Skip to content

Harness rules: vendor-org upstream first (never rebuild), and a lean, budgeted startup context for Claude and Codex - #726

Merged
seathatflowsinourveins merged 10 commits into
mainfrom
c5/harness-official-upstream-20261005
Oct 5, 2026
Merged

seathatflowsinourveins merged 10 commits into
mainfrom
c5/harness-official-upstream-20261005

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Scope

  • What this PR changes. Two things, across Claude and Codex on both WSLs and in the trading lane.
    • It adds the user's 2026-10-05T04:26:41Z rule to the harness rules: prefer the maintainer's own organization repositories and their clean releases, and never rebuild, fork or wrap what upstream ships.
    • It trims the always-loaded startup context. Client- and task-specific passages move verbatim behind pointers, and a fixed per-client byte budget replaces the upward word ratchet.
  • Base commit: f946c6d4c
  • Lane: lane:foundation. It includes one clause in blueprints/us-equities/AGENTS.md and moves the trading north-star paragraph there verbatim. Trading custody (5f) acknowledges.
  • Owned paths touched: AGENTS.md, examples/claude-native/CLAUDE.md, adoption/templates/codex.AGENTS.template.md, adoption/scaffold/AGENTS.md, the regenerated new-WSL carriers and handbook, blueprints/us-equities/AGENTS.md, docs/decisions/2026-10-05-official-upstream-never-rebuild.md, docs/decisions/2026-10-05-harness-context-budget.md, tests, catalogs/foundation/upstream-surface-dispositions.json, and manifests/evidence.json (last commit).

Measured startup bytes (rendered; record has details):

Surface Before After
AGENTS.md 13,986 10,959
examples/claude-native/CLAUDE.md 13,776 11,575
Codex template 8,190 7,307 (limit < 8,192; rtk's verbatim awareness text moved to adoption/templates/rtk-awareness-full.md, 1,121 B, appended by the carrier)
Claude rendered startup scope 28,794 23,566 (ceiling 24,458)
Codex rendered startup scope 22,176 19,332 (ceiling 20,103)

SOTA sources

  • Claude Code memory and skills documentation:
  • Codex AGENTS.md discovery and size limit: https://developers.openai.com/codex/guides/agents-md, and openai/codex rust-v0.159.3 codex-rs/core/src/agents_md.rs. project_doc_max_bytes is 32 KiB, and @ references are not expanded.
  • rtk's own Claude layout: rtk-ai/rtk v0.51.0 native Claude initializer (RTK.md plus the @RTK.md import).
  • Vendor organizations cited in the rule: alpacahq (alpaca-py v0.44.0, alpaca-mcp-server v2.3.2), nautechsystems (NautilusTrader 1.231.0, 2.0.0rc6), and the official IBKR TWS API (1050.02 / 1051.01).

Evidence-class table

Claim Evidence class Command / receipt
Rendered byte budgets and moves local_integration tests.test_install_claude_profile PortableTopRuleTests (fixed ceilings: Claude 23,062 B, Codex 19,102 B)
Template ≤ 8,192 B local_integration wc -c adoption/templates/codex.AGENTS.template.md = 8,091
Carriers and handbook current local_integration new_wsl_client_config.py --write-blocks/--check, build_new_wsl_handbook.py --write
The 11 moves are verbatim, with pointers kept source_review the record's move table

Local commands run

$ python3 -m unittest tests.test_install_claude_profile tests.test_codex_worker_lane tests.test_scaffold_repo tests.test_new_wsl_client_config tests.test_new_wsl_handbook tests.test_managed_block tests.test_upstream_surface_watch
645 tests: 623 passed, 22 skipped (exit 0)
$ python3 scripts/validate.py   (after the registry commit)
exit 0
$ python3 scripts/validate_convergence.py --all-recorded
exit 0

Decision record

  • docs/decisions/2026-10-05-official-upstream-never-rebuild.md
  • docs/decisions/2026-10-05-harness-context-budget.md: the budget rule and its overturn conditions. The upstream /doctor prompt-audit has no machine-readable CLI form on 2.1.289, which is why a glue test is needed.

Checklist

  • No workflow or Actions change.
  • No secrets.
  • No paid surface.
  • Peer-owned files preserved.

Review chain (bounded): GPT build (jobs 072 and 075), then four rounds:

Round Result
Claude read 1 P1, 6 P2, 1 P3
GPT repair all fixed; co-op sentences S1-S3 adopted
Claude re-check 2 P1, 1 P2, 1 P3
GPT repair 2 all fixed

The coordinator verified repair 2 at ee37894:

  • the CI contract suites: node test-envelope.mjs 254/0 and node test-contract-mutations.mjs 74/0;
  • the budget tests with a symlinked TMPDIR;
  • 7 test modules, exit 0;
  • handbook check, validate and validate_convergence, exit 0;
  • no login-name or host-path hits.

Repair 3 (after CI run 37283231657 found 3 failures): the name-only skill listing is reverted, because the user's 2026-09-30 directive keeps every eligible skill fully listed ("make sure all the skills can invoke seamlessly with llm native end, rather than user end"). 2604's skillListingBudgetFraction is kept, and rtk v0.51.0's awareness text is carried verbatim. Verified at 4f490d3: 1,076 tests OK (29 skipped) across the 10 affected modules, the contract suites 254/0 and 74/0, handbook and client-config checks 0, validate 0, convergence 0.

Recorded gate after landing: the coordinator re-renders the managed blocks on both hosts with F9. After that host gate, the temporary root routing (680 B) is removed and the ceilings re-tighten, per the budget record.

Recorded residuals (bounded review, 2026-10-05)

Claude Opus 5.5 gate read (session 5f) at cb8b3b8 at cb8b3b88c2af returned ACCEPT with no p1. Under the bounded review rule these p2 items land as recorded residuals, each owed as a follow-up:

  • docs/decisions/2026-10-02-new-wsl-client-configuration.md:996 and :1014-1015: Two addenda that the PR added (main cb33948 has neither sentence) still describe the overturned design as current.

