Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion OUTSTANDING_TASKS.md
Original file line number Diff line number Diff line change
Expand Up @@ -162,7 +162,7 @@ The maintainer directed (2026-08-30) that the repository goes **private for the
- [ ] **SC-7 — register the isolated runners after cutover (`#2328`, `#2337` B8).** Registration tokens never enter the repository; no runner is attached while the repository is public; `CI_EXECUTION_MODE` moves to `hybrid` only after the runners are proven.
- [x] **SC-8 — public-asset and launch-kit decision (`#2337` A; `#2242`).** GitHub Pages keeps publishing from a private repository on Pro (the site stays public); the launch kit and the REVIVAL public-source messaging assumed a public repository — decide keep / move / reword and record it on `#2337`. *(**Ruled 2026-09-03, maintainer decision packet SC8: private development repository + public release/source mirror.** Releases, checksums/provenance and the GPL source stay public through a mirror; development, CI and issues go private; GitHub Pages keeps publishing. Mechanics — which repository, what syncs on a tag, how the launch kit and `awesome-selfhosted` wording point at the mirror — are seeded as CI-16 `#2439` and recorded on `#2337`.)*
- [ ] **SC-9 — Codex review credits are exhausted (maintainer billing).** On 2026-09-03 at 22:34Z the Codex connector answered PR `#2462`'s second and third pushes with "You have reached your Codex usage limits for code reviews" (it still reviewed the first and the fourth head). Until credits are added at the Codex usage dashboard, the documentation-only review gate falls back to one fresh-context agent review per PR (global law 2), which is what `#2462` used. Decide: top up, or accept the fallback and record that on `#2337` A (review-integration billing).
- [ ] **SC-10 — control-plane PRs awaiting the maintainer's review (ADR-0066 amendment 2026-09-03).** The amendment says control-plane (T0/T2) and runner changes merge only after the maintainer's review plus the fresh-context review. Queued by the 2026-09-04 overnight orchestrator, each already reviewed clean by a fresh-context agent and re-proven hosted at the current head: `#2502` (CI-11 slice 1: 152 external actions pinned to full SHAs, guard enforced in `smart-ci-self-test.yml`; SC-5 command in the body), `#2506` (Smart CI planner: accept a merge ref regenerated against the live base tip — closes the shadow false-red shape seen on `#2485`, `#2496`, `#2500`), and the `#1898` dev-up port-release PR once open. Also decide the CI-07 `#2331` proposal (move the Windows launcher regression suite off the required hosted `windows-latest` leg per SC-3). **Post-hoc disclosure:** `#2479` (Paper colour-audit scanner, touches `reusable-paper-color-audit.yml`) was merged on 2026-09-04 (merge `5054c723e`) with the fresh-context review but without the maintainer's review — please review post hoc; revert is a one-liner if wanted.
- [ ] **SC-10 — control-plane PRs awaiting the maintainer's review (ADR-0066 amendment 2026-09-03).** The amendment says control-plane (T0/T2) and runner changes merge only after the maintainer's review plus the fresh-context review. Queued by the 2026-09-04 overnight orchestrator, each already reviewed clean by a fresh-context agent and re-proven hosted at the current head: `#2502` (CI-11 slice 1: 152 external actions pinned to full SHAs, guard enforced in `smart-ci-self-test.yml`; SC-5 command in the body), `#2506` (Smart CI planner: accept a merge ref regenerated against the live base tip — closes the shadow false-red shape seen on `#2485`, `#2496`, `#2500`), `#2522` (dev-up port release, `#1898`), and `#2532` (release-cache scanner comment handling, CI-09). Also decide the CI-07 `#2331` proposal (move the Windows launcher regression suite off the required hosted `windows-latest` leg per SC-3). **Post-hoc disclosure:** `#2479` (Paper colour-audit scanner, touches `reusable-paper-color-audit.yml`) was merged on 2026-09-04 (merge `5054c723e`) with the fresh-context review but without the maintainer's review — please review post hoc; revert is a one-liner if wanted.

