From fcee815743f1c42b277b69eccbde778f61ff38f0 Mon Sep 17 00:00:00 2001 From: Nils Lehnen <30603423+iderex@users.noreply.github.com> Date: Tue, 1 Sep 2026 06:25:38 +0200 Subject: [PATCH] Refuse a logger installed in the core (#266) 0243 admits a logging facade on the standing condition that the core installs no logger and states that it installs none, and it says in its own text that nothing refuses one installed tomorrow. The narrowing it executes on 0103's fourth refused behaviour rests entirely on the facade's default sink writing nothing, so a registration behind it reopens a second exit for the values 0071 classifies field by field, with nothing having caught the change. no-logger-installed refuses the five registration calls under src/. It is a name list rather than a purpose test, which the block says of itself, and the near miss beside it is a diagnostic event handed to the client's sink carrying the word a careless pattern would key on - so a rule written as 'logger' would refuse the sentence 0243 requires the core to state about itself. Proven by planting the fixture under src/ and running the check three times: with the rule it refuses exactly that line and nothing else, with the rule deleted the same line is green, and with the line removed the register judges ten rules and refuses nothing. Signed-off-by: Nils Lehnen <30603423+iderex@users.noreply.github.com> --- .github/invariants/rules | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/invariants/rules b/.github/invariants/rules index 46638e5..23903b9 100644 --- a/.github/invariants/rules +++ b/.github/invariants/rules @@ -120,3 +120,11 @@ grounds: docs/decisions/0068-the-data-locality-position.md prevents: A telemetry, analytics or crash-reporting package arriving in the graph, which 0068 rules out and which is normally added as a dependency rather than as a decision, so the decision never gets made. The subject is the committed lockfile, so a reporter pulled in by something else is judged the same way one written by hand is. It is a name list rather than a purpose test: a reporter published under a name nobody has written here is not refused. fixture: name = "sentry" clean: name = "metrics" + +id: no-logger-installed +pattern: (^|[^A-Za-z_])(set_logger|set_boxed_logger|set_logger_racy|set_global_default|set_default_dispatch) +paths: src/ +grounds: docs/decisions/0243-the-means-a-certificate-is-validated-with.md +prevents: A logger registered behind the logging facade 0243 admits. That record narrows 0103's fourth refused behaviour from linking a facade to writing to a log, and the whole narrowing rests on the facade's default sink writing nothing, which stops being true the moment something is registered behind it. The second exit for the values 0071 classifies field by field is then open with nothing having caught the change, and a record two levels away saying the case was considered. It is a name list rather than a purpose test: the five names are the registration calls of the facade this graph carries and of its neighbour, so a registration written through a name nobody listed walks past it, and a logger implementation arriving in the graph is 0103's question rather than this rule's. +fixture: log::set_boxed_logger(Box::new(EventSinkLogger))?; +clean: sink.event(&event); // the sink is the client's, and no logger stands behind it