Skip to content

Keep daily catalog reports and Monday proposals consistent - #639

Merged
seathatflowsinourveins merged 2 commits into
mainfrom
foundation/catalog-freshness-residuals-main-20261003
Oct 3, 2026
Merged

seathatflowsinourveins merged 2 commits into
mainfrom
foundation/catalog-freshness-residuals-main-20261003

Conversation

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

Scope

Keep catalog reports daily at06:17UTC and restrict scheduled proposals to Monday, preserving the existing opt-in and safety gates. Align the foundation catalog, workflow comments and documentation with that behavior, correct hook-path/trust and historical-review attribution, and retain the original bounded outputs.

  • Base: dcae68bd08a191f37ba564eceda9fc4a9d6d4a6e (Retire historical WSL retrieval replay and isolate its archive scan #622 merged retirement). Published HEAD: e91407d0843d31ba55344359a11d0553f79c8885; source commit 3b1e29b2f837afed4b4059bec25093ec57c3bb39.
  • Lane: lane:foundation.
  • Owned paths: three foundation workflows, foundation automation catalog, three dated decisions, catalog proposal/parser tests, practice-references cadence note, four residual evidence files and their owned registration. The security workflow changes one cadence comment against main; the accepted retirement implementation is preserved.
  • Follow-up to #613's eight findings. Three owner-path residuals remain with the accepted Claude pin-move handoff: adoption/templates/codex.hooks.template.json trust wording/parity, docs/harness-defaults.md published-source/installed-version distinction, and docs/token-session-handbook.md daily/Monday text. This PR does not claim full eight-item closure.

SOTA sources

Evidence-class table

Claim Evidence class Command / receipt
Proposal selection and surrounding gate behavior at the original reviewed preparation local_integration / synthetic 128 unchanged proposal/pin/trading tests,0; retained integration.stdout.txt
Documentation/catalog/cadence consistency at that original preparation local_integration 79 unchanged docs/automation/practice tests,0/1skip; retained docs.stdout.txt
Combined retirement-candidate proposal/parser fixture checks local_integration / synthetic 121tests/85.835s/1skip,0 at9c4d4d8cea; this published tree is exactly byte-identical, native git diff --quiet0
Current fresh-main registration and scope local_integration native validator0:69components/9413hashedfiles/4profiles/187receipts; diffcheck0; owned native registration and exact candidate-tree equality
Bounded correction source acceptance is preserved with exact input bindings source_review Sol/max source ACCEPT at246390aba;13/14 source/artifact files match that reviewed preparation, remaining workflow preserves retirement behavior and changes one comment
Historical PR613 structural review is retained with its original scope source_review 25,478-byte sanitized pr613-source-review.json, SHA256 ca7cc90d94684da52b3b952ecb84c2c15565dcf3ba832a1e09f36bcc7021febc; not a new acceptance run

Local commands run

Original preparation at246390aba032b51346250904dca934f10c6f6079, with outputs retained in the artifact directory:

PYTHONDONTWRITEBYTECODE=1 python3 -m unittest tests.test_catalog_freshness_propose tests.test_catalog_freshness_pins tests.test_catalog_freshness_trading
exit0;128tests;57.592s
PYTHONDONTWRITEBYTECODE=1 python3 -m unittest tests.test_adoption_docs_consistency tests.test_github_automation_practice tests.test_practice_references
exit0;79tests;1skip;14.201s

Additional actual combined-candidate checks at9c4d4d8cea2b6db5858ff59dff758bcb927a9d10:

rtk python3 -m unittest tests.test_catalog_freshness_propose tests.test_shell_parser_ci
exit0;121tests;85.835s;1skip
actionlint .github/workflows/catalog-freshness.yml .github/workflows/practice-references-freshness.yml .github/workflows/security-scan.yml
exit0;native1.17.0;empty output
python3 scripts/component_matrix.py --check
exit0;32metadata rows
python3 scripts/new_host_grand_list.py --check
exit0;generated metadata check only

Fresh-main carryover before the final registry-only commit, subsequently unchanged at published HEADe91407d:

rtk git diff --quiet 553c566c6d47c07e3fe1cafbf02bb6efef35fbb1 dcae68bd08a191f37ba564eceda9fc4a9d6d4a6e
exit0;retirement squash has the identical tree
rtk git diff --quiet 9c4d4d8cea2b6db5858ff59dff758bcb927a9d10 HEAD
exit0;published carryover has the identical complete tree
rtk python3 scripts/validate.py
exit0;69components;9413hashedfiles;4profiles;187receipts
rtk git diff --check
exit0
rtk git diff --name-only HEAD^ HEAD
exit0;manifests/evidence.json only

Passing fixture/lint checks are reused because their complete inputs match. Historical128/79 checks retain their earlier inputs; the fresh validator does not retell them as new runs. These checks establish local integration/integrity, not a future scheduled Actions execution, new provider/model/GPU acceptance or upstream qualification. All original RED, fetch, publication-validation, lint-discovery and Git-metadata failures remain retained; standalone register_file.py discovery failed2 and was corrected to the maintained host_receipts.py function. No failed evidence was deleted or silently relabelled.

Decision record

docs/decisions/2026-10-02-daily-catalog-currency.md records daily reports/Monday proposals and unmeasured quota-isolation limits. evidence/artifacts/catalog-freshness-residuals-20261003/README.md records provenance, failures and the owner-path closure boundary. PR613's historical body already identifies its real immutable original verdict locator.

Host evidence

No host receipt or platform-acceptance change.

Checklist

  • Existing full-commit Action pins are preserved.
  • Narrow workflow permissions and proposal gates are preserved.
  • No credential value/auth file or active client configuration was read or copied.
  • No paid hosting or subscription surface is introduced.
  • Peer-owned paths and worktrees are preserved. Claude retains its three owner-path residuals.

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 3, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T05:50:33.839581Z e91407d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

ACCEPT of the bounded source carryover, exact HEAD e91407d0843d31ba55344359a11d0553f79c8885, base dcae68bd08a191f37ba564eceda9fc4a9d6d4a6e. #613 remains incomplete until this source and its three Claude-owned residuals land.

The whole published tree and the additionally tested retirement candidate9c4d4d8cea2b6db5858ff59dff758bcb927a9d10 both resolve to Git tree 62850ad73b9811be87057b00d78438a8f7efa9e9, native git rev-parse0 and git diff --quiet0. Thus the121-test/1skip proposal/parser observation, pinned three-workflow actionlint and generated metadata checks retain their identical inputs; they were not rerun or presented as upstream/model acceptance. Earlier128/79 checks and Sol/max source ACCEPT at246390aba retain their original narrower inputs. Thirteen of fourteen carried files match that reviewed source; the security workflow preserves merged retirement behavior and changes one cadence comment. The complete new eight-item source/path mapping was read against the original findings.

Actual current-main registration reused register_file atdcae68bd under the shared-file protocol. Eight existing rows update/four are added; all9401 other rows,187receipts,26convergence records and other metadata are preserved. Actual registry SHA256 7868b1ee3132077075a68603dec2950e6e16b67db564c522882e71110ec06bbe; final commit changes only that registry. Fresh validator returned0:69components/9413files/4profiles/187receipts. Diffcheck, clean-status/source-tree proof and native push returned0, with three pre-push guards passing. Actual main was rechecked unchanged atdcae68bd before publication. Native PR API0 confirmed this exact head/base, lane:foundation and exact body equality.

Source interfaces remain the cited GitHub schedule selector and Codex0.160 full hook-source trust discovery. This read adds no installation/default/model/role qualification. Hosted required checks remain pending and govern merge; do not waive them. Preserve all original failed conditions and unknown usage. Native sign-ins stay native; no credential/auth file was read or copied, no Claude-owned path edited.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

#613 eight residuals: current source closure map

Read heads: #639 e91407d0843d31ba55344359a11d0553f79c8885, #619 b4f843852556232d88baf0b3ef1bb87ecd6ad423, #620 e7a83d495a344fc4ed70bedab0f6cf09ffa876a3. This maps the original eight findings. It supplements the existing bounded #639 source ACCEPT. All three PRs were open/unmerged at this read; five root-owned source/publication closures and three Claude-owned passages are distinguished below.

Finding Current closure
1. Daily proposal eligibility #639 source fixes disjoint daily report triggers and the exact Monday-only proposal guard: workflow L194.
2. Inventory cadence #639 source matches the schedule and report/proposal distinction: automation L217.
3. Neighboring schedules #639 records the actual offsets: decision L121. Quota isolation remains unmeasured; this is a wording closure.
4. Template trust states Claude owner pending. Template L2 at #620 still says universally untrusted, byte-identical at all three heads. Historical oracle L9 distinguishes absent state untrusted from stored-hash mismatch modified. #639's corrected multiline explanation L259 needs template parity. This historical oracle used Codex0.157.1, not a new destination run.
5. Column-zero list item #639 source fixes item4's indentation while preserving continuation/contract indentation: decision L154.
6. Published wording/client attribution #639 decision L47 separates published text, repository-installed0.159.3 and destination0.160.0. Claude owner pending: harness-defaults L89 at #619 retains unpublished/Selected wording at all three pins.
7. Weekly references #639 source fixes parser-test/practice references. Claude owner pending: handbook L394 at #620 remains weekly, same blob at all three pins.
8. Unnamed acceptance/spacing Historical PR613 description now names its immutable checkpoint and residual limits; exact readback SHA256 72e93c401b22ddd9c43772ceda084074c7d65a1a1f9d7ae525db7f2c0cae9138.

The template, harness paragraph and handbook passage remain assigned to the Claude owner; no root edit was made there. Their current statuses follow pinned public source, not installation metadata or a repeat test/model run. Required CI and actual landings still gate #639 and full #613 closure. The earlier shorthand “modified/untracked” in my consolidated handoff should read modified/untrusted, as the pinned historical oracle names the absent state; I am correcting that exact handoff body and retaining the correction path.

@seathatflowsinourveins
seathatflowsinourveins merged commit e88d59e into main Oct 3, 2026
25 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the foundation/catalog-freshness-residuals-main-20261003 branch October 3, 2026 07:16
seathatflowsinourveins pushed a commit that referenced this pull request Oct 3, 2026
…uide is on main

The skill-lifecycle bullet pointed to adoption/skills/lifecycle.md "(lands with unit F3)". F3 landed in
3361b34 (#553) and the guide is on main, so the parenthesis is stale. Shared hot file (docs/lanes.md):
AGENTS.md and its manifests/evidence.json re-registration are this branch's only commit, rebuilt on main
e88d59e (#639) with AGENTS.md byte-identical to the acknowledged head 1283e4e.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 3, 2026
Hot-file protocol (docs/lanes.md): the branch's last commit, on main e88d59e (#639), after round 5 and the
rebase (the earlier registration commit was dropped). scripts/validate.py passed (69 components, 9,413 hashed
files); validate_convergence --all-recorded valid (26 records); the verdict review gate passed against
origin/main; 668 focused tests OK (9 environment skips).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 3, 2026
…-16 cause, authority and review date

Round 3 of PR #635, answering the reviews of round 2:
- tests/test_frozen_macos_variant_no_use.py is now a tripwire for direct references. It matches the
  artifact directory's name (the parent of variant/) in every file git ls-files lists except the
  record classes (*.md, evidence/**, manifests/evidence.json, catalogs/**, blueprints/**/*.json), and
  scans configuration and scripts inside those classes too (package.json and other workspace
  manifests, .devcontainer/**, *.toml, *.yml, *.yaml, script suffixes, build files, shebangs,
  executable modes, symbolic links). Whole-file allowances are replaced by 31 pinned lines in 15
  files (sha256 of each stripped line, the module's own constant included); a new referencing line
  fails anywhere, and a pinned line that is no longer found fails too, so a broken scope rule cannot
  drop a pinned file. git ls-files failing is a failure, not a skip. OS metadata files are ignored
  in the variant directory, and an absent variant passes. Its docstring states the limit: a route
  that never spells the name (inventory loop, glob, fragments, Markdown recipe) is not caught.
- Mutation checks in a scratch clone: the reconstructed round-2 mutants, the five round-3 mutants and
  eight added checks fail; the four stated limits and the two allowed cases pass; the unmutated tree
  passes. The results are retained in the receipt's guard_mutation_checks.
- evidence/receipts/dependabot-alert-16-dismissal-20261003.json and the closure record's alert-16
  note: Dependabot alerts come from the dependency graph (manifests, lock files and submissions;
  GitHub Docs read 2026-10-03), so the alert is independent of the OSV exception's scope; the
  dismissal was made at the user's request of 2026-10-03 under section 8's not_used practice
  (alerts 7-15); it has no expiry and is rechecked when the frozen OSV exception (ignoreUntil
  2026-12-24) is renewed, changed or removed, or when the tripwire fails; the live recipe lock pins
  next 16.3.8 (the frozen config's 16.3.6 clause predates #587 and is left unedited). The branch is
  rebased onto main 652c15a (#620, after #639), and the receipt's checked_commit moves to it; the
  files the receipt cites are identical at e88d59e and 652c15a.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant