursor/Owned, never a cursorless GenericItem::One -- so cursor is always Some here; kept for exhaustiveness/symmetry with the Some arm (#2103)
src/jq/eval_generic.rs tolerate 17935 both unreachable: each_negate_generic pushes only GenericItem::Owned (arith_negate's result), which converts infallibly (#3410)
src/jq/eval_generic.rs tolerate 18517 both unreachable: is_escape() is exactly `Error
src/jq/eval_generic.rs tolerate 18518 both unreachable: see the if let above -- push_generic_owned_values never answers None for an is_escape() result (#2180)
src/jq/eval_generic.rs tolerate 19616 both unreachable: escape_generic!/ensure_owned! set terminal before Demand::Stop; already returned above (#2138)
src/jq/eval_generic.rs tolerate 19742 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval_generic.rs tolerate 19743 both unreachable in a test: see the line above (#1634)
src/jq/eval_generic.rs tolerate 19749-19752 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval_generic.rs tolerate 19768-19773 both unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval_generic.rs tolerate 20303-20307 both unreachable: this function's sole caller, slice_one_generic_computed, already runs the identical unreadable_value_error(&target) check on the same target and returns before ever calling here; kept as this function's own contract in case a future literal-bounds caller reaches it directly (#3222)
src/jq/eval_generic.rs tolerate 20762 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 20772 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 21523 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 21556 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21604 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21672 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21688 both unreachable: effective_fields_checked already rejects key_is_malformed, the same decoded_key_str Ok(None) that makes key_display_string return None (#3022)
src/jq/eval_generic.rs tolerate 21834 both unreachable: both callers match Field, Index or Iterate before dispatching here (#3022)
src/jq/eval_generic.rs tolerate 23410 both unreachable: len_checked and SliceBounds::resolve already bound every index in range to [0, len), so get_cursor cannot miss (#2168)
src/jq/eval_generic.rs tolerate 26805 both unreachable by construction: path_context_resolvable admits an any(cond) read only through admits.prefetch, so the rewriter always has one -- the AnyCond arm above carries the identical assertion (#3079)
src/jq/eval_generic.rs tolerate 26809 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 26810 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 27181 both unreachable: the callback records downstream_flow before every Demand::Stop, and that flow is returned above (#3022)
src/jq/eval_generic.rs tolerate 27679 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 27700 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 28069 both unreachable: malformed_object_member above already proved every key stringifies (the None half), and to_owned_cursor on an untagged key decoded_key_str decoded cannot fail (the Err half) (#2785)
src/jq/eval_generic.rs tolerate 28150 both unreachable: map(f) over an array emits exactly one array; kept so a future map shape produces no output rather than a panic (#2785)
src/jq/eval_generic.rs tolerate 28488 both unreachable by design -- eval_single's #2368 debug_assert forbids optional=true on Builtin::Reverse, so length never answers None here (#2730)
src/jq/eval_generic.rs tolerate 28887 both unreachable: to_owned_with_cursor of a document number literal cannot fail, so the macro's error arms never run (#3191)
src/jq/eval_generic.rs tolerate 29144 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 29150 both see above: the input-queue deferral never fires from the CLI
src/jq/eval_generic.rs tolerate 30639 both unreachable by construction: every shape either guard admits now has an arm above (#2771), and expr_dispatch_catchall_guards_default_conservatively_2549 pins both guards' _ => false defaults directly
src/jq/eval_generic.rs tolerate 31295 both unreachable in a passing suite by design -- owned_identity_rule maps a bare Expr::Var to Bound too (for the static gate, which sees a body before its as substitution runs), but every runtime dispatch that reaches this rule (owned_identity_after_stage/owned_identity_placed_by, from owned_identity_leaving_cursor's Bound arm) only ever sees a stage after eval_owned_identity_as's unconditional substitute_bound_var_from call, which always turns $x into Expr::TrackedVar before recursing -- confirmed by running the full suite with this arm replaced by a hard panic!(), which never fired (#2072)
src/jq/eval_generic.rs tolerate 31313 both unreachable: this Slice rule's own two execution paths both exclude Expr::Slice before ever reaching owned_identity_placed_by -- eval_owned_identity_stages's catch-all only runs a stage owned_identity_nav_supported refused, and owned_identity_leaving_cursor (identity_from_first, eval_generic.rs:10724) only runs a stage path_context_is_navigational refused -- and both predicates admit Expr::Slice (owned_identity_nav_supported/path_context_is_navigational_at each list Expr::Slice { .. } => true), so a bare slice is always resolved by owned_identity_step's own arm first. Kept in owned_identity_rule's match for exhaustiveness/symmetry with the rule table's other entries, the same reason #2072's Bound arm above is kept unreachable-by-construction (#2966's review of #2834)
src/jq/eval_generic.rs tolerate 31409 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval_generic.rs tolerate 31782 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval_generic.rs tolerate 32843 both unreachable: the arm's or-pattern admits Expr::Limit, Builtin::Skip and Builtin::NthStream only, and each has its own arm above (#3610)
src/jq/eval_generic.rs tolerate 32939 both optional is never true through this pipe: ? is eval_owned_identity_try, which catches the escape instead, and after #693 only the IndexExpr/SliceExpr special case ever sets it -- kept as any_all_f's scalar_fallback mirror
src/jq/eval_generic.rs tolerate 32940 both optional is never true here, see above
src/jq/eval_generic.rs tolerate 33364 both unreachable in a passing suite by design -- the failure message for the assertion the tests below make (#2999)
src/jq/eval_generic.rs tolerate 33611 both unreachable in a passing suite by design -- the fixture's map(.+1) is always a LazySeq; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 33639 both unreachable in a passing suite by design -- the fixture's only escape is Control::Error; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 33944 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval_generic.rs tolerate 38995 both failure message for the assertion this #3222 test exists to make
src/jq/eval_generic.rs tolerate 40051 both unreachable in a passing suite by design -- the failure message for the shape assertion the test makes (#3471)
src/jq/eval_generic.rs tolerate 43931 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 43988 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 44015 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 44049 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 44167 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 44746 both unreachable in a passing suite: reports a failed test invariant (#3477)
src/jq/eval_generic.rs tolerate 44749 both unreachable in a passing suite: reports a failed test invariant (#3477)
src/jq/eval_generic.rs tolerate 44778 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44785 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44798 both unreachable in a passing suite: [x] always builds an array (#3856)
src/jq/eval_generic.rs tolerate 44823 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44830 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44854 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44879 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44911 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44923 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44959 both unreachable in a passing suite: reports a failed test invariant (#3815)
src/jq/eval_generic.rs tolerate 45315 both unreachable in a passing suite: reports a failed test invariant (#3923)
src/jq/eval_generic.rs tolerate 45323 both unreachable in a passing suite: reports a failed test invariant (#3923)
src/jq/eval_generic.rs tolerate 45388 both unreachable in a passing suite by design: a panic message, formatted only if the walk's failure were not a plain Error (#3478)
src/jq/eval_generic.rs tolerate 45392 both no document here answers a plain Error since #3478 (the walk is the consumer's); kept so a future eager walk reports its own message instead of falling to the arm below, which swallows it
src/jq/eval_generic.rs tolerate 45408 both unreachable: [., .] holds only document nodes, so no pulled element is an owned value (#3856)
src/jq/eval_generic.rs tolerate 47056 both unreachable in a passing suite by design -- the failure arm of a #3722 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47110 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47114 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47117 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47173 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47253 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47268 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47291 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47312 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47478 both unreachable in a passing suite by design -- the failure arm of a #3702 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47682 both unreachable in a passing suite by design -- the failure arm of a #3702 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47737 both unreachable in a passing suite by design -- the failure arm of a #3839 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47741 both unreachable in a passing suite by design -- the failure arm of a #3839 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 48429 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48451 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48458 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48536 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48587 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48648 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48684 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48693 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 48694 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 48695 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 49657 both unreachable in a passing suite by design -- a panic-message format argument for the #3483 differential test's own assertion, evaluated only if that assert's own condition is false (#3483)
src/jq/expr.rs tolerate 3411 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/expr.rs tolerate 3427 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/lazy.rs tolerate 657 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/lazy.rs tolerate 1474 both failure message for the shape the test asserts
src/jq/parser.rs tolerate 246 both unreachable: parse_join_expr only calls join_expr with two to four arguments (#3046)
src/jq/parser.rs tolerate 268 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 270 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 272 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 279 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 283 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 313 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 317 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 326 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 328 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 330 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 345 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 10245 both unreachable in a passing suite by design -- this is the panic message for the #3044 pin itself, only formatted if the let-else pattern fails to match (#3044)
src/jq/resolve.rs tolerate 921 both unreachable by construction: every plain entry was listed under its name when it was pushed
src/jq/resolve.rs tolerate 924 both unreachable by construction: every plain entry was listed under its arity when it was pushed
src/jq/resolve.rs tolerate 974 both unreachable by construction: FnScope::floor only ever names a begin marker
src/jq/resolve.rs tolerate 2684 both unreachable by construction: this match is only entered when is_marker (marker.is_some()) is true, and RunMarker has only Begin/End variants -- the None arm exists solely for exhaustiveness against Option's type
src/jq/resolve.rs tolerate 2959 both unreachable in practice today: this arm needs builtin_fallback==None (the name was never a shadow candidate) yet is_jq_builtin==true (a real jq builtin at this arity) -- every implemented builtin's own dedicated parse already lowers that shape to Expr::Builtin before resolve.rs ever runs, and #3042/#3046 closed the once-real 'unimplemented builtin' gap this existed for (see JQ_BUILTIN_ROSTER's own doc comment)
src/jq/resolve.rs tolerate 2961 both unreachable with the current roster: every JQ_BUILTIN_ROSTER entry of arity >= 1 already has a dedicated parser form (a matches_keyword special case or a Libm1/Libm2/Libm3::ALL entry -- confirmed by cross-referencing the full roster against both), so it is parsed straight to Expr::Builtin and never reaches here as a bare FuncCall. This arm exists for a roster name with no dedicated parse yet and a nonzero arity -- there is none today, so the loop body is reached with an empty args on every pinned-suite run (355 hits on the arm's own condition, 0 in the loop) and would only start executing if such a name were added (#2964)
src/jq/share_stats.rs tolerate 105 both process-global env var; exercised by the CLI audit run, not by an in-process test (#2999)
src/jq/value.rs tolerate 365 both unreachable by construction: the slow path is entered only after significant_digit_count found 18+ digits over the same mantissa bytes this loop walks (#2936)
src/jq/value.rs tolerate 389 both unreachable by construction: 18+ significant digits were counted, so at least one nonzero digit was kept (#2936)
src/jq/value.rs tolerate 2906 both unreachable by construction -- the block above replaces every Shared with Owned before this line (#3191)
src/jq/value.rs tolerate 3278 both unreachable: format_float_with_fraction of a finite double is always RFC 8259 number text, which parse_i64_or_f64 reads (#2936)
src/jq/value.rs tolerate 5976 both unreachable in a passing suite by design -- built as a string on the line above (#3191)
src/jq/value.rs tolerate 5985 both unreachable in a passing suite by design -- built as a number literal on the line above (#3191)
src/jq/value.rs tolerate 6126 both unreachable in a passing suite by design -- every caller built the value as an array (#2999)
src/jq/value.rs tolerate 6369 both unreachable in a passing suite by design -- the value was built as this container a few lines above (#2999)
src/jq/value.rs tolerate 7191 both unreachable in a passing suite by design -- the failure message for a malformed oracle table (#2936)
src/jq/value.rs tolerate 7580 both failure message for the assertion the calling test makes
src/jq/value.rs tolerate 7912 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 7921 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 7929 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 8070 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 8076 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 8188 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/jq/value.rs tolerate 9304 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/jq/value.rs tolerate 9322 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/jq/value.rs tolerate 9855 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make: the two serializers disagreeing on whether a nest is too deep (#3479)
src/jq/walk.rs tolerate 796 both unreachable: ArrayKey is only built from a resolved key at path-resolution time, never parsed, so no rewrite of parsed source meets it (#3506)
src/json/light.rs tolerate 2810-2816 both unreachable in practice: UNMEASURED_SPAN only arises when end - text_pos in number_at overflows u32 -- a single number span >= 4 GiB -- which no realistic (or practically constructible) test document approaches (#3222)
src/json/light.rs tolerate 3619 both reachable only through a bare 64-bit hash collision between keys the pairwise scan already proved distinct
src/json/light.rs tolerate 9548 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9630 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9719 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9752 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9781 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9869 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/json/light.rs tolerate 9874 both unreachable in a passing suite by design -- see the assert_eq! format argument above, same sweep (#3222)
src/json/light.rs tolerate 9900 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9911 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9992 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 10016 both unreachable in a passing suite: every caller passes an object (#3180)
src/json/light.rs tolerate 10022 both unreachable in a passing suite: every caller passes an array (#3180)
src/json/light.rs tolerate 10112 both unreachable in a passing suite by design -- panic-message format argument (#3180)
src/yaml/index.rs tolerate 1296 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1300 both unreachable: every fixture field_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1311 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1313 both unreachable: every call to field_key_head_foot in this test module passes a key that the fixture's mapping actually has (#798)
src/yaml/index.rs tolerate 1323 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1327 both unreachable: every fixture seq_item_head_foot is called with in this test module is a top-level sequence (#798)
src/yaml/index.rs tolerate 1350 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1369 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1392 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1401 both unreachable: every fixture field_key_head_foot_in_doc is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1412 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1414 both unreachable: every call to field_key_head_foot_in_doc in this test module passes a key that the fixture's document actually has (#798)
src/yaml/index.rs tolerate 1425 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1429 both unreachable: every fixture nested_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1433 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this let-else's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1439 both unreachable: every fixture nested_key_head_foot is called with has a nested mapping under outer (#798)
src/yaml/index.rs tolerate 1450 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1453 both unreachable: every call to nested_key_head_foot in this test module passes an outer.inner pair that the fixture actually has (#798)
src/yaml/light.rs tolerate 3372 both unreachable: an alias target is never None for a built index (#1374)
src/yaml/light.rs tolerate 15479 both unreachable in a passing suite by design -- the fixture above is a block sequence (#2640)
src/yaml/light.rs tolerate 15506 both unreachable in a passing suite by design -- the fixture above is a block mapping (#2640)
src/yaml/light.rs tolerate 16243 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 16254 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 16411 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/parser.rs tolerate 1583 both unreachable: every block-sequence open registers a frame at its own depth before any item of it can be parsed (#1079)
src/yaml/parser.rs tolerate 1613 both unreachable: this function's sole caller (record_standalone_comment) only invokes it from inside a match on pending_head_lines.last(), so pending_head_lines is already known non-empty here (#798)
src/yaml/parser.rs tolerate 8013 both unreachable: every byte here already passed the [0-9.eE+-] charset check above, a strict subset of ASCII, so str::from_utf8 can never fail (#2778)

