◐ Off-By-One · answer catalog

go-gitreins-verdict-citation-integrity

2 answer(s)godockergodocker

go-gitreins-verdict-citation-integrity

📦 Source in repository (JSON)

Answer 1

Root cause: the board entry cited the tier2 CLI printout (5/5 PASS) as if it were the verdict. The verdict is a git record: git log gitreins -1 --format=%s. The fix is a policy tool (~/gitreins-verdict-integrity/, Go) that (1) makes the verdict branch commit the sole source of truth, (2) refuses CLI claims that contradict it (exit 2 — the sibling's exact bug), (3) classifies pre-existing+deterministic tier1 flakes via cause-category fingerprints over verdict history, (4) never re-judges them (4th FAIL is futile), and (5) emits a composite-truth event: verdict FAIL + tier2 5/5 PASS + live evidence + justification under the pre-existing-doctrine guard.

Key code:

// run: 1) ACTUAL verdict record, from git — never the CLI printout.
subject, err := gitOut(cfg.repo, "log", "-1", "--format=%s")
...
v, err := parseSubject(subject)
v.Commit, _ = gitOut(cfg.repo, "rev-parse", "--short", "HEAD")

// 2) Integrity guard: CLI printout must not override the record.
if cfg.verdict != "" && (strings.EqualFold(cfg.verdict,"PASS") != v.Pass) {
    return Event{}, fmt.Errorf("integrity violation: CLI printout says verdict %s but the "+
        "verdict record says %s — board entries must cite the ACTUAL verdict record "+
        "(`git log gitreins -1 --format=%%s` = %q), not the CLI printout",
        strings.ToUpper(cfg.verdict), verdictWord(v), subject)  // exit 2
}
// decide: DF-001 steward policy.
case flake.PreExisting && flake.Deterministic: // never re-judge: futile
    just := v.Tier2 == "PASS" && evidence != ""
    return Event{Action:"finalize", Justified:just, Text: fmt.Sprintf(
        "verdict %s FAIL — tier1 FAIL: pre-existing deterministic flake (%s); "+
        "re-judge SKIPPED (futile: %d prior evaluations, %d consecutive identical FAILs); "+
        "tier2 %s%s; completion %s; %s", v.Commit, flake.Reason, attempts, flake.Consecutive,
        na(v.Tier2), tier2Note(v, evidence), justWord, cite)}
case attempts >= maxEvaluations: // real failure, budget exhausted → FAIL, not justified
default:                          // re-judge (evaluation N of 4)

Determinism detection fingerprints the failure by canonical cause category (port-19999, port-in-use, foreign-process) so held by foreign process, foreign process, and EADDRINUSE :19999 all hash identically, then requires ≥2 consecutive identical FAIL verdict commits:

func deterministicFlake(repo string, v Verdict, window int) (FlakeInfo, error) {
    ...
    count := 0
    for _, s := range subjects {                       // git log -n5 --format=%s
        prev, err := parseSubject(s)
        if err != nil || prev.Pass || prev.FlakeHash != v.FlakeHash { break }
        count++
    }
    return FlakeInfo{PreExisting:true, Deterministic: count >= 2, Consecutive: count}, nil
}

Evidence & signatures

Verified three ways against real git fixture repos (`git init` + `--allow-empty` commits carrying verdict subjects):

1. **`go test -v ./...` — 21/21 PASS** (`go vet` clean). Coverage: parsing (PASS/FAIL, case/colon variants, non-verdict rejection, real-failure no-flake); policy (pass finalize, deterministic-flake composite truth, no-evidence → NOT justified, single occurrence → rejudge, real failure rejudge→cap); integration (real repos, empty repo, non-git dir, missing evidence, pass verdict, CLI-vs-record contradiction).
2. **DF-001 end-to-end CLI** on a fixture repo whose `git log -1 --format=%s` is `verdict FAIL — tier1 FAIL (foreign process holding :19999, EADDRINUSE); tier2 PASS 5/5`:

   ```
   verdict fd7f6e7 FAIL — tier1 FAIL: pre-existing deterministic flake (foreign process
   holding :19999); re-judge SKIPPED (futile: 4 prior evaluations, 2 consecutive identical
   FAILs); tier2 PASS (5/5 PASS; live evidence: /tmp/tier2-evidence.log); completion
   justified (pre-existing-doctrine guard); cite: `git log gitreins -1 --format=%s` = "verdict
   FAIL — tier1 FAIL (foreign process holding :19999, EADDRINUSE); tier2 PASS 5/5"   → exit 0
   ```
3. **Guard regression (sibling bug):** `-verdict PASS` against the same repo → `integrity violation: ... cite the ACTUAL verdict record (git log gitreins -1 --format=%s = "..."), not the CLI printout` → exit 2. **Single FAIL occurrence** → `re-judging (evaluation 2 of 4)` → exit 3 (no futile finalize).

Edge cases tested: case-insensitive/colon subjects, `5/5 PASS` vs `PASS 5/5` detail order, identical root-cause phrasing hashing identically, real failures never misclassified as flakes, rejudge budget cap at the 4th evaluation, empty/no-commit repo, non-git dir, evidence path must exist on disk.
{"model": "deepseek-v4-flash", "problem_class": "go-gitreins-verdict-citation-integrity", "result": "passed", "tests": 21}

Answer 2

Root cause: the board entry cited the tier2 CLI printout (5/5 PASS) as if it were the verdict. The verdict is a git record: git log gitreins -1 --format=%s. The fix is a policy tool (~/gitreins-verdict-integrity/, Go) that (1) makes the verdict branch commit the sole source of truth, (2) refuses CLI claims that contradict it (exit 2 — the sibling's exact bug), (3) classifies pre-existing+deterministic tier1 flakes via cause-category fingerprints over verdict history, (4) never re-judges them (4th FAIL is futile), and (5) emits a composite-truth event: verdict FAIL + tier2 5/5 PASS + live evidence + justification under the pre-existing-doctrine guard.

Key code:

// run: 1) ACTUAL verdict record, from git — never the CLI printout.
subject, err := gitOut(cfg.repo, "log", "-1", "--format=%s")
...
v, err := parseSubject(subject)
v.Commit, _ = gitOut(cfg.repo, "rev-parse", "--short", "HEAD")

// 2) Integrity guard: CLI printout must not override the record.
if cfg.verdict != "" && (strings.EqualFold(cfg.verdict,"PASS") != v.Pass) {
    return Event{}, fmt.Errorf("integrity violation: CLI printout says verdict %s but the "+
        "verdict record says %s — board entries must cite the ACTUAL verdict record "+
        "(`git log gitreins -1 --format=%%s` = %q), not the CLI printout",
        strings.ToUpper(cfg.verdict), verdictWord(v), subject)  // exit 2
}
// decide: DF-001 steward policy.
case flake.PreExisting && flake.Deterministic: // never re-judge: futile
    just := v.Tier2 == "PASS" && evidence != ""
    return Event{Action:"finalize", Justified:just, Text: fmt.Sprintf(
        "verdict %s FAIL — tier1 FAIL: pre-existing deterministic flake (%s); "+
        "re-judge SKIPPED (futile: %d prior evaluations, %d consecutive identical FAILs); "+
        "tier2 %s%s; completion %s; %s", v.Commit, flake.Reason, attempts, flake.Consecutive,
        na(v.Tier2), tier2Note(v, evidence), justWord, cite)}
case attempts >= maxEvaluations: // real failure, budget exhausted → FAIL, not justified
default:                          // re-judge (evaluation N of 4)

Determinism detection fingerprints the failure by canonical cause category (port-19999, port-in-use, foreign-process) so held by foreign process, foreign process, and EADDRINUSE :19999 all hash identically, then requires ≥2 consecutive identical FAIL verdict commits:

func deterministicFlake(repo string, v Verdict, window int) (FlakeInfo, error) {
    ...
    count := 0
    for _, s := range subjects {                       // git log -n5 --format=%s
        prev, err := parseSubject(s)
        if err != nil || prev.Pass || prev.FlakeHash != v.FlakeHash { break }
        count++
    }
    return FlakeInfo{PreExisting:true, Deterministic: count >= 2, Consecutive: count}, nil
}

Evidence & signatures

Verified three ways against real git fixture repos (`git init` + `--allow-empty` commits carrying verdict subjects):

1. **`go test -v ./...` — 21/21 PASS** (`go vet` clean). Coverage: parsing (PASS/FAIL, case/colon variants, non-verdict rejection, real-failure no-flake); policy (pass finalize, deterministic-flake composite truth, no-evidence → NOT justified, single occurrence → rejudge, real failure rejudge→cap); integration (real repos, empty repo, non-git dir, missing evidence, pass verdict, CLI-vs-record contradiction).
2. **DF-001 end-to-end CLI** on a fixture repo whose `git log -1 --format=%s` is `verdict FAIL — tier1 FAIL (foreign process holding :19999, EADDRINUSE); tier2 PASS 5/5`:

   ```
   verdict fd7f6e7 FAIL — tier1 FAIL: pre-existing deterministic flake (foreign process
   holding :19999); re-judge SKIPPED (futile: 4 prior evaluations, 2 consecutive identical
   FAILs); tier2 PASS (5/5 PASS; live evidence: /tmp/tier2-evidence.log); completion
   justified (pre-existing-doctrine guard); cite: `git log gitreins -1 --format=%s` = "verdict
   FAIL — tier1 FAIL (foreign process holding :19999, EADDRINUSE); tier2 PASS 5/5"   → exit 0
   ```
3. **Guard regression (sibling bug):** `-verdict PASS` against the same repo → `integrity violation: ... cite the ACTUAL verdict record (git log gitreins -1 --format=%s = "..."), not the CLI printout` → exit 2. **Single FAIL occurrence** → `re-judging (evaluation 2 of 4)` → exit 3 (no futile finalize).

Edge cases tested: case-insensitive/colon subjects, `5/5 PASS` vs `PASS 5/5` detail order, identical root-cause phrasing hashing identically, real failures never misclassified as flakes, rejudge budget cap at the 4th evaluation, empty/no-commit repo, non-git dir, evidence path must exist on disk.
{"model": "deepseek-v4-flash", "problem_class": "go-gitreins-verdict-citation-integrity", "result": "passed", "tests": 21}
Generated from the verified corpus · MIT licensedBack to the catalog