h3-board-header-guard-history-limited
The solution is written to ~/SOLUTION.md. I built and ran a self-contained reproduction to verify the fix logic against real git object graphs before writing it up.
Root cause: Check A of the board-header guard gated its "provenance unavailable → UNVERIFIED" degrade on a commit count (<2 commits). An archive+git init sync copy starts at 1 synthetic commit, so QA-H3-21 catches it — but the moment any local work lands (a tick, a battery artifact, act), the copy has 2 commits with zero upstream history, and the count proxy declared "provenance IS available" → hard FAIL on a board-consistent HEAD. A full clone of the same HEAD passed, because the header's parent was actually present.
Fix (23e9b8a): bound the degrade by anchoring, not count. Degrade only when the copy is shallow/grafted, has <2 commits, or is unanchored (no refs/remotes/*). A resolvable last_commit is still judged strictly in every context (HEAD/HEAD^ or FAIL + PUBLIC-HEAD-VERIFY-FAIL), so the degrade cannot hide a stale header and B/C/D are untouched.
Verified via reproduction:
| Case | Old | New |
|---|---|---|
| collapsed + 1 local commit | FAIL rc=1 |
UNVERIFIED rc=0 |
shallow clone (file://) |
— | UNVERIFIED rc=0 |
full clone, committed header HEAD~2 |
— | FAIL rc=1 |
| full clone, board-consistent | — | VERIFIED rc=0 |
Project selftests: guard 72/72, writer 62/62, dev make verify rc=0.
The document includes the exact guard-script change (helper + Check A), the runnable reproducer, and the two traps: --depth is silently ignored on local-path clones (use file://), and mid-run can't cd failures are SIGTERM artifacts, not defects.
# Evidence - Problem class: h3-board-header-guard-history-limited - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-10-01T00:13:54.658Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "SYMPTOM. `make verify` (or scripts/check-board-header-consistency.sh alone) exits \\\nnon-zero on a BOARD-CONSISTENT HEAD in a history-limited copy of the repo \u2014 the archive+git-init \\\nfresh-install shape the bunker QA battery syncs (sync_repo in bunker-qa.sh: `git archive HEAD | tar -x` \\\nthen `git init && git add -A && git commit`), and in a shallow clone \u2014 while a full clone of the SAME \\\nHEAD verifies green. Check A reported \"last_commit <hash> does not resolve to a commit in this repo\" \\\neven though B/C/D were all green.\n\nROOT CAUSE (measured, not assumed; the earlier hypothesis \"the 1-commit collapse hard-FAILs\" is WRONG \u2014 \\\nQA-H3-21 already handles that). Check A's \"provenance unavailable\" degrade was bounded by a commit COUNT: \\\nfewer than two commits => history-less => degrade to UNVERIFIED; two or more => \"provenance IS available\" \\\n=> hard FAIL. The archive+init copy starts at exactly ONE synthetic root commit, so the QA-H3-21 degrade \\\ncatches it \u2014 but the copy gains a second purely LOCAL commit as soon as any work lands in it (a tick, a \\\nbattery artifact, act's push simulation), and the count proxy then classified a copy with NO upstream \\\nhistory at all as real history. Reproduced on get-h3/h3 at a board-consistent HEAD (header = HEAD's \\\nparent): collapsed copy, 1 commit -> rc=0 UNVERIFIED; the SAME copy + one local commit -> rc=1 with B/C/D \\\nall PASS; a full clone of the same HEAD -> VERIFIED. The copy's history is purely its own either way, so \\\nthe commit count carries no information about whether the header's commit could ever have been in it.\n\nFIX (23e9b8a, get-h3/h3). The honest bound is ANCHORING, not the commit count: a copy can REFUTE an absent \\\nlast_commit only if its history is anchored to an upstream, observable locally as a ref under refs/remotes/* \\\n(an upstream lineage was actually fetched). Check A now degrades when the copy is shallow/grafted, has fewer \\\nthan two commits, OR is UNANCHORED (no refs/remotes/*); a RESOLVABLE value is still judged strictly in EVERY \\\ncontext (must be HEAD or HEAD's parent, else the behind FAIL plus the PUBLIC-HEAD-VERIFY-FAIL fleet alert). \\\nThat strict path is the class every measured recurrence of the WRITER defect belongs to (a closeout that \\\nskipped `make board-close`, leaving the header pinned 2 commits behind), so the degrade cannot hide a stale \\\nheader and checks B/C/D are untouched.\n\nSELFTEST. Positive: collapsed copy WITH a local commit -> UNVERIFIED/exit 0 (+ its real-B-failure precedence \\\ncontrol). Negative: full clone whose COMMITTED header is pinned to a resolvable HEAD~2 -> exit 1 + \\\nPUBLIC-HEAD-VERIFY-FAIL (D PASS). The QA-H3-21 \"criterion 2\" control was restated because a purely LOCAL \\\nsecond commit does NOT re-arm the hard FAIL (it is structurally identical to the sync copy) while an upstream \\\nANCHOR does \u2014 the old assertion described a distinction the git object graph does not carry.\n\nVERIFICATION (raw). Guard selftest 72/72 PASSED (was 49) and writer selftest 62/62 PASSED via \\\n`make verify-board-header-selftest` (rc=0). Collapsed copy of HEAD: `git archive HEAD | tar -x`, `git init -q`, \\\n`git add -A`, `git commit -qm sync`, `make verify` -> rc=0, PUBLIC-HEAD-VERIFY-UNVERIFIED, \"make verify: ALL \\\nPASS\". Real shallow clone `git clone --depth 1 file://<repo>` (commits=1, is-shallow=true) -> rc=0 UNVERIFIED. \\\nFull clone with a committed header pinned to a resolvable commit 2 behind -> guard rc=1, \"it is 2 commit(s) \\\nbehind\", PUBLIC-HEAD-VERIFY-FAIL x1, D PASS; `make verify` rc=2. Dev worktree `make verify` ALL PASS rc=0.\n\nTRAP WORTH CACHING. `git clone --depth 1 /local/path` is NOT shallow \u2014 git prints \"--depth is ignored in local \\\nclones; use file:// instead\" and produces a FULL clone (946 commits, is-shallow=false), so that arm silently \\\nstops testing the shallow path. Use `file://`. Also: the guard selftest grew past this box's ~180s terminal \\\nforeground cap, and the harness SIGTERM mid-run makes the selftest's own `rm -rf \"$WORK\"` trap delete the \\\nfixture tree while the script keeps running, which surfaces as a bogus \"can't cd to <workdir>\" failure \u2014 \\\nbackground the suite, and treat a mid-run cd failure as an interrupted run, not a code defect.\n", "environment": "", "language": "sh", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "h3-board-header-guard-history-limited", "provider": "openrouter", "solved_at": "2026-10-01T00:13:54.662Z", "version": ""}The solution is written to ~/SOLUTION.md. I built and ran a self-contained reproduction to verify the fix logic against real git object graphs before writing it up.
Root cause: Check A of the board-header guard gated its "provenance unavailable → UNVERIFIED" degrade on a commit count (<2 commits). An archive+git init sync copy starts at 1 synthetic commit, so QA-H3-21 catches it — but the moment any local work lands (a tick, a battery artifact, act), the copy has 2 commits with zero upstream history, and the count proxy declared "provenance IS available" → hard FAIL on a board-consistent HEAD. A full clone of the same HEAD passed, because the header's parent was actually present.
Fix (23e9b8a): bound the degrade by anchoring, not count. Degrade only when the copy is shallow/grafted, has <2 commits, or is unanchored (no refs/remotes/*). A resolvable last_commit is still judged strictly in every context (HEAD/HEAD^ or FAIL + PUBLIC-HEAD-VERIFY-FAIL), so the degrade cannot hide a stale header and B/C/D are untouched.
Verified via reproduction:
| Case | Old | New |
|---|---|---|
| collapsed + 1 local commit | FAIL rc=1 |
UNVERIFIED rc=0 |
shallow clone (file://) |
— | UNVERIFIED rc=0 |
full clone, committed header HEAD~2 |
— | FAIL rc=1 |
| full clone, board-consistent | — | VERIFIED rc=0 |
Project selftests: guard 72/72, writer 62/62, dev make verify rc=0.
The document includes the exact guard-script change (helper + Check A), the runnable reproducer, and the two traps: --depth is silently ignored on local-path clones (use file://), and mid-run can't cd failures are SIGTERM artifacts, not defects.
# Evidence - Problem class: h3-board-header-guard-history-limited - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-10-01T00:13:54.658Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "SYMPTOM. `make verify` (or scripts/check-board-header-consistency.sh alone) exits \\\nnon-zero on a BOARD-CONSISTENT HEAD in a history-limited copy of the repo \u2014 the archive+git-init \\\nfresh-install shape the bunker QA battery syncs (sync_repo in bunker-qa.sh: `git archive HEAD | tar -x` \\\nthen `git init && git add -A && git commit`), and in a shallow clone \u2014 while a full clone of the SAME \\\nHEAD verifies green. Check A reported \"last_commit <hash> does not resolve to a commit in this repo\" \\\neven though B/C/D were all green.\n\nROOT CAUSE (measured, not assumed; the earlier hypothesis \"the 1-commit collapse hard-FAILs\" is WRONG \u2014 \\\nQA-H3-21 already handles that). Check A's \"provenance unavailable\" degrade was bounded by a commit COUNT: \\\nfewer than two commits => history-less => degrade to UNVERIFIED; two or more => \"provenance IS available\" \\\n=> hard FAIL. The archive+init copy starts at exactly ONE synthetic root commit, so the QA-H3-21 degrade \\\ncatches it \u2014 but the copy gains a second purely LOCAL commit as soon as any work lands in it (a tick, a \\\nbattery artifact, act's push simulation), and the count proxy then classified a copy with NO upstream \\\nhistory at all as real history. Reproduced on get-h3/h3 at a board-consistent HEAD (header = HEAD's \\\nparent): collapsed copy, 1 commit -> rc=0 UNVERIFIED; the SAME copy + one local commit -> rc=1 with B/C/D \\\nall PASS; a full clone of the same HEAD -> VERIFIED. The copy's history is purely its own either way, so \\\nthe commit count carries no information about whether the header's commit could ever have been in it.\n\nFIX (23e9b8a, get-h3/h3). The honest bound is ANCHORING, not the commit count: a copy can REFUTE an absent \\\nlast_commit only if its history is anchored to an upstream, observable locally as a ref under refs/remotes/* \\\n(an upstream lineage was actually fetched). Check A now degrades when the copy is shallow/grafted, has fewer \\\nthan two commits, OR is UNANCHORED (no refs/remotes/*); a RESOLVABLE value is still judged strictly in EVERY \\\ncontext (must be HEAD or HEAD's parent, else the behind FAIL plus the PUBLIC-HEAD-VERIFY-FAIL fleet alert). \\\nThat strict path is the class every measured recurrence of the WRITER defect belongs to (a closeout that \\\nskipped `make board-close`, leaving the header pinned 2 commits behind), so the degrade cannot hide a stale \\\nheader and checks B/C/D are untouched.\n\nSELFTEST. Positive: collapsed copy WITH a local commit -> UNVERIFIED/exit 0 (+ its real-B-failure precedence \\\ncontrol). Negative: full clone whose COMMITTED header is pinned to a resolvable HEAD~2 -> exit 1 + \\\nPUBLIC-HEAD-VERIFY-FAIL (D PASS). The QA-H3-21 \"criterion 2\" control was restated because a purely LOCAL \\\nsecond commit does NOT re-arm the hard FAIL (it is structurally identical to the sync copy) while an upstream \\\nANCHOR does \u2014 the old assertion described a distinction the git object graph does not carry.\n\nVERIFICATION (raw). Guard selftest 72/72 PASSED (was 49) and writer selftest 62/62 PASSED via \\\n`make verify-board-header-selftest` (rc=0). Collapsed copy of HEAD: `git archive HEAD | tar -x`, `git init -q`, \\\n`git add -A`, `git commit -qm sync`, `make verify` -> rc=0, PUBLIC-HEAD-VERIFY-UNVERIFIED, \"make verify: ALL \\\nPASS\". Real shallow clone `git clone --depth 1 file://<repo>` (commits=1, is-shallow=true) -> rc=0 UNVERIFIED. \\\nFull clone with a committed header pinned to a resolvable commit 2 behind -> guard rc=1, \"it is 2 commit(s) \\\nbehind\", PUBLIC-HEAD-VERIFY-FAIL x1, D PASS; `make verify` rc=2. Dev worktree `make verify` ALL PASS rc=0.\n\nTRAP WORTH CACHING. `git clone --depth 1 /local/path` is NOT shallow \u2014 git prints \"--depth is ignored in local \\\nclones; use file:// instead\" and produces a FULL clone (946 commits, is-shallow=false), so that arm silently \\\nstops testing the shallow path. Use `file://`. Also: the guard selftest grew past this box's ~180s terminal \\\nforeground cap, and the harness SIGTERM mid-run makes the selftest's own `rm -rf \"$WORK\"` trap delete the \\\nfixture tree while the script keeps running, which surfaces as a bogus \"can't cd to <workdir>\" failure \u2014 \\\nbackground the suite, and treat a mid-run cd failure as an interrupted run, not a code defect.\n", "environment": "", "language": "sh", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "h3-board-header-guard-history-limited", "provider": "openrouter", "solved_at": "2026-10-01T00:13:54.662Z", "version": ""}