docs: reconcile repository direction and v0.3 release programme - #3353
Chris0Jeky wants to merge 7 commits into
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review Please review exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3bd8d0e946
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| ## Immediate next actions | ||
|
|
||
| 1. Qualify and disposition `#3156`, `#3167`, `#3295`, and stacked child `#3296` in dependency order. |
There was a problem hiding this comment.
Remove merged PRs from the active dependency queue
PRs #3156 and #3167 are already merged into the reviewed main as commits 409291f7 and fd1381be, respectively, so directing agents to qualify and disposition them as active dependencies is stale. Their remaining work is the separately tracked collector/integration residual and the human post-hoc acknowledgement in OUTSTANDING_TASKS.md J.4; leaving the merged PRs in this immediate-action queue can cause agents to redo landed work or misreport the release stack.
AGENTS.md reference: AGENTS.md:L17-L18
Useful? React with 👍 / 👎.
| The order below is programme order, not permission to merge any PR. Exact-head CI, review, stack | ||
| ancestry, control-plane authority, and maintainer gates still apply. | ||
|
|
||
| ### A. Reconcile retained release scope |
There was a problem hiding this comment.
Make the release sequence agree across the programme docs
This declares the following A–J sections to be programme order and therefore puts milestone reconciliation first, but the same commit's docs/REVIVAL_PLAN.md:80-88 places Smart CI, CI-17, and other prerequisites before reconciliation, while this document's own immediate actions at lines 304-311 put reconciliation seventh. Because the active-agent routing now points at all of these as current sequencing sources, agents receive contradictory priorities; either align the ordering or describe A–J as unordered workstreams.
Useful? React with 👍 / 👎.
| @@ -1,5 +1,44 @@ | |||
| # Taskdeck Implementation Masterplan | |||
|
|
|||
| ## Current programme integration (2026-09-21) | |||
There was a problem hiding this comment.
Refresh the masterplan's Last Updated date
The new current-programme section is explicitly dated 2026-09-21, but the document's Last Updated field remains 2026-09-19 at line 42. Readers and automation using that field to assess freshness will treat this canonical sequencing document as older than the reconciliation it now contains; update the field and keep it with the document header.
Useful? React with 👍 / 👎.
9bd14b9 to
08c9c87
Compare
|
@codex review Please review exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 08c9c87c7f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - PR `#2838` merged on 2026-09-19, delivering checkout `persist-credentials: false` coverage and | ||
| Pages permission scoping. Do not describe that implementation as parked or awaiting rebase. |
There was a problem hiding this comment.
Update canonical records for merged #2838
This correctly declares #2838 merged, but the canonical shipped-reality source still says that its persist-credentials work is open and explicitly calls the PR “Not shipped reality” (docs/STATUS.md:1342,1346), while the executable cutover checklist still leaves that implementation unchecked and requires the PR to be qualified (docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md:118-121). With no later STATUS entry superseding those claims, agents and cutover operators encounter opposite states and may redo landed work or falsely block privacy; add the shipped record and replace the stale checklist gate with the actual remaining acceptance, ruling, and CodeQL work.
AGENTS.md reference: AGENTS.md:L17-L18
Useful? React with 👍 / 👎.
| trusted, fail-closed Linux-only rehearsal owned by `#3170`. | ||
| 4. **Close release prerequisites.** Reconcile post-merge Windows timeout evidence after `#3162`, | ||
| finish the remaining `#2335`/CodeQL acceptance after merged `#2838`, and complete storage | ||
| (`#2333`), nightly/exact-tag qualification (`#2334`), runner proof (`#2328`), and mirror/GHCR |
There was a problem hiding this comment.
Defer exact-tag qualification until after cutover
The plan declares itself the wave-sequencing authority, but step 4 requires completing #2334's exact-tag qualification before step 6 executes the private cutover. The executable checklist limits pre-cutover #2334 work to contract and no-publish rehearsals (docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md:124-130) and schedules the real tag and exact-tag qualification only after privacy and the runner decision in section L. Following this sequence therefore either creates the tag too early or blocks cutover on an impossible precondition; restrict this step to pre-cutover rehearsal and leave exact-tag qualification in step 7.
Useful? React with 👍 / 👎.
| This row consolidates the human actions that remain after the merged release-assessment pass and the | ||
| September 18-21 implementation wave. It does not replace the detailed evidence and order on `#2337`, | ||
| `#2439`, `#3170`, or the private-cutover checklist. Historical parked wording in J.3 is not current: | ||
| `#2838`, `#3156`, `#3162`, and `#3167` are recorded as merged in J.4. |
There was a problem hiding this comment.
Add the CodeQL ruling to the open human checkpoint
J.5 says it consolidates the remaining release-control human actions, but it omits the still-human CodeQL posture required by docs/releases/V0_3_0_READINESS.md:227-240 and the programme brief. Its only mention in this human-action file is buried in checked item SC-5 at line 168, which also says the decision is not a maintainer action; because handoffs surface open [ ] items, the required #2335 ruling can now disappear from release handoffs. Add an explicit unchecked CodeQL decision item here.
AGENTS.md reference: AGENTS.md:L17-L18
Useful? React with 👍 / 👎.
829cf7c to
3ee5881
Compare
|
@codex address that feedback Apply the already-prepared review repairs currently stored in
After applying, run the documentation governance tests and link checker, update the PR body to the actual final head/file count, and request a fresh exact-head review. |
Summary
Testing
|
|
@codex address that feedback Your previous task successfully applied and verified the repairs in its local Publish the already-verified local tree using the authenticated GitHub App / PR creation or repository-write tool, not unauthenticated Do not merely report local completion again. The completion condition is a visible GitHub commit/PR whose changed-file list contains only the intended documentation/tracker files and whose actual head is named in the response. |
Summary
Publication blockerThe requested GitHub publication could not be completed because the environment exposes only the metadata-recording The final GitHub REST verification confirms that PR #3353 is still visibly at There are 50 open human-action items remaining in Testing
|
Maintainer handoff: final cleanup required before mergeThe documentation/direction/release-programme work is submitted in this PR, but do not merge the current head as-is. Current live state
Why one more branch update is requiredSix temporary patch chunks were accidentally committed instead of being applied:
The PR body is also stale: it names head Required finalization
cat .github/docs-reviewfix.part-00 \
.github/docs-reviewfix.part-01 \
.github/docs-reviewfix.part-02 \
.github/docs-reviewfix.part-03 \
.github/docs-reviewfix.part-04 \
.github/docs-reviewfix.part-05 > /tmp/pr3353-review-fixes.patch
git apply --check /tmp/pr3353-review-fixes.patch
git apply /tmp/pr3353-review-fixes.patch
rm .github/docs-reviewfix.part-0{0,1,2,3,4,5}
node scripts/check-docs-governance.mjs
node scripts/check-doc-links.mjs
node --test scripts/check-docs-governance*.test.mjs scripts/check-doc-links*.test.mjs
git diff --checkThe prepared tree previously produced 159 passing documentation regression tests and zero broken relative links, but fresh post-refresh evidence is authoritative. Scope already delivered in this PRThe substantive documentation package is present: current repository/v0.3 programme brief, rewritten release readiness authority, aligned product direction/revival/masterplan, agent and issue routing, outstanding human-gate checkpoint, index updates, and an explicit historical boundary around the 2026-09-17 assessment. No issue closure, milestone movement, visibility/branch-protection mutation, package visibility change, storage deletion, credential creation, runner association, release tag or publication is authorized by this PR. A complete finalization bundle and one-command helper were also exported in the originating ChatGPT conversation as |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 94180660a6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| | Agent runtime & MCP | `Application` (`AutomationPolicyEngine`), **MCP surface in `Api`** (`Program.cs` `--mcp` branch, `Api/Mcp/*`), `.codex/config.toml`, `.mcp.json`, `.grok/config.toml` (permissions only — no MCP servers), `docs/MCP_TOOLING_GUIDE.md` | Policy evaluated before execute; egress/telemetry guards; tool registry; Docker MCP gateway is user-scope only | security tests, MCP inventory/egress tests | | ||
| | Agent tooling / CI / docs | `.claude/`, `.codex/`, `.grok/` (README + permissions; Grok loads `.claude/skills/`), `scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1`, `scripts/agent_hooks/` (manual ledger projection only), `.github/workflows/` (`ci-required.yml` = the required CI evidence; `smart-ci-shadow.yml` = the shadow planner + observation-mode gate, **landed** and now running `Smart CI / Plan`, `Smart CI / Planner Self-Test` and `Smart CI / Required Gate` on every PR), `ci/policy.v1.json` + `scripts/ci/smart-ci/` (planner `plan.mjs` and gate evaluator `evaluate-gate.mjs` from CI-02, plus the CLIs `measure-ci-estate.mjs`, `recall-report.mjs`, `action-pins.mjs`, `artifact-cleanup.mjs` and `resolve-merge-ref.mjs` (`#2401`, PR `#2404`); map `docs/ci/SMART_CI.md`, tracker CI-00 `#2324`), `scripts/check-*.mjs` | Delegated shell-backed inventory enters through the opt-in read-only argv wrapper; direct Git/GitHub mutation stays coordinator-owned; review and merge disposition come from live authority plus the canonical global pipeline; no Taskdeck-owned runtime hooks or local command-deny list; Smart CI is in **shadow mode** — the planner and gate change no job selection until the recall report (CI-02 `#2326`) and the gate is registered only by the maintainer (CI-03 `#2327`); CI-control paths (`.github/**`, `ci/**`, `scripts/ci/**`) are R4/T2 and qualify hosted-only, never on a self-hosted runner; the repository goes private for v0.3.0 by maintainer action only (CI-13 `#2337`) and no self-hosted runner is attached while it is public | `powershell -NoProfile -ExecutionPolicy Bypass -File scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1 -SelfTest`; failure-ledger synchronization unittest, settings/tier parsing, worktree helper suite when touched, then docs gates (see `scripts/agent_hooks/CLAUDE.md`); `node --test scripts/ci/smart-ci/*.test.mjs` when `ci/**` or `scripts/ci/smart-ci/**` change | | ||
| | Docs & planning | `docs/STATUS.md`, `docs/IMPLEMENTATION_MASTERPLAN.md`, `docs/ISSUE_EXECUTION_GUIDE.md`, `docs/TESTING_GUIDE.md` | STATUS is source of truth for shipped reality; keep governance line intact | `node scripts/check-docs-governance.mjs`, `node scripts/check-golden-principles.mjs`, `node scripts/check-doc-links.mjs` | | ||
| | Agent tooling / CI / docs | `.claude/`, `.codex/`, `.grok/` (README + permissions; Grok loads `.claude/skills/`), `scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1`, `scripts/agent_hooks/` (manual ledger projection only), `.github/workflows/` (`ci-required.yml` = the required CI evidence; `smart-ci-shadow.yml` = the shadow planner + observation-mode gate, **landed** and now running `Smart CI / Plan`, `Smart CI / Planner Self-Test` and `Smart CI / Required Gate` on every PR), `ci/policy.v1.json` + `scripts/ci/smart-ci/` (planner `plan.mjs` and gate evaluator `evaluate-gate.mjs` from CI-02, plus the CLIs `measure-ci-estate.mjs`, `recall-report.mjs`, `action-pins.mjs`, `artifact-cleanup.mjs` and `resolve-merge-ref.mjs` (`#2401`, PR `#2404`); map `docs/ci/SMART_CI.md`, tracker CI-00 `#2324`), `scripts/check-*.mjs` | Delegated shell-backed inventory enters through the opt-in read-only argv wrapper; direct Git/GitHub mutation stays coordinator-owned; review and merge disposition come from live authority plus the canonical global pipeline; no Taskdeck-owned runtime hooks or local command-deny list; Smart CI is in **shadow mode** - the planner and gate change no job selection until the recall report (CI-02 `#2326`) and the gate is registered only by the maintainer (CI-03 `#2327`); CI-control paths (`.github/**`, `ci/**`, `scripts/ci/**`) are R4/T2 and qualify hosted-only, never on a self-hosted runner; the repository goes private for v0.3.0 by maintainer action only (CI-13 `#2337`); CI-17 `#3170` must first prove a fail-closed Linux-only rehearsal across the workflow graph, and no self-hosted runner is associated until that post-privacy rehearsal passes | `powershell -NoProfile -ExecutionPolicy Bypass -File scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1 -SelfTest`; failure-ledger synchronization unittest, settings/tier parsing, worktree helper suite when touched, then docs gates (see `scripts/agent_hooks/CLAUDE.md`); `node --test scripts/ci/smart-ci/*.test.mjs` when `ci/**` or `scripts/ci/smart-ci/**` change | |
There was a problem hiding this comment.
Route every control path through the CI gate
The rewritten CI row still describes only .github/**, ci/**, and scripts/ci/** as R4/T2 control paths, but ci/policy.v1.json:53-87 and .claude/rules/ci-control.md:2-39 classify many additional paths, including dependency manifests and scripts/deploy/**/scripts/security/**. An agent relying on this required orientation map can therefore treat one of those edits as ordinary work and miss the hosted-only qualification and maintainer-review gate; point to the authoritative control-path inventory or represent the full scope rather than this three-path subset.
AGENTS.md reference: AGENTS.md:L15-L15
Useful? React with 👍 / 👎.
| - `START_HERE.md` -> `manual/02_home_and_today.md` -> `manual/03_projects_and_cards.md` -> `manual/08_recipes.md` | ||
| - Maintainer or planner: | ||
| - `strategy/PRODUCT_DIRECTION.md` -> `STATUS.md` -> `REVIVAL_PLAN.md` -> `IMPLEMENTATION_MASTERPLAN.md` -> `ISSUE_EXECUTION_GUIDE.md` -> `TESTING_GUIDE.md` | ||
| - `strategy/PRODUCT_DIRECTION.md` -> `STATUS.md` -> `analysis/2026-09-21-repository-direction-and-v0.3-programme.md` -> `REVIVAL_PLAN.md` -> `releases/V0_3_0_READINESS.md` -> `IMPLEMENTATION_MASTERPLAN.md` -> `ISSUE_EXECUTION_GUIDE.md` -> `TESTING_GUIDE.md` |
There was a problem hiding this comment.
Replace the obsolete phase order in the maintainer path
The new maintainer read path introduces the current convergence brief, but the immediately following directive still calls the old truth + safety → transcript engine → open-beta launch → checkpoint phases the active execution order. This commit adds a superseding seven-step v0.3 convergence sequence in docs/REVIVAL_PLAN.md:68-97, including an explicit prohibition on pulling v0.4 work forward, so a planner following this index can prioritize the hosted/open-beta phase ahead of unfinished v0.3 release-control dependencies; update this summary to the current sequence or mark the phase order historical.
Useful? React with 👍 / 👎.
Summary
Reconcile Taskdeck's current repository direction, v0.3 release readiness, programme sequencing, agent routing, tracker authority, and human-gate documentation against live GitHub as measured on 2026-09-21.
This pass treats the merged 2026-09-17 assessment as a historical snapshot and gives the repository one current operational release view. It incorporates the large September 18-21 correctness wave without changing shipped-status claims or pulling later-horizon product work into v0.3.
Live snapshot used
main:f001dd92149dd3dc807f48691772f2ac2cd3f1f5ci, 5dogfooding, 9 othermainstill requires the three security contexts onlyv0.3.0-rc.1; finalv0.3.0has not been createdThe formal release verdict remains no-go for the final tag until the retained scope, Smart CI, storage, runner, CI-17, cutover, exact-tag, mirror, and publication contracts are complete.
What changed
Current direction and programme
Add
docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.mdas the dated programme brief covering:Live release readiness
Rewrite
docs/releases/V0_3_0_READINESS.mdinto the current operational authority instead of retaining a long mixed-age September 3-11 narrative. The document now names:Strategy and execution authority
Align:
docs/strategy/PRODUCT_DIRECTION.md;docs/REVIVAL_PLAN.md;docs/IMPLEMENTATION_MASTERPLAN.md.The v0.3 ladder now explicitly names the approved public mirror, public GHCR continuity, CI-17 before runner association, private-Release-first publication, and the distinction between current release convergence and later Context Fabric horizons.
Repository routing and coordination
Update:
docs/INDEX.md;.codex/memories/00_ACTIVE.md;autodoc/AGENT_INDEX.md;docs/ISSUE_EXECUTION_GUIDE.md;OUTSTANDING_TASKS.md.These now route maintainers and agents to the current programme/readiness authorities, preserve dated assessments as history, add dependency-stack and exact-head rules, record the current human-action checkpoint, and prevent stale snapshots from competing with live GitHub.
Historical assessment boundary
Add an explicit historical-snapshot notice to
docs/analysis/2026-09-17-v0.3-release-assessment.mdrather than rewriting its measured facts.Current engineering direction captured
The pass consolidates five recurring correctness rules:
Current release-control sequence
push: mainpath.Boundary
Documentation and tracker files only.
This PR does not:
Verification
Exact final head:
08c9c87c7f6300740c0073fdb54468da7ac8d375.The final tree was verified before collapsing the branch back to one commit:
node scripts/check-docs-governance.mjs- passed;node scripts/check-doc-links.mjs- 719 Markdown files, 0 broken relative links;node --test scripts/check-docs-governance*.test.mjs scripts/check-doc-links*.test.mjs- 159 passed, 0 failed;git diff --check- passed;main: one commit, 11 documentation/tracker files, no temporary applicator or workflow files.Fresh exact-head hosted qualification and Codex review remain authoritative after the final live-state correction.
Supports #2235, #2324, #2335, #2337, #2439, and #3170.