Skip to content

ci: Bump actions/upload-pages-artifact from 3 to 5 - #2

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/upload-pages-artifact-5
Open

ci: Bump actions/upload-pages-artifact from 3 to 5#2
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions/upload-pages-artifact-5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 12, 2026

Copy link
Copy Markdown

Bumps actions/upload-pages-artifact from 3 to 5.

Release notes

Sourced from actions/upload-pages-artifact's releases.

v5.0.0

Changelog

See details of all code changes since previous release.

v4.0.0

What's Changed

Full Changelog: actions/upload-pages-artifact@v3.0.1...v4.0.0

v3.0.1

Changelog

See details of all code changes since previous release.

Commits
  • fc324d3 Merge pull request #139 from Tom-van-Woudenberg/patch-1
  • fe9d4b7 Merge branch 'main' into patch-1
  • 0ca1617 Merge pull request #137 from jonchurch/include-hidden-files
  • 57f0e84 Update action.yml
  • 4a90348 v7 --> hash
  • 56f665a Update upload-artifact action to version 7
  • f7615f5 Add include-hidden-files input
  • 7b1f4a7 Merge pull request #127 from heavymachinery/pin-sha
  • 4cc19c7 Pin actions/upload-artifact to SHA
  • 2d163be Merge pull request #107 from KittyChiu/main
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [actions/upload-pages-artifact](https://github.com/actions/upload-pages-artifact) from 3 to 5.
- [Release notes](https://github.com/actions/upload-pages-artifact/releases)
- [Commits](actions/upload-pages-artifact@v3...v5)

---
updated-dependencies:
- dependency-name: actions/upload-pages-artifact
  dependency-version: '5'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github May 12, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: ci/cd. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

AlbSar added a commit that referenced this pull request May 14, 2026
…VISION + IDENTITY sync

Sprint 166 sonrası user-facing doc sync (5 paralel doc-writer agent dispatch,
Sprint 164 patterni). Ground-truth verified: 15 agents (Bug Y2 anchor),
21 skills, 27 MCP tools, 55+ CLI, 46 ADRs, 89.33% coverage, ~16,434 tests.

- docs/ROADMAP-GOD-LEVEL.md (+78/-4): Sprint 165 + Sprint 166 + Sprint 167+168
  timeline. Last update + Next audit refreshed. Sprint 167 P0 4 bug forensic
  (Bug E spawn-lock, Bug G OOM, Bug Z2 Files parser, Bug Z3 memory rebuild).
- BETA-TRACKER.md (+136 net) + BETA-TRACKER-TR.md (+104 net): Gate table
  17/20 PASS+1 FAIL → 19/20 PASS+1 PENDING. Gate #2 vitest closure via
  Sprint 165 T3. Gate #16 ADRs 46. Sprint 165 + 166 detailed summaries +
  Sprint 167+168 timeline.
- DECKENT-MASTER-BLUEPRINT.md (+110/-30): ADR-046 Step Ordering Contract
  documented (§5.1.1), Data Integrity Closure (§5.1.2 — Bug U/V/M), Living
  Docs Pipeline (§5.1.3 — Bug P/Q/W). Version 3.0 → 3.1. Sprint history
  extended.
- README.md + README-TR.md (~16 lines each): badges (tests 12485→16434,
  sprints 164→166), "What's New in Sprint 166" mini section.
- VISION.md + VISION-TR.md (+5/-5 each): **Bug Y2 critical fix** — L19
  "16 agents" → "15 agents" + extended snapshot (27 MCP tools, 46 ADRs,
  Memory V2). Sprint 165 + 166 milestone paragraphs. Phase 2 → Sprint 83-166.
- .deckent/workspace/IDENTITY.md (+13/-9): Sprint metric → sprint-166, MCP
  22→27, CLI 49+→55+, ADRs 46, Sprint 165/166 features appended.

Verify: grep -c "16 agent|test-writer" current-state assertions → 0.
Historical sprint references (Sprint 148 reform, Sprint 73/146) preserved
as factual records.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 14, 2026
…on — 17 madde fix

Sprint 168 v1→v4 zinciri:
- v1 (commit fc91fcd): brainstorming output
- v2 systematic-debugging eval (Agent A): 79/100, Phase 4.5 trigger, 5 critical/high
- v3 devil's advocate eval (Agent B): 22/100 — hedef <30 KARŞILANDI ✅
- v4 (bu commit): 17 madde fix integration
- v5 Alperen final approval bekliyor

17 madde fix entegre:
1. (Agent A #1 CRITICAL) C0e cross-sprint orphan handling — Option C selective filter + startup invocation
2. (Agent A #2 CRITICAL) C0a bundle split → C0a-1/C0a-2/C0a-3/C0a-4 (4 sub-anchor)
3. (Agent A #3 CRITICAL) C0c subscriber owner: decision-engine.ts designate + function signature + BRAIN→SPAWN:BLOCKED event mandatory test
4. (Agent A #4 + B V7 HIGH) ADR-047 Manuel Subagent Dispatch Protocol Sprint 168'de (önceki 168.5 ertelenmiş)
5. (Agent A #5 + B Saldırı #2 HIGH) Smoke test complex scenario: 3+ task (collision + crash + parallel)
6. (B V5 HIGH) Sprint 168 NO_GO → Sprint 168.5 fallback explicit (recursion paradox kabul)
7. (B V7 HIGH) TDD skip enforcement gate (skip artış 0 + Alperen review)
8. (Agent A #8 MED) checkSpawnLock singular helper eklendi
9. (Agent A #9 MED) auto_archive_directives Alperen decision NOW (spec yazımı sırasında)
10. (Agent B #5 MED) Subagent git branch isolation (worktree per cluster)
11. (Agent B #7 MED) ADR-046 invariant test C0a-2 + C0a-3 integration test
12. (Agent B #6 MED) ADR-048 multi-provider parity (Docker + Subprocess + Tmux)
13. (Agent B #4 MED) ADR-048 Wave 1.5 serial gate + Alperen CHECKPOINT
14. (P4.5 MED) Cross-cluster dependency graph spec içinde explicit (Section 2)
15. (Agent B #3 MED) Baseline tolerance "0 yeni skip" GO/NO_GO row
16. (Agent B V6 LOW) Effort yeniden tahmin 22-30h → 35h gerçekçi
17. (Agent B #1 LOW) Brain "kırık" iddiası modül-fonksiyon-satır kanıtı (Section 1)

v1 → v4 büyük yapı değişiklikleri:
- Scope 5 task → 8 task (C0a split + ADR-047 yeni)
- Effort tahmin 22-30h → 35h
- ADR sayısı 1 (ADR-048) → 2 (ADR-047 + ADR-048)
- Smoke test 2-task echo → 3+ task complex (collision + crash + parallel)
- Subagent dispatch "manuel" → "hardened (worktree + file authority + lock + TDD gate)"
- Sprint 168.5 dependency açıklama (NO_GO → manuel dispatch replay)
- Section 2 cross-cluster dependency graph yeni
- Section 3.2 (dispatch mechanism + lock pattern + TDD gate + fallback) yeni
- Section 5.3 complex smoke test suite yeni
- Pre-Flight checklist 11 → 14 madde (git worktree, dispatch locks, smoke test, Alperen auto_archive decision)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 14, 2026
… (çift hedef başarılı)

v4 üzerine 2nd round eval patch — Sprint 167 paterni gibi (v1→v5):
- v4 (72b4880): 17 madde 1st round integration
- v5 2nd round Agent A: 96/100 APPROVED ✅ (hedef ≥95)
- v5 2nd round Agent B: 26/100 SHIP_AS_IS ✅ (hedef <30 korundu)
- v5 patch (bu): 6 madde minor — 4 Agent A cosmetic + 2 Agent B clarification

6 madde patch:
1. (Agent A 2nd round #2) Section 1 — 10 bug attribution explicit per cluster:
   Cluster A 4 bug + B 1 + C 3 + D 1 + E 1 = 10 ✓
2. (Agent A 2nd round #1 CRITICAL miss) C0e scope — getActiveWorkerIds() public
   helper extract instruction (auditor.ts:2162-2168 → src/core/active-workers.ts)
3. (Agent A 2nd round MINOR-3) Section 5.1 prompt template reword —
   "Skip artış YASAK" → "Yeni test'lerde skip kullanma" daha net
4. (Agent A 2nd round Section 3.4 önerisi) GO_WTD ≤1 candidate netleştir —
   en muhtemel C0d cosmetic metrics fix
5. (Agent B 2nd round Saldırı #2) Section 5.3 — Sprint 168.5 pre-flight smoke test
   eklendi (multi-file + DB write + repo scan pattern coverage)
6. (Agent B 2nd round Saldırı #3) Section 8 — Sprint 168.5 wave split opsiyonu
   (168.5a + 168.5b auto-split threshold ≥10 task)
+ (Agent A 2nd round MINOR-4) Pre-Flight checkbox count netleştir: 16 madde

Sprint 168 eval final:
- Agent A 1st 79 → 2nd 96 (+17 puan, APPROVED ≥95 ✓)
- Agent B 1st 22 → 2nd 26 (+4 puan, SHIP_AS_IS <30 korundu ✓)
- v5 patch sonrası spec çift hedef başarılı + minor refinement

v6 Alperen final approval bekliyor — sonra writing-plans skill Sprint 168 TDD plan.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…ical docs

Sub-project #1/4 (Embedded Web Terminal) shipped 2026-05-19→2026-05-20,
operationally smoke-confirmed by Alperen. Update reader-facing docs to
reflect the delivery honestly + the four-part path ahead.

- README + README-TR: new Highlights bullet (top), link to terminal guide
- VISION + VISION-TR: extend 'Where we are now' / 'Where we are going'
  with the embedded terminal as the first concrete step toward agentic-
  OS workflows + the 3 deferred sub-projects (#2 self-security,
  #3 multi-tenant/k8s, #4 enterprise integrations) with the seams
  (AuthProvider / SessionBackend / tenantId) called out
- docs/release/roadmap.md: new 'Phase 3.6: Embedded Web Terminal' before
  Phase 3.5, with delivered checklist + sub-project #2-4 backlog
- docs/release/beta-tracker.md + -tr.md: Last-updated header refreshed
  (2026-05-14→2026-05-20); new 'Sprint 175 — Embedded Web Terminal'
  section with metrics (46/46 tests, build/pack clean), honest debt
  (node-pty linux-x64 prebuild, DECKENT_API_AUTH_DISABLED=1 dashboard
  precondition), process learnings (two durable feedback memories)
- docs/ROADMAP-GOD-LEVEL.md: new ⚡ 2026-05-20 section at the top, full
  Sprint 175 record + sub-project backlog table + Sprint 176+ priorities
- docs/adr/README.md: regenerated index (already had ADR-062/063 after
  collision rename earlier)

No exaggeration: smoke confirmed, but DECKENT_API_AUTH_DISABLED=1 is
still required for dashboard data calls (frontend general API auth
plumbing is sub-project #2/#3 scope) and node-pty linux-x64 prebuild
needs the optionalDep fix in Sprint 176. Recorded as honest debt.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…ems)

The §1d backlog had 3 items captured during Sprint 175 prep; the
post-implementation review surfaced 3 more (4–6) plus a self-security
procedure scope section for the #2 spec phase. All references checked
against current source (npm run lint:link clean):

4. Schema-gate coverage enforcement gap — coverage_threshold auto-lowers
   when avg <70%, so the gate moves with reality instead of holding the
   bar. Needs hard-floor vs aspirational split.
5. WorkerCard/DashboardPage pre-existing TS errors — TS2345 i18n
   contravariance, suppressed because root `lint` doesn't recurse into
   src/dashboard/tsconfig.json. Wire the dashboard tsc into root lint.
6. `doctor` DECISIONS.md obsolete check — Memory V2 (Sprint 143) moved
   this to memory.db; doctor still hard-requires .brain/DECISIONS.md.
   Cascade fossils across constants.ts, debt-manager.ts, sprint-docs-
   helpers.ts, authority-enforcer.ts catalogued.

Self-security scope section (sub-project #2): prompt guard, command
guard, outbound rate-limit, mutual-TLS hook on AuthProvider, self-audit-
of-audit. To be ADR'd in the #2 spec phase.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
systematic-debugging Phase 1+4.5: 5-sprint loop root cause = auto-debt-
injection (sprint-planner.ts:197-216) producing empty-scope CRITICAL
tasks; workers cannot resolve a bookkeeping artifact; re-injection 4
sprints (170→174) was the 3+ failed identical-mode fixes pattern.

Original 170-001 code verified in repo (tmux.ts:61-70, commit 5ffbf3e).
Structural cause already fixed (Sprint 138 T-13 Docker HB Core Fix).

Non-destructive DB upsert: status active→resolved, metadata.resolution
attached (1020 char honest closure). Unblocks Sprint 175 dry-run:
21→20 tasks, dependency IDs realigned (W0.1=175-001, off-by-one fixed).

Architectural follow-up (empty-scope auto-inject) deferred to sub-project
#2 per Alperen 2026-05-20.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…cts)

Caught during Sprint 175 prep, deferred to #2 per Alperen 2026-05-20:
(1) auto-debt-injection empty-scope bug — sprint-planner.ts:197-216,
4-sprint loop root cause for debt-170-001-fix; (2) re-plan orphan
cleanup — .tasks/task-{id}-*.json from prior iteration not unlinked
(today's finding: orphan task-175-021.json hand-removed).

.tasks/ is gitignored — orphan removal not in git history; spec §1d
backlog is the durable record.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
Observed during Sprint 175 EXECUTE (user reported terminal warning).
Three call-sites pass args array WITH shell:true on all platforms:
- src/core/plugin-hooks.ts:395, :577
- src/orchestra/baseline-tracker.ts:85
Node DEP0190 + ADR-006 violation + already flagged by
authority-enforcer.ts:464-481 (lint, not runtime-enforced).
Deferred to sub-project #2 per Alperen 2026-05-20.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…ical docs

Sub-project #1/4 (Embedded Web Terminal) shipped 2026-05-19→2026-05-20,
operationally smoke-confirmed by Alperen. Update reader-facing docs to
reflect the delivery honestly + the four-part path ahead.

- README + README-TR: new Highlights bullet (top), link to terminal guide
- VISION + VISION-TR: extend 'Where we are now' / 'Where we are going'
  with the embedded terminal as the first concrete step toward agentic-
  OS workflows + the 3 deferred sub-projects (#2 self-security,
  #3 multi-tenant/k8s, #4 enterprise integrations) with the seams
  (AuthProvider / SessionBackend / tenantId) called out
- docs/release/roadmap.md: new 'Phase 3.6: Embedded Web Terminal' before
  Phase 3.5, with delivered checklist + sub-project #2-4 backlog
- docs/release/beta-tracker.md + -tr.md: Last-updated header refreshed
  (2026-05-14→2026-05-20); new 'Sprint 175 — Embedded Web Terminal'
  section with metrics (46/46 tests, build/pack clean), honest debt
  (node-pty linux-x64 prebuild, DECKENT_API_AUTH_DISABLED=1 dashboard
  precondition), process learnings (two durable feedback memories)
- docs/ROADMAP-GOD-LEVEL.md: new ⚡ 2026-05-20 section at the top, full
  Sprint 175 record + sub-project backlog table + Sprint 176+ priorities
- docs/adr/README.md: regenerated index (already had ADR-062/063 after
  collision rename earlier)

No exaggeration: smoke confirmed, but DECKENT_API_AUTH_DISABLED=1 is
still required for dashboard data calls (frontend general API auth
plumbing is sub-project #2/#3 scope) and node-pty linux-x64 prebuild
needs the optionalDep fix in Sprint 176. Recorded as honest debt.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…ems)

The §1d backlog had 3 items captured during Sprint 175 prep; the
post-implementation review surfaced 3 more (4–6) plus a self-security
procedure scope section for the #2 spec phase. All references checked
against current source (npm run lint:link clean):

4. Schema-gate coverage enforcement gap — coverage_threshold auto-lowers
   when avg <70%, so the gate moves with reality instead of holding the
   bar. Needs hard-floor vs aspirational split.
5. WorkerCard/DashboardPage pre-existing TS errors — TS2345 i18n
   contravariance, suppressed because root `lint` doesn't recurse into
   src/dashboard/tsconfig.json. Wire the dashboard tsc into root lint.
6. `doctor` DECISIONS.md obsolete check — Memory V2 (Sprint 143) moved
   this to memory.db; doctor still hard-requires .brain/DECISIONS.md.
   Cascade fossils across constants.ts, debt-manager.ts, sprint-docs-
   helpers.ts, authority-enforcer.ts catalogued.

Self-security scope section (sub-project #2): prompt guard, command
guard, outbound rate-limit, mutual-TLS hook on AuthProvider, self-audit-
of-audit. To be ADR'd in the #2 spec phase.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
PR #16 main merge surfaced 3 test failures that all pass locally on the
same Node 24.15.0 runtime — pure CI environment divergence. Captured in
sub-project #2 backlog as item #7 (lokal-CI gap) with concrete fix
candidates (mock hygiene, process.kill semantics, vitest --retry tag).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…rity

Sprint 176 spec — 12 task, 5 wave, June 1 2026 beta-blocker:

A. Planner state-hygiene (W1-W3, 7 task):
   1. Auto-debt empty-scope (sprint-planner.ts:197-216)
   2. Re-plan orphan task file cleanup
   3. DEP0190 shell:true (3 call-site)
   4. Coverage hard-floor / aspirational split
   5. Dashboard TS errors + root lint wire
   6. doctor DECISIONS.md obsolete + 5-file cascade
   7. CI-only test flakes (lokal-CI divergence)

B. Self-security guards (W4-W5, 5 task — interceptor pattern, 5 new files):
   8. Prompt guard (input pattern matcher)
   9. Command guard (shell-kind deny-list, remote-only)
   10. Outbound rate-limit (daily tenant-scoped quota)
   11. mTLS hook (AuthProvider interface extension)
   12. Self-audit-of-audit (HMAC append-only chain + verify CLI)

Five non-negotiable security invariants (I1-I5):
- I1 no silent drop, I2 no raw payload in audit, I3 default-deny
  on host≠127.0.0.1, I4 append-only audit + HMAC tamper detect,
  I5 tenant-scope isolation (audit + quota + guard state).

Locked decisions: single sprint #176, structured planning, sequential
self-modifying dispatch (Sprint 175 pattern), Brain manuel wave gates
(ADR-047), non-destructive memory.db ALTER, GO_WITH_TECH_DEBT acceptable
verdict (≤2 GWT, W1-W3≥5 DONE, W4≥2 DONE).

Predecessor: PR #16 (sub-project #1, terminal, merged 2026-05-20).
Successor: sub-project #3 (multi-tenant + k8s + mTLS impl, post-beta).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…down

759-line plan covering 12 task across 5 sequential waves (W1-W5):
W1 planner P0 (auto-debt + orphan cleanup), W2 discipline gate (DEP0190
+ coverage split + CI flakes), W3 Memory-V2 cascade + frontend
(dashboard TS + doctor cascade), W4 self-security core (prompt-guard,
command-guard, outbound-limiter — I1-I3+I5), W5 self-security ileri
(mTLS hook + audit HMAC chain — I4).

Each task carries bite-sized RED->GREEN->REFACTOR steps, exact file
paths + line numbers from spec §1d, GO/NO_GO criteria, and commit
message templates. Plan also includes ready-to-paste DIRECTIVES.md
content for Sprint 176 launch via deckent_set_directives.

