◆ NFRGate / Rule Reference

T1 — Spans on external calls

high 🔍 traces · static analyzable

Every outbound HTTP/gRPC call or DB query introduced in the diff is wrapped in a trace span.

Python Implementation

T1: every outbound HTTP/gRPC/DB call introduced in the diff is wrapped in
a trace span. rubric_store/definitions/traces.yaml tags this fully
static_analyzable — of the four rules implemented this sprint, it's the
cleanest: "is this call inside a `with ...start_as_current_span(...)`
block" is answerable from syntax alone, no semantic judgment needed.

Fail-branch confidence retuned from designed-by-inspection (was 0.9) to
0.154, per docs/false_positive_rate_study_v1.md: a hand-labeled sample of
this exact fail case on real code scored 0/9 correct — the shared
`outbound_calls` construct this rule keys on matches any `object.method(...)`
call, not just genuine outbound calls, so most "fail" verdicts on real code
are wrong. 0.154 is a Beta(2,2)-smoothed estimate from that 0/9, not a
literal 0.0, and is pooled across Python/Java/Go since the study confirmed
the same root cause reproduces identically in all three. The pass-branch
confidence (0.9) is untouched — a pass requires actually finding a real
span-wrapping AST pattern, a much more specific positive signal the study
did not find reason to doubt.

Java Implementation

T1 for Java: every outbound call is wrapped in an OTel span, detected via
Java's try-with-resources-on-Scope idiom. See ast_helpers.is_wrapped_in_span
for the exact heuristic and its limits.

Fail-branch confidence retuned to 0.154 — see trace_span_rule.py (Python)
for the full rationale from docs/false_positive_rate_study_v1.md; the
underlying outbound_call over-matching problem is shared across all three
languages, confirmed to reproduce identically in the study.

Go Implementation

T1 for Go: was a span started (tracer.Start(...)) earlier in the
enclosing function before this outbound call? Go's OTel idiom isn't
block-scoped (no `with`/try-with-resources equivalent) — see
ast_helpers.is_wrapped_in_span for what that means for this heuristic's
precision.
← All rules