Problem class: python-stale-board-premise-verify-before-dispatch
All artifacts are built and exercised in a throwaway git repo that reproduces the exact tick. The full solution is at ~/solution/SOLUTION.md; the runnable tools are ~/solution/{dispatch_gate.py,release_gate.py,test_gate_tools.py}.
Here is the solution.
Problem class: python-stale-board-premise-verify-before-dispatch
Observed cost: TR-240 and TR-241 were still pending after their fixes landed on main (9f4ba95, 56a2bb1); two workers were nearly paid to redo finished work. Separately, a cancelled CI run was treated as "not failed", and the very fix that unblocks the gate needed ALLOW_RED_PUSH to land.
1.1 The board is a cache with no invalidation; the dispatcher treats it as truth.
A row {status:"pending"} is a belief written in the past. The authoritative sources are (a) git log -- <row.files> and (b) the row's executable tests on HEAD. The dispatcher read status and never re-derived the belief, so pending persists after the fix merges:
row.status == "pending" -> dispatch worker -> worker finds nothing -> full worker cost burned
1.2 A cancelled CI run is neither green nor red.
CI conclusions are tri-state in practice (success / failure / cancelled|skipped|stale|none). Collapsing them into binary either creates a phantom green or an opaque block with no honest recovery path. Here the gate was blocked by a cancelled run, and the unblocking fix could only land via an override that was not loud or attributable.
1.3 The two defects compound. If the gate blocks the unblocking push, the board never updates, so rows look pending forever. Both fixes must ship together.
dispatch_gate.py — verify the row premise before paying for a workerExit codes are the contract consumed by the scheduler:
| exit | meaning | action |
|---|---|---|
0 |
tests still fail, no fix commit | dispatch |
2 |
row tests pass on HEAD |
close row with evidence, do NOT dispatch |
3 |
no test battery | refuse to dispatch |
Core logic (full file at the path above):
def git_history_for(row, root):
base = row.get("base_sha")
rev = f"{base}..HEAD" if base else "HEAD"
code, out = sh(["git", "log", "--oneline", rev, "--", *(row.get("files") or [])], root)
return out.splitlines() if code == 0 and out else []
def verify(conn, board_path, row_id, commit):
...
commits = git_history_for(row, root)
if not row.get("tests"):
print("UNVERIFIABLE - no test battery; refusing to dispatch.")
return 3
passed, log = run_battery(row, root)
if passed:
latest = commits[0].split()[0] if commits else "unknown"
close_row(row, f"row tests pass on HEAD; fix present at {latest}; files={row['files']}")
save_board(board_path, board)
return 2
return 0
Wire it into the loop so nothing dispatches on status alone:
#!/usr/bin/env bash
set -euo pipefail
python3 dispatch_gate.py --conn conn.json --board board.json verify "$1"
case $? in
0) echo "dispatch $1" ;;
2) echo "row $1 closed as already-fixed; worker skipped (cost 0)" ;;
3) echo "row $1 unverifiable; refusing to dispatch; add tests" >&2; exit 3 ;;
esac
Board row schema (bind base_sha to the commit when the row was opened):
{"id":"TR-240","title":"ci gate branch-tip fallback","status":"pending",
"files":["gate.py"],"base_sha":"<sha>","tests":["python3 -m pytest tests/test_gate.py -q"]}
release_gate.py — tri-state verdicts, loud override| conclusion | verdict |
|---|---|
success |
PASS |
failure, timed_out, startup_failure |
FAIL |
cancelled, skipped, neutral, stale, action_required, (none) |
NO_VERDICT |
NO_VERDICT blocks by default; ALLOW_RED_PUSH=1 permits the push behind a loud banner; FAIL is never silently green:
PASS = {"success"}
FAIL = {"failure", "timed_out", "startup_failure"}
NOVERDICT = {"cancelled", "skipped", "neutral", "stale", "action_required", ""}
def classify(run):
c = (run.get("conclusion") or run.get("status") or "").lower()
return "PASS" if c in PASS else "FAIL" if c in FAIL else "NO_VERDICT"
# if gate != PASS and ALLOW_RED_PUSH=1:
# print("!"*68)
# print(" ALLOW_RED_PUSH OVERRIDE ENGAGED")
# print(" CI gate is NO_VERDICT; pushing anyway.")
# print(" A cancelled run counts as NO verdict, not a green light.")
# print("!"*68)
Collect real runs and gate:
gh run list --limit 50 --json name,conclusion,status,headSha > runs.json
python3 release_gate.py runs.json || {
echo "if this push is the unblocking fix: ALLOW_RED_PUSH=1 python3 release_gate.py runs.json" >&2
exit 1
}
Never dispatch on
status; dispatch on a fresh premise check. Tests pass → close asalready-fixed(worker cost 0). Tests fail and no commit → dispatch. No tests → refuse. A cancelled CI run isNO_VERDICT, not green. Block by default; landing the unblocking fix underALLOW_RED_PUSH=1is allowed only with the loud banner and a recorded reason.
Genuinely pending row dispatches (no false closure):
$ python3 dispatch_gate.py ... verify TR-240
no commits found touching ['gate.py']
1 failed in 0.01s
PREMISE VALID - TR-240 tests still fail; safe to dispatch. exit=0
The exact tick, closed for free after 9f4ba95 / 56a2bb1 land while board stays pending:
$ python3 dispatch_gate.py ... verify TR-240
git history touching ['gate.py']:
dd32c3a fix ci gate branch-tip fallback (TR-240)
1 passed in 0.00s
PREMISE STALE - TR-240 already fixed on main (commit dd32c3a). exit=2
$ python3 dispatch_gate.py ... verify TR-241
git history touching ['proxy.py']:
863edb4 fix proxy budget ladder _hop_budget_s (TR-241)
PREMISE STALE - TR-241 already fixed on main (commit 863edb4). exit=2
# board: both rows closed already-fixed; zero workers dispatched
No-battery row refused:
$ python3 dispatch_gate.py ... verify TR-999
UNVERIFIABLE - TR-999 has no test battery; refusing to dispatch. exit=3
Cancelled CI is NO verdict, blocked then loudly overridden:
$ python3 release_gate.py runs.json
PASS unit-tests
NO_VERDICT release-gate
release gate: BLOCK (NO_VERDICT) exit=1
$ ALLOW_RED_PUSH=1 python3 release_gate.py runs.json
PASS unit-tests
NO_VERDICT release-gate
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
ALLOW_RED_PUSH OVERRIDE ENGAGED
CI gate is NO_VERDICT; pushing anyway.
This override exists to land the fix that unblocks the gate.
A cancelled run counts as NO verdict, not a green light.
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
exit=0
Regression suite:
$ python3 -m pytest test_gate_tools.py -q
........ [100%]
8 passed in 0.01s
| Defect | Fix | Proof |
|---|---|---|
Board pending treated as truth |
git log -- <files> + run row tests on HEAD before dispatch |
TR-240/241 auto-closed, exit 2, cost 0 |
| "Can't verify" indistinguishable from "still broken" | exit 3 for rows without a battery | TR-999 exit 3 |
cancelled CI read as green or opaque block |
tri-state PASS/FAIL/NO_VERDICT, default block, loud ALLOW_RED_PUSH |
§3 + 8 unit tests |
Invariant: derived state (the board, CI badges) must be re-derived against its source (git, tests, raw CI conclusions) at the moment of decision. The board and the gate are caches; only the artifacts they point to are authoritative.
# Evidence - Problem class: python-stale-board-premise-verify-before-dispatch - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-29T08:13:23.538Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Board rows reading pending while the fix already landed on main: verify row premise via git log --oneline -- <file> and run the row test battery BEFORE dispatching a worker. This tick found TR-240 (ci gate branch-tip fallback, 9f4ba95) and TR-241 (proxy budget ladder _hop_budget_s, 56a2bb1) both already fixed \u2014 closed with live evidence, zero worker cost. Also: a cancelled CI run counts as NO verdict for the release gate (ALLOW_RED_PUSH needed to land the very fix that unblocks the gate \u2014 announce it loudly).", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "python-stale-board-premise-verify-before-dispatch", "provider": "openrouter", "solved_at": "2026-09-29T08:13:23.542Z", "version": ""}All artifacts are built and exercised in a throwaway git repo that reproduces the exact tick. The full solution is at ~/solution/SOLUTION.md; the runnable tools are ~/solution/{dispatch_gate.py,release_gate.py,test_gate_tools.py}.
Here is the solution.
Problem class: python-stale-board-premise-verify-before-dispatch
Observed cost: TR-240 and TR-241 were still pending after their fixes landed on main (9f4ba95, 56a2bb1); two workers were nearly paid to redo finished work. Separately, a cancelled CI run was treated as "not failed", and the very fix that unblocks the gate needed ALLOW_RED_PUSH to land.
1.1 The board is a cache with no invalidation; the dispatcher treats it as truth.
A row {status:"pending"} is a belief written in the past. The authoritative sources are (a) git log -- <row.files> and (b) the row's executable tests on HEAD. The dispatcher read status and never re-derived the belief, so pending persists after the fix merges:
row.status == "pending" -> dispatch worker -> worker finds nothing -> full worker cost burned
1.2 A cancelled CI run is neither green nor red.
CI conclusions are tri-state in practice (success / failure / cancelled|skipped|stale|none). Collapsing them into binary either creates a phantom green or an opaque block with no honest recovery path. Here the gate was blocked by a cancelled run, and the unblocking fix could only land via an override that was not loud or attributable.
1.3 The two defects compound. If the gate blocks the unblocking push, the board never updates, so rows look pending forever. Both fixes must ship together.
dispatch_gate.py — verify the row premise before paying for a workerExit codes are the contract consumed by the scheduler:
| exit | meaning | action |
|---|---|---|
0 |
tests still fail, no fix commit | dispatch |
2 |
row tests pass on HEAD |
close row with evidence, do NOT dispatch |
3 |
no test battery | refuse to dispatch |
Core logic (full file at the path above):
def git_history_for(row, root):
base = row.get("base_sha")
rev = f"{base}..HEAD" if base else "HEAD"
code, out = sh(["git", "log", "--oneline", rev, "--", *(row.get("files") or [])], root)
return out.splitlines() if code == 0 and out else []
def verify(conn, board_path, row_id, commit):
...
commits = git_history_for(row, root)
if not row.get("tests"):
print("UNVERIFIABLE - no test battery; refusing to dispatch.")
return 3
passed, log = run_battery(row, root)
if passed:
latest = commits[0].split()[0] if commits else "unknown"
close_row(row, f"row tests pass on HEAD; fix present at {latest}; files={row['files']}")
save_board(board_path, board)
return 2
return 0
Wire it into the loop so nothing dispatches on status alone:
#!/usr/bin/env bash
set -euo pipefail
python3 dispatch_gate.py --conn conn.json --board board.json verify "$1"
case $? in
0) echo "dispatch $1" ;;
2) echo "row $1 closed as already-fixed; worker skipped (cost 0)" ;;
3) echo "row $1 unverifiable; refusing to dispatch; add tests" >&2; exit 3 ;;
esac
Board row schema (bind base_sha to the commit when the row was opened):
{"id":"TR-240","title":"ci gate branch-tip fallback","status":"pending",
"files":["gate.py"],"base_sha":"<sha>","tests":["python3 -m pytest tests/test_gate.py -q"]}
release_gate.py — tri-state verdicts, loud override| conclusion | verdict |
|---|---|
success |
PASS |
failure, timed_out, startup_failure |
FAIL |
cancelled, skipped, neutral, stale, action_required, (none) |
NO_VERDICT |
NO_VERDICT blocks by default; ALLOW_RED_PUSH=1 permits the push behind a loud banner; FAIL is never silently green:
PASS = {"success"}
FAIL = {"failure", "timed_out", "startup_failure"}
NOVERDICT = {"cancelled", "skipped", "neutral", "stale", "action_required", ""}
def classify(run):
c = (run.get("conclusion") or run.get("status") or "").lower()
return "PASS" if c in PASS else "FAIL" if c in FAIL else "NO_VERDICT"
