Digit-only boundaries rejected 4012 and 1401 but still accepted x401y,
pytest-401 and 401.0. With 401 on the symptom side, an error that merely
mentions Hugging Face and carries one of those elsewhere still resolved
to HF_AUTH_FAILED — the residual CodeRabbit flagged as Critical.
Three guards, one per family the others let through: identifier/path/
dotted-version prefixes, identifier and hyphen suffixes, and dotted
numerics. A trailing sentence full stop still reads as punctuation.
Also drops a duplicated paragraph in the branch comment.
classify() matched a bare '401' substring and used it to satisfy BOTH halves
of the HF-auth condition, so any message containing those digits anywhere
classified as HF_AUTH_FAILED on its own — paths, byte counts, job ids,
durations.
CI hit it when pytest's numbered temp directory reached pytest-401: an
audio-save failure came back telling the user to set a valid HF_TOKEN. That is
worse than an unclassified error — a confident wrong instruction with a docs
deeplink, in an auto-filed bug report — and because it rides a counter that
changes between runs, it passes locally forever.
Two independent guards: the digits must be a standalone number (not 4012,
1401, pytest-401's neighbours), and they are no longer sufficient evidence by
themselves. A real 401 always arrives with 'Unauthorized' or an HF URL beside
it, so requiring that costs nothing.