Excluded by ignore-filename-regex: 1 file (none of them touched by this diff).

Patch coverage

Patch: 98.48% (65/66 new lines covered)

File Patch Uncovered new lines
src/jq/eval.rs 98.48% (65/66) 102308
Uncovered new lines (1)
  • src/jq/eval.rs:102308

Indirect coverage changes

🔴 0 lines lost coverage, 🟢 1 lines gained coverage on unchanged code.

Indirect changes
  • src/jq/eval.rs:21527 🟢 uncovered → covered

📦 Full per-file coverage summary · run summary

@github-actions

github-actions Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Coverage

Total: 94.94% ⚪ 0 pp vs main

Comparing 17cd2b2..6761d51 (merge-base → PR head)

No per-file coverage changes vs main.

🔇 0 ignored region(s), 410 tolerated region(s)

ignore removes the lines from both reports; tolerate keeps them in the reported percentage but scores them against the baseline, so a cross-run flip cannot move a delta. Regions are read from each revision's own source.

File Kind Lines Rev Reason
src/bin/succinctly/jq_runner.rs tolerate 1332 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted, for the identical reason run_jq's own analogous fallback (#2395) is tolerated -- see that line's own comment (#2950)
src/bin/succinctly/jq_runner.rs tolerate 1705 both unreachable while the walk and the loader agree on what fails: both resolve with resolve_module_in/resolve_data_file_in, parse with parse_program and name a cycle by canonical file, which the fuzz in #3573 held over thousands of programs; kept so drift prints the loader's failure and not 0 compile errors
src/bin/succinctly/jq_runner.rs tolerate 2422-2434 both unreachable: try_parse_meta_op only fires under ParserMode::Yq (src/jq/parser.rs), and rewrite_namespaced_calls is only reached via ModuleProcessor::process_program, which jq_runner's own jq-mode run is the sole caller of -- so a MetaAssign node can never reach this function (#798)
src/bin/succinctly/jq_runner.rs tolerate 3022 both unreachable by construction: every error this wrapper receives today is a decode or nesting-depth failure the evaluator raised itself, never error(v); kept so a future one is rendered rather than dropped (#2999)
src/bin/succinctly/jq_runner.rs tolerate 3023 both see the arm above (#2999)
src/bin/succinctly/jq_runner.rs tolerate 3442 both unreachable in practice today: def is only None when occurrences.module_def() is None, which (given origin is Some) would require an open run whose innermost frame has no def set at a check point that isn't itself inside a module-level def body -- but every module run is a strict chain of def nodes (the loader's own defs, each wrapping its dependency stubs INSIDE its own body via wrap_defs/dep_stubs_for) terminated by the run's own end marker, so a diagnosable call/var/break site is always reached either inside a module-level def's body (module_def Some) or outside every run (origin None) -- and even when def is Some, self.defs is always ModuleSource::read's own re-parse of the exact same file run_id_for interned this origin's id from, so collect_def_sites always finds the matching (name, arity, ordinal) span. Kept as a defensive fallback rather than a panic/unwrap in case that invariant is ever violated (#3085)
src/bin/succinctly/jq_runner.rs tolerate 3691-3694 both unreachable in a single-process run by construction: run_id_for (the sole source of an origin id) always inserts a run_origins entry for the id it hands back -- from a real load's canonical path, or its own literal-path fallback on a resolve failure -- and a def body only ever gets stamped with an origin after its module loaded successfully, so at always names a file that existed and was readable moments earlier. Reaching this arm needs that same file to vanish (or become unreadable) in the narrow window between that load and this re-read, entirely outside this process's control (#2964)
src/bin/succinctly/jq_runner.rs tolerate 3960 both unreachable: widening the shadow-candidate set never rejects a program the first parse accepted -- a newly covered name only wraps an already-successful dedicated parse, and a failing one would have propagated its error in the first parse too, so the retry budget is charged at the identical sites in both (#2395)
src/bin/succinctly/jq_runner.rs tolerate 4606-4642 both unreachable from any query this suite can build since #3457: the path walkers were the sites that panicked at MAX_NESTING_DEPTH here (sort/join/map, path()/paths/setpath/del()/assignment on a deep document), and they now return a decode-failure-tagged error, so a deep document is reported through the ordinary Err arm instead. The panic sites still in the evaluator (lazy.rs cursor_to_owned, owned_identity_recurse_step, owned_from_standard_json_at_depth, the YAML comment-preserving materialization) are not reached by a jq-mode CLI query at 250-500 levels, probed by hand; the catch is kept as the net for them and for a future guard that panics, and nesting_depth_panic_message itself is pinned by a unit test (#3457)
src/bin/succinctly/jq_runner.rs tolerate 9974 both unreachable: this test builds only ResolveError::Call values (#3313)
src/bin/succinctly/jq_runner.rs tolerate 12025 both unreachable in a passing suite by design -- the fixed b\
src/bin/succinctly/main.rs tolerate 1372 both unreachable given clap 4.6's own unknown_argument() error constructor: every ErrorKind::UnknownArgument it builds sets ContextKind::InvalidArg to ContextValue::String(arg) in the same call, so this arm only guards a future clap release changing that invariant
src/bin/succinctly/main.rs tolerate 1541 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_accepted_via_sjq_multicall_alias_3389's '-x' row demonstrably reaches the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1710 both llvm-cov line-attribution artifact, not unreachable: test_negative_filter_boundary_characters_3389's '-x'/'-n1'/'--bogus' rows demonstrably reach the e.exit() two lines below (exit code 2, confirmed by that test passing), which this if-let's own closing brace sits directly above -- the brace itself is never credited a hit, the same class of artifact eval.rs's own tolerate list documents for other closing braces (#3389)
src/bin/succinctly/main.rs tolerate 1732 both the CLI suites drive yq through the syq multi-call arm above; this arm is the same call reached only when spelled succinctly yq (#2999)
src/bin/succinctly/yq_runner.rs tolerate 1650 both unreachable: bytes already parsed successfully by every caller (#1350)
src/bin/succinctly/yq_runner.rs tolerate 1752 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1753 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 1754 both unreachable: see the block comment above this arm
src/bin/succinctly/yq_runner.rs tolerate 3365 both unreachable: path is always the raw output of the path(TARGET) builtin evaluated a few lines up in resolve_one_meta_assign -- path/1 is a jq/yq language invariant that always answers an array of path components (see Expr::Builtin(Builtin::PathNoArg) => Ok(Some(OwnedValue::Array(..))) in eval_generic.rs), never any other shape (#798)
src/bin/succinctly/yq_runner.rs tolerate 3467 both unreachable: resolve_meta_assign_writes runs expr through this before any evaluation begins (see its own doc comment), and Expr::Shared is never constructed by the parser -- only at eval time, by function-call argument substitution (substitute_func_param in eval.rs) -- so a pre-evaluation AST can never contain one here (#798)
src/bin/succinctly/yq_runner.rs tolerate 4123 both unreachable: every arm of the match result { .. } above that assigns docs (L3492-3622) constructs Ok(..) -- none ever produces Err, so this if let's implicit else can't be taken; symmetric to L1625's ? (#798)
src/bin/succinctly/yq_runner.rs tolerate 6936-6938 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 7127-7132 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/bin/succinctly/yq_runner.rs tolerate 7892-7897 both unreachable: this whole _ => arm is dead code -- root.value() always reports the virtual document sequence, so single-document YAML never falls through here (documented above, verified in d4c03a6); only the formatting changed when is_falsy() dropped its JsonConvention parameter (#3222)
src/jq/document.rs tolerate 406 both unreachable: the only caller, eval_generic::embed_at_or_within, is gated on jq semantics, and the YAML cursor (the one implementor without an override) is only ever evaluated under yq semantics (#3179)
src/jq/document.rs tolerate 1096-1100 both unreachable: both implementors (JsonCursor, YamlCursor) override this; the default exists as the conservative-false contract a future implementor inherits (#3222)
src/jq/document.rs tolerate 1275-1282 both unreachable: both implementors (StandardJson, YamlValue) override this to decode once; the default exists as the contract a future implementor inherits, and is deliberately the two-call sequence it replaces (#965)
src/jq/eval.rs tolerate 1217 both unreachable: def is always a collect_alias_groups anchor path, which step_to_expr never fails on (#1351)
src/jq/eval.rs tolerate 1238 both unreachable: redirect_paths with Redirect::SINGLE always contributes exactly one output per input, so a 1-element paths always pops Some (#1351)
src/jq/eval.rs tolerate 1247 both unreachable: a concrete setpath/delpaths path's components are always Field/Index -- step_to_expr never produces another shape (#1351)
src/jq/eval.rs tolerate 1251 both unreachable: the map above never yields None, since it only ever matches Field/Index (#1351)
src/jq/eval.rs tolerate 1785 both unreachable: key_or_parent_root_construct's identical structural match already refused any expr shape that would reach this arm
src/jq/eval.rs tolerate 2357 both unreachable: same invariant as the tolerated line below (#3069)
src/jq/eval.rs tolerate 2358 both unreachable: same invariant as the tolerated line below (#3069)
src/jq/eval.rs tolerate 2360 both unreachable: a bridge document is its source's serialization, so the node at each recorded position is the recorded kind (#3069)
src/jq/eval.rs tolerate 2361 both unreachable: see the debug_assert above (#3069)
src/jq/eval.rs tolerate 2407 both unreachable: a scalar has no children, and node lies inside the subtree the walk is in (#3069)
src/jq/eval.rs tolerate 4971 both unreachable: is_escape() is exactly `Error
src/jq/eval.rs tolerate 4972 both unreachable: see the if let above -- push_owned_values never answers None for an is_escape() result (#2180)
src/jq/eval.rs tolerate 6240 both unreachable today: to_owned's only failures are is_decode_failure()-tagged, and suppresses() answers false for those whatever optional is -- the same defensive-but-dead arm eval_generic's own Builtin::Path materialization documents under #2280 (#2908)