Recorded residuals (bounded review, 2026-10-05; Claude Opus 5.5 gate read (session 5f) at 4eebe4c at 4eebe4c)

Claude Opus 5.5 gate read (session 5f) at 4eebe4c at 4eebe4cb486c returned ACCEPT with no p1. Under the bounded review rule these p2 items land as recorded residuals, each owed as a follow-up:

  • docs/decisions/2026-10-02-new-wsl-client-configuration.md:1033 and :1062-1078: The refresh introduced this one.
  • docs/decisions/2026-09-25-skills-trial-and-usage.md:146 (amendment at :1767): This was already on main and is not a merge regression.

🤖 Generated with Claude Code

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 5, 2026
@socket-security

socket-security Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Dependency limit exceeded — report not shown.

This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report.

Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard.

Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account.

@seathatflowsinourveins
seathatflowsinourveins force-pushed the c5/harness-official-upstream-20261005 branch 2 times, most recently from 5096e54 to ee37894 Compare October 5, 2026 08:06
@seathatflowsinourveins
seathatflowsinourveins marked this pull request as ready for review October 5, 2026 08:06
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Trading-lane acknowledgement (trading-owned path blueprints/us-equities/AGENTS.md, docs/lanes.md) at ee37894af62470e581d54fc760de76f5cdeb0071.

I read the blueprint clause at this head against base 4af7417 and acknowledge it from the trading lane:

  • The vendor-org clause matches the user's 2026-10-05 directive. It names alpaca-py, the official Alpaca MCP server where an MCP is needed, nautilus_trader and the official IBKR TWS API distribution, and says to never rebuild what upstream ships, with glue only for demonstrated gaps cited at a pin. It does not conflict with the dispositions in Trading catalog corrections: alpaca-py source pin and mirrors, alpacahq dispositions, IBKR forward note #728:
    • alpaca-mcp-server's paper order path stays rejected;
    • read-only research toolsets stay conditional on qualified credential isolation;
    • "runtime selections stay with the trading lane" keeps NautilusTrader 2.0.0rc5 as the selected destination until rc6 qualifies.
  • The trading north-star paragraph moved verbatim from the root AGENTS.md. The root AGENTS.md:57 routes trading research, experiments, data, strategy gates, decision registration and paper or broker operation to this file.

Follow-up for the trading lane, not a blocker for this PR: the moved paper-lane sentence ("authorized ... after the current foundation work") predates the user's 2026-10-05 instruction to always go on the paper lane for both Alpaca and IBKR. The trading lane will update docs/paper-lane-policy.md and this paragraph in its own PR after this lands.

🤖 Generated with Claude Code

@seathatflowsinourveins seathatflowsinourveins added lane:shared Touches files owned by both lanes; needs both lanes' acknowledgement and removed lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers labels Oct 5, 2026
@seathatflowsinourveins
seathatflowsinourveins force-pushed the c5/harness-official-upstream-20261005 branch 2 times, most recently from 4f490d3 to cb8b3b8 Compare October 5, 2026 14:03
seathatflowsinourveins added a commit that referenced this pull request Oct 5, 2026
…g (macOS full suite red since #732) (#746)

### Scope

- **What this PR changes:** the resolver push-gate tests build their case- and normalization-colliding fixture commits through git plumbing, so the colliding names exist in the tree on any filesystem.
  - Main's macOS full suite has failed `test_case_and_unicode_collisions` (case_collision, unicode_nfc_collision) on every commit since #732 (4fd7106). That failure also shows on every PR.
  - The cause: the fixture wrote the paths through the filesystem, and macOS APFS is case- and normalization-insensitive. Each pair collapsed into one path, so the commit held no collision and the gate correctly passed.
  - The gate (`push_gate.py`) is unchanged.
- **Base commit:** `cb339488e3e0` (origin/main).
- **Lane:** `lane:foundation`, the resolver lane. Tests only, plus the registry row in the last commit.

### SOTA sources

- git/git v2.43.0 `t/t2107-update-index-basic.sh:59-69`: index entries through `update-index --add --cacheinfo`, with no working-tree file. Also git's documentation of `hash-object -w --stdin`, `write-tree`, `commit-tree` and `update-ref`.
- git's `core.ignorecase` and `core.precomposeunicode` settings, both on by default on macOS. They are set to false on every fixture git call.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| main's macOS full suite fails only this test on the main side | hosted CI (observed) | adoption-bootstrap macOS runs 37321600538 (#726) and 37320629278 (#713): the same two subtests; main runs at 4fd7106, c148e04 and cb33948 failed |
| the helper keeps both exact names regardless of the working tree | local_integration (Linux probe) | both names and distinct blobs in `ls-tree` with a pre-existing same-named working-tree file and both folding settings true; restoring the old fixture makes the new tree assertion fail |
| the suite passes | local_integration | `python3 -m unittest tests.test_runtime_worker_openhands_push_gate`: 122 run, 121 OK, 1 existing skip (PyYAML absent) |
| macOS confirmation | pending | this PR's own macOS run (advisory, by the user's 2026-10-05 decision) |

### Local commands run

```
$ python3 -m unittest tests.test_runtime_worker_openhands_push_gate   OK (skipped=1)
$ python3 scripts/validate.py                                         exit 0
$ python3 scripts/evidence_manifest.py --check                        exit 0
$ git diff --check                                                    exit 0
```

### Review

- Built by GPT-6.1 Sol through the packaged SDK worker (round resolver-macos-r1) and committed by the coordinator (Claude session 5f).
- A Claude Opus cross-family read follows.

### Checklist

- [x] No GitHub Actions or workflow changes.
- [x] No secrets printed, logged or committed.
- [x] The gate's behavior is unchanged; tests only.

### Recorded residuals (bounded review, 2026-10-05)

Claude Opus 5.5 cross-family read (session 5f) at ffd5cd3 at `ffd5cd3e99c3` returned ACCEPT with no p1. Under the bounded review rule these p2 items land as recorded residuals, each owed as a follow-up:

- `tests/test_runtime_worker_openhands_push_gate.py:1589 and :1606`: Non-blocking hardening, not a defect.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
Scout and others added 10 commits October 5, 2026 12:24
…ipped functionality

Carry the rule across repository, client, scaffold, new-WSL and trading instructions.
Keep the Codex template within its byte budget through lossless session-lane compressions.
Record the user's words and verified vendor sources without changing runtime selections.

Built by GPT bounded job 072 (GPT-6.1 Sol at max); committed by the coordinator.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Move client-specific and task-specific passages verbatim behind pointers,
retain native workflow dispatch, and correct the RTK safety claim. Use RTK
0.51.0's native Claude RTK.md/import layout and upstream skill-listing
defaults with name-only visibility for specialized audit skills.

Freeze per-client UTF-8 startup ceilings and reopen the dated context audit
when the three upstream instruction documents change. Regenerate the
new-WSL carriers and handbook; preserve historical evidence and role model choices.

Sources and byte measurements:
docs/decisions/2026-10-05-harness-context-budget.md

SOTA sources: Claude memory/skills documentation; openai/codex
rust-v0.159.3 agents_md.rs; rtk-ai/rtk v0.51.0 native Claude initializer.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Restore the A/B-backed StructuredOutput sentence and cross-family dispatch
in Claude's user block. Keep root Codex routing until both hosts render and
read back the current carrier; record that rollout gate explicitly.

Use one installed-skill discovery conditional and the pinned-gap glue rule
on every instruction surface. Amend accepted records and user attribution,
restore the supplied directives, and clean relocated self-pointers.

Retire the owned skillListingBudgetFraction through the existing settings
writer with backup, idempotence and absence read-back. Extend the fixed byte
gate to imports, unconditional Claude rules and Codex overrides; bind moved
passages to heading-scoped frozen bytes and name the child-carrier exemption.
Record required repair ceilings with 5% headroom; keep Codex strictly <8192.

Regenerate carriers and handbook. Seven requested modules pass: 653 tests,
22 skipped. Validate exits 1 for registry drift only (36 mismatches across
18 registered files); diff --check exits 0. The coordinator refreshes registry
hashes and commits last. Protected manifests and standing delegation stay intact.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Restore the effort and unrestricted-size clauses in portable Claude
instructions, adding 273 bytes while retaining the pinned workflow config.
Regenerate the carrier and its dated instruction projection.

Resolve scratch roots and the startup-discovery base before relative-key
comparisons. Reproduce the macOS path layout on Linux with a symlinked
TMPDIR, then verify the existing import/rule/override tests pass.

Correct the budget record: S1-S3 caused the first ceiling raise; the
restored schema and routing rules fit the old ceilings. Record the real
on-demand alternative, mark superseded discovery prose, and require lower
fixed ceilings in the same diff that retires temporary routing after the
host gate. Current ceiling constants and Codex's strict byte limit stay.

The coordinator owns registry reconciliation and the commit.

Acceptance: seven Python modules pass (654 tests, 22 skipped). Symlinked
TMPDIR passes all 12 focused context tests. Workflow envelope and mutation
suites pass 254/254 and 74/74. Carriers check and handbook check pass.
Validate exits 1 for registry drift only (8 mismatches across 4 registered
files). Codex remains 8,186 bytes, strictly below 8,192; diff --check passes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Restore all nine audit skill descriptions and the accepted 0.05 Claude listing
fraction under the user's September 30 LLM-native invocation directive. Keep
explicit key retirement available without automatically retiring this fraction.

Carry the complete rtk-ai/rtk v0.51.0 awareness file at e001f773 verbatim in Codex
carriers and roles, with local exceptions separate. Expand its vendored bytes
through the existing managed-block writer so the template stays below 8,192 B.
Update staging assertions, role hashes, records and the generated carrier.

Rendered startup: Claude 23,566 B; Codex 19,332 B. Keep fixed ceilings
24,458/20,103 B and document mandatory tightening after the host routing gate.

Validation: 421 regression-module tests (7 skipped), 655 harness-module tests
(22 skipped), 90 projection/listing checks; all exit 0. Node contract suites:
254/254 and 74/74. Carrier write/check and handbook check exit 0; template
7,307 B; diff check exit 0. validate.py exits 1 for registry drift only.
Coordinator rebases, re-renders both hosts and refreshes registry last.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Restore main's adopt-pending skillListingBudgetFraction and skillOverrides
observations exactly, preserving the pending host rollout. Keep the accepted
0.05 listing fraction independent of startup file budgets under the user's
September 30 LLM-native skill invocation directive.

Restore apply_claude_settings.py byte for byte from main and align all settings
documentation with its ordinary merge contract. Correct the remaining audit
row that misclassified the accepted listing fraction.

Measure rendered outputs with wc: both Codex carriers are 8,373 B; the inline
source before the 86 B local qualification is 8,287 B. The 8,192 B test covers
only the 7,307 B compact source. The post-host-gate Codex scope is 18,652 B,
with a 19,585 B ceiling; current fixed ceilings remain unchanged.

Validation: 421 regression tests (7 skipped), 655 harness tests (22 skipped),
167 watch/apply-settings tests (6 skipped), all exit 0. Node suites pass 254/254
and 74/74. Carrier write/check, handbook check, wc and diff check exit 0.
validate.py exits 1 for registry drift only. Protected manifests are unchanged;
coordinator commits and refreshes registry last.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…: registry last)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…skill-on decision (five name-only rows read on)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…, 16 authorization) and in-place supersession notes for the listing-fraction lines (gate-read P2)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…: registry last)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins force-pushed the c5/harness-official-upstream-20261005 branch from cb8b3b8 to 4eebe4c Compare October 5, 2026 16:26
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session 5f (trading custody): trading-lane ACK at 4eebe4cb486c80fe4152d2c108a3bd026d88e29f for this lane:shared PR. The command center's foundation ACK is at the same head.

The basis is the Opus gate reads:

  • r2: ACCEPT.
  • r3: FINDINGS, 1 P1 and 3 P2. All four were fixed in repair 4.
  • r4, at cb8b3b88c: ACCEPT.
  • r5, the refresh onto main e7d94e7bc: ACCEPT.
    • The r4 P2 is fixed in place.
    • Two doc P2s are recorded as residuals in this body.
    • 68 of 71 owned paths are patch-id-equal to the accepted head.

The trading lane's sessions and workers read these harness defaults. The skills listing (every skill on) and the context budgets match the decisions on record.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session native-agent-stack-5f: landing at head 4eebe4cb486c80fe4152d2c108a3bd026d88e29f. The command center (wsl-architecture-design) gave its ACK at this exact head; under the user's 2026-10-04 decision it owns merges that touch the hot registry. The read-only cross-family review (GPT-6.1 Sol max, the packaged Codex SDK worker) returned FINDINGS at 5096e547c47b; this head is reached from it through recorded carry edges (equal owned patch-ids, or a cross-family delta read returning ACCEPT at the edge's target), with its 2 P1 item(s) resolved in one repair round as recorded.

Observed main fc500430b794face8841dba25e47a5736e394bc8. coordination/merge_tree_landing_check.py (sha256 a11649fcf2e5844c…) exit 0:

main fc500430b794face8841dba25e47a5736e394bc8 head 4eebe4cb486c80fe4152d2c108a3bd026d88e29f base e7d94e7bcc074edba093994c8853e59b650ce7e0 merged-tree cdb7fbb872c0a9d4ac8ca46d6b4a9252721288ef merge-tree-exit 0
ok   1: clean three-way merge
ok   2: merged-vs-main paths 72, outside PR-owned 0 []
ok   3: main drift 24 paths, overlap with PR-owned inputs (registry excluded) []
ok   4: registry foreign rows equal True, order preserved True, PR-owned rows 50, unowned top-level keys differing []
ok   5: merged files[] sorted by path with no duplicates: True (10206 rows)
LANDABLE
condition 5: merged files[] sorted and unique (tree cdb7fbb872c0a9d4ac8ca46d6b4a9252721288ef)

Required checks at this head: 7 pass . Unresolved review threads: 0.

macOS (advisory). The user decided on 2026-10-05 that macOS checks are advisory. Ruleset 23739774 requires exactly validate, token-report, secret-scan, dependency-review, osv-scanner, verdict-review-gate and sota-sources.

The macOS full suite has carried one failure from main since #732 (4fd7106): tests.test_runtime_worker_openhands_push_gate OwnedPathGateTests.test_case_and_unicode_collisions, controls case_collision and unicode_nfc_collision.

  • Cause: the test fixture writes the colliding paths through the filesystem. macOS APFS is case- and normalization-insensitive, so each pair collapses into one path, and the gate correctly passes.
  • Scope: a test-fixture defect, not a gate defect.
  • Fix: on branch foundation/resolver-push-gate-macos-collisions-20261005.

@seathatflowsinourveins
seathatflowsinourveins merged commit 2d849ba into main Oct 5, 2026
29 of 30 checks passed
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session native-agent-stack-5f: post-merge observation. Landed as 2d849ba1fe1b879144cfa470f0514d3ac3b8e487 (parent fc500430b794face8841dba25e47a5736e394bc8), tree cdb7fbb872c0a9d4ac8ca46d6b4a9252721288ef. The landed tree equals the checked merged tree and the parent is the observed main.

@seathatflowsinourveins
seathatflowsinourveins deleted the c5/harness-official-upstream-20261005 branch October 5, 2026 17:35
seathatflowsinourveins pushed a commit that referenced this pull request Oct 5, 2026
…the new-WSL handbook (registry last)

CI validate at ef48bca failed one test: tests.test_new_wsl_handbook reported "stale generated output:
docs/new-wsl-handbook.md". The earlier merge changed handbook inputs, the merged catalog among them, without
regenerating the handbook. This merge brings in main 2d849ba (#713, #726, #736 and the other afternoon landings).
Only the registry conflicted; it is main's registry with this branch's rows re-registered.

The handbook was regenerated with `python3 scripts/build_new_wsl_handbook.py --write`, and --check passes. Its
receipt records the new outputs, the current generator and profile digests, and an eighth regenerations entry with the
previous outputs.

Checks: validate.py exit 0; validate_convergence --all-recorded exit 0; evidence_manifest --check passed (10,240
files); tests.test_architecture_pin_source, test_new_wsl_handbook, test_ecosystem_manifest and test_stack_lifecycle OK.
uv.lock and pyproject.toml of the 2604 runtime are unchanged, so the 2604 qualification still carries.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 6, 2026
…726 gate-read P2s, and #713's macOS-only failures

- Codex: the new-WSL additions set service_tier = "default" (standard), per the user's
  "Normal, fast on demand (Recommended)" at 2026-10-05T13:22:24Z; cited at openai/codex
  rust-v0.160.0; dated amendment in the changelog-parity record (and "their yes").
- #726 residuals: the repair-round-3 authorization table regenerated from --check --markdown
  (16 rows); find-skills' pinned Listing row matches the manifest (on, Codex yes).
- #713 residuals: the research-harnesses owner note names round 4's compatibility amendments;
  the ntfy.sh/Telegram 'alert text leaves the host' note in the plan README and row.
- #713 macOS-only failures (CI 37320629278): the chrome acceptance test stubs the WSL-only dpkg
  comparator with exact arguments; the Harbor guard uses the Bash 3.2-portable ${VAR+x} test
  instead of [[ -v ]] (main's bootstrap-macos.sh precedent).

