Follow-up to #1025 / #1033. Not a defect in #1033 — that gate is a clear improvement and catches the recurring shell-function class cleanly. This records two variants it does not catch, so the gap is not assumed closed.
How this was found
The prior session's handoff recorded that #1033's gate, executed against #1024's corrupted content, blocked "both the shell duplicate and the AGENTS.md heading duplication." Re-running the gate at #1033's head 47778d92 against #1024's actual tree (663a334a), only the shell duplicate is reported:
::error::Duplicate top-level declarations found — the #1485 corruption class.
- `./scripts/compliance-audit.sh` — duplicated top-level function declarations:
- `ensure_required_labels` (declared 2 times)
Running it against only AGENTS.md + standards/ci-standards.md from that same tree reports nothing, while both files demonstrably carry duplicates.
Gap 1 — duplicated deep (####) Markdown headings are not detected
#1024's AGENTS.md carries #### Pull Request Limits (automation open-PR cap) at both line 599 and line 1091. The gate reports nothing; it appears to consider only top-level headings.
Note the constraint that makes this non-trivial: repeated headings under different parents are legitimate Markdown and are live on main today — AGENTS.md ### Agentic Directives ×3 and standards/ci-standards.md #### Adopting in a new repo ×2. The gate correctly passes main today, and must keep doing so. So the fix is not "flag all repeated headings" — it needs to key on the heading's full ancestor path, or on adjacency/near-duplication of the section body.
Gap 2 — duplicate YAML keys inside fenced Markdown blocks (highest blast radius)
#1024's standards/ci-standards.md emits the claude-issue: job key twice (lines 926 and 961), both inside the ```yaml fence opened at line 865. Fenced blocks are deliberately skipped — correct for prose examples — so this can never be caught by the current design.
This is the variant that matters most: standards/ci-standards.md is the template adopting repos copy their workflows from. A duplicate YAML mapping key makes the resulting workflow unparseable, so a corruption here propagates fleet-wide as broken CI in every repo that syncs the stub. It is the highest-blast-radius form of the #1485 class and it is currently unguarded.
Acceptance criteria
Not in scope
Widening to arbitrary structural duplication. The three concrete shapes actually observed in this corruption class are: duplicated shell functions (caught today), duplicated Markdown sections, and duplicated YAML keys.
Related: #1025, #1033, #1024, #1039, #1040, #1485, petry-projects/.github-private#1520, petry-projects/.github-private#1609.
Follow-up to #1025 / #1033. Not a defect in #1033 — that gate is a clear improvement and catches the recurring shell-function class cleanly. This records two variants it does not catch, so the gap is not assumed closed.
How this was found
The prior session's handoff recorded that #1033's gate, executed against #1024's corrupted content, blocked "both the shell duplicate and the
AGENTS.mdheading duplication." Re-running the gate at #1033's head47778d92against #1024's actual tree (663a334a), only the shell duplicate is reported:Running it against only
AGENTS.md+standards/ci-standards.mdfrom that same tree reports nothing, while both files demonstrably carry duplicates.Gap 1 — duplicated deep (
####) Markdown headings are not detected#1024's
AGENTS.mdcarries#### Pull Request Limits (automation open-PR cap)at both line 599 and line 1091. The gate reports nothing; it appears to consider only top-level headings.Note the constraint that makes this non-trivial: repeated headings under different parents are legitimate Markdown and are live on
maintoday —AGENTS.md### Agentic Directives×3 andstandards/ci-standards.md#### Adopting in a new repo×2. The gate correctly passesmaintoday, and must keep doing so. So the fix is not "flag all repeated headings" — it needs to key on the heading's full ancestor path, or on adjacency/near-duplication of the section body.Gap 2 — duplicate YAML keys inside fenced Markdown blocks (highest blast radius)
#1024's
standards/ci-standards.mdemits theclaude-issue:job key twice (lines 926 and 961), both inside the```yamlfence opened at line 865. Fenced blocks are deliberately skipped — correct for prose examples — so this can never be caught by the current design.This is the variant that matters most:
standards/ci-standards.mdis the template adopting repos copy their workflows from. A duplicate YAML mapping key makes the resulting workflow unparseable, so a corruption here propagates fleet-wide as broken CI in every repo that syncs the stub. It is the highest-blast-radius form of the #1485 class and it is currently unguarded.Acceptance criteria
.githubmainand.github-privatemainstill pass — verify explicitly againstAGENTS.md### Agentic Directives×3 andci-standards.md#### Adopting in a new repo×2. A gate that turnsmainred is worse than no gate.```yaml/```ymlblocks in Markdown are detected, at least for repeated keys at the same indentation within one fence. Prose fences (bash,text, untagged) stay exempt.AGENTS.md(#### Pull Request Limits×2) andci-standards.md(claude-issue:×2) must both fail the gate; the currentmaincopies of both files must pass.Not in scope
Widening to arbitrary structural duplication. The three concrete shapes actually observed in this corruption class are: duplicated shell functions (caught today), duplicated Markdown sections, and duplicated YAML keys.
Related: #1025, #1033, #1024, #1039, #1040, #1485,
petry-projects/.github-private#1520,petry-projects/.github-private#1609.