src/jq/eval.rs tolerate 7119 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 8504 both unreachable: optional is never true here. eval_each is entered with a forced true at exactly one site (Expr::Optional over an IndexExpr/SliceExpr), and both of those evaluate their target (eval_index_expr) and their key (eval_each(key, .., false)) with a hardcoded false, so only the final index/slice step ever sees it -- nothing carries it down to an Expr::Object (#2180)
src/jq/eval.rs tolerate 9790 both unreachable: owned_write_door calls this only on a clone of a head write_target already matched, and the two list the same five variants (#3188)
src/jq/eval.rs tolerate 9804 both unreachable: every value path_over_owned hands back is a path() output, which is always an array (#3188)
src/jq/eval.rs tolerate 10088 both unreachable: any_child_witnessed is false for every non-container, checked just above (#3178)
src/jq/eval.rs tolerate 10280 both unreachable: the if above replaces every other state with Owned before this match
src/jq/eval.rs tolerate 10786 both reachable only on a genuine allocation failure: owned_assign_step's single-step arms map every non-allocation error to unreachable_owned_assign_write (provably impossible, see its own doc comment), and its Chain arm's set_path call walks exactly the steps owned_assign_step_child already validated as Field-into-Object/Null or Index-in-[0,len]-into-Array/Null with no mutation in between, so the only way set_path/set_field/set_index/pad_with_nulls can still fail is the same try_reserve-fails-under-OOM branch the codebase already tolerates elsewhere (#2267) (#3138)
src/jq/eval.rs tolerate 10906 both unreachable: owned_assign_shape's only caller (owned_step_shape) gates the call on is_owned_assign(expr), which recognizes exactly Assign/Update/CompoundAssign/AlternativeAssign -- the same four variants this match already has explicit arms for, so expr can never be anything else here (#3138)
src/jq/eval.rs tolerate 11106 both unreachable: both call sites (try_eval_owned_step, gated on is_owned_assign; eval_owned_reindex_free's own Assign
src/jq/eval.rs tolerate 11180 both unreachable: this function's own doc comment states why -- the borrow on state between owned_assign_step_child's check and the single write makes the container changing shape impossible, so debug_assert!(false, ..) can never fire (#3138)
src/jq/eval.rs tolerate 11181 both unreachable: same invariant as the false above -- this message is only ever formatted if that assert fires (#3138)
src/jq/eval.rs tolerate 11183 both unreachable: this function is only called from owned_assign_step's single-step arms, both of which the invariant above already rules out ever calling it for real (#3138)
src/jq/eval.rs tolerate 11184 both unreachable: the whole function body above is provably dead by the same borrow-checker invariant its doc comment states (#3138)
src/jq/eval.rs tolerate 11221 both unreachable: Expr::pipe() (the parser's sole Pipe constructor) collapses a one-element list to the bare inner expr instead of wrapping it, and substitute_vars's substitute_var walk preserves a Pipe's stage count rather than dropping stages -- no other site builds an Expr::Pipe for a parsed assignment path, so a path's top-level Pipe here is never single-element (#3138)
src/jq/eval.rs tolerate 14402 both unreachable: every entry point supplies path context, so path never evaluates without one; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 14535 both unreachable: only ever constructed by builtin_sort_keys's own eval_update_no_vivify call, whose enclosing eval_update_impl already runs to_owned on the whole document up front (#2855) -- a decode failure anywhere raises there, before this filter ever sees a value to re-decode; confirmed live, sort_keys(.a)/sort_keys(..) on a document with a decode-failure subtree both raise from the outer to_owned
src/jq/eval.rs tolerate 14678-14680 both unreachable: builtin_length's sole caller is eval_builtin's Builtin::Length dispatch, and Length is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before this match ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 14901-14903 both unreachable: has_one_key's sole caller is builtin_has (via eval_builtin's Builtin::Has dispatch), and Has is in builtin_operand_is_input, so eval_builtin's own top-of-function guard already returns the identical decode_failure for an Error value before builtin_has ever runs; kept as this function's own contract in case a future caller reaches it directly (#3222)
src/jq/eval.rs tolerate 18188 both unreachable: entry is one of to_entries's already-materialized {key,value} pairs, so its depth here is provably no deeper than whatever earlier check let it exist -- a document-decoded entry is already <256 deep (MAX_NESTING_DEPTH, stricter than this 384 guard), and a filter-constructed one already survived becoming a cursor via its own whole-object reindex, which is strictly deeper than any single field extracted from it could be (unwrapping only reduces depth); confirmed live, {a: (reduce range(400) as $i (0; [.]))}
src/jq/eval.rs tolerate 26102 both unreachable: escape_with_prefix! sets terminal before Demand::Stop; already returned above (#2138)
src/jq/eval.rs tolerate 26198 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval.rs tolerate 26199 both unreachable in a test: see the line above (#1634)
src/jq/eval.rs tolerate 26205-26208 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval.rs tolerate 26223-26228 both unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval.rs tolerate 28307 both unreachable via --eval-all: every document here comes straight from parse_input, whose own MAX_NESTING_DEPTH (256) guard already rejects anything deep enough to reach MAX_VALUE_TREE_DEPTH (384) here -- confirmed live, a 300-level document fails parse_input's guard before ever reaching this reindex (#3261)
src/jq/eval.rs tolerate 28638 both unreachable: eval_assign returns collect_assign for JqSemantics before this point, and yq_prepare_assign_targets is Some for every YqSemantics call (#3448)
src/jq/eval.rs tolerate 30240 both unreachable: eval_compound_assign/eval_alternative_assign return collect_assign for JqSemantics before this point, and yq_prepare_assign_targets is Some for every YqSemantics call (#3448)
src/jq/eval.rs tolerate 30567-30570 both unreachable: a materialization only ever raises a decode failure, which suppresses never swallows -- debug_assert_materialization_error (#2334) asserts exactly that; kept so the one classification rule is applied here as at every sibling to_owned site (#1953, #3448)
src/jq/eval.rs tolerate 30580-30583 both unreachable: assign_pristine is to_owned, which only ever raises a decode failure (#2334's debug_assert_materialization_error), and suppresses never swallows one; kept so the one classification rule is applied here as at every sibling to_owned site (#1953, #3448)
src/jq/eval.rs tolerate 30718 both unreachable: the eager route runs only when the path resolves to at most one path -- needs_path_prepass false is one verbatim path, and true with resolves_to_at_most_one_path is at most one resolved path (#2976) -- so no path is ever followed by another; kept as the loop's own contract (#3448)
src/jq/eval.rs tolerate 31799 both unreachable: descriptor_path_component builds a Verbatim key only from an object (#3300)
src/jq/eval.rs tolerate 32368 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval.rs tolerate 35726 both unreachable: an anchor is always a proper ancestor, so it records at least one step (#3134)
src/jq/eval.rs tolerate 37006 both reachable only on a genuine allocation failure: Vec::try_reserve(1) on a vector that has spare capacity, or can grow, cannot fail -- this is the whole purpose of the branch, converting an OOM into a catchable error rather than an abort (ADR-0018's 'would take the host process down' exception). The pre-#2267 form of the same guard, out.try_reserve(branches.len()) in resolve_index_expr/resolve_slice_expr, was 0-hit for the identical reason (#2267)
src/jq/eval.rs tolerate 37007 both see the line above -- the Demand::Stop half of the same allocation-failure-only branch (#2267)
src/jq/eval.rs tolerate 37013 both reachable only when the try_reserve above failed, i.e. only on a genuine allocation failure (#2267)
src/jq/eval.rs tolerate 39985 both unreachable: owned_value_jq_length's own match only ever constructs OwnedValue::Int or OwnedValue::Float, checked just above this arm (#2744)
src/jq/eval.rs tolerate 40040 both unreachable: owned_value_jq_length's own match only ever constructs OwnedValue::Int or OwnedValue::Float, as in the Reverse arm of builtin_navigation (#3888)
src/jq/eval.rs tolerate 40981 both unreachable: is_primitive admits only Identity/Field/Index/Slice, and of those only a Slice's computed bounds can halt -- all four have their own arm in resolve_node_sink/resolve_node_eager, so none reaches this function. Pre-existing; #2694 only wrapped the return in Some (#2694)
src/jq/eval.rs tolerate 41015 both unreachable, as this arm's own comment above says: indexing or slicing a value yields zero or one result, so is_primitive never produces more than one -- kept as a named error rather than a panic. Pre-existing; #2694 only wrapped the enclosing return in Some (#2694)
src/jq/eval.rs tolerate 41794 both unreachable: a cond that flattens to no stages is . or a pipe of ., which cannot_move_register admits, so it never takes the live route (#3757); the debug_assert where stages is built fails a test build that breaks that
src/jq/eval.rs tolerate 46502 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 48066 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), returned just above (#2872)
src/jq/eval.rs tolerate 48949 both unreachable: every arm of the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 49528 both unreachable: every path through the loop's last iteration returns -- a walk refusal, an exhausted walk, and a step outcome that never retries on the last alternative (#2979, #2872)
src/jq/eval.rs tolerate 52757 both unreachable in a passing suite by design -- a panic-message format argument for the #682 single-valued-tail pin, evaluated only if that assert's own condition is false (#2190)
src/jq/eval.rs tolerate 52834 both unreachable: the only caller reaches this after classify_static_component answered Field for this same value, which it does only for an object (#2190)
src/jq/eval.rs tolerate 52878 both unreachable: both callers establish the container first -- navigate_static_component_ref via classify_static_component's Index arm, and walk_path's Expr::Iterate arm by matching on the container itself (#2190)
src/jq/eval.rs tolerate 55859 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 57602 both unreachable: stop_with_escape's only write is slot.set(Some(control)) with the control it was handed, which is always the Control::Error built one line above (#2180)
