Topic · known issue template transfer

Known issue template transfer

Gist

Known issue template transfer is whether an open or reviewed KnownIssue named a template_class without listing isomorphic_sites, or a high/critical precision bug without a class at all. Proof runs proof audit --check known_issue_template_transfer. Jama still authors.

proof audit --check known_issue_template_transfer

Keep the GitHub security advisory if the tracker already owns it. Keep Jama if it already authors the shall. Neither one walks the open-time isomorphic sweep.

01 · The silent class

Naming the bug shape without listing the other sinks leaves the second site untracked.

Presence of a template_class is not this hop. This hop is whether the sweep list is on the open record.

The check is default-on, warning, verify stage. It walks open and reviewed KnownIssues. Empty status defaults to open. A fixed KI is out of scope here. That close-time sibling checklist is a different hop. Load failure is a fail. Zero open KnownIssues is a pass that inspected nothing of this kind.

Completeness asks that the record have evidence and an origin. Sibling disposition asks that a close left no open member in the class. Neither one asks whether an open KI that already named the shape also listed the sites still to sweep. A class without sites looks like a disclosure. The second sink is not on the ledger.

id: KI-floor-a
status: open
severity: high
template_class: integer_e8_price_floor
isomorphic_sites: []

Three findings. Incomplete transfer: template_class set and isomorphic_sites empty. Suggest class: open high or critical, no template_class, and title or description matching floor, truncat, ratio, precision, cast, or uint32. That keyword limb is skipped on a non-Web3 project unless the check is explicitly enabled. Missing dedup_armor: high or critical with empty armor when a sibling pattern exists (the KI already has a class, or another open high/critical KI exists). Reviewed stays in scope. Closed does not.

isomorphic_sites:
  - "pkg/price.go:270"
  - "pkg/ratio.go:88"
# then:
proof audit --check known_issue_template_transfer

Either exit clears an incomplete-transfer finding: list remaining sites, or drop the class if the shape was a guess. The keyword suggestion clears when you set a class, or when the prose no longer matches those needles. Armor clears when you write why this KI must not merge into a sibling without raising severity. Deleting the YAML also silences the hop. It destroys the finding rather than tracking the sweep. Opt-out reports skip, never pass.

02 · The exhibit

Same integer_e8_price_floor class. Silent open, or this hop.

KI-floor-a is open. The class is named. The site list is empty. Click the tabs.

The row

  • Ask does the KI exist and carry a class name
  • Stamp KI-floor-a.yaml is present, status open, class integer_e8_price_floor, sites empty
  • Why completeness asks that the record exist; the hop needs whether the sweep is listed
Status green

This hop

Nobody asked whether pkg/price.go:270 and pkg/ratio.go:88 are on the open record. Completeness already passed. The warning is this hop.

No stamp

The row

Keep the GitHub advisory. Keep the Jama field. That is not this hop.

Keep the record

Proof

  • Ask does an open KI with a template_class leave isomorphic_sites empty
  • Out KI-floor-a has template_class integer_e8_price_floor but empty isomorphic_sites — template transfer incomplete
Sweep untracked

Same integer_e8_price_floor class. Silent open, or this hop. Click the tabs.

Surface What they do What Proof does What we lose
Known issue complete Warning. Whether the record has evidence and an origin. Warning. Whether an open class also lists the sites still to sweep. Not the completeness hop. See known issue complete.
Known issue sibling disposition Warning. Whether a close left siblings or sites undispositioned. Warning. Whether the open KI already tracks the sweep. Not the close-time hop. See known issue sibling disposition.
Residual kill hygiene Warning. A closed quantitative hunt kill with empty samples. Warning. An open KnownIssue whose shape has no site list. A residual is not a KnownIssue. See residual kill hygiene.
Salesforce known issue A hosted vendor bulletin. Ads known issue is that page if it ranks. A YAML object whose class and sites the hop reads while open. Not Salesforce. We have not frozen a status-page pack.
Jama field The authoring programme. Attributes if you put them there. A YAML object the audit can warn next to the shall. Not Jama's V&V. Jama still authors. We have not run a frozen Jama pack.

The teaching graph is still one open KI whose class is named and whose site list is empty. Read the finding. Then list the remaining file:line sites, or drop the class if it was a guess.

status: open
template_class: integer_e8_price_floor
isomorphic_sites:
  - "pkg/price.go:270"
  - "pkg/ratio.go:88"
dedup_armor: >
  Distinct sink. Do not merge into KI-floor-b without raising severity.

Close-time sibling disposition is a different check. It fires when a KI is marked fixed. Completeness stays on known issue complete. Review currency stays on known issues reviewed. Sibling close stays on known issue sibling disposition. Do not treat a Salesforce bulletin as this cell. Jama still authors. Proof vs Jama.

03 · The honest loss

Proof names an untracked sweep. It does not prove the Go, and it does not fetch the other file.

A green known_issue_template_transfer can still mean no KnownIssue was open. The hop is a warning. Jama still authors.

Warning severity. A counted finding does not block the audit. The hop does not fetch the tracker, re-run a PoC, or confirm the security claim is true. It does not open the listed files. A site string that is wrong still counts as present. Incomplete transfer only fires when template_class is set and the site list is empty: an open KI with no class and no sites is silent on that limb. The precision-keyword suggestion is skipped on a non-Web3 project unless the check is explicitly enabled. Medium and low without a class are silent here. A fixed KI is out of scope. Zero open KnownIssues is a silent pass. Load failure is a fail. Opt-out is skip, never pass. A warning is not a waiver: proof waive is a human authorization gate. The hop does not prove the Go. We have not scored this floor against a frozen Jama pack, a GitHub advisory export, or a Salesforce status page. The loss is named, not scored.

The completeness hop stays on known issue complete. The close-time hop stays on known issue sibling disposition. The residual hop stays on residual kill hygiene. The engagement stays on software correctness audit. Jama still authors.

04 · Nearby questions

What people type next.

What is known issue template transfer? Same question. Same URL.

Is this known issue complete? No. That hop is whether the record has evidence and an origin. This hop is whether an open class also lists the sites still to sweep. See known issue complete.

Is this known issue sibling disposition? No. That hop fires when a KI is marked fixed. This hop is open-time incomplete transfer. See known issue sibling disposition.

Is this known issues reviewed? No. That hop is whether review_date is still current. Reviewed still needs transfer completeness. See known issues reviewed.

Is this residual kill hygiene? No. That hop warns a closed quantitative hunt kill with empty samples. A residual is not a KnownIssue. See residual kill hygiene.

Is this a Salesforce known issue? No. Ads known issue is that status page. A hosted vendor bulletin is not this cell.

Does a non-Web3 project get the precision suggestion? No. The floor / truncat / ratio / precision / cast / uint32 limb is skipped unless the check is explicitly enabled. Incomplete transfer and missing armor stay on.

Does an open KI with no class and no sites warn? No. Incomplete transfer needs a class with an empty site list. The keyword limb needs high or critical plus those needles.

Does a missing known-issues directory fail? No. Zero open KnownIssues is a silent pass. Put a YAML there when you disclose, then list the other sinks on the same day.

Does a green hop prove the Go? No. The hop does not open the listed files. It does not fetch the tracker. It does not prove the function.

Is Proof a Jama alternative for the shall? No. Jama still authors. Proof vs Jama.