# Reported issues for automatised-pipeline

Pod holds 16 of 16 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.

Back to [automatised-pipeline](/mcp/automatised-pipeline).

## Most discussed

### bug(distribution): live-mount dev symlink is structurally incompatible with the marketplace digest pin — server dies with 'cached binary digest mismatch'

## Symptom

The plugin MCP server fails to connect in Claude Code (`✘ Failed to connect — -32000: Connection closed`). Manual launch with `CLAUDE_PLUGIN_ROOT` set reproduces:

```
ai-architect-mcp-codebase: FATAL: cached binary digest mismatch; reinstall the plugin
```

Observed 2026-08-07 on the 0.9.0 marketplace install. This is also the root cause of BOTH tool-availability caveats in the A/B bench rev.2 report (`harness-comparison/results/COMPARISON-rev2.md`): the cortex-viz probe session…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/206) · 2026-08-07 · closed · 1 comment

### distribution: ship a SessionStart/SubagentStart code-discovery nudge — codebase-memory-mcp captures tool preference globally and ai-architect ships nothing

Measured on this machine 2026-08-06. codebase-memory-mcp (the competitor tracked in the CBM parity arc) has installed itself into the **user's global `~/.claude/settings.json`**, not just its own plugin manifest:

```
PreToolUse:     matcher "Grep|Glob"  -> ~/.claude/hooks/cbm-code-discovery-gate
SessionStart:   matchers startup / resume / clear / compact -> ~/.claude/hooks/cbm-session-reminder
SubagentStart:  matcher "*"          -> ~/.claude/hooks/cbm-subagent-reminder
```

The SessionStart…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/198) · 2026-08-06 · open · 1 comment

### analyze_codebase fails with 'unknown relationship type: Uses_Field_TypeAlias' on real Rust codebases

## Summary
`analyze_codebase` fails on any Rust codebase that uses a type alias as a struct/enum field type. The resolver constructs an edge table name dynamically (`Uses_Field_<TargetLabel>`) but the schema only registers `Uses_Field_Struct`, `Uses_Field_Enum`, and `Uses_Field_Trait` — never `Uses_Field_TypeAlias`.

The pipeline's own `src/` triggers it.

## Reproduction
Drove the MCP binary directly via stdio JSON-RPC against the pipeline's own source:

```bash…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/1) · 2026-04-17 · closed · 1 comment

### index_status reports zero counts, without an error, when the graph is held by another request

Found by the review of PR #360 (issue #352), by reading the code; not reproduced yet.

`index_status` reads its counts through `graph_counts`, which ends in `unwrap_or_default` (src/history_handlers.rs). Since #360, opening a graph while another request in the same process holds the cached handle is refused with `graph_handle_in_use` or `graph_cache_busy`. For the write tools that refusal is an error. For `index_status` the refusal is swallowed by `unwrap_or_default`, so the tool answers…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/361) · 2026-09-25 · closed · 0 comments

### resolver(rust): a return-type hint promoted after an external use stays accepted when a later incremental run changes the crate names

## Summary

When the return-type rule of #348 accepts an explicit `use` because its first segment is a crate of the repository, the result is stored in the call site's hint and never re-checked. A later incremental run that changes the crate names in `Cargo.toml` does not re-examine the files it did not touch, so their hints stay accepted under the old names. The graph then depends on the order of the runs: an incremental run and a fresh full run over the same tree disagree.

## Context

Found…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/358) · 2026-09-24 · closed · 0 comments

### resolver(rust): use crate::X inside a tests/, benches/, examples/ or bin target is trusted by name, so a re-exported external type gets an edge to a library homonym

## Summary

Inside a Cargo test, bench, example or binary target, `crate` names that target, not the library. The receiver-from-return-type rule of #348 accepts `use crate::Set;` as evidence that `Set` is a type of the repository, by name only. A test file that re-exports an external `Set` at its root and reaches it through `crate::Set` gets an edge to the library's unrelated `Set::answer` at confidence 0.85.

## Context

Found by reading the code during the review of PR #351 (which introduced…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/357) · 2026-09-24 · closed · 0 comments

### graph: calls to a tuple-struct constructor are marked resolved but have no per-site row and no edge, because no relationship table targets a Struct

## Summary

A call to a tuple-struct constructor, such as `Tier(1)`, is marked `is_resolved = true` but gets no row in any `Calls_CallSite_*` table and no function-level `Calls_*` edge. The schema has no relationship table whose target is a `Struct`, so the resolution has nowhere to go. #335 closed the same gap for calls that resolve to a function or a method and left this one open on purpose, because covering it needs a schema change.

## Context

Noted while fixing #335 (PR #337): calls to a…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/356) · 2026-09-24 · closed · 0 comments

### resolver(rust): a receiver that is a tuple-struct constructor, a struct literal or Type::new(..) written in place is left unresolved statically

## Summary

The static resolver types a receiver bound by `let t = Type::new(..)` but not one bound by `let t = Tier(1)` (a tuple-struct constructor) or `let v = Named { n: 3 }` (a struct literal), and not a receiver that is written in place: `Tier(1).join(..)`, `Tier::new(1).join(..)`, `Named { n: 3 }.get()`. The type is written in the expression in every one of these forms. `lsp_resolve` resolves all of them; a static-only run misses them.

## Context

Found by replaying failure shapes from…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/355) · 2026-09-24 · closed · 0 comments

## Most recent

### get_impact: test, bench and example callers are counted with production callers, and entry_kind marks only plain #[test]

## Summary

`get_impact` lists test functions, bench code and example code among the callers of a production function, in the same list, with the same fields, and counts them in `callers_total`. A reader cannot tell how many callers are production code. The graph does carry a marker for tests (`Function.entry_kind = 'test'`), but it is set only for a plain `#[test]` attribute, and `get_impact` does not use it.

## Context

Found by replaying failure shapes from the public tracker of…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/354) · 2026-09-24 · closed · 0 comments

### coverage: an unknown Cargo target map renders identically to a fully-compiled one

Follow-up from the 2026-09-22 AxonOS re-verification of #282/#284 (`tasks/axon-verify-20260922/REPORT.md`, finding F2).

## Measured

In the #282 nested-workspace shape, `cargo metadata --no-deps` fails with `current package believes it's in a workspace when it's not`. Per the #284 design (`tasks/plan-issues-282-283-284.md` section 3.2: if `cargo` is absent, or there is no `Cargo.toml`, or the command fails, the target map becomes `Unknown` and no file is attributed, an honest absence), no file…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/316) · 2026-09-22 · closed · 0 comments

### lsp: analysing a workspace root outside every compiled target still reports state=completed

Follow-up from the 2026-09-22 AxonOS re-verification of #282 (`tasks/axon-verify-20260922/REPORT.md`, finding F1).

## Measured

`analyze_codebase(path=<nested-nogit>/, lsp=true)` against a virtual `[workspace] members = []` root whose only child (`dy-wcet/`) is not listed as a member (`raw/lsp-parent-root-nogit/analyze.json`, commit `22b11da` on branch `docs/axon-verify-20260922`):

```
lsp_status = {
  state: "completed",
  server_health: {health: "warning", message: "Failed to read Cargo…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/315) · 2026-09-22 · closed · 0 comments

### indexer: 270 of 818 tracked files absent from the index, none of them reported, and src/bin pruned as build output

Measured on this repository on 2026-09-09 with the release binary at `04e326a`:

```
tracked files                 818
files_indexed (reported)      549
files with a recorded gap      10
absent from the manifest      270
```

270 tracked files were absent from the index and not one of them appeared anywhere in the coverage report. The run reported `status: ok`.

## A. The walk prunes a Cargo source directory

`bin` is in the built-in prune list under "General build output" beside `dist` and…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/300) · 2026-09-09 · closed · 0 comments

### Calls from files outside compiled Cargo targets are never resolved — Kani proof harnesses are structurally invisible to the call graph

## Summary

Source files that are **not part of a compiled Cargo target** are parsed and indexed — their declarations are recovered correctly — but their outgoing calls are **never resolved**, even with rust-analyzer enabled. Verification harnesses are the canonical case: Kani proof files live outside `src/`/`tests/` and are compiled only under `cargo kani`.

The consequence is a graph that knows a proof harness *exists* but not that it *exercises* the function it proves. For a tool whose…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/284) · 2026-09-08 · closed · 0 comments

### LSP resolution silently resolves nothing when the target sits under a parent Cargo workspace — reports state=completed, status=ok

## Summary

When the analyzed codebase sits **inside a parent Cargo workspace that does not list it as a member**, the LSP resolution phase resolves **nothing** — and reports success anyway. `lsp_status.state` is `"completed"`, the envelope `status` is `"ok"`, and the coverage sidecar flags no gap. The consumer receives a graph whose audited projection is byte-identical to a static (no-LSP) run, with no signal that the phase it explicitly requested did nothing.

On Rust, where static resolution…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/282) · 2026-09-08 · closed · 0 comments

### feat(index_codebase): user-configurable folder exclusion — an unreadable secrets directory aborts the entire walk

## Problem

A user cannot complete `index_codebase` on their repository: the tree contains a directory that is locked down because it holds secrets (permission-denied at the filesystem level), and the indexer has no way to route around it.

Two distinct gaps compound into a hard failure:

1. **No user-facing exclusion parameter.** The `index_codebase` input schema (`src/tool_schemas.rs`, `index_codebase_schema`) exposes `language`, `dependency_scope`, `bootstrap`, `full`, `cochange`, … but…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/249) · 2026-08-13 · closed · 0 comments

### SECURITY.md points at a private advisory channel that is disabled — no working private disclosure path

SECURITY.md tells reporters to open a private GitHub security advisory, but that channel is **switched off**, so a non-collaborator who follows the instructions has nowhere to go.

## Evidence (measured 2026-07-27)

```
$ gh api repos/cdeust/automatised-pipeline/private-vulnerability-reporting
{"enabled":false}
```

SECURITY.md's only disclosure channel is `https://github.com/cdeust/automatised-pipeline/security/advisories/new`. With private vulnerability reporting disabled, that form is…

[Read the thread](https://github.com/cdeust/ai-architect-mcp-codebase/issues/159) · 2026-07-27 · closed · 0 comments

The remaining reports are on [the project's issue tracker](https://github.com/cdeust/automatised-pipeline/issues).
