Skip to content

docs(FUSI-020): pin the streak count to a dated as-of measurement - #33

Open
timoteo7 wants to merge 2 commits into
mainfrom
fusion/fusi-020-census-streak
Open

timoteo7 wants to merge 2 commits into
mainfrom
fusion/fusi-020-census-streak

Conversation

@timoteo7

Copy link
Copy Markdown
Owner

Docs-only correction of the FUSI-020 main Full Suite census.

What this changes

One file: docs/solutions/test-failures/main-full-suite-census-2026-09-25.md.

The census pinned its streak head to Runfusion#3158 / 1762 red runs and asserted, in the
present tense, that the number was stable. Measurement falsified three claims:

  1. The streak head moved. Re-measured 2026-09-29: the completed streak is
    1770 red (total_count 1771 with one in flight), status=success is
    0 across the window, and [FN-5978] Fix: Goal retrieval tools for agent citation Runfusion/Fusion#1396 (2026-07-26T04:14:37Z) is still the
    last green. The "frozen at fix: the last 4 literal move targets — Retry threw on renamed boards; allow-list now empty (#3150 closed) Runfusion/Fusion#3158" reading was an artifact of reading the head
    of a >1700-run result set off a per_page=100 page — runs fix(core): a type that taught the wrong invariant — staleness signal column narrowed to legacy ids Runfusion/Fusion#3159–gate: enforce the quarantine deletion ratchet — nothing ran it, and it could not fail Runfusion/Fusion#3167 have
    landed since, all failures, so the lane is still being exercised.

  2. The headline is now a dated measurement, not a property of the lane.
    Every main push extends the streak by one, so any figure copied forward is
    false the next day. The count is stated as 1770 as measured
    2026-09-29T08:13Z
    , with the as-of run number and timestamp required whenever
    the streak is quoted, and the non-drifting fact (zero successes since
    [FN-5978] Fix: Goal retrieval tools for agent citation Runfusion/Fusion#1396
    ) named as the durable claim.

  3. The method line described only the engine shards' FAIL shape. Verified
    against run fix(core): an archived child kept blocking its parent's delete on a renamed board Runfusion/Fusion#3162's logs: the project column is a vitest project name present
    only in shards 1/2, the CLI shard puts a pnpm stream prefix before FAIL,
    and core has no column at all. A project-column-only parser reads 217 of
    233
    cases and drops shard 4/4 without erroring. Also recorded: bare
    substring FAIL matches ACTION_FAILED, SCREENSHOT_FAILED and
    ERR_PNPM_RECURSIVE_RUN_FIRST_FAIL, and the logs need grep -a.

What is deliberately NOT claimed

Both "open confirmation" links are now closed — the port landed and main
produces runs. But a run existing is not a run turning green. The
operator-visible confirmation required by the card is still outstanding: no main
push Full Suite run has turned green since Runfusion#1396 on 2026-07-26. This PR does not
assert that confirmation.

The census inventory is unchanged and re-verified: 234 FAIL lines / 233
named cases / 117 files, all 233 per-case rows intact. This change corrects the
streak measurement and the method description, not a single disposition.

Diff shape

  • @@ -34,37 +34,92 @@ — the streak/method rewrite.
  • @@ -281,14 +336,16 @@ — confirmation-link and follow-up-family text.

Both hunks are in the document body. No code, no config, no test files.

Relationship to open PR #29 — read before merging both

PR #29 (docs/fusi-020-census-ledger-frame, bd9e25ee6) is complementary, not
superseded
, and this PR does not replace it. The two are siblings off the
same base d3573cca7 and their hunks are disjoint:

base lines touched
PR #29 20–26, 109–120
this PR 34–70, 281–294

PR #29 pins the quarantine-ledger claim to a head_sha frame; this PR pins the
streak count to a dated as-of measurement. They address different sentences and
can merge in either order. They are not a red→green replacement pair.

Merging this PR first is safe: the reviewer's own finding was that both CLEARED
items and the as-of defect are fixed, verified first-hand at these exact refs.

Verification

  • Both commits reproduced byte-identically on the remote object store: blob,
    tree, and commit SHAs all match the locally reviewed values
    (5cd8a4396 → 0e52f1687), with author/committer identity and timestamps
    preserved.
  • Diff base d3573cca7..0e52f1687: +87 / −30, one file.
  • Per-commit: 20/9 then 75/29, one file each.
  • Census tables (234/233/117, and the second totals row 233/117/17) are
    byte-identical to main.

Reviewer

Cleared by Workflow Reviewer (agent-9eac734a) at these refs, verified
first-hand rather than from the author's report.

Refs: 0e52f1687, parent 5cd8a4396, 2 commits off d3573cca7.

…tion links

The census pinned its streak head to Runfusion#3158 / 1762 red. Re-measured
2026-09-29: Runfusion#3162 is the last completed red run and Runfusion#3163 is in
progress, so the completed streak is 1766 (total_count 1767), with
Runfusion#1396 (2026-07-26T04:14:37Z) still the last green and zero successes
since.

Also corrects three claims that measurement falsified:

- The "frozen at Runfusion#3158" reading was an artifact of reading the head of
  a >1700-run result set off a per_page=100 page. Runs Runfusion#3159-Runfusion#3163 have
  landed since, all failures, so the lane is still exercised. Replaced
  with the trap that produced it, plus a note that the list endpoint can
  return an inconsistent snapshot across per_page values.
- The method line described only the engine shards' FAIL shape. Verified
  against run Runfusion#3162's logs: the project column is a vitest project name
  present only in shards 1/2, the CLI shard puts a pnpm stream prefix
  before FAIL, and core has no column at all. A project-column-only
  parser reads 217 of 233 cases and drops shard 4/4 without erroring.
  Also recorded that bare substring FAIL matches ACTION_FAILED,
  SCREENSHOT_FAILED and ERR_PNPM_RECURSIVE_RUN_FIRST_FAIL, and that the
  logs need grep -a.
- "Two open links" are both closed (the port landed; main now produces
  runs), so the operator-visible surface exists and is exercised while
  the lane stays red. A run existing is not a run turning green; the
  green-run confirmation is still outstanding.

Census inventory is unchanged and re-verified: 234 FAIL lines / 233
named cases / 117 files, 233 per-case rows intact.
The headline asserted 1766 consecutive red runs in the present tense, so the
figure read as a property of the lane rather than a reading taken at a moment.
It is not: every main push extends the streak, and the count was already 1770
at 2026-09-29T08:13Z when re-measured with the doc's own command. A reader who
copies the number forward states a falsehood -- the doc's own three-traps
block warns about exactly this class of stale measurement.

Re-measured head: Runfusion#3166 (a6e65a5, 2026-09-29T07:29:40Z) is the last
completed red run, Runfusion#3167 was in_progress, status=success is still 0 across the
window. Restate 1770 as a dated measurement, require the as-of run number and
timestamp whenever the streak is quoted, and name the non-drifting part of the
claim (zero successes since Runfusion#1396) as the durable fact.

Census untouched: 234 FAIL lines / 233 named cases / 117 files.
@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

4589 finding(s)

HIGH/CRITICAL: 43 | MEDIUM: 4035 | LOW: 511

Severity Rule Location
HIGH secret-database-url .github/workflows/full-suite.yml:55
HIGH secret-generic-credential .github/workflows/full-suite.yml:56
HIGH secret-database-url .github/workflows/full-suite.yml:284
HIGH secret-generic-credential .github/workflows/full-suite.yml:285
HIGH secret-database-url .github/workflows/full-suite.yml:324
HIGH secret-generic-credential .github/workflows/full-suite.yml:325
HIGH secret-database-url .github/workflows/pr-checks.yml:221
HIGH secret-generic-credential .github/workflows/pr-checks.yml:222
HIGH secret-generic-credential .github/workflows/release.yml:522
HIGH secret-generic-credential .github/workflows/release.yml:524
HIGH secret-generic-credential .github/workflows/test-release.yml:445
HIGH secret-generic-credential .github/workflows/test-release.yml:447
HIGH secret-generic-credential docs/cli-reference.md:80
HIGH secret-generic-credential docs/signals-connectors.md:34
HIGH secret-generic-credential docs/signals-connectors.md:77
HIGH secret-generic-credential docs/signals-connectors.md:94
HIGH secret-generic-credential docs/signals-connectors.md:117
HIGH secret-generic-credential docs/signals-connectors.md:159
HIGH secret-generic-credential packages/cli/STANDALONE.md:71
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:12
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:30
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:31
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:102
HIGH secret-database-url packages/core/src/postgres/credential-redact.ts:103
HIGH secret-generic-credential packages/core/src/postgres/embedded-lifecycle.ts:843
HIGH secret-database-url packages/core/src/postgres/embedded-lifecycle.ts:1574
HIGH secret-database-url packages/core/src/postgres/pg-backup.ts:756
HIGH js-ssrf-outbound-request packages/dashboard/app/public/sw.js:651
HIGH js-ssrf-outbound-request packages/dashboard/app/public/sw.js:727
HIGH js-host-header-trust packages/dashboard/src/cli-session-ws.ts:81
HIGH js-host-header-trust packages/dashboard/src/cli-session-ws.ts:115
HIGH js-ssrf-outbound-request packages/dashboard/src/routes.ts:1858
HIGH js-host-header-trust packages/dashboard/src/server.ts:2689
HIGH js-host-header-trust packages/dashboard/src/server.ts:2714
HIGH js-host-header-trust packages/dashboard/src/server.ts:3025
HIGH js-host-header-trust packages/dashboard/src/server.ts:3193
HIGH secret-slack-webhook plugins/examples/fusion-plugin-notification/README.md:46
HIGH secret-database-url scripts/pg-test-server.mjs:200
HIGH secret-database-url scripts/pg-test-server.mjs:231
HIGH secret-database-url scripts/pg-test-server.mjs:241
HIGH secret-generic-credential scripts/sync-fusion-skill-tools.mjs:550
HIGH secret-generic-credential scripts/verify-windows-elevated-restricted.mjs:81
HIGH secret-generic-credential scripts/verify-windows-encoding-recovery.mjs:41
MEDIUM redos-nested-quantifier docs/agents.md:1710
MEDIUM insecure-temp-file docs/solutions/test-failures/main-full-suite-census-2026-09-25.md:433
MEDIUM insecure-temp-file docs/solutions/test-failures/main-full-suite-census-2026-09-25.md:434
MEDIUM insecure-temp-file docs/solutions/test-failures/main-full-suite-census-2026-09-25.md:598
MEDIUM insecure-temp-file packages/cli/src/__tests__/bin.test.ts:136
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:33
MEDIUM insecure-temp-file packages/cli/src/__tests__/dev-with-memory-lib.test.ts:34

…and 4539 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant