Skip to content

Make standing Ultracode opt-in and record task dispatch scope - #829

Draft
seathatflowsinourveins wants to merge 3 commits into
mainfrom
codex/ns2604-ultracode-standing-off-20261007
Draft

seathatflowsinourveins wants to merge 3 commits into
mainfrom
codex/ns2604-ultracode-standing-off-20261007

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Scope

Shared project settings currently enable Ultracode for every checkout, overriding a user's lower-precedence choice. The portable template also overwrites an existing false with true at the next apply. Remove the standing key from both inputs, preserve explicit task opt-in and generic merge behavior, and clarify the adoption directions that would copy the opt-in profile into persistent settings.

  • Base commit: e712bae606e8d27f010af8e3c13ded6b7a7c207a.
  • Lane: lane:foundation.
  • Owned paths: the two shared JSON inputs, two settings tests, adoption/recipe directions, the workflow README, three dated decision amendments, one displaced catalog citation, and the evidence registry.
  • The September 23 record actually decided the standing switch. The September 29 effort record gains a pointer amendment; effort, models, workflow availability, environment and size guidance retain their values. The October 2 record gains a dated projection read-back for the omitted settings piece; its old counts remain.

Landing path and overlaps

Draft for an independent GPT read, the command center's ACK, then the owner's own direction on the settings change before 5f's landing cue. Requested landing path follows #803, which has landed at b593372; #802 and #813 keep their existing landing turns. The draft and checks are authorized; landing remains held for that owner direction and the relayed 5f cue. One rebase at the landing turn, with main's registry and this PR's registrations last.

#823 adds claudeMdExcludes near the removed project key. #813 changes the same README. Each later lander rebases once on its cue. This PR does not push or rebase either records PR. Instruction files, host/user settings and vendored workflow scripts are outside this change.

SOTA sources

  • Installed Claude Code 2.1.292, native claude --version and claude --help (--settings <file-or-json>, --setting-sources <sources>). Public executable SHA256 a967e7b1d8b4e47ee421d5433027880347952b0c0857abf880e2c942a4ec93b3: optional-boolean ultracode schema at byte 204350508; independent keyword-trigger default at bytes 224707120–224707650. This is installed-client source review, not a new workflow execution.
  • Anthropic settings reference, Ultracode and keyword trigger and settings scope precedence, reviewed 2026-10-07. CLI and project settings outrank user settings; omission leaves explicit user choices intact.
  • Anthropic workflow invocation and Ultracode, especially lines 115–162 and 416–447 in the retrieved Markdown snapshot. Session /effort ultracode on|off, interactive keyword and launch --settings are distinct opt-ins. Ultracode suppresses the large-workflow warning and session concurrency limit; a finite brief is required rather than treating the size setting as an enforced cap.
  • Anthropic subagents and experimental agent teams, reviewed 2026-10-07, for choosing a bounded dispatch mode instead of a standing workflow switch.
  • Anthropic Claude Code changelog at v2.1.292, 2.1.284 effort behavior, line 821 in the reviewed snapshot: Ultracode and effort remain independent.
  • Existing repository merge implementation: tools/adoption/apply_claude_settings.py:297-340,402-443 at the base above. Incoming scalars win; omitted fields and unrelated user choices are preserved. Existing repository decision addendum convention and scripts/host_receipts.py registration govern the append-only records and final registry commit.

Writer and pin audit

Locators in this inventory refer to the base commit above. Complete literal and case-insensitive scans preceded edits: 222 matching files, including historical evidence. The writer denominator is nine distinct setting inputs, generic write paths and adoption directions. Four changed: two standing JSON inputs and two persistent-merge directions. The four generic paths consume the corrected template unchanged; the explicit launch input remains true.

