Public report — iggy, published 30 Sep 2026.
Concrete security findings (which rule fired, in which file, on which line; CVE IDs, secret matches,
dependency versions) are REDACTED in this version; ask the repo owner for the full report.
Public
Codebase surveyMeasured under the Code Assurance Index · rubric rubric-2026.09.18 (frozen) · verify this surveyFiledcd_6c40a0d4e4a943038d56396053570251
Filed 30 September 2026, 06:45 UTC
Public
Large · 495,792 LoC · 62 projects · rebuild ~5.6 person-years · weakest lens: Readiness (47%)
Findings by grade
277 critical1461 serious103 minor3 could not be resolved — could be critical — see Limitations
This survey was produced by
Watchdog
Producer
Canine Development
Analyzer
Watchdog engine 1.0.0
Measured
30 September 2026, 06:26 UTC
A measurement, not a certificate. The Code Assurance Index does not certify,
approve or guarantee this codebase; it records a reproducible number and the evidence it was computed from. The
standard is authored by Canine Development, who also build Watchdog — its only implementation today. That is said
here so the number is checked rather than believed.
Grounded in facts. Every number here is computed, not narrated — reproducible, tool-backed, and traceable to a line of code. How to trust this ▸
1750findings with an exact file:lineof 1841 — the remainder are repo-wide signals (a dimension-level measurement, not a single line); open any file:line and verify
92/135dimensions across the health lenses495792 LoC · 62 projects — wide & deep
Preview (pre-1.0). This repo hasn't declared a stable release, so it's judged against a relaxed, pre-production bar.
This system holds significant value but carries substantial operational risk. With a health score of 55%, it is a large, complex asset that is currently adequate in structure but fragile in execution. The primary concern is not the code’s design, which is robust, but its readiness for safe, reliable operation in production. The business faces a high cost of failure because the system is too large to rebuild quickly, making stability paramount.
The asset represents a major investment, requiring approximately 5.6 person-years and €810,000 to rebuild. It consists almost entirely of core business logic with minimal boilerplate, meaning changes are impactful and costly. While the architecture is excellent and the domain modeling is mature, the system lacks the operational safeguards needed to support this scale. The weakest area is production readiness, where gaps in testing, observability, and security expose the business to potential outages and data loss. This misalignment between architectural strength and operational maturity creates a dangerous dependency on individual knowledge rather than systemic resilience.
The most critical risk is the lack of disaster recovery capabilities. A persistence guard is not a backup strategy. Without codified geo-recovery and documented restore procedures, a single failure could lead to prolonged downtime and data loss, directly impacting revenue and customer trust. Additionally, leaked secrets in configuration files pose an immediate security threat that must be addressed to prevent unauthorized access. These issues are not theoretical; they are active vulnerabilities that could compromise the entire platform.
On the positive side, the codebase is well-structured and easy to understand, which aids in future maintenance. The high score in architecture and event sourcing indicates a solid foundation that, if properly operationalized, can support long-term growth. However, this potential is currently unrealized due to operational neglect.
The first action must be to implement and document disaster recovery procedures. This provides the highest leverage by securing the business against catastrophic failure. Once this is in place, focus should shift to resolving security leaks and improving test coverage. The current picture is partial, as some areas like domain modeling were not measured, but the existing data clearly points to operational readiness as the immediate priority.
How the score is built — each lens's share of the headlineWidth is the lens's weight in the worst-heaviest fold (the weakest area pulls hardest); colour is that lens's own band. A lens fixes the score in proportion to its width.
246 finding(s) are new versus the previous scan (2026-09-13) — surfaced by this scheduled scan itself, no pull request required. Showing the first 100; the full set is in the report.
A full-fidelity diff against the previous run's complete recorded findings — line-move tolerant: a finding that only shifted line counts as unchanged, only genuinely new titles/files surface here.
Rebuild cost & value ~ Modeled — €270,000–€1,400,000
0.8× (at 55% quality) — the last 20% of quality is most of the work
Size & shape
Large · effort split not classified for 479,299 line(s) outside the .NET model (the tier breakdown is a C#-only syntax walk)
Effort basis
The rebuild estimate prices 493,560 code lines. Comment-only lines count toward the 495,792-line size but are not build effort.
This codebase represents roughly ~5.6 person-years of build effort (about ~€810,000 to rebuild). Its weakest lens is Readiness at 47% — the part of that asset most exposed by the findings below.
How we model this: boilerplate at a scaffolding rate + logic × domain Standard (×1.2) — library/CLI, DDD/clean architecture, high decision density × a 0.8× quality factor, at €60–95/h; indicative, ±~30% · size measured directly from source. Indicative only — most sensitive to the hourly rate and the domain tier (both tunable in config).
Top priorities
The highest-leverage moves; the full ranked list is in the Roadmap below.
1
Resolve the 5 Leaked secret finding(s) in REDACTED Scanning — start with REDACTED, REDACTED, REDACTED.
Value concentrated against a weak lens · Medium · Value at risk
This is a Large asset (~5.6 person-years to rebuild), and its weakest lens is Readiness at 47%. The operational and business risk on an asset this size concentrates there — that's where remediation buys the most protection.
→ Direct remediation budget at Readiness first — highest risk-reduction per euro on an asset this size.
Highest-leverage move · Medium · Leverage
Of everything flagged, the best return on effort is: Codify backups + geo-recovery in IaC and document RTO/RPO and the restore procedure — a persistence guard alone is not disaster recovery. The rest can wait behind it.
Evidence: priority ranking: top of 5 ranked by impact/effort
→ Codify backups + geo-recovery in IaC and document RTO/RPO and the restore procedure — a persistence guard alone is not disaster recovery.
Architecture — module dependency graph
Project dependencies, layered top-to-bottom; arrows show direction. Any dashed red edge points upward or sideways — a layering smell or cycle. A clean layered graph has none.
Architecture — module dependency matrix
Rows and columns are the same modules, ordered so that a module only depends on ones above it. A cell means the row depends on the column, and its number is how many type pairs create that dependency. Read one thing: is anything above the diagonal? A mark there is a dependency cycle. (A cycle is all this shows — an unusual but cycle-free dependency sits below the diagonal like any other.)
1195 modules, 2973 dependencies. 17 dependency cycles across 83 modules, marked above the diagonal.
Showing the 40 most-connected modules; 1155 more are not drawn.
Module dependency matrix. The row depends on the column; the number is how many type pairs create the dependency. A cell above the diagonal is part of a dependency cycle.
configs.server_config.server uses iggy_common.traits.validatable. Changing iggy_common.traits.validatable can break configs.server_config.server, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
13→5 iggy.leader_aware depends on iggy_common.error.iggy_error✕
Type pairs
1 distinct (type in iggy.leader_aware → type in iggy_common.error.iggy_error) reference.
iggy_binary_protocol.consensus.header uses iggy_binary_protocol.consensus.operation. Changing iggy_binary_protocol.consensus.operation can break iggy_binary_protocol.consensus.header, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
15→2 iggy_binary_protocol.primitives.identifier depends on iggy_binary_protocol.codec✕
Type pairs
4 distinct (type in iggy_binary_protocol.primitives.identifier → type in iggy_binary_protocol.codec) references.
iggy_binary_protocol.primitives.identifier uses iggy_binary_protocol.codec. Changing iggy_binary_protocol.codec can break iggy_binary_protocol.primitives.identifier, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
16→8 iggy_common.utils.duration depends on iggy_connector_sdk✕
Type pairs
1 distinct (type in iggy_common.utils.duration → type in iggy_connector_sdk) reference.
metadata.stm.result uses iggy_binary_protocol.consensus.operation. Changing iggy_binary_protocol.consensus.operation can break metadata.stm.result, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
19→10 simulator.workload.shadow depends on simulator.workload.effect✕
Type pairs
2 distinct (type in simulator.workload.shadow → type in simulator.workload.effect) references.
iggy_common.utils.byte_size uses iggy_common.utils.duration. Changing iggy_common.utils.duration can break iggy_common.utils.byte_size, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
22→16 iggy_common.utils.timestamp depends on iggy_common.utils.duration✕
Type pairs
1 distinct (type in iggy_common.utils.timestamp → type in iggy_common.utils.duration) reference.
iggy_common.utils.timestamp uses iggy_common.utils.duration. Changing iggy_common.utils.duration can break iggy_common.utils.timestamp, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
23→12 message_bus depends on configs.server_config.server✕
Type pairs
1 distinct (type in message_bus → type in configs.server_config.server) reference.
simulator.client uses iggy_binary_protocol.consensus.operation. Changing iggy_binary_protocol.consensus.operation can break simulator.client, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
24→9 simulator.client depends on iggy_mcp.service.requests✕
Type pairs
1 distinct (type in simulator.client → type in iggy_mcp.service.requests) reference.
simulator.client uses iggy_binary_protocol.consensus.header. Changing iggy_binary_protocol.consensus.header can break simulator.client, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
25→9 consensus.impls depends on iggy_mcp.service.requests✕
Type pairs
3 distinct (type in consensus.impls → type in iggy_mcp.service.requests) references.
iggy_bench.args.common uses bench_report.types.benchmark_kind. Changing bench_report.types.benchmark_kind can break iggy_bench.args.common, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
26→7 iggy_bench.args.common depends on iggy_common.utils.expiry✕
Type pairs
1 distinct (type in iggy_bench.args.common → type in iggy_common.utils.expiry) reference.
iggy_common.types.identifier uses iggy_common.traits.validatable. Changing iggy_common.traits.validatable can break iggy_common.types.identifier, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
28→21 iggy_common.types.identifier depends on iggy_common.utils.byte_size✕
Type pairs
1 distinct (type in iggy_common.types.identifier → type in iggy_common.utils.byte_size) reference.
iggy_common.types.identifier uses iggy_common.utils.byte_size. Changing iggy_common.utils.byte_size can break iggy_common.types.identifier, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
29→7 iggy_common.types.options depends on iggy_common.utils.expiry✕
Type pairs
2 distinct (type in iggy_common.types.options → type in iggy_common.utils.expiry) references.
simulator.workload.ops.change_password uses iggy_mcp.service.requests. Changing iggy_mcp.service.requests can break simulator.workload.ops.change_password, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
30→10 simulator.workload.ops.change_password depends on simulator.workload.effect✕
Type pairs
1 distinct (type in simulator.workload.ops.change_password → type in simulator.workload.effect) reference.
simulator.workload.ops.change_password uses simulator.workload.effect. Changing simulator.workload.effect can break simulator.workload.ops.change_password, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
30→11 simulator.workload.ops.change_password depends on simulator.workload.options✕
Type pairs
1 distinct (type in simulator.workload.ops.change_password → type in simulator.workload.options) reference.
simulator.workload.ops.change_password uses simulator.workload.options. Changing simulator.workload.options can break simulator.workload.ops.change_password, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
30→13 simulator.workload.ops.change_password depends on iggy.leader_aware✕
Type pairs
1 distinct (type in simulator.workload.ops.change_password → type in iggy.leader_aware) reference.
simulator.workload.ops.change_password uses iggy.leader_aware. Changing iggy.leader_aware can break simulator.workload.ops.change_password, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
30→19 simulator.workload.ops.change_password depends on simulator.workload.shadow✕
Type pairs
1 distinct (type in simulator.workload.ops.change_password → type in simulator.workload.shadow) reference.
simulator.workload.ops.change_password uses simulator.workload.shadow. Changing simulator.workload.shadow can break simulator.workload.ops.change_password, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
30→24 simulator.workload.ops.change_password depends on simulator.client✕
Type pairs
1 distinct (type in simulator.workload.ops.change_password → type in simulator.client) reference.
simulator.workload.ops.change_password uses simulator.client. Changing simulator.client can break simulator.workload.ops.change_password, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
31→6 iggy_common.types.consumer.consumer_kind depends on iggy_common.traits.validatable✕
Type pairs
1 distinct (type in iggy_common.types.consumer.consumer_kind → type in iggy_common.traits.validatable) reference.
iggy_common.types.consumer.consumer_kind uses iggy_common.traits.validatable. Changing iggy_common.traits.validatable can break iggy_common.types.consumer.consumer_kind, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
31→28 iggy_common.types.consumer.consumer_kind depends on iggy_common.types.identifier✕
Type pairs
2 distinct (type in iggy_common.types.consumer.consumer_kind → type in iggy_common.types.identifier) references.
iggy_common.types.consumer.consumer_kind uses iggy_common.types.identifier. Changing iggy_common.types.identifier can break iggy_common.types.consumer.consumer_kind, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
iggy.client_wrappers.client_wrapper uses iggy_common.utils.duration. Changing iggy_common.utils.duration can break iggy.client_wrappers.client_wrapper, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
33→20 iggy.client_wrappers.client_wrapper depends on consensus.oneshot✕
Type pairs
1 distinct (type in iggy.client_wrappers.client_wrapper → type in consensus.oneshot) reference.
iggy.client_wrappers.client_wrapper uses iggy_common.traits.client. Changing iggy_common.traits.client can break iggy.client_wrappers.client_wrapper, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
33→28 iggy.client_wrappers.client_wrapper depends on iggy_common.types.identifier✕
Type pairs
1 distinct (type in iggy.client_wrappers.client_wrapper → type in iggy_common.types.identifier) reference.
iggy.client_wrappers.client_wrapper uses iggy_common.types.identifier. Changing iggy_common.types.identifier can break iggy.client_wrappers.client_wrapper, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
33→29 iggy.client_wrappers.client_wrapper depends on iggy_common.types.options✕
Type pairs
5 distinct (type in iggy.client_wrappers.client_wrapper → type in iggy_common.types.options) references.
iggy.client_wrappers.client_wrapper uses iggy_common.types.options. Changing iggy_common.types.options can break iggy.client_wrappers.client_wrapper, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
33→31 iggy.client_wrappers.client_wrapper depends on iggy_common.types.consumer.consumer_kind✕
Type pairs
1 distinct (type in iggy.client_wrappers.client_wrapper → type in iggy_common.types.consumer.consumer_kind) reference.
iggy.client_wrappers.client_wrapper uses iggy_common.types.consumer.consumer_kind. Changing iggy_common.types.consumer.consumer_kind can break iggy.client_wrappers.client_wrapper, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
34→16 iggy.http.http_client depends on iggy_common.utils.duration✕
Type pairs
1 distinct (type in iggy.http.http_client → type in iggy_common.utils.duration) reference.
iggy.http.http_client uses iggy_common.types.consumer.consumer_kind. Changing iggy_common.types.consumer.consumer_kind can break iggy.http.http_client, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
35→9 iggy_common.wire_conversions depends on iggy_mcp.service.requests✕
Type pairs
2 distinct (type in iggy_common.wire_conversions → type in iggy_mcp.service.requests) references.
iggy_common.wire_conversions uses iggy_mcp.service.requests. Changing iggy_mcp.service.requests can break iggy_common.wire_conversions, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
35→28 iggy_common.wire_conversions depends on iggy_common.types.identifier✕
Type pairs
1 distinct (type in iggy_common.wire_conversions → type in iggy_common.types.identifier) reference.
iggy_common.wire_conversions uses iggy_common.types.identifier. Changing iggy_common.types.identifier can break iggy_common.wire_conversions, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
35→29 iggy_common.wire_conversions depends on iggy_common.types.options✕
Type pairs
1 distinct (type in iggy_common.wire_conversions → type in iggy_common.types.options) reference.
iggy_common.wire_conversions uses iggy_common.types.options. Changing iggy_common.types.options can break iggy_common.wire_conversions, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
35→31 iggy_common.wire_conversions depends on iggy_common.types.consumer.consumer_kind✕
Type pairs
1 distinct (type in iggy_common.wire_conversions → type in iggy_common.types.consumer.consumer_kind) reference.
iggy_common.wire_conversions uses iggy_common.types.consumer.consumer_kind. Changing iggy_common.types.consumer.consumer_kind can break iggy_common.wire_conversions, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
36→2 metadata.stm.stream depends on iggy_binary_protocol.codec✕
Type pairs
2 distinct (type in metadata.stm.stream → type in iggy_binary_protocol.codec) references.
metadata.stm.stream uses iggy_binary_protocol.primitives.identifier. Changing iggy_binary_protocol.primitives.identifier can break metadata.stm.stream, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
36→18 metadata.stm.stream depends on metadata.stm.result✕
Type pairs
1 distinct (type in metadata.stm.stream → type in metadata.stm.result) reference.
partitions.iggy_partition uses iggy_binary_protocol.consensus.operation. Changing iggy_binary_protocol.consensus.operation can break partitions.iggy_partition, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
37→5 partitions.iggy_partition depends on iggy_common.error.iggy_error✕
Type pairs
1 distinct (type in partitions.iggy_partition → type in iggy_common.error.iggy_error) reference.
partitions.iggy_partition uses iggy_common.error.iggy_error. Changing iggy_common.error.iggy_error can break partitions.iggy_partition, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
37→7 partitions.iggy_partition depends on iggy_common.utils.expiry✕
Type pairs
2 distinct (type in partitions.iggy_partition → type in iggy_common.utils.expiry) references.
partitions.iggy_partition uses iggy_binary_protocol.consensus.header. Changing iggy_binary_protocol.consensus.header can break partitions.iggy_partition, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
37→20 partitions.iggy_partition depends on consensus.oneshot✕
Type pairs
1 distinct (type in partitions.iggy_partition → type in consensus.oneshot) reference.
partitions.iggy_partition uses iggy_common.types.consumer.consumer_kind. Changing iggy_common.types.consumer.consumer_kind can break partitions.iggy_partition, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
38→16 iggy.clients.client depends on iggy_common.utils.duration✕
Type pairs
1 distinct (type in iggy.clients.client → type in iggy_common.utils.duration) reference.
iggy.clients.client uses iggy_common.types.consumer.consumer_kind. Changing iggy_common.types.consumer.consumer_kind can break iggy.clients.client, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
38→33 iggy.clients.client depends on iggy.client_wrappers.client_wrapper✕
Type pairs
1 distinct (type in iggy.clients.client → type in iggy.client_wrappers.client_wrapper) reference.
iggy.clients.client uses iggy.client_wrappers.client_wrapper. Changing iggy.client_wrappers.client_wrapper can break iggy.clients.client, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
39→3 metadata.impls.metadata depends on iggy_binary_protocol.consensus.operation✕
Type pairs
2 distinct (type in metadata.impls.metadata → type in iggy_binary_protocol.consensus.operation) references.
metadata.impls.metadata uses iggy_binary_protocol.consensus.operation. Changing iggy_binary_protocol.consensus.operation can break metadata.impls.metadata, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
39→8 metadata.impls.metadata depends on iggy_connector_sdk✕
Type pairs
3 distinct (type in metadata.impls.metadata → type in iggy_connector_sdk) references.
metadata.impls.metadata uses iggy_binary_protocol.consensus.header. Changing iggy_binary_protocol.consensus.header can break metadata.impls.metadata, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
39→15 metadata.impls.metadata depends on iggy_binary_protocol.primitives.identifier✕
Type pairs
2 distinct (type in metadata.impls.metadata → type in iggy_binary_protocol.primitives.identifier) references.
metadata.impls.metadata uses iggy_binary_protocol.primitives.identifier. Changing iggy_binary_protocol.primitives.identifier can break metadata.impls.metadata, not the reverse.
Position
Below the diagonal — points down the layering, which is what you want.
39→25 metadata.impls.metadata depends on consensus.impls✕
Type pairs
3 distinct (type in metadata.impls.metadata → type in consensus.impls) references.
Findings mapped to OWASP categories; the specific CVEs/secrets are in the Security dimension cards below and findings.md (redacted only on the public version of this report).
OWASP category
Findings
Severity
A03:2021 — Injection
232
High / Critical
A05:2021 — Security Misconfiguration
93
High / Critical
A06:2021 — Vulnerable & Outdated Components
20
High / Critical
A02:2021 — Cryptographic Failures
17
High / Critical
Roadmap
First, codify disaster recovery by documenting RTO/RPO and restore procedures in infrastructure as code, and immediately resolve the five leaked secrets in configuration files. Next, expand test coverage by adding tests for currently unreached production modules to ensure code reliability. Finally, maintain release hygiene by keeping a changelog and clean up dependencies by removing unused packages and properly categorizing development tools.
Ranked by impact ÷ effort. "Helps" is the estimated gain on the 0–100 health score.
Do this
Helps
Effort
Dimension
Resolve the 5 Leaked secret finding(s) in REDACTED Scanning — start with REDACTED, REDACTED, REDACTED.
Dependabot is configured but does not watch `pip`, `composer`, `bundler` — add those `package-ecosystem` entries to .github/dependabot.yml so those dependencies get the same automatic update and advisory pressure as the ones it already covers.
TypeScript/JavaScript: use the promise APIs (fs/promises, a promisified child_process.execFile, the async zlib/crypto functions) and await them instead of the *Sync variants.
Add a benchmarking harness for the hot paths and run it in CI to catch regressions (for .NET, a BenchmarkDotNet project with [MemoryDiagnoser] to track allocations).
Per-file score 0–10 — a quality signature. Of 438 files carrying findings, judged against the Preview bar: 2% slop · 14% mixed · 84% near-clean.
File
Score
Band
Worst signal
REDACTED
0.0
Slop
IaC & Container Security: High IaC: REDACTED
REDACTED
0.2
Slop
IaC & Container Security: High IaC: REDACTED
REDACTED
1.3
Slop
Static Analysis (SAST): High: REDACTED
REDACTED
1.3
Slop
IaC & Container Security: High IaC: REDACTED
REDACTED
2.7
Slop
IaC & Container Security: High IaC: REDACTED
REDACTED
2.7
Slop
IaC & Container Security: High IaC: REDACTED
REDACTED
2.7
Slop
IaC & Container Security: High IaC: REDACTED
REDACTED
2.7
Slop
IaC & Container Security: High IaC: REDACTED
REDACTED
3.0
Mixed
REDACTED Scanning: Leaked secret: REDACTED
REDACTED
3.0
Mixed
IaC & Container Security: High IaC: REDACTED
REDACTED
3.3
Mixed
IaC & Container Security: High IaC: REDACTED
REDACTED
3.5
Mixed
IaC & Container Security: High IaC: REDACTED
REDACTED
3.5
Mixed
IaC & Container Security: High IaC: REDACTED
REDACTED
3.7
Mixed
IaC & Container Security: High IaC: REDACTED
REDACTED
4.4
Mixed
REDACTED Scanning: Leaked secret: REDACTED
REDACTED
4.4
Mixed
Static Analysis (SAST): High: REDACTED
REDACTED
4.4
Mixed
Static Analysis (SAST): High: REDACTED
REDACTED
4.4
Mixed
Static Analysis (SAST): High: REDACTED
REDACTED
4.4
Mixed
Static Analysis (SAST): High: REDACTED
REDACTED
4.4
Mixed
Static Analysis (SAST): High: REDACTED
How the grades work
Every finding carries one of four grades. Three say how serious it is. The fourth says this
survey could not settle it — and it is a grade, not a gap.
Critical — 277
A definite problem that already costs you something and drags the score down: a
missing authorisation check, a dependency with a known exploit, a build that does not reproduce. Failure here
tends to cause failures elsewhere.
Serious — 1461
Likely wrong, but not failing yet. It degrades
the codebase over a longer horizon and can cause failures elsewhere — not urgent this week, not something to
carry for two years either.
Minor — 103
Recorded, with no effect on how the codebase functions.
Present so the survey is complete, not because it needs doing.
Could not be resolved — 3
Something this survey could not settle
from the outside, and which could be critical or serious. Either a control was required and no
positive evidence of it exists in the repository — a backup job that nothing shows was ever restored from proves
nothing about restores — or our own analysis could not run over that part of the tree. This is not a clean
result. These are excluded from the score rather than awarded a pass, so the number on the cover neither
rewards nor penalises them: if you act on this survey without resolving them, you carry that risk yourself. Each
one is named under Limitations.
Methodology & how to trust this report
Watchdog is a deep, periodic assessment — run each sprint, monthly, or quarterly, taking the time to go wider and deeper than a quick check and surfacing in one coherent report what you'd otherwise piece together from a dozen separate tools. It scores deterministically: the same commit yields the same score, every run. 85 of 92 evaluated dimensions are computed purely by tools and static analysis (confidence 1.0); 7 documentation/naming judgement(s) are LLM-assisted and labelled advisory. Overall confidence is 0.9 — the weighted average across measured dimensions; it falls as more of the score leans on LLM-assisted judgement and rises when it's fully tool-backed.
Every figure here is one of three kinds, and we label which: ✓ Measured — a deterministic fact (LoC, complexity, coverage); ~ Modeled — an estimate from a stated model (cost, effort, value-at-risk), always a range with its assumptions, never a precise fact; ◐ Advisory — an LLM prose judgement. We never present a modelled estimate as if it were measured. Perfect or absent scores carry their provenance too (ADR-0011): ✓ Tool-verified means the property itself was measured across the surface; ○ Nothing flagged means the probes came back clean — a claim bounded by what a repository can show; ⊘ Not evidenced means a working control (a tested restore, an automated rollback) showed no positive evidence — absence of evidence is not evidence of a control, so it's excluded from the score rather than awarded a spurious 10; ◐ Sampled · advisory marks an LLM verdict over a bounded sample — advisory, never a deterministic measurement.
What we checked — 92 dimensions across the health lenses
Each chip is a dimension scored from real signals across architecture, testing, dependencies, security & compliance, documentation, git-history and code quality — in one coherent pass. A surface report typically covers a handful.
How to trust any code-health report — three questions
Can you open the finding? Real findings cite a repo-relative file and line you can open at the cited line — never an absolute scratch path. Here, 1750 of 1841 do; the remainder are repo-wide signals — a dimension-level measurement, not a single line. (Every path in this report is repo-relative by construction: paths are normalized at the producer and the report is rejected if any rooted path leaks through.)
Is there a tool behind the number? Every score below names the method that produced it — Roslyn, git, a scanner, or (for a handful of documentation/naming dimensions) an LLM labelled sampled · advisory — not a narrative.
Does re-running give the same result? Run it again on the same commit and the score — and this report, byte for byte — is identical. A report whose numbers move between runs is describing the run, not the code.
This report answers yes to all three. That's the bar to hold any assessment to.
Tools & methods
The actual versions used this run (captured at analysis time) — re-run on the same commit for the identical score.
Method
Backs
Version
Evaluator
Roslyn static analysis
Complexity, cohesion, coupling, dead code, API surface, layering
What ran differently this time — a tool absent, degraded, or that fell back to an estimate. Named openly, not folded silently into the scores. A degraded run also records its exact cause in diagnostics.md.
D8 Code Coverage — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Coverage NOT MEASURED: the analyzer environment could not build/run this repository's test suite, whose production source is .cpp, .go, .java, .php, .py, .rs, .swift, .ts. This is OUR limitation, not a defect in the repo — coverage is excluded from the score rather than counted as a near-zero. We track the analyzer-image gap so it can be closed; in the meantime, produce a coverage report in a standard format (Cobertura — `dotnet test --collect:"XPlat Code Coverage"` with a `coverlet.collector` PackageReference (.NET: C#, VB.NET and F# alike), lcov — `swift test --enable-code-coverage` or `xcodebuild -enableCodeCoverage YES` then `xcrun llvm-cov export -format=lcov` (Swift/Xcode), `cargo llvm-cov --lcov`, `go test -coverprofile`, `rebar3 do eunit --cover, cover` or covertool (Erlang/BEAM), `flutter test --coverage` or `dart test --coverage=coverage` then `dart run coverage:format_coverage --lcov` (Dart/Flutter), `sbt clean coverage test coverageReport` via the sbt-scoverage plugin in `project/plugins.sbt` (Scala/sbt), jest/nyc, JaCoCo/Cobertura XML, coverage.py … most ecosystems' coverage tools can emit one) and commit it — a hosted scan measures a clone of the repository, so a report that exists only in a working tree, a CI runner's or your own, never reaches it; the artefact is commonly gitignored, so `git add -f` that one file (or un-ignore its path) and commit it alongside the code it measures and real coverage will be read. You can widen what we reach: optional: commit the Cobertura/OpenCover/lcov report your CI already produces, and the real number is read on the next scan.
D10 Test Quality — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. The 667 test(s) behind this row are the ones the C# collector could read, and this repository also carries at least 694 test source file(s) (.go, .java, .py, .rs, .ts, .mjs) that it cannot: it parses C# syntax and matches C# test attributes, so a vitest/jest/JUnit/pytest-style suite is invisible to it. Skipped tests, zero-assertion tests and the other quality signals on this row are UNMEASURED in that suite — their absence from the counts above is a gap in this analyzer's language coverage, not a finding that those tests are sound.
D11 Test Reliability — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. Test reliability NOT MEASURED: the test run produced no results for any test tier, so no test ever ran and flakiness could not be exercised. The cause could not be attributed, so it is excluded from the score rather than read as an absence of tests.
D14 License Compliance — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. This repository declares a Cargo manifest, but the licence verdict published here was taken over its NuGet package dependencies. Nothing was read about its Cargo dependencies' licensing in either direction, and a clean score on this card must not be read as covering them.
D14 License Compliance — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. This repository declares package.json, but the licence verdict published here was taken over its NuGet package dependencies. Nothing was read about its npm dependencies' licensing in either direction, and a clean score on this card must not be read as covering them.
D15 Churn × Complexity Hotspots — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. A hotspot's complexity is meant to be the worst body its churn actually touched. For core/simulator/src/workload/ops/mod.rs that could not be established — the complexity reader for the file reports no body extents, or the history carries no per-line attribution — so the row quotes the file's worst body, which the counted changes may never have touched. The churn count is unaffected.
D17 Explicit Debt — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. The 8 deducted marker(s) and the 0.6/KLoC density on this row were taken over this repository's .NET projects ALONE: .rs (407,510 lines, 82% of production source) went unread, because every marker collector on this path is reached through a C# workspace. A read-only sweep of that source finds at least 52 task marker(s) (TODO/FIXME/HACK/XXX) across 40 file(s) that this score does not count — a floor, since only line comments are read there and D17's other eight marker kinds (suppressions, NoWarn, editorconfig severities, empty catches, commented-out code, Obsolete, dead code, preprocessor branches) need a compiler we do not have for that language. The debt in that source is UNMEASURED — its absence from the score above is a gap in this analyzer's language coverage, not a finding that the code carries none.
D23 Boundary Type-Coupling — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. At 500k LoC across 24 projects this is a large multi-module system that clearly needs explicit bounded contexts. Bounded contexts cannot be inferred from a codebase that is not physically organised by them (D-321), so with none declared there are no boundaries for the coupling pass to measure across. You can widen what we reach: name this codebase's bounded contexts (≥2 module groups, e.g. per subsystem) so cross-boundary type coupling can be assessed. Declare them in `.codehealth/config.yaml` at the repository root (create it if absent), mapping each context name to the module-path or namespace prefixes that belong to it — e.g. `architecture:` → `contexts:` → `Billing: ["src/billing", "Acme.Billing"]`, `Catalog: ["src/catalog", "Acme.Catalog"]`.
D32 Data Compliance (PII/GDPR) — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. `foreign/csharp/Iggy_SDK/Exceptions/VsrRequestOutcomeUnknownException.cs`, `foreign/csharp/Iggy_SDK/Exceptions/VsrSessionEvictedException.cs`, `foreign/csharp/Iggy_SDK/Utils/ArrayPoolHelper.cs`, `foreign/csharp/Iggy_SDK/Vsr/ConsumerGroupClientState.cs`, `foreign/csharp/Iggy_SDK/Vsr/VsrConnection.cs`, … (+5 more) produced a parse error, so every rule in this engine's `gdpr.yml` was absent there. That absence is NOT a clean result: these rules detect personal data crossing a boundary into a log sink, a URL or browser storage, and a file that was never parsed cannot report any of the three. The rest of the tree analysed normally and its rows above stand; only these files are unaccounted for. You can widen what we reach: fix the syntax error (or exclude the file deliberately) and re-scan to cover it.
D39 IL Efficiency — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. IL NOT MEASURED: the analyzer's own build of this repository failed for an ENVIRONMENT reason (exit 1) — MSBuild's engine or the CLR gave up, or our image does not carry the SDK band/targeting pack this repository needs. This is OUR limitation, not a defect in the repo, and it is not a statement that this repository fails to build. D18 owns the question of whether this repository builds; it was not answered here.
P8 Schema migrations — not measured this run — Watchdog could not measure this here. That is a gap on our side — a collector, parser or image we have not built yet — and it is neither a defect in this repository nor evidence that the check would have passed. The schema may be created by a runner, a deploy script or a config file outside what this check reads, so an absence here is our blind spot rather than a missing migration strategy. The card abstains instead of scoring. You can widen what we reach: if the schema is created and evolved by a tool this check does not name, naming it lets us teach the detector to read it.
R10 Code Duplication — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. 4 further occurrence(s) are not listed individually; the score already reflects all 44.
R4 Test Coverage — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. 95 further occurrence(s) are not listed individually; the score already reflects all 135.
R7 Dead Code — measured, with a gap in what it reached — Watchdog measured this, but not all of it. What it did not reach is a gap on our side — a collector, parser or image we have not built yet — so the numbers on that dimension cover less than the repository, and the part left out is not evidence that it would have passed. 80 further occurrence(s) are not listed individually; the score already reflects all 120.
Repo exclusion declarations: 14 pattern(s) declared (.gitattributes linguist-generated/vendored, .editorconfig generated_code) excluded 0 source file(s) from code-quality scoring. Declarations are the repo's own visible statement that a tree is machine-written or vendored — auditable in any diff, honored by GitHub the same way.
Limitations & what we did not check
Watchdog assesses the repository exactly as committed, and only the repository. By design it does not reach outside the source tree: the live cloud account, the running CI/CD pipeline, the host's branch-protection and approval rules, the production configuration, or a restore actually exercised against a backup are all out of scope. That boundary is a feature, not a gap — a repo-relative, deterministic scan re-runs identically on any commit and every finding opens at a real file and line, where a live audit can neither be reproduced nor traced. The visible consequence is that controls which leave no in-repo evidence are reported as "not evidenced" and excluded from the score rather than awarded a number a static scan cannot justify.
Per-dimension blind spots
For each dimension that was measured, what a static, repo-only scan structurally cannot see — the honest edge of the measurement, not a failure of it.
D1 Cyclomatic Complexity: Cyclomatic complexity counts branches statically — it cannot tell an essential decision tree from accidental tangle, nor see complexity that lives in data or configuration (large switch-case token tables, DSL lexers/parsers, data-as-code rule tables) rather than control flow: a tokenizer's many single-character cases read as high complexity though each branch is trivial.
D2 Cognitive Complexity: Cognitive-complexity heuristics approximate how hard code is to follow; genuine domain difficulty and well-named intent that eases reading are not captured.
D3 God Classes: "God class" is sized by members and responsibilities visible in the type — a deliberately broad facade over a coherent subsystem can read the same as an accidental grab-bag. For front-end JS the file-length check is cohesion-aware (a single-responsibility module — one class/IIFE — earns a 3× threshold), but cohesion is approximated from top-level declarations, not true dependency structure.
D4 Code Duplication: Duplication is token-similarity — an in-process token-stream comparison over sliding windows, with type-aware normalization — so it finds copy-paste, not semantic duplication expressed differently. Committed machine-written code (scaffolded migrations, designer/codegen output, protobuf/OpenAPI stubs, model snapshots) is EXCLUDED — its repetition is the tool's, not the team's — so the score reflects hand-written duplication only.
D5 Coupling: Coupling is measured between projects/assemblies — runtime coupling through DI, reflection, messaging or shared databases is invisible to a static reference graph.
D6 Cohesion (LCOM4): LCOM4 cohesion is syntactic — it infers connectivity from which methods touch which fields/methods by name, not from real runtime behaviour or intent.
D9 Test Distribution: The test-pyramid shape is inferred from project/folder naming and references, with a single test host bucketed per-file by its path tier and content signals — a suite that names tiers unconventionally and gives no per-file signal can still be mis-bucketed.
D10 Test Quality: Assertion density is structural — it cannot tell a meaningful behavioural assertion from a trivial one, only that an assertion is present.
D12 Dependency Hygiene: Dependency health reads manifests and lockfiles — a vulnerability in a vendored/copied dependency, or risk from how a dependency is actually used, is outside this view.
D13 REDACTED Scanning: REDACTED detection is signature- and entropy-based on the current tree — a secret that does not match a known pattern, or one already rotated, will not be flagged (a clean scan is "nothing matched", not "no secrets exist").
D14 License Compliance: License compatibility is checked against declared package metadata and a policy — mislabelled or missing license metadata, and obligations that depend on how you distribute, are not resolved here.
D15 Churn × Complexity Hotspots: Churn hotspots come from git history — a freshly imported or squashed repository has no churn signal, and recent rewrites can mask a historically risky file.
D16 Bus Factor: Bus-factor is a time-decayed model of commit attribution (who has recently, repeatedly worked a file), not comprehension — pairing, review and reading-without-committing spread knowledge it can't see; bot commits and shared accounts still distort it.
D17 Explicit Debt: Acknowledged-debt signals (TODO/FIXME, suppressions, dead code) are textual — undocumented debt that nobody marked, and debt that lives in design rather than annotations, is invisible. Committed machine-written code (scaffolded migrations, designer/codegen output, generated stubs) is excluded — it is never the team's dead code to delete.
D19 Documentation Quality: Documentation quality is judged by an LLM over a bounded sample of docs — it reads what is written, not whether the docs match the running system, and it is advisory, not a measurement. Its critique rows are drawn from a closed category vocabulary and each row means the same thing in every run, so two scans can be compared row by row; the SET that fires is still a sample, and does not repeat exactly. Measured on one frozen input, six scans at one engine SHA: 2-5 critique rows per scan, 8 distinct rows across the six, 3 of those 8 seen in only one scan. So a D19 row is evidence about the documentation, but a COUNT of D19 rows is not a quantity — never read a change in it as an improvement or a regression.
D21 Naming Consistency: Naming quality is an LLM judgement over a bounded sample — it assesses clarity/consistency of the names it sees, not domain-correctness, and is advisory.
D22 Internal API Consistency: API-surface coherence is an LLM judgement over a sample of the public surface — consistency of intent across the whole API is approximated, not exhaustively verified.
D24 Comment Value: Comment value (WHY vs WHAT) is an LLM judgement over a bounded sample — it is advisory and cannot weigh a comment against the precise code change it was written to explain.
D26 Project Cohesion: Project focus is sized from members/namespaces per project — a project that is broad by deliberate design reads the same as one that has sprawled.
D28 Secrets (history): Secret-history scanning sweeps the git log for known patterns — a secret that predates the available history, or never matched a signature, is not found (clean means "nothing matched in the history we can see").
D29 Static Analysis (SAST): SAST findings are pattern-based (semgrep) — it finds classes of bug it has rules for; logic flaws, auth/authorization gaps and issues needing runtime context are out of reach (and clean means "no rule matched").
D30 Dependency Vulnerabilities: CVE matching depends on accurate package/version metadata and on the advisory databases — a vulnerability with no published advisory, or in code not declared as a dependency, is not seen. Coverage needs a RESOLVED graph: an unpinned requirements.txt, or a pom without a resolved build, yields partial coverage rather than a clean verdict. An ecosystem the analyzer cannot scan is reported as unmeasured, never as clean.
D31 IaC & Container Security: IaC scanning checks Dockerfiles/Terraform/Kubernetes against best-practice rules — it cannot see the live cloud account, runtime configuration, or drift between the committed config and what is actually deployed.
D34 Knowledge Freshness: Freshness is decayed commit RECENCY, not comprehension — code read often but rarely committed reads as orphaned, and stable code that genuinely needs no changes is penalised the same as forgotten code; bot/squash commits distort it like the bus factor.
D35 Change Coupling: Change coupling is co-change in COMMITS — files split across separate commits, or coupled only through a shared config/build step, read as uncoupled, and a sweeping commit (rename/format) is excluded so it doesn't couple everything. It shows that files change together, not WHY: a high coupling can be a healthy cohesive pair as readily as a hidden leak.
D40 Network Egress Confinement: Egress confinement is read from committed Kubernetes manifests — a policy applied out-of-band (cluster-default deny, a service mesh, or a cloud firewall/security group off-repo) is invisible, and a present NetworkPolicy is declared config, not proof the cluster admission-controller actually enforces it at runtime.
D41 Kernel & Syscall Confinement: Syscall/MAC confinement is read from committed manifests — a profile applied by a cluster-wide PodSecurity default or a mutating webhook off-repo isn't seen, and a declared seccomp/AppArmor profile is config presence, not proof the node's kernel actually loaded and enforced it.
D43 Malicious Dependencies: Only packages some vulnerability database has already NAMED as malicious are seen — a compromise published in the last hours, or never reported at all, is invisible here, and this dimension reading 10 is not evidence that a dependency is trustworthy. There is no typosquat or dependency-confusion analysis: a package nobody has reported is simply absent from the feeds. Coverage is the dependency scan's: an ecosystem that could not be scanned is disclosed as unmeasured, never as clean.
D44 Platform End-of-Life: The support table is FROZEN, so it goes out of date by losing RECALL: a release that ended support after the table was written is missed until the table is refreshed, and this dimension reading 10 is not evidence that a platform is current. Only platforms the repository DECLARES in a place this pass reads are seen — a runtime named only in a REDACTED (D31's subject), in a CI workflow (D29's), or in a file this pass does not parse (REDACTED, a Gemfile ruby directive) is invisible here, which is why a repository declaring none of them abstains rather than scoring. Only frameworks with a PUBLISHED support policy are tracked: React, Flask and Express publish none, so their age cannot be judged and their absence from a report is not a statement that they are supported.
AX10 Code composition: Role is inferred from namespace/folder convention, not semantics — a domain concept living in a folder named "Services" reads as application, and the split is lines-of-code, not business value. The business-logic-share score is a SOFT, FLOORED signal: it contributes to the Architecture lens but is floored at the Critical gate, so an infrastructure-heavy design (a gateway, an ETL, a driver) is legitimately low without being nuked to zero.
AX9 CQS / query purity: Handlers are found by interface/name convention — a query handler using neither is not seen. Mutation is a resolved write/publish invocation (SaveChanges/repository/bus), so a write hidden behind a hand-rolled wrapper, reflection, or a string-keyed service locator resolves to a non-persistence type and isn't flagged; it detects that a query writes state, not whether the write is a legitimate read-side cache update. Clean means "no resolved write/publish in a query body", not a proof of CQS purity.
ED5 Idempotency: Idempotency is judged from the handler body's visible writes and guards — a guard enforced by a database unique constraint, a broker's exactly-once delivery, or a domain method whose no-op-when-applied logic the scan can't follow may read as at-risk; the at-risk candidates are confirmed by a SAMPLED LLM verdict (advisory, not exhaustive) and degrade to heuristic-only when no model is configured. It flags the at-least-once double-apply SHAPE, not a runtime proof of a duplicate effect.
M4 Documentation accuracy: Onboarding quality is an LLM read of the docs/setup present — it cannot run the onboarding or measure how long a real new joiner takes; the verdict is sampled and advisory.
P4 Deployment & Rollback: Approval/branch-protection rules live in repository settings the scan cannot see — only their in-repo evidence (config files, workflows) is checked, so a control enforced purely in the host's settings reads as "not evidenced".
P5 DR & Backup: Backup/restore and disaster-recovery readiness is judged from in-repo evidence — a config that exists is not a tested restore, so the absence of positive evidence is reported as "not evidenced", never scored as present.
P6 Release Hygiene: Rollback/observability controls are inferred from repo artefacts (pipelines, dashboards-as-code) — controls configured in external tooling, with no in-repo trace, cannot be credited.
The LLM boundary
LLM-set scores this run (7): D19, D21, D22, D24, D26, ED5, M4 (model: Local LLM). For these, a model reads a bounded sample and sets the numeric score; each names its own sample and method on its card. They are sampled and advisory by design: they vary at the margins between runs and are never a deterministic measurement. Every other score in this report is tool-computed at confidence 1.0.
What it measures: How tangled the control flow is — methods with many branches are hard to test and change.
Method: Cyclomatic complexity per method (1 + decision points), computed exhaustively across production source; test projects separated by convention. Deterministic.
120 method(s) exceeded the cyclomatic complexity threshold of 15; the worst was IggyShard::tick_partitions at 66. A further 39 method(s) were over the threshold but excluded as flat dispatchers (a long switch/match over independent cases: many branches, almost no nesting), the largest being IggyErrorCode.name at 241 — they are counted neither in the figure above nor in this dimension's score. 23 files carry no cyclomatic complexity row at all for this reason — every one of their over-threshold methods was excluded, so the exclusion is disclosed nowhere in the file itself: foreign/swift/Sources/Iggy/Errors/IggyErrorCode.swift (IggyErrorCode.name at 241), foreign/node/src/wire/error.code.ts (error.code.translateErrorCode at 240), core/binary_protocol/src/dispatch.rs (iggy_binary_protocol::dispatch::lookup_command at 55), core/connectors/sources/postgres_source/src/lib.rs (iggy_connector_postgres_source::extract_column_value at 36), core/consensus/src/observability.rs (consensus::observability::operation_as_str at 34), and 18 more not listed here. They are named here because the per-file figures other dimensions report are taken BEFORE this exclusion, so such a file can show a high maximum complexity elsewhere in this report and nothing here, with nothing to reconcile the two.
+ 62 more group(s) — more in Appendix A; the complete list is findings.md.
What to do
Resolve the 15 IggyPartition finding(s) in Cyclomatic Complexity — start with iggy_partition.rs (11), state_transfer.rs (4). — One of this dimension's main actionable groups (15 warning-level).
Resolve the 14 IggyShard finding(s) in Cyclomatic Complexity — start with REDACTED (11), router.rs (2), poll.rs. — One of this dimension's main actionable groups (14 warning-level).
Resolve the 6 server finding(s) in Cyclomatic Complexity — start with mod.rs (2), reads.rs, partition_reconciler.rs. — One of this dimension's main actionable groups (6 warning-level).
Enforce Cyclomatic Complexity in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d1_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: How hard the code is for a person to follow, beyond raw branching.
Method: Cognitive complexity per method (Sonar-style nesting-penalized score), computed exhaustively over production code, excluding test projects. Deterministic.
+ 126 more group(s) — more in Appendix A; the complete list is findings.md.
What to do
Resolve the 22 IggyPartition finding(s) in Cognitive Complexity — start with iggy_partition.rs (17), state_transfer.rs (5). — One of this dimension's main actionable groups (22 warning-level).
Resolve the 17 IggyShard finding(s) in Cognitive Complexity — start with REDACTED (13), router.rs (3), poll.rs. — One of this dimension's main actionable groups (17 warning-level).
Resolve the 12 iggy_gateway_kafka finding(s) in Cognitive Complexity — start with bounds_guard.rs (7), state.rs, produce.rs. — One of this dimension's main actionable groups (12 warning-level).
Enforce Cognitive Complexity in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d2_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D3 · God Classes8.8 / 10Strong✓ Tool-verified
What it measures: Over-large classes that try to do too much ("god classes").
Method: God-class detection by line and method-count thresholds per logical type (partial classes unified), filtered for generated code and registration/contract false positives. Deterministic.
+ 1 more group(s) — more in Appendix A; the complete list is findings.md.
What to do
Resolve the 81 FileTooLong finding(s) in God Classes — start with REDACTED (12), server.rs (3), mod.rs (3). — One of this dimension's main actionable groups (81 warning-level).
Resolve the 34 ClassTooLong finding(s) in God Classes — start with REDACTED (7), client.rs (3), impls.rs. — One of this dimension's main actionable groups (34 warning-level).
Resolve the 33 TooManyMethods finding(s) in God Classes — start with REDACTED (4), client.rs (3), mod.rs (2). — One of this dimension's main actionable groups (33 warning-level).
Enforce God Classes in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d3_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Copy-pasted code that should be shared instead.
Method: Code duplication via token-stream sliding windows with type-aware normalization (locals masked, type names preserved), density-scored per KLoC of production code. Deterministic.
443 duplicated block group(s) detected. A further 21 rows report members as variants of one another; they aggregate block groups already counted above and are not themselves counted. 75 of the 464 are in trees this repository does not ship — vendored, example/demo, fixture and benchmark code — and are ranked below the shipped groups rather than excluded from them: the duplication there is real and is still counted in this dimension's score. The dimensions that publish a production-file census leave those trees out of theirs, so this count is deliberately drawn over the wider population.
+ 129 more group(s) — more in Appendix A; the complete list is findings.md.
What to do
Resolve the 39 Duplicated block (8 lines × 2) finding(s) in Code Duplication — start with REDACTED (2), client.rs (2), journal.rs (2). — One of this dimension's main actionable groups (39 warning-level).
Resolve the 31 Duplicated block (7 lines × 2) finding(s) in Code Duplication — start with REDACTED (3), hero.rs (3), TcpContracts.cs (2). — One of this dimension's main actionable groups (31 warning-level).
Resolve the 26 Duplicated block (11 lines × 2) finding(s) in Code Duplication — start with websocket_connection_stream.rs (3), sink.rs (3), REDACTED (2). — One of this dimension's main actionable groups (26 warning-level).
Enforce Code Duplication in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Verified — provenance only; does not change the score.
Detailed fixes: d4_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D5 · Coupling9.2 / 10Stronggated by 7 serious findings✓ Tool-verified
What it measures: Whether volatile projects sit underneath others that depend on them (so their churn ripples upward), and whether project dependencies form cycles. A widely-depended-on but stable shared/kernel project is healthy, not penalised.
Method: Dependency cycles via elementary-DFS over real .csproj references, plus Martin instability (afferent/efferent) per project. Exhaustive over the reference graph, deterministic.
Coverage: Exhaustive · type-level: afferent/efferent coupling + cycles computed over every production type — the population is all types, not a name convention.
62 production modules (Gradle+Cargo+npm+Go+SwiftPM), 0 dependency cycle(s), 1 unstable depended-on module(s). Read from the build's own module declarations; edges a convention plugin adds from buildSrc or build-logic are not visible there; 6 module(s) off the main sequence, with abstractness counted on 56 of the 62 (the rest declare no modelled class or interface, export only macros, or have no source directory of their own).
Off the main sequence: cpu_allocation · ×6
Unstable project server
What to do
Resolve the 6 Off the main sequence finding(s) in Coupling. — One of this dimension's main actionable groups (6 warning-level).
Resolve the 1 Unstable project server finding(s) in Coupling. — One of this dimension's main actionable groups (1 warning-level).
Enforce Coupling in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d5_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether a class's methods are focused on a single responsibility.
Method: LCOM4 cohesion per production class with at least two methods: connected components of methods sharing state or calls, computed syntactically. Deterministic, not a proxy.
Coverage: Exhaustive · type-level: LCOM4 cohesion computed over every production class — the population is all types, not a name convention.
Resolve the 1 Low cohesion finding(s) in Cohesion (LCOM4) — start with REDACTED. — One of this dimension's main actionable groups (1 warning-level).
Enforce Cohesion (LCOM4) in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Verified — provenance only; does not change the score.
Detailed fixes: d6_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D9 · Test Distribution9.8 / 10Exemplary✓ Tool-verified
What it measures: Whether the test suite has a healthy mix of unit / integration / end-to-end tests.
Method: Test projects classified (Unit/Integration/BDD/E2E) from compiled metadata; test methods counted exhaustively across projects with placement-agnostic disk fallback. Deterministic.
8953 test methods: 6893 unit, 1931 integration, 10 BDD, 119 e2e. The JavaScript/TypeScript suite contributes 390 `it`/`test` case(s) across 54 test file(s) declaring at least one beside 1326 .NET test method(s); its tier split is read from package names and paths only. The Rust suite contributes 6291 `#[test]` function(s) across 604 file(s) declaring at least one; its unit/integration split is Cargo's own — 130 of those file(s) are integration-test targets under a crate's tests/ directory, and the rest are #[test] functions compiled into the crate they test. The Python suite contributes 504 test function(s) across 16 file(s) declaring at least one — every `def test…` in a file pytest or unittest would collect, which is those frameworks' own definition of a case; a parametrize table counts once, so this is a floor. Its tier split is read from file names and paths only. The Go suite contributes 388 test case(s) across 46 `_test.go` file(s) declaring at least one — every `func Test…(t *testing.T)` that `go test` would collect, plus the suite methods a testify-style runner reaches; a table-driven case list counts once, so this is a floor. Its tier split is INFERRED from file names, paths and build constraints, not declared: 2 of those file(s) use Go's external test package (`package x_test`), which is a visibility boundary rather than a pyramid tier and was not read as one. The swift suite(s) contribute 54 test method(s), read from the language model's own test census — every XCTest `test…` method on an XCTestCase, every swift-testing `@Test` and every JUnit/TestNG `@Test`-annotated method, which is those frameworks' own discovery rule. Their tier split is INFERRED from the test target's name and path only, not declared.
✓ On the Gold path — maintain.
Detailed fixes: d9_recommendation.md.
Do you agree with this assessment?
D10 · Test Quality9.9 / 10Stronggated by 5 serious findings✓ Tool-verified
What it measures: Whether the tests truly assert behaviour rather than just running the code.
Method: Per-test assertions, skips, and mock references analyzed via Roslyn; structured skip-reason tags (BUG:/ENV:) separate documented deferrals from debt. Deterministic.
0 skipped, 5 zero-assertion, 1 mock references across 667 tests. Measured on the C# suite only — at least 694 test source file(s) (.go, .java, .py, .rs, .ts, .mjs) went unread, so its test quality is unmeasured and is not in these counts.
No assertions: CreateClient_TcpClientDisposesTwice · ×5foreign/csharp/Iggy_SDK_Tests/ClientTests/IggyClientFactoryTests.cs:91
Mock framework: Moq
What to do
Resolve the 5 No assertions finding(s) in Test Quality — start with CredentialBoundsTests.cs (2), IggyClientFactoryTests.cs, PooledBufferWriterTests.cs. — One of this dimension's main actionable groups (5 warning-level).
Enforce Test Quality in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d10_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether dependencies are current, secure, and not bloated.
Method: Manifest scan via dotnet list package across all projects; worst-signal-per-package deduction (saturating for vulnerabilities, capped-linear for deprecation/outdated) per KLoC. Exhaustive, deterministic.
4 outdated, 0 vulnerable, 0 deprecated packages. Those are the NuGet packages; this repository's npm dependencies were read too — 50 outdated of 114 package(s) across 4 lockfile(s).
Enforce Dependency Hygiene in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Verified — provenance only; does not change the score.
Detailed fixes: d12_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether any secrets (keys, tokens, passwords) have leaked into the code.
Method: In-process native secret scanner (entropy plus signature patterns) across all tracked files; no external tool. A clean result is a measured 10, not no-data zero. Deterministic.
Resolve the 5 Leaked secret finding(s) in REDACTED Scanning — start with REDACTED, REDACTED, REDACTED. — One of this dimension's main actionable groups (5 issue-level).
Enforce REDACTED Scanning in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d13_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether the licenses of third-party packages are compatible with your policy.
Method: Third-party package licenses resolved from declared package metadata and checked against the configured policy (allow/deny/copyleft). Deterministic; clean = no incompatible license found at metadata depth.
0 of 138 packages use a banned license. ★ DEPTH: this repository's MSBuild projects declare 19 direct `PackageReference`(s), and 96 further package(s) were reached beyond them by closing the graph over nuget.org's own nuspec dependency graph — so a banned licence pulled in only by a dependency's OWN dependencies is inside this verdict. A package whose licence nuget.org could not be asked for is not graded, and version ranges are taken at their lower bound, so this is the closure as that graph states it rather than a restored consumer's exact resolution. ★ COVERAGE OF THIS VERDICT: it grades this repository's NuGet package dependencies and nothing else. The repository also declares a Cargo manifest and package.json, and the licences of those dependency graphs were NOT read by this pass — a gap in this engine's coverage, not a statement about them. So this result says the graded closure carries no banned licence; it does NOT say this repository's licensing is clear.
What it measures: Files that change often and are also complex — the riskiest hotspots.
Method: Per production file churn times cyclomatic complexity over a rolling window, computed from git and Roslyn/JS/Razor analysis. Exhaustive, deterministic per commit date.
Top hotspots: core/shard/src/lib.rs (58×66=3828); core/partitions/src/iggy_partition.rs (53×36=1908); foreign/node/src/wire/error.code.ts (5×240=1200) Repeated repair below the complexity floor: core/shard/src/metrics.rs (11 of 18 changes were fixes); core/consensus/src/plane_helpers.rs (10 of 19 changes were fixes); core/server/src/boot/recovery.rs (7 of 12 changes were fixes)
Resolve the 58 Hotspot finding(s) in Churn × Complexity Hotspots — start with REDACTED (4), REDACTED (3), mod.rs (3). — One of this dimension's main actionable groups (58 warning-level).
Resolve the 20 Repeated repair finding(s) in Churn × Complexity Hotspots — start with metrics.rs (2), REDACTED (2), plane_helpers.rs. — One of this dimension's main actionable groups (20 warning-level).
Detailed fixes: d15_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D16 · Bus Factor9.5 / 10Exemplary✓ Tool-verified
What it measures: Whether knowledge is concentrated in too few people (the "bus factor").
Method: Living knowledge per author via time-decayed commit attribution (6-month half-life, focus weighting) across largest source files. Deterministic, avoids blame's mechanical-refactor false positives.
54 source file(s) have their living knowledge concentrated in one author (≥90% of recent, decayed contribution). The largest is core/message_bus/src/lifecycle/connection_registry.rs. Counted over 1199 of the 1968 production source files in this repository: the rest are under the ~2,400-byte size floor this dimension measures over.
Off-boarding risk: anonymized user #1 · ×5
Further sole-owners (lower concentration)
✓ On the Gold path — maintain.
Detailed fixes: d16_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D17 · Explicit Debt8.8 / 10Strong✓ Tool-verified
What it measures: Acknowledged debt left in the code — TODOs, dead code, suppressed warnings.
Method: Roslyn syntactic debt markers (suppressions/TODO/FIXME/HACK/empty-catch/commented-code/Obsolete) plus SymbolFinder dead-code analysis; weighted-debt-per-KLoC density deducted 2.0x per unit. Deterministic, exhaustive.
8 deducted debt markers + 58 dead symbols across 22625 LoC in the .NET projects (0.6/KLoC) → score 8.8. Measured on the .NET source only: .rs (82% of production source) was not read, and carries at least 52 uncounted task marker(s) in 40 file(s).