Refs spec docs/superpowers/specs/2026-05-21-sub-project-2-design.md.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…rift

Sprint 176 worker on task 176-001 produced a 3 KB NO_GO refuse note
documenting auto-debt-injection empty-scope failure — a live reproduction
of spec §1d.1, the exact bug W1-1 fixes. On SIGTERM the brain-honest-
gate mechanism stub-overwrote the result file to 364 bytes erasing the
forensic notes.

This document restores the original notes from the conversation
transcript + records the two concurrent dogfood bugs that triggered the
kill: (1) config.json template-regen losing spawn_backend (cascade from
PR #16 git rm --cached); (2) nervous_system.directives_protection
auto_restore rolling DIRECTIVES.md back to Sprint 175 after cleanup.

Cross-referenced in sub-project #2 plan Task 1 — to be cited in the
regression fixture for sprint-planner debt injection. Open question
captured for sub-project #2 backlog #8 (nervous_system baseline-update
hook on deckent_set_directives success).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
Sprint 176 dogfood produced 8 simultaneous failure modes (documented in
docs/audits/sprint-176/dogfood-evidence.md). The original sub-project #2
spec only addressed item 7 (planner state-hygiene + self-security); this
master spec covers all 8 + remaining feature backlog, decomposed into 4
sprints with beta-gate prioritization.

Locked decisions (Alperen 2026-05-21):
- Worker rollback = git stash --include-untracked snapshot-on-spawn;
  NO_GO drops stash + reverts worker scope writes.
- Tmux backend = deprecate. Sprint 177 marks @deprecated + warning;
  Sprint 178 removes code path.

Sprint 177 = 5 tasks (critical runtime stability):
  177-001 Worker rollback (git stash snapshot-on-spawn)
  177-002 deckent kill cascade fix (worker → controller → metadata)
  177-003 Tmux backend deprecate path
  177-004 Config template-regen guard + restore docs
  177-005 nervous_system directives_protection baseline-update hook

Sprint 178 = 4 tasks (Node 24/26 spread + tmux code removal + CI flakes).
Sprint 179 = 12 tasks (original sub-project #2 scope, references
2026-05-21-sub-project-2-design.md unchanged).
Sprint 180 = nervous defaults + dashboard + feature backlog (post-beta).

Beta gate (June 1 2026) MUST: items 1, 2, 3, 4a-b, 5 (Sprint 177) +
item 7c self-security (Sprint 179 W4-W5). Total beta-required: 10 tasks
in ~7 days, with worker rollback live from Task 177-001 onward.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
…m 6e)

Crisis Stabilization master spec missed the TOPP continuous-dispatch
work documented in memory project_topp_continuous_dispatch.md (Alperen
onayı 2026-05-19). Without TOPP, Sprint 179's 12-task sub-project #2
scope runs wave-barrier-throttled (~2-3 effective parallel slots even
with max_workers=6) putting the June 1 beta gate at risk.

Changes:
- §2 inventory: add item 6e (TOPP) — beta MUST
- §4 Sprint 178 scope: 4 task → 5 task (added Task 178-005 with full
  implementation details: result-collector.ts:380 dispatchTick flag-
  agnostic, sprint-spawner.ts:472/509/296-313 continuous body + initial
  fill, prompt-god-template.ts:291-307 TOPP C predecessor digest embed,
  DECKENT_LEGACY_FIFO=1 escape hatch, new ADR contract-first)
- §7 beta gate analysis: TOPP factored into Sprint 178 timing + Sprint
  179 day estimate (3-4 with TOPP vs 5-6 without)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
Sprint 177 CLEANUP/RETRO phase auto-generated bookkeeping:
- docs/CHANGELOG.md + docs/SPRINT-LOG.md + docs/vision/roadmap.md +
  docs/ROADMAP-GOD-LEVEL.md: Sprint 177 entry appended by sprint-docs-
  updater.
- .deckent/ci-baseline.json + features-manifest.json + provider-cache.json:
  runtime stats refresh.
- .deckent/archive/metrics/metrics-sprint-{165,167}.jsonl.gz: aged out
  per sprint_file_retention.keep_last_n=10 policy.
- .gitignore: add .tmp/ (Sprint 177 worker runtime artifact pattern;
  sub-project #2 backlog cleanup-debris #8 follow-up).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 20, 2026
Sprint 178 delivers Crisis Stabilization §4 in 35m 11s with 9 DONE +
0 debt + 2 NO_GO (auto-debt 175-020 cluster only). +965 / -131 across
src + tests + docs + 1 new ADR. Coverage 95% on TOPP impl.

Highlights:
  178-007 ★ TOPP B+C continuous-dispatch — DONE on FIX retry
    src/orchestra/result-collector.ts: NEW planDispatch(state) pure
    function (flag-agnostic, returns DispatchPlan { toSpawn, toKill,
    mode }) supersedes ADR-045 §3 wave-barrier semantics. dispatchTick
    closure-scoped async wrapper replaces dual await processQueue +
    maybeRespawn sequence. 440-line G1-G10 test matrix.
    docs/adr/064-topp-continuous-dispatch.md (NEW): ADR contract first.

  178-003 Node 24/26 test assertion sweep — DONE
    4 test files: publish-workflow.test.ts, publish.test.ts, install-
    matrix/fresh-install.test.ts ('22.x' → '24.x', NODE_VERSIONS
    [18,20,22] → [24,26], engines.node >= 24), release-prep.test.ts.

  178-004 Doc updates Node 24/26 yayılma — DONE
    docs/guide/{deckent-nedir,getting-started,quickstart}.md +
    docs/CHANGELOG.md + docs/SPRINT-LOG.md engines refs.

  178-005 Tmux removal — DONE on FIX retry
    src/core/multi-ide.ts + orphan-cleaner.ts + src/orchestra/
    heartbeat-daemon.ts + sprint-phases.ts + sprint-pid-manager.ts
    tmux import refactoring. (tmux.ts file deletion deferred — Sprint
    179 follow-up; spawn_backend type narrowing partial.)

  178-006 CI flake fix — DONE
    tests/cli/archive-debt.test.ts (mock factory hygiene) +
    tests/core/orphan-cleaner-ipc.test.ts (PID liveness mock).

Auto-debt outcomes:
  178-002 (ADR-019 reconciliation) — DONE on FIX retry. ADR-019
    "Language-Agnostic Worker Verify" finally implemented (docs/adr/
    019 updated). Long-standing CRITICAL debt closed.
  178-001 (debt-175-020-fix verification gates) — NO_GO + NO_GO retry.
    Root fix is Sprint 179 W1-1 (auto-debt empty-scope inheritance);
    worker rollback (Sprint 177 Task 1) ensured src/ stayed clean
    despite repeated empty-scope dispatch.

Brain dispatch behavior observations (Sprint 179 backlog candidates):
  - FIX retry result not propagated to main task verdict in event
    stream (sequence 35-83 showed 22 minutes of stale dependency
    states); CLI aggregate summary correctly shows DONE for
    178-002/005/007 even though sprint-state.json kept original
    NO_GO. User flagged: "ana worker NO_GO ama fix DONE = doğru akış
    iletişim kanalları."
  - Brain re-evaluates DONE tasks during FIX phase (DONE → fix retry
    spawn). User confirmed this is intentional ("Brain done işleri
    tekrar dürüstçe değerlendiriyor, dokunmayalım").
  - DIRECTIVES Dependencies field plan-slot vs disk-task-ID mapping
    drift when auto-debt prepends (178-005 misrouted to auto-debt
    178-002 instead of plan-slot Doc updates).

Verdict: 9 DONE + 0 debt + 2 NO_GO → CLI shows full GO assessment
(verdict matrix per DIRECTIVES would normally call this NO_GO due
to "Task 5 fails outright" but the FIX retry closed 178-007). Sprint
verdict acceptance per Brain auto-evaluation.

Crisis Stabilization §4 closed. Sprint 179 (sub-project #2 original
12 task + 1 Bug A fix) ready to spec.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 21, 2026
…Bug A foundation

Sprint 179 deliverables (modified files; new src/ files lost due to uncommitted state — recovery in Sprint 181):
- Bug A foundation: aggregate verdict + DEPENDENCY_RESOLVED_BY_FIX event channel + planDispatch aggregate-aware + buildDependenciesBlock dual digest (src/orchestra/result-evaluator.ts, event-stream.ts, result-collector.ts, prompt-god-template.ts)
- Self-security W4-W5 modifications: audit.ts, auth-provider.ts, session-manager.ts, types.ts, ws-gateway.ts (Sprint 179 hooks live, but interceptor src/api/terminal/{audit-integrity,command-guard,prompt-guard,outbound-limiter}.ts + src/cli/commands/audit-verify.ts deleted — Sprint 181 recovery)
- Planner state-hygiene W1-W3: sprint-planner.ts (auto-debt scope inherit + orphan cleanup), coverage hard-floor/aspirational split, doctor Memory-V2 cascade, dashboard TranslatorProp split, DEP0190 shell:true fix
- Quality assessor coverage parse (Sprint 180 W4-1)

Sprint 180 deliverables (survivors):
- Nervous Faz 1 partial: ipc-queue.ts (W2-2) + 7 nervous tests (bootstrap, action-handlers, integration-runtime, ipc-queue, directives-protection-auto-restore, faz1-smoke, accept-panic)
- Worker .result coverage zorunluluk (W4-1): worker-verify.ts vitest --coverage parse
- npm publish v1.0.0-beta.1 readiness scripts/validate-publish.mjs
- Nervous user guide kısa giriş: docs/guide/nervous-system.md
- OSS GA docs: README, installation, quickstart, getting-started

Critical incident: Sprint 179 NOT committed before Sprint 180 launch.
Worker-rollback.ts (Sprint 177 deliverable) git stash --include-untracked + git stash drop
cycle deleted Sprint 179's uncommitted NEW src/ files (5 self-security + 2 nervous core).
Modified tracked files survived. dist/ build intact (runtime functional).
Root cause memory: feedback_post_sprint_commit_mandatory (NEW, to add).

