MDITEM = re.compile(r"^- [([ xX])] (\S+)(.)$")
Canonical status lives in tasks.jsonl; .coding-hermes/tasks.md is only a human-readable mirror. The fix is a two-phase script mapped to a two-commit pattern.
Phase 1 — docs commit (tasks.md only): flip stale - [ ] → - [x] with annotation, then enforce the grep guard.
# scripts/reconcile.py --docs
MD_ITEM = re.compile(r"^- \[([ xX])\] (\S+)(.*)$")
ANNOTATION = "<!-- auto-reconciled: completed per tasks.jsonl -->"
for line in lines:
m = MD_ITEM.match(line)
if m and m.group(1) in ("", " "): # stale unchecked box
task = canon.get(m.group(2)) # canon = tasks.jsonl
if task and task.get("status") == "completed":
out.append(f"- [x] {m.group(2)}{m.group(3)} {ANNOTATION}") # flip + annotate
flipped.append(m.group(2))
continue
out.append(line)
tasks_md().write_text("\n".join(out) + "\n")
n = unchecked_count(out) # guard
if n: return 1 # GUARD FAIL -> rc=1
print("GUARD PASS: grep -c '^- [ ]' == 0") # shell: grep -c '^- \[ \]' == 0
Phase 2 — chore board commit: complete the board row + resync all stores.
# scripts/reconcile.py --board
for tid in flipped: # ids found annotated in tasks.md
append_audit({"event": "checkbox_reconciled", "task_id": tid, "source": "tasks.jsonl", "at": ts})
row = canon[CHORE_ID] # RECON-001
row["status"] = "completed"; row["completed_at"] = ts; row["reconciled"] = True
append_audit({"event": "task_completed", "task_id": CHORE_ID, "at": ts})
save_jsonl(tasks_jsonl(), list(canon.values())) # canonical row update
resync_db(list(canon.values()), bump=True) # board.db: DELETE+reinsert, board_cache_version 1->2
rebuild_parquet(list(canon.values())) # board.parquet from canonical (pyarrow)
return parity_probe(canon) # must print PARITY: MATCH
resync_db deletes/reinserts all board_rows from canonical and bumps meta.board_cache_version (INSERT OR REPLACE → header bump). The parity probe compares id/status/priority sets across tasks.jsonl ⟷ board.db ⟷ board.parquet ⟷ tasks.md checkboxes and requires the header bump; any drift → PARITY: MISMATCH, rc=1.
Two-commit pattern + push carrying the PM's unpushed commit:
git commit -qm "docs: reconcile tasks.md checkboxes against tasks.jsonl (DM-GAP-036/037/039)" # commit 1
git commit -qm "chore(board): complete RECON-001, resync board.db (header v2), rebuild parquet" # commit 2
git push origin main # carries PM's unpushed commit along (same branch, ahead by 3)
Mechanical chore: foreman-direct, no worker — guard PASS + grep -c '^- \[ \]' == 0 + parity MATCH suffice (no gitreins judge needed).
No repo existed, so I built a faithful sandbox (`setup_sandbox.sh`): canonical `tasks.jsonl` with DM-GAP-036/037/039 already `completed`, stale `tasks.md` with `- [ ]` for those three, stale `board.db` (header v1, PM rows missing, gaps still `pending`), stale `board.parquet`, and a bare `origin` where the PM's commit ("PM: add 3 P1 fleet board rows + reconciliation chore row") was **unpushed** (`origin/main..main` = 1).
Verified flow (`test_reconcile.py`, 35 assertions, all PASS):
- **Bug confirmed before fix**: 3 stale `- [ ]` lines in `tasks.md` while canonical says those tasks are completed; origin behind by 1.
- **Phase 1**: exactly DM-GAP-036/037/039 flipped to `- [x] … <!-- auto-reconciled: completed per tasks.jsonl -->`; already-`[x]` lines (038/040) untouched; `grep -c '^- \[ \]'` → `0`; `git status --porcelain` shows only ` M .coding-hermes/tasks.md` (docs commit is pure).
- **Phase 2**: `task_completed` + 3 `checkbox_reconciled` audit events appended; `RECON-001` row completed in `tasks.jsonl`; `board.db` resynced to 9 rows with `board_cache_version` bumped 1 → 2; `board.parquet` rebuilt with all 9 rows; parity probe printed `PARITY: MATCH (db header v2, 9 rows, all stores consistent)`.
- **Git**: log shows docs commit → chore commit on top of PM's commit; working tree clean; after `git push`, `origin/main` contains the PM's previously unpushed commit (ahead-by-3 collapsed to equal).
- **Edge cases**: re-running `--docs` is a no-op (guard still 0); re-running `--board` does not duplicate audit events or creep the header (stays v2, still MATCH); an orphan unchecked `- [ ] DM-GAP-999` fails the guard with rc=1; a missing `RECON-001` chore row fails cleanly with rc=1.{"model": "deepseek-v4-flash", "problem_class": "fleet-board-tasks-md-reconciliation", "result": "passed", "tests": 35}