Skip to content

docs: reconcile repository direction and v0.3 release programme - #3353

Open
Chris0Jeky wants to merge 7 commits into
mainfrom
docs/2026-09-21-direction-release-programme
Open

Chris0Jeky wants to merge 7 commits into
mainfrom
docs/2026-09-21-direction-release-programme

Conversation

@Chris0Jeky

@Chris0Jeky Chris0Jeky commented Sep 21, 2026

Copy link
Copy Markdown
Owner

Summary

Reconcile Taskdeck's current repository direction, v0.3 release readiness, programme sequencing, agent routing, tracker authority, and human-gate documentation against live GitHub as measured on 2026-09-21.

This pass treats the merged 2026-09-17 assessment as a historical snapshot and gives the repository one current operational release view. It incorporates the large September 18-21 correctness wave without changing shipped-status claims or pulling later-horizon product work into v0.3.

Live snapshot used

  • main: f001dd92149dd3dc807f48691772f2ac2cd3f1f5
  • v0.3 milestone: 104 closed / 30 open / 134 total (77.6%)
  • open split: 16 ci, 5 dogfooding, 9 other
  • 10 Priority I v0.3 issues
  • development repository remains public
  • main still requires the three security contexts only
  • latest v0.3 release remains v0.3.0-rc.1; final v0.3.0 has not been created

The formal release verdict remains no-go for the final tag until the retained scope, Smart CI, storage, runner, CI-17, cutover, exact-tag, mirror, and publication contracts are complete.

What changed

Current direction and programme

Add docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md as the dated programme brief covering:

  • the current release-convergence posture;
  • live milestone and repository state;
  • the engineering thesis emerging from the September correctness wave;
  • the current A-J critical path;
  • product-work admission rules during convergence;
  • open human decisions and actions;
  • the final definition of done and immediate next sequence.

Live release readiness

Rewrite docs/releases/V0_3_0_READINESS.md into the current operational authority instead of retaining a long mixed-age September 3-11 narrative. The document now names:

Strategy and execution authority

Align:

  • docs/strategy/PRODUCT_DIRECTION.md;
  • docs/REVIVAL_PLAN.md;
  • docs/IMPLEMENTATION_MASTERPLAN.md.

The v0.3 ladder now explicitly names the approved public mirror, public GHCR continuity, CI-17 before runner association, private-Release-first publication, and the distinction between current release convergence and later Context Fabric horizons.

Repository routing and coordination

Update:

  • docs/INDEX.md;
  • .codex/memories/00_ACTIVE.md;
  • autodoc/AGENT_INDEX.md;
  • docs/ISSUE_EXECUTION_GUIDE.md;
  • OUTSTANDING_TASKS.md.

These now route maintainers and agents to the current programme/readiness authorities, preserve dated assessments as history, add dependency-stack and exact-head rules, record the current human-action checkpoint, and prevent stale snapshots from competing with live GitHub.

Historical assessment boundary

Add an explicit historical-snapshot notice to docs/analysis/2026-09-17-v0.3-release-assessment.md rather than rewriting its measured facts.

Current engineering direction captured

The pass consolidates five recurring correctness rules:

  1. Bind every asynchronous completion to an explicit route, session, credential, request, and object owner.
  2. Separate durable commit from post-commit notification, cleanup, and reconciliation tails.
  3. Read one authoritative snapshot or versioned evidence set per decision.
  4. Distinguish empty state from pending, failed, unavailable, or stale state.
  5. Treat CI receipts and release evidence as product trust boundaries, bound to repository, workflow, run, commit, tree, policy, selected lanes, and unexpired artifacts.

