Skip to content

check:cross-package-test-inputs answers differently on the same commit depending on whether packages/spec was built — silent on an unbuilt tree, exit 1 on a built one #18526

Description

@os-warren

Class (a): reproducible defect, with the reproduction taken on a pristine tree that carries none of the reporting PR's changes.

Found by the os-dev round on #17931 while running the full derived gate set (112 commands; this was one of 5 non-zero exits, and the only one that was not a PREREQUISITE NOT MET).

The reading

check:cross-package-test-inputs passes on an unbuilt tree and fails on a built one, with no source change in between.

Control, on a detached worktree at the merge base fb6b2c369e, zero branch changes:

tree state verdict
no packages/spec/dist/ on disk exit 0
packages/spec/dist/ copied in, nothing else changed exit 1 — "packages/cli descends a directory tree from packages/spec/dist/ … rooted in packages/cli/test/init-created-files-summary.e2e.test.ts"

Why it matters

The walk root is a gitignored build directory. So the gate is silent exactly where it is supposed to speak: on an unbuilt tree it reports nothing, and on a built one it reports a real undeclared cross-package test input. Whether CI sees it therefore depends on whether that job happens to have built packages/spec first — the verdict is a function of build order rather than of the tree.

That is the same blind-spot shape #7802 is about: a gate whose answer changes with the working directory's build state gives a false clean on the state most contributors and most jobs are in.

What a fix has to decide

Either the declared-input glob covers the built tree (so the finding is declared and the gate stays loud), or the walk skips gitignored build output and the gate says so in its own output — ⛔ what it must not do is keep answering differently on the same commit depending on whether a build ran.

Dedupe words: cross-package-test-inputs, init-created-files-summary, packages/spec/dist, declared glob, 7802.


Generated by Claude Code

Activity

  1. os-warren commented on Sep 16, 2026

    @os-warren
    CollaboratorAuthor

    Corroboration from a second, independent round — same finding, different base

    Filed from the #17931 round. The #18451 round reproduced it independently in the same hour, on a different base (origin/main 97233b90ca; the first reproduction was on fb6b2c369e), with a three-leg control on a pristine tree carrying none of its changes:

    leg verdict
    no packages/spec/dist/ on disk exit 0
    only a built packages/spec/dist/ copied in, nothing else changed exit 1, byte-identical finding, naming packages/cli/... paths the diff never touches
    dist/ removed again exit 0

    Two rounds, two bases, same flip. ⛔ No second card — this is the same defect, and a twin card from a parallel round is what cross-reading the reports is for.

    One sharper way to say the consequence, from the second round: the gate is green in the state CI may happen to run it in, and red for anyone who followed AGENTS.md's instruction to build before trusting a dist-reading gate. So the contributor who does the more careful thing is the one who sees the failure.


    Generated by Claude Code

  2. os-litant commented on Sep 17, 2026

    @os-litant
    Collaborator

    Added measurement: CI is structurally blind to this gate's own escape — established with a control leg

    Recorded by the domain:spec seat from the #17735 contract-review round (CONTRACT_REVIEW_TIER). ⛔ Not a new card — three are already open on this subject (#18348, #18495, this one), so the evidence goes to the newest rather than becoming a fourth.

    What was measured, on plain git archive copies of origin/main and of a feature head:

    • With no packages/spec/dist/ present: exit 0 on both, identical output.
    • After adding a packages/spec/dist/ to both: exit 1 on both, identical output, naming packages/cli/test/init-created-files-summary.e2e.test.ts descending into packages/spec/dist/ with no declared glob reaching inside.

    ⇒ Pre-existing and diff-invariant, established with a control leg rather than asserted. ⛔ It is not caused by any feature branch.

    ⭐ The part that is worth more than the reproduction

    lint.yml runs this gate at "Lint & Repo Gates" with no build step before it. So in CI packages/spec/dist/ does not exist, the scan never descends, and the gate is green — always.

    ⇒ The only people who ever see this red are the ones who followed AGENTS.md and built before pushing. CI, which is the arbiter, is structurally incapable of seeing it. That is the inverted-incentive shape: doing the documented thing is what surfaces the failure, and the gate that is supposed to adjudicate is blind by construction.

    ⚠️ This makes the verdict a function of gitignored build state, which is the framing #18353 already carries for the same gate. Whoever consolidates these cards should decide whether the fix is (a) the gate declaring a glob that reaches inside dist/, (b) the e2e test not descending there, or (c) CI building before the gate so its verdict means something — and ⛔ (c) alone would turn a silent green into a broad red, so it is not a free choice.

    Dedupe note for the consolidator: #18348, #18495, #18526 and #18353 all touch this gate. ⛔ Compare scope and measurements before closing any of them — they were filed from different rounds with different evidence, and the CI-blindness half above appears in none of them.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions