# Silent divergence: what the operating system does without telling you

Run 28 September 2026. 24 probes, POSIX shell on both arms, so the shell dialect is held
constant and anything that differs belongs to the operating system and its filesystem.
No model, nothing billed. Raw records in `L-bash.silent.json` and `W-gitbash.silent.json`.

Nothing was hardcoded as expected. Several of these I did not know the answer to, and an
invented expectation would have been a guess dressed as a control. Each arm recorded what
actually happened and Linux was taken as ground truth afterwards.

## The result

| | |
|---|---|
| Probes | 24 |
| Identical on both arms | 18 |
| **Diverged silently, exit 0 on both sides** | **6** |
| Failed loudly on Windows | **0** |

**Zero and six is the finding.** Hold the shell constant and the operating system never once
announces a difference. It does not refuse, it does not warn, it does not return non-zero.
It does something else and reports success.

That is the opposite of the failure mode the study was designed to count. A failure rate, a
retry counter and a turns-to-completion figure would all have shown these 24 probes as clean
on both platforms.

## The six

**1. Two files become one, and the first one's contents are gone.**
Write `one` into `Beta.txt`, write `two` into `beta.txt`, read `Beta.txt` back.
Linux returns `one` and counts 2 files. Windows returns `two` and counts 1.
The second write destroyed the first. Nothing said so.

**2. `cd` into the wrong case works.**
`mkdir RealDir` then `cd realdir`. Linux refuses. Windows enters.
An agent can hold a path that is wrong and have it keep working, until the day the same
string is used somewhere case matters, at which point the failure appears far from its cause.

**3. `ln -s` does not make a symlink. It makes a copy.**
Linux reports `symlink`. Windows reports `copy`.
The command succeeds either way. The agent believes it created a link, so it believes edits
to the target will be visible through it. They will not. Two files now drift apart silently,
and every subsequent read of either one is plausible and wrong.

**4. `chmod` is a no-op, and `ls -l` confirms the lie.**
`chmod 600 f` then `ls -l`. Linux shows `-rw-------`. Windows shows `-rw-r--r--`.
The permission was not applied, `chmod` returned 0, and the very command an agent would use
to verify the change reports the old mode. This is the one to worry about for anything writing
a key, a token or a config file it intends to restrict.

**5. `sed -i` rewrites the line endings of the whole file.**
A CRLF file of 6 bytes, after `sed -i "s/a/x/"`, is 6 bytes on Linux and **4 on Windows**.
The edit asked for one character. It also converted every line ending in the file. On a real
repository that is a diff touching every line, attributed to a one character change.

**6. The same `grep` gives the opposite answer.**
`grep -c "abc$"` against a CRLF line returns **0 on Linux and 1 on Windows**.
Both are defensible: on Linux the line genuinely ends `abc\r`, so the anchor does not match.
The point is not which is right. The point is that a text-matching decision, the kind an agent
makes constantly to decide whether an edit is needed, silently inverts between platforms.

## Why this reframes the paper

The study was built to measure failures, reissues and turns. Those measures are still worth
having, and the first oracle showed they are dominated by the shell rather than the operating
system: 97.4% against 26.3% on one machine.

**But the operating system's contribution does not live in that column at all.** It is six
commands that worked, returned zero, printed nothing to stderr, and left the machine in a
state the agent has no reason to doubt. Three of the six corrupt something: a file's contents,
a file's permissions, or every line ending in a file. One of them, the symlink, leaves behind
a plausible copy that will keep being read as though it were live.

**This is a class no counter reaches, and it needs its own detector.** Not a failure rate: an
acceptance script that reads what is actually on disk and compares it against what the
transcript claims was put there, and a count of the disagreements. That measure is now in the
plan as outcome 5, and family F of the task suite exists to walk an agent into two of these
traps deliberately and grade whether it noticed.

## What is not claimed

These are properties of the environment, established without a model. **They say nothing yet
about whether an agent falls into them.** A capable model may check `ls -l` after `chmod` and
spot the discrepancy, may know that MSYS2 copies instead of linking, may avoid case variants
entirely. Whether it does is exactly what the 104 session run is for, and it is the only
question left that costs anything to answer.

The 18 probes that matched are worth as much as the 6 that did not, and they are recorded in
full rather than summarised away: trailing dots and spaces, reserved device names, colons in
filenames, deleting and overwriting open files, 20 level deep paths, unicode filenames, hard
links, the exec bit, read only deletion and binary through a pipe all behaved identically.
**Windows is not broadly strange. It is strange in six specific places, and it is quiet in
all six.**
