You started the free model lane at 11:52.
The patch looked clean, so you applied it locally.
By 19:10 the failing log existed only on the remote box.
That loss was a records problem, not a clever bug.
Three missing checks ate the rest of your day.
This letter hands you the workflow before the first call.
This scene is a reconstructed failure mode for teaching.
It is not a measured incident from a named customer.
Do not treat those clock times as collected telemetry.
The three missing checks
You skipped a lane id, a role rule, and a diff contract.
Each skip looked small in the moment you made it.
Together they made the evening impossible to reconstruct.
Mistake 1: the lane had no name
You saved two patches under the same file name.
One patch came from the free model lane.
The other came from a local model path.
Hours later both files were still called fix.diff.
You could not say which lane wrote which hunk.
You spent the afternoon re-prompting both lanes again.
A lane id is a short token you choose yourself.
It is not the vendor model name itself.
Keep that id stable for the whole attempt.
Write the id into a manifest before any prompt.
An empty lane field is a failed start.
Do not downgrade that failure into a warning.
Where the free options fit
Disclosure: This article was prepared as part of MonkeyCode's product outreach.
MonkeyCode enters this workflow at two stated points.
The operator supplied a free model access option.
The operator also supplied a free server option.
Use the free model lane as one named lane.
Use the free server only as an executor.
Read the current docs before you rely on either option.
This letter does not state quotas, hardware, or duration.
Those facts change, and this draft does not verify them.
If a page lists limits, trust that page over this letter.
Mistake 2: the box kept the only log
You treated the free server disk as durable storage.
The workflow role for that box is executor.
An executor may vanish without taking your archive with it.
This letter does not claim the server always resets.
It claims your process must survive if the box does.
Unique evidence belongs in the local store of record.
You left fail.log only on the remote box.
The session closed, and the log closed with it.
Your laptop held the patch and none of the evidence.
Copy artifacts back before you end the session.
Keep the prompt, the manifest, and the log locally.
Leave the remote box with no unique files.
If the copy fails, do not send a second prompt.
A second prompt without the first log stacks confusion.
Stop there, restore the log, and then decide.
Mistake 3: the diff was graded by eye
You read two diffs and called them close enough.
Close enough is not a contract you can rerun.
A full working day hid inside that one adjective.
List the files that the two lanes must match.
Hash each listed file with a SHA-256 digest.
Fail the attempt when any listed digest differs.
Do that check before you debate names or style.
Keep this file comparison contract mechanical on purpose.
Taste and naming come after the hashes agree.
Steps before the next prompt
Follow these steps in the order written below.
- Create a local runs directory inside the repo.
- Put the exact prompt text into a file named prompt.txt.
- Init a manifest with the lane id you chose.
- Set the remote server role field to executor.
- Run the already stamped job on the free server.
- Copy logs and diffs back into the local repo.
- Bind each returned file hash into the manifest.
- Check the contract against the other lane tree.
Do not skip from the stamp step to the remote run.
The stamp is the point of this whole sequence.
A remote run without a manifest repeats the old mistake.
Proposed stamp script
Save the script as lane_stamp.py at the repo root.
It uses only the Python 3 standard library.
It does not call a model or open a socket.
Use Python 3.9 or newer for this file.
This script is a proposal for you to run locally.
It was not executed against a live service in this draft.
Verify the output on your machine before you trust it.
A green local run still is not a live product test.
Keep that distinction in the manifest notes you store.
#!/usr/bin/env python3
"""Proposed lane stamp. Not executed in this draft."""
import argparse
import hashlib
import json
import sys
from datetime import datetime, timezone
from pathlib import Path
RUNS = Path(".runs")
def sha256(path: Path) -> str:
digest = hashlib.sha256()
digest.update(path.read_bytes())
return digest.hexdigest()
def now() -> str:
return datetime.now(timezone.utc).strftime("%Y-%m-%dT%H:%M:%SZ")
def init_run(lane: str, role: str, prompt: Path) -> None:
if not lane.strip():
sys.exit("lane id is required")
if role != "executor":
sys.exit("server role must be executor")
if not prompt.is_file():
sys.exit("prompt file is missing")
RUNS.mkdir(exist_ok=True)
run_id = now().replace(":", "").replace("-", "")
manifest = {
"run_id": run_id,
"lane": lane,
"role": role,
"store_of_record": "local",
"prompt_sha256": sha256(prompt),
"started_at": now(),
"artifacts": [],
}
path = RUNS / f"{run_id}.json"
path.write_text(json.dumps(manifest, indent=2) + "\n", encoding="utf-8")
print(path)
def bind_artifact(manifest_path: Path, artifact: Path) -> None:
if not artifact.is_file():
sys.exit("artifact must be a local file")
data = json.loads(manifest_path.read_text(encoding="utf-8"))
if data.get("store_of_record") != "local":
sys.exit("store of record must stay local")
data["artifacts"].append(
{
"path": str(artifact),
"sha256": sha256(artifact),
"bound_at": now(),
}
)
manifest_path.write_text(
json.dumps(data, indent=2) + "\n",
encoding="utf-8",
)
print(manifest_path)
def check_contract(left: Path, right: Path, names: list) -> None:
mismatches = []
for name in names:
a = left / name
b = right / name
if not a.is_file() or not b.is_file():
mismatches.append(name + ":missing")
continue
if sha256(a) != sha256(b):
mismatches.append(name + ":hash")
if mismatches:
print("\n".join(mismatches))
sys.exit(1)
print("contract ok")
def main() -> None:
parser = argparse.ArgumentParser()
sub = parser.add_subparsers(dest="cmd", required=True)
p_init = sub.add_parser("init")
p_init.add_argument("--lane", required=True)
p_init.add_argument("--role", required=True)
p_init.add_argument("--prompt", type=Path, required=True)
p_bind = sub.add_parser("bind")
p_bind.add_argument("--manifest", type=Path, required=True)
p_bind.add_argument("--artifact", type=Path, required=True)
p_check = sub.add_parser("check")
p_check.add_argument("--left", type=Path, required=True)
p_check.add_argument("--right", type=Path, required=True)
p_check.add_argument("--files", nargs="+", required=True)
args = parser.parse_args()
if args.cmd == "init":
init_run(args.lane, args.role, args.prompt)
elif args.cmd == "bind":
bind_artifact(args.manifest, args.artifact)
else:
check_contract(args.left, args.right, args.files)
if __name__ == "__main__":
main()
Command sequence
Run init before you send the prompt anywhere.
Use the manifest path that the init command prints.
Bind logs only after they exist on local disk.
Create both lane trees before you run the check command.
Point check at two local trees, not at the server.
Pass the file names that the contract must cover.
The check command fails until both trees contain app.py.
A non-zero exit means you stop and keep both trees.
Read the printed token before you edit either tree.
mkdir -p artifacts/free-model artifacts/local-model
printf '%s\n' "Fix the null check in parse()." > prompt.txt
MANIFEST=$(python3 lane_stamp.py init --lane free-model --role executor --prompt prompt.txt)
python3 lane_stamp.py bind --manifest "$MANIFEST" --artifact artifacts/free-model/app.py
python3 lane_stamp.py check --left artifacts/free-model --right artifacts/local-model --files app.py
How to read a failed check
A missing line means one tree never received the file.
A hash line means both files exist and differ.
Do not open a third lane until you name that cause.
Example manifest shape
Treat this JSON as a shape, not a captured run.
Your init command should print a file like it.
The hashes below are placeholders, not live measurements.
{
"run_id": "example",
"lane": "free-model",
"role": "executor",
"store_of_record": "local",
"prompt_sha256": "<sha256>",
"started_at": "<utc>",
"artifacts": []
}
Decision table
| Gate | Pass | Fail | Action |
|---|---|---|---|
| Lane id | Non-empty token | Blank or missing | Stop before the prompt |
| Server role | executor | store or unset | Stop before the prompt |
| Unique log | Local copy exists | Remote copy only | Copy the log, then stop |
| File contract | Digests match | Missing file or hash mismatch | Keep both trees |
A pass on all four gates allows a patch review.
A fail on any gate blocks the merge.
Human review never substitutes for a failed gate.
What the hashes miss
Equal hashes mean the listed files have equal bytes.
They do not mean the program behavior is acceptable.
Run your existing tests after the contract passes.
Different hashes can still be semantically fine later.
The contract will flag a comment-only change too.
That flag is a stop for review, not a quality verdict.
The stamp does not remove secrets from a prompt.
A hashed secret is still a secret you already sent.
Keep tokens and keys out of prompt.txt entirely.
This script does not fence raw shell commands.
Pair it with the command allowlist you already keep.
This letter does not replace that older control.
Who should skip this
Skip this if you need a published benchmark today.
This harness records provenance, not model quality scores.
It will not tell you which lane writes better code.
Skip this workflow if policy forbids any remote execution.
A free server option does not override a written policy.
Stay on a local executor until that policy changes.
Skip this if you would park credentials on the box.
The workflow treats the remote disk as untrusted storage.
Untrusted storage is a poor place for long-lived keys.
Skip this if you want a ranking of named models.
No model names are recommended anywhere in this letter.
Pick the lane your current docs actually list.
Limits to say out loud
Free model access can be rate limited on a given day.
This letter intentionally states no token quota at all.
Check the live product page for the number you will use.
A free server may differ from your laptop image.
Installed packages, clocks, and paths can all diverge.
Do not debug that kind of drift from memory alone.
Write the interpreter version into a local env.txt file.
Bind env.txt with the same manifest bind command.
That note explains many false product bugs later.
Earlier letters in this series covered other controls.
This one does not restate the test-first gate.
This one does not restate the tool-trace replay.
Use those controls beside this stamp, not instead of it.
Overlap is fine when the records stay distinct.
A second copy of an old letter helps nobody.
Before the next prompt
Start the next attempt with a fresh runs directory.
Stamp the lane id, and only then send the prompt.
Let the free server execute the job you already stamped.
Bring every unique file home before you disconnect.
Check the file contract, and only then read the diff.
Ship the patch only when both the contract and tests pass.
If you already use the free model lane, run this stamp once.
Keep the JSON beside the patch you intend to review.
That file is the receipt your 11:52 self never kept.
Top comments (0)