python-foreman-board-demo-db-side-effect-guard-drift-from-judge-tier1-pnpm-test-seeding
Solution written and verified for structural integrity. Findings:
Environment check (before writing):
- No EduOS checkout exists in this sandbox, but this tick is docs-only by classification, so the deliverable is the markdown itself.
- Both Postgres instances are live (5433, 55432) but I could not authenticate to run the count probes (repo .env credentials not present here) — those are left as exact runnable commands in §4.
- ps aux | grep vitest → empty; crontab → empty. Consistent with an idle window, no sanctioned writer live right now.
Deliverable: ~/t428-demo-db-side-effect-guard-drift-repin.md
Contents, per the task's required structure:
- Title/meta — T428, exec tick BETA-007, commit 71c2e88, t361 re-pin class.
- Root-cause analysis — the "drift" was the gitreins tier-2 judge's tier-1 tests step (pnpm -r run test, config.yaml timeout: 600) writing to the shared demo DB eduos@5433 (per apps/api/vitest.config.ts; the isolated eduos_test@55432 only shields the suite when test-env/.env exists, and -r also runs the workspace-default env). Two waves = judge run-1 + reruns 2/3; API globalSetup reseeds users + 3 dead-beef-GUID quizzes per run; load/e2e fixtures add submissions/gradebook/quizzes; e2e teardown returns them to 0. Exculpated: host cron (empty), rogue seeder (user timers: cube-duckbrain-sync only).
- Exact fix — (1) policy: judge-run windows are sanctioned writers, never diagnose mid-window, check ps aux | grep vitest + judge log first; (2) re-pin b2f001-teacher-battery.py P3/P7 and the regression battery GUARD to the settled baseline with t428-dated t361-class comments — users 38, quizzes 10535, submissions 0, gradebook 0, parent_links ACTIVE 5, analytics_events 376 floor (exact vs. floor semantics preserved); (3) optional sanctioned-writer guard annotation that reports instead of alarming.
- Verification — four gates: process/log gate, row-timestamp settlement gate, settled-count SQL (equal-to-pins, ≥-floor for analytics_events), and end-to-end battery pass; plus the follow-up trap note that mid-run 48/10483/24/31 numbers will recur and must not trigger another re-pin.
Verification of the doc: 6 sections, balanced code fences (14), all pinned numbers and diagnosis artifacts (5433/55432, dead-beef, cube-duckbrain-sync, 71c2e88, t361) present.
# Evidence - Problem class: python-foreman-board-demo-db-side-effect-guard-drift-from-judge-tier1-pnpm-test-seeding - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-09-06T16:47:54.174Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "EduOS foreman tick 428 (exec tick BETA-007, docs-only foreman-direct commit 71c2e88): mid-tick demo-DB side-effect probe showed guard drift vs pinned rotation-battery constants (users 35->48->38, quizzes 10449->10483->10535, submissions 0->24->0, gradebook 0->31->0) with NO battery running. Diagnosis that worked: (1) timestamps of new rows fell inside the gitreins tier2 judge's tier1 'tests' step window (pnpm -r run test, config.yaml timeout: 600); (2) apps/api/vitest.config.ts is EXPLICIT that the suite targets the shared dev/demo Postgres (eduos@5433, 'shared with the live API container') - the isolated eduos_test@55432 is used only when apps/api/test-env/.env exists (it did, correctly pointing at 55432, but pnpm -r runs the workspace default env too); (3) API suite globalSetup reseeds demo users + 3 fixed-GUID quizzes (dead-beef GUIDs) each run, api tier-3 load tests + web e2e fixtures add submissions/gradebook/quizzes, and web e2e teardown cleans them back to 0. Two waves = two judge runs (run-1 task complete + run-2/3 judge reruns), not a foreign actor; no host cron, no rogue seeder (systemd user timers: only cube-duckbrain-sync). Remedy: treat judge-run windows as sanctioned writers, re-pin rotation-battery keeper constants (b2f001-teacher-battery.py P3/P7 + regression battery GUARD) to the settled post-run baseline with t428-dated comments (t361 re-pin class), and NEVER chase 'drift' observed while a gitreins judge tests step is live - check 'ps aux | grep vitest' + judge log before diagnosing. Pinned baseline after settle: users 38, quizzes 10535, submissions 0, gradebook 0, parent_links ACTIVE 5, analytics_events 376 (floor).", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "python-foreman-board-demo-db-side-effect-guard-drift-from-judge-tier1-pnpm-test-seeding", "provider": "openrouter", "solved_at": "2026-09-06T16:47:54.175Z", "version": ""}Solution written and verified for structural integrity. Findings:
Environment check (before writing):
- No EduOS checkout exists in this sandbox, but this tick is docs-only by classification, so the deliverable is the markdown itself.
- Both Postgres instances are live (5433, 55432) but I could not authenticate to run the count probes (repo .env credentials not present here) — those are left as exact runnable commands in §4.
- ps aux | grep vitest → empty; crontab → empty. Consistent with an idle window, no sanctioned writer live right now.
Deliverable: ~/t428-demo-db-side-effect-guard-drift-repin.md
Contents, per the task's required structure:
- Title/meta — T428, exec tick BETA-007, commit 71c2e88, t361 re-pin class.
- Root-cause analysis — the "drift" was the gitreins tier-2 judge's tier-1 tests step (pnpm -r run test, config.yaml timeout: 600) writing to the shared demo DB eduos@5433 (per apps/api/vitest.config.ts; the isolated eduos_test@55432 only shields the suite when test-env/.env exists, and -r also runs the workspace-default env). Two waves = judge run-1 + reruns 2/3; API globalSetup reseeds users + 3 dead-beef-GUID quizzes per run; load/e2e fixtures add submissions/gradebook/quizzes; e2e teardown returns them to 0. Exculpated: host cron (empty), rogue seeder (user timers: cube-duckbrain-sync only).
- Exact fix — (1) policy: judge-run windows are sanctioned writers, never diagnose mid-window, check ps aux | grep vitest + judge log first; (2) re-pin b2f001-teacher-battery.py P3/P7 and the regression battery GUARD to the settled baseline with t428-dated t361-class comments — users 38, quizzes 10535, submissions 0, gradebook 0, parent_links ACTIVE 5, analytics_events 376 floor (exact vs. floor semantics preserved); (3) optional sanctioned-writer guard annotation that reports instead of alarming.
- Verification — four gates: process/log gate, row-timestamp settlement gate, settled-count SQL (equal-to-pins, ≥-floor for analytics_events), and end-to-end battery pass; plus the follow-up trap note that mid-run 48/10483/24/31 numbers will recur and must not trigger another re-pin.
Verification of the doc: 6 sections, balanced code fences (14), all pinned numbers and diagnosis artifacts (5433/55432, dead-beef, cube-duckbrain-sync, 71c2e88, t361) present.
# Evidence - Problem class: python-foreman-board-demo-db-side-effect-guard-drift-from-judge-tier1-pnpm-test-seeding - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-09-06T16:47:54.174Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "EduOS foreman tick 428 (exec tick BETA-007, docs-only foreman-direct commit 71c2e88): mid-tick demo-DB side-effect probe showed guard drift vs pinned rotation-battery constants (users 35->48->38, quizzes 10449->10483->10535, submissions 0->24->0, gradebook 0->31->0) with NO battery running. Diagnosis that worked: (1) timestamps of new rows fell inside the gitreins tier2 judge's tier1 'tests' step window (pnpm -r run test, config.yaml timeout: 600); (2) apps/api/vitest.config.ts is EXPLICIT that the suite targets the shared dev/demo Postgres (eduos@5433, 'shared with the live API container') - the isolated eduos_test@55432 is used only when apps/api/test-env/.env exists (it did, correctly pointing at 55432, but pnpm -r runs the workspace default env too); (3) API suite globalSetup reseeds demo users + 3 fixed-GUID quizzes (dead-beef GUIDs) each run, api tier-3 load tests + web e2e fixtures add submissions/gradebook/quizzes, and web e2e teardown cleans them back to 0. Two waves = two judge runs (run-1 task complete + run-2/3 judge reruns), not a foreign actor; no host cron, no rogue seeder (systemd user timers: only cube-duckbrain-sync). Remedy: treat judge-run windows as sanctioned writers, re-pin rotation-battery keeper constants (b2f001-teacher-battery.py P3/P7 + regression battery GUARD) to the settled post-run baseline with t428-dated comments (t361 re-pin class), and NEVER chase 'drift' observed while a gitreins judge tests step is live - check 'ps aux | grep vitest' + judge log before diagnosing. Pinned baseline after settle: users 38, quizzes 10535, submissions 0, gradebook 0, parent_links ACTIVE 5, analytics_events 376 (floor).", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "python-foreman-board-demo-db-side-effect-guard-drift-from-judge-tier1-pnpm-test-seeding", "provider": "openrouter", "solved_at": "2026-09-06T16:47:54.175Z", "version": ""}