---

Expand Down
20 changes: 20 additions & 0 deletions docs/STATUS.md
Original file line number Diff line number Diff line change
Expand Up @@ -130,6 +130,26 @@ Guards, tests and docs:
- **Docs only:** PR `#2509` (merge `9e431ab02`) records the seventh block above. PR `#2512` (merge `e88e5e513`) adds human-action item SC-10 to `OUTSTANDING_TASKS.md` §J — the control-plane PRs prepared but not merged under ADR-0066's amendment (`#2502`, `#2506`, the `#1898` dev-up port-release work, and the CI-07 `#2331` proposal) — and discloses post hoc that `#2479` was merged with the fresh-context review but without the maintainer's review. It records open items; it checks nothing off.
- **Not shipped reality:** PR `#2496` (`#2434`, clearing a stale board-load error after background recovery) was reviewed SHIP and merged, but into its stacked base branch `issue-2430/board-mutation-alert` **after** that base had already landed as `#2495`, so merge `c60d0156a` is **not** an ancestor of `main` and the fix has not shipped; its owner must re-target it. Its review filed a MEDIUM on `#2523` (the new spec's success mock clears the store error itself, so the view branch is untested). `main`'s first completed CI run of the night, at `17e48815e`, was red only on the Windows launcher regression suite — the `#2378` shape recorded there — with every other required leg green. Open at the time of writing: PRs `#2500`, `#2502`, `#2506`, `#2510`, `#2516`, `#2517`, `#2518`, `#2521`, `#2522`, `#2527` and `#2528`; `#2527` (`#2141`, a transcript source option in the Paper capture composer) was still open when this block was written. Their state lives on the PRs and their issues, and `docs/releases/V0_3_0_READINESS.md` carries the release-gate view.

v0.3 integration wave, ninth block (2026-09-04, `main` `c174a517a` to `9943804bc`; overnight orchestrator lane continued, nine merges). Codex review credits stayed exhausted (SC-9) for this whole range too, so **every PR below carried one fresh-context independent reviewer subagent instead of a Codex outcome**, and the connector's usage-limit notice was classified once per PR as informational rather than a finding. Control-plane PRs `#2502`, `#2506`, `#2522` and `#2532` were deliberately **not** merged by the orchestrator: under ADR-0066's 2026-09-03 amendment they wait for the maintainer's review, queued as human-action item SC-10. The stacked-base trap recorded in the eighth block now has a ritual, applied in this range: a PR stacked on a merged-but-undeleted base branch merges into that branch, not `main`, so re-target with `gh pr edit N --base main` before merging:

Capture composer:
- **The Paper composer can file a transcript capture (`#2141` partial, PR `#2527`, merge `ca6fe42fe`).** A Typed / Transcript radio pair is added to the existing Paper composer and forwarded to the API, so the source that keys `CaptureRequestContract.IsTranscriptSource` — the `transcript.v1` queue request type, the 200,000-character limit and LLM extractor candidacy — is reachable without the Legacy `CaptureModal`. The limits move into a shared `constants/capture.ts` that `CaptureModal.vue` imports too, the transcript-only length guard both disables Capture and explains itself through `role=alert`, the plain sentence that transcript captures are sent to the configured assistant renders on selection before submit, the chosen source crosses the `#2142` 401 stash (an absent or unrecognised value reads back as `Typed`, never as a transcript), and `transcript` joins the New Capture palette keywords. Evidence: 8 spec files / 240 tests passed, typecheck, `npm run lint` 0 errors and 8 pre-existing warnings; the reviewer confirmed label handling is byte-identical (`#2481`/`#2485`/`#2490` unregressed), the radio group is a real fieldset/legend and all five i18n keys exist in en/es/it. `Refs #2141`, not `Closes`: the board-less triage dead end (CF-09 `#2263`), transcript **file** upload and the Legacy-modal visual fit stay open there. Not verified: no backend suite, no Playwright, no full vitest run.
- **The composer flushes the pending label on submit (`#2490`, PR `#2539`, merge `9943804bc`; closes `#2490`).** `submit()` calls the existing `addLabel()` before emitting, so a label typed but not committed with Enter reaches the payload with the same trim, dedupe and comma-is-content behaviour (`#2485`) instead of being silently dropped — a loss the `#2481` success-only reset used to erase along with the evidence. `labelInput` joins the draft snapshot and the `captureDraftStash` record with the same tolerant read shape as `#2527`'s `source` (a pre-change record restores as an empty box), an over-long pending label is dropped whole and flips `labelsDropped`, and the reset assertion that `resetDraft` removes committed chips is restored. Evidence: red-first — 5 of the new tests fail without the fix — then 124 passed / 3 files, typecheck, lint 0 errors; the reviewer confirmed the `canSubmit` guard precedes the flush so a refused submit leaves the pending text on screen, and that `canSubmit` does not read `labels` so the flush cannot make a form unsubmittable. Follow-up `#2540`: `PaperTriageRowEdit.save()` has the same drop-uncommitted-label class. Not verified: no browser or Playwright run, no full vitest suite.

Review and board frontend:
- **The stale board-load error clear reached `main` (`#2434`, PR `#2530`, merge `b83dc6e11`; closes `#2434`).** This carries PR `#2496`'s exact delta (`BoardView.vue` +16/-1, `BoardView.spec.ts` +69) from the same branch head, re-targeted onto `main`: a successful current-board background refresh clears the matching stale board-load error without hiding a newer mutation failure, guarded against route changes, stale refreshes and post-unmount completions. **The eighth block's "`#2496` did not reach `main`" note is now resolved** — that merge (`c60d0156a`) landed on the dead base branch `issue-2430/board-mutation-alert` and is still not an ancestor of `main`; the fix ships through this PR instead. Review: the identical diff's one fresh-context review on `#2496`, verdict SHIP, hosted `ci-required` at this head as the proof. Follow-up `#2523` carries that review's MEDIUM (the new spec's success mock clears the store error itself, so the view branch is untested).
- **Unavailable review evidence is retried inside the same Apply action (`#2465`, PR `#2528`, merge `94d2b8217`; closes `#2465`).** A failed automatic selector batch is consumed and its retry started during the first explicit Apply rather than requiring a second attempt; the unavailable state is scoped to the active proposal **revision** and cleared when the proposal is replaced or leaves actionable `PendingReview`. Evidence: the `usePaperReviewSelectors` and `PaperReviewView` specs, typecheck, scoped ESLint; the reviewer confirmed Apply is gated on the refresh epoch (deleted only after a settled batch plus identity, status and expiry re-verification), that the retry starts synchronously inside the failed promise continuation reusing the existing generation/abort guards, and that both outcomes toast plus a `role=status` note. Three LOWs declined, including that superseded revisions' flags linger in the set and that a second concurrent waiter would see a spurious failure (single-caller today).
- **Batch approval returns focus to a surviving control (`#2198`, PR `#2534`, merge `d11bd4ada`; closes `#2198`).** The opener is captured when the confirmation opens and focus is restored after success or failure to a surviving decision or queue control, with the keyboard path covered for both outcomes. Evidence: the batch-scoped and full `PaperReviewView.spec.ts` runs, typecheck, scoped ESLint; the reviewer refuted both blocker candidates — the fallback chain ends on the always-rendered queue-rail filter pills so focus never strands on `body`, and ordering against the dialog's own restore holds because `confirmationOpen` clears synchronously before the await. Four LOWs declined, including that the restore-to-opener branch is effectively dead (both outcomes clear the selection, so the PR body's "failure restores to the opener" overstates it) and that the specs drive the mouse path rather than a keydown.

Backend:
- **Bounded log truncation preserves supplementary Unicode scalars (`#1700`, PR `#2500`, merge `dffb01de8`; closes `#1700`).** Truncation is centralized so it never cuts through a surrogate pair, malformed standalone UTF-16 surrogates are removed from log values, and the Application, API and MCP logging paths are covered. Evidence: the focused `LogControlCharacterSanitizer`, `LogQueryService`, `TelemetryEventService`, `LogSanitizer`, `McpOperationLogger` and `UnhandledExceptionMiddleware` filters green; the reviewer confirmed the back-off never emits a lone high surrogate on any wired path, that strip precedes truncate in all three wrappers, that a high/U+0000/low sequence is dropped rather than rejoined, and that nothing persisted changes. This PR was stacked on the merged `#2497` branch and was **re-targeted to `main` before merging** — the eighth block's trap, avoided here. Follow-up `#2538`: `AutomationPlannerService` and `ProvenanceQueryService` still split pairs in non-log truncations. Not verified: no full backend suite.

Harness, CI and docs:
- **The worktree harness test models protected permission modes accurately (`#2400`, PR `#2533`, merge `5aa792707`; closes `#2400`).** `Test-New-CodexIssueWorktree.ps1` ignores `bypassPermissions` when it appears in project or local settings, preserves local allow rules and command-line permission-mode authority, and uses a valid `acceptEdits` local-inheritance fixture with negative controls for both protected modes at both scopes. Evidence: PowerShell AST parse, the focused headless-permission-contract case, and the full helper suite at 28/28; the reviewer confirmed the helpers contain no permission-mode logic (the model lives in the test file), that the fixture stays gitignored and uncopied, that allow-rule merging is untouched, and that the Docs Governance job's count/order coupling is undisturbed. Follow-up `#2537` carries two MEDIUMs: the negative controls only restate the in-file model, and the claim that `auto` is protected at project/local scope has no in-repo source. `scripts/git` is not a CI-control path, so this did not need the maintainer's review.
- **Container builds install frontend dependencies against a build-local npm cache (`#2472`, PR `#2536`, merge `298eb5444`; closes `#2472`).** Both `deploy/docker/frontend.Dockerfile` and the production image's frontend stage install with `/tmp/taskdeck-npm-cache` and with audit/fund network writes disabled, and the observed cacache rename race plus its bounded rerun ritual are recorded in the failure ledger. Evidence: `docker build --check` on both files, an actual frontend image build and production `frontend-build` stage build, failure-ledger renderer and sync tests 11 passed, docs governance, golden principles; the reviewer confirmed no BuildKit cache mount and no `cache-from`/`cache-to` (the release-cache contract is untouched), still `npm ci` with no lockfile bypass, and the cache directory confined to the build stage. **Reviewer's caveat, declined as a note rather than a fix:** the stated mechanism (a stale `/root/.npm` cache persisting across builds) is not supported by Docker layer semantics, so **the root cause of the cacache race stays unconfirmed** — read the change as "per-build cache plus no audit/fund network writes", and the ledger row is honestly still open.
- **Docs only:** PR `#2529` (merge `b461be49f`) records the eighth block above.
- **Not shipped reality:** open at the time of writing: PRs `#2502`, `#2506`, `#2510`, `#2516`, `#2517`, `#2518`, `#2521`, `#2522`, `#2531`, `#2532`, `#2535`, `#2541` and `#2542`. `main` at `b461be49f` had the night's **first clean completed CI run** — all seventeen reported checks completed green with `Secret Scan` skipped, unlike the red run at `17e48815e` recorded in the eighth block. Their state lives on the PRs and their issues, and `docs/releases/V0_3_0_READINESS.md` carries the release-gate view.

v0.3.0-rc.1 SHIPPED (2026-08-30, annotated tag `3fc9f6e8e` peels to `9d2ea3c7c`):
- **The public v0.3.0-rc.1 pre-release exists**, cut by the agent under the maintainer's v0.3 RC deck reply q-1 A (2026-08-30; map `map:v1:bec0a8dd…dd9138`; record `#1947`) and the repository's declared authority. The GitHub Release is `prerelease=true`, `draft=false`, published 2026-08-30T02:26:06Z with three assets — `taskdeck-v0.3.0-rc.1-win-x64.zip` (53,916,746 bytes), its `.sha256` sidecar, and `taskdeck-v0.3.0-rc.1-provenance.txt` — and a composed page (download badge first, RC banner, SHA-256, quick-start link, `## Breaking changes` lifted from UPGRADING, `## Highlights` from `docs/releases/notes/v0.3.0-rc.1.md`, grouped `## What's changed`). `/releases/latest` still resolves to `v0.2.0`.
- **Tag workflows:** CI Release 33287786328, Release Security 33287786318, Release Container 33287786267, Release Desktop 33287786253 — all four success. **GHCR:** `ghcr.io/chris0jeky/taskdeck:0.3.0-rc.1` published (`sha256:d47bdf2d…2db67`), `latest` and `0.2` both still `sha256:e4915d72…8c752`, and no `0.3` alias exists — the floating `latest` / `0.2` index digest is unchanged from the pre-tag capture (`sha256:e4915d72…8c752`) and no `0.3` alias was created, which is the live proof of `#2217`/PR `#2223` that the threat-model row was waiting for.
Expand Down
Loading