Skip to content
[bmdpat]
All writing
5 min read

My P0 decision expired while the doctor showed red

On 2026-09-28, a pending secret rotation expired, 1 suite file failed out of 555, and commit 000b3235f fixed discovery so showwork 0.6.5 could ship to PyPI.

Share LinkedIn

A credential decision expired on 2026-09-28 while my test suite stayed red. The gate failed. My authority secret stayed open. I had 0 automated fallback when that timer lapsed. The nightly queue sweep for 2026-09-27 finished overnight with sequential dispatch and 0 subagents. Leaving BMD_BRAIN_AUTHORITY_SECRET unrotated broke the security loop. I must fix it.

Key decisions from My P0 decision expired while the doctor showed red

Why did my P0 decision expire?

My automated decision loop failed to trigger a response before the timer ran out on 2026-09-28. The timer died. That lapse left BMD_BRAIN_AUTHORITY_SECRET exposed without rotation. When automated gates stall, pending security decisions sit open until someone writes the reason down by hand.

The digest for 2026-09-28 processed 84 items. The pipeline rejected 68 items and failed on 2 items, while 14 items went wiki-only. It felt quiet. Meanwhile, SecurityAnalyst returned a GREEN verdict with 0 P0 issues, 0 P1 issues, and 10 P2 issues. That looked clean on paper. It was hollow. Two scanners had covered exactly 0 repositories. A green flag on 0 scanned repos means nothing.

Silence was the danger. I cannot leave BMD_BRAIN_AUTHORITY_SECRET hanging when an automation run fails to trigger a response. The secret remained active on disk. When you use BMD, see what your agents actually did, you notice where execution halted. I saw the gap. For 2026-09-29, the plan is to rotate that secret and write 1 line of reasoning into the Request file.

How did 43 passing tests hide a broken suite?

Targeted test passes mask broken files by shrinking the evaluation window on 2026-09-28. The doctor stayed red. Two focused test files passed completely, but 1 test file out of 555 still failed. A narrow pass hides wide failures.

Brain worker ran targeted checks on 2026-09-28. In config/brain_core/test_brain_core.py, 40 tests passed out of 40. In config/test_suite_durability.py, 3 tests passed out of 3. Those 43 tests completed in 88.59s. I checked the disk. Vault test failures had resolved on disk, so I updated supervisor-suite-failures-20260927.md to reflect that clean state. The boundary looked solid.

Step outside the boundary and the picture changes. The full suite still recorded 1 failed file out of 555 files. I do not trust a narrow slice. A passing subset does not make a whole system green. You need to verify what an agent actually produced before trusting its summary. What check caught a false pass in your own runs?

What shipped after commit 000b3235f fixed discovery?

Commit 000b3235f skipped .codex, site-packages, and git-ignored paths on 2026-09-28. That unblocked showwork 0.6.5. The package shipped to PyPI with release copy rewritten in plain language. It also let test_pypi_reporter.py verify 17 passing tests without choking on vendored directories.

Discovery had choked on vendored files before that fix landed. The fix cleared the path. Brain worker archived 6 session-dupe cards tied to the showwork 0.6.5 release cluster. Next, test_pypi_reporter.py verified 17 out of 17 tests. That allowed updating pypi_reporter.py and removing stale claims from daily-artifacts-assert-an-agentguard-push-pause-that-ended-20260924.md and Prompts/Daily/morning brief.md.

Overnight triage on 2026-09-28 identified 4 doable tasks: 2 completed and 2 remain. Then Reports/Downloads/pypi-2026-09-28.md generated with a neutral footer. Files hold state. When coordination breaks across sessions, give an agent a file, not a memory. Files leave clear traces on disk.

The table below tracks the verified test passes against the overall test suite for 2026-09-28:

Suite AreaTarget File or PathTests RunResult
Brain Coreconfig/brain_core/test_brain_core.py4040 passed
Durabilityconfig/test_suite_durability.py33 passed
PyPI Reportertest_pypi_reporter.py1717 passed
Full Workspace555 suite files5551 failed file

The first-use work gave readers paths from articles to runnable examples. Its 1 report kept outside adoption unknown on 2026-09-28. Package requests and test runs show activity without proving return visits. I need that distinction.

The blog reached its public page at 09:52 CT on 2026-09-28, after failed publication and repair attempts. Gemini handled the recorded QA. The later healer report said already healthy, but 1 run ledger kept the earlier failures. Both belong in the story.

Brain Worker corrected stale AgentGuard reporting and confirmed 43 focused tests passed on 2026-09-28. The broader suite still recorded 1 failed file out of 555. SecurityAnalyst called its result green after 2 scanners covered 0 repositories. I cannot use an empty scan as proof.

The record for 2026-09-28 gives me useful work and unfinished checks in 1 place. That is a more usable account of what I own.

What should you do with this?

Inspect your automated gates on 2026-09-28 before trusting passing verdicts. Verify that test runners exclude vendor directories, check whether credentials expire silently, and log failed files explicitly. Three concrete steps will isolate these issues in your local setup.

  1. Filter test discovery paths. Add .codex, site-packages, and .git to discovery ignore rules in commit 000b3235f style so 0 vendor files get scanned.
  2. Log open decisions to disk. Set an alert on pending credentials like BMD_BRAIN_AUTHORITY_SECRET so 1 expired timer raises an error instead of stalling silently.
  3. Count the full suite denominator. Record the total file count, such as 1 failed file out of 555, instead of relying on 43 passing unit tests.

Accompanying prompt

What the prompt does: Audits a repository test configuration to exclude vendor directories and report uninspected failure files.

Copy/paste this prompt:

Copy-ready prompt

Paste the exact block into your coding agent.

No article chrome, no footnotes, no formatting drift.

Role: Test Infrastructure Engineer Context: Test runners can pull in vendor packages, virtual environments, or git-ignored directories, skewing suite metrics and hiding genuine test failures. Inputs: - Repo path: __ - Test command: __ - Ignored directory names: __ Task: 1. Inspect the configuration for the specified Test command in Repo path. 2. Verify that Ignored directory names like vendor, site-packages, and cache directories are explicitly excluded from discovery. 3. Run Test command across Repo path and count both passing checks and total suite files. 4. Flag any file that fails or skips execution during the discovery pass. Output: - A list of excluded directories added to the configuration. - A pass/fail summary showing passing test count and total file denominator. Constraints: - Do not modify production source code outside test configuration files. - Report all skipped files explicitly without omitting errors.
24 lines937 chars
Ready

This prompt and every other one we publish live in the free prompt library.

Copy the block above.

Weekly measured local runs: https://bmdpat.com/5090-reports

Get the Local AI Field Kit

Four copy-ready tools now, then one evidence-backed Local AI Lab Note on Friday when there is something worth sharing.

Try the free agent run check first

Get the requested artifact now, then at most one evidence-backed Local AI Lab Note on Friday when there is something worth sharing. One-click unsubscribe. No sponsored placements. Privacy.

PH

Patrick Hughes

I build BMD and publish measured AI runs, failure reports, and reusable checks. Nashville, Tennessee.

More writing