Writer/input Disposition
.claude/settings.json:4 Remove only the standing key.
adoption/templates/claude.settings.template.json:360 Remove only the standing key; fresh apply omits it and existing false or true survives.
examples/claude-native/ultracode.settings.json:4 Retain true as the explicitly selected per-task launch profile.
tools/adoption/apply_claude_settings.py:402-433 (default template :38,438) Retain generic atomic merge; corrected default input prevents re-enabling false. Test omission, preserved choices, idempotence and deliberate opt-in.
tools/adoption/render_config.py:255-270 (template :68) Retain; rendered default settings inherit omission.
tools/adoption/new_wsl_client_config.py:2188-2237 (source :131) Retain; shared-template-derived pieces omit the setting. Read back the resulting piece count in a dated amendment.
adoption/bootstrap-linux.sh:1382-1387 Retain full-profile wrapper; it applies the corrected rendered template.
recipes/claude-native-ultracode.md:58-59 Persistent merge excludes Ultracode; task launches select the explicit profile.
examples/claude-native/workflows/README.md:47-48 Append adjacent dated clarification of explicit profile versus persistent baseline, and task opt-in under “Opt-in and limits.”
Other pin/carrier Disposition
catalogs/foundation/upstream-surface-dispositions.json:2267-2276 Open follow-up for currency/CC: the standing-adoption row still describes the October 4 user setting. Separate standing-off from per-task availability; no row/schema change here.
recipes/claude-native-ultracode.md:181 Correct current starting-choice wording; retain the observed qualification cell.
recipes/claude-native-ultracode.md:109-117 Retain the dated September 23 standing-default paragraph and append a local October 7 supersession linked to the dispatch amendment. This ninth pin was missed in the initial inventory and found by the exact-head read.
catalogs/foundation/decisions.json:2662 Open follow-up for its catalog owner/CC: qualify current activation text that assumes the coordinator is under Ultracode; preserve measured evidence.
adoption/bootstrap.md:548-555 Remove Ultracode from the persistent baseline property list and describe task-scoped selection.
examples/claude-native/workflows/contract.config.json:2 Retain explicit opt-in contract input; writes no live setting.
tools/token-e2e/freeze_snapshot.py:133 Retain boolean observation/drift schema; writes no default.
catalogs/foundation/upstream-surface-baseline.json:280 Retain supported upstream capability name.
adoption/new-wsl/client-config-map.json:299 Retain capability match, which supplies no boolean and creates no piece without an input key.
recipes/sota-convergence-practice.md:36 Open follow-up for its recipe owner/CC: its conditional “with Ultracode on” reference still points to the project file; redirect to explicit opt-in. It does not write a setting.

scripts/build_ecosystem.py:117-125,820,985-987 indexes paths and renders guide content; it contains no independent true-setting writer. It is unchanged; the supported --write refresh was run. tools/adoption/scaffold_repo.py does not emit a Claude settings file (the six-output contract is tested).

Test and historical-record dispositions

The nine test files in the brief are not nine defaults. The complete scan also found the resolver metadata fixture and four generic-writer modules:

Test module Disposition
test_install_claude_profile.py Add omission guard for project/template and retain explicit opt-in; preserve effort/model assertions.
test_apply_claude_settings.py Add actual apply regressions for fresh omission, existing false/true with unrelated settings, idempotence and explicit opt-in.
test_render_config.py, test_new_wsl_client_config.py Retain generic render/apply contracts; run against corrected template.
test_effort_default_guard.py Retain true fixtures that test selected-task compatibility and effort behavior.
test_adoption_bootstrap.py Retain explicit effort selection and historical RTK probe context.
test_adoption_status.py Retain historical E1 tools/profile relationship.
test_freeze_snapshot.py Retain true/false observation and drift fixtures.
test_runtime_worker_openhands.py, test_runtime_worker_openhands_resolver.py Retain source=ultracode SDK serialization metadata fixtures; these are not settings.
test_token_e2e_receipt_checks.py, test_token_e2e_grader.py, test_token_e2e_preregistration.py Retain immutable receipt, grading and source-resolution fixtures.
test_scaffold_repo.py Retain positive six-file output enumeration.

The brief's eight-record count was a lead. Fourteen decision files contain lowercase ultracode; ten more contain a case-insensitive mention. All original text/observations stay intact:

Decision file under docs/decisions/ Disposition
2026-09-23-max-effort-default.md Append the dated task-selection amendment to the actual standing decision.
2026-09-29-max-default-effort.md Append a pointer amendment; preserve the relocated frozen rule and effort history.
2026-10-02-new-wsl-client-configuration.md Append the current projection count; preserve old read-back.
2026-09-25-model-fallback-guard.md Retain historical recipe scope/reference.
2026-09-26-harness-rules-cleanup.md Retain installed-source observation.
2026-09-26-stack-agents-role-dispatch.md Retain historical dispatch reference.
2026-09-27-claude-harness-settings.md Retain settings/source context.
2026-09-27-model-currency.md Retain model/template context.
2026-09-27-token-lanes-subagent-start.md Retain historical recipe reference.
2026-09-28-community-sweep.md Retain sweep/candidate observations.
2026-09-28-delegated-decisions.md Retain source/reference.
2026-09-29-sonnet-5-5-dispatch.md Retain model/effort and dispatch observations.
2026-09-30-task-model-routing.md Retain research/source reference.
2026-10-04-new-wsl-token-layer-default.md Retain historical recipe reference.
2026-10-04-token-full-stack-owner-default.md Retain historical recipe reference.
2026-09-23-claude-user-profile.md, 2026-09-25-codex-mcp-scope.md, 2026-09-25-skills-trial-and-usage.md, 2026-09-26-telemetry-writer-identity.md, 2026-09-28-ecosystem-roadmap.md Retain historical references and observations.
2026-09-30-rule-text-every-layer.md, 2026-09-30-sol-primary-quality-defaults.md, 2026-10-02-mac-claude-resolution.md, 2026-10-03-compaction-window-ab-retirement.md, 2026-10-05-harness-context-budget.md Retain historical references and observations.

