chore: coordinate 0.0.7 milestone - #1641
Conversation
|
[PHASE: RESEARCH] Step 0 captured 61 owner-scheduled product issues at Current gate
NextReconcile the independent synthesis, freeze the wave plan, run the sole required PLAN-EVAL, then activate exactly four topic orchestrators. |
|
PLAN checkpoint @ |
|
[PHASE: PLAN-EVAL] [VERDICT: CHANGES_REQUESTED] PLAN-EVAL — release-0.0.7--orchestration (composed milestone wave plan)Evaluator identity and evaluated head
What I independently verified as soundRecorded first so the findings below are read as targeted, not as a rejection of the whole run.
Checklist results
6 FAIL / 2 PASS. Any unchecked box is Open-decision sweep (evaluator-run)Decisions the plan leaves open that would force rework if deferred. Each is an automatic unchecked box under
Decisions I judge genuinely safe to defer: the two owner-undecided canary cadence questions ( Findings, severity-rankedF1 — BLOCKING. The sole wave-0 merge barrier is scoped from a consumer audit that baseline
|
| Issue | Live acceptance row | The amendment says |
|---|---|---|
#1349 |
- [ ] createHttpClientLink, ClientLinkPort and ClientLinkCallOptions are exported from their… |
must not publicly export any of the three |
#1349 |
- [ ] port and timeout are removed from the client and defineServices option records. |
must keep them accepted/deprecated rather than remove |
#1353 |
- [ ] traceContextContribution() ships as an SdkClientContribution declaring its header keys… |
"Do not ship traceContextContribution()" |
#1353 |
- [ ] createHttpClientLink contains no trace-header authorship; the contribution is the only… |
the transport "remains the sole final author of trace headers" |
#1353 |
- [ ] NEGATIVE: with the contribution removed from the chain, a request carries no traceparent… |
reversed by the above |
#1351 |
- [ ] deno task deps:latest shows the oRPC family at 1.14.15 and deno why @orpc/shared shows a… |
any dependency move is a separate decision targeting stable v1.15.0 |
milestone-run.md pre-merge gate check 2 requires "zero unticked - [ ] on every issue the PR closes", and the honesty rule states a criterion that cannot be truthfully ticked moves with its issue and "is never ticked to clear a gate." Those two rules are now in direct collision for #1349, #1351 and #1353: the leaf either ticks a box the amendment forbids implementing, or its close-gate stays red. That is the #1024/#1061 mid-flight-split class arriving at merge time in waves 4–5, after the SDK chain has already consumed the critical path.
Required fix. Before dispatch, rewrite the Acceptance sections of #1349, #1351, #1352 and #1353 to the amended scope — strike or restate each contradicted row in place, rather than leaving it under a superseding note. Any row that survives only as history must be moved out of the checklist.
F3 — BLOCKING. Five Plan-Gate boxes have no artifact at all
Open-decision sweep, per-leaf gate + file surface, risk register, gate set selection, and the jsr-audit surface scan are each simply absent from the run dir, not merely thin. gates/plan-gate.md:45 is explicit that absence of a script is not permission to omit a check, and evaluator/plan-protocol.md:44-47 forbids downgrading missing evidence to advice. See the checklist rows for the per-box citation and consequence.
Required fix. Add to plan.md (or a committed companion the leaf briefs reference): a risk register with mitigations, including a shared-surface collision table for concurrently dispatched leaves; the gate set selected from gates/archetype-gate-matrix.md per surface plus the scope overlays in play; a jsr-audit surface scan over the planned public surface naming slow-type and export risks per package leaf, with an explicit N/A + reason on non-package leaves; an open-decision sweep with each item marked "safe to defer" or "must resolve now"; and, per leaf, the proving gate and the file surface it touches — this is the field milestone-leaf-plan.json's schema is missing and the field every leaf supervisor needs.
F4 — MAJOR. #1606 was closed with an acceptance criterion that is false on live GitHub right now
Its fourth criterion is - [ ] #1377's [post-merge] row is ticked, referencing this issue. I checked #1377: it is CLOSED/COMPLETED in milestone 0.0.6, and its line 115 is still - [ ] [post-merge] The published JSR landing page for @netscript/sdk shows the canonical dialect. — unticked. The close comment on #1606 does not mention that row.
The other three criteria I verified as genuinely true (JSR latest: 0.0.6; the published 0.0.6 README contains no lib/api-clients.ts and leads its value bullets with createQueryFactories as "the golden path"; version and observation date recorded on the issue). So this is not hidden work — the observational discharge is real. It is an honesty-rule slip on one row, and it is cheap to fix.