Built by a GPT-6.1 Sol worker (job-080); reviewed by the coordinator.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Oct 6, 2026
…726 gate-read P2s, #713's macOS-only fixes (#752)

### Scope

An upgraded Codex home kept the previous managed `service_tier = "fast"` despite the selected normal default. F9 now migrates that one declared value through the native config writer, verifies readback and records completion so later `/fast` choices survive. Round 3 also completes adoption for preserved tiers such as `flex`, and handles marker-only completion without a config write, process check or backup.

- Base: `ecfa112764c664d35377dd66b8cfcb67e5a94d60`; lane: `lane:foundation`.
- Native migration introduced by `3c779ea2f97d9cc1b437c0385c53fff5887a8f13`; Round 3 repairs: `8c1cfd39dc7058464667d235e30019aa187883d3`. Validated head: `d2f6d8c3de42226cf37fea5b145bfae73f867482`.
- Existing differing scalars remain conflicts. Native replacement is limited to literal previous `fast`; actual marker readback must match `plan.expected`. Missing-writer dry-run refuses consistently with apply, and native local rejection diagnostics retain their text.
- Retained original residual repairs: regenerated authorization table; find-skills' on/Codex listing; round-4 research-harness owner note; alert-text egress note; macOS comparator fixture and Bash 3.2-portable Harbor guard.
- Owned paths: client-config tool/test/map/template, WSL operator recipe, linked decisions, install-plan residual files, sanitized migration receipt and evidence registry. Registry is the final commit. Disposition-catalog correction is a dated follow-up in the migration decision.
- #756 separately reports profile drift; whichever of #752 and #756 lands second rebases onto the first. PR readiness and landing remain with the command center.

## SOTA sources

- Handbook CI repair follows the maintained repository generator at `native-agent-stack@d2f6d8c:scripts/build_new_wsl_handbook.py:189-190,693,1196-1199,1209-1242`, its existing freshness oracle `tests/test_new_wsl_handbook.py:1440-1457`, and the exact native CI command `.github/workflows/validate.yml:235-240`.

- openai/codex@`a956835d020762cb2b570053af06f643a11c0ecc` (rust-v0.160.0): [service-tier persistence:105-122](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/tui/src/config_update.rs#L105-L122), [native batch request:154-170](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/tui/src/config_update.rs#L154-L170), [toggle:47-57](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/tui/src/chatwidget/service_tiers.rs#L47-L57), [persistence event:99-117](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/tui/src/chatwidget/service_tiers.rs#L99-L117), [event dispatch:2391-2396](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/tui/src/app/event_dispatch.rs#L2391-L2396) and [Fast aliases:547-551](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/protocol/src/config_types.rs#L547-L551). These support completion for preserved tiers while retaining later native choices.
- Same pin: [config-manager write response:426-438](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/app-server/src/config_manager_service.rs#L426-L438), [canonical fingerprint:54-65](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/config/src/fingerprint.rs#L54-L65), [tier resolution:35-42](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/tui/src/service_tier_resolution.rs#L35-L42) and [model catalog:512](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/models-manager/models.json#L512). Native versions are configuration hashes; rollback hashes the same validated disk snapshot.
- Reused native wrapper, native-agent-stack@`32e6b0bde15d82cfbcccb117af3a728c5e9eeb5d`: [AppServer:514-560](https://github.com/seathatflowsinourveins/native-agent-stack/blob/32e6b0bde15d82cfbcccb117af3a728c5e9eeb5d/tools/adoption/apply_codex_lane.py#L514-L560), [guarded transaction:1257-1273](https://github.com/seathatflowsinourveins/native-agent-stack/blob/32e6b0bde15d82cfbcccb117af3a728c5e9eeb5d/tools/adoption/apply_codex_lane.py#L1257-L1273). No new scalar editor or RPC wrapper.
- Marker-only contract at native-agent-stack@`3bbcc780dfc34829219dff169b283f29a10845c1`: [Decision 11:210](https://github.com/seathatflowsinourveins/native-agent-stack/blob/3bbcc780dfc34829219dff169b283f29a10845c1/docs/decisions/2026-10-02-new-wsl-client-configuration.md#L210), [running-process control:3599-3602](https://github.com/seathatflowsinourveins/native-agent-stack/blob/3bbcc780dfc34829219dff169b283f29a10845c1/tests/test_new_wsl_client_config.py#L3599-L3602), [failed-pgrep control:3662-3668](https://github.com/seathatflowsinourveins/native-agent-stack/blob/3bbcc780dfc34829219dff169b283f29a10845c1/tests/test_new_wsl_client_config.py#L3662-L3668).
- Original residual sources: native-agent-stack@`2d849ba1fe1b879144cfa470f0514d3ac3b8e487`, `tools/adoption/new_wsl_client_config.py:1421-1446`, `adoption/skills/manifest.json:542-564`, `evidence/artifacts/final-architecture-round2-20261004/integration-resolutions.json:1614-1674` and `adoption/bootstrap-macos.sh`; prometheus/alertmanager@v0.34.1, [Telegram configuration](https://github.com/prometheus/alertmanager/blob/v0.34.1/docs/configuration.md#telegram_config); historical hosted-macOS [run 37320629278](https://github.com/seathatflowsinourveins/native-agent-stack/actions/runs/37320629278), artifact `full-suite-macos.log:12587-12637`.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Tier semantics and supported native writer | source_review | Pinned upstream and repository sources above |
| Upgrade, preserved flex followed by fast, version/readback rejection and rollback | synthetic | AppServer fixture checks RPC edits/versions; no real native writer or provider session |
| Marker-only works with a running process or failing pgrep, without backup/native calls; dry-run and actual readback controls | local_integration with synthetic homes/clients | Full module: 205 tests, exit 0; owned sleep process in one control |
| Wiring, registered hashes and scope | local_integration | `--check` and `validate.py`, exit 0; integrity only |
| Original hosted-macOS failure diagnosis | historical hosted CI | Run 37320629278; new macOS acceptance is not claimed |

### Local commands run

The three requested checks were rerun on the committed head above. Heavy checks use `nice 19`, `PYTHONDONTWRITEBYTECODE=1` and an owned external-cache `TMPDIR`; private paths are omitted here. Generator outputs and whitespace checks are from the final commit preparation.

```text
rtk proxy nice -n 19 python3 -m unittest tests.test_new_wsl_client_config -q
exit 0: Ran 205 tests in 78.337s; OK
rtk proxy nice -n 19 python3 -B tools/adoption/new_wsl_client_config.py --check
exit 0: check passed; two existing mcp-inspector manifest/install-plan warnings
rtk proxy nice -n 19 python3 scripts/component_matrix.py --write
exit 0: 32 rows, 0 flip-rule violations
rtk proxy nice -n 19 python3 scripts/new_host_grand_list.py --write
exit 0: 32 layers, 66 winners
rtk proxy nice -n 19 python3 scripts/validate.py
exit 0: 69 components, 10274 hashed files, 4 profiles, 212 receipts; passed
rtk git diff --check
exit 0
```

The receipt retains earlier failures/results and Round 3's five failing controls followed by 16 passing focused checks and the full module. The original pre-migration 426-test run remains historical; it is not represented as rerun after these repairs. CI status is separate from local acceptance.

### Validate repair (2026-10-06)

The required validate job at `d2f6d8c3de42226cf37fea5b145bfae73f867482` failed its existing handbook freshness assertion. #752 added migration prose to the hashed distro guide without regenerating the two handbook artifacts. The recorded `4e505c4e...` digest matches main/base `ecfa112...`; the PR's input is `f6401392...`. This is #752 input drift, and OSV is a separate job.

Regenerated through the unchanged repository builder and refreshed the handbook receipt's two output hashes, preserving its regeneration history. The generated MD and JSON diffs contain **only that provenance digest**. No generator, test, client template, migration logic or host configuration changed in this repair.

Source chain: `native-agent-stack@d2f6d8c:scripts/build_new_wsl_handbook.py:189-190,693,1196-1199,1209-1242`; `tests/test_new_wsl_handbook.py:1440-1457`; `.github/workflows/validate.yml:235-240`. [Original failed CI job](https://github.com/seathatflowsinourveins/native-agent-stack/actions/runs/37401702955/job/112071390644). Repair receipt: `evidence/artifacts/codex-service-tier-migration-20261005/ci-validate-repair-20261006.json`.

| Repair observation | Evidence class | Returned result |
| --- | --- | --- |
| Original hosted CI failure | independent CI observation | 11,365 tests / 1 freshness failure / 1,026 skips |
| Exact workflow command on frozen local head | local integration, native environment differs | exit 1; 10,361 tests / 19 failures / 18 errors / 905 skips; targeted freshness failure reproduced |
| Native generator before/after repair | structural validation, discriminating control | --check exit 1 before; --write and --check exit 0 after |
| Existing handbook test module | local integration | 76 tests, 32.202s, exit 0 |
| Attribution and minimal output delta | source review | independent reader confirms only one of 38 input hashes changed; no generator edit |

The full local suite result is retained without calling it green: it lacks `exchange_calendars`, and has additional native shell/fixture/containment/export/installed-client notification findings not present in CI's failure summary. Those are separate owner follow-ups; this repair disables no gate and installs nothing on the shared host. Local Python is 3.13.16; CI's declared interpreter is 3.12.3.

The workflow's run block was executed unchanged at nice 19, with private external-cache RUNNER_TEMP/TMPDIR:
```sh
set -o pipefail
mkdir -p "$RUNNER_TEMP/suite"
timeout --signal=ABRT --kill-after=60s 55m \
  python3 -m unittest -v --durations 50 2>&1 | tee "$RUNNER_TEMP/suite/unittest-verbose.log"
# exit 1; frozen baseline above

rtk proxy nice -n 19 python3 scripts/build_new_wsl_handbook.py --write
rtk proxy nice -n 19 python3 scripts/build_new_wsl_handbook.py --check
# each exit 0

TMPDIR=<owned-cache> PYTHONDONTWRITEBYTECODE=1 rtk proxy nice -n 19 python3 -m unittest -v tests.test_new_wsl_handbook
# exit 0; 76 tests, 32.202s
```

Final repair validation: `TMPDIR=<owned-cache> PYTHONDONTWRITEBYTECODE=1 rtk proxy nice -n 19 python3 scripts/validate.py` exit 0 (69 components, 10,275 hashed files, 4 profiles, 212 receipts); `rtk git diff --check` exit 0. Component-matrix and grand-list regeneration both exit 0, unchanged, with zero status flips.

Generated handbook/receipt and registry changes are in the last repair commit. New-head CI is observed after push; local green is not a predeclared GitHub acceptance result.

### Decision record

[Codex service-tier migration](docs/decisions/2026-10-05-codex-service-tier-migration.md), including Round 3 marker policy and dated disposition follow-up; [normal-default amendment](docs/decisions/2026-10-04-new-wsl-changelog-parity.md#amendment-2026-10-05-normal-by-default-fast-on-demand). A later user policy choice or supported upstream migration facility would reopen the decision.

### Host evidence

No new host receipt, native-writer execution, provider acceptance or platform-status promotion. The next approved F9 apply after landing **rewrites an upgraded home's unmarked previous `fast` value through a native app-server write**, with backup and readback before marker completion. Marker-only adoption leaves config bytes intact. The configuration owner performs host application; this lane made no host configuration change.

Recovery limits remain documented: separate config/marker writes, failed fresh adoption before a later `/fast` choice, canonical-version formatting limits and additional migration-rule recovery policy. The synthetic AppServer fixture does not establish native writer acceptance.

### Checklist

- [x] No GitHub Actions changes; workflow pin and permission requirements unaffected.
- [x] No secrets printed, logged or committed; no new required secret.
- [x] No new paid hosting, subscription or billing surface.
- [x] Peer-owned files and worktrees preserved.
- [x] Native supported writer reused; one `lane:foundation` label; registry last; no merge or readiness toggle.
seathatflowsinourveins added a commit that referenced this pull request Oct 7, 2026
### Scope

Route catalog lookup through QMD's lexical queries and bounded document retrieval; use SocratiCode for semantic catalog search at the main checkout's projectPath. Keep reranking available and prohibit qmd embed/pull. Update current maintenance recipes and native instruction carriers through the repository renderers.

Existing Serena consumers read its manual before navigation, and jCodeMunch consumers obtain the current guide before a typed route with the actual caller model and execution off. Four existing Claude roles gain only Serena's manual tool. Reviewer/builder keep their no-menu boundary, and a focused read of a known path and line remains valid.

This landing repair appends the preregistration's Amendment4 to bind the deliberately changed role bodies and compacts lane-authored RTK explanations within the unchanged compact and startup budgets. The entire composed pre-RTK prefix, upstream awareness, owner's blocks, exact SKILL line, seven exceptions, models and effort are preserved. Prior amendment rows, observations, seals and RUNBOOK bytes remain unchanged.

The canonical code-graph rename is prepared as a separate patch and is excluded from this head under command-center ruling081016Z. Main's existing names remain in both templates, the map, fixtures and carriers. The protected lane token requires the owner's word before the rename can land. Until that follow-up, this host's Claude code-graph access is through the vendor's hook channel only; the stale MCP carrier id is a recorded limitation and is not claimed fixed.

- Base commit: `c44993b379da25fae923dbbe70188978af5104aa` (verified native source; #803 already landed).
- Lane: `lane:foundation`; draft.
- Head: `9985e468fa4997d22630714b2fa6a76666e3cda9`. Native bytes: compact 8076 <8192, rendered 9142, three-file startup 20101 <=20103; full Claude block 4087 <=4100. These are byte gates, not token-use measurements.
- Owned paths: token-lane carriers and their paired handbook text, minimal manual grants and mirrors, Codex template/rendered copies, native loader/routing/sequence tests, current recipes and generated handbook, append-only decisions/preregistration amendment, follow-up receipts and checksum/registry projections.
- ROLE-CARRIER-GAPS and ROLE-GRANTS are separate future work and stay out of this change.

Landing path: explicit command-center cue070358Z and fallback ruling081016Z permit one pushed rebase/content repair onto then-current main while #802/#813/#830 land. The co-op performs the new-head delta read with its CI result; the command center ACKs; 5f lands. A further pushed rebase requires the separate dated landing-conflict cue. Host configuration, cutover and fresh-session/working-day acceptance belong to their owners.

## SOTA sources

- [QMD v2.8.3 lexical query](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L294), [typed searches/rerank](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L321) and [document retrieval](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L412): native lexical subqueries, retrieval and optional rerank. Rerank defaults true (:334-335). [README maintenance syntax:1033-1037](https://github.com/tobi/qmd/blob/v2.8.3/README.md#L1033-L1037) supplies bounded commands.
- [SocratiCode v1.15.0 codebase_search](https://github.com/giancarloerra/SocratiCode/blob/v1.15.0/src/index.ts#L138): semantic search at an absolute projectPath. Owner ruling224125Z selects the routing and preserves rerank-on acceptance; this PR performs no host cutover.
- [Serena c6fbd1c5 manual order](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/resources/config/prompt_templates/system_prompt.yml#L5-L6), [manual tool:28-40](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/workflow_tools.py#L28-L40) and [project/session binding:44-49](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/config_tools.py#L44-L49): manual first, active cwd project and returned session id for switches.
- [jCodeMunch 1.108.330, 28803366, typed route:446-463](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L446-L463), [guide:4743-4752](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L4743-L4752) and [policy:101-128](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/cli/policy.py#L101-L128): guide-first and typed task/model route. These files are unchanged at target1.108.331/d94049d0. The executable schema corrects the guide's query example; no new adaptive-tier setting or upstream rebuild.
- `native-agent-stack@c44993b:tests/test_token_e2e_preregistration.py:637-663,905-909`: later dated role-pin amendment and sealed RUNBOOK contracts. Amendment4 preserves every earlier row/seal and extends the current-row selector. The command center records merge chronology at landing; this is a structural repair and authorizes no run.
- [DeusData/codebase-memory-mcp v0.11.0 release](https://github.com/DeusData/codebase-memory-mcp/releases/tag/v0.11.0), the repository's pinned component, and the command center's native-client read-back identify the canonical server name. Its proposed client-key/wire-id/owner-token correction is kept in the separate patch, preserving every payload and strict fixture. Ruling081016Z explicitly keeps main's names in this publication while the owner's instruction-token decision remains open.
- RTK explanation provenance: `native-agent-stack@2d849ba` (#726) and `@50b9579` (#389), `adoption/templates/codex.AGENTS.template.md` after its exceptions marker. The eight explanations shorten while all facts and protected bytes remain. Command-center064832Z accepted their class and scoped wording.
- Native helpers at `native-agent-stack@c44993b`: `tools/adoption/managed_block.py:169` (`codex_block`), `tools/adoption/codex_roles.py:287` (`f4_block`), `scripts/host_receipts.py:710` (`register_file`), `docs/lanes.md:94-128`. Current generated inventory/handbook and checksum bindings use those repository tools; historical receipts and the frozen catalog passage are preserved.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Documented native routing/manual/guide interfaces | source_review | Pinned upstream files above |
| Carrier rendering, protected bytes, new body pins and tool ids | local_integration | Existing native helpers, hashes and required modules |
| Permission/sequence/byte-mutant/frozen-row controls | synthetic | Existing tests with assertions preserved |
| Deployed use and token savings | Pending owner evidence | No model, host apply or working-day measurement in this repair |

### Local commands run

```text
$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_token_lanes_session_start tests.test_token_lanes_subagent_start tests.test_scaffold_repo tests.test_new_wsl_handbook tests.test_adoption_docs_consistency tests.test_codex_agents tests.test_codex_roles tests.test_codex_worker_lane tests.test_token_e2e_preregistration tests.test_new_wsl_client_config.RecordTests tests.test_install_claude_profile tests.test_managed_block tests.test_task_model_routing tests.test_new_wsl_client_config.MapTests tests.test_new_wsl_client_config.AgentGapTests tests.test_new_wsl_client_config.RenderTests tests.test_new_wsl_client_config.ApplyTests.test_the_first_run_writes_what_the_wired_pieces_name_and_nothing_else
exit 0; Ran 595 tests in 109.929s; OK (skipped=14)

$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_install_claude_profile tests.test_adoption_docs_consistency tests.test_new_wsl_client_config.RecordTests
exit 0; Ran 150 tests in 16.306s; OK (skipped=2)

$ CI=true nice -n 19 ionice -c3 node examples/claude-native/workflows/test-envelope.mjs
exit 0; SUMMARY passed=254 failed=0 total=254

$ CI=true nice -n 19 ionice -c3 python3 -B tools/adoption/new_wsl_client_config.py --check --markdown
exit 0

$ CI=true nice -n 19 ionice -c3 python3 -B scripts/build_new_wsl_handbook.py --check
exit 0
```

The passing 595-test run is retained on unchanged source/assertion inputs from the pre-window checkpoint; the 150-test run checks the concrete relocation-fixture and workflows-README changes in the new main base. Their counts overlap and are not added. The fresh Node run passes 254/254. Strict checksums in both Codex directories and the Claude hook directory, plus `git diff --check`, exit 0. All three Amendment-4 role digests were re-derived in both copies and are unchanged from the previous published head.

```text
$ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py
exit 0; 69 components, 10,482 hashed files, 4 profiles, 224 receipts, status passed
```

The earlier landing composition used source `630b6ece8485a7710ea51321682d5a12e364e25c` and hot commit `5703ef1061b982078038425fada888fd35153868`; its native checks and source-critic result are retained. The authorized locator follow-up changes only `catalogs/foundation/upstream-surface-dispositions.json` and that file's registry row: the `otel.environment` citation now points to the command at `examples/codex-native/README.md:214`. Source commit `2b36cfee` is followed by registry-last commit `9985e468fa4997d22630714b2fa6a76666e3cda9`, with no further rebase. Claude/Codex instruction bytes, role hashes, historical records, namespace and byte budgets remain unchanged.

The registry starts from exact main `c44993b379da25fae923dbbe70188978af5104aa`, registers the same 67 changed-file rows through the native producer, and preserves main's receipt and convergence arrays. The two-file correction passed the 114-test citation module, the two exact failing methods and a second native validator run. The worktree is clean; the shifted-citation scan found no other current target to repair. Historical before/after references remain intact.

```text
$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch
exit 0; 114 tests, 6 skipped

$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch.DispositionCitationTests.test_every_cited_line_names_the_key tests.test_upstream_surface_watch.DispositionCitationTests.test_a_dotted_key_has_its_parent_near_the_citation
exit 0; 2 tests

$ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py
exit 0; integrity and scope passed
```

The hosted run at5703 returned two failures in11,495 tests because the documentation locator moved. A reviewed locator still gates when its repository test fails. This follow-up closes that exact contract; it adds no assertion waiver or namespace change.

Read-only overlap metadata checked all 47 open PRs, including full file pagination where needed. Source overlaps: #645, #706, #709, #754, #769, #770, #775, #776, #795, #810, #821, #826, #829. Shared registry/checksum paths use the hot-file protocol; no peer branch is changed.

Earlier failed CI at3ba ran11,381tests and failed six role-body-pin subcases; its complete failed log is retained privately. The failed 560-test and earlier 595-test preparation runs also remain retained. This repair uses a dated amendment, preserves the older source evidence and strict current-body comparison, and performs no full-suite or provider acceptance run. Validator results are integrity and scope evidence only.

### Decision record

`docs/decisions/2026-10-06-qmd-lexical-catalog-instructions.md` and `docs/decisions/2026-10-07-serena-jcodemunch-native-navigation-wiring.md`, with appended clarifications and the new landing follow-up, explain the behavior and limits. The preregistration README gains Amendment4 only; its RUNBOOK and earlier sealed records stay byte-identical. No prior result is recast as a new run.

### Host evidence

Repository-only change. No live instruction file, MCP registration, hook trust, client setting, gateway setting/key or model session changed. Source/render checks and synthetic fixtures remain distinct from the configuration owner's read-back and organic-use acceptance.

### Checklist

- [x] No GitHub Actions or paid service change.
- [x] No credentials, raw conversations or live client configuration committed.
- [x] Models, effort, owner's blocks and historical observations preserved.
- [x] Peer-owned worktrees and source preserved.
- [x] Native validation passed; changed checksums/registry committed last at the final head.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:shared Touches files owned by both lanes; needs both lanes' acknowledgement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant