roadmap/labels/yaml gates: residuals ledger after the six-round critic loop (#1226) — one P2 (privacy classifier fails open) closed in round 7; 8 ranked residuals
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 35/100
Research direction
Start with roadmap_check.sh and the [99zb] gate, then read the caller paths and the daily issue-triage.yml workflow; docs/CI.md records the stated boundary. Reproduce the ranked residuals using the mentioned fixtures and existing selftest pin. Done means the selected residuals have agreed fixes, accurate receipts or diagnostics, and regression coverage without reopening the pinned exclusions.
Written by the indexing model from the issue text.
Description
Residuals ledger for the front-door gates after the six-round blind-critic loop on PR #1226 (m1b-front-doors, head 93ff029). Final verdicts: Fable PASS / dry / fit to merge; Astra FAIL on one P2 (item 1 below) which both critics found and which is closed in the past-cap round 7 of #1226. Reproducers live under /tmp/critic-fable-c-r6/ and /tmp/critic-astra-c-r6/ on the dev box.
Class the six rounds closed: a caller that certifies a gate without an independent measurement — exit status (r1), the gate's own contract (r2), the gate's own SKIP token with no token-holding lane (r3), an explicit owner discarded (r3), the oracle's identity and the verification's outcome not on the receipt (r5–r6).
Ranked residuals
- P2 — unknown privacy is certified public (both critics):
roadmap_check.sh's classifier treats every.privatevalue other than the literaltrueas public, so a listing with.privatemissing/null yieldsrepos=verified:13with zero explicitfalsevalues; both callers accept it. Real GitHub responses always carry a boolean, so fixture-only today. → closed in round 7 (only explicitfalsecounts; anything else is "unknown visibility", red). - P3 —
[99zb]'s identity check keys on the GNU banner, notBASH_VERSINFO(Fable): a genuine bash 3.2 with a non-GNU--versionbanner completes the audit and is failed "never named its interpreter" — a false RED, unreachable on any current lane. Fix shape: the gate printsoracle-major=NfromBASH_VERSINFO[0]and the caller parses that. - P3 — the
[99zb]identity arm has no in-tree selftest (both; inside caveat 2): the only mechanical guard is Astra's reproducer under /tmp. - P3 — under a public-only listing (
github.token) a KNOWN_REPOS entry that flipped private is diagnosed "does not exist … not about the token" (both; inside caveat 1): still red, wrong reason; a listing with zero private rows is a public-only view and "absent" means absent-or-private. - P3 — a self-echoing org listing forges
repos=verified:13(both; INSIDE the stated forged-receipt boundary): gutting the verifier is caught by the selftest pin; forging only the live path passes with zero listing calls. - P3 — the daily workflow's "this lane exports GH_TOKEN" wording when both token variables are UNSET (both; caveat 4): correct failure, inaccurate wording.
- A user-owned fork running the daily audit goes RED by name (
orgs/<user>/repos404s →repos=skipped:org-listing-unavailablerejected by the live pin) — the safer direction; a behaviour change worth knowing. verified:Nis not pinned to |KNOWN_REPOS| at the callers; a shrunken list is stricter, never a false green.- README "~940K minimal binary" measures 951 KiB (inside the pinned ±10%; drift in progress).
Stated and pinned (do not re-file)
- A gate that fabricates its own receipts is outside the caller's power (stated in
[99zd], both gate headers, docs/CI.md). - The BUILTIN-FAMILIES class covers the seven-file doc set only;
docs/TRACE.mdand other executed-example docs are outside it. - Sanitizer shards hold no token by design (three redundant API walks per push).
- DONE-cell equality is after whitespace/full-stop normalisation; lowercase repo names are red (typed case-sensitive
KNOWN_REPOS). - The daily
issue-triage.ymllanes (schedule,issues) are unobserved until the branch is onmain.
- Dominant language
- C
- Stars
- 3
- Forks
- 7
- Avg merge
- 3h 56m
- Merged PRs (30d)
- 102
Getting set up
Starts the project's dev container in your browser, under your own GitHub account.
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from InauguralSystems/EigenScript
-
area:lint-tooling bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
InauguralSystems/EigenScript#1340 ·
Maintainers usually reply within 1 day
-
area:stdlib found-by:code-review kind:silent-wrong
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
InauguralSystems/EigenScript#1338 ·
Maintainers usually reply within 1 day
-
area:lint-tooling found-by:critic kind:docs-drift
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
InauguralSystems/EigenScript#1335 ·
Maintainers usually reply within 1 day
-
area:ci found-by:critic kind:gate-defect
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
InauguralSystems/EigenScript#1311 ·
Maintainers usually reply within 1 day
-
enrolment: decide test_gc_runner_controls.py (exempt vs enrol) and whether floors need a ratchetOpenarea:gates found-by:critic kind:decision
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
InauguralSystems/EigenScript#1280 · 1 comment ·
Maintainers usually reply within 1 day
All issues in InauguralSystems/EigenScript
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
libretro/libretro-common#233 ·
-
[Bug]: chunk_span_bounds and _validated_chunk_spans reject Pydantic models ChunkSpan and AudioFileOpen
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
BasedHardware/omi#19047 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
obsproject/obs-studio#13936 · 2 comments ·
Maintainers usually reply within 1 day