The README's insertions preserve all original text. All eleven frozen workflow fixtures and their exact passages remain unchanged. One current catalog citation is adjusted to the sentence's new line; historical source locators are retained as recorded.

Evidence-class table

Claim Evidence class Command / receipt
Optional standing setting, separate opt-in mechanisms and scope precedence source_review Installed 2.1.292 schema/help plus the official documents above.
Default inputs omit the key without changing other settings; apply preserves user choices local_integration Real file apply tests and parsed before/after comparison.
One read-only five-point task, one session per client on 2026-10-07 native_proven CC/co-op sanitized revision-2 extract SHA256 7f5d26c423134ee3c11c4265375d5bdaf1c49280639f4bb7ebc231585c04190d; original/raw records are not committed.
Codex Sol max input 1,390,078, including cached subset 1,264,640; output 18,609; runner wall time 356 s native_proven Client usage block and runner start/end stamps, runner-log SHA256 e41bffad6830f3f25ef922a4140009bcbedd6b03c8bd26ebcc731141a5bb31b9. Cached input is not added again.
Claude standing-on session launched one workflow, 45 turns, about 536 s; cache-read Opus 5.5 25,503,839 and Sonnet 5.5 17,108,897; Fable 5.1 advisor input 297,092/output 34,949 native_proven Client result block in the same sanitized extract. Advisor estimate 4.72 USD is included in total 26.38 USD.
Cost and comparison limits source_review Total is a client estimate, not billing. Different counter scopes and one run each establish no token/cost ratio or quality-equivalent head-to-head.

Local commands run

All commands run under nice -n 19 ionice -c3; durable private logs retain the original output. No live provider run was added.

python3 -m unittest tests.test_install_claude_profile tests.test_apply_claude_settings
rc 0 — 164 tests, 1 skip

python3 -m unittest tests.test_upstream_surface_watch
rc 0 — 114 tests, 6 skips; displaced README citation corrected

python3 -m unittest tests.test_install_claude_profile tests.test_apply_claude_settings tests.test_upstream_surface_watch
rc 0 after J829 amendment — 278 tests, 7 skips

python3 scripts/validate.py
rc 0 — 69 components, 10419 hashed files, 4 profiles, 224 receipts

sha256sum --check --strict SHA256SUMS
node test-envelope.mjs
node test-contract-mutations.mjs
all rc 0 in examples/claude-native/workflows

python3 tools/adoption/new_wsl_client_config.py --check
rc 0 — 397 pieces, 357 wired, 24 not wired, 16 authorization-gated

python3 scripts/build_ecosystem.py --write
rc 0 — refreshed ignored offline guide; generator unchanged

The first full unittest attempt used an interpreter without CI's calendar dependencies. It was stopped with rc 130 after 8678 completed events; that partial run is not a pass. The corrected complete native run at 695d344 returned rc 1: 11501 tests, 15 failures, 1087 skips, 1742.178 s, with CI's hash-locked .github/requirements-ci.txt in an isolated suite venv, separate promotion-gate venv, pinned tree-sitter-bash 0.25.1 and yaml 2.9.0. Invocation matches CI's PYTHONFAULTHANDLER=1 timeout --signal=ABRT --kill-after=60s 55m python3 -m unittest -v --durations 50, with private interpreter paths. Native Python is 3.13.16 and Node 24.21.0; CI uses Python 3.12.3 and Node 22.23.2. This returned native result is a baseline comparison with the environment limitations below; hosted landing CI supplies acceptance of record.

Verification classes (A8, 2026-10-07)

  1. Checks covering this change: validate rc 0; amended apply/install modules 164 tests/1 skip rc 0; citation module 114/6 skips rc 0; workflow checksums/contracts rc 0. Independent source critics verified the nine writer dispositions, preserved historical prefixes and frozen fixtures, and corrected the displaced current citation.

  2. Acceptance of record: hosted validate at the eventual landing head. At initial head 695d344abc61aadda16bff54a3e73a576da1e56a, CodeQL passed; validate did not run because the conflicting PR had no merge ref. Per the co-op's J829 ruling, validate follows the single landing rebase. The exact-head delta read and CC ACK remain conditional on that landing CI and the owner's own settings-change direction.

    CI at 44f77fd: CodeQL green; validate not run (DIRTY, no merge ref)

  3. NativeStack2604 baseline comparison only: the complete local suite returned the failure result above, not a passing result or a gate for opening this draft. native-baseline-failures.json, SHA256 ce14378c52469415de2479eb4b27c680a72d2f62e89aff49da7543888e794eca, retains exact native micro-check failures and positive byte comparisons against unmodified base e712bae and observed main b593372. The co-op checked that the affected files are unchanged and routes the findings separately. The remaining full-run failures are retained and classified separately; they are not silently excluded or all attributed to that four-case receipt.

Reproduced native baseline test IDs:

tests.test_adoption_bootstrap.SystemPackagesBeforePrerequisiteCheckTests.test_skip_system_packages_with_missing_tool_lists_it_and_exits_4
tests.test_adoption_launchd.LaunchdAgentsScriptBehaviorTests.test_lint_falls_back_to_plistlib_when_plutil_is_absent
tests.test_adoption_launchd.LaunchdAgentsScriptBehaviorTests.test_lint_prefers_plutil_when_present
tests.test_adoption_guarded_runners.BoundedRunContainmentTests.test_containment_or_refusal

Three restricted-PATH fixtures omit dirname; the guarded-runner case assumes a positional order for systemd property values and receives running first. The adaptive-paper mutation helper additionally selects a deficient existing host-pinned interpreter rather than the isolated suite interpreter, with no supported override; its five mutation self-test failures remain visible in the full run. CI's fresh runner uses the provisioned interpreter fallback. The co-op routes the shell/property-order findings to the foundation defect owner and the pinned runtime gap to the trading owner through the command center. No unrelated test, host runtime or configuration is changed to bypass these failures. The complete returned result and exact-head CI will be reported before a landing request.

A separate runner correction applies to two additional Codex role-directory failures: setting umask 077 for the local suite's private logs also changed its tests' directory creation modes. Same-head paired controls pass both tests under the ordinary umask 022 (rc 0) and reproduce both failures under 077 (rc 1). These are invocation differences, not inherited defects or PR regressions. The original full output is retained with that limitation; hosted CI remains the acceptance of record.

The completed classification receipt full-baseline-result.json has SHA256 f6c8f557812719fdc6a3620af7a01b21f3ac6c8aeffca92d78ffae178d1ae262. Its fifteen failures are: four restricted-fixture/property-order cases, five pinned-runtime mutation cases, three runner-umask cases (including the dashboard control), one venv user-site skip/mutant-expectation mismatch, one forced local-clone hardlink failure across filesystems, and one installed Claude 2.1.292 notification name (auth_storage_failure) missing from the decision inventory. Related source bytes match the base and observed main; the notification's policy/introduction release is unassigned. Controls/source locators and original failed output remain separate from the change-covering checks and hosted landing acceptance.

Contract changes

contract-changes=none. This PR adds assertions for the default omission and explicit opt-in without reversing or narrowing an existing main assertion. Main's unedited versions of both modified main-carried test files pass on the prepared composition; they will be checked again against the relayed landing base. Any undeclared main-version failure blocks landing.

Decision record

Append-only Amendment (2026-10-07) in docs/decisions/2026-09-23-max-effort-default.md, with alternatives and the upstream-evidence comparison that would overturn the choice. The September 29 pointer amendment directs current readers to it without rewriting decided text. Current new-WSL projection is 397 pieces: 357 wired, 24 not wired, 16 authorization-gated; the earlier recorded 398 remains.

Host evidence

No files under evidence/hosts/ change. This PR records attributed measurements and source review, not a fresh host acceptance or provider run.

Checklist

  • No GitHub Actions changes; existing pinned workflow is used.
  • No secrets printed, logged or committed; no new required secret.
  • No new paid hosting, subscription or billing surface.
  • Peer-owned files and worktrees preserved.
  • Historical observations and decided text retained; amendments are dated additions.
  • Validate, amended modules and workflow contracts pass; final registry-only commit last.
  • Complete suite/remote CI and inherited native-blocker disposition confirmed before landing.

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 7, 2026
@seathatflowsinourveins
seathatflowsinourveins force-pushed the codex/ns2604-ultracode-standing-off-20261007 branch from 695d344 to 44f77fd Compare October 7, 2026 07:51
seathatflowsinourveins added a commit that referenced this pull request Oct 7, 2026
### Scope

Route catalog lookup through QMD's lexical queries and bounded document retrieval; use SocratiCode for semantic catalog search at the main checkout's projectPath. Keep reranking available and prohibit qmd embed/pull. Update current maintenance recipes and native instruction carriers through the repository renderers.

Existing Serena consumers read its manual before navigation, and jCodeMunch consumers obtain the current guide before a typed route with the actual caller model and execution off. Four existing Claude roles gain only Serena's manual tool. Reviewer/builder keep their no-menu boundary, and a focused read of a known path and line remains valid.

This landing repair appends the preregistration's Amendment4 to bind the deliberately changed role bodies and compacts lane-authored RTK explanations within the unchanged compact and startup budgets. The entire composed pre-RTK prefix, upstream awareness, owner's blocks, exact SKILL line, seven exceptions, models and effort are preserved. Prior amendment rows, observations, seals and RUNBOOK bytes remain unchanged.

The canonical code-graph rename is prepared as a separate patch and is excluded from this head under command-center ruling081016Z. Main's existing names remain in both templates, the map, fixtures and carriers. The protected lane token requires the owner's word before the rename can land. Until that follow-up, this host's Claude code-graph access is through the vendor's hook channel only; the stale MCP carrier id is a recorded limitation and is not claimed fixed.

- Base commit: `c44993b379da25fae923dbbe70188978af5104aa` (verified native source; #803 already landed).
- Lane: `lane:foundation`; draft.
- Head: `9985e468fa4997d22630714b2fa6a76666e3cda9`. Native bytes: compact 8076 <8192, rendered 9142, three-file startup 20101 <=20103; full Claude block 4087 <=4100. These are byte gates, not token-use measurements.
- Owned paths: token-lane carriers and their paired handbook text, minimal manual grants and mirrors, Codex template/rendered copies, native loader/routing/sequence tests, current recipes and generated handbook, append-only decisions/preregistration amendment, follow-up receipts and checksum/registry projections.
- ROLE-CARRIER-GAPS and ROLE-GRANTS are separate future work and stay out of this change.

Landing path: explicit command-center cue070358Z and fallback ruling081016Z permit one pushed rebase/content repair onto then-current main while #802/#813/#830 land. The co-op performs the new-head delta read with its CI result; the command center ACKs; 5f lands. A further pushed rebase requires the separate dated landing-conflict cue. Host configuration, cutover and fresh-session/working-day acceptance belong to their owners.

## SOTA sources

- [QMD v2.8.3 lexical query](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L294), [typed searches/rerank](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L321) and [document retrieval](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L412): native lexical subqueries, retrieval and optional rerank. Rerank defaults true (:334-335). [README maintenance syntax:1033-1037](https://github.com/tobi/qmd/blob/v2.8.3/README.md#L1033-L1037) supplies bounded commands.
- [SocratiCode v1.15.0 codebase_search](https://github.com/giancarloerra/SocratiCode/blob/v1.15.0/src/index.ts#L138): semantic search at an absolute projectPath. Owner ruling224125Z selects the routing and preserves rerank-on acceptance; this PR performs no host cutover.
- [Serena c6fbd1c5 manual order](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/resources/config/prompt_templates/system_prompt.yml#L5-L6), [manual tool:28-40](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/workflow_tools.py#L28-L40) and [project/session binding:44-49](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/config_tools.py#L44-L49): manual first, active cwd project and returned session id for switches.
- [jCodeMunch 1.108.330, 28803366, typed route:446-463](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L446-L463), [guide:4743-4752](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L4743-L4752) and [policy:101-128](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/cli/policy.py#L101-L128): guide-first and typed task/model route. These files are unchanged at target1.108.331/d94049d0. The executable schema corrects the guide's query example; no new adaptive-tier setting or upstream rebuild.
- `native-agent-stack@c44993b:tests/test_token_e2e_preregistration.py:637-663,905-909`: later dated role-pin amendment and sealed RUNBOOK contracts. Amendment4 preserves every earlier row/seal and extends the current-row selector. The command center records merge chronology at landing; this is a structural repair and authorizes no run.
- [DeusData/codebase-memory-mcp v0.11.0 release](https://github.com/DeusData/codebase-memory-mcp/releases/tag/v0.11.0), the repository's pinned component, and the command center's native-client read-back identify the canonical server name. Its proposed client-key/wire-id/owner-token correction is kept in the separate patch, preserving every payload and strict fixture. Ruling081016Z explicitly keeps main's names in this publication while the owner's instruction-token decision remains open.
- RTK explanation provenance: `native-agent-stack@2d849ba` (#726) and `@50b9579` (#389), `adoption/templates/codex.AGENTS.template.md` after its exceptions marker. The eight explanations shorten while all facts and protected bytes remain. Command-center064832Z accepted their class and scoped wording.
- Native helpers at `native-agent-stack@c44993b`: `tools/adoption/managed_block.py:169` (`codex_block`), `tools/adoption/codex_roles.py:287` (`f4_block`), `scripts/host_receipts.py:710` (`register_file`), `docs/lanes.md:94-128`. Current generated inventory/handbook and checksum bindings use those repository tools; historical receipts and the frozen catalog passage are preserved.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Documented native routing/manual/guide interfaces | source_review | Pinned upstream files above |
| Carrier rendering, protected bytes, new body pins and tool ids | local_integration | Existing native helpers, hashes and required modules |
| Permission/sequence/byte-mutant/frozen-row controls | synthetic | Existing tests with assertions preserved |
| Deployed use and token savings | Pending owner evidence | No model, host apply or working-day measurement in this repair |

### Local commands run

```text
$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_token_lanes_session_start tests.test_token_lanes_subagent_start tests.test_scaffold_repo tests.test_new_wsl_handbook tests.test_adoption_docs_consistency tests.test_codex_agents tests.test_codex_roles tests.test_codex_worker_lane tests.test_token_e2e_preregistration tests.test_new_wsl_client_config.RecordTests tests.test_install_claude_profile tests.test_managed_block tests.test_task_model_routing tests.test_new_wsl_client_config.MapTests tests.test_new_wsl_client_config.AgentGapTests tests.test_new_wsl_client_config.RenderTests tests.test_new_wsl_client_config.ApplyTests.test_the_first_run_writes_what_the_wired_pieces_name_and_nothing_else
exit 0; Ran 595 tests in 109.929s; OK (skipped=14)

$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_install_claude_profile tests.test_adoption_docs_consistency tests.test_new_wsl_client_config.RecordTests
exit 0; Ran 150 tests in 16.306s; OK (skipped=2)

$ CI=true nice -n 19 ionice -c3 node examples/claude-native/workflows/test-envelope.mjs
exit 0; SUMMARY passed=254 failed=0 total=254

$ CI=true nice -n 19 ionice -c3 python3 -B tools/adoption/new_wsl_client_config.py --check --markdown
exit 0

$ CI=true nice -n 19 ionice -c3 python3 -B scripts/build_new_wsl_handbook.py --check
exit 0
```

The passing 595-test run is retained on unchanged source/assertion inputs from the pre-window checkpoint; the 150-test run checks the concrete relocation-fixture and workflows-README changes in the new main base. Their counts overlap and are not added. The fresh Node run passes 254/254. Strict checksums in both Codex directories and the Claude hook directory, plus `git diff --check`, exit 0. All three Amendment-4 role digests were re-derived in both copies and are unchanged from the previous published head.

```text
$ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py
exit 0; 69 components, 10,482 hashed files, 4 profiles, 224 receipts, status passed
```

The earlier landing composition used source `630b6ece8485a7710ea51321682d5a12e364e25c` and hot commit `5703ef1061b982078038425fada888fd35153868`; its native checks and source-critic result are retained. The authorized locator follow-up changes only `catalogs/foundation/upstream-surface-dispositions.json` and that file's registry row: the `otel.environment` citation now points to the command at `examples/codex-native/README.md:214`. Source commit `2b36cfee` is followed by registry-last commit `9985e468fa4997d22630714b2fa6a76666e3cda9`, with no further rebase. Claude/Codex instruction bytes, role hashes, historical records, namespace and byte budgets remain unchanged.

The registry starts from exact main `c44993b379da25fae923dbbe70188978af5104aa`, registers the same 67 changed-file rows through the native producer, and preserves main's receipt and convergence arrays. The two-file correction passed the 114-test citation module, the two exact failing methods and a second native validator run. The worktree is clean; the shifted-citation scan found no other current target to repair. Historical before/after references remain intact.

```text
$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch
exit 0; 114 tests, 6 skipped

$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch.DispositionCitationTests.test_every_cited_line_names_the_key tests.test_upstream_surface_watch.DispositionCitationTests.test_a_dotted_key_has_its_parent_near_the_citation
exit 0; 2 tests

$ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py
exit 0; integrity and scope passed
```

The hosted run at5703 returned two failures in11,495 tests because the documentation locator moved. A reviewed locator still gates when its repository test fails. This follow-up closes that exact contract; it adds no assertion waiver or namespace change.

Read-only overlap metadata checked all 47 open PRs, including full file pagination where needed. Source overlaps: #645, #706, #709, #754, #769, #770, #775, #776, #795, #810, #821, #826, #829. Shared registry/checksum paths use the hot-file protocol; no peer branch is changed.

Earlier failed CI at3ba ran11,381tests and failed six role-body-pin subcases; its complete failed log is retained privately. The failed 560-test and earlier 595-test preparation runs also remain retained. This repair uses a dated amendment, preserves the older source evidence and strict current-body comparison, and performs no full-suite or provider acceptance run. Validator results are integrity and scope evidence only.

### Decision record

`docs/decisions/2026-10-06-qmd-lexical-catalog-instructions.md` and `docs/decisions/2026-10-07-serena-jcodemunch-native-navigation-wiring.md`, with appended clarifications and the new landing follow-up, explain the behavior and limits. The preregistration README gains Amendment4 only; its RUNBOOK and earlier sealed records stay byte-identical. No prior result is recast as a new run.

### Host evidence

Repository-only change. No live instruction file, MCP registration, hook trust, client setting, gateway setting/key or model session changed. Source/render checks and synthetic fixtures remain distinct from the configuration owner's read-back and organic-use acceptance.

### Checklist

- [x] No GitHub Actions or paid service change.
- [x] No credentials, raw conversations or live client configuration committed.
- [x] Models, effort, owner's blocks and historical observations preserved.
- [x] Peer-owned worktrees and source preserved.
- [x] Native validation passed; changed checksums/registry committed last at the final head.
seathatflowsinourveins added a commit that referenced this pull request Oct 8, 2026
…heck (#838)

### Scope

The required Linux test job runs serially and blocks each landing for roughly half an hour. This change runs native unittest discovery as eight module shards and keeps one final required check named `validate`, which fails on any unsuccessful dependency or incomplete module coverage.

- Base commit: `b16cb8cf7cb8e37bf0d0edb9924502beb3e6a276`.
- Lane: `lane:shared`; the command center requests trading acknowledgement for the one promotion workflow-contract method.
- Owned paths: validate workflow, shard helper/weights, its fixtures, declared workflow-contract tests, the decision/receipt and the final registry commit.
- Landing path: exact-head co-op cross-family read after the draft's hosted timing run; command-center ACK; 5f lands after #833/#836 and before #820/#829/#776, per GO-RELAUNCH230713Z and RULING203309Z. The draft stays draft until that read. Critical-path cap allowance confirmed by item191739Z; all25kind3rows accepted by name in203309Z subject to their stronger-assertion condition.
- #706 relation: this final summary supersedes G-6 (serial suite counts); G-1 (PR-metadata workflow work) stays in #706 for its rank38 turn.

## SOTA sources

- [GitHub matrix strategies and failure handling](https://docs.github.com/en/actions/how-tos/write-workflows/choose-what-workflows-do/run-job-variations), read 2026-10-07.
- [GitHub needs result](https://docs.github.com/en/actions/reference/workflows-and-actions/contexts#needs-context) and [always](https://docs.github.com/en/actions/reference/workflows-and-actions/expressions#always), read 2026-10-07.
- [Skipped jobs](https://docs.github.com/en/actions/how-tos/write-workflows/choose-when-workflows-run/control-jobs-with-conditions) report success even when required; [required status checks](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches#require-status-checks-before-merging) accept skipped statuses. This final job always runs and explicitly rejects skipped/cancelled/failed dependencies.
- [CPython v3.12.3 native discovery](https://github.com/python/cpython/blob/v3.12.3/Lib/unittest/loader.py#L109), [load_tests protocol](https://docs.python.org/3.12/library/unittest.html#load-tests-protocol) and [TextTestRunner](https://docs.python.org/3.12/library/unittest.html#unittest.TextTestRunner). The helper supplies assignment and receipt glue; unittest runs the tests.
- `native-agent-stack@b16cb8c:.github/workflows/validate.yml:147-250`: the unchanged provisioners and diagnostics.
- Same pin, `docs/decisions/2026-10-03-suite-parallelism-trial-outcome.md:24-27`: the superseded Linux serial instruction; failed pool-trial evidence and macOS instruction preserved.
- Existing pinned download/upload artifact actions are reused; no requirement file or other workflow job changes.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Historical timing weights | source_review of retained native output | run37653671981/job112905135751, log SHA b1d2d43e; 17 failures retained |
| Native discovery and assignment | local_integration | Current tree discovery-only sample:272owners/11607cases, no bodies; predates final fixture set |
| Focused contracts and fixtures | local_integration; synthetic fixtures remain synthetic | 368tests/95.067s with one retained serial-binding failure; its authorized class delta3tests/0.874s passes; final new-module13tests/3.383s passes |
| Syntax/integrity | local_integration | actionlint0; offlinezizmor0/findings[]; py_compile0; diff--check0; validate.py0 |
| Hosted timing and exact module/count union | pending | The draft's actual run supplies this; historical estimates are not acceptance |

Expected first-run limitation: this branch is still based on b16cb8c, while main28327acc carries #837's new frozen-lock exceptions. The first osv-scanner check is expected red for that base; it is refreshed only at the command-center landing cue's single rebase. No exception or requirement change is added here, and a local check never substitutes for the landing head's hosted result.

### Local commands run

```text
nice -n 19 ionice -c3 actionlint -color .github/workflows/validate.yml
exit0

nice -n 19 ionice -c3 zizmor --offline --no-config --no-ignores --format json .github/workflows/validate.yml
exit0, []

python3 -I -B -X pycache_prefix=<ignored-owned-path> -m py_compile <helper and five touched test modules>
exit0

nice -n 19 ionice -c3 <activated Python3.12.3> -I -B -X faulthandler <stdlib unittest bootstrap> -q --durations 50
selected: test_validate_shards, test_workflow_hardening, test_shell_parser_ci,
test_landscape_sweep_skills, test_workflow_security_coverage, test_promotion_gate,
test_adoption_docs_consistency
exit1, 368ran/95.067s/onefailure/fiveskips (retained)
Only failure: the promotion class's serial-command binding.
Authorized delta: that class exit0, 3ran/0.874s; other36method ASTs and surrounding bytes preserved.
New fixture deltas:12ran/3.407s and13ran/3.383s, both exit0.
No full-suite phase or hidden baseline waiver.

nice -n 19 ionice -c3 <activated Python3.12.3> -I -B scripts/validate.py
exit0, components69/hashed_files10559/profiles4/receipts226.
git diff --check
exit0
```

The local environment has Python3.12.3/PyYAML6.0.3 and real Node24.21.0/npm11.19.0 bins before generic PATH. It is a focused environment, not full hosted-image parity. Every hosted cell keeps the current installer and promotion/parser/NodeYAML provisioners; non-test checks execute once in cell zero.