Current release-control sequence

  1. Reconcile all retained v0.3 scope without bulk closure.
  2. Treat merged fix(ci): close Smart CI merge-base receipt residuals #3156 and feat(ci): add fail-closed landed-verifier decision core #3167 as foundations, not pending work.
  3. Qualify fix(ci): require enforced repository-bound landed receipts #3295 and then its stacked child fix(ci): make landed-verifier CLI failures explicitly deny bounded work #3296 in dependency order.
  4. Add authoritative landed-evidence collection and workflow integration before replacing the full push: main path.
  5. Qualify test(ci): inventory Windows-capable workflows and reusable callers #3297, then implement and prove the actual CI-17: Add a fail-closed Linux-only private-cutover rehearsal across all workflows #3170 trusted Linux-only rehearsal control.
  6. Classify the post-merge Bound API integration hangs and preserve timeout evidence #3162 timeout observations and close or explicitly retain the remaining Frontend Unit (windows-latest) times out on slow runners: dev-up.test.mjs PowerShell spawns hit ETIMEDOUT and the job hits its timeout #2378/[CI][dev-up] 'Node helper: TERM closes an active frontend connection' reds ubuntu Frontend Unit on a docs-only PR: frontend helper did not bind within 5 s #2588 Windows qualification residuals.
  7. Complete the remaining CI-11: Full-SHA action pinning, least privilege, and hosted-only qualification of CI-control changes #2335 hosted-proof, CodeQL, and human control-plane decisions after merged Disable checkout credential persistence and scope Pages permissions #2838.
  8. Reconcile storage, nightly, mirror/GHCR, and runner proof.
  9. Execute the private cutover in the canonical checklist order.
  10. Freeze one head, create and qualify the real tag, publish privately, mirror publicly, verify anonymously, then announce.

Boundary

Documentation and tracker files only.

This PR does not:

  • close or re-milestone issues;
  • change repository visibility, branch protection, Actions settings, package visibility, or budgets;
  • create credentials or repositories;
  • authorize storage deletion;
  • register or associate runners;
  • create a tag or Release;
  • infer completion of any maintainer-owned decision or action;
  • change runtime code, schemas, dependencies, workflows, or shipped-status claims.

Verification

Exact final head: 08c9c87c7f6300740c0073fdb54468da7ac8d375.

The final tree was verified before collapsing the branch back to one commit:

  • node scripts/check-docs-governance.mjs - passed;
  • node scripts/check-doc-links.mjs - 719 Markdown files, 0 broken relative links;
  • existing masking warnings remain in three unrelated historical/template files and are reported without suppressing link checking;
  • node --test scripts/check-docs-governance*.test.mjs scripts/check-doc-links*.test.mjs - 159 passed, 0 failed;
  • git diff --check - passed;
  • added-line em-dash scan - passed;
  • placeholder scan - passed;
  • final compare against main: one commit, 11 documentation/tracker files, no temporary applicator or workflow files.

Fresh exact-head hosted qualification and Codex review remain authoritative after the final live-state correction.

Supports #2235, #2324, #2335, #2337, #2439, and #3170.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-21T23:59:20.527967Z 9418066 Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact head 3bd8d0e94694e8872dbca710a95f4bfb3797ccad. This is a documentation/tracker-only reconciliation across 11 files. Focus on authority conflicts, stale live-state claims, release-sequence contradictions, issue/PR dependency accuracy, human-action boundaries, and whether any wording accidentally upgrades planned or in-flight work into shipped reality.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3bd8d0e946

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".


## Immediate next actions

1. Qualify and disposition `#3156`, `#3167`, `#3295`, and stacked child `#3296` in dependency order.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Remove merged PRs from the active dependency queue

PRs #3156 and #3167 are already merged into the reviewed main as commits 409291f7 and fd1381be, respectively, so directing agents to qualify and disposition them as active dependencies is stale. Their remaining work is the separately tracked collector/integration residual and the human post-hoc acknowledgement in OUTSTANDING_TASKS.md J.4; leaving the merged PRs in this immediate-action queue can cause agents to redo landed work or misreport the release stack.

AGENTS.md reference: AGENTS.md:L17-L18

Useful? React with 👍 / 👎.

Comment on lines +118 to +121
The order below is programme order, not permission to merge any PR. Exact-head CI, review, stack
ancestry, control-plane authority, and maintainer gates still apply.

