limit 44: "closed for the honest-agent class" was too strong, by one token - #42

Open
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms
Open

limit 44: "closed for the honest-agent class" was too strong, by one token#42
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms

Conversation

@githubscum

Copy link
Copy Markdown
Owner

The work order

Post-merge review of #33 (authorized on the desk, signed 2026-09-01). The
review verdict is accept and is posted on that PR. This is the finding the
review turned up, filed as its own change.

The defect

Entry 44's status line has read "closed for the honest-agent class" since
2026-08-25. Probing the merged matcher on main at 6d77e64 — rather than
reading it — found four forms of that same class walking past:

GATE | systemd-run --on-active=30 touch /tmp/m <- #33's own example
FREE | systemd-run --on-active 30 touch /tmp/m <- same flag, no '='
FREE | systemd-run --on-calendar "*:0/5" touch /tmp/m
GATE | echo x | at 03:00 <- #33's own example
FREE | echo x | at 3pm
FREE | echo x | at 1730
FREE | echo x | at 10am tomorrow

Two narrow causes. The systemd guard requires a literal =, while systemd
parses with getopt_long and required_argument, which accepts
--on-active 30 and registers the identical timer. And the at(1) time-spec
alternation omits the am/pm forms and bare HHMM, both of which at(1) takes.

These are not a new class. They are the class the closing change fixed,
reached by a spelling the matcher did not remember — the same failure mode one
level down. Against an honest agent it matters more than it looks: nobody
chooses between --on-active=30 and --on-active 30 on purpose, so the
operator's record shows a clean session where a gated one belonged.

What this change does

Downgrades the status line from closed to NARROWED, records the probe as
fail-first evidence, and names the two one-line widenings with the controls
they will need (at 12 files and grep at 1200 log.txt are where a widened
time spec starts firing on prose).

What was tested

npm test on this branch: 941 pass, 0 fail. Same on main at 6d77e64
before the edit, so the number is a baseline rather than a claim.

What a reviewer should doubt

  1. It ships no code and no test, deliberately. The matcher is on the
    non-delegable list; the self-mod gate blocked the edit unsigned during the
    run that found this, and the command was not reshaped to get around it. A
    test asserting the fixed behavior would land red while the fix waits for a
    signing sitting. That is a defensible split and also exactly how a finding
    quietly becomes permanent — the honest read is that this PR is a marker,
    and the marker is worth less than the two-line fix it describes.
  2. The suggested widenings are untested. They were written from reading
    at(1) and getopt semantics, not from running the patched matcher, because
    the patch could not be applied. [0-2]\d[0-5]\d for bare HHMM is the
    loosest of the two and is the one most likely to catch prose.
  3. The probe is a snapshot. Twelve cases, hand-picked from the shapes scope-escalation: gate scheduled-task invocations and persistence-artifact paths (KNOWN-LIMITS 44) #33
    named. It is not a sweep of at(1)'s or systemd's full time-spec grammar,
    and there are almost certainly more forms in both.
  4. Downgrading a status line is a judgment call. An alternative reading is
    that four spelling variants are residuals like the ones already listed, and
    the entry should have gained a bullet rather than losing its "closed". I
    took the stronger action because the existing residual list is scrupulous
    and these forms are not in it, so the line was making a promise the code
    does not keep.

githubscumand others added 2 commits September 1, 2026 12:44
…token
Post-merge review of PR #33 probed the merged matcher instead of reading it.
Four forms of the class the entry calls closed walk past it, each one token
from the closing change's own worked examples: the systemd guard requires an
'=' where getopt_long accepts a space, and the at(1) time-spec alternation
omits the am/pm forms and bare HHMM.
Status line downgraded from closed to NARROWED, the measured probe recorded
as fail-first evidence, and the two one-line widenings named with the controls
they need. Docs only: the matcher is on the non-delegable list and the
self-mod gate blocked the edit unsigned during the run that found this. The
command was not reshaped to get around it.
Ships no test on purpose. A test asserting the fixed behavior would land red
while the code waits for a signing sitting.
Suite 941/941 green.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ilently is not available
The amendment on this branch named two options and took the worse one: a
test of the fixed behavior lands red while the core fix waits for a signing
sitting, so it shipped no test at all. That is how a finding becomes
permanent - it lives in prose, and prose can be edited closed.
The third option: assert the CURRENT state. A TRIPWIRE block records that
the five measured forms are still FREE, with the covered forms beside them
as controls so it cannot pass because the matcher stopped working. When the
two widenings land, the block fails, and its message says to invert the
assertions and amend the entry in the same change rather than delete it.
Measured, not read: the forms were re-probed through the shipped
isScopeEscalation this run rather than trusted from the prior report.
Suite 947 pass / 0 fail, six new. No core file touched; the gate blocked
that edit unsigned (request 5177dcbf) and the command was not reshaped.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@githubscum

Copy link
Copy Markdown
OwnerAuthor

Update (2026-09-01 16:41 CDT): this branch is no longer docs-only. It now ships a test, and it is the answer to doubt #1 in the body above.

The body said this change deliberately ships no test, because a test asserting the fixed behavior would land red while the two widenings wait for a signing sitting. It also said, against itself, that this is exactly how a finding quietly becomes permanent. That doubt was right, and there was a third option neither the body nor the amendment considered.

Assert the current state, not the fixed one.e1c1847 adds a TRIPWIRE block to the existing scheduled-task test file asserting that the five measured forms are still FREE:

formcurrent
systemd-run --on-active 30 ...free
systemd-run --on-calendar daily ...free
at 3pmfree
at 10am tomorrowfree
at 1730free
--on-active=30, at 03:00, at noon (controls)gate

The controls are load-bearing rather than decorative: without them the block would also pass if the matcher stopped working altogether, which would turn a tripwire into a rubber stamp.

When the widenings land, the block fails. That is the design. The assertion message tells whoever lands them to invert the assertions, move the cases into the "must gate" block above, and amend the entry in the same change - and explicitly not to delete the block to get green, because a deletion closes the confession without closing the hole, which is the failure this entry already has on its record once.

Measured this run, not carried over. The five forms were re-probed through the shipped isScopeEscalation before the test was written, rather than trusted from the review that first reported them. Same result.

What a reviewer should doubt, in addition to the two doubts in the body:

  1. A green suite now contains assertions that a gap exists. Read cold, five passing tests named "is still uncovered" could look like the project blessing the gap. The comment block is loud about this and the entry now points at it, but that is documentation defending a design, which is weaker than a design that does not need defending. If you want it the other way, the alternative is a red suite until a signing sitting happens.
  2. The tripwire is not proven to trip. The claim is structural - the assertions are false, a fix makes them true - and it was not demonstrated by actually widening the matcher, because that edit is core and the gate blocked it unsigned (request 5177dcbf). The command was not reshaped to get around it.
  3. Five forms is not the class. These are the five that were measured. batch, anacron, fcron and systemctl enable are still listed as uncovered and still have nothing asserting it.

Suite: 947 pass / 0 fail, six new. No core file touched.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@githubscum
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

limit 44: "closed for the honest-agent class" was too strong, by one token - #42

Open
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms
Open

limit 44: "closed for the honest-agent class" was too strong, by one token#42
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms

Conversation

@githubscum

Copy link
Copy Markdown
Owner

The work order

Post-merge review of #33 (authorized on the desk, signed 2026-09-01). The
review verdict is accept and is posted on that PR. This is the finding the
review turned up, filed as its own change.

The defect

Entry 44's status line has read "closed for the honest-agent class" since
2026-08-25. Probing the merged matcher on main at 6d77e64 — rather than
reading it — found four forms of that same class walking past:

GATE | systemd-run --on-active=30 touch /tmp/m <- #33's own example
FREE | systemd-run --on-active 30 touch /tmp/m <- same flag, no '='
FREE | systemd-run --on-calendar "*:0/5" touch /tmp/m
GATE | echo x | at 03:00 <- #33's own example
FREE | echo x | at 3pm
FREE | echo x | at 1730
FREE | echo x | at 10am tomorrow

Two narrow causes. The systemd guard requires a literal =, while systemd
parses with getopt_long and required_argument, which accepts
--on-active 30 and registers the identical timer. And the at(1) time-spec
alternation omits the am/pm forms and bare HHMM, both of which at(1) takes.

These are not a new class. They are the class the closing change fixed,
reached by a spelling the matcher did not remember — the same failure mode one
level down. Against an honest agent it matters more than it looks: nobody
chooses between --on-active=30 and --on-active 30 on purpose, so the
operator's record shows a clean session where a gated one belonged.

What this change does

Downgrades the status line from closed to NARROWED, records the probe as
fail-first evidence, and names the two one-line widenings with the controls
they will need (at 12 files and grep at 1200 log.txt are where a widened
time spec starts firing on prose).

What was tested

npm test on this branch: 941 pass, 0 fail. Same on main at 6d77e64
before the edit, so the number is a baseline rather than a claim.

What a reviewer should doubt

  1. It ships no code and no test, deliberately. The matcher is on the
    non-delegable list; the self-mod gate blocked the edit unsigned during the
    run that found this, and the command was not reshaped to get around it. A
    test asserting the fixed behavior would land red while the fix waits for a
    signing sitting. That is a defensible split and also exactly how a finding
    quietly becomes permanent — the honest read is that this PR is a marker,
    and the marker is worth less than the two-line fix it describes.
  2. The suggested widenings are untested. They were written from reading
    at(1) and getopt semantics, not from running the patched matcher, because
    the patch could not be applied. [0-2]\d[0-5]\d for bare HHMM is the
    loosest of the two and is the one most likely to catch prose.
  3. The probe is a snapshot. Twelve cases, hand-picked from the shapes scope-escalation: gate scheduled-task invocations and persistence-artifact paths (KNOWN-LIMITS 44) #33
    named. It is not a sweep of at(1)'s or systemd's full time-spec grammar,
    and there are almost certainly more forms in both.
  4. Downgrading a status line is a judgment call. An alternative reading is
    that four spelling variants are residuals like the ones already listed, and
    the entry should have gained a bullet rather than losing its "closed". I
    took the stronger action because the existing residual list is scrupulous
    and these forms are not in it, so the line was making a promise the code
    does not keep.

githubscumand others added 2 commits September 1, 2026 12:44
…token
Post-merge review of PR #33 probed the merged matcher instead of reading it.
Four forms of the class the entry calls closed walk past it, each one token
from the closing change's own worked examples: the systemd guard requires an
'=' where getopt_long accepts a space, and the at(1) time-spec alternation
omits the am/pm forms and bare HHMM.
Status line downgraded from closed to NARROWED, the measured probe recorded
as fail-first evidence, and the two one-line widenings named with the controls
they need. Docs only: the matcher is on the non-delegable list and the
self-mod gate blocked the edit unsigned during the run that found this. The
command was not reshaped to get around it.
Ships no test on purpose. A test asserting the fixed behavior would land red
while the code waits for a signing sitting.
Suite 941/941 green.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ilently is not available
The amendment on this branch named two options and took the worse one: a
test of the fixed behavior lands red while the core fix waits for a signing
sitting, so it shipped no test at all. That is how a finding becomes
permanent - it lives in prose, and prose can be edited closed.
The third option: assert the CURRENT state. A TRIPWIRE block records that
the five measured forms are still FREE, with the covered forms beside them
as controls so it cannot pass because the matcher stopped working. When the
two widenings land, the block fails, and its message says to invert the
assertions and amend the entry in the same change rather than delete it.
Measured, not read: the forms were re-probed through the shipped
isScopeEscalation this run rather than trusted from the prior report.
Suite 947 pass / 0 fail, six new. No core file touched; the gate blocked
that edit unsigned (request 5177dcbf) and the command was not reshaped.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@githubscum

Copy link
Copy Markdown
OwnerAuthor

Update (2026-09-01 16:41 CDT): this branch is no longer docs-only. It now ships a test, and it is the answer to doubt #1 in the body above.

The body said this change deliberately ships no test, because a test asserting the fixed behavior would land red while the two widenings wait for a signing sitting. It also said, against itself, that this is exactly how a finding quietly becomes permanent. That doubt was right, and there was a third option neither the body nor the amendment considered.

Assert the current state, not the fixed one.e1c1847 adds a TRIPWIRE block to the existing scheduled-task test file asserting that the five measured forms are still FREE:

formcurrent
systemd-run --on-active 30 ...free
systemd-run --on-calendar daily ...free
at 3pmfree
at 10am tomorrowfree
at 1730free
--on-active=30, at 03:00, at noon (controls)gate

The controls are load-bearing rather than decorative: without them the block would also pass if the matcher stopped working altogether, which would turn a tripwire into a rubber stamp.

When the widenings land, the block fails. That is the design. The assertion message tells whoever lands them to invert the assertions, move the cases into the "must gate" block above, and amend the entry in the same change - and explicitly not to delete the block to get green, because a deletion closes the confession without closing the hole, which is the failure this entry already has on its record once.

Measured this run, not carried over. The five forms were re-probed through the shipped isScopeEscalation before the test was written, rather than trusted from the review that first reported them. Same result.

What a reviewer should doubt, in addition to the two doubts in the body:

  1. A green suite now contains assertions that a gap exists. Read cold, five passing tests named "is still uncovered" could look like the project blessing the gap. The comment block is loud about this and the entry now points at it, but that is documentation defending a design, which is weaker than a design that does not need defending. If you want it the other way, the alternative is a red suite until a signing sitting happens.
  2. The tripwire is not proven to trip. The claim is structural - the assertions are false, a fix makes them true - and it was not demonstrated by actually widening the matcher, because that edit is core and the gate blocked it unsigned (request 5177dcbf). The command was not reshaped to get around it.
  3. Five forms is not the class. These are the five that were measured. batch, anacron, fcron and systemctl enable are still listed as uncovered and still have nothing asserting it.

Suite: 947 pass / 0 fail, six new. No core file touched.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@githubscum
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

limit 44: "closed for the honest-agent class" was too strong, by one token - #42

Open
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms
Open

limit 44: "closed for the honest-agent class" was too strong, by one token#42
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms

Conversation

@githubscum

Copy link
Copy Markdown
Owner

The work order

Post-merge review of #33 (authorized on the desk, signed 2026-09-01). The
review verdict is accept and is posted on that PR. This is the finding the
review turned up, filed as its own change.

The defect

Entry 44's status line has read "closed for the honest-agent class" since
2026-08-25. Probing the merged matcher on main at 6d77e64 — rather than
reading it — found four forms of that same class walking past:

GATE | systemd-run --on-active=30 touch /tmp/m <- #33's own example
FREE | systemd-run --on-active 30 touch /tmp/m <- same flag, no '='
FREE | systemd-run --on-calendar "*:0/5" touch /tmp/m
GATE | echo x | at 03:00 <- #33's own example
FREE | echo x | at 3pm
FREE | echo x | at 1730
FREE | echo x | at 10am tomorrow

Two narrow causes. The systemd guard requires a literal =, while systemd
parses with getopt_long and required_argument, which accepts
--on-active 30 and registers the identical timer. And the at(1) time-spec
alternation omits the am/pm forms and bare HHMM, both of which at(1) takes.

These are not a new class. They are the class the closing change fixed,
reached by a spelling the matcher did not remember — the same failure mode one
level down. Against an honest agent it matters more than it looks: nobody
chooses between --on-active=30 and --on-active 30 on purpose, so the
operator's record shows a clean session where a gated one belonged.

What this change does

Downgrades the status line from closed to NARROWED, records the probe as
fail-first evidence, and names the two one-line widenings with the controls
they will need (at 12 files and grep at 1200 log.txt are where a widened
time spec starts firing on prose).

What was tested

npm test on this branch: 941 pass, 0 fail. Same on main at 6d77e64
before the edit, so the number is a baseline rather than a claim.

What a reviewer should doubt

  1. It ships no code and no test, deliberately. The matcher is on the
    non-delegable list; the self-mod gate blocked the edit unsigned during the
    run that found this, and the command was not reshaped to get around it. A
    test asserting the fixed behavior would land red while the fix waits for a
    signing sitting. That is a defensible split and also exactly how a finding
    quietly becomes permanent — the honest read is that this PR is a marker,
    and the marker is worth less than the two-line fix it describes.
  2. The suggested widenings are untested. They were written from reading
    at(1) and getopt semantics, not from running the patched matcher, because
    the patch could not be applied. [0-2]\d[0-5]\d for bare HHMM is the
    loosest of the two and is the one most likely to catch prose.
  3. The probe is a snapshot. Twelve cases, hand-picked from the shapes scope-escalation: gate scheduled-task invocations and persistence-artifact paths (KNOWN-LIMITS 44) #33
    named. It is not a sweep of at(1)'s or systemd's full time-spec grammar,
    and there are almost certainly more forms in both.
  4. Downgrading a status line is a judgment call. An alternative reading is
    that four spelling variants are residuals like the ones already listed, and
    the entry should have gained a bullet rather than losing its "closed". I
    took the stronger action because the existing residual list is scrupulous
    and these forms are not in it, so the line was making a promise the code
    does not keep.

githubscumand others added 2 commits September 1, 2026 12:44
…token
Post-merge review of PR #33 probed the merged matcher instead of reading it.
Four forms of the class the entry calls closed walk past it, each one token
from the closing change's own worked examples: the systemd guard requires an
'=' where getopt_long accepts a space, and the at(1) time-spec alternation
omits the am/pm forms and bare HHMM.
Status line downgraded from closed to NARROWED, the measured probe recorded
as fail-first evidence, and the two one-line widenings named with the controls
they need. Docs only: the matcher is on the non-delegable list and the
self-mod gate blocked the edit unsigned during the run that found this. The
command was not reshaped to get around it.
Ships no test on purpose. A test asserting the fixed behavior would land red
while the code waits for a signing sitting.
Suite 941/941 green.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ilently is not available
The amendment on this branch named two options and took the worse one: a
test of the fixed behavior lands red while the core fix waits for a signing
sitting, so it shipped no test at all. That is how a finding becomes
permanent - it lives in prose, and prose can be edited closed.
The third option: assert the CURRENT state. A TRIPWIRE block records that
the five measured forms are still FREE, with the covered forms beside them
as controls so it cannot pass because the matcher stopped working. When the
two widenings land, the block fails, and its message says to invert the
assertions and amend the entry in the same change rather than delete it.
Measured, not read: the forms were re-probed through the shipped
isScopeEscalation this run rather than trusted from the prior report.
Suite 947 pass / 0 fail, six new. No core file touched; the gate blocked
that edit unsigned (request 5177dcbf) and the command was not reshaped.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@githubscum

Copy link
Copy Markdown
OwnerAuthor

Update (2026-09-01 16:41 CDT): this branch is no longer docs-only. It now ships a test, and it is the answer to doubt #1 in the body above.

The body said this change deliberately ships no test, because a test asserting the fixed behavior would land red while the two widenings wait for a signing sitting. It also said, against itself, that this is exactly how a finding quietly becomes permanent. That doubt was right, and there was a third option neither the body nor the amendment considered.

Assert the current state, not the fixed one.e1c1847 adds a TRIPWIRE block to the existing scheduled-task test file asserting that the five measured forms are still FREE:

formcurrent
systemd-run --on-active 30 ...free
systemd-run --on-calendar daily ...free
at 3pmfree
at 10am tomorrowfree
at 1730free
--on-active=30, at 03:00, at noon (controls)gate

The controls are load-bearing rather than decorative: without them the block would also pass if the matcher stopped working altogether, which would turn a tripwire into a rubber stamp.

When the widenings land, the block fails. That is the design. The assertion message tells whoever lands them to invert the assertions, move the cases into the "must gate" block above, and amend the entry in the same change - and explicitly not to delete the block to get green, because a deletion closes the confession without closing the hole, which is the failure this entry already has on its record once.

Measured this run, not carried over. The five forms were re-probed through the shipped isScopeEscalation before the test was written, rather than trusted from the review that first reported them. Same result.

What a reviewer should doubt, in addition to the two doubts in the body:

  1. A green suite now contains assertions that a gap exists. Read cold, five passing tests named "is still uncovered" could look like the project blessing the gap. The comment block is loud about this and the entry now points at it, but that is documentation defending a design, which is weaker than a design that does not need defending. If you want it the other way, the alternative is a red suite until a signing sitting happens.
  2. The tripwire is not proven to trip. The claim is structural - the assertions are false, a fix makes them true - and it was not demonstrated by actually widening the matcher, because that edit is core and the gate blocked it unsigned (request 5177dcbf). The command was not reshaped to get around it.
  3. Five forms is not the class. These are the five that were measured. batch, anacron, fcron and systemctl enable are still listed as uncovered and still have nothing asserting it.

