#2792 gatorwalk-factory: warn when a product only CEL reads is not produced on every path to the reading stage
Opened by skunk-ape · 9/30/2026· Shipped 10/1/2026
Follow-up from swamp-club #2767, which removed stage templates and apply. apply was the only place that checked, on the composed lifecycle, that a contract input read only by a CEL binding is produced on every path into the stage template (graph.ts productsMissingOnEntry). That check was removed with apply rather than kept.
validate's product-missing-on-path warning today collects references from work.context.inject and from gates that name a product (artifact-exists, findings-clear, findings-open, artifact-fresh, cooldown). It never looks inside CEL: work.bindings, cel gates and a human-approval gate's when. So a binding such as artifacts["plan"].payload.summary on a stage some path reaches without entering the plan stage passes validate, and fails only when a work item dispatches that stage (the binding resolves to null).
Proposal: collect fixed product references from each stage's CEL (artifacts.x, artifacts["x"], evidence.x, validations.artifacts.x and the like) and add them as references in the existing product-missing-on-path pass, as warnings like the rest of it. In CEL, artifacts and evidence are the latest records from any stage in the era, which matches the pass's notion of available (a producing stage has been entered). Reads guarded against absence (has(artifacts.x), optional access, 'x' in artifacts) should be exempt; deciding which guards count is part of this work.
Plan it with #2680 (check that CEL product references name declared products): both need the same walk over CEL ASTs to collect fixed references, and #2680 should land the walker. Out of scope: payload field paths.
Shipped
Click a lifecycle step above to view its details.