### A. Reconcile retained release scope

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Make the release sequence agree across the programme docs

This declares the following A–J sections to be programme order and therefore puts milestone reconciliation first, but the same commit's docs/REVIVAL_PLAN.md:80-88 places Smart CI, CI-17, and other prerequisites before reconciliation, while this document's own immediate actions at lines 304-311 put reconciliation seventh. Because the active-agent routing now points at all of these as current sequencing sources, agents receive contradictory priorities; either align the ordering or describe A–J as unordered workstreams.

Useful? React with 👍 / 👎.

@@ -1,5 +1,44 @@
# Taskdeck Implementation Masterplan

## Current programme integration (2026-09-21)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P3 Badge Refresh the masterplan's Last Updated date

The new current-programme section is explicitly dated 2026-09-21, but the document's Last Updated field remains 2026-09-19 at line 42. Readers and automation using that field to assess freshness will treat this canonical sequencing document as older than the reconciliation it now contains; update the field and keep it with the document header.

Useful? React with 👍 / 👎.

@Chris0Jeky
Chris0Jeky force-pushed the docs/2026-09-21-direction-release-programme branch from 9bd14b9 to 08c9c87 Compare September 21, 2026 22:46

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact head 08c9c87c7f6300740c0073fdb54468da7ac8d375 after the final live-state correction. The current documents now record #3156, #3167, #3162, and #2838 as merged foundations, keep #3295 before stacked child #3296, and preserve the remaining collector/integration, timeout-classification, CodeQL, hosted-proof, CI-17, cutover, and publication work. Focus on authority conflicts, current-state accuracy, release-order contradictions, human-action boundaries, and accidental promotion of in-flight work into shipped reality.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 08c9c87c7f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +190 to +191
- PR `#2838` merged on 2026-09-19, delivering checkout `persist-credentials: false` coverage and
Pages permission scoping. Do not describe that implementation as parked or awaiting rebase.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update canonical records for merged #2838

This correctly declares #2838 merged, but the canonical shipped-reality source still says that its persist-credentials work is open and explicitly calls the PR “Not shipped reality” (docs/STATUS.md:1342,1346), while the executable cutover checklist still leaves that implementation unchecked and requires the PR to be qualified (docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md:118-121). With no later STATUS entry superseding those claims, agents and cutover operators encounter opposite states and may redo landed work or falsely block privacy; add the shipped record and replace the stale checklist gate with the actual remaining acceptance, ruling, and CodeQL work.

AGENTS.md reference: AGENTS.md:L17-L18

Useful? React with 👍 / 👎.

Comment thread docs/REVIVAL_PLAN.md
trusted, fail-closed Linux-only rehearsal owned by `#3170`.
4. **Close release prerequisites.** Reconcile post-merge Windows timeout evidence after `#3162`,
finish the remaining `#2335`/CodeQL acceptance after merged `#2838`, and complete storage
(`#2333`), nightly/exact-tag qualification (`#2334`), runner proof (`#2328`), and mirror/GHCR

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Defer exact-tag qualification until after cutover

The plan declares itself the wave-sequencing authority, but step 4 requires completing #2334's exact-tag qualification before step 6 executes the private cutover. The executable checklist limits pre-cutover #2334 work to contract and no-publish rehearsals (docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md:124-130) and schedules the real tag and exact-tag qualification only after privacy and the runner decision in section L. Following this sequence therefore either creates the tag too early or blocks cutover on an impossible precondition; restrict this step to pre-cutover rehearsal and leave exact-tag qualification in step 7.

Useful? React with 👍 / 👎.

Comment thread OUTSTANDING_TASKS.md
Comment on lines +207 to +210
This row consolidates the human actions that remain after the merged release-assessment pass and the
September 18-21 implementation wave. It does not replace the detailed evidence and order on `#2337`,
`#2439`, `#3170`, or the private-cutover checklist. Historical parked wording in J.3 is not current:
`#2838`, `#3156`, `#3162`, and `#3167` are recorded as merged in J.4.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Add the CodeQL ruling to the open human checkpoint

J.5 says it consolidates the remaining release-control human actions, but it omits the still-human CodeQL posture required by docs/releases/V0_3_0_READINESS.md:227-240 and the programme brief. Its only mention in this human-action file is buried in checked item SC-5 at line 168, which also says the decision is not a maintainer action; because handoffs surface open [ ] items, the required #2335 ruling can now disappear from release handoffs. Add an explicit unchecked CodeQL decision item here.

AGENTS.md reference: AGENTS.md:L17-L18

Useful? React with 👍 / 👎.

@Chris0Jeky
Chris0Jeky force-pushed the docs/2026-09-21-direction-release-programme branch from 829cf7c to 3ee5881 Compare September 21, 2026 22:56

Copy link
Copy Markdown
Owner Author

@codex address that feedback

Apply the already-prepared review repairs currently stored in .github/docs-reviewfix.part-00 through .github/docs-reviewfix.part-05 to their actual target files, then delete all six temporary docs-reviewfix.part-* files. Specifically:

  1. Add the merged Disable checkout credential persistence and scope Pages permissions #2838 shipped checkpoint to docs/STATUS.md and update its date.
  2. Reconcile section G of docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md so Disable checkout credential persistence and scope Pages permissions #2838/persist-credentials and Pages scoping are delivered, while hosted-proof reconciliation, the standing ADR-0066 control-plane rule, and CodeQL remain open.
  3. Add an explicit unchecked CI-11: Full-SHA action pinning, least privilege, and hosted-only qualification of CI-control changes #2335 CodeQL posture decision to OUTSTANDING_TASKS.md J.5.
  4. Change pre-cutover step 4 consistently in docs/REVIVAL_PLAN.md, docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md, docs/releases/V0_3_0_READINESS.md, and docs/IMPLEMENTATION_MASTERPLAN.md to require the nightly/release contract plus no-publish rehearsal only; real-tag creation and exact-tag qualification remain after privacy and the runner decision in step 7.
  5. Preserve the already-correct 2026-09-21 masterplan date and merged-foundation state.
  6. Do not create replacement patch chunks, helper files, workflows, or runtime changes.

After applying, run the documentation governance tests and link checker, update the PR body to the actual final head/file count, and request a fresh exact-head review.

@chatgpt-codex-connector

Copy link
Copy Markdown

Summary

  • Applied all six prepared review-fix chunks and deleted the temporary .github/docs-reviewfix.part-00 through part-05 files without creating replacement helpers, workflows, or runtime changes.
  • Added the merged #2838 least-privilege checkpoint to shipped status, including the 48 checkout credential changes and scoped Pages permissions, while preserving the remaining hosted-proof, control-plane-policy, and CodeQL work as open. docs/STATUS.mdL3-L15
  • Reconciled cutover checklist section G so the delivered #2838 work is checked and the hosted evidence, ADR-0066 standing rule, and CodeQL posture remain unchecked. The checklist continues to reserve real-tag and exact-tag work for post-cutover section L. docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.mdL113-L132
  • Added the explicit unchecked #2335 CodeQL decision to the human-action ledger. OUTSTANDING_TASKS.mdL212-L220
  • Aligned the release sequence so pre-cutover step 4 requires the nightly/release contract and no-publish rehearsal, while real-tag creation and exact-tag qualification remain in step 7 after privacy and the runner decision. docs/REVIVAL_PLAN.mdL80-L95 docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.mdL118-L129 docs/releases/V0_3_0_READINESS.mdL52-L63 docs/IMPLEMENTATION_MASTERPLAN.mdL21-L35
  • Preserved the masterplan’s merged-foundation state and corrected final Last Updated value of 2026-09-21. docs/IMPLEMENTATION_MASTERPLAN.mdL23-L31 docs/IMPLEMENTATION_MASTERPLAN.mdL44
  • Committed the repairs as 5a5a544dbce5d26f7dc39e3b9af70e7b77b94804 and created the follow-up PR metadata with the exact final head, the 13-file comparison count, verification results, and a fresh exact-head review request.
  • Human-action status remains open: OUTSTANDING_TASKS.md contains 50 unchecked items. The immediate J.5 checkpoint includes the ADR-0066 standing rule, CodeQL posture, dependency-stack review, runner decision, storage authorization, mirror provisioning, privacy transition, and final release approval. OUTSTANDING_TASKS.mdL212-L233

Testing

  • node scripts/check-docs-governance.mjs
  • node scripts/check-doc-links.mjs — 719 Markdown files checked, 0 broken relative links; 3 pre-existing masking warnings were reported.
  • node --test scripts/check-docs-governance*.test.mjs scripts/check-doc-links*.test.mjs — 159 passed, 0 failed.
  • git diff --check
  • git diff --unified=0 | rg '^\+.*—' — no added-line em dashes.
  • git diff --unified=0 | rg '^\+.*(TODO|TBD|PLACEHOLDER)' — no added placeholders.
  • find .github -maxdepth 1 -type f -name 'docs-reviewfix.part-*' -print — no temporary patch chunks remain.
  • git status --short --branch — clean working tree on work.
  • ⚠️ gh pr list --repo Chris0Jeky/Taskdeck --state open --search 'docs: reconcile repository direction and v0.3 release programme in:title' --json number,title,headRefName,headRefOid,baseRefName,url --limit 10 — direct GitHub CLI follow-up was unavailable because this environment has no authenticated GH_TOKEN; the required PR creation tool succeeded and its body contains the fresh exact-head review request.

View task →

Copy link
Copy Markdown
Owner Author

@codex address that feedback

Your previous task successfully applied and verified the repairs in its local work branch, but nothing was published: GitHub still shows head 94180660a624a983f9da8a49d4e4fd53c155d54e, 17 changed files, and all six .github/docs-reviewfix.part-* artifacts.

Publish the already-verified local tree using the authenticated GitHub App / PR creation or repository-write tool, not unauthenticated gh CLI. Preferred outcome: update the existing docs/2026-09-21-direction-release-programme branch and PR #3353. If that tool cannot update an existing branch, create a new replacement branch and PR containing the complete verified tree, with no patch chunks, and clearly mark #3353 superseded only after the replacement is visible and exact-head verified.

Do not merely report local completion again. The completion condition is a visible GitHub commit/PR whose changed-file list contains only the intended documentation/tracker files and whose actual head is named in the response.

@chatgpt-codex-connector

Copy link
Copy Markdown

Summary

Publication blocker

The requested GitHub publication could not be completed because the environment exposes only the metadata-recording make_pr tool, not an authenticated repository-write tool. The checkout has no authenticated GitHub credentials, and the mandated non-CLI push attempt failed before transferring anything.

The final GitHub REST verification confirms that PR #3353 is still visibly at 94180660a624a983f9da8a49d4e4fd53c155d54e with 17 changed files. Therefore, I am not claiming that the repaired commit is published or that the trigger’s completion condition has been met.

There are 50 open human-action items remaining in OUTSTANDING_TASKS.md, including the immediate control-plane rule, CodeQL, dependency-stack, runner, storage, mirror, cutover, and final-release decisions. OUTSTANDING_TASKS.mdL212-L233

Testing

  • node scripts/check-docs-governance.mjs
  • node scripts/check-doc-links.mjs — 719 Markdown files checked, 0 broken relative links; 3 pre-existing masking warnings reported.
  • node --test scripts/check-docs-governance*.test.mjs scripts/check-doc-links*.test.mjs — 159 passed, 0 failed.
  • git diff --check
  • git diff --unified=0 | rg '^\+.*—' — no added-line em dashes.
  • git diff --unified=0 | rg '^\+.*(TODO|TBD|PLACEHOLDER)' — no added placeholders.
  • find .github -maxdepth 1 -type f -name 'docs-reviewfix.part-*' -print — no temporary patch artifacts remain.
  • git diff --name-only f001dd92149dd3dc807f48691772f2ac2cd3f1f5...HEAD — exactly 13 intended documentation/tracker files.
  • git status --short --branch — clean local working tree on work.
  • ⚠️ git push origin HEAD:docs/2026-09-21-direction-release-programme — publication blocked because no authenticated GitHub credential or repository-write transport is available.
  • python3 GitHub REST exact-head verification — PR docs: reconcile repository direction and v0.3 release programme #3353 remains at 94180660a624a983f9da8a49d4e4fd53c155d54e with 17 changed files; local repaired head 46fdfe9800c57a7308d3657981c849bcea5727dd is not visible on GitHub.

View task →

Copy link
Copy Markdown
Owner Author

Maintainer handoff: final cleanup required before merge

The documentation/direction/release-programme work is submitted in this PR, but do not merge the current head as-is.

Current live state

  • PR head: 94180660a624a983f9da8a49d4e4fd53c155d54e
  • PR base recorded at open: f001dd92149dd3dc807f48691772f2ac2cd3f1f5
  • current main at this handoff: 68ffe976eb486143faf41f43b95d24f792dd0255
  • PR is open, non-draft and GitHub reports it mergeable, but it is behind live main and still has unresolved documentation-review findings
  • current head has 21 check runs with no failure, queued or in-progress result found; these checks become historical after any repair/rebase

Why one more branch update is required

Six temporary patch chunks were accidentally committed instead of being applied:

  • .github/docs-reviewfix.part-00
  • .github/docs-reviewfix.part-01
  • .github/docs-reviewfix.part-02
  • .github/docs-reviewfix.part-03
  • .github/docs-reviewfix.part-04
  • .github/docs-reviewfix.part-05

The PR body is also stale: it names head 08c9c87..., one commit and 11 files, while GitHub currently reports head 9418066..., seven commits and 17 changed files.

Required finalization

  1. Refresh this branch against the latest main and resolve only real documentation conflicts.
  2. Concatenate and apply the six prepared unified-diff chunks in numeric order:
cat .github/docs-reviewfix.part-00 \
    .github/docs-reviewfix.part-01 \
    .github/docs-reviewfix.part-02 \
    .github/docs-reviewfix.part-03 \
    .github/docs-reviewfix.part-04 \
    .github/docs-reviewfix.part-05 > /tmp/pr3353-review-fixes.patch

git apply --check /tmp/pr3353-review-fixes.patch
git apply /tmp/pr3353-review-fixes.patch
rm .github/docs-reviewfix.part-0{0,1,2,3,4,5}
  1. Confirm the applied result includes all of the following:
    • docs/STATUS.md: update the date to 2026-09-21 and add the merged #2838 least-privilege delivery checkpoint.
    • docs/ci/PRIVATE_REPO_CUTOVER_CHECKLIST.md: mark the delivered persist-credentials: false/Pages-scoping work complete; leave hosted-proof reconciliation, the standing ADR-0066 rule and CodeQL posture open.
    • OUTSTANDING_TASKS.md J.5: add an explicit unchecked #2335 CodeQL posture decision.
    • docs/REVIVAL_PLAN.md, docs/analysis/2026-09-21-repository-direction-and-v0.3-programme.md, docs/releases/V0_3_0_READINESS.md, and docs/IMPLEMENTATION_MASTERPLAN.md: step 4 is pre-cutover nightly/release-contract plus no-publish rehearsal only; real-tag creation and exact-tag qualification stay after privacy and the runner decision in step 7.
    • docs/IMPLEMENTATION_MASTERPLAN.md: change its Last Updated field from 2026-09-19 to 2026-09-21. This review item is not fully covered by the six temporary chunks and must be applied explicitly.
  2. Verify the resulting PR contains the intended documentation/tracker changes only. After deleting the six chunks and adding the two canonical files above, the expected changed-file set is 13 documentation/tracker files, subject only to legitimate conflict resolution against newer main documentation.
  3. Run and read the complete output of:
node scripts/check-docs-governance.mjs
node scripts/check-doc-links.mjs
node --test scripts/check-docs-governance*.test.mjs scripts/check-doc-links*.test.mjs
git diff --check

The prepared tree previously produced 159 passing documentation regression tests and zero broken relative links, but fresh post-refresh evidence is authoritative.
6. Update this PR body with the actual final head, base, commit count, changed-file count and fresh verification results. Remove the obsolete 08c9c87.../one-commit/11-file claims.
7. Reply to and resolve all six existing review threads only after their requested changes are present on the branch.
8. Request a fresh exact-head review with @codex review, wait for current-head hosted checks to finish, and merge only when the final head is clean.

Scope already delivered in this PR

The substantive documentation package is present: current repository/v0.3 programme brief, rewritten release readiness authority, aligned product direction/revival/masterplan, agent and issue routing, outstanding human-gate checkpoint, index updates, and an explicit historical boundary around the 2026-09-17 assessment.

No issue closure, milestone movement, visibility/branch-protection mutation, package visibility change, storage deletion, credential creation, runner association, release tag or publication is authorized by this PR.

A complete finalization bundle and one-command helper were also exported in the originating ChatGPT conversation as Taskdeck-PR3353-finalization-bundle.zip in case the prepared patch needs to be recovered.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 94180660a6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread autodoc/AGENT_INDEX.md
| Agent runtime & MCP | `Application` (`AutomationPolicyEngine`), **MCP surface in `Api`** (`Program.cs` `--mcp` branch, `Api/Mcp/*`), `.codex/config.toml`, `.mcp.json`, `.grok/config.toml` (permissions only — no MCP servers), `docs/MCP_TOOLING_GUIDE.md` | Policy evaluated before execute; egress/telemetry guards; tool registry; Docker MCP gateway is user-scope only | security tests, MCP inventory/egress tests |
| Agent tooling / CI / docs | `.claude/`, `.codex/`, `.grok/` (README + permissions; Grok loads `.claude/skills/`), `scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1`, `scripts/agent_hooks/` (manual ledger projection only), `.github/workflows/` (`ci-required.yml` = the required CI evidence; `smart-ci-shadow.yml` = the shadow planner + observation-mode gate, **landed** and now running `Smart CI / Plan`, `Smart CI / Planner Self-Test` and `Smart CI / Required Gate` on every PR), `ci/policy.v1.json` + `scripts/ci/smart-ci/` (planner `plan.mjs` and gate evaluator `evaluate-gate.mjs` from CI-02, plus the CLIs `measure-ci-estate.mjs`, `recall-report.mjs`, `action-pins.mjs`, `artifact-cleanup.mjs` and `resolve-merge-ref.mjs` (`#2401`, PR `#2404`); map `docs/ci/SMART_CI.md`, tracker CI-00 `#2324`), `scripts/check-*.mjs` | Delegated shell-backed inventory enters through the opt-in read-only argv wrapper; direct Git/GitHub mutation stays coordinator-owned; review and merge disposition come from live authority plus the canonical global pipeline; no Taskdeck-owned runtime hooks or local command-deny list; Smart CI is in **shadow mode** — the planner and gate change no job selection until the recall report (CI-02 `#2326`) and the gate is registered only by the maintainer (CI-03 `#2327`); CI-control paths (`.github/**`, `ci/**`, `scripts/ci/**`) are R4/T2 and qualify hosted-only, never on a self-hosted runner; the repository goes private for v0.3.0 by maintainer action only (CI-13 `#2337`) and no self-hosted runner is attached while it is public | `powershell -NoProfile -ExecutionPolicy Bypass -File scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1 -SelfTest`; failure-ledger synchronization unittest, settings/tier parsing, worktree helper suite when touched, then docs gates (see `scripts/agent_hooks/CLAUDE.md`); `node --test scripts/ci/smart-ci/*.test.mjs` when `ci/**` or `scripts/ci/smart-ci/**` change |
| Docs & planning | `docs/STATUS.md`, `docs/IMPLEMENTATION_MASTERPLAN.md`, `docs/ISSUE_EXECUTION_GUIDE.md`, `docs/TESTING_GUIDE.md` | STATUS is source of truth for shipped reality; keep governance line intact | `node scripts/check-docs-governance.mjs`, `node scripts/check-golden-principles.mjs`, `node scripts/check-doc-links.mjs` |
| Agent tooling / CI / docs | `.claude/`, `.codex/`, `.grok/` (README + permissions; Grok loads `.claude/skills/`), `scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1`, `scripts/agent_hooks/` (manual ledger projection only), `.github/workflows/` (`ci-required.yml` = the required CI evidence; `smart-ci-shadow.yml` = the shadow planner + observation-mode gate, **landed** and now running `Smart CI / Plan`, `Smart CI / Planner Self-Test` and `Smart CI / Required Gate` on every PR), `ci/policy.v1.json` + `scripts/ci/smart-ci/` (planner `plan.mjs` and gate evaluator `evaluate-gate.mjs` from CI-02, plus the CLIs `measure-ci-estate.mjs`, `recall-report.mjs`, `action-pins.mjs`, `artifact-cleanup.mjs` and `resolve-merge-ref.mjs` (`#2401`, PR `#2404`); map `docs/ci/SMART_CI.md`, tracker CI-00 `#2324`), `scripts/check-*.mjs` | Delegated shell-backed inventory enters through the opt-in read-only argv wrapper; direct Git/GitHub mutation stays coordinator-owned; review and merge disposition come from live authority plus the canonical global pipeline; no Taskdeck-owned runtime hooks or local command-deny list; Smart CI is in **shadow mode** - the planner and gate change no job selection until the recall report (CI-02 `#2326`) and the gate is registered only by the maintainer (CI-03 `#2327`); CI-control paths (`.github/**`, `ci/**`, `scripts/ci/**`) are R4/T2 and qualify hosted-only, never on a self-hosted runner; the repository goes private for v0.3.0 by maintainer action only (CI-13 `#2337`); CI-17 `#3170` must first prove a fail-closed Linux-only rehearsal across the workflow graph, and no self-hosted runner is associated until that post-privacy rehearsal passes | `powershell -NoProfile -ExecutionPolicy Bypass -File scripts/github/Invoke-TaskdeckReadOnlyInventory.ps1 -SelfTest`; failure-ledger synchronization unittest, settings/tier parsing, worktree helper suite when touched, then docs gates (see `scripts/agent_hooks/CLAUDE.md`); `node --test scripts/ci/smart-ci/*.test.mjs` when `ci/**` or `scripts/ci/smart-ci/**` change |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Route every control path through the CI gate

The rewritten CI row still describes only .github/**, ci/**, and scripts/ci/** as R4/T2 control paths, but ci/policy.v1.json:53-87 and .claude/rules/ci-control.md:2-39 classify many additional paths, including dependency manifests and scripts/deploy/**/scripts/security/**. An agent relying on this required orientation map can therefore treat one of those edits as ordinary work and miss the hosted-only qualification and maintainer-review gate; point to the authoritative control-path inventory or represent the full scope rather than this three-path subset.

AGENTS.md reference: AGENTS.md:L15-L15

Useful? React with 👍 / 👎.

Comment thread docs/INDEX.md
- `START_HERE.md` -> `manual/02_home_and_today.md` -> `manual/03_projects_and_cards.md` -> `manual/08_recipes.md`
- Maintainer or planner:
- `strategy/PRODUCT_DIRECTION.md` -> `STATUS.md` -> `REVIVAL_PLAN.md` -> `IMPLEMENTATION_MASTERPLAN.md` -> `ISSUE_EXECUTION_GUIDE.md` -> `TESTING_GUIDE.md`
- `strategy/PRODUCT_DIRECTION.md` -> `STATUS.md` -> `analysis/2026-09-21-repository-direction-and-v0.3-programme.md` -> `REVIVAL_PLAN.md` -> `releases/V0_3_0_READINESS.md` -> `IMPLEMENTATION_MASTERPLAN.md` -> `ISSUE_EXECUTION_GUIDE.md` -> `TESTING_GUIDE.md`

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Replace the obsolete phase order in the maintainer path

The new maintainer read path introduces the current convergence brief, but the immediately following directive still calls the old truth + safety → transcript engine → open-beta launch → checkpoint phases the active execution order. This commit adds a superseding seven-step v0.3 convergence sequence in docs/REVIVAL_PLAN.md:68-97, including an explicit prohibition on pulling v0.4 work forward, so a planner following this index can prioritize the hosted/open-beta phase ahead of unfinished v0.3 release-control dependencies; update this summary to the current sequence or mark the phase order historical.

Useful? React with 👍 / 👎.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Pending

Development

Successfully merging this pull request may close these issues.

1 participant