11: Correctness gates¶
Where the tool refuses to proceed, and what each refusal is protecting against. Generated from the code; do not hand-edit.
flowchart TD
classDef gate fill:#51452d,stroke:#b59658,color:#fff
classDef step fill:#44372b,stroke:#c49a6c,color:#fff
classDef stop fill:#542f2b,stroke:#b96f5c,color:#fff
corpus[Seed corpus]:::step --> sift{{"run --sift<br/>a crashing seed stops<br/>libFuzzer before it starts"}}:::gate
sift -->|all seeds crash| sift_stop[Abort: broken harness,<br/>not a dirty corpus]:::stop
sift -->|crashers moved| smoke{{"harness-smoke<br/>clean / crash / did-not-run"}}:::gate
smoke -->|did-not-run| smoke_stop[Not ready:<br/>the binary never executed]:::stop
smoke -->|ready| campaign[Campaign]:::step
campaign --> sup{{"run --supervise<br/>restart past crashes,<br/>cap the log"}}:::gate
sup -->|25 runs under 2s| thrash[Abort: harness or<br/>environment fault]:::stop
sup -->|no new signature| sat[Halt: SATURATION SIGNAL,<br/>not a verdict. Triage them.]:::stop
sup -->|artifacts| triage[triage: replay,<br/>Observe + Exact dedup]:::step
triage --> complete{{"complete?<br/>skips, timeouts, walk errors,<br/>unreadable artifacts, failed writes"}}:::gate
complete -->|any| incomplete[complete=false + note]:::stop
complete -->|none| prov{{"provenance --strict<br/>target commit AND dirty state"}}:::gate
prov -->|dirty tree| prov_stop[The witness does not<br/>describe that commit]:::stop
prov -->|clean| bank[Bank evidence + receipt]:::step
bank --> eviq{{"check-evidence.py<br/>named bundles + coarse<br/>sanitizer fragments only"}}:::gate
eviq -->|fragment absent| evi_stop[Not supported.<br/>Re-witness or drop the fragment]:::stop
eviq -->|present; exact frames/lines unchecked| claim{{"claim ledger<br/>exact filing text, frame, line,<br/>build and provenance"}}:::gate
claim -->|unresolved| claim_stop[Do not claim<br/>publication integrity]:::stop
claim -->|adjudicated| sev{{"severity<br/>UNRATED unless an operator<br/>supplies a vector"}}:::gate
sev --> op[Operator ratifies + approves]:::step
op --> file[Disclosure]:::step The gates, and the exit contract each one keeps¶
A gate whose "cannot tell" branch returns success is not a gate. The column matters.
| gate | protects against | exit 0 | exit 1 | exit 2 | in CI |
|---|---|---|---|---|---|
tools/check-findings-yaml.py | reports/findings.yaml parses AND has no duplicate mapping keys | parses, no duplicates | malformed, or a duplicate key | no YAML parser available | yes |
tools/check-evidence.py | named bundles exist and coarse sanitizer fragments occur somewhere in those bundles | paths and selected fragments present; exact frames/lines/builds unchecked | a selected fragment is in no named bundle | evidence tree absent on this machine | yes |
tools/check-locked-artifacts.py | locked reference manifests are unchanged | all locked digests match | a locked artifact was edited | a locked artifact is missing | yes |
tools/diagrams/check.sh | diagram ground truth matches the code it describes | ground truth current | drifted; regenerate | - | yes |
tools/docs/generate_public_site.py | public metrics and CVE catalog match their structured sources | generated public facts current | stale; regenerate | - | yes |
tools/cveviz | public CVE mechanism diagrams match reports/cve-ledger.yaml | all committed SVGs current | a visual is stale or invalid | - | yes |
tools/docs/audit_public_docs.py | public commands, API signatures, and confidence contracts match the tool | public contracts current | a public contract drifted | required CLI binaries unavailable | yes |
tools/verify-mutators.sh | final harness binaries retain the intended custom-mutator symbols | all discovered mutator harnesses verified | a harness is mislinked | no mutator harness was available to inspect | no |
cmd/crucible/provenance.go | records the target commit AND dirty state a witness ran against | clean checkout | --strict and the tree has modified tracked files | - | no |
4 of 9 gates keep an explicit "cannot tell" exit code distinct from success.
The CLI carries 177 flags across 51 commands; the campaign gates above are --sift, --supervise, --stale-after, --max-restarts on run, and --strict on provenance.
Source: 6733034d; extracted: 2026-09-03.