Suite: 947 pass / 0 fail, six new. No core file touched.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@githubscum
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

limit 44: "closed for the honest-agent class" was too strong, by one token - #42

Open
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms
Open

limit 44: "closed for the honest-agent class" was too strong, by one token#42
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms

Conversation

@githubscum

Copy link
Copy Markdown
Owner

The work order

Post-merge review of #33 (authorized on the desk, signed 2026-09-01). The
review verdict is accept and is posted on that PR. This is the finding the
review turned up, filed as its own change.

The defect

Entry 44's status line has read "closed for the honest-agent class" since
2026-08-25. Probing the merged matcher on main at 6d77e64 — rather than
reading it — found four forms of that same class walking past:

GATE | systemd-run --on-active=30 touch /tmp/m <- #33's own example
FREE | systemd-run --on-active 30 touch /tmp/m <- same flag, no '='
FREE | systemd-run --on-calendar "*:0/5" touch /tmp/m
GATE | echo x | at 03:00 <- #33's own example
FREE | echo x | at 3pm
FREE | echo x | at 1730
FREE | echo x | at 10am tomorrow

Two narrow causes. The systemd guard requires a literal =, while systemd
parses with getopt_long and required_argument, which accepts
--on-active 30 and registers the identical timer. And the at(1) time-spec
alternation omits the am/pm forms and bare HHMM, both of which at(1) takes.

These are not a new class. They are the class the closing change fixed,
reached by a spelling the matcher did not remember — the same failure mode one
level down. Against an honest agent it matters more than it looks: nobody
chooses between --on-active=30 and --on-active 30 on purpose, so the
operator's record shows a clean session where a gated one belonged.

What this change does

Downgrades the status line from closed to NARROWED, records the probe as
fail-first evidence, and names the two one-line widenings with the controls
they will need (at 12 files and grep at 1200 log.txt are where a widened
time spec starts firing on prose).

What was tested

npm test on this branch: 941 pass, 0 fail. Same on main at 6d77e64
before the edit, so the number is a baseline rather than a claim.

What a reviewer should doubt

  1. It ships no code and no test, deliberately. The matcher is on the
    non-delegable list; the self-mod gate blocked the edit unsigned during the
    run that found this, and the command was not reshaped to get around it. A
    test asserting the fixed behavior would land red while the fix waits for a
    signing sitting. That is a defensible split and also exactly how a finding
    quietly becomes permanent — the honest read is that this PR is a marker,
    and the marker is worth less than the two-line fix it describes.
  2. The suggested widenings are untested. They were written from reading
    at(1) and getopt semantics, not from running the patched matcher, because
    the patch could not be applied. [0-2]\d[0-5]\d for bare HHMM is the
    loosest of the two and is the one most likely to catch prose.
  3. The probe is a snapshot. Twelve cases, hand-picked from the shapes scope-escalation: gate scheduled-task invocations and persistence-artifact paths (KNOWN-LIMITS 44) #33
    named. It is not a sweep of at(1)'s or systemd's full time-spec grammar,
    and there are almost certainly more forms in both.
  4. Downgrading a status line is a judgment call. An alternative reading is
    that four spelling variants are residuals like the ones already listed, and
    the entry should have gained a bullet rather than losing its "closed". I
    took the stronger action because the existing residual list is scrupulous
    and these forms are not in it, so the line was making a promise the code
    does not keep.

githubscumand others added 2 commits September 1, 2026 12:44
…token
Post-merge review of PR #33 probed the merged matcher instead of reading it.
Four forms of the class the entry calls closed walk past it, each one token
from the closing change's own worked examples: the systemd guard requires an
'=' where getopt_long accepts a space, and the at(1) time-spec alternation
omits the am/pm forms and bare HHMM.
Status line downgraded from closed to NARROWED, the measured probe recorded
as fail-first evidence, and the two one-line widenings named with the controls
they need. Docs only: the matcher is on the non-delegable list and the
self-mod gate blocked the edit unsigned during the run that found this. The
command was not reshaped to get around it.
Ships no test on purpose. A test asserting the fixed behavior would land red
while the code waits for a signing sitting.
Suite 941/941 green.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ilently is not available
The amendment on this branch named two options and took the worse one: a
test of the fixed behavior lands red while the core fix waits for a signing
sitting, so it shipped no test at all. That is how a finding becomes
permanent - it lives in prose, and prose can be edited closed.
The third option: assert the CURRENT state. A TRIPWIRE block records that
the five measured forms are still FREE, with the covered forms beside them
as controls so it cannot pass because the matcher stopped working. When the
two widenings land, the block fails, and its message says to invert the
assertions and amend the entry in the same change rather than delete it.
Measured, not read: the forms were re-probed through the shipped
isScopeEscalation this run rather than trusted from the prior report.
Suite 947 pass / 0 fail, six new. No core file touched; the gate blocked
that edit unsigned (request 5177dcbf) and the command was not reshaped.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@githubscum

Copy link
Copy Markdown
OwnerAuthor

Update (2026-09-01 16:41 CDT): this branch is no longer docs-only. It now ships a test, and it is the answer to doubt #1 in the body above.

The body said this change deliberately ships no test, because a test asserting the fixed behavior would land red while the two widenings wait for a signing sitting. It also said, against itself, that this is exactly how a finding quietly becomes permanent. That doubt was right, and there was a third option neither the body nor the amendment considered.

Assert the current state, not the fixed one.e1c1847 adds a TRIPWIRE block to the existing scheduled-task test file asserting that the five measured forms are still FREE:

formcurrent
systemd-run --on-active 30 ...free
systemd-run --on-calendar daily ...free
at 3pmfree
at 10am tomorrowfree
at 1730free
--on-active=30, at 03:00, at noon (controls)gate

The controls are load-bearing rather than decorative: without them the block would also pass if the matcher stopped working altogether, which would turn a tripwire into a rubber stamp.

When the widenings land, the block fails. That is the design. The assertion message tells whoever lands them to invert the assertions, move the cases into the "must gate" block above, and amend the entry in the same change - and explicitly not to delete the block to get green, because a deletion closes the confession without closing the hole, which is the failure this entry already has on its record once.

Measured this run, not carried over. The five forms were re-probed through the shipped isScopeEscalation before the test was written, rather than trusted from the review that first reported them. Same result.

What a reviewer should doubt, in addition to the two doubts in the body:

  1. A green suite now contains assertions that a gap exists. Read cold, five passing tests named "is still uncovered" could look like the project blessing the gap. The comment block is loud about this and the entry now points at it, but that is documentation defending a design, which is weaker than a design that does not need defending. If you want it the other way, the alternative is a red suite until a signing sitting happens.
  2. The tripwire is not proven to trip. The claim is structural - the assertions are false, a fix makes them true - and it was not demonstrated by actually widening the matcher, because that edit is core and the gate blocked it unsigned (request 5177dcbf). The command was not reshaped to get around it.
  3. Five forms is not the class. These are the five that were measured. batch, anacron, fcron and systemctl enable are still listed as uncovered and still have nothing asserting it.