Dead code: ErrorFactory · ×58foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:22
Resolve the 58 Dead code finding(s) in Explicit Debt — start with ErrorFactory.cs (51), DummyObjFactory.cs (2), PermissionsFactory.cs (2). — One of this dimension's main actionable groups (58 warning-level).
Resolve the 8 TodoComment finding(s) in Explicit Debt — start with HttpMessageStream.cs (5), IggyConsumer.cs, ErrorFactory.cs. — One of this dimension's main actionable groups (8 warning-level).
Enforce Explicit Debt in CI to reach Verified (currently Documented). — Hardens enforcement from Documented toward Prevented — provenance only; does not change the score.
Detailed fixes: d17_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether the project's documentation is clear, complete, and useful.
Method: Judged by language model at low temperature (0.0-0.1) on a deterministic doc sample (READMEs plus first 25 architecture docs), with two-pass stability filtering. Advisory, sampled.
The repository's root README gives a strong overview (Apache Iggy website, releases badge, crates.io links) plus installation/usage guidance for the CLI and web UI. The bdd/README is an internal BDD test directory README that documents its own structure and quick-start command, while the examples/, gateways/, and core/binary_protocol/READMEs are per-directory READMEs (e.g., cross-SDK BDD tests, Web UI, AI module). All visible documents are well structured with headings and a consistent overview; the only unreviewed element is whether the root README's architecture/design docs are present. The internal-focused jargon ('[kafka](kafka/)' table) appears in non-clipped sections but does not violate any category. The repository's READMEs and examples directories are excellent: the core/sdk/README gives a clear overview of the Rust Iggy SDK for Apache Iggy, its transports, TLS, and an official crate badge plus links to docs, getting started, and examples; each example directory (core/server/, core/simulator/, examples/csharp/, examples/java/, examples/node/, examples/php/, examples/python/) is a focused README that documents what it contains with code samples for running the examples, configuration options, and a full outline of its sections. The architecture/Docs markdown files and XML-doc coverage are also strong. The repository's READMEs and architecture/Docs markdown files are well documented. The root README is the authoritative overview of the project (Apache Iggy SDK for message streaming), covering what it does, its two main tiers (C# and Go SDKs), and a link to the getting started guide. Each foreign language README (C#/.NET, Go) documents that directory rather than the repository as a whole, so its own scope is clear. The architecture/Docs files cover design decisions like binary-command support, new state bootstrap semantics, and multi-tenant auto-commit polling; they are well structured with an outline. Coverage across all Iggy_SDK packages (e.g. Examples.Shared) is thin but consistent with the visible content.
Resolve the 13 Low XML-doc coverage finding(s) in Documentation Quality — start with Shared.csproj, Benchmarks.csproj, Iggy_SDK.Examples.Basic.Consumer.csproj. — One of this dimension's main actionable groups (13 warning-level).
Resolve the 1 Documentation finding(s) in Documentation Quality — start with README.md. — One of this dimension's main actionable groups (1 recommendation-level).
Detailed fixes: d19_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether names — types, methods, variables — are clear and consistent.
Method: Judged by language model at low temperature (0.0-0.1) on a deterministic random symbol sample (fixed size, not exhaustive), with disclosed confidence band. Advisory, sampled.
1 naming inconsistencies across 200 sampled symbols.
Inconsistent use of 'Stop' vs 'Return' for test outcomes. The first test uses 'ReturnImmediately' to describe the method's return behavior, while the second uses 'StopCleanly' to describe the termination of an async operation. In the context of async cancellation, 'Return' or 'Complete' is more consistent with the 'ReturnImmediately' pattern, whereas 'Stop' is less precise for a method named 'ReceiveDeserializedAsync'.
✓ On the Gold path — maintain.
Detailed fixes: d21_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D22 · Internal API ConsistencyStrong◐ Sampled · advisory
What it measures: Whether the internal API surface is consistent and coherent.
Method: Judged by language model at low temperature over a sample of the public API surface (IsPackable or .Contracts types). Sampled, advisory; confidence discounted by model uncertainty.
3 API inconsistencies across a 400-member sample of 252 exposed types.
Inconsistent factory method naming convention. One uses 'For' and the other uses 'ForPersonalAccessToken'. Given that 'For' is already overloaded for credentials, 'ForToken' or 'ForAccessToken' would be more consistent with the existing 'For' pattern.
Duplicate intent across generic and non-generic builders. The non-generic `IggyConsumerBuilder` and generic `IggyConsumerBuilder<T>` have nearly identical `Create` signatures, differing only by the presence of a deserializer. This forces users to choose between two parallel builder hierarchies for essentially the same operation.
Ambiguous naming for similar operations. `ReceiveAsync` returns `ReceivedMessage` (which wraps `MessageResponse`), while `ReceiveRentedAsync` returns `ReceivedRentedMessage` (which wraps `RentedMessageResponse`). The distinction between 'Message' and 'RentedMessage' is not immediately obvious to a user and suggests a potential naming inconsistency regarding memory ownership semantics.
What to do
Resolve the 1 Inconsistent factory method naming convention. One uses 'For' and the… finding(s) in Internal API Consistency. — One of this dimension's main actionable groups (1 warning-level).
Resolve the 1 Duplicate intent across generic and non-generic builders. The… finding(s) in Internal API Consistency. — One of this dimension's main actionable groups (1 warning-level).
Resolve the 1 Ambiguous naming for similar operations. `ReceiveAsync` returns… finding(s) in Internal API Consistency. — One of this dimension's main actionable groups (1 warning-level).
Detailed fixes: d22_recommendation.md · top locations in Appendix A, every location in findings.md.
Do you agree with this assessment?
D24 · Comment ValueExemplary◐ Sampled · advisory
What it measures: Whether comments are worth it — explaining WHY (valuable) rather than WHAT (redundant).
Method: Judged by language model at low temperature (0.0-0.1) on deterministically sampled inline comments with surrounding code; findings verified back to sampled comments by substring match. Advisory, sampled.
1 of 19 projects flagged as possibly oversized/incoherent.
Projects may be oversized for their cohesion
What to do
Resolve the 1 Projects may be oversized for their cohesion finding(s) in Project Cohesion. — One of this dimension's main actionable groups (1 recommendation-level).
Detailed fixes: d26_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether any secrets were ever committed — scanned across the full git history, not just now.
Method: REDACTED scan via TWO gitleaks detect passes in an isolated checkout — the full git history, then a second --no-git pass over the working tree as it stands — merged and de-duplicated by (rule, file, line); each match flagged High. Both invocations are recorded in the audit trail. Exhaustive; when the tool is absent, or when its output cannot be parsed into the expected shape, the dimension is WITHHELD as an explicit measurement gap on our side — unscored and excluded from the lens, never a hedged middling score.
11 finding(s): 0 critical, 11 high, 0 medium, 0 low. Remediation for historically-committed secrets is credential rotation — they remain in history regardless of later deletion.
REDACTED
REDACTED
REDACTED
What to do
Resolve the 10 REDACTED finding(s) in Secrets (history) — start with REDACTED (5), REDACTED (3), REDACTED (2). — One of this dimension's main actionable groups (10 issue-level).
Resolve the 1 High secret finding(s) in Secrets (history) — start with REDACTED. — One of this dimension's main actionable groups (1 issue-level).
Resolve the 1 Rotate the exposed credentials finding(s) in Secrets (history). — One of this dimension's main actionable groups (1 recommendation-level).
Detailed fixes: d28_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Real static-analysis (SAST) findings — likely security bugs in the code, any language.
Method: Polyglot static analysis via semgrep across the repo using the pinned, image-baked p/security-audit + p/owasp-top-ten rulesets (no scan-time registry fetch); severity rules (ERROR/WARNING/INFO) map to a full-band severity-weighted score. Exhaustive, deterministic; degrades on parse failure.
Coverage: semgrep pattern rules over all files — exhaustive for the rule set, blind to classes of bug without a rule (clean = no rule matched).
232 finding(s): 0 critical, 225 high, 6 medium, 1 low. 117 unpinned-GitHub-Actions row(s) are reported here but scored by D36 (supply-chain provenance), which measures that posture as `pinned_actions` — one pinning decision is charged once, not once per lens. semgrep hit a parse error in 35 file(s) — `bdd/java/gradlew` (line 74, line 227), `core/sdk/src/clients/consumer.rs` (line 1216, line 1391, lines 1418–1419, …), `core/shard/src/lib.rs` (line 11590), `core/shard/src/poll.rs` (line 288, lines 289–290), `core/simulator/src/lib.rs` (line 1409, lines 1431–1433, line 1434, …), … (+30 more) — so no absence of findings in the named regions is evidence of anything; rows reported elsewhere in those files are real. Fix the syntax error (or exclude the file deliberately) and re-scan to cover them. In 9 of those file(s) — `foreign/csharp/Iggy_SDK.Tests.Integration/Attributes/SkipHttpAttribute.cs`, `foreign/csharp/Iggy_SDK.Tests.Integration/Attributes/SkipTcpAttribute.cs`, `foreign/csharp/Iggy_SDK/Exceptions/VsrRequestOutcomeUnknownException.cs`, `foreign/csharp/Iggy_SDK/Exceptions/VsrSessionEvictedException.cs`, `foreign/csharp/Iggy_SDK/Utils/ArrayPoolHelper.cs`, … (+4 more) — the break is a C# primary constructor, which semgrep's grammar cannot parse and which hides the type from every rule scoped to it; those files were re-scanned from a shadow copy with the constructor's parameter list blanked (line and column preserving), which restores the type to the rules, and 0 additional row(s) came from that pass. Only the header's own parameter list is unread in them. In 1 of those file(s) — `foreign/csharp/Iggy_SDK/Exceptions/VsrRequestOutcomeUnknownException.cs` — the break is at a TYPE DECLARATION (a C# primary constructor semgrep's grammar cannot parse), so the loss is wider than the named lines: rules scoped to that type see no type to scope to and are blind over its whole body, while rules matching statements keep working there. Absence of a type-scoped finding in those types is not evidence of anything. Separately, one or more rules could not re-parse an embedded snippet in 31 file(s) (e.g. a workflow `run:` block read as shell). Those files WERE scanned and their other rows are unaffected; only those rules' view of those snippets is missing.
REDACTED
REDACTED
REDACTED
REDACTED
REDACTED
+ 7 more group(s) — more in Appendix A; the complete list is findings.md.
What to do
Resolve the 46 REDACTED finding(s) in Static Analysis (SAST) — start with REDACTED (33), REDACTED (5), REDACTED (5). — One of this dimension's main actionable groups (46 issue-level).
Resolve the 33 REDACTED finding(s) charged to Static Analysis (SAST) — the other 117 are reported here at file:line but scored by D36 (supply-chain provenance), which charges them once. — One of this dimension's main actionable groups (150 issue-level, 33 of them charged here).
Resolve the 16 REDACTED finding(s) in Static Analysis (SAST) — start with REDACTED (7), REDACTED (7), REDACTED. — One of this dimension's main actionable groups (16 issue-level).
Detailed fixes: d29_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether any dependency has a known published vulnerability (CVE), direct or transitive, in ANY ecosystem the repository declares — Dart pub, Elixir and Erlang via Hex, Go modules, Java and Kotlin via Maven/Gradle, JavaScript/npm, .NET/NuGet, PHP/Composer, Python/PyPI, RubyGems, Rust/Cargo and Swift.
Method: Dependency-CVE scan across every ecosystem the repository declares, scored ONCE. Three sources are unioned and deduplicated by advisory identity (rule id + alias closure, CVE<->GHSA) scoped to package+version, keeping the worst severity: `osv-scanner --recursive` over osv.dev for Dart pub, Elixir/Hex (and Erlang, whose `rebar.lock` syft first converts to a CycloneDX SBOM the scanner reads, with rows attributed back to the lock), Go, Java and Kotlin via Maven/Gradle (and Scala, whose sbt build's pinned direct declarations are written into a CycloneDX SBOM the scanner reads, with rows attributed back to the build file), npm, PHP/Composer, Python/PyPI, RubyGems, Rust/Cargo and Swift; `trivy fs --scanners vuln` for npm lockfiles; and `dotnet list package --vulnerable --include-transitive` for NuGet (with per-advisory collapse of the project x target-framework fan-out), plus a DECLARED-dependency arm that resolves a published gem's gemspec against rubygems.org where no Gemfile.lock is committed. `SeverityScore(c,h,m,l, normalizer 8.0)`. NotApplicable only when NO ecosystem is readable; if any applicable ecosystem could not be scanned the findings are REPORTED and the score is withheld. Supersedes the npm and OSV arms, retired 2026-09-05.
Resolve the 1 High CVE finding(s) in Dependency Vulnerabilities — start with REDACTED. — One of this dimension's main actionable groups (1 issue-level).
Resolve the 9 Medium advisory (unmaintained) finding(s) in Dependency Vulnerabilities — start with REDACTED (9). — One of this dimension's main actionable groups (9 warning-level).
Resolve the 7 Medium CVE finding(s) in Dependency Vulnerabilities — start with REDACTED (4), REDACTED (2), REDACTED. — One of this dimension's main actionable groups (7 warning-level).
Detailed fixes: d30_recommendation.md · top locations in Appendix A, every location in findings.md.
Resolve the 42 Medium IaC finding(s) in IaC & Container Security — start with REDACTED (27), REDACTED (7), REDACTED (5). — One of this dimension's main actionable groups (42 warning-level).
Resolve the 34 High IaC finding(s) in IaC & Container Security — start with REDACTED (22), REDACTED (5), REDACTED.test (5). — One of this dimension's main actionable groups (34 issue-level).
Resolve the 17 Low IaC finding(s) in IaC & Container Security — start with REDACTED (11), REDACTED (6). — One of this dimension's main actionable groups (17 recommendation-level).
Detailed fixes: d31_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether anyone still has living knowledge of each file, or it has been orphaned — last understood long ago by someone now gone quiet. The sibling of the bus factor: D16 asks who owns it, D34 asks whether anyone still knows it.
Method: File orphaning as total living-knowledge decay below one focused-commit's worth within a year, computed per-file from the D16 decay model. Exhaustive, deterministic over fixed history.
111 of 1199 significant source file(s) are orphaned — their living knowledge has decayed to nothing, so no one currently understands them. The largest is core/cli/src/args/permissions/stream.rs. Counted over 1199 of the 1968 production source files in this repository: the rest are under the ~2,400-byte size floor this dimension measures over.
Resolve the 1 Orphaned knowledge finding(s) in Knowledge Freshness — start with stream.rs. — One of this dimension's main actionable groups (1 issue-level).
Resolve the 1 Further orphaned files (smaller) finding(s) in Knowledge Freshness. — One of this dimension's main actionable groups (1 recommendation-level).
Detailed fixes: d34_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether files that change together actually belong together — pairs that repeatedly co-change in git history despite having no explicit code dependency, surfacing the hidden/logical coupling (and boundaries in the wrong place) a static scan can't see.
Method: Pairwise co-occurrence over the per-commit file sets in git history (production source only — tests and generated dropped): Degree-of-Coupling = shared ÷ min individual revisions, reported above noise floors (each file ≥10 revisions, ≥5 shared commits, ≥50% strength); sweeping commits excluded. Deterministic over fixed history.
Coverage: Population: PRODUCTION source files only — test and generated files are dropped before pairing, so a class co-changing with its own test (trivially ~100%) can't drown the real production↔production coupling. Pairs ranked by Degree-of-Coupling. A non-source file is never a coupling PARTICIPANT either: documentation, schemas, config and data files are dropped with the rest, so a code↔docs pair — a command and the reference page that restates it — is not reported however strongly the two co-change; nor is coupling that runs THROUGH a build step or config file.
Resolve the 3 Change coupling finding(s) in Change Coupling — start with partition_helpers.rs, benchmark_producer.rs, iggy_partition.rs. — One of this dimension's main actionable groups (3 warning-level).
Detailed fixes: d35_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether the build pipeline provides supply-chain integrity — generated provenance/attestation, signed artifacts (cosign/sigstore), an SBOM, and pinned build actions. Presence of the configuration, not a runtime guarantee.
Method: Supply-chain provenance/signing read deterministically from CI/build config (.github/workflows, .gitlab-ci.yml, azure-pipelines, Jenkinsfile, .circleci) + the release surface: four signals — generated provenance/attestation (SLSA/in-toto/actions-attest), artifact signing (cosign/sigstore/gitsign), an SBOM (syft/sbom-action/*.spdx.json/*.cdx.json), and SHA-pinned build actions — scored 10·present/denom. NotApplicable without a build pipeline. Detects configuration presence, not runtime enforcement.
Resolve the 2 REDACTED finding(s) in Supply-chain Provenance & Signing — start with REDACTED (2). — One of this dimension's main actionable groups (2 warning-level).
Resolve the 1 REDACTED finding(s) in Supply-chain Provenance & Signing. — One of this dimension's main actionable groups (1 warning-level).
Resolve the 1 REDACTED finding(s) in Supply-chain Provenance & Signing. — One of this dimension's main actionable groups (1 recommendation-level).
Detailed fixes: d36_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether the repository publishes a coordinated-vulnerability-disclosure policy (SECURITY.md or security.txt) with a reporting contact, so finders know how to report a vulnerability. Presence of a policy file with a contact, not whether the policy is adequate or honoured.
Method: Vulnerability-disclosure policy read deterministically from the repo: a SECURITY.md (root/.github/docs) or .well-known/security.txt / security.txt, regex-checked for a reporting contact (email / URL / mailto). Present + contact → 10; present without a contact → 4; NotApplicable when no policy file exists (it may live off-repo). Detects the policy file's presence + contact, not its adequacy.
What it measures: Whether Kubernetes workloads restrict network EGRESS with a NetworkPolicy (or Cilium policy), limiting where a compromised pod can send data or reach a command-and-control server. Presence of committed egress-restricting policy, not runtime enforcement.
Method: Deterministic YAML-manifest inspection (no external tool, no Roslyn — language-agnostic): Kubernetes workloads gate applicability; credits a NetworkPolicy / Cilium policy that restricts egress (policyTypes: [Egress] / egress rules). Reward-leaning (neutral floor climbing to 10, never a deduction — baseline misconfigs stay with D31). Deterministic.
What it measures: Whether Kubernetes workloads confine the kernel boundary — a seccomp profile (RuntimeDefault/Localhost) plus an AppArmor/SELinux mandatory-access-control layer — shrinking the syscall attack surface a container escape would use. Presence of committed confinement config, not runtime enforcement.
Method: Deterministic YAML-manifest inspection (no external tool, no Roslyn): on Kubernetes workloads, credits a seccomp profile (RuntimeDefault/Localhost) and an AppArmor/SELinux MAC layer. Reward-leaning (neutral floor climbing to 10); NotApplicable without workloads. Deterministic.
Resolve the 1 No AppArmor/SELinux confinement finding(s) in Kernel & Syscall Confinement. — One of this dimension's main actionable groups (1 recommendation-level).
Detailed fixes: d41_recommendation.md · top locations in Appendix A, every location in findings.md.
What it measures: Whether any dependency the repository declares is published as MALICIOUS rather than merely vulnerable — a package that is an attacker's work, in any ecosystem osv-scanner reads. Scored apart from D30 because the answer is binary: there is no safe version to upgrade to, and the fix is to remove the package and rotate every credential it could have read.
Method: The same dependency scan D30 reads, partitioned on the scanner's own classification rather than rescanned: a row is MALICIOUS when its id is in the `MAL-` space (the ossf/malicious-packages feed) OR its `database_specific.cwe_ids` carries `CWE-506` ("Embedded Malicious Code"). Both channels are structural; the summary text is deliberately NOT read, because a malicious-package record whose summary says only "Critical severity vulnerability" is a real shape ([GHSA redacted]) and a text matcher misses it. Scored BINARY: any surviving row is 0, whatever its severity and however many CVEs sit beside it — a hostile dependency is not a quantity. Applicability and degradation are D30's: NotApplicable only when no ecosystem is readable, and an unscannable ecosystem degrades rather than reading clean. SCORED, not informational.
What it measures: Whether anyone still ships security patches for the platform this repository RUNS ON — the runtime it pins and the framework majors its own constraints hold it to. Separate from D12 because the question differs: a current Django on an end-of-life Python is perfectly up to date and completely unsupported, and the fix is a migration rather than a version bump. What the repository says it merely SUPPORTS is never charged.
Method: End-of-life PLATFORM read from the repository's own declarations and graded against a FROZEN, dated table of vendor support dates — no network, no feed, no API, so this dimension answers identically inside a closed scan fence. Two subjects: a RUNTIME the project pins (a single or all-end-of-life TargetFramework, a .nvmrc or .python-version, a requires-python CAP) and a FRAMEWORK major a dependency constraint cannot move off (a caret, tilde or exact version; `vue@^2.7.16` pins Vue 2). A FLOOR is deliberately never charged — `requires-python = ">=3.8"` states what a package SUPPORTS, not what it runs on — and a multi-target project is charged only when EVERY target is out of support. Runtime 4.0/product capped 8.0, framework 1.5 capped 4.5. The table is safe to freeze because a statement about support that ended in the past cannot become false: it loses recall as it ages, never precision, and a test asserts every entry predates the freeze date. Disjoint from D31 (a container image's OS layer) and D29 (the toolchain a CI workflow installs). Abstains when the repository declares no platform this pass reads — never scores it clean.
0 end-of-life runtime(s) and 0 end-of-life framework(s), read from 25 platform declaration(s) and 47 dependency declaration(s). This dimension reads what the repository says about ITSELF — a pinned target framework, a version file, a capped requires-python, a Rust toolchain pin, a framework major a constraint cannot move off. A FLOOR is deliberately never charged: `requires-python = ">=3.8"` states what the package SUPPORTS, not what it runs on, and a well-maintained library declares exactly that while running its own CI on a current release. The end-of-life facts are FROZEN and dated, so this dimension needs no network and answers identically inside a closed scan fence; as the table ages it loses recall and never precision, because a statement about support that ended in the past cannot become false. The OS layer of a container image is D31's question and the toolchain a CI workflow installs is D29's; this row is neither.
Other · Architecture — How the codebase splits by code ROLE — domain, application, infrastructure, test, generated. The significance map behind the knowledge/coupling weighting, and a DDD signal in its own right: a thin domain core under fat infrastructure is the anemic-domain smell, quantified. How each file's role is decided, because the split is only as good as that: a generated name or a build-output tree makes it Generated, a test project makes it Test, and otherwise the file's NAMESPACE and PATH words are matched against fixed vocabularies in a fixed ORDER — domain, then infrastructure, then application — so a file whose words hit two layers is counted under the earlier one. A production file matching none of them counts as application, so that share reads 'application or unclassified' rather than a measured application layer. Roles come from naming convention, never from what the code does.
Method: Roslyn line-count by code ROLE: every source file classified Domain/Application/Infrastructure/Test/Generated by namespace + path convention (the shared CodeRoleClassifier), then significant lines summed per role. Deterministic; the advisory score is the business-logic (domain+application) share of production code.
Coverage: Population: ALL source files, each bucketed into ONE of five roles (Domain/Application/Infrastructure/Test/Generated) by namespace + path convention — a file whose layer isn't named in the convention falls to Application (the neutral default), and the split is line-count, not semantic depth or business value.
What to do
The domain core is a small share of production code, but most of the rest matched no layer vocabulary at all — so this is not yet an anemic-domain finding. The namespace/path convention could not place that code, which makes the composition above a statement about the naming, not about the design. Name the layers (or check that the repository's conventions differ from the ones this check knows) before reading a thin domain into it.
Other · Architecture — Whether the project-reference graph is acyclic (cycles block independent build/deploy and signal eroding boundaries).
Method: Project reference cycles via elementary-DFS over real .csproj references, using the engine shared with D5/D7; cyclic versus acyclic. Exhaustive, deterministic.
Other · Architecture — Whether dependencies point inward (Domain ← Application ← Infrastructure/Web) — the clean-architecture dependency rule, checked across the project graph.
Method: Layer violations by name-segment inference (Domain/Core to Application to Infrastructure/Web) over the project-reference graph. Exhaustive over all projects, deterministic.
Other · Architecture — Whether the codebase has a recognisable, scale-appropriate structure (a named architectural style, or modular enough for its size) rather than being an ad-hoc ball of mud.
Method: Roslyn plus csproj analysis: architecture style detection (DDD, clean, vertical-slice, CQRS) and structure fitness for repo size. Deterministic.
Other · Architecture — Whether interfaces stay focused rather than fat — the Interface-Segregation principle (SOLID 'I').
Method: Roslyn scan: public interface declared-member counts (accessors fold into their property/event); fat-interface threshold (over 15 declared members) flagged per type. Each finding also reports the distinct-OPERATION count — members counted by name, so an overload group counts once — which decides whether it states the caller-side ISP harm or the implementer-side burden of an overload set. Deterministic, type-level.
Do you agree with this assessment?
AX8 · Test isolation10.0 / 10Exemplary✓ Tool-verified
Other · Architecture — Whether production projects stay free of references to test projects — tests may depend on production, never the reverse.
Method: Csproj graph: each production project checked for references to test projects (identified by test-framework presence, not name). Zero violations is clean. Deterministic.
Other · Architecture — Whether read (query) handlers stay side-effect-free — a query that writes persistent state or raises events breaks CQS and makes reads unsafe to retry, cache, or route to a read replica.
Method: Roslyn scan: CQRS handlers classified query-vs-command by interface (IQueryHandler/ICommandHandler/IRequestHandler<TQuery,TResult>) and name convention (*Query/Get*/Find* vs *Command); each query handler's body checked for persistent-state writes (SaveChanges/repository Add-Update) or event publishes by resolved invocation. Deterministic, type-level, exhaustive over the detected handlers.
Coverage: Population: CQRS handlers identified by IQueryHandler/ICommandHandler/IRequestHandler interface + *Query/Get*/Find*/*Command NAME convention; query purity then checked exhaustively within that set — a query handler using neither convention is invisible, and mutation is a resolved persistence/publish CALL, not full dataflow.
Other · Readiness — Whether retry-prone mutations (command handlers + message/event consumers) are idempotent so an at-least-once redelivery or client retry doesn't double-apply the effect — heuristic at-risk detection confirmed by language model, advisory.
Method: Roslyn heuristic (any mutation, ungated): command handlers and message/event consumers that mutate persistent state without a visible idempotency guard (exists/dedup check, upsert, idempotency-key/inbox, conditional/versioned write, fixed-value set) flagged as at-risk; each at-risk candidate then confirmed or cleared by a language model as genuinely non-idempotent versus naturally-idempotent. Advisory without a model (heuristic-only, degraded), per-candidate judged with one.
Coverage: Population: retry-prone mutations — command handlers (CQRS write side) + message/event consumers (IConsumer/I*EventHandler) — that mutate persistent state; runs on any repo with mutations, not only event-driven ones. The at-risk subset (no obvious guard) is a HEURISTIC candidate set, each then LLM-JUDGED non-idempotent vs safe; a handler outside those conventions, or a guard the LLM can't confirm, is bounded by the sample. Degrades to heuristic-only when no model is configured.
Other · Event Sourcing — Whether the recovery-replay fold is deterministic — state derived purely from each event's own fields, no clock/random/IO on the replay path.
Method: Roslyn syntax scan (event-sourcing gated): Apply/When folds checked for forbidden tokens (DateTime.Now, Guid.NewGuid, Random, IO), stripped of comments/strings. Deterministic, hard fact per fold.
Other · Event Sourcing — Whether domain events stay immutable (private fields, set once) rather than carrying mutable state.
Method: Roslyn scan (event-sourcing gated): persisted events checked for public setters; immutability verified per property/field. Deterministic, hard fact.
Other · Code Health — Unreviewed-generation residue: shipped members still throwing NotImplementedException, and placeholder string literals left in non-test, non-generated code. Scored as a quality signature, never as a claim about authorship.
Method: Roslyn syntax scan: NotImplementedException throws and placeholder string literals in non-test, non-generated shipped code. Deterministic, code-shape signature.
A shipped member still throws NotImplementedException — generated scaffolding that was never completed. Implement it or remove the dead surface. (×5) — foreign/csharp/Iggy_SDK/JsonConverters/ConsumerConverter.cs:27, foreign/csharp/Iggy_SDK/JsonConverters/ExpiryConverter.cs:37, foreign/csharp/Iggy_SDK/JsonConverters/MessageConverter.cs:27, …
What to do
Finish or delete NotImplementedException stubs and replace placeholder literals before shipping.
Other · Code Health — Unfinished work detected by code SHAPE, not keywords: members that only throw a "not implemented" exception, methods that take inputs and return a constant, async methods that never await, dead `if (false)` / `#if false` branches, and skeleton types most of whose members are holes. A real, objective slice of technical debt.
Method: Roslyn syntax scan: incompleteness by code shape (constant-returning methods, async-never-await, #if false branches, guards that return what the code already falls through to, tests an earlier guard already decided, comparisons against NaN, skeleton types), not keyword-gated. Deterministic, code-shape heuristic.
`Write` is a shipped member whose whole body throws NotImplementedException — scaffolding that was never completed. Implement it or remove the dead surface. (×2) — foreign/csharp/Iggy_SDK/JsonConverters/ExpiryConverter.cs:37, foreign/csharp/Iggy_SDK/JsonConverters/SizeConverter.cs:50
What to do
Finish or delete the unfinished stubs (NotImplementedException / empty / constant-returning bodies) — they are dead surface that looks live.
Maturity · Maturity — Whether the repo and its projects have a README, and whether it's substantive and current.
Method: Filesystem scan: README presence, word count, and headings for depth; git history for staleness. Exhaustive across root and project dirs, deterministic.
What to do
Add a 'Testing' section to the root README — how to run the test suite.
Add a README to the 18 of 19 project(s) that lack one — worth up to 1.9 pts.
Maturity · Maturity — Whether key decisions (ADRs) and the high-level shape (C4/diagrams) are written down.
Method: Filesystem scan: ADR folder/naming conventions or content, plus Mermaid/PlantUML/C4/architecture.md discovery. Exhaustive, deterministic.
No Architecture Decision Records found — no conventional ADR directory, no numbered `NNNN-title` documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer.
What to do
Record significant decisions one document per decision — dated, stating the context, the decision and its consequences — and keep them together wherever your design docs already live (a conventional `docs/adr/` tree, with each file named `NNNN-title` in whatever markup those docs already use, is the most discoverable form).
Maturity · Maturity — Whether the README actually describes the code that exists (LLM-judged, advisory).
Method: Judged by language model at low temperature: README accuracy versus actual projects, within a disclosed tolerance. Advisory, not a measured number.
Readiness · Readiness — Whether an automated pipeline builds and tests every change.
Method: Filesystem scan: CI workflow files (.github/workflows, .gitlab-ci.yml, etc.) for build and test stages. Exhaustive, deterministic.
Do you agree with this assessment?
P10 · Library API & versioning10.0 / 10Exemplary○ Nothing flagged
Readiness · Readiness — For a library: a deliberate (small) public API surface and explicit semantic versioning so consumers can depend on it safely.
Method: Roslyn scan: public API surface area and semantic-versioning markers (SemVer attributes, changelog entries) for libraries; off .NET, a library is the ecosystem's publication act (an npm package that is not private and names an entry point, a PyPI distribution with a build system, a Rust library crate, a Maven/Gradle module that publishes, a Go module with no package main, a gemspec, a Composer library, a SwiftPM library product, a pub.dev or Hex package), its surface is the share of types the language model records as public (Rust, Swift, Java, Kotlin, Go, Dart; not measured where the model records no type visibility or, as in TypeScript, only module-level export), and its version is read from the manifest, a semver CHANGELOG, release tooling or semver git tags. Exhaustive, deterministic.
Readiness · Readiness — Whether behaviour is captured as executable Gherkin specifications (a plus for shared understanding) — only assessed when a BDD framework is present.
Method: Filesystem scan: BDD framework presence (SpecFlow, Gherkin files) when a project references a BDD tool. Exhaustive, deterministic.
Readiness · Readiness — Whether SAST, secret/dependency scanning and performance benchmarking are wired in (presence, not runtime).
Method: Filesystem scan: SAST configuration, dependency-update automation, secret scanning, and a benchmark harness or benchmark step — in this repository's own ecosystem. Exhaustive, deterministic.
What to do
Dependabot is configured but does not watch `pip`, `composer`, `bundler` — add those `package-ecosystem` entries to .github/dependabot.yml so those dependencies get the same automatic update and advisory pressure as the ones it already covers.
Add gitleaks/trufflehog in CI to block PRs that introduce committed secrets.
Readiness · Readiness — Whether releases are automated and safely reversible (probes, rolling updates, approval gates) — from manifests/pipeline files, not the live environment.
Method: Filesystem scan: deployment manifests/IaC (K8s YAML, Helm, Terraform) for rolling updates, probes, approval gates, migration hooks. Exhaustive, deterministic.
Do you agree with this assessment?
P5 · DR & Backup0.0 / 10Critical✓ Tool-verified
Readiness · Readiness — Whether disaster recovery is planned and codified — backups, geo-recovery, RTO/RPO, persistence guarantees — from IaC + container manifests + docs, never the live cloud.
Method: Filesystem scan: disaster recovery, backup, geo-recovery, RTO/RPO, persistence guarantees from IaC, manifests, and docs. Exhaustive, deterministic, never a live environment.
A persistence guard (data volume / purge-protection) was found, but no backup, geo-recovery or RTO/RPO controls were evidenced — a volume that survives a container recreate is not a tested restore from catastrophic loss.
What to do
Codify backups + geo-recovery in IaC and document RTO/RPO and the restore procedure — a persistence guard alone is not disaster recovery.
Readiness · Readiness — Whether releases are traceable — a maintained changelog and explicit version stamping.
Method: Filesystem scan: changelog file presence and version tags in csproj or git tags. Exhaustive, deterministic.
No CHANGELOG/HISTORY/RELEASES file — what shipped when isn't easy to reconstruct for support or audit. (Versioning/tagging makes releases traceable, but a changelog records the what.)
What to do
Keep a changelog (e.g. Keep-a-Changelog) recording what shipped in each release.
Readiness · Performance — Whether the code protects its performance with benchmarks — a benchmark suite, allocation/memory measurement, and (ideally) a CI gate. Presence is credited as a bonus, never a deduction.
Method: Repo + source scan: BenchmarkDotNet referenced (csproj/source), [Benchmark]/[MemoryDiagnoser] attribute counts, and a benchmark step in CI; off .NET, the same ladder over Go testing.B, Rust criterion/#[bench]/divan, JMH/kotlinx-benchmark, pytest-benchmark/asv/pyperf, tinybench/mitata/vitest bench/benchmark.js and Swift package-benchmark — scored as a bonus ladder (absence is neutral, never a deduction). Deterministic, presence detection.
No benchmark suite was found by the two searches this check runs. FIRST, a BenchmarkDotNet package reference in any project file — every project the workspace loaded, plus a walk of project files on disk that never loaded, because a benchmark suite is exactly the project a partial load drops. SECOND, a script harness: a file whose name contains `benchmark` and ends `.py`, `.sh`, `.ps1`, `.bash`, `.rb`, `.js` or `.mjs`, credited ONLY when this repository's CI text also mentions benchmarks — a harness no pipeline runs is read as a fixture, deliberately. Neither search can see a benchmark suite in another ecosystem's idiom (a Go `testing.B` file, a JMH or criterion project, a pytest-benchmark run), so this is 'no benchmark found by those two searches', not a verdict that the repository has none. Where code is performance-sensitive, a benchmark guards against silent regressions — but it's a bonus here, not a deduction.
What to do
Add a benchmarking harness for the hot paths and run it in CI to catch regressions (for .NET, a BenchmarkDotNet project with [MemoryDiagnoser] to track allocations).
Readiness · Performance — Whether the code is written to minimise allocations so it doesn't pressure its host's memory manager — buffer/slice views over copies, object pooling, stack or value-type allocation, and buffer writers. Reward-only: credited where present, never penalised where a simpler style is fine.
Method: Production-source scan: density (per 1k LoC) of allocation-aware APIs — in .NET Span/Memory, ArrayPool/ObjectPool, stackalloc, ValueTask, value-type structs, IBufferWriter, string.Create, SkipLocalsInit; off .NET, with comments and strings blanked, Go's sync.Pool, preallocated slices/maps, Grow, strconv.Append* and buf[:0] reuse; the JVM's NIO buffer views, MemorySegment, primitive collections, pools and literal presizes (plus Kotlin primitive arrays and value classes, Scala AnyVal and @specialized); Swift's reserveCapacity, ContiguousArray, withUnsafe* access and ~Copyable. Activated off .NET on the same floor (400 lines, and benchmarks or 8 uses); Rust and garbage-collected scripting languages are not applicable. Reward-only. Deterministic, syntax/text detection.
Readiness · Performance — Whether asynchronous code stays responsive — it avoids sync-over-async blocking (a .NET .Wait()/.GetAwaiter().GetResult(), a time.sleep or blocking HTTP call inside a Python coroutine, a *Sync call inside an async JavaScript function, block_on inside a Rust async fn, runBlocking inside a Kotlin suspend function, block() inside a Reactor publisher) that stalls a thread or event loop and risks deadlock, and, where the code is a reusable library on .NET, awaits with ConfigureAwait(false) so it never captures and stalls its caller's context.
Method: Production-source scan: sync-over-async blocking counted everywhere — .Wait()/.GetAwaiter().GetResult() in .NET; off .NET, read from the language model, a blocking call inside an async function (Python, TS/JS, Rust, Kotlin) or inside a Java method returning a Reactor Mono/Flux — and, for a .NET library with ≥5 awaits, the share of awaits using ConfigureAwait(false). Deterministic, syntax/text detection.
`main` is async and calls readFileSync — a blocking call inside async code stalls the event loop — every other request waits for as long as it runs. (×2) — examples/node/src/tcp-tls/consumer.ts:99, examples/node/src/tcp-tls/producer.ts:91
Only 0/423 awaits use ConfigureAwait(false). A library that captures the caller's context can stall or deadlock its host — the classic way a dependency drags an app down.
What to do
TypeScript/JavaScript: use the promise APIs (fs/promises, a promisified child_process.execFile, the async zlib/crypto functions) and await them instead of the *Sync variants.
In library code, append .ConfigureAwait(false) to every await (or set <ConfigureAwait>false</ConfigureAwait> / use the analyzer CA2007) so the library never captures the host's context.
Do you agree with this assessment?
R1 · Type Safety10.0 / 10Exemplary✓ Tool-verified
React / JS · Code Health — How much of the frontend is typed TypeScript vs untyped JavaScript.
Method: Frontend file inventory: the share of typed TypeScript vs untyped JavaScript across the source tree. Deterministic, exhaustive over frontend files.
React / JS · Code Health — Near-exact copy-pasted blocks of substantial extent across the frontend (the D4 clone algorithm over JS/TS tokens, D-386): a block is reported only where its copies still agree on most of their own identifiers and literals, or were renamed as they were pasted but kept most of their constants, and where the copies carry enough code to stand on their own or the copied extent reaches 30 lines — so a re-implementation sharing neither names nor values, and a small pasted declaration, are both found and deliberately not reported, and a clean R10 is not a claim that nothing was copied.
Method: Near-exact copy-pasted blocks of substantial extent across the frontend (the D4 clone algorithm run over JS/TS tokens). Masking finds the candidates; a block is reported when its copies still agree on most of their own identifiers and literals, or when a renamed copy still agrees on most of its constants, AND the copies carry enough code to stand on their own — or when the copied extent reaches 30 lines. So a re-implementation sharing neither names nor values, and a small pasted declaration, are deliberately not counted. Deterministic.
17 duplicated blocks under foreign/node/src/wire/ have copies in at least two of the sibling directories client, consumer-group, partition, session, stream, system (+3 more sibling(s) not listed) — 11 of them are reported below, and 6 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 17 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 17 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 17 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on. — foreign/node/src/wire/client/get-clients.command.ts:23
web/src/lib/components/Modals/AddPartitionsModal.svelte:49 · web/src/lib/components/Modals/DeletePartitionsModal.svelte:65 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it. — web/src/lib/components/Modals/AddPartitionsModal.svelte:49
web/src/lib/components/Modals/AddTopicModal.svelte:66 · web/src/lib/components/Modals/AddUserModal.svelte:62 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — web/src/lib/components/Modals/AddTopicModal.svelte:66
web/src/lib/components/Modals/AddStreamModal.svelte:45 · web/src/lib/components/Modals/StreamSettingsModal.svelte:57 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — web/src/lib/components/Modals/AddStreamModal.svelte:45
foreign/node/src/wire/topic/create-topic.command.ts:61 · foreign/node/src/wire/topic/update-topic.command.ts:41 — the two spans are one implementation copied and then locally edited — 212 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — foreign/node/src/wire/topic/create-topic.command.ts:61
web/src/lib/components/RouteComponents/Settings/UsersTab.svelte:46 · web/src/routes/dashboard/settings/users/+page.svelte:48 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — web/src/lib/components/RouteComponents/Settings/UsersTab.svelte:46
web/src/lib/components/SlimSortableList.svelte:24 · web/src/lib/components/SortableList.svelte:27 — the two spans are one implementation copied and then locally edited — 213 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — web/src/lib/components/SlimSortableList.svelte:24
foreign/node/src/debug-send.ts:94 · foreign/node/src/debug.ts:92 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/debug-send.ts:94
web/src/lib/components/Modals/StreamSettingsModal.svelte:103 · web/src/lib/components/Modals/StreamSettingsModal.svelte:135 — the two spans are one implementation copied and then locally edited — 75 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — web/src/lib/components/Modals/StreamSettingsModal.svelte:103
foreign/node/src/wire/message/header.utils.ts:314 · foreign/node/src/wire/message/header.utils.ts:333 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. — foreign/node/src/wire/message/header.utils.ts:314
foreign/node/src/wire/client/get-clients.command.ts:23 · foreign/node/src/wire/stream/get-streams.command.ts:27 — the 2 copies are spread across 2 files, and the CITED SPAN is a run of MODULE-LEVEL DECLARATIONS — bindings the module declares and exports — rather than statements with a call site. Do not read this as an extract-a-helper row: a call expression cannot stand where a declaration was, and putting one there would delete the names themselves, which are what the rest of the codebase imports. What actually repeats here is the INITIALISER — the same expression shape written once per binding. So give that expression one name (a small helper the initialisers call, or a shared base value they are each derived from) and keep every binding under the name it already has. Where the run is an enumeration — one binding per distinct thing, differing precisely in the thing each one names — the repetition IS the enumeration and collapsing it would delete entries; consider instead whether the set belongs in one exported table the individual names are read out of. Reported because the copies drift apart the first time only one of them is edited. — foreign/node/src/wire/client/get-clients.command.ts:23
web/src/lib/components/Modals/StreamSettingsModal.svelte:45 · web/src/lib/components/Modals/TopicSettingsModal.svelte:48 — the 2 copies are spread across 2 files, and the CITED SPAN is a run of MODULE-LEVEL DECLARATIONS — bindings the module declares and exports — rather than statements with a call site. Do not read this as an extract-a-helper row: a call expression cannot stand where a declaration was, and putting one there would delete the names themselves, which are what the rest of the codebase imports. What actually repeats here is the INITIALISER — the same expression shape written once per binding. So give that expression one name (a small helper the initialisers call, or a shared base value they are each derived from) and keep every binding under the name it already has. Where the run is an enumeration — one binding per distinct thing, differing precisely in the thing each one names — the repetition IS the enumeration and collapsing it would delete entries; consider instead whether the set belongs in one exported table the individual names are read out of. Reported because the copies drift apart the first time only one of them is edited. — web/src/lib/components/Modals/StreamSettingsModal.svelte:45
foreign/node/src/duration.utils.ts:175 · foreign/node/src/duration.utils.ts:258 — the two spans are one implementation copied and then locally edited — 81 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — foreign/node/src/duration.utils.ts:175
foreign/node/src/debug-send.ts:52 · foreign/node/src/debug.ts:49 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/debug-send.ts:52
foreign/node/src/wire/stream/get-stream.command.ts:27 · foreign/node/src/wire/user/get-user.command.ts:28 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/wire/stream/get-stream.command.ts:27
foreign/node/src/wire/system/get-stats.command.ts:67 · foreign/node/src/wire/system/get-stats.command.ts:80 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. — foreign/node/src/wire/system/get-stats.command.ts:67
foreign/node/src/wire/user/permissions.utils.ts:291 · foreign/node/src/wire/user/permissions.utils.ts:349 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/wire/user/permissions.utils.ts:291
web/src/lib/components/Modals/InspectMessage.svelte:52 · web/src/lib/components/Modals/InspectMessage.svelte:65 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — web/src/lib/components/Modals/InspectMessage.svelte:52
foreign/node/src/client/client.frame.ts:140 · foreign/node/src/client/client.frame.ts:158 — the two spans are one implementation copied and then locally edited — 78 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — foreign/node/src/client/client.frame.ts:140
foreign/node/src/wire/stream/delete-stream.command.ts:20 · foreign/node/src/wire/stream/get-stream.command.ts:21 · foreign/node/src/wire/stream/purge-stream.command.ts:20 · foreign/node/src/wire/topic/get-topics.command.ts:21 · +1 more site(s) not listed — the 5 copies are spread across 5 files, and the SHAPE of this repetition could not be determined. It is not a run of declarations, a listing, a declaration header, a type body or a slice through a construct — and it was not measured as a run of executable statements either, so this row cannot tell you whether a function can stand where these lines are. Read the two spans before acting, because the move is opposite in the two cases. Where they are statements, the ordinary answer holds: give the shared part one home and call it from each site. Where they turn out to be declarations, a literal's entries, or the cases of an enumeration, there is no call site to call anything from, and collapsing them would delete what each copy pins — a shared base type, a generated set, or one exported constant each site refers to is the move instead, and sometimes the honest answer is that there is nothing to extract at all. Reported because the copies drift apart the first time only one of them is edited, which is true whichever of those they are. — foreign/node/src/wire/stream/delete-stream.command.ts:20
web/src/lib/api/clientApi.ts:35 · web/src/lib/api/fetchRouteApi.ts:28 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it. — web/src/lib/api/clientApi.ts:35
REDACTED:58 · REDACTED:75 — the two spans are one implementation copied and then locally edited — 65 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one. — REDACTED:58
foreign/node/src/wire/number.utils.ts:26 · foreign/node/src/wire/number.utils.ts:50 · foreign/node/src/wire/number.utils.ts:74 · foreign/node/src/wire/number.utils.ts:98 · +1 more site(s) not listed — all 5 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/wire/number.utils.ts:26
foreign/node/src/wire/session/login.utils.ts:90 · foreign/node/src/wire/token/delete-token.command.ts:38 — the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another. — foreign/node/src/wire/session/login.utils.ts:90
foreign/node/src/wire/token/token.utils.ts:100 · foreign/node/src/wire/user/user.utils.ts:139 — the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another. — foreign/node/src/wire/token/token.utils.ts:100
foreign/node/src/debug-send.ts:68 · foreign/node/src/debug.ts:67 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/debug-send.ts:68
foreign/node/src/wire/client/client.utils.ts:31 · foreign/node/src/wire/user/user.utils.ts:67 — the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another. — foreign/node/src/wire/client/client.utils.ts:31
foreign/node/src/wire/consumer-group/get-group.command.ts:37 · foreign/node/src/wire/topic/get-topic.command.ts:45 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/wire/consumer-group/get-group.command.ts:37
foreign/node/src/wire/vsr/register.ts:57 · foreign/node/src/wire/vsr/register.ts:74 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/wire/vsr/register.ts:57
web/src/lib/api/clientApi.ts:47 · web/src/lib/api/fetchApi.ts:37 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it. — web/src/lib/api/clientApi.ts:47
foreign/node/src/wire/cluster/cluster.utils.ts:53 · foreign/node/src/wire/cluster/cluster.utils.ts:127 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/wire/cluster/cluster.utils.ts:53
foreign/node/src/wire/consumer-group/create-group.command.ts:43 · foreign/node/src/wire/stream/create-stream.command.ts:40 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/wire/consumer-group/create-group.command.ts:43
foreign/node/src/wire/session/login.utils.ts:49 · foreign/node/src/wire/user/create-user.command.ts:47 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/wire/session/login.utils.ts:49
foreign/node/src/wire/stream/stream.utils.ts:61 · foreign/node/src/wire/topic/topic.utils.ts:136 — the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another. — foreign/node/src/wire/stream/stream.utils.ts:61
foreign/node/src/wire/user/permissions.utils.ts:251 · foreign/node/src/wire/user/permissions.utils.ts:318 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. — foreign/node/src/wire/user/permissions.utils.ts:251
foreign/node/src/wire/cluster/cluster.utils.ts:69 · foreign/node/src/wire/cluster/cluster.utils.ts:133 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported. — foreign/node/src/wire/cluster/cluster.utils.ts:69
foreign/node/src/wire/message/iggy-header.utils.ts:87 · foreign/node/src/wire/message/iggy-header.utils.ts:157 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. — foreign/node/src/wire/message/iggy-header.utils.ts:87
foreign/node/src/wire/user/permissions.utils.ts:159 · foreign/node/src/wire/user/permissions.utils.ts:243 — all 2 copies are in the same file, and the CITED SPAN is a run of DECLARATIONS inside a construct — the members of a type, or the entries of an object or array literal — with no statement anywhere in it. Do not read this as an extract-a-helper row: nothing here executes, so there is no call site, and a call expression cannot stand where a member declaration or a literal's entry was. What repeats is a SHAPE, and which shape decides the move. Where the copies declare the same members, the repetition is a missing common ancestor: give it a base type, an interface both extend, a generic instantiated twice, or — where the copies are a literal's entries rather than a type's members — one shared constant each site spreads or refers to, so the set is written once. Where they declare DIFFERENT members and only the form is shared — a decorator and its options, an annotation, a registration table's keys — the form is prescribed by a framework or a schema rather than copied, and the only collapse available is to generate the declarations from that schema; where you do not own the generator, this is the cost of the framework and there is nothing to extract. Check which of the two it is before acting: these copies still drift apart the first time only one of them is edited, which is why the repetition is reported, but the sentence to act on is not the same in both cases. — foreign/node/src/wire/user/permissions.utils.ts:159
REDACTED:104 · REDACTED:110 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. — REDACTED:104
REDACTED:255 · REDACTED:261 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. — REDACTED:255
What to do
Act on each finding's own remediation rather than one rule: the move depends on what recurs. Where the copies are executable blocks, give the shared part one home and call it from each site; where they are declarations, a listing, a specialisation already delegating to its base, or one shape repeated per entity, there is no call site and the move is a shared type, a generated set or a factory — sometimes there is nothing to extract.
React / JS · Code Health — Per-function cyclomatic/cognitive complexity from the token-level function scanner (D-386) — real branching, not a regex heuristic.
Method: Per-function cyclomatic/cognitive complexity from a token-level function scanner (real branching, not a regex heuristic), computed over every frontend function. Deterministic.
_pollOnPrimary has cyclomatic complexity 40 and cognitive complexity 87; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/client/client.socket.ts:586
sendCommand has cyclomatic complexity 32 and cognitive complexity 50; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/client/client.socket.ts:305
_processVsr has cyclomatic complexity 29 and cognitive complexity 44; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/client/client.socket.ts:879
(anonymous) has cyclomatic complexity 23 and cognitive complexity 22; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/client/client.connection-string.ts:59
(anonymous) has cyclomatic complexity 21 and cognitive complexity 19; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/client/client.config.ts:35
_reconnectUntilConnected has cyclomatic complexity 19 and cognitive complexity 35; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/client/client.connection.ts:408
(anonymous) has cyclomatic complexity 19 and cognitive complexity 5; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/wire/vsr/reply.ts:129
serialize has cyclomatic complexity 18 and cognitive complexity 21; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/wire/topic/create-topic.command.ts:86
(anonymous) has cyclomatic complexity 18 and cognitive complexity 5; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — web/src/lib/components/Modals/InspectMessage.svelte:38
parse has cyclomatic complexity 15 and cognitive complexity 29; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/duration.utils.ts:159
_rememberCredentials has cyclomatic complexity 15 and cognitive complexity 20; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/client/client.socket.ts:748
onUpdate has cyclomatic complexity 14 and cognitive complexity 19; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. (×2) — web/src/lib/components/Modals/AddPartitionsModal.svelte:49, web/src/lib/components/Modals/DeletePartitionsModal.svelte:65
(anonymous) has cyclomatic complexity 14 and cognitive complexity 14; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/client/client.connection-string.ts:151
_processQueue has cyclomatic complexity 13 and cognitive complexity 19; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/client/client.socket.ts:796
(anonymous) has cyclomatic complexity 13 and cognitive complexity 18; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes. — foreign/node/src/client/client.socket.test.ts:358
What to do
Break down the listed branch-heavy functions; aim P95 cyclomatic ≤ 5.
Do you agree with this assessment?
R3 · Large Files9.4 / 10Exemplary✓ Tool-verified
React / JS · Code Health — How many source files exceed the large-file threshold.
Method: Components/modules exceeding the large-file threshold, counted exhaustively across the frontend source tree. Deterministic.
What to do
Split each oversized file along the responsibilities already in it, into smaller focused modules in the same package.
Do you agree with this assessment?
R4 · Test Coverage4.2 / 10Adequate✓ Tool-verified
React / JS · Readiness — Static test reachability (D-386): the share of production files reachable from any test via the import graph — measured without running anything.
Method: Static test reachability: the share of production files reachable from any test via the import graph — measured without running anything. Deterministic.
No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one. (×40) — web/src/lib/components/PermissionsManager.svelte, REDACTED, scripts/ci/render-node-licenses.mjs, …
What to do
Add tests that import the unreached modules (directly or through their public entry).
React / JS · Readiness — How outdated the npm dependencies are (a maturity signal). JS/npm CVEs are scored separately in D30 (JS/npm Dependency Vulnerabilities).
Method: npm dependency staleness from manifest/registry metadata (a maturity signal; JS/npm CVEs are scored separately in D30, which answers dependency vulnerabilities for every ecosystem). Deterministic.
What to do
Bump outdated dependencies to current versions to limit upgrade debt.
Do you agree with this assessment?
R6 · Tooling10.0 / 10Exemplary✓ Tool-verified
React / JS · Readiness — Whether the project wires up test, lint and typecheck — detected from each package.json script's COMMAND (eslint / tsc / vitest / jest / playwright), not just its name, and corroborated against CI-workflow invocations so a tool run only in CI still counts.
Method: package.json scanned for test/lint/typecheck script wiring. Deterministic presence check.
Do you agree with this assessment?
R7 · Dead Code0.7 / 10Critical✓ Tool-verified
React / JS · Code Health — Files unreachable from every application/tooling/test entry point, and exports nothing imports (module-graph reachability, D-386).
Method: Dead code: files unreachable from every application/tooling/test entry point plus exports nothing imports, via module-graph reachability. Deterministic, exhaustive over the import graph.
Unreachable from the 40 application, 11 tooling and 57 test entry point(s) detected in this repo. Gate removals on `npm run build` — an undetected custom entry would make these reachable.
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AddUserModal.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it (×2) — web/src/lib/components/PermissionsManager.svelte, web/src/lib/components/Listbox.svelte
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/api/fetchRouteApi.ts) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/api/ApiSchema.ts
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make (×15) — web/src/lib/actions/tooltip.ts, web/src/lib/domain/Stats.ts, web/src/lib/utils/addOnKeyDownListener.ts, …
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AppModals.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it (×8) — web/src/lib/components/Modals/StreamSettingsModal.svelte, web/src/lib/components/Modals/TopicSettingsModal.svelte, web/src/lib/components/Modals/DeletePartitionsModal.svelte, …
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (web/src/lib/components/Modals/AddTopicModal.svelte, web/src/lib/components/Modals/TopicSettingsModal.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/components/DurationInput.svelte
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/domain/UserDetails.ts) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/domain/Permissions.ts
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/domain/MessageDetails.ts) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/domain/Message.ts
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 17 in-repo import(s) from 15 other file(s) do name it (web/src/lib/components/AppToasts.svelte, web/src/lib/components/Breadcrumbs.svelte, web/src/lib/components/Combobox.svelte and 12 more) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/components/Icon.svelte
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/PermissionsManager.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/components/Combobox.svelte
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/RouteComponents/Settings/UsersTabActions.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/components/RouteComponents/Settings/UsersTab.svelte
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 8 in-repo import(s) from 8 other file(s) do name it (web/src/lib/components/Modals/AddPartitionsModal.svelte, web/src/lib/components/Modals/AddStreamModal.svelte, web/src/lib/components/Modals/AddTopicModal.svelte and 5 more) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/components/AppToasts.svelte
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 3 in-repo import(s) from 3 other file(s) do name it (web/src/lib/api/clientApi.ts, web/src/lib/api/fetchRouteApi.ts, web/src/lib/api/handleFetchErrors.ts) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/api/getJson.ts
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Header.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/components/Breadcrumbs.svelte
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 15 in-repo import(s) from 15 other file(s) do name it (web/src/lib/components/Combobox.svelte, web/src/lib/components/DeleteButtonWithConfirmation.svelte, web/src/lib/components/Header.svelte and 12 more) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/components/Button.svelte
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 8 in-repo import(s) from 8 other file(s) do name it (web/src/lib/components/Header.svelte, web/src/lib/components/Modals/AddPartitionsModal.svelte, web/src/lib/components/Modals/AddStreamModal.svelte and 5 more) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/components/PeriodicInvalidator.svelte
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 2 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Header.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/components/ThemeController.svelte
no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (web/src/lib/components/MessageDecoder/MessageDecoder.svelte, web/src/lib/components/Modals/AddTopicModal.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it — web/src/lib/components/Select.svelte
What to do
Delete the dead files and unused exports — every line is maintenance cost and rebuild-estimate inflation with zero runtime value.
React / JS · Readiness — npm dependency truthfulness (D-386): unused dependencies, imports not declared anywhere, and type-/test-only packages shipped as production deps.
Method: npm dependency truthfulness: unused dependencies, imports declared nowhere, and type-/test-only packages shipped as production deps — from the manifest + import graph. Deterministic.
Declared in the root package.json but never imported anywhere in that package or its workspace members — no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it.
Declared in web/package.json but never imported anywhere in that package or its workspace members — no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it. (×2)
What to do
Remove unused dependencies, declare unlisted imports explicitly, and demote type-/test-only packages to devDependencies.
