go-gitreins-verdict-citation-integrity
Root cause: the board entry cited the tier2 CLI printout (5/5 PASS) as if it were the verdict. The verdict is a git record: git log gitreins -1 --format=%s. The fix is a policy tool (~/gitreins-verdict-integrity/, Go) that (1) makes the verdict branch commit the sole source of truth, (2) refuses CLI claims that contradict it (exit 2 — the sibling's exact bug), (3) classifies pre-existing+deterministic tier1 flakes via cause-category fingerprints over verdict history, (4) never re-judges them (4th FAIL is futile), and (5) emits a composite-truth event: verdict FAIL + tier2 5/5 PASS + live evidence + justification under the pre-existing-doctrine guard.
Key code:
// run: 1) ACTUAL verdict record, from git — never the CLI printout.
subject, err := gitOut(cfg.repo, "log", "-1", "--format=%s")
...
v, err := parseSubject(subject)
v.Commit, _ = gitOut(cfg.repo, "rev-parse", "--short", "HEAD")
// 2) Integrity guard: CLI printout must not override the record.
if cfg.verdict != "" && (strings.EqualFold(cfg.verdict,"PASS") != v.Pass) {
return Event{}, fmt.Errorf("integrity violation: CLI printout says verdict %s but the "+
"verdict record says %s — board entries must cite the ACTUAL verdict record "+
"(`git log gitreins -1 --format=%%s` = %q), not the CLI printout",
strings.ToUpper(cfg.verdict), verdictWord(v), subject) // exit 2
}
// decide: DF-001 steward policy.
case flake.PreExisting && flake.Deterministic: // never re-judge: futile
just := v.Tier2 == "PASS" && evidence != ""
return Event{Action:"finalize", Justified:just, Text: fmt.Sprintf(
"verdict %s FAIL — tier1 FAIL: pre-existing deterministic flake (%s); "+
"re-judge SKIPPED (futile: %d prior evaluations, %d consecutive identical FAILs); "+
"tier2 %s%s; completion %s; %s", v.Commit, flake.Reason, attempts, flake.Consecutive,
na(v.Tier2), tier2Note(v, evidence), justWord, cite)}
case attempts >= maxEvaluations: // real failure, budget exhausted → FAIL, not justified
default: // re-judge (evaluation N of 4)
Determinism detection fingerprints the failure by canonical cause category (port-19999, port-in-use, foreign-process) so held by foreign process, foreign process, and EADDRINUSE :19999 all hash identically, then requires ≥2 consecutive identical FAIL verdict commits:
func deterministicFlake(repo string, v Verdict, window int) (FlakeInfo, error) {
...
count := 0
for _, s := range subjects { // git log -n5 --format=%s
prev, err := parseSubject(s)
if err != nil || prev.Pass || prev.FlakeHash != v.FlakeHash { break }
count++
}
return FlakeInfo{PreExisting:true, Deterministic: count >= 2, Consecutive: count}, nil
}
Verified three ways against real git fixture repos (`git init` + `--allow-empty` commits carrying verdict subjects): 1. **`go test -v ./...` — 21/21 PASS** (`go vet` clean). Coverage: parsing (PASS/FAIL, case/colon variants, non-verdict rejection, real-failure no-flake); policy (pass finalize, deterministic-flake composite truth, no-evidence → NOT justified, single occurrence → rejudge, real failure rejudge→cap); integration (real repos, empty repo, non-git dir, missing evidence, pass verdict, CLI-vs-record contradiction). 2. **DF-001 end-to-end CLI** on a fixture repo whose `git log -1 --format=%s` is `verdict FAIL — tier1 FAIL (foreign process holding :19999, EADDRINUSE); tier2 PASS 5/5`: ``` verdict fd7f6e7 FAIL — tier1 FAIL: pre-existing deterministic flake (foreign process holding :19999); re-judge SKIPPED (futile: 4 prior evaluations, 2 consecutive identical FAILs); tier2 PASS (5/5 PASS; live evidence: /tmp/tier2-evidence.log); completion justified (pre-existing-doctrine guard); cite: `git log gitreins -1 --format=%s` = "verdict FAIL — tier1 FAIL (foreign process holding :19999, EADDRINUSE); tier2 PASS 5/5" → exit 0 ``` 3. **Guard regression (sibling bug):** `-verdict PASS` against the same repo → `integrity violation: ... cite the ACTUAL verdict record (git log gitreins -1 --format=%s = "..."), not the CLI printout` → exit 2. **Single FAIL occurrence** → `re-judging (evaluation 2 of 4)` → exit 3 (no futile finalize). Edge cases tested: case-insensitive/colon subjects, `5/5 PASS` vs `PASS 5/5` detail order, identical root-cause phrasing hashing identically, real failures never misclassified as flakes, rejudge budget cap at the 4th evaluation, empty/no-commit repo, non-git dir, evidence path must exist on disk.
{"model": "deepseek-v4-flash", "problem_class": "go-gitreins-verdict-citation-integrity", "result": "passed", "tests": 21}Root cause: the board entry cited the tier2 CLI printout (5/5 PASS) as if it were the verdict. The verdict is a git record: git log gitreins -1 --format=%s. The fix is a policy tool (~/gitreins-verdict-integrity/, Go) that (1) makes the verdict branch commit the sole source of truth, (2) refuses CLI claims that contradict it (exit 2 — the sibling's exact bug), (3) classifies pre-existing+deterministic tier1 flakes via cause-category fingerprints over verdict history, (4) never re-judges them (4th FAIL is futile), and (5) emits a composite-truth event: verdict FAIL + tier2 5/5 PASS + live evidence + justification under the pre-existing-doctrine guard.
Key code:
// run: 1) ACTUAL verdict record, from git — never the CLI printout.
subject, err := gitOut(cfg.repo, "log", "-1", "--format=%s")
...
v, err := parseSubject(subject)
v.Commit, _ = gitOut(cfg.repo, "rev-parse", "--short", "HEAD")
// 2) Integrity guard: CLI printout must not override the record.
if cfg.verdict != "" && (strings.EqualFold(cfg.verdict,"PASS") != v.Pass) {
return Event{}, fmt.Errorf("integrity violation: CLI printout says verdict %s but the "+
"verdict record says %s — board entries must cite the ACTUAL verdict record "+
"(`git log gitreins -1 --format=%%s` = %q), not the CLI printout",
strings.ToUpper(cfg.verdict), verdictWord(v), subject) // exit 2
}
// decide: DF-001 steward policy.
case flake.PreExisting && flake.Deterministic: // never re-judge: futile
just := v.Tier2 == "PASS" && evidence != ""
return Event{Action:"finalize", Justified:just, Text: fmt.Sprintf(
"verdict %s FAIL — tier1 FAIL: pre-existing deterministic flake (%s); "+
"re-judge SKIPPED (futile: %d prior evaluations, %d consecutive identical FAILs); "+
"tier2 %s%s; completion %s; %s", v.Commit, flake.Reason, attempts, flake.Consecutive,
na(v.Tier2), tier2Note(v, evidence), justWord, cite)}
case attempts >= maxEvaluations: // real failure, budget exhausted → FAIL, not justified
default: // re-judge (evaluation N of 4)
Determinism detection fingerprints the failure by canonical cause category (port-19999, port-in-use, foreign-process) so held by foreign process, foreign process, and EADDRINUSE :19999 all hash identically, then requires ≥2 consecutive identical FAIL verdict commits:
func deterministicFlake(repo string, v Verdict, window int) (FlakeInfo, error) {
...
count := 0
for _, s := range subjects { // git log -n5 --format=%s
prev, err := parseSubject(s)
if err != nil || prev.Pass || prev.FlakeHash != v.FlakeHash { break }
count++
}
return FlakeInfo{PreExisting:true, Deterministic: count >= 2, Consecutive: count}, nil
}
Verified three ways against real git fixture repos (`git init` + `--allow-empty` commits carrying verdict subjects): 1. **`go test -v ./...` — 21/21 PASS** (`go vet` clean). Coverage: parsing (PASS/FAIL, case/colon variants, non-verdict rejection, real-failure no-flake); policy (pass finalize, deterministic-flake composite truth, no-evidence → NOT justified, single occurrence → rejudge, real failure rejudge→cap); integration (real repos, empty repo, non-git dir, missing evidence, pass verdict, CLI-vs-record contradiction). 2. **DF-001 end-to-end CLI** on a fixture repo whose `git log -1 --format=%s` is `verdict FAIL — tier1 FAIL (foreign process holding :19999, EADDRINUSE); tier2 PASS 5/5`: ``` verdict fd7f6e7 FAIL — tier1 FAIL: pre-existing deterministic flake (foreign process holding :19999); re-judge SKIPPED (futile: 4 prior evaluations, 2 consecutive identical FAILs); tier2 PASS (5/5 PASS; live evidence: /tmp/tier2-evidence.log); completion justified (pre-existing-doctrine guard); cite: `git log gitreins -1 --format=%s` = "verdict FAIL — tier1 FAIL (foreign process holding :19999, EADDRINUSE); tier2 PASS 5/5" → exit 0 ``` 3. **Guard regression (sibling bug):** `-verdict PASS` against the same repo → `integrity violation: ... cite the ACTUAL verdict record (git log gitreins -1 --format=%s = "..."), not the CLI printout` → exit 2. **Single FAIL occurrence** → `re-judging (evaluation 2 of 4)` → exit 3 (no futile finalize). Edge cases tested: case-insensitive/colon subjects, `5/5 PASS` vs `PASS 5/5` detail order, identical root-cause phrasing hashing identically, real failures never misclassified as flakes, rejudge budget cap at the 4th evaluation, empty/no-commit repo, non-git dir, evidence path must exist on disk.
{"model": "deepseek-v4-flash", "problem_class": "go-gitreins-verdict-citation-integrity", "result": "passed", "tests": 21}