Recovery plan: Sprint 181 — TDD re-write of lost deliverables from
docs/superpowers/plans/2026-05-21-sub-project-2.md (sub-project #2 plan) +
dist/ runtime behavior reference + Sprint 180 NO_GO/GWT closure.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 21, 2026
…start + worker-rollback fix

Sprint 180 GO_WITH_GATE_FAILURE root cause analysis:
- 4 DONE / 8 GWT / 8 NO_GO verdict
- 5 TS2307 errors (audit-integrity, command-guard, prompt-guard, outbound-limiter, audit-verify)
- 7 src/ files deleted by worker-rollback git stash --include-untracked + drop cycle
- Sprint 179 NOT committed before Sprint 180 launch → uncommitted deliverables lost

Sprint 181 scope (16 task, 6 wave):
- W0 P0: worker-rollback untracked-safe (scope-bounded stash + archive + pre-spawn guard)
- W1 (5): self-security recovery — audit-integrity, command-guard, prompt-guard, outbound-limiter, audit-verify
- W2 (2): nervous core recovery — bootstrap, action-handlers
- W3 (5): Sprint 180 NO_GO/GWT closure — state-tracker, smoke config, gate fix, npm publish, integration
- W4 (1): NERVOUS-TODO.md restore from mirror
- W5 (2): beta launch smoke v1.0.0-beta.1 + Sprint 181 retro + Sprint 182 stub

Locked decisions:
- W0 SEQUENTIAL FIRST blocker (W1+ ancak W0 DONE sonrası)
- dist/ runtime reference KORUNUR (npm run build only at W5-1)
- Recovery 3-source: dist/.js + sub-project #2 plan §Task NN + Sprint 179/180 retro learning
- memory.db schema ALTER YOK (Sprint 179'da uygulanmış intact)
- Post-sprint commit ZORUNLU (feedback_post_sprint_commit_mandatory)

Beta gate: June 1 2026, ~10 gün, Sprint 181 son beta-blocker.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 21, 2026
…er-rollback untracked-safe fix

Manual recovery (Claude Code) after Sprint 180 worker-rollback deleted 7 uncommitted
src/ files via git stash --include-untracked + drop cycle. Source: dist/ runtime build
+ sub-project #2 plan + Sprint 179/180 retro learning.

Recovered src/ files (7):
- src/api/terminal/audit-integrity.ts (HMAC chain, I4)
- src/api/terminal/command-guard.ts (default-deny remote, I3)
- src/api/terminal/prompt-guard.ts (input pattern, I1+I2)
- src/api/terminal/outbound-limiter.ts (tenant quota, I5)
- src/cli/commands/audit-verify.ts (CLI tamper detect)
- src/nervous/bootstrap.ts (createNervousSystemIfEnabled)
- src/nervous/action-handlers.ts (4 MVP action handlers)
- src/orchestra/sprint-state-tracker.ts (Sprint 180 W1-1)

Worker-rollback Sprint 181 untracked-safe fix (src/agents/worker-rollback.ts +99 LoC):
- snapshotWorkerScope: scope-bounded git stash via pathspec (no more sweep of
  out-of-scope untracked files)
- Pre-spawn guard: collectOutOfScopeUntracked + onWarn callback
- dropWorkerSnapshot: archive folder write before drop (.deckent/worker-rollback-history/
  {sprintId}/{taskId}/stash-{iso}.patch, 7-sprint TTL)
- NOSTASH sentinel: empty-scope stash skip
- rollbackWorkerScope: per-path checkout iteration (untracked-tolerant)

Test recovery (5 + 1 new untracked-safety + 1 sprint-state-tracker):
- tests/api/terminal/audit-integrity.test.ts (5 case, I4 invariant)
- tests/security/prompt-guard.test.ts (6 case, I1+I2)
- tests/security/command-guard.test.ts (12 case, I3)
- tests/security/outbound-limiter.test.ts (4 case, I5)
- tests/orchestra/dependency-aggregate-fix-aware.test.ts (5 case, Bug A foundation)
- tests/agents/worker-rollback-untracked-safety.test.ts (5 case, Sprint 181 P0)
- tests/orchestra/sprint-state-snapshot.test.ts (3 case, Sprint 180 W1-1)

NERVOUS-TODO.md restored from /home/alperen/.claude/plans mirror (540 lines, 31KB).

DIRECTIVES.md: Sprint 181 deferred for manual recovery; new Sprint 181 (post-recovery
continuation work) will be specced after this commit lands.

tsc --noEmit: exit 0. vitest sweep: 16785/16845 pass (5 pre-existing failures in
Docker e2e + cli/run, scope-out).

Memories: feedback_post_sprint_commit_mandatory, project_worker_rollback_untracked_bug.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request May 26, 2026
`.cursor/` `.codex/` `.gemini/` adapter audit dokümanına kapanış kaydı:
- Commit Geçmişi tablosu (3a2f06e, e45ffbe, 5646520, 685e65c, 9a353a4)
- Doğrulama özeti güncellendi
- Kapanış bölümü: 7 sorundan 6'sı düzeltildi, kalan maddeler izleniyor
- Gelecek Öneriler #2'ye "Part 2" (DECKENT.md agent-rolleri redesign'ı —
  Alperen kararıyla ertelendi) notu
- README indeks açıklaması güncellendi

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 3, 2026
…status anchor + queue preview

Closes the orientation findings (Alperen live test):
- #1 visible cursor: InputBar renders an inverse-video caret → you always SEE
  where you are. Reuses the tested editInput reducer + InputHistory.
- #4 arrow keys: ←/→/Home/End move the cursor, ↑/↓ walk history, Backspace/
  Delete/Ctrl-A/E/U edit — full line editing (was append-only).
- #2 'working vs done': a PERSISTENT status anchor above the input shows the
  phase every frame — ⠋ düşünüyor… / üretiliyor… (animated, so a mid-reply
  network pause still reads as 'working') / ✓ hazır · sıra sende when idle.
- #3 queue visibility: queued continuation prompts render as '⋯ kuyrukta N: …'
  previews while busy (was invisible).

InputBar owns input only while active (isActive=false during the confirm modal);
batched/pasted Enter is split so completed lines submit. PTY-harness verified
(scripts/ink-pty-test.mjs now supports <LEFT>/<CR>/<BS> tokens): edit + reply +
clean exit code 0. i18n: tui.generating/ready keys. Opt-in DECKENT_INK=1.
tsc+build+tests/cli green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 9, 2026
… starts immediately)

Sprint start ran the FULL vitest suite TWICE before SPAWN (~400s combined),
blocking start with no user value (block_on_test_fail=false → didn't even gate):
 1. captureVitestBaseline (sprint-controller Phase 1.9, 180s) — honesty baseline.
 2. ci-guardian pre-sprint vitest (runPreSprintValidation, full suite, the
    "vitest had N failures" warning).

New `pre_sprint_tests` config flag (default FALSE) gates #1; sprint-phases now
passes `{track_test_count:false}` to runPreSprintValidation (uses its existing
configOverride param) to skip #2 while KEEPING the fast tsc gate. Both default-off
→ sprint starts immediately. Honesty verify-delta degrades gracefully without a
baseline; opt back in with `pre_sprint_tests: true`.

Zero test churn (new flag default-false + existing configOverride; no
DEFAULT_CI_GUARDIAN_CONFIG change). 215 config/ci/ci-pre-sprint tests green; tsc
clean. Surfaced live during the Sprint 255 dogfood ("sprintler çok geç başlıyor").

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 9, 2026
… live engine (gaps #1+#2)

Closes the top-2 dormant seams from docs/analysis/deckent-capability-maturity.md §5:

Seam #1 — reenqueueRecurring → runtime loop (AUT-5 end-to-end):
- backlog.ts: queryDue now surfaces pending recurring entries (cadence is
  gated at flip-time by reenqueueRecurring; pending recurring = due now);
  new applyRecurringReenqueue persists the done→pending flip atomically
  only when something changed.
- runtime-loop.ts: buildEngineRuntime's backlog loader applies the
  recurring re-enqueue on every tick — a recurring entry now fires at
  each cron cadence instead of dying after its first run.
- CLI/MCP user surface: `deckent autonomous backlog add --cron <expr>`
  + MCP `cron` param create recurring entries; malformed cron rejected
  at intake via core nextRun (i18n en/tr: autonomous.backlog.invalid_cron).

Seam #2 — makeWorkGeneratorSource → trigger composition (AUT-9 live):
- runtime-loop.ts: optional generateWork producer composes a
  work-generator trigger source at the LOWEST priority; candidates are
  enqueued into the backlog first (execute-dispatcher's status writeback
  requires the entry to exist) via new backlog.enqueueCandidates
  (any-status id dedupe, validation, fail-safe).
- work-generator-source.ts: makeDebtWorkGenerator — production producer
  mapping ACTIVE Memory-V2 debt records to candidates (HIGH/CRITICAL →
  risk-tagged), SQLite scans throttled to work_generator.interval_ms.
- Flag-gated config: autonomous.work_generator { enabled: false,
  interval_ms: 600000 } + validation; CLI handleStart wires the producer
  only when enabled (backward-safe, default-off).

Honest gap left explicit: todoMarkers half of WorkGeneratorInput has no
production scanner yet — debt records are the only live feed.

TDD: 19 new tests (engine-wiring 6, backlog 7, debt-generator 5 + cron
CLI 3, config 4); tsc clean; 285 targeted tests green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 11, 2026
…dy-read verified

- 040 [BOTH]: S279/280 behavior evolution recorded — approve-mode 10s panic-gate
  timeout (SAFETY_FLOOR exempt), edit end-to-end live (modifiedPayload), cross-
  process approval round-trip; detectors 5→12; safety-floor/presets/30-actions verbatim ✓
- 041 [BOTH]: taxonomy verified (15 agents, no test-writer, 0.40 threshold);
  distribution-goal reality: chronic refactorer relapse → ADR-072/075 mitigations
- 042 [BOTH]: task-mode now the autonomous engine's execution primitive (5 live
  consumers); THIRD MODE direction recorded — process (ADR-067 proposed; Alperen:
  'sprint' not universal + task-mode not agentic); style≠surface (ADR-081 REPL)
- 043 [BOTH]: 3 layers re-verified (boot-wired crash handlers, atomic checkpoint,
  restore); battle-tested (S267 sleep-crash 6/6, S270 WSL-VM crash)
- 044 [BOTH]: 4 call-sites re-verified (current lines); known gap — dashboard
  .dashboard snapshot stale post-finalize (UX-audit finding #2, product-sprint)
- 045 [BOTH]: dogfood FLIP false→true LIVE-PROVEN (S279/280 multi-wave);
  dependency-satisfying set = DONE ∪ MANUAL_REVIEW_REQUIRED (S280 9f966ee);
  DECKENT.md:52 stale 'deckent-dev false' claim fixed

memory.db synced, exports regenerated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 11, 2026
…dy-read verified

- 062 [BOTH]: sub-project #2 DELIVERED (4 guard modules: command/prompt-guard,
  outbound-limiter, audit-integrity); security invariants verbatim (AUTH_DISABLED
  deliberately ignored + timingSafeEqual); @lydell/node-pty rename; LIVE proof
  (UX-audit token auto-mint); known UI overlap bug → product-sprint
- 063 [BOTH]: consent pattern became reusable anchor (S270 F1-IMG --fix-image
  cites this ADR); 23 tests verbatim; numbering gaps explained (reserved slots)
- 064 [BOTH]: behavioral contract LIVE (dispatchTick + LEGACY_FIFO escape,
  S279/280 proof) BUT planner-bypass found — planDispatch pure-planner is
  tested-but-unwired (dispatchTick doesn't call it; :180 comment wrong) → ADR-064-W
- 065 [BOTH]: sync-to-product verified; audits-immutability is registry-exclusion
  (not literal path-guard — never register docs/audits); axis clarification vs
  MOD-SPLIT (develop/product ≠ community/enterprise); active migration mechanism
- 066 [BOTH]: resolver lives in task-types.ts; INVARIANT-DRIFT ?? 'claude' 3→9
  → ADR-066-W; S248-254 evolution recorded (host-adapters + OAuth mounts +
  ProviderCommandSpec + billing-follows-auth supersede the API-key-only auth table)

MASTER-PLAN: + ADR-064-W (planDispatch wire), ADR-066-W (claude-fallback re-audit).
memory.db synced, exports regenerated.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 13, 2026
…rame throw (SP-1 M2p2a review)

Final-review findings #2 (collision-free synthesized ids for id-omitting OpenAI-compat backends) + #4 (Anthropic mid-stream error frame must throw, not silently complete as success — CLAUDE.md no-silent-failure).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 13, 2026
…r persist (SP-1 M2p2b review)

Opus combined-review follow-ups: #1 cancel() breaks the per-call loop so a later auto-tier tool in the same batch cannot run; #2 a self-modifying-elevated call never persists a session/always grant (each deckent-source write re-confirms — the guard's intent is preserved). Tests: elevated-non-persist, cancel-stops-later-auto-tool, ordering-B (requestPermission parks first).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 13, 2026
…d assertion (M3 review)

Final-review findings: #2 dist-missing must SKIP→exit 0 (header/sibling consistency, no pre-build false-red); #3 tighten confirm-card assertion to the strict 'y = allow'/'y = izin' form.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 15, 2026
…ommand, not a JSON edit)

JSON-edit yerine tek komut: autonomous.enabled=true'yu project config'e yazar (diğer
key'leri korur, hermetik — global config okumaz), güvenlik-sözleşmesi banner'ı basar
(RBAC→policy→risk; onay-gerektiren/risk-etiketli PARK eder; yıkıcı sessiz-çalışmaz).
Default OFF korunur (kasıtlı opt-in). autonomous.disabled mesajı da `enable` komutuna
yönlendirir. i18n en/tr, TDD 2 test, tsc temiz, 30 ilgili test yeşil.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 15, 2026
…e [--mode]`

Autonomous'a paralel: tek komutla nervous_system.enabled=true + opsiyonel authority
preset (strict|balanced|autopilot|full-auto), diğer config key'leri korur. Default OFF
korunur, authority default 'balanced' (orta/yüksek-risk→insan-onayı, 5 safety-floor hep
açık-onay). Geçersiz preset reddedilir (enable etmez). Güvenlik-sözleşmesi banner'ı +
i18n en/tr. TDD 3 test, tsc temiz, 21 ilgili test yeşil.

make-usable batch #2 (autonomous+nervous one-command enable) TAMAM.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 15, 2026
…oval codes, bot chat grounding

From Alperen's live dogfood feedback (nervous-on sprint-289):

#1 Stale-worker false-positive noise (was: WORKER_RESPAWN spam on DONE workers)
  - sprint-state-tracker: a worker that has written its .result is FINISHED, not
    active — its .hb is never deleted so it ages out and read as 'stale'. Exclude
    such .hb from activeWorkers at the source (every consumer benefits).
  - stale-worker detector: default threshold 3min → 10min (finished workers are
    already excluded; this is only for a genuinely-hung ACTIVE worker, so don't
    flag a long tool-call early). Configurable via stale_worker.threshold_ms.

#2 Bot chat quality (3/100): the conversational path grounds the persistent claude
   session in NOTHING but tool directives. buildBotSystemPrompt() now injects the
   live project context (.brain/exports/summary.md, bounded) + a 'be an accurate
   deckent-expert, do not make things up' instruction. Volatile state stays
   tool-driven (deckent_status), never baked into the prompt.

#3 Short approval codes: nervous notifications showed a full UUID — typing
   'approve <uuid>' on a phone is torture. Proposer now mints a deterministic
   5-char shortCode per notification; every operator surface (Telegram message,
   deckent status/watch, CLI/REPL nervous accept) shows + resolves it. Also fixed
   a real gap: connector-notify-adapter never rendered notification actions, so
   the Telegram message now carries the copy-pasteable approve/reject command.

Follow-up to f326a68: narrow isObserverNoiseFile to ONLY self-cascade files
(ERRORS.md/nervous-*/metrics/events.jsonl). .hb + sprint-state.json are written by
the worker/controller, never self-cascade, and are useful debounced triggers — so
they're no longer filtered (restores the observer-phase-guard contract).

tsc clean; nervous+connectors 575/575 green (incl. new tests for each fix).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 16, 2026
…ent tasks

Structural floor: an economy-tier model (haiku family — haiku, gpt-5-mini,
gpt-4.1-mini, gemini-2.0-flash) may ONLY run a document-write / audit task.
A code-development task (anything touching source, incl. in-code i18n string
work) can never auto-default to economy — the router upgrades economy→standard
(provider-appropriate) unless the user explicitly pinned the model (forceModel).

Live proof (Sprint-283): the FIX-router misrouted a tsx-i18n task to haiku +
doc-writer; CC caught it pre-spawn. This guard re-asserts the floor in both
model-finalization paths.

- New shared guard: src/core/model-tier-guard.ts (enforceModelTierGuard,
  isEconomyAllowedForKind, isCodeKindString). Pure, deterministic,
  provider-agnostic via model registry; English diagnostic reasons (mechanism
  module, no i18n binding). Self-contained scope→kind classifier (no orchestra
  import — ADR-008).
- Wire #1+#3 (routing/planner default + brain model): resolveTaskModel
  (model-selector.ts) guards the auto-selected model before return. forceModel
  paths return early (Layer 0) = explicit override honored. sprint-planner.ts:414
  / decision-engine.ts:169 inherit the guard transitively (no planner-smoke edit).
- Wire #2 (FIX/reroute): mid-sprint-adapter.applyReroute re-asserts the floor
  using task.type + task.scope, honoring task.forceModel.

TDD: 16 guard-unit tests + 5 reroute tests; updated 6 stale tests that pinned
the old (buggy) economy-on-code behavior to assert the new floor (+ added
doc-scope economy-allowed and explicit-override-honored cases).

Verify: tsc --noEmit clean; tests/core + tests/orchestra green (655 files,
11242 tests, 0 fail).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 19, 2026
… MCP-table drift/dup

#1 ensureDeckentImport: was forcing @DECKENT.md auto-load back whenever the
literal `@DECKENT.md` was absent — which reverts a deliberate on-demand
"see DECKENT.md" reference (e.g. the CLAUDE.md context-trim) on the next
`deckent sync`. Now reference-aware: ANY mention of DECKENT.md satisfies the
requirement; only prepend the @-import when there is NO reference at all.
Backward-compatible (existing @DECKENT.md files unchanged). +1 test.

#2 DECKENT.md: the inline "MCP Tool Reference" table had drifted to 33 rows vs
the canonical 35 (missing deckent_usage + deckent_process) despite the file's
own note that the list is auto-generated. Replaced the hand-table with a pointer
to docs/reference/mcp-tools.md (single source). De-duped the agent/skill name
enumeration (already in the Built-in Agents/Skills sections) to a pointer. -38/+21.

53/53 affected sync/utils tests green; no test asserts DECKENT.md table content;
tsc --noEmit clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 24, 2026
…t (B-SENTINEL-CLOBBER)

Lifecycle-robustness #2 (sprint-323). writeHonestSentinelResult wrote a
worker-crashed-no-result NO_GO sentinel whenever a .result was absent — but
absence is NOT a crash when the sprint was already finalized and the result moved
to .brain/archive. sprint-323: finalize --force archived 26 real results, then a
late honest-gate pass (orphan RETRO) overwrote them with brain-honest-gate NO_GO
sentinels, destroying the true verdicts (the committed code work survived only
because the sentinel touches .result, not src).

Fix: writeHonestSentinelResult is now a NO-OP when a real result already exists —
either in .tasks (worker wrote one) or archived under .brain/archive/sprint-*-tasks/
(sprint finalized). New archivedResultExists() scans the archive. The genuine
crash case (no result anywhere) still writes the sentinel (Scenario-c preserved).

