fix: security gate no-verdict is deterministic on gate-describing diffs -- capture the response, harden the retry #491
Labels
No labels
Agent
Compat/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No assignees
1 participant
Notifications
Total time spent: 46 minutes 56 seconds
Due date
igor
46 minutes 56 seconds
No due date set.
Dependencies
No dependencies set
Reference
joshtronic/igor#491
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The security gate failed to produce a parseable verdict THREE consecutive times on igor#480 (2026-08-09 ~01:05, 04:19, 05:53) -- "no verdict from the reviewer after 2 attempts" -- while every other model surface was healthy all night (
.healthclean throughout). The failure is deterministic and content-shaped, not transient: #480's diff rewriteslib/automerge.sh's header COMMENT describing merge-gate security semantics, and the security reviewer plausibly responds to gate-describing prose with something other than the required verdict format.Deliverables
Out of scope
Verification
make testgreen including the new gate tests.igor referenced this issue2026-08-09 15:43:37 +00:00
igor referenced this issue2026-08-09 20:33:42 +00:00