Repository navigation
Advance the pinned decision core to fe9a6f5b91886e4f07296dc6a264deb345b1618f - #1138
Conversation
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThis proposal-only repin advances the decision core from b21f010013fa51960c77377a8582943435b6db32 to the main-reachable commit 9293b55b557df85ffb808c825058279464cfe515 across the authoritative pin and workflow checkouts, then updates the byte-derived floor snapshot metadata and generated entries to cover openspec/specs/packet-citation-report/spec.md. Flow diagram for the floor snapshot updateflowchart LR
Commit["Pinned core 9293b55b557df85ffb808c825058279464cfe515"] --> Generate["Regenerate floor snapshot"]
Generate --> Snapshot["Update snapshot sha256 and entry_count"]
Snapshot --> Covered["Add openspec/specs/packet-citation-report/spec.md"]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="contracts/review-lane-floor-snapshot.yaml" line_range="160" />
<code_context>
# source_repository: opensoft/openxFactory
- # generated_at: fc837dffb9be0b8c28823c339e401f97e0e3e28a
- # entry_count: 63
+ # generated_at: 6b298a1ee132120a4956591cc2e26105682a7954
+ # entry_count: 64
# regenerate with:
</code_context>
<issue_to_address>
**nitpick:** The updated `generated_at` declares `6b298a1ee132120a4956591cc2e26105682a7954`, while the adjacent provenance comment still states that the generator ran against `b5eddaa3`. The snapshot therefore contains contradictory provenance, so readers and maintenance tooling cannot determine which source revision the generated block represents.
**Suggested fix:** Update the adjacent provenance comment to describe the revision declared by `generated_at`, or change `generated_at` if `b5eddaa3` is the actual source revision.
</issue_to_address>Sourcery assessment
Needs a human reviewer. This changes which pinned decision-core code controls merge approval, so a wrong commit could approve changes that should be blocked or block authorized merges from the moment it ships. Reverting restores the old decision core, but any unauthorized merges already accepted would remain and cannot be undone by the revert.
…e it exists to judge Copilot round 8 on #1145. Two findings, both FACT, both taken -- and the previously-missed one would have made this packet decorative. UNDER pull_request_target THE WORKFLOW RUNS FROM THE BASE, so a gate that parses the checked-out contracts/review-lane-pin.yaml reads the commit ALREADY IN PLACE. Measured against the live reproduction this packet cites throughout: for #1138 that is base b21f0100 compared to the aggregation's b21f0100 -- a PASS, while the advance proposes 491fc54d and is never seen. The gate would have been green on exactly the act it exists to judge. This is D14's cost paid in full rather than an oversight: choosing the safe trigger moved the workflow's own code to the base, and the pin came with it. The remedy keeps the safety and pays the cost explicitly -- the gate FETCHES the candidate pin as INERT BYTES at the verified head.sha (a file read over the API, not a checkout and not an execution), PARSES IT WITH BASE CODE, and RE-READS head.sha after the fetch so a force-push between the two is refused rather than reported. An end-to-end test drives a candidate whose pin differs from the base's and asserts the verdict names the CANDIDATE commit. The distinction that makes pull_request_target usable rather than merely safe is exactly this one: head CODE is never run, head DATA may be read as bytes. The estate's own rule states the first half -- "rules must come from the base branch" -- and this packet needed the second half stated to be correct at all. The requirement now carries it. r4076635713 -- D8's heading said "only one of the four fails" while the table has five rows and TWO of them fail, both counts stale since round 6 added the absent-or-foreign outcome. Now "two of the five fail", with the round it moved in named beside it. AND THE WHOLE PACKET WAS EYEBALLED AGAIN, not only swept: 119 number-words with context across .md, .yaml and .py, each read against the files. One further inconsistency surfaced that no finding had named -- the target_release archive-evidence clause still said "one real observation of the check RUNNING" while tasks 5.4 had moved to "running AND CONCLUDING". The gate clause is the one a release-realization check reads, so the weaker of the two wordings is the one that matters. Now identical. Recorded at design.md D14c; tasks 5.1i. Lane: openxfactory-4 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…es and the mint it needs Copilot's reviews at c82c8f7 and 4570063 found four, and this commit takes each. - r4077898334: the gate reads the candidate pin from the PR head, so its converged_with: entries are head-controlled. Had they chosen the paths read in the private aggregation, a candidate could turn the xFactory token on any file there, and D16's rule of naming a non-commit surface by its value would print that file into the verdict. The requirement now takes only core_commit and the declared state from the candidate, and the aggregation and every surface path from the base; a surface's value is the field extracted from its fixed location, never the file. - r4077837498: a declared permissions: block sets undeclared scopes to none (merge-master-approval.yml:448-449), so checks: write alone left the gate unable to fetch the candidate pin or re-read its head. The gate job now declares exactly contents: read, pull-requests: read and checks: write. - r4077837539: the advance side publishes no check run. It records its verdict in the pull-request body the lane already composes (review-lane-repin.yml:597, :840-861), and the gate carries the conclusion on the same head: the lane's App-token push starts pull_request_target runs, measured on #1138's head (merge-master-approval, event pull_request_target, openxfactory[bot]). - r4077898366: the advance lane's grant had no mint. It gains a third, owner opensoft, repositories xFactory, permission-contents read, beside its codexFactory read and its own write (review-lane-repin.yml:276-311). Re-proved at this tree: openspec validate of this change --strict valid, six scenarios; the three front-matter validators exit 0; proposal-origin and modified-block-currency name this packet in zero findings; scripts/validate-openspec-cli-pin.py --all --no-cache exit 0, the one failure the dispositioned add-chain-attestation finding. Lane: openxfactory-4 (openXfactory-4-openDox_extraction) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nd the refusal tested Copilot's review at 62a0945 found three, and one previously-missed item; this commit takes all four. - r4078098160: the triple named only main. It now carries this lane's literals, author openxfactory[bot] (the author of #1138), head ref bot/review-lane-repin (BOT_BRANCH, scripts/review_lane_repin.py:553) and base main, and says the envelope's own values and the caller test's ENROLLED_* literals are another lane's (intents/rolling). The bot/review-lane-repin literal that a rewording in c82c8f7 dropped from 5.1g is restored. - review 5285753827's previously-missed item: the requirement named no selector for the three values. Each is now read at a named selector, the ref: of each workflow's step that checks out the pin's own repository:, parsed as YAML, and the MIGRATION_PIN assignment in tests/test_merge_master_workflows.py. Measured on opensoft/xFactory main 6e52e98e, each file carries exactly one 40-hex literal today (:152, :308, :72), so the item's premise of historical literals does not hold yet; the gap it names does, and a decoy-literal fixture now guards it. - r4078098133: the third mint breaks tests that fix the lane at two (test_repin_lane.py:2384, :2393, :2409) and the workflow's "TWO TOKENS" comment (review-lane-repin.yml:244). 5.1c now moves each to three in the same realization. - r4078098168: nothing drove the two head.sha reads apart. 5.1i now adds that test and asserts that no verdict is published for it. Re-proved: openspec validate of this change --strict valid, six scenarios; the three front-matter validators exit 0; proposal-origin names this packet in zero findings. Lane: openxfactory-4 (openXfactory-4-openDox_extraction) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ggregation, not declared alone (#1145) Lane: openxfactory-4 (openXfactory-4-openDox_extraction) **The remedy the pin file recorded for itself.** Copilot raised a HIGH finding on #1136 — the lockstep flip at the fourth re-point ceremony, merge `7c49825e` — at [`r4067694104`](#1136 (comment)), review [`5273295522`](#1136 (review)). The lane **verified the premise** and **declined the remedy** as outside that pull request's mandate ([`r4067703286`](#1136 (comment))), and the flip's own appended `reason:` paragraph recorded the remedy's shape as option **(b)**: > *"make the CROSS-REPOSITORY fact assertable at all — nothing today reads xFactory's three surfaces and compares them to this value, which is why a false `status` survives in EITHER direction until a human notices … **(b) is the better fix, because (a) still leaves this file's truth depending on a lane remembering to write it.** Both are OpenSpec-class acts on a realized capability, which is exactly why neither rides here."* **This packet is that act.** `Status: draft` — not ratified by the authoring lane. --- ## The hazard, measured on `main` `2e222d98` | fact | measurement | | --- | --- | | the declaring field | `contracts/review-lane-pin.yaml`:714 `status: converged` | | the value it is about | `core_commit`:60 `b21f0100…` | | the aggregation's three surfaces | `opensoft/xFactory` `main`: `merge-master-approval.yml`:152, `council-convening-lane.yml`:308, `tests/test_merge_master_workflows.py`'s `MIGRATION_PIN`:72 — all three `b21f0100…` | | what the repin lane may write | `WRITABLE_PATHS` = four files; within the pin, only regex-anchored `core_commit`, `floor_snapshot.sha256`, `floor_snapshot.entry_count` | | can it write the field? | **`grep -c lockstep scripts/review_lane_repin.py` → `0`** | | does anything read the aggregation? | **`grep -nE "opensoft/xFactory\|MIGRATION_PIN\|council-convening" scripts/review_lane_repin.py .github/workflows/review-lane-repin.yml` → no output.** `MIGRATION_PIN` appears in no file under `scripts/` or `.github/workflows/`. | | the guarding test | `test_the_pin_records_its_lockstep_state_with_the_aggregation_pin` asserts the field against a **literal in the test file** — this repository's value against this repository's own constant | > **Beware the substring.** A bare `grep -c xFactory` on those two files answers **13** and **32**, and every hit is `openxFactory`. The measurement above is the one that means anything. So the declaration is **true today and nothing keeps it true.** ## It is not hypothetical, and it is live right now It last went false on **2026-09-18**, when the hourly lane's advance (#1122 → `38f826c2`, 20:53:37-04:00) moved `core_commit` and left `converged` standing. The hand repair (#1123 → `8184d74a`, 21:27:43-04:00) followed **34 minutes 6 seconds** later, both first-parent on `main`. Thirty-four minutes because a human was watching that evening. **Nothing bounds it.** **And #1138 is OPEN as this is written** — not a draft, platform auto-merge **armed**, proposing `core_commit` `b21f0100…` → `491fc54d…`: ``` $ git diff main...origin/bot/review-lane-repin --stat .github/workflows/merge-master-approval.yml | 4 ++-- .github/workflows/pytest-suite.yml | 2 +- contracts/review-lane-floor-snapshot.yaml | 9 ++++++--- contracts/review-lane-pin.yaml | 6 +++--- $ git diff main...origin/bot/review-lane-repin | grep -cE "^[-+].*(lockstep|converged|diverged)" 0 ``` `tests/review_lane_pin/test_review_lane_caller.py` is not in that diff at all. **The hour it merges, `lockstep.status` becomes false, the test still passes, and nothing reports it.** ## Why shape (b) and not shape (a) — decided by measurement **The lane cannot write the field honestly, because it has no reading of the aggregation to write from.** Zero hits, in both files. Under (a) it would have exactly one thing it could write — `diverged`, on every advance — by **inference** from *"`MIGRATION_PIN` does not move on a routine advance."* **That inference is already falsified by this estate's own history.** At the fourth ceremony (`opensoft/xFactory` #475 → `c88d1fdd`, 2026-09-21) the aggregation converged **onto** a commit this file had been pinned to since 2026-09-18 — three days apart, not a pairing at all, which the pin file records as the first time that happened. An advance landing where the aggregation already is leaves the pair **converged**. **So (a) does not remove the false declaration; it changes which direction it is false in.** **And the capability has already ruled on assertion-versus-measurement, one requirement over.** *An automated pin advance moves every pinned site in one commit or opens nothing* closes: *"what is added here is that an UNATTENDED author must prove the lockstep by measurement rather than assert it."* Shape (a) would install inside that same capability precisely what that sentence forbids. Shape (b) extends its principle to the one lockstep it does not yet reach. **The capability is also already built for (b).** Its realization's declared split — *"the workflow reads the two repositories with `gh` … and hands this module PURE INPUTS … Every requirement's refusal is then a unit test with a fixture, not a workflow that has to be fired to be believed"* — is exactly what the assertion needs: one more repository read where reads already happen, one more pure comparison where judgments already happen. **No new architecture.** **(a) is not forbidden by this requirement.** If a later act teaches the lane to read the aggregation, it may then write the field — and it would be writing a measurement, which makes (a) a special case of (b) rather than an alternative to it. ## The requirement ONE `## ADDED`, **eight scenarios** — an absent or foreign declaration, a stale `converged`, a stale `diverged`, surfaces disagreeing with each other, the check's own access failing, an unreadable aggregation, a candidate unread or its head moved, and the pure-function reproduction. The state is **measured**, not declared; the check runs **at least at every proposed advance and its pull request, whoever opened it** — in practice on every pull request that changes the pin, a fork's included — so the contradiction is reported on the same pull request that creates it rather than whenever a human next reads the field; it observes **this repository's side of the pair**, so a `MIGRATION_PIN` re-point in the aggregation is reported at the next pull request here that changes the pin (`tasks.md` § 6.7); the **read** lives in the workflow and the **comparison** is a pure function; it is **symmetric** (a false `converged` and a false `diverged` alike); and the declaration is **not removed** — it becomes the subject of the measurement rather than its only evidence. **The aggregation's surfaces are read AS A SET** (`r4075976905`) **at ONE resolved commit of it** — never independently from a moving branch, because a re-point landing between two API calls returns a mixed set the check would report as INCONSISTENT, *a state that never existed in the repository it was reading*. They must agree with each other before either state is concluded; disagreement is its own outcome, INCONSISTENT, with each surface named by a digest and the commit they were read at named with the verdict. **The outcomes are ORDERED and exactly one holds for any input a run judges** (`r4076152698`, `r4076557241`, `r4084891099`, `r4085195340`) — **the candidate unread FIRST** (a read of this repository failing, for any reason but the pin's absence), then **the declaration outside its vocabulary** (a foreign state, a non-commit `core_commit`, an unparseable candidate, the pin absent, or a `converged_with:` other than the read plan's workflow members), before the aggregation is read at all, then the check's own **access failing**, then unreadable (a surface whose value is not a commit counts as unreadable, `r4076989950`), then disagreeing, then the comparison — because giving each outcome a conclusion is exactly the moment overlapping cases become a contradiction, and two of mine did. **One partition classifies every failure to read, of either repository**: a transient failure is UNDETERMINED, a 404 for a branch, a commit or a file is an absence, and every other failure is the check's own access failing, a 404 from the head's lookup (a read of the pull request) among them. **A run that finds its head moved publishes no verdict**. It is the one run that publishes none, because the push that moved the head starts a run of its own. **Each outcome carries a CONCLUSION and three fail:** | outcome | conclusion | why | | --- | --- | --- | | declaration **absent or outside its vocabulary** — a foreign state, a non-commit `core_commit`, an unparseable candidate, the pin absent at the verified head, a `converged_with:` other than the read plan's workflow members | **FAIL**, naming the value found or the pin's absence | this repository's own file, checked once the candidate is in hand and before the aggregation is read — a defect that makes every later question moot | | the check's own **access fails** — binding unresolved, mint refused, either repository refusing its request, or any failure to read that is neither transient nor an absence | **FAIL**, naming the failure | this repository's own configuration or code; an UNDETERMINED here would stand on every run | | declared state **CONTRADICTED** | **FAIL**, naming `core_commit` and the agreed commit's digest | this repository's own file states something false; the remedy is one edit | | surfaces **disagree** (INCONSISTENT) | **NEUTRAL**, visible | another repository's defect | | aggregation **unreadable**, or a read of the candidate failing transiently (UNDETERMINED) | **NEUTRAL**, visible | another repository's availability, or the host's | | declared state agrees | pass | | That does not contradict the decision not to block a lawful divergence: **what fails is not the divergence but the false declaration about it.** And **UNDETERMINED is forbidden as a STANDING state**: the check's own access failing is its own FAIL, so it cannot stand as a permanent NEUTRAL. **No aggregation value is published as it is**: this repository and its checks are public and the aggregation is private, so a surface is published only by its classification, its relation to `core_commit` and a digest (`design.md` D20). `## ADDED` and no `## MODIFIED` is a decision (`design.md` D3): three active changes carry deltas on this capability and none names this requirement or is named by it, and the hazard lives in the **gap** between the advance this capability automates and a field no requirement obliges anyone to measure — not in any promoted requirement's text. ## Boundaries this packet holds - **The disposition mechanism is untouched** — `validate-openspec-cli-pin.py`, `reconcile()` and `contracts/openspec-cli-pin.yaml` are not this packet's subject in any respect. - **The pin file is not hand-patched.** `lockstep.status`, `converged_with:` and the append-only `reason:` narrative do not move. A packet that edited the value it proposes to start checking would assert the very fact it exists to stop asserting. - **`WRITABLE_PATHS` and `PINNED_SITES` gain no member.** - **No act in `opensoft/xFactory` is proposed.** The aggregation is READ. `MIGRATION_PIN` advances only at a recorded ceremony and this packet neither performs nor requires one. - **The `obligation:` "only at a ceremony" clause is NOT narrowed here** — still the ratifier's act, registered at `tasks.md` § 6.1. This packet makes the state measurable, which is what lets that clause be narrowed on evidence rather than on argument. - **#1138 is not this packet's to land, hold or amend.** It is cited as the live reproduction. ## Gate - `OPENSPEC_TELEMETRY=0 openspec validate assert-review-lane-lockstep-against-aggregation --strict` → **valid** — a narrowed claim, about this change alone. - `validate-code-surface.py` / `validate-target-release.py` / `validate-sequenced-after.py` → **exit 0** each. - **Corpus-wide, through the adjudicated entrypoint the gate itself runs** — `python3 scripts/validate-openspec-cli-pin.py --all --no-cache` (`.github/workflows/openspec-cli-pin-gate.yml`:101) → **exit 0**: `@fission-ai/openspec@1.12.0` verified against its content address, `111 passed, 1 failed (112 items)`, **0 undispositioned**. The one failure is `add-chain-attestation` / `signed-execution-chain/spec.md`, INHERITED from `main` and not this packet's, applied as the disposition `contracts/openspec-cli-pin.yaml` carries for it (Brett Heap, 2026-09-05, *"take exit 2"*). The raw `openspec validate --all --strict` reports that same finding as a blocking error because it cannot read the disposition — which is why, under the now-ratified `require-adjudicated-validation-entrypoint` (landed on `main` as `2e222d98`), a corpus-wide claim names the entrypoint and not the raw tool. - `code_surface: openxFactory` is **not empty**, so under `release-realization` this archives on merged **plus** green realization evidence — the check landed, **all eight** of its scenarios exercised by fixtures plus the positive cases, the negative control (`review-lane-repin.yml` carries no `pull_request` trigger) and the gate's own trigger test, and one real observation of it **concluding** — `converged`, `diverged` or a named contradiction, and not UNDETERMINED, because an observation of UNDETERMINED proves the access is missing rather than that the check works. Stated here rather than discovered at the archive gate. ## Sequencing with the lane's other open packet This and #1143 both added a row to the README "OpenSpec Records" block and to `tests/sequenced_after/corpus-ledger.yaml`. **#1143 has landed, as `a151e462`, and this branch still merges cleanly with `main`**: `git merge-tree --write-tree origin/main HEAD` exits 0. The collision was measured and removed before that landing. With both rows at the head of the list, #1145 conflicted in `README.md` once #1143 had landed, so #1145's row was moved after the lane's other 2026-09-22 row; both orders then merged cleanly to the SAME tree, the ledger auto-merging throughout. On that fully merged tree, all of these passed: the three front-matter validators, both packets' strict validation, #1143's carriage proof, and the adjudicated entrypoint (`112 passed, 1 failed (113 items)`, the one failure the dispositioned `add-chain-attestation`). `main`'s required-check rules are not strict (`strict_required_status_checks_policy: false`), so this branch needs no merge from `main`. ## Review record — 35 Copilot reviews at 31 heads; 87 findings (73 as threads, 14 only in *Previously missed* blocks), plus eight summary-line themes; 0 unresolved threads **82 taken as fixes, 4 answered by measurement, 1 measured and registered. Of the eight summary-line themes, six were taken, one was answered by measurement and one is registered.** The last review, `5294384086` at `d05ce453`, reports **Findings: None**. - **Answered:** `r4076254100`, raised against a README count that a `gh pr edit --body` had already corrected. The edit and the review carry the SAME timestamp, `20:39:17Z`. - **Answered:** `r4078998769`, which held that a base-repository check run cannot attach to a fork's head commit. Measured, it can: every pull request's head is published in the base repository as `refs/pull/<n>/head`. On the public fork pull request `cli/cli#14474`, the base repository resolves the fork's head commit and carries 20 check runs on it. - **Answered:** `r4085195422`, which held that a 404 from the head's lookup had no outcome. The partition already made it the check's own access (*"a 404 for the repository or the pull request itself"*); what it did not say was that the head is looked up by reading the pull request, and `d05ce453` says so and lists the fixture. - **Answered:** `r4085195461`, a stale count of seven scenarios in this description. The review's run began at `17:08:42Z`, and the description had been corrected to eight by `17:10:30Z`. - **Registered:** `r4078145216`, the approver race. It needs an approver that admits a pin-changing pull request, and none does today, so `tasks.md` § 6.5 registers the obligation for the two active changes that would admit one. Every thread carries a reply and is resolved. Every review's **`Previously missed`** block was read rather than trusting a zero-unresolved count: fourteen findings came only from there, and two more appeared there before they appeared as threads. **The three that changed the packet most, each a defect in my own text:** 1. **`r4076152594` — the check had no way to read the repository it measures.** Measured: `opensoft/xFactory` is **PRIVATE** (`gh api repos/opensoft/xFactory --jq .visibility` → `private`; an unauthenticated raw read of a surface → **404**), and `contracts/review-lane-repin-binding.template.yaml` grants `contents:read` on `codeXfactory/codexFactory` and nothing on the aggregation. **On today's credentials the check could never conclude**: it would have answered UNDETERMINED on every run then, and would end every run in its ACCESS FAIL now — and a check that never concludes looks exactly like one that works. Three consequences are now written down: a declared read-only binding in the same shape as the existing grant (with the same `never_grants:` set, so the family's rule that neither lane reaches into the other's repository holds); the standing-UNDETERMINED prohibition above; and § 5.4's evidence becoming *one observation of the check **concluding***, not merely running. 2. **`r4076152698` — two outcomes overlapped**, so one set of inputs demanded both FAIL and NEUTRAL. A requirement no implementation could satisfy, introduced by my own previous-round fix. Answered by ordering the outcomes rather than by patching one `WHEN`. 3. **`r4076152473` / `r4076152544` — the contract had no workflow representation.** A step exits 0 or non-zero — a green pass or a red failure and nothing else — so *"NEUTRAL, visible, not a pass"* needs the check-run API and a test that asserts the **published conclusion** rather than the exit code, or it degrades silently to green. And a read failure has to be an **input**, never a fatal step, or the UNDETERMINED path is unreachable by the only route that reaches it. **Rounds 4 and 5 found four more, every one a consequence of an earlier fix of mine rather than of the original text** — which is the honest way to describe them: - **`r4076254027`** — the binding covered one run of two. The PR-side gate is a separate workflow run: it cannot reuse a minted App token any more than it can reuse step outputs, and `GITHUB_TOKEN` cannot read a private repository. It mints its own from the same App, under a binding of its own (next item). - **`r4076368784`** — and the binding is *structurally* single-consumer (`consumer.holder_ref` `:100`, `resolution.resolved_by` `:167`, *"never passed to a second workflow"* `:190`), so "names both consumers" needed a representation. It was first answered with a **second consumer entry**, and `r4076990082` found that wrong one level down: the template's `privileges:` and `resolution.scoped_to` are binding-wide and its `floored_repository` grants write, so a seated consumer would mint with the advance lane's write authority. The gate now gets **a binding of its own** — `contents:read` on `xFactory` only, one down-scoped mint — and the never-passed statement is **carried unchanged on both, because nothing is passed.** - **`r4076368722` then `r4076474882` — and the second REVERSED my answer to the first, on a test this repository already runs.** A fork pull request receives no secrets, so the gate would answer UNDETERMINED on every fork event; my fix was a plain `pull_request` gate scoped by `head.repo.full_name`. `test_the_head_executing_trigger_is_absent` refuses exactly that on the secret-bearing caller — *"a plain `pull_request` trigger would run the head's copy of this file with the App credential that reads a private repository in scope — the exfiltration shape the base-branch rule prevents"* — and a same-repository condition cannot fix it, because under `pull_request` **the head's copy of the workflow runs and can delete the condition**. The gate now takes the estate's worked shape: **`pull_request_target`** (the base's copy runs), **no checkout of the PR head** (costing nothing — this check reads two repositories over the API and needs no candidate code). It first carried an allowlist as well, as defence in depth, and the review at `eb01c3d1` showed that this capability forbids exactly that (below). - **the neutral publication had no write path** — no workflow here grants `checks: write` (`merge-master-approval.yml`:453 grants `checks: read`), so the publish would 403 and the contract would degrade to the silent green pass by a second route. The gate's own job declares exactly `contents: read`, `pull-requests: read` and `checks: write` — `r4077837498` found that `checks: write` alone would have left it unable to read the candidate pin — and **the aggregation token stays read-only.** **The three reviews at `918e30e3` found nine, all taken in `c82c8f76`, and a search-based sweep found the same defects standing in places no thread named:** - **the gate was still called `pull_request`-triggered** after D14 reversed it (`r4076845460`, `r4076990021`, and D7) — now `pull_request_target` throughout, with the reason the two existing pin gates may run on `pull_request`: neither holds a secret; - **the trigger test binds `merge-master-approval.yml` only** (`r4076845535`) — § 5.1b now asserts the gate's own triggers; - **D9 still held the superseded order** (`r4076845591`); - **a published check run does not change the job's own, and a `pull_request_target` job check lands on the PR head** — measured on this very pull request (`r4076902144`, `r4077054569`) — so the verdict run's name matches no job id, and it hangs on the verified candidate `head.sha`, never `github.sha`; - **agreeing surfaces could carry a non-commit into the comparison** (`r4076989950`) — a surface is now read only as a 40-hex commit, or it is UNREADABLE; - **the second consumer inherited the advance lane's write grant** (`r4076990082`) — the gate gets a binding of its own; - **two outcomes fail, not one** (`r4077054636`, and D8, which undercounted one paragraph below its own table). **The reviews at `c82c8f76` and `4570063f` found four more, all taken in `16fdd730`:** - **the candidate could have chosen what the gate reads** (`r4077898334`). Its `converged_with:` is head-controlled, and my own D16 rule of naming a non-commit surface by its value would then have printed any private xFactory file into the verdict. The requirement now takes only `core_commit` and the declared state from the candidate, and every aggregation path from the base; head data is judged, never followed. - **`checks: write` alone would have starved the gate** (`r4077837498`): a declared `permissions:` block sets undeclared scopes to `none`, so the job declares `contents: read`, `pull-requests: read` and `checks: write`. - **the advance side had no publication path** (`r4077837539`). It now records its verdict in the pull-request body the lane already composes, and the gate carries the conclusion on the same head. A lane push starts the gate, measured on `#1138`. - **the advance lane's grant had no mint** (`r4077898366`): it gains a third, `xFactory` `contents: read`. **And the review at `16fdd730` found one, taken in `cb97b7ae`:** the requirement resolved "the aggregation's branch" without saying WHICH (`r4078009970`). It now resolves the aggregation's DEFAULT BRANCH at run time, never a caller-supplied ref. That is the capability's own rule for the source repository, which `review-lane-repin.yml`:433-459 already realizes. **The reviews at `cb97b7ae`, `62a0945c` and `eb01c3d1` found eight more**, six as threads and two only in *Previously missed* blocks: - **every outcome needed a published conclusion, not only NEUTRAL** (`r4078058050`, taken in `62a0945c`). `failure`, `neutral` and `success` are now each mapped, and the test asserts each one. - **the aggregation's constant needed a selector** (review `5285753827`'s *previously missed* item, taken in `eb01c3d1`). Each value is now read at its selector, and a decoy-literal fixture proves it. - **the third mint needed the tests that fix the binding at two mints to move with it** (`r4078098133`, taken in `eb01c3d1`). - **the triple named its base but not its author or head ref** (`r4078098160`, taken in `eb01c3d1`, since superseded). - **the head re-read needed a test that drives it** (`r4078098168`, taken in `eb01c3d1`). - **the allowlist itself was the defect** (`r4078145229`, and review `5285808064`'s *previously missed* item, taken in `16dc4416`). This capability's promoted *An automated pin advance is judged by the freshness checks that already exist, with no exemption* forbids any check that judges a pin advance to branch on the pull request's author, branch or origin. The gate now judges every pull request that changes the pin, a fork's included. Its safety rests on base code, inert candidate data and a read plan now fixed in its code (`design.md` D17, D19). That is the second defence of mine on this packet that turned out to be the defect. - **the approver race** (`r4078145216`) is measured absent today and registered at `tasks.md` § 6.5. **The reviews at `16dc4416` through `d36cb68f` found thirty-one more**, over ten rounds. Each was taken in the round it was raised, and every reply names its fixing commit. By theme: - **the trigger and the token:** the `paths:` filter is exactly the pin (`r4078252960`). A skip for edits that move no judged value was added (`r4078308120`) and later withdrawn as a bypass of the ordered outcomes (`r4078883755`). The declaration is validated first (`r4078425707`). - **what is read:** the read plan is fixed in the gate's code, never taken from the pin file (`r4078365046`). It has two workflow members and one additional `MIGRATION_PIN` read (`r4078528181`, `r4078528208`, `r4078528244`). - **what is published:** no aggregation value is published as it is. A classification, a relation to `core_commit` and a digest are published instead (`r4078468841`, `r4078835190`). - **untrusted input:** the candidate is parsed strictly under a byte ceiling (`r4078835237`), and nothing derived from it reaches a script except through `env:` (`r4078835258`). A non-commit `core_commit` and an unparseable candidate each FAIL first (`r4078528147`, `r4078425733`). - **outcomes:** the check's own access failure is its own FAIL (review `5286349291`). Every outcome is data to one always-run publisher (`r4078594297`). The comparison scenarios' WHENs are disjoint on their own text (reviews `5286144492`, `5286193943`). - **the runs:** - overlapping runs are serialized, with the guarantee bounded to what holds without atomicity (`r4078468867`, `r4078883704`); - the lane's body record is historical (`r4078594266`); - the gate's identity is named once (review `5285930613`); - an approver approves only on `success` (`r4078528254`). - **scope and records:** - the check says it observes this repository's side of the pair (`r4078648320`); - the live literal test is retired (`r4078883732`); - the pure function takes structured read results (review `5286688301`); - three inventories I left behind were each found by review: D17's two-value comparison, `target_release`'s six scenarios, and this description's counts (`r4078425764`, `r4078648354`, review `5286688301`). - **the last round** (`d36cb68f`): - the App installation grant on `opensoft` is named as the realization's first prerequisite, since a binding and a mint declare the read without provisioning it (`r4078926291`); - the requirement now states the host's 3,000-file path-filter exception itself rather than only registering it (`r4078926263`); - seven statements that still said a missing grant would leave the check UNDETERMINED now say it fails on its own access. - **the reviews at `1c037be6`:** - one thread was answered by measurement (`r4078998769`, above); - review `5286923179` reported **Findings: None**, but its summary named three themes, and each held on measurement. All three were taken in `d6787530`: - the conclusion paragraph now names all six outcomes' conclusions, the one PASS included; - D5's rationale is brought onto the fixed plan; - the reproduction scenario is given the pure function's whole input. - **the review at `d6787530`** found one, `r4084891099`, and its summary named three themes. The finding and all three themes were taken in `b0f02bd9` (`design.md` D21): - the candidate's own reads had no outcome, so *"exactly one holds for any input"* was false. The order now begins at the candidate unread; - one partition now classifies every failure to read, of either repository, with the check's own access as the residual class; - a verified head is now defined, a moved head publishes no verdict, and *"is a commit"* means the grammar; - an eighth scenario was added and the five inventories moved with it. D8's stale count of two failing outcomes is corrected. - **the review at `b0f02bd9`** found three. One was taken in `d05ce453`: the one-outcome claim is scoped to the inputs a run judges, since a moved head judges nothing (`r4085195340`). The other two were answered, above (`r4085195422`, `r4085195461`). - **the review at `d05ce453`** (`5294384086`) reported **Findings: None**. Its summary named two themes. Both classes had already had their two head-moving rounds, so each was answered by measurement in one comment, and the head stays: - **access classification** — no defect found. The partition is total and disjoint, and every statement of the class agrees with it; - **branch-resolution inputs** — the reproduction scenario's input list names the resolved commit but not the branch that the verdict also names. `tasks.md` § 5.2 already takes both. **Registered for the next act on `spec.md`.** Lane: openxfactory-4 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…, RULED 5815412869 C1) (#1152) Lane: openxfactory-4 (openXfactory-4-openDox_extraction) ## What this is This is D-13 of the owed-acts register. RULED at #656 comment [5815412869](#656 (comment)) (item 3, **C1, option (a)**: *"correct the stale '124 of 143' current-corpus count (D-13) to the figure re-derived at authoring time"*) and claimed at [5815604830](#656 (comment)). The present-tense claim *"124 of this corpus's 143 [archived rows carry a later `moved_on`]"* goes stale by construction every time another change archives. So the figure is derived when the commit is made. ## The figure: 129 of 183, at `main` `dd2466ad` It was derived two independent ways, and the build refuses (exit 3) if they disagree: | method | archived | later `moved_on` | equal | predating | | --- | ---: | ---: | ---: | ---: | | the repository's own `scripts/sequenced_after.py` (`archive_dates()` + the ledger) | 183 | **129** | 54 | 0 | | a from-scratch regex parse of `corpus-ledger.yaml` and `openspec/changes/archive/` (no shared code) | 183 | **129** | 54 | 0 | `openspec/changes/archive/` holds 183 directories. The register's own figure (128/172), the helper's (129/180 at `2e222d98`) and a first read today (129/182 at `94b6f7f1`) have all rotted since. `#1149`'s archive landed in between. ## The six live sites All six are undated, present-tense "current corpus" claims. The change is prose only: no site is on an `assert` line, and no test compares the renumbered text. | file | line | where | | --- | ---: | --- | | `scripts/validate-sequenced-after.py` | 42 | module docstring | | `scripts/validate-sequenced-after.py` | 402 | the `validate_corpus` comment | | `scripts/validate-sequenced-after.py` | 739 | `--strict-archive-dates` help text | | `tests/sequenced_after/test_sweep.py` | 2015, 2017 | `test_an_UNMOVED_archived_row_is_NOT_RESTAMPED_by_the_new_rule` docstring | | `tests/sequenced_after/test_sweep.py` | 2049 | `test_a_LATER_moved_on_is_NOT_a_finding_by_default` docstring | | `tests/sequenced_after/test_sweep.py` | 2108 | `test_STRICT_ARCHIVE_DATES_asks_for_the_STRONGER_reading` docstring | **Left alone, because they are dated:** - the validator's two *"before it was made a gate"* `143`s (lines 36 and 396); - the whole MOVEMENT LOG docstring of `test_the_LIVE_corpus_and_the_LEDGER_agree_row_by_row()` (lines 232–1254, every entry pinned to a historical sha). It is located by function name, not by line range; - `scripts/sequenced_after.py`'s own *"as measured 2026-09-18"* commentary. The build refuses (exit 4) if any site is missing or duplicated, if one sits on an assert line, or if an unexpected undated `124`/`143` appears in either file. ## If main gains an archive before this lands `main` has since moved to `cd494e4c` (#1151, which touched no archive directory and not the ledger). Re-derived there, both methods still agree on **129 of 183**. If an archive lands, the total moves by one. The build is re-runnable: [`d13-build.sh`](https://github.com/opensoft/brett-wip/tree/main/handoffs/xFactory/attachments/lane-opendox/c134) re-derives the figure at any `main`. ## Touches `scripts/validate-sequenced-after.py`, `tests/sequenced_after/test_sweep.py` (+7 / −7). Nothing under `openspec/changes/`, and not the README OpenSpec Records block, **so no Rule 6 landing window**. Sibling search at build time: none of the open PRs (#518, #594, #1138) touches either file. ## Measured (local, same-kind full clones at `…/openxFactory`, pinned CI lock, pinned OpenSpec CLI 1.12.0, pinned decision core `b21f0100`) | gate | `main` `dd2466ad` | this branch | | --- | --- | --- | | `scripts/validate-sequenced-after.py .` | passes | passes | | `pytest tests/sequenced_after -q` | 286 passed | 286 passed | | the PR gates' scripts (`verify-openxwallet-pin`, `validate-clearing-dispatch`, `verify-openxdox-pin`, `verify-opendox-pin`, `validate-release-tag-gate`, `validate-signed-execution-chain --require-pinned-wallet-vocabulary`, `wallet-yaml-syntax-gate`, `validate-openxwallet`, `validate-factory-identity`, `validate-openspec-cli-pin --all --no-cache`, `validate-openreposhape-pin`, `validate-carve-manifest`) | all rc=0 | all rc=0 | | `validate-former-id-arrival.py --base dd2466a --head HEAD` | — | passed | | `openxdox-consumer-gate` pin suites | 105 / 105 / 0, HOLDS | 105 / 105 / 0, HOLDS | | `openxdox-consumer-gate` `tests/ideation-dashboard` | 1137 / 1137 / 0, HOLDS | 1137 / 1137 / 0, HOLDS | | `pytest-suite` in CI (`tests/ -m "not postgres"`, the required check) | 8857 / 8851 / 6, freshness and vector replay passed (`main`'s test tree, from #1151's run; #1151 touched no test) | 8857 / 8851 / 6, freshness and vector replay passed ([job 107683353404](https://github.com/opensoft/openxFactory/actions/runs/36014484303/job/107683353404)) | | `pytest-suite` locally, per test case | 8435 passed, 8 skipped, 3 failed | 8435 passed, 10 skipped, 1 failed | Both local full runs collected the same 8446 test cases, with none unique to either side. The six cases whose outcome differs are environment-bound, and these seven prose lines do not reach them: - five are in `tests/doc-health/test_pin_reachability.py`, which skips or fails when a local clone cannot consult the retention ref namespace; - one is `tests/snapshot_equivalence/test_snapshot_equivalence.py::test_a_prefix_whose_path_cannot_be_resolved_is_replaced_not_raised_on`, which passed on the branch run. Both runs share one failure: `tests/hermes_runtime_contracts/test_validator_cli.py::test_release_mode_field_is_preserved_on_the_real_repository[--require-realization-realization]`. It is a subprocess timeout that occurred while five full suites ran at once. CI is free of all of that, and it gives the same triple on both sides. Lane: openxfactory-4 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…ef4ff33 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…5dac254 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…afb99d1 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…e99d33c All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
|
CLAIMED — lane openXfactory-5, session bbe4d255-02db-4578-840b-09924442e544@Eagle, 2026-10-06T19:19:08Z, for #1138 Logged in The three reads (lane-collision-protocol Rule 1): |
…e13f510 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…193ae14 All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
…5b1618f All five sites move in this one commit. Opened by the review-lane-repin lane, which arms the platform auto-merge and neither merges by its own act nor approves. No candidate class admits this lane today, so the merge still waits for the same human word a hand-authored advance needs. Lane: review-lane-repin-bot
|
|
Lane: openxfactory-5 (openXfactory-5) Disposition of the non-required The red is structural, and this pull request is its cure.
Every required check is green at this head, 0 threads are open, and no closing keyword appears in the body or the commits. It lands by squash, as #1122 did. The lockstep residue (C2, released to lane openXfactory-5 in #656 comment 6023711538) follows at once. |
|
Lane: openxfactory-5 (openXfactory-5) LANDING — lane openXfactory-5, session bbe4d255-02db-4578-840b-09924442e544@Eagle, 2026-10-06T22:03:48Z, PR #1138 into opensoft/openxFactory main |
|
RELEASED — lane openXfactory-5, session bbe4d255-02db-4578-840b-09924442e544@Eagle, 2026-10-06T22:05:06Z, for #1138 |
…n 038) (#1251) Lane: openxfactory-4 (openXfactory-4-openDox_extraction) **T002, plan 038: release 2's base (`evidence/r2-base.md`), and plan 038's `tasks.md` bookkeeping, items 1 to 15.** Bookkeeping and evidence, so this PR carries no `Arc:` line. It touches no `openspec/changes/` path, so no Rule 6 window applies. ## From plan 038's `tasks.md`, T002 - **Task**: T002, "Release-2 base, and the re-measure at the ruling". Record in `evidence/r2-base.md` every repository's `main` (research.md's R0 command), the box census, and `PACKET_MERGE=94b6f7f1` for F11.1, with lane 3's composed re-run quoted against R2-INV-P4F's 174. **README**: links `evidence/r2-base.md`. **After**: T004. **Lane**: 4 (lane 3 for the composed run). - **Realizes**: none (bookkeeping; FR-025). **Falsifier**: T002 names none. Its gates are the brief's, and are quoted under "Gates" below. - **Ruled / Decisions**: T002 carries none. Part 2 encodes rulings already posted on `#656`, each cited by comment id, and takes no decision of its own. ## Part 1: `evidence/r2-base.md` (new), linked from the README's feature-038 entry Each figure is a command quoted with its output, or lane 3's measurement quoted and attributed. - **Every repository's `main`** (the R0 command, run 2026-10-06T16:09:44Z to 16:10:31Z, and again at 16:26:12Z): `openDox-code 34c20641`, `openXdox-code 56e1c238` (then `c6d15b27`, T020's #39, committed 16:10:44Z), `openDox d77f8cbf`, `openXdox 9564d5d9`, `openDox-spec 7db9438b`, `openXdox-spec f088b097`, `openxFactory 5145683`, `xFactory 1047586d`, `codexFactory 563212a1`. The file gives each full SHA with its commit date and subject, against the R0 values of plan time, and what moved. - **The box census**: plan 034's `box_census.py` over #1144's `tasks.md` at `51456835` reads `total 125 Counter({'x': 74, ' ': 42, '~': 9})`. At `ce64afc9` it reads the same, and `diff` of the two full outputs is empty: delta 0. Batch Q (#1248) landed between them, adding 526 lines and removing none. - **`PACKET_MERGE=94b6f7f1`** (`94b6f7f13b45c351b9142345738965c974b7dd37`), on `origin/main`'s first-parent line; 83 first-parent commits since, 3 with the `Arc:` trailer (release 1's consumer pins). - **Lane openXfactory-3's composed re-run**, quoted from `lane3-to-lane4.log` (09:52:07Z and 09:52:31Z), claimed on `#656` `6013610393`: "174 red vs 174 (170 failed + 4 errors, 668 passed ...)"; "moved: none"; "5 suites / 210 cases"; openDox installed from openDox-code `main` `a9ac96f9` while openXdox-code's `pyproject.toml:126` and openxFactory's nested `openDox/code` pin `dede32b4` (v0.1.0); openxFactory `main` `0f2a87f6` to `92010d3e`. I verified one thing there: of the 48 files that differ, the two under `scripts/` are `scripts/ideation_dashboard/nightly_lane.py` and `scripts/validate-factory-mcp.py`. Nothing was re-run. ## Part 2: plan 038's bookkeeping Every item is a holder ruling or a Brett ruling already posted on `#656`, encoded as worded. The files are `tasks.md`, `plan.md`, `data-model.md`, `contracts/health-finding.md`, `contracts/cli-http-health.md` and `checklists/requirements.md`. | # | Task | What changed | Record | |---|---|---|---| | 1 | T022 | Files gain new `tests/test_composed_placements.py` (openXdox-code#41) | holder `6016356225` | | 2 | T023 | Files gain new `tests/test_swb_session_transport.py` (the bound and unbound probes in one committed file; #42) | holder `6016676145` | | 3 | T026 | Files gain `tests/test_protected_suite_check.py`, and T020's `tests/conftest.py` and `tests/test_host_plane.py` after T020 lands; 'cluster' respells to "group neighbourhood"; the single-writer table's chain | holder `6016356225`, Brett `6016648451` | | 4 | T029 | Files gain the two floor lines `MIN_SELECTED` and `MIN_PASSED` of openXdox-code's `validate.yml`, raised ONCE at its final head after merging `main`; no other PR raises them; a new single-writer row | holder `6017860539` | | 5 | R-1 (a), widened | SIX spans of `tests/test_staging_workbench.py` (`_CREATE_HARNESS`, `_SESSION_HARNESS`, `_run_create`, `_run_session`, `_hostile_descriptors`, `_HOSTILE_HARNESS`), served display, in T026, plan.md § R-1 and the ruled-answers row | Brett `6016648451` | | 6 | F12.1 | `--chains`, carried out by T026 and T029; the amendments table gains the row | Brett `6016648451` | | 7 | T073 | After gains T095+; new T094 (lane 3, read-only, claimed `6017801219`) and T095+; T073's PR stays a DRAFT until they land; the lane table, the critical path, the slice tables and the dependency list follow | holder `6016982816` | | 8 | T073 `open_until` | `doc_health` keeps its words plus lane 3's clause; `status-exemption-rail` and `openxfactory-contracts` read the ruled sentence, quoted | holder `6016982816` | | 9 | T076 / F9.2 | the WRITTEN DISPOSITION naming `realize-doc-health-direction-arc` as F9.2's carrier, in T076, T084, the box-accounting row and plan.md's ARC-5 | holder, ARC-5 (a) `6013547504` | | 10 | T003 | ticked, CLOSED ON THE RE-CHECK | holder `6017901451` | | 11 | T074 | Files gain the six openXdox-code files of the arc change's `design.md` § 10; the single-writer table: `validate.yml` T029 (floors) then T074 (`LEFT_OUT`) | holder, from #1247's `design.md` § 10 | | 12 | `identity` | stored (a `health_findings` column, canonical sorted-key JSON, capped) and emitted, bounded as T040's schema bounds it: `contracts/health-finding.md`, `data-model.md` § Finding, `contracts/cli-http-health.md`, plan.md, T041, T042 and T046; the cross-run collision stays an accepted limit, detectable now, whether the engine reports it being T046's | holder `6018624750` | | 13 | ticks | T005 #1248 `91e961a0`; T008 codeXfactory/codexFactory#515 `f1b019fe`; T010 openDox-code#89 `34c20641`; T040 openDox-spec#17 `7db9438b`; T070 #1247 `51456835`; and, on the coordinator's later word, T020 openXdox-code#39 `c6d15b27` and T024 openXdox-code#38 `8b64fae0`. Each was verified with `gh pr view <n> -R <repo> --json mergeCommit` | landed 2026-10-06 | | 14 | T073 | Files gain new `tests/test_declared_rail_registration.py` (the conftest rail block's 5 lone cases with stand-in rails) | holder `6020698021`, answering `6020683941` | | 15 | T026 | the H-2 in-test respellings move from 17 to 20: `test_gate_off_descriptor_is_the_real_cli_invocation`, `test_gate_off_session_affordances_are_the_real_cli_invocations` and `test_the_notebook_refresh_is_a_descriptor_in_BOTH_gate_postures`, admitted under CF-4; plan.md's CF-4 row notes it | holder `6020859092` | T002 itself is ticked. **Items skipped because already present: none.** Each was searched for at `origin/main` (`git show origin/main:<file> | grep -c`), and none was in place. **Where an item could not be encoded exactly as worded, or needed a reading:** - **Item 9**: no task of § "Close" archives #1144 (the archive act stays the holder's, ARC-5 (a)). The coordinator accepted placing the disposition in T084, the last task to edit #1144's `tasks.md`, and in T076 and the F9.2 accounting row. - **Item 3, the chain**: the rulings order T020 before T026, and T020 before T021, but not T021 against T026. The table says "T021 and T026, in landing order", as the coordinator confirmed. - **Item 12's grep**: the brief's `\|` is a markdown-table escape, so I ran it with plain `|`. Four hits remain, each the note that reverses the old wording ("reversing the engine-internal refinement"). The ruling gives no cap value, so none is written: the engine caps it, and the cap is T041's. - The commit trailer names the model that wrote it, `Claude Sonnet 5.5`, as the session's attribution rule requires, where the writer rules spell `Claude Opus 5.5 (1M context)`. ## The holder's answers on this PR's four open questions 1. **`tests/test_declared_exclusion.py`** is NOT in T073's Files: T073 measured its lone CI green while touching only its own four files. It IS in T074's Files (item 11). 2. **FR-011 and an `identity` response-shape falsifier** are DEFERRED to the holder's next bookkeeping batch, with T094's T095 to T104 entries. This PR keeps to its list, so `spec.md` is as `origin/main` has it. (Copilot asked; the edit was made at `76b9428b` and taken back at `7ddfda5e`.) 3. **The `identity` cap is T041's**: the contract module owns the field bounds, and T042 stores what T041 bounds. T041's and T042's entries, `data-model.md` § Finding and `contracts/health-finding.md` say so (`80c6fee7`). No value is written. 4. **T003**: the constitution's analyze gate was met by round 1 (`evidence/analyze-round-1.md`) and its re-check (`6013547504`). T003 was a discretionary second round, so the closure (`6017901451`) stands. ## Review and gates | Copilot at | verdict | findings | answered | |---|---|---|---| | `8b0a535d` | Changes recommended | 5: FR-011 and the identity's response shape; an exact aggregate cap; the T003/T004 states; the F9.2 disposition against ARC-5; the task count | the T003/T004 states, ARC-5 and the count were fix-now, fixed in `76b9428b`. The cap is an accepted limit (no value is written, by the holder's word); FR-011 is the holder's (open question 2) | | `da00b298` | Changes recommended | 3 new: FR-011 against the bookkeeping scope; T003 without a fresh analyze; T020's tick against the old body | FR-011 taken back in `7ddfda5e`; T003 is the holder's (open question 4); the body is corrected (item 13) | | `7ddfda5e` | Needs a closer look | 0 new threads; the 2 it listed as "previously missed" are those two | answered, see the threads | | `80c6fee7` | Needs a closer look | 2 body-level findings: `identity` should be NOT NULL in the store's model; `r2-base.md` called its figures an input to T004's ruling, but T002 follows T004 | both fix-now, fixed in `fb57b851` | | `f0f6923d` (final) | Changes recommended | 1: the "stored identity makes a collision detectable" sentence overstates it for an exception-only finding, which is never stored | accepted limit (#656 `5988818366`): the sentence is the holder's own wording (`6018624750`), and what T046 can detect from stored rows is T046's. Answered and resolved; no push | 9 threads, 0 unresolved. Every reply cites its commit or ruling. - **`python3 scripts/validate-openspec-cli-pin.py --all`**, in the clone named `openxFactory`, at `f0f6923d`: exit 0, `Totals: 113 passed, 1 failed (114 items)`, `0 UNDISPOSITIONED failures`. The one failure is the dispositioned `add-chain-attestation` finding, the same on `main`. - **openxFactory pytest**, locally at `8b0a535d` (CI venv, `-m "not postgres"`, TMPDIR under `~/.local/state`): `1 failed, 9206 passed, 7 skipped, 338 deselected, 9 warnings, 598 subtests passed in 2589.39s`. The one failure is `tests/hermes_runtime_contracts/test_validator_cli.py::test_release_mode_field_is_preserved_on_the_real_repository[--require-realization-realization]`, a 30s `TimeoutExpired`. It fails the same way on `origin/main` in the same clone (`1 failed, 1 passed in 54.40s`), and the CI job passes it, so it is pre-existing and environmental. My later commits change documents only. - **Doc-health**, `scripts/doc-health.py --single-repo .`, branch `f0f6923d` against `origin/main` `c44c1610` in the same clone: the two reports are byte-identical (sha256 `3b2e1f59db747178…`; `Findings: 31 critical, 26 error, 69 warning, 20 info. New regressions vs previous report: 0.`). So no new error. - **CI at `f0f6923d`**: all 15 check runs completed at the head: `pytest-suite` success (19:00:34Z to 19:27:22Z), `SonarCloud Code Analysis` success, `doc-health-py314`, `openxdox-consumer-gate`, `openspec-cli-pin`, `wallet-validation`, `clearing-dispatch-gate`, `signed-execution-chain-gate`, `former-id-arrival-gate`, `release-tag-gate`, `openreposhape-pin` and the three `lane-line` runs all success. One is RED, `merge-master-approval`, and it is inherited from `main`: its floor evaluation stops at `floor_incomplete`, "4 covered-pending path(s) exceed the tolerance of 3", the four being `openspec/specs/corpus-adapter-seam`, `domain-mapping-declaration`, `factory-mcp-conformance` and `packet-citation-report`, each `added_to_base_after_pin`. This PR touches no `openspec/specs` path. #1252 (the archive that promoted `factory-mcp-conformance`) merged at 18:58:07Z, and this run (18:59:37Z) is the first gate run after it; every other open PR's last run predates it. It passed on this PR at `7ddfda5e` and `80c6fee7`. A rerun reads the same base, so the pin or floor refresh (#1138, "Advance the pinned decision core") is what clears it; the holder rules on landing over it. - **`main` moved once more after these gates**, to `a2dc658d` (#1254, which touches `contracts/schemas/project-register.schema.yaml`, `docs/project-repo-schema.md` and `openspec/changes/prefer-triad-project-shape/tasks.md`). It shares no file with this PR, and `git merge-tree` reports a clean merge. I did not merge it in, since each merge restarts the 27-minute gate; the holder can run `gh pr update-branch` before landing if wanted. ## Files changed - `specs/038-opendox-document-tool-self-maintenance/evidence/r2-base.md` (new) - `specs/038-opendox-document-tool-self-maintenance/tasks.md`, `plan.md`, `data-model.md`, `checklists/requirements.md` - `specs/038-opendox-document-tool-self-maintenance/contracts/health-finding.md`, `contracts/cli-http-health.md` - `README.md` (the feature-038 entry's evidence list, one link) ## What is NOT done - No requirement, scenario or spec delta is touched: `spec.md` is as `origin/main` has it, and nothing is under `openspec/changes/`. - No box of #1144 is ticked, and T071 and the other tasks are left as they stand. - T046's falsifier is unchanged: whether the engine reports a cross-run collision is named as its concern in `contracts/health-finding.md` only. - Lane 3's composed run is quoted, not repeated. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Lane: openxfactory-4 (openXfactory-4-openDox_extraction) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…RATION_PIN b21f0100) (#1256) Record the review-lane pin's lockstep with the xFactory aggregation as diverged. #1138 (squash 9171d14) advanced core_commit b21f0100 to fe9a6f5b (codexFactory #524), while the aggregation's MIGRATION_PIN stays b21f0100 on all three surfaces, as measured on xFactory main 1047586d. The dated reason paragraph and the test literal move together, in the form of #1123 → 8184d74. This is owed by Brett Heap's ruling of 2026-09-24 on #656 (comment 5815412869, item C2) and lands on his word "land C2 when green" (2026-10-06). Lane: openxfactory-5 (openXfactory-5) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Brings in 8c1eeae (#1256, lane 5's C2: the review-lane pin lockstep after #1138), which landed after this branch was cut from 3cec62f. It touches contracts/review-lane-pin.yaml and one test literal, and no path this archive moves. A merge, never a rebase: the archive commit a9bbcba stays the adding commit of the archive directory, dated 2026-10-06 UTC. Lane: openxfactory-1 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e identity response shape and the single-writer chains (plan 038) (#1257) Lane: openxfactory-4 (openXfactory-4-openDox_extraction) **T002, second bookkeeping batch, plan 038: T094 and the slice entries T095 to T104, the identity response shape, the single-writer chains, and the ticks.** Bookkeeping, so this PR carries no `Arc:` line. It touches no `openspec/changes/` path, so no Rule 6 window applies. It began stacked on #1251's head; #1251 has landed (`1837ea75`) and `main` is merged in (`543f6ce1`), so the diff against `main` is this batch alone. ## From plan 038's `tasks.md`, T002 - **Task**: T002, "Release-2 base, and the re-measure at the ruling" (landed in #1251; this is its second batch of bookkeeping, the brief of the holder's `T002b`). - **Realizes**: none (bookkeeping; FR-025). **Falsifier**: T002 names none. Its gates are the brief's, quoted under "Review and gates". - **Ruled / Decisions**: none of its own. Every item is a ruling already posted on `#656`, or a landing already merged, encoded as worded and cited by comment id or merge commit. ## The items | # | Where | What changed | Record | |---|---|---|---| | 1 | tasks.md: T094, T095 to T104, T073 | T094 ticked, with its result quoted: 436 composed reds over 51 files, outside 12.5's set (Base 2; 533 at Base 1). The `T095+` placeholder becomes ten entries, T095 to T104, each with its slice name, Files, After and Falsifier from R2-INV-R9's outline and the holder's rulings, `Lane: 3 (openXfactory-3)`. T073's After and Files name them. The map's means, the rulings (R9-R1 (a), R9-R2 (a), W1 to W7) and the OQ defaults are recorded once, above the entries | map `R2-INV-R9.md`; `6021830607`; claim `6021862323`; rulings `6021830531` | | 2 | T095, T101, T104, T097 | T095: the two confirmed departures from OQ-R9-1 (`plane_host_for` untouched, an autouse fixture registers the declared host; `DECLARED_HOST_SUITES` guarded structurally). T101: `tests/declared_exclusion.yaml` for ONE entry (reasons `[doc_health]`, note dropped, the `only` list loses the file, count stays 66). T104: `tests/test_binding_stylesheets.py`, the pin 572 to 574. T097: its served-display respelling is R9-R1 (a) applied | `6022291206`; the T097 line is `6023517122` (the holder confirmed the citation, `6026622117`) | | 3 | plan.md: the single-writer table; tasks.md Files and After lines | W7's chains: `tests/conftest.py` T020, then T021 and T026 in landing order, then T095, T073, T074; `tests/test_host_plane.py` T020, T026, T095; `declared_exclusion.yaml` T101, T073, T074; the four T074 test files T103 then T074; the census T025, T104, T015, T016, T057 (the row splits, so `test_web_boundary.py` keeps its own chain). T015's and T074's After gain T104 and T103 | `6021830531`, `6022291206` | | 4 | tasks.md: T072, T074, T075 falsifiers | The four folds of #1253, in the arc change's own wording: T072 asserts that ONLY CR, LF and CRLF split rows; T074's seam tests assert that an empty-seam read names the seam AND its registrar; T075's host-wiring test shows a leg declaring only SOME of the four seams refused, and a leg declaring the six and none of the four accepted; T074's protected-suite oracle computes 12.5's set as 12.5 does (`git grep -l -e 'open-pr' -e 'open_pr' -e 'FakePullRequests'`), from the pre-arc and the final tree, the floor of 16 on each, and takes the union | openxFactory#1253 to `fc4fa0ff`; Copilot `5427373153` | | 5 | spec.md FR-011; tasks.md T041 | FR-011's JSON shape gains `identity`, emitted and bounded as openDox-spec's finding schema bounds it (no `excerpt`, `text`, `content` or `quote` key, no number, strings of at most 200 characters, `{category, entry}` for a pathless finding, `{collided_id}` for a collision). T041's falsifier gains a response-shape test asserting exactly that bound. The coverage row for FR-011 names T041. The serialized-size cap was already T041's at the base (T041's text says so, and T042 "stores what T041 bounds"), so nothing moved | holder `6018624750` | | 6 | tasks.md ticks | T011, T014, T021, T023, T025, T026 and T060 ticked, T070's tick gains #1253, and T002's own landing is recorded. Each merge commit was verified with `gh pr view <n> -R <repo> --json mergeCommit` (listed below) | the landings | | 7 | tasks.md: T072 | A Files line (`src/opendox/lines.py`, `tests/test_lines.py`); the Ruled line gains `6023517122`: `head_sha` (a), its own public `head_sha` parity-tested against `serve._head_of`, `serve.py` untouched; the line split (a), `doxbench_defaults.py` untouched. Folding either private helper is recorded as unscheduled and optional, and is not scheduled | holder `6023517122` | | 8 | contracts/health-finding.md:91 | The sentence reads: a stored `identity` makes a cross-run collision between STORED findings detectable; an exception-only finding is never stored; whether the engine reports it remains T046's concern. Nothing else on the line changed | holder `6018624750`; Copilot `5433292692` | | 9 | plan.md; tasks.md | Copilot's three items at #1251's head `1eb8e9eb`, accepted by the holder at its landing: (a) the pin and landing-order row