Faithful: stub-eradication tests — sentinel does NOT clobber an existing .result
(stays DONE/w-real) nor write over an archived result; pre-fix both were
clobbered. tsc=0; tests/orchestra pass. Build deferred to end of P0 batch.

Part of LIFECYCLE-ROBUSTNESS-FIX-PLAN.md (P0-B of 3).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 26, 2026
…n spec

Turns the confirmed #2 wiring gap into an implementable flag-gated plan
(DESIGN-ADR-075-AFFINITY-REORDER.md): reorder routeTaskV2 to skill-first so
selectBestAgent can build the affinity context, gated by routing.skill_agent_affinity
(default-off → byte-identical), with faithful test plan + routing-balance gate.
Bundles with iter-2 agent-cache finding. Implementation attended-defer.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 26, 2026
…l matrix)

The token counter never worked because deckent captures the worker's final-text
stdout, not the provider's usage — which lives in each provider's NATIVE source, not
stdout. Gap spans MULTIPLE providers + classes (claude+codex buildArgs lack a
usage-emit flag; gemini already has --output-format json; API workers default 0/0) —
a Claude-only fix is wrong (Law #2).

Design grounded in proven references: tokscale (per-provider native session-store
extraction → one schema), LiteLLM (normalized usage + completion_cost across 100+
providers), Vercel AI SDK (rich LanguageModelUsage schema w/ cache+reasoning detail),
Hermes/OpenClaw (API side via OpenRouter unified gateway). Provider matrix in 4
usage-source classes (A session-store CLI · B HTTP-response API · C unified gateway ·
D SaaS web-API). Contract: each adapter's extractUsage reads its class's native
source; one rich normalized schema (add cacheWrite+reasoning); cost via pricing table;
gateway-first (OpenRouter) for the API side. Verified per-provider, full-matrix.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 26, 2026
… (sprint-328 dogfood)

Implements the design (docs/.../2026-06-26-provider-agnostic-usage-cost-design.md) so
EVERY provider surfaces real token usage from its NATIVE source — NOT a Claude special
case (Law #2). deckent dogfood, 6/6 DONE (5 DONE + 1 TECH_DEBT), tsc=0, suite green:

- token-usage.ts: rich normalized schema (added cacheWriteTokens + reasoningTokens,
  AI-SDK parity).
- Class-A CLI-agents: claude (subprocess.ts usageEmitArgs --output-format json +
  claude.ts extractUsage), codex (CODEX_USAGE_EMIT_ARGS --json + token_count parse,
  same shape as its /sessions/*.jsonl native store — tokscale pattern),
  gemini (verified --output-format json → usageMetadata incl. thoughts=reasoning).
- Class-B API: agentic-worker-entry accumulates response usage across the loop →
  result.tokenUsage (ollama/openai-compatible/bedrock; replaces zeroTokenUsage).
- Class-C gateway: openai-compatible parses OpenRouter normalized usage (cache+reasoning).

CC fix: codex.test.ts spawn assertion updated for the appended --json (the codex task
left it as TECH_DEBT). Full affected suite 7367 green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jun 27, 2026
…rk (16/16, 0 NO_GO)

Track A (sprint-330 fixes): error-convention (3 generic throws → DeckentError DECKENT_E072/E073),
opus outputTokens:null robust capture, KPI live-backfill (1067 measurements from 96 sprints).
Track B (Beta): F1-012 provider-registry de-hardcode (Law #2 PASS — unknown fails honestly),
F1-014r auth non-leak, codex token parity, Dockerfile.worker ship, B-HANDOFF/B-ZOMBIE hygiene,
KPI Faz-2 surfaces (deckent_kpi MCP tool, /api/kpi, kpi --trend).

Independent verification: GO_WITH_TECH_DEBT. Regen IDENTITY/README stats (new MCP tool count).
3 KPI bugs found for sprint-332: (1) `deckent kpi` no-arg returns sprintId:null (no fallback to
latest finalized sprint) — proof-of-function blocker; (2) forward-collection doesn't fire at
finalize (recordKpiMeasurements); (3) cost/token KPIs=0 (backfill has no per-task telemetry).
Backfill itself verified working (kpi --sprint <id> → 8 real KPIs).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 1, 2026
…nnels + born-427/428 closed + docs

Second consecutive perfect sprint (15/15 DONE, 317/317 verify, tsc=0):
WLT emit+reader (flag-gated progress-stream) · telegram/terminal/nervous approval
channels · rollback wire-or-kill decided+completed · spawnlock TOCTOU closed ·
doc-pillars disk-verified · WM-7 language penalty (gated) · corpus-lint ·
'deckent do' golden-flow command · app approval wiring (sub-flag) · approval
config load · post-sprint smoke chain audited.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 7, 2026
… — sprints/ + directives/

Alperen'in archive-reorganizasyonu (202 sprint-klasörü → archive/sprints/, 173 DIRECTIVES →
archive/directives/, retro'lar+pid-üçlüsü silindi) koda bağlandı:
- Yazıcılar yeni-hedefe: task-arşivi + DIRECTIVES-arşivi + orphan-hb + orphan-pid/snapshot +
  cleanup log-arşivi (constants: ARCHIVE_SPRINTS_SUBDIR / ARCHIVE_DIRECTIVES_SUBDIR)
- Okuyucular yeni-öncelik + eski-düz-yerleşim FALLBACK (mevcut kullanıcı-projeleri kırılmaz —
  Yasa #2): archivedResultExists, sdk getSprintArchive, finalize, series-metrics.mjs
- restore-quirk test-yolları yeni-düzene

Verify: arşiv-aile testleri 11/11 + finalize/sdk/series 184-test yeşil; tsc + build temiz.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 10, 2026
…ions wiring (prefix-stable cache)

Anthropic'in prefix-instability için sevk-ettiği bayrak: per-machine bölümler
(cwd, env, memory-paths, GIT STATUS) default system-prompt'tan ilk-user-mesajına
taşınır → system-prompt PREFIX byte-stabil kalır. GERÇEK kazanç (dürüst): CLI
worker'lar prompt-cache PAYLAŞMAZ (memory: worker_prompt_cache_finding) → bu
CROSS-WORKER cache-read DEĞİL; asıl fayda git-status'un her commit'te değişip
mid-sprint whatever-cache-applies'ı (single-session/subscription) invalidate
etmesini durdurması. Bayrak yalnız default-prompt'la çalışır (deckent hiç
--system-prompt geçmez) ve yalnız claude'da (v2.1.204 --help doğrulandı).

Wiring (Law #2 — 4 claude-arg builder tutarlı, drift yok):
  • provider-command-spec: ProviderCommandSpec.excludeDynamicPromptSectionsFlag
    (claude=flag, codex/gemini=null) + buildProviderCommand emit (docker + spec).
  • CLAUDE_SUBPROCESS_CONFIG.buildArgs + buildCommandString.
  • ClaudeProvider.buildCommand (subprocess + tmux branch).
  • tmux buildProviderWorkerCommand (claude branch).
Config: PromptConfig.exclude_dynamic_system_prompt_sections (default TRUE) +
DEFAULT_PROMPT_CONFIG + boolean-validation. Opts: ProviderSpawnOptions +
tmux SpawnOptions .excludeDynamicPromptSections; sprint-spawner her spawn-path'e
config-global değeri geçirir (adapterRouted/effectiveBackend/tmux, iki fonksiyon).

Provider-agnostik guard doğrulandı: codex/gemini opts-set olsa bile flag ASLA
emit edilmez (spec-flag=null). Test: +5 (spec claude ON/OFF + codex/gemini-null;
subprocess buildArgs/buildCommandString). tsc 0-hata, 366+144 test yeşil.
Canlı-binary smoke ayrı adımda (default-on doğrulaması).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 10, 2026
A fresh `deckent init` project (or root-only README+LICENSE repo) has ZERO
tracked directories, making the invented-dir rule unsatisfiable for every
nested path: git ls-files exits 0 with empty stdout, the gate still ran, and
every first-sprint src/ task hard-blocked without --force-scope (Law #2,
REPRODUCED red-first in tests).

Posture per Alperen (2026-07-10): Advisory-WARN. Predicate is structural, not
a threshold: trackedDirs.size === 0 — exactly the condition under which the
rule has no signal (extends the literal "0 tracked files" wording to root-only
repos with the same rationale; advisor-endorsed, flagged here).

- scope-gate.ts: greenfield classify -> new-plausible with honest reason;
  additive ScopeGatePass.greenfield/greenfieldNotice (only when >=1 write was
  unvalidated). Wrong-dir rule untouched (self-disabling via empty byBasename).
- sprint-controller.ts: surfaces the notice on BOTH channels per the
  sprint-finalizer advisory precedent — SCOPE_GATE_GREENFIELD_ADVISORY event
  (MCP/bot/dashboard see it) + one console.warn line (CLI).
- Bonus (same classify() fix): worker prompts in root-only repos no longer
  label every nested file "Unverified ... STOP+NO_GO" (mass-NO_GO noise);
  they label "New — expected to create". Twin reproduce test added.

Verify: scope-gate 13/13 + pcomp 14/14 (5 new tests, 2 written RED-first),
sprint-controller/debt-integration/scope suites 216/216, tsc EXIT 0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 10, 2026
…gistry (born-549 generalized)

Daemon side of the Electron desktop shell (approved blueprint, phase B1):

- src/api/serve-daemon-meta.ts: .deckent/serve-daemon.json handshake file —
  atomic temp+rename, mode 0600 re-asserted against umask (carries live API +
  terminal tokens, gitignored). Readers treat it as a HINT: adopt only after
  pid-ownership + /health identity verify (stale-after-crash is by design).
- server.ts: /health gains loopback-gated identity fields (version/pid/
  projectRoot/terminalEnabled) for the adopt-vs-spawn decision — remote
  callers keep the exact minimal body (no new fingerprinting surface).
  HttpApi.apiToken exposes the resolved bearer token (additive).
- serve.ts: writes the handshake on startup (fail-soft i18n warn), clears it
  on shutdown — which surfaced a REPRODUCED pre-existing bug:

FIX (advisor variant-B): every command-level process.on(SIGINT/SIGTERM)
listener is dead code — entry.ts's bootstrap onSignal wins registration order
and exits synchronously, so serve's graceful api.close() never ran on a real
signal. born-549's REPL teardown registry is generalized into cycle-free
src/cli/helpers/shutdown-hooks.ts; onSignal awaits it (bounded 5s, settle-all,
no-hook sync fast-path preserved); registerReplTeardown stays as alias (REPL
call sites + sigterm-teardown.test.ts untouched). serve registers
clear-then-close (sync clear first — a hung close can never block it).
Remaining 5 dead-listener commands (nervous/chat/flow/heartbeat/dashboard)
filed as born-587.

Verify: real-binary REPRODUCE proof (pre-fix SIGTERM left stale handshake ×2;
post-fix SIGTERM ✓ + SIGINT ✓ cleared + clean exit). 15 new tests; both signal
suites unmodified-green (4+13); serve.test.ts's 3 dead-behavior tests
rewritten intent-preserving + strengthened (negative listener assert,
clear-before-close order, clear-survives-rejection). tests/api 900/900,
targeted 49/49, tsc EXIT 0. tests/cli's 42 latent reds reproduce on clean
HEAD (pre-existing family #2, untouched).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 10, 2026
…rd-isolation pattern)

- src/desktop/: package.json (private, electron 43 + electron-vite 4 +
  electron-builder + @playwright/test, all desktop-scoped — root publish tree
  untouched, npm pack --dry-run: 0 desktop entries), .npmrc restating the
  root ignore-scripts security posture (npm per-project config would silently
  bypass it; electron binary fetched explicitly via bootstrap:electron only
  when launching), tsconfig (bundler resolution, dashboard precedent),
  electron.vite.config.ts (ESM main / CJS sandboxed preload / thin pre-daemon
  renderer — real dashboard is loadURL'd from the daemon, never built here).
- src/desktop/src/shared/desktop-api.ts: typed preload⇄renderer contract SSOT
  (zod ConnectionProfile — 4-kind matrix schema-complete per Law #2, tokens
  deliberately never stored; DeckentDesktopApi UI-grade surface).
- Root integration: tsconfig exclude + copy-assets walk-skip (the exact
  dist-leak gotcha class), .gitignore (node_modules/out/release), scripts
  (tsc:desktop, build:desktop, dev:desktop, test:desktop, install:all chain),
  vitest.desktop.config.ts (Electron-free unit scope).

Verify: tsc:desktop EXIT 0 (electron 43.1.0 resolved), root lint green
(2091-file hermetic-lint 0 violations), npm pack isolation proven.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 10, 2026
…ho skip (sprint-396) + lint crossReach sınıfı

- born-601 (sprint-396 T1+T2): 4 agent + 6 skill manifesti onarıldı — architecture/
  migration intent'e, database/monorepo/git stackDetection+intent'e, onboarding/
  provider-cli dar-sinyale; integration-engineer + terminal-ux-engineer $or-collapse
  (gerçek-kuralın skorunda: 8/6 — advisor: DÜZ-SİLME yabancı-projede bugün-ateşleyen
  kuralı kaybederdi, Yasa-#2). Worker dürüst-DEBT bıraktı çünkü goCriteria'm
  $or-tasarımıyla çelişiyordu (ölü-kelime kasıtlı korunur) → Brain-fix: lint'e
  "Cross-reach (sanctioned $or)" sınıfı eklendi (gerçek/alias-kardeşli $or-dalı
  kelimeleri borç değil); 3 orphan-girdisi emekli. SONUÇ: Known debt 11→0,
  8 alias-canlı + 3 sanctioned, 0 yeni ölü-kelime.
- born-603 (T3): fix-wave "no defect / no source change" debt'leri artık CRITICAL
  yeniden-doğmaz — konjonktif desen (fix-köken originTaskId VE tam-content
  no-defect işareti; 80-char-title değil), skip-without-permanent-resolve
  (denetlenebilir), enjekte-description artık debt-notunu taşır. Yapısal v2 =
  born-604 (ledger'lı).

Sprint-396: 3/3 (2 DONE + 1 dürüst-DEBT→Brain-kapattı), 0 NO_GO. Verify:
routing+planner bataryası 215/215 + yeni 50/50, vocab-lint EXIT 0 (borç 0),
npm run lint 0, tsc 0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 10, 2026
… tam-uygulama)

Sprint-397 (15/15, 0 NO_GO): 8 test-stale ailesi + ELOOP DeckentError CODE-FIX +
katalog re-zero/$or-uyum + docs-site 2-blocker (vitepress build EXIT 0) +
README sprint-badge restore (K4) + update-readme-stats kalıcılık-fix'i +
secret/spawnsync baseline-refresh (advisor'ın merge-tuzağı reçetesiyle) +
validate-publish orphan-test GATES-API rewrite.

Brain post-fix'leri:
- T8 stats-sıfırı sprint'in KENDİ finalizer'ınca geri-basılmıştı (born-605
  canlı-kanıt #2) → sprint-sonrası donduruldu (61/61).
- agsk3/onboarding-ux: RCA-anlığı 396-öncesiydi — post-601 kontratına taşındı
  (domain-veya-intent beklentisi + builtin-parite); builtins 160/160.
- routing-live-diversity: 396-T1 data-engineer'ı evrensel-dominated bırakmıştı
  (migration@6+3 < migration-specialist@10, HER projede) + integration-engineer'a
  uygulanan cross-project $or-koruması eksikti → database|db|models $or@8 geri
  (Yasa-#2 foreign-reach, lint-orphan-gerekçeli) + migration@6 korunur;
  agent-rule-rewrite pin'i özel-case'le revize; 327/327 routing+builtins yeşil.

Yeni kayıt: born-617 CI-testglob-GAP (tests/{kpi,brain,e2e,audits,governance,
docker,config,...} CI'da hiç koşmuyor + 9-dosya latent-set — Faz-0-dışı, havuza).

Verify: tam-suite 29714-pass (29-fail'in 28'i CI-dışı aileler=617'ye, 1'i fix'lendi);
hedef-batarya 327/327 + builtins 160/160 + tsc 0 + lint 0 + vocab 0 + docs-build 0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 10, 2026
… muafiyeti + backend-aware force-sweep

- P0 (ana-vaat FIX-kapısından deliniyordu): cascade-skip synthetic-result'ına
  cascadeSkipped:true — handleEvaluation artık skip'e dependencies:[]'li direkt-fix
  AÇMAZ (iş incelenmemiş MRR-temelinde yeniden koşmaz) + handleCrossDependencies
  skip'ten DONE-dep'lere xfix fan-out YAPMAZ (born-624 amplifikasyonu kesildi;
  NOT_DISPATCHED-muafiyeti emsali). Retry sonraki-sprint'in işi, upstream
  incelendikten sonra
- P1 (Yasa #2): forceKillLiveWorkers artık kill.ts killSingle kompozisyonunu
  kullanıyor (subprocess/docker-first + tmux-fallback + status/lock/prompt
  temizliği) — tmux-dışı backend'de sessiz no-op bitti; öldürülemeyenler
  COMPLETE-öncesi dürüst-uyarıyla yüzeye çıkıyor
- Testler: fix-kapısı muafiyeti (skip→fix-yok · normal-NO_GO→fix-var ·
  xfix-yok) + boolean-seam sweep + composition-pin güncel

Kanıt: scheduler-single-truth 8/8 + orchestra+cli+governance+core 21395/21426 + tsc-0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 11, 2026
… 528 denied-honesty · 641-spawner + publish-pin senkronu

Sprint-409 (4/4 DONE, FIX-turu dahil, 13dk):
- born-527: Home/End gerçek-Ink eşlemesi + boş-history-push guard + keylog os.tmpdir/config (Yasa #2)
- born-528: confirm-denial toolSink dürüst-çıktı yolundan (denied-işaretli; 633-sözlüğüyle tutarlı)
- 641-spawner: spawn-time yeniden-atama yalnız assignedAgent yok/generic'se; spawn-fallback
  journal'lı (source:'spawn-fallback') — born-641 ailesi TAMAMEN kapandı

CI-kırmızı (d839682) kökü — ÜÇÜNCÜ workflow-pin kör-noktası (tests/workflows/):
- publish.test.ts eski publish-otoritesi şeklini pinliyordu → emekli-gerçeğe senkron
  (dry-run-only; gerçek publish yalnız release.yml; not-match pin'i run-adımına daraltıldı)
+ repl_surface.bg_turns dogfood-flag lokal-AÇIK (642 canlı-deneyim hazır)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 11, 2026
…rçek-durum senkronu + Windows-EOF + kalıcı pin'ler

Sprint-410 (3/3 DONE, 5.5dk): worker'lar disk-verify ile DÜRÜST keşif yaptı —
üç işin çoğu ZATEN inmişti (494→sprint-377 c8e839a · 501-tabanı→sprint-390
03adf3e · 505→380-013); MASTER-PLAN satırları bayattı. Gerçek-delta:
- 410-002: EPIPE-zarafeti Windows EOF-eşdeğerine genişletildi (Yasa #2) + sınıf-ayrımı pin
- 410-001/003: lazy-split + dedup + tek-tanım kalıcı pin-testleri (drift-kapanı)
- MASTER-PLAN 494/501/505 ✅ gerçek-tarihçeyle işlendi

DERS (386-duplicate'in ⬜-varyantı): eski ⬜-satır sprint'e alınmadan ÖNCE disk-verify —
marathon-kuralına eklendi. + born-645 (pre-flight claude-probe yanlış-negatif flake) kayıtlı.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 15, 2026
…u kapat (ADR-G-013)

Advisor-yakalaması (yük-taşıyan): S2 flag-ON'da child.stdout'u pipe'layıp on('data')
attach ediyor → flowing-Readable KENDİ loop-ref'ini stdout-EOF'a (≈worker-exit) kadar
tutar. child'ı unref ettim ama stdout'u DEĞİL → .result yazıp linger eden worker
coordinator-loop'unu yeniden pinler (tam da child.unref'in çözdüğü MOAT-2 senaryosu),
yalnız live_trace-ON'da. moat2-linger testi flag-OFF koşuyor → yapısal olarak yakalayamaz.

Fix: pipe'lı stdout'a unref (hbInterval.unref deseni — unref'li stream 'data' hâlâ
verir ama EXECUTE result-poll timer loop'u canlı tutar; kendi başına anchor etmez).
Flag-ON linger-assertion eklendi (stdout.unref çağrıldığını doğrular).

Ayrıca advisor #2 denetimi (subprocess .log tüketicileri stream-json'da kırılıyor mu):
TEMİZ — captureSubprocessOutput line-based/format-agnostik · readLogEvents isLogEvent-guard
(subprocess ZATEN []) · readModelUsageFromLog whole-parse-then-line-scan fail-safe ·
heartbeat/liveness mtime-check · extractUsage line-scan stream-json-safe. Whole-parse eden
kırılan tüketici YOK.

Kanıt: tsc 0 · subprocess-live-activity 4 + moat2-linger 8 yeşil (flag-ON unref +
flag-OFF byte-stable ikisi de).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Jul 17, 2026
…aemon transport (real RunFlow SSE into the Console)

The window is no longer handed over to the daemon's dashboard on
connect: the local shell stays mounted and consumes the daemon's
tokened HTTP API directly (approved SURF-4 decision #2). markDaemonActive
registers the origin (CSP/navigation allowlist) without loadURL;
connectWindow remains only as the legacy-dashboard escape until SURF-7.

- IPC session bridge: DaemonSession {profileId, origin, apiToken} pushed
  on `daemon.session` after connect (null on disconnect) + `session.get`
  pull for renderer reloads — LOCAL-renderer tier (token-bearing).
- CSP: connect-src allows the loopback port-wildcards in BOTH twins
  (index.html meta — the enforced one on file:// — and the
  buildLocalRendererCsp header): the connect flow already hard-rejects
  non-loopback plain-http (born-600), so loopback IS the boundary.
  Chromium rejects a bracketed-IPv6 wildcard → ::1 joins dynamically.
- Renderer shell (approved stack, exact-pinned: react 19.2.7,
  react-router 7.9.4 HashRouter, @tanstack/react-query 5.90.3,
  zustand 5.0.14, react-aria-components 1.19.0; ADR-D-005 rationale
  rows added): persistent 4-view nav (Console/Chat/Approval/History),
  typed api-client for BOTH contracts — RunFlow REST
  (list/get/preview/propose/decision/start/cancel) + per-flow SSE
  (named events, id:=durable sequence, ?token= + ?after= replay) and
  the SEPARATE poll-based ApprovalBroker (/api/approvals). 404 surfaces
  as the honest terminal.run_flow_v2 flag notice. SSE events land in
  the Query cache (SSE→cache) and render in the Console's live feed.
  i18n: 11 new desktop.shell.* keys en+tr; zero shell literals.
- PRODUCT BUG found by the smoke and fixed: `deckent serve` never
  bootstrapped providers — EVERY /api/run-flow/propose died with
  "No providers registered" (born-680's API twin). serve.ts now runs
  the same bootstrap convention as do/start (fail-soft, API-only mode
  unaffected). Also: bare-IPv6 connect URLs are now bracketed.

Tests: desktop 90 green (api-client Bearer/?token=/?after=/404-flag/
named-SSE pins, CSP builder pins, session.get joins the local tier).

REAL-BINARY PROOF (playwright _electron + REAL `deckent serve` daemon
in a tmp project, run_flow_v2 on): add profile → connect (adopt) →
session push → shell mounts → 4 hash-routes navigate → POST
/api/run-flow/propose (201) → the flow appears in the Console and its
durable events stream over SSE into the live feed:
1 PROPOSAL_SUBMITTED · 2 PREVIEW_STARTED · 3 PREVIEW_READY. Screenshot
captured — the done-criterion verbatim.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Aug 3, 2026
…kaydı (327 satır)

Alperen 7 kararı onayladı. Beşi uygulandı, ikisi validator tarafından bloke edildi —
ve bu doğru davranıştı (governance-by-construction çalışıyor).

UYGULANANLAR:
- SSOT-001 VERIFY -> DONE. Truth 1/1/1/1/1/-/-,
  `proof=master-archive-fresh-checkout-56d5406f0`. Arşiv SHA-256 header'daki beklenen
  d6a90fc0... ile birebir, dosya tracked, `git archive HEAD` ile temiz dizine çıkarılan
  kopya aynı hash'i verdi. Bu satır 318 aktif satırın 290'ını bekletiyordu.
- 4 yeni satır: RUNTIME-FLOOR-001 (450), ERROR-REGISTRY-001 (460), CONFIG-TRUTH-001 (470)
  P00'a; LIFECYCLE-VOCAB-001 (3305) P03'e. Ledger 323 -> 327.
- TRUTH-BASELINE-001 evidence: test-failure ratchet kuruldu, baseline 118/598 -> 113/539;
  codex-analysis'in 115/591 rakamının aynı günün daha eski snapshot'ı olduğu kayda geçti.

VALIDATOR'IN DURDURDUKLARI:
- READY (karar #2) owner receipt'i olmadan MÜMKÜN DEĞİL. İki katman: (a) SSOT-003'ün tek
  child'ı MASTER-CLI-SYMLINK-FLAKE-001 OPEN olduğu için SSOT-003 READY olamıyor;
  (b) o satırı READY yapınca ADMISSION_RECEIPT_MISSING — READY, satıra+G1'e özel
  owner-issued admission receipt'i (GR-YYYY-MM-DD-..., exact file manifest,
  owner=Alperen; decision=APPROVED) gerektiriyor. Receipt üretmedim; satır OPEN bırakıldı,
  READY-eligibility gerekçesi evidence'a yazıldı.
  BU, KENDİ TESPİTİMİN DÜZELTMESİDİR: "0 READY yalnız yazım boşluğu" demiştim; eksikti.
  Doğrusu READY hem yazım hem owner admission authority gerektirir.
- P0 yeniden sınıflandırması (karar #5): "246 -> ~90" tahminim YANLIŞTI. Codex'in 4 soruluk
  politikası doğru uygulanınca savunulabilir P1 adayı 56 değil 9 çıkıyor. Toplu indirme
  YAPILMADI. Sebep: dependents=0 olan satırların çoğu RECOVERY-BORN-* — gerçek koşularda
  gözlenmiş execution hataları, yani politikanın 1. sorusundan P0 kalıyorlar.
  Bulgu: P0 enflasyonu esas olarak yanlış etiketleme değil; gerçek çare owner-set P0
  BÜTÇESİ (eşzamanlı admission limiti) olmalı — bu bir owner kararı.

Ledger: 323/318/5 -> 327/321/6 · READY hâlâ 0 (admission receipt bekliyor) ·
P0 250, P1 57 -> 61.
Doğrulama: lint:master-plan OK (327 satır, 23 receipt, projeksiyonlar in-sync) · lint:link 0.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
AlbSar added a commit that referenced this pull request Aug 3, 2026
PAZARTESI.md geçici köprüydü ("FAZ 3 bitince içeriği MASTER-PLAN'a taşınır ve
bu dosya silinir") — taşındı ve silindi. İş-takibi artık TEK SSOT: MASTER.

Emilen içerik (MASTER'da karşılığı olmayan her şey):
- SKILL-DURABILITY-001 (3310, P0): FORCED_SKILL_UNAVAILABLE — crosswalk'ta
  satırı olmayan tek FAZ-4a maddesi; diğer beşi mevcut satırlarla kapsanıyor
  (eşleme evidence'ta).
- PROD-SPAWNSYNC-ASYNC-001 (3315): Alperen karar #2 (2026-08-02)
  transkripsiyonu — üretim hot-path'i, TEST-SPAWN-001'den ayrı.
- BOT-LIFECYCLE-HONESTY-001 (3320): 4a-ek canlı bulguları — identity-guard
  recovery komutlarını bloklamasın + SIGTERM pid hijyeni.
- CLEAN-DASHBOARD-POLICY-001 (3325): clean↔build:dashboard policy çelişkisi;
  487-CLEAN-HOLD-EXIT komşu ama ayrı (fark evidence'ta).
- Stop-line: sprint-491 kanıt seti dondurma (FAZ-0 owner kararı).
- TRUTH-BASELINE-001: paket ölçümleri (564: P1 211/19 · P2 135 · P3 116 ·
  P4 96 · P6 kapalı) + CANONICAL kritik yol P6→P1→P3+P4→P2 (OQ-XV-06) +
  P1=FAZ-4a aynı-dilim kararı + Type Check maskesi dersi.
- DOCS-RELEASE-TRUTH-001: FAZ-5 managed-docs sahiplik kuralı.

Ayrıca TRUST-ANCHOR-001 X 0→1: PR #27'nin required-check koşusu (run
30846122775) trust-anchor kodu + 84-case suite ile 3 platformda geçti; merge
ancak bu bacaklar yeşilken mümkündü — ruleset'in kendisi kanıt zincirinde.

9 canlı dosyadaki PAZARTESI referansı MASTER satırlarına yönlendirildi
(README ×2, check-test-failures, 5 test dosyası + reference-drift ×2).
RECONCILIATION-WP0.md'deki anlatı referansları bilinçli bırakıldı — o dosya
versioned tarihsel kayıttır.

Kapılar: lint:master-plan OK (337/330/25), 7 suite 121 passed / 0 fail,
lint:link 0, tsc temiz.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants