Refusal leaves board data in the inspector, project tree, footer and
scan line, and bus data in the Inbox count and the Ctrl+K palette.
Gate green, 13 of 20 mutants killed, fonts match the upstream archive.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
R4 holds. R5: a relative Pi path resolves against the given workspace in
the gate and against the real path in Pi, so a workspace on a symlink lets
.. reach outside. Comment 27032, queue rev 271.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
R4: Pi read opens a spelling variant of a missing name, which the gate
never checked; a variant-named workspace link reads outside. Comment 27010.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Candidate 5cbf22c0, comment 27001 on #1522. T1 blocks: the terminal's
input hold is drained by an earlier chunk's run, so text typed after
Ctrl-G then Ctrl-T is refused and cleared. Suites, probes and 16 mutants
(13 killed; the 3 survivors checked by hand) in the packet.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
R1 and R3 block: a late broker reply shifts later replies on the host IPC
channel, and a dangling workspace symlink passes the gate. R2 (close waits
on an open launch.sock client) should be fixed in the same round. Probes,
mutants and suite outputs alongside. Comment 26995 on #1523, queue rev 247.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
R1: the guarded close send at host.mjs:144 and :150 can still fail with
EPIPE after a broker SIGKILL; reproduced, fix is a send callback.
R2: give-up lands 7.5 min after the first refusal, against decision 72's
reason; Sage's ruling.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
The ignoreTerm tool child was TERMed before Node installed its handler
when the claim store sits on a fast disk. Candidate fixes the fixture;
the patch itself is not committed.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
B1 truncates due dates to the second; B2 records what landed when the
final read fails; tests for V9, V21 and S5. Candidate manifest
e10e30e3, 28 files over c9ef7ee4. Mutants 46/63. Live provider cases
in test-release and test-task failed on a zai usage limit (429).
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Candidate for #1520 against 81339889: packages/tasks and the bus task
verbs. Live run rehearsed on a scratch v2.7.0 container; the estate run
waits for T236's base URL.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Verdict comment 26778, queue rev 156. Within-role citations never reach
the authority check or the grant event; other sends keep S2b. 58/58 on
Node 24 and 26, seven of seven mutants killed.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Verdict comment 26769, queue rev 146. R1, R2 and both lead decision 64
rulings are in; round 1 probes now refuse. 55/55 on Node 24 and 26,
nine of ten mutants killed, the survivor equivalent.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Verdict comment 26765, queue rev 140. R1: message.send and role.revoke
verbs use gated decisions without consuming them. R2: a cross-role
decision authorizes without limit once policy makes the action gated.
Two rulings for Sage on cross-role reuse and class drift.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Round 2 of #1519: R1 to R5 fixed and reproduced, 43/43 on Node 26 and
Node 24, 22 of 23 mutants killed against a clean baseline. Records a
reparented-CLI path past the human proof for Sage's ruling.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Answers Filbert's round 1 (#1518 comment 26724): launch.by must hold
role.launch, launch is null when limits.authority drops it, a test for
cross-role narrowing, and the business file checked on its open
descriptor.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Record for #1516 comment 26725: 34/34 cases reproduce, and a wrapped
Claude command hook fails closed on crash, missing path, noexec and hang.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Lead decision 59. task_current picks each task's current snapshot,
skipping a poll row whose read_at is at or before the latest self row's
at; tasks_open reads it. Prototype on Node 24 and 26, two mutants
caught, and Dewey's fixture replayed: tasks_open now differs from v3a
only on #42 (in-progress). The notes add an S3 poller rule: compare a
read against task_current, not the raw latest row.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
S1 candidate for Filbert's review on #1518: build.md, build.patch and
build-manifest.sha256 (34 files at base fef4b362). The candidate itself
is not committed.
proto-v3a-notes-correction: the schema has 36 triggers; the printed 35 is
counted after the tamper check's DROP TRIGGER. Found by Rocko.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Verdict changes, #1517 comment 26712: the Vikunja rotation removes the
owner header before the revoke that needs it.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Verdict changes, #1517 comment 26709. Gitea 1.27.1 and Vikunja 2.7.0
source checks for Sage's three questions; two mint defects.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Two triggers: every task.* event names its task in subject, and
task.created cites a human.input event and a requirement id. The task
ref pattern is tightened on snapshots, decisions and subjects. Runs on
Node 24.21.0 and 26.8.1 match apart from the version line.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
task_snapshots gains via and read_at, an integer-bucket CHECK with a
tombstone exception, the read-ordering rule in task_external_changes and
the tasks_open view. task.missing names its task and a reason. Prototype
rerun on Node 24.21.0 and 26.8.1; a mutant without the read_at rule
reports the broker's own move as external. Lead decision 52 (B3).
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Real Vikunja scope map, a read-only sync bot, a two-request poll that
sees column moves and deletions, and task_snapshots changes.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Darkwing's schema-v2 adds task_snapshots, decisions.blocking and a
closed events.kind list. Sage reran proto-v2 on Node 26 with matching
output. Decision 50 accepts the five choices beyond addendum A.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Darkwing's addendum as a record. Broker verbs enforce field ownership,
broker push from a bare repo, polling without webhooks, Vikunja probes
before the adapter interface is fixed.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Darkwing's design note and SQLite prototype as records. Sage accepts
seven of eight open questions; the PM launching sessions goes to Jason.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Both reviewers requested changes (26681, 26683). Darkwing's verdict
landed on #1508; pointer 26685 on #1507.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
The ledger prints a queue section above the weekly table. It checks four
things:
- open issues named by done rows;
- owner registrations for active rows;
- closed issues for done rows;
- the age of required rows.
The result is fail, incomplete or reduced pass. It uses its own Gitea
budget of the open list plus at most 10 lookups. A full open page counts
only while an issue in some row's closes has no known state (lead
decision 40). T3 seats are exempt per run with --unsupported-runtime.
The weekly routine is in packages/ledger/README.md.
Built by Darkwing (build.patch ab1f12ca, manifest 0b20bbca). Filbert
reviewed it: round 1 81f26f2e asked for changes (C1, ISO requiredSince
never aged); round 2 ce8ce150 approved. Also carries Filbert's plan
amendment for decision 40 (68a25ffe).
Co-Authored-By: Claude Opus 5.5 <[email protected]>
queue move ID in-review posts the review request as a Gitea comment and
review record reads verdicts back, so reviews stop being files in
docs/plans/reviews/. On a comment round, in-review to waiting-on-jason
now needs every listed reviewer's approval for the current round, the
same as in-review to done (Filbert r1 C1). scripts/gitea-api.sh reads
the raw per-seat token files (lead decisions 37 to 39): config built and
checked before curl starts, export attribute cleared, fixed base URL.
test-queue.sh skips its live checks outside the canonical root.
Darkwing authored. Filbert approved D r2 (cf1d3fd0) after r1 (a2dc2302)
and corrected the plan (293747cd). Rocko reviewed the helper (e896192f,
2096b0a3), and Sage's lead check passed under decision 38. Manifest
b402fb38, 19 files.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Filbert approved round 1 (f167b85e). Manifest 782bcb62, 21 files, plus
the QUEUE.md markers and the TOOLS.md section. Lead decision 35.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
test-foundation.sh and test-discord.sh ran a nested node --test that would
exit 0 on failure under a parent runner. Both clear the variable now, and
each has a check that fails the suite if it comes back. Darkwing wrote it,
Filbert approved it (e464be6c). Nine suites green on an index export.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
packages/queue, scripts/queue-commit.sh, scripts/git-hooks and
scripts/test-queue.sh, plus docs/plans/BRIEF-TEMPLATE.md. There is no
queue.json yet, so verify skips until the genesis commit after A2.
Darkwing built it, and Filbert reviewed R0 (6933b885, changes requested)
and r1 (e464be6c, approved). The 20 files match manifest 85a8a453. The
nine suites passed on an index export, including the new queue suite.
test-queue.sh joins the suite list in AGENTS.md. Lead decisions 20, 23
and 26.
Co-Authored-By: Claude Opus 5.5 <[email protected]>
Darkwing's follow-up to the T3 thread source: manifest 382f5bb0 pins
t3.mjs, ledger.test.mjs and README.md. Filbert approved it (review
6fd693b6). Ledger 51/51; the eight suites pass on the index.
Co-Authored-By: Claude Opus 5.5 <[email protected]>