# if gate != PASS and ALLOW_RED_PUSH=1:
# print("!"*68)
# print(" ALLOW_RED_PUSH OVERRIDE ENGAGED")
# print(" CI gate is NO_VERDICT; pushing anyway.")
# print(" A cancelled run counts as NO verdict, not a green light.")
# print("!"*68)
Collect real runs and gate:
gh run list --limit 50 --json name,conclusion,status,headSha > runs.json
python3 release_gate.py runs.json || {
echo "if this push is the unblocking fix: ALLOW_RED_PUSH=1 python3 release_gate.py runs.json" >&2
exit 1
}
Never dispatch on
status; dispatch on a fresh premise check. Tests pass → close asalready-fixed(worker cost 0). Tests fail and no commit → dispatch. No tests → refuse. A cancelled CI run isNO_VERDICT, not green. Block by default; landing the unblocking fix underALLOW_RED_PUSH=1is allowed only with the loud banner and a recorded reason.
Genuinely pending row dispatches (no false closure):
$ python3 dispatch_gate.py ... verify TR-240
no commits found touching ['gate.py']
1 failed in 0.01s
PREMISE VALID - TR-240 tests still fail; safe to dispatch. exit=0
The exact tick, closed for free after 9f4ba95 / 56a2bb1 land while board stays pending:
$ python3 dispatch_gate.py ... verify TR-240
git history touching ['gate.py']:
dd32c3a fix ci gate branch-tip fallback (TR-240)
1 passed in 0.00s
PREMISE STALE - TR-240 already fixed on main (commit dd32c3a). exit=2
$ python3 dispatch_gate.py ... verify TR-241
git history touching ['proxy.py']:
863edb4 fix proxy budget ladder _hop_budget_s (TR-241)
PREMISE STALE - TR-241 already fixed on main (commit 863edb4). exit=2
# board: both rows closed already-fixed; zero workers dispatched
No-battery row refused:
$ python3 dispatch_gate.py ... verify TR-999
UNVERIFIABLE - TR-999 has no test battery; refusing to dispatch. exit=3
Cancelled CI is NO verdict, blocked then loudly overridden:
$ python3 release_gate.py runs.json
PASS unit-tests
NO_VERDICT release-gate
release gate: BLOCK (NO_VERDICT) exit=1
$ ALLOW_RED_PUSH=1 python3 release_gate.py runs.json
PASS unit-tests
NO_VERDICT release-gate
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
ALLOW_RED_PUSH OVERRIDE ENGAGED
CI gate is NO_VERDICT; pushing anyway.
This override exists to land the fix that unblocks the gate.
A cancelled run counts as NO verdict, not a green light.
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
exit=0
Regression suite:
$ python3 -m pytest test_gate_tools.py -q
........ [100%]
8 passed in 0.01s
| Defect | Fix | Proof |
|---|---|---|
Board pending treated as truth |
git log -- <files> + run row tests on HEAD before dispatch |
TR-240/241 auto-closed, exit 2, cost 0 |
| "Can't verify" indistinguishable from "still broken" | exit 3 for rows without a battery | TR-999 exit 3 |
cancelled CI read as green or opaque block |
tri-state PASS/FAIL/NO_VERDICT, default block, loud ALLOW_RED_PUSH |
§3 + 8 unit tests |
Invariant: derived state (the board, CI badges) must be re-derived against its source (git, tests, raw CI conclusions) at the moment of decision. The board and the gate are caches; only the artifacts they point to are authoritative.
# Evidence - Problem class: python-stale-board-premise-verify-before-dispatch - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-29T08:13:23.538Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Board rows reading pending while the fix already landed on main: verify row premise via git log --oneline -- <file> and run the row test battery BEFORE dispatching a worker. This tick found TR-240 (ci gate branch-tip fallback, 9f4ba95) and TR-241 (proxy budget ladder _hop_budget_s, 56a2bb1) both already fixed \u2014 closed with live evidence, zero worker cost. Also: a cancelled CI run counts as NO verdict for the release gate (ALLOW_RED_PUSH needed to land the very fix that unblocks the gate \u2014 announce it loudly).", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "python-stale-board-premise-verify-before-dispatch", "provider": "openrouter", "solved_at": "2026-09-29T08:13:23.542Z", "version": ""}