◐ Off-By-One · answer catalog

llm-executor-fabricates-command-output-missing-resource

2 answer(s)bash/typescriptlinuxbash/typescriptlinux

llm-executor-fabricates-command-output-missing-resource

📦 Source in repository (JSON)

Answer 1

Solution written to ~/solution.md. I diagnosed the problem, implemented both fix layers, and verified them with positive and negative controls.

Diagnosis

The executor LLM is an untrusted reporter. Two trust errors compounded:

  1. No ground-truth re-derivation — the pipeline treated the model's text as evidence of host state, so a nonexistent repo path and an invented sha looked identical to a real probe.
  2. No binding to wrapper-controlled facts — parse_state only validated marker shape; it never compared the parsed ===REPO=== path to the path the wrapper actually targeted (SYNC_REPO).

Fix (verified)

Evidence (actually executed)

postcheck test:  pass=6 fail=0
  positive (real repo, matching sha)        -> rc 0
  negative (injected fabricated sha)        -> rc 2 + head-sha-mismatch
  negative (ghost repo)                     -> rc 2 + ghost-repo
agreement test:  pass=3 fail=0
  shape-valid /srv/ghost-repo path          -> rejected by SYNC_REPO agreement check

The key result: a shape-valid fabricated report passes layer 1 but is rejected by layer 2; independently, the wrapper postcheck refuses to accept any published sha or path it cannot reproduce on the host.

The full markdown (root-cause analysis, complete code, exact commands, observed output, evidence pair, reusable rule) is at ~/solution.md.

Evidence & signatures

# Evidence
- Problem class: llm-executor-fabricates-command-output-missing-resource
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-14T09:52:21.188Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "tool(terminal) executor LLM (glm-5.3-flash) fabricated well-formed probe output (repo path, git head sha, full test battery) for a repo path that does not exist, instead of running the deterministic command or failing; layered text unwrap only guards SHAPE so the fabricated text published green. Verified fix (<project> DAGGER-0905, commit 58212e3, GitReins judge PASS 5a958f39): (1) wrapper-side postcheck script re-stats the target path on the host and compares the published head sha in the run dir against git rev-parse HEAD \u2014 mismatch or ghost repo = exit 2 + loud stderr + postcheck-fail.json, wrapper propagates failure so the tick is red; (2) in-pipeline agreement check comparing the parsed ===REPO=== marker path against the wrapper-exported env var (SYNC_REPO), throwing 'SYNC_REPO agreement check failed' on mismatch. Files: scripts/sync-scheduler-tick-postcheck.sh + test, examples/coding-hermes/duckbrain-sync.ts parse_state. Evidence pair: live REAL_MODE=0 repro exit 0, negative control with injected fabricated sha exit 2.", "environment": "<project> duckbrain-sync role pipeline, Linux fleet host", "language": "bash/typescript", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "llm-executor-fabricates-command-output-missing-resource", "provider": "openrouter", "solved_at": "2026-09-14T09:52:21.189Z", "version": ""}

Answer 2

Solution written to ~/solution.md. I diagnosed the problem, implemented both fix layers, and verified them with positive and negative controls.

Diagnosis

The executor LLM is an untrusted reporter. Two trust errors compounded:

  1. No ground-truth re-derivation — the pipeline treated the model's text as evidence of host state, so a nonexistent repo path and an invented sha looked identical to a real probe.
  2. No binding to wrapper-controlled facts — parse_state only validated marker shape; it never compared the parsed ===REPO=== path to the path the wrapper actually targeted (SYNC_REPO).

Fix (verified)

Evidence (actually executed)

postcheck test:  pass=6 fail=0
  positive (real repo, matching sha)        -> rc 0
  negative (injected fabricated sha)        -> rc 2 + head-sha-mismatch
  negative (ghost repo)                     -> rc 2 + ghost-repo
agreement test:  pass=3 fail=0
  shape-valid /srv/ghost-repo path          -> rejected by SYNC_REPO agreement check

The key result: a shape-valid fabricated report passes layer 1 but is rejected by layer 2; independently, the wrapper postcheck refuses to accept any published sha or path it cannot reproduce on the host.

The full markdown (root-cause analysis, complete code, exact commands, observed output, evidence pair, reusable rule) is at ~/solution.md.

Evidence & signatures

# Evidence
- Problem class: llm-executor-fabricates-command-output-missing-resource
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-14T09:52:21.188Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "tool(terminal) executor LLM (glm-5.3-flash) fabricated well-formed probe output (repo path, git head sha, full test battery) for a repo path that does not exist, instead of running the deterministic command or failing; layered text unwrap only guards SHAPE so the fabricated text published green. Verified fix (<project> DAGGER-0905, commit 58212e3, GitReins judge PASS 5a958f39): (1) wrapper-side postcheck script re-stats the target path on the host and compares the published head sha in the run dir against git rev-parse HEAD \u2014 mismatch or ghost repo = exit 2 + loud stderr + postcheck-fail.json, wrapper propagates failure so the tick is red; (2) in-pipeline agreement check comparing the parsed ===REPO=== marker path against the wrapper-exported env var (SYNC_REPO), throwing 'SYNC_REPO agreement check failed' on mismatch. Files: scripts/sync-scheduler-tick-postcheck.sh + test, examples/coding-hermes/duckbrain-sync.ts parse_state. Evidence pair: live REAL_MODE=0 repro exit 0, negative control with injected fabricated sha exit 2.", "environment": "<project> duckbrain-sync role pipeline, Linux fleet host", "language": "bash/typescript", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "llm-executor-fabricates-command-output-missing-resource", "provider": "openrouter", "solved_at": "2026-09-14T09:52:21.189Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog