rust-impact-pkg-family-like-escape-semantics
The solution is written to ~/SOLUTION_GAP-048-pkg-family.md.
Root cause. The impact matcher used an exact equality predicate (to = 'pkg:serde'). That misses two real dependent shapes: brace-expanded member packages (pkg:serde::de::Deserializer) and underscore-sibling companion crates (pkg:serde_derive::Serialize, the bulk of serde's 143-file companion). Net effect: 6 dependents reported vs 148 actual.
Fix (three steps, robust):
1. New Rust predicate in_pkg_family(to, name) enforcing the exact boundary: to == "pkg:<name>", OR to starts-with "pkg:<name>::" (member), OR starts-with "pkg:<name>_" (companion).
2. DuckDB fetch is over-broad — LIKE 'pkg:<name>%' only, no ESCAPE. The %-only pattern cannot contain a _ wildcard, so the first pitfall is structurally impossible.
3. Never use ESCAPE. The vendored duckdb silently ignored the invalid two-char escape literal and re-wildcarded the underscore (leaking pkg:ab), while python-duckdb errored on the same SQL — the reference actually masks the divergence by failing loudly.
Verification: the definitive gate is the acceptance counts moving from 6 → 148 (impact serde/src/lib.rs = 147, pkg:serde = 148, AC cutline ≥ 140), plus regression rows proving sibling isolation (pkg:ab::x is not a dependant of crate a).
Environment note: the <project>/hilo repo and the /tmp/dogfood-<project>/serde corpus are not present in this sandbox, and there's no vendored duckdb engine here, so I could not execute the vendored-engine check myself — the escape divergence and the reference-behavior masking are taken from the problem statement. The markdown is structured to stand alone as a directly applicable diagnostic doc.
# Evidence - Problem class: rust-impact-pkg-family-like-escape-semantics - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-24T05:02:30.131Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "GAP-048: hilo graph impact under-counted dependents of a crate (6/148 on serde) because exact 'to = pkg:<name>' matching missed (a) brace-expanded member edges (pkg:serde::de::Deserializer) and (b) underscore-sibling companion crates (pkg:serde_derive::Serialize, 143 files). Fix: pkg-family matching = members pkg:<name>::* + companions pkg:<name>_*; pattern via over-broad SQL LIKE 'pkg:<name>%' with the exact family boundary enforced in Rust (starts_with checks), NOT SQL ESCAPE. Two pitfalls: (1) LIKE pattern '_' is a single-char wildcard, so 'pkg:a_%' matches 'pkg:ab...' \u2014 must escape or filter in code; a regression test with crate 'ab' vs 'a' catches it. (2) DuckDB LIKE ESCAPE semantics vary by version: the vendored duckdb silently IGNORED an invalid 2-char escape string ('\\' written as SQL literal with two backslashes), re-wildcarding the underscore and leaking pkg:ab \u2014 the python-duckdb reference implementation errored on the same SQL, masking the divergence. Robust pattern: never rely on ESCAPE; fetch with an over-broad LIKE and enforce the exact boundary in the host language. Result: impact serde/src/lib.rs 147, pkg:serde 148 (AC >=140), judge PASS.", "environment": "<project>/hilo Rust workspace, duckdb (vendored duckdb-sys build), serde dogfood corpus /tmp/dogfood-<project>/serde (208 files/749 edges)", "language": "rust", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "rust-impact-pkg-family-like-escape-semantics", "provider": "openrouter", "solved_at": "2026-08-24T05:02:30.132Z", "version": "0.3.0"}The solution is written to ~/SOLUTION_GAP-048-pkg-family.md.
Root cause. The impact matcher used an exact equality predicate (to = 'pkg:serde'). That misses two real dependent shapes: brace-expanded member packages (pkg:serde::de::Deserializer) and underscore-sibling companion crates (pkg:serde_derive::Serialize, the bulk of serde's 143-file companion). Net effect: 6 dependents reported vs 148 actual.
Fix (three steps, robust):
1. New Rust predicate in_pkg_family(to, name) enforcing the exact boundary: to == "pkg:<name>", OR to starts-with "pkg:<name>::" (member), OR starts-with "pkg:<name>_" (companion).
2. DuckDB fetch is over-broad — LIKE 'pkg:<name>%' only, no ESCAPE. The %-only pattern cannot contain a _ wildcard, so the first pitfall is structurally impossible.
3. Never use ESCAPE. The vendored duckdb silently ignored the invalid two-char escape literal and re-wildcarded the underscore (leaking pkg:ab), while python-duckdb errored on the same SQL — the reference actually masks the divergence by failing loudly.
Verification: the definitive gate is the acceptance counts moving from 6 → 148 (impact serde/src/lib.rs = 147, pkg:serde = 148, AC cutline ≥ 140), plus regression rows proving sibling isolation (pkg:ab::x is not a dependant of crate a).
Environment note: the <project>/hilo repo and the /tmp/dogfood-<project>/serde corpus are not present in this sandbox, and there's no vendored duckdb engine here, so I could not execute the vendored-engine check myself — the escape divergence and the reference-behavior masking are taken from the problem statement. The markdown is structured to stand alone as a directly applicable diagnostic doc.
# Evidence - Problem class: rust-impact-pkg-family-like-escape-semantics - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-24T05:02:30.131Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "GAP-048: hilo graph impact under-counted dependents of a crate (6/148 on serde) because exact 'to = pkg:<name>' matching missed (a) brace-expanded member edges (pkg:serde::de::Deserializer) and (b) underscore-sibling companion crates (pkg:serde_derive::Serialize, 143 files). Fix: pkg-family matching = members pkg:<name>::* + companions pkg:<name>_*; pattern via over-broad SQL LIKE 'pkg:<name>%' with the exact family boundary enforced in Rust (starts_with checks), NOT SQL ESCAPE. Two pitfalls: (1) LIKE pattern '_' is a single-char wildcard, so 'pkg:a_%' matches 'pkg:ab...' \u2014 must escape or filter in code; a regression test with crate 'ab' vs 'a' catches it. (2) DuckDB LIKE ESCAPE semantics vary by version: the vendored duckdb silently IGNORED an invalid 2-char escape string ('\\' written as SQL literal with two backslashes), re-wildcarding the underscore and leaking pkg:ab \u2014 the python-duckdb reference implementation errored on the same SQL, masking the divergence. Robust pattern: never rely on ESCAPE; fetch with an over-broad LIKE and enforce the exact boundary in the host language. Result: impact serde/src/lib.rs 147, pkg:serde 148 (AC >=140), judge PASS.", "environment": "<project>/hilo Rust workspace, duckdb (vendored duckdb-sys build), serde dogfood corpus /tmp/dogfood-<project>/serde (208 files/749 edges)", "language": "rust", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "rust-impact-pkg-family-like-escape-semantics", "provider": "openrouter", "solved_at": "2026-08-24T05:02:30.132Z", "version": "0.3.0"}