High coverage still hides untested guards
A mutation sweep found four untested runtime guards behind statement coverage of 98.56 percent.

A coverage gate in the high nineties says nothing about assertion strength. Our Muniment Mobile sweep deleted or inverted runtime guards and found four breaks that their suites did not notice.
High coverage gave us the wrong comfort
The full run measured 98.56 percent of statements, 95.41 percent of branches, and 96.53 percent of functions. It covered 246 test suites and 2809 tests.
Those totals showed that lines ran. They did not show whether an assertion could notice a meaningful line disappear.
Our sweep covered a speech-input controller, a theme hook, and seven top-level screens. For each mutation, we ran only the suite that covered its module.
Most mutations turned their suite red. Four left every scenario green.
| Guard removed or disabled | Green scenarios | Fault the suite would miss |
|---|---|---|
Idle-session return in cancel() |
44 | abort() dispatches a bogus “cancelling” state and passes a null session identifier to the native layer |
| Copy-diagnostics re-entrancy guard | 17 | Two fast taps race two clipboard writes |
| Missing-error return in the font-loading hook | 4 | Every render logs a font failure, including successful renders |
| Early return for the “not available” notice | 20 | The wrong render path passes because both paths print the same sentence |
Every guard already counted as covered. Mutation testing asked the stronger question: would its suite catch the break?
Isolate the sweep from false failures
Run mutations on an isolated checkout. Our full harness once read a file while another run had mutated it, then reported a product-like failure.
Check the working directory too. Four scenarios read process.cwd(), so a run from a subdirectory produced another false regression.
Both failures wasted diagnosis time. Each affected suite passed alone from the expected directory.
Four is a floor
This sweep does not prove that any surviving mutation would have broken in production. It measures no defect-escape rate.
The sweep was time-boxed, so four is a floor rather than a total. It establishes only that high coverage did not make these assertions sensitive to four guard changes.
This evidence comes from our Muniment Mobile note pinned to commit 6dc162d8b927c3d98139d5384.
If your suite has a coverage gate but no mutation practice, pick three safety-relevant modules. Delete one guard in each and see whether the focused suites object.