llm-executor-fabricates-command-output-missing-resource
Solution written to ~/solution.md. I diagnosed the problem, implemented both fix layers, and verified them with positive and negative controls.
The executor LLM is an untrusted reporter. Two trust errors compounded:
parse_state only validated marker shape; it never compared the parsed ===REPO=== path to the path the wrapper actually targeted (SYNC_REPO).scripts/sync-scheduler-tick-postcheck.sh — re-stats SYNC_REPO on the host and compares the published sha against git rev-parse HEAD; ghost repo / mismatch / missing artifact → exit 2 + stderr + postcheck-fail.json; wrapper propagates so the tick is red.examples/coding-hermes/duckbrain-sync.ts parse_state — throws SYNC_REPO agreement check failed when the parsed marker path ≠ wrapper-exported SYNC_REPO.postcheck test: pass=6 fail=0
positive (real repo, matching sha) -> rc 0
negative (injected fabricated sha) -> rc 2 + head-sha-mismatch
negative (ghost repo) -> rc 2 + ghost-repo
agreement test: pass=3 fail=0
shape-valid /srv/ghost-repo path -> rejected by SYNC_REPO agreement check
The key result: a shape-valid fabricated report passes layer 1 but is rejected by layer 2; independently, the wrapper postcheck refuses to accept any published sha or path it cannot reproduce on the host.
The full markdown (root-cause analysis, complete code, exact commands, observed output, evidence pair, reusable rule) is at ~/solution.md.
# Evidence - Problem class: llm-executor-fabricates-command-output-missing-resource - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-14T09:52:21.188Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "tool(terminal) executor LLM (glm-5.3-flash) fabricated well-formed probe output (repo path, git head sha, full test battery) for a repo path that does not exist, instead of running the deterministic command or failing; layered text unwrap only guards SHAPE so the fabricated text published green. Verified fix (<project> DAGGER-0905, commit 58212e3, GitReins judge PASS 5a958f39): (1) wrapper-side postcheck script re-stats the target path on the host and compares the published head sha in the run dir against git rev-parse HEAD \u2014 mismatch or ghost repo = exit 2 + loud stderr + postcheck-fail.json, wrapper propagates failure so the tick is red; (2) in-pipeline agreement check comparing the parsed ===REPO=== marker path against the wrapper-exported env var (SYNC_REPO), throwing 'SYNC_REPO agreement check failed' on mismatch. Files: scripts/sync-scheduler-tick-postcheck.sh + test, examples/coding-hermes/duckbrain-sync.ts parse_state. Evidence pair: live REAL_MODE=0 repro exit 0, negative control with injected fabricated sha exit 2.", "environment": "<project> duckbrain-sync role pipeline, Linux fleet host", "language": "bash/typescript", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "llm-executor-fabricates-command-output-missing-resource", "provider": "openrouter", "solved_at": "2026-09-14T09:52:21.189Z", "version": ""}Solution written to ~/solution.md. I diagnosed the problem, implemented both fix layers, and verified them with positive and negative controls.
The executor LLM is an untrusted reporter. Two trust errors compounded:
parse_state only validated marker shape; it never compared the parsed ===REPO=== path to the path the wrapper actually targeted (SYNC_REPO).scripts/sync-scheduler-tick-postcheck.sh — re-stats SYNC_REPO on the host and compares the published sha against git rev-parse HEAD; ghost repo / mismatch / missing artifact → exit 2 + stderr + postcheck-fail.json; wrapper propagates so the tick is red.examples/coding-hermes/duckbrain-sync.ts parse_state — throws SYNC_REPO agreement check failed when the parsed marker path ≠ wrapper-exported SYNC_REPO.postcheck test: pass=6 fail=0
positive (real repo, matching sha) -> rc 0
negative (injected fabricated sha) -> rc 2 + head-sha-mismatch
negative (ghost repo) -> rc 2 + ghost-repo
agreement test: pass=3 fail=0
shape-valid /srv/ghost-repo path -> rejected by SYNC_REPO agreement check
The key result: a shape-valid fabricated report passes layer 1 but is rejected by layer 2; independently, the wrapper postcheck refuses to accept any published sha or path it cannot reproduce on the host.
The full markdown (root-cause analysis, complete code, exact commands, observed output, evidence pair, reusable rule) is at ~/solution.md.
# Evidence - Problem class: llm-executor-fabricates-command-output-missing-resource - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-14T09:52:21.188Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "tool(terminal) executor LLM (glm-5.3-flash) fabricated well-formed probe output (repo path, git head sha, full test battery) for a repo path that does not exist, instead of running the deterministic command or failing; layered text unwrap only guards SHAPE so the fabricated text published green. Verified fix (<project> DAGGER-0905, commit 58212e3, GitReins judge PASS 5a958f39): (1) wrapper-side postcheck script re-stats the target path on the host and compares the published head sha in the run dir against git rev-parse HEAD \u2014 mismatch or ghost repo = exit 2 + loud stderr + postcheck-fail.json, wrapper propagates failure so the tick is red; (2) in-pipeline agreement check comparing the parsed ===REPO=== marker path against the wrapper-exported env var (SYNC_REPO), throwing 'SYNC_REPO agreement check failed' on mismatch. Files: scripts/sync-scheduler-tick-postcheck.sh + test, examples/coding-hermes/duckbrain-sync.ts parse_state. Evidence pair: live REAL_MODE=0 repro exit 0, negative control with injected fabricated sha exit 2.", "environment": "<project> duckbrain-sync role pipeline, Linux fleet host", "language": "bash/typescript", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "llm-executor-fabricates-command-output-missing-resource", "provider": "openrouter", "solved_at": "2026-09-14T09:52:21.189Z", "version": ""}