src/jq/eval.rs tolerate 58293 both unreachable: on_update records a step_outcome before every Demand::Stop it answers, and the fallback match runs only when it recorded none (#2872)
src/jq/eval.rs tolerate 58333 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval.rs tolerate 59260 both unreachable by construction: the per-fork match only ever hands stop_with_downstream a non-Exhausted flow, so terminal can never hold Exhausted (#2899)
src/jq/eval.rs tolerate 61600 both llvm-cov line-attribution artifact, not unreachable: the new gate test above (Builtin::Length as first) demonstrably takes key_or_parent_root_construct(first) == false and falls through to the reindex-bridge route below, passing -- but this closing brace, like the one at #56920 for the same reason, is never itself credited a hit
src/jq/eval.rs tolerate 61614 both unreachable in the current test suite: eval_path_context_pipe_owned itself has zero total call-site coverage today (not just this arm), confirmed by a full-suite eprintln probe across every test binary -- reaching its error arm needs first solving how to reach the function at all, out of scope for #3261's reindex-bridge fix
src/jq/eval.rs tolerate 62688 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 62694 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval.rs tolerate 64814 both pre-existing zero-hit line; #2999 changed only which null constant it names
src/jq/eval.rs tolerate 67231 both ? suppresses mktime's error outside builtin dispatch, so the optional flag is false even for an invalid date (#3083)
src/jq/eval.rs tolerate 67234 both unreachable for mktime's C-int-clamped fields: checked civil-date arithmetic stays within i64; the guard protects other callers of the shared helpers (#3083)
src/jq/eval.rs tolerate 67423 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 67426 both defensive, unreachable via ordinary JSON parsing (#3068)
src/jq/eval.rs tolerate 67471 both optional is never true through either caller of this function -- confirmed live (eprintln! probe): `[1,2,3]
src/jq/eval.rs tolerate 67480 both every array literal written in filter source, and every array-element JSON parses, decodes to NumberLiteral (#1035), not a bare Int -- Int is for internally-synthesized values spliced post-parse; probed a computed element ([1970,(0+0),..]) and it still decoded as NumberLiteral here, so this arm has no known real producer (#3068)
src/jq/eval.rs tolerate 67516 both optional is never true through either caller of this function, same as the array-length check above (#3068)
src/jq/eval.rs tolerate 67580 both unreachable for strftime's C-int-clamped fields and bounded zone offset; shared checked date helpers retain overflow guards for other callers (#3083)
src/jq/eval.rs tolerate 67736 both llvm-cov line-attribution artifact, not unreachable: the call's own argument lines (immediately above) show 3 hits under the #3055 test's three E/O pass-through rows, but this closing-token line is never itself credited -- verified via the raw lcov DA: records
src/jq/eval.rs tolerate 68926 both unreachable: YamlIndex::root always wraps the documents in a virtual root sequence, so the arm above takes every input (#2664)
src/jq/eval.rs tolerate 68927 both unreachable: the same defensive arm as the line above (#2664)
src/jq/eval.rs tolerate 69239 both unreachable from combinations, whose own empty-input return runs first; pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval.rs tolerate 70343 both confirmed live (eprintln! probe): optional is always false in builtin_abs regardless of whether the filter writes abs?, since that suppression happens entirely outside builtin dispatch here -- the same 'optional is never true here' shape eval.rs already documents elsewhere (#2180) (#3041)
src/jq/eval.rs tolerate 72401 both unreachable: the sink is a plain collector that always answers Demand::Continue (#2872)
src/jq/eval.rs tolerate 72511 both unreachable: optional: false makes index_one_owned answer Ok(Some)/Err only (#2872)
src/jq/eval.rs tolerate 72816 both unreachable: pattern_has_computed_key is false for Pattern::Var, so the loop walker above always takes it (#2872)
src/jq/eval.rs tolerate 72864 both unreachable: every caller gates on pattern_has_computed_key being false (#2872)
src/jq/eval.rs tolerate 74560 both unreachable: bind_def_call only calls this for a non-empty params, install_def_calls only builds a DefCall whose args.len() equals params.len(), and the last parameter is never shadowed, so at least one entry is always built (#2560)
src/jq/eval.rs tolerate 75974 both unreachable in a passing suite by design -- this panic only fires if eval_owned_reindex_free declined a shape this loop's own handled table asserts is always answered (#3138)
src/jq/eval.rs tolerate 75983 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a shape this loop's own handled table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 76022 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step handled a shape this loop's own declined table asserts is always declined (#3138)
src/jq/eval.rs tolerate 76043 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on a yq shape this loop's own table asserts is always answered Ok (#3138)
src/jq/eval.rs tolerate 76143 both unreachable in a passing suite by design -- this panic only fires if the tracked \
src/jq/eval.rs tolerate 76145 both unreachable in a passing suite by design -- this panic only fires if state stopped being an Object, which every owned_assign_step write in the loop below preserves (#3138)
src/jq/eval.rs tolerate 76153 both unreachable in a passing suite by design -- this panic only fires if try_eval_owned_step declined or errored on the single-step shape this loop drives every iteration (#3138)
src/jq/eval.rs tolerate 76158 both unreachable in a passing suite by design -- this arm only fires if state stopped being an Object, which every write in the loop above preserves (#3138)
src/jq/eval.rs tolerate 76196 both unreachable in a passing suite by design -- this panic only fires if the tracked \
src/jq/eval.rs tolerate 76198 both unreachable in a passing suite by design -- this panic only fires if state stopped being an Object, which every owned_assign_step write in the loop below preserves (#3241)
src/jq/eval.rs tolerate 76216 both unreachable in a passing suite by design -- this arm only fires if state stopped being an Object, which every write in the loop above preserves (#3241)
src/jq/eval.rs tolerate 76293 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on the single closed assignment this test drives (#3241)
src/jq/eval.rs tolerate 76308 both unreachable in a passing suite by design -- both values are built as objects above and an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 76353 both unreachable in a passing suite by design -- doc builds an object (#3241)
src/jq/eval.rs tolerate 76361 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on the single closed assignment this test drives (#3241)
src/jq/eval.rs tolerate 76369 both unreachable in a passing suite by design -- an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 76402 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step declined or errored on a closed assignment this table asserts is always answered (#3241)
src/jq/eval.rs tolerate 76405 both unreachable in a passing suite by design -- an object assignment keeps its kind (#3241)
src/jq/eval.rs tolerate 76449 both unreachable in a passing suite by design -- this panic only fires if fold_step_each reported anything but an escape (not optional) or exhaustion (optional) for a failing owned step (#3241)
src/jq/eval.rs tolerate 76492 both unreachable in a passing suite by design -- this panic only fires if try_owned_assign_step answered an UPDATE holding an Expr::TrackedVar, which closed_expr_to_owned rejects (#3241)
src/jq/eval.rs tolerate 76520 both unreachable in a passing suite: every row below is a reduce or a foreach (#3329)
src/jq/eval.rs tolerate 76595 both unreachable in a passing suite: every row below is a reduce or a foreach (#3896)
src/jq/eval.rs tolerate 76916 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 76938 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 76956 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 77026 both substitute_var_impl's FuncDef arm always returns FuncDef (#2283)
src/jq/eval.rs tolerate 77044 both substitute_func_param_impl's FuncDef arm always returns FuncDef (#2555)
src/jq/eval.rs tolerate 85102 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval.rs tolerate 85261 both unreachable in a passing suite by design -- this is the failure message for the assertion the test exists to make (#2190)
src/jq/eval.rs tolerate 85641 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval.rs tolerate 86300 both unreachable in a passing suite: reports a failed test invariant (#3682)
src/jq/eval.rs tolerate 86515 both the no-std arm: `cfg!(feature = \
src/jq/eval.rs tolerate 87373 both unreachable in a passing suite: every source this helper parses starts with def f(n): ...; (#3296)
src/jq/eval.rs tolerate 87426 both unreachable in a passing suite: f(1) under def f(n) always installs as a DefCall, which the assert above has just settled (#3296)
src/jq/eval.rs tolerate 98894 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 98946 both unreachable in a passing suite by design -- this test's own diagnostic (#3102)
src/jq/eval.rs tolerate 99860-99871 both the closure is asserted never called below (on_update_calls stays 0) -- Err(_) with optional=true short-circuits fold_step_each before this sink runs (#3122)
src/jq/eval.rs tolerate 104712 both unreachable in a passing suite by design -- the door's sink never stops and it never breaks or halts (#3439)
src/jq/eval.rs tolerate 105410 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 107961 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval.rs tolerate 107970 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval.rs tolerate 107990 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval.rs tolerate 110482 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 110493 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 110510 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 110530 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 110538 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make
src/jq/eval.rs tolerate 111689 both unreachable in a passing suite by design -- this test's own diagnostic (#3071)
src/jq/eval.rs tolerate 113625 both unreachable in a passing suite by design -- check_value_tree_depth's only Err variant is EvalError, and From for EvalEscape always produces EvalEscape::Error (#3275)
src/jq/eval.rs tolerate 114230 both unreachable in a passing suite by design -- the failure message for the shape assertion the test makes (#3471)
src/jq/eval.rs tolerate 117734 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117776 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117781 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117816 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117837 both unreachable in a passing suite by design -- the failure arm of a #3704 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117940 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 117956 both unreachable in a passing suite by design -- the failure arm of a #3689 pin, only reached when the pin is already failing
src/jq/eval.rs tolerate 121492 both unreachable in a passing suite by design -- every filter this helper is called with parses to an AsPattern (#2649)
src/jq/eval.rs tolerate 121536 both unreachable in a passing suite by design -- a literal-key pattern's walk either completes or refuses with an error (#2872)
src/jq/eval.rs tolerate 121545 both unreachable in a passing suite by design -- every call site passes the origin of a binding this same test already proved carries a marker (#2649)
src/jq/eval.rs tolerate 121873 both unreachable in a passing suite by design -- the assertion above is the test (#2872)
src/jq/eval.rs tolerate 122573 both unreachable in a passing suite by design -- every row here is a shape jq accepts, confirmed live (#2649)
src/jq/eval.rs tolerate 122641 both unreachable in a passing suite by design -- every row here is a shape jq refuses, confirmed live (#2649)
src/jq/eval.rs tolerate 123026 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 123042 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the let-else pattern fails to match (#2072)
src/jq/eval.rs tolerate 123076 both unreachable in a passing suite by design -- this is the panic message for the #3069 pin itself, only formatted if the let-else pattern fails to match
src/jq/eval.rs tolerate 123093 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 123109 both unreachable in a passing suite by design -- this is the panic message for the #2072 pin itself, only formatted if the match doesn't hit the expected arm above (#2072)
src/jq/eval.rs tolerate 123126 both unreachable in a passing suite by design -- this is the panic message for the #3069 pin itself, only formatted if the match doesn't hit the expected arm above
src/jq/eval.rs tolerate 123212 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3037)
src/jq/eval.rs tolerate 123290 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3037)
src/jq/eval.rs tolerate 124174 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3135)
src/jq/eval.rs tolerate 124281 both unreachable in a passing suite by design -- every expression this closure receives is built by marker above (#3122)
src/jq/eval.rs tolerate 124299 both unreachable in a passing suite by design -- rewrite_markers rebuilds the same node kind it was given (#3122)
src/jq/eval.rs tolerate 124367 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 124371 both unreachable in a passing suite by design -- fires only if demote_for_reentry's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 124411 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 124415 both unreachable in a passing suite by design -- fires only if reroot's own let-else assertion condition is false (#3122)
src/jq/eval.rs tolerate 126153 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3119)
src/jq/eval.rs tolerate 126208 both unreachable in a passing suite by design -- this is the panic message for the assertion above, only formatted if the match doesn't hit the Error arm (#3127)
src/jq/eval.rs tolerate 128902 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#2937)
src/jq/eval.rs tolerate 128989 both unreachable in a passing suite by design -- every READERS filter raises a decode failure on every malformed json in this sweep, so this fallback never fires (#3222)
src/jq/eval.rs tolerate 128995 both unreachable in a passing suite by design -- see the concrete match above, same sweep (#3222)
src/jq/eval.rs tolerate 129001-129003 both unreachable in a passing suite by design -- this is the failure-recording line for the assertion below, only reached if a READERS filter fails to raise (#3222)
src/jq/eval.rs tolerate 129059 both unreachable in a passing suite by design -- none of NON_READERS ever raises through eval_with_cursor_using, on the malformed document or the well-formed one; kept so a filter that starts erroring is still comparable rather than panicking (#3222)
src/jq/eval.rs tolerate 129365 both unreachable in a passing suite by design -- every filter below builds an array (#3191)
src/jq/eval.rs tolerate 129372 both unreachable in a passing suite by design -- each element is built as {k: } (#3191)
src/jq/eval.rs tolerate 129374 both unreachable in a passing suite by design -- each element is built as {k: } (#3191)
src/jq/eval.rs tolerate 129476 both every pinned filter below yields an owned value; kept so a cursor answer still renders rather than panics (#2999)
src/jq/eval.rs tolerate 129477 both unreachable in a passing suite by design -- the failure message for the assertions this helper serves (#2999)
src/jq/eval.rs tolerate 129811 both unreachable in a passing suite: every corpus program starts with a def (#3307)
src/jq/eval.rs tolerate 129936 both unreachable in a passing suite: every corpus program's first node is a def (#3307)
src/jq/eval.rs tolerate 129973 both unreachable in a passing suite: the last def's call is bound (#3307)
src/jq/eval.rs tolerate 130135 both unreachable in a passing suite: every caller passes a def head (#3307)
src/jq/eval.rs tolerate 130211 both unreachable in a passing suite: chain builds a def head (#3307)
src/jq/eval.rs tolerate 130215 both unreachable in a passing suite: a 50-def chain has a second def (#3307)
src/jq/eval.rs tolerate 130311 both unreachable in a passing suite: spine_node builds a def head (#3307)
src/jq/eval.rs tolerate 130372 both unreachable in a passing suite: the loop above builds a def (#3307)
src/jq/eval.rs tolerate 130380 both unreachable in a passing suite: the main filter is a pipe (#3307)
src/jq/eval.rs tolerate 130384 both unreachable in a passing suite: stages 0 and 2 are the spliced arguments (#3307)
src/jq/eval_generic.rs tolerate 1241 both unreachable: validate_cursor, CheckOnly's only instantiation, passes no nested nodes, so the walk never asks (#3179)
src/jq/eval_generic.rs tolerate 4634 both unreachable: the decode above replaced every cursor with an owned value, or returned an error that skips this block (#3856)
src/jq/eval_generic.rs tolerate 5165 both unreachable: the sole remaining caller (retain_truthy_generic's Many arm) runs to_owned on an item before keeping it, so re-converting a kept item here cannot fail; the ManyCursor caller that made this reachable went with the truthiness walk (#2692, re-establishing #2661's premise)
src/jq/eval_generic.rs tolerate 7217 both unreachable: hi is find_close of a container's own open paren, which a built index always matches (#3179)
src/jq/eval_generic.rs tolerate 8149 both unreachable for the one format that claims materializes_members_one_to_one: a JSON object's children always pair key-then-value; kept so an implementor whose mapping could end on a key declines instead of miscounting (#3483)
src/jq/eval_generic.rs tolerate 8166 both unreachable for JSON: a key node always decodes or falls back to its raw spelling, so key_display_string is Some; kept so a format whose key can be non-string declines to the generic walk (#3483)
src/jq/eval_generic.rs tolerate 8377 both unreachable: the climb starts at a container (embed_at_or_within's is_container gate) and only ever moves to a parent, which is a container too, and a key is a leaf -- no node on the climb can be a key; kept as a refusal rather than a panic (#3897)
src/jq/eval_generic.rs tolerate 8406 both unreachable: materializes_members_one_to_one holds, so the value held for a node is an array exactly when the node is a sequence and an object exactly when it is a mapping, and the step the climb recorded is an index for the first and a string key for the second; kept as a refusal rather than a panic (#3897)
src/jq/eval_generic.rs tolerate 10309 both unreachable: this loop is entered only with a LazyKeys/LazyIndexRange/LazySeq head, and every fold_lazy_*_stage answers OneCursor, Owned, ManyOwned or a lazy marker (eval_on_owned never returns One); kept so a stage that did return One hands off by value instead of falling to the eager fold (#1565, #3886)
src/jq/eval_generic.rs tolerate 10828 both unreachable in a passing suite by design -- this is the panic message for the #2368 pin itself, only formatted if the assert's own condition is false (#2368)
src/jq/eval_generic.rs tolerate 10889 both unreachable: this arm's own match guard already evaluated value.as_array().is_some_and(..) as true to be here at all, and as_array() is a pure read of value -- the second call inside the body can never answer None where the guard's own call just answered Some
src/jq/eval_generic.rs tolerate 12800 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 12817 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 13376 both unreachable: a step from a live node emits only live children (#3023)
src/jq/eval_generic.rs tolerate 14292 both unreachable: every Demand::Stop the sink answers is preceded by outcome = Some(..), handled just above (#2872)
src/jq/eval_generic.rs tolerate 16118 both unreachable: every producer that reaches this empty-exprs tail (each_lazy_keys_iterate_sink's sorted/!sorted arms, each_lazy_index_range_iterate_sink, each_lazy_seq_iterate_sink) yields OneCursorValue/OneCursor/Owned, never a cursorless GenericItem::One -- so cursor is always Some here; kept for exhaustiveness/symmetry with the Some arm (#2103)
src/jq/eval_generic.rs tolerate 17935 both unreachable: each_negate_generic pushes only GenericItem::Owned (arith_negate's result), which converts infallibly (#3410)
src/jq/eval_generic.rs tolerate 18517 both unreachable: is_escape() is exactly `Error
src/jq/eval_generic.rs tolerate 18518 both unreachable: see the if let above -- push_generic_owned_values never answers None for an is_escape() result (#2180)
src/jq/eval_generic.rs tolerate 19616 both unreachable: escape_generic!/ensure_owned! set terminal before Demand::Stop; already returned above (#2138)
src/jq/eval_generic.rs tolerate 19742 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval_generic.rs tolerate 19743 both unreachable in a test: see the line above (#1634)
src/jq/eval_generic.rs tolerate 19749-19752 both unreachable in a test: needs the allocator to refuse a one-element growth of the collector (#1634)
src/jq/eval_generic.rs tolerate 19768-19773 both unreachable: every consumer that records a wrapping stop resets it per invocation (#3293), so a stash-less Stopped needs one that regresses
src/jq/eval_generic.rs tolerate 20303-20307 both unreachable: this function's sole caller, slice_one_generic_computed, already runs the identical unreadable_value_error(&target) check on the same target and returns before ever calling here; kept as this function's own contract in case a future literal-bounds caller reaches it directly (#3222)
src/jq/eval_generic.rs tolerate 20762 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 20772 both unreachable by construction: key_elements_generic builds every key of a run from the same Option<&Expr> (#2999)
src/jq/eval_generic.rs tolerate 21523 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 21556 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21604 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21672 both unreachable: both step dispatchers route owned nodes to path_step_owned before calling this cursor helper (#3022)
src/jq/eval_generic.rs tolerate 21688 both unreachable: effective_fields_checked already rejects key_is_malformed, the same decoded_key_str Ok(None) that makes key_display_string return None (#3022)
src/jq/eval_generic.rs tolerate 21834 both unreachable: both callers match Field, Index or Iterate before dispatching here (#3022)
src/jq/eval_generic.rs tolerate 23410 both unreachable: len_checked and SliceBounds::resolve already bound every index in range to [0, len), so get_cursor cannot miss (#2168)
src/jq/eval_generic.rs tolerate 26805 both unreachable by construction: path_context_resolvable admits an any(cond) read only through admits.prefetch, so the rewriter always has one -- the AnyCond arm above carries the identical assertion (#3079)
src/jq/eval_generic.rs tolerate 26809 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 26810 both unreachable by construction, see above
src/jq/eval_generic.rs tolerate 27181 both unreachable: the callback records downstream_flow before every Demand::Stop, and that flow is returned above (#3022)
src/jq/eval_generic.rs tolerate 27679 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 27700 both pre-existing zero-hit line; #2999 changed only how its array payload is constructed
src/jq/eval_generic.rs tolerate 28069 both unreachable: malformed_object_member above already proved every key stringifies (the None half), and to_owned_cursor on an untagged key decoded_key_str decoded cannot fail (the Err half) (#2785)
src/jq/eval_generic.rs tolerate 28150 both unreachable: map(f) over an array emits exactly one array; kept so a future map shape produces no output rather than a panic (#2785)
src/jq/eval_generic.rs tolerate 28488 both unreachable by design -- eval_single's #2368 debug_assert forbids optional=true on Builtin::Reverse, so length never answers None here (#2730)
src/jq/eval_generic.rs tolerate 28887 both unreachable: to_owned_with_cursor of a document number literal cannot fail, so the macro's error arms never run (#3191)
src/jq/eval_generic.rs tolerate 29144 both the CLI evaluates every program that uses input/inputs on the eager route (jq_runner's can_use_lazy_path excludes them), so this guard never fires today -- #2968's identical guards on the arms above are equally unfired; kept for the day the lazy path admits such a program (#1309)
src/jq/eval_generic.rs tolerate 29150 both see above: the input-queue deferral never fires from the CLI
src/jq/eval_generic.rs tolerate 30639 both unreachable by construction: every shape either guard admits now has an arm above (#2771), and expr_dispatch_catchall_guards_default_conservatively_2549 pins both guards' _ => false defaults directly
src/jq/eval_generic.rs tolerate 31295 both unreachable in a passing suite by design -- owned_identity_rule maps a bare Expr::Var to Bound too (for the static gate, which sees a body before its as substitution runs), but every runtime dispatch that reaches this rule (owned_identity_after_stage/owned_identity_placed_by, from owned_identity_leaving_cursor's Bound arm) only ever sees a stage after eval_owned_identity_as's unconditional substitute_bound_var_from call, which always turns $x into Expr::TrackedVar before recursing -- confirmed by running the full suite with this arm replaced by a hard panic!(), which never fired (#2072)
src/jq/eval_generic.rs tolerate 31313 both unreachable: this Slice rule's own two execution paths both exclude Expr::Slice before ever reaching owned_identity_placed_by -- eval_owned_identity_stages's catch-all only runs a stage owned_identity_nav_supported refused, and owned_identity_leaving_cursor (identity_from_first, eval_generic.rs:10724) only runs a stage path_context_is_navigational refused -- and both predicates admit Expr::Slice (owned_identity_nav_supported/path_context_is_navigational_at each list Expr::Slice { .. } => true), so a bare slice is always resolved by owned_identity_step's own arm first. Kept in owned_identity_rule's match for exhaustiveness/symmetry with the rule table's other entries, the same reason #2072's Bound arm above is kept unreachable-by-construction (#2966's review of #2834)
src/jq/eval_generic.rs tolerate 31409 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval_generic.rs tolerate 31782 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/eval_generic.rs tolerate 32843 both unreachable: the arm's or-pattern admits Expr::Limit, Builtin::Skip and Builtin::NthStream only, and each has its own arm above (#3610)
src/jq/eval_generic.rs tolerate 32939 both optional is never true through this pipe: ? is eval_owned_identity_try, which catches the escape instead, and after #693 only the IndexExpr/SliceExpr special case ever sets it -- kept as any_all_f's scalar_fallback mirror
src/jq/eval_generic.rs tolerate 32940 both optional is never true here, see above
src/jq/eval_generic.rs tolerate 33364 both unreachable in a passing suite by design -- the failure message for the assertion the tests below make (#2999)
src/jq/eval_generic.rs tolerate 33611 both unreachable in a passing suite by design -- the fixture's map(.+1) is always a LazySeq; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 33639 both unreachable in a passing suite by design -- the fixture's only escape is Control::Error; this arm is the test's own diagnostic (#2666)
src/jq/eval_generic.rs tolerate 33944 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3261)
src/jq/eval_generic.rs tolerate 38995 both failure message for the assertion this #3222 test exists to make
src/jq/eval_generic.rs tolerate 40051 both unreachable in a passing suite by design -- the failure message for the shape assertion the test makes (#3471)
src/jq/eval_generic.rs tolerate 43931 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 43988 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 44015 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 44049 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 44167 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/eval_generic.rs tolerate 44746 both unreachable in a passing suite: reports a failed test invariant (#3477)
src/jq/eval_generic.rs tolerate 44749 both unreachable in a passing suite: reports a failed test invariant (#3477)
src/jq/eval_generic.rs tolerate 44778 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44785 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44798 both unreachable in a passing suite: [x] always builds an array (#3856)
src/jq/eval_generic.rs tolerate 44823 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44830 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44854 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44879 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44911 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44923 both unreachable in a passing suite: reports a failed test invariant (#3856)
src/jq/eval_generic.rs tolerate 44959 both unreachable in a passing suite: reports a failed test invariant (#3815)
src/jq/eval_generic.rs tolerate 45315 both unreachable in a passing suite: reports a failed test invariant (#3923)
src/jq/eval_generic.rs tolerate 45323 both unreachable in a passing suite: reports a failed test invariant (#3923)
src/jq/eval_generic.rs tolerate 45388 both unreachable in a passing suite by design: a panic message, formatted only if the walk's failure were not a plain Error (#3478)
src/jq/eval_generic.rs tolerate 45392 both no document here answers a plain Error since #3478 (the walk is the consumer's); kept so a future eager walk reports its own message instead of falling to the arm below, which swallows it
src/jq/eval_generic.rs tolerate 45408 both unreachable: [., .] holds only document nodes, so no pulled element is an owned value (#3856)
src/jq/eval_generic.rs tolerate 47056 both unreachable in a passing suite by design -- the failure arm of a #3722 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47110 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47114 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47117 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47173 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47253 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47268 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47291 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47312 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 47478 both unreachable in a passing suite by design -- the failure arm of a #3702 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47682 both unreachable in a passing suite by design -- the failure arm of a #3702 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47737 both unreachable in a passing suite by design -- the failure arm of a #3839 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 47741 both unreachable in a passing suite by design -- the failure arm of a #3839 pin, only reached when the pin is already failing
src/jq/eval_generic.rs tolerate 48429 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48451 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48458 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48536 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48587 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48648 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48684 both unreachable in a passing suite: this panic reports a failed test invariant (#3022)
src/jq/eval_generic.rs tolerate 48693 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 48694 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 48695 both unreachable in a passing suite: yq rolls back every position before this sink, as the zero-count assertion verifies (#3022)
src/jq/eval_generic.rs tolerate 49657 both unreachable in a passing suite by design -- a panic-message format argument for the #3483 differential test's own assertion, evaluated only if that assert's own condition is false (#3483)
src/jq/expr.rs tolerate 3411 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/expr.rs tolerate 3427 both unreachable in a passing suite: reports a failed test invariant (#3673)
