(green if val is True else red).append(f"{k}={val}") if val is not None else None
Root cause. The reopen was an artifact of stale evidence: the PM's hunter check ran against a tree before implementation commit eb5ce22, so "route not implemented" was a description of the old tree, not the current one. The foreman's error mode to guard against is re-dispatching (re-doing) work based on a claim whose premises were never re-verified against the current tree + gitreins state.
The fix: a two-gate stale-reopen guard (~/solution/verify_reopen.py). Before any reopen or re-dispatch, the foreman must pass both gates; a reopen requires a live red check, never a claim:
H is an ancestor of the implementation commit C (git merge-base --is-ancestor H C), the claim predates the fix → claim_stale=True. Stale claims get zero re-work weight; they only trigger live verification.HEAD (git cat-file -e HEAD:<path>); (b) a fresh HTTP probe: implemented route → 200, decoy route → 404 (proving the 404 the PM saw is not the real route missing); (c) gitreins state still shows the task complete (N/N).Verdicts: CLOSED_WITH_EVIDENCE (≥1 green live check, no red → zero re-work), REOPEN (any proven live gap), UNVERIFIABLE (nothing probeable → do not reopen on the claim alone).
Core logic:
def is_ancestor(ancestor, descendant, repo):
if not repo or not (repo / ".git").exists():
return None # unverifiable, not "stale"
r = subprocess.run(["git", "merge-base", "--is-ancestor",
ancestor, descendant], cwd=repo,
capture_output=True, text=True)
return {0: True, 1: False}.get(r.returncode, None) # 128 -> None
# verdict: red = proven live gap; green = live corroboration; None = proves nothing
for k, val in v.checks.items():
if k == "artifact_exists":
(green if val is True else red).append(f"{k}={val}") if val is not None else None
elif k in ("route_status", "decoy_status") and type(val) is int:
ok = val == (expect_status if k == "route_status" else 404)
(green if ok else red).append(f"{k}={val}")
elif k == "gitreins_status":
(green if val == "complete" else red).append(f"{k}={val}") if val is not None else None
elif k == "gitreins_done" and expected_done and val is not None:
(green if val == expected_done else red).append(f"{k}={val}")
if red: decision = "REOPEN" # dispatch work
elif green: decision = "CLOSED_WITH_EVIDENCE" # zero re-work
else: decision = "UNVERIFIABLE" # never reopen on claim
Note the subtlety that bit a naive version: bool is a subclass of int in Python, so val in (200, 404, None) misclassifies True — the verdict uses type(val) is int and explicit val is True/False, never isinstance/membership on mixed types.
Verified with a hermetic fixture reproducing the incident exactly (baseline hunter commit `H`, then implementation commit `C` adding `src/routes/gap.py` + `gitreins.state.json` `U-GAP-005: complete 7/7`, plus a live local HTTP server answering 200 on `/api/gap` and 404 elsewhere). Replaying the incident produces: ``` decision: CLOSED_WITH_EVIDENCE claim_stale: true STALE: hunter check 8c5eda8 is an ancestor of implementation 3cc53d4 artifact present in HEAD: src/routes/gap.py live probe /api/gap -> 200 (expected 200) decoy probe /api/does-not-exist -> 404 (expected 404) gitreins: U-GAP-005 complete (7/7) CLOSED_WITH_EVIDENCE: claim stale/refuted by current tree — zero re-work. ``` Test matrix — **14/14 passed** (`verify_reopen_test.py`): | # | Scenario | Expected | Got | |---|---|---|---| | incident | stale claim, tree+gitreins+live all green | CLOSED_WITH_EVIDENCE | ✅ | | incident | claim flagged stale (H ancestor of C) | stale=True | ✅ | | incident | gitreins still `7/7`, route 200, decoy 404 | 7/7, 200, 404 | ✅ | | edge1 | artifact genuinely missing in HEAD | REOPEN | ✅ | | edge2 | *fresh* claim (H not ancestor) still refuted by live tree | CLOSED_WITH_EVIDENCE | ✅ | | edge3 | route live but 500 | REOPEN | ✅ | | edge4 | gitreins regressed to 6/7 | REOPEN | ✅ | | edge5 | no commits/repo/state probeable | UNVERIFIABLE (no reopen on claim) | ✅ | | edge6 | repo gone, but live route + gitreins green | CLOSED on live evidence | ✅ | | cli | `--json` run exits 0 with verdict | (0, CLOSED_WITH_EVIDENCE) | ✅ | Edge cases covered: stale vs. fresh claims, worktree drift, wrong-but-present implementation, gitreins regression, unverifiable inputs, missing repo, failed network probes (probe `None` is treated as *inconclusive*, never as proof either way — a reopen needs a proven gap).
{"model": "deepseek-v4-flash", "problem_class": "foreman-verification-stale-reopen", "result": "passed", "tests": 14}Root cause. The reopen was an artifact of stale evidence: the PM's hunter check ran against a tree before implementation commit eb5ce22, so "route not implemented" was a description of the old tree, not the current one. The foreman's error mode to guard against is re-dispatching (re-doing) work based on a claim whose premises were never re-verified against the current tree + gitreins state.
The fix: a two-gate stale-reopen guard (~/solution/verify_reopen.py). Before any reopen or re-dispatch, the foreman must pass both gates; a reopen requires a live red check, never a claim:
H is an ancestor of the implementation commit C (git merge-base --is-ancestor H C), the claim predates the fix → claim_stale=True. Stale claims get zero re-work weight; they only trigger live verification.HEAD (git cat-file -e HEAD:<path>); (b) a fresh HTTP probe: implemented route → 200, decoy route → 404 (proving the 404 the PM saw is not the real route missing); (c) gitreins state still shows the task complete (N/N).Verdicts: CLOSED_WITH_EVIDENCE (≥1 green live check, no red → zero re-work), REOPEN (any proven live gap), UNVERIFIABLE (nothing probeable → do not reopen on the claim alone).
Core logic:
def is_ancestor(ancestor, descendant, repo):
if not repo or not (repo / ".git").exists():
return None # unverifiable, not "stale"
r = subprocess.run(["git", "merge-base", "--is-ancestor",
ancestor, descendant], cwd=repo,
capture_output=True, text=True)
return {0: True, 1: False}.get(r.returncode, None) # 128 -> None
# verdict: red = proven live gap; green = live corroboration; None = proves nothing
for k, val in v.checks.items():
if k == "artifact_exists":
(green if val is True else red).append(f"{k}={val}") if val is not None else None
elif k in ("route_status", "decoy_status") and type(val) is int:
ok = val == (expect_status if k == "route_status" else 404)
(green if ok else red).append(f"{k}={val}")
elif k == "gitreins_status":
(green if val == "complete" else red).append(f"{k}={val}") if val is not None else None
elif k == "gitreins_done" and expected_done and val is not None:
(green if val == expected_done else red).append(f"{k}={val}")
if red: decision = "REOPEN" # dispatch work
elif green: decision = "CLOSED_WITH_EVIDENCE" # zero re-work
else: decision = "UNVERIFIABLE" # never reopen on claim
Note the subtlety that bit a naive version: bool is a subclass of int in Python, so val in (200, 404, None) misclassifies True — the verdict uses type(val) is int and explicit val is True/False, never isinstance/membership on mixed types.
Verified with a hermetic fixture reproducing the incident exactly (baseline hunter commit `H`, then implementation commit `C` adding `src/routes/gap.py` + `gitreins.state.json` `U-GAP-005: complete 7/7`, plus a live local HTTP server answering 200 on `/api/gap` and 404 elsewhere). Replaying the incident produces: ``` decision: CLOSED_WITH_EVIDENCE claim_stale: true STALE: hunter check 8c5eda8 is an ancestor of implementation 3cc53d4 artifact present in HEAD: src/routes/gap.py live probe /api/gap -> 200 (expected 200) decoy probe /api/does-not-exist -> 404 (expected 404) gitreins: U-GAP-005 complete (7/7) CLOSED_WITH_EVIDENCE: claim stale/refuted by current tree — zero re-work. ``` Test matrix — **14/14 passed** (`verify_reopen_test.py`): | # | Scenario | Expected | Got | |---|---|---|---| | incident | stale claim, tree+gitreins+live all green | CLOSED_WITH_EVIDENCE | ✅ | | incident | claim flagged stale (H ancestor of C) | stale=True | ✅ | | incident | gitreins still `7/7`, route 200, decoy 404 | 7/7, 200, 404 | ✅ | | edge1 | artifact genuinely missing in HEAD | REOPEN | ✅ | | edge2 | *fresh* claim (H not ancestor) still refuted by live tree | CLOSED_WITH_EVIDENCE | ✅ | | edge3 | route live but 500 | REOPEN | ✅ | | edge4 | gitreins regressed to 6/7 | REOPEN | ✅ | | edge5 | no commits/repo/state probeable | UNVERIFIABLE (no reopen on claim) | ✅ | | edge6 | repo gone, but live route + gitreins green | CLOSED on live evidence | ✅ | | cli | `--json` run exits 0 with verdict | (0, CLOSED_WITH_EVIDENCE) | ✅ | Edge cases covered: stale vs. fresh claims, worktree drift, wrong-but-present implementation, gitreins regression, unverifiable inputs, missing repo, failed network probes (probe `None` is treated as *inconclusive*, never as proof either way — a reopen needs a proven gap).
{"model": "deepseek-v4-flash", "problem_class": "foreman-verification-stale-reopen", "result": "passed", "tests": 14}