Summary
Reverse-engineered from the tig/xuss-c first ship. Across five unrelated findings the mechanism was identical: agents extend what the plate ships and ignore what the plate only says. Prose in AGENTS.md is not a scaffold; code is.
Three independent confirmations from one product:
| gcu-c plate ships |
xuss-c produced |
host/test_defaults.c, host/test_time.c (2 files) |
exactly those 2, lightly extended — no third test ever written |
main.c implementing only identity |
same function name, same shape, only identity |
plate AGENTS.md: "Escape hatch (repl / reboot) is a product requirement" |
repl and reboot absent |
The plate's prose required the escape hatch; the plate's code implemented one command. The product inherited the code.
Why this one bites hardest
silico inspect knocks identity and nothing else. So the one command silico verifies is the one that got built, and the two it never knocks for are the two that are missing — Goodhart's law on the gate.
The consequence is not cosmetic. xuss-c spec.md §6.2 says "A build without the door fails L1", and §8 has acceptance rows for Link mid-song and Escape hatch. That firmware cannot pass either, while install/README.md records first ship as accepted.
There was a second-order cause too: dispatch lived in firmware/main/main.c, which is device-side and outside the host build — so §2 L0's "protocol parsing" requirement was structurally impossible to satisfy. The plate put the parser on the wrong side of the HAL seam.
Landed in #115
gcu_parse_command / gcu_handle_command move to src/domain.c; main.c only moves bytes
repl parks outputs (new park_outputs HAL hook) and stops the tick driving them; reboot defers the reset so the ack flushes first; unknown input fails closed with a short error
host/test_protocol.c — third test file, covering the escape hatch on the host
Still open (not in that PR)
Non-goals
- Turning product specs into agent-optimized command matrices (#104).
- Making the plate a framework. It should scaffold the shapes that are required, not every shape a product might want.
Summary
Reverse-engineered from the tig/xuss-c first ship. Across five unrelated findings the mechanism was identical: agents extend what the plate ships and ignore what the plate only says. Prose in
AGENTS.mdis not a scaffold; code is.Three independent confirmations from one product:
host/test_defaults.c,host/test_time.c(2 files)main.cimplementing onlyidentityidentityAGENTS.md: "Escape hatch (repl/reboot) is a product requirement"replandrebootabsentThe plate's prose required the escape hatch; the plate's code implemented one command. The product inherited the code.
Why this one bites hardest
silico inspectknocksidentityand nothing else. So the one command silico verifies is the one that got built, and the two it never knocks for are the two that are missing — Goodhart's law on the gate.The consequence is not cosmetic. xuss-c
spec.md§6.2 says "A build without the door fails L1", and §8 has acceptance rows forLink mid-songandEscape hatch. That firmware cannot pass either, whileinstall/README.mdrecords first ship as accepted.There was a second-order cause too: dispatch lived in
firmware/main/main.c, which is device-side and outside the host build — so §2 L0's "protocol parsing" requirement was structurally impossible to satisfy. The plate put the parser on the wrong side of the HAL seam.Landed in #115
gcu_parse_command/gcu_handle_commandmove tosrc/domain.c;main.conly moves bytesreplparks outputs (newpark_outputsHAL hook) and stops the tick driving them;rebootdefers the reset so the ack flushes first; unknown input fails closed with a short errorhost/test_protocol.c— third test file, covering the escape hatch on the hostStill open (not in that PR)
[protocol].requiredinsilico.toml— let a product declare its command surface, and havesilico inspectexercise each entry rather than onlyidentity. This is the actual fix; the plate change just stops the bleeding for new scaffolds.inspectwarning or a failure.silico gateshould flag a product whosespec.mddeclares commands that no host test names (advisory only — see the first-ship: explicit spec-review step for every session (not only under-specified interview) #104 anti-pattern about agent-optimized specs).Non-goals