React / JS · Architecture — Import cycles in the module graph (D-386) — files that can only be understood and changed together.
Method: Import cycles in the module graph, detected exhaustively over JS/TS imports (the same cycle detection as the .NET coupling dimension). Deterministic.
Other · Code Health — Whether the code avoids sync-over-async (deadlock-prone blocking on tasks) and async void.
Method: Roslyn syntax scan: async methods scanned for .Wait()/.GetAwaiter().GetResult() and async-void outside event handlers. Deterministic, hard fact per invocation.
Other · Code Health — Whether any branch is dead by construction — a switch arm whose label can never equal a case-normalised subject, or an `else if` whose predicate the arm above has already swallowed.
Method: Roslyn syntax + semantics: switch labels compared against the subject's own case normaliser, and if/else-if chains checked for a literal an earlier arm's containment test already swallows. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X13 · Undrained process stream10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a child process that has BOTH standard streams redirected drains both — reading one to the end while the other is never read deadlocks once the child fills the unread pipe.
Method: Roslyn syntax + semantics: ProcessStartInfo launches with both streams redirected, checked for a drain of each stream across the enclosing type. Deterministic, provable per finding. Advisory.
Other · Security — Whether a hand-rolled public/private IP check can be walked past — a method that unwraps IPv4-mapped IPv6 but returns the opposite verdict for the same host written as IPv4-compatible, 6to4 or NAT64.
Method: Roslyn syntax + semantics: methods that unwrap IPv4-mapped IPv6 and hand-roll IPv4 range carve-outs, checked for whether the IPv6 branch also accounts for the IPv4-compatible, 6to4 and NAT64 embeddings. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X15 · Unvalidated length from an untrusted reader10.0 / 10Exemplary○ Nothing flagged
Other · Security — Whether a length read out of the stream being parsed is bounded before it is allocated or read — an unchecked count taken from the input lets the input choose the allocation.
Method: Roslyn syntax + semantics: integer lengths read from a BinaryReader and spent on a bulk read or an array allocation, checked for any comparison or bounding call on the value anywhere in the method. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a loop that shortens a string until it fits a length budget has a floor — one with none grinds the value down to the empty string, or past it into a negative-length `Substring`.
Method: Roslyn syntax + semantics: while/do loops whose body's only effect on a string is to drop its last character, checked for whether anything — a direct comparison on the length, a body guard, a break — bounds that length below. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X17 · Uncapped recursion over a caller-supplied document10.0 / 10Exemplary○ Nothing flagged
Other · Security — Whether a walk that recurses through a JSON/XML tree handed in by its caller bounds how deep it will go — an uncapped walk lets the document's nesting choose the stack depth, and the resulting StackOverflowException cannot be caught.
Method: Roslyn syntax + semantics: methods that take a JSON/XML document node and call themselves with a child of it, reachable from an externally-callable member of the same type that accepts a document, checked for any depth parameter, descent counter or threaded arithmetic anywhere in the walk. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a type's disposal matches what it OWNS — releasing what it created, leaving alone what it was handed, and not declaring a finalizer for state that has nothing unmanaged to finalize.
Method: Roslyn syntax + semantics: every assignment to a disposable field is read to decide whether the type CREATED the value or was handed it, and the type's disposal is checked against that answer — an injected interface it disposes, a value it constructed and never releases, a finalizer on a type holding nothing unmanaged, and a disposable local whose every reference is a plain member read. A value handed to a container that disposes its contents (a parent control's `Controls` collection, a component `IContainer`) is released by that container and is not reported; generated code is out of population. Deterministic, provable per finding. Advisory.
`_client` is never created by `IggyConsumer` — every assignment to it takes a constructor parameter — yet this type disposes it here (line 145). Its declared type `IIggyClient` is an interface, so the instance came from whoever resolved it, and that owner decides when it ends. Disposing it from here reaches outside this object's lifetime: a dependency shared with the rest of the process is torn down when THIS instance goes away, and the real owner's later `Dispose()` runs a second time on an object already disposed. Drop the call — a type disposes what it constructed, and only that. If this dependency genuinely is exclusive to this instance, construct it here (or take an owned factory) so the ownership is stated in the code rather than assumed. — foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.cs:145
`_owner` is never created by `PolledMessagesRental` — every assignment to it takes a constructor parameter — yet this type disposes it here (line 71). Its declared type `IMemoryOwner` is an interface, so the instance came from whoever resolved it, and that owner decides when it ends. Disposing it from here reaches outside this object's lifetime: a dependency shared with the rest of the process is torn down when THIS instance goes away, and the real owner's later `Dispose()` runs a second time on an object already disposed. Drop the call — a type disposes what it constructed, and only that. If this dependency genuinely is exclusive to this instance, construct it here (or take an owned factory) so the ownership is stated in the code rather than assumed. — foreign/csharp/Iggy_SDK/Contracts/PolledMessagesRental.cs:71
`TcpMessageStream` implements `IDisposable` — so it has told every caller it holds something worth releasing — and it constructs `_connectGate` itself (line 59), which makes that instance its own. But `_connectGate` is named in none of the methods the disposal search covered: `Dispose` (line 119), `SetConnectionState` (line 1476) — that is `Dispose` plus every method `Dispose` calls BY NAME, so a release reached through an interface, a delegate or a base class is not followed and is worth checking before acting. On what was read, the type's disposal releases everything except the one thing it owns. A disposable the owner never disposes is held until finalization if its type has a finalizer, and forever if it does not — which for a synchronisation primitive, a timer, a stream or a handle means the resource accumulates once per instance for the life of the process. Release it in `Dispose` (`_connectGate?.Dispose();`), or, if it truly does not need releasing, drop `IDisposable` from the type so the claim and the behaviour agree. — foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs:59
`TcpMessageStream` implements `IDisposable` — so it has told every caller it holds something worth releasing — and it constructs `_connectionSemaphore` itself (line 61), which makes that instance its own. But `_connectionSemaphore` is named in none of the methods the disposal search covered: `Dispose` (line 119), `SetConnectionState` (line 1476) — that is `Dispose` plus every method `Dispose` calls BY NAME, so a release reached through an interface, a delegate or a base class is not followed and is worth checking before acting. On what was read, the type's disposal releases everything except the one thing it owns. A disposable the owner never disposes is held until finalization if its type has a finalizer, and forever if it does not — which for a synchronisation primitive, a timer, a stream or a handle means the resource accumulates once per instance for the life of the process. Release it in `Dispose` (`_connectionSemaphore?.Dispose();`), or, if it truly does not need releasing, drop `IDisposable` from the type so the claim and the behaviour agree. — foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs:61
`TcpMessageStream` implements `IDisposable` — so it has told every caller it holds something worth releasing — and it constructs `_sendingSemaphore` itself (line 64), which makes that instance its own. But `_sendingSemaphore` is named in none of the methods the disposal search covered: `Dispose` (line 119), `SetConnectionState` (line 1476) — that is `Dispose` plus every method `Dispose` calls BY NAME, so a release reached through an interface, a delegate or a base class is not followed and is worth checking before acting. On what was read, the type's disposal releases everything except the one thing it owns. A disposable the owner never disposes is held until finalization if its type has a finalizer, and forever if it does not — which for a synchronisation primitive, a timer, a stream or a handle means the resource accumulates once per instance for the life of the process. Release it in `Dispose` (`_sendingSemaphore?.Dispose();`), or, if it truly does not need releasing, drop `IDisposable` from the type so the claim and the behaviour agree. — foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs:64
What to do
Each finding names the value and the span that decides who owns it — the `new` that created it, or the constructor parameter that handed it over. Confirm ownership from that span, then make the disposal match it: release what this type created, leave what it was injected with to whoever created THAT, and drop a finalizer whose type holds nothing unmanaged to release.
Other · Code Health — Whether a method that temporarily changes state belonging to the whole process — the working directory, an environment variable — puts it back on EVERY path: a restore reached only when nothing throws leaks the change to the rest of the process.
Method: Roslyn syntax + semantics: method bodies that write the process working directory or an environment variable and write it back in the same body, checked for whether that restore sits in a `finally`/`catch` or only on the straight-line path. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether async methods accept a CancellationToken so work can be cancelled (adoption curve).
Method: Roslyn scan: every async method (excluding framework-fixed overrides/Blazor handlers) checked for CancellationToken parameter presence. Deterministic, adoption percentage.
Only 157/176 async methods accept a CancellationToken, so in-flight work can't be stopped early when the caller gives up — whatever ends it in your host (shutdown signal, timeout, abandoned request, user cancel). Thread a token through the call chain and honour it at each await and loop; where a method genuinely cannot be interrupted, omitting it is a deliberate choice — judge against your hosting model.
No CancellationToken parameter — this work can't be stopped early once started. (×17) — foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.cs:599, foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.cs:654, foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs:1093, …
No CancellationToken parameter — the body observes an ambient token instead (a field or a context object), so the work does stop on cancellation, but a caller cannot cancel this call independently of the owner that created that token. (×2) — foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs:1267, foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.Vsr.cs:793
What to do
Thread a CancellationToken through async methods so work stops promptly on cancellation.
Other · Code Health — Whether an argument guard throws the exception its own condition describes — a guard that rejects a value for being EMPTY and reports it as `ArgumentNullException` tells the caller a parameter was null when it provably was not.
Method: Roslyn syntax: `throw new ArgumentNullException(nameof(p))` statements controlled by an `if`, whose condition is read for a test that is true of a NON-null `p` — an emptiness test that dereferences it (`p.Count == 0`, `!p.Any()`) or a BCL predicate documented true of the empty value (`string.IsNullOrEmpty(p)`). Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a `when` guard is free of side effects — a guard that increments a counter or assigns while deciding whether its arm matches applies that change during PATTERN MATCHING, on an arm that may not be selected, and skips it entirely when a short-circuit to its left answers first.
Method: Roslyn syntax: `when` guards on case labels and switch-expression arms, read for a mutation (`++`/`--`/assignment) sitting in a position the guard's own `&&`/`||`/`??`/`?:`/`?.` can skip. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a method that TAKES a lock or semaphore and gives it back from a flag-guarded `finally` returns the value that flag implies — reporting success while the guard hands the primitive back admits a second caller the exclusion was there to keep out, and reporting failure while the guard keeps it leaves nothing to ever give it back.
Method: Roslyn syntax: `try` statements whose `finally` releases a synchronisation primitive under a bare local-bool guard, where the method also TOOK that same primitive before the `try`, checked for a `return` of a bool literal whose value disagrees with the flag state the method's own straight-line assignments put it in. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether the work a diagnostic log line costs is paid only when that line is wanted — C# evaluates a call's arguments BEFORE the call, so a trace/debug message joined or projected out of a collection is built in full on every pass, and then discarded by a sink the shipped configuration leaves switched off.
Method: Roslyn syntax: log calls at a diagnostic level (a `Log`-prefixed method naming Trace/Debug/Verbose, or a bare `Debug`/`Trace`/`Verbose` on a receiver named for a logger), whose argument list is read for a call whose cost scales with a sequence — a LINQ operator, a materialisation, `string.Join`, a serializer — with no enclosing level check or conditional-compilation region. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X24 · Document value interpolated into markup unescaped10.0 / 10Exemplary○ Nothing flagged
Other · Security — Whether text read out of the document being converted is escaped before it is written into generated markup — a value the document's author chose, interpolated into an attribute the surrounding literal delimits, can close that attribute and open another.
Method: Roslyn semantic model over the whole compilation: a string-typed `Value`/`InnerText`/`InnerXml`/`Text` member declared inside `DocumentFormat.OpenXml` or `System.Xml` is a taint SOURCE, propagated through assignments, returns, arguments, tuple elements and string composition to its transitive closure, then read at interpolated-string holes that sit in a markup position the surrounding literal itself delimits. Escaper/encoder calls and enclosing validator conditions cut the flow. Flow- and container-insensitive by construction. A second arm needs no provenance at all and reports a type that CONTRADICTS ITSELF — the same expression escaped at one delimited markup hole and interpolated raw at another hole in the same markup position of the same type, which the type's own escaping proves is a defect without knowing where the value came from. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a value the caller is invited to supply is the value the type actually uses — a constructor parameter stored in a private field that nothing ever reads while the default it was given is spelled out a second time at the site that should have read it, a keyed lookup that falls back to a different setting than the one its key names while the same type falls back to the matching one for that same key, or a culture-sensitive parse given no format provider by a type that feeds its own settable culture to the same kind of parse elsewhere. Either way, every caller who supplies a value silently gets something else.
Method: Roslyn syntax: private instance fields of a non-partial type assigned in a constructor from one of its own parameters with a `??` fallback, checked for whether anything in the type body reads the field and whether that same fallback expression is spelled out again outside the constructor; and `??` fallbacks onto a member access from a lookup call carrying exactly one string literal, grouped by that key across the type and checked for a fallback member whose folded name disagrees with the key while a sibling site for the same key agrees with it. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether a value handed from a callback to the body that waits on it crosses on something built to be crossed — a `Queue<T>`/`List<T>`/`Dictionary<K,V>` written inside an event handler and read back outside it is mutated by two flows at once, and the semaphore or completion source beside it orders how MANY items exist while leaving the collection's own head, tail and backing array unprotected.
Method: Roslyn syntax: method, accessor, local-function and lambda bodies that declare BOTH a non-thread-safe generic collection (`Queue`/`Stack`/`List`/`Dictionary`/`HashSet`/`Sorted*`/`LinkedList`) and a synchronisation primitive (`SemaphoreSlim`/`TaskCompletionSource`/`ManualResetEvent(Slim)`/`AutoResetEvent`/`CountdownEvent`) as locals, then read for a `+=`-registered lambda that raises that primitive while the body outside every lambda waits on it — and, in that scope, a mutating call on the collection inside the lambda paired with a mention of it outside. Any `lock` in the scope abstains it. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X27 · Collection changed while being enumerated10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a `foreach` leaves the collection it is walking alone — a body that adds to or removes from the very collection the loop is enumerating invalidates the enumerator it is holding, so the next `MoveNext` throws `InvalidOperationException` and the remaining items are never seen.
Method: Roslyn syntax + semantics: `foreach` statements whose body calls a structural mutator (`Add`/`Remove`/`Clear`/`Insert`/…) on the very expression the loop is enumerating. Two arms. ARM A — the source is a concrete fragile BCL collection, or a live `Keys`/`Values` view over one, and the mutator resolves to that same collection's own member; concurrent and immutable collections and arrays are outside the population by construction, since their enumerators survive a structural change. ARM B — the source is an argument-less accessor CALL on a receiver whose body is in source: the accessor must return a stored field VERBATIM and a sibling member must structurally change that same field, both read off the implementations rather than from the members' names. A mutation the loop provably exits immediately after (`break`/`return`/`throw`/`goto`), or one written inside a nested loop or a lambda, is counted and never reported. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X28 · Index access outside its own emptiness guard10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a condition that tests a value for emptiness indexes that same value only where the test holds — an `||` written one parenthesis too far to the left leaves an index access outside the guard beside it, so the empty case the guard exists to anticipate reaches the index and throws.
Method: Roslyn syntax only, no semantic model: the OUTERMOST `&&`/`||` of every boolean condition, read for a symbol the condition tests for emptiness (`string.IsNullOrEmpty`/`IsNullOrWhiteSpace`, a `Length`/`Count` comparison against a literal, `Any()`, a `Length`/`Count` pattern, or a comparison against `""`) and ALSO indexes. Each `symbol[...]` access is placed by a boolean-reachability walk from the access up to the outermost connective: an access is COVERED when some enclosing step has it in the right operand and the left operand, under the truth value that step forces, proves the symbol non-empty — a recursion over `&&`/`||` whose true- and false-directions are asymmetric. A finding needs BOTH an uncovered access and a covered one on the same symbol in the same condition, which is the agreeing twin that separates a misplaced parenthesis from an unrelated length test. Bare index accesses with no emptiness test in the condition are neither counted nor reported; a non-identifier receiver and a lambda nested inside the condition are outside the population. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X29 · Per-element action decided by a fixed element10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a decision taken once per element is taken ABOUT that element — a test inside a counted loop that reads a fixed subscript of the very collection its guarded statement indexes by the loop variable applies element zero's answer to all of them, so the elements that differ from it are all handled wrongly, and in the same direction.
Method: Roslyn syntax only, no semantic model: every `for` statement declaring exactly ONE loop variable, and every `if` inside its body that is not under a nested loop or a lambda. A site enters the population when the `if`’s condition never mentions the loop variable while the statement it guards indexes some collection by that variable ALONE (`c[i]`; `c[i + 1]` and `c[i, j]` are outside it). A finding additionally needs the AGREEING TWIN at the same-collection grain: the condition must read THAT SAME collection at a subscript that does not move — written into the condition, or reached through a local declared BEFORE the loop, so an alias bound inside the body is not followed. Both collection expressions must be simple identifiers. On a repository with no .NET source the same rule reads JavaScript/TypeScript off the engine’s own token stream (tests included, bundles and vendored paths not): a `for (let|var|const x = …; …; …)` with one declarator and a braced body, an alias followed only when it is declared before the loop in a block that encloses it and never assigned inside the loop. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether exceptions are handled rather than silently swallowed or rethrown with lost stack traces.
Method: Roslyn syntax scan: every catch clause counted; empty catches and bare rethrows flagged. Population is all catch clauses, not estimated. Deterministic, hard fact.
Do you agree with this assessment?
X30 · Support guard that admits what it rejects10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a guard written as a NEGATED `||` says what its author meant — `!(a || b || x != k)` is `!a && !b && x == k` by De Morgan, so a bail-out that mixes capabilities the code needs with a fault it refuses turns inside out: it fires only where the capabilities are ABSENT, and lets every value the fault term names walk straight into the body that cannot handle it.
Method: Roslyn syntax only, no semantic model: every logical-not whose operand is a parenthesised `||` chain of two or more disjuncts, flattened (a left-nested `a || b || c` read once would see `(a || b)` as one disjunct). A site enters the population on that shape alone. A finding additionally needs the disjuncts to DISAGREE in polarity: at least one bare boolean read — an identifier or member access, never an invocation, which is a predicate rather than a capability flag — and at least one `x != <constant>`, the only form that negates into an exact-value pin (`== null` negates into a looser requirement and is outside the fault set). Consistently-polarised disjunctions, all-fault or all-capability, are counted and never reported; a negated `&&` is outside the population entirely. No same-receiver gate: it was measured to cost a real defect and remove no false positive. Deterministic, provable per finding. Advisory.
Do you agree with this assessment?
X32 · Type resolved by simple name across every loaded assembly10.0 / 10Exemplary○ Nothing flagged
Other · Code Health — Whether a plugin lookup names the type it means — searching every assembly loaded into the process for a candidate whose SIMPLE name equals a string supplied at runtime, and taking the first one found, is decided by assembly LOAD ORDER rather than by this source, so the same name can resolve to a different type on the next run.
Method: Roslyn syntax only, no semantic model: every invocation of `First`/`FirstOrDefault`/`Single`/`SingleOrDefault` whose OWN expression subtree contains both a `GetAssemblies()` call and a `GetTypes()`/`GetExportedTypes()` call — a single-element pick out of every type loaded into the process. A nested selector in the same chain sees no `GetAssemblies()` in its own subtree and is outside the population, so one lookup counts once however many links its chain has. A finding additionally needs both remaining halves: the selector must be `First`/`FirstOrDefault` (`Single`/`SingleOrDefault` reports the ambiguity rather than resolving it, and is counted and never reported), and the chain must carry an `==` comparison of `<lambda parameter>.Name` against something that is not a literal. The receiver must be a plain identifier bound by one of the chain’s own lambdas, which places `assembly.GetName().Name == "X"` outside the rule by construction. One exemption: a `.Name` test joined by `&&` to a `FullName`/`AssemblyQualifiedName` test on the same identifier is spared; joined by `||` it is not. Deterministic, provable per finding. Advisory.
Other · Code Health — Whether log calls use message templates (queryable) rather than interpolated strings.
Method: Roslyn syntax scan: every log call-site counted; interpolated-string first-argument violations flagged. Population is all log calls, not estimated. Deterministic.
Other · Code Health — Whether nullable reference types are enabled and not undermined by heavy `!` suppression.
Method: Roslyn compiler-options scan: NullableContextOptions per project; null-forgiving (!) suppression density per 1k syntax nodes. Deterministic, adoption plus suppression penalty.
~0.5 `!` suppressions per 1k syntax nodes — 37 suppression(s) across the 75382 syntax node(s) in code where nullable warnings are ENABLED, which is the only code a `!` can suppress anything in (a `!` under `#nullable disable` is inert and is not counted, and its file's nodes are not in the denominator). Each one tells the compiler to trust you about null, suppressing the very safety NRTs provide.
What to do
Enable <Nullable>enable</Nullable> across all projects and resolve warnings rather than suppressing with `!`.
Do you agree with this assessment?
Reference — by lens
The score is the rank-weighted fold of these lenses (worst-heaviest), each including its meta-dimensions; a lens with a Critical contributor is capped at Fair (its band reads "gated by …") and is never the strongest area however high its average.
Capped at Fair by a Critical contributor — resolve it before relying on this lens.
Unscored — 3 check(s) recorded observations but carry no score
These checks ran and found something, but they do not carry a score — either by design (an advisory check reports evidence rather than grading it) or because they could not be scored here. They are excluded from the score for that reason, not because there was nothing to see.
P12 CI test-gate honesty — 1 observation(s) recorded · Reported, not scored — this card publishes what the CI gate does with the test inventory rather than grading it. The findings above are its output.
X10 Duplicated predicate — 1 observation(s) recorded · Advisory — this card reports evidence and never carries a score.
X7 Silent fallback defaults — 7 observation(s) recorded · Advisory — this card reports evidence and never carries a score.
Not included — 40 check(s) not relevant to this codebase
These checks had nothing to measure here (no tests, no git history, the codebase is small, or the architecture style doesn't apply), so they're omitted above rather than scored low.
AC1 Text alternatives — No user-facing web UI (the repo is a library/CLI/worker/headless service) — accessibility is not applicable.
AC2 Forms & labels — No user-facing web UI (the repo is a library/CLI/worker/headless service) — accessibility is not applicable.
AC3 Page structure — No user-facing web UI (the repo is a library/CLI/worker/headless service) — accessibility is not applicable.
AC4 Keyboard semantics — No user-facing web UI (the repo is a library/CLI/worker/headless service) — accessibility is not applicable.
AC5 ARIA correctness — No user-facing web UI (the repo is a library/CLI/worker/headless service) — accessibility is not applicable.
AC6 Visual & motion safety — No user-facing web UI (the repo is a library/CLI/worker/headless service) — accessibility is not applicable.
AC7 A11y enforcement — No user-facing web UI (the repo is a library/CLI/worker/headless service) — accessibility is not applicable.
AX1 Captive dependencies — no DI registrations detected
AX2 Stateful singletons — no singleton implementations detected
AX7 Slice cohesion — not applicable — not a vertical-slice architecture
AXB2 Runtime readiness — Advisory — this card reports evidence and never carries a score, so there is nothing missing here.
AXR1 Runtime accessibility — compose up failed (exit 17 — an image could not be built) — failed to solve: debian:trixie-slim: failed to resolve source metadata for docker.io/library/debian:trixie-slim: failed to do request: Head "https://registry-1.docker.io/v2/library/debian/manifests/trixie-slim": Forbidden; runtime evidence skipped This is a statement about this run, not a statement about your application: nothing here says the surface is inaccessible, only that it was never rendered.
C1 Data Protection — No personal data detected in the analyzed source — no PII-typed entity/column names (Email, FirstName, DateOfBirth, …), no ASP.NET Identity / user-account model, and no stored user credentials. GDPR data-protection controls are therefore N/A here. If this is intentional, record the no-PII posture in an ADR; if the app does process personal data, name those fields conventionally so this dimension activates.
C2 Access Controls — No access-control surface detected in the analyzed source — no web/app surface to authorize (no HTTP API or web-UI project) and no authorization code at all (no [Authorize]/policies, no imperative guard methods). Access control is therefore N/A here — this is a library/CLI, which is authorized by its CALLER, not by itself. If this codebase grows request handlers, the dimension reactivates and a default-deny posture is expected then.
C3 Audit Trail — No personal data detected in the analyzed source — no PII-typed entity/column names (Email, FirstName, DateOfBirth, …), no ASP.NET Identity / user-account model, and no stored user credentials. GDPR data-protection controls are therefore N/A here. If this is intentional, record the no-PII posture in an ADR; if the app does process personal data, name those fields conventionally so this dimension activates.
C4 Data Retention — No personal data detected in the analyzed source — no PII-typed entity/column names (Email, FirstName, DateOfBirth, …), no ASP.NET Identity / user-account model, and no stored user credentials. GDPR data-protection controls are therefore N/A here. If this is intentional, record the no-PII posture in an ADR; if the app does process personal data, name those fields conventionally so this dimension activates.
C5 Data-Subject Rights — No personal data detected in the analyzed source — no PII-typed entity/column names (Email, FirstName, DateOfBirth, …), no ASP.NET Identity / user-account model, and no stored user credentials. GDPR data-protection controls are therefore N/A here. If this is intentional, record the no-PII posture in an ADR; if the app does process personal data, name those fields conventionally so this dimension activates.
D11 Test Reliability — Test reliability not measured — no test run produced results
D18 Solution Shape — D18 scores the shape of a C#/VB .NET solution, but this repository's production source is mostly .cpp, .go, .java, .php, .py, .rs, .swift, .ts, which the C#/VB workspace does not load — the projects that loaded are an immaterial minority, so solution shape was not assessed for this repository. Not scored — this is a gap in the analyzer's reach, not a verdict about this repository.
D20 ADR Quality — N/A — ADRs are expected on deployable products with a user-facing host, not consumed libraries; no ADR log is required here.
D23 Boundary Type-Coupling — Cross-context type coupling could not be assessed — this codebase's bounded contexts are neither declared nor inferable.
D25 ADR Conformance — no ADRs to check
D27 Navigability — symbol resolution incomplete — navigability not assessed
D32 Data Compliance (PII/GDPR) — 10 file(s) were not parsed by semgrep — the PII/GDPR ruleset never ran over them
D39 IL Efficiency — IL not measured — the analyzer's build of the target did not succeed
D42 Runtime Threat Enforcement — The repository ships application workloads but no cluster-governance resources (CRDs, admission webhooks, or a committed policy engine). Runtime threat-detection (Falco/Tetragon) and admission control (Kyverno/OPA-Gatekeeper/PodSecurity) are cluster-OPERATOR controls owned by the platform, not shipped by an application repo/chart — nothing for this repo to assess.
D7 Architectural Integrity — no checkable ADRs and no dependency cycles — architectural integrity not assessed
D8 Code Coverage — Coverage not measured — analyzer environment
DM1 Domain Modelling — applicable but not scored (4 signals for this style, 2 needed — the count is met but a required primary signal is absent): 1 aggregate root(s) (types guarding their own state behind command methods — this language has no AggregateRoot base to inherit); 243 value object(s); 3 domain event(s); its domain events are published by services or handlers — no domain entity raises one; a Domain/Aggregates/ValueObjects layer; a top-level examples/ tree: a library or framework whose examples are its consumers — these types are building blocks, not a domain
ED2 Event/command shape — not scored — deciding whether a command has more than one competing handler requires resolving the call graph, and this analysis resolves a call's owner only where the receiver's type is written down in the source. Reported as guidance rather than measured
ED2 Event/command shape — not scored — deciding whether a command has more than one competing handler requires resolving the call graph, and a call made through an inferred or generic receiver has no resolvable owner in the source. Reported as guidance rather than measured
P2 Observability — This repo is a library, not a deployed service — it has no process to operate, so production observability (structured logging, tracing/metrics, health checks) is N/A. A library may log via an injected ILogger, but the absence of operational telemetry is not a defect here. If it grows a host (web API, worker), the dimension reactivates.
P7 Outbound HTTP resilience — not applicable — this isn't a service/API/worker
P8 Schema migrations — sqlx is declared, but the schema-migration mechanism could not be identified. Our limit, not a verdict on this repository.
P9 Domain vs controller coverage — no coverage report found on disk — produce a coverage report in a standard format (lcov — `cargo install cargo-llvm-cov`, then `cargo llvm-cov --lcov --output-path lcov.info`) and commit it — a hosted scan measures a clone of the repository, so a report that exists only in a working tree, a CI runner's or your own, never reaches it; the artefact is commonly gitignored, so `git add -f` that one file (or un-ignore its path) and commit it alongside the code it measures, or wire coverage collection into CI, to enable this cross-layer check
R11 Import Boundaries — No recognizable feature-sliced/layered src layout — boundary rules not applicable.
S1 Web-Security Posture — No web surface detected in the analyzed source — no HTTP API or web-UI project (no controllers/minimal-API endpoints, no Razor/Blazor views) and no web middleware (HTTPS redirection, HSTS, security headers, cookies). Transport security, security headers, secure cookies, CSRF/input-validation and middleware-order controls are therefore N/A here — this is a library/CLI/worker, not a web app. Crypto hygiene was still checked and found nothing to flag. If this codebase becomes web-facing, the dimension reactivates automatically.
SC1 Supply-chain hygiene — Advisory — this card reports evidence and never carries a score, so there is nothing missing here.
X6 Hand-rolled structured-format parsing — Advisory — this card reports evidence and never carries a score, so there is nothing missing here.
X9 Subsumed condition operand — Advisory — this card reports evidence and never carries a score, so there is nothing missing here.
Appendix A — Findings (grouped)
The findings behind the scores, grouped by severity, then by dimension and kind. The high-severity issues are enumerated in full below; items per group are capped at 25 with any overflow stated explicitly per group, never silently truncated. The complete machine-readable list of every finding (all severities) is the companion findings.md in this report's bundle.
Orphaned knowledge core/cli/src/args/permissions/stream.rs— No living knowledge remains for this large file — its last meaningful change has decayed away, so if it breaks, no one currently understands it. It does carry its own tests, so the behaviour is pinned even though the understanding is gone: schedule a read-through, using those tests as the specification, before the next change lands here.
FileTooLong: REDACTED core/shard/src/lib.rs— FileTooLong — 6190 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 77% of them inside a single declaration: IggyShard (3 blocks, 1368-10413), declaring 49 free functions. The bar is 500 significant lines; this is 5690 over it, 12.38× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: src/iggy_partition.rs core/partitions/src/iggy_partition.rs— FileTooLong — 4917 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted). The bar is 500 significant lines; this is 4417 over it, 9.83× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: impls/metadata.rs core/metadata/src/impls/metadata.rs— FileTooLong — 1990 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted). The bar is 500 significant lines; this is 1490 over it, 3.98× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: src/state_transfer.rs core/partitions/src/state_transfer.rs— FileTooLong — 1949 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted). The bar is 500 significant lines; this is 1449 over it, 3.90× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: src/impls.rs core/consensus/src/impls.rs— FileTooLong — 1877 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 70% of them inside a single declaration: VsrConsensus (4 blocks, 406-4248). The bar is 500 significant lines; this is 1377 over it, 3.75× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: REDACTED core/connectors/sources/postgres_source/src/lib.rs— FileTooLong — 1801 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), declaring 33 free functions. The bar is 500 significant lines; this is 1301 over it, 3.60× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: stm/stream.rs core/metadata/src/stm/stream.rs— FileTooLong — 1710 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted). The bar is 500 significant lines; this is 1210 over it, 3.42× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: src/segment_recovery.rs core/partitions/src/segment_recovery.rs— FileTooLong — 1616 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted). The bar is 500 significant lines; this is 1116 over it, 3.23× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: consensus/header.rs core/binary_protocol/src/consensus/header.rs— FileTooLong — 1519 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted). The bar is 500 significant lines; this is 1019 over it, 3.04× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: http/handlers.rs core/server/src/http/handlers.rs— FileTooLong — 1269 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), declaring 47 free functions. The bar is 500 significant lines; this is 769 over it, 2.54× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: src/partition_journal.rs core/journal/src/partition_journal.rs— FileTooLong — 1219 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 78% of them inside a single declaration: PartitionPrepareJournal (4 blocks, 106-1552). The bar is 500 significant lines; this is 719 over it, 2.44× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: REDACTED REDACTED— FileTooLong — 1098 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted). The bar is 500 significant lines; this is 598 over it, 2.20× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: src/persistence.rs core/partitions/src/persistence.rs— FileTooLong — 1061 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 72% of them inside a single declaration: PartitionPersistence (3 blocks, 166-1487). The bar is 500 significant lines; this is 561 over it, 2.12× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: src/client_table.rs core/consensus/src/client_table.rs— FileTooLong — 940 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 69% of them inside a single declaration: ClientTable (3 blocks, 669-2094). The bar is 500 significant lines; this is 440 over it, 1.88× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: tcp/tcp_client.rs core/sdk/src/tcp/tcp_client.rs— FileTooLong — 938 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 93% of them inside a single declaration: TcpClient (7 blocks, 95-1675). The bar is 500 significant lines; this is 438 over it, 1.88× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: src/client.rs foreign/cpp/src/client.rs— FileTooLong — 918 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 91% of them inside a single declaration: Client (2 blocks, 59-1226). The bar is 500 significant lines; this is 418 over it, 1.84× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: src/client.rs foreign/python/src/client.rs— FileTooLong — 908 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 94% of them inside a single declaration: IggyClient (2 blocks, 60-1700). The bar is 500 significant lines; this is 408 over it, 1.82× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: Mappers/BinaryMapper.cs foreign/csharp/Iggy_SDK/Mappers/BinaryMapper.cs— FileTooLong — 879 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 379 over it, 1.76× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: tcp/AsyncTcpConnection.java foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/tcp/AsyncTcpConnection.java— FileTooLong — 872 significant lines (blank, comment-only and punctuation-only lines excluded), about 93% of them inside a single declaration: AsyncTcpConnection (90-1238). The bar is 500 significant lines; this is 372 over it, 1.74× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: REDACTED core/simulator/src/lib.rs— FileTooLong — 866 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 84% of them inside a single declaration: Simulator (2 blocks, 187-1611). The bar is 500 significant lines; this is 366 over it, 1.73× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: src/config.rs foreign/python/src/config.rs— FileTooLong — 864 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted). The bar is 500 significant lines; this is 364 over it, 1.73× the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them.
FileTooLong: REDACTED REDACTED— FileTooLong — 856 significant lines (blank, comment-only and punctuation-only lines excluded), about 74% of them inside a single declaration: IggyTcpClient (30 blocks, 71-1555). The bar is 500 significant lines; this is 356 over it, 1.71× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: clients/consumer.rs core/sdk/src/clients/consumer.rs— FileTooLong — 841 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 80% of them inside a single declaration: IggyConsumer (6 blocks, 271-1837). The bar is 500 significant lines; this is 341 over it, 1.68× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: REDACTED core/connectors/sinks/surrealdb_sink/src/lib.rs— FileTooLong — 822 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 63% of them inside a single declaration: SurrealDbSink (4 blocks, 52-882). The bar is 500 significant lines; this is 322 over it, 1.64× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
FileTooLong: REDACTED core/connectors/sinks/http_sink/src/lib.rs— FileTooLong — 816 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), about 78% of them inside a single declaration: HttpSink (3 blocks, 203-1256). The bar is 500 significant lines; this is 316 over it, 1.63× the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body — the parts that share the same inputs and are named together — into its own unit in a sibling file, and have the original call them.
Hotspot: core/shard/src/lib.rs core/shard/src/lib.rs:7575— core/shard/src/lib.rs changed 58 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 66 in IggyShard::tick_partitions at line 7575. 32 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/shard/src/lib.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/partitions/src/iggy_partition.rs core/partitions/src/iggy_partition.rs:4848— core/partitions/src/iggy_partition.rs changed 53 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 36 in IggyPartition::on_replicate at line 4848. 26 of those changes were fix/bug commits, and the other 27 changed it for other reasons — this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/partitions/src/iggy_partition.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: foreign/node/src/wire/error.code.ts foreign/node/src/wire/error.code.ts:18— foreign/node/src/wire/error.code.ts changed 5 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 240 in error.code.translateErrorCode at line 18. 3 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- foreign/node/src/wire/error.code.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/shard/src/router.rs core/shard/src/router.rs:674— core/shard/src/router.rs changed 30 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 36 in IggyShard::process_lifecycle at line 674. 13 of those changes were fix/bug commits, and the other 17 changed it for other reasons — this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/shard/src/router.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/server/src/partition_reconciler.rs core/server/src/partition_reconciler.rs:573— core/server/src/partition_reconciler.rs changed 42 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 18 in server::partition_reconciler::reconcile_additions at line 573. 13 of those changes were fix/bug commits, and the other 29 changed it for other reasons — this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/server/src/partition_reconciler.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/metadata/src/impls/metadata.rs core/metadata/src/impls/metadata.rs:1733— core/metadata/src/impls/metadata.rs changed 42 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in IggyMetadata::install_state_transfer at line 1733. 17 of those changes were fix/bug commits, and the other 25 changed it for other reasons — this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/metadata/src/impls/metadata.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/partitions/src/state_transfer.rs core/partitions/src/state_transfer.rs:2558— core/partitions/src/state_transfer.rs changed 15 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 33 in IggyPartition::install_state_transfer at line 2558. 8 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/partitions/src/state_transfer.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/configs/src/server_config/validators.rs core/configs/src/server_config/validators.rs:51— core/configs/src/server_config/validators.rs changed 13 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 38 in ServerConfig::validate at line 51. 5 of those changes were fix/bug commits, and the other 8 changed it for other reasons — this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/configs/src/server_config/validators.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/sdk/src/quic/quic_client.rs core/sdk/src/quic/quic_client.rs:168— core/sdk/src/quic/quic_client.rs changed 11 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 44 in QuicClient::send_raw_with_response at line 168. 6 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/sdk/src/quic/quic_client.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/sdk/src/websocket/websocket_client.rs core/sdk/src/websocket/websocket_client.rs:162— core/sdk/src/websocket/websocket_client.rs changed 11 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 44 in WebSocketClient::send_raw_with_response at line 162. 7 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one — a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/sdk/src/websocket/websocket_client.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/simulator/src/replica.rs core/simulator/src/replica.rs:143— core/simulator/src/replica.rs changed 24 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 19 in simulator::replica::new_shard at line 143. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/simulator/src/replica.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/configs/src/server_config/cluster.rs core/configs/src/server_config/cluster.rs:868— core/configs/src/server_config/cluster.rs changed 8 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 49 in ClusterConfig::validate at line 868. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/configs/src/server_config/cluster.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/metadata/src/stm/stream.rs core/metadata/src/stm/stream.rs:2191— core/metadata/src/stm/stream.rs changed 26 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 15 in CreateTopicWithAssignmentsRequest::apply at line 2191. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/metadata/src/stm/stream.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs:1049— foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs changed 13 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 28 in TcpMessageStream.TryEstablishConnectionAsync at line 1049. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/metadata/src/impls/recovery.rs core/metadata/src/impls/recovery.rs:355— core/metadata/src/impls/recovery.rs changed 16 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 21 in metadata::impls::recovery::recover at line 355. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/metadata/src/impls/recovery.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/sdk/src/clients/consumer.rs core/sdk/src/clients/consumer.rs:1533— core/sdk/src/clients/consumer.rs changed 12 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 28 in IggyConsumer::poll_next at line 1533. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/sdk/src/clients/consumer.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/server/src/boot/mod.rs core/server/src/boot/mod.rs:410— core/server/src/boot/mod.rs changed 10 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 27 in server::boot::shard_main at line 410. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/server/src/boot/mod.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: REDACTED REDACTED:1043— REDACTED changed 10 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 27 in IggyTcpClient.Connect at line 1043. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- REDACTED`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/server_common/src/consensus_message.rs core/server_common/src/consensus_message.rs:920— core/server_common/src/consensus_message.rs changed 12 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 22 in MessageBag::try_from at line 920. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/server_common/src/consensus_message.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: foreign/node/src/client/client.socket.ts foreign/node/src/client/client.socket.ts:305— foreign/node/src/client/client.socket.ts changed 9 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 29 in CommandResponseStream.sendCommand at line 305. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- foreign/node/src/client/client.socket.ts`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/journal/src/prepare_journal.rs core/journal/src/prepare_journal.rs:411— core/journal/src/prepare_journal.rs changed 12 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 21 in PrepareJournal::scan at line 411. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/journal/src/prepare_journal.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/sdk/src/tcp/tcp_client.rs core/sdk/src/tcp/tcp_client.rs:1317— core/sdk/src/tcp/tcp_client.rs changed 10 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 25 in TcpClient::send_raw at line 1317. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/sdk/src/tcp/tcp_client.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/metadata/src/stm/authz.rs core/metadata/src/stm/authz.rs:128— core/metadata/src/stm/authz.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 39 in metadata::stm::authz::authorize at line 128. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/metadata/src/stm/authz.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/partitions/src/segment_recovery.rs core/partitions/src/segment_recovery.rs:570— core/partitions/src/segment_recovery.rs changed 12 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 19 in partitions::segment_recovery::load_persisted_segments_with_checkpoint at line 570. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/partitions/src/segment_recovery.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Hotspot: core/server/src/dispatch/mod.rs core/server/src/dispatch/mod.rs:408— core/server/src/dispatch/mod.rs changed 11 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 20 in server::dispatch::handle_client_request at line 408. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/server/src/dispatch/mod.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Dead code: ErrorFactory foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:22— NamedType ErrorFactory — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: IoError foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:97— Method IoError — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotCreateStreamDirectory foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:102— Method CannotCreateStreamDirectory — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotCreateStreamInfo foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:108— Method CannotCreateStreamInfo — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotUpdateStreamInfo foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:114— Method CannotUpdateStreamInfo — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotOpenStreamInfo foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:120— Method CannotOpenStreamInfo — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotReadStreamInfo foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:126— Method CannotReadStreamInfo — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotCreateStream foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:132— Method CannotCreateStream — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotDeleteStream foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:137— Method CannotDeleteStream — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotDeleteStreamDirectory foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:142— Method CannotDeleteStreamDirectory — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: StreamNotFound foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:148— Method StreamNotFound — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: StreamAlreadyExists foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:153— Method StreamAlreadyExists — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotCreateTopicsDirectory foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:158— Method CannotCreateTopicsDirectory — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotCreateTopicDirectory foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:164— Method CannotCreateTopicDirectory — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotCreateTopicInfo foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:170— Method CannotCreateTopicInfo — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotUpdateTopicInfo foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:176— Method CannotUpdateTopicInfo — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotOpenTopicInfo foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:182— Method CannotOpenTopicInfo — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotReadTopicInfo foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:188— Method CannotReadTopicInfo — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotCreateTopic foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:194— Method CannotCreateTopic — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotDeleteTopic foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:200— Method CannotDeleteTopic — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotDeleteTopicDirectory foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:206— Method CannotDeleteTopicDirectory — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: TopicNotFound foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:212— Method TopicNotFound — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: TopicAlreadyExists foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:218— Method TopicAlreadyExists — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotCreatePartition foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:224— Method CannotCreatePartition — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
Dead code: CannotCreatePartitionDirectory foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:230— Method CannotCreatePartitionDirectory — Roslyn's SymbolFinder walked every project the solution loads, including Iggy_SDK(net8.0), and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository — a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol's name, and any project the workspace could not load. This is 'no caller found by this walk', not a verdict that the symbol is unused.
R4 · Test Coverage· No test reaches this file · ×40
No test reaches this file web/src/lib/components/PermissionsManager.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file REDACTED— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file scripts/ci/render-node-licenses.mjs— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/actions/tooltip.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/domain/Stats.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/components/Modals/StreamSettingsModal.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/components/DurationInput.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/components/Modals/TopicSettingsModal.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/utils/addOnKeyDownListener.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/components/Modals/DeletePartitionsModal.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file foreign/node/src/debug-send.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file REDACTED— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/components/Modals/AddTopicModal.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file foreign/node/src/debug.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/components/Modals/AddUserModal.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/components/Modals/InspectMessage.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file foreign/node/src/bdd/message.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/components/Modals/AddPartitionsModal.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/components/SortableList.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/api/clientApi.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/components/Modals/AddStreamModal.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/routes/auth/sign-in/+page.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/domain/Permissions.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/lib/domain/Message.ts— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
No test reaches this file web/src/routes/dashboard/streams/[streamId=i32]/topics/[topicId=i32]/partitions/[partitionId=i32]/messages/+page.svelte— No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL — if neither does, no test reaches this one.
Duplicated block (8 lines × 2) core/ai/mcp/src/stream.rs:75— core/ai/mcp/src/stream.rs:75-82 | core/connectors/runtime/src/stream.rs:107-114 — before extracting anything, compare `core/ai/mcp/src/stream.rs` and `core/connectors/runtime/src/stream.rs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 52 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (8 lines × 2) core/binary_protocol/src/requests/users/create_user.rs:59— core/binary_protocol/src/requests/users/create_user.rs:59-66 | core/binary_protocol/src/requests/users/login_user.rs:51-58 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (8 lines × 2) core/connectors/sinks/http_sink/src/lib.rs:746— core/connectors/sinks/http_sink/src/lib.rs:746-753 | core/connectors/sinks/http_sink/src/lib.rs:828-835 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) core/connectors/sources/postgres_source/src/lib.rs:771— core/connectors/sources/postgres_source/src/lib.rs:771-778 | core/connectors/sources/postgres_source/src/lib.rs:1499-1506 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) core/integration/src/harness/handle/client.rs:116— core/integration/src/harness/handle/client.rs:116-123 | core/integration/src/harness/handle/client.rs:189-196 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) core/message_bus/src/transports/ws.rs:249— core/message_bus/src/transports/ws.rs:249-256 | core/message_bus/src/transports/wss.rs:400-407 — before extracting anything, compare `core/message_bus/src/transports/ws.rs` and `core/message_bus/src/transports/wss.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 81 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (8 lines × 2) core/metadata/src/impls/metadata.rs:3875— core/metadata/src/impls/metadata.rs:3875-3882 | core/metadata/src/impls/metadata.rs:3913-3920 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) core/partitions/src/iggy_partitions.rs:135— core/partitions/src/iggy_partitions.rs:135-142 | core/partitions/src/iggy_partitions.rs:151-158 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) core/partitions/src/journal.rs:529— core/partitions/src/journal.rs:529-536 | core/partitions/src/journal.rs:598-605 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) core/partitions/src/journal.rs:585— core/partitions/src/journal.rs:585-592 | core/partitions/src/journal.rs:1133-1140 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) core/partitions/src/persistence.rs:360— core/partitions/src/persistence.rs:360-367 | core/partitions/src/persistence.rs:400-407 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) core/sdk/src/quic/quic_client.rs:501— core/sdk/src/quic/quic_client.rs:501-508 | core/sdk/src/websocket/websocket_client.rs:497-504 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (8 lines × 2) core/sdk/src/quic/quic_client.rs:758— core/sdk/src/quic/quic_client.rs:758-765 | core/sdk/src/tcp/tcp_client.rs:766-773 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/tcp/tcp_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 134 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (8 lines × 2) core/simulator/src/client.rs:769— core/simulator/src/client.rs:769-776 | core/simulator/src/client.rs:787-794 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) gateways/kafka/src/bridge/iggy_bridge/topics.rs:108— gateways/kafka/src/bridge/iggy_bridge/topics.rs:108-115 | gateways/kafka/src/bridge/iggy_bridge/topics.rs:372-379 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) gateways/kafka/tools/kafka-tool/src/response.rs:303— gateways/kafka/tools/kafka-tool/src/response.rs:303-310 | gateways/kafka/tools/kafka-tool/src/response.rs:327-334 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) core/connectors/sdk/src/decoders/proto.rs:85— core/connectors/sdk/src/decoders/proto.rs:85-92 | core/connectors/sdk/src/encoders/proto.rs:107-114 — `core/connectors/sdk/src/decoders/proto.rs` and `core/connectors/sdk/src/encoders/proto.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 11 separate duplicated blocks between them, totalling at least 151 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (8 lines × 2) core/simulator/src/workload/ops/delete_stream.rs:44— core/simulator/src/workload/ops/delete_stream.rs:44-51 | core/simulator/src/workload/ops/purge_stream.rs:44-51 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (8 lines × 2) foreign/python/src/config.rs:1492— foreign/python/src/config.rs:1492-1499 | foreign/python/src/producer.rs:910-917 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (8 lines × 2) core/cli/src/commands/binary_consumer_groups/get_consumer_groups.rs:33— core/cli/src/commands/binary_consumer_groups/get_consumer_groups.rs:33-40 | core/cli/src/commands/binary_topics/get_topics.rs:33-40 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (8 lines × 2) core/connectors/runtime/src/sink.rs:445— core/connectors/runtime/src/sink.rs:445-452 | core/connectors/runtime/src/source.rs:280-287 — before extracting anything, compare `core/connectors/runtime/src/sink.rs` and `core/connectors/runtime/src/source.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 50 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (8 lines × 2) core/simulator/src/workload/ops/delete_personal_access_token.rs:68— core/simulator/src/workload/ops/delete_personal_access_token.rs:68-75 | core/simulator/src/workload/ops/delete_stream.rs:68-75 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (8 lines × 2) core/cli/src/commands/binary_users/change_password.rs:65— core/cli/src/commands/binary_users/change_password.rs:65-72 | core/cli/src/commands/binary_users/change_password.rs:78-85 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) foreign/python/src/config.rs:398— foreign/python/src/config.rs:398-405 | foreign/python/src/config.rs:1413-1420 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 2) core/integration/src/harness/handle/server.rs:470— core/integration/src/harness/handle/server.rs:470-477 | core/integration/src/harness/handle/server.rs:482-489 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
ClassTooLong: IggyShard core/shard/src/lib.rs:1368— ClassTooLong — 4779 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 151 methods, 3 blocks, lines 1368-10413. The bar is 400 significant lines; this is 4379 over it, 11.95× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: VsrConsensus core/consensus/src/impls.rs:1071— ClassTooLong — 1318 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 119 methods, 4 blocks, lines 406-4248. The bar is 400 significant lines; this is 918 over it, 3.30× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: PostgresSource core/connectors/sources/postgres_source/src/lib.rs:57— ClassTooLong — 972 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 34 methods, 4 blocks, lines 57-1550. The bar is 400 significant lines; this is 572 over it, 2.43× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: PartitionPrepareJournal core/journal/src/partition_journal.rs:106— ClassTooLong — 953 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 64 methods, 4 blocks, lines 106-1552. The bar is 400 significant lines; this is 553 over it, 2.38× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: TcpClient core/sdk/src/tcp/tcp_client.rs:95— ClassTooLong — 870 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 26 methods, 7 blocks, lines 95-1675. The bar is 400 significant lines; this is 470 over it, 2.18× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: IggyClient foreign/python/src/client.rs:60— ClassTooLong — 849 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 42 methods, 2 blocks, lines 60-1700. The bar is 400 significant lines; this is 449 over it, 2.12× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: Client foreign/cpp/src/client.rs:59— ClassTooLong — 835 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 48 methods, 2 blocks, lines 59-1226. The bar is 400 significant lines; this is 435 over it, 2.09× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: AsyncTcpConnection foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/tcp/AsyncTcpConnection.java:90— ClassTooLong — 809 significant lines (blank, comment-only and punctuation-only lines excluded), 62 methods. The bar is 400 significant lines; this is 409 over it, 2.02× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: PartitionPersistence core/partitions/src/persistence.rs:166— ClassTooLong — 763 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 56 methods, 3 blocks, lines 166-1487. The bar is 400 significant lines; this is 363 over it, 1.91× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: WebSocketClient core/sdk/src/websocket/websocket_client.rs:81— ClassTooLong — 734 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 21 methods, 7 blocks, lines 81-1220. The bar is 400 significant lines; this is 334 over it, 1.84× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: Simulator core/simulator/src/lib.rs:187— ClassTooLong — 729 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 43 methods, 2 blocks, lines 187-1611. The bar is 400 significant lines; this is 329 over it, 1.82× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: CommandResponseStream foreign/node/src/client/client.socket.ts:163— ClassTooLong — 698 significant lines (blank, comment-only and punctuation-only lines excluded), 35 methods. The bar is 400 significant lines; this is 298 over it, 1.75× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: QuicClient core/sdk/src/quic/quic_client.rs:84— ClassTooLong — 680 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 16 methods, 7 blocks, lines 84-1140. The bar is 400 significant lines; this is 280 over it, 1.70× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: IggyConsumer core/sdk/src/clients/consumer.rs:637— ClassTooLong — 676 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 21 methods, 6 blocks, lines 271-1837. The bar is 400 significant lines; this is 276 over it, 1.69× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: ClientTable core/consensus/src/client_table.rs:669— ClassTooLong — 650 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 32 methods, 3 blocks, lines 669-2094. The bar is 400 significant lines; this is 250 over it, 1.63× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: ServerHandle core/integration/src/harness/handle/server.rs:69— ClassTooLong — 646 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 50 methods, 8 blocks, lines 69-1172. The bar is 400 significant lines; this is 246 over it, 1.62× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: Streams core/metadata/src/stm/stream.rs:846— ClassTooLong — 644 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 34 methods, 2 blocks, lines 1112-2777. The bar is 400 significant lines; this is 244 over it, 1.61× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: HttpSink core/connectors/sinks/http_sink/src/lib.rs:203— ClassTooLong — 640 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 14 methods, 3 blocks, lines 203-1256. The bar is 400 significant lines; this is 240 over it, 1.60× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: IggyTcpClient REDACTED:71— ClassTooLong — 637 significant lines (blank, comment-only and punctuation-only lines excluded), 98 methods, 30 blocks, lines 71-1555. The bar is 400 significant lines; this is 237 over it, 1.59× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: IggyService core/ai/mcp/src/service/mod.rs:41— ClassTooLong — 571 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 42 methods, 3 blocks, lines 41-765. The bar is 400 significant lines; this is 171 over it, 1.43× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: AsyncIggyTcpClient foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/tcp/AsyncIggyTcpClient.java:124— ClassTooLong — 562 significant lines (blank, comment-only and punctuation-only lines excluded), 48 methods. The bar is 400 significant lines; this is 162 over it, 1.41× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: SurrealDbSink core/connectors/sinks/surrealdb_sink/src/lib.rs:52— ClassTooLong — 518 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 18 methods, 4 blocks, lines 52-882. The bar is 400 significant lines; this is 118 over it, 1.30× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: IggyError core/common/src/error/iggy_error.rs:38— ClassTooLong — 515 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 4 methods, 3 blocks, lines 38-597. The bar is 400 significant lines; this is 115 over it, 1.29× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: MeilisearchSink core/connectors/sinks/meilisearch_sink/src/lib.rs:101— ClassTooLong — 502 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 20 methods, 3 blocks, lines 101-891. The bar is 400 significant lines; this is 102 over it, 1.26× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
ClassTooLong: ProtoConvert core/connectors/sdk/src/transforms/proto_convert.rs:83— ClassTooLong — 497 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted), 22 methods, 4 blocks, lines 83-798. The bar is 400 significant lines; this is 97 over it, 1.24× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: IggyPartition core/partitions/src/iggy_partition.rs:117— TooManyMethods — 219 methods, declared across 2 files: src/iggy_partition.rs (203), src/state_transfer.rs (16). The bar is 30 methods; this is 189 over it, 7.30× the bar. That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: IggyShard core/shard/src/lib.rs:1368— TooManyMethods — 151 methods, declared across 3 files: REDACTED (136), src/router.rs (12), src/poll.rs (3). The bar is 30 methods; this is 121 over it, 5.03× the bar. That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: VsrConsensus core/consensus/src/impls.rs:1071— TooManyMethods — 119 methods. The bar is 30 methods; this is 89 over it, 3.97× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: TcpMessageStream foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs— TooManyMethods — 1261 significant lines (blank, comment-only and punctuation-only lines excluded), 117 methods, declared across 3 files: Implementations/TcpMessageStream.cs (81), Implementations/TcpMessageStream.Vsr.cs (22), Implementations/TcpMessageStream.PollRouting.cs (14). The bar is 30 methods; this is 87 over it, 3.90× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: IggyTcpClient REDACTED:71— TooManyMethods — 98 methods, declared across 16 files: REDACTED (29), tcp/tcp_poll_routing.go (10), tcp/tcp_session_management.go (10), tcp/tcp_user_management.go (8), +12 more file(s). The bar is 30 methods; this is 68 over it, 3.27× the bar. That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: HttpMessageStream foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs— TooManyMethods — 496 significant lines (blank, comment-only and punctuation-only lines excluded), 64 methods. The bar is 30 methods; this is 34 over it, 2.13× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: PartitionPrepareJournal core/journal/src/partition_journal.rs:106— TooManyMethods — 64 methods, declared across 2 files: src/partition_journal.rs (44), partition_journal/segments.rs (20). The bar is 30 methods; this is 34 over it, 2.13× the bar. That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: AsyncTcpConnection foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/tcp/AsyncTcpConnection.java:90— TooManyMethods — 62 methods. The bar is 30 methods; this is 32 over it, 2.07× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: TestHarness core/integration/src/harness/orchestrator/harness.rs:46— TooManyMethods — 57 methods. The bar is 30 methods; this is 27 over it, 1.90× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: PartitionPersistence core/partitions/src/persistence.rs:166— TooManyMethods — 56 methods. The bar is 30 methods; this is 26 over it, 1.87× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: ErrorFactory foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs— TooManyMethods — 184 significant lines (blank, comment-only and punctuation-only lines excluded), 50 methods. The bar is 30 methods; this is 20 over it, 1.67× the bar. The type holds no instance state, so there is no shared data to group its members by. To reduce it, split it by area instead: give each cohesive family of members its own smaller type, so no one type has to be read whole to change one of them.
TooManyMethods: ServerHandle core/integration/src/harness/handle/server.rs:69— TooManyMethods — 50 methods. The bar is 30 methods; this is 20 over it, 1.67× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: AsyncIggyTcpClient foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/tcp/AsyncIggyTcpClient.java:124— TooManyMethods — 48 methods. The bar is 30 methods; this is 18 over it, 1.60× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: Client foreign/cpp/src/client.rs:59— TooManyMethods — 48 methods. The bar is 30 methods; this is 18 over it, 1.60× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: BinaryMapper foreign/csharp/Iggy_SDK/Mappers/BinaryMapper.cs— TooManyMethods — 865 significant lines (blank, comment-only and punctuation-only lines excluded), 46 methods. The bar is 30 methods; this is 16 over it, 1.53× the bar. The type holds no instance state, so there is no shared data to group its members by. To reduce it, split it by area instead: give each cohesive family of members its own smaller type, so no one type has to be read whole to change one of them.
TooManyMethods: Permissioner core/metadata/src/permissioner/mod.rs:24— TooManyMethods — 46 methods, declared across 10 files: permissioner_rules/users.rs (9), permissioner_rules/streams.rs (7), permissioner_rules/topics.rs (7), permissioner_rules/consumer_groups.rs (6), +6 more file(s). The bar is 30 methods; this is 16 over it, 1.53× the bar. That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: IggyConsumer foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Logging.cs— TooManyMethods — 450 significant lines (blank, comment-only and punctuation-only lines excluded), 43 methods, declared across 3 files: Consumers/IggyConsumer.Logging.cs (23), Consumers/IggyConsumer.cs (17), Consumers/IggyConsumer.Rented.cs (3). The bar is 30 methods; this is 13 over it, 1.43× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: BytesDeserializer foreign/java/java-sdk/src/main/java/org/apache/iggy/serde/BytesDeserializer.java:81— TooManyMethods — 43 methods. The bar is 30 methods; this is 13 over it, 1.43× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: Simulator core/simulator/src/lib.rs:187— TooManyMethods — 43 methods. The bar is 30 methods; this is 13 over it, 1.43× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: TcpContracts foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs— TooManyMethods — 545 significant lines (blank, comment-only and punctuation-only lines excluded), 42 methods. The bar is 30 methods; this is 12 over it, 1.40× the bar. The type holds no instance state, so there is no shared data to group its members by. To reduce it, split it by area instead: give each cohesive family of members its own smaller type, so no one type has to be read whole to change one of them.
TooManyMethods: IggyService core/ai/mcp/src/service/mod.rs:41— TooManyMethods — 42 methods. The bar is 30 methods; this is 12 over it, 1.40× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: SimClient core/simulator/src/client.rs:60— TooManyMethods — 42 methods. The bar is 30 methods; this is 12 over it, 1.40× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: IggyClient foreign/python/src/client.rs:60— TooManyMethods — 42 methods. The bar is 30 methods; this is 12 over it, 1.40× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: IggyMetadata core/metadata/src/impls/metadata.rs:697— TooManyMethods — 41 methods. The bar is 30 methods; this is 11 over it, 1.37× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
TooManyMethods: IggyMessageBus core/message_bus/src/lib.rs:719— TooManyMethods — 38 methods. The bar is 30 methods; this is 8 over it, 1.27× the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility.
FunctionTooLong: iggy_swift_golden_vectors::main REDACTED:299— FunctionTooLong — iggy_swift_golden_vectors::main runs 889 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 789 over it, 8.89× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: iggy_connector_postgres_source::extract_column_value core/connectors/sources/postgres_source/src/lib.rs:1552— FunctionTooLong — iggy_connector_postgres_source::extract_column_value runs 346 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 246 over it, 3.46× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: server::boot::shard_main core/server/src/boot/mod.rs:410— FunctionTooLong — server::boot::shard_main runs 341 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 241 over it, 3.41× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: kafka_message_gen::build_payload gateways/kafka/tools/kafka-tool/src/main.rs:242— FunctionTooLong — kafka_message_gen::build_payload runs 272 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 172 over it, 2.72× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: iggy_connector_clickhouse_sink::binary::serialize_value core/connectors/sinks/clickhouse_sink/src/binary.rs:83— FunctionTooLong — iggy_connector_clickhouse_sink::binary::serialize_value runs 251 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 151 over it, 2.51× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: iggy_connectors::source::source_forwarding_loop core/connectors/runtime/src/source.rs:555— FunctionTooLong — iggy_connectors::source::source_forwarding_loop runs 216 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 116 over it, 2.16× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: iggy_cli::get_command core/cli/src/main.rs:107— FunctionTooLong — iggy_cli::get_command runs 194 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 94 over it, 1.94× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: server::boot::recovery::build_shard_for_thread core/server/src/boot/recovery.rs:69— FunctionTooLong — server::boot::recovery::build_shard_for_thread runs 182 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 82 over it, 1.82× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: iggy_connectors::sink::process_messages core/connectors/runtime/src/sink.rs:548— FunctionTooLong — iggy_connectors::sink::process_messages runs 177 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 77 over it, 1.77× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: iggy_connector_influxdb_source::v3::poll core/connectors/sources/influxdb_source/src/v3.rs:439— FunctionTooLong — iggy_connector_influxdb_source::v3::poll runs 177 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 77 over it, 1.77× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: simulator::replica::new_shard core/simulator/src/replica.rs:143— FunctionTooLong — simulator::replica::new_shard runs 172 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 72 over it, 1.72× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: partitions::segment_recovery::load_persisted_segments_with_checkpoint core/partitions/src/segment_recovery.rs:570— FunctionTooLong — partitions::segment_recovery::load_persisted_segments_with_checkpoint runs 168 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 68 over it, 1.68× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: partitions::segment_recovery::recover_segment_bounds core/partitions/src/segment_recovery.rs:1572— FunctionTooLong — partitions::segment_recovery::recover_segment_bounds runs 155 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 55 over it, 1.55× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: metadata::stm::authz::authorize core/metadata/src/stm/authz.rs:128— FunctionTooLong — metadata::stm::authz::authorize runs 147 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 47 over it, 1.47× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: iggy_connectors::main core/connectors/runtime/src/main.rs:121— FunctionTooLong — iggy_connectors::main runs 137 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 37 over it, 1.37× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: iggy_connectors::source::init core/connectors/runtime/src/source.rs:96— FunctionTooLong — iggy_connectors::source::init runs 137 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 37 over it, 1.37× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: kafka_message_gen::response::decode_body gateways/kafka/tools/kafka-tool/src/response.rs:205— FunctionTooLong — kafka_message_gen::response::decode_body runs 137 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 37 over it, 1.37× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: server::partition_helpers::load_partition_or_fence core/server/src/partition_helpers.rs:157— FunctionTooLong — server::partition_helpers::load_partition_or_fence runs 131 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 31 over it, 1.31× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: server::partition_reconciler::reconcile_additions core/server/src/partition_reconciler.rs:573— FunctionTooLong — server::partition_reconciler::reconcile_additions runs 131 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 31 over it, 1.31× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: message_bus::installer::replica::install_replica_conn core/message_bus/src/installer/replica.rs:326— FunctionTooLong — message_bus::installer::replica::install_replica_conn runs 127 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 27 over it, 1.27× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: server::partition_helpers::load_partition core/server/src/partition_helpers.rs:375— FunctionTooLong — server::partition_helpers::load_partition runs 124 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 24 over it, 1.24× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: iggy_connector_clickhouse_sink::schema::parse_type_inner core/connectors/sinks/clickhouse_sink/src/schema.rs:155— FunctionTooLong — iggy_connector_clickhouse_sink::schema::parse_type_inner runs 121 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 21 over it, 1.21× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: iggy_connector_sdk::source::handle_messages core/connectors/sdk/src/source.rs:288— FunctionTooLong — iggy_connector_sdk::source::handle_messages runs 116 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 16 over it, 1.16× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: harness_derive::codegen::generate_harness_setup core/harness_derive/src/codegen.rs:389— FunctionTooLong — harness_derive::codegen::generate_harness_setup runs 115 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 15 over it, 1.15× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
FunctionTooLong: message_bus::replica::io::start_on_shard_zero core/message_bus/src/replica/io.rs:166— FunctionTooLong — message_bus::replica::io::start_on_shard_zero runs 115 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 15 over it, 1.15× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
Duplicated block (7 lines × 2) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:46— foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:46-52 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:55-61 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (7 lines × 2) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:831— foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:831-837 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:840-846 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (7 lines × 2) core/ai/mcp/src/stream.rs:91— core/ai/mcp/src/stream.rs:91-97 | core/connectors/runtime/src/stream.rs:123-129 — before extracting anything, compare `core/ai/mcp/src/stream.rs` and `core/connectors/runtime/src/stream.rs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 52 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (7 lines × 2) core/common/src/types/options/mod.rs:1182— core/common/src/types/options/mod.rs:1182-1188 | core/common/src/types/options/mod.rs:1238-1244 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (7 lines × 2) core/configs/src/configs_impl/parsing.rs:77— core/configs/src/configs_impl/parsing.rs:77-83 | core/connectors/sources/influxdb_source/src/common.rs:475-481 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (7 lines × 2) core/connectors/runtime/src/configs/connectors/local_provider.rs:546— core/connectors/runtime/src/configs/connectors/local_provider.rs:546-552 | core/connectors/runtime/src/configs/connectors/local_provider.rs:575-581 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (7 lines × 2) core/connectors/runtime/src/stats.rs:44— core/connectors/runtime/src/stats.rs:44-50 | core/connectors/runtime/src/stats.rs:70-76 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (7 lines × 2) core/connectors/sdk/src/lib.rs:196— core/connectors/sdk/src/lib.rs:196-202 | core/connectors/sdk/src/lib.rs:340-346 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (7 lines × 2) core/connectors/sinks/elasticsearch_sink/src/lib.rs:137— core/connectors/sinks/elasticsearch_sink/src/lib.rs:137-143 | core/connectors/sources/elasticsearch_source/src/lib.rs:327-333 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (7 lines × 2) core/connectors/sources/influxdb_source/src/common.rs:522— core/connectors/sources/influxdb_source/src/common.rs:522-528 | core/connectors/sources/influxdb_source/src/lib.rs:805-811 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (7 lines × 2) core/integration/src/harness/handle/server.rs:789— core/integration/src/harness/handle/server.rs:789-795 | core/integration/src/harness/handle/server.rs:800-806 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (7 lines × 2) core/sdk/src/quic/quic_client.rs:596— core/sdk/src/quic/quic_client.rs:596-602 | core/sdk/src/websocket/websocket_client.rs:547-553 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (7 lines × 2) core/server/src/http/handlers.rs:1103— core/server/src/http/handlers.rs:1103-1109 | core/server/src/http/handlers.rs:1127-1133 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (7 lines × 2) core/shard/src/lib.rs:4485— core/shard/src/lib.rs:4485-4491 | core/shard/src/lib.rs:4530-4536 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (7 lines × 2) gateways/kafka/src/group/state.rs:875— gateways/kafka/src/group/state.rs:875-881 | gateways/kafka/src/group/state.rs:883-889 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (7 lines × 2) core/ai/mcp/src/configs.rs:201— core/ai/mcp/src/configs.rs:201-207 | core/connectors/runtime/src/configs/runtime.rs:128-134 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (7 lines × 2) core/common/src/http/partitions/create_partitions.rs:52— core/common/src/http/partitions/create_partitions.rs:52-58 | core/common/src/http/partitions/delete_partitions.rs:52-58 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (7 lines × 2) core/common/src/http/streams/create_stream.rs:41— core/common/src/http/streams/create_stream.rs:41-47 | core/common/src/http/streams/update_stream.rs:53-59 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (7 lines × 2) core/connectors/sdk/src/encoders/proto.rs:532— core/connectors/sdk/src/encoders/proto.rs:532-538 | core/connectors/sdk/src/transforms/proto_convert.rs:455-461 — before extracting anything, compare `core/connectors/sdk/src/encoders/proto.rs` and `core/connectors/sdk/src/transforms/proto_convert.rs` as WHOLE FILES: this scan already matched 10 separate duplicated blocks between them, totalling at least 137 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (7 lines × 2) core/sdk/src/tcp/tcp_client.rs:799— core/sdk/src/tcp/tcp_client.rs:799-805 | core/sdk/src/websocket/websocket_client.rs:697-703 — `core/sdk/src/tcp/tcp_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 9 separate duplicated blocks between them, totalling at least 158 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (7 lines × 2) core/bench/report/src/types/server_stats.rs:121— core/bench/report/src/types/server_stats.rs:121-127 | core/common/src/types/stats/mod.rs:125-131 — before extracting anything, compare `core/bench/report/src/types/server_stats.rs` and `core/common/src/types/stats/mod.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 31 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (7 lines × 2) core/binary_protocol/src/responses/system/describe_options.rs:136— core/binary_protocol/src/responses/system/describe_options.rs:136-142 | core/binary_protocol/src/responses/topics/get_topics.rs:50-56 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (7 lines × 2) core/metadata/src/impls/metadata.rs:1462— core/metadata/src/impls/metadata.rs:1462-1468 | core/partitions/src/iggy_partitions.rs:782-788 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (7 lines × 2) core/common/src/types/configuration/http_config/http_connection_string_options.rs:41— core/common/src/types/configuration/http_config/http_connection_string_options.rs:41-47 | core/common/src/types/configuration/tcp_config/tcp_connection_string_options.rs:76-82 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (7 lines × 2) core/common/src/types/consumer/consumer_kind.rs:145— core/common/src/types/consumer/consumer_kind.rs:145-151 | core/server/src/http/jwt.rs:441-447 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
MethodTooLong: IggyPartition.apply_checked_install core/partitions/src/state_transfer.rs:2859— MethodTooLong — apply_checked_install runs 377 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 277 over it, 3.77× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: ClusterConfig.validate core/configs/src/server_config/cluster.rs:868— MethodTooLong — validate runs 246 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 146 over it, 2.46× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: IggyErrorCode.name foreign/swift/Sources/Iggy/Errors/IggyErrorCode.swift:271— MethodTooLong — name runs 242 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 142 over it, 2.42× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: ServerConfig.validate core/configs/src/server_config/validators.rs:51— MethodTooLong — validate runs 214 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 114 over it, 2.14× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: IggyShard.on_partition_transfer_progress core/shard/src/lib.rs:9505— MethodTooLong — on_partition_transfer_progress runs 185 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 85 over it, 1.85× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: PartitionPrepareJournal.rewrite core/journal/src/partition_journal.rs:1353— MethodTooLong — rewrite runs 156 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 56 over it, 1.56× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: WebSocketClient.send_raw_with_response core/sdk/src/websocket/websocket_client.rs:162— MethodTooLong — send_raw_with_response runs 155 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 55 over it, 1.55× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: QuicClient.send_raw_with_response core/sdk/src/quic/quic_client.rs:168— MethodTooLong — send_raw_with_response runs 152 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 52 over it, 1.52× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: InfluxDbSource.poll core/connectors/sources/influxdb_source/src/lib.rs:469— MethodTooLong — poll runs 146 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 46 over it, 1.46× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: IggyPartition.install_state_transfer core/partitions/src/state_transfer.rs:2558— MethodTooLong — install_state_transfer runs 140 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 40 over it, 1.40× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: IggyShard.on_partition_request_state_chunk core/shard/src/lib.rs:8546— MethodTooLong — on_partition_request_state_chunk runs 138 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 38 over it, 1.38× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: QuicClient.connect_inner core/sdk/src/quic/quic_client.rs:672— MethodTooLong — connect_inner runs 137 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 37 over it, 1.37× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: InfluxDbSource.open core/connectors/sources/influxdb_source/src/lib.rs:258— MethodTooLong — open runs 135 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 35 over it, 1.35× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: GetStatsCmd.execute_cmd core/cli/src/commands/binary_system/stats.rs:63— MethodTooLong — execute_cmd runs 132 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 32 over it, 1.32× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: IggyShard.on_partition_state_transfer_target core/shard/src/lib.rs:9231— MethodTooLong — on_partition_state_transfer_target runs 132 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 32 over it, 1.32× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: RabbitMQSink.publish_batch_with_retry core/connectors/sinks/rabbitmq_sink/src/lib.rs:193— MethodTooLong — publish_batch_with_retry runs 127 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 27 over it, 1.27× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: Simulator.build_inner core/simulator/src/lib.rs:364— MethodTooLong — build_inner runs 125 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 25 over it, 1.25× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: IggyTcpClient.Connect REDACTED:1043— MethodTooLong — Connect runs 122 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 22 over it, 1.22× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: IggyMetadata.prepare_request core/metadata/src/impls/metadata.rs:3458— MethodTooLong — prepare_request runs 120 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 20 over it, 1.20× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: SendMessages.deserialize core/common/src/http/messages/send_messages.rs:129— MethodTooLong — deserialize runs 118 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 18 over it, 1.18× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: PrepareJournal.scan core/journal/src/prepare_journal.rs:411— MethodTooLong — scan runs 116 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 16 over it, 1.16× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: PartitionPrepareJournal.reset_with_segment_checkpoint core/journal/src/partition_journal/segments.rs:172— MethodTooLong — reset_with_segment_checkpoint runs 114 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 14 over it, 1.14× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: IggyShard.on_partition_request_state_transfer core/shard/src/lib.rs:8354— MethodTooLong — on_partition_request_state_transfer runs 114 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 14 over it, 1.14× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: PartitionRecoveryRefusal.fmt core/partitions/src/segment_recovery.rs:282— MethodTooLong — fmt runs 113 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code — #[cfg(test)] modules and bare #[test] functions — not counted) in one body. The bar is 100 significant lines; this is 13 over it, 1.13× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
MethodTooLong: CommandResponseStream._pollOnPrimary foreign/node/src/client/client.socket.ts:586— MethodTooLong — _pollOnPrimary runs 111 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 11 over it, 1.11× the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body — the runs of statements that work on the same values and would earn the same name — into its own named unit, and have this one call them in order.
Duplicated block (11 lines × 2) core/ai/mcp/src/log.rs:127— core/ai/mcp/src/log.rs:127-137 | core/connectors/runtime/src/log.rs:83-93 — before extracting anything, compare `core/ai/mcp/src/log.rs` and `core/connectors/runtime/src/log.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 87 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 2) core/ai/mcp/src/stream.rs:26— core/ai/mcp/src/stream.rs:26-36 | core/connectors/runtime/src/stream.rs:36-46 — before extracting anything, compare `core/ai/mcp/src/stream.rs` and `core/connectors/runtime/src/stream.rs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 52 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 2) core/common/src/types/configuration/quic_config/quic_connection_string_options.rs:200— core/common/src/types/configuration/quic_config/quic_connection_string_options.rs:200-210 | core/common/src/types/configuration/tcp_config/tcp_connection_string_options.rs:113-123 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (11 lines × 2) core/configs/src/configs_impl/typed_env_provider.rs:393— core/configs/src/configs_impl/typed_env_provider.rs:393-403 | core/integration/src/harness/config/resolve.rs:183-193 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (11 lines × 2) core/connectors/sinks/postgres_sink/src/lib.rs:542— core/connectors/sinks/postgres_sink/src/lib.rs:542-552 | REDACTED:1055-1065 — before extracting anything, compare `core/connectors/sinks/postgres_sink/src/lib.rs` and `REDACTED` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 44 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 2) core/message_bus/src/transports/tcp_tls.rs:258— core/message_bus/src/transports/tcp_tls.rs:258-268 | core/message_bus/src/transports/wss.rs:258-268 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (11 lines × 2) core/sdk/src/quic/quic_client.rs:938— core/sdk/src/quic/quic_client.rs:938-948 | core/sdk/src/websocket/websocket_client.rs:976-986 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (11 lines × 2) core/sdk/src/websocket/websocket_connection_stream.rs:195— core/sdk/src/websocket/websocket_connection_stream.rs:195-205 | core/sdk/src/websocket/websocket_tls_connection_stream.rs:200-210 — before extracting anything, compare `core/sdk/src/websocket/websocket_connection_stream.rs` and `core/sdk/src/websocket/websocket_tls_connection_stream.rs` as WHOLE FILES: this scan already matched 8 separate duplicated blocks between them, totalling at least 102 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 2) core/shard/src/lib.rs:7252— core/shard/src/lib.rs:7252-7262 | core/shard/src/lib.rs:8717-8727 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (11 lines × 2) core/connectors/sdk/src/decoders/avro.rs:215— core/connectors/sdk/src/decoders/avro.rs:215-225 | core/connectors/sdk/src/decoders/flatbuffer.rs:158-168 — before extracting anything, compare `core/connectors/sdk/src/decoders/avro.rs` and `core/connectors/sdk/src/decoders/flatbuffer.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 69 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 2) core/connectors/runtime/src/api/sink.rs:160— core/connectors/runtime/src/api/sink.rs:160-170 | core/connectors/runtime/src/api/source.rs:163-173 — before extracting anything, compare `core/connectors/runtime/src/api/sink.rs` and `core/connectors/runtime/src/api/source.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 63 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 2) core/connectors/runtime/src/api/sink.rs:211— core/connectors/runtime/src/api/sink.rs:211-221 | core/connectors/runtime/src/api/source.rs:214-224 — before extracting anything, compare `core/connectors/runtime/src/api/sink.rs` and `core/connectors/runtime/src/api/source.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 63 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 2) core/partitions/src/iggy_partition.rs:4453— core/partitions/src/iggy_partition.rs:4453-4469 | core/partitions/src/iggy_partition.rs:4491-4501 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (11 lines × 2) core/partitions/src/partition_storage.rs:68— core/partitions/src/partition_storage.rs:68-78 | core/partitions/src/partition_storage.rs:81-95 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (11 lines × 2) core/server_common/src/segment_storage/index_writer.rs:57— core/server_common/src/segment_storage/index_writer.rs:57-67 | core/server_common/src/segment_storage/messages_writer.rs:65-78 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (11 lines × 2) core/integration/src/harness/handle/client_builder.rs:189— core/integration/src/harness/handle/client_builder.rs:189-199 | core/integration/src/harness/handle/client_builder.rs:256-266 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (11 lines × 2) core/connectors/runtime/src/context.rs:95— core/connectors/runtime/src/context.rs:95-105 | core/connectors/runtime/src/context.rs:141-151 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (11 lines × 2) core/sdk/src/websocket/websocket_connection_stream.rs:52— core/sdk/src/websocket/websocket_connection_stream.rs:52-62 | core/sdk/src/websocket/websocket_tls_connection_stream.rs:55-65 — before extracting anything, compare `core/sdk/src/websocket/websocket_connection_stream.rs` and `core/sdk/src/websocket/websocket_tls_connection_stream.rs` as WHOLE FILES: this scan already matched 8 separate duplicated blocks between them, totalling at least 102 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 2) core/connectors/runtime/src/sink.rs:76— core/connectors/runtime/src/sink.rs:76-86 | core/connectors/runtime/src/source.rs:114-124 — before extracting anything, compare `core/connectors/runtime/src/sink.rs` and `core/connectors/runtime/src/source.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 50 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 2) gateways/kafka/src/protocol/bounds_guard.rs:287— gateways/kafka/src/protocol/bounds_guard.rs:287-297 | gateways/kafka/src/protocol/bounds_guard.rs:330-340 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (11 lines × 2) core/sdk/src/websocket/websocket_connection_stream.rs:69— core/sdk/src/websocket/websocket_connection_stream.rs:69-79 | core/sdk/src/websocket/websocket_tls_connection_stream.rs:72-82 — before extracting anything, compare `core/sdk/src/websocket/websocket_connection_stream.rs` and `core/sdk/src/websocket/websocket_tls_connection_stream.rs` as WHOLE FILES: this scan already matched 8 separate duplicated blocks between them, totalling at least 102 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 2) foreign/go/contracts/node_status.go:56— foreign/go/contracts/node_status.go:56-66 | foreign/go/contracts/role.go:45-55 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (11 lines × 2) core/bench/src/analytics/time_series/calculator.rs:50— core/bench/src/analytics/time_series/calculator.rs:50-60 | core/bench/src/analytics/time_series/calculator.rs:86-97 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (11 lines × 2) examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java:286— examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java:286-296 | examples/java/src/main/java/org/apache/iggy/examples/multitenant/producer/MultiTenantProducer.java:329-339 — before extracting anything, compare `examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java` and `examples/java/src/main/java/org/apache/iggy/examples/multitenant/producer/MultiTenantProducer.java` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 57 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any `return` inside it is the body's own exit and keeps its meaning in the moved unit.
Duplicated block (11 lines × 2) examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java:329— examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java:329-339 | examples/java/src/main/java/org/apache/iggy/examples/multitenant/producer/MultiTenantProducer.java:342-352 — before extracting anything, compare `examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java` and `examples/java/src/main/java/org/apache/iggy/examples/multitenant/producer/MultiTenantProducer.java` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 57 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any `return` inside it is the body's own exit and keeps its meaning in the moved unit.
Duplicated block (9 lines × 2) core/ai/mcp/src/log.rs:85— core/ai/mcp/src/log.rs:85-93 | core/ai/mcp/src/log.rs:96-104 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/ai/mcp/src/api.rs:166— core/ai/mcp/src/api.rs:166-176 | core/connectors/runtime/src/api/mod.rs:121-129 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (9 lines × 2) core/binary_protocol/src/framing.rs:106— core/binary_protocol/src/framing.rs:106-114 | core/binary_protocol/src/framing.rs:182-190 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/binary_protocol/src/requests/users/create_user.rs:68— core/binary_protocol/src/requests/users/create_user.rs:68-76 | core/binary_protocol/src/requests/users/update_permissions.rs:47-55 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (9 lines × 2) core/cli/src/args/permissions/global.rs:113— core/cli/src/args/permissions/global.rs:113-121 | core/cli/src/args/permissions/topic.rs:106-114 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (9 lines × 2) core/connectors/runtime/src/manager/sink.rs:45— core/connectors/runtime/src/manager/sink.rs:45-53 | core/connectors/runtime/src/manager/source.rs:45-53 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (9 lines × 2) core/connectors/runtime/src/manager/sink.rs:121— core/connectors/runtime/src/manager/sink.rs:121-129 | core/connectors/runtime/src/manager/sink.rs:248-256 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/connectors/runtime/src/manager/source.rs:131— core/connectors/runtime/src/manager/source.rs:131-139 | core/connectors/runtime/src/manager/source.rs:313-321 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/connectors/sources/http_source/src/management.rs:330— core/connectors/sources/http_source/src/management.rs:330-338 | core/connectors/sources/http_source/src/management.rs:376-387 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/integration/src/harness/handle/common.rs:34— core/integration/src/harness/handle/common.rs:34-42 | core/integration/src/harness/handle/server.rs:652-660 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (9 lines × 2) core/server_common/src/send_messages.rs:322— core/server_common/src/send_messages.rs:322-330 | core/server_common/src/send_messages.rs:385-393 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/shard/src/lib.rs:3302— core/shard/src/lib.rs:3302-3310 | core/shard/src/lib.rs:3337-3345 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/simulator/src/workload/state_checker.rs:109— core/simulator/src/workload/state_checker.rs:109-117 | core/simulator/src/workload/state_checker.rs:288-296 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) foreign/cpp/src/type_conversion.rs:677— foreign/cpp/src/type_conversion.rs:677-685 | foreign/cpp/src/type_conversion.rs:695-703 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) foreign/python/src/permissions.rs:67— foreign/python/src/permissions.rs:67-77 | foreign/python/src/permissions.rs:315-323 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) foreign/python/src/producer.rs:549— foreign/python/src/producer.rs:549-557 | foreign/python/src/producer.rs:588-596 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) gateways/kafka/src/protocol/bounds_guard.rs:845— gateways/kafka/src/protocol/bounds_guard.rs:845-853 | gateways/kafka/src/protocol/bounds_guard.rs:993-1001 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/connectors/sdk/src/decoders/avro.rs:76— core/connectors/sdk/src/decoders/avro.rs:76-84 | core/connectors/sdk/src/encoders/avro.rs:66-74 — `core/connectors/sdk/src/decoders/avro.rs` and `core/connectors/sdk/src/encoders/avro.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 6 separate duplicated blocks between them, totalling at least 110 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (9 lines × 2) core/integration/src/harness/handle/client.rs:131— core/integration/src/harness/handle/client.rs:131-139 | core/integration/src/harness/handle/client.rs:156-164 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/connectors/runtime/src/sink.rs:67— core/connectors/runtime/src/sink.rs:67-75 | core/connectors/runtime/src/source.rs:105-113 — before extracting anything, compare `core/connectors/runtime/src/sink.rs` and `core/connectors/runtime/src/source.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 50 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (9 lines × 2) core/connectors/runtime/src/configs/connectors/local_provider.rs:415— core/connectors/runtime/src/configs/connectors/local_provider.rs:415-423 | core/connectors/runtime/src/configs/connectors/local_provider.rs:450-458 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/metadata/src/impls/metadata.rs:2730— core/metadata/src/impls/metadata.rs:2730-2738 | core/metadata/src/impls/metadata.rs:2836-2844 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/bench/dashboard/frontend/src/components/layout/sidebar.rs:133— core/bench/dashboard/frontend/src/components/layout/sidebar.rs:133-141 | core/bench/dashboard/frontend/src/components/layout/sidebar.rs:143-151 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/bench/dashboard/frontend/src/components/selectors/param_filters_panel.rs:93— core/bench/dashboard/frontend/src/components/selectors/param_filters_panel.rs:93-101 | core/bench/dashboard/frontend/src/components/selectors/param_filters_panel.rs:148-156 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (9 lines × 2) core/bench/dashboard/frontend/src/components/layout/hero.rs:449— core/bench/dashboard/frontend/src/components/layout/hero.rs:449-457 | core/bench/dashboard/frontend/src/format.rs:55-63 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
IggyPartition::commit_messages_inner (cognitive 65) core/partitions/src/iggy_partition.rs:5830— IggyPartition::commit_messages_inner has cognitive complexity 65 (threshold 15). Drivers by points: if/else 28 (55 pts), boolean chains 7, loops 2 (3 pts) (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::on_replicate (cognitive 62) core/partitions/src/iggy_partition.rs:4848— IggyPartition::on_replicate has cognitive complexity 62 (threshold 15). Drivers by points: if/else 33 (53 pts), boolean chains 7, match/switch 2 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::apply_checked_install (cognitive 43) core/partitions/src/state_transfer.rs:2859— IggyPartition::apply_checked_install has cognitive complexity 43 (threshold 15). Drivers by points: if/else 17 (24 pts), loops 8 (9 pts), match/switch 4 (9 pts), boolean chains 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::drain_request_queue_into_prepares (cognitive 41) core/partitions/src/iggy_partition.rs:4649— IggyPartition::drain_request_queue_into_prepares has cognitive complexity 41 (threshold 15). Drivers by points: if/else 13 (37 pts), match/switch 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::on_request (cognitive 40) core/partitions/src/iggy_partition.rs:4249— IggyPartition::on_request has cognitive complexity 40 (threshold 15). Drivers by points: if/else 17 (25 pts), match/switch 5 (8 pts), boolean chains 7 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::install_state_transfer (cognitive 39) core/partitions/src/state_transfer.rs:2558— IggyPartition::install_state_transfer has cognitive complexity 39 (threshold 15). Drivers by points: if/else 20 (26 pts), boolean chains 12, loops 1 (nesting depth added 6). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
IggyPartition::handle_committed_entries (cognitive 37) core/partitions/src/iggy_partition.rs:6173— IggyPartition::handle_committed_entries has cognitive complexity 37 (threshold 15). Drivers by points: if/else 17 (29 pts), loops 3, match/switch 1 (3 pts), boolean chains 2 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::persist_consumer_offset_commit (cognitive 35) core/partitions/src/iggy_partition.rs:2804— IggyPartition::persist_consumer_offset_commit has cognitive complexity 35 (threshold 15). Drivers by points: if/else 10 (23 pts), boolean chains 6, match/switch 3 (6 pts) (nesting depth added 16). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
IggyPartition::converge_to_empty_after_failed_install (cognitive 29) core/partitions/src/state_transfer.rs:3502— IggyPartition::converge_to_empty_after_failed_install has cognitive complexity 29 (threshold 15). Drivers by points: match/switch 5 (14 pts), if/else 3 (7 pts), loops 5 (7 pts), boolean chains 1 (nesting depth added 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
IggyPartition::open_persistence_with_recovered (cognitive 27) core/partitions/src/iggy_partition.rs:811— IggyPartition::open_persistence_with_recovered has cognitive complexity 27 (threshold 15). Drivers by points: if/else 15 (20 pts), loops 4 (5 pts), boolean chains 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::build_poll_plan (cognitive 25) core/partitions/src/iggy_partition.rs:3823— IggyPartition::build_poll_plan has cognitive complexity 25 (threshold 15). Drivers by points: if/else 7 (14 pts), match/switch 5 (9 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::resynchronize_consumer_offset_reservations_inner (cognitive 24) core/partitions/src/iggy_partition.rs:3643— IggyPartition::resynchronize_consumer_offset_reservations_inner has cognitive complexity 24 (threshold 15). Drivers by points: if/else 8 (12 pts), boolean chains 9, match/switch 1 (2 pts), loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::reuse_staged_segments (cognitive 23) core/partitions/src/state_transfer.rs:2462— IggyPartition::reuse_staged_segments has cognitive complexity 23 (threshold 15). Drivers by points: if/else 9 (16 pts), loops 2 (3 pts), boolean chains 2, match/switch 1 (2 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::remove_sealed_segments_up_to (cognitive 21) core/partitions/src/iggy_partition.rs:7251— IggyPartition::remove_sealed_segments_up_to has cognitive complexity 21 (threshold 15). Drivers by points: if/else 5 (9 pts), match/switch 2 (5 pts), loops 3 (4 pts), boolean chains 3 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::purge (cognitive 21) core/partitions/src/iggy_partition.rs:7746— IggyPartition::purge has cognitive complexity 21 (threshold 15). Drivers by points: if/else 8 (13 pts), loops 2 (3 pts), match/switch 1 (3 pts), boolean chains 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::apply_repaired_prepare (cognitive 21) core/partitions/src/iggy_partition.rs:8152— IggyPartition::apply_repaired_prepare has cognitive complexity 21 (threshold 15). Drivers by points: if/else 12 (14 pts), boolean chains 5, match/switch 1 (2 pts) (nesting depth added 3). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
IggyPartition::complete_repair (cognitive 20) core/partitions/src/iggy_partition.rs:8253— IggyPartition::complete_repair has cognitive complexity 20 (threshold 15). Drivers by points: if/else 10 (14 pts), boolean chains 4, match/switch 1 (2 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::state_transfer_offer (cognitive 20) core/partitions/src/state_transfer.rs:1902— IggyPartition::state_transfer_offer has cognitive complexity 20 (threshold 15). Drivers by points: if/else 11 (14 pts), boolean chains 4, loops 2 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
IggyPartition::commit_partition_entry (cognitive 19) core/partitions/src/iggy_partition.rs:6574— IggyPartition::commit_partition_entry has cognitive complexity 19 (threshold 15). Drivers by points: if/else 7 (17 pts), boolean chains 1, match/switch 1 (nesting depth added 10). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
IggyPartition::persistence_checkpoint_files (cognitive 16) core/partitions/src/iggy_partition.rs:1056— IggyPartition::persistence_checkpoint_files has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (9 pts), loops 4 (5 pts), boolean chains 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::persist_repaired_prefix_through (cognitive 16) core/partitions/src/iggy_partition.rs:1283— IggyPartition::persist_repaired_prefix_through has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (14 pts), boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPartition::reanchor_to_offset_frontier (cognitive 16) core/partitions/src/iggy_partition.rs:7488— IggyPartition::reanchor_to_offset_frontier has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (6 pts), match/switch 2 (4 pts), boolean chains 3, loops 2 (3 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Duplicated block (10 lines × 2) foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Rented.cs:125— foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Rented.cs:125-134 | foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.cs:422-431 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Rented.cs:125` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (10 lines × 2) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:104— foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:104-113 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:115-124 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/connectors/runtime/src/api/models.rs:63— core/connectors/runtime/src/api/models.rs:63-72 | core/connectors/runtime/src/api/models.rs:78-87 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/connectors/runtime/src/configs/connectors/http_provider.rs:400— core/connectors/runtime/src/configs/connectors/http_provider.rs:400-409 | core/connectors/runtime/src/configs/connectors/http_provider.rs:432-441 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/connectors/runtime/src/configs/connectors/local_provider.rs:485— core/connectors/runtime/src/configs/connectors/local_provider.rs:485-494 | core/connectors/runtime/src/configs/connectors/local_provider.rs:507-516 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/connectors/sinks/surrealdb_sink/src/lib.rs:433— core/connectors/sinks/surrealdb_sink/src/lib.rs:433-442 | core/connectors/sinks/surrealdb_sink/src/lib.rs:489-498 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/journal/src/prepare_journal.rs:857— core/journal/src/prepare_journal.rs:857-866 | core/journal/src/prepare_journal.rs:1049-1058 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/message_bus/src/lifecycle/connection_registry.rs:888— core/message_bus/src/lifecycle/connection_registry.rs:888-897 | core/message_bus/src/lifecycle/connection_registry.rs:915-924 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/partitions/src/partition_storage.rs:632— core/partitions/src/partition_storage.rs:632-641 | core/partitions/src/partition_storage.rs:671-680 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/common/src/http/personal_access_tokens/create_personal_access_token.rs:46— core/common/src/http/personal_access_tokens/create_personal_access_token.rs:46-55 | core/common/src/http/personal_access_tokens/delete_personal_access_token.rs:41-50 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (10 lines × 2) core/connectors/runtime/src/api/sink.rs:60— core/connectors/runtime/src/api/sink.rs:60-69 | core/connectors/runtime/src/api/source.rs:63-72 — before extracting anything, compare `core/connectors/runtime/src/api/sink.rs` and `core/connectors/runtime/src/api/source.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 63 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (10 lines × 2) core/simulator/src/workload/ops/create_partitions.rs:108— core/simulator/src/workload/ops/create_partitions.rs:108-117 | core/simulator/src/workload/ops/delete_partitions.rs:133-142 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (10 lines × 2) core/simulator/src/workload/ops/delete_user.rs:44— core/simulator/src/workload/ops/delete_user.rs:44-53 | core/simulator/src/workload/ops/update_permissions.rs:44-53 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (10 lines × 2) core/integration/src/harness/orchestrator/builder.rs:354— core/integration/src/harness/orchestrator/builder.rs:354-363 | core/integration/src/harness/orchestrator/builder.rs:366-375 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/connectors/runtime/src/sink.rs:489— core/connectors/runtime/src/sink.rs:489-498 | core/connectors/runtime/src/source.rs:439-448 — before extracting anything, compare `core/connectors/runtime/src/sink.rs` and `core/connectors/runtime/src/source.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 50 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (10 lines × 2) core/connectors/sources/postgres_source/src/lib.rs:1131— core/connectors/sources/postgres_source/src/lib.rs:1131-1140 | core/connectors/sources/postgres_source/src/lib.rs:1151-1160 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/message_bus/src/transports/tls/mod.rs:111— core/message_bus/src/transports/tls/mod.rs:111-120 | core/message_bus/src/transports/tls/mod.rs:130-139 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) core/server/src/boot/credentials.rs:344— core/server/src/boot/credentials.rs:344-353 | core/server/src/boot/credentials.rs:360-369 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10 lines × 2) examples/csharp/src/Basic/Iggy_SDK.Examples.Basic.Consumer/Settings.cs:22— examples/csharp/src/Basic/Iggy_SDK.Examples.Basic.Consumer/Settings.cs:22-31 | examples/csharp/src/Basic/Iggy_SDK.Examples.Basic.Producer/Settings.cs:22-31 — `examples/csharp/src/Basic/Iggy_SDK.Examples.Basic.Consumer/Settings.cs` and `examples/csharp/src/Basic/Iggy_SDK.Examples.Basic.Producer/Settings.cs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 1 separate duplicated blocks between them, totalling at least 10 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at `examples/csharp/src/Basic/Iggy_SDK.Examples.Basic.Consumer/Settings.cs:22` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (10 lines × 2) core/bench/dashboard/frontend/src/components/tooltips/benchmark_info_toggle.rs:28— core/bench/dashboard/frontend/src/components/tooltips/benchmark_info_toggle.rs:28-37 | core/bench/dashboard/frontend/src/components/tooltips/server_stats_toggle.rs:28-37 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (10 lines × 2) foreign/java/bench/src/main/java/org/apache/iggy/bench/report/FinalReportBuilder.java:219— foreign/java/bench/src/main/java/org/apache/iggy/bench/report/FinalReportBuilder.java:219-228 | foreign/java/bench/src/main/java/org/apache/iggy/bench/report/FinalReportBuilder.java:231-240 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any `return` inside it is the body's own exit and keeps its meaning in the moved unit.
Duplicated block (10 lines × 2) examples/python/high-level/background_producer.py:82— examples/python/high-level/background_producer.py:82-94 | examples/python/high-level/producer.py:82-91 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at `examples/python/high-level/background_producer.py:82` it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names — the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately.
Duplicated block (13 lines × 2) foreign/csharp/Iggy_SDK/Mappers/BinaryMapper.cs:155— foreign/csharp/Iggy_SDK/Mappers/BinaryMapper.cs:155-167 | foreign/csharp/Iggy_SDK/Mappers/BinaryMapper.cs:170-182 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/csharp/Iggy_SDK/Mappers/BinaryMapper.cs:155` it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (13 lines × 2) core/binary_protocol/src/requests/topics/create_topic.rs:66— core/binary_protocol/src/requests/topics/create_topic.rs:66-78 | core/binary_protocol/src/requests/topics/update_topic.rs:64-76 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (13 lines × 2) core/binary_protocol/src/requests/users/login_register.rs:82— core/binary_protocol/src/requests/users/login_register.rs:82-94 | core/binary_protocol/src/requests/users/login_register_with_pat.rs:61-73 — before extracting anything, compare `core/binary_protocol/src/requests/users/login_register.rs` and `core/binary_protocol/src/requests/users/login_register_with_pat.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 33 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (13 lines × 2) core/connectors/runtime/src/configs/connectors/http_provider.rs:233— core/connectors/runtime/src/configs/connectors/http_provider.rs:233-245 | core/connectors/runtime/src/configs/connectors/http_provider.rs:254-266 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (13 lines × 2) core/connectors/runtime/src/configs/connectors.rs:162— core/connectors/runtime/src/configs/connectors.rs:162-174 | core/connectors/runtime/src/configs/connectors.rs:215-227 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (13 lines × 2) core/connectors/runtime/src/main.rs:273— core/connectors/runtime/src/main.rs:273-285 | core/connectors/runtime/src/main.rs:290-302 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (13 lines × 2) core/connectors/sdk/src/decoders/proto.rs:175— core/connectors/sdk/src/decoders/proto.rs:175-187 | core/connectors/sdk/src/transforms/proto_convert.rs:201-213 — before extracting anything, compare `core/connectors/sdk/src/decoders/proto.rs` and `core/connectors/sdk/src/transforms/proto_convert.rs` as WHOLE FILES: this scan already matched 10 separate duplicated blocks between them, totalling at least 143 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (13 lines × 2) core/connectors/sinks/postgres_sink/src/lib.rs:527— core/connectors/sinks/postgres_sink/src/lib.rs:527-539 | REDACTED:1040-1052 — before extracting anything, compare `core/connectors/sinks/postgres_sink/src/lib.rs` and `REDACTED` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 44 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (13 lines × 2) core/integration/src/harness/handle/connectors_runtime.rs:167— core/integration/src/harness/handle/connectors_runtime.rs:167-179 | core/integration/src/harness/handle/mcp.rs:167-179 — before extracting anything, compare `core/integration/src/harness/handle/connectors_runtime.rs` and `core/integration/src/harness/handle/mcp.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 39 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (13 lines × 2) core/integration/src/harness/handle/server.rs:698— core/integration/src/harness/handle/server.rs:698-710 | core/integration/src/harness/handle/server.rs:869-881 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (13 lines × 2) core/sdk/src/clients/consumer.rs:1544— core/sdk/src/clients/consumer.rs:1544-1556 | core/sdk/src/clients/consumer.rs:1666-1678 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (13 lines × 2) core/sdk/src/tcp/tcp_client.rs:1318— core/sdk/src/tcp/tcp_client.rs:1318-1330 | core/sdk/src/websocket/websocket_client.rs:1078-1090 — `core/sdk/src/tcp/tcp_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 9 separate duplicated blocks between them, totalling at least 158 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (13 lines × 2) foreign/php/src/receive_message.rs:39— foreign/php/src/receive_message.rs:39-51 | foreign/php/src/send_message.rs:39-51 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (13 lines × 2) core/ai/mcp/src/configs.rs:375— core/ai/mcp/src/configs.rs:375-387 | core/connectors/runtime/src/api/config.rs:250-262 — before extracting anything, compare `core/ai/mcp/src/configs.rs` and `core/connectors/runtime/src/api/config.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 56 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (13 lines × 2) core/message_bus/src/transports/ws.rs:263— core/message_bus/src/transports/ws.rs:263-275 | core/message_bus/src/transports/wss.rs:414-427 — before extracting anything, compare `core/message_bus/src/transports/ws.rs` and `core/message_bus/src/transports/wss.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 81 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (13 lines × 2) core/connectors/sources/influxdb_source/src/v2.rs:584— core/connectors/sources/influxdb_source/src/v2.rs:584-596 | core/connectors/sources/influxdb_source/src/v3.rs:93-105 — before extracting anything, compare `core/connectors/sources/influxdb_source/src/v2.rs` and `core/connectors/sources/influxdb_source/src/v3.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 37 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (13 lines × 2) core/journal/src/prepare_journal.rs:484— core/journal/src/prepare_journal.rs:484-496 | core/journal/src/prepare_journal.rs:552-564 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (13 lines × 2) core/connectors/sinks/http_sink/src/lib.rs:805— core/connectors/sinks/http_sink/src/lib.rs:805-817 | core/connectors/sinks/http_sink/src/lib.rs:898-910 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (13 lines × 2) core/connectors/runtime/src/state/http.rs:310— core/connectors/runtime/src/state/http.rs:310-322 | core/connectors/runtime/src/state/http.rs:354-366 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (13 lines × 2) foreign/java/external-processors/iggy-connector-pinot/src/main/java/org/apache/iggy/connector/pinot/consumer/IggyPartitionGroupConsumer.java:125— foreign/java/external-processors/iggy-connector-pinot/src/main/java/org/apache/iggy/connector/pinot/consumer/IggyPartitionGroupConsumer.java:125-137 | foreign/java/external-processors/iggy-connector-pinot/src/main/java/org/apache/iggy/connector/pinot/metadata/IggyStreamMetadataProvider.java:155-167 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/java/external-processors/iggy-connector-pinot/src/main/java/org/apache/iggy/connector/pinot/consumer/IggyPartitionGroupConsumer.java:125` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. ★ These copies have DRIFTED, and that is worth reading before extracting anything: just after the matched lines, `foreign/java/external-processors/iggy-connector-pinot/src/main/java/org/apache/iggy/connector/pinot/consumer/IggyPartitionGroupConsumer.java:139` calls `of`, `valueOf` and `foreign/java/external-processors/iggy-connector-pinot/src/main/java/org/apache/iggy/connector/pinot/metadata/IggyStreamMetadataProvider.java:169` does not — after which the two agree again for 3 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live.
Duplicated block (13 lines × 2) core/bench/dashboard/frontend/src/components/layout/sidebar.rs:236— core/bench/dashboard/frontend/src/components/layout/sidebar.rs:236-248 | core/bench/dashboard/frontend/src/components/layout/sidebar.rs:257-269 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Repeated repair: core/shard/src/metrics.rs core/shard/src/metrics.rs:893— core/shard/src/metrics.rs changed 18 times in last 90 days and 11 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 2 (its worst body is FrameDropMetrics::record at line 893), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(cluster): preserve group membership and reduce produce/poll overhead (#4169)”; “fix(partitions): complete polls on the owning shard (#4119)”; “fix(shard): refuse a frame no consensus plane claims (#4103)”; “fix(partitions): bound consumer offset state per partition (#4063)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/shard/src/metrics.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/consensus/src/plane_helpers.rs core/consensus/src/plane_helpers.rs:345— core/consensus/src/plane_helpers.rs changed 19 times in last 90 days and 10 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 6 (its worst body is consensus::plane_helpers::replicate_preflight at line 345), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(consensus): count an unservable header as a nack (#4109)”; “fix(consensus): keep a replica off a hole in its committed prefix (#4073)”; “fix(cluster): prevent repaired prepares from rewinding WAL parent (#3978)”; “refactor(consensus): single restore constructor + wedge/replay/ack fixes (#3909)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/consensus/src/plane_helpers.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/server/src/boot/recovery.rs core/server/src/boot/recovery.rs:69— core/server/src/boot/recovery.rs changed 12 times in last 90 days and 7 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 11 (its worst body is server::boot::recovery::build_shard_for_thread at line 69), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(server): recover stalled consumer groups after restarts (#4283)”; “fix(partitions): complete polls on the owning shard (#4119)”; “fix(metadata): roll deleted partitions and topics out of parent stats (#4046)”; “fix(partitions): bound consumer offset state per partition (#4063)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/server/src/boot/recovery.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/common/src/error/iggy_error.rs core/common/src/error/iggy_error.rs:572— core/common/src/error/iggy_error.rs changed 9 times in last 90 days and 6 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 1 (its worst body is IggyError::as_code at line 572), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(partitions): bound consumer offset state per partition (#4063)”; “fix(server): truncate torn segment tails instead of resurrecting them (#3946)”; “fix(metadata): enforce namespace caps at admission to stop aliasing (#3907)”; “fix(sdk): forward unknown command codes instead of rejecting them (#3766)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/common/src/error/iggy_error.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/common/src/traits/binary_impls/messages.rs core/common/src/traits/binary_impls/messages.rs:169— core/common/src/traits/binary_impls/messages.rs changed 9 times in last 90 days and 5 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 9 (its worst body is iggy_common::traits::binary_impls::messages::poll_group_messages at line 169), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(cluster): preserve group membership and reduce produce/poll overhead (#4169)”; “fix(sdk): preserve consumer progress and client error handling (#4151)”; “fix(server): preserve write responses and validate CLI input (#4150)”; “fix(sdk): correct consumer group polling and commits in IggyConsumer (#4034)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/common/src/traits/binary_impls/messages.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/binary_protocol/src/consensus/operation.rs core/binary_protocol/src/consensus/operation.rs:225— core/binary_protocol/src/consensus/operation.rs changed 7 times in last 90 days and 4 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 3 (its worst body is Operation::to_command_code at line 225), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(server): preserve write responses and validate CLI input (#4150)”; “fix(shard): refuse a frame no consensus plane claims (#4103)”; “fix(shard): tell an unknown consensus operation from a corrupt header (#3931)”; “fix(integration): pass remaining tests for server-ng (#3585)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/binary_protocol/src/consensus/operation.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/server/src/shell.rs core/server/src/shell.rs:86— core/server/src/shell.rs changed 6 times in last 90 days and 4 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 1 (its worst body is server::shell::duration_to_ticks at line 86), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(server): recover stalled consumer groups after restarts (#4283)”; “fix(partitions): complete polls on the owning shard (#4119)”; “fix(shard): drive metadata repair and the commit walk from the tick (#4008)”; “fix(shard): drive partition repair and the commit walk from the tick (#4006)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/server/src/shell.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/sdk/src/leader_aware.rs core/sdk/src/leader_aware.rs:71— core/sdk/src/leader_aware.rs changed 6 times in last 90 days and 4 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 7 (its worst body is iggy::leader_aware::check_and_redirect_to_leader at line 71), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(cluster): preserve group membership and reduce produce/poll overhead (#4169)”; “fix(partitions): bound consumer offset state per partition (#4063)”; “fix(cluster): recover writes after a fast partition primary rejoin (#3987)”; “fix(server-ng): fix restart/reconnect hardening and cg integration tests (#3625)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/sdk/src/leader_aware.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/connectors/sinks/quickwit_sink/src/lib.rs core/connectors/sinks/quickwit_sink/src/lib.rs:212— core/connectors/sinks/quickwit_sink/src/lib.rs changed 5 times in last 90 days and 4 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 8 (its worst body is QuickwitSink::ingest at line 212), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(connectors): tag sink batches with the payload's schema (#4204)”; “fix(connectors): defer source checkpoints and surface sink failures (#4153)”; “fix(connectors): validate sink writes and startup readiness (#4154)”; “fix(connectors): bring quickwit_sink up to convention (#3523)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/connectors/sinks/quickwit_sink/src/lib.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/connectors/sinks/elasticsearch_sink/src/lib.rs core/connectors/sinks/elasticsearch_sink/src/lib.rs:205— core/connectors/sinks/elasticsearch_sink/src/lib.rs changed 4 times in last 90 days and 4 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 14 (its worst body is ElasticsearchSink::bulk_index_documents at line 205), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(connectors): tag sink batches with the payload's schema (#4204)”; “fix(connectors): defer source checkpoints and surface sink failures (#4153)”; “fix(connectors): validate sink writes and startup readiness (#4154)”; “fix(connectors): Harden Elasticsearch sink test readiness (#3729)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/connectors/sinks/elasticsearch_sink/src/lib.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/sdk/src/clients/client.rs core/sdk/src/clients/client.rs:870— core/sdk/src/clients/client.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 5 (its worst body is IggyClient::send_binary_request at line 870), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(sdk): preserve consumer progress and client error handling (#4151)”; “fix(rust): add heartbeat handle and drop for rust sdk (#3852)”; “fix(sdk): forward unknown command codes instead of rejecting them (#3766)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/sdk/src/clients/client.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/server/src/dispatch/submit.rs core/server/src/dispatch/submit.rs:54— core/server/src/dispatch/submit.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 11 (its worst body is server::dispatch::submit::handle_metadata_submit at line 54), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(server): recover stalled consumer groups after restarts (#4283)”; “fix(cluster): preserve group membership and reduce produce/poll overhead (#4169)”; “fix(cluster): serve metadata reads at or above the client's own writes (#4024)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/server/src/dispatch/submit.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/partitions/src/persistence.rs core/partitions/src/persistence.rs:1152— core/partitions/src/persistence.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 13 (its worst body is PartitionPersistence::run_inner at line 1152), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(partitions): sync checkpoints through original writers (#4253)”; “fix(partitions): account for segment-backed append batches (#4202)”; “fix(cluster): preserve group membership and reduce produce/poll overhead (#4169)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/partitions/src/persistence.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/message_bus/src/client_listener/mod.rs core/message_bus/src/client_listener/mod.rs:115— core/message_bus/src/client_listener/mod.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 1 (its worst body is message_bus::client_listener::bind_nodelay_listener at line 115), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(server): distribute TCP-TLS and WSS connections across shards (#4193)”; “fix(io_uring): keep shard startup off blocking fallbacks”; “fix(integration): pass remaining tests for server-ng (#3585)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/message_bus/src/client_listener/mod.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/connectors/runtime/src/manager/source.rs core/connectors/runtime/src/manager/source.rs:375— core/connectors/runtime/src/manager/source.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 7 (its worst body is SourceDetails::apply_status at line 375), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(connectors): defer postgres source progress until ack (#3957)”; “fix(connectors): report failures and correct format conversion (#4152)”; “fix(connectors): close the source instance a failed start leaves behind (#4064)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/connectors/runtime/src/manager/source.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/server/src/http/error.rs core/server/src/http/error.rs:117— core/server/src/http/error.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 10 (its worst body is ErrorResponse::from_error at line 117), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(partitions): complete polls on the owning shard (#4119)”; “fix(cluster): serve metadata reads at or above the client's own writes (#4024)”; “fix(server)!: reject a wildcard bind with no advertised address (#3923)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/server/src/http/error.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/sdk/src/clients/producer_dispatcher.rs core/sdk/src/clients/producer_dispatcher.rs:449— core/sdk/src/clients/producer_dispatcher.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 10 (its worst body is ProducerDispatcher::dispatch at line 449), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(sdk): respect max_buffer_size when merging batches (#3933)”; “fix(sdk): error callback should await shard flush on producer shutdown (#3953)”; “fix(rust,sdk): stop late offset stores from hitting a left group (#3668)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/sdk/src/clients/producer_dispatcher.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/connectors/runtime/src/metrics.rs core/connectors/runtime/src/metrics.rs:74— core/connectors/runtime/src/metrics.rs changed 3 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 6 (its worst body is Stage::as_label at line 74), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(connectors): tag sink batches with the payload's schema (#4204)”; “fix(connectors): close the source instance a failed start leaves behind (#4064)”; “fix(connectors): stop rendering counter metrics with a doubled _total (#3921)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/connectors/runtime/src/metrics.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/integration/src/harness/handle/connectors_runtime.rs core/integration/src/harness/handle/connectors_runtime.rs:210— core/integration/src/harness/handle/connectors_runtime.rs changed 3 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 7 (its worst body is ConnectorsRuntimeHandle::stop at line 210), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(connectors): defer postgres source progress until ack (#3957)”; “fix(connectors): Harden Elasticsearch sink test readiness (#3729)”; “fix(sdk): rejoin consumer group after membership loss under vsr (#3703)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/integration/src/harness/handle/connectors_runtime.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Repeated repair: core/common/src/consumer_group_client_state.rs core/common/src/consumer_group_client_state.rs:72— core/common/src/consumer_group_client_state.rs changed 3 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file's churn. Its max cyclomatic complexity is 2 (its worst body is ConsumerGroupClientState::set_assignment at line 72), UNDER the 15 threshold, so this is deliberately not filed as a churn × complexity hotspot — the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: “fix(sdk): preserve consumer progress and client error handling (#4151)”; “fix(sdk): correct consumer group polling and commits in IggyConsumer (#4034)”; “fix(sdk): rejoin consumer group after membership loss under vsr (#3703)”. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with `git log --since='2026-07-01 21:36:42 +02:00' --until='2026-09-29 21:36:42 +02:00' --full-history --no-merges -- core/common/src/consumer_group_client_state.rs`: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each — a difference of several commits on a file whose history was re-landed or reverted inside the window.
Duplicated block (12 lines × 2) core/binary_protocol/src/primitives/user_headers.rs:168— core/binary_protocol/src/primitives/user_headers.rs:168-179 | core/binary_protocol/src/primitives/user_headers.rs:182-193 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (12 lines × 2) core/binary_protocol/src/responses/streams/stream_response.rs:74— core/binary_protocol/src/responses/streams/stream_response.rs:74-85 | core/binary_protocol/src/responses/users/user_response.rs:68-79 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (12 lines × 2) core/common/src/wire_conversions.rs:609— core/common/src/wire_conversions.rs:609-620 | foreign/cpp/src/type_conversion.rs:321-332 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (12 lines × 2) core/connectors/sinks/influxdb_sink/src/protocol.rs:49— core/connectors/sinks/influxdb_sink/src/protocol.rs:49-60 | core/connectors/sinks/influxdb_sink/src/protocol.rs:86-97 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (12 lines × 2) core/connectors/sinks/postgres_sink/src/lib.rs:171— core/connectors/sinks/postgres_sink/src/lib.rs:171-182 | core/connectors/sources/postgres_source/src/lib.rs:486-497 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (12 lines × 2) core/partitions/src/iggy_partition.rs:7417— core/partitions/src/iggy_partition.rs:7417-7428 | core/partitions/src/partition_storage.rs:348-359 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (12 lines × 2) core/sdk/src/quic/quic_client.rs:464— core/sdk/src/quic/quic_client.rs:464-475 | core/sdk/src/websocket/websocket_client.rs:460-471 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (12 lines × 2) core/sdk/src/websocket/websocket_connection_stream.rs:171— core/sdk/src/websocket/websocket_connection_stream.rs:171-182 | core/sdk/src/websocket/websocket_tls_connection_stream.rs:176-187 — before extracting anything, compare `core/sdk/src/websocket/websocket_connection_stream.rs` and `core/sdk/src/websocket/websocket_tls_connection_stream.rs` as WHOLE FILES: this scan already matched 8 separate duplicated blocks between them, totalling at least 102 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (12 lines × 2) core/server/src/dispatch/session_ops.rs:898— core/server/src/dispatch/session_ops.rs:898-909 | core/server/src/dispatch/session_ops.rs:924-935 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (12 lines × 2) foreign/python/src/config.rs:324— foreign/python/src/config.rs:324-335 | foreign/python/src/config.rs:1340-1351 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (12 lines × 2) core/sdk/src/websocket/websocket_connection_stream.rs:82— core/sdk/src/websocket/websocket_connection_stream.rs:82-94 | core/sdk/src/websocket/websocket_tls_connection_stream.rs:85-96 — before extracting anything, compare `core/sdk/src/websocket/websocket_connection_stream.rs` and `core/sdk/src/websocket/websocket_tls_connection_stream.rs` as WHOLE FILES: this scan already matched 8 separate duplicated blocks between them, totalling at least 102 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (12 lines × 2) core/sdk/src/websocket/websocket_connection_stream.rs:158— core/sdk/src/websocket/websocket_connection_stream.rs:158-169 | core/sdk/src/websocket/websocket_tls_connection_stream.rs:163-174 — before extracting anything, compare `core/sdk/src/websocket/websocket_connection_stream.rs` and `core/sdk/src/websocket/websocket_tls_connection_stream.rs` as WHOLE FILES: this scan already matched 8 separate duplicated blocks between them, totalling at least 102 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (12 lines × 2) core/simulator/src/workload/ops/create_consumer_group.rs:59— core/simulator/src/workload/ops/create_consumer_group.rs:59-70 | core/simulator/src/workload/ops/update_topic.rs:54-65 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (12 lines × 2) core/message_bus/src/client_listener/tcp_tls.rs:112— core/message_bus/src/client_listener/tcp_tls.rs:112-123 | core/message_bus/src/client_listener/wss.rs:106-117 — before extracting anything, compare `core/message_bus/src/client_listener/tcp_tls.rs` and `core/message_bus/src/client_listener/wss.rs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 44 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (12 lines × 2) core/server/src/dispatch/session_ops.rs:511— core/server/src/dispatch/session_ops.rs:511-522 | core/server/src/dispatch/session_ops.rs:765-776 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (12 lines × 2) foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/sink/IggyCommittable.java:50— foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/sink/IggyCommittable.java:50-61 | foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/source/IggySourceSplit.java:52-63 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (12 lines × 2) foreign/go/binary_serialization/binary_response_deserializer.go:614— foreign/go/binary_serialization/binary_response_deserializer.go:614-625 | foreign/go/binary_serialization/binary_response_deserializer.go:630-641 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/go/binary_serialization/binary_response_deserializer.go:614` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (12 lines × 2) core/bench/dashboard/frontend/src/components/layout/main_content.rs:114— core/bench/dashboard/frontend/src/components/layout/main_content.rs:114-125 | core/bench/dashboard/frontend/src/components/layout/main_content.rs:208-219 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (12 lines × 2) core/bench/dashboard/frontend/src/api/mod.rs:107— core/bench/dashboard/frontend/src/api/mod.rs:107-118 | core/bench/dashboard/frontend/src/api/mod.rs:196-207 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
IggyShard::tick_partitions (cognitive 147) core/shard/src/lib.rs:7575— IggyShard::tick_partitions has cognitive complexity 147 (threshold 15). Drivers by points: if/else 55 (131 pts), boolean chains 8, loops 4, match/switch 2 (4 pts) (nesting depth added 78). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
IggyShard::on_repair_range_reply (cognitive 63) core/shard/src/lib.rs:5405— IggyShard::on_repair_range_reply has cognitive complexity 63 (threshold 15). Drivers by points: if/else 27 (55 pts), boolean chains 5, match/switch 2 (3 pts) (nesting depth added 29). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::run_message_pump (cognitive 42) core/shard/src/router.rs:281— IggyShard::run_message_pump has cognitive complexity 42 (threshold 15). Drivers by points: if/else 12 (28 pts), match/switch 4 (11 pts), boolean chains 2, loops 1 (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::on_partition_transfer_progress (cognitive 37) core/shard/src/lib.rs:9505— IggyShard::on_partition_transfer_progress has cognitive complexity 37 (threshold 15). Drivers by points: if/else 19 (27 pts), match/switch 4 (7 pts), boolean chains 2, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::on_request_prepares (cognitive 35) core/shard/src/lib.rs:4964— IggyShard::on_request_prepares has cognitive complexity 35 (threshold 15). Drivers by points: if/else 15 (28 pts), loops 3 (5 pts), boolean chains 2 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::tick_metadata (cognitive 35) core/shard/src/lib.rs:10184— IggyShard::tick_metadata has cognitive complexity 35 (threshold 15). Drivers by points: if/else 18 (32 pts), match/switch 1 (3 pts) (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::process_lifecycle (cognitive 32) core/shard/src/router.rs:674— IggyShard::process_lifecycle has cognitive complexity 32 (threshold 15). Drivers by points: if/else 12 (26 pts), match/switch 2 (4 pts), boolean chains 2 (nesting depth added 16). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
IggyShard::drain_queued_frames_for_shutdown (cognitive 31) core/shard/src/router.rs:530— IggyShard::drain_queued_frames_for_shutdown has cognitive complexity 31 (threshold 15). Drivers by points: if/else 10 (27 pts), loops 3 (4 pts) (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::on_transfer_progress (cognitive 28) core/shard/src/lib.rs:7347— IggyShard::on_transfer_progress has cognitive complexity 28 (threshold 15). Drivers by points: if/else 14 (21 pts), match/switch 4 (6 pts), loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::on_start_view (cognitive 26) core/shard/src/lib.rs:4606— IggyShard::on_start_view has cognitive complexity 26 (threshold 15). Drivers by points: if/else 16 (23 pts), boolean chains 3 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::on_repair_prepare (cognitive 25) core/shard/src/lib.rs:5210— IggyShard::on_repair_prepare has cognitive complexity 25 (threshold 15). Drivers by points: if/else 13 (22 pts), boolean chains 3 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::on_partition_request_state_chunk (cognitive 25) core/shard/src/lib.rs:8546— IggyShard::on_partition_request_state_chunk has cognitive complexity 25 (threshold 15). Drivers by points: if/else 7 (12 pts), match/switch 5 (11 pts), boolean chains 1, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::dispatch_message (cognitive 22) core/shard/src/lib.rs:3128— IggyShard::dispatch_message has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (15 pts), match/switch 3 (5 pts), boolean chains 2 (nesting depth added 11). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
IggyShard::on_partition_state_transfer_target (cognitive 19) core/shard/src/lib.rs:9231— IggyShard::on_partition_state_transfer_target has cognitive complexity 19 (threshold 15). Drivers by points: if/else 13 (14 pts), boolean chains 2, match/switch 2, loops 1 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
IggyShard::on_partition_read (cognitive 18) core/shard/src/poll.rs:135— IggyShard::on_partition_read has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (12 pts), match/switch 3 (4 pts), boolean chains 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::on_commit (cognitive 17) core/shard/src/lib.rs:4816— IggyShard::on_commit has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (12 pts), match/switch 2 (3 pts), boolean chains 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyShard::park_if_unmaterialised (cognitive 16) core/shard/src/lib.rs:3731— IggyShard::park_if_unmaterialised has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10 (11 pts), boolean chains 3, match/switch 1 (2 pts) (nesting depth added 2). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
Duplicated block (6 lines × 2) core/bench/src/utils/mod.rs:113— core/bench/src/utils/mod.rs:113-118 | core/connectors/sinks/influxdb_sink/src/lib.rs:421-426 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (6 lines × 2) core/connectors/runtime/src/configs/connectors/local_provider.rs:406— core/connectors/runtime/src/configs/connectors/local_provider.rs:406-411 | core/connectors/runtime/src/configs/connectors/local_provider.rs:441-446 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) core/connectors/runtime/src/manager/sink.rs:71— core/connectors/runtime/src/manager/sink.rs:71-76 | core/connectors/runtime/src/manager/source.rs:71-76 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (6 lines × 2) core/connectors/sdk/src/decoders/proto.rs:429— core/connectors/sdk/src/decoders/proto.rs:429-434 | core/connectors/sdk/src/decoders/proto.rs:482-487 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) core/connectors/sdk/src/sink.rs:68— core/connectors/sdk/src/sink.rs:68-73 | core/connectors/sdk/src/source.rs:161-166 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (6 lines × 2) core/connectors/sinks/clickhouse_sink/src/binary.rs:486— core/connectors/sinks/clickhouse_sink/src/binary.rs:486-491 | core/connectors/sinks/clickhouse_sink/src/binary.rs:679-684 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) core/consensus/src/client_table.rs:1997— core/consensus/src/client_table.rs:1997-2002 | core/consensus/src/client_table.rs:2063-2068 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) core/metadata/src/stm/consumer_group.rs:435— core/metadata/src/stm/consumer_group.rs:435-440 | core/metadata/src/stm/consumer_group.rs:504-509 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) core/metadata/src/stm/stream.rs:1215— core/metadata/src/stm/stream.rs:1215-1220 | core/metadata/src/stm/stream.rs:1236-1241 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) core/sdk/src/stream_builder/build/build_iggy_consumer.rs:45— core/sdk/src/stream_builder/build/build_iggy_consumer.rs:45-50 | core/sdk/src/stream_builder/build/build_iggy_producer.rs:46-51 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (6 lines × 2) core/simulator/src/workload/state_checker.rs:286— core/simulator/src/workload/state_checker.rs:286-291 | core/simulator/src/workload/state_checker.rs:359-364 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) core/common/src/utils/serde_secret.rs:66— core/common/src/utils/serde_secret.rs:66-71 | core/connectors/sources/http_source/src/state.rs:587-592 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (6 lines × 2) core/connectors/sinks/clickhouse_sink/src/binary.rs:689— core/connectors/sinks/clickhouse_sink/src/binary.rs:689-694 | core/connectors/sinks/clickhouse_sink/src/binary.rs:746-751 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) core/binary_protocol/src/consensus/header.rs:941— core/binary_protocol/src/consensus/header.rs:941-946 | core/binary_protocol/src/consensus/header.rs:1089-1094 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) core/connectors/runtime/src/configs/connectors/local_provider.rs:707— core/connectors/runtime/src/configs/connectors/local_provider.rs:707-712 | core/connectors/runtime/src/configs/connectors/local_provider.rs:758-763 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) foreign/go/contracts/user_headers.go:160— foreign/go/contracts/user_headers.go:160-165 | foreign/go/contracts/user_headers.go:189-194 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2) foreign/go/errors/generator/main.go:189— foreign/go/errors/generator/main.go:189-194 | foreign/go/errors/generator/main.go:204-209 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/go/errors/generator/main.go:189` it runs out through the closing brace of the declaration holding it — the window is that declaration's tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (5 lines × 2) core/binary_protocol/src/responses/streams/get_stream.rs:92— core/binary_protocol/src/responses/streams/get_stream.rs:92-96 | core/binary_protocol/src/responses/streams/stream_response.rs:73-77 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (5 lines × 2) core/journal/src/prepare_journal.rs:742— core/journal/src/prepare_journal.rs:742-746 | core/journal/src/prepare_journal.rs:971-975 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (5 lines × 2) core/journal/src/prepare_journal.rs:799— core/journal/src/prepare_journal.rs:799-803 | core/journal/src/prepare_journal.rs:949-953 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (5 lines × 2) core/partitions/src/journal.rs:233— core/partitions/src/journal.rs:233-237 | core/partitions/src/journal.rs:806-810 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (5 lines × 2) foreign/csharp/Iggy_SDK/Consumers/IggyConsumerBuilder.cs:311— foreign/csharp/Iggy_SDK/Consumers/IggyConsumerBuilder.cs:311-315 | foreign/csharp/Iggy_SDK/Publishers/IggyPublisherBuilder.cs:375-379 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (5 lines × 2) foreign/csharp/Iggy_SDK/Identifier.cs:53— foreign/csharp/Iggy_SDK/Identifier.cs:53-57 | foreign/csharp/Iggy_SDK/Kinds/Partitioning.cs:52-56 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (5 lines × 2) core/binary_protocol/src/requests/users/login_register.rs:140— core/binary_protocol/src/requests/users/login_register.rs:140-144 | core/binary_protocol/src/requests/users/login_register_with_pat.rs:115-119 — before extracting anything, compare `core/binary_protocol/src/requests/users/login_register.rs` and `core/binary_protocol/src/requests/users/login_register_with_pat.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 33 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (5 lines × 2) foreign/python/src/config.rs:1444— foreign/python/src/config.rs:1444-1448 | foreign/python/src/producer.rs:904-908 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (5 lines × 2) core/partitions/src/segment_recovery.rs:2912— core/partitions/src/segment_recovery.rs:2912-2916 | core/sdk/src/vsr.rs:310-314 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (5 lines × 2) core/connectors/sinks/postgres_sink/src/lib.rs:168— core/connectors/sinks/postgres_sink/src/lib.rs:168-175 | REDACTED:142-146 — before extracting anything, compare `core/connectors/sinks/postgres_sink/src/lib.rs` and `REDACTED` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 44 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (5 lines × 2) core/common/src/types/message/iggy_message.rs:618— core/common/src/types/message/iggy_message.rs:618-622 | core/common/src/types/message/iggy_message.rs:628-634 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (5 lines × 2) core/message_bus/src/transports/ws.rs:243— core/message_bus/src/transports/ws.rs:243-247 | core/message_bus/src/transports/wss.rs:394-398 — before extracting anything, compare `core/message_bus/src/transports/ws.rs` and `core/message_bus/src/transports/wss.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 81 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (5 lines × 2) core/connectors/sinks/postgres_sink/src/lib.rs:193— core/connectors/sinks/postgres_sink/src/lib.rs:193-197 | REDACTED:601-605 — before extracting anything, compare `core/connectors/sinks/postgres_sink/src/lib.rs` and `REDACTED` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 44 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (5 lines × 2) core/consensus/src/client_table.rs:1892— core/consensus/src/client_table.rs:1892-1896 | core/consensus/src/client_table.rs:1906-1910 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (5 lines × 2) foreign/go/binary_serialization/binary_response_deserializer.go:111— foreign/go/binary_serialization/binary_response_deserializer.go:111-115 | foreign/go/binary_serialization/binary_response_deserializer.go:461-465 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (5 lines × 2) foreign/java/bench/src/main/java/org/apache/iggy/bench/models/report/FinalReport.java:43— foreign/java/bench/src/main/java/org/apache/iggy/bench/models/report/FinalReport.java:43-47 | foreign/java/bench/src/main/java/org/apache/iggy/bench/models/report/metrics/IndividualMetrics.java:35-39 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice. ★ These copies have DRIFTED, and that is worth reading before extracting anything: just after the matched lines, `foreign/java/bench/src/main/java/org/apache/iggy/bench/models/report/FinalReport.java:48` calls `copyOf`, `requireNonNull` and `foreign/java/bench/src/main/java/org/apache/iggy/bench/models/report/metrics/IndividualMetrics.java:40` does not — after which the two agree again for 2 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live.
IggyPartition::on_replicate (cyclomatic 36) core/partitions/src/iggy_partition.rs:4848— IggyPartition::on_replicate has cyclomatic complexity 36 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPartition::commit_messages_inner (cyclomatic 36) core/partitions/src/iggy_partition.rs:5830— IggyPartition::commit_messages_inner has cyclomatic complexity 36 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPartition::install_state_transfer (cyclomatic 33) core/partitions/src/state_transfer.rs:2558— IggyPartition::install_state_transfer has cyclomatic complexity 33 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
IggyPartition::apply_checked_install (cyclomatic 30) core/partitions/src/state_transfer.rs:2859— IggyPartition::apply_checked_install has cyclomatic complexity 30 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPartition::on_request (cyclomatic 28) core/partitions/src/iggy_partition.rs:4249— IggyPartition::on_request has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPartition::handle_committed_entries (cyclomatic 23) core/partitions/src/iggy_partition.rs:6173— IggyPartition::handle_committed_entries has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPartition::persist_consumer_offset_commit (cyclomatic 22) core/partitions/src/iggy_partition.rs:2804— IggyPartition::persist_consumer_offset_commit has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPartition::open_persistence_with_recovered (cyclomatic 19) core/partitions/src/iggy_partition.rs:811— IggyPartition::open_persistence_with_recovered has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPartition::resynchronize_consumer_offset_reservations_inner (cyclomatic 19) core/partitions/src/iggy_partition.rs:3643— IggyPartition::resynchronize_consumer_offset_reservations_inner has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPartition::build_poll_plan (cyclomatic 18) core/partitions/src/iggy_partition.rs:3823— IggyPartition::build_poll_plan has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPartition::apply_repaired_prepare (cyclomatic 18) core/partitions/src/iggy_partition.rs:8152— IggyPartition::apply_repaired_prepare has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
IggyPartition::state_transfer_offer (cyclomatic 18) core/partitions/src/state_transfer.rs:1902— IggyPartition::state_transfer_offer has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
IggyPartition::drain_request_queue_into_prepares (cyclomatic 17) core/partitions/src/iggy_partition.rs:4649— IggyPartition::drain_request_queue_into_prepares has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPartition::converge_to_empty_after_failed_install (cyclomatic 17) core/partitions/src/state_transfer.rs:3502— IggyPartition::converge_to_empty_after_failed_install has cyclomatic complexity 17 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
IggyPartition::complete_repair (cyclomatic 16) core/partitions/src/iggy_partition.rs:8253— IggyPartition::complete_repair has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::tick_partitions (cyclomatic 66) core/shard/src/lib.rs:7575— IggyShard::tick_partitions has cyclomatic complexity 66 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::process_lifecycle (cyclomatic 36) core/shard/src/router.rs:674— IggyShard::process_lifecycle has cyclomatic complexity 36 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::on_repair_range_reply (cyclomatic 33) core/shard/src/lib.rs:5405— IggyShard::on_repair_range_reply has cyclomatic complexity 33 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::dispatch_message (cyclomatic 32) core/shard/src/lib.rs:3128— IggyShard::dispatch_message has cyclomatic complexity 32 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
IggyShard::on_partition_transfer_progress (cyclomatic 26) core/shard/src/lib.rs:9505— IggyShard::on_partition_transfer_progress has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::run_message_pump (cyclomatic 24) core/shard/src/router.rs:281— IggyShard::run_message_pump has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::on_request_prepares (cyclomatic 21) core/shard/src/lib.rs:4964— IggyShard::on_request_prepares has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::on_start_view (cyclomatic 19) core/shard/src/lib.rs:4606— IggyShard::on_start_view has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::on_transfer_progress (cyclomatic 19) core/shard/src/lib.rs:7347— IggyShard::on_transfer_progress has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::on_partition_state_transfer_target (cyclomatic 19) core/shard/src/lib.rs:9231— IggyShard::on_partition_state_transfer_target has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
IggyShard::tick_metadata (cyclomatic 18) core/shard/src/lib.rs:10184— IggyShard::tick_metadata has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::on_repair_prepare (cyclomatic 17) core/shard/src/lib.rs:5210— IggyShard::on_repair_prepare has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::on_partition_request_state_chunk (cyclomatic 17) core/shard/src/lib.rs:8546— IggyShard::on_partition_request_state_chunk has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyShard::on_partition_read (cyclomatic 17) core/shard/src/poll.rs:135— IggyShard::on_partition_read has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
iggy_gateway_kafka::protocol::bounds_guard::validate_fetch_shape (cognitive 51) gateways/kafka/src/protocol/bounds_guard.rs:476— iggy_gateway_kafka::protocol::bounds_guard::validate_fetch_shape has cognitive complexity 51 (threshold 15). Drivers by points: if/else 23 (38 pts), loops 5 (13 pts) (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_gateway_kafka::protocol::bounds_guard::validate_create_topics_shape (cognitive 34) gateways/kafka/src/protocol/bounds_guard.rs:633— iggy_gateway_kafka::protocol::bounds_guard::validate_create_topics_shape has cognitive complexity 34 (threshold 15). Drivers by points: if/else 16 (26 pts), loops 4 (8 pts) (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_gateway_kafka::group::state::join_step (cognitive 29) gateways/kafka/src/group/state.rs:745— iggy_gateway_kafka::group::state::join_step has cognitive complexity 29 (threshold 15). Drivers by points: if/else 18 (24 pts), boolean chains 4, match/switch 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_gateway_kafka::protocol::bounds_guard::validate_list_offsets_shape (cognitive 24) gateways/kafka/src/protocol/bounds_guard.rs:575— iggy_gateway_kafka::protocol::bounds_guard::validate_list_offsets_shape has cognitive complexity 24 (threshold 15). Drivers by points: if/else 12 (21 pts), loops 2 (3 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_gateway_kafka::protocol::bounds_guard::validate_produce_shape (cognitive 23) gateways/kafka/src/protocol/bounds_guard.rs:421— iggy_gateway_kafka::protocol::bounds_guard::validate_produce_shape has cognitive complexity 23 (threshold 15). Drivers by points: if/else 13 (20 pts), loops 2 (3 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_gateway_kafka::protocol::handlers::produce::handle (cognitive 23) gateways/kafka/src/protocol/handlers/produce.rs:100— iggy_gateway_kafka::protocol::handlers::produce::handle has cognitive complexity 23 (threshold 15). Drivers by points: if/else 15 (18 pts), match/switch 3 (5 pts) (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
iggy_gateway_kafka::protocol::bounds_guard::validate_join_group_shape (cognitive 21) gateways/kafka/src/protocol/bounds_guard.rs:844— iggy_gateway_kafka::protocol::bounds_guard::validate_join_group_shape has cognitive complexity 21 (threshold 15). Drivers by points: if/else 17 (20 pts), loops 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
iggy_gateway_kafka::protocol::handlers::list_offsets::resolve_topic_lookups (cognitive 20) gateways/kafka/src/protocol/handlers/list_offsets.rs:190— iggy_gateway_kafka::protocol::handlers::list_offsets::resolve_topic_lookups has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (16 pts), match/switch 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_gateway_kafka::protocol::bounds_guard::validate_leave_group_shape (cognitive 20) gateways/kafka/src/protocol/bounds_guard.rs:947— iggy_gateway_kafka::protocol::bounds_guard::validate_leave_group_shape has cognitive complexity 20 (threshold 15). Drivers by points: if/else 11 (18 pts), loops 1 (2 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_gateway_kafka::protocol::bounds_guard::validate_sync_group_shape (cognitive 18) gateways/kafka/src/protocol/bounds_guard.rs:992— iggy_gateway_kafka::protocol::bounds_guard::validate_sync_group_shape has cognitive complexity 18 (threshold 15). Drivers by points: if/else 14 (17 pts), loops 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
iggy_gateway_kafka::protocol::handlers::create_topics::validate_create_topic_shape (cognitive 18) gateways/kafka/src/protocol/handlers/create_topics.rs:413— iggy_gateway_kafka::protocol::handlers::create_topics::validate_create_topic_shape has cognitive complexity 18 (threshold 15). Drivers by points: if/else 12 (14 pts), boolean chains 4 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
iggy_gateway_kafka::load_config (cognitive 18) gateways/kafka/src/main.rs:180— iggy_gateway_kafka::load_config has cognitive complexity 18 (threshold 15). Drivers by points: if/else 16 (18 pts) (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
Duplicated block (18 lines × 2) core/ai/mcp/src/configs.rs:286— core/ai/mcp/src/configs.rs:286-303 | core/connectors/runtime/src/api/config.rs:178-195 — before extracting anything, compare `core/ai/mcp/src/configs.rs` and `core/connectors/runtime/src/api/config.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 56 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (18 lines × 2) core/connectors/runtime/src/configs/connectors/http_provider.rs:308— core/connectors/runtime/src/configs/connectors/http_provider.rs:308-325 | core/connectors/runtime/src/configs/connectors/http_provider.rs:372-389 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (18 lines × 2) core/connectors/sdk/src/source.rs:380— core/connectors/sdk/src/source.rs:380-397 | core/connectors/sdk/src/source.rs:404-421 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (18 lines × 2) core/sdk/src/clients/producer.rs:949— core/sdk/src/clients/producer.rs:949-966 | core/sdk/src/clients/producer.rs:989-1006 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (18 lines × 2) core/sdk/src/quic/quic_client.rs:389— core/sdk/src/quic/quic_client.rs:389-406 | core/sdk/src/websocket/websocket_client.rs:385-402 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (18 lines × 2) core/sdk/src/quic/quic_client.rs:653— core/sdk/src/quic/quic_client.rs:653-670 | core/sdk/src/websocket/websocket_client.rs:580-597 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (18 lines × 2) core/connectors/sinks/elasticsearch_sink/src/lib.rs:373— core/connectors/sinks/elasticsearch_sink/src/lib.rs:373-390 | core/connectors/sinks/meilisearch_sink/src/lib.rs:786-803 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (18 lines × 2) foreign/go/internal/command/partition.go:37— foreign/go/internal/command/partition.go:37-54 | foreign/go/internal/command/partition.go:67-84 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any `return` inside it is the body's own exit and keeps its meaning in the moved unit.
Duplicated block (18 lines × 2) core/bench/dashboard/server/src/handlers.rs:464— core/bench/dashboard/server/src/handlers.rs:464-481 | core/bench/dashboard/server/src/handlers.rs:659-676 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (18 lines × 2) core/bench/dashboard/server/src/handlers.rs:496— core/bench/dashboard/server/src/handlers.rs:496-513 | core/bench/dashboard/server/src/handlers.rs:678-695 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (18 lines × 2) core/bench/report/src/types/group_metrics.rs:93— core/bench/report/src/types/group_metrics.rs:93-110 | core/bench/report/src/types/individual_metrics.rs:90-107 — before extracting anything, compare `core/bench/report/src/types/group_metrics.rs` and `core/bench/report/src/types/individual_metrics.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 34 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (15 lines × 2) core/binary_protocol/src/primitives/permissions.rs:120— core/binary_protocol/src/primitives/permissions.rs:120-134 | core/binary_protocol/src/primitives/permissions.rs:162-176 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (15 lines × 2) core/connectors/runtime/src/configs/connectors/http_provider.rs:411— core/connectors/runtime/src/configs/connectors/http_provider.rs:411-425 | core/connectors/runtime/src/configs/connectors/http_provider.rs:443-457 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (15 lines × 2) core/connectors/sources/postgres_source/src/lib.rs:1770— core/connectors/sources/postgres_source/src/lib.rs:1770-1784 | core/connectors/sources/postgres_source/src/lib.rs:1804-1818 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (15 lines × 2) core/sdk/src/quic/quic_client.rs:907— core/sdk/src/quic/quic_client.rs:907-921 | core/sdk/src/tcp/tcp_client.rs:942-956 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/tcp/tcp_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 134 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (15 lines × 2) foreign/python/src/config.rs:306— foreign/python/src/config.rs:306-320 | foreign/python/src/config.rs:1319-1333 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (15 lines × 2) gateways/kafka/src/protocol/handlers/metadata.rs:402— gateways/kafka/src/protocol/handlers/metadata.rs:402-416 | gateways/kafka/src/protocol/handlers/metadata.rs:447-461 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (15 lines × 2) core/metadata/src/impls/metadata.rs:1127— core/metadata/src/impls/metadata.rs:1127-1141 | core/metadata/src/impls/metadata.rs:3145-3159 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (15 lines × 2) core/message_bus/src/transports/tcp_tls.rs:226— core/message_bus/src/transports/tcp_tls.rs:226-240 | core/message_bus/src/transports/wss.rs:185-199 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (15 lines × 2) foreign/java/java-sdk/src/main/java/org/apache/iggy/serde/BytesSerializer.java:224— foreign/java/java-sdk/src/main/java/org/apache/iggy/serde/BytesSerializer.java:224-238 | foreign/java/java-sdk/src/main/java/org/apache/iggy/serde/BytesSerializer.java:241-255 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any `return` inside it is the body's own exit and keeps its meaning in the moved unit.
Duplicated block (15 lines × 2) foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:172— foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:172-186 | foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:238-252 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:172` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (15 lines × 2) examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java:93— examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java:93-107 | examples/java/src/main/java/org/apache/iggy/examples/multitenant/producer/MultiTenantProducer.java:93-107 — before extracting anything, compare `examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java` and `examples/java/src/main/java/org/apache/iggy/examples/multitenant/producer/MultiTenantProducer.java` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 57 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Read the line range as the matched WINDOW rather than a finished unit: at `examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java:93` it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (14 lines × 2) core/bench/report/src/types/server_stats.rs:174— core/bench/report/src/types/server_stats.rs:174-187 | core/common/src/types/stats/mod.rs:177-190 — before extracting anything, compare `core/bench/report/src/types/server_stats.rs` and `core/common/src/types/stats/mod.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 31 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (14 lines × 2) core/binary_protocol/src/requests/partitions/create_partitions.rs:47— core/binary_protocol/src/requests/partitions/create_partitions.rs:47-60 | core/binary_protocol/src/requests/partitions/delete_partitions.rs:47-60 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (14 lines × 2) core/connectors/runtime/src/api/sink.rs:92— core/connectors/runtime/src/api/sink.rs:92-105 | core/connectors/runtime/src/api/source.rs:95-108 — before extracting anything, compare `core/connectors/runtime/src/api/sink.rs` and `core/connectors/runtime/src/api/source.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 63 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (14 lines × 2) core/connectors/sources/postgres_source/src/lib.rs:1720— core/connectors/sources/postgres_source/src/lib.rs:1720-1733 | core/connectors/sources/postgres_source/src/lib.rs:1737-1750 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (14 lines × 2) core/metadata/src/impls/metadata.rs:1081— core/metadata/src/impls/metadata.rs:1081-1094 | core/metadata/src/impls/metadata.rs:3127-3140 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (14 lines × 2) core/sdk/src/websocket/websocket_connection_stream.rs:126— core/sdk/src/websocket/websocket_connection_stream.rs:126-139 | core/sdk/src/websocket/websocket_tls_connection_stream.rs:131-144 — before extracting anything, compare `core/sdk/src/websocket/websocket_connection_stream.rs` and `core/sdk/src/websocket/websocket_tls_connection_stream.rs` as WHOLE FILES: this scan already matched 8 separate duplicated blocks between them, totalling at least 102 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (14 lines × 2) core/binary_protocol/src/requests/personal_access_tokens/login_with_personal_access_token.rs:30— core/binary_protocol/src/requests/personal_access_tokens/login_with_personal_access_token.rs:30-43 | core/binary_protocol/src/responses/personal_access_tokens/create_personal_access_token.rs:35-48 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (14 lines × 2) core/binary_protocol/src/requests/users/delete_user.rs:30— core/binary_protocol/src/requests/users/delete_user.rs:30-43 | core/binary_protocol/src/requests/users/get_user.rs:30-43 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (14 lines × 2) foreign/go/internal/command/topic.go:77— foreign/go/internal/command/topic.go:77-90 | foreign/go/internal/command/topic.go:218-231 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (14 lines × 2) core/bench/dashboard/frontend/src/components/layout/sidebar.rs:196— core/bench/dashboard/frontend/src/components/layout/sidebar.rs:196-209 | core/bench/dashboard/frontend/src/components/layout/sidebar.rs:213-226 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (14 lines × 2) examples/python/basic/producer.py:114— examples/python/basic/producer.py:114-127 | examples/python/getting-started/producer.py:220-233 — `examples/python/basic/producer.py` and `examples/python/getting-started/producer.py` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 3 separate duplicated blocks between them, totalling at least 57 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at `examples/python/basic/producer.py:114` it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. ★ These copies have DRIFTED, and that is worth reading before extracting anything: just before the matched lines, `examples/python/basic/producer.py:113` calls `partition_id` and `examples/python/getting-started/producer.py:219` does not — after which the two agree again for 2 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live.
Duplicated block (16 lines × 2) foreign/csharp/Iggy_SDK/Publishers/IggyPublisherOfT.cs:102— foreign/csharp/Iggy_SDK/Publishers/IggyPublisherOfT.cs:102-117 | foreign/csharp/Iggy_SDK/Publishers/IggyPublisherOfT.cs:137-152 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/csharp/Iggy_SDK/Publishers/IggyPublisherOfT.cs:102` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names — the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately.
Duplicated block (16 lines × 2) core/connectors/sinks/http_sink/src/lib.rs:755— core/connectors/sinks/http_sink/src/lib.rs:755-770 | core/connectors/sinks/http_sink/src/lib.rs:837-852 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (16 lines × 2) core/connectors/sources/influxdb_source/src/v2.rs:854— core/connectors/sources/influxdb_source/src/v2.rs:854-869 | core/connectors/sources/influxdb_source/src/v3.rs:419-434 — before extracting anything, compare `core/connectors/sources/influxdb_source/src/v2.rs` and `core/connectors/sources/influxdb_source/src/v3.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 37 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (16 lines × 2) core/integration/src/harness/disk.rs:193— core/integration/src/harness/disk.rs:193-208 | core/integration/src/harness/disk.rs:348-363 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (16 lines × 2) core/integration/src/harness/seeds.rs:71— core/integration/src/harness/seeds.rs:71-86 | core/integration/src/harness/seeds.rs:95-110 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (16 lines × 2) gateways/kafka/src/protocol/bounds_guard.rs:875— gateways/kafka/src/protocol/bounds_guard.rs:875-890 | gateways/kafka/src/protocol/bounds_guard.rs:1019-1034 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (16 lines × 2) core/server/src/dispatch/session_ops.rs:1220— core/server/src/dispatch/session_ops.rs:1220-1235 | core/server/src/dispatch/session_ops.rs:1258-1277 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (16 lines × 2) core/partitions/src/poll_plan.rs:858— core/partitions/src/poll_plan.rs:858-873 | core/partitions/src/poll_plan.rs:904-919 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (16 lines × 2) examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs:86— examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs:86-101 | examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Producer/Utils.cs:91-106 — before extracting anything, compare `examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs` and `examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Producer/Utils.cs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 87 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Read the line range as the matched WINDOW rather than a finished unit: at `examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs:86` it runs out through the closing brace of the declaration holding it — the window is that declaration's tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (16 lines × 2) core/bench/dashboard/frontend/src/components/layout/hero.rs:297— core/bench/dashboard/frontend/src/components/layout/hero.rs:297-312 | core/bench/dashboard/frontend/src/components/layout/main_content.rs:261-276 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
TooManyFields: IggyPartition core/partitions/src/iggy_partition.rs:117— TooManyFields — 63 stored fields beside 219 methods. The bar is 30 stored fields; this is 33 over it, 2.10× the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member — each reader then names only the group it uses.
TooManyFields: IggyShard core/shard/src/lib.rs:1368— TooManyFields — 45 stored fields beside 151 methods. The bar is 30 stored fields; this is 15 over it, 1.50× the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member — each reader then names only the group it uses.
TooManyFields: PartitionPersistence core/partitions/src/persistence.rs:166— TooManyFields — 45 stored fields beside 56 methods. The bar is 30 stored fields; this is 15 over it, 1.50× the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member — each reader then names only the group it uses.
TooManyFields: Args core/common/src/types/args/mod.rs:225— TooManyFields — 43 stored fields beside 1 method. The bar is 30 stored fields; this is 13 over it, 1.43× the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member — each reader then names only the group it uses.
TooManyFields: IggyConsumer core/sdk/src/clients/consumer.rs:637— TooManyFields — 39 stored fields beside 21 methods. The bar is 30 stored fields; this is 9 over it, 1.30× the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member — each reader then names only the group it uses.
TooManyFields: VsrConsensus core/consensus/src/impls.rs:1071— TooManyFields — 37 stored fields beside 119 methods. The bar is 30 stored fields; this is 7 over it, 1.23× the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member — each reader then names only the group it uses.
TooManyFields: Args core/simulator/src/bin/workload-fuzz.rs:85— TooManyFields — 36 stored fields. The bar is 30 stored fields; this is 6 over it, 1.20× the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member — each reader then names only the group it uses.
TooManyFields: ShardMetrics core/shard/src/metrics.rs:223— TooManyFields — 32 stored fields beside 25 methods. The bar is 30 stored fields; this is 2 over it, 1.07× the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member — each reader then names only the group it uses.
TooManyFields: IggyTcpClient REDACTED:71— TooManyFields — 31 stored fields beside 98 methods. The bar is 30 stored fields; this is 1 over it, 1.03× the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member — each reader then names only the group it uses.
D30 · Dependency Vulnerabilities· Medium advisory (unmaintained) · ×9
Duplicated block (17 lines × 2) core/binary_protocol/src/requests/users/create_user.rs:93— core/binary_protocol/src/requests/users/create_user.rs:93-109 | core/binary_protocol/src/requests/users/update_permissions.rs:63-79 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (17 lines × 2) core/common/src/http/users/create_user.rs:58— core/common/src/http/users/create_user.rs:58-74 | core/common/src/http/users/login_user.rs:37-53 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (17 lines × 2) core/connectors/runtime/src/api/sink.rs:118— core/connectors/runtime/src/api/sink.rs:118-134 | core/connectors/runtime/src/api/source.rs:121-137 — before extracting anything, compare `core/connectors/runtime/src/api/sink.rs` and `core/connectors/runtime/src/api/source.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 63 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (17 lines × 2) core/connectors/runtime/src/configs/connectors.rs:386— core/connectors/runtime/src/configs/connectors.rs:386-402 | core/connectors/runtime/src/configs/connectors.rs:407-423 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (17 lines × 2) core/connectors/sinks/influxdb_sink/src/lib.rs:127— core/connectors/sinks/influxdb_sink/src/lib.rs:127-143 | core/connectors/sources/influxdb_source/src/common.rs:60-76 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (17 lines × 2) core/sdk/src/quic/quic_client.rs:892— core/sdk/src/quic/quic_client.rs:892-908 | core/sdk/src/websocket/websocket_client.rs:932-948 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (17 lines × 2) core/shard/src/lib.rs:5101— core/shard/src/lib.rs:5101-5117 | core/shard/src/lib.rs:5643-5659 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (17 lines × 2) core/simulator/src/workload/ops/delete_topic.rs:47— core/simulator/src/workload/ops/delete_topic.rs:47-63 | core/simulator/src/workload/ops/purge_topic.rs:46-62 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (17 lines × 2) core/tools/src/data-seeder/seeder.rs:58— core/tools/src/data-seeder/seeder.rs:58-74 | core/tools/src/data-seeder/seeder.rs:82-98 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
TodoComment foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.cs:370— // 5004 - Consumer group already exists TODO: refactor errors — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment foreign/csharp/Iggy_SDK/Errors/ErrorFactory.cs:20— //TODO - refactor whole error system, once the contract is set and stone. — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs:57— //TODO - create mechanism for refreshing REDACTED token — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs:58— //TODO - replace the HttpClient with IHttpClientFactory, when implementing support for ASP.NET Core DI — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs:59— //TODO - the error handling pattern is pretty ugly, look into moving it into an extension method — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs:729— //TODO - this doesn't work prob needs a custom json serializer — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs:825— // TODO: Add binary protocol version — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
TodoComment foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.Vsr.cs:488— // todo: change after error refactoring, error code 5 is for feature not supported — source code is not a task system: move the work to your tracker and leave a reference instead (e.g. `// REF: #123`), so the task is planned where tasks live and the ticket links back to the code.
server::boot::shard_main (cognitive 44) core/server/src/boot/mod.rs:410— server::boot::shard_main has cognitive complexity 44 (threshold 15). Drivers by points: if/else 28 (38 pts), boolean chains 2, loops 1 (2 pts), match/switch 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
server::partition_reconciler::reconcile_additions (cognitive 39) core/server/src/partition_reconciler.rs:573— server::partition_reconciler::reconcile_additions has cognitive complexity 39 (threshold 15). Drivers by points: if/else 15 (36 pts), match/switch 1 (2 pts), loops 1 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
server::http::forward::forward_partition_or_pass (cognitive 26) core/server/src/http/forward.rs:335— server::http::forward::forward_partition_or_pass has cognitive complexity 26 (threshold 15). Drivers by points: if/else 10 (16 pts), match/switch 2 (4 pts), boolean chains 3, loops 2 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
server::dispatch::handle_client_request (cognitive 24) core/server/src/dispatch/mod.rs:408— server::dispatch::handle_client_request has cognitive complexity 24 (threshold 15). Drivers by points: match/switch 7 (14 pts), if/else 6 (10 pts) (nesting depth added 11). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
server::dispatch::reads::handle_non_replicated_request (cognitive 23) core/server/src/dispatch/reads.rs:353— server::dispatch::reads::handle_non_replicated_request has cognitive complexity 23 (threshold 15). Drivers by points: if/else 10 (18 pts), match/switch 3 (5 pts) (nesting depth added 10). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
server::snapshot::procdump::dump_file (cognitive 21) core/server/src/snapshot/procdump.rs:96— server::snapshot::procdump::dump_file has cognitive complexity 21 (threshold 15). Drivers by points: if/else 5 (9 pts), match/switch 2 (6 pts), loops 1 (4 pts), boolean chains 2 (nesting depth added 11). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
server::boot::recovery::build_shard_for_thread (cognitive 17) core/server/src/boot/recovery.rs:69— server::boot::recovery::build_shard_for_thread has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (8 pts), loops 4 (7 pts), match/switch 1 (2 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
server::consumer_group::liveness::report_sessions (cognitive 17) core/server/src/consumer_group/liveness.rs:153— server::consumer_group::liveness::report_sessions has cognitive complexity 17 (threshold 15). Drivers by points: if/else 4 (8 pts), boolean chains 3, loops 2 (3 pts), match/switch 1 (3 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Duplicated block (7 lines × 3) core/ai/mcp/src/log.rs:161— core/ai/mcp/src/log.rs:161-167 | core/connectors/runtime/src/log.rs:114-120 | core/server_common/src/log/logger.rs:386-392 — before extracting anything, compare `core/ai/mcp/src/log.rs` and `core/connectors/runtime/src/log.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 87 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (7 lines × 3) core/ai/mcp/src/log.rs:197— core/ai/mcp/src/log.rs:197-203 | core/connectors/runtime/src/log.rs:150-156 | core/server_common/src/log/logger.rs:417-423 — before extracting anything, compare `core/ai/mcp/src/log.rs` and `core/connectors/runtime/src/log.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 87 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (7 lines × 3) core/integration/src/harness/handle/connectors_runtime.rs:173— core/integration/src/harness/handle/connectors_runtime.rs:173-179 | core/integration/src/harness/handle/mcp.rs:173-179 | core/integration/src/harness/handle/server.rs:979-985 — before extracting anything, compare `core/integration/src/harness/handle/connectors_runtime.rs` and `core/integration/src/harness/handle/mcp.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 39 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (7 lines × 3) core/connectors/sources/postgres_source/src/lib.rs:1627— core/connectors/sources/postgres_source/src/lib.rs:1627-1633 | core/connectors/sources/postgres_source/src/lib.rs:1635-1641 | core/connectors/sources/postgres_source/src/lib.rs:1651-1657 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (7 lines × 3) core/bench/dashboard/frontend/src/api/mod.rs:82— core/bench/dashboard/frontend/src/api/mod.rs:82-88 | core/bench/dashboard/frontend/src/api/mod.rs:170-176 | core/bench/dashboard/frontend/src/api/mod.rs:235-241 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (7 lines × 3) examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Producer/Utils.cs:38— examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Producer/Utils.cs:38-44 | examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs:39-45 | examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Producer/Utils.cs:40-46 — before extracting anything, compare `examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs` and `examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Producer/Utils.cs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 87 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (7 lines × 3) foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:171— foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:171-177 | foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:237-243 | foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:303-309 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (7 lines × 3) examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/producer/MessageEnvelopeProducer.java:70— examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/producer/MessageEnvelopeProducer.java:70-76 | examples/java/src/main/java/org/apache/iggy/examples/messageheaders/producer/MessageHeadersProducer.java:71-77 | examples/java/src/main/java/org/apache/iggy/examples/streambuilder/StreamBasic.java:120-126 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made 3 times. Read the line range as the matched WINDOW rather than a finished unit: at `examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/producer/MessageEnvelopeProducer.java:70` it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
iggy_connectors::source::source_forwarding_loop (cognitive 56) core/connectors/runtime/src/source.rs:555— iggy_connectors::source::source_forwarding_loop has cognitive complexity 56 (threshold 15). Drivers by points: if/else 26 (46 pts), match/switch 1 (4 pts), boolean chains 3, loops 2 (3 pts) (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connectors::sink::process_messages (cognitive 45) core/connectors/runtime/src/sink.rs:548— iggy_connectors::sink::process_messages has cognitive complexity 45 (threshold 15). Drivers by points: if/else 16 (30 pts), match/switch 4 (10 pts), loops 4 (5 pts) (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connectors::main (cognitive 29) core/connectors/runtime/src/main.rs:121— iggy_connectors::main has cognitive complexity 29 (threshold 15). Drivers by points: if/else 9 (16 pts), loops 10 (12 pts), match/switch 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connectors::sink::consume_messages (cognitive 22) core/connectors/runtime/src/sink.rs:302— iggy_connectors::sink::consume_messages has cognitive complexity 22 (threshold 15). Drivers by points: if/else 9 (16 pts), match/switch 2 (4 pts), boolean chains 1, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connectors::sink::init (cognitive 21) core/connectors/runtime/src/sink.rs:59— iggy_connectors::sink::init has cognitive complexity 21 (threshold 15). Drivers by points: if/else 5 (10 pts), match/switch 3 (7 pts), loops 2 (4 pts) (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connectors::source::init (cognitive 20) core/connectors/runtime/src/source.rs:96— iggy_connectors::source::init has cognitive complexity 20 (threshold 15). Drivers by points: if/else 5 (10 pts), match/switch 4 (9 pts), loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connectors::source::process_messages (cognitive 18) core/connectors/runtime/src/source.rs:930— iggy_connectors::source::process_messages has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (12 pts), loops 2 (3 pts), match/switch 1 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
partitions::segment_recovery::load_persisted_segments_with_checkpoint (cognitive 32) core/partitions/src/segment_recovery.rs:570— partitions::segment_recovery::load_persisted_segments_with_checkpoint has cognitive complexity 32 (threshold 15). Drivers by points: if/else 14 (23 pts), match/switch 2 (4 pts), boolean chains 3, loops 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
partitions::segment_recovery::recover_segment_bounds (cognitive 26) core/partitions/src/segment_recovery.rs:1572— partitions::segment_recovery::recover_segment_bounds has cognitive complexity 26 (threshold 15). Drivers by points: if/else 9 (24 pts), boolean chains 1, match/switch 1 (nesting depth added 15). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
partitions::segment_recovery::find_provable_index_anchor (cognitive 23) core/partitions/src/segment_recovery.rs:2228— partitions::segment_recovery::find_provable_index_anchor has cognitive complexity 23 (threshold 15). Drivers by points: if/else 8 (20 pts), boolean chains 2, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
partitions::segment_recovery::index_is_consistent (cognitive 20) core/partitions/src/segment_recovery.rs:2361— partitions::segment_recovery::index_is_consistent has cognitive complexity 20 (threshold 15). Drivers by points: if/else 4 (12 pts), boolean chains 5, loops 2 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
partitions::segment_recovery::sweep_scratch_files_and_collect_offsets (cognitive 18) core/partitions/src/segment_recovery.rs:1111— partitions::segment_recovery::sweep_scratch_files_and_collect_offsets has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (13 pts), match/switch 2 (3 pts), loops 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
partitions::segment_recovery::recover_by_walking_log (cognitive 17) core/partitions/src/segment_recovery.rs:1856— partitions::segment_recovery::recover_by_walking_log has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9 (16 pts), loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
partitions::segment_recovery::walk_chain_from_anchor (cognitive 16) core/partitions/src/segment_recovery.rs:1988— partitions::segment_recovery::walk_chain_from_anchor has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (15 pts), loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Duplicated block (11 lines × 3) core/connectors/sdk/src/decoders/proto.rs:163— core/connectors/sdk/src/decoders/proto.rs:163-173 | core/connectors/sdk/src/encoders/proto.rs:195-205 | core/connectors/sdk/src/transforms/proto_convert.rs:189-199 — `core/connectors/sdk/src/decoders/proto.rs` and `core/connectors/sdk/src/encoders/proto.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 11 separate duplicated blocks between them, totalling at least 151 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (11 lines × 3) core/integration/src/harness/disk.rs:194— core/integration/src/harness/disk.rs:194-204 | core/integration/src/harness/disk.rs:349-359 | core/integration/src/harness/disk.rs:381-391 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (11 lines × 3) core/partitions/src/partition_storage.rs:68— core/partitions/src/partition_storage.rs:68-78 | core/partitions/src/partition_storage.rs:81-93 | core/partitions/src/partition_storage.rs:97-111 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (11 lines × 3) core/common/src/types/configuration/quic_config/quic_connection_string_options.rs:115— core/common/src/types/configuration/quic_config/quic_connection_string_options.rs:115-125 | core/common/src/types/configuration/quic_config/quic_connection_string_options.rs:139-149 | core/common/src/types/configuration/quic_config/quic_connection_string_options.rs:155-165 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (11 lines × 3) core/message_bus/src/client_listener/tcp.rs:64— core/message_bus/src/client_listener/tcp.rs:64-74 | core/message_bus/src/client_listener/tcp_tls.rs:106-116 | core/message_bus/src/client_listener/wss.rs:100-110 — before extracting anything, compare `core/message_bus/src/client_listener/tcp.rs` and `core/message_bus/src/client_listener/tcp_tls.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 32 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (11 lines × 3) core/integration/src/harness/handle/client_builder.rs:189— core/integration/src/harness/handle/client_builder.rs:189-199 | core/integration/src/harness/handle/client_builder.rs:256-266 | core/integration/src/harness/handle/client_builder.rs:311-321 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (11 lines × 3) examples/python/high-level/background_producer.py:43— examples/python/high-level/background_producer.py:43-53 | examples/python/high-level/consumer.py:43-53 | examples/python/high-level/producer.py:37-47 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from all 3 call sites, so a change lands once. The `return` at the foot of the matched lines is the enclosing body's own terminal exit, not an early one: it moves with them unchanged, and each site calls the extracted unit from the position that `return` occupied — no decision has to be handed back and re-acted on.
server::boot::shard_main (cyclomatic 27) core/server/src/boot/mod.rs:410— server::boot::shard_main has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
server::dispatch::reads::handle_non_replicated_request (cyclomatic 21) core/server/src/dispatch/reads.rs:353— server::dispatch::reads::handle_non_replicated_request has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
server::dispatch::handle_client_request (cyclomatic 20) core/server/src/dispatch/mod.rs:408— server::dispatch::handle_client_request has cyclomatic complexity 20 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
server::partition_reconciler::reconcile_additions (cyclomatic 18) core/server/src/partition_reconciler.rs:573— server::partition_reconciler::reconcile_additions has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
server::http::forward::forward_partition_or_pass (cyclomatic 17) core/server/src/http/forward.rs:335— server::http::forward::forward_partition_or_pass has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
server::boot::threads::validate_sharding_runtime_knobs (cyclomatic 16) core/server/src/boot/threads.rs:566— server::boot::threads::validate_sharding_runtime_knobs has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
PartitionPrepareJournal::rewrite (cognitive 35) core/journal/src/partition_journal.rs:1353— PartitionPrepareJournal::rewrite has cognitive complexity 35 (threshold 15). Drivers by points: if/else 16 (30 pts), boolean chains 4, loops 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PartitionPrepareJournal::append_batch_inner (cognitive 26) core/journal/src/partition_journal.rs:771— PartitionPrepareJournal::append_batch_inner has cognitive complexity 26 (threshold 15). Drivers by points: if/else 10 (19 pts), boolean chains 4, loops 3 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PartitionPrepareJournal::reset_with_segment_checkpoint (cognitive 25) core/journal/src/partition_journal/segments.rs:172— PartitionPrepareJournal::reset_with_segment_checkpoint has cognitive complexity 25 (threshold 15). Drivers by points: if/else 13 (20 pts), boolean chains 4, match/switch 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PartitionPrepareJournal::recover_entries (cognitive 18) core/journal/src/partition_journal.rs:930— PartitionPrepareJournal::recover_entries has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (12 pts), boolean chains 5, loops 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PartitionPrepareJournal::recover_segment_files (cognitive 17) core/journal/src/partition_journal/segments.rs:504— PartitionPrepareJournal::recover_segment_files has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (13 pts), boolean chains 3, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PartitionPrepareJournal::recover_unpublished_tail (cognitive 17) core/journal/src/partition_journal.rs:1003— PartitionPrepareJournal::recover_unpublished_tail has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (13 pts), boolean chains 3, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Off the main sequence: cpu_allocation — cpu_allocation: abstractness 0.00, instability 0.00, distance 1.00 — zone of pain — concrete and depended on by 3 project(s), so it's rigid to change.
Off the main sequence: github.com/apache/iggy/foreign/go — github.com/apache/iggy/foreign/go: abstractness 0.01, instability 0.00, distance 0.99 — zone of pain — concrete and depended on by 1 project(s), so it's rigid to change.
Off the main sequence: iggy_binary_protocol — iggy_binary_protocol: abstractness 0.02, instability 0.00, distance 0.98 — zone of pain — concrete and depended on by 15 project(s), so it's rigid to change.
Off the main sequence: iggy_connector_sdk — iggy_connector_sdk: abstractness 0.07, instability 0.08, distance 0.85 — zone of pain — concrete and depended on by 23 project(s), so it's rigid to change.
Off the main sequence: iggy_common — iggy_common: abstractness 0.14, instability 0.03, distance 0.83 — the shape a shared-kernel / building-block library has BY DESIGN — concrete and widely depended-on is what makes it useful, and this dimension does not penalise it (the distance is reported for completeness, not as a defect). Worth a look only if it has grown past one coherent kernel into an everything-bucket.
Off the main sequence: iggy (Cargo) — iggy (Cargo): abstractness 0.14, instability 0.15, distance 0.71 — zone of pain — concrete and depended on by 11 project(s), so it's rigid to change.
No assertions: CreateClient_TcpClientDisposesTwice foreign/csharp/Iggy_SDK_Tests/ClientTests/IggyClientFactoryTests.cs:91— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: Dispose_IsIdempotent foreign/csharp/Iggy_SDK_Tests/UtilityTests/PooledBufferWriterTests.cs:116— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: BatchDispose_IsIdempotent foreign/csharp/Iggy_SDK_Tests/UtilityTests/RentedMessageBatchTests.cs:192— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: ValidateUsername_AcceptsTheServerBounds foreign/csharp/Iggy_SDK_Tests/VsrTests/CredentialBoundsTests.cs:29— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
No assertions: ValidatePassword_AcceptsTheServerBounds foreign/csharp/Iggy_SDK_Tests/VsrTests/CredentialBoundsTests.cs:45— This method's body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* — so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as 'no assertion this check knows how to see', and if that is right, add one.
