reqproof.com Place a notice

The Extinction Ledger

A record of software defects that will not recur · Published by Proof · reqproof.com

Obituaries

Here lie the bugs that will never ship again.

Most teams fix bugs. The same class returns wearing different code. A continuous correctness audit closes the class: root-caused, siblings swept, pinned by a test that runs on every release, forever.

Notices of death appear below. To commission notices of your own, apply within.

Deaths

F-002 · Escaped to production · Class closed 2026

Silent Data Loss, of Set()

Died twice: once in production, once in the postmortem.

Silent Data Loss departed the Set() function in the spring of 2026, after a brief but consequential residence. It is recorded here as the one that got past us first. It escaped under full instrumentation, with one hundred percent MC/DC coverage attesting to every decision it touched, and it was discovered not by its authors but by a downstream user, whose data it had quietly declined to write. Witnesses report no panic, no stack trace, no log line. It simply returned success.

A postmortem was published in the open, naming the miss without qualification. The root cause was established, the specification that should have forbidden it was written, and in the sweep that followed, every sibling in its family was located and closed. None survived. The coverage report, which had vouched for the deceased, was retired from the role of sole character witness; behavior now testifies for itself.

Interment was in the test suite, where the class remains under continuous observation. It is not expected to return. The pin sees to that.

Survived by: a failing reproducer preserved in the corpus, a regression pin that runs on every release, and a signed public finding.

F-001 · Discovered 2026 · Class closed 2026

Unguarded Negative Index, of Get()

Lived quietly at eight call sites. Died at all of them on the same day.

Unguarded Negative Index entered the codebase early and settled at eight call sites, any one of which could be made to panic by input it had no reason to expect. It kept to itself and drew no attention from the test suite.

It was discovered in the opening weeks of the audit and root-caused once. In accordance with the practice of this house, its family was then swept: all eight siblings located, all eight closed, the same day. No further appearances are anticipated at any address.

Survived by: a regression pin, eight sibling checks, and a signed finding in the public register.

Notice · F-003

Class closed.

Extinct

Pinned on every release.

Notice · F-004

Class closed.

Extinct

Pinned on every release.

Notice · F-005

Class closed.

Extinct

Pinned on every release.

Notice · F-006

Class closed.

Extinct

Pinned on every release.

Notice · F-007

Class closed.

Extinct

Pinned on every release.

The two principal obituaries record documented findings from the public jsonparser audit. The shorter notices mark the campaign's remaining closed classes and carry representative dates and identifiers; their particulars, with runnable reproducers, live in the public register.

In Memoriam, Pending
— Still at Large —

Classes known to be living in production codebases. Whereabouts unconfirmed.

At large

The Race Condition

Appears only under load, at night, in the region you don't watch. Every test that has ever looked for it has reported green.

At large

Silent Data Loss (yours)

Returns success. Writes nothing. Your users will make its acquaintance before you do.

At large

Contract Drift

The API still answers. It no longer means what the documentation says it means. Nobody has updated either party.

At large

The Hallucinated API

Written by an agent, reviewed at five o'clock, merged. Calls a function that has never existed. The build passed.

Your codebase has its own obituaries waiting to be written.
We write them.

How a Class Dies

I.

Finding

A defect is observed and recorded. Not a ticket; an entry in a register, with a name, a severity, and a signature.

II.

Failing reproducer

The defect is made to happen on demand. Until it can be summoned, it cannot be pronounced dead.

III.

Root cause

Not where it surfaced; why it existed. Usually a promise the code was never asked, in writing, to keep.

IV.

Sibling sweep

The same cause is hunted everywhere else it lives. A bug fixed in one place and left in eight is not fixed.

V.

Regression pin

A test that fails if the class ever returns, traced to the requirement that forbids it. It runs on every release, forever.

VI.

Gate

The pin joins the audit gate in your CI. From this point the class cannot ship. The obituary goes to print.

The corpus remembers

123

Requirements standing over one component

Every finding signed by a named reviewer

Every closed class leaves a requirement behind: a written promise the code is now obliged to keep, traced to the lines that keep it and to the tests that prove it. On the jsonparser campaign that record grew to one hundred twenty-three requirements over a single component, and it compounds every quarter the audit runs. Institutions forget; the corpus does not.

The record is built for both kinds of reader. Agents receive copy-ready fix prompts, with the finding, its context, and the reproducer attached, so the machine can do the labor. Humans sign the findings, because a signature is the one thing a machine cannot honestly produce.

Place a Notice

Tell us where it hurts. An email address is enough; everything else is optional.

Optional particulars for the ledger