ORB-262: make orchestrate own final-head PR readiness - #694
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. 1 Skipped Deployment
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 50d3a3082b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f16d0057ac
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
DEGRADED: same-vendor review BLOCKING: independent pr-review round 1 on Blocking findings
Follow-up tickets filed
Dimensions marked N/A
Dimensions 1, 2, 3, 5, and 13 were walked across the complete 3,902-line harness diff. No Non-blocking findings survived verification. A machine never merges. |
|
@codex review |
|
DEGRADED: same-vendor review BLOCKING: independent pr-review round 2 on Frozen findings
Admitted round-two blocker
Follow-up tickets filed
Review scope
A machine never merges. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0ad30d5acb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
…dy-lifecycle # Conflicts: # CLAUDE.md
There was a problem hiding this comment.
💡 Codex Review
orbit-ui-mobile/tools/resolve-bot-thread.mjs
Line 212 in 599edae
When the reply succeeds but the resolve mutation fails, the structured retry command omits the now-required --repo argument. Executing the recovery command immediately exits with usage code 2, leaving the thread unresolved; include the current repoKey in this command.
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
@codex review |
|
DEGRADED: same-vendor review Verdict: BLOCKING on head Blocking findings:
No non-blocking findings were retained, so no follow-up Linear tickets were filed. Rubric coverage:
The external-interface evidence in the PR body was also checked against the changed reads; no additional retained finding was found. Rubric snapshot: A machine does not merge. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3d5dc3b530
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2e3051c236
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c56770e0a7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2543b28ec4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d9bb423e28
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: acade79b0f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c2937f068b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a6105a7a5f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
DEGRADED: same-vendor review Verdict: BLOCKING (round 1) Blocking findings:
Follow-up tickets: none. Dimensions marked N/A:
Dimensions 1–6 were applied. Verification on the exact reviewed head passed: Canonical receipt: {
"reviewerKind": "independent",
"verdict": "BLOCKING",
"rounds": 1,
"reviewedHeadOid": "a6105a7a5f949b3ad4fcbf04f19c2dd8511bcec5",
"baseSha": "868cd816b7f609318ac37d9dbf6f3ee925d7df30",
"rubricBaseOid": "868cd816b7f609318ac37d9dbf6f3ee925d7df30",
"rubricArtifactPath": "C:/Users/thoma/AppData/Local/Temp/orbit-pr-review-694-a6105a7a/pr-694-rubric.md",
"artifactPath": "C:/Users/thoma/AppData/Local/Temp/orbit-pr-review-694-a6105a7a/findings.json",
"frozenFindingIds": ["F1", "F2"],
"findings": [
{
"id": "F1",
"severity": "High",
"file": "tools/lib/readiness-receipt.mjs",
"line": 68,
"claim": "Round-two readiness accepts newly admitted blocking findings as CLOSED, so a final receipt can hide a blocker that the capped review contract requires to remain OPEN and still become READY.",
"blocking": true
},
{
"id": "F2",
"severity": "High",
"file": ".claude/hooks/_lib/rules-orchestrator.mjs",
"line": 58,
"claim": "Literal directory pathspecs bypass the broad-staging guard, so commands such as git add apps/web or git commit tools can still sweep unrelated worker residue into a commit.",
"blocking": true
}
]
} |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6627da4014
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
DEGRADED: same-vendor review Verdict: BLOCKING (round 2; review cap reached) Frozen finding disposition:
Admitted touched-line blocker:
Follow-up tickets: none. Dimensions marked N/A remain unchanged from round 1:
Canonical receipt: {
"reviewerKind": "independent",
"verdict": "BLOCKING",
"rounds": 2,
"reviewedHeadOid": "6627da4014d29ba43b37f6a92990d08d8c6e5a80",
"baseSha": "868cd816b7f609318ac37d9dbf6f3ee925d7df30",
"rubricBaseOid": "868cd816b7f609318ac37d9dbf6f3ee925d7df30",
"rubricArtifactPath": "C:/Users/thoma/AppData/Local/Temp/orbit-pr-review-694-a6105a7a/pr-694-rubric.md",
"artifactPath": "C:/Users/thoma/AppData/Local/Temp/orbit-pr-review-694-6627da40/findings.json",
"roundOneArtifactPath": "C:/Users/thoma/AppData/Local/Temp/orbit-pr-review-694-a6105a7a/findings.json",
"roundOneArtifactSha256": "fb3230b6c3346cf06fd8492a225047a966224fb46dae6855d48e7528e9490dcb",
"frozenFindingIds": ["F1", "F2"],
"findings": [
{
"id": "F1",
"severity": "High",
"file": "tools/lib/readiness-receipt.mjs",
"line": 68,
"claim": "Round-two readiness accepts newly admitted blocking findings as CLOSED, so a final receipt can hide a blocker that the capped review contract requires to remain OPEN and still become READY.",
"blocking": true,
"status": "CLOSED"
},
{
"id": "F2",
"severity": "High",
"file": ".claude/hooks/_lib/rules-orchestrator.mjs",
"line": 58,
"claim": "Literal directory pathspecs bypass the broad-staging guard, so commands such as git add apps/web or git commit tools can still sweep unrelated worker residue into a commit.",
"blocking": true,
"status": "OPEN"
},
{
"id": "F3",
"severity": "Critical",
"file": "tools/record-readiness.mjs",
"line": 119,
"claim": "Round-one registration overwrites an existing ledger, so a post-fixer caller can replace the supposedly immutable pre-fixer identity and make a forged round-two receipt pass readiness.",
"blocking": true,
"status": "OPEN"
}
]
} |
|
@codex review |
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7b5b647a8e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| new Set(blockingIds).size !== blockingIds.length || | ||
| JSON.stringify(blockingIds) !== JSON.stringify(registered.frozenFindingIds) | ||
| ) fail("round-one registration requires one valid BLOCKING receipt with its exact ordered frozen IDs") | ||
| const path = roundOneLedgerPath(registered.reviewedHeadOid) |
There was a problem hiding this comment.
Include the base SHA in the round-one ledger key
When the target branch advances while the PR head remains unchanged, the review contract requires a fresh round one against the new base, but this path still resolves to the prior head-only ledger file. The new receipt has a different baseSha, so the immutable-ledger comparison rejects it as a replacement and leaves the PR unable to register the required fresh review. Key registrations by both base and head while preserving each existing record's immutability.
Useful? React with 👍 / 👎.



DEGRADED: same-vendor review
Summary
Makes
/orchestrateown the complete same-head/base readiness lifecycle and makes PR size advisory rather than a correctness gate. It also closes the mid-run gaps around connector issue comments, bounded process cleanup, observable waits, and ORB-260 parity guidance.Linked Linear work: ORB-262 and ORB-260. API canonical-review companion: thomasluizon/orbit-api#463 (ORB-261).
The only product-tree change is the mandatory generated Zod contract artifact required by live API-main drift; no hand-written product behavior changed. No gate or baseline was weakened or reseeded. This delivery process never merges.
Observed failure -> fix -> red-capable regression -> external evidence
/ticketsplits only at real behavior/deployment boundaries and keeps required output with its source.additions,deletions, andchangedFilesare retained only as numeric review information./orchestratenow runs one bounded proactive loop until simultaneous READY or a genuine permission/external/human-only blocker. It never merges.verify-deliveryreads live comparebehind_by; positive values returnOUT_OF_DATEwith base/head/count.behind_by=1cannot deliver and preserves exact values.behind_by.--repo; full URLs must map unambiguously; API review cwd is configured API primarymain.git remote get-url origin, consumed as one string.findings: [].frozenFindingIds; round 2 cannot change it, and readiness verifies every frozen ID remains a Blocking finding.REVIEW_STALE; a preserved CLOSED list can become READY.src/andtests/against the API target, drops Medium/Low/Info before receipts/tickets, requests both OIDs, and snapshots the rubric from capturedbaseRefOid.gh pr viewkey/type evidence and reproduction appear here and in API #463.gh auth switchmutated global account state, and the thread resolver later reproduced the same class by inheriting the globally active account.GH_TOKEN; inherited token variables are replaced; errors redact secrets.gh auth token --user <TARGET_OWNER>returns one token string; the first live resolver attempt failed before mutation, proving the wrong global account could not be relied upon..orcacould be silently discarded; aliases, automatic commit staging, and Git pathspec magic could bypass the hook.commit -a/--all, indirect or abbreviated pathspec-file flags, and all non-literal magic including:,:/, and empty:(literal). Named literal bracketed paths remain valid, and attached-S<keyid>values are consumed rather than misread as staging flags.git commit -Sapi; salvage also rejects unselected source.git commit -hproves-S[<keyid>]is value-bearing.Guardsidentities under the repository's Git common directory. Every checkout refuses readiness until newer instances register. Bounded launcher children keep the wake source live.gh pr edit; unchanged old rollups stayCI_PENDING/CI_STALE; a later process with newerGuardsinstances settles; hanging post-worker descendants are removed.STALE) could be treated as green.SUCCESS,NEUTRAL, orSKIPPEDallowlist; every other or future value fails closed.STALE, and an unknown future conclusion.--branch, refuses protectedmain, inventories the tree, requires a real green test receipt, rejects every unselected source path while allowing only untracked.orca/residue, and refuses any staged path outside the exact named set.behind_by, and the protected base branch's required-check inventory. Every missing required context isNOT_REGISTERED/CI_PENDING.STALE_PR; empty and one-fast-check partial rollups remain pending until every required context registers.reviewerKind: independent, rounds 1..2, and exact Linear issue/repository/PR identity. A synchronizedvisual/In Progress pair can reach technical READY withvisualCheckOwed:true; premature visual/In Review remains stale.REVIEW_STALE; wrong Linear identity is rejected; visual/In Progress => READY; wrong visual status =>LINEAR_STALE.git remote get-url originstring.test-toolshung for over ten minutes and parent termination left a Node descendant; Linux PID 1 can leave a killed descendant as a defunct zombie thatkill(pid, 0)still sees./proc/<pid>/statstateZas terminated.list-bot-threadsexceeded 120 seconds without useful output and could orphan descendants.PENDINGorDISMISSEDcould be accepted as a completed pass.APPROVED,CHANGES_REQUESTED, orCOMMENTED; pending and dismissed Reviews remainNO_REVIEW.PENDINGandDISMISSED; issue-comment evidence remains separately head-pinned.PullRequestReviewStateenum and reproduction below.verify-deliverynow uses the full-tree bounded runner with a configurable hard timeout.Reviewed commitSHA prefix matches the full current head; stale comments areNO_REVIEW. CurrentCHANGES_REQUESTEDReviews still block.comments.nodesand a 10-character reviewed SHA prefix; shape below.visible-effectlabel in either direction, and Orca reads/writes were unbounded.LINEAR_STALE, and a hanging Linear descendant removed after timeout.--fullOrca issue shape below; writes depend only on exit status.parity:exemptlabel now name the exact closed exception list. Gate logic is unchanged.habitIdsrequest field.npm run generate:zod -w @orbit/sharedusing Orval 8.20.0 against current API main.Verification
node tools/test-tools.mjs: PASS on final harness code; 19 scripts and 8 libraries structurally covered, all decision paths green, completed in 216.7 seconds.node .claude/hooks/test-hooks.mjs: PASS on final local head, including ORB-260 guidance and unchanged gate assertions.node tools/arch-map.mjs: completed;architecture.jsonandarchitecture.htmlhad no content drift.Final-head GitHub CI, independent pr-review, current connector result, thread count, base freshness, and Linear receipt are reacquired after every push; their current status is not inferred from these local results.
Current pushed UI head:
7b5b647a8e5db76591da3a178db829cfc22ff9d0. Current base:868cd816b7f609318ac37d9dbf6f3ee925d7df30. Current canonical hashes:SKILL.md 3FBF6D133B4A7BAFBE8DA8345EA10D45FF96AC6B83D6C78F348651FA3C830059;rubric.md 672F14194F2BC7834828D434BABDAD152D5B361B2059B75F34F5B0D370BE72B6.Installed Git 2.52 accepts the unambiguous long-option abbreviations
git add --aandgit add --up; a live temporary-repository reproduction exited zero and respectively selected all tracked/untracked changes and all tracked updates.git add -hexposes the complete relevant option spellings as--[no-]alland--[no-]update. Reproduction and observed behavior: current-head connector evidence. The hook therefore compares every supplied long-option prefix against the complete dangerous allowlist instead of assuming callers use the documented full spelling.Confirmed external response shapes
Values below are replaced by type names. Tokens, credentials, personal data, and account values are omitted. Commands derive credentials into child scope and remove them immediately.
GitHub PR, checks, and PR list
Reproduce:
Complete selected shapes:
Observed
__typename:CheckRun,StatusContext. Live GraphQL introspection returned the completeCheckConclusionStateenum:ACTION_REQUIRED,TIMED_OUT,CANCELLED,FAILURE,SUCCESS,NEUTRAL,SKIPPED,STARTUP_FAILURE,STALE. OnlySUCCESS,NEUTRAL, andSKIPPEDpass; every other or future completed value fails closed. The completeStatusStateenum isEXPECTED,ERROR,FAILURE,PENDING,SUCCESS; onlySUCCESSpasses,EXPECTED/PENDINGremain pending, and the rest fail.Reproduce the enum proof:
Complete introspection result shape:
GitHub required-status inventory
Reproduce:
Complete live response shape for both protected
mainbranches:verify-deliveryreads onlycontexts. The live UI list contains 20 names and the API list 15;missing names are reported individually as
NOT_REGISTERED, while registered advisory checks arestill evaluated and cannot hide a failure.
GitHub compare
Reproduce:
Complete top-level live key/type set:
The code reads only numeric
behind_by; no comparestatusvalue is assumed.GitHub Codex Review and issue-comment surfaces
Reproduce the exact query from
tools/list-bot-threads.mjs:The exact query was run live against UI PR #690. Complete selected shape:
Measured clean issue comment: GraphQL author login
chatgpt-codex-connector(REST exposes the same bot aschatgpt-codex-connector[bot]), body beginsCodex Review: Didn't find any major issues.and containsReviewed commitwith a 10-hex-character prefix;createdAtis ISO-8601 andurlis a string. PR #690 returned head445962dc803eaff136458e4d50464bbc91eac64eand clean comment prefix445962dc80, proving the prefix/full-head relationship used by the tool. Only those two measured bot aliases are accepted.Live GraphQL introspection returned the complete
PullRequestReviewStateenum:PENDING,COMMENTED,APPROVED,CHANGES_REQUESTED,DISMISSED. OnlyAPPROVED,CHANGES_REQUESTED, andCOMMENTEDare completed connector Review evidence;CHANGES_REQUESTEDblocks, whilePENDINGandDISMISSEDcannot clearNO_REVIEW.Reproduce:
Complete selected response shape:
GitHub label
Reproduce:
Complete selected live shape:
The live description is now
Parity exemption: platform adapter or enumerated layout-shell divergence; justify in PR body.Linear issue read and writes
Reproduce with the pinned installed binary after
orca skills get orca-linear:Complete selected live shape:
The sync tool reads only
result.issue.state.name,.type, and everylabels[].name;labelsis confirmed as an array above. Compared closed types are the complete setcompleted,canceled,duplicate. Status, comment, and attachment writes depend only on command exit status, not an invented response field. Installed response forwarding source:C:\Users\thoma\AppData\Local\Programs\orca\resources\app.asar.unpacked\out\cli\handlers\linear.js:100and:149.Git metadata and commit option parsing
Reproduce against installed Git 2.52 from the linked worktree:
The first command exited 0 in both the primary checkout and linked worktree and returned one non-empty path string resolving to the same repository Git common directory; no structured field is parsed. The installed commit usage includes
-S[<keyid>], proving that the remainder of an attached-Stoken is a key ID value rather than more short options.git symbolic-ref --quiet --short HEADexited 0 with the single checked-out branch-name string, and installed push usage identifies the final operand as<refspec>, proving whyHEAD:<caller branch>must be rejected unless the caller branch equals the symbolic branch. The persisted invalidation JSON is harness-owned and contains exactlyrepositoryKey:null|string,prNumber:number,headSha:string,baseSha:string,editedAt:string,guardsRuns:array<{name:string,startedAt:string}>, andpreEditWorkflowRuns:array<{conclusion:string,createdAt:string,databaseId:number,headSha:string,status:string}>. A null repository key is safe for launcher-created receipts because the common directory is repository-qualified and the file is PR-qualified; verifier/recorder receipts also store and validate the configured key. A marker clears only for a new run ID absent from the pre-edit snapshot, created at/after the edit for the exact head, and completed successfully; an opened-event job that starts late cannot qualify.Node child-process termination
Reproduce against the installed Node binary:
Complete observed result:
The tool reads only the numeric
pid, stdout/stderr byte streams, and close code/signal. Windows uses installedtaskkill /T /F /PID; POSIX uses a detached process group and negative-PID kill. Both real regressions prove the descendant is absent after timeout. On Linux, reproduce the defunct-state check withnode tools/test-tools.mjs; the helper reads the installed procfs line/proc/<pid>/statin its literal<pid> (<comm>) <state> ...form and accepts only stateZas terminated afterkill(pid, 0)succeeds.Latest Codex findings addressed
Validate the Linear receipt identity before readiness: fixed in09940dd3; exact issue/repository/PR mismatch regression; replied and resolved.Document the required Linear synchronization flags: fixed in09940dd3; README now matches--help; replied and resolved.Treat terminated zombie descendants as no longer alive: fixed in09940dd3; all four process-tree regressions share the Linux-aware helper; replied and resolved.Wait for every required check to register: fixed in09940dd3; protected-branch inventory plus partial-rollup regression; replied and resolved.09940dd3; the superseded review receipt remains BLOCKING by design and a fresh final-head review is reacquired.Allow salvage before a PR number exists: fixed inc8375839;--pris optional until creation and the result records pending readiness registration.Include the repository in the retry command: fixed inc8375839; the emitted--resolve-onlycommand retains the exact repository key.5ee1c951: fixed inc8375839; salvage refuses unrelated staged paths, connector Review states use a proved allowlist, codex-only body enforcement runs again at delivery and receipt aggregation, and every delivery child has bounded full-tree cleanup. The round-one receipt remains BLOCKING by design until round-two verification on the final head.Derive visual state from the live ticket label: fixed in312e765c; a livevisible-effectlabel mechanically overrides a mistaken ready request and keeps the ticket In Progress.Bound every Linear CLI invocation: fixed in312e765c; reads and writes use the shared bounded runner with full descendant-tree cleanup and a red hanging-child regression.Prove the exact non-full Linear response: fixed in312e765cby removing that interface read; synchronization now requests the already evidenced complete--fullshape and validates its state and labels before use.312e765c: fixed inda738111; worker staging recognizesgit stageand rejects indirect pathspec-file staging.Bound the post-worker GitHub calls: fixed inda738111; degradation-marker calls are bounded, kill descendants, and remain covered by the wake source.Derive visual state solely from the live label: fixed inda738111; the authoritative label corrects mistaken caller state in both directions.Test the exact subset that salvage commits: fixed inda738111; every unselected dirty source path is rejected before commit/push.5be49769; the hook rejects the complete--pathspec...option family, including installed Git's accepted--pathspec-from-fabbreviation, with the exact red case.5be49769: fixed inf09476ac; all root/bare/empty pathspec magic is blocked, resolver GraphQL children are bounded with descendant cleanup, and the documented Linear stdin sentinel works.Block broad staging through git commit: fixed inf09476ac; workercommit -a,-am, and--allare rejected.Paginate review threads before declaring readiness: fixed inf09476ac; the connector follows livepageInfoto exhaustion and readiness requires a complete artifact.Bound the bot-thread GraphQL calls: fixed inf09476ac; reply, resolve, and resolve-only reads/mutations use the shared bounded runner with a hang/tree-kill regression.d8187b2d; commit-time auto, interactive, patch, dot, glob/magic, and indirect pathspec staging are blocked while explicit named literal commit paths remain allowed.d8187b2d; thread pagination has one total deadline, a 100-page ceiling, repeated-cursor refusal, and structured per-page progress with a red cursor-cycle test.d8187b2d: fixed ina413a826; the worker hook prefix-matches Git's dangerous long commit-staging options, so installed Git's accepted--interaand--patcabbreviations are blocked. Exact red cases cover both spellings while explicit named commit paths remain allowed.Derive review cleanliness from blocker entries: fixed incef4f90a; readiness preserves the findings array and refuses a nominally CLEAN artifact with any OPEN blocking entry.Bound Git operations during salvageandKill the complete timed-out test tree: fixed incef4f90a; every Git and workspace-test child uses the shared bounded runner, with real hanging pre-commit and workspace-test descendant cleanup regressions.Define the connector fixer bound: fixed incef4f90a; one positivecaps.connectorFixAttemptsvalue is validated and governs both connector sections.Prove body on the exact PR-view invocation: fixed in this PR body from the live exactnumber,baseRefName,baseRefOid,headRefOid,isDraft,bodycommand; the complete selected key/type set is recorded above.Reverify CI after mutating the PR body: fixed incef4f90a; a marker-restoring edit mechanically invalidates the delivery CI artifact until delivery is rerun.Gate queue completion on the readiness receipt: fixed incef4f90a; run-state maintains an append-only repository-qualified readiness ledger within the exact current session and the stop hook opens every receipt before allowing completion.Validate the frozen rubric OID before readiness: fixed incef4f90a; rubric base/path evidence is preserved and must match the live base.Revalidate live Linear state during aggregation: fixed incef4f90a; aggregation rereads the confirmed full issue state/label shape and invalidates stale status or visible-effect artifacts.Parse attached -m values before broad-stage flags: fixed incef4f90a; attached message/file values are consumed before short staging flags, with safe-mapiand-Fpath-to-messageregressions.Recheck CI after restoring the degraded marker: fixed in9d5c30a1; a body edit returns CI_PENDING immediately and only a later delivery invocation can settle edited-event checks.9d5c30a1; the stop hook boundedly rereads the exact live GitHub PR and full Linear issue shapes before accepting a cached READY receipt.Reject malformed blocker flags: fixed in9d5c30a1; every finding must carry a booleanblockingvalue and every true blocker must be CLOSED.Match each ledger receipt to its PR identity: fixed in9d5c30a1; repository key, PR number, head/base/draft, ticket, Linear status, and visible-effect state must all match live values.Revalidate CI and review threads before allowing stop: fixed in0ee82f9d; the stop hook boundedly rereads newest required CI, current connector evidence, complete thread inventory, and Linear state before accepting cached READY. Same-SHA failed-rerun, dismissed-review, and reopened-thread regressions are green.Persist body-edit invalidation until replacement CI registers: fixed in0ee82f9d, completed in2543b28e; delivery stores pre-editGuardsidentities in shared repository Git metadata and every checkout remains pending until strictly newer instances appear.Consume attached GPG key IDs before scanning staging flags: fixed in0ee82f9d; the hook treats the remainder of-S<keyid>as a value, withgit commit -Sapicovered while broad commit staging remains blocked.Revalidate GitHub readiness before recording READY: fixed inabc4d2e3; aggregation now rereads newest required CI, current connector evidence, and the complete thread inventory, and combines them with the exact-head input artifacts. Red same-SHA failed-rerun, dismissed-review, and reopened-thread cases all prevent READY.Verify the salvage branch before pushing: fixed in2e3051c2; salvage resolves the checked-out symbolic branch before testing, rejects any caller mismatch and protectedmain, then pushes only the already-proved exact branch. Both refusal cases leave the change uncommitted and unpushed.Persist CI invalidation for launcher body edits: fixed inc56770e0; launcher and verifier now share one repository-local receipt implementation, and the launcher records the exact pre-edit head/base and newestGuardsruns beforegh pr edit. The launcher regression proves the persisted receipt; the verifier regressions prove old green results stay stale until replacement runs register.Reset the ledger when a new session starts: fixed in2543b28e; prior identities are unioned only when the exact non-emptysessionIdmatches, while a new session's regression proves the ledger begins empty.Persist invalidation before the recorder edits the body: fixed in2543b28e; receipt aggregation writes the same common-directory head/base/Guards baseline beforegh pr edit, rejects unchanged old runs asCI_STALE, and clears the marker only after newer runs register.Preserve the frozen blocker list in round two: fixed ind9bb423e; canonical UI/API receipts carry immutablefrozenFindingIds, and readiness rejects an absent, empty, duplicate, or dropped round-two list.Identify the edited-event Guards run before clearing invalidation: fixed ind9bb423e; every editor snapshots live workflow run IDs and only a new completed successful same-head run created after the edit clears the marker. The zero-baseline regression proves a late-starting opened-event run remains pending.acade79b; the CI loop awaits each refreshed invalidation result. The strengthened test enters a real one-second pending poll and would reproduce the priorrollup.failingTypeError without the fix.Compare complete frozen blocker list: fixed inc2937f06; round two names and SHA-256-verifies the immutable round-one artifact, then readiness requires the exact ordered blocker IDs. A red artifact that drops F2 from both the final ID list and findings returnsREVIEW_STALE.Reject closed blocker statuses in round one: fixed inc2937f06; round-one CLEAN is valid only with an empty frozen ID list and no blocking findings. A red round-one CLOSED blocker cannot persist READY.Recheck PR identity before writing READY: fixed inc2937f06; aggregation repeats the confirmed livenumber,baseRefOid,headRefOid,isDraftquery immediately before persisting. A head/base change during connector or Linear reads fails before the receipt write.Verify tests do not mutate staged tree: fixed inc2937f06; salvage fingerprints every explicitly named path before and after the caller-specified green test and refuses mutation before staging or push. The red test mutates a named file while exiting zero and proves nothing is committed or pushed.Block abbreviated broad git-add flags: fixed ina6105a7a; the guard now rejects every unambiguous prefix of--all,--update, and--renormalize, including the live-proved--aand--up, while explicit named literal paths remain allowed. Hook regressions cover both abbreviations.Recheck volatile GitHub state in the closing read: fixed ina6105a7a; immediately before receipt evaluation, aggregation rereads the complete selected PR/status-check shape and the current connector/thread inventory, then replaces the cached values. Red sequence tests turn CI red, dismiss the connector review, and reopen a thread during aggregation; each prevents READY.Reject closed statuses for newly admitted blockers: fixed in6627da40; only frozen round-one blockers may close in round two. Any newly admitted blocker marked CLOSED isREVIEW_STALE, and an OPEN one keeps the verdict blocking because no third fixer exists.Block literal directory pathspecs: fixed in6627da40; the worker guard resolves every literal named path and rejects directories for bothgit addand commit-time staging, preventing subtree sweeps while preserving individual literal files.Persist the authoritative round-one hash before round two: fixed in6627da40; round-one BLOCKING artifacts are mechanically registered before the fixer under repository Git state with exact path, SHA-256, base/head, and frozen IDs. Round two must match that independent ledger; a forged reduced artifact plus matching caller hash is rejected.Block fully deleted directory pathspecs: fixed in7b5b647a; for a missing literal path the guard boundedly asks the Git index for exact matches. One different descendant or multiple matches identifies a directory/subtree sweep; one exact deleted file remains an allowed named path. The real linked-worktree regression deletes.claudeand provesgit add .claudeis blocked.Make round-one registration immutable: fixed in7b5b647a; an identical registration is idempotent, while any non-identical attempt for the same repo/PR/reviewed head fails without writing. Red tests prove a reduced blocker list cannot replace the ledger.Deliberately deferred