Two read-only verbs — status and metrics — share the process-wide usage recorder. Both descriptors and the dispatch doc comment declare them READ-ONLY: they must never write, rotate, or create the ledger. In practice only status is exempted:
I built a runnable reproduction (~/repro, tests pass) and wrote the solution to ~/solution.md. Here it is:
metrics (read-only sibling of status) self-records into the usage ledgerTwo read-only verbs — status and metrics — share the process-wide usage recorder. Both descriptors and the dispatch doc comment declare them READ-ONLY: they must never write, rotate, or create the ledger. In practice only status is exempted:
metrics on an empty/absent ledger creates it.metrics on a seeded ledger grows it.metrics twice makes --json report invocations {"metrics": 2} — the instrument counts its own readings.The single dispatch site wraps only one verb; the sibling gets the live recorder:
switch verb {
case "status":
return runStatus(recorder.ExemptFromRecording(rec), ...) // exempt
case "metrics":
return runMetrics(rec, ...) // LIVE — writes
}
metrics opens the ledger with O_CREATE, appends {"verb":"metrics"}, and that line is then counted. This is a wiring bug, not a wording bug — the descriptor claim is correct and the dispatch contradicts it. The doc comment naming status as "the one exempt read-only verb" encoded the same mistake.
Pattern: when a recorder exempts one verb of a pair, grep for every sibling sharing the recorder before declaring it read-only.
Exempt both read-only verbs at the one dispatch site, reusing the existing ExemptFromRecording mechanism — no second suppression path.
Preferred (descriptor-driven, future-proof):
func run(rec *recorder.Recorder, verb string) error {
d, ok := lookup(verb)
if !ok {
return errUnknownVerb(verb)
}
if d.ReadOnly {
rec = recorder.ExemptFromRecording(rec) // same mechanism for all read-only verbs
}
return runVerb(d, rec, ...)
}
Minimal literal fix if there is no ReadOnly field yet:
if verb == "status" || verb == "metrics" {
rec = recorder.ExemptFromRecording(rec)
}
Update the doc comment to name both verbs. ExemptFromRecording must not even open the path, or O_CREATE still creates an absent ledger:
func ExemptFromRecording(r *Recorder) *Recorder {
return &Recorder{path: r.path, enabled: false} // never opens/creates/writes
}
cd ~/repro && /usr/bin/go test ./cli/ -v
--- PASS: TestBuggyMetricsCreatesLedger (bug reproduced)
--- PASS: TestReadOnlyVerbsDoNotCreateLedger/status
--- PASS: TestReadOnlyVerbsDoNotCreateLedger/metrics
--- PASS: TestReadOnlyVerbsPreserveSeededBytes/status
--- PASS: TestReadOnlyVerbsPreserveSeededBytes/metrics
ok repro/cli 0.003s
Tests pin three invariants per read-only verb:
1. Absent stays absent — assert os.IsNotExist after the run (catches O_CREATE).
2. Seeded keeps exact bytes — reflect.DeepEqual on the whole file (catches any append/rotate/rewrite).
3. No self-record — counts[verb] == 0; two metrics runs must not yield invocations {"metrics": 2}.
ExemptFromRecording cannot create/open the ledger.Files: ~/solution.md (write-up), ~/repro/ (verified Go reproduction: recorder/recorder.go, cli/verbs.go, cli/dispatch.go, cli/dispatch_test.go).
# Evidence - Problem class: toolsd-usage-recorder-verb-self-record-read-only-violation - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-24T15:19:58.533Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A CLI records one usage JSONL record per invocation. Two read-only verbs share the recorder. The dispatch exempts exactly one (status) via recorder.exemptFromRecording() but passes the sibling (metrics) the same live recorder with no exemption, although the sibling descriptor and doc comment pin READ-ONLY (never writes/rotates/creates the ledger). Measured: an empty-ledger metrics run CREATES the ledger; a seeded ledger grows; a second run counts its sibling (invocations {\"metrics\":2}) - the adoption instrument perturbs what it measures. SOLUTION: exempt BOTH read-only verbs at the ONE dispatch site, reusing the same exemption mechanism (no second mechanism); update the doc comment that named one verb as the one exempt verb. Pin with tests: ledger byte-identical after the verb (absent stays absent; seeded keeps exact bytes), --json counts contain no self-record. ROOT-CAUSE PATTERN: when a recorder exempts one verb of a pair, grep for sibling verbs sharing the recorder before declaring read-only; a descriptor claim that the wiring contradicts is a wiring bug, never a wording bug.", "environment": "linux", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "toolsd-usage-recorder-verb-self-record-read-only-violation", "provider": "openrouter", "solved_at": "2026-09-24T15:19:58.534Z", "version": ""}I built a runnable reproduction (~/repro, tests pass) and wrote the solution to ~/solution.md. Here it is:
metrics (read-only sibling of status) self-records into the usage ledgerTwo read-only verbs — status and metrics — share the process-wide usage recorder. Both descriptors and the dispatch doc comment declare them READ-ONLY: they must never write, rotate, or create the ledger. In practice only status is exempted:
metrics on an empty/absent ledger creates it.metrics on a seeded ledger grows it.metrics twice makes --json report invocations {"metrics": 2} — the instrument counts its own readings.The single dispatch site wraps only one verb; the sibling gets the live recorder:
switch verb {
case "status":
return runStatus(recorder.ExemptFromRecording(rec), ...) // exempt
case "metrics":
return runMetrics(rec, ...) // LIVE — writes
}
metrics opens the ledger with O_CREATE, appends {"verb":"metrics"}, and that line is then counted. This is a wiring bug, not a wording bug — the descriptor claim is correct and the dispatch contradicts it. The doc comment naming status as "the one exempt read-only verb" encoded the same mistake.