IggyConsumer::poll_next (cognitive 67) core/sdk/src/clients/consumer.rs:1533— IggyConsumer::poll_next has cognitive complexity 67 (threshold 15). Drivers by points: if/else 22 (55 pts), boolean chains 5, loops 2 (5 pts), match/switch 1 (2 pts) (nesting depth added 37). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyConsumer::create_poll_messages_future (cognitive 34) core/sdk/src/clients/consumer.rs:1214— IggyConsumer::create_poll_messages_future has cognitive complexity 34 (threshold 15). Drivers by points: if/else 18 (29 pts), boolean chains 4, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyConsumer::consume_messages (cognitive 24) core/sdk/src/consumer_ext/consumer_message_ext.rs:47— IggyConsumer::consume_messages has cognitive complexity 24 (threshold 15). Drivers by points: if/else 5 (11 pts), match/switch 4 (10 pts), boolean chains 2, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyConsumer::init (cognitive 19) core/sdk/src/clients/consumer.rs:954— IggyConsumer::init has cognitive complexity 19 (threshold 15). Drivers by points: if/else 10 (15 pts), boolean chains 2, loops 1, match/switch 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyConsumer::shutdown (cognitive 16) core/sdk/src/clients/consumer.rs:1729— IggyConsumer::shutdown has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (11 pts), boolean chains 3, loops 1 (2 pts) (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connector_clickhouse_sink::binary::serialize_value (cognitive 55) core/connectors/sinks/clickhouse_sink/src/binary.rs:83— iggy_connector_clickhouse_sink::binary::serialize_value has cognitive complexity 55 (threshold 15). Drivers by points: if/else 13 (30 pts), loops 5 (12 pts), match/switch 5 (10 pts), boolean chains 3 (nesting depth added 29). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
iggy_connector_clickhouse_sink::binary::strip_timezone (cognitive 42) core/connectors/sinks/clickhouse_sink/src/binary.rs:801— iggy_connector_clickhouse_sink::binary::strip_timezone has cognitive complexity 42 (threshold 15). Drivers by points: if/else 11 (29 pts), match/switch 2 (12 pts), loops 1 (nesting depth added 28). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
iggy_connector_clickhouse_sink::schema::parse_type_inner (cognitive 22) core/connectors/sinks/clickhouse_sink/src/schema.rs:155— iggy_connector_clickhouse_sink::schema::parse_type_inner has cognitive complexity 22 (threshold 15). Drivers by points: if/else 17 (20 pts), boolean chains 1, match/switch 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
iggy_connector_clickhouse_sink::schema::strip_named_tuple_field (cognitive 18) core/connectors/sinks/clickhouse_sink/src/schema.rs:402— iggy_connector_clickhouse_sink::schema::strip_named_tuple_field has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10 (16 pts), boolean chains 1, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connector_clickhouse_sink::binary::parse_decimal_str (cognitive 16) core/connectors/sinks/clickhouse_sink/src/binary.rs:605— iggy_connector_clickhouse_sink::binary::parse_decimal_str has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10 (12 pts), boolean chains 2, match/switch 2 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
message_bus::transports::ws::run_pump (cognitive 34) core/message_bus/src/transports/ws.rs:186— message_bus::transports::ws::run_pump has cognitive complexity 34 (threshold 15). Drivers by points: match/switch 5 (15 pts), if/else 3 (12 pts), loops 3 (7 pts) (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
message_bus::transports::wss::run_pump (cognitive 34) core/message_bus/src/transports/wss.rs:334— message_bus::transports::wss::run_pump has cognitive complexity 34 (threshold 15). Drivers by points: match/switch 5 (15 pts), if/else 3 (12 pts), loops 3 (7 pts) (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
message_bus::installer::replica::install_replica_conn (cognitive 26) core/message_bus/src/installer/replica.rs:326— message_bus::installer::replica::install_replica_conn has cognitive complexity 26 (threshold 15). Drivers by points: if/else 16 (21 pts), boolean chains 4, match/switch 1 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
message_bus::transports::tcp_tls::run_pump (cognitive 25) core/message_bus/src/transports/tcp_tls.rs:521— message_bus::transports::tcp_tls::run_pump has cognitive complexity 25 (threshold 15). Drivers by points: if/else 3 (10 pts), match/switch 3 (8 pts), loops 3 (7 pts) (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
message_bus::transports::tcp::writer_loop (cognitive 16) core/message_bus/src/transports/tcp.rs:397— message_bus::transports::tcp::writer_loop has cognitive complexity 16 (threshold 15). Drivers by points: if/else 3 (6 pts), loops 3 (5 pts), match/switch 2 (5 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyMetadata::install_state_transfer (cognitive 28) core/metadata/src/impls/metadata.rs:1733— IggyMetadata::install_state_transfer has cognitive complexity 28 (threshold 15). Drivers by points: if/else 17 (25 pts), boolean chains 3 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyMetadata::commit_committable_prefix (cognitive 24) core/metadata/src/impls/metadata.rs:2861— IggyMetadata::commit_committable_prefix has cognitive complexity 24 (threshold 15). Drivers by points: if/else 10 (21 pts), loops 2, boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyMetadata::submit_logout_in_process (cognitive 17) core/metadata/src/impls/metadata.rs:2239— IggyMetadata::submit_logout_in_process has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9 (13 pts), match/switch 2 (3 pts), boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyMetadata::on_replicate (cognitive 16) core/metadata/src/impls/metadata.rs:1153— IggyMetadata::on_replicate has cognitive complexity 16 (threshold 15). Drivers by points: if/else 12 (13 pts), match/switch 2 (3 pts) (nesting depth added 2). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
IggyMetadata::repair_primary_self_acks (cognitive 16) core/metadata/src/impls/metadata.rs:2767— IggyMetadata::repair_primary_self_acks has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (10 pts), loops 4 (5 pts), boolean chains 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
integration::harness::disk::collect_comparable_files (cognitive 17) core/integration/src/harness/disk.rs:191— integration::harness::disk::collect_comparable_files has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (13 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This shape REPEATS in the file: one other method here (integration::harness::disk::total_log_bytes) has the same decision points, in the same order, at the same nesting depths — so this is one pattern written twice rather than two separate problems. Splitting this body alone leaves the other exactly as it is. Where these are variations on one operation, the change that clears both is the shared one: lift the common shape into a single routine the variants call, parameterised by whatever genuinely differs between them, and keep in each method only the part that is not shared.
integration::harness::disk::total_log_bytes (cognitive 17) core/integration/src/harness/disk.rs:346— integration::harness::disk::total_log_bytes has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (13 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This shape REPEATS in the file: one other method here (integration::harness::disk::collect_comparable_files) has the same decision points, in the same order, at the same nesting depths — so this is one pattern written twice rather than two separate problems. Splitting this body alone leaves the other exactly as it is. Where these are variations on one operation, the change that clears both is the shared one: lift the common shape into a single routine the variants call, parameterised by whatever genuinely differs between them, and keep in each method only the part that is not shared.
integration::bench_utils::run_bench_and_wait_for_finish (cognitive 16) core/integration/src/bench_utils.rs:42— integration::bench_utils::run_bench_and_wait_for_finish has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (9 pts), loops 2 (3 pts), boolean chains 2, match/switch 1 (2 pts) (nesting depth added 4). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
integration::harness::disk::read_replicated_consumer_offset (cognitive 16) core/integration/src/harness/disk.rs:379— integration::harness::disk::read_replicated_consumer_offset has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (11 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
integration::harness::config::resolve::resolve_config_paths (cognitive 16) core/integration/src/harness/config/resolve.rs:45— integration::harness::config::resolve::resolve_config_paths has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (11 pts), boolean chains 2, match/switch 1 (2 pts), loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
D4 · Code Duplication· Members sharing a duplicated core (4 members, 50+ identical tokens) · ×5
Members sharing a duplicated core (4 members, 50+ identical tokens) core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs:56— core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs:56-68 | core/binary_protocol/src/requests/consumer_offsets/get_consumer_offset.rs:50-61 | core/binary_protocol/src/requests/consumer_offsets/store_consumer_offset.rs:58-71 | core/binary_protocol/src/requests/messages/poll_messages.rs:64-78 — These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times.
Members sharing a duplicated core (4 members, 50+ identical tokens) core/message_bus/src/lifecycle/connection_registry.rs:558— core/message_bus/src/lifecycle/connection_registry.rs:558-569 | core/message_bus/src/lifecycle/connection_registry.rs:582-601 | core/message_bus/src/lifecycle/connection_registry.rs:883-899 | core/message_bus/src/lifecycle/connection_registry.rs:909-927 — These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times.
Members sharing a duplicated core (4 members, 50+ identical tokens) core/sdk/src/http/consumer_groups.rs:34— core/sdk/src/http/consumer_groups.rs:34-55 | core/sdk/src/http/consumer_offsets.rs:56-79 | core/sdk/src/http/streams.rs:33-48 | core/sdk/src/http/topics.rs:35-55 — These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times.
Members sharing a duplicated core (4 members, 50+ identical tokens) core/shard/src/lib.rs:4484— core/shard/src/lib.rs:4484-4519 | core/shard/src/lib.rs:4529-4603 | core/shard/src/lib.rs:4613-4813 | core/shard/src/lib.rs:4924-4957 — These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times.
Members sharing a duplicated core (4 members, 50+ identical tokens) examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java:62— examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java:62-115 | examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/consumer/MessageEnvelopeConsumer.java:71-124 | examples/java/src/main/java/org/apache/iggy/examples/messageheaders/consumer/MessageHeadersConsumer.java:74-119 | examples/java/src/main/java/org/apache/iggy/examples/tcptls/consumer/TcpTlsConsumer.java:83-136 — These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times.
Unfinished stub — throws NotImplementedException foreign/csharp/Iggy_SDK/JsonConverters/ConsumerConverter.cs:27— A shipped member still throws NotImplementedException — generated scaffolding that was never completed. Implement it or remove the dead surface.
Unfinished stub — throws NotImplementedException foreign/csharp/Iggy_SDK/JsonConverters/ExpiryConverter.cs:37— A shipped member still throws NotImplementedException — generated scaffolding that was never completed. Implement it or remove the dead surface.
Unfinished stub — throws NotImplementedException foreign/csharp/Iggy_SDK/JsonConverters/MessageConverter.cs:27— A shipped member still throws NotImplementedException — generated scaffolding that was never completed. Implement it or remove the dead surface.
Unfinished stub — throws NotImplementedException foreign/csharp/Iggy_SDK/JsonConverters/MessagesConverter.cs:36— A shipped member still throws NotImplementedException — generated scaffolding that was never completed. Implement it or remove the dead surface.
Unfinished stub — throws NotImplementedException foreign/csharp/Iggy_SDK/JsonConverters/SizeConverter.cs:50— A shipped member still throws NotImplementedException — generated scaffolding that was never completed. Implement it or remove the dead surface.
Duplicated block (9 lines × 2 locations) foreign/node/src/debug-send.ts:68— foreign/node/src/debug-send.ts:68 · foreign/node/src/debug.ts:67 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (9 lines × 2 locations) foreign/node/src/wire/client/client.utils.ts:31— foreign/node/src/wire/client/client.utils.ts:31 · foreign/node/src/wire/user/user.utils.ts:67 — the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another.
Duplicated block (9 lines × 2 locations) foreign/node/src/wire/consumer-group/get-group.command.ts:37— foreign/node/src/wire/consumer-group/get-group.command.ts:37 · foreign/node/src/wire/topic/get-topic.command.ts:45 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (9 lines × 2 locations) foreign/node/src/wire/vsr/register.ts:57— foreign/node/src/wire/vsr/register.ts:57 · foreign/node/src/wire/vsr/register.ts:74 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (9 lines × 2 locations) web/src/lib/api/clientApi.ts:47— web/src/lib/api/clientApi.ts:47 · web/src/lib/api/fetchApi.ts:37 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it.
Duplicated block (8 lines × 2 locations) foreign/node/src/wire/cluster/cluster.utils.ts:53— foreign/node/src/wire/cluster/cluster.utils.ts:53 · foreign/node/src/wire/cluster/cluster.utils.ts:127 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (8 lines × 2 locations) foreign/node/src/wire/consumer-group/create-group.command.ts:43— foreign/node/src/wire/consumer-group/create-group.command.ts:43 · foreign/node/src/wire/stream/create-stream.command.ts:40 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (8 lines × 2 locations) foreign/node/src/wire/session/login.utils.ts:49— foreign/node/src/wire/session/login.utils.ts:49 · foreign/node/src/wire/user/create-user.command.ts:47 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (8 lines × 2 locations) foreign/node/src/wire/stream/stream.utils.ts:61— foreign/node/src/wire/stream/stream.utils.ts:61 · foreign/node/src/wire/topic/topic.utils.ts:136 — the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another.
Duplicated block (8 lines × 2 locations) foreign/node/src/wire/user/permissions.utils.ts:251— foreign/node/src/wire/user/permissions.utils.ts:251 · foreign/node/src/wire/user/permissions.utils.ts:318 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
iggy_gateway_kafka::protocol::bounds_guard::validate_fetch_shape (cyclomatic 23) gateways/kafka/src/protocol/bounds_guard.rs:476— iggy_gateway_kafka::protocol::bounds_guard::validate_fetch_shape has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
iggy_gateway_kafka::group::state::join_step (cyclomatic 23) gateways/kafka/src/group/state.rs:745— iggy_gateway_kafka::group::state::join_step has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
iggy_gateway_kafka::protocol::handlers::produce::handle (cyclomatic 16) gateways/kafka/src/protocol/handlers/produce.rs:100— iggy_gateway_kafka::protocol::handlers::produce::handle has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
iggy_gateway_kafka::load_config (cyclomatic 16) gateways/kafka/src/main.rs:180— iggy_gateway_kafka::load_config has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
TcpClient::send_raw (cognitive 56) core/sdk/src/tcp/tcp_client.rs:1317— TcpClient::send_raw has cognitive complexity 56 (threshold 15). Drivers by points: if/else 16 (43 pts), match/switch 3 (7 pts), loops 2 (4 pts), boolean chains 2 (nesting depth added 33). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
TcpClient::connect_inner (cognitive 38) core/sdk/src/tcp/tcp_client.rs:617— TcpClient::connect_inner has cognitive complexity 38 (threshold 15). Drivers by points: if/else 9 (23 pts), match/switch 3 (9 pts), boolean chains 3, loops 2 (3 pts) (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
TcpClient::send_raw_with_response (cognitive 20) core/sdk/src/tcp/tcp_client.rs:222— TcpClient::send_raw_with_response has cognitive complexity 20 (threshold 15). Drivers by points: if/else 16 (17 pts), boolean chains 3 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
TcpClient::send_raw_vsr_attempt (cognitive 20) core/sdk/src/tcp/tcp_client.rs:1496— TcpClient::send_raw_vsr_attempt has cognitive complexity 20 (threshold 15). Drivers by points: if/else 7 (12 pts), match/switch 4 (6 pts), boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
kafka_message_gen::run_send (cognitive 44) gateways/kafka/tools/kafka-tool/src/main.rs:730— kafka_message_gen::run_send has cognitive complexity 44 (threshold 15). Drivers by points: if/else 9 (33 pts), match/switch 2 (6 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 29). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
kafka_message_gen::response::decode_body (cognitive 42) gateways/kafka/tools/kafka-tool/src/response.rs:205— kafka_message_gen::response::decode_body has cognitive complexity 42 (threshold 15). Drivers by points: loops 9 (21 pts), if/else 10 (20 pts), match/switch 1 (nesting depth added 22). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
kafka_message_gen::build_payload (cognitive 26) gateways/kafka/tools/kafka-tool/src/main.rs:242— kafka_message_gen::build_payload has cognitive complexity 26 (threshold 15). Drivers by points: if/else 14 (25 pts), match/switch 1 (nesting depth added 11). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
kafka_message_gen::cmd_generate (cognitive 18) gateways/kafka/tools/kafka-tool/src/main.rs:616— kafka_message_gen::cmd_generate has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (11 pts), loops 2 (3 pts), match/switch 1 (3 pts), boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
simulator::replica::new_shard (cognitive 28) core/simulator/src/replica.rs:143— simulator::replica::new_shard has cognitive complexity 28 (threshold 15). Drivers by points: if/else 17 (22 pts), loops 2 (4 pts), boolean chains 2 (nesting depth added 7). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
simulator::workload::state_checker::assert_partition_prefixes_agree (cognitive 20) core/simulator/src/workload/state_checker.rs:352— simulator::workload::state_checker::assert_partition_prefixes_agree has cognitive complexity 20 (threshold 15). Drivers by points: if/else 5 (14 pts), loops 3 (6 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
simulator::bin::workload-fuzz::network_options (cognitive 16) core/simulator/src/bin/workload-fuzz.rs:459— simulator::bin::workload-fuzz::network_options has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, boolean chains 2. To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
simulator::workload::run_with_faults (cognitive 16) core/simulator/src/workload/mod.rs:734— simulator::workload::run_with_faults has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (11 pts), loops 3 (5 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
consensus::view_change_quorum::dvc_suffix_decode (cognitive 27) core/consensus/src/view_change_quorum.rs:343— consensus::view_change_quorum::dvc_suffix_decode has cognitive complexity 27 (threshold 15). Drivers by points: if/else 10 (23 pts), boolean chains 3, loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
consensus::dvc_merge::merge_dvc_quorum (cognitive 24) core/consensus/src/dvc_merge.rs:401— consensus::dvc_merge::merge_dvc_quorum has cognitive complexity 24 (threshold 15). Drivers by points: if/else 13 (22 pts), boolean chains 1, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
consensus::dvc_merge::tally_op (cognitive 21) core/consensus/src/dvc_merge.rs:175— consensus::dvc_merge::tally_op has cognitive complexity 21 (threshold 15). Drivers by points: if/else 7 (13 pts), match/switch 1 (4 pts), boolean chains 3, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
consensus::dvc_merge::committed_elsewhere (cognitive 21) core/consensus/src/dvc_merge.rs:324— consensus::dvc_merge::committed_elsewhere has cognitive complexity 21 (threshold 15). Drivers by points: if/else 7 (16 pts), loops 3 (4 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ServerHandle::start (cognitive 18) core/integration/src/harness/handle/server.rs:883— ServerHandle::start has cognitive complexity 18 (threshold 15). Drivers by points: if/else 11 (13 pts), boolean chains 5 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
ServerHandle::set_protocol_addresses (cognitive 17) core/integration/src/harness/handle/server.rs:402— ServerHandle::set_protocol_addresses has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14 (16 pts), boolean chains 1 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
ServerHandle::build_envs (cognitive 16) core/integration/src/harness/handle/server.rs:281— ServerHandle::build_envs has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10 (12 pts), loops 2, boolean chains 1, match/switch 1 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
ServerHandle::start_dependents (cognitive 16) core/integration/src/harness/handle/server.rs:777— ServerHandle::start_dependents has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (14 pts), boolean chains 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Duplicated block (24 lines × 2) core/common/src/types/options/mod.rs:666— core/common/src/types/options/mod.rs:666-689 | core/common/src/types/options/mod.rs:904-927 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (24 lines × 2) core/sdk/src/tcp/tcp_client.rs:1159— core/sdk/src/tcp/tcp_client.rs:1159-1182 | core/sdk/src/websocket/websocket_client.rs:829-852 — `core/sdk/src/tcp/tcp_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 9 separate duplicated blocks between them, totalling at least 158 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (24 lines × 2) foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/MessagesClient.java:131— foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/MessagesClient.java:131-188 | foreign/java/java-sdk/src/main/java/org/apache/iggy/client/blocking/MessagesClient.java:43-66 — `foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/MessagesClient.java` and `foreign/java/java-sdk/src/main/java/org/apache/iggy/client/blocking/MessagesClient.java` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 1 separate duplicated blocks between them, totalling at least 58 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/MessagesClient.java:131` it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows — the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members' bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run — a one-line delegation has no helper inside it to lift — so generate the run from the set it enumerates, or accept it and keep each member's own documentation with it. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (24 lines × 2) examples/python/basic/producer.py:85— examples/python/basic/producer.py:85-108 | examples/python/getting-started/producer.py:195-218 — `examples/python/basic/producer.py` and `examples/python/getting-started/producer.py` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 3 separate duplicated blocks between them, totalling at least 57 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at `examples/python/basic/producer.py:85` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (20 lines × 2) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:806— foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:806-825 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:903-922 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:806` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (20 lines × 2) core/integration/src/harness/handle/connectors_runtime.rs:214— core/integration/src/harness/handle/connectors_runtime.rs:214-233 | core/integration/src/harness/handle/server.rs:1027-1046 — before extracting anything, compare `core/integration/src/harness/handle/connectors_runtime.rs` and `core/integration/src/harness/handle/server.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 46 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (20 lines × 2) core/partitions/src/iggy_partition.rs:5607— core/partitions/src/iggy_partition.rs:5607-5626 | core/partitions/src/iggy_partition.rs:8467-8486 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (20 lines × 2) gateways/kafka/src/protocol/bounds_guard.rs:912— gateways/kafka/src/protocol/bounds_guard.rs:912-931 | gateways/kafka/src/protocol/bounds_guard.rs:994-1013 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (19 lines × 2) core/binary_protocol/src/consensus/header.rs:392— core/binary_protocol/src/consensus/header.rs:392-410 | core/binary_protocol/src/consensus/header.rs:418-436 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (19 lines × 2) core/binary_protocol/src/requests/users/login_register.rs:118— core/binary_protocol/src/requests/users/login_register.rs:118-136 | core/binary_protocol/src/requests/users/login_user.rs:102-120 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (19 lines × 2) core/partitions/src/iggy_index_writer.rs:56— core/partitions/src/iggy_index_writer.rs:56-74 | core/partitions/src/messages_writer.rs:68-86 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (19 lines × 2) examples/go/getting-started/consumer/main.go:41— examples/go/getting-started/consumer/main.go:41-59 | examples/go/getting-started/producer/main.go:43-61 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice. The matched lines also register a scope-exit action (a `defer`-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead — before the caller uses what it releases — so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register.
Duplicated block (13 lines × 3) foreign/python/src/config.rs:312— foreign/python/src/config.rs:312-324 | foreign/python/src/config.rs:663-675 | foreign/python/src/config.rs:1325-1337 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (13 lines × 3) core/connectors/sdk/src/decoders/proto.rs:175— core/connectors/sdk/src/decoders/proto.rs:175-187 | core/connectors/sdk/src/encoders/proto.rs:207-222 | core/connectors/sdk/src/transforms/proto_convert.rs:201-213 — `core/connectors/sdk/src/decoders/proto.rs` and `core/connectors/sdk/src/encoders/proto.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 11 separate duplicated blocks between them, totalling at least 151 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (13 lines × 3) core/connectors/sdk/src/decoders/proto.rs:67— core/connectors/sdk/src/decoders/proto.rs:67-79 | core/connectors/sdk/src/encoders/proto.rs:89-101 | core/connectors/sdk/src/transforms/proto_convert.rs:92-104 — `core/connectors/sdk/src/decoders/proto.rs` and `core/connectors/sdk/src/encoders/proto.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 11 separate duplicated blocks between them, totalling at least 151 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (13 lines × 3) foreign/java/external-processors/iggy-connector-flink/iggy-flink-examples/src/main/java/org/apache/iggy/flink/example/MultiStreamJoinJob.java:148— foreign/java/external-processors/iggy-connector-flink/iggy-flink-examples/src/main/java/org/apache/iggy/flink/example/MultiStreamJoinJob.java:148-160 | foreign/java/external-processors/iggy-connector-flink/iggy-flink-examples/src/main/java/org/apache/iggy/flink/example/StreamTransformJob.java:128-140 | foreign/java/external-processors/iggy-connector-flink/iggy-flink-examples/src/main/java/org/apache/iggy/flink/example/WordCountJob.java:123-135 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from all 3 call sites, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/java/external-processors/iggy-connector-flink/iggy-flink-examples/src/main/java/org/apache/iggy/flink/example/MultiStreamJoinJob.java:148` it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (12–13 lines × 2) core/connectors/sdk/src/decoders/proto.rs:196— core/connectors/sdk/src/decoders/proto.rs:196-207 | core/connectors/sdk/src/encoders/proto.rs:231-243 — `core/connectors/sdk/src/decoders/proto.rs` and `core/connectors/sdk/src/encoders/proto.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 11 separate duplicated blocks between them, totalling at least 151 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (12–13 lines × 2) core/sdk/src/quic/quic_client.rs:748— core/sdk/src/quic/quic_client.rs:748-760 | core/sdk/src/websocket/websocket_client.rs:862-873 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (12–13 lines × 2) core/server/src/partition_helpers.rs:502— core/server/src/partition_helpers.rs:502-513 | core/server/src/partition_helpers.rs:837-849 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (12–13 lines × 2) core/server_common/src/bootstrap.rs:127— core/server_common/src/bootstrap.rs:127-138 | core/server_common/src/fs_utils.rs:101-113 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (12 lines × 3) core/bench/src/analytics/report_builder.rs:214— core/bench/src/analytics/report_builder.rs:214-225 | core/common/src/wire_conversions.rs:458-469 | foreign/cpp/src/type_conversion.rs:256-267 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made 3 times.
Duplicated block (12 lines × 3) core/sdk/src/clients/producer.rs:957— core/sdk/src/clients/producer.rs:957-968 | core/sdk/src/clients/producer.rs:997-1008 | core/sdk/src/clients/producer.rs:1029-1040 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (12 lines × 3) foreign/python/src/config.rs:165— foreign/python/src/config.rs:165-176 | foreign/python/src/config.rs:461-472 | foreign/python/src/config.rs:1017-1028 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (12 lines × 3) examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java:342— examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java:342-353 | examples/java/src/main/java/org/apache/iggy/examples/multitenant/producer/MultiTenantProducer.java:355-366 | examples/java/src/main/java/org/apache/iggy/examples/sinkdataproducer/SinkDataProducer.java:161-172 — before extracting anything, compare `examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java` and `examples/java/src/main/java/org/apache/iggy/examples/multitenant/producer/MultiTenantProducer.java` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 57 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Read the line range as the matched WINDOW rather than a finished unit: at `examples/java/src/main/java/org/apache/iggy/examples/sinkdataproducer/SinkDataProducer.java:161` it runs out through the closing brace of the declaration holding it — the window is that declaration's tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. The `return` at the foot of the matched lines is the enclosing body's own terminal exit, not an early one: it moves with them unchanged, and each site calls the extracted unit from the position that `return` occupied — no decision has to be handed back and re-acted on. ★ These copies have DRIFTED, and that is worth reading before extracting anything: just before the matched lines, `examples/java/src/main/java/org/apache/iggy/examples/sinkdataproducer/SinkDataProducer.java:160` calls `toLowerCase`, `replace` and `examples/java/src/main/java/org/apache/iggy/examples/multitenant/consumer/MultiTenantConsumer.java:341` does not — after which the two agree again for 2 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live.
Duplicated block (9 lines × 3) core/binary_protocol/src/primitives/permissions.rs:107— core/binary_protocol/src/primitives/permissions.rs:107-115 | core/binary_protocol/src/primitives/permissions.rs:160-168 | core/binary_protocol/src/primitives/permissions.rs:219-227 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (9 lines × 3) core/sdk/src/quic/quic_client.rs:445— core/sdk/src/quic/quic_client.rs:445-453 | core/sdk/src/tcp/tcp_client.rs:374-382 | core/sdk/src/websocket/websocket_client.rs:441-449 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/tcp/tcp_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 134 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (9 lines × 3) core/sdk/src/http/http_client.rs:289— core/sdk/src/http/http_client.rs:289-297 | core/sdk/src/quic/quic_client.rs:605-613 | core/sdk/src/tcp/tcp_client.rs:555-563 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/tcp/tcp_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 134 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (9 lines × 3) examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java:52— examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java:52-60 | examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/consumer/MessageEnvelopeConsumer.java:61-69 | examples/java/src/main/java/org/apache/iggy/examples/messageheaders/consumer/MessageHeadersConsumer.java:64-72 — before extracting anything, compare `examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java` and `examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/consumer/MessageEnvelopeConsumer.java` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 86 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (12 lines × 2 locations) foreign/node/src/wire/stream/get-stream.command.ts:27— foreign/node/src/wire/stream/get-stream.command.ts:27 · foreign/node/src/wire/user/get-user.command.ts:28 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (12 lines × 2 locations) foreign/node/src/wire/system/get-stats.command.ts:67— foreign/node/src/wire/system/get-stats.command.ts:67 · foreign/node/src/wire/system/get-stats.command.ts:80 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (12 lines × 2 locations) foreign/node/src/wire/user/permissions.utils.ts:291— foreign/node/src/wire/user/permissions.utils.ts:291 · foreign/node/src/wire/user/permissions.utils.ts:349 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (12 lines × 2 locations) web/src/lib/components/Modals/InspectMessage.svelte:52— web/src/lib/components/Modals/InspectMessage.svelte:52 · web/src/lib/components/Modals/InspectMessage.svelte:65 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
kafka_message_gen::build_payload (cyclomatic 37) gateways/kafka/tools/kafka-tool/src/main.rs:242— kafka_message_gen::build_payload has cyclomatic complexity 37 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
kafka_message_gen::response::decode_body (cyclomatic 27) gateways/kafka/tools/kafka-tool/src/response.rs:205— kafka_message_gen::response::decode_body has cyclomatic complexity 27 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
kafka_message_gen::run_send (cyclomatic 17) gateways/kafka/tools/kafka-tool/src/main.rs:730— kafka_message_gen::run_send has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
iggy_connectors::source::source_forwarding_loop (cyclomatic 25) core/connectors/runtime/src/source.rs:555— iggy_connectors::source::source_forwarding_loop has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
iggy_connectors::sink::process_messages (cyclomatic 23) core/connectors/runtime/src/sink.rs:548— iggy_connectors::sink::process_messages has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
iggy_connectors::main (cyclomatic 21) core/connectors/runtime/src/main.rs:121— iggy_connectors::main has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
TcpClient::send_raw (cyclomatic 25) core/sdk/src/tcp/tcp_client.rs:1317— TcpClient::send_raw has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
TcpClient::connect_inner (cyclomatic 21) core/sdk/src/tcp/tcp_client.rs:617— TcpClient::connect_inner has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
TcpClient::send_raw_with_response (cyclomatic 18) core/sdk/src/tcp/tcp_client.rs:222— TcpClient::send_raw_with_response has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
PrepareJournal::scan (cyclomatic 21) core/journal/src/prepare_journal.rs:411— PrepareJournal::scan has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
PrepareJournal::truncate_from (cyclomatic 17) core/journal/src/prepare_journal.rs:778— PrepareJournal::truncate_from has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
PrepareJournal::drain (cyclomatic 17) core/journal/src/prepare_journal.rs:930— PrepareJournal::drain has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
message_bus::installer::replica::install_replica_conn (cyclomatic 21) core/message_bus/src/installer/replica.rs:326— message_bus::installer::replica::install_replica_conn has cyclomatic complexity 21 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
message_bus::transports::ws::run_pump (cyclomatic 18) core/message_bus/src/transports/ws.rs:186— message_bus::transports::ws::run_pump has cyclomatic complexity 18 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
message_bus::transports::wss::run_pump (cyclomatic 18) core/message_bus/src/transports/wss.rs:334— message_bus::transports::wss::run_pump has cyclomatic complexity 18 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
PartitionPrepareJournal::reset_with_segment_checkpoint (cyclomatic 18) core/journal/src/partition_journal/segments.rs:172— PartitionPrepareJournal::reset_with_segment_checkpoint has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
PartitionPrepareJournal::rewrite (cyclomatic 18) core/journal/src/partition_journal.rs:1353— PartitionPrepareJournal::rewrite has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
PartitionPrepareJournal::append_batch_inner (cyclomatic 17) core/journal/src/partition_journal.rs:771— PartitionPrepareJournal::append_batch_inner has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
WebSocketClient::send_raw_with_response (cognitive 90) core/sdk/src/websocket/websocket_client.rs:162— WebSocketClient::send_raw_with_response has cognitive complexity 90 (threshold 15). Drivers by points: if/else 32 (61 pts), match/switch 6 (19 pts), boolean chains 5, loops 2 (5 pts) (nesting depth added 45). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
WebSocketClient::connect_inner (cognitive 30) core/sdk/src/websocket/websocket_client.rs:599— WebSocketClient::connect_inner has cognitive complexity 30 (threshold 15). Drivers by points: if/else 8 (19 pts), match/switch 2 (8 pts), loops 2 (3 pts) (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
WebSocketClient::send_raw_request (cognitive 16) core/sdk/src/websocket/websocket_client.rs:1072— WebSocketClient::send_raw_request has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (12 pts), match/switch 2 (3 pts), loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PrepareJournal::scan (cognitive 39) core/journal/src/prepare_journal.rs:411— PrepareJournal::scan has cognitive complexity 39 (threshold 15). Drivers by points: if/else 14 (32 pts), boolean chains 4, match/switch 1 (2 pts), loops 1 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PrepareJournal::truncate_from (cognitive 23) core/journal/src/prepare_journal.rs:778— PrepareJournal::truncate_from has cognitive complexity 23 (threshold 15). Drivers by points: if/else 11 (16 pts), loops 4, match/switch 1 (2 pts), boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PrepareJournal::drain (cognitive 23) core/journal/src/prepare_journal.rs:930— PrepareJournal::drain has cognitive complexity 23 (threshold 15). Drivers by points: if/else 10 (15 pts), loops 5, match/switch 1 (2 pts), boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Logging::cleanup_log_files (cognitive 28) core/server_common/src/log/logger.rs:618— Logging::cleanup_log_files has cognitive complexity 28 (threshold 15). Drivers by points: if/else 12 (19 pts), loops 4 (6 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Logging::read_log_files (cognitive 19) core/server_common/src/log/logger.rs:550— Logging::read_log_files has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (11 pts), match/switch 4 (7 pts), loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Logging::late_init (cognitive 17) core/server_common/src/log/logger.rs:227— Logging::late_init has cognitive complexity 17 (threshold 15). Drivers by points: if/else 12 (17 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connector_influxdb_source::v3::poll (cognitive 21) core/connectors/sources/influxdb_source/src/v3.rs:439— iggy_connector_influxdb_source::v3::poll has cognitive complexity 21 (threshold 15). Drivers by points: if/else 12 (14 pts), boolean chains 4, match/switch 2 (3 pts) (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
iggy_connector_influxdb_source::row::parse_csv_rows (cognitive 20) core/connectors/sources/influxdb_source/src/row.rs:58— iggy_connector_influxdb_source::row::parse_csv_rows has cognitive complexity 20 (threshold 15). Drivers by points: if/else 7 (15 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connector_influxdb_source::v2::process_rows (cognitive 19) core/connectors/sources/influxdb_source/src/v2.rs:786— iggy_connector_influxdb_source::v2::process_rows has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (12 pts), match/switch 2 (6 pts), loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
D30 · Dependency Vulnerabilities· Medium vulnerability · ×3
Change coupling: partition_helpers.rs ↔ REDACTED core/server/src/partition_helpers.rs— `core/server/src/partition_helpers.rs` and `core/shard/src/lib.rs` change together 67% of the time (8 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are `bad22c03` feat(server): dedup partition writes with per-group client table slic…; `e9b1c9a1` fix(cluster): stop a late partition materialiser from wedging its gro…; `db14a4b1` fix(cluster): make the advertised leader accept partition writes (#3985) — run `git show` on any of them.
Change coupling: benchmark_producer.rs ↔ common.rs core/bench/src/actors/producer/benchmark_producer.rs— `core/bench/src/actors/producer/benchmark_producer.rs` and `core/bench/src/args/common.rs` change together 58% of the time (7 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 7 shared commits counted here, the most recent 3 are `fcc5a447` feat(bench): prettier table output (#3090); `8294ccef` feat(bench): add high-level consumer API for benchmarking (#1855); `f859e170` Add cache metrics to `Stats` and p9999 latency tracking to `Benchmark… (at that commit the files were still `bench/src/actors/producer.rs` and `bench/src/args/common.rs`) — run `git show` on any of them.
Change coupling: iggy_partition.rs ↔ metrics.rs core/partitions/src/iggy_partition.rs— `core/partitions/src/iggy_partition.rs` and `core/shard/src/metrics.rs` change together 55% of the time (6 of the 11 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well — a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency — the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE — the registration is the link, and it is meant not to be an import — and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are `22778643` fix(shard): drive metadata repair and the commit walk from the tick (…; `9914f5a8` fix(shard): drive partition repair and the commit walk from the tick …; `bad22c03` feat(server): dedup partition writes with per-group client table slic… — run `git show` on any of them.
Duplicated block (29 lines × 2) foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Rented.cs:185— foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Rented.cs:185-213 | foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.cs:469-497 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Rented.cs:185` it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows — the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members' bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run — a one-line delegation has no helper inside it to lift — so generate the run from the set it enumerates, or accept it and keep each member's own documentation with it.
Duplicated block (29 lines × 2) core/message_bus/src/transports/ws.rs:187— core/message_bus/src/transports/ws.rs:187-215 | core/message_bus/src/transports/wss.rs:335-363 — before extracting anything, compare `core/message_bus/src/transports/ws.rs` and `core/message_bus/src/transports/wss.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 81 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (29 lines × 2) core/bench/src/actors/consumer/benchmark_consumer.rs:96— core/bench/src/actors/consumer/benchmark_consumer.rs:96-124 | core/bench/src/actors/producer/benchmark_producer.rs:113-141 — `core/bench/src/actors/consumer/benchmark_consumer.rs` and `core/bench/src/actors/producer/benchmark_producer.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 201 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (22 lines × 2) core/binary_protocol/src/requests/partitions/create_partitions_with_assignments.rs:84— core/binary_protocol/src/requests/partitions/create_partitions_with_assignments.rs:84-105 | core/binary_protocol/src/requests/topics/create_topic_with_assignments.rs:119-140 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (22 lines × 2) core/server_common/src/consensus_message.rs:290— core/server_common/src/consensus_message.rs:290-311 | core/server_common/src/consensus_message.rs:329-350 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (22 lines × 2) gateways/kafka/src/protocol/bounds_guard.rs:494— gateways/kafka/src/protocol/bounds_guard.rs:494-515 | gateways/kafka/src/protocol/bounds_guard.rs:588-609 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8 lines × 4) core/message_bus/src/lifecycle/connection_registry.rs:561— core/message_bus/src/lifecycle/connection_registry.rs:561-568 | core/message_bus/src/lifecycle/connection_registry.rs:592-599 | core/message_bus/src/lifecycle/connection_registry.rs:891-898 | core/message_bus/src/lifecycle/connection_registry.rs:918-925 — all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (8 lines × 4) core/message_bus/src/client_listener/tcp.rs:67— core/message_bus/src/client_listener/tcp.rs:67-74 | core/message_bus/src/client_listener/tcp_tls.rs:109-118 | core/message_bus/src/client_listener/ws.rs:81-88 | core/message_bus/src/client_listener/wss.rs:103-112 — before extracting anything, compare `core/message_bus/src/client_listener/tcp.rs` and `core/message_bus/src/client_listener/tcp_tls.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 32 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (8 lines × 4) foreign/go/client/tcp/tcp_access_token_management.go:47— foreign/go/client/tcp/tcp_access_token_management.go:47-54 | foreign/go/client/tcp/tcp_clients_management.go:28-35 | foreign/go/client/tcp/tcp_stream_management.go:29-36 | foreign/go/client/tcp/tcp_user_management.go:41-48 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from all 4 call sites, so a change lands once.
Duplicated block (8 lines × 3) core/connectors/sinks/mongodb_sink/src/lib.rs:587— core/connectors/sinks/mongodb_sink/src/lib.rs:587-594 | core/connectors/sinks/postgres_sink/src/lib.rs:556-563 | core/connectors/sources/postgres_source/src/lib.rs:2492-2499 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made 3 times.
Duplicated block (8 lines × 3) foreign/java/java-sdk/src/main/java/org/apache/iggy/serde/BytesDeserializer.java:655— foreign/java/java-sdk/src/main/java/org/apache/iggy/serde/BytesDeserializer.java:655-662 | foreign/java/java-sdk/src/main/java/org/apache/iggy/serde/BytesDeserializer.java:708-715 | foreign/java/java-sdk/src/main/java/org/apache/iggy/serde/BytesDeserializer.java:722-729 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (8 lines × 3) core/bench/src/actors/consumer/benchmark_consumer.rs:288— core/bench/src/actors/consumer/benchmark_consumer.rs:288-295 | core/bench/src/actors/producer/benchmark_producer.rs:298-305 | core/bench/src/actors/producing_consumer/benchmark_producing_consumer.rs:375-382 — `core/bench/src/actors/consumer/benchmark_consumer.rs` and `core/bench/src/actors/producer/benchmark_producer.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 201 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (26 lines × 2) core/ai/mcp/src/stream.rs:38— core/ai/mcp/src/stream.rs:38-63 | core/connectors/runtime/src/stream.rs:48-73 — before extracting anything, compare `core/ai/mcp/src/stream.rs` and `core/connectors/runtime/src/stream.rs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 52 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (26 lines × 2) core/common/src/types/consumer/consumer_group_offsets.rs:25— core/common/src/types/consumer/consumer_group_offsets.rs:25-50 | core/common/src/types/consumer/consumer_offsets.rs:24-49 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (26 lines × 2) examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/producer/MessageEnvelopeProducer.java:62— examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/producer/MessageEnvelopeProducer.java:62-87 | examples/java/src/main/java/org/apache/iggy/examples/messageheaders/producer/MessageHeadersProducer.java:63-88 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any `return` inside it is the body's own exit and keeps its meaning in the moved unit.
Duplicated block (10 lines × 3) core/connectors/sdk/src/transforms/add_fields.rs:56— core/connectors/sdk/src/transforms/add_fields.rs:56-65 | core/connectors/sdk/src/transforms/delete_fields.rs:57-66 | core/connectors/sdk/src/transforms/update_fields.rs:67-76 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from all 3 call sites, so a change lands once.
Duplicated block (10 lines × 3) core/partitions/src/segment_recovery.rs:2245— core/partitions/src/segment_recovery.rs:2245-2254 | core/partitions/src/segment_recovery.rs:2370-2379 | core/partitions/src/segment_recovery.rs:2381-2390 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (10 lines × 3) foreign/python/src/config.rs:215— foreign/python/src/config.rs:215-224 | foreign/python/src/config.rs:511-520 | foreign/python/src/config.rs:1067-1076 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (7 lines × 2 locations) foreign/node/src/wire/cluster/cluster.utils.ts:69— foreign/node/src/wire/cluster/cluster.utils.ts:69 · foreign/node/src/wire/cluster/cluster.utils.ts:133 — all 2 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (7 lines × 2 locations) foreign/node/src/wire/message/iggy-header.utils.ts:87— foreign/node/src/wire/message/iggy-header.utils.ts:87 · foreign/node/src/wire/message/iggy-header.utils.ts:157 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (7 lines × 2 locations) foreign/node/src/wire/user/permissions.utils.ts:159— foreign/node/src/wire/user/permissions.utils.ts:159 · foreign/node/src/wire/user/permissions.utils.ts:243 — all 2 copies are in the same file, and the CITED SPAN is a run of DECLARATIONS inside a construct — the members of a type, or the entries of an object or array literal — with no statement anywhere in it. Do not read this as an extract-a-helper row: nothing here executes, so there is no call site, and a call expression cannot stand where a member declaration or a literal's entry was. What repeats is a SHAPE, and which shape decides the move. Where the copies declare the same members, the repetition is a missing common ancestor: give it a base type, an interface both extend, a generic instantiated twice, or — where the copies are a literal's entries rather than a type's members — one shared constant each site spreads or refers to, so the set is written once. Where they declare DIFFERENT members and only the form is shared — a decorator and its options, an annotation, a registration table's keys — the form is prescribed by a framework or a schema rather than copied, and the only collapse available is to generate the declarations from that schema; where you do not own the generator, this is the cost of the framework and there is nothing to extract. Check which of the two it is before acting: these copies still drift apart the first time only one of them is edited, which is why the repetition is reported, but the sentence to act on is not the same in both cases.
Dead file (~63 LoC) web/src/lib/components/Paginator.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~63 LoC) web/src/lib/components/ThemeController.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 2 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Header.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~63 LoC) web/src/lib/utils/formatters/uuidFormatter.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
X18 · Disposal-pattern correctness· Owned disposable field is never released · ×3
Owned disposable field is never released foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs:59— `TcpMessageStream` implements `IDisposable` — so it has told every caller it holds something worth releasing — and it constructs `_connectGate` itself (line 59), which makes that instance its own. But `_connectGate` is named in none of the methods the disposal search covered: `Dispose` (line 119), `SetConnectionState` (line 1476) — that is `Dispose` plus every method `Dispose` calls BY NAME, so a release reached through an interface, a delegate or a base class is not followed and is worth checking before acting. On what was read, the type's disposal releases everything except the one thing it owns. A disposable the owner never disposes is held until finalization if its type has a finalizer, and forever if it does not — which for a synchronisation primitive, a timer, a stream or a handle means the resource accumulates once per instance for the life of the process. Release it in `Dispose` (`_connectGate?.Dispose();`), or, if it truly does not need releasing, drop `IDisposable` from the type so the claim and the behaviour agree.
Owned disposable field is never released foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs:61— `TcpMessageStream` implements `IDisposable` — so it has told every caller it holds something worth releasing — and it constructs `_connectionSemaphore` itself (line 61), which makes that instance its own. But `_connectionSemaphore` is named in none of the methods the disposal search covered: `Dispose` (line 119), `SetConnectionState` (line 1476) — that is `Dispose` plus every method `Dispose` calls BY NAME, so a release reached through an interface, a delegate or a base class is not followed and is worth checking before acting. On what was read, the type's disposal releases everything except the one thing it owns. A disposable the owner never disposes is held until finalization if its type has a finalizer, and forever if it does not — which for a synchronisation primitive, a timer, a stream or a handle means the resource accumulates once per instance for the life of the process. Release it in `Dispose` (`_connectionSemaphore?.Dispose();`), or, if it truly does not need releasing, drop `IDisposable` from the type so the claim and the behaviour agree.
Owned disposable field is never released foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs:64— `TcpMessageStream` implements `IDisposable` — so it has told every caller it holds something worth releasing — and it constructs `_sendingSemaphore` itself (line 64), which makes that instance its own. But `_sendingSemaphore` is named in none of the methods the disposal search covered: `Dispose` (line 119), `SetConnectionState` (line 1476) — that is `Dispose` plus every method `Dispose` calls BY NAME, so a release reached through an interface, a delegate or a base class is not followed and is worth checking before acting. On what was read, the type's disposal releases everything except the one thing it owns. A disposable the owner never disposes is held until finalization if its type has a finalizer, and forever if it does not — which for a synchronisation primitive, a timer, a stream or a handle means the resource accumulates once per instance for the life of the process. Release it in `Dispose` (`_sendingSemaphore?.Dispose();`), or, if it truly does not need releasing, drop `IDisposable` from the type so the claim and the behaviour agree.
iggy_connector_clickhouse_sink::binary::serialize_value (cyclomatic 54) core/connectors/sinks/clickhouse_sink/src/binary.rs:83— iggy_connector_clickhouse_sink::binary::serialize_value has cyclomatic complexity 54 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
iggy_connector_clickhouse_sink::schema::parse_type_inner (cyclomatic 41) core/connectors/sinks/clickhouse_sink/src/schema.rs:155— iggy_connector_clickhouse_sink::schema::parse_type_inner has cyclomatic complexity 41 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
QuicClient::send_raw_with_response (cyclomatic 44) core/sdk/src/quic/quic_client.rs:168— QuicClient::send_raw_with_response has cyclomatic complexity 44 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
QuicClient::connect_inner (cyclomatic 21) core/sdk/src/quic/quic_client.rs:672— QuicClient::connect_inner has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
metadata::stm::authz::authorize (cyclomatic 39) core/metadata/src/stm/authz.rs:128— metadata::stm::authz::authorize has cyclomatic complexity 39 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
metadata::impls::recovery::recover (cyclomatic 21) core/metadata/src/impls/recovery.rs:355— metadata::impls::recovery::recover has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyConsumer::poll_next (cyclomatic 28) core/sdk/src/clients/consumer.rs:1533— IggyConsumer::poll_next has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyConsumer::create_poll_messages_future (cyclomatic 20) core/sdk/src/clients/consumer.rs:1214— IggyConsumer::create_poll_messages_future has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
InfluxDbSource::open (cyclomatic 24) core/connectors/sources/influxdb_source/src/lib.rs:258— InfluxDbSource::open has cyclomatic complexity 24 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
InfluxDbSource::poll (cyclomatic 17) core/connectors/sources/influxdb_source/src/lib.rs:469— InfluxDbSource::poll has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
simulator::replica::new_shard (cyclomatic 19) core/simulator/src/replica.rs:143— simulator::replica::new_shard has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
simulator::bin::workload-fuzz::network_options (cyclomatic 17) core/simulator/src/bin/workload-fuzz.rs:459— simulator::bin::workload-fuzz::network_options has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
QuicClient::send_raw_with_response (cognitive 90) core/sdk/src/quic/quic_client.rs:168— QuicClient::send_raw_with_response has cognitive complexity 90 (threshold 15). Drivers by points: if/else 32 (61 pts), match/switch 6 (19 pts), boolean chains 5, loops 2 (5 pts) (nesting depth added 45). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
QuicClient::connect_inner (cognitive 52) core/sdk/src/quic/quic_client.rs:672— QuicClient::connect_inner has cognitive complexity 52 (threshold 15). Drivers by points: if/else 13 (36 pts), match/switch 4 (11 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 31). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shard::dispatch_vsr_actions (cognitive 42) core/shard/src/lib.rs:11567— shard::dispatch_vsr_actions has cognitive complexity 42 (threshold 15). Drivers by points: if/else 8 (24 pts), loops 6 (13 pts), match/switch 2 (5 pts) (nesting depth added 26). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
shard::dispatch_partition_journal_actions (cognitive 26) core/shard/src/lib.rs:11873— shard::dispatch_partition_journal_actions has cognitive complexity 26 (threshold 15). Drivers by points: if/else 4 (12 pts), loops 5 (12 pts), match/switch 1 (2 pts) (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
InfluxDbSource::poll (cognitive 40) core/connectors/sources/influxdb_source/src/lib.rs:469— InfluxDbSource::poll has cognitive complexity 40 (threshold 15). Drivers by points: if/else 15 (29 pts), match/switch 5 (11 pts) (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
InfluxDbSource::open (cognitive 23) core/connectors/sources/influxdb_source/src/lib.rs:258— InfluxDbSource::open has cognitive complexity 23 (threshold 15). Drivers by points: if/else 12 (13 pts), boolean chains 7, match/switch 3 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
PacketSimulator::step (cognitive 39) core/simulator/src/packet.rs:667— PacketSimulator::step has cognitive complexity 39 (threshold 15). Drivers by points: if/else 8 (32 pts), loops 3 (6 pts), boolean chains 1 (nesting depth added 27). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PacketSimulator::auto_partition_network (cognitive 23) core/simulator/src/packet.rs:819— PacketSimulator::auto_partition_network has cognitive complexity 23 (threshold 15). Drivers by points: loops 6 (11 pts), if/else 4 (9 pts), boolean chains 2, match/switch 1 (nesting depth added 10). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline.
metadata::stm::authz::authorize (cognitive 34) core/metadata/src/stm/authz.rs:128— metadata::stm::authz::authorize has cognitive complexity 34 (threshold 15). Drivers by points: if/else 16 (31 pts), match/switch 2 (3 pts) (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
metadata::impls::recovery::recover (cognitive 29) core/metadata/src/impls/recovery.rs:355— metadata::impls::recovery::recover has cognitive complexity 29 (threshold 15). Drivers by points: if/else 16 (23 pts), boolean chains 3, match/switch 2, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Simulator::step (cognitive 27) core/simulator/src/lib.rs:792— Simulator::step has cognitive complexity 27 (threshold 15). Drivers by points: if/else 6 (13 pts), match/switch 3 (9 pts), loops 3 (4 pts), boolean chains 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Simulator::build_inner (cognitive 16) core/simulator/src/lib.rs:364— Simulator::build_inner has cognitive complexity 16 (threshold 15). Drivers by points: loops 6 (9 pts), if/else 3 (7 pts) (nesting depth added 7). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline.
PostgresSource::poll_tables (cognitive 25) core/connectors/sources/postgres_source/src/lib.rs:806— PostgresSource::poll_tables has cognitive complexity 25 (threshold 15). Drivers by points: if/else 12 (21 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PostgresSource::process_row (cognitive 25) core/connectors/sources/postgres_source/src/lib.rs:1419— PostgresSource::process_row has cognitive complexity 25 (threshold 15). Drivers by points: if/else 12 (20 pts), boolean chains 4, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
DiskReadPlan::walk_segment (cognitive 23) core/partitions/src/poll_plan.rs:628— DiskReadPlan::walk_segment has cognitive complexity 23 (threshold 15). Drivers by points: if/else 10 (21 pts), boolean chains 1, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
DiskReadPlan::read_disk (cognitive 18) core/partitions/src/poll_plan.rs:497— DiskReadPlan::read_disk has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (12 pts), match/switch 3, boolean chains 2, loops 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
DorisSink::send_stream_load (cognitive 22) core/connectors/sinks/doris_sink/src/lib.rs:255— DorisSink::send_stream_load has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (14 pts), match/switch 3 (7 pts), loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
DorisSink::open (cognitive 17) core/connectors/sinks/doris_sink/src/lib.rs:941— DorisSink::open has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8 (11 pts), match/switch 4, boolean chains 2 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ElasticsearchSource::search_documents (cognitive 22) core/connectors/sources/elasticsearch_source/src/lib.rs:339— ElasticsearchSource::search_documents has cognitive complexity 22 (threshold 15). Drivers by points: if/else 8 (17 pts), boolean chains 3, loops 1 (2 pts) (nesting depth added 10). To reduce it, flatten the nesting: this score is depth rather than breadth — most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language's equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function.
ElasticsearchSource::source_state_to_internal_state (cognitive 16) core/connectors/sources/elasticsearch_source/src/lib.rs:261— ElasticsearchSource::source_state_to_internal_state has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10 (11 pts), boolean chains 5 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
iggy_connector_postgres_source::parse_record_columns (cognitive 19) core/connectors/sources/postgres_source/src/lib.rs:2344— iggy_connector_postgres_source::parse_record_columns has cognitive complexity 19 (threshold 15). Drivers by points: if/else 4 (10 pts), loops 3 (5 pts), match/switch 1 (3 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connector_postgres_source::substitute_query_tokens (cognitive 16) core/connectors/sources/postgres_source/src/lib.rs:2137— iggy_connector_postgres_source::substitute_query_tokens has cognitive complexity 16 (threshold 15). Drivers by points: if/else 3 (8 pts), loops 2 (3 pts), match/switch 1 (3 pts), boolean chains 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ProtoConvert::transform (cognitive 17) core/connectors/sdk/src/transforms/proto_convert.rs:730— ProtoConvert::transform has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10 (16 pts), match/switch 1 (nesting depth added 6). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
ProtoConvert::apply_field_transformations (cognitive 16) core/connectors/sdk/src/transforms/proto_convert.rs:487— ProtoConvert::apply_field_transformations has cognitive complexity 16 (threshold 15). Drivers by points: loops 2 (8 pts), if/else 4 (6 pts), match/switch 1 (2 pts) (nesting depth added 9). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline.
ClientTable::commit_request (cognitive 17) core/consensus/src/client_table.rs:1260— ClientTable::commit_request has cognitive complexity 17 (threshold 15). Drivers by points: if/else 11 (16 pts), boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ClientTable::decode (cognitive 16) core/consensus/src/client_table.rs:1945— ClientTable::decode has cognitive complexity 16 (threshold 15). Drivers by points: if/else 9 (12 pts), loops 2 (3 pts), match/switch 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
D4 · Code Duplication· Members sharing a duplicated core (6 members, 50+ identical tokens) · ×2
Members sharing a duplicated core (6 members, 50+ identical tokens) core/connectors/runtime/src/configs/connectors/http_provider.rs:136— core/connectors/runtime/src/configs/connectors/http_provider.rs:136-156 | core/connectors/runtime/src/configs/connectors/http_provider.rs:162-182 | core/connectors/runtime/src/configs/connectors/http_provider.rs:184-204 | core/connectors/runtime/src/configs/connectors/http_provider.rs:206-226 | core/connectors/runtime/src/configs/connectors/http_provider.rs:268-289 | core/connectors/runtime/src/configs/connectors/http_provider.rs:331-352 — These 6 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 6 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 6 times.
Members sharing a duplicated core (6 members, 50+ identical tokens) core/bench/dashboard/frontend/src/api/mod.rs:55— core/bench/dashboard/frontend/src/api/mod.rs:55-75 | core/bench/dashboard/frontend/src/api/mod.rs:77-97 | core/bench/dashboard/frontend/src/api/mod.rs:102-127 | core/bench/dashboard/frontend/src/api/mod.rs:165-185 | core/bench/dashboard/frontend/src/api/mod.rs:191-216 | core/bench/dashboard/frontend/src/api/mod.rs:229-250 — These 6 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 6 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 6 times.
D4 · Code Duplication· Members sharing a duplicated core (5 members, 50+ identical tokens) · ×2
Members sharing a duplicated core (5 members, 50+ identical tokens) core/binary_protocol/src/codec.rs:84— core/binary_protocol/src/codec.rs:84-102 | core/binary_protocol/src/codec.rs:110-128 | core/binary_protocol/src/codec.rs:136-154 | core/binary_protocol/src/codec.rs:187-205 | core/binary_protocol/src/codec.rs:213-231 — These 5 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 5 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 5 times.
Members sharing a duplicated core (5 members, 50+ identical tokens) foreign/go/internal/command/offset.go:42— foreign/go/internal/command/offset.go:42-75 | foreign/go/internal/command/offset.go:88-119 | foreign/go/internal/command/offset.go:132-164 | foreign/go/internal/command/partition.go:36-54 | foreign/go/internal/command/partition.go:66-84 — These 5 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 5 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 5 times.
Duplicated block (43 lines × 2) core/connectors/sdk/src/decoders/avro.rs:87— core/connectors/sdk/src/decoders/avro.rs:87-129 | core/connectors/sdk/src/encoders/avro.rs:77-119 — `core/connectors/sdk/src/decoders/avro.rs` and `core/connectors/sdk/src/encoders/avro.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 6 separate duplicated blocks between them, totalling at least 110 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (43 lines × 2) examples/python/getting-started/consumer.py:110— examples/python/getting-started/consumer.py:110-152 | examples/python/getting-started/producer.py:109-151 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (31 lines × 2) core/ai/mcp/src/log.rs:149— core/ai/mcp/src/log.rs:149-179 | core/connectors/runtime/src/log.rs:102-132 — before extracting anything, compare `core/ai/mcp/src/log.rs` and `core/connectors/runtime/src/log.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 87 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (31 lines × 2) core/ai/mcp/src/log.rs:185— core/ai/mcp/src/log.rs:185-215 | core/connectors/runtime/src/log.rs:138-168 — before extracting anything, compare `core/ai/mcp/src/log.rs` and `core/connectors/runtime/src/log.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 87 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (21 lines × 2) foreign/csharp/Iggy_SDK/JsonConverters/MessageConverter.cs:91— foreign/csharp/Iggy_SDK/JsonConverters/MessageConverter.cs:91-111 | foreign/csharp/Iggy_SDK/JsonConverters/UserHeadersConverter.cs:236-256 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (21 lines × 2) core/connectors/sources/http_source/src/server.rs:826— core/connectors/sources/http_source/src/server.rs:826-846 | core/connectors/sources/http_source/src/server.rs:922-942 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (19 lines × 3) core/integration/src/harness/handle/connectors_runtime.rs:183— core/integration/src/harness/handle/connectors_runtime.rs:183-201 | core/integration/src/harness/handle/mcp.rs:183-201 | core/integration/src/harness/handle/server.rs:989-1007 — before extracting anything, compare `core/integration/src/harness/handle/connectors_runtime.rs` and `core/integration/src/harness/handle/mcp.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 39 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (19 lines × 3) examples/python/basic/producer.py:63— examples/python/basic/producer.py:63-81 | examples/python/getting-started/producer.py:173-191 | examples/python/message-headers/common.py:121-139 — `examples/python/basic/producer.py` and `examples/python/getting-started/producer.py` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 3 separate duplicated blocks between them, totalling at least 57 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (18 lines × 3) core/connectors/sdk/src/decoders/proto.rs:95— core/connectors/sdk/src/decoders/proto.rs:95-112 | core/connectors/sdk/src/encoders/proto.rs:117-134 | core/connectors/sdk/src/transforms/proto_convert.rs:111-128 — `core/connectors/sdk/src/decoders/proto.rs` and `core/connectors/sdk/src/encoders/proto.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 11 separate duplicated blocks between them, totalling at least 151 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (18 lines × 3) gateways/kafka/src/protocol/bounds_guard.rs:433— gateways/kafka/src/protocol/bounds_guard.rs:433-450 | gateways/kafka/src/protocol/bounds_guard.rs:494-511 | gateways/kafka/src/protocol/bounds_guard.rs:588-605 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (15 lines × 3) core/binary_protocol/src/requests/users/login_register.rs:117— core/binary_protocol/src/requests/users/login_register.rs:117-131 | core/binary_protocol/src/requests/users/login_register_with_pat.rs:93-107 | core/binary_protocol/src/requests/users/login_user.rs:101-115 — before extracting anything, compare `core/binary_protocol/src/requests/users/login_register.rs` and `core/binary_protocol/src/requests/users/login_register_with_pat.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 33 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (15 lines × 3) core/connectors/sinks/elasticsearch_sink/src/lib.rs:372— core/connectors/sinks/elasticsearch_sink/src/lib.rs:372-386 | core/connectors/sinks/meilisearch_sink/src/lib.rs:785-799 | core/connectors/sinks/stdout_sink/src/lib.rs:74-88 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made 3 times.
Duplicated block (14 lines × 5) core/binary_protocol/src/codec.rs:85— core/binary_protocol/src/codec.rs:85-98 | core/binary_protocol/src/codec.rs:111-124 | core/binary_protocol/src/codec.rs:137-150 | core/binary_protocol/src/codec.rs:188-201 | core/binary_protocol/src/codec.rs:214-227 — all 5 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (14 lines × 5) core/binary_protocol/src/requests/consumer_groups/delete_consumer_group.rs:49— core/binary_protocol/src/requests/consumer_groups/delete_consumer_group.rs:49-62 | core/binary_protocol/src/requests/consumer_groups/get_consumer_group.rs:49-62 | core/binary_protocol/src/requests/consumer_groups/join_consumer_group.rs:49-62 | core/binary_protocol/src/requests/consumer_groups/leave_consumer_group.rs:49-62 | core/binary_protocol/src/requests/consumer_groups/sync_consumer_group.rs:52-65 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from all 5 call sites, so a change lands once.
Duplicated block (14 lines × 4) core/connectors/sources/postgres_source/src/lib.rs:1839— core/connectors/sources/postgres_source/src/lib.rs:1839-1852 | core/connectors/sources/postgres_source/src/lib.rs:1870-1883 | core/connectors/sources/postgres_source/src/lib.rs:1887-1900 | core/connectors/sources/postgres_source/src/lib.rs:1904-1917 — all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (14 lines × 4) core/binary_protocol/src/requests/streams/delete_stream.rs:30— core/binary_protocol/src/requests/streams/delete_stream.rs:30-43 | core/binary_protocol/src/requests/streams/get_stream.rs:30-43 | core/binary_protocol/src/requests/streams/purge_stream.rs:30-43 | core/binary_protocol/src/requests/topics/get_topics.rs:30-43 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 4 call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made 4 times.
Duplicated block (13–14 lines × 2) core/metadata/src/impls/metadata.rs:3594— core/metadata/src/impls/metadata.rs:3594-3607 | core/metadata/src/impls/metadata.rs:3634-3646 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (13–14 lines × 2) examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Producer/Utils.cs:69— examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Producer/Utils.cs:69-81 | examples/csharp/src/TcpTls/Iggy_SDK.Examples.TcpTls.Producer/Program.cs:114-127 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at `examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Producer/Utils.cs:69` it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows — the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members' bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run — a one-line delegation has no helper inside it to lift — so generate the run from the set it enumerates, or accept it and keep each member's own documentation with it.
Duplicated block (12–14 lines × 2) core/partitions/src/iggy_partition.rs:4962— core/partitions/src/iggy_partition.rs:4962-4975 | core/partitions/src/iggy_partition.rs:5175-5186 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (12–14 lines × 2) core/partitions/src/iggy_partition.rs:7310— core/partitions/src/iggy_partition.rs:7310-7323 | core/partitions/src/iggy_partition.rs:7777-7788 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (12 lines × 6) core/connectors/runtime/src/configs/connectors/http_provider.rs:145— core/connectors/runtime/src/configs/connectors/http_provider.rs:145-156 | core/connectors/runtime/src/configs/connectors/http_provider.rs:171-182 | core/connectors/runtime/src/configs/connectors/http_provider.rs:193-204 | core/connectors/runtime/src/configs/connectors/http_provider.rs:215-226 | core/connectors/runtime/src/configs/connectors/http_provider.rs:278-289 | core/connectors/runtime/src/configs/connectors/http_provider.rs:341-352 — all 6 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (12 lines × 6) core/bench/dashboard/frontend/src/api/mod.rs:62— core/bench/dashboard/frontend/src/api/mod.rs:62-73 | core/bench/dashboard/frontend/src/api/mod.rs:84-95 | core/bench/dashboard/frontend/src/api/mod.rs:114-125 | core/bench/dashboard/frontend/src/api/mod.rs:172-183 | core/bench/dashboard/frontend/src/api/mod.rs:203-214 | core/bench/dashboard/frontend/src/api/mod.rs:237-248 — all 6 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (11–12 lines × 2) core/connectors/runtime/src/sink.rs:612— core/connectors/runtime/src/sink.rs:612-623 | core/connectors/runtime/src/source.rs:945-955 — before extracting anything, compare `core/connectors/runtime/src/sink.rs` and `core/connectors/runtime/src/source.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 50 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (11–12 lines × 2) core/server_common/src/iobuf.rs:459— core/server_common/src/iobuf.rs:459-470 | core/server_common/src/iobuf.rs:495-505 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10–12 lines × 2) core/partitions/src/state_transfer.rs:2379— core/partitions/src/state_transfer.rs:2379-2390 | core/partitions/src/state_transfer.rs:2432-2441 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (10–12 lines × 2) core/sdk/src/tcp/tcp_client.rs:1288— core/sdk/src/tcp/tcp_client.rs:1288-1297 | core/sdk/src/websocket/websocket_client.rs:1033-1044 — `core/sdk/src/tcp/tcp_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 9 separate duplicated blocks between them, totalling at least 158 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (10 lines × 4) core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs:57— core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs:57-66 | core/binary_protocol/src/requests/consumer_offsets/get_consumer_offset.rs:51-60 | core/binary_protocol/src/requests/consumer_offsets/store_consumer_offset.rs:59-68 | core/binary_protocol/src/requests/messages/poll_messages.rs:65-74 — before extracting anything, compare `core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs` and `core/binary_protocol/src/requests/consumer_offsets/get_consumer_offset.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 32 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (10 lines × 4) core/message_bus/src/client_listener/tcp.rs:63— core/message_bus/src/client_listener/tcp.rs:63-73 | core/message_bus/src/client_listener/tcp_tls.rs:105-115 | core/message_bus/src/client_listener/wss.rs:99-109 | core/message_bus/src/replica/listener.rs:97-106 — before extracting anything, compare `core/message_bus/src/client_listener/tcp.rs` and `core/message_bus/src/client_listener/tcp_tls.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 32 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (9–10 lines × 2) core/bench/report/src/types/server_stats.rs:136— core/bench/report/src/types/server_stats.rs:136-145 | core/common/src/types/stats/mod.rs:140-148 — before extracting anything, compare `core/bench/report/src/types/server_stats.rs` and `core/common/src/types/stats/mod.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 31 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (9–10 lines × 2) core/partitions/src/journal.rs:240— core/partitions/src/journal.rs:240-249 | core/partitions/src/journal.rs:812-820 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8–9 lines × 2) core/metadata/src/impls/metadata.rs:2292— core/metadata/src/impls/metadata.rs:2292-2299 | core/metadata/src/impls/metadata.rs:2307-2315 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (8–9 lines × 2) foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/sink/IggySink.java:127— foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/sink/IggySink.java:127-134 | foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/source/IggySource.java:163-171 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/sink/IggySink.java:127` it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names — the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately.
Duplicated block (7 lines × 4) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:601— foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:601-607 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:610-616 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:619-625 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:635-641 — all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (7 lines × 4) core/cli/src/commands/binary_consumer_groups/get_consumer_group.rs:64— core/cli/src/commands/binary_consumer_groups/get_consumer_group.rs:64-72 | core/cli/src/commands/binary_streams/get_stream.rs:50-56 | core/cli/src/commands/binary_topics/get_topic.rs:63-69 | core/cli/src/commands/binary_users/get_user.rs:54-61 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 4 call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made 4 times.
Duplicated block (5 lines × 3) core/connectors/sinks/postgres_sink/src/lib.rs:526— core/connectors/sinks/postgres_sink/src/lib.rs:526-530 | REDACTED:1039-1043 | core/connectors/sources/postgres_source/src/lib.rs:2471-2477 — before extracting anything, compare `core/connectors/sinks/postgres_sink/src/lib.rs` and `REDACTED` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 44 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (5 lines × 3) core/cli/src/commands/binary_users/change_password.rs:64— core/cli/src/commands/binary_users/change_password.rs:64-70 | core/cli/src/commands/binary_users/change_password.rs:77-83 | core/cli/src/credentials.rs:130-134 — there are 3 copies across 2 file(s) — more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart.
Duplicated block (6 lines × 3) core/common/src/types/configuration/quic_config/quic_client_config_builder.rs:159— core/common/src/types/configuration/quic_config/quic_client_config_builder.rs:159-164 | core/common/src/types/configuration/tcp_config/tcp_client_config_builder.rs:108-113 | core/common/src/types/configuration/websocket_config/websocket_client_config_builder.rs:143-148 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made 3 times.
Duplicated block (6 lines × 3) core/bench/src/actors/consumer/typed_benchmark_consumer.rs:95— core/bench/src/actors/consumer/typed_benchmark_consumer.rs:95-100 | core/bench/src/actors/producer/typed_benchmark_producer.rs:94-99 | core/bench/src/actors/producing_consumer/typed_benchmark_producing_consumer.rs:124-129 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made 3 times.
Duplicated block (7 lines × 5) foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/sink/IggySinkWriter.java:248— foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/sink/IggySinkWriter.java:248-254 | foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/source/IggyPartitionSplitReader.java:250-256 | foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/source/IggySourceSplitEnumerator.java:259-265 | foreign/java/external-processors/iggy-connector-pinot/src/main/java/org/apache/iggy/connector/pinot/consumer/IggyPartitionGroupConsumer.java:229-235 | foreign/java/external-processors/iggy-connector-pinot/src/main/java/org/apache/iggy/connector/pinot/metadata/IggyStreamMetadataProvider.java:207-213 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 5 call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made 5 times.
Duplicated block (7 lines × 5) foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/sink/IggySinkWriter.java:259— foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/sink/IggySinkWriter.java:259-265 | foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/source/IggyPartitionSplitReader.java:261-267 | foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/source/IggySourceSplitEnumerator.java:270-276 | foreign/java/external-processors/iggy-connector-pinot/src/main/java/org/apache/iggy/connector/pinot/consumer/IggyPartitionGroupConsumer.java:240-246 | foreign/java/external-processors/iggy-connector-pinot/src/main/java/org/apache/iggy/connector/pinot/metadata/IggyStreamMetadataProvider.java:218-224 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 5 call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made 5 times.
Duplicated block (29 lines × 3) foreign/go/internal/command/offset.go:43— foreign/go/internal/command/offset.go:43-71 | foreign/go/internal/command/offset.go:89-117 | foreign/go/internal/command/offset.go:133-161 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited. ★ These copies have DRIFTED, and that is worth reading before extracting anything: just after the matched lines, `foreign/go/internal/command/offset.go:72` calls `PutUint64` and `foreign/go/internal/command/offset.go:118` does not — after which the two agree again for 3 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live.
Duplicated block (29 lines × 3) core/bench/src/actors/consumer/benchmark_consumer.rs:255— core/bench/src/actors/consumer/benchmark_consumer.rs:255-283 | core/bench/src/actors/producer/benchmark_producer.rs:265-293 | core/bench/src/actors/producing_consumer/benchmark_producing_consumer.rs:342-370 — `core/bench/src/actors/consumer/benchmark_consumer.rs` and `core/bench/src/actors/producer/benchmark_producer.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 201 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (53 lines × 3) examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Consumer/Utils.cs:36— examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Consumer/Utils.cs:36-88 | examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Consumer/Utils.cs:38-90 | examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Consumer/Utils.cs:39-91 — before extracting anything, compare `examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Consumer/Utils.cs` and `examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Consumer/Utils.cs` as WHOLE FILES: 89% of the shorter file's lines also appear in the other, so this reads as one file having been copied from the other rather than as a helper waiting to be extracted. The 2 duplicated block(s) this scan matched between them are fragments of that copy, not the extent of it — treat the file pair as the unit. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (53 lines × 3) examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java:63— examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java:63-115 | examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/consumer/MessageEnvelopeConsumer.java:72-124 | examples/java/src/main/java/org/apache/iggy/examples/tcptls/consumer/TcpTlsConsumer.java:84-136 — before extracting anything, compare `examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java` and `examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/consumer/MessageEnvelopeConsumer.java` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 86 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any `return` inside it is the body's own exit and keeps its meaning in the moved unit.
Duplicated block (36 lines × 2) foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:189— foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:189-224 | foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:255-290 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/java/bench/src/main/java/org/apache/iggy/bench/report/IndividualMetricsCalculator.java:189` it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (36 lines × 2) examples/python/basic/consumer.py:62— examples/python/basic/consumer.py:62-97 | examples/python/getting-started/consumer.py:176-211 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. ★ These copies have DRIFTED, and that is worth reading before extracting anything: just before the matched lines, `examples/python/getting-started/consumer.py:172` calls `exception` and `examples/python/basic/consumer.py:58` does not — after which the two agree again for 2 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live.
Unfinished stub — throws NotImplementedException foreign/csharp/Iggy_SDK/JsonConverters/ExpiryConverter.cs:37— `Write` is a shipped member whose whole body throws NotImplementedException — scaffolding that was never completed. Implement it or remove the dead surface.
Unfinished stub — throws NotImplementedException foreign/csharp/Iggy_SDK/JsonConverters/SizeConverter.cs:50— `Write` is a shipped member whose whole body throws NotImplementedException — scaffolding that was never completed. Implement it or remove the dead surface.
Sync-over-async blocking examples/node/src/tcp-tls/consumer.ts:99— `main` is async and calls readFileSync — a blocking call inside async code stalls the event loop — every other request waits for as long as it runs.
Sync-over-async blocking examples/node/src/tcp-tls/producer.ts:91— `main` is async and calls readFileSync — a blocking call inside async code stalls the event loop — every other request waits for as long as it runs.
Duplicated block (16 lines × 2 locations) foreign/node/src/wire/client/get-clients.command.ts:23— foreign/node/src/wire/client/get-clients.command.ts:23 · foreign/node/src/wire/stream/get-streams.command.ts:27 — the 2 copies are spread across 2 files, and the CITED SPAN is a run of MODULE-LEVEL DECLARATIONS — bindings the module declares and exports — rather than statements with a call site. Do not read this as an extract-a-helper row: a call expression cannot stand where a declaration was, and putting one there would delete the names themselves, which are what the rest of the codebase imports. What actually repeats here is the INITIALISER — the same expression shape written once per binding. So give that expression one name (a small helper the initialisers call, or a shared base value they are each derived from) and keep every binding under the name it already has. Where the run is an enumeration — one binding per distinct thing, differing precisely in the thing each one names — the repetition IS the enumeration and collapsing it would delete entries; consider instead whether the set belongs in one exported table the individual names are read out of. Reported because the copies drift apart the first time only one of them is edited.
Duplicated block (16 lines × 2 locations) web/src/lib/components/Modals/StreamSettingsModal.svelte:45— web/src/lib/components/Modals/StreamSettingsModal.svelte:45 · web/src/lib/components/Modals/TopicSettingsModal.svelte:48 — the 2 copies are spread across 2 files, and the CITED SPAN is a run of MODULE-LEVEL DECLARATIONS — bindings the module declares and exports — rather than statements with a call site. Do not read this as an extract-a-helper row: a call expression cannot stand where a declaration was, and putting one there would delete the names themselves, which are what the rest of the codebase imports. What actually repeats here is the INITIALISER — the same expression shape written once per binding. So give that expression one name (a small helper the initialisers call, or a shared base value they are each derived from) and keep every binding under the name it already has. Where the run is an enumeration — one binding per distinct thing, differing precisely in the thing each one names — the repetition IS the enumeration and collapsing it would delete entries; consider instead whether the set belongs in one exported table the individual names are read out of. Reported because the copies drift apart the first time only one of them is edited.
R10 · Code Duplication· Duplicated block with local edits (11 matched lines × 2 locations) · ×2
Duplicated block with local edits (11 matched lines × 2 locations) foreign/node/src/client/client.frame.ts:140— foreign/node/src/client/client.frame.ts:140 · foreign/node/src/client/client.frame.ts:158 — the two spans are one implementation copied and then locally edited — 78 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block with local edits (11 matched lines × 2 locations) REDACTED:58— REDACTED:58 · REDACTED:75 — the two spans are one implementation copied and then locally edited — 65 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block (10 lines × 2 locations) foreign/node/src/wire/session/login.utils.ts:90— foreign/node/src/wire/session/login.utils.ts:90 · foreign/node/src/wire/token/delete-token.command.ts:38 — the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another.
Duplicated block (10 lines × 2 locations) foreign/node/src/wire/token/token.utils.ts:100— foreign/node/src/wire/token/token.utils.ts:100 · foreign/node/src/wire/user/user.utils.ts:139 — the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another.
Duplicated block (6 lines × 2 locations) REDACTED:104— REDACTED:104 · REDACTED:110 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (6 lines × 2 locations) REDACTED:255— REDACTED:255 · REDACTED:261 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Complex function onUpdate (cyclomatic 14, cognitive 19) web/src/lib/components/Modals/AddPartitionsModal.svelte:49— onUpdate has cyclomatic complexity 14 and cognitive complexity 19; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function onUpdate (cyclomatic 14, cognitive 19) web/src/lib/components/Modals/DeletePartitionsModal.svelte:65— onUpdate has cyclomatic complexity 14 and cognitive complexity 19; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Dead file (~145 LoC) web/src/lib/components/Modals/TopicSettingsModal.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AppModals.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~145 LoC) web/src/lib/utils/addOnKeyDownListener.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~123 LoC) REDACTED— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~123 LoC) web/src/lib/components/Modals/AddTopicModal.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AppModals.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~114 LoC) foreign/node/src/bdd/message.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~114 LoC) web/src/lib/components/Modals/AddPartitionsModal.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AppModals.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~86 LoC) web/src/lib/components/Combobox.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/PermissionsManager.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~86 LoC) web/src/lib/components/Modals/AppModals.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~70 LoC) web/src/lib/components/Button.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 15 in-repo import(s) from 15 other file(s) do name it (web/src/lib/components/Combobox.svelte, web/src/lib/components/DeleteButtonWithConfirmation.svelte, web/src/lib/components/Header.svelte and 12 more) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~70 LoC) web/src/lib/components/SlimSortableList.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
X18 · Disposal-pattern correctness· Disposes a dependency it does not own · ×2
Disposes a dependency it does not own foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.cs:145— `_client` is never created by `IggyConsumer` — every assignment to it takes a constructor parameter — yet this type disposes it here (line 145). Its declared type `IIggyClient` is an interface, so the instance came from whoever resolved it, and that owner decides when it ends. Disposing it from here reaches outside this object's lifetime: a dependency shared with the rest of the process is torn down when THIS instance goes away, and the real owner's later `Dispose()` runs a second time on an object already disposed. Drop the call — a type disposes what it constructed, and only that. If this dependency genuinely is exclusive to this instance, construct it here (or take an owned factory) so the ownership is stated in the code rather than assumed.
Disposes a dependency it does not own foreign/csharp/Iggy_SDK/Contracts/PolledMessagesRental.cs:71— `_owner` is never created by `PolledMessagesRental` — every assignment to it takes a constructor parameter — yet this type disposes it here (line 71). Its declared type `IMemoryOwner` is an interface, so the instance came from whoever resolved it, and that owner decides when it ends. Disposing it from here reaches outside this object's lifetime: a dependency shared with the rest of the process is torn down when THIS instance goes away, and the real owner's later `Dispose()` runs a second time on an object already disposed. Drop the call — a type disposes what it constructed, and only that. If this dependency genuinely is exclusive to this instance, construct it here (or take an owned factory) so the ownership is stated in the code rather than assumed.
iggy_cli::get_command (cyclomatic 50) core/cli/src/main.rs:107— iggy_cli::get_command has cyclomatic complexity 50 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
ClusterConfig::validate (cyclomatic 49) core/configs/src/server_config/cluster.rs:868— ClusterConfig::validate has cyclomatic complexity 49 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
WebSocketClient::send_raw_with_response (cyclomatic 44) core/sdk/src/websocket/websocket_client.rs:162— WebSocketClient::send_raw_with_response has cyclomatic complexity 44 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
CommandResponseStream._pollOnPrimary (cyclomatic 40) foreign/node/src/client/client.socket.ts:586— CommandResponseStream._pollOnPrimary has cyclomatic complexity 40 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ServerConfig::validate (cyclomatic 38) core/configs/src/server_config/validators.rs:51— ServerConfig::validate has cyclomatic complexity 38 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
Args::from (cyclomatic 30) core/common/src/types/args/mod.rs:424— Args::from has cyclomatic complexity 30 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
iggy_cpp::type_conversion::decode_field (cyclomatic 29) foreign/cpp/src/type_conversion.rs:849— iggy_cpp::type_conversion::decode_field has cyclomatic complexity 29 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
CommandResponseStream.sendCommand (cyclomatic 29) foreign/node/src/client/client.socket.ts:305— CommandResponseStream.sendCommand has cyclomatic complexity 29 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
CommandResponseStream._processVsr (cyclomatic 29) foreign/node/src/client/client.socket.ts:879— CommandResponseStream._processVsr has cyclomatic complexity 29 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
TcpMessageStream.TryEstablishConnectionAsync (cyclomatic 28) foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs:1049— TcpMessageStream.TryEstablishConnectionAsync has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyTcpClient.Connect (cyclomatic 27) REDACTED:1043— IggyTcpClient.Connect has cyclomatic complexity 27 (threshold 15). Of this number, 21 points are the body's own statements and 6 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyTcpClient.pollOnRoute (cyclomatic 27) foreign/go/client/tcp/tcp_poll_routing.go:219— IggyTcpClient.pollOnRoute has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
HttpSourceConfig::validate (cyclomatic 26) core/connectors/sources/http_source/src/lib.rs:610— HttpSourceConfig::validate has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
TcpMessageStream.SendRawAsync (cyclomatic 25) foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.Vsr.cs:531— TcpMessageStream.SendRawAsync has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyPublisherBuilder.Validate (cyclomatic 25) foreign/csharp/Iggy_SDK/Publishers/IggyPublisherBuilder.cs:385— IggyPublisherBuilder.Validate has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
QuicConnectionStringOptions::parse_options (cyclomatic 25) core/common/src/types/configuration/quic_config/quic_connection_string_options.rs:90— QuicConnectionStringOptions::parse_options has cyclomatic complexity 25 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
ConsumerGroup::rebalance_cooperative (cyclomatic 24) core/metadata/src/stm/consumer_group.rs:186— ConsumerGroup::rebalance_cooperative has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
shard::dispatch_vsr_actions (cyclomatic 24) core/shard/src/lib.rs:11567— shard::dispatch_vsr_actions has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
Shadow::apply (cyclomatic 23) core/simulator/src/workload/shadow.rs:195— Shadow::apply has cyclomatic complexity 23 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
IggyTcpClient.sendFrame (cyclomatic 22) REDACTED:657— IggyTcpClient.sendFrame has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyTcpClient.pollPrimary (cyclomatic 22) foreign/go/client/tcp/tcp_poll_routing.go:154— IggyTcpClient.pollPrimary has cyclomatic complexity 22 (threshold 15). Of this number, 18 points are the body's own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
QuicTransportConn::run (cyclomatic 21) core/message_bus/src/transports/quic.rs:379— QuicTransportConn::run has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyTcpClient.exchangeLocked (cyclomatic 21) REDACTED:854— IggyTcpClient.exchangeLocked has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
client.connection-string.parseConnectionString (cyclomatic 21) foreign/node/src/client/client.connection-string.ts:59— client.connection-string.parseConnectionString has cyclomatic complexity 21 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
IggyConsumerBuilder.Validate (cyclomatic 20) foreign/csharp/Iggy_SDK/Consumers/IggyConsumerBuilder.cs:321— IggyConsumerBuilder.Validate has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
iggy_connector_delta_sink::coercions::apply_coercion (cyclomatic 20) core/connectors/sinks/delta_sink/src/coercions.rs:104— iggy_connector_delta_sink::coercions::apply_coercion has cyclomatic complexity 20 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
RabbitMQSink::publish_batch_with_retry (cyclomatic 20) core/connectors/sinks/rabbitmq_sink/src/lib.rs:193— RabbitMQSink::publish_batch_with_retry has cyclomatic complexity 20 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions.
JournalState::decode (cyclomatic 20) core/journal/src/partition_journal.rs:1600— JournalState::decode has cyclomatic complexity 20 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
IggyTcpClient.attempt (cyclomatic 20) REDACTED:758— IggyTcpClient.attempt has cyclomatic complexity 20 (threshold 15). Of this number, 19 points are the body's own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyConsumer.PollRentedMessagesAsync (cyclomatic 19) foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Rented.cs:103— IggyConsumer.PollRentedMessagesAsync has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
WebSocketConnectionStringOptions::parse_options (cyclomatic 19) core/common/src/types/configuration/websocket_config/websocket_connection_string_options.rs:102— WebSocketConnectionStringOptions::parse_options has cyclomatic complexity 19 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
AdvertisedAddress::from_str (cyclomatic 19) core/configs/src/server_config/cluster.rs:714— AdvertisedAddress::from_str has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
PartitionConfig::validate (cyclomatic 19) core/configs/src/server_config/partition.rs:283— PartitionConfig::validate has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
AvroStreamEncoder::serde_json_to_avro_value (cyclomatic 19) core/connectors/sdk/src/encoders/avro.rs:171— AvroStreamEncoder::serde_json_to_avro_value has cyclomatic complexity 19 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform — the same kind of value, with no behaviour of its own — a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing.
InfluxDbSink::append_line (cyclomatic 19) core/connectors/sinks/influxdb_sink/src/lib.rs:489— InfluxDbSink::append_line has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
partitions::segment_recovery::load_persisted_segments_with_checkpoint (cyclomatic 19) core/partitions/src/segment_recovery.rs:570— partitions::segment_recovery::load_persisted_segments_with_checkpoint has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
IggyConnection._reconnectUntilConnected (cyclomatic 19) foreign/node/src/client/client.connection.ts:408— IggyConnection._reconnectUntilConnected has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
BackgroundMessageProcessor.SendWithRetry (cyclomatic 18) foreign/csharp/Iggy_SDK/Publishers/BackgroundMessageProcessor.cs:480— BackgroundMessageProcessor.SendWithRetry has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
server_common::diagnostics::report_io_uring_environment (cyclomatic 18) core/server_common/src/diagnostics.rs:280— server_common::diagnostics::report_io_uring_environment has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
EndpointRegistry::restore (cyclomatic 17) core/connectors/sources/http_source/src/state.rs:103— EndpointRegistry::restore has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
harness_derive::codegen::generate_harness_setup (cyclomatic 17) core/harness_derive/src/codegen.rs:389— harness_derive::codegen::generate_harness_setup has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
IggyMetadata::install_state_transfer (cyclomatic 17) core/metadata/src/impls/metadata.rs:1733— IggyMetadata::install_state_transfer has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
QuicConfig::new (cyclomatic 17) foreign/python/src/config.rs:608— QuicConfig::new has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
TcpContracts.CreateMessage (cyclomatic 16) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:338— TcpContracts.CreateMessage has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top. This is NOT this file's highest cyclomatic complexity: TcpContracts.HeaderKindToByte (cyclomatic 17) is higher and carries no row of its own — it was excluded as a flat dispatcher (a long switch/match over independent cases: many branches, almost no nesting), which this dimension does not treat as a refactor obligation. It is named here so the ranking you see in this file is not mistaken for the whole of it; the excluded method is counted neither in this dimension's figures nor in its score.
ShardingConfig::validate (cyclomatic 16) core/configs/src/server_config/sharding.rs:177— ShardingConfig::validate has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
iggy_connector_sdk::source::handle_messages (cyclomatic 16) core/connectors/sdk/src/source.rs:288— iggy_connector_sdk::source::handle_messages has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
ElasticsearchSource::source_state_to_internal_state (cyclomatic 16) core/connectors/sources/elasticsearch_source/src/lib.rs:261— ElasticsearchSource::source_state_to_internal_state has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
iggy_connector_influxdb_source::v3::poll (cyclomatic 16) core/connectors/sources/influxdb_source/src/v3.rs:439— iggy_connector_influxdb_source::v3::poll has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
ServerHandle::set_protocol_addresses (cyclomatic 16) core/integration/src/harness/handle/server.rs:402— ServerHandle::set_protocol_addresses has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
Logging::cleanup_log_files (cyclomatic 16) core/server_common/src/log/logger.rs:618— Logging::cleanup_log_files has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
iggcon.DeserializeHeaders (cyclomatic 16) foreign/go/contracts/user_headers.go:135— iggcon.DeserializeHeaders has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top.
CommandResponseStream._pollOnPrimary (cognitive 86) foreign/node/src/client/client.socket.ts:586— CommandResponseStream._pollOnPrimary has cognitive complexity 86 (threshold 15). Drivers by points: if/else 21 (57 pts), ternaries 4 (14 pts), boolean chains 8, error handling 2 (4 pts), loops 2 (3 pts) (nesting depth added 49). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ClusterConfig::validate (cognitive 83) core/configs/src/server_config/cluster.rs:868— ClusterConfig::validate has cognitive complexity 83 (threshold 15). Drivers by points: if/else 38 (65 pts), loops 7 (15 pts), boolean chains 3 (nesting depth added 35). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
TcpMessageStream.TryEstablishConnectionAsync (cognitive 52) foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.cs:1049— TcpMessageStream.TryEstablishConnectionAsync has cognitive complexity 52 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
QuicTransportConn::run (cognitive 49) core/message_bus/src/transports/quic.rs:379— QuicTransportConn::run has cognitive complexity 49 (threshold 15). Drivers by points: if/else 11 (28 pts), match/switch 5 (15 pts), loops 3 (5 pts), boolean chains 1 (nesting depth added 29). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
CommandResponseStream.sendCommand (cognitive 47) foreign/node/src/client/client.socket.ts:305— CommandResponseStream.sendCommand has cognitive complexity 47 (threshold 15). Drivers by points: if/else 15 (32 pts), boolean chains 7, ternaries 3 (5 pts), error handling 1 (2 pts), loops 1 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ConsumerGroup::rebalance_cooperative (cognitive 46) core/metadata/src/stm/consumer_group.rs:186— ConsumerGroup::rebalance_cooperative has cognitive complexity 46 (threshold 15). Drivers by points: if/else 16 (33 pts), loops 6 (10 pts), boolean chains 3 (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyTcpClient.sendFrame (cognitive 46) REDACTED:657— IggyTcpClient.sendFrame has cognitive complexity 46 (threshold 15). Drivers by points: if/else 14 (41 pts), boolean chains 2, match/switch 1 (2 pts), loops 1 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ServerConfig::validate (cognitive 45) core/configs/src/server_config/validators.rs:51— ServerConfig::validate has cognitive complexity 45 (threshold 15). Drivers by points: if/else 22 (27 pts), boolean chains 12, loops 3 (6 pts) (nesting depth added 8). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
CommandResponseStream._processVsr (cognitive 44) foreign/node/src/client/client.socket.ts:879— CommandResponseStream._processVsr has cognitive complexity 44 (threshold 15). Drivers by points: if/else 15 (33 pts), boolean chains 7, error handling 2 (3 pts), loops 1 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyPublisherBuilder.Validate (cognitive 43) foreign/csharp/Iggy_SDK/Publishers/IggyPublisherBuilder.cs:385— IggyPublisherBuilder.Validate has cognitive complexity 43 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
TcpContracts.CreateMessage (cognitive 41) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:338— TcpContracts.CreateMessage has cognitive complexity 41 (threshold 15). To reduce it, flatten the nesting: invert conditions into early returns or guard clauses so the happy path stays at one level, and lift the deepest nested block into its own named function.
iggy_connector_sdk::source::handle_messages (cognitive 41) core/connectors/sdk/src/source.rs:288— iggy_connector_sdk::source::handle_messages has cognitive complexity 41 (threshold 15). Drivers by points: if/else 7 (24 pts), match/switch 6 (16 pts), loops 1 (nesting depth added 27). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
SendMessages::deserialize (cognitive 40) core/common/src/http/messages/send_messages.rs:129— SendMessages::deserialize has cognitive complexity 40 (threshold 15). Drivers by points: if/else 10 (27 pts), loops 3 (10 pts), match/switch 2 (3 pts) (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyTcpClient.pollOnRoute (cognitive 40) foreign/go/client/tcp/tcp_poll_routing.go:219— IggyTcpClient.pollOnRoute has cognitive complexity 40 (threshold 15). Drivers by points: if/else 18 (31 pts), match/switch 2 (5 pts), loops 1 (3 pts), boolean chains 1 (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
TcpMessageStream.SendRawAsync (cognitive 37) foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.Vsr.cs:531— TcpMessageStream.SendRawAsync has cognitive complexity 37 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyTcpClient.exchangeLocked (cognitive 37) REDACTED:854— IggyTcpClient.exchangeLocked has cognitive complexity 37 (threshold 15). Drivers by points: if/else 12 (30 pts), boolean chains 4, match/switch 1 (2 pts), loops 1 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
BackgroundMessageProcessor.SendWithRetry (cognitive 34) foreign/csharp/Iggy_SDK/Publishers/BackgroundMessageProcessor.cs:480— BackgroundMessageProcessor.SendWithRetry has cognitive complexity 34 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_connector_delta_sink::coercions::apply_coercion (cognitive 34) core/connectors/sinks/delta_sink/src/coercions.rs:104— iggy_connector_delta_sink::coercions::apply_coercion has cognitive complexity 34 (threshold 15). Drivers by points: if/else 7 (17 pts), loops 4 (12 pts), boolean chains 4, match/switch 1 (nesting depth added 18). The drivers above price the dispatch low by construction — a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full — so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
IggyTcpClient.pollPrimary (cognitive 34) foreign/go/client/tcp/tcp_poll_routing.go:154— IggyTcpClient.pollPrimary has cognitive complexity 34 (threshold 15). Drivers by points: if/else 16 (29 pts), boolean chains 4, loops 1 (nesting depth added 13). Of this number, 29 points are the body's own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
RabbitMQSink::publish_batch_with_retry (cognitive 32) core/connectors/sinks/rabbitmq_sink/src/lib.rs:193— RabbitMQSink::publish_batch_with_retry has cognitive complexity 32 (threshold 15). Drivers by points: if/else 5 (13 pts), match/switch 5 (13 pts), loops 3 (5 pts), boolean chains 1 (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
HttpSourceConfig::validate (cognitive 32) core/connectors/sources/http_source/src/lib.rs:610— HttpSourceConfig::validate has cognitive complexity 32 (threshold 15). Drivers by points: if/else 15 (22 pts), boolean chains 7, loops 3 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
FileScanner::probe_for_survivor (cognitive 32) core/partitions/src/segment_recovery.rs:2804— FileScanner::probe_for_survivor has cognitive complexity 32 (threshold 15). Drivers by points: if/else 7 (27 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyConnection._reconnectUntilConnected (cognitive 31) foreign/node/src/client/client.connection.ts:408— IggyConnection._reconnectUntilConnected has cognitive complexity 31 (threshold 15). Drivers by points: if/else 7 (18 pts), boolean chains 7, error handling 1 (3 pts), loops 2 (3 pts) (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Args::from (cognitive 30) core/common/src/types/args/mod.rs:424— Args::from has cognitive complexity 30 (threshold 15). Drivers by points: if/else 28 (29 pts), loops 1 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
KafkaGateway::run (cognitive 29) gateways/kafka/src/server.rs:328— KafkaGateway::run has cognitive complexity 29 (threshold 15). Drivers by points: if/else 5 (20 pts), match/switch 3 (8 pts), loops 1 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyTcpClient.Connect (cognitive 29) REDACTED:1043— IggyTcpClient.Connect has cognitive complexity 29 (threshold 15). Drivers by points: if/else 14 (21 pts), match/switch 3 (5 pts), boolean chains 2, loops 1 (nesting depth added 9). Of this number, 19 points are the body's own statements and 10 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
DurationParser.parse (cognitive 29) foreign/node/src/duration.utils.ts:159— DurationParser.parse has cognitive complexity 29 (threshold 15). Drivers by points: if/else 11 (24 pts), loops 3 (5 pts) (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyConsumerBuilder.Validate (cognitive 28) foreign/csharp/Iggy_SDK/Consumers/IggyConsumerBuilder.cs:321— IggyConsumerBuilder.Validate has cognitive complexity 28 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_cli::get_command (cognitive 27) core/cli/src/main.rs:107— iggy_cli::get_command has cognitive complexity 27 (threshold 15). Drivers by points: match/switch 14 (27 pts) (nesting depth added 13). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
binaryserialization.DeserializeFetchMessagesResponse (cognitive 27) foreign/go/binary_serialization/binary_response_deserializer.go:175— binaryserialization.DeserializeFetchMessagesResponse has cognitive complexity 27 (threshold 15). Drivers by points: if/else 10 (21 pts), loops 2 (3 pts), match/switch 1 (3 pts) (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyConsumer.PollRentedMessagesAsync (cognitive 26) foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Rented.cs:103— IggyConsumer.PollRentedMessagesAsync has cognitive complexity 26 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ElasticsearchSink::bulk_index_documents (cognitive 26) core/connectors/sinks/elasticsearch_sink/src/lib.rs:205— ElasticsearchSink::bulk_index_documents has cognitive complexity 26 (threshold 15). Drivers by points: if/else 10 (19 pts), loops 3 (5 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
harness_derive::codegen::generate_harness_setup (cognitive 26) core/harness_derive/src/codegen.rs:389— harness_derive::codegen::generate_harness_setup has cognitive complexity 26 (threshold 15). Drivers by points: if/else 21 (23 pts), match/switch 2 (3 pts) (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
tools::data-seeder::seeder::send_messages (cognitive 26) core/tools/src/data-seeder/seeder.rs:113— tools::data-seeder::seeder::send_messages has cognitive complexity 26 (threshold 15). Drivers by points: if/else 3 (10 pts), loops 4 (10 pts), match/switch 1 (5 pts), boolean chains 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
EndpointRegistry::restore (cognitive 25) core/connectors/sources/http_source/src/state.rs:103— EndpointRegistry::restore has cognitive complexity 25 (threshold 15). Drivers by points: if/else 11 (18 pts), boolean chains 3, loops 2, match/switch 1 (2 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PartitionJournal::evict_prefix (cognitive 25) core/partitions/src/journal.rs:581— PartitionJournal::evict_prefix has cognitive complexity 25 (threshold 15). Drivers by points: if/else 6 (15 pts), loops 4 (8 pts), boolean chains 2 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
server_common::diagnostics::report_io_uring_environment (cognitive 25) core/server_common/src/diagnostics.rs:280— server_common::diagnostics::report_io_uring_environment has cognitive complexity 25 (threshold 15). Drivers by points: if/else 9 (14 pts), boolean chains 5, match/switch 3 (4 pts), loops 1 (2 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggcon.DeserializeHeaders (cognitive 25) foreign/go/contracts/user_headers.go:135— iggcon.DeserializeHeaders has cognitive complexity 25 (threshold 15). Drivers by points: if/else 10 (20 pts), boolean chains 4, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
UserHeadersConverter.Read (cognitive 24) foreign/csharp/Iggy_SDK/JsonConverters/UserHeadersConverter.cs:26— UserHeadersConverter.Read has cognitive complexity 24 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
TestHarness::start_internal (cognitive 24) core/integration/src/harness/orchestrator/harness.rs:106— TestHarness::start_internal has cognitive complexity 24 (threshold 15). Drivers by points: loops 5 (11 pts), if/else 6 (10 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 11). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline.
JwksClient::refresh_keys (cognitive 24) core/server/src/http/jwks.rs:180— JwksClient::refresh_keys has cognitive complexity 24 (threshold 15). Drivers by points: if/else 7 (18 pts), match/switch 1 (3 pts), loops 2, boolean chains 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
LocalConnectorsConfigProvider::init (cognitive 23) core/connectors/runtime/src/configs/connectors/local_provider.rs:148— LocalConnectorsConfigProvider::init has cognitive complexity 23 (threshold 15). Drivers by points: if/else 7 (18 pts), match/switch 2 (4 pts), loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Shard::new (cognitive 23) core/sdk/src/clients/producer_sharding.rs:204— Shard::new has cognitive complexity 23 (threshold 15). Drivers by points: if/else 3 (11 pts), match/switch 2 (5 pts), loops 2 (4 pts), boolean chains 3 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
BinaryMapper.MapPermissions (cognitive 22) foreign/csharp/Iggy_SDK/Mappers/BinaryMapper.cs:138— BinaryMapper.MapPermissions has cognitive complexity 22 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
BinaryMapper.MapRentedMessages (cognitive 22) foreign/csharp/Iggy_SDK/Mappers/BinaryMapper.cs:350— BinaryMapper.MapRentedMessages has cognitive complexity 22 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AvroStreamDecoder::apply_field_transformations (cognitive 22) core/connectors/sdk/src/decoders/avro.rs:177— AvroStreamDecoder::apply_field_transformations has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (12 pts), loops 2 (8 pts), match/switch 1 (2 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
FlatBufferStreamDecoder::apply_field_transformations (cognitive 22) core/connectors/sdk/src/decoders/flatbuffer.rs:120— FlatBufferStreamDecoder::apply_field_transformations has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (12 pts), loops 2 (8 pts), match/switch 1 (2 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ProtoStreamDecoder::apply_field_transformations (cognitive 22) core/connectors/sdk/src/decoders/proto.rs:524— ProtoStreamDecoder::apply_field_transformations has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (12 pts), loops 2 (8 pts), match/switch 1 (2 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
AvroStreamEncoder::apply_field_transformations (cognitive 22) core/connectors/sdk/src/encoders/avro.rs:121— AvroStreamEncoder::apply_field_transformations has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (12 pts), loops 2 (8 pts), match/switch 1 (2 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
FlatBufferStreamEncoder::apply_field_transformations (cognitive 22) core/connectors/sdk/src/encoders/flatbuffer.rs:66— FlatBufferStreamEncoder::apply_field_transformations has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (12 pts), loops 2 (8 pts), match/switch 1 (2 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
HttpRetryMiddleware::handle (cognitive 22) core/connectors/sdk/src/retry.rs:401— HttpRetryMiddleware::handle has cognitive complexity 22 (threshold 15). Drivers by points: if/else 5 (13 pts), match/switch 3 (7 pts), boolean chains 1, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Permissions.MarshalBinary (cognitive 22) foreign/go/contracts/users.go:47— Permissions.MarshalBinary has cognitive complexity 22 (threshold 15). Drivers by points: if/else 8 (16 pts), loops 2 (6 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
VsrConnection.SendAttemptAsync (cognitive 21) foreign/csharp/Iggy_SDK/Vsr/VsrConnection.cs:96— VsrConnection.SendAttemptAsync has cognitive complexity 21 (threshold 15). To reduce it, flatten the nesting: invert conditions into early returns or guard clauses so the happy path stays at one level, and lift the deepest nested block into its own named function.
IggyMessagesBatch::validate (cognitive 21) core/common/src/types/message/messages_batch.rs:170— IggyMessagesBatch::validate has cognitive complexity 21 (threshold 15). Drivers by points: if/else 12 (20 pts), loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
MongoDbSink::insert_batch (cognitive 21) core/connectors/sinks/mongodb_sink/src/lib.rs:282— MongoDbSink::insert_batch has cognitive complexity 21 (threshold 15). Drivers by points: match/switch 5 (13 pts), if/else 4 (7 pts), loops 1 (nesting depth added 11). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
client.connection-string.parseConnectionString (cognitive 21) foreign/node/src/client/client.connection-string.ts:59— client.connection-string.parseConnectionString has cognitive complexity 21 (threshold 15). Drivers by points: if/else 11, ternaries 5 (6 pts), boolean chains 4 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
AdvertisedAddress::from_str (cognitive 20) core/configs/src/server_config/cluster.rs:714— AdvertisedAddress::from_str has cognitive complexity 20 (threshold 15). Drivers by points: if/else 11 (13 pts), boolean chains 6, loops 1 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition.
TcpMessageStream.PollPrimaryOnceAsync (cognitive 19) foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.PollRouting.cs:115— TcpMessageStream.PollPrimaryOnceAsync has cognitive complexity 19 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
BackgroundMessageProcessor.RunBackgroundProcessor (cognitive 19) foreign/csharp/Iggy_SDK/Publishers/BackgroundMessageProcessor.cs:250— BackgroundMessageProcessor.RunBackgroundProcessor has cognitive complexity 19 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
InfluxDbSink::append_line (cognitive 19) core/connectors/sinks/influxdb_sink/src/lib.rs:489— InfluxDbSink::append_line has cognitive complexity 19 (threshold 15). Drivers by points: if/else 10, boolean chains 6, match/switch 2 (3 pts) (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
Invariants::check (cognitive 19) core/simulator/src/workload/invariants.rs:108— Invariants::check has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (16 pts), loops 2 (3 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyTcpClient.attempt (cognitive 19) REDACTED:758— IggyTcpClient.attempt has cognitive complexity 19 (threshold 15). Drivers by points: if/else 11 (15 pts), boolean chains 2, match/switch 2 (nesting depth added 4). Of this number, 17 points are the body's own statements and 2 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
main.types (cognitive 19) foreign/go/errors/generator/main.go:101— main.types has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (10 pts), loops 3 (7 pts), boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
CreateTopic.options (cognitive 19) foreign/go/internal/command/topic.go:76— CreateTopic.options has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (14 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
util.CheckAndRedirectToLeader (cognitive 19) foreign/go/internal/util/leader_aware.go:62— util.CheckAndRedirectToLeader has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (12 pts), match/switch 2 (5 pts), boolean chains 1, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
CommandResponseStream._processQueue (cognitive 19) foreign/node/src/client/client.socket.ts:796— CommandResponseStream._processQueue has cognitive complexity 19 (threshold 15). Drivers by points: if/else 7 (12 pts), boolean chains 2, error handling 1 (2 pts), ternaries 1 (2 pts), loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyCredentials::new (cognitive 18) core/cli/src/credentials.rs:59— IggyCredentials::new has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10 (12 pts), match/switch 2 (4 pts), boolean chains 2 (nesting depth added 4). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
QuicConnectionStringOptions::parse_options (cognitive 18) core/common/src/types/configuration/quic_config/quic_connection_string_options.rs:90— QuicConnectionStringOptions::parse_options has cognitive complexity 18 (threshold 15). Drivers by points: match/switch 10 (15 pts), if/else 1 (2 pts), loops 1 (nesting depth added 6). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
PartitionConfig::validate (cognitive 18) core/configs/src/server_config/partition.rs:283— PartitionConfig::validate has cognitive complexity 18 (threshold 15). Drivers by points: if/else 13, boolean chains 5. To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
ClickHouseClient::insert (cognitive 18) core/connectors/sinks/clickhouse_sink/src/client.rs:175— ClickHouseClient::insert has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (15 pts), match/switch 1 (2 pts), loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
HttpSink::open (cognitive 18) core/connectors/sinks/http_sink/src/lib.rs:1040— HttpSink::open has cognitive complexity 18 (threshold 15). Drivers by points: if/else 9 (13 pts), loops 3, boolean chains 1, match/switch 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
MeilisearchSink::retry_sdk_operation_with_retries (cognitive 18) core/connectors/sinks/meilisearch_sink/src/lib.rs:670— MeilisearchSink::retry_sdk_operation_with_retries has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (14 pts), match/switch 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
S3Sink::close (cognitive 18) core/connectors/sinks/s3_sink/src/sink.rs:135— S3Sink::close has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (16 pts), loops 1 (2 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
SurrealDbSink::insert_records_with_retry (cognitive 18) core/connectors/sinks/surrealdb_sink/src/lib.rs:718— SurrealDbSink::insert_records_with_retry has cognitive complexity 18 (threshold 15). Drivers by points: match/switch 4 (9 pts), if/else 2 (6 pts), boolean chains 2, loops 1 (nesting depth added 9). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
RouteTable::build_with (cognitive 18) core/connectors/sources/http_source/src/routes.rs:282— RouteTable::build_with has cognitive complexity 18 (threshold 15). Drivers by points: match/switch 3 (8 pts), if/else 3 (7 pts), loops 2 (3 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
PartitionPersistence::run_inner (cognitive 18) core/partitions/src/persistence.rs:1152— PartitionPersistence::run_inner has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (13 pts), boolean chains 2, match/switch 1 (2 pts), loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
Workload::on_reply (cognitive 18) core/simulator/src/workload/mod.rs:475— Workload::on_reply has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10 (12 pts), match/switch 2 (4 pts), boolean chains 2 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth — checks laid out side by side rather than stacked — so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level.
binaryserialization.deserializePermissions (cognitive 18) foreign/go/binary_serialization/binary_response_deserializer.go:597— binaryserialization.deserializePermissions has cognitive complexity 18 (threshold 15). Drivers by points: if/else 4 (12 pts), loops 2 (6 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
CommandResponseStream._rememberCredentials (cognitive 18) foreign/node/src/client/client.socket.ts:748— CommandResponseStream._rememberCredentials has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (14 pts), boolean chains 4 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
poll-messages.command.pollConsumerGroup (cognitive 18) foreign/node/src/wire/message/poll-messages.command.ts:188— poll-messages.command.pollConsumerGroup has cognitive complexity 18 (threshold 15). Drivers by points: if/else 3 (7 pts), boolean chains 4, ternaries 2 (4 pts), error handling 1 (2 pts), loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
IggyConsumer.PollMessagesAsync (cognitive 17) foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.cs:402— IggyConsumer.PollMessagesAsync has cognitive complexity 17 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
TcpMessageStream.PollAutoCommitAsync (cognitive 17) foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.PollRouting.cs:60— TcpMessageStream.PollAutoCommitAsync has cognitive complexity 17 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
CreatePartitionsWithAssignmentsRequest::apply (cognitive 17) core/metadata/src/stm/stream.rs:2534— CreatePartitionsWithAssignmentsRequest::apply has cognitive complexity 17 (threshold 15). Drivers by points: if/else 11 (15 pts), loops 2 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ConnectionString::new (cognitive 17) core/common/src/types/configuration/auth_config/connection_string.rs:45— ConnectionString::new has cognitive complexity 17 (threshold 15). Drivers by points: if/else 14 (15 pts), boolean chains 2 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
RedshiftSink::process_messages (cognitive 17) REDACTED:375— RedshiftSink::process_messages has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (14 pts), match/switch 1 (2 pts), loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
VsrConsensus::tick (cognitive 17) core/consensus/src/impls.rs:2433— VsrConsensus::tick has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10 (15 pts), match/switch 1 (2 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
WriterLease::acquire (cognitive 17) core/partitions/src/persistence.rs:235— WriterLease::acquire has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8 (15 pts), boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
QuicConfig::new (cognitive 17) foreign/python/src/config.rs:608— QuicConfig::new has cognitive complexity 17 (threshold 15). Drivers by points: if/else 16 (17 pts) (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
poll.utils.deserializeBatchMessages (cognitive 17) foreign/node/src/wire/message/poll.utils.ts:273— poll.utils.deserializeBatchMessages has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (13 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
TcpMessageStream.LoginRegisterAsync (cognitive 16) foreign/csharp/Iggy_SDK/IggyClient/Implementations/TcpMessageStream.Vsr.cs:133— TcpMessageStream.LoginRegisterAsync has cognitive complexity 16 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
CreateTopicWithAssignmentsRequest::apply (cognitive 16) core/metadata/src/stm/stream.rs:2191— CreateTopicWithAssignmentsRequest::apply has cognitive complexity 16 (threshold 15). Drivers by points: if/else 12 (13 pts), loops 2 (3 pts) (nesting depth added 2). To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
TypedEnvProvider::warn_unknown_env_vars_inner (cognitive 16) core/configs/src/configs_impl/typed_env_provider.rs:270— TypedEnvProvider::warn_unknown_env_vars_inner has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (9 pts), match/switch 3 (5 pts), boolean chains 1, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
ProtoStreamEncoder::apply_field_transformations (cognitive 16) core/connectors/sdk/src/encoders/proto.rs:282— ProtoStreamEncoder::apply_field_transformations has cognitive complexity 16 (threshold 15). Drivers by points: loops 2 (8 pts), if/else 4 (6 pts), match/switch 1 (2 pts) (nesting depth added 9). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline.
ClickHouseSink::open (cognitive 16) core/connectors/sinks/clickhouse_sink/src/sink.rs:31— ClickHouseSink::open has cognitive complexity 16 (threshold 15). Drivers by points: if/else 3 (8 pts), match/switch 2 (5 pts), loops 2 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
DynamicRouter::route_data (cognitive 16) core/connectors/sinks/iceberg_sink/src/router/dynamic_router.rs:107— DynamicRouter::route_data has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (8 pts), match/switch 3 (6 pts), loops 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body.
iggy_cpp::type_conversion::decode_field (cognitive 16) foreign/cpp/src/type_conversion.rs:849— iggy_cpp::type_conversion::decode_field has cognitive complexity 16 (threshold 15). Drivers by points: match/switch 14 (16 pts) (nesting depth added 2). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident.
IggyClient::consumer_group (cognitive 16) foreign/python/src/client.rs:1567— IggyClient::consumer_group has cognitive complexity 16 (threshold 15). Drivers by points: if/else 14, boolean chains 2. To reduce it, split the body: this score is breadth rather than depth — many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages.
D22 · Internal API Consistency· Inconsistent factory method naming convention. One uses 'For' and the other uses 'ForPersonalAccessToken'. Given that 'For' is already overloaded for credentials, 'ForToken' or 'ForAccessToken' would be more consistent with the existing 'For' pattern. · ×1
Inconsistent factory method naming convention. One uses 'For' and the other uses 'ForPersonalAccessToken'. Given that 'For' is already overloaded for credentials, 'ForToken' or 'ForAccessToken' would be more consistent with the existing 'For' pattern. — Rename 'ForPersonalAccessToken' to 'ForToken' or 'ForAccessToken' to align with the 'For' factory pattern used for username/password. (signatures: AutoLoginSettings.AutoLoginSettings.For(string username, string password) | AutoLoginSettings.AutoLoginSettings.ForPersonalAccessToken(string token))
D22 · Internal API Consistency· Duplicate intent across generic and non-generic builders. The non-generic `IggyConsumerBuilder` and generic `IggyConsumerBuilder<T>` have nearly identical `Create` signatures, differing only by the presence of a deserializer. This forces users to choose between two parallel builder hierarchies for essentially the same operation. · ×1
Duplicate intent across generic and non-generic builders. The non-generic `IggyConsumerBuilder` and generic `IggyConsumerBuilder<T>` have nearly identical `Create` signatures, differing only by the presence of a deserializer. This forces users to choose between two parallel builder hierarchies for essentially the same operation. — Consolidate into a single `IggyConsumerBuilder<T>` where `T` can be `byte[]` or `object` if deserialization is not desired, or ensure the non-generic builder is clearly deprecated/hidden in favor of the generic one. (signatures: IggyConsumerBuilder.IggyConsumerBuilder.Create(Identifier streamId, Identifier topicId, Consumer consumer) | IggyConsumerBuilder<T>.IggyConsumerBuilder<T>.Create(Identifier streamId, Identifier topicId, Consumer consumer, IDeserializer<T> deserializer))
D22 · Internal API Consistency· Ambiguous naming for similar operations. `ReceiveAsync` returns `ReceivedMessage` (which wraps `MessageResponse`), while `ReceiveRentedAsync` returns `ReceivedRentedMessage` (which wraps `RentedMessageResponse`). The distinction between 'Message' and 'RentedMessage' is not immediately obvious to a user and suggests a potential naming inconsistency regarding memory ownership semantics. · ×1
Ambiguous naming for similar operations. `ReceiveAsync` returns `ReceivedMessage` (which wraps `MessageResponse`), while `ReceiveRentedAsync` returns `ReceivedRentedMessage` (which wraps `RentedMessageResponse`). The distinction between 'Message' and 'RentedMessage' is not immediately obvious to a user and suggests a potential naming inconsistency regarding memory ownership semantics. — Rename `ReceiveAsync` to `ReceiveAsync` (keeping it as the standard) but ensure `ReceiveRentedAsync` is clearly named to reflect its memory management contract, e.g., `ReceiveRentedAsync` is okay, but consider if `ReceiveAsync` should be the only public entry point and `ReceiveRentedAsync` is an internal optimization, or if the naming should be `Receive` vs `ReceiveWithRental`. (signatures: IggyConsumer.IggyConsumer.ReceiveAsync(CancellationToken ct) | IggyConsumer.IggyConsumer.ReceiveRentedAsync(CancellationToken ct))
D4 · Code Duplication· Near-duplicate member family (3 members, 11 shared lines) · ×1
Near-duplicate member family (3 members, 11 shared lines) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:779— foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:779-803 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:806-828 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:903-926 — These 3 members are variants of one another: a block of 11 lines reported below appears in every one of them, and the pairwise near-duplicate rows they would otherwise produce are collapsed into this row. Read them as one construct written 3 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 3 times.
Near-duplicate member pair (220 shared lines) core/sdk/src/quic/quic_client.rs:168— core/sdk/src/quic/quic_client.rs:168-406 | core/sdk/src/websocket/websocket_client.rs:162-402 — These two members are variants of one another: 220 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members' grain — factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice.
Near-duplicate member pair (81 shared lines) core/message_bus/src/installer/replica.rs:331— core/message_bus/src/installer/replica.rs:331-592 | core/message_bus/src/installer/tcp.rs:72-240 — These two members are variants of one another: 81 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members' grain — factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice.
Near-duplicate member pair (77 shared lines) core/message_bus/src/transports/ws.rs:186— core/message_bus/src/transports/ws.rs:186-286 | core/message_bus/src/transports/wss.rs:334-438 — These two members are variants of one another: 77 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members' grain — factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice.
Near-duplicate member pair (52 shared lines) core/sdk/src/websocket/websocket_connection_stream.rs:46— core/sdk/src/websocket/websocket_connection_stream.rs:46-120 | core/sdk/src/websocket/websocket_tls_connection_stream.rs:49-125 — These two members are variants of one another: 52 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members' grain — factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice.
Near-duplicate member pair (42 shared lines) core/journal/src/prepare_journal.rs:778— core/journal/src/prepare_journal.rs:778-877 | core/journal/src/prepare_journal.rs:930-1067 — These two members are variants of one another: 42 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members' grain — factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice.
Near-duplicate member pair (37 shared lines) core/connectors/sinks/http_sink/src/lib.rs:741— core/connectors/sinks/http_sink/src/lib.rs:741-817 | core/connectors/sinks/http_sink/src/lib.rs:826-910 — These two members are variants of one another: 37 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members' grain — factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice.
D4 · Code Duplication· Edited copy of a member (22 corresponding lines) · ×1
Edited copy of a member (22 corresponding lines) core/integration/src/harness/handle/connectors_runtime.rs:210— core/integration/src/harness/handle/connectors_runtime.rs:210-233 | core/integration/src/harness/handle/server.rs:1021-1046 — These two members are one piece of code written twice and then edited apart: 22 consecutive lines correspond almost exactly, broken only by small local edits. Most of that correspondence is NOT reported as duplicated blocks below — the edits cut it into fragments and only the largest of them clear the block floor, so the rows below understate it. The repair is at the members' grain — factor the shared implementation into one the two call with their differences as parameters or as an injected step, or, where the difference is systematic (an extra return value, one transport against another), generate one from the other. Left alone, the next edit has to be made twice and the two will drift further apart.
D4 · Code Duplication· Members sharing a duplicated core (13 members, 50+ identical tokens) · ×1
Members sharing a duplicated core (13 members, 50+ identical tokens) core/consensus/src/observability.rs:480— core/consensus/src/observability.rs:480-512 | core/consensus/src/observability.rs:514-546 | core/consensus/src/observability.rs:548-580 | core/consensus/src/observability.rs:582-614 | core/consensus/src/observability.rs:616-648 | core/consensus/src/observability.rs:718-736 | core/consensus/src/observability.rs:743-763 | core/consensus/src/observability.rs:766-788 | core/consensus/src/observability.rs:792-818 | core/consensus/src/observability.rs:822-847 | core/consensus/src/observability.rs:851-875 | core/consensus/src/observability.rs:879-903 | core/consensus/src/observability.rs:907-930 — These 13 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 13 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 13 times.
D4 · Code Duplication· Members sharing a duplicated core (10 members, 50+ identical tokens) · ×1
Members sharing a duplicated core (10 members, 50+ identical tokens) core/binary_protocol/src/requests/consumer_groups/create_consumer_group.rs:47— core/binary_protocol/src/requests/consumer_groups/create_consumer_group.rs:47-63 | core/binary_protocol/src/requests/consumer_groups/delete_consumer_group.rs:46-62 | core/binary_protocol/src/requests/consumer_groups/get_consumer_group.rs:46-62 | core/binary_protocol/src/requests/consumer_groups/join_consumer_group.rs:46-62 | core/binary_protocol/src/requests/consumer_groups/leave_consumer_group.rs:46-62 | core/binary_protocol/src/requests/consumer_groups/sync_consumer_group.rs:49-65 | core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs:72-102 | core/binary_protocol/src/requests/consumer_offsets/get_consumer_offset.rs:65-91 | core/binary_protocol/src/requests/consumer_offsets/store_consumer_offset.rs:75-108 | core/binary_protocol/src/requests/messages/poll_messages.rs:82-120 — These 10 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 10 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 10 times.
D4 · Code Duplication· Members sharing a duplicated core (8 members, 50+ identical tokens) · ×1
Members sharing a duplicated core (8 members, 50+ identical tokens) core/connectors/sdk/src/decoders/avro.rs:177— core/connectors/sdk/src/decoders/avro.rs:177-207 | core/connectors/sdk/src/decoders/flatbuffer.rs:120-150 | core/connectors/sdk/src/decoders/proto.rs:524-554 | core/connectors/sdk/src/encoders/avro.rs:121-151 | core/connectors/sdk/src/encoders/flatbuffer.rs:66-96 | core/connectors/sdk/src/encoders/proto.rs:282-314 | core/connectors/sdk/src/transforms/avro_convert.rs:75-101 | core/connectors/sdk/src/transforms/proto_convert.rs:487-514 — These 8 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below — it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 8 times. The repair is at the members' grain — factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 8 times.
Duplicated block (165 lines × 2) core/sdk/src/quic/quic_client.rs:169— core/sdk/src/quic/quic_client.rs:169-333 | core/sdk/src/websocket/websocket_client.rs:163-327 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (42–46 lines × 2) core/connectors/sources/influxdb_source/src/lib.rs:547— core/connectors/sources/influxdb_source/src/lib.rs:547-592 | core/connectors/sources/influxdb_source/src/lib.rs:633-674 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (38–44 lines × 2) foreign/csharp/Iggy_SDK/Consumers/IggyConsumerConfig.cs:46— foreign/csharp/Iggy_SDK/Consumers/IggyConsumerConfig.cs:46-83 | foreign/csharp/Iggy_SDK/Publishers/IggyPublisherConfig.cs:44-87 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/csharp/Iggy_SDK/Consumers/IggyConsumerConfig.cs:46` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names — the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately.
Duplicated block (27–39 lines × 2) core/journal/src/prepare_journal.rs:818— core/journal/src/prepare_journal.rs:818-844 | core/journal/src/prepare_journal.rs:980-1018 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (28–34 lines × 2) core/message_bus/src/installer/replica.rs:414— core/message_bus/src/installer/replica.rs:414-447 | core/message_bus/src/installer/tcp.rs:102-129 — before extracting anything, compare `core/message_bus/src/installer/replica.rs` and `core/message_bus/src/installer/tcp.rs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 108 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (31–33 lines × 2) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:646— foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:646-678 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:702-732 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:646` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names — the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately.
Duplicated block (32 lines × 2) foreign/csharp/Iggy_SDK/JsonConverters/UserHeadersConverter.cs:93— foreign/csharp/Iggy_SDK/JsonConverters/UserHeadersConverter.cs:93-124 | foreign/csharp/Iggy_SDK/JsonConverters/UserHeadersConverter.cs:138-169 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/csharp/Iggy_SDK/JsonConverters/UserHeadersConverter.cs:93` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (26–32 lines × 2) core/sdk/src/quic/quic_client.rs:335— core/sdk/src/quic/quic_client.rs:335-366 | core/sdk/src/websocket/websocket_client.rs:332-357 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (19–31 lines × 3) core/sdk/src/quic/quic_client.rs:358— core/sdk/src/quic/quic_client.rs:358-376 | core/sdk/src/tcp/tcp_client.rs:264-294 | core/sdk/src/websocket/websocket_client.rs:349-367 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/tcp/tcp_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 134 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (13–31 lines × 2) core/message_bus/src/installer/replica.rs:380— core/message_bus/src/installer/replica.rs:380-410 | core/message_bus/src/installer/tcp.rs:86-98 — before extracting anything, compare `core/message_bus/src/installer/replica.rs` and `core/message_bus/src/installer/tcp.rs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 108 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (28–29 lines × 3) core/connectors/sdk/src/decoders/proto.rs:118— core/connectors/sdk/src/decoders/proto.rs:118-145 | core/connectors/sdk/src/encoders/proto.rs:147-175 | core/connectors/sdk/src/transforms/proto_convert.rs:141-169 — `core/connectors/sdk/src/decoders/proto.rs` and `core/connectors/sdk/src/encoders/proto.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 11 separate duplicated blocks between them, totalling at least 151 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (27 lines × 3) core/connectors/sdk/src/encoders/avro.rs:316— core/connectors/sdk/src/encoders/avro.rs:316-342 | core/connectors/sdk/src/encoders/flatbuffer.rs:193-219 | core/connectors/sdk/src/encoders/proto.rs:685-711 — before extracting anything, compare `core/connectors/sdk/src/encoders/avro.rs` and `core/connectors/sdk/src/encoders/flatbuffer.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 85 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (16–27 lines × 3) core/sdk/src/quic/quic_client.rs:235— core/sdk/src/quic/quic_client.rs:235-250 | core/sdk/src/tcp/tcp_client.rs:1413-1439 | core/sdk/src/websocket/websocket_client.rs:229-244 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/tcp/tcp_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 134 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (25–27 lines × 2) core/connectors/runtime/src/configs/connectors/local_provider.rs:724— core/connectors/runtime/src/configs/connectors/local_provider.rs:724-748 | core/connectors/runtime/src/configs/connectors/local_provider.rs:777-803 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (27 lines × 2) core/simulator/src/workload/ops/create_partitions.rs:58— core/simulator/src/workload/ops/create_partitions.rs:58-84 | core/simulator/src/workload/ops/delete_partitions.rs:71-97 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (8–26 lines × 2) core/message_bus/src/installer/replica.rs:495— core/message_bus/src/installer/replica.rs:495-502 | core/message_bus/src/installer/tcp.rs:148-173 — before extracting anything, compare `core/message_bus/src/installer/replica.rs` and `core/message_bus/src/installer/tcp.rs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 108 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (25 lines × 2) core/ai/mcp/src/configs.rs:261— core/ai/mcp/src/configs.rs:261-285 | core/connectors/runtime/src/api/config.rs:153-177 — before extracting anything, compare `core/ai/mcp/src/configs.rs` and `core/connectors/runtime/src/api/config.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 56 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place.
Duplicated block (22–25 lines × 2) core/message_bus/src/transports/ws.rs:221— core/message_bus/src/transports/ws.rs:221-242 | core/message_bus/src/transports/wss.rs:369-393 — before extracting anything, compare `core/message_bus/src/transports/ws.rs` and `core/message_bus/src/transports/wss.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 81 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (23 lines × 6) core/connectors/sdk/src/decoders/avro.rs:179— core/connectors/sdk/src/decoders/avro.rs:179-201 | core/connectors/sdk/src/decoders/flatbuffer.rs:122-144 | core/connectors/sdk/src/decoders/proto.rs:526-548 | core/connectors/sdk/src/encoders/avro.rs:123-145 | core/connectors/sdk/src/encoders/flatbuffer.rs:68-90 | core/connectors/sdk/src/transforms/avro_convert.rs:76-98 — before extracting anything, compare `core/connectors/sdk/src/decoders/avro.rs` and `core/connectors/sdk/src/decoders/flatbuffer.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 69 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (18–23 lines × 2) core/simulator/src/lib.rs:447— core/simulator/src/lib.rs:447-469 | core/simulator/src/lib.rs:1250-1267 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (22 lines × 3) core/sdk/src/quic/quic_client.rs:422— core/sdk/src/quic/quic_client.rs:422-443 | core/sdk/src/tcp/tcp_client.rs:351-372 | core/sdk/src/websocket/websocket_client.rs:418-439 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/tcp/tcp_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 134 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (21–22 lines × 2) foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs:831— foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs:831-851 | foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs:914-935 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/csharp/Iggy_SDK/IggyClient/Implementations/HttpMessageStream.cs:831` it runs out through the closing brace of the declaration holding it — the window is that declaration's tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (17–21 lines × 2) core/consensus/src/impls.rs:2575— core/consensus/src/impls.rs:2575-2595 | core/consensus/src/impls.rs:2831-2847 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (17–20 lines × 2) core/server/src/boot/handoff.rs:145— core/server/src/boot/handoff.rs:145-164 | core/server/src/boot/handoff.rs:185-201 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (17–18 lines × 2) core/sdk/src/websocket/websocket_connection_stream.rs:98— core/sdk/src/websocket/websocket_connection_stream.rs:98-114 | core/sdk/src/websocket/websocket_tls_connection_stream.rs:100-117 — before extracting anything, compare `core/sdk/src/websocket/websocket_connection_stream.rs` and `core/sdk/src/websocket/websocket_tls_connection_stream.rs` as WHOLE FILES: this scan already matched 8 separate duplicated blocks between them, totalling at least 102 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (16–17 lines × 4) core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs:73— core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs:73-88 | core/binary_protocol/src/requests/consumer_offsets/get_consumer_offset.rs:66-81 | core/binary_protocol/src/requests/consumer_offsets/store_consumer_offset.rs:76-91 | core/binary_protocol/src/requests/messages/poll_messages.rs:83-99 — before extracting anything, compare `core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs` and `core/binary_protocol/src/requests/consumer_offsets/get_consumer_offset.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 32 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (15–17 lines × 2) core/message_bus/src/installer/replica.rs:457— core/message_bus/src/installer/replica.rs:457-473 | core/message_bus/src/installer/tcp.rs:134-148 — before extracting anything, compare `core/message_bus/src/installer/replica.rs` and `core/message_bus/src/installer/tcp.rs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 108 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (14–16 lines × 4) core/sdk/src/http/consumer_groups.rs:41— core/sdk/src/http/consumer_groups.rs:41-55 | core/sdk/src/http/consumer_offsets.rs:64-79 | core/sdk/src/http/streams.rs:35-48 | core/sdk/src/http/topics.rs:41-55 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from all 4 call sites, so a change lands once.
Duplicated block (11–16 lines × 3) core/common/src/types/args/mod.rs:438— core/common/src/types/args/mod.rs:438-448 | core/common/src/types/args/mod.rs:452-463 | core/common/src/types/args/mod.rs:473-488 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (10–16 lines × 2) core/server/src/dispatch/session_ops.rs:602— core/server/src/dispatch/session_ops.rs:602-617 | core/server/src/dispatch/session_ops.rs:810-819 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (15 lines × 7) core/connectors/sdk/src/decoders/avro.rs:193— core/connectors/sdk/src/decoders/avro.rs:193-207 | core/connectors/sdk/src/decoders/flatbuffer.rs:136-150 | core/connectors/sdk/src/decoders/proto.rs:540-554 | core/connectors/sdk/src/encoders/avro.rs:137-151 | core/connectors/sdk/src/encoders/flatbuffer.rs:82-96 | core/connectors/sdk/src/encoders/proto.rs:300-314 | core/connectors/sdk/src/transforms/proto_convert.rs:500-514 — before extracting anything, compare `core/connectors/sdk/src/decoders/avro.rs` and `core/connectors/sdk/src/decoders/flatbuffer.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 69 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (15 lines × 5) core/consensus/src/observability.rs:498— core/consensus/src/observability.rs:498-512 | core/consensus/src/observability.rs:532-546 | core/consensus/src/observability.rs:566-580 | core/consensus/src/observability.rs:600-614 | core/consensus/src/observability.rs:634-648 — all 5 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (12–15 lines × 2) core/integration/src/harness/disk.rs:96— core/integration/src/harness/disk.rs:96-107 | core/integration/src/harness/disk.rs:459-473 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (14 lines × 3) core/binary_protocol/src/primitives/options.rs:154— core/binary_protocol/src/primitives/options.rs:154-167 | core/binary_protocol/src/responses/system/describe_options.rs:72-85 | core/binary_protocol/src/responses/system/describe_options.rs:90-103 — there are 3 copies across 2 file(s) — more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart.
Duplicated block (10–14 lines × 3) core/partitions/src/iggy_partition.rs:7317— core/partitions/src/iggy_partition.rs:7317-7327 | core/partitions/src/iggy_partition.rs:7508-7517 | core/partitions/src/state_transfer.rs:2907-2920 — there are 3 copies across 2 file(s) — more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart.
Duplicated block (12–13 lines × 8) core/connectors/sdk/src/decoders/avro.rs:192— core/connectors/sdk/src/decoders/avro.rs:192-203 | core/connectors/sdk/src/decoders/flatbuffer.rs:135-146 | core/connectors/sdk/src/decoders/proto.rs:539-550 | core/connectors/sdk/src/encoders/avro.rs:136-147 | core/connectors/sdk/src/encoders/flatbuffer.rs:81-92 | core/connectors/sdk/src/encoders/proto.rs:299-310 | core/connectors/sdk/src/transforms/avro_convert.rs:89-101 | core/connectors/sdk/src/transforms/proto_convert.rs:499-510 — before extracting anything, compare `core/connectors/sdk/src/decoders/avro.rs` and `core/connectors/sdk/src/decoders/flatbuffer.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 69 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (12–13 lines × 3) core/sdk/src/quic/quic_client.rs:388— core/sdk/src/quic/quic_client.rs:388-399 | core/sdk/src/tcp/tcp_client.rs:313-325 | core/sdk/src/websocket/websocket_client.rs:384-395 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/tcp/tcp_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 134 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (8–13 lines × 2) core/partitions/src/iggy_partition.rs:8033— core/partitions/src/iggy_partition.rs:8033-8045 | core/partitions/src/state_transfer.rs:3257-3264 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once.
Duplicated block (12 lines × 13) core/consensus/src/observability.rs:492— core/consensus/src/observability.rs:492-503 | core/consensus/src/observability.rs:526-537 | core/consensus/src/observability.rs:560-571 | core/consensus/src/observability.rs:594-605 | core/consensus/src/observability.rs:628-639 | core/consensus/src/observability.rs:723-734 | core/consensus/src/observability.rs:748-759 | core/consensus/src/observability.rs:772-783 | core/consensus/src/observability.rs:798-809 | core/consensus/src/observability.rs:828-839 | core/consensus/src/observability.rs:857-868 | core/consensus/src/observability.rs:887-898 | core/consensus/src/observability.rs:913-924 — all 13 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (11 lines × 4) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:308— foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:308-318 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:782-792 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:809-819 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:906-916 — all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited. Read the line range as the matched WINDOW rather than a finished unit: at `foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:308` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (10–11 lines × 2) core/sdk/src/quic/quic_client.rs:921— core/sdk/src/quic/quic_client.rs:921-930 | core/sdk/src/websocket/websocket_client.rs:958-968 — `core/sdk/src/quic/quic_client.rs` and `core/sdk/src/websocket/websocket_client.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 16 separate duplicated blocks between them, totalling at least 414 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (10 lines × 5) core/consensus/src/observability.rs:481— core/consensus/src/observability.rs:481-490 | core/consensus/src/observability.rs:515-524 | core/consensus/src/observability.rs:549-558 | core/consensus/src/observability.rs:583-592 | core/consensus/src/observability.rs:617-626 — all 5 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (6–10 lines × 2) core/journal/src/partition_journal.rs:1782— core/journal/src/partition_journal.rs:1782-1787 | core/journal/src/partition_journal/segments.rs:790-799 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (7–9 lines × 2) core/consensus/src/vsr_timeout.rs:285— core/consensus/src/vsr_timeout.rs:285-293 | core/consensus/src/vsr_timeout.rs:310-316 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
Duplicated block (5–9 lines × 3) core/server_common/src/send_messages.rs:146— core/server_common/src/send_messages.rs:146-150 | core/server_common/src/send_messages.rs:333-341 | core/server_common/src/send_messages.rs:396-404 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (7–8 lines × 3) core/connectors/sdk/src/decoders/proto.rs:223— core/connectors/sdk/src/decoders/proto.rs:223-229 | core/connectors/sdk/src/encoders/proto.rs:263-270 | core/connectors/sdk/src/transforms/proto_convert.rs:260-267 — `core/connectors/sdk/src/decoders/proto.rs` and `core/connectors/sdk/src/encoders/proto.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 11 separate duplicated blocks between them, totalling at least 151 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (7 lines × 10) core/connectors/sources/postgres_source/src/lib.rs:1719— core/connectors/sources/postgres_source/src/lib.rs:1719-1725 | core/connectors/sources/postgres_source/src/lib.rs:1736-1742 | core/connectors/sources/postgres_source/src/lib.rs:1753-1759 | core/connectors/sources/postgres_source/src/lib.rs:1787-1793 | core/connectors/sources/postgres_source/src/lib.rs:1838-1844 | core/connectors/sources/postgres_source/src/lib.rs:1869-1875 | core/connectors/sources/postgres_source/src/lib.rs:1886-1892 | core/connectors/sources/postgres_source/src/lib.rs:1903-1909 | core/connectors/sources/postgres_source/src/lib.rs:1920-1926 | core/connectors/sources/postgres_source/src/lib.rs:1937-1943 — all 10 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (7 lines × 7) core/connectors/sdk/src/decoders/avro.rs:178— core/connectors/sdk/src/decoders/avro.rs:178-184 | core/connectors/sdk/src/decoders/flatbuffer.rs:121-127 | core/connectors/sdk/src/decoders/proto.rs:525-531 | core/connectors/sdk/src/encoders/avro.rs:122-128 | core/connectors/sdk/src/encoders/flatbuffer.rs:67-73 | core/connectors/sdk/src/encoders/proto.rs:283-289 | core/connectors/sdk/src/transforms/proto_convert.rs:488-494 — before extracting anything, compare `core/connectors/sdk/src/decoders/avro.rs` and `core/connectors/sdk/src/decoders/flatbuffer.rs` as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 69 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (3–6 lines × 4) core/shard/src/lib.rs:4494— core/shard/src/lib.rs:4494-4499 | core/shard/src/lib.rs:4548-4550 | core/shard/src/lib.rs:4643-4645 | core/shard/src/lib.rs:4932-4937 — all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited.
Duplicated block (5 lines × 9) core/binary_protocol/src/requests/consumer_groups/delete_consumer_group.rs:49— core/binary_protocol/src/requests/consumer_groups/delete_consumer_group.rs:49-53 | core/binary_protocol/src/requests/consumer_groups/get_consumer_group.rs:49-53 | core/binary_protocol/src/requests/consumer_groups/join_consumer_group.rs:49-53 | core/binary_protocol/src/requests/consumer_groups/leave_consumer_group.rs:49-53 | core/binary_protocol/src/requests/consumer_groups/sync_consumer_group.rs:52-56 | core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs:75-79 | core/binary_protocol/src/requests/consumer_offsets/get_consumer_offset.rs:68-72 | core/binary_protocol/src/requests/consumer_offsets/store_consumer_offset.rs:78-82 | core/binary_protocol/src/requests/messages/poll_messages.rs:85-89 — before extracting anything, compare `core/binary_protocol/src/requests/consumer_offsets/delete_consumer_offset.rs` and `core/binary_protocol/src/requests/consumer_offsets/get_consumer_offset.rs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 32 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together — extracting one helper per block leaves the fork in place.
Duplicated block (5 lines × 6) core/binary_protocol/src/requests/consumer_groups/create_consumer_group.rs:48— core/binary_protocol/src/requests/consumer_groups/create_consumer_group.rs:48-52 | core/binary_protocol/src/requests/consumer_groups/delete_consumer_group.rs:47-51 | core/binary_protocol/src/requests/consumer_groups/get_consumer_group.rs:47-51 | core/binary_protocol/src/requests/consumer_groups/join_consumer_group.rs:47-51 | core/binary_protocol/src/requests/consumer_groups/leave_consumer_group.rs:47-51 | core/binary_protocol/src/requests/consumer_groups/sync_consumer_group.rs:50-54 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from all 6 call sites, so a change lands once.
Duplicated block (23 lines × 3) core/binary_protocol/src/requests/topics/delete_topic.rs:31— core/binary_protocol/src/requests/topics/delete_topic.rs:31-53 | core/binary_protocol/src/requests/topics/get_topic.rs:31-53 | core/binary_protocol/src/requests/topics/purge_topic.rs:31-53 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from all 3 call sites, so a change lands once.
Duplicated block (5 lines × 4) foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:628— foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:628-632 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:756-760 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:764-768 | foreign/csharp/Iggy_SDK/Contracts/Tcp/TcpContracts.cs:771-775 — all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (11–14 lines × 3) foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/tcp/ConsumerGroupsTcpClient.java:141— foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/tcp/ConsumerGroupsTcpClient.java:141-154 | foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/tcp/ConsumerGroupsTcpClient.java:164-177 | foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/tcp/ConsumerGroupsTcpClient.java:188-198 — all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites — resolving only two of them leaves the rest to drift apart the first time one is edited. The `return` at the foot of the matched lines is the enclosing body's own terminal exit, not an early one: it moves with them unchanged, and each site calls the extracted unit from the position that `return` occupied — no decision has to be handed back and re-acted on.
Duplicated block (8 lines × 5) foreign/go/internal/command/offset.go:53— foreign/go/internal/command/offset.go:53-60 | foreign/go/internal/command/offset.go:99-106 | foreign/go/internal/command/offset.go:143-150 | foreign/go/internal/command/partition.go:37-44 | foreign/go/internal/command/partition.go:67-74 — there are 5 copies across 2 file(s) — more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 5 sites; resolving a subset leaves the remainder to drift apart. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Near-duplicate member pair (34 shared lines) core/bench/report/src/types/group_metrics.rs:42— core/bench/report/src/types/group_metrics.rs:42-123 | core/bench/report/src/types/individual_metrics.rs:43-121 — These two members are variants of one another: 34 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members' grain — factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice.
Duplicated block (73 lines × 3) core/bench/src/actors/consumer/benchmark_consumer.rs:315— core/bench/src/actors/consumer/benchmark_consumer.rs:315-387 | core/bench/src/actors/producer/benchmark_producer.rs:325-397 | core/bench/src/actors/producing_consumer/benchmark_producing_consumer.rs:405-477 — `core/bench/src/actors/consumer/benchmark_consumer.rs` and `core/bench/src/actors/producer/benchmark_producer.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 201 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (38 lines × 2) examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs:48— examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs:48-85 | examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Producer/Utils.cs:49-86 — before extracting anything, compare `examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs` and `examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Producer/Utils.cs` as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 87 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Read the line range as the matched WINDOW rather than a finished unit: at `examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs:48` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (26 lines × 8) examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Consumer/Utils.cs:101— examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Consumer/Utils.cs:101-126 | examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Producer/Utils.cs:96-121 | examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Consumer/Utils.cs:129-154 | examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Producer/Utils.cs:104-129 | examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Consumer/Utils.cs:130-155 | examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Producer/Utils.cs:109-134 | examples/csharp/src/NewSdk/Iggy_SDK.Examples.NewSdk.Consumer/Utils.cs:71-96 | examples/csharp/src/NewSdk/Iggy_SDK.Examples.NewSdk.Producer/Utils.cs:84-109 — before extracting anything, compare `examples/csharp/src/GettingStarted/Iggy_SDK.Examples.GettingStarted.Consumer/Utils.cs` and `examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Consumer/Utils.cs` as WHOLE FILES: 89% of the shorter file's lines also appear in the other, so this reads as one file having been copied from the other rather than as a helper waiting to be extracted. The 2 duplicated block(s) this scan matched between them are fragments of that copy, not the extent of it — treat the file pair as the unit. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it.
Duplicated block (21 lines × 3) core/bench/src/actors/consumer/benchmark_consumer.rs:218— core/bench/src/actors/consumer/benchmark_consumer.rs:218-238 | core/bench/src/actors/producer/benchmark_producer.rs:228-248 | core/bench/src/actors/producing_consumer/benchmark_producing_consumer.rs:305-325 — `core/bench/src/actors/consumer/benchmark_consumer.rs` and `core/bench/src/actors/producer/benchmark_producer.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 201 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (20 lines × 3) examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Consumer/Utils.cs:104— examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Consumer/Utils.cs:104-123 | examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Consumer/Utils.cs:105-124 | examples/csharp/src/NewSdk/Iggy_SDK.Examples.NewSdk.Consumer/Utils.cs:46-65 — before extracting anything, compare `examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Consumer/Utils.cs` and `examples/csharp/src/MessageHeaders/Iggy_SDK.Examples.MessageHeaders.Consumer/Utils.cs` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 99 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Read the line range as the matched WINDOW rather than a finished unit: at `examples/csharp/src/MessageEnvelope/Iggy_SDK.Examples.MessageEnvelope.Consumer/Utils.cs:104` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names — the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately. Note first that the copies are not typed on the same thing: the declarations holding them bind `message` to `MessageResponse` in one and `ReceivedMessage` in another, and the duplicated lines use it. The extracted unit therefore needs a parameter type that fits BOTH — their common supertype where they have one, or a new abstraction over them where they do not — and settling that is the step that comes BEFORE the extraction above. Where the two types are deliberately unrelated, the duplication is the price of that separation and the honest resolution is to record the decision rather than to extract.
Duplicated block (15–16 lines × 2) core/bench/dashboard/frontend/src/components/embed_modal.rs:86— core/bench/dashboard/frontend/src/components/embed_modal.rs:86-100 | core/bench/dashboard/frontend/src/components/tooltips/benchmark_info_tooltip.rs:42-57 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice.
Duplicated block (25 lines × 3) core/bench/src/actors/consumer/benchmark_consumer.rs:193— core/bench/src/actors/consumer/benchmark_consumer.rs:193-217 | core/bench/src/actors/producer/benchmark_producer.rs:203-227 | core/bench/src/actors/producing_consumer/benchmark_producing_consumer.rs:280-304 — `core/bench/src/actors/consumer/benchmark_consumer.rs` and `core/bench/src/actors/producer/benchmark_producer.rs` are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other — this scan matched 8 separate duplicated blocks between them, totalling at least 201 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own.
Duplicated block (34 lines × 2) examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/producer/GettingStartedProducer.java:70— examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/producer/GettingStartedProducer.java:70-103 | examples/java/src/main/java/org/apache/iggy/examples/tcptls/producer/TcpTlsProducer.java:91-124 — before extracting anything, compare `examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/producer/GettingStartedProducer.java` and `examples/java/src/main/java/org/apache/iggy/examples/tcptls/producer/TcpTlsProducer.java` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 51 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any `return` inside it is the body's own exit and keeps its meaning in the moved unit.
Duplicated block (24 lines × 4) examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java:70— examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java:70-93 | examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/consumer/MessageEnvelopeConsumer.java:79-102 | examples/java/src/main/java/org/apache/iggy/examples/messageheaders/consumer/MessageHeadersConsumer.java:81-104 | examples/java/src/main/java/org/apache/iggy/examples/tcptls/consumer/TcpTlsConsumer.java:91-114 — before extracting anything, compare `examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java` and `examples/java/src/main/java/org/apache/iggy/examples/messageenvelope/consumer/MessageEnvelopeConsumer.java` as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 86 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Read the line range as the matched WINDOW rather than a finished unit: at `examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java:70` it does not close everything it opens, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that. ★ These copies have DRIFTED, and that is worth reading before extracting anything: just after the matched lines, `examples/java/src/main/java/org/apache/iggy/examples/gettingstarted/consumer/GettingStartedConsumer.java:94` calls `sleep` and `examples/java/src/main/java/org/apache/iggy/examples/messageheaders/consumer/MessageHeadersConsumer.java:105` does not — after which the two agree again for 3 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live.
Duplicated block (14–15 lines × 2) examples/java/src/main/java/org/apache/iggy/examples/async/AsyncConsumer.java:147— examples/java/src/main/java/org/apache/iggy/examples/async/AsyncConsumer.java:147-161 | examples/java/src/main/java/org/apache/iggy/examples/async/AsyncProducer.java:95-108 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at `examples/java/src/main/java/org/apache/iggy/examples/async/AsyncConsumer.java:147` it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand — widen the region to the smallest complete statement or declaration that contains it, and extract that.
Duplicated block (35 lines × 2) examples/python/getting-started/consumer.py:70— examples/python/getting-started/consumer.py:70-104 | examples/python/getting-started/producer.py:69-103 — the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach — a file they already depend on, or a new one alongside them — and call it from both call sites, so a change lands once. The `return` at the foot of the matched lines is the enclosing body's own terminal exit, not an early one: it moves with them unchanged, and each site calls the extracted unit from the position that `return` occupied — no decision has to be handed back and re-acted on.
Duplicated block (28 lines × 2) examples/go/getting-started/consumer/main.go:141— examples/go/getting-started/consumer/main.go:141-168 | examples/go/getting-started/producer/main.go:137-164 — the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach — a location they all depend on today, or a new shared one if there is none — and call it from each site; until then, every change has to be made twice. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any `return` inside it is the body's own exit and keeps its meaning in the moved unit.
Low cohesion: Permissions (LCOM4 4) core/ai/mcp/src/main.rs:189— Permissions's methods fall into 4 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable — your repository's bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 4 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected — and which would otherwise dominate this list — are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting.
No DR/backup evidence — A persistence guard (data volume / purge-protection) was found, but no backup, geo-recovery or RTO/RPO controls were evidenced — a volume that survives a container recreate is not a tested restore from catastrophic loss.
Awaits without ConfigureAwait(false) — Only 0/423 awaits use ConfigureAwait(false). A library that captures the caller's context can stall or deadlock its host — the classic way a dependency drags an app down.
Duplication concentrated across 9 sibling directories (17 clone groups) foreign/node/src/wire/client/get-clients.command.ts:23— 17 duplicated blocks under foreign/node/src/wire/ have copies in at least two of the sibling directories client, consumer-group, partition, session, stream, system (+3 more sibling(s) not listed) — 11 of them are reported below, and 6 are counted here but not reported individually: those copies match on shape but no longer clear R10's bar for an individually reported row — either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 17 and which does not depend on how exactly each block's copies still match. That concentration is one structural fact, not 17 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module — a common library every sibling imports — rather than 17 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on.
Duplicated block (65 lines × 2 locations) web/src/lib/components/Modals/AddPartitionsModal.svelte:49— web/src/lib/components/Modals/AddPartitionsModal.svelte:49 · web/src/lib/components/Modals/DeletePartitionsModal.svelte:65 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it.
Duplicated block (50 lines × 2 locations) web/src/lib/components/Modals/AddTopicModal.svelte:66— web/src/lib/components/Modals/AddTopicModal.svelte:66 · web/src/lib/components/Modals/AddUserModal.svelte:62 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (38 lines × 2 locations) web/src/lib/components/Modals/AddStreamModal.svelte:45— web/src/lib/components/Modals/AddStreamModal.svelte:45 · web/src/lib/components/Modals/StreamSettingsModal.svelte:57 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
R10 · Code Duplication· Duplicated block with local edits (36 matched lines × 2 locations) · ×1
Duplicated block with local edits (36 matched lines × 2 locations) foreign/node/src/wire/topic/create-topic.command.ts:61— foreign/node/src/wire/topic/create-topic.command.ts:61 · foreign/node/src/wire/topic/update-topic.command.ts:41 — the two spans are one implementation copied and then locally edited — 212 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block (29 lines × 2 locations) web/src/lib/components/RouteComponents/Settings/UsersTab.svelte:46— web/src/lib/components/RouteComponents/Settings/UsersTab.svelte:46 · web/src/routes/dashboard/settings/users/+page.svelte:48 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
R10 · Code Duplication· Duplicated block with local edits (27 matched lines × 2 locations) · ×1
Duplicated block with local edits (27 matched lines × 2 locations) web/src/lib/components/SlimSortableList.svelte:24— web/src/lib/components/SlimSortableList.svelte:24 · web/src/lib/components/SortableList.svelte:27 — the two spans are one implementation copied and then locally edited — 213 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block (20 lines × 2 locations) foreign/node/src/debug-send.ts:94— foreign/node/src/debug-send.ts:94 · foreign/node/src/debug.ts:92 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
R10 · Code Duplication· Duplicated block with local edits (20 matched lines × 2 locations) · ×1
Duplicated block with local edits (20 matched lines × 2 locations) web/src/lib/components/Modals/StreamSettingsModal.svelte:103— web/src/lib/components/Modals/StreamSettingsModal.svelte:103 · web/src/lib/components/Modals/StreamSettingsModal.svelte:135 — the two spans are one implementation copied and then locally edited — 75 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block (17 lines × 2 locations) foreign/node/src/wire/message/header.utils.ts:314— foreign/node/src/wire/message/header.utils.ts:314 · foreign/node/src/wire/message/header.utils.ts:333 — both copies are in the same file, so extract the block into one function there and call it from each site — the copies drift apart the first time only one of them is edited.
R10 · Code Duplication· Duplicated block with local edits (15 matched lines × 2 locations) · ×1
Duplicated block with local edits (15 matched lines × 2 locations) foreign/node/src/duration.utils.ts:175— foreign/node/src/duration.utils.ts:175 · foreign/node/src/duration.utils.ts:258 — the two spans are one implementation copied and then locally edited — 81 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row's finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters — or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one.
Duplicated block (13 lines × 2 locations) foreign/node/src/debug-send.ts:52— foreign/node/src/debug-send.ts:52 · foreign/node/src/debug.ts:49 — the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Duplicated block (11 lines × 5 locations) foreign/node/src/wire/stream/delete-stream.command.ts:20— foreign/node/src/wire/stream/delete-stream.command.ts:20 · foreign/node/src/wire/stream/get-stream.command.ts:21 · foreign/node/src/wire/stream/purge-stream.command.ts:20 · foreign/node/src/wire/topic/get-topics.command.ts:21 · +1 more site(s) not listed — the 5 copies are spread across 5 files, and the SHAPE of this repetition could not be determined. It is not a run of declarations, a listing, a declaration header, a type body or a slice through a construct — and it was not measured as a run of executable statements either, so this row cannot tell you whether a function can stand where these lines are. Read the two spans before acting, because the move is opposite in the two cases. Where they are statements, the ordinary answer holds: give the shared part one home and call it from each site. Where they turn out to be declarations, a literal's entries, or the cases of an enumeration, there is no call site to call anything from, and collapsing them would delete what each copy pins — a shared base type, a generated set, or one exported constant each site refers to is the move instead, and sometimes the honest answer is that there is nothing to extract at all. Reported because the copies drift apart the first time only one of them is edited, which is true whichever of those they are.
Duplicated block (11 lines × 2 locations) web/src/lib/api/clientApi.ts:35— web/src/lib/api/clientApi.ts:35 · web/src/lib/api/fetchRouteApi.ts:28 — the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it.
Duplicated block (10 lines × 5 locations) foreign/node/src/wire/number.utils.ts:26— foreign/node/src/wire/number.utils.ts:26 · foreign/node/src/wire/number.utils.ts:50 · foreign/node/src/wire/number.utils.ts:74 · foreign/node/src/wire/number.utils.ts:98 · +1 more site(s) not listed — all 5 copies are in the same file, and the CITED SPAN is not a self-contained block — it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead — the whole function, component or branch these lines sit in — and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported.
Complex function _pollOnPrimary (cyclomatic 40, cognitive 87) foreign/node/src/client/client.socket.ts:586— _pollOnPrimary has cyclomatic complexity 40 and cognitive complexity 87; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function sendCommand (cyclomatic 32, cognitive 50) foreign/node/src/client/client.socket.ts:305— sendCommand has cyclomatic complexity 32 and cognitive complexity 50; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function _processVsr (cyclomatic 29, cognitive 44) foreign/node/src/client/client.socket.ts:879— _processVsr has cyclomatic complexity 29 and cognitive complexity 44; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function (anonymous) (cyclomatic 23, cognitive 22) foreign/node/src/client/client.connection-string.ts:59— (anonymous) has cyclomatic complexity 23 and cognitive complexity 22; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function (anonymous) (cyclomatic 21, cognitive 19) foreign/node/src/client/client.config.ts:35— (anonymous) has cyclomatic complexity 21 and cognitive complexity 19; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function _reconnectUntilConnected (cyclomatic 19, cognitive 35) foreign/node/src/client/client.connection.ts:408— _reconnectUntilConnected has cyclomatic complexity 19 and cognitive complexity 35; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function (anonymous) (cyclomatic 19, cognitive 5) foreign/node/src/wire/vsr/reply.ts:129— (anonymous) has cyclomatic complexity 19 and cognitive complexity 5; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function serialize (cyclomatic 18, cognitive 21) foreign/node/src/wire/topic/create-topic.command.ts:86— serialize has cyclomatic complexity 18 and cognitive complexity 21; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function (anonymous) (cyclomatic 18, cognitive 5) web/src/lib/components/Modals/InspectMessage.svelte:38— (anonymous) has cyclomatic complexity 18 and cognitive complexity 5; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth — arms side by side rather than stacked — and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function parse (cyclomatic 15, cognitive 29) foreign/node/src/duration.utils.ts:159— parse has cyclomatic complexity 15 and cognitive complexity 29; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function _rememberCredentials (cyclomatic 15, cognitive 20) foreign/node/src/client/client.socket.ts:748— _rememberCredentials has cyclomatic complexity 15 and cognitive complexity 20; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function (anonymous) (cyclomatic 14, cognitive 14) foreign/node/src/client/client.connection-string.ts:151— (anonymous) has cyclomatic complexity 14 and cognitive complexity 14; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function _processQueue (cyclomatic 13, cognitive 19) foreign/node/src/client/client.socket.ts:796— _processQueue has cyclomatic complexity 13 and cognitive complexity 19; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Complex function (anonymous) (cyclomatic 13, cognitive 18) foreign/node/src/client/client.socket.test.ts:358— (anonymous) has cyclomatic complexity 13 and cognitive complexity 18; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side — extracting each decision into its own named function is the change that pays. Measured by this repository's own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes.
Dead file (~363 LoC) web/src/lib/components/PermissionsManager.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AddUserModal.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~187 LoC) web/src/lib/api/ApiSchema.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/api/fetchRouteApi.ts) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~177 LoC) web/src/lib/actions/tooltip.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~166 LoC) web/src/lib/domain/Stats.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~157 LoC) web/src/lib/components/Modals/StreamSettingsModal.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AppModals.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~146 LoC) web/src/lib/components/DurationInput.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (web/src/lib/components/Modals/AddTopicModal.svelte, web/src/lib/components/Modals/TopicSettingsModal.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~134 LoC) web/src/lib/components/Modals/DeletePartitionsModal.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AppModals.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~126 LoC) foreign/node/src/debug-send.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~121 LoC) foreign/node/src/debug.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~119 LoC) web/src/lib/components/Modals/AddUserModal.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AppModals.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~116 LoC) web/src/lib/components/Modals/InspectMessage.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AppModals.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~108 LoC) web/src/lib/components/SortableList.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~104 LoC) web/src/lib/api/clientApi.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~100 LoC) web/src/lib/components/Modals/AddStreamModal.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AppModals.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~92 LoC) web/src/lib/domain/Permissions.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/domain/UserDetails.ts) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~90 LoC) web/src/lib/domain/Message.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/domain/MessageDetails.ts) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~89 LoC) web/src/lib/components/Icon.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 17 in-repo import(s) from 15 other file(s) do name it (web/src/lib/components/AppToasts.svelte, web/src/lib/components/Breadcrumbs.svelte, web/src/lib/components/Combobox.svelte and 12 more) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~88 LoC) web/src/lib/components/MessageDecoder/MessageDecoder.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~85 LoC) web/src/lib/components/RouteComponents/Settings/UsersTab.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/RouteComponents/Settings/UsersTabActions.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~84 LoC) web/src/lib/api/handleFetchErrors.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), and no other file in the scanned tree imports it — nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make
Dead file (~82 LoC) web/src/lib/components/AppToasts.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 8 in-repo import(s) from 8 other file(s) do name it (web/src/lib/components/Modals/AddPartitionsModal.svelte, web/src/lib/components/Modals/AddStreamModal.svelte, web/src/lib/components/Modals/AddTopicModal.svelte and 5 more) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~74 LoC) web/src/lib/api/getJson.ts— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 3 in-repo import(s) from 3 other file(s) do name it (web/src/lib/api/clientApi.ts, web/src/lib/api/fetchRouteApi.ts, web/src/lib/api/handleFetchErrors.ts) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~71 LoC) web/src/lib/components/Breadcrumbs.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Header.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~69 LoC) web/src/lib/components/PeriodicInvalidator.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 8 in-repo import(s) from 8 other file(s) do name it (web/src/lib/components/Header.svelte, web/src/lib/components/Modals/AddPartitionsModal.svelte, web/src/lib/components/Modals/AddStreamModal.svelte and 5 more) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~67 LoC) web/src/lib/components/Listbox.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (web/src/lib/components/Modals/AddUserModal.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Dead file (~62 LoC) web/src/lib/components/Select.svelte— no import path from any entry point (40 application, 11 tooling, 57 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (web/src/lib/components/MessageDecoder/MessageDecoder.svelte, web/src/lib/components/Modals/AddTopicModal.svelte) — every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it
Unused dependency 'ccusage' — Declared in the root package.json but never imported anywhere in that package or its workspace members — no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it.
Unused dependency 'd3-interpolate' — Declared in web/package.json but never imported anywhere in that package or its workspace members — no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it.
Unused dependency 'svelte-popperjs' — Declared in web/package.json but never imported anywhere in that package or its workspace members — no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it.
Silent fallback default on Err core/bench/dashboard/frontend/src/components/selectors/dense_benchmark_row.rs:151— `relative_time` turns every `Err` into `"-".to_string()` — a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with `?`. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing.
Silent fallback default on Err core/common/src/types/message/user_headers.rs:542— `to_string_value` turns every `Err` into `"<malformed int8>".to_string()` — a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with `?`. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing.
Silent fallback default on Err core/connectors/runtime/src/configs/runtime.rs:451— `state_url_label` turns every `Err` into `"<invalid URL>".to_string()` — a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with `?`. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing.
Silent fallback default on Err core/connectors/sinks/meilisearch_sink/src/lib.rs:968— `sanitize_url_for_log` turns every `Err` into `"<invalid-url>".to_string()` — a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with `?`. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing.
Silent fallback default on Err core/integration/src/harness/handle/server.rs:223— `stdout_plain` turns every `Err` into `String::new()` — a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with `?`. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing.
Silent fallback default on Err core/metadata/src/stm/stream.rs:2331— `encode_create_topic_reply` turns every `Err` into `Bytes::new()` — a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with `?`. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing.
Silent fallback default on Err core/partitions/src/state_transfer.rs:3924— `offset_dir_entries` turns every `Err` into `Vec::new()` — a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with `?`. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing.
Off-boarding risk: anonymized user #1 — If anonymized user #1 becomes unavailable, 19 significant file(s) lose their only recent owner: core/message_bus/src/lifecycle/connection_registry.rs, core/message_bus/src/transports/tcp_tls.rs, core/server/src/http/jwt.rs, core/configs/src/server_config/message_bus.rs, core/message_bus/src/transports/tls/mod.rs, core/bench/src/analytics/metrics/individual.rs, core/bench/dashboard/shared/src/subtext.rs, core/integration/src/harness/handle/mcp.rs (+11 more). Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #2 — If anonymized user #2 becomes unavailable, 16 significant file(s) lose their only recent owner: foreign/csharp/Iggy_SDK/Publishers/BackgroundMessageProcessor.cs, foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Rented.cs, foreign/csharp/Iggy_SDK/Publishers/IggyPublisherOfT.cs, foreign/csharp/Iggy_SDK/Kinds/Partitioning.cs, foreign/csharp/Iggy_SDK/Consumers/IggyConsumer.Logging.cs, foreign/csharp/Iggy_SDK/Consumers/IggyConsumerBuilderOfT.cs, foreign/csharp/Iggy_SDK/Publishers/IggyPublisherBuilderOfT.cs, foreign/csharp/Iggy_SDK/Identifier.cs (+8 more). Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #3 — If anonymized user #3 becomes unavailable, 4 significant file(s) lose their only recent owner: foreign/java/bench/src/main/java/org/apache/iggy/bench/cli/PinnedProducerCommand.java, foreign/java/bench/src/main/java/org/apache/iggy/bench/cli/IggyBenchCommand.java, foreign/java/bench/src/main/java/org/apache/iggy/bench/benchmarks/runners/tcp/async/TcpAsyncPinnedProducer.java, foreign/java/bench/src/main/java/org/apache/iggy/bench/models/cli/GlobalCliArgs.java. Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #4 — If anonymized user #4 becomes unavailable, 3 significant file(s) lose their only recent owner: core/bench/dashboard/frontend/src/components/layout/hero.rs, core/bench/dashboard/frontend/src/components/layout/top_app_bar.rs, core/bench/dashboard/frontend/src/components/layout/main_content.rs. Pair on, review, or document these before any departure.
Off-boarding risk: anonymized user #5 — If anonymized user #5 becomes unavailable, 3 significant file(s) lose their only recent owner: core/system_stats/src/cgroup_memory.rs, foreign/java/java-sdk/src/main/java/org/apache/iggy/client/blocking/tcp/IggyTcpClientBuilder.java, foreign/java/java-sdk/src/main/java/org/apache/iggy/client/async/tcp/vsr/VsrLoginCodec.java. Pair on, review, or document these before any departure.
D16 · Bus Factor· Further sole-owners (lower concentration) · ×1
Further sole-owners (lower concentration) — 6 other contributor(s) are each the sole owner of a small amount of code below the off-boarding threshold — folded into the bus-factor score and metrics (54 single-owned of 1199 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 1199 of the 1968 production source files in this repository met that bar). They are anonymized user #6 (2 file(s)), anonymized user #7 (2 file(s)), anonymized user #8 (2 file(s)), anonymized user #9 (1 file(s)), anonymized user #10 (1 file(s)), anonymized user #11 (1 file(s)) — spread or document their files in the same way, at lower priority than the named off-boarding risks above.
Documentation: no architecture or design documentation core/server/README.md— The Running section describes how to run the server with cargo run but does not mention the architecture or design docs that accompany the core server component (thread-per-core io_uring, shared-nothing compio, VSR). Link to the architecture/design documentation for the core server.
D21 · Naming Consistency· Inconsistent use of 'Stop' vs 'Return' for test outcomes. The first test uses 'ReturnImmediately' to describe the method's return behavior, while the second uses 'StopCleanly' to describe the termination of an async operation. In the context of async cancellation, 'Return' or 'Complete' is more consistent with the 'ReturnImmediately' pattern, whereas 'Stop' is less precise for a method named 'ReceiveDeserializedAsync'. · ×1
Inconsistent use of 'Stop' vs 'Return' for test outcomes. The first test uses 'ReturnImmediately' to describe the method's return behavior, while the second uses 'StopCleanly' to describe the termination of an async operation. In the context of async cancellation, 'Return' or 'Complete' is more consistent with the 'ReturnImmediately' pattern, whereas 'Stop' is less precise for a method named 'ReceiveDeserializedAsync'. — Use 'Return' or 'Complete' consistently for async method termination scenarios (e.g., 'ReceiveDeserializedAsync_Should_ReturnImmediately_OnCancellation'). (symbols: Method: Apache.Iggy.Tests.Integrations.IggyPublisherTests.WaitUntilAllSends_WithoutBackgroundSending_Should_ReturnImmediately, Method: Apache.Iggy.Tests.Integrations.IggyTypedConsumerTests.ReceiveDeserializedAsync_Should_StopCleanly_OnCancellation)
D26 · Project Cohesion· Projects may be oversized for their cohesion · ×1
Projects may be oversized for their cohesion — 1 of 19 project(s) overshoot their size bounds, lowering Project Cohesion to 8.9/10. The most over is `Iggy_SDK(net8.0)` (20443 LoC, 126 public types across 20 namespaces). Review these for cohesion — draw the boundary inside the assembly first (group each responsibility into its own namespace/folder and keep the cross-boundary members internal), since splitting a published assembly moves types between packages and breaks consumers.
D28 · Secrets (history)· Rotate the exposed credentials · ×1
D34 · Knowledge Freshness· Further orphaned files (smaller) · ×1
Further orphaned files (smaller) — 110 smaller file(s) also have no living knowledge — folded into the freshness score and metrics rather than raised one row each — most significant first: core/connectors/sinks/s3_sink/src/lib.rs, core/cli/src/args/permissions/global.rs, core/connectors/sdk/src/encoders/flatbuffer.rs, core/cli/src/args/user.rs, core/connectors/sdk/src/transforms/json/filter_fields.rs, core/cli/src/args/permissions/topic.rs, foreign/java/external-processors/iggy-connector-flink/iggy-flink-examples/src/main/java/org/apache/iggy/flink/example/MultiStreamJoinJob.java, foreign/java/external-processors/iggy-connector-flink/iggy-connector-library/src/main/java/org/apache/iggy/connector/flink/source/IggySourceSplitEnumerator.java (and 102 more) (111 orphaned of 1199 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 1199 of the 1968 production source files in this repository met that bar). Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway.
D40 · Network Egress Confinement· No network policy · ×1
No network policy — No Kubernetes NetworkPolicy (or Cilium policy) found. Without one, every pod can talk to every other pod and reach out to the internet by default. Add a default-deny policy and open only the flows you need.
No AppArmor/SELinux confinement — Workloads declare no AppArmor or SELinux profile. A mandatory-access-control profile confines what a compromised container can touch on the host, complementing seccomp's syscall filter.
No ADRs — No Architecture Decision Records found — no conventional ADR directory, no numbered `NNNN-title` documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer.
P12 · CI test-gate honesty· Sleep-based test synchronization · ×1
Sleep-based test synchronization — 12 Task.Delay/Thread.Sleep call(s) in test code synchronize with background work by sleeping — a known flakiness precursor on slow runners. Prefer polling with a deadline or completion signals.
No changelog — No CHANGELOG/HISTORY/RELEASES file — what shipped when isn't easy to reconstruct for support or audit. (Versioning/tagging makes releases traceable, but a changelog records the what.)
PF1 · Benchmark discipline· No performance benchmarks · ×1
No performance benchmarks — No benchmark suite was found by the two searches this check runs. FIRST, a BenchmarkDotNet package reference in any project file — every project the workspace loaded, plus a walk of project files on disk that never loaded, because a benchmark suite is exactly the project a partial load drops. SECOND, a script harness: a file whose name contains `benchmark` and ends `.py`, `.sh`, `.ps1`, `.bash`, `.rb`, `.js` or `.mjs`, credited ONLY when this repository's CI text also mentions benchmarks — a harness no pipeline runs is read as a fixture, deliberately. Neither search can see a benchmark suite in another ecosystem's idiom (a Go `testing.B` file, a JMH or criterion project, a pytest-benchmark run), so this is 'no benchmark found by those two searches', not a verdict that the repository has none. Where code is performance-sensitive, a benchmark guards against silent regressions — but it's a bonus here, not a deduction.
Duplicated predicate core/message_bus/src/transports/ws.rs:505— `recv_res.is_err() || recv_res.expect("timeout outer").is_err()` appears character-identically in 2 files — core/message_bus/src/transports/ws.rs, core/message_bus/src/transports/wss.rs. It is one line, so the duplication detector's token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home.
X2 · Cancellation propagation· Not all async methods take a CancellationToken · ×1
Not all async methods take a CancellationToken — Only 157/176 async methods accept a CancellationToken, so in-flight work can't be stopped early when the caller gives up — whatever ends it in your host (shutdown signal, timeout, abandoned request, user cancel). Thread a token through the call chain and honour it at each await and loop; where a method genuinely cannot be interrupted, omitting it is a deliberate choice — judge against your hosting model.
Null-forgiving operator (`!`) suppressions reduce the NRT score — ~0.5 `!` suppressions per 1k syntax nodes — 37 suppression(s) across the 75382 syntax node(s) in code where nullable warnings are ENABLED, which is the only code a `!` can suppress anything in (a `!` under `#nullable disable` is inert and is not counted, and its file's nodes are not in the denominator). Each one tells the compiler to trust you about null, suppressing the very safety NRTs provide.
Every external tool invocation behind a deep-scan dimension — the tool, its captured version, the exact command, how many findings it yielded, and a link to the retained raw output. To reproduce any finding: check out the same commit and run the command shown (repo-relative — never an absolute scratch path). The complete raw scanner output is retained verbatim under artifacts/raw/ (indexed in artifacts/raw/index.json); per-invocation exit codes and wall-clock durations are in sidecar.json — kept out of this table so the rendered report stays byte-identical across runs of the same commit.
semgrep: not applicable — No personal data was found crossing a boundary the PII/GDPR ruleset checks — nothing written to a log or console sink, placed in a URL or query string, or persisted to browser storage. That is a clean result for the LEAK surface only: this ruleset detects personal data escaping, it does not inventory the personal data a repository holds, so it is not evidence that this repository has no personal-data surface. The personal-data map (Appendix C) and the C1-C5 compliance cards are what speak to that. semgrep could not parse 10 file(s) — `foreign/csharp/Iggy_SDK/Exceptions/VsrRequestOutcomeUnknownException.cs`, `foreign/csharp/Iggy_SDK/Exceptions/VsrSessionEvictedException.cs`, `foreign/csharp/Iggy_SDK/Utils/ArrayPoolHelper.cs`, `foreign/csharp/Iggy_SDK/Vsr/ConsumerGroupClientState.cs`, `foreign/csharp/Iggy_SDK/Vsr/VsrConnection.cs`, … (+5 more) — so the PII/GDPR sweep did not cover the unparsed regions of them; rows reported elsewhere in those files are real.
runtime-hardening: not applicable — The repository ships application workloads but no cluster-governance resources (CRDs, admission webhooks, or a committed policy engine). Runtime threat-detection (Falco/Tetragon) and admission control (Kyverno/OPA-Gatekeeper/PodSecurity) are cluster-OPERATOR controls owned by the platform, not shipped by an application repo/chart — nothing for this repo to assess.
Run 01a0f0fe-10f9-7b7e-9bc7-d1d1a36b6254 · every finding is also locatable in findings.md, and the complete scoring record (with exit codes + durations) in sidecar.json.
Issues: 277 · Warnings: 1461 · Recommendations: 47 · Info: 56 — Appendix A · all findings · full markdown report.
Generated by Watchdog — deterministic code-health analysis. 30-09-2026 @ 06:26 UTC.
Downloadable artifacts
Machine-readable and reproducible from this commit + frozen rubric — drop them straight into a contract appendix, a CRA dossier, or a downstream SCA / VEX tool.