forked from mosaicstack/stack
Same required gate, both directions wrong: fails OPEN on state=unknown (5 meaningless greens this session, wrong branch too), and fails CLOSED on credential resolution, hard-blocking a worker's completed work. The identical command succeeded from that worker's own worktree in another shell, so the checkout was fine. A gate that waves through unchecked work and blocks ready work has its failure modes backwards. Availability failures must degrade to a loud, audited CANNOT_ASSERT; correctness failures must block. Also the Pi-brick shape: a gate whose unavailability prevents recovery from it. RM-03 extended to a third requirement: distinguish CANNOT_ASSERT from ASSERTED_NOT_READY, both registered with must-fail controls, neither exiting 0 silently. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>