Skip to content

Record gateway provenance corrections for readiness evidence - #830

Merged
seathatflowsinourveins merged 4 commits into
mainfrom
codex/ns2604-gw-evidence-relabel-prep-20261007
Oct 7, 2026
Merged

seathatflowsinourveins merged 4 commits into
mainfrom
codex/ns2604-gw-evidence-relabel-prep-20261007

Conversation

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

Scope

This PR adds 31 scoped gateway-provenance correction records and their preparation notes. It preserves original results, record bytes and basis digests; it changes no client configuration, runtime, model route or readiness state.

  • Base commit: cd1cd78ec3f8bb82ca4343be4f859a2e107e2035
  • Prepared head: d4565a13a2fc4b1a4ec09f05d5bd7c7c960f87a9
  • Lane: lane:foundation
  • Owned paths: evidence/artifacts/ns2604-gateway-evidence-relabel-20261007/ and native-generated manifests/evidence.json.

Landing path

This is a prerequisite of #775 and #791 under the gateway plan's T10. The co-op performs the byte/hash check and validate at the exact head, the command center ACKs it, and 5f lands it in the slot immediately before #775 on the command center's cue. Records merge before #791's references and #775's publication. Rebase once at the landing turn only if its landing check needs it, then re-register hashes last; no rebase before opening.

Dated cap exception (2026-10-07): this one additive, registry-only-overlap prerequisite may open separately because folding it into #776 at rank 24 would delay the monitoring change; authorized by review-ns2604-coop-20261007T071859Z.

SOTA sources

  • native-agent-stack at 0d5e6506434fab598dee861c749a22e628beb75a: the original caller and artifact snapshots cited by each correction, including examples/omniroute-codex-sdk/worker.py and the install plan's accept.sh. Those pinned sources establish the recorded caller/default basis; they do not prove an unrecorded endpoint.
  • native-agent-stack at cd1cd78ec3f8bb82ca4343be4f859a2e107e2035: docs/acceptance-evidence-policy.md, docs/lanes.md and the unchanged native scripts/host_receipts.py registration API (SHA256 c3dc47cdab33e2ed2f1473700774a006a34c6218d6cd7ceb36f33d7f71f0fd6f).
  • Reviewed gateway plan revision 3.1, SHA256 8ce35229f4b1628e274675b1ab6fa283a240ecaf6ae9165e7dbe7fb7b6424cc3, and readiness change set sections 1–5, SHA256 99c42fd333feef63ad48a5a8b6ff0852540463ff98afd82551b739d37887b088. The new dated A19 schema amendment preserves that SHA-bound original.

Evidence-class table

Claim Evidence class Command / receipt
Five old-default/old-host inferred scopes and 26 unknown reviewer/profile scopes source_review The 31 v1 records contain original item digests and quoted source line/hash bases. No inference is promoted to a recorded endpoint.
Original observations, scoped record bytes and v1 shape preserved source_review Byte/hash and nine-field comparisons against the prepared original; hashes below.
Native registry and repository integrity are consistent local_integration python3 scripts/validate.py: exit 0, 10,448 hashed files; no live provider or GPU execution.

There are 3 E1, 18 E3, 4 E4, 4 E5 and 2 E12 correction scopes. The 31 JSON records are byte-unchanged through the A19 amendment. The README and schema-addendum-A19-20261007.md are separate preparation documents; the latter adds exactly native-no-gateway and not-2604 to the original six class names, retaining the v1 shape and original item scopes. The CC may rename the two spellings before publication. Positive native execution is not assigned a gateway class or left unknown when that same scope is proven native.

Frozen correction hashes

All paths in this table are relative to evidence/artifacts/ns2604-gateway-evidence-relabel-20261007/.

Correction SHA256
e1-grafana-sdk-1-old-gateway-inferred.json 41ec81ce0102a60194dea6db065ae4fd4088691d60afd9a176503b465a36b5e2
e1-grafana-sdk-2-old-gateway-inferred.json 1d26ef660e8d7f99e681062e5481578ec85b086e196f699479019c8b29c40143
e1-grafana-sdk-3-old-gateway-inferred.json 7f0a026d1f2ce4cb2befbce02958fac0aeef503511c62966fb2f61d312a7b3b5
e12-a01-old-host-20261007.json 52e8a279ece0f345a5532032b2771c7fe814a155f083f46c4c3cba06b3aff8bf
e12-a02-old-host-20261007.json ef40e3232bb64b0eaf91e41f268440d4cd24f8c1f27b63f3d742907f97de5fed
e3-L0032-mcp-surfaces--mcp-inspector-20261007.json 8eae901eae4b232e22211380a972c37e8d59598c0b1fa32d0b73c15bd0e1280c
e3-L0040-semantic-rag--code-search-20261007.json ba2e6b176e9ca6f628d7383e2a802fc02fd9428550c97ba017c65f9bb3c8e19d
e3-L0048-durable-memory--memory-owner-20261007.json e454e5348c2a34d0aa4cdf36ffbc7f77d45714448fb52b5d94d9ca49ff06f3dc
e3-L0049-token-efficiency--ccusage-20261007.json e11307552bafac444e96e4ba69bf5717930c7f2847c609f8064c07ef96003a3b
e3-L0050-token-efficiency--context-supply-20261007.json 8f9195d6dbb13b16793a73afca3d758214cb1fdd5ed61c722e19506cc31c259d
e3-L0052-token-efficiency--command-output-20261007.json 93e7707fbc1502d81de50775e8af1bbf6dea4b8e361e705015f805fcdefcb177
e3-L0053-token-efficiency--output-compression-20261007.json 8baf31b963a3d7c0273e5b02c238d60db0668ef17e92fe7205f4041e3e331cd0
e3-L0054-token-efficiency--code-index-20261007.json 68d68d3de0f1a38b75ebb8a118c473824bdf1e0ed8228c3427452d82783a82b2
e3-L0055-token-efficiency--code-graph-20261007.json ddd3cfb512ab352bb7de0185cd740df8ff02134e4facdc0d585cb311d6ce62cd
e3-L0056-token-efficiency--repo-packing-20261007.json 157af92aeb521c59eec67a10f83b0b84607f97031cf6313eb4db65120b2523b4
e3-L0057-token-efficiency--structured-data-20261007.json 70e1c63be916bcc8a8ac63d98fc45d1bee6cf5c754f0f9b03df3f1a4639316be
e3-L0058-token-efficiency--doc-conversion-20261007.json 029628fbd88c77bcfa6b7eabf95e7639e0e44966689922ca6698613dbaf2315d
e3-L0059-token-efficiency--api-docs-20261007.json 24ff83fa47274834f5f9f277457654ce70988b12c57f02a878768afb52f6e00b
e3-L0060-token-efficiency--trace-viewer-20261007.json d07a932f7f8707b6e095e479c8a782f4c879db5bcc65119931ca124b8acf01b7
e3-L0070-observation-inference--session-analytics-20261007.json 6e6b1f164accf1b8e66483e59f6180bf92a00533ca0a611e15364a3b1e6d9b82
e3-L0071-quality-evaluation--inspect-ai-20261007.json f5f1eef8cd97062ab69ec3794f40792e02502a7f3427b09191fab1f31d505d9b
e3-L0083-git-github-automation--difftastic-20261007.json bd9deb930af367e52d58c4f5d7c168d2d586811cb230390c050a36129061c1b3
e3-L0092-isolation--sandbox-runtime-srt-20261007.json fbc83cdbf3e54e51ba6241200e0878a35e9d0bc8741ad949cf21829c043d4f59
e4-a06-unknown-gateway.json e0081f7c97a60f5040968953635c502eec2dd7cae0a719c052fdae85ffe627fa
e4-a07-unknown-gateway.json 5afaf8d5e0c41c3083de986121bbb703328a9f9edb01f35320ff95a78dc9c44d
e4-a09-unknown-gateway.json 1a37c91464ca2fa37cf105d22fb8744f1cf787c3d293d89475cad7188d4a9ab2
e4-a12-unknown-gateway.json d6c646938507c23d7727dd1ee8440f9ed61c8defa3c6d2bc5dba067c972cafcb
e5-b06-profile-scope-unknown.json 83a9b5d602a92880cad07968d71bd563497a7f1c73f9592be9c37c5bd02f35ff
e5-b08-profile-scope-unknown.json 6ae9a2e2f23688d86749d6ad1522c20e976acea32367575cdd73bc7a16e4ce2a
e5-b09-attempt-endpoint-unknown.json cbe2bec96018145b4c71274de24b2f2927fffeda0365a69642cfbf0f2a2834d0
e5-b12-attempt-endpoint-unknown.json 4fc0d03ebeada335538e299226b82cd7be020078d970e7f6974cfc760ca3b471

Preparation-document hashes: README 1323912a18fa87ab13a5121e0c44acc19593d5f7db5b1473ace925fe1b97a571; dated schema amendment 15977627eae5c107e90ae6e5073fc63574f779d466a1a2075222e8cf04fa9124.

Local commands run

rtk proxy nice -n 19 ionice -c3 python3 scripts/validate.py
exit 0; 69 components, 10,448 hashed files, 4 profiles, 224 receipts

git diff --check (captured with the owned-worktree selector)
exit 0

The unchanged native registration API updated the README and registered the new schema document; every other 10,446 registry entry and manifest metadata was retained. Content is committed first; the registry is the last commit. No custom acceptance runner, new client smoke, model request, host apply or organic counter is introduced.

Decision record

evidence/artifacts/ns2604-gateway-evidence-relabel-20261007/schema-addendum-A19-20261007.md is the dated additive record-format amendment. This PR makes no new component-selection or host-readiness decision.

Remaining conditions

E2/E4-private/E5-private/E6/E7/E8/E10 require their qualified, sanitized originals and bases; E9 remains its existing owner's responsibility. Disarmed/provenance labels remain draft until the actual T5 apply receipt and archive bindings exist. The T5 record plus renamed originals are the archive; their bytes are not duplicated. Missing call-log rows prove no route. T4's flagless acceptance-stage hold remains until C0, C1 and A have merged and GW-01 passes. This PR is a provenance publication prerequisite, not a new acceptance or organic-use receipt.

Host evidence

No files under evidence/hosts/ change. No platform status is changed.

Checklist

  • No GitHub Actions workflow changes.
  • No secrets, raw conversations, new authentication requirement or private active configuration.
  • No paid hosting, subscription or billing surface.
  • Peer-owned files, worktrees and historical observations preserved.
  • Independent exact-head read and CC ACK requested through the named landing path.
  • CI at the eventual landing head required; prepared validation is not a claim of current hosted CI.

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 7, 2026
@seathatflowsinourveins
seathatflowsinourveins marked this pull request as ready for review October 7, 2026 08:32
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session native-agent-stack-5f: landing at head d4565a13a2fc4b1a4ec09f05d5bd7c7c960f87a9. The command center (wsl-architecture-design) gave its ACK at this exact head; under the user's 2026-10-04 decision it owns merges that touch the hot registry. The read-only cross-family review (GPT-6.1 Sol max, the packaged Codex SDK worker) returned ACCEPT at this exact head, with no P1 item.

Observed main 5af3e6b89f584cd673766f3724083265c872fcd6. coordination/merge_tree_landing_check.py (sha256 a11649fcf2e5844c…) exit 0:

main 5af3e6b89f584cd673766f3724083265c872fcd6 head d4565a13a2fc4b1a4ec09f05d5bd7c7c960f87a9 base cd1cd78ec3f8bb82ca4343be4f859a2e107e2035 merged-tree a82aecff32de3d7bb27c9720980eaade5141c669 merge-tree-exit 0
ok   1: clean three-way merge
ok   2: merged-vs-main paths 34, outside PR-owned 0 []
ok   3: main drift 45 paths, overlap with PR-owned inputs (registry excluded) []
ok   4: registry foreign rows equal True, order preserved True, PR-owned rows 33, unowned top-level keys differing []
ok   5: merged files[] sorted by path with no duplicates: True (10461 rows)
LANDABLE
condition 5: merged files[] sorted and unique (tree a82aecff32de3d7bb27c9720980eaade5141c669)

Required checks at this head: 7 pass . Unresolved review threads: 0.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T08:37:35.386029Z d4565a1 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@seathatflowsinourveins
seathatflowsinourveins merged commit c44993b into main Oct 7, 2026
25 checks passed
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Claude session native-agent-stack-5f: post-merge observation. Landed as c44993b379da25fae923dbbe70188978af5104aa (parent 5af3e6b89f584cd673766f3724083265c872fcd6), tree a82aecff32de3d7bb27c9720980eaade5141c669. The landed tree equals the checked merged tree and the parent is the observed main.

@seathatflowsinourveins
seathatflowsinourveins deleted the codex/ns2604-gw-evidence-relabel-prep-20261007 branch October 7, 2026 08:32

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d4565a13a2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

"item": "evidence/artifacts/new-wsl-install-plan-20261002/accept.sh",
"item_sha256": "808fd9eef9b48db7a930573f28e660f1b5f9dfc569642ee31fac17a8fb043ba7",
"class": "unknown-gateway",
"label": "E5; original_revision=0d5e6506434fab598dee861c749a22e628beb75a; scope=mcp-inspector profile-based acceptance command, with its failed attempt retained at line1793. The profile command alone does not bind a recorded per-run CODEX_HOME or endpoint; no execution is invented for an unrun entry.",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Distinguish the failed run from the unrun entry

This record simultaneously says the MCP Inspector command has a retained failed attempt and calls the same scope an “unrun entry,” while its only basis is accept.sh:1793, which is merely the recipe command rather than execution evidence. The pinned slots.json separately records the after_sign_in and post_install attempts with exit code 1; when downstream readiness records consume this correction, the current wording can misclassify those historical executions as never run. Cite the actual attempt observations or remove the failed/unrun assertions.

AGENTS.md reference: AGENTS.md:L17-L18

Useful? React with 👍 / 👎.

seathatflowsinourveins added a commit that referenced this pull request Oct 7, 2026
### Scope

Route catalog lookup through QMD's lexical queries and bounded document retrieval; use SocratiCode for semantic catalog search at the main checkout's projectPath. Keep reranking available and prohibit qmd embed/pull. Update current maintenance recipes and native instruction carriers through the repository renderers.

Existing Serena consumers read its manual before navigation, and jCodeMunch consumers obtain the current guide before a typed route with the actual caller model and execution off. Four existing Claude roles gain only Serena's manual tool. Reviewer/builder keep their no-menu boundary, and a focused read of a known path and line remains valid.

This landing repair appends the preregistration's Amendment4 to bind the deliberately changed role bodies and compacts lane-authored RTK explanations within the unchanged compact and startup budgets. The entire composed pre-RTK prefix, upstream awareness, owner's blocks, exact SKILL line, seven exceptions, models and effort are preserved. Prior amendment rows, observations, seals and RUNBOOK bytes remain unchanged.

The canonical code-graph rename is prepared as a separate patch and is excluded from this head under command-center ruling081016Z. Main's existing names remain in both templates, the map, fixtures and carriers. The protected lane token requires the owner's word before the rename can land. Until that follow-up, this host's Claude code-graph access is through the vendor's hook channel only; the stale MCP carrier id is a recorded limitation and is not claimed fixed.

- Base commit: `c44993b379da25fae923dbbe70188978af5104aa` (verified native source; #803 already landed).
- Lane: `lane:foundation`; draft.
- Head: `9985e468fa4997d22630714b2fa6a76666e3cda9`. Native bytes: compact 8076 <8192, rendered 9142, three-file startup 20101 <=20103; full Claude block 4087 <=4100. These are byte gates, not token-use measurements.
- Owned paths: token-lane carriers and their paired handbook text, minimal manual grants and mirrors, Codex template/rendered copies, native loader/routing/sequence tests, current recipes and generated handbook, append-only decisions/preregistration amendment, follow-up receipts and checksum/registry projections.
- ROLE-CARRIER-GAPS and ROLE-GRANTS are separate future work and stay out of this change.

Landing path: explicit command-center cue070358Z and fallback ruling081016Z permit one pushed rebase/content repair onto then-current main while #802/#813/#830 land. The co-op performs the new-head delta read with its CI result; the command center ACKs; 5f lands. A further pushed rebase requires the separate dated landing-conflict cue. Host configuration, cutover and fresh-session/working-day acceptance belong to their owners.

## SOTA sources

- [QMD v2.8.3 lexical query](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L294), [typed searches/rerank](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L321) and [document retrieval](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L412): native lexical subqueries, retrieval and optional rerank. Rerank defaults true (:334-335). [README maintenance syntax:1033-1037](https://github.com/tobi/qmd/blob/v2.8.3/README.md#L1033-L1037) supplies bounded commands.
- [SocratiCode v1.15.0 codebase_search](https://github.com/giancarloerra/SocratiCode/blob/v1.15.0/src/index.ts#L138): semantic search at an absolute projectPath. Owner ruling224125Z selects the routing and preserves rerank-on acceptance; this PR performs no host cutover.
- [Serena c6fbd1c5 manual order](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/resources/config/prompt_templates/system_prompt.yml#L5-L6), [manual tool:28-40](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/workflow_tools.py#L28-L40) and [project/session binding:44-49](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/config_tools.py#L44-L49): manual first, active cwd project and returned session id for switches.
- [jCodeMunch 1.108.330, 28803366, typed route:446-463](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L446-L463), [guide:4743-4752](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L4743-L4752) and [policy:101-128](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/cli/policy.py#L101-L128): guide-first and typed task/model route. These files are unchanged at target1.108.331/d94049d0. The executable schema corrects the guide's query example; no new adaptive-tier setting or upstream rebuild.
- `native-agent-stack@c44993b:tests/test_token_e2e_preregistration.py:637-663,905-909`: later dated role-pin amendment and sealed RUNBOOK contracts. Amendment4 preserves every earlier row/seal and extends the current-row selector. The command center records merge chronology at landing; this is a structural repair and authorizes no run.
- [DeusData/codebase-memory-mcp v0.11.0 release](https://github.com/DeusData/codebase-memory-mcp/releases/tag/v0.11.0), the repository's pinned component, and the command center's native-client read-back identify the canonical server name. Its proposed client-key/wire-id/owner-token correction is kept in the separate patch, preserving every payload and strict fixture. Ruling081016Z explicitly keeps main's names in this publication while the owner's instruction-token decision remains open.
- RTK explanation provenance: `native-agent-stack@2d849ba` (#726) and `@50b9579` (#389), `adoption/templates/codex.AGENTS.template.md` after its exceptions marker. The eight explanations shorten while all facts and protected bytes remain. Command-center064832Z accepted their class and scoped wording.
- Native helpers at `native-agent-stack@c44993b`: `tools/adoption/managed_block.py:169` (`codex_block`), `tools/adoption/codex_roles.py:287` (`f4_block`), `scripts/host_receipts.py:710` (`register_file`), `docs/lanes.md:94-128`. Current generated inventory/handbook and checksum bindings use those repository tools; historical receipts and the frozen catalog passage are preserved.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Documented native routing/manual/guide interfaces | source_review | Pinned upstream files above |
| Carrier rendering, protected bytes, new body pins and tool ids | local_integration | Existing native helpers, hashes and required modules |
| Permission/sequence/byte-mutant/frozen-row controls | synthetic | Existing tests with assertions preserved |
| Deployed use and token savings | Pending owner evidence | No model, host apply or working-day measurement in this repair |

### Local commands run

```text
$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_token_lanes_session_start tests.test_token_lanes_subagent_start tests.test_scaffold_repo tests.test_new_wsl_handbook tests.test_adoption_docs_consistency tests.test_codex_agents tests.test_codex_roles tests.test_codex_worker_lane tests.test_token_e2e_preregistration tests.test_new_wsl_client_config.RecordTests tests.test_install_claude_profile tests.test_managed_block tests.test_task_model_routing tests.test_new_wsl_client_config.MapTests tests.test_new_wsl_client_config.AgentGapTests tests.test_new_wsl_client_config.RenderTests tests.test_new_wsl_client_config.ApplyTests.test_the_first_run_writes_what_the_wired_pieces_name_and_nothing_else
exit 0; Ran 595 tests in 109.929s; OK (skipped=14)

$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_install_claude_profile tests.test_adoption_docs_consistency tests.test_new_wsl_client_config.RecordTests
exit 0; Ran 150 tests in 16.306s; OK (skipped=2)

$ CI=true nice -n 19 ionice -c3 node examples/claude-native/workflows/test-envelope.mjs
exit 0; SUMMARY passed=254 failed=0 total=254

$ CI=true nice -n 19 ionice -c3 python3 -B tools/adoption/new_wsl_client_config.py --check --markdown
exit 0

$ CI=true nice -n 19 ionice -c3 python3 -B scripts/build_new_wsl_handbook.py --check
exit 0
```

The passing 595-test run is retained on unchanged source/assertion inputs from the pre-window checkpoint; the 150-test run checks the concrete relocation-fixture and workflows-README changes in the new main base. Their counts overlap and are not added. The fresh Node run passes 254/254. Strict checksums in both Codex directories and the Claude hook directory, plus `git diff --check`, exit 0. All three Amendment-4 role digests were re-derived in both copies and are unchanged from the previous published head.

```text
$ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py
exit 0; 69 components, 10,482 hashed files, 4 profiles, 224 receipts, status passed
```

The earlier landing composition used source `630b6ece8485a7710ea51321682d5a12e364e25c` and hot commit `5703ef1061b982078038425fada888fd35153868`; its native checks and source-critic result are retained. The authorized locator follow-up changes only `catalogs/foundation/upstream-surface-dispositions.json` and that file's registry row: the `otel.environment` citation now points to the command at `examples/codex-native/README.md:214`. Source commit `2b36cfee` is followed by registry-last commit `9985e468fa4997d22630714b2fa6a76666e3cda9`, with no further rebase. Claude/Codex instruction bytes, role hashes, historical records, namespace and byte budgets remain unchanged.

The registry starts from exact main `c44993b379da25fae923dbbe70188978af5104aa`, registers the same 67 changed-file rows through the native producer, and preserves main's receipt and convergence arrays. The two-file correction passed the 114-test citation module, the two exact failing methods and a second native validator run. The worktree is clean; the shifted-citation scan found no other current target to repair. Historical before/after references remain intact.

```text
$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch
exit 0; 114 tests, 6 skipped

$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch.DispositionCitationTests.test_every_cited_line_names_the_key tests.test_upstream_surface_watch.DispositionCitationTests.test_a_dotted_key_has_its_parent_near_the_citation
exit 0; 2 tests

$ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py
exit 0; integrity and scope passed
```

The hosted run at5703 returned two failures in11,495 tests because the documentation locator moved. A reviewed locator still gates when its repository test fails. This follow-up closes that exact contract; it adds no assertion waiver or namespace change.

Read-only overlap metadata checked all 47 open PRs, including full file pagination where needed. Source overlaps: #645, #706, #709, #754, #769, #770, #775, #776, #795, #810, #821, #826, #829. Shared registry/checksum paths use the hot-file protocol; no peer branch is changed.

Earlier failed CI at3ba ran11,381tests and failed six role-body-pin subcases; its complete failed log is retained privately. The failed 560-test and earlier 595-test preparation runs also remain retained. This repair uses a dated amendment, preserves the older source evidence and strict current-body comparison, and performs no full-suite or provider acceptance run. Validator results are integrity and scope evidence only.

### Decision record

`docs/decisions/2026-10-06-qmd-lexical-catalog-instructions.md` and `docs/decisions/2026-10-07-serena-jcodemunch-native-navigation-wiring.md`, with appended clarifications and the new landing follow-up, explain the behavior and limits. The preregistration README gains Amendment4 only; its RUNBOOK and earlier sealed records stay byte-identical. No prior result is recast as a new run.

### Host evidence

Repository-only change. No live instruction file, MCP registration, hook trust, client setting, gateway setting/key or model session changed. Source/render checks and synthetic fixtures remain distinct from the configuration owner's read-back and organic-use acceptance.

### Checklist

- [x] No GitHub Actions or paid service change.
- [x] No credentials, raw conversations or live client configuration committed.
- [x] Models, effort, owner's blocks and historical observations preserved.
- [x] Peer-owned worktrees and source preserved.
- [x] Native validation passed; changed checksums/registry committed last at the final head.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant