gitreins-version-skew-lsp-lane-vacuous-pass
Solution written to /workspace/SOLUTION.md (389 lines). Here's the summary.
I downloaded both PyPI releases and exercised the LSP lane directly. Two distinct root causes:
A. The LSP lane is fail-open (the actual vacuous green).
engine/lsp.py:run_lsp_check() returns [] when the tool is missing, and guard_manager.py:_check_lsp() treats [] as "<tool> — clean". Verified on the real wheels with pylsp absent and a staged app.py:
released 0.12.1 -> OVERALL passed: True lane=lsp passed=True out=' pylsp — clean'
released 0.13.0 -> OVERALL passed: True lane=lsp passed=True out=' pylsp — clean'
A lane that ran zero work reports as a clean check. This bug exists in both public releases.
B. The version string is not an engine identity.
Grepping the published 0.13.0 wheel for allow_skips/DEGRADED finds nothing — so ~/gitreins-poc is a local build that declares 0.13.0 but contains code PyPI's 0.13.0 doesn't have. A >= 0.13.0 floor is necessary but insufficient; you must pin to an artifact hash and stamp it into the verdict (the released engine records no engine identity in persisted verdicts at all).
PATH.find_lsp_tool, track missing tools, and return GuardResult(passed=False, ...). Verified: the same run flips to OVERALL passed: False.pip install "python-lsp-server[all]") rather than setting allow_skips: true in a public repo.guard_manager.py SHA256 against a trusted manifest, run with the exact interpreter the engine will use. Verified: 0.12.1 → exit 1 (satisfied=False), 0.13.0 → exit 0 with digest 56b0a4e5…028312.The doc includes the exact diff, the attestation script, the wrapper, trusted hashes, reproduction commands, and acceptance criteria.
# Evidence - Problem class: gitreins-version-skew-lsp-lane-vacuous-pass - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-18T05:50:29.750Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Two gitreins engines in the same fleet give OPPOSITE readings for the same tree, so a green verdict carries no information without the engine version. Verified: `gitreins --version` = 0.12.1 (pipx shim on PATH) vs 0.13.0 (~/gitreins-poc); grepping the pipx site-packages for 'allow_skips'/'DEGRADED' finds no gitreins hit while engine/guard_manager.py in 0.13.0 implements allow_skips, the DEGRADED PASS line and the exit-code policy. Measured by the observing tick with the SAME staged diff: 0.12.1 -> the lsp lane reads checked and the run PASSes exit 0 EVEN with no LSP tool on PATH (vacuous green); 0.13.0 -> '~ lsp - skipped (no LSP tool on PATH (pylsp not installed))' + DEGRADED, and with allow_skips unset a zero-work run exits 2 while allow_skips: true makes it exit 0. Action: name a version floor (or pin the engine) before trusting a skipped/checked lane, and prefer installing the missing tool over enabling allow_skips in a public repo.", "environment": "pipx gitreins 0.12.1 on PATH vs ~/gitreins-poc/.venv/bin/gitreins 0.13.0, same repo and same staged diff", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-version-skew-lsp-lane-vacuous-pass", "provider": "openrouter", "solved_at": "2026-09-18T05:50:29.750Z", "version": ""}Solution written to /workspace/SOLUTION.md (389 lines). Here's the summary.
I downloaded both PyPI releases and exercised the LSP lane directly. Two distinct root causes:
A. The LSP lane is fail-open (the actual vacuous green).
engine/lsp.py:run_lsp_check() returns [] when the tool is missing, and guard_manager.py:_check_lsp() treats [] as "<tool> — clean". Verified on the real wheels with pylsp absent and a staged app.py:
released 0.12.1 -> OVERALL passed: True lane=lsp passed=True out=' pylsp — clean'
released 0.13.0 -> OVERALL passed: True lane=lsp passed=True out=' pylsp — clean'
A lane that ran zero work reports as a clean check. This bug exists in both public releases.
B. The version string is not an engine identity.
Grepping the published 0.13.0 wheel for allow_skips/DEGRADED finds nothing — so ~/gitreins-poc is a local build that declares 0.13.0 but contains code PyPI's 0.13.0 doesn't have. A >= 0.13.0 floor is necessary but insufficient; you must pin to an artifact hash and stamp it into the verdict (the released engine records no engine identity in persisted verdicts at all).
PATH.find_lsp_tool, track missing tools, and return GuardResult(passed=False, ...). Verified: the same run flips to OVERALL passed: False.pip install "python-lsp-server[all]") rather than setting allow_skips: true in a public repo.guard_manager.py SHA256 against a trusted manifest, run with the exact interpreter the engine will use. Verified: 0.12.1 → exit 1 (satisfied=False), 0.13.0 → exit 0 with digest 56b0a4e5…028312.The doc includes the exact diff, the attestation script, the wrapper, trusted hashes, reproduction commands, and acceptance criteria.
# Evidence - Problem class: gitreins-version-skew-lsp-lane-vacuous-pass - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-18T05:50:29.750Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Two gitreins engines in the same fleet give OPPOSITE readings for the same tree, so a green verdict carries no information without the engine version. Verified: `gitreins --version` = 0.12.1 (pipx shim on PATH) vs 0.13.0 (~/gitreins-poc); grepping the pipx site-packages for 'allow_skips'/'DEGRADED' finds no gitreins hit while engine/guard_manager.py in 0.13.0 implements allow_skips, the DEGRADED PASS line and the exit-code policy. Measured by the observing tick with the SAME staged diff: 0.12.1 -> the lsp lane reads checked and the run PASSes exit 0 EVEN with no LSP tool on PATH (vacuous green); 0.13.0 -> '~ lsp - skipped (no LSP tool on PATH (pylsp not installed))' + DEGRADED, and with allow_skips unset a zero-work run exits 2 while allow_skips: true makes it exit 0. Action: name a version floor (or pin the engine) before trusting a skipped/checked lane, and prefer installing the missing tool over enabling allow_skips in a public repo.", "environment": "pipx gitreins 0.12.1 on PATH vs ~/gitreins-poc/.venv/bin/gitreins 0.13.0, same repo and same staged diff", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-version-skew-lsp-lane-vacuous-pass", "provider": "openrouter", "solved_at": "2026-09-18T05:50:29.750Z", "version": ""}