jsonl-board-duplicate-closeout-events
Done. The verified solution is written to:
~/jsonl-board-duplicate-closeout-events.md
Root cause — the legacy appender is not transactional and not topology-aware: it appends the task_completed+audit pair to events.jsonl, then does json.load(board.jsonl), which explodes with Extra data because a thin (topology-A) board.jsonl is JSONL with the header on line 1 (plus extra non-empty rows). The crash leaves an uncommitted pair; a blind boardctl retry appends a second pair → two closeouts for one task/tick. boardctl validate still reports OK, so it is silent.
Exact fix — a prefix + tail model:
events.jsonl before any closeout → the immutable committed prefix;recover_duplicate_closeout.py drops only uncommitted tail rows, keeps the committed pair, and renumbers it into the freed ids;board_closeout.py makes boardctl the sole writer, requires the diff to be exactly +2 (task_completed + audit), requires the boardctl validate health signature to equal the pre-write baseline, and rolls the whole board back on any violation.
Full source for both scripts (copied verbatim from what was executed), plus a no-Python manual fallback.
Verification showing the reproduced crash and both repair paths (residue-only and already-duplicated), plus negative checks (prefix tamper → REFUSE, second closeout → ROLLED BACK).
Both scenarios end with prefix byte-identical, exactly +2 events, exactly one task_completed + one audit, and an unchanged boardctl validate signature. The final acceptance run used the scripts extracted directly from the markdown (confirmed byte-identical to the tested files) and printed ALL GREEN.
# Evidence - Problem class: jsonl-board-duplicate-closeout-events - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-15T11:50:38.011Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Legacy append_board_task_completed.py appends its event pair to a JSONL-canonical board and THEN crashes reading board.jsonl as single-JSON (JSONDecodeError Extra data) because the header now lives as line 1 of board.jsonl. Blind retry with boardctl creates a duplicate closeout: two task_completed + two audit events for one task/tick, which makes event-derived status ambiguous. Recovery that keeps the ledger clean: (1) boardctl is the writer on thin JSONL boards; (2) before commit, diff events.jsonl \u2014 expect exactly +2 lines (auto task_completed + rich audit); (3) if the crashed legacy append left residue, drop ONLY the uncommitted tail rows from the crashed attempt, renumber the kept pair to the freed ids (touch only your own tail; assert the committed prefix byte-identical before writing); (4) boardctl validate signature must equal the pre-write baseline; one closeout, one commit.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "jsonl-board-duplicate-closeout-events", "provider": "openrouter", "solved_at": "2026-09-15T11:50:38.012Z", "version": ""}Done. The verified solution is written to:
~/jsonl-board-duplicate-closeout-events.md
Root cause — the legacy appender is not transactional and not topology-aware: it appends the task_completed+audit pair to events.jsonl, then does json.load(board.jsonl), which explodes with Extra data because a thin (topology-A) board.jsonl is JSONL with the header on line 1 (plus extra non-empty rows). The crash leaves an uncommitted pair; a blind boardctl retry appends a second pair → two closeouts for one task/tick. boardctl validate still reports OK, so it is silent.
Exact fix — a prefix + tail model:
events.jsonl before any closeout → the immutable committed prefix;recover_duplicate_closeout.py drops only uncommitted tail rows, keeps the committed pair, and renumbers it into the freed ids;board_closeout.py makes boardctl the sole writer, requires the diff to be exactly +2 (task_completed + audit), requires the boardctl validate health signature to equal the pre-write baseline, and rolls the whole board back on any violation.
Full source for both scripts (copied verbatim from what was executed), plus a no-Python manual fallback.
Verification showing the reproduced crash and both repair paths (residue-only and already-duplicated), plus negative checks (prefix tamper → REFUSE, second closeout → ROLLED BACK).
Both scenarios end with prefix byte-identical, exactly +2 events, exactly one task_completed + one audit, and an unchanged boardctl validate signature. The final acceptance run used the scripts extracted directly from the markdown (confirmed byte-identical to the tested files) and printed ALL GREEN.
# Evidence - Problem class: jsonl-board-duplicate-closeout-events - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-15T11:50:38.011Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Legacy append_board_task_completed.py appends its event pair to a JSONL-canonical board and THEN crashes reading board.jsonl as single-JSON (JSONDecodeError Extra data) because the header now lives as line 1 of board.jsonl. Blind retry with boardctl creates a duplicate closeout: two task_completed + two audit events for one task/tick, which makes event-derived status ambiguous. Recovery that keeps the ledger clean: (1) boardctl is the writer on thin JSONL boards; (2) before commit, diff events.jsonl \u2014 expect exactly +2 lines (auto task_completed + rich audit); (3) if the crashed legacy append left residue, drop ONLY the uncommitted tail rows from the crashed attempt, renumber the kept pair to the freed ids (touch only your own tail; assert the committed prefix byte-identical before writing); (4) boardctl validate signature must equal the pre-write baseline; one closeout, one commit.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "jsonl-board-duplicate-closeout-events", "provider": "openrouter", "solved_at": "2026-09-15T11:50:38.012Z", "version": ""}