Make the wiring gates honest, and the suites that judge them hermetic - #832
Conversation
CLOUD-1339 `hook wire duplicate` names no remedy, so its refusal sent a session to a menu instead of the verb that fixes it
§1 SubjectThe §2 The measurementMeasured 2026-09-02 while landing CLOUD-1321 in a Claude Code web container.
The remedy exists and ships in this repository: The refusal did not name it.
Both are prose documents. Neither names a command, and neither of those documents names Its own sibling in the same module does name its fix. The class prose actively points away from the remedy. It reads "The wiring this judges is the launcher's own merged settings, which live outside this repository". That sentence is true about where the file lives and false about what can fix it, and it is the sentence a reader reasons from. §3 What it cost, measured rather than supposedThe session read the refusal, read
All of it was closed by one command the refusal could have named. **AND THE REMEDY DOES NOT HOLD, WHICH IS THE SECOND HALF AND WAS MEASURED AFTER THE ROUTES LANDED. ** That changes what naming the verb buys: it turns a session-long dead end into a per-session chore, which is a large improvement and not a resolution. The row that would resolve it is a different one — either the registrations stop being written, or §4 Why the contract already covers thisCLOUD-122's refusal contract is that every deny names the fix. Refinement — Ready (name the verb in the refusal) Refinement gate: Definition of Ready & Done. This body carries only specializations. {
"source_of_truth": "`hook wire duplicate`'s `[[verdict]]` row in batten.toml carries two `[[verdict.route]]` entries, both `kind = \"document\"` pointing at prose, and no mention of `batten wiring reclaim` in either the routes or the class — while its sibling `hook wire loose` names its fix inline",
"gate": { "task": "batten-check", "exits": [0, 2] },
"commit_type": "fix",
"blockers": [],
"tests": [
{ "file": "policy/verdict-routes-resolve.rego", "mutation": "route-task-unchecked" },
{ "file": "policy/remedy-authorship.rego", "mutation": "remedy-prefix-unchecked" }
]
}
Acceptance
§6 Cost of not doing itAlready paid once, above: a false claim on two commits, a gate switched off three times, and a decision put to a human that the tree already answered. The next session meets the identical refusal with the identical documents. Found while landing CLOUD-1321 (PR #828). CLOUD-1191 The hook command spelling exists as three unlinked literals, so `doctor hooks` would report stale wiring as healthy and the golden test would pass a half-rename — derive all three from SURFACE
Why
Plus five committed wiring files ( Nothing derives any of them from the row. Three consequences, in ascending order of nastiness:
Why this is worse than a normal drift**The failure mode is silent fail-open. **
An unknown subcommand is a clap error → This is hook-convergence work regardless of any rename: three authorities over one fact, where disagreement disables the gate. Refinement — Ready (one authority for the hook invocation) Refinement gate: Definition of Ready & Done. This body carries only specializations.
Acceptance
Found while pressure-testing a proposed CLOUD-940 A guard retired from the wiring but left in the tree is invisible to every wiring gate, and `gh-guard` has been in that state with a header claiming it is wired
Why
Its enforcement moved into the engine — The mechanism gap, which is the point rather than the instance
CLOUD-713 built the census for the other direction ("nothing counts the PreToolUse commands that are not batten's, so six shell guards accreted beside the engine unremarked") and is Done. CLOUD-312 owns the ten declared rows that are still wired and must retire. Neither owns the absence direction: a guard whose registration is gone while its file, its suite, its documentation and its own header all still assert it is live. So the tree can carry a program that:
A SECOND DIRECTION, measured 2026-08-31 — a gate that IS wired to a caller that is itself unreachableThis row's §2 predicate is scoped to hook-body-shaped programs: those whose
**The corrected finding is one level up, and it holds. That is CLOUD-825**'s recorded finding, and that row is Done while the condition**** The consequence, measured rather than argued
At The predicate this direction needs, and why it is not §2'sA program is unreachable iff, transitively, no config-surface entry Measured first pass, non-transitive, over 123 governed programs: 15 have no Two directions, one subject: a program in the tree that decides nothing. §2 catches Why this is not simply "delete two files"That was the first read and it is wrong. The pair is entangled, and
Concretely: So the disposition is a decision per file, not a sweep:
Refinement — Ready Refinement gate: Definition of Ready & Done. This body carries only specializations.
Acceptance
Found while pressure-testing the CLOUD-927 bundle, after asserting in a plan that this was two dead files to delete in passing — which the tree contradicted in four places. CLOUD-122 Refusal output contract: every deny points to the fix
Generalizes the actionable-refusal principle (design-decisions doc, principle #5). CLOUD-96 is the first concrete instance; this makes it a contract across the hook / exec / check layers. Why. A block should get the agent to right in one hop, not make it thrash — and a one-line remediation pointer is far cheaper than an agent guessing. A denial is a linter result, not a closed door. Scope. Every mediated deny returns, in machine-readable form: the error / rule id, a short reason, and a fix pointer — the exact command to run, plus an apply affordance ( Acceptance.
Sources (public). Bound (CLOUD-211 note): a mediated deny originates only from a computable predicate — never a judge verdict (any model signal is advisory-only) — so the refusal shape need not model advisory output; refusal copy uses conformance-gate vocabulary, not "permission hook". Refinement — Ready (one refusal type, constructed at every deny site, carrying the fix pointer by construction) Refinement gate: Definition of Ready & Done. This body carries only specializations.
Landed — PR #298, Two deviations from the Ready block, both deliberate.
Where each fix comes from, since the Ready block did not pin it. A shape row's fix is its Follow-up seam, now open. CLOUD-215 landed mid-flight ( Defect found while landing, filed not absorbed: CLOUD-405 — CLOUD-199 run-shape-guard covers `mise run` only — `git push | tail` masks a verdict the same way
Why. Measured, minutes after the guard landed. The guard refused The failure was benign this time. The mechanism was identical to the one the guard exists to stop, and the guard could not see it. Second measurement, 2026-08-08 — and a shape neither the guard nor this issue's acceptance covers: a filter whose pattern cannot match the output format. While landing the CLOUD-241 fix I "confirmed clippy green" with: Empty output, so I reported it clean and committed. This is not the pager shape. The exit status was not handed to a pager — What this adds to the acceptance. The rule the guard should encode is narrower and sharper than "no pagers": a verdict-bearing command's status must be read from the harness, never inferred from its output. A filter, a pager, a The self-indicting detail: the compliant form is already documented and I used it everywhere else in the same session ( The generalisable lesson the guard's own comment states, and its matcher does not implement: a pipe replaces the command's exit status with the pager's. That is a property of pipes, not of Acceptance.
Third measurement, 2026-08-08 — the trailing-list shape is worse than "looks compliant": backgrounded, the harness itself reports the wrong verdict. The acceptance bullet above already names Fourth measurement, 2026-08-09 (CLOUD-40) — a tail window that is itself a well-formed green verdict. This is a sharper variant than the three above, and the reason is Caught only by re-running as It adds nothing to the deny list — Stronger form, where it applies. A guard is feedforward; it can only catch shapes. For anything whose effect is observable, prefer asserting the state over trusting a status — Refinement — Ready (the decision table generalises from Refinement gate: Definition of Ready & Done. This body carries only specializations.
CLOUD-1163 Retire the eight small multi-program units — 59.7s, and SIX of eight land today: BOTH remaining blockers (CLOUD-1108, CLOUD-1115) disclaim blocking in their own bodies, by name
COLUMN CORRECTED 2026-09-02 — In Progress → Todo; unit 8 landed, the other seven are unclaimedMeasured against
A claim nobody is working is not a claim. Back to Todo; the Ready block below still holds and CORRECTION (2026-08-31, second pass) — the two BLOCKERS were read from this row's own table instead of from the rows they cite, and both cited rows say the opposite IN BOLDThis row's 2026-08-31 correction fixed three wrong reasons by reading the programs. It did not re-read the two BLOCKER ROWS, and that is where the remaining error was. Read each of them at head and both disclaim blocking this row, by name:
Both blockers were carried on this row's TITLE-adjacent verdict rather than on the cited row's body. That is CLOUD-1166's class one level up from the three this row already corrected: not classifying a program instead of reading it, but classifying a BLOCKER instead of reading it. The reading took minutes, as it did the first three times. The seconds are stale, and every rank movedThe 52.2s in the old title and the per-unit column below predate CLOUD-1198's corpus regeneration. Re-derived from
Unit 11 went from fourth-largest to largest, and units 11 and 9 together — 32.9s, 55% of this row — were the two carried as blocked. The row is now: six units and 52.4s land today, 6.8s is genuinely blocked on CLOUD-1251, and 0.5s is not migrating. Arm-4 evidence for the one surviving block, quoted rather than categorised: Why Units 3, 4, 6, 7, 8, 9, 10 and 11 of the 83-unit partition. Eight independent deltas, 19 programs, 52.2s combined. They are one row because each is small and none glues to another; each still lands as its own PR with its own ledger arms.
Glue, per unit (each is a
The home each unit's decision lands inA disposition is chosen before a successor is designed (CLOUD-1176). "Port it into
Which of the eight are actually reachable
So three of eight land today — units 8, 10, and (comparator-first) 7. That is the honest count and it is why CLOUD-1151 cannot size a wave from unit count. CORRECTION (2026-08-31) — the blocked verdicts above predate the fact surface they were judged againstEvery blocked verdict in this row was written on 2026-08-29/30. Seven fact families have landed since, and the row was never re-read against them. Enumerated from the generated
~~THE COUNT CHANGES: it is now FOUR of eight, not three. ~~(Superseded 2026-08-31 by the second-pass correction at the top: it is SIX of eight. Units 9 and 11 were blocked on rows that each disclaim blocking.) Unit 6 was carried as blocked on a comparator input it does not need, and reading Every wrong reason in this row came from classifying a program instead of reading it. Three corrections, three instances: "out-of-root" for unit 4, "missing fact" for unit 3, "comparator inputs" for units 6 and 7. The reading in each case took minutes. Read the program before recording why it cannot move. Two need a runnable successor at a real path, not just a ledger arm
Refinement — Ready (eight deltas, one row; units 8, 10 and 7 land today) Refinement gate: Definition of Ready & Done. This body carries only specializations.
Weakens: rule-removed rule[harness-wiring-merged] Weakens: rule-predicate-changed rule[harness-wiring].documents Weakens: rule-predicate-changed rule[harness-wiring].external Weakens: rule-predicate-changed rule[harness-wiring].minted Unit 9's landing carries four config smells against Acceptance
Units 3, 4, 6, 7, 8, 9, 10, 11 of 83. CLOUD-1373 The committed-policy suites read the developer's own admission store, so a spent admission on the machine turns a deny assertion green
Why
Both scrubs are walks over environment variables. An admission is not one. CLOUD-1051 retired **This suite already knew. ** Measured 2026-09-02, and it is a false green in the unsafe direction. A spent admission for It is not one case. State is keyed by repository, so every suite that drives the binary against the REAL root shares the real repository's own segment: **Predecessor. **CLOUD-619 (Done) fixed the platform half of this class: suites redirected with Refinement — Ready (redirect the suite's state root by default) Refinement gate: Definition of Ready & Done. This body carries only specializations.
Acceptance
|
|
Warning Review limit reachedNext included review available in 16 minutes. View limit detailsLimit details: You’ve used the included review currently available. Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Free Run ID: 📒 Files selected for processing (14)
Note 🎁 Summarized by CodeRabbit FreeYour organization is on the Free plan. CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please upgrade your subscription to CodeRabbit Essentials by visiting https://app.coderabbit.ai/settings/billing. Comment |
b26ee81 to
3f89401
Compare
`hook wire duplicate` fired correctly and named no remedy. Its two routes were both `document` — AGENTS.md and `.claude/rules/toolchain.md` — and neither document mentions `batten wiring reclaim`, the verb that removes the registration and takes the rule to exit 0. Its class actively pointed away from the remedy: "the launcher's own merged settings, which live outside this repository" is true about where the file lives and false about what can fix it, and it is the sentence a reader reasons from. `doctor.rs`'s `MERGED_SIBLING` doc said the same thing more plainly — "editing the repository cannot remove the registration" — which is a statement about editing tracked files that reads as a statement about this repository's reach. Measured 2026-09-02 (CLOUD-1339 §3): a session read the refusal, read that doc, concluded the condition was unfixable from here, spent `HK_SKIP_STEPS=hooks-wiring-check` on three commits, wrote that conclusion into two commit messages on main-bound history, and put a three-option menu to a human. All of it was closed by one command the refusal could have named. A second session reproduced the same dead end today before finding the verb. So the class says it is repairable and says what the repair does not buy — a launcher that registers at session start registers again next session, so this is a REPAIR and not a fix, and a reader must not go looking for a permanent one. The command route is FIRST, because a reader who follows only the first route has to reach the thing that clears the refusal. The generalisable half is deliberately split rather than taken here. Measured over the committed registry: 87 of 130 `[[verdict]]` rows carry no command or task route and no `no_fix_reason`, so a gate asserting that obligation fires on 87 rows on its first run — the false-positive-first- firing shape CLOUD-199 prices and `privileged-lane.rego:60-65` records. That needs its own row and a triage pass, not a clause in this one. Verified: `batten policy explain "hook wire duplicate"` lists `verb run first command batten wiring reclaim` first; `verdict-routes-resolve` and `remedy-authorship` both exit 0. Closes: CLOUD-1339 Admits: 7ada5204221a96b63ea99a358227f06f94c8d71eb92c1d6bdba2f532652eb0b5 Admits-rule: protected-mutation Admits-verdict: path write refused Admits-subject: batten.toml Admits-head: 8c95e02 Admits-epoch: 740d686e61edc7dad9b8a104e1f1f406ab53254158581a5a05a9452914dd6a47 Admits-author: alec@wenzowski.com Admits-prev: 7c8bc6d7c40b7bd40a10433b44d540707913c7fd6e78be19d55f6b3e95984e55 Admits-answer-lost: The refusal keeps naming only two prose documents, neither of which mentions `batten wiring reclaim`. Measured 2026-09-02 (CLOUD-1339 §3): that cost one session three commits with `hooks-wiring-check` switched off via HK_SKIP_STEPS, a false claim about this repository being unable to remove the registration written into two commit messages on main-bound history, and a three-option menu put to a human that one command already answered. Admits-answer-precondition: The change is a new [[verdict.route]] entry and a class rewrite on the `hook wire duplicate` row. batten.toml is the ONLY surface where a [[verdict]] row declares its routes — no verb adds one — so writing the protected path directly is the only route left. The write lands in the PR diff for CLOUD-1339, where a reviewer sees it. Admits-answer-rejected-route: `config read first` targets batten.toml itself — reading the file is not a change to it, and the change IS to that file. `patch run first` is `git restore`, which discards a working-tree change; I am adding one, not reverting one. Refs: CLOUD-1339
`batten hook --harness <x>` was spelled independently in three places with nothing linking them: the `SURFACE` row that declares it, the generator in `hook::wiring_command`, and the diagnostic in `doctor::reaches_engine`. Five committed wiring files carry it as data. A disagreement between them is not ordinary drift, it is a SILENT FAIL-OPEN. An unknown subcommand is a clap error, which is `ExitCode::Usage` (1), and `exit.rs` states the consequence as a design property: every host reads anything but 0/2 as "the hook itself failed, let the call through". So three literals that disagree do not break loudly — they turn enforcement off across every harness while `doctor hooks` reports green. `reaches_engine` matched the literal `"hook"`, so against a settings file naming a command the surface no longer declares it returned true: the one diagnostic built for this exact failure was blind to it. So both consumers now derive from the row, anchored on `CommandDecl::id` and never on `path`. That is the field's own contract — `path` is "the one thing about a row that is expected to change", so a derivation keyed on it re-breaks on exactly the rename it exists to survive. A fourth loose literal goes with them: the binary's own name, which the diagnostic matched as a file stem. It is `surface::BINARY` now, beside the row the generator emits, because those two agreeing is what makes a registration reach the engine. No fallback literal anywhere. A surface declaring no mediation row yields a command with no verb in it, which matches nothing, so every registration reads as drift — loud. Emitting `"hook"` when the declaration is gone would be the fourth spelling again, and it would report healthy. Shown able to fail, per CLOUD-418: - `wiring_naming_an_undeclared_path_does_not_reach_the_engine` asserts `reaches_engine` is FALSE against `batten adjudicate --harness claude-code` — the shape a half-done rename leaves in a committed wiring file. It passed as healthy before this change. Reverting either consumer to a literal reds it. - `the_emitted_argv_is_the_rows_path_and_its_required_flags` pins the derivation itself. - `the_mediation_row_resolves` makes a deleted or renamed `id` loud, since that is the one edit the anchor does not survive. The five committed wiring files and their fixtures are byte-identical, which is this row's stated acceptance and the reason it takes no bump. `mise run test:cargo`: 4126/4126 green. Closes: CLOUD-1191 Refs: CLOUD-1191
…d it CLOUD-1191 removed three unlinked spellings of the mediation verb; two test assertions still carried a fourth and a fifth as literals, and both fail in the direction that asserts nothing. `doctor.rs`'s Windows-image case hardcoded `/opt/bin/batten.exe hook --harness claude-code`. `spec.rs`'s `the_mediation_entrypoint_is_never_read_only` hardcoded `"hook"` — after a rename that case would ask whether a path the surface no longer declares is read-only, get "not in the allowlist" for the trivial reason, and pass green while pinning nothing. That is the same false green CLOUD-1191 exists to remove, one level down, in the test that guards it. Both now derive from `surface::mediation()` / `mediation_argv()`, so the row is the single authority the rest of the change already made it. Found by attempting CLOUD-1192's rename against this branch: the derivation carried the generator and the diagnostic without an edit, and these two literals are what went red. Measurement recorded on CLOUD-1192; the rename itself is not in this change. Refs: CLOUD-1191
… the real repository `common::batten()` scrubs the ambient environment twice — every `BATTEN_` variable the surface declares, and every bypass name beside it. Both are walks over ENVIRONMENT VARIABLES, and an admission is not one: CLOUD-1051 retired `BATTEN_FILED_HERE_BYPASS` and its siblings precisely so that suppressing a refusal would cost a signed record in the state store rather than a knowable string. So the channel that replaced the scrubbed ones is unreachable from the scrub by construction. `bypass_scrub.rs` already knew half of this. `the_hatch_is_load_bearing` had to stop observing the hatch through a protected-path refusal, and its comment says why: "that class declares an override route and the boundary honours a spent admission for it, so the variable stopped being its way out." The suite recorded that an admission had replaced the variable, and left the store ambient. Measured 2026-09-02, a false green in the unsafe direction: a spent admission for `batten.toml` in the developer's own store turned `cli.rs::the_committed_protected_paths_fire_on_a_mutating_verb` green-side — `mv batten.toml elsewhere.toml` answered exit 0 where the case demands 2, so the suite reported that the committed protected-path policy refuses a write while a record on that machine was admitting it. State is keyed by repository, so the affected suites are exactly those whose subject IS the committed configuration and which therefore run at the real root: `cli.rs`'s hook helpers, `mediated_verbs.rs` (whose `AUTHORITY` is `batten.toml`), `gh_guard.rs`, `pipeline_shapes.rs`, `refusal_ceiling.rs`, `shell_write_advisory.rs`, `preset_segments.rs`. They cannot escape it with a fixture home, because the segment is derived from the root that carries the config. NOT A DEFAULT ON EVERY SPAWN, which was the first shape tried and is wrong. A fixture suite may spawn a child that writes the store and read it back in-process — `admission.rs`'s `a_correctly_answered_override_completes_end_to_end` does, through `admission::load`, which resolves the root from the PARENT's environment. Redirecting only the child splits the two. That case is not the defect: its subject is a scratch repo, so it already has a segment of its own. `state_roots` lives in `common/` rather than in the asserting suite because that module is the one place the variables may be named at all, which `primitives::no_suite_sets_the_state_dir_variables_itself` enforces — a case that re-typed them would become the copy that audit refuses while claiming there are none. Shown able to fail, both halves, matching this file's own discipline: the mechanism half reddens when the redirect is removed, and an anti-vacuity mirror issues and spends a real admission against the real root and shows the committed protected gate flipping from exit 2 to exit 0. Refs: CLOUD-1373
3f89401 to
604815b
Compare
|
❌ The last analysis has failed. |
|
/fast-forward |
Three rows on one matrix. All three are the same defect class: a gate or a diagnostic that could not be trusted, in ascending order of nastiness — one reported stale wiring as healthy, one refused without naming a remedy, and one let a record on the developer's machine turn a deny assertion green.
Closes CLOUD-1191
Closes CLOUD-1339
Closes CLOUD-1373
CLOUD-1191 — derive the mediation spelling from the
SURFACErowbatten hookwas spelled independently in three unlinked places, and five committed wiring files carry it as data.reaches_enginematched the literal"hook", so against a settings file naming a command that no longer exists it returnedtrue— the one diagnostic built for this failure was blind to it, and the golden test would have passed a half-rename.surface.rsnow owns the answer (BINARY,MEDIATION_ID,mediation(),mediation_argv());hook.rs'swiring_commandanddoctor.rs'sreaches_engineboth derive from it with no literal fallback. Emitted bytes are unchanged, so no wiring file moves.Two test assertions carried a fourth and fifth literal and are derived too.
spec.rs'sthe_mediation_entrypoint_is_never_read_onlyis the instructive one: hardcoded, after a rename it would ask whether a path the surface no longer declares is read-only, get "not in the allowlist" for the trivial reason, and pass green while pinning nothing — the same false green this row removes, one level down, in the test that guards it.Shown able to fail by attempting CLOUD-1192's
hook→adjudicaterename against this branch: the generator and the diagnostic followed the row with no edit, and exactly those two literals went red.CLOUD-1339 — the refusal names the verb that clears it
hook wire duplicatesent a session to a prose document instead of a command. The class now carriesbatten wiring reclaimas its first route,kind = "command", so a reader following only the refusal reaches the verb.MERGED_SIBLING's doc comment is corrected to match.CLOUD-1373 — the committed-policy suites read the developer's own admission store
common::batten()scrubs the ambient environment twice — everyBATTEN_variable the surface declares, and every bypass name beside it. Both are walks over environment variables, and an admission is not one: CLOUD-1051 retiredBATTEN_FILED_HERE_BYPASSand its siblings precisely so suppressing a refusal would cost a signed record in the state store rather than a knowable string. The channel that replaced the scrubbed ones is unreachable from the scrub by construction.bypass_scrub.rsalready knew half of it.the_hatch_is_load_bearinghad to stop observing the hatch through a protected-path refusal, and its comment says why — "that class declares an override route and the boundary honours a spent admission for it, so the variable stopped being its way out." The suite recorded that an admission had replaced the variable, and left the store ambient.Measured, and a false green in the unsafe direction. A spent admission for
batten.tomlin the developer's own store turnedcli.rs::the_committed_protected_paths_fire_on_a_mutating_verbgreen-side:mv batten.toml elsewhere.tomlanswered exit0where the case demands2. The suite reported that the committed protected-path policy refuses a write while a record on that machine was admitting it.State is keyed by repository, so the affected suites are exactly those whose subject is the committed configuration and which therefore run at the real root:
cli.rs's hook helpers,mediated_verbs.rs(whoseAUTHORITYisbatten.toml),gh_guard.rs,pipeline_shapes.rs,refusal_ceiling.rs,shell_write_advisory.rs,preset_segments.rs. They cannot escape it with a fixture home, because the state segment is derived from the root that carries the config.Not a default on every spawn, which was the first shape tried and is wrong: a fixture suite may spawn a child that writes the store and read it back in-process (
admission.rs'sa_correctly_answered_override_completes_end_to_enddoes, viaadmission::load, which resolves the root from the parent's environment), and redirecting only the child splits the two. That case is not the defect — its subject is a scratch repo, so it already has a segment of its own.state_rootslives incommon/rather than in the asserting suite because that module is the one place those variables may be named, whichprimitives::no_suite_sets_the_state_dir_variables_itselfenforces — a case that re-typed them would become the copy that audit refuses while claiming there are none.Shown able to fail, both halves, matching that file's own discipline: the mechanism half reddens when the redirect is removed, and an anti-vacuity mirror issues and spends a real admission against the real root and shows the committed protected gate flipping from exit
2to exit0.What was scoped out, and why — each measured rather than judged
hook→adjudicate) — attempted here and backed out at 136 occurrences across 53+ files, 112 of them argv in the compiled-binary tier. It renames the entrypoint every wiring file names, so putting it in the same matrix as the change that repairs the diagnostic validating that wiring means if both are wrong together, the wiring gates cannot tell you. Back in Todo, unassigned, and now immediately pullable against an honest diagnostic.mise-tasks/ready-guard.sh, and only 12 of its 24 cases were ported by CLOUD-312. The other 12 cover the landing lease and the landing commit, which nothing enforces (leased-pushreads like the successor and is not — it decides git's--force-with-leasespelling). So the gate redsverifyon day one and cannot land until that retirement does. Filed as CLOUD-1363, which blocks it.list_issuesreduction — measured at 20,366 bytes emitted, more than the 17,313 stored. It is not a config row:Reduce::Projectis a flat field-pick at one node path, so projecting each element ofissues[]needs an engine arm. Left for its own change.Filed from this work, not fixed here
land, which rebases every lap. Three re-issues of one identical articulation, chained byAdmits-prev.filed-over-own-diffintersects path names, and every rule in this repository registers in one ~11k-line file, so any rule-proposing row overlaps any rule-touching PR whatever the two are about.wiring reclaimremoves registrationsharness-declared.jsondeclares. Hit live: running CLOUD-1339's own named remedy deleted the two hooks declared under CLOUD-1079 (still In Progress), turning a green tree into twohook declare stalefindings that neitherreclaim -nnordoctor hookscan see.Verification
mise run lint:clippy,mise run test:cargo,mise run policy-test, thenmise run verifygreen on the branch. Each row's shown-able-to-fail case is described above.