e4f0935f98996b0381478eba20b9233646ccc483
`gates_every_route_and_never_logs_the_token` failed about one full-suite run in ten, on the assertion that a rejection *was* logged. Its sibling ends with an unauthenticated request of its own, made with no subscriber on that thread -- and tracing caches a callsite's interest process-wide the first time it is reached, so whichever test got there first decided whether the warning would ever be recorded. That is the rule already written at the top of "Things that have bitten", applied to one member of a set: the combined gating+logging test exists because of it, and the enrollment test added later did not get it. Twenty runs clean since. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Languages
Rust
53%
Kotlin
44.4%
Shell
2.6%