What happened (measured 2026-09-21, #3669 guard-tree job 106269529439, head 55b123f2f)
check_ont_ratchet.sh FAILed: contracts_anchored rose 3 -> 6 while consumer_present=false. The consumer probe (scripts/check_ont_ratchet.sh:45-57) is:
pvbin="$(command -v pv 2>/dev/null || true)"
help_out="$("$pvbin" --help 2>&1 || true)"
grep -qE '^[[:space:]]+census[[:space:]]' <<<"$help_out" || return 1
That's a bare pv from PATH. On intel the fleet pin is being clobbered to 0.65.2 (paiml-implement#315), and 0.65.2 has no census. So the probe answers "no consumer" about the runner, not about the tree. In-tree pv has census (ONT-1 landed: contracts/census.json is produced by it). It's the same class as #3567 (the shapes gate on an unpinned pv), and it's the sibling that #3567's repair didn't touch.
The pinned-binary guard is blind to this form. check_apr_bin_pinned.sh:503 must-match table: 'PV=$(command -v pv)' 'require_tool pv "x"' 'which pv'. It has no row for <anyvar>="$(command -v pv …)", so a lowercase variable name and a redirect walk past it.
done_when
Found by the cop while triaging #3669's reds. #3669 takes the restamp (make ont-ratchet with a census-capable pv); this row is the root cause. Refs #3567, paiml-implement#315.
What happened (measured 2026-09-21, #3669 guard-tree job 106269529439, head
55b123f2f)check_ont_ratchet.shFAILed:contracts_anchored rose 3 -> 6 while consumer_present=false. The consumer probe (scripts/check_ont_ratchet.sh:45-57) is:That's a bare
pvfrom PATH. On intel the fleet pin is being clobbered to 0.65.2 (paiml-implement#315), and 0.65.2 has nocensus. So the probe answers "no consumer" about the runner, not about the tree. In-treepvhascensus(ONT-1 landed:contracts/census.jsonis produced by it). It's the same class as #3567 (the shapes gate on an unpinned pv), and it's the sibling that #3567's repair didn't touch.The pinned-binary guard is blind to this form.
check_apr_bin_pinned.sh:503must-match table:'PV=$(command -v pv)' 'require_tool pv "x"' 'which pv'. It has no row for<anyvar>="$(command -v pv …)", so a lowercase variable name and a redirect walk past it.done_when
UNMEASUREDnaming the version, neverconsumer_present=false. A version too old to judge is not evidence of absence.pvwithoutcensuson PATH plus a pinned pv WITH census gives consumer_present=true (RED-turning: revert the resolution and the row fails)check_apr_bin_pinned.shcase table gains must-match rowspvbin="$(command -v pv 2>/dev/null || true)"andx=$(command -v pv), and the scan finds this site before the fix (the mutation proof)Found by the cop while triaging #3669's reds. #3669 takes the restamp (
make ont-ratchetwith a census-capable pv); this row is the root cause. Refs #3567, paiml-implement#315.