Class: verification-probe-fixture-premise-invariant
Solution written to ~/SOLUTION.md, with a runnable verification artifact at ~/probe-repro/ (go vet clean, go test -race -count=1 PASS). Full document:
Class: verification-probe-fixture-premise-invariant
Repo: <project> · Fixing commit: 1ee6d92 · Files: src/errs/reconciliation.go, src/errs/reconciliation_test.go, src/hconformance/h35.go
A generated verification matrix covering every pair of a closed 6-value enum (6 × 6 = 36 cells) reported 33 of 36 cells FAILING. Every failing cell carried the same refusal from a domain constructor:
refused member="unresolved_operation_ids" value="1 entries"
reason=requires_reconciliation is false while unresolved_operation_ids is
not empty: requires an empty array for a false flag
That reads as a systemic product defect and sends you into reconciliation.go. It is not a product defect.
The fixture helper built each cell through the validated record constructor pairing a decided enum value with a non-empty identifier list while leaving the boolean flag false. The closed contract is total:
| rule | consequence |
|---|---|
requires_reconciliation == false |
unresolved_operation_ids must be empty |
requires_reconciliation == true |
unresolved_operation_ids must be non-empty |
requires_reconciliation == true |
retryable must be false |
The constructor obeyed its contract and refused 33 of 36 inputs; the behaviour under test was never reached. Three cells happened to carry an empty list, which is why the count was 33, not 36.
Diagnostic tell: when every failing cell quotes the same constructor refusal, suspect the fixture, not 33 independent product paths.
Part 1 — build every cell in the lawful form (src/hconformance/h35.go):
for _, declared := range enum.Values() {
for _, observed := range enum.Values() {
declared, observed := declared, observed
t.Run(fmt.Sprintf("%s/%s", declared, observed), func(t *testing.T) {
// LAWFUL: flag true => ids non-empty AND retryable false.
rec, err := errs.NewRecord(
"probe-subject",
declared,
true, // requires_reconciliation = true
[]string{"op-1"}, // non-empty => lawful with true
false, // flag constrains retryability
)
if err != nil {
// A constructor refusal is an INVALID PROBE, never a product failure.
t.Fatalf("premise: cell (%s,%s): fixture constructor refused: %v",
declared, observed, err)
}
// ... story continues in Part 2 ...
})
}
}
Cells supposed to be refused by the code under test are still refused — by the code, not the constructor.
Part 2 — assert the fixture premise before the behaviour:
if got := rec.Subject(); got != "probe-subject" {
t.Fatalf("premise: cell (%s,%s): subject=%q", declared, observed, got)
}
if got := rec.Outcome(); got != declared {
t.Fatalf("premise: cell (%s,%s): outcome=%s want %s", declared, observed, got, declared)
}
// Only now exercise the code under test.
got, err := hconformance.Resolve(rec, observed)
// ... assert got/err for this cell ...
Ordering is the point: premise first, behaviour second. If the premise fails, the behaviour was never meaningfully executed.
Part 3 — the two real product cells (src/errs/reconciliation.go): with lawful fixtures, exactly two cells were still red; those were the genuine defect (two lawful transitions wrongly refused pre-fix). reconciliation_test.go pins them as unit regressions.
A single green run does not prove the probe is load-bearing; the two-revision comparison does.
~/probe-repro/model_test.go reproduces the same closed-enum/constructor/refusal shapes. go test -race -count=1 -v ./...:
naive probe: pass=3 invalid-probe=33 product-fail=0
fixed probe @ fixed product: pass=36 invalid-probe=0 product-fail=0
fixed probe @ pre-fix product: pass=34 invalid-probe=0 product-fail=2
load-bearing cell (reconcile,ok): unexpected refusal: refused member="observed" value="ok" reason=illegal transition from reconcile
load-bearing cell (reconcile,fail): unexpected refusal: refused member="observed" value="fail" reason=illegal transition from reconcile
unlawful premise reported as invalid probe: refused member="unresolved_operation_ids" value="1 entries" ...
PASS
ok hermesprobe 1.012s
go test -race -count=1 ./src/hconformance/... ./src/errs/... # HEAD: green
git worktree add --detach /tmp/<project>-prefix '1ee6d92^'
# Port ONLY the fixed probe; leave the old product in place.
cp src/hconformance/h35.go /tmp/<project>-prefix/src/hconformance/h35.go
( cd /tmp/<project>-prefix && go test -race -count=1 ./src/hconformance/... )
git worktree remove --force /tmp/<project>-prefix
Expected at pre-fix: exactly two failing cells, each quoting the production refusal verbatim; other 34 identical. Then gitreins verify --tier tier1,tier2 (verdict f3b60821, PASS); CI runs 35165786809 and 35166660269 both green.
In a generated test/verification matrix, assert the fixture premise independently of the behaviour under test. A domain constructor refusing an input is an invalid probe, never evidence of a defect.
Checklist: lawful constructor calls · premise asserted first · one subtest per cell · separate invalid-probe vs product-fail counters · prove the probe is load-bearing and surgical by red-on-exactly-the-defect-cells at the pre-fix revision.
Files produced
- ~/SOLUTION.md — the write-up above
- ~/probe-repro/go.mod, ~/probe-repro/model_test.go — runnable, race-clean verification artifact reproducing 3/33/0, 36/0/0, and 34/0/2
# Evidence - Problem class: verification-probe-fixture-premise-invariant - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-17T00:38:59.627Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "SYMPTOM: a generated verification matrix (every pair of a 6-value closed enum, 36 cells) reported 33 of 36 cells FAILING against the code under test, which reads as a mass defect and sends you into the production code. Every failing cell carried the same refusal from a domain CONSTRUCTOR: 'refused member=\"unresolved_operation_ids\" value=\"1 entries\" reason=requires_reconciliation is false while unresolved_operation_ids is not empty: requires an empty array for a false flag'.\n\nROOT CAUSE (probe, not product): the matrix built each cell through a real fixture helper that constructs a validated record, and paired a decided enum value with an identifier list while leaving the boolean flag false. The domain rule (a closed error-record contract) forbids exactly that combination: a non-empty unresolved-identifier list is only lawful when the accompanying flag is true, and that flag in turn constrains the retryability field. So the CONSTRUCTOR correctly refused the inputs; the behaviour under test was never reached. 33 'failures' were 33 invalid fixtures.\n\nFIX (two parts, both cheap):\n(1) Build every matrix cell in the lawful form: set the flag true, use the value the flag requires for the dependent field, and keep the identifier list non-empty. The cells that are SUPPOSED to be refused by the code under test are still refused - by the code, not by the constructor.\n(2) Assert the FIXTURE PREMISE separately from the behaviour, before the assertion that matters: that the record declares the subject, and that the accessor returns the exact enum value the cell intends (premise assert -> 'premise: ...'). A constructor refusal then reports as an invalid probe instead of a product failure, and the diagnostic names the premise rather than the code.\n\nVERIFICATION: with the premise fixed, all 36 cells passed at the fixed revision, and the SAME probe run in a throwaway git worktree at the pre-fix revision failed on exactly the two cells the defect actually covered (with the production refusal quoted verbatim) while the other 34 cells were identical on both revisions. That two-revision comparison is what proves the probe is load-bearing AND surgical, which a single green run never shows.\n\nGENERAL RULE: in a generated test/verification matrix, assert the fixture premise independently of the behaviour under test. A domain constructor refusing an input is an INVALID PROBE, never evidence of a defect - and a matrix whose cells can be silently invalid turns one bad fixture into a wall of false REDs that look like a systemic failure.", "environment": "Go 1.23, go test -race -count=1, git worktree for the pre-fix comparison", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "verification-probe-fixture-premise-invariant", "provider": "openrouter", "solved_at": "2026-09-17T00:38:59.628Z", "version": ""}Solution written to ~/SOLUTION.md, with a runnable verification artifact at ~/probe-repro/ (go vet clean, go test -race -count=1 PASS). Full document:
Class: verification-probe-fixture-premise-invariant
Repo: <project> · Fixing commit: 1ee6d92 · Files: src/errs/reconciliation.go, src/errs/reconciliation_test.go, src/hconformance/h35.go
A generated verification matrix covering every pair of a closed 6-value enum (6 × 6 = 36 cells) reported 33 of 36 cells FAILING. Every failing cell carried the same refusal from a domain constructor:
refused member="unresolved_operation_ids" value="1 entries"
reason=requires_reconciliation is false while unresolved_operation_ids is
not empty: requires an empty array for a false flag
That reads as a systemic product defect and sends you into reconciliation.go. It is not a product defect.
The fixture helper built each cell through the validated record constructor pairing a decided enum value with a non-empty identifier list while leaving the boolean flag false. The closed contract is total:
| rule | consequence |
|---|---|
requires_reconciliation == false |
unresolved_operation_ids must be empty |
requires_reconciliation == true |
unresolved_operation_ids must be non-empty |
requires_reconciliation == true |
retryable must be false |
The constructor obeyed its contract and refused 33 of 36 inputs; the behaviour under test was never reached. Three cells happened to carry an empty list, which is why the count was 33, not 36.
Diagnostic tell: when every failing cell quotes the same constructor refusal, suspect the fixture, not 33 independent product paths.
Part 1 — build every cell in the lawful form (src/hconformance/h35.go):
for _, declared := range enum.Values() {
for _, observed := range enum.Values() {
declared, observed := declared, observed
t.Run(fmt.Sprintf("%s/%s", declared, observed), func(t *testing.T) {
// LAWFUL: flag true => ids non-empty AND retryable false.
rec, err := errs.NewRecord(
"probe-subject",
declared,
true, // requires_reconciliation = true
[]string{"op-1"}, // non-empty => lawful with true
false, // flag constrains retryability
)
if err != nil {
// A constructor refusal is an INVALID PROBE, never a product failure.
t.Fatalf("premise: cell (%s,%s): fixture constructor refused: %v",
declared, observed, err)
}
// ... story continues in Part 2 ...
})
}
}
Cells supposed to be refused by the code under test are still refused — by the code, not the constructor.
Part 2 — assert the fixture premise before the behaviour:
if got := rec.Subject(); got != "probe-subject" {
t.Fatalf("premise: cell (%s,%s): subject=%q", declared, observed, got)
}
if got := rec.Outcome(); got != declared {
t.Fatalf("premise: cell (%s,%s): outcome=%s want %s", declared, observed, got, declared)
}
// Only now exercise the code under test.
got, err := hconformance.Resolve(rec, observed)
// ... assert got/err for this cell ...
Ordering is the point: premise first, behaviour second. If the premise fails, the behaviour was never meaningfully executed.
Part 3 — the two real product cells (src/errs/reconciliation.go): with lawful fixtures, exactly two cells were still red; those were the genuine defect (two lawful transitions wrongly refused pre-fix). reconciliation_test.go pins them as unit regressions.
A single green run does not prove the probe is load-bearing; the two-revision comparison does.
~/probe-repro/model_test.go reproduces the same closed-enum/constructor/refusal shapes. go test -race -count=1 -v ./...:
naive probe: pass=3 invalid-probe=33 product-fail=0
fixed probe @ fixed product: pass=36 invalid-probe=0 product-fail=0
fixed probe @ pre-fix product: pass=34 invalid-probe=0 product-fail=2
load-bearing cell (reconcile,ok): unexpected refusal: refused member="observed" value="ok" reason=illegal transition from reconcile
load-bearing cell (reconcile,fail): unexpected refusal: refused member="observed" value="fail" reason=illegal transition from reconcile
unlawful premise reported as invalid probe: refused member="unresolved_operation_ids" value="1 entries" ...
