release-script-cleanliness-gate-rejects-agent-harness-local-state
Wrote the solution to ~/solution.md.
Root cause: scripts/release.sh gated tagging on raw git status --porcelain. In an agent-harness repo that output is never empty because .gitreins/ (tasks, usage, history, locks) and .coding-hermes/ board files are dirty/untracked by convention — so the gate permanently blocked the tag cut by treating bookkeeping as code dirt.
Fix: filter porcelain to a remainder before refusing:
NON_CODE_RE='^.. [.]gitreins/|^.. [.]coding-hermes/'
dirty_code() { git status --porcelain | grep -Ev "$NON_CODE_RE" || true; }
[ -n "$(dirty_code)" ] && { echo "release: worktree is not clean" >&2; dirty_code >&2; exit 1; }
git rev-parse -q --verify "refs/tags/$TAG" >/dev/null && { echo "release: tag $TAG already exists" >&2; exit 1; }
git tag -a "$TAG" -m "release $TAG"
Verified live in a temp repo simulating the harness:
- bash -n → exit 0
- clean code + only .gitreins//.coding-hermes/ dirty → exit 0, annotated tag created
- pre-existing v0.7.0 → exit 1
- staged and unstaged code dirt → exit 1, listing only the real path
Key design point noted in the doc: grep -Ev is line-anchored, so only root-level harness prefixes are ignored, genuinely untracked source still blocks, and || true prevents set -e -o pipefail from aborting on a clean tree.
# Evidence - Problem class: release-script-cleanliness-gate-rejects-agent-harness-local-state - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-21T13:06:49.998Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A release script whose safety gate is 'git status --porcelain non-empty' can NEVER run on an agent-harness repo where .gitreins/ (tasks.yaml, usage.jsonl, history/, *.lock) and .coding-hermes/ board files are always dirty or untracked by fleet convention (board commits land at tick end; gitreins local state is never committed). Symptom: scripts/release.sh exits 1 'worktree is not clean' listing only .gitreins/.coding-hermes paths and untracked prompt files, blocking the required annotated tag cut. Root cause: the gate conflates harness-local bookkeeping state with real code dirt. Fix: filter the porcelain output to exclude documented non-code path prefixes (git status --porcelain | grep -Ev '^.. [.]gitreins/|^.. [.]coding-hermes/') and refuse only on the remainder; keep refusing genuinely dirty code trees and pre-existing tags. Verification: bash -n exit 0; live run correctly refuses with exit 1 when tag v0.7.0 already exists; cuts the annotated tag on a clean-code tree; commits land through the guard; judge round 2 re-verified by simulating the script in a temp clone (exit 0, correct output) and the live refusal (exit 1).", "environment": "linux, git 2.x, gitreins pre-commit-guard repo, pnpm monorepo", "language": "bash", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "release-script-cleanliness-gate-rejects-agent-harness-local-state", "provider": "openrouter", "solved_at": "2026-09-21T13:06:49.998Z", "version": ""}Wrote the solution to ~/solution.md.
Root cause: scripts/release.sh gated tagging on raw git status --porcelain. In an agent-harness repo that output is never empty because .gitreins/ (tasks, usage, history, locks) and .coding-hermes/ board files are dirty/untracked by convention — so the gate permanently blocked the tag cut by treating bookkeeping as code dirt.
Fix: filter porcelain to a remainder before refusing:
NON_CODE_RE='^.. [.]gitreins/|^.. [.]coding-hermes/'
dirty_code() { git status --porcelain | grep -Ev "$NON_CODE_RE" || true; }
[ -n "$(dirty_code)" ] && { echo "release: worktree is not clean" >&2; dirty_code >&2; exit 1; }
git rev-parse -q --verify "refs/tags/$TAG" >/dev/null && { echo "release: tag $TAG already exists" >&2; exit 1; }
git tag -a "$TAG" -m "release $TAG"
Verified live in a temp repo simulating the harness:
- bash -n → exit 0
- clean code + only .gitreins//.coding-hermes/ dirty → exit 0, annotated tag created
- pre-existing v0.7.0 → exit 1
- staged and unstaged code dirt → exit 1, listing only the real path
Key design point noted in the doc: grep -Ev is line-anchored, so only root-level harness prefixes are ignored, genuinely untracked source still blocks, and || true prevents set -e -o pipefail from aborting on a clean tree.
# Evidence - Problem class: release-script-cleanliness-gate-rejects-agent-harness-local-state - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-21T13:06:49.998Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A release script whose safety gate is 'git status --porcelain non-empty' can NEVER run on an agent-harness repo where .gitreins/ (tasks.yaml, usage.jsonl, history/, *.lock) and .coding-hermes/ board files are always dirty or untracked by fleet convention (board commits land at tick end; gitreins local state is never committed). Symptom: scripts/release.sh exits 1 'worktree is not clean' listing only .gitreins/.coding-hermes paths and untracked prompt files, blocking the required annotated tag cut. Root cause: the gate conflates harness-local bookkeeping state with real code dirt. Fix: filter the porcelain output to exclude documented non-code path prefixes (git status --porcelain | grep -Ev '^.. [.]gitreins/|^.. [.]coding-hermes/') and refuse only on the remainder; keep refusing genuinely dirty code trees and pre-existing tags. Verification: bash -n exit 0; live run correctly refuses with exit 1 when tag v0.7.0 already exists; cuts the annotated tag on a clean-code tree; commits land through the guard; judge round 2 re-verified by simulating the script in a temp clone (exit 0, correct output) and the live refusal (exit 1).", "environment": "linux, git 2.x, gitreins pre-commit-guard repo, pnpm monorepo", "language": "bash", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "release-script-cleanliness-gate-rejects-agent-harness-local-state", "provider": "openrouter", "solved_at": "2026-09-21T13:06:49.998Z", "version": ""}