Skip to content

Daily workspace / Buganizer tracker (review vehicle) - #12387

Closed
briansrls wants to merge 271 commits into
mainfrom
test/main-plus-roadmap-daily
Closed

briansrls wants to merge 271 commits into
mainfrom
test/main-plus-roadmap-daily

Conversation

@briansrls

@briansrls briansrls commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

2026-09-28: Google OIDC login + tracker identity surface + GLM 262K×8 qualification

This is the deployment line (test/main-plus-roadmap-daily) as it stands after the 2026-09-27/28 work. Per-area, in reviewable order:

Human identity (auth)

  • Google OIDC login end-to-end on the tracker: verified ID-token boundary (RS256 signature, issuer/audience/hd/nonce/expiry), PKCE, session store with rotation, CSRF write law. The full defect chain is in the commits (client-id alphabet, clock record binding, percent-decoded auth code, signature byte transport, response headers through the socket).
  • Session profile projection: name/picture/email ride as three optional members (mint → durable session-file codec → /auth/session wire), three-valued decode, never gating. The login claims receipt records which optional profile members the verified token carried, post-verdict, with typed publication.
  • The durable profile projection (C4.2): per-principal profile store, login-produced, merge-retain (omission never erases an observation), the display source for assignee/picker surfaces.
  • Logout 303s home; the account chip is a menu (Switch account via the closed OidcLoginPrompt coproduct = prompt=select_account; Sign out). One client-side session read serves the header swap and inline assignment.
  • The assignee surfaces render the profile identity (name/email/resolved avatar; confirmation text included); the assignee cell truncates inside its track.
  • Plan: docs/plans/google-workspace-identity-convergence.md (Cut 4: Workspace settings as modeled manual-admin obligations with readback; Directory-backed profile source next).

Tracker surface

  • Durable comments + assignment work through the write law; the comment composer carries the session's CSRF at render (synchronizer-token, no-store detail pages); the text/plain form reader strips the browser's CR (the "CSRF mismatch despite live session" defect).

GLM-5.3-Flash group B — the 262K×8 qualification

  • Memory proof: exact hybrid block fold — 6 seats proved, 8 seats = 984/1035 blocks (conditional expectation; the 8-seat verdict must come from the 8-seat candidate's own resolved plan).
  • W1: one cold 262K prefill = 323.16s with zero preemptions, no cohort. NOT established: compute-bound, immutability.
  • W2 (cache-reuse qualification, four legs): replay 2.47s, suffix 3.38s, miss 309.7s cold — prefix/state reuse is real and general; the engine's cached_tokens counter is blind to the hybrid-cache hits (located instrumentation fact).
  • Root cause of every churn-phase death: the engine units' RuntimeMaxSec reused the 3600s ready timeout as the whole-run lifetime — a deliberate SIGTERM mid-churn. The admitted runtime now derives the whole sequence (10180s at the largest subject). Earlier layers disproved along the way: harness cross-run staleness (fd7cde5), concurrent >500KB request bodies silently closed (flock serializer, repro obligation open), the sampler tail backstop vs the flock queue (window-bounded skip).
  • The workload registry: 5 matrix repro variants + w1 (attribution) + w2 (cache reuse) + q (eight-seat closing), per-variant declared budgets, timing TSV + /metrics deltas on every seat, phase-long stall watchdog (capture-only, never a verdict).
  • Plans: docs/plans/glm-group-b-workload-qualification.md (frozen objective: qualified 262K×8; unified single-execution closing qualification; deployment gate vs follow-on table; W1b follow-up not a blocker).

Honest notes

… declares

The witness asserted 1 from before the test merge, while #11617 landed
serving_group_b_route_turn_ceiling at 4 (matching group A's allocation reasoning,
never the arm's --max-num-seqs 16). Pre-existing red on the merge head, measured
at 62c7a0e; the row's literal is its point, so the repair is the new literal,
stated in the row's comment.
…pleted GLM tool round carries no reasoning and is not a truncated chain

harness_thinking_format_cause refused ANY closer-less completion under a
requested thinking mode, on the claim that GLM-5.3-Flash reasons
unconditionally. Production falsified it (dispatch probe, attempt-state
shell-typed-invocation-a19c151825c6f6eff): finish_reason tool_calls,
reasoning null, zero reasoning tokens, and the refusal killed a healthy
four-round turn. The invariant the check protects -- a truncated chain of
thought must not be transcribed as speech -- is a property of the stop
reason, so the cause now fires only on a ceiling stop with no thinking
block, and the more specific truncated-mid-tool-call arm is judged first.
…sing witness

The first live harness experiment's result, harvested from attempt
ci-executed-coverage-receipt-closing-contract-ad0bb338a840f2be3: the closing
witness (4 clauses over gunbc.merge_admission's check-coverage classifier,
each on a planted input) and the authority row re-bound through
with_execution + gunbc_claim_execution_contract. Witness green by execution:
claim-run over dag/test/claim/closing/ci_executed_coverage_receipt_closing_contract_witness_test.dag, 4/4 PASS.
…node plans, a launch gate

Operator ruling 2026-09-19: the first live harness worker spent 23 of 40
tool rounds orienting (how to test, where witnesses live, what a planted
input is, what the row edit looks like). Centering is now supplied, never
derived per attempt.

- gunbc.roadmap.roadmap_centering (new, single authority):
  dispatch_centering_preamble authored once — it REFERENCES the doctrine
  (the system-prompt contract, gunbc.compute.test_run's command spellings,
  DESIGN.md Operational essentials) rather than restating command prose —
  plus declared_node_centerings, one NodeCentering row per dispatch-ready
  node carrying the near-complete plan (exact witness path + module name,
  clause-to-test-fn mapping, exemplar to imitate, the with_execution row
  edit shape, the acceptance pattern). Rosters the seven experiment nodes
  and the launch canary's two synthetic nodes (so the admission's
  admit-path witnesses traverse the gate).
- gunbc.roadmap_launch_admission: new pre-session centering gate between
  the contract and dependencies gates; a node with no roster row refuses
  with the typed LaunchCenteringAbsent cause (wire: centering_absent).
  Gate and brief read ONE projection (node_centering), so the plan that
  admits is the plan the worker receives — the gate is not a presence flag.
- roadmap_dispatch_actuator: dispatch_brief_with_centering joins preamble
  (exactly once, by construction at the two assembly sites) + the node's
  plan + the filled template, on both the fresh and continuation paths.
- roadmap_serve: LaunchCenteringAbsent maps to 409 beside contract-missing.
- roadmap_belt_actuate: LaunchCenteringAbsent bands BandFail.
- roadmap_launch_deployment_cli: rlm1_contract_digest_frozen re-pinned to
  7bcb9aaf9a17d274 (the gate and refusal arm change the frozen contract
  text by design; recomputed via launch_admission_contract_digest_hex).

Witnesses (claim-run, systemd-run MemoryMax=6G, all green):
- test.claim.roadmap.roadmap_centering_witness_test (new, 7/7): absence
  refuses centering_absent; the gate is load-bearing (mutation control);
  a centered node admits; the admitted plan is the briefed plan; the
  preamble occurs exactly once; the seven rows resolve and render.
- roadmap_launch_admission_witness_test 52/52 (pins moved: 24 refusals,
  10 gates, gate order + pre-session strings; capacity fixtures re-keyed
  to centered ids).
- roadmap_serve_witness_test 27/27, component_dispatch_button 6/6 (wire
  total pin 25 to 26 with the new exemplar), belt_actuate + canary +
  presentation + dispatch_actuator witnesses green (166 PASS batch).
… centering plans

Ten verified shell-in-decision-code sites, one roadmap node each under the
shared shell-dag- id prefix (the roadmap model carries no project/component
grouping mechanism yet; dependency edges to the completed shell-typed-invocation
exemplar are the only parent relationship used). Each node closes on a new
witness dag/test/claim/shell/<id>_witness_test.dag asserting no shell control
word beside a typed-form positive control, accepted via the named test process
pattern //dag/test/claim/shell:all. Staggering constraints (same-file pairs in
ci_spec.dag and live_deploy/emit.dag) recorded in the centering plans.

Verified in a shadow worktree at HEAD plus these three files (the live tree
does not typecheck while agent-15's submission/belt files are mid-flight):
roadmap_centering_witness_test (8/8, incl. the new ten-node claim),
roadmap_launch_admission_witness_test (15/15), roadmap_serve_witness_test
(11/11).
…r just reads it

closing_contract_authored was textual: it read the witness source, pinned a
digest and checked the named function was declared, and attempt
ci-gate-contention-independent-verdict-closing-contract-a54b739dd2acf738f
passed it with a witness that could not resolve a single one of the 21 names
it imported. The textual checks stay as necessary-but-insufficient conditions;
every GunbcClaimValidation the contract names now also executes as a child
claim-run adjudicated by exit status: a resolve refusal (the runner's
'error: resolve failed for' stderr prefix) is ClosingContractWitnessResolveRefused,
any other nonzero exit is ClosingContractWitnessRefused, and only exit 0
greens. The belt's validation argv now passes --arg runner=<the dispatch
host's GunbcClaimRunnerCapability executable>; by hand the runner defaults to
the checkout's target/release/gunbc, then PATH, else a typed refusal.

Discrimination is behavioral on planted fixtures written into a mktemp source
root under target/ at run time (a committed unresolvable witness would fail
every whole-root resolve): pass / unresolvable-imports / resolved-but-false,
enrolled as a bin_wet row beside the other exit-status witnesses.
…erion

3db98ec moved the attempt-identity mint to the spawner for the worker
and auditor but missed harness_reviewer_cli, which kept building it from
the absolute verdict path. The fleet ssh context's safe-segment law
(gunbc.fleet_known_hosts_anchor fleet_ssh_attempt_identity) refuses any
identity that is not a safe path segment, so every reviewer's seat bind
refused before any ssh leg: measured 2026-09-20 on srv2, all fourteen
reviewer lanes of one belt review pass exited 1 with no verdict written.

The mint follows the worker's and auditor's, with the criterion key
appended because the lanes of one attempt share the node id and attempt
key and each lane's identity must stay distinct. The actor stays seeded
on the verdict path (an affinity key, not a path segment), as the
auditor fix kept it.

Witnesses: the minted identity is path_segment_is_safe-admitted, the
review argv and the unit spawn site carry the new argument, and the
pre-fix path-bearing identity is refused -- the row that would have
caught the bug.
…und verify gate, fanin seam

Slice 2 of docs/plans/harness-work-lifecycle.md under the 2026-09-20 substrate
ruling (gunbc SCM inside, git at the edge).

- gunbc.roadmap.roadmap_submission (new, single authority): the .gunbc-submission.json
  artifact (ready | blocked | needs-context + explanation + limitations), the
  capture record (schema v2: git edge head + the AUTHORITATIVE SCM binding —
  project envelope path + commit ordinal), the capture-freshness judgment (a
  byte-identical declaration re-swept is a checkpoint, never a re-binding), and
  the evidence-state fold: Yielded / Submitted / Verified->PublicationOwed /
  BlockedOnPublication(cause) / Published, derived fresh from receipts only, so
  restart loses nothing and a disabled helper reads as owed, never discharged.
- gunbc.scm.worktree_inventory (new): the worktree bridge the SCM layer declares
  while workers edit git worktrees — git ls-files -z argv + NUL-row parse; every
  later capture step is an SCM verb.
- roadmap_belt_commit: the decision splits candidate (fresh decodable submission)
  from checkpoint (absent/undecodable/already-captured) — submission ≠ checkpoint.
- roadmap_belt_actuate: candidate capture mints the tree into the project's SCM
  envelope (stage whole tree -> store_corpus_manifest -> commit_staged ->
  save_repository; nothing-to-freeze is the typed resume), then the git edge
  commit, then the v2 capture record; the verify gate admits only a head with a
  decodable capture (a checkpoint head defers — yielded, not ready; blocked /
  needs-context declarations bind but do not advance).
- gunbc.roadmap.roadmap_fanin (new seam): verified candidates squash-merge into
  the project's one integration head via gunbc.scm.squash_merge; conflicts are a
  typed FaninConflicted carrying the complete conflict population, never a git
  merge failure. Standalone task = project of one (project key = node id).
- dashboard: new Submission workflow segment renders the lifecycle states on the
  attempt row (workflow_stage/progress/presentation).
- harness_guidance: grounded premise — writing the submission artifact is how the
  worker ends the task; ending without it is a yield, preserved as a checkpoint.

Witnesses (claim-run under systemd-run MemoryMax=6G, all green):
- test.claim.roadmap.roadmap_submission_witness_test (new, 18/18): terminal-
  without-submission is yielded not ready; pass discharges into PublicationOwed
  with no discretionary ask; blocked-on-publication names its cause; an observed
  PR receipt discharges; a bound PR is answered as observed and never
  re-actuated (uncertain remote success reconciles without a duplicate); a later
  head inherits no prior evidence; two candidates fan into one integration head
  carrying both sides; a conflicting pair yields the typed conflict and mints no
  head; codecs round-trip the SCM binding.
- roadmap_belt_commit_witness_test rewritten for the candidate/checkpoint split
  (7/7); workflow_progress, belt_actuate, presentation, serve, validation_oracle,
  workflow_command, verification_evidence_addressing, harness_guidance suites
  green (obligation-roster pins moved 7 -> 8 for the new segment).
- belt_actuate witness retains two PRE-EXISTING failures
  (witness_band_fold_pins_operator_vocabulary,
  witness_exemplar_roster_reconciles_variant_set): launch-label rosters moved
  22 -> 26 by in-flight launch-admission work owned by another lane; pins are
  theirs to move.
…nded payloads, lane aggregation, stale-revision dimming

Owner ruling 2026-09-20: the attempt/activity rendering was overwhelming — a
Verification lane rendered a ~98-file "unparseable .dag source(s)" dump inline,
a Review lane rendered fourteen "key: reviewer exited 1 without a verdict"
clauses, and refusals rendered as raw multi-line error strings.

- Refusals render as labels: "Kind · refused — <short reason>" on the summary
  line; the full (bounded) reason sits behind the existing ›details disclosure,
  closed by default in both realizations (the client's auto-open-on-refused and
  its data-auto-opened guard are deleted).
- Bounded payloads: workflow_segment_detail_bounded is the one bound consumed
  by the server ledger, the /workflow.json wire, and the presentation seam's
  located reason — an enumerated payload renders as count + first 3 entries +
  a pointer to the attempt receipt artifact; the receipt content is unchanged.
- Repeated identical lane failures aggregate: "Review · refused — 14/14
  lanes — reviewer exited 1 without a verdict"; mixed messages never aggregate
  (non-uniformity is information).
- Staleness dims: WorkRowView.attempt_stale, decided by
  stale_attempt_nodes as a pure revision comparison (attempt launch-identity
  revision vs the deployed-tree head the launch host standing observed at the
  tick, read in roadmap_served_observation), renders node-attempt-stale +
  data-attempt-revision="stale" and dims the activity region; an unobservable
  current revision or an unreadable launch record dims nothing.
- Lane states render generically through workflow_segment_state_key, so new
  states (Yielded, BlockedOnPublication) need no presentation change.

NOTE: the workflow_stage bounded-detail authority and the bounded wire detail
in roadmap_workflow_progress ride in e9f0683 (swept into that lane's commit
from the shared working tree); this commit carries the rest of the pass.

Witnesses (claim-run under systemd-run MemoryMax=6G):
- test.claim.roadmap_presentation_witness 27/27 (6 new: bounded dump
  count+excerpt+pointer, passthrough control, uniform-lane aggregation,
  mixed-lane refusal to aggregate, refused Review lane label+bound,
  stale-revision comparison both honest arms)
- test.claim.long.roadmap_page_witness: all parity, script-census, selection
  and rendering claims green incl. new refused-arm-behind-disclosure and
  stale-attempt-dimmed pins; six failures
  (ready_node_doc_emits_button, upcoming_dispatch_refused,
  ticket_rows_render_structured, ticket_brief_budget,
  item_detail_disclosure, authority_leads_within_budget) reproduce identically
  without this diff (in-flight launch-admission/authority lane owns those pins)
- roadmap_serve 27/27, component_dispatch_button 6/6, belt 10/10,
  dispatch_presentation 6/6, served_observation 14/14, launch_canary 13/13
…r onto the stable shell_typed_invocation witness
…ered fixture ids, fixture-grounded disclosure negatives, lead-budget trims

The long page-witness suite carried six reds predating the status-surface
presentation pass (baseline-proven identical with and without that work):

- witness_ready_node_doc_emits_button_and_external_script and
  witness_upcoming_node_dispatch_refused_dependencies_blocked read back
  centering_absent since the centering gate landed (9948b04): their
  fixture-minted node ids are not in gunbc.roadmap.roadmap_centering
  declared_node_centerings, and the gate runs before the dependency and
  capacity gates their subjects are about. The fixtures now carry the
  launch canary's rostered parent/followup ids, the same pattern as
  rlm_ready_node in the launch admission witnesses.
- witness_ticket_rows_render_structured and
  witness_item_detail_disclosure_present each pinned a negative over the
  LIVE authority population (no ticket-updates block; no brief-labelled
  disclosure) — change detectors that redded the day an authored row
  legitimately produced the forbidden markup. The decided laws
  (disclosure_updates_block renders the thread exactly when non-empty;
  view_detail_block labels a legacy-body row 'brief') are now pinned on
  constructed fixtures beside the kept live-page positives.
- witness_authority_leads_within_budget measured 17 overlong leads: 15
  identical superseded-row boilerplate sentences from the CI cost re-cut
  plus the two judgment supersession rows. A punctuation split at the
  natural clause boundary brings every lead under 300 chars without
  dropping a word.

Remaining red, routed: witness_ticket_brief_budget_holds_and_reds
measures six active rows whose boundary fields exceed the 100-word
reading budget (2-scm-native-authority-program 134,
floor-ceiling-roster-cut-completeness 123, frontend-eval-training-program
177, fleet-mtcollins1-first-host 153, fleet-slot-retirement-wet-proof
116, cardinality-vertical-slice 119). Those are live program contracts
owned by six different lanes; the trim is their call.

Also: the workflow strip is eight obligations since Submission landed
(seven-obligation wording in roadmap_component notes corrected).
…try-line-builder

Plants dag/test/claim/shell/shell_dag_cron_entry_line_builder_witness_test.dag as the
pattern-prover for the shell-dag migration batch: four adversarial-field arms (schedule,
command, log_path, tag each planting a shell control word) red on today's string concat in
gunbc.tools.cron_tag build_cron_entry_line, two green positive controls, and the acceptance
conjunction cron_entry_line_builder_acceptance_holds bound in the node's execution contract.
The five red identities are enrolled in v2.workflow.floor_expected_red (new meaning-named
chunk) so the required floor holds them as known red. Restores the node's real execution
contract binding, retiring the temporary machinery-smoke binding onto the shell_typed_invocation
witness on exactly the condition it declared, and rewrites the M0 step in roadmap_authority.dag
and its centering plan to point the dispatched worker at M1-M3 with the pinned-witness
no-edit rule.
…eak-calibration-rows

Plants dag/test/claim/shell/shell_dag_floor_peak_calibration_rows_witness_test.dag: two red
arms over the pre-calibration surface (the echo reset row's 2>/dev/null swallow), two green
positive controls (cgroup memory.peak read, [calibration] labels), and the acceptance
conjunction floor_peak_calibration_rows_acceptance_holds bound in the node's execution
contract. The three red identities are enrolled in v2.workflow.floor_expected_red; the M0 step
and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…gate-line

Plants dag/test/claim/shell/shell_dag_ci_fmt_gate_line_witness_test.dag: one red arm (the
hand-spelled "$CARGO_BIN" indirection the typed cargo.Build.Fmt operation has no spelling
for), two green positive controls (the workspace fmt check shape, no shell control word), and
the acceptance conjunction ci_fmt_gate_line_acceptance_holds bound in the node's execution
contract. The two red identities are enrolled in v2.workflow.floor_expected_red; the M0 step
and centering plan point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…oy-invoke-prelude

Plants dag/test/claim/shell/shell_dag_ci_deploy_invoke_prelude_witness_test.dag: two red arms
over the rendered invoke (the ROOT prelude's || pwd absorbing fallback and 2>/dev/null
swallow), two green positive controls (the toplevel read, the declared stage's entry/function),
and the acceptance conjunction ci_deploy_invoke_prelude_acceptance_holds bound in the node's
execution contract. The three red identities are enrolled in v2.workflow.floor_expected_red;
the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness
no-edit rule.
…-regen-invoke

Plants dag/test/claim/shell/shell_dag_ci_heal_regen_invoke_witness_test.dag: two red arms over
the rendered invoke (the ROOT prelude's || pwd absorbing fallback and 2>/dev/null swallow),
two green positive controls (the shared toplevel read, the declared regen+verify two-call
composition), and the acceptance conjunction ci_heal_regen_invoke_acceptance_holds bound in
the node's execution contract. The three red identities are enrolled in
v2.workflow.floor_expected_red; the M0 step and centering plan point the dispatched worker at
M1-M3 with the pinned-witness no-edit rule.
…-pool-slice-install

Plants dag/test/claim/shell/shell_dag_compile_pool_slice_install_witness_test.dag: two red arms
over the rendered install body (the benign body's set -euo pipefail opener, an adversarial
slice unit name carrying a command separator), two green positive controls (installs the
declared unit, starts never restarts), and the acceptance conjunction
compile_pool_slice_install_acceptance_holds bound in the node's execution contract. The three
red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan
point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…pulation-census-read

Plants dag/test/claim/shell/shell_dag_slot_population_census_read_witness_test.dag: one red arm
(over a planted unexecutable transport, the census cause must carry the transport's typed
refusal — not the bare exit code that is the text-carrier signature of the re-joined shell
read), three green positive controls (refusal-shape pairing, planted command failure keeps its
exit code, planted success classifies), and the acceptance conjunction
slot_population_census_read_acceptance_holds bound in the node's execution contract. The two
red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan
point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…pp-server-trip-script

Plants dag/test/claim/shell/shell_dag_codex_app_server_trip_script_witness_test.dag: three red
arms over the rendered trip surface (shell control words, the literal stdio sentinels, an
adversarial codex_home), one green positive control (the declared payload and subject), and
the acceptance conjunction codex_app_server_trip_script_acceptance_holds bound in the node's
execution contract. The four red identities are enrolled in v2.workflow.floor_expected_red;
the M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness
no-edit rule, plus the one sanctioned exception inherited from the exemplar: M2 deletes the
surface the witness reads, so its import is re-pointed at the typed realization's rendering of
the same trip with fn names and claims unchanged.
…ploy-install-owned

Plants dag/test/claim/shell/shell_dag_live_deploy_install_owned_witness_test.dag: one red arm
(an install path carrying a command separator, rendered into the privileged install line),
two green positive controls (benign surface clean, declared path and principal realized), and
the acceptance conjunction live_deploy_install_owned_acceptance_holds bound in the node's
execution contract. The two red identities are enrolled in v2.workflow.floor_expected_red; the
M0 step and centering plan point the dispatched worker at M1-M3 with the pinned-witness
no-edit rule.
…ploy-restart-tailscale

Plants dag/test/claim/shell/shell_dag_live_deploy_restart_tailscale_witness_test.dag: one red
arm (the tree-sync restart step's diagnosis appended as shell text — a || fallback arm with ;
separators), three green positive controls (tailscale step clean, declared unit named, both
steps elevate through sudo), and the acceptance conjunction
live_deploy_restart_tailscale_acceptance_holds bound in the node's execution contract. The two
red identities are enrolled in v2.workflow.floor_expected_red; the M0 step and centering plan
point the dispatched worker at M1-M3 with the pinned-witness no-edit rule.
…d progress bars on the daily workspace

A project is a rendered row with at least one rendered task, and a row's
tasks are its PREREQUISITES — the edge law's direction, never its
inverse: edge(child: X, parent: Y) says X depends on Y, so
display_children(P) = roadmap_parent_ids(edges, P) restricted to rows
the page renders. The arc shell-typed-invocation thereby renders as a
project whose ten shell-dag-* nodes are its tasks, and nesting recurses
(a task with its own prerequisites is an intermediate project — the
shell-residue-zero → shell-gate-migration → shell-effectplan-to-bash
chain), with rendered depth capped at 3 behind a collapsed '+N deeper'
disclosure that still renders every deeper row inside it.

Placement rules, each a pure function of the decided rows and the
declared edges, decided in gunbc.roadmap_presentation (the seam) and
only painted by gunbc.roadmap_page:

- RENDERED-ONLY: a task joins a tree (and a progress denominator) only
  if its row renders somewhere today; an unplanned prerequisite reports
  no invisible work.
- FAMILY-FIRST: a closing-contract family member never nests and never
  counts — the family is the presentation authority for generated task
  rows, and edge-nesting would double-render it.
- ACTIVE-SURFACES: a row with live work keeps the attention law and
  renders flat in the Active band rather than inside a tree; it still
  counts in its project's denominator and still pulses auto-open.
- PRIMARY-PARENT: a task that gates several rendered projects nests
  under the first in edge declaration order (never duplicated) while
  counting toward each. roadmap_primary_parent was consulted and does
  not fit — it selects a node's own first prerequisite, the opposite
  direction of the display parent needed here.
- NOTHING-VANISHES: a row whose display-parent chain reaches no
  top-level entry (only possible on a cycle, refused upstream) renders
  as an ordinary top-level row.

Progress counts closure, never implementation evidence: closed =
accepted or superseded (node_closes_dependency) read off the decided
lifecycle, so a merged PR without an accepting signoff (ReviewLifecycle)
never counts. The project row is the same row shape as every task (the
decided head, activity region, disclosure — no forked renderer), plus
'k of n tasks closed' and a CSS-only bar flex-weighted by the counts
(the round strip's proportional-by-construction idiom). The task
disclosure's open attribute is derived: a project opens when a
descendant has a live attempt or a non-routine event-log standing, and
collapses when quiet.

Witnesses: eight derivation receipts in
test.claim.roadmap_presentation_witness (direction, counting,
no-loss/no-duplication, primary-parent, active-surfaces, auto-open,
recursion, family-first) and four rendering receipts in
test.claim.long.roadmap_page_witness (row shape and bar, derived open
attribute, depth-cap affordance, the live shell-arc exemplar at identity
grain). The .project-progress / .project-tasks style family is tokened
and role-routed; the roadmap_css lift-parity digest is re-derived by
execution, never chosen.
…needs-context or yield

continuation_decision read only workflow segments, so a worker that ended
truthfully blocked (attempt cd172fe81b806160: budget spent with its
acceptance run still in flight) routed to Fresh-from-base on re-dispatch,
discarding the committed implementation. PriorAttemptFacts now carries the
same head-grain SubmissionCaptureObservation the verify gate binds, read by
the belt through the same reader, and the decision gains a capture arm
ordered before the segment arms: blocked / needs-context / yield continue
from the prior branch at the next turn with the worker's explanation (or
the yield reason, bounded) leading the brief; a ready capture falls through
to the segment arms unchanged; an unestablishable capture refuses. The
turn-cap and unreadable-turn refusals are shared by every continuation
route through continuation_continue_next_turn. Witnesses: capture arms,
red control that a ready candidate never continues, cap/unreadable
refusals, and the worktree-add argv carrying the prior branch end-to-end.
… integration-head advancement

Owner ruling 2026-09-20: the 10-task batch integrates via native gunbc SCM
fanin, not a git-side fold.

- gunbc.roadmap.roadmap_project (new): project membership DERIVED from the
  roadmap authority's dependency edges — a node's project is the arc that
  depends on it (edge child: arc, parent: task); no dependent arc = project of
  one keyed by the node id; two arcs over one node is a typed ambiguity, not a
  default. No parallel roster.
- Base seeding: project envelopes key by the ARC id. An envelope with no
  commits is seeded once from the attempt's RECORDED spawn-origin base sha via
  the declared git bridge (gunbc.scm.worktree_inventory worktree_base_file_args:
  git show <base>:<path> per tracked path), committed as the envelope's root.
  Candidates are minted descending from that shared base (selection moves to
  the base for the mint and is restored); between belt operations checked_out
  IS the integration head, so restart recovery is a pure envelope derivation.
  A candidate identical to the intake base refuses (nothing to deliver).
- Integration-head advancement: the publish pass first runs the integration
  step — capture binds this head, verification passed — then
  fanin_integrate_candidate (squash_merge: target = integration head, source =
  candidate). FaninAlreadyIntegrated is its own arm (the consumed-source record
  makes re-integration a typed no-op; that IS the restart path). FaninConflicted
  writes a per-candidate integration receipt naming the complete conflict
  population; the candidate stays verified-but-unintegrated and the others are
  unaffected. Members of a multi-member project never publish alone: they defer
  with the k-of-n standing (census derived from the per-attempt receipts); a
  fully integrated project defers naming the publish-edge change that lands the
  materialize-to-branch edge next.
- Handoff states: IntegrationOutstanding/Complete/BlockedStanding sit between
  Verified and PublicationOwed (HandoffAwaitingIntegration /
  HandoffBlockedOnIntegration), rendered on the dashboard's Submission segment
  from the per-attempt integration receipt.
- roadmap_fanin: IntegrationReceipt codec (roadmap-integration-receipt/v1) +
  IntegrationReceiptObservation for the read path.

Witnesses (whole-file claim-run, systemd-run MemoryMax=6G):
- roadmap_submission_witness_test 27/27: membership derivation (member /
  standalone / ambiguous), awaiting-integration and blocked-on-integration
  states, receipt codec round trip, re-integrating a consumed candidate is a
  typed no-op minting nothing (the restart-safety control), plus the prior 18.
- belt_actuate / belt_commit / workflow_progress / presentation / serve /
  validation_oracle / workflow_command / verification_evidence_addressing all
  green (belt_actuate's two launch-label pin FAILs remain another lane's).

Publish edge (materialize the integration head to a git branch + one PR per
project) follows as a second commit.
…ad to its git branch

Slice 2's final mechanism. When every member of a multi-node project is
integrated, the belt materializes the project's SCM integration head into a
belt-owned integration worktree (<worktree-root>/<project>-integration,
created detached at the intake base and reset per publication with checkout -B
+ clean -fdx, so the tree afterwards holds exactly the integration head's
corpus), commits it on the dispatch-<project>-integration branch, and enqueues
a project-shaped publication subject (node_id: the arc, attempt_key:
integration) into the existing helper spool — one PR per project, answered by
the same observe-first helper that discovers an existing PR rather than
duplicating it. The project receipt lands beside the envelope at
projects/<project>.publication-receipt.json.

SCM inside, git only at the edge: the materialization reads the corpus out of
the object store through the SCM checkout verbs (commit_at_reference +
find_corpus_manifest_record + recover_corpus) and writes plain files; git's
whole role is worktree-add / checkout / clean / add / commit. The
parent-directory computation for the materialized paths is the one pure
decision in the edge and is pinned by
the_publish_edge_parent_dir_drops_exactly_the_basename; the rest of the edge is
effectful by construction and is exercised by the production fanin, not by
hermetic witnesses (route-gap honesty, not a mocked boundary).

Members of an incomplete project keep deferring with the k-of-n standing; the
project-of-one path is unchanged.

Witnesses (whole-file claim-run, systemd-run MemoryMax=6G): belt_actuate suite
green including the new dirname control (the two launch-label pin FAILs remain
another lane's); submission 27/27; serve green.
…ith red-flagged stages and semantic activity coloring

INCREMENT 1 — collapse single-child project chains (operator ruling
2026-09-21). A project with EXACTLY ONE display child that is itself a
project collapses: the chain renders as one project row carrying the
topmost project's identity and headline, with the chain END's display
children as its tasks and its k-of-n counts — so the shell chain
shell-residue-zero → shell-gate-migration → shell-effectplan-to-bash →
shell-typed-invocation renders as one residue-zero row whose bar counts
the arc's ten shell-dag-* tasks, one disclosure down. A project
collapses through a child only it OWNS (the child's primary display
parent is the collapsing project): fleet-closed-loop-converge's single
display child shell-gate-migration is owned by shell-residue-zero
(first declared edge), so the fleet row does not collapse and its
"k of 1" stays honest. Multi-child projects never collapse. Swallowed
intermediates render as the chain line inside the task disclosure
(identity + lifecycle chip each), so nothing vanishes and nothing
duplicates; the depth cap counts a collapsed chain as one level and
applies after collapsing.

INCREMENT 2 — hero progress rows (operator request 2026-09-21: the bar
prominent, everything else a drop down, errors flagged red). Attempt
rows render the stage strip on the face — one segment per workflow
obligation, classed by the wire's own decided state key (complete lit
in the figure role, active on the in-progress band and pulsing while
the worker is live, pending dimmed, failed and refused red at that
segment) — plus the one-line state and the throughput line; the round
strip, obligation ledger texts, bounded refusal payloads and evidence
move behind the activity disclosure, which never arrives open
(superseding the 2026-09-05 open-while-live rule; the 2026-09-20
label-first refusal ruling stands). The refused and completed
ActivityView arms now carry the obligation roster so their strips paint
the red segment. Project bars flag red (project-error) when the decided
subtree_error holds — derived from refused/anomalous attempt arms over
the display-children relation, never text-sniffed. Activity coloring
classifies from typed sources through gunbc.roadmap_presentation's
ActivityLineClass (read/write/provider-call/error-refusal/done/neutral):
round segments re-home their paint onto it (values unchanged), the
summary line wears its decided class, and the wire carries summary_class
plus a throughput cell so the client paints both verbatim; the strip is
painted by the client from the wire segments' decided state keys. The
exec class is declared vocabulary with no on-page producer today — the
provider fold flattens CodexItemActivity into the current-activity
string, and the named trigger is ProviderRunning carrying the typed
item; no regex over free text was introduced anywhere.

Witnesses: presentation +4 (classification per class with an
unclassifiable-neutral control, refused/completed roster carriage,
red-flag derivation both directions, wire summary_class), page +6
(bar-first face and strip state mapping, live-pulse gating, round strip
disclosed and classified, red-flagged refused/failed rows, project bar
red flag from the decided field, client verbatim hero paint), plus the
collapse law receipts (single-child collapses, multi-child never,
chain-end counting, no-duplication, shared-child ownership). The
roadmap_css lift-parity digest is re-derived by execution
(9d5d1d23dce5e2f8), never chosen.
briansrls and others added 22 commits September 29, 2026 19:45
…e whole ticket, and every edge argues its contribution

The membership walk no longer accepts a standalone end at an arbitrary node: only a declared root
(gunbc.roadmap_nesting declared_roadmap_roots = gunbc-project-root) may be parentless, and any
other halt resolves AlignmentWalkUnrooted naming where the walk stopped -- a chain that never
reaches the top of its functional decomposition has no alignment answer (review 5354823380).
AlignmentChainLink keeps the full ticket carrier (approach, red control, handback, displaced cost)
plus contribution_to_parent, the edge's own argument for why the child's work advances its parent;
RoadmapMembership gains that field and the fingerprint preimage covers it (alignment-chain/v2).
Levels and renders are root-to-leaf with cadence still counted from the leaf. The hierarchy is
authored: gunbc-project-root <- harness-work-lifecycle <- harness-recursive-alignment <-
harness-alignment-checkpoint-resume and harness-conversation-log-forking, plus the shell batch
attached at the root. KNOWN GATE: dispatch of any node whose walk does not reach the root now
refuses at the alignment step; attaching the wider population is follow-on authoring, not assumed
here. Witnesses updated to the rooted fixtures; two pre-existing reds (page ticket-brief budget,
belt two-lineage escalation) reproduce on the clean baseline and are untouched.
…oject level gets a suite page

The issue detail page now shows the node's alignment chain as a breadcrumb, root to leaf, derived
from the same alignment_resolve the dispatch gate consumes -- never a second path answer. Project
crumbs link to the new GET /project/<node_id> suite page, which lists the project's direct members
in stable topological order (declared dependency edges restricted to the member set, Kahn-layered,
authored order within a layer) with links to their issues; the task crumb is plain text, and an
unresolved chain renders the typed refusal instead of a partial path. Four presentation witnesses
pin root-to-leaf rendering, refusal honesty, exact direct-membership, and prerequisite-first
ordering.
…ots, plans, render receipts

