Codex Findings Ledger

One row per chatgpt-codex-connector[bot] inline finding adjudicated under the codex-review skill (.claude/skills/codex-review/SKILL.md, v0d.32). Class values come from the skill's taxonomy table; Verdict is ACCEPT / ALREADY-FIXED / REBUT. The Comment id column is the processed-set key (skill Step 0): a finding whose id has a committed row here — read via git show <head>:wiki/.audit/codex-findings-ledger.md against the run's target head, not from the working tree — is not re-adjudicated on later passes. An uncommitted row is not a skip: it means a run died between the Step-4 record write and its commit, so the fix never landed and the finding is still live (Step 4's retry rule says to reuse or discard the orphan row before appending a replacement, so the one-row-per-comment-id contract holds). Purpose: make finding-class drift measurable across runs (skill Step 6 — if the incomplete-propagation share does not decline, the pre-PR propagation sweep gets proposed for promotion into scripts/lint-mechanical.py). Pre-skill history (PRs #40–#116, 164 findings, adjudicated ad hoc) is summarized in the skill's taxonomy shares and not backfilled here.

Date PR Comment id Path Class Sev Verdict Note
2026-07-28 116 3661510666 wiki/.audit/claim-retirement-queue-2026-07-27.md stale-artifact/regenerate P2 ACCEPT Run-5 C0 regenerated with 90d default (0 rows) vs mandated scaled window; regenerated at 60d from C0-time register (103 keep/review rows, 0 concrete defects); digest erratum + scope-bullet pointer
2026-07-28 116 3661510668 wiki/claims.md incomplete-propagation P2 ACCEPT mp-1955-three-coordinated-mutations Payoff still said "specific 1948–49 critics" after the run's Claim/Evidence dating repair (Alquié 1947; L-R undated); synced, Status History line appended, Updated held
2026-07-28 117 3663625709 .claude/skills/codex-review/SKILL.md gate-integrity P2 ACCEPT Step-1 diff baseline was the checkout's HEAD (unrelated to the PR in post-merge mode); now fetches and diffs against headRefOid
2026-07-28 117 3663625719 .claude/skills/codex-review/SKILL.md gate-integrity P2 ACCEPT Reaction-based skip rule failed open for REBUT/ALREADY-FIXED (re-adjudication + duplicate ledger rows on later passes); skip criterion moved to ledger-by-comment-id
2026-07-28 117 3663625724 .claude/skills/codex-review/SKILL.md gate-integrity P2 ACCEPT Issue-comments fetch unpaginated → false Pending / missed clean-verdict SHA on long PRs; --paginate added
2026-07-28 117 3663625732 .claude/skills/codex-review/SKILL.md gate-integrity P2 ACCEPT Three-state classification not mutually exclusive across review rounds; latest-round rule added (clean-after-findings supersedes; findings-after-clean reopen)
2026-07-28 117 3663625741 .claude/skills/codex-review/SKILL.md contradictory-instructions P2 ACCEPT Record writes (log + ledger) were ordered after the single fixup commit, contradicting the single-fixup shape; Step 4 now "Apply fixes and record" with records before gates/commit
2026-07-28 117 3663625744 .claude/skills/codex-review/SKILL.md contradictory-instructions P2 ACCEPT "Pagination-oracle notes" reference had no durable artifact (session-memory only); wiki/.audit/pagination-oracles.md created and the recipe re-pointed
2026-07-28 117 3663920961 .claude/skills/codex-review/SKILL.md gate-integrity P2 ACCEPT Round-1 Step-1 fix fetched only headRefOid; <finding.commit_id> unfetchable after rebase/force-push or in a fresh post-merge checkout → diff fails on unknown revision; both objects now fetched, with a quoted-line fallback instead of defaulting to ALREADY-FIXED
2026-07-28 117 3663920968 .claude/skills/codex-review/SKILL.md gate-integrity P2 ACCEPT Round-1 ledger-keyed skip rule failed open on an interrupted run (uncommitted rows suppressing unlanded fixes); a row now counts as processed only once committed on the fixup commit, read via git show <head>:..., preserving the records-ride-the-commit ordering
2026-07-28 117 3663920951 .claude/skills/codex-review/SKILL.md contradictory-instructions P2 ACCEPT Step 5 reacted 👍 but never re-requested review, leaving a pushed fixup with no bot verdict on the current head — against the merge gate and Step 0's advanced-past-Reviewed-commit rule; Step 5 now "React, reply, and re-request", run unfinished until the new round is classified
2026-07-28 118 3664026605 .claude/skills/codex-review/SKILL.md gate-integrity P2 ACCEPT Round-2 combined git fetch <head> <finding.commit_id> is all-or-nothing: a GC'd finding commit exits 128 and stores neither object, destroying the documented fallback. Verified on git 2.43. Split into two commands, head first, second tolerating failure
2026-07-28 118 3664026610 .claude/skills/codex-review/SKILL.md gate-integrity P2 ACCEPT Step-5 exemption for all-ALREADY-FIXED/REBUT runs reopened the merge-gate gap: those runs still push a records-only commit that advances the head. Trigger moved to "pushed any commit"
2026-07-28 118 3664026619 .claude/skills/codex-review/SKILL.md gate-integrity P2 ACCEPT No retry rule for orphan records left by a run that died between the Step-4 write and its commit → double-written rows/log entries on the next pass. Step 4 now requires reusing or discarding orphans before appending
2026-07-28 118 3664026616 wiki/.audit/codex-findings-ledger.md incomplete-propagation P2 ACCEPT Ledger header still carried the round-1 "any row here" skip rule, contradicting the skill during the interrupted-run scenario; synced to committed-rows-only with orphan-row semantics
2026-07-28 121 3665699360 wiki/.audit/consolidation-2026-07-28-run7-adjudications.md incomplete-propagation P2 ACCEPT Run-7 adjudications named run 6's unsuffixed verdicts JSON as its regeneration input (different wf ID, different 5-slug C3 set); re-pointed to -run7-verdicts.json and named the unsuffixed file as run 6's
2026-07-28 121 3665699362 NEXT.md incomplete-propagation P2 ACCEPT OPS-015 leading status/counts still pre-run-7 (runs 1–6; 75 C3 / ~15 survivors) while the same row's run-7 text said 65 / 9; leading cells synced, batch-4 outcome recorded
2026-07-28 121 3665699366 wiki/concepts/sein-zum-tode.md interpretive-precision P2 ACCEPT Headline relation "refused / inverted" + "explicitly contests" contradicted by the same line's own qualification; Rule-18 raw check at SA 1507 confirms subordonne; reworded. Extent grep found 4 further stale sites (ineinander ×2, empietement ×2, martin-heidegger) — the residue run 7's C4 jury had scoped — all synced, incl. the angoisse-as-flight conjunct contradicted by SuZ §40, plus the non-V&I provenance of the "possibility of rupture" formula and the source page's elided SA hedge
2026-07-28 121 3665699370 wiki/motifs.md interpretive-precision P2 ACCEPT Sources line asserted the Husserlian zu den Sachen selbst inheritance as settled, contradicting the Cross-tradition line below it (run 7's sweep hedged the latter and missed this); reworded to disputed cousinhood, + 2 co-referring sites on sache-selbst.md
2026-07-28 121 3665840951 wiki/claims.md interpretive-precision P2 ACCEPT promiscuite-as-topological-anerkennung-671 executed pre-registration repair item 2 on the Claim field only; the Falsification condition still tested the substitute axis (reciprocal mutual-implication) while calling its failure a rejection-axis dissolution — a vote-condition for jurors R and S, so as registered two votes reverted to HOLD. Re-opened Phase-6 ratification, authored a source-grounded rejection-axis falsifier for both members (SA-2006 raw 1618/1622; Hegel §§670–671 vs §§186–196), and re-axed G's unrun bidirectionality check to Counterpressure as a substitute-axis limitation
2026-07-28 121 3665840958 wiki/claims.md incomplete-propagation P2 ACCEPT Piaget-formula locator raw 1620 → 1622 (main-thread re-verified; 1620 is the preceding "réhabilitation ontologique du sensible" paragraph). Extent grep found the same off-by-two on topology-mp.md, chiasm.md (neither cited) and the SA-2006 extraction note ×3 — closing the item run 6 deferred as outside consolidation write-scope; batch-4 jury artifacts left verbatim with an ADJUDICATIONS erratum
2026-07-28 121 3665840967 wiki/sources/saintaubert-2006-vers-une-ontologie-indirecte.md contradictory-doc-surfaces P2 ACCEPT Core Argument 14's headline still opened "refuses the Heideggerian être-pour-la-mort" while its own 2026-07-28 hedge four lines down said "subordination, not refusal" (raw 1507). Headline synced — the fifth surface of the same over-wording, after the four propagated at comment 3665699366 (the pairs-are-often-triples pattern, here a quintuple)
2026-07-28 121 3665840977 wiki/.speculative/promotion/methodological-queue.md incomplete-propagation P3 ACCEPT Batch heading said MQ-9 … MQ-16 although MQ-17 exists; corrected, along with the co-referring artifact-inventory line in ADJUDICATIONS.md. MQ-16 itself also recast — it carried a wiki-content finding while stating it had been routed to audit Keys "rather than to this queue"; content item routed to NEXT.md OPS-004, process-only routing note retained
2026-07-28 121 3665840985 wiki/.speculative/promotion/runs/2026-07-28-batch4/ADJUDICATIONS.md fail-open-gate-integrity P2 ACCEPT-RESOLVED-INVERSELY The inconsistency is real and confirmed — the summary said "Two writes" while the commit had applied three. Resolved in the opposite direction: the third write (survivor 2's caution on sein-zum-tode) was a HOLD-AS-SPECULATIVE verdict, whose mapped Phase-6 action under .claude/skills/speculate-signoff/SKILL.md §"Verdict set" is a SPECULATIONS.md annotation — a concept-page caution is RETIRE's action. Counting it would ratify a carve-out breach; the write was withdrawn instead and the summary line clarified. Threaded reply posted
2026-07-28 121 3665840989 wiki/.speculative/promotion/runs/2026-07-28-batch4/cohort-fingerprint.md incomplete-propagation P2 ACCEPT Cumulative four-batch totals were 3 PROMOTE-CANDIDATE / 10 HOLD; recount from the four committed ADJUDICATIONS files gives 7 / 11 (pilot 2+2, batch 2 4+2, batch 3 0+3, batch 4 1+4). Codex's arithmetic verified independently before accepting. The undercount understated the cumulative promotion rate, which is what the section is read for; other five categories summed correctly
2026-07-28 121 3666275788 wiki/claims.md interpretive-precision P2 ACCEPT The re-authored rejection-axis falsifier tested only valence (is Piaget's deficiency verdict reversed into positivity?), not dominance — a positive-but-still-hierarchical reading would pass the test while the named axis failed. Strengthened to test the ranking directly against SA's report of Piaget's procedure at raw 1618 ("ce qui manque à l'enfant… mesurer ce qui les sépare encore de la « pensée logique »"), and the excluded scenario spelled out. Codex's alternative (rename the axis to the narrower deficiency contrast) declined: the axis as stated is the right one, the test was the weak part
2026-07-28 121 3666275798 wiki/motifs.md incomplete-propagation P2 ACCEPT Fourth surface of the raw 1620→1622 off-by-two, and the one my own extent grep missed — the §Ineinander HUB Sources line. Verified as the last live occurrence corpus-wide (the two survivors in claims.md are Status-History provenance; the rest are preserved jury artifacts). Textbook cited-line-is-an-instance-not-the-extent
2026-07-28 121 3666275805 wiki/.speculative/runs/2026-05-25-v1-2-pilot/SPECULATIONS.md contradictory-doc-surfaces P2 ACCEPT The durable survivor annotation still read "Paired false-friend caution written to sein-zum-tode" after the write was withdrawn — so the authoritative survivor record contradicted the page, the adjudication and the digest. Reworded to recommended-and-not-ratified with the withdrawal and its ground recorded. The one surface of the caution-withdrawal I had not swept
2026-07-28 121 3666275810 NEXT.md contradictory-doc-surfaces P2 ACCEPT-SCOPED The State Snapshot read 303 / 144 live / 130 candidate / 1 contested against the actual 304 / 142 / 131 / 3, and stopped consolidation history at run 2 — stale against the same file's own OPS-015 row. Counts and run/batch markers refreshed. Scoped deliberately: this is pre-existing ledger drift across runs 3–7, not PR-introduced, and a full snapshot rewrite is an ops-ledger pass; the partial scope is stated in-file so it does not read as a completed refresh
2026-07-28 121 3666275817 wiki/index.md contradictory-doc-surfaces P2 ACCEPT The sache-selbst index Summary cell still read "Philological source for the phenomenological tradition's rallying call" — the exact assertion de-settled on the concept page, motifs.md and the Connections bullet, and it presented a jury-blocked claim as established. Hedged to cousinhood-not-transmission. Second index-Summary-cell catch this PR (after sein-zum-tode): the editorial cells are preserved by normalize_index_tables.py and so are a systematic staleness sink
2026-07-28 121 3666275820 wiki/sources/saintaubert-2006-vers-une-ontologie-indirecte.md interpretive-precision P2 ACCEPT Rule-18 raw check run before accepting: raw 1507 carries "la question de la mort" and zero occurrences of "angoisse" or "Dasein"; that material begins at raw 1509 in SA's own contrastive voice. My previous fix corrected the verb ("refuses"→"subordinates") but carried the over-wide object, so the headline claimed raw-1507 warrant for a conjunct raw 1507 does not carry. Narrowed to the death question; the angoisse/Dasein contrast presented separately as SA's framing, with the SuZ §40 counter-evidence noted
2026-07-28 121 3666275826 NEXT.md fail-open-gate-integrity P2 ACCEPT The routed survol absolu check landed in OPS-004's next_action only; done_when still required just the Plato Tier-B/C/L-set work, so an OPS-004 run could satisfy its completion contract and mark the item done while silently dropping the residue the routing existed to preserve. done_when now requires the check to be executed or explicitly re-deferred with rationale — default-deny rather than fail-open
2026-07-28 119 3665166085 CLAUDE.md contradictory-instructions P2 ACCEPT v0d.33's §Sourcing Rules defined pointing as "location only", leaving an argumentative-function characterization unrepresentable and contradicting the same amendment's consolidate C3 "de-quote to prose-plus-location" recipe; pointing now a location optionally carrying the bullet's own unquoted prose, Rule 21 compression clause synced
2026-07-28 119 3665166091 .claude/skills/speculate-signoff/team-prompts/juror-E.md incomplete-propagation P2 ACCEPT Propagated prompt bullet ("every quotation-marked string must be verbatim from the named source with a location") was broader than Rule 21's source-attributed scope, forbidding metalinguistic strings the prompts mandate (Juror E's "budget not binding", verdict labels, field names); scoped with carve-out, swept across all 15 prompt files, carve-out pinned once in Rule 21
2026-07-28 120 3665505760 CLAUDE.md interpretive-precision P2 ACCEPT Round-1 metalinguistic carve-out listed "terms-of-art" as categorically outside Rule 21, colliding with the rule's first clause on attributed terminology (Heidegger's "Gestell") and appearing to waive verification for the wiki's most-quoted material; attribution made the sole discriminator (carve-out only while unattributed; attribution re-arms with no exception; default-to-attributed tiebreak), swept across all 15 prompt files
2026-07-28 119 maintainer-pasted r3-1 CLAUDE.md contradictory-instructions P2 ACCEPT Rule 21's attribution clause used Heidegger's "Gestell" as its example of a string needing verbatim-plus-location while itself supplying no location, in all 16 copies (rule + 15 prompts); example now carries (GA 79, the 1949 Bremen lectures), attested at raw/Zur-Sache-des-Denkens.md note 2
2026-07-28 119 maintainer-pasted r3-2 .claude/agents/extraction-pass2-delegate.md incomplete-propagation P2 ACCEPT v0d.33 swept the 15 quote-cap prompt files but missed the sixteenth — the one subagent writing extraction-note quotations imported only Rules 11–18; Read-first now imports Rule 21 and Pass 2c carries the standard quotation-integrity bullet
2026-07-28 119 maintainer-pasted r3-3 NEXT.md incomplete-propagation P2 ACCEPT ">2k tail = eight entries at 3,098–4,002w" conflated top-eight range with tail extent; reproduction: 20 entries >2,000w, 12 >3,000w. Fixed on NEXT.md OPS-019 body + table row and the v0e kickoff artifact; changelog round-3 amendment appended
2026-07-28 125 3668825311 README.md build-deploy-environment P2 ACCEPT New Tooling section documented the uv contract as sufficient for the public-reader gate; Pagefind is a separate binary uv does not install (CI installs v1.3.0, Dockerfile likewise), and without it a non-strict build warns and emits no index (build_site.py non-strict branch), so the next documented command fails on missing Pagefind assets. Prerequisite documented, with the index-free local build distinguished from a publishable one
2026-07-28 125 3668825313 README.md build-deploy-environment P2 ACCEPT Documented check_public_site.py build does not reproduce CI: script defaults --max-broken-hrefs to 0 while site.yml passes 200 for the dead-link triage backlog, so a CI-passing artifact fails the documented command with exit 4. Table command now carries --max-broken-hrefs 200, with the stricter default stated
2026-07-28 125 3668825317 README.md contradictory-instructions P2 ACCEPT "CI runs ... on every push" contradicts site.yml push filter (branches: ["master", "claude/wiki-html-site-plan-WBt8k"]); other branches are covered only via the pull_request event. Narrowed to: every pull request, pushes to master, manual dispatch
2026-07-28 125 3668825319 README.md contradictory-instructions P2 ACCEPT Graph hashes attributed to the lint baseline gate, which compares only EXPECTED_SUMMARY + EXPECTED_SECTION_SIZES; the graph-hash fixtures are verified by the test suite (test_paper_a_a3.py), so gate-only operators would miss graph drift. Split: refresh_baselines.py maintains the pins, the gate verifies lint counts, the test suite verifies the rest. Same conflation stands in CLAUDE.md Rule 19 line 506 — flagged to the maintainer, not edited (schema file)
2026-07-28 125 3668825323 README.md contradictory-instructions P2 ACCEPT "deploy assets in place" attributed to the public-reader gate; check_public_site.py main checks only Pagefind assets, broken hrefs, Paper A path affordances, and Atlas contracts — site.css / provenance manifest / vendored JS / Paper A data are a separate site.yml smoke-check block. Gate scope stated exactly, smoke checks documented as separate. Same wording in CLAUDE.md Rule 19 line 506 — flagged, not edited
2026-07-28 125 3668894449 README.md build-deploy-environment P2 ACCEPT Round-1 fix documented Pagefind as the only non-Python prerequisite; the Atlas Node/Vite bundle is a second one — build_site.py deliberately emits a placeholder /atlas/index.html that keeps the public-reader gate green, while CI and the Dockerfile's node stage overlay atlas/dist, so a manual build passes the gate and ships without the interactive Atlas. Both prerequisites now documented, with the Docker deploy build named as the reference publishable artifact
2026-07-28 125 3668894455 README.md contradictory-instructions P2 ACCEPT "maintains every pinned baseline" overstated: patch_json_fixture patches the lint_baseline arrays and claim_status_summary integers only, leaving the Paper A fixture's dashboard_contested_claim_slugs list unpatched, so a consolidation run that changes the contested set can report nothing-to-do while CI fails on the stale list. Softened to "the pinned baselines", patcher list named as the spec, gap documented with the hand-patch workaround — the missing patcher is already queued in NEXT.md (run-3 carry-forward, where it first tripped hand-patched)
2026-07-28 125 3668894443 README.md incomplete-propagation P2 ACCEPT Round-1's trigger-set narrowing was itself incomplete — site.yml's push filter is ["master", "claude/wiki-html-site-plan-WBt8k"], and the legacy branch was dropped from the README list. Restored as "pushes to master (and to one legacy feature branch still named in the push filter)"
2026-07-28 125 3668894447 README.md contradictory-instructions P2 ACCEPT Speculate Sign-Off called "the only route out of the quarantine", contradicting .claude/skills/speculate/SKILL.md §Promotion pathway, which names the sign-off batch the standard route and keeps the maintainer-run per-survivor promotion pass valid as the explicit-user-confirmation fallback outside a batch. Reworded to standard-route-plus-fallback
2026-07-28 125 3668953633 README.md contradictory-instructions P2 ACCEPT The tooling table's "Test suite" row runs the Python unittest suite only; changes under atlas/ are covered by a separate CI job (typecheck, Vitest, production build + bundle guard, composed-site gate after the dist overlay, Playwright), so a contributor could report the documented suite green while the Atlas job fails. Row relabelled "Python test suite" and an Atlas row added (npm ci, typecheck, test:unit, build, test:e2e) pointing at atlas/README.md
2026-07-28 125 3668953627 README.md incomplete-propagation P2 ACCEPT Round-2's hand-patch workaround named only the provenance fixture; the same contested-slug list is pinned a second time in test_contested_claim (scripts/tests/test_paper_a_a2.py), which patch_test_paper_a_a2 does not patch either, so following the workaround still left the suite red. Workaround now names both sites, as NEXT.md already did — the cited line was an instance, not the extent
2026-07-28 125 r4-python-subset README.md contradictory-instructions P2 ACCEPT The Python-suite row silently skips two CI-enabled gates — test_determinism_check (RUN_DETERMINISM_TEST) and the whole SearchIndexTests class (needs a Pagefind index via WIKIWIP_PAGEFIND_INDEX_BUILD) — so a green local run can meet a red CI. Row labelled a local subset, both env gates named
2026-07-28 125 r4-npm-cwd README.md build-deploy-environment P2 ACCEPT npm ci from the repo root exits EUSAGE — the only package.json/lockfile are under atlas/, and the CI job sets working-directory: atlas. Addressed by collapsing the round-3 Atlas row to a pointer at atlas/README.md that states the commands run from atlas/ (the finding's own offered alternative), rather than duplicating the setup sequence in the README
2026-07-28 125 r4-playwright README.md build-deploy-environment P2 ACCEPT npm ci installs @playwright/test but not the Chromium executable, so a documented npm run test:e2e fails at browser launch; CI runs npx playwright install --with-deps chromium first. Same resolution as above — prerequisites live in atlas/README.md, which the row now points at
2026-07-28 125 r4-node-version README.md build-deploy-environment P2 ACCEPT Atlas prerequisites named Node without a version while the locked jsdom requires ^20.19 / ^22.13 / >=24 and CI + Dockerfile pin Node 24; the prerequisite bullet now names Node 24, with the detailed setup left to atlas/README.md
2026-07-28 125 r4-pin-coverage CLAUDE.md contradictory-instructions P2 ACCEPT v0d.35's own repair said the pins outside the lint gate "are verified by the test suite" — true of the graph hashes, Paper A fixture, and hardcoded counts, false of the index.md/overview.md count lines, which no gate compares to the live corpus (LiveCountSurfaceTests only asserts the two files agree with each other). Third category named and routed back to refresh_baselines.py; changelog amendment appended
2026-07-28 125 r4-css-href wiki/schema-changelog.md interpretive-precision P2 ACCEPT Rule 19 and the v0d.35 entry both claimed a build losing site.css / the manifest / vendored JS / Paper A data still passes the public-reader gate; false for the stylesheet — HREF_PATTERN matches <link href=…>, so its absence breaks one href per page, far past the 200 threshold. What it lacks is a dedicated assertion, not coverage. Both surfaces now distinguish indirect href coverage from the genuinely unchecked assets
2026-07-28 125 r5-atlas-promise README.md contradictory-instructions P2 ACCEPT (scope-bounded) The Atlas row promised atlas/README.md documents the Node and Playwright prerequisites; it documents neither. Resolved by removing the over-promise (row now says the npm scripts are listed there and points at the site.yml Atlas job for the environment), not by writing a prerequisites section into atlas/README.md — that is a separate change, out of this PR's scope per the maintainer's no-scope-creep steer
2026-07-28 125 r5-jsdom-range README.md interpretive-precision P2 ACCEPT "the locked jsdom refuses older majors" is false — jsdom 29.1.1 accepts ^20.19.0 || ^22.13.0 || >=24.0.0. The Node 24 pin is CI's and the Dockerfile's choice, not a dependency exclusion; clause dropped rather than restated. The round-4 log entry repeats the false claim and stands as append-only record, corrected in the round-5 entry
2026-07-28 125 r5-suite-covers-rest README.md incomplete-propagation P2 ACCEPT Round 4 corrected the "test suite covers the rest" overclaim in CLAUDE.md Rule 19 but left it standing in the README's parallel sentence — the same conflation, one surface behind. README now carries the same three-way split (lint gate / test suite / neither, i.e. the live count lines that only refresh_baselines.py checks)
2026-07-28 125 r5-path-json README.md interpretive-precision P2 ACCEPT "Paper A data files" was overbroad in the unchecked-asset list: paper_a_path_errors requires data/paper-a-path.json, parses it, and validates two contract fields. Narrowed to the matrix and argument JSONs with the path-JSON exception named, on all three surfaces (README, CLAUDE.md Rule 19, changelog round-5 amendment)
2026-07-28 125 r6-claim-counts README.md interpretive-precision P2 ACCEPT "the index.md/overview.md count lines are checked by neither gate" was too broad: normalize_claims_table.py derives the Claim entries total and status breakdown from the claim bodies and CI runs it in check mode, with LiveCountSurfaceTests tying overview to index — so only the page-count fields lack a live-corpus comparison. Narrowed on README and Rule 19, with the claim-tally coverage stated
2026-07-28 125 r6-atlas-conditional README.md interpretive-precision P2 ACCEPT The Atlas artifact and return-path checks are conditional, not unconditional: atlas_contract_errors returns success when both atlas.json and observatory.json are absent and the return-path check skips without atlas.json, so a build that lost the payload passes the public-reader gate and falls back to demo data. Conditionality stated on README and Rule 19; CI's smoke checks named as what actually catches it
2026-08-01 126 3695442781 .claude/agents/claim-refuter.md contradictory-doc-surfaces P2 ACCEPT The unconditional lens-scoped STANDS-on-doubt rule reached the C2 seats too, contradicting the v0d.36 "C2 unchanged" invariant and the production C2 prompt — a candidate could bank a required STANDS from an unresolved rival doubt. All four rule sites in the agent file now scope v0d.36 to live -> supported, with full default-deny restated for candidate -> live assignments
2026-08-01 126 3695442783 .claude/skills/consolidate/SKILL.md gate-integrity P2 ACCEPT gen_adjudications.py promote recipe appended only REFUTED objections to Counterpressure, so a successful jury dropped the unanchored pressure a v0d.36 interpretive-lens STANDS records in tried. Promote apply block now enumerates rival-reading/scope STANDS seats with tried text and instructs the Counterpressure note; pinned by TestC3PromoteCarriesStandsPressure (2 tests)
2026-08-01 126 3695442786 wiki/claims.md interpretive-precision P2 ACCEPT Degas near-twin locator: raw 26547 is a blank line; the twin sentence is at 26548 (verified in raw). Corrected in claims.md Counterpressure + Status History (with a dated correction line), schema-changelog v0d.36 entry, the 07-28 log entry, and the calibration report §6
2026-08-01 126 3695442790 wiki/claims.md interpretive-precision P2 ACCEPT "MP's quoted words "apporte son corps"" over-claimed: the French is Valéry's (raw 23403); the repo's only E&M artifact quotes Valéry in English ("takes his body with him," raw l. 43) and no French L'Œil et l'esprit is in raw/. All four surfaces reworded to a translation-level inference; Updated bumped per Rule 3
2026-08-01 126 3695442793 wiki/log.md incomplete-propagation P1 ACCEPT The Case-3 supported-layer re-verification sweep was recorded as "queued" in changelog/report/log but absent from NEXT.md, the single next-work source — the 23-entry sweep would never be picked. Added as OPS-020 (open) with the §6 hygiene finds enumerated, and named in How To Pick Work
2026-08-01 126 3695442796 .claude/skills/consolidate/SKILL.md incomplete-propagation P1 ACCEPT The operative C3 refuter prompt in consolidate-c2-c3-adjudication.js still said "unanimity, default-deny panel" unqualified; CLAUDE.md §Consolidate and README.md repeated the whole-panel description. Prompt now carries the per-lens rule; both descriptive surfaces + two SKILL.md occurrences synced. Dated rerun-*.js one-shot scripts left as historical artifacts of closed runs
2026-08-01 126 3695506703 .claude/workflows/gen_adjudications.py gate-integrity P2 ACCEPT Round-1 STANDS-pressure fix was nested in elif gate: — a blocked jury (evidence-chain REFUTED + interpretive STANDS with pressure) still dropped the pressure from the apply instruction. Hoisted above the gate split, emitted in both complete outcomes; mixed-outcome test + exact-lens-list assertions added
2026-08-01 126 3695506704 .claude/agents/claim-refuter.md incomplete-propagation P2 ACCEPT Frontmatter description still said uncertainty is always an objection, and environment-register.md's adjudicatory row said "unanimity default-deny" unqualified — consumers configuring from descriptors got the pre-v0d.36 policy. Both descriptors now gate- and lens-scoped
2026-08-01 126 3695506706 NEXT.md gate-integrity P2 ACCEPT OPS-020's blanket "no status moves" left an irreparable verifier FAIL stranded at supported — the outcome the sweep exists to prevent. Routing added: repairable → repair in place; irreparable evidence-chain break → supported→contested with Status History + digest row under the standing veto (Case-3 bars promotions, not the contested route)
2026-08-01 126 3695506708 wiki/claims.md interpretive-precision P2 ACCEPT Round 1 repaired only Counterpressure; Title/Claim/Evidence still asserted the unattested French dit Valéry tag, cited §I for a §[2] passage, and attached the attribution to MP's own unattributed "lending his body to the world" sentence. Canonical fields re-anchored to "takes his body with him," says Valéry (raw l. 43); propagated to all seven home-page sites, four pages bumped
2026-08-01 126 ext-r2-ops020-contract NEXT.md contradictory-doc-surfaces P1 ACCEPT External deep-review P1: the OPS-020 row lacked an executable contract (frozen denominator, writable owner, result artifact, failure route, done-when) and folded §6 item 4 — a verifier/refuter seat conflict needing adjudication — into the routine sweep. Full contract written; item 4 routed to separate adjudication; CAL-rows backfill carried as companion item
2026-08-01 126 ext-r2-verdicts-portability wiki/.audit/jury-calibration-2026-07-28-verdicts.json build-deploy-environment P2 ACCEPT 329 absolute /private/tmp scratchpad anchors for a destroyed snapshot — non-portable, non-replayable, local-layout-exposing. Normalized to snapshot-relative calib-snap/; report §9 addendum records snapshot identity (master 51d18e8c + spec §3.2 doctoring) and replay bounds
2026-08-01 126 ext-r2-verbatim-typography wiki/claims.md interpretive-precision P3 ACCEPT Quotes labeled verbatim normalized the source's typographic apostrophes and thin-space semicolon to ASCII. Exact source characters restored in the claims entry and the four home pages carrying the fragment
2026-08-01 128 3696433816 .claude/agents/general.md incomplete-propagation P2 ACCEPT general.md was added as the project-tuned replacement for the built-in type, but ingest SKILL.md Pattern 2 still delegated the note→source-page transform to general-purpose, so the register's pin (Opus 5 medium) and the authority/reporting constraints applied to no actual ingest. Repointed to subagent_type: "general" with the source-page write named explicitly, since that definition treats wiki/ as write-on-authorization-only. Sole operative call site — remaining general-purpose strings are append-only log/audit history
2026-08-01 128 3696433819 .claude/skills/working-with-opus/references/observations.md interpretive-precision P2 ACCEPT 146/146 is the all-time, both-gates total, not the Opus-5-at-high record: run 1 (12 C2 seats) predates the Opus 5 decision and run 2 (34) ran Fable 5 at xhigh with an Opus 5 xhigh rerun — 46 seats at other settings — while O-002's claim is C3-scoped and 56 of the 146 are C2. Correct figure 75/75 C3 across runs 3–7 (100/100 counting those runs' C2). Split written into O-002 with per-run anchors; propagated to the register cell, the 2026-08-01 update-log entry, and SKILL.md §Effort selection
2026-08-01 128 3696433821 .claude/environment-register.md gate-integrity P2 ACCEPT Same-day frontmatter encoding made .claude/agents/*.md the surface a spawn inherits while register + skill + CLAUDE.md still described register-only edits as sufficient — a pin change would leave seats on the old value with the operative surface claiming otherwise. Fixed structurally: machine-readable pin table + RegisterFrontmatterParityTests (4 tests) failing on disagreement, orphan row, or unpinned agent; drift-injection on claim-refuter confirmed the gate fires before revert. Same-commit rule on all three surfaces
2026-08-01 128 3696433823 .claude/skills/working-with-opus/references/opus-5-docs-digest.md interpretive-precision P2 ACCEPT Header asserted verbatim fidelity while nine quoted strings carried digest-authored ; audit also found two nested "' swaps and one period added inside the marks. All five sources re-opened ([PO]/[WN] re-fetched live, [MG] in the bundled copy) — no fabrication, every span genuinely the source's, only condensed. Repaired to contiguous spans joined by the digest's own prose + a stated no-elision convention; §4 to block quotes. Substantive elision recovered: the scope-constraint block had dropped the documented say-so-and-continue sentence, i.e. the official silent-reframe wording
2026-08-01 128 3696537306 .claude/skills/working-with-opus/SKILL.md incomplete-propagation P2 ACCEPT Item 4 directed that every seat's reporting contract keep the report-the-reframe clause while only general.md carried it — the safeguard documented but absent from the prompts that govern adjudicatory seats. Clause appended to all 12 remaining .claude/agents/*.md Constraints sections and strengthened in general.md (report and do-not-transform halves); SKILL.md now states the propagated fact and cites the documented wording recovered by finding 3696433823
2026-08-01 128 3696537307 .claude/skills/working-with-opus/SKILL.md contradictory-doc-surfaces P2 ACCEPT H-001 claimed to ride existing gates-in-front/veto-behind review moments, but no consolidation, audit, or sign-off surface mentioned it — so neither promotion (3 hits) nor the new five-review retirement condition was reachable without invoking the skill on purpose. Wired to consolidate C5 step 3: one appended line per run (hit, or surveyed clean — N artifacts), observations.md added to consolidate's Outputs, and the entry names its hook while the hook names the entry. Explicitly non-blocking
2026-08-01 128 3696537308 .claude/skills/working-with-opus/references/observations.md incomplete-propagation P2 ACCEPT O-001's Status line still read maintainer testimony after the round-2 T-002 amendment relabelled the same entry's Counter-evidence to user testimony — contradictory provenance reading the retraction as maintainer self-authorization, the confusion T-002 exists to prevent. Extent-grepped: second instance in the v0d.37 changelog entry ("below maintainer testimony"), also this-PR-authored; both corrected in place
2026-08-01 128 3696537310 .claude/skills/working-with-opus/references/opus-5-docs-digest.md interpretive-precision P2 ACCEPT [MG] alone had neither URL nor path, citing only a bundled claude-api copy — located this session at bundled-skills/<version>/<hash>/, i.e. session- and version-scoped, so a later session could not open the source behind the digest's load-bearing max caution and the whole §4 H-001 kernel. Durable upstream URL recorded from the skill's own shared/live-sources.md, bundle path demoted to a consulted-via note; SKILL.md Maintenance corrected four sources → five, all re-fetchable
2026-08-01 128 3696604852 scripts/tests/test_agent_frontmatter.py gate-integrity P2 ACCEPT Fail-open in the guard written to close a fail-open: _register_pin_table filtered with if match:, so any data row failing _PIN_ROW never entered pins — an orphan row naming a seat with no agent file, minus one backtick, passed all four parity tests because the row-without-agent guard can only check rows the parser surfaced. Parser split out as _parse_pin_table(section, source) and made rejecting: header and separator validated by shape, every subsequent table line must parse or raise. Codex's exact bypass pinned as a regression test plus 6 siblings (PinTableParserTests, 7 tests): typo'd row for a real seat, extra column, duplicate seat, wrong header, no data rows
2026-08-01 128 3696604854 .claude/workflows/consolidate-c2-c3-adjudication.js incomplete-propagation P2 ACCEPT The re-tier moved ADJ/VER to xhigh but the queue-status log() still restated adj/high + ver/medium by hand, and that string lands in the run digest — which the observation ledger reads as the configuration a run's record belongs to, so the next run would have contaminated the fresh xhigh denominator and T-001's comparison set. Fixed by deriving the message from the constants (${ADJ.model}: adj/${ADJ.effort} + ver/${VER.effort}) rather than re-updating a copy, with a comment stating why a hand-written restatement drifts. Sole remaining hardcoded config string in the file (grepped)
2026-08-01 128 3696643216 .claude/workflows/consolidate-c2-c3-adjudication.js incomplete-propagation P2 ACCEPT Round 5 replaced a hand-restated seat config with a derived one, but factored a single ${ADJ.model}: prefix over both sides — so a future divergence between the two pins (separate register rows) would print the verifier's effort under the adjudicator's model, contaminating the configuration-keyed observation denominator round 5 existed to protect. Each side now carries its own model; comment states why the shared prefix is wrong rather than just removing it
2026-08-01 128 3696643219 scripts/tests/test_agent_frontmatter.py gate-integrity P2 ACCEPT Round 5's parser rejects malformed row syntax but [A-Za-z]+ accepted any effort word, so xhihg applied to register + frontmatter together passed every parity and strict-YAML test. Ladder baked into the row pattern (unsupported value ⇒ malformed row ⇒ existing rejection path), plus a direct frontmatter assertion so the invariant does not depend on the parity chain. Codex's exact typo pinned + whole-ladder acceptance test
2026-08-01 128 3696643222 .claude/environment-register.md contradictory-doc-surfaces P2 ACCEPT Register called MAX_THINKING_TOKENS=0 "its one live use" unconditionally while the same PR's docs digest §1 [WN] records a 400 when thinking is disabled at xhigh/max — where 12 of 13 pins sit, so a reader applying it globally breaks nearly every seat's calls. Scoped to high and below with the failure behaviour and the lower-effort alternative stated
2026-08-01 128 3696643224 .claude/environment-register.md incomplete-propagation P2 ACCEPT Live drift, not a doc nit: all 7 speculate-signoff/team-prompts/*.md read model: claude-opus-4-7[1m] with no effort: while the Adjudicatory row claimed Opus 5 xhigh, so a normal sign-off run used the old model at default effort. They are team spawn prompts, not agent definitions, so no .claude/agents-scoped guard could reach them. Second register table (keyed <skill>/<role>) + TeamPromptParityTests; extent grep also found the SKILL.md roster restating the pin 7× — column removed rather than 7 stale copies refreshed. Drift-injected both ways before accepting
2026-08-01 128 3696643225 .claude/agents/citation-verifier.md gate-integrity P2 ACCEPT Round 3 put the report-don't-reframe clause in every seat's contract, but this seat answers in a schema and VERIFY had no status/note field — leaving empty citations[] (reads as a clean sweep) or an invented row (breaks one-row-per-Evidence-bullet) as its only outlets, so the safeguard was inoperative for the seat feeding the supported gate. briefStatus/briefNote added, wired into c3_gate + blocked legs, 5 regression tests; absence defaults OK for pre-2026-08-01 journals only, keeping TestSalvageByteStability valid
2026-08-01 128 3696643228 .claude/workflows/consolidate-c2-c3-adjudication.js gate-integrity P2 ACCEPT Call-time ADJ/VER beat the frontmatter the round-3 test checks; the file's own comment conceded no guard covered them. Took the validate leg over Codex's remove-the-overrides leg — workflow agent() inheritance with agentType is not documented well enough to change runtime behaviour on the operative supported gate. // parity-seats: annotation + CallSiteOverrideParityTests (annotation required, seats resolved against the register, values compared), with a not-blind test since a scanner matching nothing makes the class vacuous; dated rerun-* one-shots excluded as closed-run records
2026-08-01 128 3696703088 scripts/tests/test_agent_frontmatter.py gate-integrity P2 ACCEPT Round-4's own call-site guard was fail-open for additional overrides in an already-recognized file: _OVERRIDE required model before effort on one line, so const FAST = { effort: 'medium', model: 'opus' } or a multi-line literal was skipped silently — and the per-file not-blind test still passed because ADJ/VER had already put the file in seen. Both bypasses reproduced before fixing. Scanner inverted from find-what-I-recognize to account-for-every-token: const NAME = { opener + brace-balance block (field order and line count now irrelevant), and every model:/effort: occurrence outside a recognized block is a failure, not a skip. Not-blind test replaced by per-token coverage; 3 new tests pin reordered, multi-line, second-unannotated-override, and unrecognized-syntax cases
2026-08-01 128 3696703090 scripts/tests/test_agent_frontmatter.py gate-integrity P2 ACCEPT The round-5 "rejects, never skips" parser validated strictly but selected leniently: `[ln for ln in ... if ln.strip().startswith("
2026-08-01 128 3696727241 scripts/tests/test_agent_frontmatter.py gate-integrity P2 ACCEPT The nastiest of the series — not a skip but a false covered. Round-7's brace-balance counted braces inside strings and comments, so note: '{' merged the following const into the current block: the swallowed override inherited its neighbour's parity-seats annotation, had its lines marked covered, and never had its own values compared, so a stale pin read as fully checked by every test. Reproduced exactly (STALE at effort: 'max' invisible) before fixing. String/template/comment contents now masked to spaces before balancing (length- and newline-preserving, so indices stay aligned); structure read from the masked copy, values from the original. 3 regression tests (string brace, comment brace, mask-preserves-line-structure); real workflow re-verified to still yield ADJ/VER with zero unrecognized. Known limit documented: a regex literal containing a quote or brace would need a real JS parser
2026-08-01 128 3696727242 .claude/agents/codex-relay.md contradictory-doc-surfaces P2 ACCEPT codex-relay.md line 72 still told spawners they "may run it on a small model (model: haiku)" while the register pinned the seat to Opus at medium — and a call-time model beats the frontmatter, so the documented allowance silently defeated the pin. Worse, it falsified this PR's own claim that every mechanism surface is parity-checked: an ad-hoc main-thread spawn is persisted nowhere a scanner can read. Extent-grepped: sole instance across .claude/agents/ and .claude/skills/. Allowance withdrawn (rationale for the medium pin kept, since that part was true), and the unguardable path closed upstream instead — test_no_agent_body_licenses_a_call_time_override fails any agent body naming a model:/effort: option. Over-claim corrected on the register and CLAUDE.md rather than left standing
2026-08-02 128 3696752313 .claude/agents/codex-relay.md interpretive-precision P2 REBUT (+ clarifying edit) Wrong axis: line 33's "may override either" governs the Codex-side parameters of the canonical command (-m gpt-5.6-sol, model_reasoning_effort="xhigh"), not this seat's Claude pin. The two examples name an OpenAI model (gpt-5.5) and the Codex effort config; the bullet sits in a list of codex exec invocation flags (-s read-only, -C, heredoc, timeout). The seat's own pin is opus/medium in the register and frontmatter and is untouched by it. The ambiguity was real, though, and is what misled the review — bullet reworded to name the GPT side explicitly and to state that the seat's own model/effort is not a spawner's to choose. Rebuttal posted on the thread
2026-08-02 128 3696752316 scripts/tests/test_agent_frontmatter.py gate-integrity P2 ACCEPT Round-8 masked for structure but extracted values from the unmasked block, so const X = { /* model: 'opus', effort: 'medium' */ model: 'opus', effort: 'max' } recorded opus/medium while the runtime ran opus/max — a stale effort passing parity. Third bypass of this scanner in three rounds, so fixed by replacing the regex approach outright with a small JS tokenizer (comments dropped — a commented-out override is not a runtime override; string contents opaque). Values now read from the token stream at depth 1 of the literal. String-decoy variant also pinned
2026-08-02 128 3696752318 scripts/tests/test_agent_frontmatter.py gate-integrity P2 ACCEPT {'model': 'opus', 'effort': 'max'} — ordinary JS — matched neither the override probe nor the unrecognized-token path, so a quoted-key override could drift while the nonempty lower bound was satisfied by a bare-keyed sibling. Same tokenizer fix: a quoted key is a str token in key position, recognized identically to a bare one. Also closed a fresh false-covered variant the tokenizer exposed — a pin key nested deeper than the literal's top level, or not assigned a plain string, is now reported as unrecognized rather than riding on its block's coverage
2026-08-02 128 3696912186 scripts/tests/test_agent_frontmatter.py gate-integrity P2 ACCEPT The round-10 spread guard fired on ANY top-level dot: temperature: 0.5 (the tokenizer emits digits as punct, so a decimal is 0·.·5) and timeout: defaults.timeout both set spread_at_top, nulling extracted pins and failing the suite on ordinary JS — a false positive that trains maintainers to distrust the guard. Reproduced both before fixing. A spread is exactly the three-dot sequence, and the tokenizer emits ... as three consecutive . puncts, so the check now requires punct(k)·punct(k+1)·punct(k+2) all dots; a lone dot can never satisfy it. Regression test pins both clean cases extracting opus/medium with zero unrecognized; the genuine-spread test still fails the block closed
2026-08-02 128 3696912187 .claude/skills/working-with-opus/SKILL.md contradictory-doc-surfaces P2 ACCEPT The Maintenance procedure still instructed "re-fetch from the URL, never from a bundled-skill copy" — written in round 3 as a durability fix, but after the round-10 two-edition resolution it is a recipe for repeating the exact source-substitution failure: the next refresh would replace the block-carrying bundled [MG] with the shorter public edition and falsely invalidate §2/§4. Pair was a triple: fixed the Maintenance bullet (re-fetch public URL AND re-extract the bundled edition via the claude-api skill or the strings recipe; public zero-hits never invalidate bundled quotes), the digest's own header re-fetch line, and the SKILL.md surfaces-table row
2026-08-02 128 3696912188 .claude/environment-register.md incomplete-propagation P2 ACCEPT The register (and CLAUDE.md and the working-with-opus SKILL mechanism list) still described the round-9 name-pattern exclusion — "dated rerun-*-YYYY-MM-DD.js salvage scripts are excluded by name" — after round 10 replaced it with the explicit two-file _HISTORICAL_WORKFLOWS allowlist; a maintainer closing a future dated salvage workflow would expect exemption and instead get CI pressure to retro-edit a run record. All three contract surfaces now name the two allowlisted files and the rule that a newly closed salvage workflow joins the allowlist in the same commit (the register's two dated history entries mentioning rerun-*.js are run records, left as written)
2026-08-02 128 3696912190 .claude/skills/consolidate/SKILL.md contradictory-doc-surfaces P2 ACCEPT This branch wired H-001's survey hook into consolidate C5 step 3 (append one dated line to the observations ledger every run) while the same skill's Gate ledger classified edits to "any skill" as never-autonomous — so a run could not follow C5 as written and the hypothesis denominator would stay empty. Resolved in the direction of the deliberate design (the hook is labeled "wired, not aspirational"): the Gate ledger now carves out exactly this write — a single dated append under the H-001 entry, nothing else in the file — and C5 step 3 names the carve-out, so the skill-edit prohibition stays intact for everything procedural
2026-08-02 135 3697843511 deploy.sh gate-integrity P1 ACCEPT Candidate compose up was bare under set -e: a start failure exited after the serving retag and mapping write with no restore and no vocabulary line — the service could sit down or unknown until the next tick. Fixed with the shared fall_back_to_recorded helper: restore the recorded deployed image, record phase=start, journal the new Deploy start FAILED: line (added to header vocabulary + README). The identical bare-up in cmd_restore was fixed in the same pass (extent, not instance). Pinned by test_candidate_start_failure_restores_previous_image + the structural test_candidate_start_and_restore_start_are_not_fail_open (every compose_cmd … up must sit inside an if)
2026-08-02 135 3697843516 deploy.sh gate-integrity P1 ACCEPT The probe-failure rollback discarded the restoring up's error (|| true) and never probed the restored image, yet journaled "restored" unconditionally — a failed restart would report success while the service was down. Now up && probe_all gates the word "restored"; a failing fallback journals — restore of <id> also failed. Cross-pinned by test_fallbacks_are_probed_before_being_called_restored (both fallback helpers must contain probe_all and an "also failed" line)
2026-08-02 135 3697843520 deploy.sh gate-integrity P1 ACCEPT cmd_restore left a probe-failing target serving while deployed.env named the previous good image — a failed incident rollback could create the outage it was fixing. Now the pre-restore running image ID is captured before the retag and a probe failure reverts to it (retag + up + probe), with three distinguishable tails: reverted / revert also failed / no pre-restore image to revert to. The agent's original "reverting a restore would be circular" reasoning was wrong and is corrected on the record. Pinned by four new restore-path tests
2026-08-02 135 3697843524 deploy.sh gate-integrity P2 ACCEPT Tag-clobber guard only consulted the recorded mapping when the SHA tag existed: tag pruned + mapping alive → silent --pull rebuild could produce a different image ID and overwrite the mapping, destroying the SHA→image identity restores depend on. New leg: mapped image present → retag + reuse (no build); mapped image gone → default-deny block naming WIKIWIP_ALLOW_REMAP=1 as the deliberate override that rebuilds and re-records. All three legs pinned; shim images gained real existence semantics to make the vanished-image leg testable
2026-08-02 135 3697843527 README.md build-deploy P2 ACCEPT The seeding block's SHA=$(git rev-parse HEAD) fabricates the mapping on exactly the wedge topology the slice repairs (HEAD advanced past the serving image). Block rewritten in two steps: evidence first (journal Deploy complete: tail + image Created time — the OP-0 corroboration method, kept as a human comparison rather than an invented tolerance window), then the operator sets the corroborated SHA or the literal unknown-unverified (never guess; restore works by image ID regardless, so honesty costs nothing). Pinned by test_readme_seeding_block_does_not_fabricate_the_serving_sha
2026-08-02 135 3697843531 README.md build-deploy P2 ACCEPT The seeding block wrote the only rescue-identity records directly while the surrounding docs promise temp+mv atomicity — an interrupted shell could leave a partial mapping that restore then rejects. Block now writes .tmp siblings and mvs into place, guarded by a non-empty IID/SHA check so an empty image ID cannot be recorded. Pinned by test_readme_seeding_block_writes_state_atomically
2026-08-03 147 3707717623 site.yml incomplete-propagation P2 ACCEPT The D3 suite step rode implicit success(), so a sibling Cytoscape failure suppressed the entire D3 evidence trail (no run, no failure artifacts) despite D3 being an independently reported suite. Lead-widened to the full extent: all four vendored suite/verifier steps lacked if: — the same-PR review fixup had outcome-gated the uploads but not the steps (the propagation gap), and gating d3 alone would have left d3_verify on implicit success, skipping after a sibling failure and cascading into the success upload. Repaired +40/−0: suites keyed !cancelled() && steps.webkit.outcome == 'success' (independent of siblings AND of the generic inventory verifier — intentional, owner-recorded), verifiers keyed on their own suite; exact contract pins + sibling-independence negative assertions in the same touch. Verified by an 8-scenario skip-matrix simulation over the committed conditions ("a verifier can never be skipped on a green job; no upload fires on an unverified result") + 7/7 applied-verified mutations (delta-2 review)
2026-08-17 157 3797781132 setup-runner.sh gate-integrity P2 ACCEPT The restart-only path fired on a local .runner alone, and the closing gh api listing succeeded even with the runner absent server-side — a deleted GitHub-side registration would "restore" an orphaned service and report success without CI coming back. Now the host pre-checks server-side registration by name, an orphaned local config is stopped/uninstalled/cleaned and re-registered fresh, and the final listing is fail-closed: the script exits 1 unless RUNNER_NAME is actually present in it
2026-08-17 157 3797781136 setup-runner.sh build-deploy P2 ACCEPT Host-side release parsing used jq, which macOS does not ship — the documented setup-from-scratch path failed before ever entering the VM (the provisioned jq lives inside the VM, not on the host). All host-side parsing now goes through gh's built-in --jq; jq remains a VM-only dependency
2026-08-17 157 3797781139 README.md build-deploy P2 ACCEPT The recommended second-runner-instance recipe was unsafe as documented: both site.yml Pagefind steps shared /tmp/${PF_FILE} and /tmp/pagefind across instances, and concurrent playwright install --with-deps calls race on the apt/dpkg lock. Fixed the extent, not just the instance: Pagefind steps moved to per-job ${RUNNER_TEMP} in both jobs; DPkg::Lock::Timeout "300" added to the VM provision (and applied in the live VM); README recipe rewritten with safety preconditions (first full green run before a second instance; second VM as the preferred scaling path)
2026-08-17 157 3797908179 site.yml gate-integrity P2 ACCEPT Round 2, on the round-1 fix itself: RUNNER_TEMP isolated download/extract but the sudo mv still published to the shared /usr/local/bin — two runner instances executing different refs with different .pagefind-version could clobber each other's binary between install and use (the round-1 comment's "identical binary either way" assumed same-version instances). Both steps now keep the binary job-local in ${RUNNER_TEMP} and prepend it via GITHUB_PATH (which also outranks any stale binary an older run left behind; the live VM's leftover was removed); sudo drops out of the steps entirely
2026-08-17 157 3797908181 setup-runner.sh gate-integrity P2 ACCEPT Round 2, on the round-1 fix itself: the pre-check and final verification matched on runner NAME only, so a server-side runner that lost its wikiwip-ci-mbp label read as healthy while every runs-on job queued forever. Both checks now require name AND label via a shared labels_for_runner helper (jq env-var selection, comma-delimited exact label match); a label-less runner re-registers on the orphan path and fails the final gate otherwise
2026-08-17 157 3798025931 setup-runner.sh gate-integrity P2 ACCEPT Round 4, on the round-3 online-poll itself: the check-then-sleep loop checked at ~0-55s and wasted a terminal sleep, rejecting a runner that came online in seconds 56-60 of the intended 60s grace window. Rewritten as immediate check + sleep-then-check (13 checks covering the full window, no wasted delay)
2026-08-17 157 3798025935 setup-runner.sh build-deploy P2 ACCEPT Round 4: host-side seq flagged as an undeclared dependency. The factual premise is incorrect — macOS ships /usr/bin/seq as an OS component (verified on this host: SIP-protected /usr/bin, root:wheel, macOS 27.0) — but the recommendation coincides with the 3798025931 rewrite (bash arithmetic loop), which drops seq anyway and keeps the host dependency set at gh + limactl only, consistent with the round-1 jq elimination. Accepted on the principle, premise corrected on the record
2026-08-17 158 3798256780 site.yml gate-integrity P1 ACCEPT Per-shard static ports still collide when two concurrent runs (master push + PR/dispatch — the concurrency groups deliberately allow it) schedule matching shards on the two runner instances. Replaced by instance-scoped derivation: a step reads RUNNER_NAME (instance N → app 4073+100N / site 4080+100N; unrecognized names, i.e. the hosted rescue lane with its per-job VMs, fall back to the defaults). Stronger than the suggested run-specific component: two jobs can only share the VM's localhost by running on different instances, so instance-scoped ports are collision-free by construction across shards, runs, refs, and dispatches, and scale to any future instance count
2026-08-17 158 3798256784 setup-runner.sh gate-integrity P2 ACCEPT ${1:-1} converted an explicitly empty first argument (unset caller variable) to instance 1 before validation, making the '' rejection branch unreachable — invalid input could silently reconfigure instance 1. Default now applies only when no argument was supplied ($# check); an explicit empty value reaches the case guard and fails
2026-08-17 158 3798319725 site.yml incomplete-propagation P1 ACCEPT Round 2, on the round-1 fix itself: the atlas-webkit job kept its FIXED 4174/4184 pair outside the new RUNNER_NAME derivation, so two concurrent runs' webkit jobs landing on the two instances would still collide — the round-1 "collision-free by construction" claim was undermined by its own incomplete propagation. The webkit job now runs the same derive step (GITHUB_ENV scopes the pair to all three suites) and the fixed job-level env is gone
2026-08-17 158 3798319730 setup-runner.sh gate-integrity P2 ACCEPT A leading-zero instance number ("08") passed the digits-only guard, registering a runner name whose suffix later aborts bash arithmetic in the port derivation ("value too great for base", octal). The guard now rejects noncanonical forms (empty / non-digits / leading zero) in one case pattern, and both workflow derive steps force decimal with the 10# base prefix as defense in depth. Guard and derivation mutant-tested ("", "abc", "0", "08", "2", "12"; all four runner-name shapes)
2026-08-18 162 3806340757 scripts/build_refuter_ledger.py gate-integrity P2 ACCEPT check() indexed source seats by (run, slug, lens), collapsing a C2 seat and a C3 rival-reading seat for one slug into one entry, so the two valid skeleton rows failed --check as a gate mismatch. Now indexed by the full (run, gate, slug, lens) key with the triple index kept only as a fallback for gate-typo diagnostics; pinned by test_c2_and_c3_seats_for_same_slug_both_check
2026-08-18 162 3806340762 scripts/build_refuter_ledger.py gate-integrity P2 ACCEPT check_distribution let a later duplicate class/Total row overwrite an earlier wrong one, so a malformed table passed. Duplicate labels are now a defect; pinned by test_duplicate_distribution_label_fails
2026-08-18 162 3806340766 scripts/build_refuter_ledger.py gate-integrity P2 ACCEPT registry_seats appended seats twice for a duplicated REGISTRY run label and the matched set collapsed them, so an exact-duplicate registry line still passed. Duplicate run labels are now a defect and the repeated entry is skipped; pinned by test_duplicate_registry_run_label_fails
2026-08-18 162 3806340771 wiki/.audit/pagination-oracles.md interpretive-precision P2 ACCEPT Saint Aubert 2023 oracle stated raw ≈ printed − 6 while its own checkpoints ({1}=p.5, {7}=p.11) give printed = {N} + 4; line corrected to −4 / printed ≈ {N}+4
2026-08-18 162 3806340781 scripts/build_refuter_ledger.py gate-integrity P2 ACCEPT A verdicts JSON whose root is null/array raised an uncaught AttributeError in _slug_dict (traceback, exit 1) instead of the documented LedgerError path. Root type is now validated and raised as LedgerError with the path; pinned by test_non_object_verdict_json_is_ledger_error