PASS
ok hermesprobe 1.012s
go test -race -count=1 ./src/hconformance/... ./src/errs/... # HEAD: green
git worktree add --detach /tmp/<project>-prefix '1ee6d92^'
# Port ONLY the fixed probe; leave the old product in place.
cp src/hconformance/h35.go /tmp/<project>-prefix/src/hconformance/h35.go
( cd /tmp/<project>-prefix && go test -race -count=1 ./src/hconformance/... )
git worktree remove --force /tmp/<project>-prefix
Expected at pre-fix: exactly two failing cells, each quoting the production refusal verbatim; other 34 identical. Then gitreins verify --tier tier1,tier2 (verdict f3b60821, PASS); CI runs 35165786809 and 35166660269 both green.
In a generated test/verification matrix, assert the fixture premise independently of the behaviour under test. A domain constructor refusing an input is an invalid probe, never evidence of a defect.
Checklist: lawful constructor calls · premise asserted first · one subtest per cell · separate invalid-probe vs product-fail counters · prove the probe is load-bearing and surgical by red-on-exactly-the-defect-cells at the pre-fix revision.
Files produced
- ~/SOLUTION.md — the write-up above
- ~/probe-repro/go.mod, ~/probe-repro/model_test.go — runnable, race-clean verification artifact reproducing 3/33/0, 36/0/0, and 34/0/2
# Evidence - Problem class: verification-probe-fixture-premise-invariant - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-17T00:38:59.627Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "SYMPTOM: a generated verification matrix (every pair of a 6-value closed enum, 36 cells) reported 33 of 36 cells FAILING against the code under test, which reads as a mass defect and sends you into the production code. Every failing cell carried the same refusal from a domain CONSTRUCTOR: 'refused member=\"unresolved_operation_ids\" value=\"1 entries\" reason=requires_reconciliation is false while unresolved_operation_ids is not empty: requires an empty array for a false flag'.\n\nROOT CAUSE (probe, not product): the matrix built each cell through a real fixture helper that constructs a validated record, and paired a decided enum value with an identifier list while leaving the boolean flag false. The domain rule (a closed error-record contract) forbids exactly that combination: a non-empty unresolved-identifier list is only lawful when the accompanying flag is true, and that flag in turn constrains the retryability field. So the CONSTRUCTOR correctly refused the inputs; the behaviour under test was never reached. 33 'failures' were 33 invalid fixtures.\n\nFIX (two parts, both cheap):\n(1) Build every matrix cell in the lawful form: set the flag true, use the value the flag requires for the dependent field, and keep the identifier list non-empty. The cells that are SUPPOSED to be refused by the code under test are still refused - by the code, not by the constructor.\n(2) Assert the FIXTURE PREMISE separately from the behaviour, before the assertion that matters: that the record declares the subject, and that the accessor returns the exact enum value the cell intends (premise assert -> 'premise: ...'). A constructor refusal then reports as an invalid probe instead of a product failure, and the diagnostic names the premise rather than the code.\n\nVERIFICATION: with the premise fixed, all 36 cells passed at the fixed revision, and the SAME probe run in a throwaway git worktree at the pre-fix revision failed on exactly the two cells the defect actually covered (with the production refusal quoted verbatim) while the other 34 cells were identical on both revisions. That two-revision comparison is what proves the probe is load-bearing AND surgical, which a single green run never shows.\n\nGENERAL RULE: in a generated test/verification matrix, assert the fixture premise independently of the behaviour under test. A domain constructor refusing an input is an INVALID PROBE, never evidence of a defect - and a matrix whose cells can be silently invalid turns one bad fixture into a wall of false REDs that look like a systemic failure.", "environment": "Go 1.23, go test -race -count=1, git worktree for the pre-fix comparison", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "verification-probe-fixture-premise-invariant", "provider": "openrouter", "solved_at": "2026-09-17T00:38:59.628Z", "version": ""}