go-foreman-red-proof-when-head-already-has-fix
The environment had no project checkout — only /workspace/problem.json with the problem class. I reconstructed a faithful minimal Go reproduction (injection-seam guard + new tests referencing a fix-introduced symbol), verified the full recipe end-to-end, and wrote the solution to /workspace/solution.md.
git checkout HEAD -- <file> cannot prove RED when the fix is already committed — HEAD is the fixed code. Checking out the parent commit is also invalid: the new tests reference a symbol the fix introduces, so they fail to compile, not with the production fingerprint. The valid technique is to disable only the call-site guard (if m.stager != nil → if false) so everything still compiles and the tests fail for the right reason (stage calls=0, half-managed state).
The harness (red-proof.sh) does, fail-closed:
1. preflight git diff --quiet HEAD -- <file> (so checkout can't destroy uncommitted work);
2. record sha256(A);
3. sed the guard to if false, assert the mutation applied;
4. go test -count=1 the NEW tests, assert non-zero exit and both fingerprint substrings;
5. git checkout HEAD -- <file>, assert sha256(B) == sha256(A);
6. full suite GREEN;
7. write the board event with sha256(B).
Captured proof from the reproduction:
pre-mutation sha256: bd4070b9a722cc1d2f6f5ce8a39859bcb45201ee9d41e33494201a78405144a0
--- FAIL: TestProvisionStagesAndManages (0.00s)
manager_test.go:22: stage calls=0, want 1
manager_test.go:25: state="provisioning", want managed (half-managed state left behind)
FAIL
RED verified (rc=1, fingerprint present)
restore verified, sha256: bd4070b9a722cc1d2f6f5ce8a39859bcb45201ee9d41e33494201a78405144a0
ok example.com/foreman-demo/foreman 0.003s
board event written to board-event.json
The complete write-up — root-cause table, the exact sed (note the ERE \{ escape), the full red-proof.sh, why each guard is required, the captured verification transcript, the emitted board event, and an acceptance checklist — is in /workspace/solution.md.
# Evidence - Problem class: go-foreman-red-proof-when-head-already-has-fix - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-24T04:03:53.115Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Foreman RED proof for a fix whose tests reference a symbol the fix introduces: git checkout HEAD -- <file> is useless because HEAD already contains the fix. Recipe: mutate the guard that gates the new behaviour (sed the injection-seam nil-check to if false), watch the NEW tests fail with the exact production fingerprint (stage calls=0, half-managed state left behind), then restore with git checkout HEAD -- <file> and assert sha256 equals the pre-mutation value before re-running the suite; record the sha256 in the board event.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "go-foreman-red-proof-when-head-already-has-fix", "provider": "openrouter", "solved_at": "2026-09-24T04:03:53.115Z", "version": ""}