### Contract changes

Each listed existing test deliberately replaces the serial whole-suite binding with complete module-shard coverage under `docs/decisions/2026-10-07-validate-module-shards.md` (kind3). Provisioning, history, timeout/faulthandler and native failure controls remain. The one promotion method additionally runs the tiny native aggregate fixture; neighboring and numeric assertions remain byte-identical.

The trading lane's conditional acknowledgement, ledger row `report-native-agent-stack-5f-20261007T200005-shardack`, binds that promotion method to three conditions:

1. Every shard runs the promotion provisioner with `--require-hashes` on `blueprints/us-equities/data/requirements.lock` and exports `REQUIRE_PROMOTION_GATE_VENV=1` before testing, including the shard assigned this module.
2. Module coverage comes from live native discovery, with each module's executed suite exactly once. Weights are scheduling estimates, not a separate test inventory.
3. Final `validate` runs under `if: always()` and passes only on successful shards; cancellation, skipping and timeout fail the gate. The trading lane checks these again on this PR before merge.

| Test ID | Kind | Record |
| --- | --- | --- |
| `tests.test_workflow_hardening.WholeSuiteJobsCheckOutFullHistory.test_whole_suite_jobs_set_fetch_depth_zero` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.WholeSuiteHeadroomAndDiagnostics.test_every_whole_suite_job_names_its_suite_step` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.WholeSuiteHeadroomAndDiagnostics.test_each_suite_lists_its_50_slowest_tests_with_faulthandler_on` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.WholeSuiteHeadroomAndDiagnostics.test_linux_suites_abort_five_minutes_before_the_job_limit` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.WholeSuiteHeadroomAndDiagnostics.test_validate_uploads_its_verbose_log_even_when_the_suite_fails` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.ValidateSuiteStepTracesAHang.test_a_hang_prints_the_hung_test_traceback_and_fails_the_step` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.ValidateSuiteStepTracesAHang.test_control_without_faulthandler_the_hang_leaves_no_traceback` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_provisioning_step_exists_in_the_validate_job` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_provisioning_step_precedes_the_unittest_step` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_step_command_is_derived_from_the_pin_file` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_step_exports_the_directory_through_github_env` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_step_cannot_be_skipped_or_ignored` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_the_provisioning_job_is_the_job_that_runs_the_suite` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_every_whole_suite_job_provisions_the_parser_or_is_a_recorded_gap` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningControls.test_each_mutant_is_reported_in_its_category` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningControls.test_a_scratch_copy_of_the_workflow_without_the_step_fails_the_structure_tests` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.RealRatchetControls.test_the_real_workflows_pass` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.RealRatchetControls.test_a_new_whole_suite_job_in_a_real_workflow_is_reported` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.RealRatchetControls.test_provisioning_a_recorded_gap_job_is_cleared_by_deleting_its_entry` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.RealRatchetControls.test_a_step_that_only_names_the_pin_file_is_judged_by_the_structure_checks` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_landscape_sweep_skills.SkillsYamlProvisioningTests.test_the_validate_job_provisions_the_yaml_pin_before_the_suite` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_landscape_sweep_skills.SkillsYamlProvisioningTests.test_every_whole_suite_job_provisions_the_yaml_pin_or_is_a_recorded_gap` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_landscape_sweep_skills.SkillsYamlProvisioningControls.test_each_mutant_is_reported_in_its_category` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_landscape_sweep_skills.SkillsYamlProvisioningControls.test_the_ratchet_reports_a_new_whole_suite_job_and_a_gap_that_now_provisions` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_promotion_gate.WorkflowProvisioningContract.test_unittest_step_runs_the_full_suite` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |

### Failed attempts and limits

The failed unittest-parallel trial remains unchanged. The historical weighting run failed17 tests. Worker fixture-authoring attempts (one missing-helper error; then one failure/one error among12cases) remain disclosed separately; later root runs do not replace them. An early validate returned1 for pending registry hashes, and an incorrect register_file CLI probe returned2 before the documented Python API was used.

The source critic's two fixture gaps (global zero discovery and a package hook invoking nested discovery) are covered by the passing native delta fixtures. Shared fixture origins trigger an explicit serial fallback; that preserves native semantics and must be reported as a performance constraint. Actual hosted latency, skips and complete module coverage remain pending.

### Decision record

`docs/decisions/2026-10-07-validate-module-shards.md`; scoped observations in `evidence/artifacts/validate-module-shards-20261007/preparation.json`. The final commit changes only `manifests/evidence.json`.

### Host evidence

No host receipt, platform-status change, install or setting change.

### Checklist

- [x] Changed actions pinned to full SHAs with version comments.
- [x] Top-level permissions empty; each job grants contents:read only.
- [x] No credential value or new secret.
- [x] No new billing surface.
- [x] Peer worktrees preserved.
- [ ] Trading acknowledgement before merge (command center requests it).
- [ ] Hosted timing/coverage receipt and exact-head cross-family read.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant