Gate: failure-handled
The declared failure has a path that handles it in the code.
| Property | Value |
|---|---|
| Checker | failure-handled |
| Confronts | spec |
| Blocking by default — new project | yes |
| Blocking by default — existing project | no — informs |
How it measures
Section titled “How it measures”A spec catalogues how its unit fails, with its own letter (-E) and a table of condition and
result. Until these gates, nothing confronted that catalogue with the code: a declared failure
crossed the whole pipeline without anyone asking whether the code handles it, whether the handling
records it, or whether a handling that exists answers any declared failure at all.
Three gates close that static layer, and none depends on production or on a log format:
failure-handledasks whether the governed code has any path that handles a failure, when the spec declares failures;failure-loggedasks whether that handling also records the occurrence;failure-declaredis the inverse of the first, and catches the commonest case: somebody wrote a defence and never declared what it prevents.
Handling is not “having a catch”. What a check that refuses, a recovered panic and a caught exception share is the effect, not the syntax, so the project’s dialect says what a handling and a record look like in its language. Without those patterns the gates have measured nothing and say so. The code is judged as a set: the code does not cite the failure’s code, so no rule can be tied to one specific path, and the gates assert the case that matters, a unit that declares failures with no handling at all.
A failure can leave the charge only with knowledge written beside it: @resilient: <reason> says
“it happens, I know why, and the flow absorbs it”. A bare marker exempts nothing. The same rows
carry the conclusions the observation layer reads: @resilient and @observing: <what was ruled out>, each with its reason read whole.
A unit whose handling matches are all normal flow (a lazy map initialisation, a pattern that did
not match) closes its failure section with none — <why>, and that satisfies failure-declared.
Declaring it
Section titled “Declaring it”gates: - name: failure-handled on: [spec] check: failure-handled