src/jq/lazy.rs tolerate 657 both pre-existing zero-hit line; #3191 changed only how its string payload is constructed
src/jq/lazy.rs tolerate 1474 both failure message for the shape the test asserts
src/jq/parser.rs tolerate 246 both unreachable: parse_join_expr only calls join_expr with two to four arguments (#3046)
src/jq/parser.rs tolerate 268 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 270 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 272 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 279 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 283 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 313 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 317 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 326 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 328 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 330 both unreachable: is_join_pair just matched this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 345 both unreachable: join_expr builds only this shape, and only join_expr names JOIN_IDX_VAR, which no program can spell (#3046)
src/jq/parser.rs tolerate 10245 both unreachable in a passing suite by design -- this is the panic message for the #3044 pin itself, only formatted if the let-else pattern fails to match (#3044)
src/jq/resolve.rs tolerate 921 both unreachable by construction: every plain entry was listed under its name when it was pushed
src/jq/resolve.rs tolerate 924 both unreachable by construction: every plain entry was listed under its arity when it was pushed
src/jq/resolve.rs tolerate 974 both unreachable by construction: FnScope::floor only ever names a begin marker
src/jq/resolve.rs tolerate 2684 both unreachable by construction: this match is only entered when is_marker (marker.is_some()) is true, and RunMarker has only Begin/End variants -- the None arm exists solely for exhaustiveness against Option's type
src/jq/resolve.rs tolerate 2959 both unreachable in practice today: this arm needs builtin_fallback==None (the name was never a shadow candidate) yet is_jq_builtin==true (a real jq builtin at this arity) -- every implemented builtin's own dedicated parse already lowers that shape to Expr::Builtin before resolve.rs ever runs, and #3042/#3046 closed the once-real 'unimplemented builtin' gap this existed for (see JQ_BUILTIN_ROSTER's own doc comment)
src/jq/resolve.rs tolerate 2961 both unreachable with the current roster: every JQ_BUILTIN_ROSTER entry of arity >= 1 already has a dedicated parser form (a matches_keyword special case or a Libm1/Libm2/Libm3::ALL entry -- confirmed by cross-referencing the full roster against both), so it is parsed straight to Expr::Builtin and never reaches here as a bare FuncCall. This arm exists for a roster name with no dedicated parse yet and a nonzero arity -- there is none today, so the loop body is reached with an empty args on every pinned-suite run (355 hits on the arm's own condition, 0 in the loop) and would only start executing if such a name were added (#2964)
src/jq/share_stats.rs tolerate 105 both process-global env var; exercised by the CLI audit run, not by an in-process test (#2999)
src/jq/value.rs tolerate 365 both unreachable by construction: the slow path is entered only after significant_digit_count found 18+ digits over the same mantissa bytes this loop walks (#2936)
src/jq/value.rs tolerate 389 both unreachable by construction: 18+ significant digits were counted, so at least one nonzero digit was kept (#2936)
src/jq/value.rs tolerate 2906 both unreachable by construction -- the block above replaces every Shared with Owned before this line (#3191)
src/jq/value.rs tolerate 3278 both unreachable: format_float_with_fraction of a finite double is always RFC 8259 number text, which parse_i64_or_f64 reads (#2936)
src/jq/value.rs tolerate 5976 both unreachable in a passing suite by design -- built as a string on the line above (#3191)
src/jq/value.rs tolerate 5985 both unreachable in a passing suite by design -- built as a number literal on the line above (#3191)
src/jq/value.rs tolerate 6126 both unreachable in a passing suite by design -- every caller built the value as an array (#2999)
src/jq/value.rs tolerate 6369 both unreachable in a passing suite by design -- the value was built as this container a few lines above (#2999)
src/jq/value.rs tolerate 7191 both unreachable in a passing suite by design -- the failure message for a malformed oracle table (#2936)
src/jq/value.rs tolerate 7580 both failure message for the assertion the calling test makes
src/jq/value.rs tolerate 7912 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 7921 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 7929 both failure message for the assertion this #3069 test exists to make
src/jq/value.rs tolerate 8070 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 8076 both failure message for the assertion this #3034 test exists to make
src/jq/value.rs tolerate 8188 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/jq/value.rs tolerate 9304 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/jq/value.rs tolerate 9322 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make (#3281)
src/jq/value.rs tolerate 9855 both unreachable in a passing suite by design -- this is the failure message for the assertion this test exists to make: the two serializers disagreeing on whether a nest is too deep (#3479)
src/jq/walk.rs tolerate 796 both unreachable: ArrayKey is only built from a resolved key at path-resolution time, never parsed, so no rewrite of parsed source meets it (#3506)
src/json/light.rs tolerate 2810-2816 both unreachable in practice: UNMEASURED_SPAN only arises when end - text_pos in number_at overflows u32 -- a single number span >= 4 GiB -- which no realistic (or practically constructible) test document approaches (#3222)
src/json/light.rs tolerate 3619 both reachable only through a bare 64-bit hash collision between keys the pairwise scan already proved distinct
src/json/light.rs tolerate 9548 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9630 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9719 both unreachable in a passing suite by design -- the failure message for the assertion this #2877 test exists to make
src/json/light.rs tolerate 9752 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9781 both failure message for the assertion this #3034 test exists to make
src/json/light.rs tolerate 9869 both unreachable in a passing suite by design -- this is a panic-message format argument for the #3222 sweep's own assertion, only evaluated if the assert's own condition is false (#3222)
src/json/light.rs tolerate 9874 both unreachable in a passing suite by design -- see the assert_eq! format argument above, same sweep (#3222)
src/json/light.rs tolerate 9900 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9911 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 9992 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/json/light.rs tolerate 10016 both unreachable in a passing suite: every caller passes an object (#3180)
src/json/light.rs tolerate 10022 both unreachable in a passing suite: every caller passes an array (#3180)
src/json/light.rs tolerate 10112 both unreachable in a passing suite by design -- panic-message format argument (#3180)
src/util/simd/x86.rs tolerate 208-258 both CPU-gated: the avx512f early-return only executes on Zen 4+ / Skylake-X runners, and its absence changes which AMD/Intel branch below executes too (#2449)
src/yaml/index.rs tolerate 1296 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1300 both unreachable: every fixture field_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1311 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1313 both unreachable: every call to field_key_head_foot in this test module passes a key that the fixture's mapping actually has (#798)
src/yaml/index.rs tolerate 1323 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1327 both unreachable: every fixture seq_item_head_foot is called with in this test module is a top-level sequence (#798)
src/yaml/index.rs tolerate 1350 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1369 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1392 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1401 both unreachable: every fixture field_key_head_foot_in_doc is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1412 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1414 both unreachable: every call to field_key_head_foot_in_doc in this test module passes a key that the fixture's document actually has (#798)
src/yaml/index.rs tolerate 1425 both unreachable: YamlIndex::build always wraps the parsed document(s) in a virtual root Sequence, at TY index 0 (#798)
src/yaml/index.rs tolerate 1429 both unreachable: every fixture nested_key_head_foot is called with in this test module is a top-level mapping (#798)
src/yaml/index.rs tolerate 1433 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this let-else's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1439 both unreachable: every fixture nested_key_head_foot is called with has a nested mapping under outer (#798)
src/yaml/index.rs tolerate 1450 both unreachable: a mapping key is always emitted as YamlValue::String -- it is never type-inferred like a value (#222), so this if-let's pattern can never fail to match (#798)
src/yaml/index.rs tolerate 1453 both unreachable: every call to nested_key_head_foot in this test module passes an outer.inner pair that the fixture actually has (#798)
src/yaml/light.rs tolerate 3372 both unreachable: an alias target is never None for a built index (#1374)
src/yaml/light.rs tolerate 15479 both unreachable in a passing suite by design -- the fixture above is a block sequence (#2640)
src/yaml/light.rs tolerate 15506 both unreachable in a passing suite by design -- the fixture above is a block mapping (#2640)
src/yaml/light.rs tolerate 16243 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 16254 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/light.rs tolerate 16411 both unreachable in a passing suite by design -- this is a panic-message format argument for the #2072 pin itself, only evaluated if the assert's own condition is false (#2072)
src/yaml/parser.rs tolerate 1583 both unreachable: every block-sequence open registers a frame at its own depth before any item of it can be parsed (#1079)
src/yaml/parser.rs tolerate 1613 both unreachable: this function's sole caller (record_standalone_comment) only invokes it from inside a match on pending_head_lines.last(), so pending_head_lines is already known non-empty here (#798)
src/yaml/parser.rs tolerate 8013 both unreachable: every byte here already passed the [0-9.eE+-] charset check above, a strict subset of ASCII, so str::from_utf8 can never fail (#2778)

Excluded by ignore-filename-regex: 1 file (none of them touched by this diff).

Patch coverage

Patch: 98.48% (65/66 new lines covered)

File Patch Uncovered new lines
src/jq/eval.rs 98.48% (65/66) 102308
Uncovered new lines (1)
  • src/jq/eval.rs:102308

Indirect coverage changes

🔴 0 lines lost coverage, 🟢 1 lines gained coverage on unchanged code.

Indirect changes
  • src/jq/eval.rs:21527 🟢 uncovered → covered

📦 Full per-file coverage summary · run summary

…3890)

jq defines `indices($i)` as `.[$i]` for every input but an array and a string, and
`index`/`rindex` as that followed by `.[0]` / `.[-1:][0]`. `unsearchable_input` answered
`null` for any key on `null` or an object, on the strength of a comment that called it
`_strindices`'s answer; that held for the `null` and `{}` it was probed with and nothing
else. `null | indices(true)` answered where jq raises `Cannot index null with boolean`,
`{"a":1} | indices("a")` answered `null` where jq answers `1`, and `{"a":[5,6]} |
rindex("a")` answered `null` where jq answers `6`.

In `path()` the wrong `null` was the root's own, so `[path(indices(true))]` on `null`
answered `[[]]` and `del`, `=` and `|=` ran through it: these are the 210 ACCEPT_WRONG
rows the path-register sweep reported for the eight indices operands, now 0.

`unsearchable_input` is now `index_one` (jq's `.[$i]`, lazy) followed, for `index` and
`rindex`, by jq's own tail through the evaluator. A tracked array input (`path(.a |
indices(1))` is `["a",[1]]`), a tracked object key and a tracked string's `index`/`rindex`
still refuse, in the safe direction; #3890 stays open for them.

Sweep, base vs candidate over the eight operands (106,587 rows): ACCEPT_WRONG 210 -> 0,
MATCH +652, REFUSE_WRONG 1712 -> 1280, DIFF 20 -> 10; 14 rows matched jq only because the
wrong `null` short-circuited an `and`, and now refuse (exit 5, no write), disclosed in
docs/compliance/jq/limitations.md.
…lazy tail (#3890)

- the lookup and the `.[0]` / `.[-1:][0]` tail run with JqSemantics, not the caller's:
  `indices` is jq surface even where yq reaches it (`--jq-extensions`, which follows jq,
  ADR-0018), and yq's lenient indexing answered `null` for `a: [1, 2]` | `indices(1)`
  (jq, and the base commit: `Cannot index object with number`) and dropped `.[0]` of a
  scalar to no output where jq raises
- the tail is applied with `eval_single` on the looked-up document value, so a container
  is no longer read in full just to take one element of it, and an owned result keeps
  every output instead of `Ok(_) => None` silently dropping a non-single count
- tests: yq-extensions rows (new), object and array patterns on `null`/an object, and the
  14-row lost-match shape pinned as a residual beside its `.a[0]` contrast
…n why (#3890)

Patch coverage on the PR read 86.67% (39/45): the scalar `optional` branch and the
`OneCursor`/`Owned` arms of `unsearchable_input`. A probe in all three, run over the whole
suite and the CLI forms (`?`, `try`, `[.[]?|...?]`, yq), fired none of them, and reading
`index_one` shows why: a cursor and a computed result come only from a slice or a subarray
search of an *array*, and the lookup here is on `null` or an object, which answers one
document value or an error.

So the arms go (a dead arm implies behaviour no test can check), the scalar branch is the
existing `suppress_or_raise`, and `index_one_on_null_or_object_answers_a_value_or_an_error_3890`
pins the contract over ten key kinds on `null` and an object -- with an array target and an
array key as the control that makes its classification able to fail -- so a change that
makes `index_one` answer a cursor fails that test instead of silently skipping the tail.
@newhoggy
newhoggy force-pushed the issue-3890-jq-path-indices-index-rindex-tracked-input branch from f74f361 to bc953ee Compare October 7, 2026 13:21
@newhoggy
newhoggy added this pull request to the merge queue Oct 7, 2026
Merged via the queue into main with commit 634cf48 Oct 7, 2026
49 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant