duckbrain-record-key-drift-exact-key-presence-check
Diagnosed and delivered a verified fix. Full write-up: ~/solution.md.
Four independent defects let the drift read as success:
/project/h3/tick/464 looked landed.h3 was internally self-consistent, so a chain-scoped check accepted the wrong shape.END = ticks_total-1 means a hole at N is only visible once ticks_total >= N+1.scripts/duckbrain-tick-record.sh — re-GETs prefix /tick/<N> after every write and fails unless exactly one item exists and items[0].key == /tick/<N>. Content is used only to name the drift candidate, never to declare success.scripts/duckbrain-census.sh — union key-shape census across all chains (never per-chain), canonical shape /tick/#, explicit LEGACY_SHAPES allowlist bounded by LEGACY_MAX, duplicate/hole detection, and the documented one-tick lag.scripts/duckbrain-backfill.sh — copies the drifted value verbatim to the canonical key, re-verifies exact-key, and keeps the twin as an allowlisted specimen.tests/mock_duckbrain + tests/run_tests.sh — reproduce the drift and verify the fix.tests/run_tests.sh → 13/13 pass, including: old grep blind to drift, hardened writer failing on drift and passing clean, verbatim backfill with twin retained, LEGACY_MAX bound, per-chain vs. union divergence, and the one-tick lag.
# Evidence - Problem class: duckbrain-record-key-drift-exact-key-presence-check - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-21T11:47:31.772Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Foreman tick record landed at a DRIFTED DuckBrain key (/project/h3/tick/464 instead of bare /tick/464) and the writer verified presence with a content grep that was blind to key shape, so the drift read as landed; a per-chain census also over-tolerated the wrong shape. What worked: (1) treat per-chain key-shape differences as a UNION census, never per-chain; (2) make the write tool enforce the exact canonical key - scripts/duckbrain-tick-record.sh re-GETs prefix /tick/<N> after every write and FAILS unless exactly one item exists AND items[0].key == /tick/<N>; (3) backfill the canonical key verbatim from the drifted record content and keep the twin as an allowlisted specimen; (4) bound any tolerated legacy key class (LEGACY_MAX) so future drift cannot hide in a tolerated branch; (5) the census window END=ticks_total-1 means a hole at N is catchable only at tick N+1 - expect and document the one-tick lag.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "duckbrain-record-key-drift-exact-key-presence-check", "provider": "openrouter", "solved_at": "2026-09-21T11:47:31.773Z", "version": ""}Diagnosed and delivered a verified fix. Full write-up: ~/solution.md.
Four independent defects let the drift read as success:
/project/h3/tick/464 looked landed.h3 was internally self-consistent, so a chain-scoped check accepted the wrong shape.END = ticks_total-1 means a hole at N is only visible once ticks_total >= N+1.scripts/duckbrain-tick-record.sh — re-GETs prefix /tick/<N> after every write and fails unless exactly one item exists and items[0].key == /tick/<N>. Content is used only to name the drift candidate, never to declare success.scripts/duckbrain-census.sh — union key-shape census across all chains (never per-chain), canonical shape /tick/#, explicit LEGACY_SHAPES allowlist bounded by LEGACY_MAX, duplicate/hole detection, and the documented one-tick lag.scripts/duckbrain-backfill.sh — copies the drifted value verbatim to the canonical key, re-verifies exact-key, and keeps the twin as an allowlisted specimen.tests/mock_duckbrain + tests/run_tests.sh — reproduce the drift and verify the fix.tests/run_tests.sh → 13/13 pass, including: old grep blind to drift, hardened writer failing on drift and passing clean, verbatim backfill with twin retained, LEGACY_MAX bound, per-chain vs. union divergence, and the one-tick lag.
# Evidence - Problem class: duckbrain-record-key-drift-exact-key-presence-check - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-21T11:47:31.772Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Foreman tick record landed at a DRIFTED DuckBrain key (/project/h3/tick/464 instead of bare /tick/464) and the writer verified presence with a content grep that was blind to key shape, so the drift read as landed; a per-chain census also over-tolerated the wrong shape. What worked: (1) treat per-chain key-shape differences as a UNION census, never per-chain; (2) make the write tool enforce the exact canonical key - scripts/duckbrain-tick-record.sh re-GETs prefix /tick/<N> after every write and FAILS unless exactly one item exists AND items[0].key == /tick/<N>; (3) backfill the canonical key verbatim from the drifted record content and keep the twin as an allowlisted specimen; (4) bound any tolerated legacy key class (LEGACY_MAX) so future drift cannot hide in a tolerated branch; (5) the census window END=ticks_total-1 means a hole at N is catchable only at tick N+1 - expect and document the one-tick lag.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "duckbrain-record-key-drift-exact-key-presence-check", "provider": "openrouter", "solved_at": "2026-09-21T11:47:31.773Z", "version": ""}