A prompt is a projection of an admitted context snapshot, never an authored string (scoped review
against 81e7c77; owner direction 2026-09-29). PromptInput types the five input kinds with their
authority revisions; PromptContextSnapshot binds them to an attempt lineage, epoch, and source
revision; PromptPlan assembly refuses a required segment whose source stands Withdrawn rather than
rendering a retracted claim as established; PromptRenderReceipt digests exactly what rendered, so
identical snapshots render identical digests and a moved authority revision invalidates the old
render. Segment content is rendered prose, digested -- the types guard provenance and revision, not
the prose, and semantic contradiction between free-text inputs is NOT inferred (conflicts must be
typed to refuse). Roadmap: harness-prompt-context-model authored under harness-work-lifecycle, with
its edge contribution. Next cuts: harness_guidance emits modeled segments; the belt probe DAG
consumes snapshots from day one; harness_turn migrates to PromptPlan last.
…ender projection

harness_guidance_segments turns the grounded-premise/derived-conclusion population into
PromptSegments on gunbc.harness.harness_prompt_context: each premise segment's source is an
AuthorityInput naming its grounding DeclarationRef at the caller's source revision, and each
conclusion segment is a DerivedConclusionInput naming its grounds, so a retracted premise moves the
conclusion's input digest. The prose stays the render projection of the same population, pinned by
a parity witness so the two cannot fork; a second witness pins that a moved source revision moves
the segment inputs while content digests stay stable. This is the first consumer of the prompt
context model and the shape the worker, reviewer, and alignment-probe prompts converge on.
…t prompt assembly, standing-sensitive identities, honest checkpoint handoff

Prompt model: assembly is now an EXACT JOIN between the snapshot's eligible inputs and their
renderings -- every non-withdrawn input renders exactly once, withdrawn inputs render zero
segments, foreign or duplicate segments refuse with typed causes (RequiredSourceUnrendered /
MissingRendering / DuplicateRendering / UnexpectedRendering / WithdrawnSourceRendered), and the
plan's segment order derives from the snapshot, never the caller's render order. Canonical
preimages are length-prefixed and carry standing/resolved/required, so a hypothesis becoming an
observation is a different input, and no field containing a separator can manufacture another
sequence's preimage. SemanticPromptArtifact carries per-segment extents with an honestly declared
char-count-fallback basis until a UTF-8 byte primitive exists; ProviderPromptArtifact separates the
shared semantic digest from the per-envelope wire digest. harness_guidance conclusions now record
their EXACT premise grounds (a moved test-process premise no longer invalidates the write-form
conclusion), conclusions are keyed once and rendered, and required is derived from the source
input, never asserted beside it.

Alignment: the fingerprint preimage covers handback and displaced_cost and the render shows them;
the contribution read is a typed fail-closed lookup (missing/vacuous/conflicting edges refuse with
the edge named) rather than defaulting to the empty string that used to read as root membership;
rootness in the render comes only from declared_roadmap_roots; duplicated same-project membership
rows are no longer misread as an ownership fork (they reach the contribution read, which judges
agreement). AlignmentCheckpointIdentity (lineage, epoch, ordinal, chain fingerprint, conversation
tip, candidate subject) is the belt adjudication lane's idempotency key.

Handoff honesty: the worker notice now states the epoch boundary returns control for an INDEPENDENT
checkpoint -- the harness makes no provider call and the worker is not asked to grade itself --
and checkpoint-due exits with the distinct admitted standing 3, never the generic failure code 1.

Witnesses: per-field fingerprint mutation controls (purpose, boundary, approach, red control,
handback, displaced cost, contribution), vacuous and conflicting contribution refusals, exact-join
assembly controls, standing-sensitive identity, extents, and the semantic/wire digest split. Full
affected suite sweep green; the two known pre-existing reds are untouched.
…rsive-alignment

The pure planner node (review 5358022153 lane C): freeze the checkpoint subject and derive the
homogeneous probe obligations idempotently, so the parallel probe fan-out is a schedule over
derived facts rather than an in-loop improvisation.
…ver the alignment ladder

Lane C of review 5358022153: checkpoint_probe_obligations walks the resolved
chain's levels root-to-leaf and derives one probe obligation per level
(principles, project, task), each keyed by a content digest over the checkpoint
identity digest plus the level identity, so a crash re-derives byte-identical
keys. A checkpoint whose chain fingerprint moved refuses rather than minting
obligations a stale checkpoint would execute; outstanding guidance carries the
cadence state's recorded verdict payload at the level's leaf distance, and
nothing for ALIGNED. No model calls, no effects, no verdicts -- the population
a durable scheduler executes later.
…bric KV residency as observation (review 5358022153, lane D)

- harness_turn: every round persists its exact request and response bytes
  under <events_path>.wire/<round>.{request,response}.json (same round
  numbering as round.usage); a refused wire-log write emits the non-terminal
  turn.wire_log_unwritable event and the turn continues -- the event stream
  is the terminal record, the wire log is recoverable evidence, and trading
  the work for the receipt is the wrong trade. Filesystem.Write does not
  create parents; the writes rely on the wire directory being provisioned
  with the attempt state directory, the same reliance the scratch pair
  carries.
- harness_conversation_fork: ConversationForkPoint/ConversationForkAdmittance
  -- a fork is admitted only while model identity, wire shape and alignment
  chain fingerprint all still hold, each refusal naming its cause (a fork
  across a model change replays context the engine never computed). The
  receipt states the law: the durable log is the correctness authority, KV
  residency is a performance derivation, never a correctness dependency.
  KvPrefixResidency/Observation model the fabric cache standing as pure
  observation: Resident prefers a warm location, every other standing --
  Unobserved honestly included -- executes cold from durable state; a fork
  receipt binds model/checkpoint/tokenizer/template/tool-schema/projection/
  prefix digests, and a shared chain fingerprint alone never establishes the
  same KV prefix.
- roadmap_provider_events: admits turn.wire_log_unwritable as a classified,
  non-terminal event with provider state unchanged (round.usage arm pattern);
  the jq projection passes unknown types through as {type} so the bounded
  envelope classifier is the single admission point.
- witnesses: fork admitted on exact identity match; each invalidation refuses
  with its named cause; five residency standings are distinct variants with
  Unobserved defaulting to cold; pure parts only, no harness IO wet-tested.
Lane B of review 5358022153. The census derived from declared_roadmap_nodes()
and declared_roadmap_memberships() found 195 nodes, 18 rooted, 177 unrooted --
18 carrying an ExecutionContract (thirteen active rows plus five completed
belt-era rows still bound), the population dispatch refuses at the alignment
step today.

Author the attachments: seven program-level nodes (dag-scm-program,
namespace-unique-on-chain, v1-deletion-program, v2-emitter-production,
ci-end-to-end-execution, progress-observation, roadmap-acceptance-integrity)
carry the thirteen rows that had no honest existing parent, and the five
completed belt-era rows ride the existing harness-work-lifecycle. Twenty-five
new membership rows, each edge's contribution arguing why that child's work
advances that parent, each program's root edge arguing why the program serves
the factory. extended-admission-cardinality stays unrooted on purpose -- it is
the named refusal subject of the unrooted controls, and it carries
ExecutionContractUnspecified, so it sits outside the dispatchable population.

roadmap_alignment_witness_test gains
every_dispatchable_node_reaches_the_admitted_root: every node whose execution
is an ExecutionContract must derive AlignmentChained, derived from the
authority, with no named exclusions.
…re separate triggers; session standing reads the profile projection; wire-log directory provisioned

Fixes the reported regression where clicking an issue title link intercepted the anchor, selected
the row, and opened the project's topological strip instead of navigating: the link click now
returns untouched (middle-click and modifiers were already untouched), and focus/topological
strip are the topological-sort chip, the row body, or Enter/Space. Cut B repairs: the session
standing endpoint prefers the durable profile projection's members (session stays the identity
authority, projection the display authority), reports the roster's degradation as data
(profile store unread / N records unreadable), and the profile read's skipped entries are
carried with reasons instead of silently dropped. The attempt-state prepare now provisions the
wire-log directory (<events>.wire/) so the harness's per-round request/response persistence
lands (harness-conversation-log-forking).
…, conversation log — PR #12684

Lane B roots the dispatchable population; lanes C and D add the pure probe planner and the
conversation/fork mechanism; the UI fixes the issue-link navigation regression and Cut B's
session-standing erasures. The alignment gate is now live: dispatch refuses unrooted chains.
…e rows -- the serve build's source-annotation phase rejects comments inside the declaration body, and the tickets carry the content
briansrls and others added 6 commits September 30, 2026 16:49
…clip the Fabric avatar

- The instance owns its auth store roots (gunbc.roadmap_dashboard_instance
  dashboard_instance_auth_store_root over DashboardAuthStore); the four auth
  modules derive their directories from it and the provision plan ensures
  them. auth-profiles was never created on srv2-deploy, so every login's
  profile publication was refused and every roster read came back unread --
  the assignee surfaces rendered the raw principal and a "1" avatar.
- A recorded comment (first write or idempotent retry) answers 303 to its own
  numbered anchor instead of a stranded text/plain 200; a readback that does
  not carry the committed comment refuses (502) instead of linking #comment-0.
- The 24px avatar circle holds only the initial; the workflow kind rides the
  chip class and hover title instead of clipped text inside the circle. The
  orphaned .issue-avatar-badge rule is deleted and the CSS pin re-derived by
  execution.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…-push hook)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…aracters

profile_store_read_all handed Filesystem.List's newline-joined `entries`
String to a decoder that walks a List<String>, so its first "entry" was a
code point and ends_with refused with "expects a string, got Int". It never
ran before today because the store directory did not exist; the first login
after provisioning wrote a profile and every issue page then failed. The read
now goes through filesystem_listing_observation and main's
filesystem_listing_entry_names (added here verbatim, the single decoder of the
List wire format), with a refused listing or subject carried as
ProfileStoreUnread. Verified by execution against the live store: 1 profile,
"Brian Searls", 0 skipped.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…he rail, the robot mark for Fabric

- Work tab: the issue route observes its own node through the SAME attempt
  observation the daily page runs (belt_workflow_attempts_observe_scoped over
  WorkflowAttemptScope), replacing the hard-coded attempts: [] and "not
  connected" refusal; a census refusal stays a refusal. Stale-revision marks
  derive the same way the daily page's do.
- Rail: "reporter" no longer promotes the owner lane (@shell) to a person --
  the ledger has no creation event, so it reads "not recorded (authored
  roadmap row)". "blocked by"/"blocking" carry a count that opens the
  Dependencies tab instead of every headline comma-joined into a 34ch column.
- Fabric's avatar is the gunb robot mark (gunbc.site.robot_mark, copied from
  gunb-ai/frontend legacy/moodboard.html #stoic-robot); both chip builders
  collapse onto issue_avatar_chip_node.
- test.claim.auth.profile_store_real_path_witness_test: the profile store's
  real path in a temp dir (red on the pre-fix read with the ends_with
  TypeError), enrolled on the local-repo wet lane (exclusion row, schedule,
  route-gap chunk 17).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… parent, Fabric badge stone

- The ledger's standing sentence takes the caller's principal naming
  (roadmap_node_standing_text_naming); the issue page names principals the
  way its chips do, so the rail reads "claimed by Fabric", not an unbreakable
  principal:gunbc/workflows/fabric token running past the rail.
- Rail labels no longer shrink under a long value ("observation" collided
  with its value); values take the remaining width and wrap unbroken tokens.
- The parent field follows the declared membership, titled from the plan rows
  then every declared node, spelled by id when untitled -- never "top-level"
  for a member whose project the plan rows omit (shell-typed-invocation under
  gunbc-project-root, which the breadcrumb already showed).
- The Fabric chip paints the owner's badge stone #f4f1ec (2026-09-30) under
  the frontend's ink robot mark, through --fabric-badge-bg/--fabric-badge-ink
  theme properties in both schemes (unthemed-colour census unchanged at 15).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…lection defers; a failed publish pass names its attempts

A blocked (or needs-context) submission capture was deferred by the verify
pass but read as a candidate by the integrate step, which then found no
verification selection (the verify pass never writes one for a
non-candidate), mapped that absence to VerificationUnreadable, and failed
the publish pass on every tick since 2026-09-29 with a sentence naming no
attempt.

- gunbc.roadmap.roadmap_submission submission_candidacy: the one
  classifier of "is this capture a verification candidate"; consumed by
  belt_verify_capture_gate, belt_integration_capture_gate and the handoff
  projection, so the passes cannot disagree.
- belt_candidate_subject_reading: SelectionAbsent is an absence
  (VerificationNotPassed -> integrate defers); unaddressable, unreadable,
  malformed and head-mismatched selections stay unreadable.
- belt_publish_pass_outcome_from names each failing outcome's node, arm
  and detail instead of "one or more publication outcomes could not be
  recorded".
- Four witnesses in roadmap_belt_actuate_witness_test, each red against
  the pre-change logic ported into the same seams.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@briansrls briansrls closed this Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant