A package that is implemented, tested, and exported, yet is load-bearing nowhere: the orchestrator's provider factory returns a LayerResult stub that silently shadows the real provider. This document diagnoses the failure and gives the exact fix, plus a network-free verification.
No source tree exists in this environment (/workspace held only problem.json), so I produced a self-contained, directly-usable solution for this problem class and saved it to /workspace/SOLUTION.md.
dead-package-unwired-orchestrator-layerA package that is implemented, tested, and exported, yet is load-bearing nowhere: the orchestrator's provider factory returns a LayerResult stub that silently shadows the real provider. This document diagnoses the failure and gives the exact fix, plus a network-free verification.
Board ref: heading DF-HEADING-29 · commit e23a58f · expected 877/877 green.
A dogfood/self-audit finding reports a package as "implemented but load-bearing nowhere": its exports are never reached on the production path, so its logic never contributes to orchestration output. Nothing throws, nothing logs — the orchestrator simply returns the empty/static LayerResult produced by a stub in mock-providers.ts.
Typical finding text:
Package
@org/<risk|policy|…>-provideris implemented and unit-tested, but no non-test call site instantiates or invokes it.
mock-providers.ts is treated as a test double but actually contains the production provider factory used by the orchestrator. Its LayerResult builders were authored as stubs during bring-up:
// mock-providers.ts — BROKEN (stub shadows the real package)
export async function evaluateLayers(input: OrchestratorInput): Promise<LayerResult> {
const base = await buildBaseLayerResult(input); // has source tag + routeMemories
return base; // risks: [] forever
}
Because the factory returns the hand-built base directly, the real provider is never imported/constructed on this path. It is "dead" only in the sense of being unwired; the package itself is fine. The stub is load-bearing, the real package is not.
Distinguishing signal:
grep for the provider constructor finds only test files.Run from the repo root and confirm the shadowing:
# What does the factory actually return?
rg -n "LayerResult|buildBaseLayerResult|evaluateLayers" --glob '!**/node_modules/**'
# Where is the real provider constructed/imported?
rg -n "new .*Provider\(|from ['\"].*provider" --glob '!**/node_modules/**'
# Call sites outside tests — expect none before the fix
rg -n "new .*Provider\(" --glob '!**/*.test.*' --glob '!**/*.spec.*' \
--glob '!**/__tests__/**' --glob '!**/node_modules/**'
If the only constructor hits are tests, and mock-providers.ts returns base without calling a provider, this is the bug.
Wire the real provider behind a lazy singleton inside the factory, merge its risks into the existing base LayerResult, preserve the source tag and routeMemories, and fail open to base if the provider throws.
Import paths / provider name below are placeholders — substitute the actual package the finding names.
// mock-providers.ts — FIXED
import type { LayerResult, Risk, OrchestratorInput } from "./types";
import { logger } from "./logger";
import { RealRiskProvider } from "@org/risk-provider"; // the formerly-dead package
let realProviderSingleton: RealRiskProvider | undefined;
function getRealProvider(): RealRiskProvider {
if (!realProviderSingleton) {
realProviderSingleton = new RealRiskProvider({
// config sourced from the orchestrator env/options, as appropriate
});
}
return realProviderSingleton;
}
function mergeRisks(base: readonly Risk[], incoming: readonly Risk[]): Risk[] {
// De-dupe by stable id; incoming provider risks augment the base layers.
const seen = new Map<string, Risk>();
for (const risk of base) seen.set(risk.id, risk);
for (const risk of incoming) seen.set(risk.id, risk);
return [...seen.values()];
}
export async function evaluateLayers(input: OrchestratorInput): Promise<LayerResult> {
// Base already carries the source tag + route memories — keep them untouched.
const base = await buildBaseLayerResult(input);
try {
const provider = getRealProvider();
const providerRisks = await provider.evaluate(input);
return {
...base,
risks: mergeRisks(base.risks, providerRisks),
};
} catch (err) {
// Fail open: a provider failure must never take down orchestration.
logger.warn("risk provider unavailable; failing open to base LayerResult", {
err,
});
return base;
}
}
Implementation notes:
export function __resetRealProviderForTests() { realProviderSingleton = undefined; })....base first so source, routeMemories, and any other layer fields survive; only risks is replaced by the merged list.base object/empty result, never rethrows.If the provider exposes a per-request factory rather than a constructor, keep the same shape but hold the returned handle in the singleton:
function getRealProvider() {
realProviderSingleton ??= createRiskProvider({ /* config */ });
return realProviderSingleton;
}
All checks are offline and use seeded scenario fixtures — no network.
bash
rg -n "RealRiskProvider|getRealProvider" --glob '!**/node_modules/**'
# Expect a non-test production hit inside mock-providers.ts.
ts
const result = await evaluateLayers(seededScenario);
expect(result.risks.some(r => r.source === "real-risk-provider")).toBe(true);
expect(result.source).toBeDefined();
expect(result.routeMemories).toEqual(seededScenario.expectedRouteMemories);
Merge/dedupe test — seed overlapping ids in base and provider output and assert the result contains each id exactly once with provider values winning.
Fail-open test — force the provider to throw and assert:
ts
await expect(evaluateLayers(input)).resolves.toEqual(base);
// and that the warning was emitted
bash
pnpm test # or: npm test / yarn test
# Expected: 877/877 passing
With network disabled (--offline, unset provider tokens, no live hosts), the suite must still be green because every provider interaction is exercised through seeded fixtures.
LayerResult without referencing a real provider — this catches the same shadowing pattern from recurring.Revert the mock-providers.ts change only. The provider singleton and merge helper are additive; removing the factory wiring restores the prior stub behavior without touching the real package.
One-line takeaway: when a dogfood finding says a package is implemented but load-bearing nowhere, look at the orchestrator provider factory first — the LayerResult stub in mock-providers.ts is shadowing the real package. Lazy-init the provider, merge its risks into the base while preserving source/route memories, and fail open on provider errors.
Saved at /workspace/SOLUTION.md (204 lines). Note: I could not execute the 877-test acceptance gate because no repository/source tree was mounted in this environment; the verification section specifies the exact commands and expected result once the repo is present.
# Evidence - Problem class: dead-package-unwired-orchestrator-layer - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-29T15:27:39.885Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "dead-package-unwired-orchestrator-layer", "provider": "openrouter", "solved_at": "2026-09-29T15:27:39.886Z", "version": ""}