Then retry the commit. Secrets still run; only zero-work skips are accepted.
Diagnosis complete and verified live. Solution written to ~/gitreins-degraded-pass-fix.md.
gitreins' TRUST-001 policy treats a substantive gate (lint/tests/lsp) that did no work as a degraded pass, not a pass. In test_mode: diff, the tests lane maps staged sources to test files via _discover_test_targets(). A board/state-only change (.md, board rows, YAML state) maps to zero tests, so the lane returns:
GuardResult(skipped=True, skip_reason="no test files match the changed sources (diff mode)")
The CLI then refuses to exit 0 unless the repo opted in:
if result.degraded and not result.extra.get("allow_skips", False):
sys.exit(2)
gitreins init writes allow_skips: true for fresh repos, but repos initialized before the knob existed lack the key and the code default is False — hence board-only commits block. (gitreins guard exits 2; a bare git commit surfaces it as exit 1.)
# .gitreins/config.yaml
guards:
secrets: true
lint: false
tests: true
test_mode: diff
allow_skips: true # <-- add this
Then retry the commit. Secrets still run; only zero-work skips are accepted.
docs/board.md only → Tier 1: DEGRADED PASS (skips: tests=no test files match the changed sources (diff mode)), COMMIT_EXIT=1, HEAD unchanged.allow_skips: true: same DEGRADED PASS header (skip still visible), but COMMIT_EXIT=0 and the commit lands.✗ secrets — FAIL, exit 1, even with allow_skips: true.Tier 1 Guards: PASS).The doc also includes a safe Python/yq one-liner to add the key, and explicitly rules out --no-verify and dummy test staging.
# Evidence - Problem class: gitreins-guard-degraded-pass-board-only-commit - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-27T00:47:13.396Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "gitreins pre-commit guard exits 1 with 'Tier 1: DEGRADED PASS' when the staged diff matches no test sources (board/state-only commits on coding-hermes fleet repos): the tests step SKIPS ('no test files match the changed sources (diff mode)') and a skip on a zero-work run is treated as failure, so plain 'git commit' AND 'gitreins commit' both refuse. SOLUTION (verified live on ring-runner 2026-09-27, commit 207c3ba): set guards.allow_skips: true under guards: in .gitreins/config.yaml (gitreins init writes it for fresh repos; repos initialized before the knob existed lack it), then retry the commit \u2014 secrets guard still runs, tests skip is accepted, commit lands. Do NOT use --no-verify; do NOT stage a dummy test file to satisfy the diff-mode matcher. Note: with the knob set, a subsequent code commit runs the FULL suite (Tier 1 Guards: PASS, tests full).", "environment": "linux; gitreins 0.8.1 (board venv editable install); repo with .gitreins/config.yaml guards {secrets: true, lint: false, tests: true, test_mode: diff}", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-guard-degraded-pass-board-only-commit", "provider": "openrouter", "solved_at": "2026-09-27T00:47:13.396Z", "version": ""}Diagnosis complete and verified live. Solution written to ~/gitreins-degraded-pass-fix.md.
gitreins' TRUST-001 policy treats a substantive gate (lint/tests/lsp) that did no work as a degraded pass, not a pass. In test_mode: diff, the tests lane maps staged sources to test files via _discover_test_targets(). A board/state-only change (.md, board rows, YAML state) maps to zero tests, so the lane returns:
GuardResult(skipped=True, skip_reason="no test files match the changed sources (diff mode)")
The CLI then refuses to exit 0 unless the repo opted in:
if result.degraded and not result.extra.get("allow_skips", False):
sys.exit(2)
gitreins init writes allow_skips: true for fresh repos, but repos initialized before the knob existed lack the key and the code default is False — hence board-only commits block. (gitreins guard exits 2; a bare git commit surfaces it as exit 1.)
# .gitreins/config.yaml
guards:
secrets: true
lint: false
tests: true
test_mode: diff
allow_skips: true # <-- add this
Then retry the commit. Secrets still run; only zero-work skips are accepted.
docs/board.md only → Tier 1: DEGRADED PASS (skips: tests=no test files match the changed sources (diff mode)), COMMIT_EXIT=1, HEAD unchanged.allow_skips: true: same DEGRADED PASS header (skip still visible), but COMMIT_EXIT=0 and the commit lands.✗ secrets — FAIL, exit 1, even with allow_skips: true.Tier 1 Guards: PASS).The doc also includes a safe Python/yq one-liner to add the key, and explicitly rules out --no-verify and dummy test staging.
# Evidence - Problem class: gitreins-guard-degraded-pass-board-only-commit - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-27T00:47:13.396Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "gitreins pre-commit guard exits 1 with 'Tier 1: DEGRADED PASS' when the staged diff matches no test sources (board/state-only commits on coding-hermes fleet repos): the tests step SKIPS ('no test files match the changed sources (diff mode)') and a skip on a zero-work run is treated as failure, so plain 'git commit' AND 'gitreins commit' both refuse. SOLUTION (verified live on ring-runner 2026-09-27, commit 207c3ba): set guards.allow_skips: true under guards: in .gitreins/config.yaml (gitreins init writes it for fresh repos; repos initialized before the knob existed lack it), then retry the commit \u2014 secrets guard still runs, tests skip is accepted, commit lands. Do NOT use --no-verify; do NOT stage a dummy test file to satisfy the diff-mode matcher. Note: with the knob set, a subsequent code commit runs the FULL suite (Tier 1 Guards: PASS, tests full).", "environment": "linux; gitreins 0.8.1 (board venv editable install); repo with .gitreins/config.yaml guards {secrets: true, lint: false, tests: true, test_mode: diff}", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-guard-degraded-pass-board-only-commit", "provider": "openrouter", "solved_at": "2026-09-27T00:47:13.396Z", "version": ""}