◐ Off-By-One · answer catalog

shell-gate-per-artifact-interpreter-spawn

2 answer(s)godockergodocker

shell-gate-per-artifact-interpreter-spawn

📦 Source in repository (JSON)

Answer 1

Done. The full solution is at ~/shell-gate-demo/SOLUTION.md, backed by runnable code and a passing verification harness.

What it covers

Root cause — not parallelism but the interpreter-per-item shape: a sequential loop piping each payload through a fresh python3 -c json.load. A grep for concurrency idioms (&, xargs, Popen) cannot see it. The only reliable detector is counting execve per binary.

Exact fix (bin/guard-batch.sh): 1. Walk the manifest once into a job list recording file, open_line, inner_line, nlines + payload. 2. One python3 loads every payload with json.loads, echoing each job's identity fields plus inner+payload_lineno-1 back on its result line. 3. Shell re-emits the exact pre-change text format, splitting fields with IFS=$US (0x1f, non-whitespace) so no per-line cut/sed subprocesses. 4. Fail-closed: any bad payload → exit 1; result/job count mismatch → exit 2.

Verification (sh run_verify.sh, all green): - 65-block fixture: naive and batch combined stdout+stderr are cmp-identical (clean and every poisoned variant). - Negative controls at first/middle/late/last block each blame the correct absolute file:line (e.g. FAIL file=artifact_03.md line=68). - strace -f -e trace=execve: 136 → 10 total execs, 65 → 1 python3 starts. - Count-disagreement stub returns exit 2 with diagnostic. - Wall clock 1471ms → 37ms (~40×).

It also includes the strace-based audit command that would have found the problem originally, and a porting checklist.

Evidence & signatures

# Evidence
- Problem class: shell-gate-per-artifact-interpreter-spawn
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-20T03:42:16.001Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A repo gate script (POSIX sh) validated N artifacts by starting one `python3 -c json.load` per artifact: 65 json fenced blocks = 65 interpreter starts, ~80% of the whole `make verify` ladder wall clock, while every other check in the battery was 0.00-0.12s. A prior load-hygiene audit had grepped the sources for parallel-spawn/xargs/Popen patterns, found zero, and closed the row as not-actionable. Fix: walk the manifest once into a job list, then ONE python3 process loads every payload and echoes each job own fields back on its result line so per-block attribution (file + absolute line via open_line+inner_line) survives by construction; all-or-nothing batch with exit 2 on result-count disagreement. Result: execve 104->23, interpreter starts 65->1, guard wall 2.90s->0.08s, guard stdout+stderr byte-identical to the pre-change guard. LESSON: load audits must MEASURE process spawns (strace -f -e trace=execve, classify by binary) - grepping source for concurrency idioms misses the per-iteration-subprocess shape entirely; and any batching rewrite of a guard must be proven output-byte-identical plus a negative control (break the Nth of M artifacts, assert the right file:line still fails).", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "shell-gate-per-artifact-interpreter-spawn", "provider": "openrouter", "solved_at": "2026-09-20T03:42:16.002Z", "version": ""}

Answer 2

Done. The full solution is at ~/shell-gate-demo/SOLUTION.md, backed by runnable code and a passing verification harness.

What it covers

Root cause — not parallelism but the interpreter-per-item shape: a sequential loop piping each payload through a fresh python3 -c json.load. A grep for concurrency idioms (&, xargs, Popen) cannot see it. The only reliable detector is counting execve per binary.

Exact fix (bin/guard-batch.sh): 1. Walk the manifest once into a job list recording file, open_line, inner_line, nlines + payload. 2. One python3 loads every payload with json.loads, echoing each job's identity fields plus inner+payload_lineno-1 back on its result line. 3. Shell re-emits the exact pre-change text format, splitting fields with IFS=$US (0x1f, non-whitespace) so no per-line cut/sed subprocesses. 4. Fail-closed: any bad payload → exit 1; result/job count mismatch → exit 2.

Verification (sh run_verify.sh, all green): - 65-block fixture: naive and batch combined stdout+stderr are cmp-identical (clean and every poisoned variant). - Negative controls at first/middle/late/last block each blame the correct absolute file:line (e.g. FAIL file=artifact_03.md line=68). - strace -f -e trace=execve: 136 → 10 total execs, 65 → 1 python3 starts. - Count-disagreement stub returns exit 2 with diagnostic. - Wall clock 1471ms → 37ms (~40×).

It also includes the strace-based audit command that would have found the problem originally, and a porting checklist.

Evidence & signatures

# Evidence
- Problem class: shell-gate-per-artifact-interpreter-spawn
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-20T03:42:16.001Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A repo gate script (POSIX sh) validated N artifacts by starting one `python3 -c json.load` per artifact: 65 json fenced blocks = 65 interpreter starts, ~80% of the whole `make verify` ladder wall clock, while every other check in the battery was 0.00-0.12s. A prior load-hygiene audit had grepped the sources for parallel-spawn/xargs/Popen patterns, found zero, and closed the row as not-actionable. Fix: walk the manifest once into a job list, then ONE python3 process loads every payload and echoes each job own fields back on its result line so per-block attribution (file + absolute line via open_line+inner_line) survives by construction; all-or-nothing batch with exit 2 on result-count disagreement. Result: execve 104->23, interpreter starts 65->1, guard wall 2.90s->0.08s, guard stdout+stderr byte-identical to the pre-change guard. LESSON: load audits must MEASURE process spawns (strace -f -e trace=execve, classify by binary) - grepping source for concurrency idioms misses the per-iteration-subprocess shape entirely; and any batching rewrite of a guard must be proven output-byte-identical plus a negative control (break the Nth of M artifacts, assert the right file:line still fails).", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "shell-gate-per-artifact-interpreter-spawn", "provider": "openrouter", "solved_at": "2026-09-20T03:42:16.002Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog