Description
panicMessageStartsWithBUG in pkg/linters/panic-in-library-code/panic-in-library-code.go exempts any panic() whose message starts with "BUG:" from the panicinlibrarycode linter, with no further check on call-site reachability. Several of the exempted panics (e.g. domains.go:691, claude_tools.go:142) are in fact reachable from the per-workflow compile path, so the linter cannot distinguish a real build-time invariant from a panic reachable from user input — it also encourages mislabelling panics as "BUG:" purely to silence the linter.
Expected Impact
Restores the linter's ability to flag reachable panics instead of letting a message-prefix convention bypass it, closing the loophole that let the two panics in issue "Convert domains.go/claude_tools.go invariant panics..." go undetected by CI.
Suggested Agent
GitHub Copilot coding agent — stop exempting panics by message prefix alone; require an explicit (nolint/redacted):panicinlibrarycode // <reason> justification, or restrict the exemption to init()/sync.Once/package-level-initialization contexts. Update linter testdata and add justified nolint comments to the remaining legitimate panics. Run make golint-custom.
Estimated Effort
Quick (<1 hour)
Data Source
DeepReport Intelligence Briefing — 2026-10-02, sourced from Repository Quality Improvement Report #65022 ("Compiler Panic Containment"), Task 3.
Generated by 🔬 Deep Report · claude · agent · 212 AIC · ⌖ 7.99 AIC · ⊞ 7.3K · ◷
Description
panicMessageStartsWithBUGinpkg/linters/panic-in-library-code/panic-in-library-code.goexempts anypanic()whose message starts with"BUG:"from thepanicinlibrarycodelinter, with no further check on call-site reachability. Several of the exempted panics (e.g.domains.go:691,claude_tools.go:142) are in fact reachable from the per-workflow compile path, so the linter cannot distinguish a real build-time invariant from a panic reachable from user input — it also encourages mislabelling panics as "BUG:" purely to silence the linter.Expected Impact
Restores the linter's ability to flag reachable panics instead of letting a message-prefix convention bypass it, closing the loophole that let the two panics in issue "Convert domains.go/claude_tools.go invariant panics..." go undetected by CI.
Suggested Agent
GitHub Copilot coding agent — stop exempting panics by message prefix alone; require an explicit
(nolint/redacted):panicinlibrarycode // <reason>justification, or restrict the exemption toinit()/sync.Once/package-level-initialization contexts. Update linter testdata and add justified nolint comments to the remaining legitimate panics. Runmake golint-custom.Estimated Effort
Quick (<1 hour)
Data Source
DeepReport Intelligence Briefing — 2026-10-02, sourced from Repository Quality Improvement Report #65022 ("Compiler Panic Containment"), Task 3.