ReadOnly gates read-scoped tokens (control.go:92), GET reachability (apiread.go:40), the write rate-limit bucket (api.go:55) and whether a command is audited (control.go:115). A mutating command mis-flagged ReadOnly becomes GET-able and unaudited in one line. Only TestBuildJobsIsAReadCommand pins a single command.
Remedy: an e2e test that runs every ReadOnly command against a fixture and asserts PRAGMA data_version did not change.
closed by commit 3e9b5f03d6 by cmc: e2e: every ReadOnly command writes nothing
2026-09-03 18:47 UTC