for T073 names T005 and T095 to T104 as prerequisites, and `T095+` reads T095 to T104 at the critical path, the lane table and the revision note; (b) the combined `conftest.py` and `test_host_plane.py` row splits, and the cross-lane summary gains T026 (and the other chains of item 3); (c) the same split in T020's, T021's and T026's Files lines | holder replies `4201056969`, `4201057311`, `4201057577`; READY note `6026651962` | ### The ticks, verified | task | pull request | merge commit | merged | |---|---|---|---| | T011 | opensoft/openDox-code#92 | `09b8d44a` | 2026-10-06T19:15:55Z | | T014 | opensoft/openDox-code#93 | `a7a1c4d3` | 2026-10-06T22:23:06Z | | T021 | opensoft/openXdox-code#40 | `f70bc9c3` | 2026-10-06T19:07:10Z | | T023 | opensoft/openXdox-code#42 | `d45a0939` | 2026-10-06T17:45:33Z | | T025 | opensoft/openDox-code#91 | `84f8ed83` | 2026-10-06T17:33:31Z | | T026 | opensoft/openXdox-code#43 | `36bbef79` | 2026-10-06T22:35:40Z | | T060 | opensoft/openDox#20, the tag `dox-v1.2` (tag object `58538ff3`, on `6a9f4902`), opensoft/openDox#21 | `6a9f4902`, `c7f75845` | 17:46:59Z, tag 17:58:45Z, 19:02:39Z | | T070 | openxFactory#1253 (T070b, added to its tick) | `fc4fa0ff` | 2026-10-06T18:56:42Z | | T002 | openxFactory#1251 (its own landing) | `1837ea75` | 2026-10-06T22:31:42Z | - **T021** landed with Copilot r4199337845 an ACCEPTED LIMIT (holder READY note `6023492215`); T021's entry records it. - **T025's** entry says its 34 nodes are "quoted at T029"; that stays T029's, and the entry says so. - **T011's** server node is T014's, as its own Falsifier says. **Skipped, because already present at the base:** T020's and T024's ticks (#1251 item 13) and T004's tick (#1245, `260234b5`), all confirmed with `git show <commit>:<tasks.md> | grep`. **T071 is NOT ticked.** Brett's word, "Ratify it (Recommended)" (`#656` `6023375303`), is recorded on T071's entry, but the change's ratification-record PR has not landed (no such PR is open or merged on `opensoft/openxFactory` at this writing). The box stays open. ## Readings the holder accepted (`6026622117`), disclosed as the brief requires - **W7 omits T026 from the openXdox-code chains.** The single-writer table keeps T026 where its own ruling (`6016648451`) puts it, and lane 3's claim (`6021862323`) says T026's PR lands before T095. So the conftest chain reads T020, then T021 and T026 in landing order, then T095, T073, T074; and `test_host_plane.py` reads T020, T026, T095, as W7 gives it with T026 added. - **R9-R2's last sentence** ("If the re-scoped test runs alone, it leaves the declaration, and the count moves with it, as the declaration's own rules require") is recorded in T100 as worded. `declared_exclusion.yaml` is NOT added to T100's Files: the holder's file list at `6022291206` names it for T101 only. - **Edits outside tasks.md**, ruled in scope as each item names its place: plan.md (items 3, 9), spec.md FR-011 (item 5) and `contracts/health-finding.md:91` (item 8). ## Other notes on where an item needed a reading - **Counting.** The task count reads 90 rows: the placeholder `T095+` is replaced by T095 to T104 (81 - 1 + 10). - **Plan 034's task numbers.** The entries cite plan 034's T103 (#80, in T099's `Host` header) and plan 034's T086 (W2, in the rulings) as "plan 034's", because plan 038 now has its own T103. - **OQ-R9-3.** The map did not measure the respelled gate-console and wheel-model skips; T097 and T103 say so, and the map's 127 passed and 5 skipped is quoted as the measurement. - **Counts of slices** are copied in the map's own form (for example "16 nodes, and +5 on R9-R1 (a)"), not summed. - **T095's chain after T026.** T095's After names T021 and T026, both landed. - **Not mirrored from the arc's 4.1:** T075's falsifier gains the some-of-four refusal and the six-and-none acceptance, which #1253 folded. The arc's two older refusals (part-way through the seams; at the column call) are not in T075, since #1253 did not add them. - **T046 and T057** carry no response-shape falsifier for `identity`: item 5 names T041's. ## Review and gates - **`python3 scripts/validate-openspec-cli-pin.py --all`**, in the clone named `openxFactory`, at `691648c6`: exit 0, `Totals: 113 passed, 1 failed (114 items)`, `0 UNDISPOSITIONED failures`. The one failure is the dispositioned `add-chain-attestation` finding, the same on `main`. - **openxFactory pytest.** The full local run was stopped at about 44% at a coordinator drain, so it is NOT a result and is not claimed. The repository's own gate, `pytest-suite` in CI at `691648c6`, completed `SUCCESS` (2026-10-06T23:32:38Z to 23:58:56Z). - **Doc-health**, `scripts/doc-health.py --single-repo . --as-of 2026-10-07`, branch `691648c6` against `origin/main` `0992369a` in the same clone: the two reports are byte-identical (sha256 `ce17aadd6d96e484170e2ec4784e44972e33c7d1a6c65830ea14a1035f2ae976`; `Findings: 31 critical, 26 error, 69 warning, 20 info. New regressions vs previous report: 0.`). So no new error. - **CI at `691648c6`**: all 14 check runs are `SUCCESS` (rollup `SUCCESS`): `pytest-suite`, `merge-master-approval` (the red inherited from `main` since #1252 was cleared by #1138), `openspec-cli-pin`, `doc-health-py314`, `openxdox-consumer-gate`, `wallet-validation`, `clearing-dispatch-gate`, `signed-execution-chain-gate`, `former-id-arrival-gate`, `release-tag-gate`, `openreposhape-pin`, the two `lane-line` runs and SonarCloud. - **`main`** has moved to `0992369a` since the last merge (`543f6ce1`). GitHub reports this PR `MERGEABLE`, and the ruleset is not strict, so `main` is not merged in again (a merge would restart the 27-minute gate). | Copilot at | verdict | findings | answered | |---|---|---|---| | `691648c6` (final; review `5435686665`) | Changes recommended | 1 (thread `4201443690`): T041's falsifier cannot verify what T046's `health list --json` and T057's HTTP route emit; the review summary adds that the new T095 to T104 collide with plan 034's task numbers cited unqualified at `spec.md:662`, `spec.md:1222` and `clarify-questions.md:437` | accepted limit (#656 `5988818366`): plan-record accuracy, not a bypass, and the T041 placement is the holder's own instruction (item 5). Answered (`4201487553`) and resolved | 1 thread, 0 unresolved. The holder ruled both points YES at `6027706377` and has them encoded in a THIRD batch, not here: the `identity` falsifier split across T041, T046 and T057, and the plan 034 references qualified. This PR therefore carries T041's wording as the brief gave it. ## Files changed - `specs/038-opendox-document-tool-self-maintenance/tasks.md`, `plan.md`, `spec.md` - `specs/038-opendox-document-tool-self-maintenance/contracts/health-finding.md` ## What is NOT done - T071 stays open (its ratification record has not landed). No box of #1144 is ticked, and no task other than those listed is ticked. - No scenario or spec delta beyond FR-011's JSON-shape bullet is touched, and nothing is under `openspec/changes/`. `README.md` is untouched. - The T095 to T104 entries record the slices; none of their work is done here. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Lane: openxfactory-4 (openXfactory-4-openDox_extraction) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>



Lane: review-lane-repin-bot
AUTOMATED PIN ADVANCE — proposal only. This lane never merges and never approves.
Advances the pinned decision core from
b21f010013fa51960c77377a8582943435b6db32tofe9a6f5b91886e4f07296dc6a264deb345b1618f, moving all five sites in one commit.contracts/review-lane-pin.yamlcore_commitb21f010013fa51960c77377a8582943435b6db32fe9a6f5b91886e4f07296dc6a264deb345b1618f.github/workflows/merge-master-approval.ymlPINNED_CORE_COMMITb21f010013fa51960c77377a8582943435b6db32fe9a6f5b91886e4f07296dc6a264deb345b1618f.github/workflows/merge-master-approval.ymlcore checkoutref:b21f010013fa51960c77377a8582943435b6db32fe9a6f5b91886e4f07296dc6a264deb345b1618f.github/workflows/pytest-suite.ymlcore checkoutref:b21f010013fa51960c77377a8582943435b6db32fe9a6f5b91886e4f07296dc6a264deb345b1618fcontracts/review-lane-floor-snapshot.yamlsha256b77b4e55fdd24a0ca00eb390f396a0ea8829880879b468e98960b86a0fdad763f2bc7d92fafb99e6a7ec52ac50e4fd0e8fbe68e733a846cd337d9b2ecffaec96contracts/review-lane-floor-snapshot.yamlentry_countgenerated_atfc837dffb9be0b8c28823c339e401f97e0e3e28aa2dc658d90be2eaf700a41f60599c68905485e46never_clearable_paths)Covered-pending paths this advance is expected to clear: 4
openspec/specs/corpus-adapter-seam/spec.mdopenspec/specs/domain-mapping-declaration/spec.mdopenspec/specs/factory-mcp-conformance/spec.mdopenspec/specs/packet-citation-report/spec.mdHow the pinned commit was resolved, and how its landedness was verified
codeXfactory/codexFactory, default branchmain, resolved at run time by this lane — not taken from any event payload.GET /repos/codeXfactory/codexFactory/compare/main...fe9a6f5b91886e4f07296dc6a264deb345b1618fansweredstatus: identical, sofe9a6f5b91886e4f07296dc6a264deb345b1618fis carried bymain.floor/openxfactory-review-authority-floor.yamlatfe9a6f5b91886e4f07296dc6a264deb345b1618f; itssha256andentry_countabove are computed from the bytes written to it, not carried across from codexFactory.Repeat the verification:
Run: https://github.com/opensoft/openxFactory/actions/runs/37533949100
This pull request is judged by the same freshness checks that judge a hand-authored advance, with no exemption of any kind.