Required fix. Tick #1377's [post-merge] row with a reference to #1606's verification comment, or record on #1606 why that row is being left for #1377's own bookkeeping. Do not leave an issue closed completed with a criterion that reads false to anyone who checks.
F5 — MAJOR. #1249's admission does not meet its recorded predicate
milestone-intake.json records admissionPredicate: "high-value-coherent" for #1249. milestone-run.md step 0.2 defines that predicate as "complete P1/feature scope that serves the release without displacing a critical prerequisite." Live, #1249 is priority:p2, type:fix — neither P1 nor feature scope. Nor is it "complete": step0-synthesis.md:140 calls it "Weakest, and one supporting claim needs correcting", shows the min/max/multipleOf claim rests on Zod 3 names read by Zod 4's def.check, calls it "unconfirmed without executing a probe", and recommends "Admit on the controlProps half only." The intake admitted both halves with "both halves require red-first reproduction" and no recorded fallback if the second half does not reproduce. The leaf fresh-typed-route-and-form-repair then couples #1249's close-gate to #1609/#1610.
This is the opportunistic-scope-growth failure mode the predicate exists to prevent, and it is sharpened by the contrast with #1637 — priority:p1, a consumer-visible false outage on published @netscript/sdk@0.0.6-canary.3, riding an existing leaf at near-zero cost — which meets the predicate cleanly and which I raise no objection to.
Required fix. Either re-scope #1249's admission to the controlProps half (as the synthesis recommended) and amend the issue accordingly, or record on the intake the explicit fallback: if the Zod-4 constraint half does not reproduce red-first, that half moves to 0.0.8 with a written reason rather than being ticked or silently dropped.
F6 — MAJOR. #1348 has no closure path, and its leaf's work is largely already done
rfc-a-stage0-ratification-board is a wave-1 leaf on the critical path — eight rfc-prerequisite edges fan out of #1348 into waves 2–6. But its own acceptance says - [ ] This issue is not closed by any implementation PR's closing keyword, and milestone-leaf-plan.json agrees: "Tracking issue - no implementation PR may carry a closing keyword on it." Meanwhile the worklog records that Stage 0's substance — RFC ratification and the realignment of #1349–#1353 — was already performed during Step 0 at 21:15Z. Two of its remaining boxes (Q1 (cookie topology) and Q2 (PluginContributions group shape) are answered on this issue) are owner decisions no agent can execute, and step0-synthesis.md:166-169 records that RFC 0001 still lists 11 unresolved questions at :1555-1599 — "the biggest unknown gating waves 3–6."
So the plan has a leaf that produces no mergeable PR, cannot be closed by one, has partly already executed, and depends on owner answers that are not scheduled — while the milestone's definition of done requires every issue closed with verified acceptance or moved with a written reason.
Required fix. State #1348's termination path in plan.md: who answers Q1/Q2 and when, which boxes Step 0 already discharged, and whether #1348 closes at the feature-complete checkpoint or moves to 0.0.8 as an epic. If the RFC's 11 open questions gate waves 3–6, say which ones and schedule them.
F7 — MODERATE. One leaf spans two topic lanes
app-service-client-wiring is lane: features and owns #1355 (features) and #1360 (fixes). milestone-run.md § Cluster control plane requires topic issue sets to be exclusive and a topic orchestrator to own only its allocated issues. The validator does not catch this: it checks lane ownership against inventory and leaf lane validity independently, never their agreement. The grouping itself is well-justified (step0-synthesis.md:117 — both edit ServiceShowcaseLab.memory.tsx.template and would collide as separate PRs), so the fix is bookkeeping, not re-clustering.
Required fix. Move #1360 to the features lane in inventory, DAG and cluster state, re-render and re-validate. Consider adding a leaf-lane/issue-lane agreement check to the validator so this class cannot recur silently.
F8 — MODERATE. The quota and paid-transport preflight is thin and pre-dates the re-freeze
milestone-run.md stage B makes these procedural gates whose proof is "the recorded check output (what was queried, when, result)", because both cost real time in 0.0.4 — a hard quota cap mid-delivery, and $7.43 billed to the wrong transport. worklog.md:9 records at 18:43:18.739Z: "Claude first-party Max; Codex ChatGPT authenticated; agentic:runtime doctor: no_change, all components ready; routing state []." That evidences authentication and runtime health, not quota headroom and not transport billing. It was also taken against the provisional 62-issue plan, ~2h45m before the 64/61/44 re-freeze at 21:28:00Z, for a milestone roughly 4× the 0.0.4 exemplar (step0-synthesis.md:98).
Required fix. Re-run the preflight against the frozen plan and record the actual numbers: remaining quota per provider lane with reset windows, and an explicit confirmation of which transport each lane bills to. A record that cannot distinguish "have headroom" from "am authenticated" does not discharge a gate whose negative case is exhaustion mid-delivery.
F9 — MODERATE. The stable-cut conditions are under-specified and the sufficiency computation is unpopulated
plan.md:20 says only "Stable waits for all committed issues/leaves to be terminal and exact-main evidence to be sufficient." It does not name GitHub Actions OIDC publication or artifact-pinned production E2E, both of which milestone-run.md § Definition of done and netscript-release require. milestone-cluster-state.json has exactMainEvidence.expectedGateIds: [] and receipts: [], and releaseCaptain.evidence: []. The validator does hard-fail on empty expectedGateIds — but only once the captain leaves inactive (validate-milestone-cluster.ts:530-532,550-551), so today nothing names the gates, and no leaf knows which receipts it is expected to produce.
Required fix. Populate expectedGateIds with the gate identities the exact-main cut will require, and state the OIDC-publication and artifact-pinned production-E2E conditions in plan.md:20 rather than relying on inheritance.
F10 — LOW. research.md is stale and drift.md contradicts the frozen state
research.md:22-23 asserts a provisional 62-issue / 4-lane split that the freeze superseded, and says the freeze "remains provisional". drift.md reads in full: "No accepted drift. Step 0 is in progress and no scope has frozen." — while scope is frozen, #1453 was moved, two issues were closed-fixed, lane allocation was rebalanced (docs 2→1, features 17→16, fixes 25→27), and two external candidates were admitted. netscript-harness § Run Artifacts makes drift.md the append-only record of exactly these events, and lane-policy.md § Selection and handoff rules requires the selected lane and any override to be recorded in supervisor.md and drift.md.
Relatedly, supervisor.md carries profile, run id, coordinator, branch, baseline and start time — but no model, session, host, checkout/worktree path, lane table, or PLAN-EVAL decision, all of which lane-policy.md § Supervisor identity and the milestone-run.md checklist require ("PLAN-EVAL decision for the wave plan recorded in supervisor.md").
Required fix. Update research.md to the frozen numbers; open drift.md with the Step 0 disposition events, the lane rebalance, and this evaluation's route substitution; complete supervisor.md with the lane table, identity fields, and the PLAN-EVAL decision.
F11 — LOW. Residual #1306 scope is unrouted, and three bookkeeping slips
#1306. Its close is defensible: the four rows read as alternative remedies across three surfaces (step0-synthesis.md:124), and I verified rows 1 and 4 are genuinely satisfied by Aspire 13.4.6 plus both skill files. But rows 2 (aspire startnon-TTY attached-or-documented contract) and 3 (dashboard login token to stdout when no TTY) were not satisfied — the close comment argues they are moot rather than met. Permilestone-run.md§ Cut-time checklist and the#1090pattern, the residual DX gap should be routed to a follow-up issue at the moment it is noticed, not left implicit in a close comment.- Four milestone issues are absent from the inventory —
#1108,#1201,#1260,#1550, all closed 2026-08-11/12, i.e. before the run. Step 0.4 says inventory every resulting target-milestone issue. The omission is harmless but undocumented; state that the inventory covers issues open atbaselineMainSha. - No watchers.
milestone-cluster-state.jsonwatchers: [], while stage A's contract names read-only watchers as part of cluster bootstrap. - Stale counts in committed artifacts.
milestone-leaf-plan.json's#1564rationale still says "With 45 leaves merging direct-to-main"; the frozen count is 44.
Verdict
FAIL_PLAN
Six of eight Plan-Gate boxes are unchecked, and the evaluator-run sweep found eight open decisions the plan did not flag, at least six of which force rework if deferred. Two findings are independently blocking on their merits: the milestone's single merge barrier is scoped from a consumer audit that baseline main contradicts (F1), and the RFC realignment left the machine-checked acceptance surface in a state where three SDK-chain leaves cannot close their issues without violating either the close-gate or the honesty rule (F2).
This is not a weak plan. Its control plane is the most internally consistent I have audited in this repository — five independent structures agreeing exactly on 61 issues, a validated acyclic DAG, GitHub moves actually performed rather than merely recorded, and three genuinely well-chosen locked mechanisms. The gap is that the run produced a dispatch schedule and stopped short of the plan the Plan-Gate asks for: the risk, gate, surface and open-decision work that turns a schedule into something 44 leaf supervisors can execute without rediscovering the same decisions. That is the cheap fix happening before the expensive one, which is what this gate exists for.
Required fixes, in dispatch-blocking order
- F1 — re-audit all seven
pull_request.base.shaconsumers at01e0960; restate#1564's scope, consumer table and boundary comment per workflow and per construct; add or explicitly excludepages.ymlandfresh-ui-quality.yml; re-state the red-first fixture against a construct that can go red; re-decide whether#1564remains a whole-milestone barrier. - F2 — rewrite the Acceptance sections of
#1349,#1351,#1352,#1353to the amended scope, striking contradicted rows in place rather than superseding them by note. - F3 — add the risk register (with a shared-surface collision table), the selected gate set and overlays, the jsr-audit surface scan with per-leaf
N/Areasons, the open-decision sweep with defer/resolve-now markers, and per-leaf proving gate + file surface. - F6 — state
#1348's termination path and schedule the RFC's open questions that gate waves 3–6. - F5 — re-scope
#1249's admission or record its fallback. - F9 — populate
expectedGateIds; name OIDC publication and artifact-pinned production E2E in the stable-cut conditions. - F8 — re-run the quota/transport preflight against the frozen plan and record actual numbers.
- F4, F7, F10, F11 — bookkeeping:
#1377's post-merge row;#1360's lane;research.md,drift.md,supervisor.mdcurrency;#1306residual routing; inventory scope note; watchers; the "45 leaves" string.
Re-render and re-run harness:milestone:validate after 1, 5, 7 and the #1360 lane move; the current ok: true does not survive an inventory or lane edit unexamined, and schema validity was never the question here.
Loop status
This is FAIL_PLAN cycle 1 of 2. A second FAIL_PLAN escalates to the owner with the unresolved items (evaluator/plan-protocol.md:52-55).
Notes
- No implementation, evaluator or publish lane was dispatched, and no repository state was mutated. The coordinator owns publishing this as the PR phase comment.
- The route substitution in the identity table (Opus 5 where
lane-policy.md:45binds Fable 5 · medium) is a recorded deviation, not an approved fallback. If the coordinator wants a route-clean verdict on the re-submitted plan, run cycle 2 on Fable 5 · medium; the opposite-family invariant is satisfied either way. #1384/#1385remaining in0.0.8: I judge this defensible and not a hidden stable-cut blocker.#1384's reasoning is sound and the credential-only carve-out is correctly refused.#1385is a p0 thatstep0-synthesis.md:139says "Needs nothing from fix(plugin):createPluginServicehas no auth seam, so every first-party plugin API is unguardable by construction #1383", andplan.md:9-10justifies only#1384— butmilestone-intake.jsoncarries a distinct, owner-ratified#1385reason (auth transport topology outside this milestone's typed-extension scope). Fold that reason intoplan.mdso the deferral does not read as covered by#1384's argument.
|
PLAN-EVAL cycle 1 remediation is pushed at immutable head All eleven findings were addressed before dispatch: #1564 was re-audited and closed-fixed; #1349/#1351/#1352/#1353 Acceptance sections were rewritten; 43 leaf contracts now name surfaces/gates/JSR audit; #1377 was synchronized; #1249 has an explicit reproduction fallback; #1348 owner decisions and closure checkpoint are locked; #1360 moved to features; quota/route evidence is recorded; exact-main release gates and OIDC/artifact-pinned E2E are explicit; counts/watchers/drift were reconciled; #1642 preserves #1306 residual docs scope. Structural proof on this head: |
|
PLAN-EVAL cycle 2/2: APPROVED at plan head The immutable verdict is recorded in |
Summary
Coordinate the complete 0.0.7 milestone through the milestone-cluster harness: freeze scope,
schedule four topic lanes, retain structured gate/evaluator evidence, publish meaningful canaries,
and cut stable only from exact-main green evidence.
Scope
four topic lanes, and nine dependency waves.
Slices
331f7c664mainValidation
deno task harness:milestone:render -- .llm/runs/release-0.0.7--orchestration— PASSdeno task harness:milestone:validate -- .llm/runs/release-0.0.7--orchestration— PASS (ok: true)deno task harness:milestone:test— PASS (15 tests)Harness
.llm/runs/release-0.0.7--orchestration/Drift / Debt
requested native JSON resource inventory path.
POST /api/v1/auth/signoutrevokes any session id an unauthenticated caller supplies #1384/fix(auth): oRPCsignin/callbackdiscard the backendSet-Cookie, so the interactive browser flow can never establish a session #1385 remain in 0.0.8; no partial credential-only workaround is accepted for fix(auth):POST /api/v1/auth/signoutrevokes any session id an unauthenticated caller supplies #1384.Definition of Done