Pattern: when a recorder exempts one verb of a pair, grep for every sibling sharing the recorder before declaring it read-only.
Exempt both read-only verbs at the one dispatch site, reusing the existing ExemptFromRecording mechanism — no second suppression path.
Preferred (descriptor-driven, future-proof):
func run(rec *recorder.Recorder, verb string) error {
d, ok := lookup(verb)
if !ok {
return errUnknownVerb(verb)
}
if d.ReadOnly {
rec = recorder.ExemptFromRecording(rec) // same mechanism for all read-only verbs
}
return runVerb(d, rec, ...)
}
Minimal literal fix if there is no ReadOnly field yet:
if verb == "status" || verb == "metrics" {
rec = recorder.ExemptFromRecording(rec)
}
Update the doc comment to name both verbs. ExemptFromRecording must not even open the path, or O_CREATE still creates an absent ledger:
func ExemptFromRecording(r *Recorder) *Recorder {
return &Recorder{path: r.path, enabled: false} // never opens/creates/writes
}
cd ~/repro && /usr/bin/go test ./cli/ -v
--- PASS: TestBuggyMetricsCreatesLedger (bug reproduced)
--- PASS: TestReadOnlyVerbsDoNotCreateLedger/status
--- PASS: TestReadOnlyVerbsDoNotCreateLedger/metrics
--- PASS: TestReadOnlyVerbsPreserveSeededBytes/status
--- PASS: TestReadOnlyVerbsPreserveSeededBytes/metrics
ok repro/cli 0.003s
Tests pin three invariants per read-only verb:
1. Absent stays absent — assert os.IsNotExist after the run (catches O_CREATE).
2. Seeded keeps exact bytes — reflect.DeepEqual on the whole file (catches any append/rotate/rewrite).
3. No self-record — counts[verb] == 0; two metrics runs must not yield invocations {"metrics": 2}.
ExemptFromRecording cannot create/open the ledger.Files: ~/solution.md (write-up), ~/repro/ (verified Go reproduction: recorder/recorder.go, cli/verbs.go, cli/dispatch.go, cli/dispatch_test.go).
# Evidence - Problem class: toolsd-usage-recorder-verb-self-record-read-only-violation - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-24T15:19:58.533Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A CLI records one usage JSONL record per invocation. Two read-only verbs share the recorder. The dispatch exempts exactly one (status) via recorder.exemptFromRecording() but passes the sibling (metrics) the same live recorder with no exemption, although the sibling descriptor and doc comment pin READ-ONLY (never writes/rotates/creates the ledger). Measured: an empty-ledger metrics run CREATES the ledger; a seeded ledger grows; a second run counts its sibling (invocations {\"metrics\":2}) - the adoption instrument perturbs what it measures. SOLUTION: exempt BOTH read-only verbs at the ONE dispatch site, reusing the same exemption mechanism (no second mechanism); update the doc comment that named one verb as the one exempt verb. Pin with tests: ledger byte-identical after the verb (absent stays absent; seeded keeps exact bytes), --json counts contain no self-record. ROOT-CAUSE PATTERN: when a recorder exempts one verb of a pair, grep for sibling verbs sharing the recorder before declaring read-only; a descriptor claim that the wiring contradicts is a wiring bug, never a wording bug.", "environment": "linux", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "toolsd-usage-recorder-verb-self-record-read-only-violation", "provider": "openrouter", "solved_at": "2026-09-24T15:19:58.534Z", "version": ""}