HapaxResearch Lab

Method, with dated incidents

How this estate decides whether an agent's output is warranted

This document describes the method the estate applies before it treats an AI agent’s output as warranted, and it illustrates each part of the method with dated incidents from the estate’s own review record. It is a draft. Before publication it goes to a hostile-reader panel, which is a separate step. The sources for the claims below are listed in the claims-and-sources table at the end. The estate’s operator is identified here only as h:rlk.

1. The question the method answers

The estate runs many AI agents, drawn from several model families, on real work: code, review, coordination and publication. An agent’s output is treated as unwarranted until specific checks pass. This document describes those checks as they operated on the dates cited.

2. The method

2.1 Work proceeds against a written exit predicate and a declared scope

Each unit of agent work is bound to a task row that carries an exit predicate, meaning the conditions under which the work counts as done, the list of paths the work may mutate, and route metadata describing the risk of the change [S1]. A lane claims one task at a time through a claim tool, and the row records who claimed it and when [S1].

2.2 Review is independent and spans model families

A change is reviewed by a panel of reviewer seats drawn from more than one model family. In the incidents cited here, the seats included models from the Claude, Codex, Gemini, GLM and Muse families [S4][S6][S8]. A review round is expected to see the whole change. When a round for pull request #4784 was at risk from the diff’s size, the change was split so that each of the three seats received the full diff of 62,463 bytes [S3][S4].

2.3 Review and release bind to an exact head

Reviews, release stamps and merges bind to the full SHA of one exact head. Pull request #4784 was merged at its reviewed head 378836af9 [S4][S5]. On #5019, before a release act, the lane verified that the stamped head matched the live pull-request head and found no drift [S1]. When the head changes, the change is reviewed again at the new head, as happened with #4793 at bb3872aee [S7].

2.4 The writer does not accept its own work

Acceptance requires reviewers from families other than the writer’s family. The writer of #5019 is from the Claude family, so its release basis was that the Gemini and GLM seats accepted independently [S1]. Lanes record “independent review by a family other than the writer” as an obligation owed before merge [S18][S19].

2.5 Findings are dispositioned against their exact text, and measurement decides disputes

A reviewer’s finding is either confirmed and fixed, or refuted with evidence. Refutation is done by measurement: a search of the diff, a linter run, a probe of the actual mechanism, or a test that goes red when the claimed defect is introduced and green when it is absent [S3][S8][S9][S12]. A finding that a reviewer stops repeating remains open until it is dispositioned. The review lane’s record states this as: “A reviewer not repeating a finding is not a fix” [S7]. When the review lane has measured a finding as refuted but the dossier still carries it, the lane reports and does not rule it away itself; the disposition goes through a governed path [S12].

2.6 A degraded quorum is witnessed and owes repair

When a reviewer family is unavailable, a round can close as a degraded quorum-accept. The accept then rests on families independent of the writer, the absence and its cause are recorded in a ledger, a witness with a fixed expiry time stands over the release, and a re-review by the missing family is owed once it recovers. This occurred for #5019 while the Codex family was walled: Gemini and GLM accepted, the degraded-merge ledger carries the record, and the Codex re-review is owed [S1].

2.7 Gates fail closed

The release machinery refuses to act when it cannot assess what it is looking at. Route metadata that fails validation blocks a release arm with the reason route_metadata_unassessable [S13][S14]. A risk flag whose mitigation check is not defined fails closed and is, in the source’s own words, never released by a manual override [S15].

3. Exemplars from the record

Each exemplar is a dated incident in which the method caught something, or in which the method itself failed and the failure was caught and recorded.

3.1 A containment leak was found and fixed (#4784, 2026-09-28)

The pull request introduced a declared execution envelope for harness jobs. A Gemini reviewer raised a critical: with CLAUDE.md symlinked to .git/CLAUDE.md, the containment check printed “leaked instructions” for both the symlink path and its target. The writer reproduced the leak red first, fixed the masking logic so the resolved target is always masked and named, and mutation-verified the test by restoring the defect, observing red, restoring the exact fixed bytes and observing green; 44 tests passed [S3]. A second claim from the same round, that a carrier crash was possible, was refuted by a probe of the actual sandbox tool rather than by argument [S3]. The pull request merged at its reviewed head on a three-of-three quorum-accept across the Codex, Gemini and GLM seats [S4][S5].

3.2 A false-clean was caught under hold (#4793, 2026-09-28)

The follow-up audit could report a harness clean when filesystem events had been lost: the code read the inotify event mask and never used it, so the overflow condition that signals lost events was undetected. The review lane confirmed the defect on one head, watched a later round return accept verdicts from all three seats at a new head, re-confirmed that the defect was still present, and asked for a hold label because the advisory label on the pull request would not stop the automatic arm from merging it with the false-clean path open [S6][S7].

3.3 Phantom criticals were refuted by measurement (2026-09-27 and 2026-09-28)

In the incidents below, some reported defects did not exist, and the record keeps them as data. On #4826, a Gemini seat raised two criticals claiming that a function “is never called”; the diff itself imports and calls it at named lines, so the claim was refuted by inspection [S8]. On #4829, a Gemini seat raised two “NameError” criticals; the variable is defined before its use, the linter’s undefined-name check is clean at that head, and the reviewer had seen the use without the assignment because its diff hunk was truncated [S9]. On #4893, a GLM seat raised the same missing-symbol critical in three consecutive rounds. The estate changed the dispatcher to include the definitions of named symbols in the excerpts reviewers see (#4898), and on the next round the GLM seat accepted [S10][S11]. A later critical on #4893, claiming that plan mode could still fetch the pull-request head, was refuted by line-level reading of the source and by a mutation-verified test: moving the fetch above the early return turns the test red [S12].

3.4 A wall message was misclassified (#5019, 2026-10-03)

The Codex command-line tool changed its usage-limit message to use a curly apostrophe. The estate’s wall-recognition expression had been written for the older wording, so it missed the new text. In the same incident, the quota reader preferred the newest sample, so a 98-percent reading taken one second after a 100-percent reading won, and the dispatcher kept seating a family that was in fact walled [S1][S2]. The fix accepts both apostrophe forms while keeping the anti-forge anchors, which are process failure, empty model output and whole-text match, and it takes the maximum reading among samples that share the same reset time so that reset detection still works [S1][S2]. Each fix carries a test that was shown red before the fix and green after [S1].

3.5 A seat error was corrected with independent concurrence (2026-10-04)

The coordinating seat stamped #5019 for release while recording a reviewer’s major finding as answered, citing a fact that did not address what the finding actually claimed [S1]. After a challenge, the seat re-read the finding’s exact title, accepted it as valid, and recorded the acceptance and the correction [S17]. The correction stands on independent concurrence: a reviewer lane from a family other than the seat’s fetched the head read-only, recomputed the content hashes of the disputed artifacts, and confirmed that they derive only from the pull request’s own source [S16][S17]. The seat recorded the error in the task row’s log, with a prevention rule: quote a finding’s exact title from the dossier before dispositioning it [S1].

3.6 The release arm refused on route metadata (2026-10-04)

The release machinery refused to arm #5019 three times in one night. The first refusal was a locality value outside the allowed enumeration [S13]. The second was an authority level that the schema forbids for work requiring frontier review [S14]. The third was a risk flag with no defined mitigation gate, which fails closed [S15]. The flag was then re-assessed on its definition: the independent lane traced every consumer of the changed code and showed that no spend path, key or billing route is affected, and the flag was corrected with the basis recorded [S16][S1].

3.7 The privacy scrub read each flagged occurrence (#5024, 2026-10-04)

The estate scanned its public repository for household names. Of three flagged functional files, two carried real exposure and were scrubbed, and one was a false positive: the token matched a public third-party tool author [S18]. Ten flagged documents were then read occurrence by occurrence. Nine were false positives, including a song title, public authors, a publisher imprint and cited researchers, and one was real exposure and was scrubbed [S19]. Reading each occurrence separated the nine false positives from the one real exposure. The regression test reuses the installed matcher rather than embedding name literals, and it was mutation-verified: injecting a registered name turns it red [S18][S19]. The record of this work uses counts only, and so does this document.

4. Scope of this document

This document describes the method as it operated on the dates cited, and the exemplars include cases where the machinery or the seat failed and the failure was caught, because the record includes them. Planned machinery that does not exist yet is not described here.

5. Claims and sources

# Claim (abbreviated) Source
1 Task rows carry an exit predicate, mutation scope and route metadata; one claim at a time; claim and stage events are logged S1
2 Reviewer seats in the cited incidents span the Claude, Codex, Gemini, GLM and Muse families S4, S6, S8
3 #4784 was split so all three seats had full coverage; the merged round delivered 62,463/62,463 bytes S3, S4
4 #4784 merged at reviewed head 378836af9 on a 3/3 quorum-accept (Codex, Gemini, GLM) S4, S5
5 #5019’s stamped head was verified against the live PR head before a release act; #4793 was re-reviewed at a new head S1, S7
6 #5019’s release basis was Gemini and GLM accepting independently of the Claude writer family S1
7 Lanes record independent review by a family other than the writer as owed before merge S18, S19
8 Refutation is by measurement (diff inspection, linter, sandbox probe, mutation-verified tests) S3, S8, S9, S12
9 “A reviewer not repeating a finding is not a fix”; un-dispositioned findings stay open S7
10 The review lane reports refuted-but-carried findings and does not rule them away itself S12
11 #5019 closed on a degraded quorum while Codex was walled; ledger record; Codex re-review owed; witness with an expiry S1
12 Invalid route metadata blocks a release arm (route_metadata_unassessable) S13, S14
13 A risk flag with no defined mitigation gate fails closed and is never manually overridden S15
14 #4784: symlink-into-.git leak found by a Gemini critical, reproduced red first, fixed, mutation-verified, 44 tests passed S3
15 #4784: the same round’s carrier-crash claim was refuted by a bwrap 0.12.0 probe S3
16 #4793: unused inotify mask lets lost events yield a clean verdict; confirmed at two heads; hold requested because the advisory label does not stop auto-arm S6, S7
17 #4826: two “never called” criticals refuted by the diff’s own import and call sites S8
18 #4829: NameError criticals refuted; variable defined before use; linter clean at head; reviewer saw a truncated hunk S9
19 #4893: same missing-symbol critical raised in three consecutive rounds; #4898 added named-symbol definitions to review excerpts; next round accepted by the GLM seat S10, S11
20 #4893: plan-mode-fetch critical refuted by line-level source reading and a mutation-verified test S12
21 #5019: curly-apostrophe wall text missed by a regex written for the older wording; 98%-over-100% sample selection kept a walled family seated S1, S2
22 #5019 fix: both apostrophe forms accepted; anti-forge anchors kept (process failure, empty model output, whole-text match); max within a shared reset window; red-first mutation-verified tests S1, S2
23 The seat recorded a #5019 major as answered by citing a fact that did not address the finding’s claim; corrected after challenge; prevention rule recorded S1, S17
24 The correction stands on independent concurrence: read-only fetch, recomputed hashes, artifacts derive only from the PR’s source S16, S17
25 Three release-arm refusals on #5019 in one night: locality enum, authority level, unmitigable risk flag S13, S14, S15
26 The risk flag was re-assessed on its definition with a consumer trace showing no spend path, key or billing route affected, and corrected with the basis recorded S16, S1
27 #5024: of 3 flagged functional files, 2 real exposure scrubbed and 1 false positive (public third-party tool author) S18
28 #5024: of 10 flagged documents read per-occurrence, 9 false positives (song title, public authors, publisher imprint, cited researchers) and 1 real exposure scrubbed S19
29 #5024’s regression test reuses the installed matcher and is mutation-verified; the record uses counts only S18, S19
30 This draft is governed by the accepted outward path and its redirect; a hostile-reader panel is a separate step S21, S22

Source list

Public pull requests are cited by number in the hapax-systems/hapax-council repository, where anyone can read the diff, the reviews and the merge. The estate’s internal review and coordination records are cited by date and subject; they are kept in the estate’s record and are not published as files.

  • S1: #5019 — the record for the curly-apostrophe wall fix: exit predicate, route metadata, the release-stamp log, and the recorded seat-error correction (2026-10-03 to 2026-10-04).
  • S2: internal review-lane note on the quota-reader latch, 2026-10-03.
  • S3: #4784 — envelope split and leak fix, build-and-review report, 2026-09-28.
  • S4: #4784 — merge report, 2026-09-28.
  • S5: #4784 — merged, review-lane confirmation, 2026-09-28.
  • S6: #4793 — baseline-host exposure, review-lane, 2026-09-28.
  • S7: #4793 — hold: overflow unfixed, review-lane, 2026-09-28.
  • S8: #4826 — phantom-critical review, 2026-09-27.
  • S9: #4829 — phantom-critical review, 2026-09-27.
  • S10: #4893 — force-round, phantom cleared, 2026-09-28.
  • S11: #4898 — merged; #4893 force-queued, 2026-09-28.
  • S12: #4893 — critical repeated against proof, review-lane, 2026-09-28.
  • S13: #5019 — arm blocked: route metadata malformed, 2026-10-04.
  • S14: #5019 — route metadata still malformed (authority level), 2026-10-04.
  • S15: #5019 — arm blocked: risk flags, 2026-10-04.
  • S16: #5019 — independent concurrence: the flag and the finding, 2026-10-04.
  • S17: #5019 — the seat ruling accepting the major finding, 2026-10-04.
  • S18: #5024 — privacy scrub, functional files, 2026-10-04.
  • S19: #5024 — privacy scrub, documents, 2026-10-04.
  • S20: public pull-request record in hapax-systems/hapax-council: #4784, #4793, #4826, #4829, #4893, #4898, #5019, #5024.
  • S21: the estate’s accepted outward-work direction (C1), accepted by the principal on 2026-09-28.
  • S22: the 2026-10-04 redirect that put C1 in force again.