@@ -141,8 +141,9 @@ Execute your task as follows:
141141
142142 ** Signature-based candidate matching (Phase 3) — TIGHTENS, never replaces:**
143143 ` signature ` may only PROMOTE a pair to "candidate for the pairwise snapshot
144- check"; it may NEVER by itself cause a hard DUPLICATE/trash. A pair is
145- eligible for hard-DUPLICATE treatment ONLY if it satisfies BOTH:
144+ check"; it may NEVER by itself cause a hard DUPLICATE/trash. A pair is a
145+ candidate for the Pairwise Snapshot Match Check below ONLY if it satisfies
146+ BOTH:
146147
147148 - it matches under today's ` code_paths ` + ` title ` similarity, comparing
148149 ` code_paths ` entries line-inclusively (WITH their trailing ` :line ` ); AND
@@ -200,6 +201,18 @@ Execute your task as follows:
200201 inherit the archived finding's ` lineage_id ` onto the current finding (so
201202 the lineage chain is preserved for report folding even when the findings
202203 are on different snapshots).
204+
205+ > [ !IMPORTANT] ** STATUS & DUPLICATE INVARIANTS:**
206+ >
207+ > - A finding MUST NOT carry both ` duplicate_of ` and ` possible_duplicate_of `
208+ > pointing to the same target UUID.
209+ > - ` status = "DUPLICATE" ` MUST NOT coexist with ` possible_duplicate_of `
210+ > pointing to the same target UUID.
211+ > - Under ** NOT_MATCHED** , the finding's ` status ` MUST remain active (e.g.
212+ > ` VALID ` , ` PROVISIONALLY_VALID ` , ` NEEDS_RESEARCH ` ), ` duplicate_of ` MUST
213+ > NOT be set, and the finding MUST NOT be moved to ` .trash/ ` . Setting
214+ > ` possible_duplicate_of ` is a non-terminal hint only.
215+
203216 - ** POSSIBLE REGRESSION:** if the archived match has a RESOLVED status
204217 (` patch_status ` in {` VERIFIED_SECURE ` ,` MITIGATION_PROPOSED ` } OR
205218 ` status ` ==` FALSE_POSITIVE ` OR ` production_viability ` ==` NON_VIABLE ` ) AND the
0 commit comments