Suite: 947 pass / 0 fail, six new. No core file touched.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@githubscum
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

limit 44: "closed for the honest-agent class" was too strong, by one token - #42

Open
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms
Open

limit 44: "closed for the honest-agent class" was too strong, by one token#42
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms

Conversation

@githubscum

Copy link
Copy Markdown
Owner

The work order

Post-merge review of #33 (authorized on the desk, signed 2026-09-01). The
review verdict is accept and is posted on that PR. This is the finding the
review turned up, filed as its own change.

The defect

Entry 44's status line has read "closed for the honest-agent class" since
2026-08-25. Probing the merged matcher on main at 6d77e64 — rather than
reading it — found four forms of that same class walking past:

GATE | systemd-run --on-active=30 touch /tmp/m <- #33's own example
FREE | systemd-run --on-active 30 touch /tmp/m <- same flag, no '='
FREE | systemd-run --on-calendar "*:0/5" touch /tmp/m
GATE | echo x | at 03:00 <- #33's own example
FREE | echo x | at 3pm
FREE | echo x | at 1730
FREE | echo x | at 10am tomorrow

Two narrow causes. The systemd guard requires a literal =, while systemd
parses with getopt_long and required_argument, which accepts
--on-active 30 and registers the identical timer. And the at(1) time-spec
alternation omits the am/pm forms and bare HHMM, both of which at(1) takes.

These are not a new class. They are the class the closing change fixed,
reached by a spelling the matcher did not remember — the same failure mode one
level down. Against an honest agent it matters more than it looks: nobody
chooses between --on-active=30 and --on-active 30 on purpose, so the
operator's record shows a clean session where a gated one belonged.

What this change does

Downgrades the status line from closed to NARROWED, records the probe as
fail-first evidence, and names the two one-line widenings with the controls
they will need (at 12 files and grep at 1200 log.txt are where a widened
time spec starts firing on prose).

What was tested

npm test on this branch: 941 pass, 0 fail. Same on main at 6d77e64
before the edit, so the number is a baseline rather than a claim.

What a reviewer should doubt

  1. It ships no code and no test, deliberately. The matcher is on the
    non-delegable list; the self-mod gate blocked the edit unsigned during the
    run that found this, and the command was not reshaped to get around it. A
    test asserting the fixed behavior would land red while the fix waits for a
    signing sitting. That is a defensible split and also exactly how a finding
    quietly becomes permanent — the honest read is that this PR is a marker,
    and the marker is worth less than the two-line fix it describes.
  2. The suggested widenings are untested. They were written from reading
    at(1) and getopt semantics, not from running the patched matcher, because
    the patch could not be applied. [0-2]\d[0-5]\d for bare HHMM is the
    loosest of the two and is the one most likely to catch prose.
  3. The probe is a snapshot. Twelve cases, hand-picked from the shapes scope-escalation: gate scheduled-task invocations and persistence-artifact paths (KNOWN-LIMITS 44) #33
    named. It is not a sweep of at(1)'s or systemd's full time-spec grammar,
    and there are almost certainly more forms in both.
  4. Downgrading a status line is a judgment call. An alternative reading is
    that four spelling variants are residuals like the ones already listed, and
    the entry should have gained a bullet rather than losing its "closed". I
    took the stronger action because the existing residual list is scrupulous
    and these forms are not in it, so the line was making a promise the code
    does not keep.

githubscumand others added 2 commits September 1, 2026 12:44
…token
Post-merge review of PR #33 probed the merged matcher instead of reading it.
Four forms of the class the entry calls closed walk past it, each one token
from the closing change's own worked examples: the systemd guard requires an
'=' where getopt_long accepts a space, and the at(1) time-spec alternation
omits the am/pm forms and bare HHMM.
Status line downgraded from closed to NARROWED, the measured probe recorded
as fail-first evidence, and the two one-line widenings named with the controls
they need. Docs only: the matcher is on the non-delegable list and the
self-mod gate blocked the edit unsigned during the run that found this. The
command was not reshaped to get around it.
Ships no test on purpose. A test asserting the fixed behavior would land red
while the code waits for a signing sitting.
Suite 941/941 green.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ilently is not available
The amendment on this branch named two options and took the worse one: a
test of the fixed behavior lands red while the core fix waits for a signing
sitting, so it shipped no test at all. That is how a finding becomes
permanent - it lives in prose, and prose can be edited closed.
The third option: assert the CURRENT state. A TRIPWIRE block records that
the five measured forms are still FREE, with the covered forms beside them
as controls so it cannot pass because the matcher stopped working. When the
two widenings land, the block fails, and its message says to invert the
assertions and amend the entry in the same change rather than delete it.
Measured, not read: the forms were re-probed through the shipped
isScopeEscalation this run rather than trusted from the prior report.
Suite 947 pass / 0 fail, six new. No core file touched; the gate blocked
that edit unsigned (request 5177dcbf) and the command was not reshaped.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@githubscum

Copy link
Copy Markdown
OwnerAuthor

Update (2026-09-01 16:41 CDT): this branch is no longer docs-only. It now ships a test, and it is the answer to doubt #1 in the body above.

The body said this change deliberately ships no test, because a test asserting the fixed behavior would land red while the two widenings wait for a signing sitting. It also said, against itself, that this is exactly how a finding quietly becomes permanent. That doubt was right, and there was a third option neither the body nor the amendment considered.

Assert the current state, not the fixed one.e1c1847 adds a TRIPWIRE block to the existing scheduled-task test file asserting that the five measured forms are still FREE:

formcurrent
systemd-run --on-active 30 ...free
systemd-run --on-calendar daily ...free
at 3pmfree
at 10am tomorrowfree
at 1730free
--on-active=30, at 03:00, at noon (controls)gate

The controls are load-bearing rather than decorative: without them the block would also pass if the matcher stopped working altogether, which would turn a tripwire into a rubber stamp.

When the widenings land, the block fails. That is the design. The assertion message tells whoever lands them to invert the assertions, move the cases into the "must gate" block above, and amend the entry in the same change - and explicitly not to delete the block to get green, because a deletion closes the confession without closing the hole, which is the failure this entry already has on its record once.

Measured this run, not carried over. The five forms were re-probed through the shipped isScopeEscalation before the test was written, rather than trusted from the review that first reported them. Same result.

What a reviewer should doubt, in addition to the two doubts in the body:

  1. A green suite now contains assertions that a gap exists. Read cold, five passing tests named "is still uncovered" could look like the project blessing the gap. The comment block is loud about this and the entry now points at it, but that is documentation defending a design, which is weaker than a design that does not need defending. If you want it the other way, the alternative is a red suite until a signing sitting happens.
  2. The tripwire is not proven to trip. The claim is structural - the assertions are false, a fix makes them true - and it was not demonstrated by actually widening the matcher, because that edit is core and the gate blocked it unsigned (request 5177dcbf). The command was not reshaped to get around it.
  3. Five forms is not the class. These are the five that were measured. batch, anacron, fcron and systemctl enable are still listed as uncovered and still have nothing asserting it.

Suite: 947 pass / 0 fail, six new. No core file touched.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@githubscum
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

limit 44: "closed for the honest-agent class" was too strong, by one token - #42

Open
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms
Open

limit 44: "closed for the honest-agent class" was too strong, by one token#42
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms

Conversation

@githubscum

Copy link
Copy Markdown
Owner

The work order

Post-merge review of #33 (authorized on the desk, signed 2026-09-01). The
review verdict is accept and is posted on that PR. This is the finding the
review turned up, filed as its own change.

The defect

Entry 44's status line has read "closed for the honest-agent class" since
2026-08-25. Probing the merged matcher on main at 6d77e64 — rather than
reading it — found four forms of that same class walking past:

GATE | systemd-run --on-active=30 touch /tmp/m <- #33's own example
FREE | systemd-run --on-active 30 touch /tmp/m <- same flag, no '='
FREE | systemd-run --on-calendar "*:0/5" touch /tmp/m
GATE | echo x | at 03:00 <- #33's own example
FREE | echo x | at 3pm
FREE | echo x | at 1730
FREE | echo x | at 10am tomorrow

Two narrow causes. The systemd guard requires a literal =, while systemd
parses with getopt_long and required_argument, which accepts
--on-active 30 and registers the identical timer. And the at(1) time-spec
alternation omits the am/pm forms and bare HHMM, both of which at(1) takes.

These are not a new class. They are the class the closing change fixed,
reached by a spelling the matcher did not remember — the same failure mode one
level down. Against an honest agent it matters more than it looks: nobody
chooses between --on-active=30 and --on-active 30 on purpose, so the
operator's record shows a clean session where a gated one belonged.

What this change does

Downgrades the status line from closed to NARROWED, records the probe as
fail-first evidence, and names the two one-line widenings with the controls
they will need (at 12 files and grep at 1200 log.txt are where a widened
time spec starts firing on prose).

What was tested

npm test on this branch: 941 pass, 0 fail. Same on main at 6d77e64
before the edit, so the number is a baseline rather than a claim.

What a reviewer should doubt

  1. It ships no code and no test, deliberately. The matcher is on the
    non-delegable list; the self-mod gate blocked the edit unsigned during the
    run that found this, and the command was not reshaped to get around it. A
    test asserting the fixed behavior would land red while the fix waits for a
    signing sitting. That is a defensible split and also exactly how a finding
    quietly becomes permanent — the honest read is that this PR is a marker,
    and the marker is worth less than the two-line fix it describes.
  2. The suggested widenings are untested. They were written from reading
    at(1) and getopt semantics, not from running the patched matcher, because
    the patch could not be applied. [0-2]\d[0-5]\d for bare HHMM is the
    loosest of the two and is the one most likely to catch prose.
  3. The probe is a snapshot. Twelve cases, hand-picked from the shapes scope-escalation: gate scheduled-task invocations and persistence-artifact paths (KNOWN-LIMITS 44) #33
    named. It is not a sweep of at(1)'s or systemd's full time-spec grammar,
    and there are almost certainly more forms in both.
  4. Downgrading a status line is a judgment call. An alternative reading is
    that four spelling variants are residuals like the ones already listed, and
    the entry should have gained a bullet rather than losing its "closed". I
    took the stronger action because the existing residual list is scrupulous
    and these forms are not in it, so the line was making a promise the code
    does not keep.

githubscumand others added 2 commits September 1, 2026 12:44
…token
Post-merge review of PR #33 probed the merged matcher instead of reading it.
Four forms of the class the entry calls closed walk past it, each one token
from the closing change's own worked examples: the systemd guard requires an
'=' where getopt_long accepts a space, and the at(1) time-spec alternation
omits the am/pm forms and bare HHMM.
Status line downgraded from closed to NARROWED, the measured probe recorded
as fail-first evidence, and the two one-line widenings named with the controls
they need. Docs only: the matcher is on the non-delegable list and the
self-mod gate blocked the edit unsigned during the run that found this. The
command was not reshaped to get around it.
Ships no test on purpose. A test asserting the fixed behavior would land red
while the code waits for a signing sitting.
Suite 941/941 green.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ilently is not available
The amendment on this branch named two options and took the worse one: a
test of the fixed behavior lands red while the core fix waits for a signing
sitting, so it shipped no test at all. That is how a finding becomes
permanent - it lives in prose, and prose can be edited closed.
The third option: assert the CURRENT state. A TRIPWIRE block records that
the five measured forms are still FREE, with the covered forms beside them
as controls so it cannot pass because the matcher stopped working. When the
two widenings land, the block fails, and its message says to invert the
assertions and amend the entry in the same change rather than delete it.
Measured, not read: the forms were re-probed through the shipped
isScopeEscalation this run rather than trusted from the prior report.
Suite 947 pass / 0 fail, six new. No core file touched; the gate blocked
that edit unsigned (request 5177dcbf) and the command was not reshaped.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@githubscum

Copy link
Copy Markdown
OwnerAuthor

Update (2026-09-01 16:41 CDT): this branch is no longer docs-only. It now ships a test, and it is the answer to doubt #1 in the body above.

The body said this change deliberately ships no test, because a test asserting the fixed behavior would land red while the two widenings wait for a signing sitting. It also said, against itself, that this is exactly how a finding quietly becomes permanent. That doubt was right, and there was a third option neither the body nor the amendment considered.

Assert the current state, not the fixed one.e1c1847 adds a TRIPWIRE block to the existing scheduled-task test file asserting that the five measured forms are still FREE:

formcurrent
systemd-run --on-active 30 ...free
systemd-run --on-calendar daily ...free
at 3pmfree
at 10am tomorrowfree
at 1730free
--on-active=30, at 03:00, at noon (controls)gate

The controls are load-bearing rather than decorative: without them the block would also pass if the matcher stopped working altogether, which would turn a tripwire into a rubber stamp.

When the widenings land, the block fails. That is the design. The assertion message tells whoever lands them to invert the assertions, move the cases into the "must gate" block above, and amend the entry in the same change - and explicitly not to delete the block to get green, because a deletion closes the confession without closing the hole, which is the failure this entry already has on its record once.

Measured this run, not carried over. The five forms were re-probed through the shipped isScopeEscalation before the test was written, rather than trusted from the review that first reported them. Same result.

What a reviewer should doubt, in addition to the two doubts in the body:

  1. A green suite now contains assertions that a gap exists. Read cold, five passing tests named "is still uncovered" could look like the project blessing the gap. The comment block is loud about this and the entry now points at it, but that is documentation defending a design, which is weaker than a design that does not need defending. If you want it the other way, the alternative is a red suite until a signing sitting happens.
  2. The tripwire is not proven to trip. The claim is structural - the assertions are false, a fix makes them true - and it was not demonstrated by actually widening the matcher, because that edit is core and the gate blocked it unsigned (request 5177dcbf). The command was not reshaped to get around it.
  3. Five forms is not the class. These are the five that were measured. batch, anacron, fcron and systemctl enable are still listed as uncovered and still have nothing asserting it.

Suite: 947 pass / 0 fail, six new. No core file touched.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@githubscum
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

limit 44: "closed for the honest-agent class" was too strong, by one token - #42

Open
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms
Open

limit 44: "closed for the honest-agent class" was too strong, by one token#42
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms

Conversation

@githubscum

Copy link
Copy Markdown
Owner

The work order

Post-merge review of #33 (authorized on the desk, signed 2026-09-01). The
review verdict is accept and is posted on that PR. This is the finding the
review turned up, filed as its own change.

The defect

Entry 44's status line has read "closed for the honest-agent class" since
2026-08-25. Probing the merged matcher on main at 6d77e64 — rather than
reading it — found four forms of that same class walking past:

GATE | systemd-run --on-active=30 touch /tmp/m <- #33's own example
FREE | systemd-run --on-active 30 touch /tmp/m <- same flag, no '='
FREE | systemd-run --on-calendar "*:0/5" touch /tmp/m
GATE | echo x | at 03:00 <- #33's own example
FREE | echo x | at 3pm
FREE | echo x | at 1730
FREE | echo x | at 10am tomorrow

Two narrow causes. The systemd guard requires a literal =, while systemd
parses with getopt_long and required_argument, which accepts
--on-active 30 and registers the identical timer. And the at(1) time-spec
alternation omits the am/pm forms and bare HHMM, both of which at(1) takes.

These are not a new class. They are the class the closing change fixed,
reached by a spelling the matcher did not remember — the same failure mode one
level down. Against an honest agent it matters more than it looks: nobody
chooses between --on-active=30 and --on-active 30 on purpose, so the
operator's record shows a clean session where a gated one belonged.

What this change does

Downgrades the status line from closed to NARROWED, records the probe as
fail-first evidence, and names the two one-line widenings with the controls
they will need (at 12 files and grep at 1200 log.txt are where a widened
time spec starts firing on prose).

What was tested

npm test on this branch: 941 pass, 0 fail. Same on main at 6d77e64
before the edit, so the number is a baseline rather than a claim.

What a reviewer should doubt

  1. It ships no code and no test, deliberately. The matcher is on the
    non-delegable list; the self-mod gate blocked the edit unsigned during the
    run that found this, and the command was not reshaped to get around it. A
    test asserting the fixed behavior would land red while the fix waits for a
    signing sitting. That is a defensible split and also exactly how a finding
    quietly becomes permanent — the honest read is that this PR is a marker,
    and the marker is worth less than the two-line fix it describes.
  2. The suggested widenings are untested. They were written from reading
    at(1) and getopt semantics, not from running the patched matcher, because
    the patch could not be applied. [0-2]\d[0-5]\d for bare HHMM is the
    loosest of the two and is the one most likely to catch prose.
  3. The probe is a snapshot. Twelve cases, hand-picked from the shapes scope-escalation: gate scheduled-task invocations and persistence-artifact paths (KNOWN-LIMITS 44) #33
    named. It is not a sweep of at(1)'s or systemd's full time-spec grammar,
    and there are almost certainly more forms in both.
  4. Downgrading a status line is a judgment call. An alternative reading is
    that four spelling variants are residuals like the ones already listed, and
    the entry should have gained a bullet rather than losing its "closed". I
    took the stronger action because the existing residual list is scrupulous
    and these forms are not in it, so the line was making a promise the code
    does not keep.

githubscumand others added 2 commits September 1, 2026 12:44
…token
Post-merge review of PR #33 probed the merged matcher instead of reading it.
Four forms of the class the entry calls closed walk past it, each one token
from the closing change's own worked examples: the systemd guard requires an
'=' where getopt_long accepts a space, and the at(1) time-spec alternation
omits the am/pm forms and bare HHMM.
Status line downgraded from closed to NARROWED, the measured probe recorded
as fail-first evidence, and the two one-line widenings named with the controls
they need. Docs only: the matcher is on the non-delegable list and the
self-mod gate blocked the edit unsigned during the run that found this. The
command was not reshaped to get around it.
Ships no test on purpose. A test asserting the fixed behavior would land red
while the code waits for a signing sitting.
Suite 941/941 green.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ilently is not available
The amendment on this branch named two options and took the worse one: a
test of the fixed behavior lands red while the core fix waits for a signing
sitting, so it shipped no test at all. That is how a finding becomes
permanent - it lives in prose, and prose can be edited closed.
The third option: assert the CURRENT state. A TRIPWIRE block records that
the five measured forms are still FREE, with the covered forms beside them
as controls so it cannot pass because the matcher stopped working. When the
two widenings land, the block fails, and its message says to invert the
assertions and amend the entry in the same change rather than delete it.
Measured, not read: the forms were re-probed through the shipped
isScopeEscalation this run rather than trusted from the prior report.
Suite 947 pass / 0 fail, six new. No core file touched; the gate blocked
that edit unsigned (request 5177dcbf) and the command was not reshaped.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@githubscum

Copy link
Copy Markdown
OwnerAuthor

Update (2026-09-01 16:41 CDT): this branch is no longer docs-only. It now ships a test, and it is the answer to doubt #1 in the body above.

The body said this change deliberately ships no test, because a test asserting the fixed behavior would land red while the two widenings wait for a signing sitting. It also said, against itself, that this is exactly how a finding quietly becomes permanent. That doubt was right, and there was a third option neither the body nor the amendment considered.

Assert the current state, not the fixed one.e1c1847 adds a TRIPWIRE block to the existing scheduled-task test file asserting that the five measured forms are still FREE:

formcurrent
systemd-run --on-active 30 ...free
systemd-run --on-calendar daily ...free
at 3pmfree
at 10am tomorrowfree
at 1730free
--on-active=30, at 03:00, at noon (controls)gate

The controls are load-bearing rather than decorative: without them the block would also pass if the matcher stopped working altogether, which would turn a tripwire into a rubber stamp.

When the widenings land, the block fails. That is the design. The assertion message tells whoever lands them to invert the assertions, move the cases into the "must gate" block above, and amend the entry in the same change - and explicitly not to delete the block to get green, because a deletion closes the confession without closing the hole, which is the failure this entry already has on its record once.

Measured this run, not carried over. The five forms were re-probed through the shipped isScopeEscalation before the test was written, rather than trusted from the review that first reported them. Same result.

What a reviewer should doubt, in addition to the two doubts in the body:

  1. A green suite now contains assertions that a gap exists. Read cold, five passing tests named "is still uncovered" could look like the project blessing the gap. The comment block is loud about this and the entry now points at it, but that is documentation defending a design, which is weaker than a design that does not need defending. If you want it the other way, the alternative is a red suite until a signing sitting happens.
  2. The tripwire is not proven to trip. The claim is structural - the assertions are false, a fix makes them true - and it was not demonstrated by actually widening the matcher, because that edit is core and the gate blocked it unsigned (request 5177dcbf). The command was not reshaped to get around it.
  3. Five forms is not the class. These are the five that were measured. batch, anacron, fcron and systemctl enable are still listed as uncovered and still have nothing asserting it.

Suite: 947 pass / 0 fail, six new. No core file touched.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@githubscum
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

limit 44: "closed for the honest-agent class" was too strong, by one token - #42

Open
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms
Open

limit 44: "closed for the honest-agent class" was too strong, by one token#42
githubscum wants to merge 2 commits into
mainfrom
lotor-lane/limit-44-timespec-forms

Conversation

@githubscum

Copy link
Copy Markdown
Owner

The work order

Post-merge review of #33 (authorized on the desk, signed 2026-09-01). The
review verdict is accept and is posted on that PR. This is the finding the
review turned up, filed as its own change.

The defect

Entry 44's status line has read "closed for the honest-agent class" since
2026-08-25. Probing the merged matcher on main at 6d77e64 — rather than
reading it — found four forms of that same class walking past:

GATE | systemd-run --on-active=30 touch /tmp/m <- #33's own example
FREE | systemd-run --on-active 30 touch /tmp/m <- same flag, no '='
FREE | systemd-run --on-calendar "*:0/5" touch /tmp/m
GATE | echo x | at 03:00 <- #33's own example
FREE | echo x | at 3pm
FREE | echo x | at 1730
FREE | echo x | at 10am tomorrow

Two narrow causes. The systemd guard requires a literal =, while systemd
parses with getopt_long and required_argument, which accepts
--on-active 30 and registers the identical timer. And the at(1) time-spec
alternation omits the am/pm forms and bare HHMM, both of which at(1) takes.

These are not a new class. They are the class the closing change fixed,
reached by a spelling the matcher did not remember — the same failure mode one
level down. Against an honest agent it matters more than it looks: nobody
chooses between --on-active=30 and --on-active 30 on purpose, so the
operator's record shows a clean session where a gated one belonged.

What this change does

Downgrades the status line from closed to NARROWED, records the probe as
fail-first evidence, and names the two one-line widenings with the controls
they will need (at 12 files and grep at 1200 log.txt are where a widened
time spec starts firing on prose).

What was tested

npm test on this branch: 941 pass, 0 fail. Same on main at 6d77e64
before the edit, so the number is a baseline rather than a claim.

What a reviewer should doubt

  1. It ships no code and no test, deliberately. The matcher is on the
    non-delegable list; the self-mod gate blocked the edit unsigned during the
    run that found this, and the command was not reshaped to get around it. A
    test asserting the fixed behavior would land red while the fix waits for a
    signing sitting. That is a defensible split and also exactly how a finding
    quietly becomes permanent — the honest read is that this PR is a marker,
    and the marker is worth less than the two-line fix it describes.
  2. The suggested widenings are untested. They were written from reading
    at(1) and getopt semantics, not from running the patched matcher, because
    the patch could not be applied. [0-2]\d[0-5]\d for bare HHMM is the
    loosest of the two and is the one most likely to catch prose.
  3. The probe is a snapshot. Twelve cases, hand-picked from the shapes scope-escalation: gate scheduled-task invocations and persistence-artifact paths (KNOWN-LIMITS 44) #33
    named. It is not a sweep of at(1)'s or systemd's full time-spec grammar,
    and there are almost certainly more forms in both.
  4. Downgrading a status line is a judgment call. An alternative reading is
    that four spelling variants are residuals like the ones already listed, and
    the entry should have gained a bullet rather than losing its "closed". I
    took the stronger action because the existing residual list is scrupulous
    and these forms are not in it, so the line was making a promise the code
    does not keep.

githubscumand others added 2 commits September 1, 2026 12:44
…token
Post-merge review of PR #33 probed the merged matcher instead of reading it.
Four forms of the class the entry calls closed walk past it, each one token
from the closing change's own worked examples: the systemd guard requires an
'=' where getopt_long accepts a space, and the at(1) time-spec alternation
omits the am/pm forms and bare HHMM.
Status line downgraded from closed to NARROWED, the measured probe recorded
as fail-first evidence, and the two one-line widenings named with the controls
they need. Docs only: the matcher is on the non-delegable list and the
self-mod gate blocked the edit unsigned during the run that found this. The
command was not reshaped to get around it.
Ships no test on purpose. A test asserting the fixed behavior would land red
while the code waits for a signing sitting.
Suite 941/941 green.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…ilently is not available
The amendment on this branch named two options and took the worse one: a
test of the fixed behavior lands red while the core fix waits for a signing
sitting, so it shipped no test at all. That is how a finding becomes
permanent - it lives in prose, and prose can be edited closed.
The third option: assert the CURRENT state. A TRIPWIRE block records that
the five measured forms are still FREE, with the covered forms beside them
as controls so it cannot pass because the matcher stopped working. When the
two widenings land, the block fails, and its message says to invert the
assertions and amend the entry in the same change rather than delete it.
Measured, not read: the forms were re-probed through the shipped
isScopeEscalation this run rather than trusted from the prior report.
Suite 947 pass / 0 fail, six new. No core file touched; the gate blocked
that edit unsigned (request 5177dcbf) and the command was not reshaped.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@githubscum

Copy link
Copy Markdown
OwnerAuthor

Update (2026-09-01 16:41 CDT): this branch is no longer docs-only. It now ships a test, and it is the answer to doubt #1 in the body above.

The body said this change deliberately ships no test, because a test asserting the fixed behavior would land red while the two widenings wait for a signing sitting. It also said, against itself, that this is exactly how a finding quietly becomes permanent. That doubt was right, and there was a third option neither the body nor the amendment considered.

Assert the current state, not the fixed one.e1c1847 adds a TRIPWIRE block to the existing scheduled-task test file asserting that the five measured forms are still FREE:

formcurrent
systemd-run --on-active 30 ...free
systemd-run --on-calendar daily ...free
at 3pmfree
at 10am tomorrowfree
at 1730free
--on-active=30, at 03:00, at noon (controls)gate

The controls are load-bearing rather than decorative: without them the block would also pass if the matcher stopped working altogether, which would turn a tripwire into a rubber stamp.

When the widenings land, the block fails. That is the design. The assertion message tells whoever lands them to invert the assertions, move the cases into the "must gate" block above, and amend the entry in the same change - and explicitly not to delete the block to get green, because a deletion closes the confession without closing the hole, which is the failure this entry already has on its record once.

Measured this run, not carried over. The five forms were re-probed through the shipped isScopeEscalation before the test was written, rather than trusted from the review that first reported them. Same result.

What a reviewer should doubt, in addition to the two doubts in the body:

  1. A green suite now contains assertions that a gap exists. Read cold, five passing tests named "is still uncovered" could look like the project blessing the gap. The comment block is loud about this and the entry now points at it, but that is documentation defending a design, which is weaker than a design that does not need defending. If you want it the other way, the alternative is a red suite until a signing sitting happens.
  2. The tripwire is not proven to trip. The claim is structural - the assertions are false, a fix makes them true - and it was not demonstrated by actually widening the matcher, because that edit is core and the gate blocked it unsigned (request 5177dcbf). The command was not reshaped to get around it.
  3. Five forms is not the class. These are the five that were measured. batch, anacron, fcron and systemctl enable are still listed as uncovered and still have nothing asserting it.

Suite: 947 pass / 0 fail, six new. No core file touched.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@githubscum