v1.91.2.0 fix: consolidate gstack reliability wave (#2959)

* fix(memory-ingest): --scan-secrets scans the rendered page and fails closed

--scan-secrets ran gitleaks on the raw transcript .jsonl, then imported a
page rendered from it. gitleaks' assignment rules don't match across a
JSON-escaped quote (KEY=\"v\" on disk), so a secret the rendered page
shows as KEY="v" was imported unflagged. And the gate skipped a file only
on scanner "gitleaks" with findings, so a scan that errored (non-zero
exit, 16MB maxBuffer overflow on a file with many findings, unparseable
report) or could not run (gitleaks missing, slow-probe cooldown) imported
the file unscanned.

Scan the rendered page body, the exact bytes writeStaged() writes, via a
new secretScanText() helper, and skip the file whenever the scan did not
complete. Skipped files stay out of the state file, so the next run
retries them. Reword the helper warnings and setup-gbrain/memory.md,
which described the fail-open as intended.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(test): reconcile Bun failure markers and footer counts

* fix(sync-gbrain): verify source-scoped reads without mutation

* fix(test): recognize grounded TTHW target choices structurally

* fix(aside): make the readiness probe work under zsh and report why it failed

The probe built its deadline into `_T` and expanded it unquoted, so
`$_T aside repl …` only worked in a shell that word-splits. zsh does not: it
looked for a command literally named "gtimeout 30", the probe answered
ASIDE_NOT_RUNNING with Aside installed and ready, and every browsing skill
fell back to the bundled Chromium in silence. zsh is the macOS default and
Aside is macOS-only, so on a stock Mac the probe could never report READY.

The deadline becomes a function, `_gs_d`. It receives the command as "$@",
already split, so sh, bash and zsh all behave the same, and the gtimeout →
timeout → perl alarm chain is unchanged. A 4th arm runs the call unbounded
when none of the three is present, which is what the empty `_T` did before.
Not `eval`: it re-parses the string, so the parens and `;` of the perl arm
become syntax and that arm dies in bash *and* zsh — on a stock Mac, the arm
that actually runs.

On failure the probe now prints the CLI's reason after ASIDE_NOT_RUNNING:,
the shape gstack-render already uses: the first line that starts with a
capital letter, i.e. the CLI's own sentence or Node's `Error:` line below its
loader frame. "Not running" covers states with different fixes — no window
open for the profile, a NODE_OPTIONS preload that kills the CLI — and a bare
verdict sent all of them to "open the Aside app". The BROWSER SETUP prose
quotes that reason before asking the user to open the app.

The text pin asserted the broken invocation verbatim, so it now pins the
function and asserts neither `$_T aside repl` nor an eval form comes back. A
second test executes the rendered probe in sh, bash and zsh on each of the
four deadline arms with stubbed binaries on a narrowed PATH, plus two failing
CLIs: one that prints its own sentence, one that crashes like Node with the
useful line below the frame.

The deadline function costs zero bytes against the lines it replaces; the
reason costs 53 per copy of the probe (44 where the reworded BROWSER SETUP
line gives 9 back). That moves four guards by the measured amount:
plan-devex-review's skeleton cap to 68,550 (measured 68,544), plan-ceo-review's
skeleton cap to 80,150 (measured 80,111) and union ratio to 1.081 (measured
1.0803), and plan-eng-review's union ratio to 1.151 (measured 1.1504).

Fixes #2842, #2941.

* Clarify engineering review startup and decision flow

* Fix Windows readiness fixture PATH and command shim

* fix(test): recognize grounded TTHW target choices structurally

* Clarify engineering review startup and decision flow

* fix(test): restrict QA-only fixture tools to its no-Edit contract

* v1.90.0.0 fix(sync-gbrain): guard readiness verdicts and refresh metadata

* fix(browse): validate canonical upload targets

* fix(gbrain): classify structured PGLite busy response

* fix(browse): preserve native extension runtime APIs

* Fix displayless browser handoff ownership

* Accept unique installed autoplan methodology aliases

* fix(skills): preserve positional literals during installation

* fix(browse): checksum installer contents through stdin

* fix(test): normalize Windows checksum fixture paths

* test: emulate unavailable shasum in Windows checksum fixture

* fix(investigate): preserve owned freeze lifecycle

* fix(review): preserve N+1 retry and Red Team completion

* fix: bound Aside readiness and preserve safe fallback

* test: exercise setup and Chromium on native ARM

* fix: preserve install ownership and ARM browser selection

* Fix gbrain ingest scan boundaries and seed observation

* Refresh managed ship hooks and supervise expanded paid census

* Reject resumed gbrain pages excluded by current policy

* Recover zombie agent locks safely and enable CI Python venv

* Repair paid actor declarations and Aside pitch assertions

* Bump consolidated wave to next free minor release

* Clarify CEO review admin choices and option tradeoffs

* Preserve CEO mode handoff anchors in clarified workflow

* Make Windows portability fixtures use shell-native paths

* Restore ARM Bun alias and clarify ship review gates

* Refresh ship workflow golden snapshots

* Fix Windows DX documentation controls without piped stdin

* Decode Codex child pipes without Bun's encoded-stream stall

* Bound DX pre-review audit before product questions

* Clarify trusted review-start read in paid revalidation

* Bump consolidated wave to next free minor release

* Clarify CEO review admin choices and option tradeoffs

* Preserve CEO mode handoff anchors in clarified workflow

* Make Windows portability fixtures use shell-native paths

* Restore ARM Bun alias and clarify ship review gates

* Refresh ship workflow golden snapshots

* Fix Windows DX documentation controls without piped stdin

* Decode Codex child pipes without Bun's encoded-stream stall

* Bound DX pre-review audit before product questions

* Clarify trusted review-start read in paid revalidation

* Reconcile new main planning flow and paid judge census

* fix: reconcile rebased planning and source-bound validation

* test: pin cookie workflow judge to scored Sonnet model

* fix: keep terminal agent boot out of module imports

* fix: preserve pending-question uncertainty in engineering review

* fix: stabilize Windows reliability-wave fixtures

* fix: clarify design consultation research workflow

* fix: preserve independent design consultation inputs

* fix: resolve design taste scope and browser research guidance

* fix: make consultation opt-in preflight unambiguous

* test: await native Edge owner readiness or terminal result

---------

Co-authored-by: Bruce Krysiak <brucek@alum.mit.edu>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Antonio Vitalic <antoninte99@gmail.com>
This commit is contained in:
Garry Tan
2026-09-26 18:57:53 -04:00
committed by GitHub
co-authored by Bruce Krysiak Claude Opus 5.5 Antonio Vitalic
parent 2a113ae7e6
commit 01593aa67c
204 changed files with 9958 additions and 1705 deletions
+23 -17
View File
@@ -66,14 +66,16 @@ Recommendation: A when a branch diff exists, otherwise B. Reply with A, B, or C.
After target selection, every question uses the preamble's full decision brief, transport and continuous D-numbering. Setup, prerequisite and preparation questions do not approve engineering remedies.
**Format precedence:** Copy required command, output and question formats exactly. Apply Voice to newly composed prose.
**Startup sequence** (after target selection):
1. Run the Preamble, including Context Recovery and its setup questions.
1. Run the Preamble command and its startup instructions (Context Recovery and setup questions). Defer Operational Self-Improvement, Telemetry and Plan Status Footer to finish; format/transport rules apply throughout.
2. Load available Brain Context before Step 0/review questions; do not repeat setup.
3. Check web-research readiness at **Web research runs in Aside**.
4. Run **Design Doc Check**, then **Prerequisite Skill Offer**.
5. Continue at **Engineering review → Step 0** below; its section Read loads Review preparation and Scope Challenge together.
5. Continue at **Engineering review → Step 0** below: full section Read → **Review preparation** → **Scope Challenge**.
Keep the reviewed target fixed when selecting the section's separate report destination.
Keep the reviewed target fixed when selecting the report destination.
## Preamble (after scope gate)
@@ -446,8 +448,6 @@ telemetry — it never blocks the workflow.
Skills that run plan reviews (`/plan-*-review`, `/codex review`) include the EXIT PLAN MODE GATE blocking checklist at the end of the skill, which verifies the plan file ends with `## GSTACK REVIEW REPORT` before ExitPlanMode is called. Skills that don't run plan reviews (operational skills like `/ship`, `/qa`, `/review`) typically don't operate in plan mode and have no review report to verify; this footer is a no-op for them. Use the selected report file and honor the Review record and write policy for every artifact.
**Format precedence:** Copy required command, output and question formats exactly. Apply Voice to newly composed prose.
## Priority hierarchy
@@ -530,19 +530,25 @@ sections. Read a section in full before doing its step; do not work from memory.
## Web research runs in Aside
When a step calls for looking something up on the web (competitors, current best practices, a known bug, prior art), do it through Aside's own agent first: it searches with the user's real browser, signed-in sessions included. If Aside is not ready, fall back to the WebSearch tool when this host provides one. If neither is available, say so once and continue on what you already know.
For web research, do it through Aside's own agent first, using the user's signed-in browser. If Aside is not ready, fall back to the WebSearch tool when this host provides one.
Check once per run that Aside is ready (if this skill already ran this same probe, in BROWSER SETUP or Third-Party Web Actions, reuse its answer):
Check once (if this skill already ran this same probe, in BROWSER SETUP or Third-Party Web Actions, reuse its answer):
```bash
_T=""; command -v gtimeout >/dev/null 2>&1 && _T="gtimeout 30"; [ -z "$_T" ] && command -v timeout >/dev/null 2>&1 && _T="timeout 30"
[ -z "$_T" ] && command -v perl >/dev/null 2>&1 && _T="perl -e alarm(shift);exec(@ARGV) 30"
_gs_d() { if command -v gtimeout >/dev/null; then gtimeout 30 "$@"; elif command -v timeout >/dev/null; then timeout 30 "$@"
elif command -v perl >/dev/null; then perl -e 'alarm(shift);exec(@ARGV)' 30 "$@"; else return 125; fi; }
if [ "${GSTACK_SKIP_ASIDE:-}" = "1" ] || ! command -v aside >/dev/null 2>&1; then
echo "NEEDS_ASIDE"
elif $_T aside repl 'console.log("ASIDE_READY " + pwd)' 2>&1 | grep -q '^ASIDE_READY'; then
echo "READY: aside $(aside --version 2>/dev/null)"
else
echo "ASIDE_NOT_RUNNING"
_rc=0; _o=$(_gs_d aside repl 'console.log("ASIDE_READY " + pwd)' 2>&1) || _rc=$?
case "$_rc" in
124|142) echo "ASIDE_TIMEOUT: probe deadline exceeded" ;;
125) echo "ASIDE_UNAVAILABLE: bounded probe unavailable" ;;
0) if printf '%s\n' "$_o" | grep -q '^ASIDE_READY '; then echo "READY: aside"
else echo "ASIDE_NOT_RUNNING: no readiness marker"; fi ;;
*) echo "ASIDE_CLI_ERROR: exit $_rc; inspect aside --help locally" ;;
esac
unset _o
fi
```
@@ -553,7 +559,7 @@ fi
_aside_exec "Search the web for <query>. Read-only: do not sign in, submit, or change anything. Reply with <format, e.g. up to 8 bullets, each with its source URL>, then stop."
```
- `NEEDS_ASIDE` or `ASIDE_NOT_RUNNING`: run the same queries with the WebSearch tool if this host provides it — same read-only intent, same untrusted-content rule. If it does not, skip the research and say once: "Search unavailable — proceeding with in-distribution knowledge only." Never install Aside yourself; mention aside.com at most once per run. The rest of the skill continues.
- Any non-READY result: report only the safe status, never raw diagnostics. Run the same queries with the WebSearch tool if available, still read-only and untrusted. Otherwise say once: "Search unavailable — proceeding with in-distribution knowledge only." Never install Aside yourself; mention aside.com at most once per run. Continue the skill.
Sanitize every query before it leaves the machine: strip hostnames, IPs, file paths, SQL fragments, and anything that looks like a secret. Search for the error class and the library, not the user's data.
@@ -653,10 +659,10 @@ Scope Challenge is mandatory before Section 1.
## Recovery routing
Use this routing at every STOP or failed verification; do not restart the review.
At every STOP or failed check, use this route; do not restart.
**Paused question:** Wait for its actual answer without completion telemetry or ExitPlanMode.
Resume that question's local procedure with the answer. A missing-result call
Resume its local procedure with the reply. A missing-result call
that may have surfaced is still pending; do not duplicate it.
**Repairable write/read failure:** Stop before the dependent question or output.
@@ -669,14 +675,14 @@ reopened choices use Decision procedure. Repeat Approval readiness, then Require
outputs steps 1–4 for changed outputs before choosing navigation again. Refresh
affected tests, tasks, dependencies and parallelization. Unchanged saved outputs
may reuse their successful Review Log. If a final gate discovers stale evidence,
follow **Blocked outcome** first; resume on this repair path.
follow **Blocked outcome** first; then resume here.
**Blocked outcome:** Stop the review and report `BLOCKED`, the missing path/work, actual attempts and what is needed to resume. Label complete chat-only output **not persisted**; it supplies no saved-review or completion credit. If startup values and a permitted telemetry command are available, run **Telemetry (run last)** once with `OUTCOME=error` and the actual `ERROR_MESSAGE`/`FAILED_STEP`. Do not call ExitPlanMode. Resume at the failed step using Recovery routing.
## Section self-check (before you finish)
Confirm you read the section and completed Scope Challenge, Sections 1–4,
Outside Voice and outputs. If evidence is missing, Read `sections/review-sections.md`
Outside Voice and outputs. If evidence is missing, Read `~/.claude/skills/gstack/plan-eng-review/sections/review-sections.md`
and use Recovery routing above. Preserve verified work.
## EXIT PLAN MODE GATE (BLOCKING)
+9 -9
View File
@@ -64,19 +64,19 @@ Recommendation: A when a branch diff exists, otherwise B. Reply with A, B, or C.
After target selection, every question uses the preamble's full decision brief, transport and continuous D-numbering. Setup, prerequisite and preparation questions do not approve engineering remedies.
**Format precedence:** Copy required command, output and question formats exactly. Apply Voice to newly composed prose.
**Startup sequence** (after target selection):
1. Run the Preamble, including Context Recovery and its setup questions.
1. Run the Preamble command and its startup instructions (Context Recovery and setup questions). Defer Operational Self-Improvement, Telemetry and Plan Status Footer to finish; format/transport rules apply throughout.
2. Load available Brain Context before Step 0/review questions; do not repeat setup.
3. Check web-research readiness at **Web research runs in Aside**.
4. Run **Design Doc Check**, then **Prerequisite Skill Offer**.
5. Continue at **Engineering review → Step 0** below; its section Read loads Review preparation and Scope Challenge together.
5. Continue at **Engineering review → Step 0** below: full section Read → **Review preparation** → **Scope Challenge**.
Keep the reviewed target fixed when selecting the section's separate report destination.
Keep the reviewed target fixed when selecting the report destination.
{{PREAMBLE}}
**Format precedence:** Copy required command, output and question formats exactly. Apply Voice to newly composed prose.
{{GBRAIN_CONTEXT_LOAD}}
## Priority hierarchy
@@ -157,10 +157,10 @@ Scope Challenge is mandatory before Section 1.
## Recovery routing
Use this routing at every STOP or failed verification; do not restart the review.
At every STOP or failed check, use this route; do not restart.
**Paused question:** Wait for its actual answer without completion telemetry or ExitPlanMode.
Resume that question's local procedure with the answer. A missing-result call
Resume its local procedure with the reply. A missing-result call
that may have surfaced is still pending; do not duplicate it.
**Repairable write/read failure:** Stop before the dependent question or output.
@@ -173,14 +173,14 @@ reopened choices use Decision procedure. Repeat Approval readiness, then Require
outputs steps 1–4 for changed outputs before choosing navigation again. Refresh
affected tests, tasks, dependencies and parallelization. Unchanged saved outputs
may reuse their successful Review Log. If a final gate discovers stale evidence,
follow **Blocked outcome** first; resume on this repair path.
follow **Blocked outcome** first; then resume here.
**Blocked outcome:** Stop the review and report `BLOCKED`, the missing path/work, actual attempts and what is needed to resume. Label complete chat-only output **not persisted**; it supplies no saved-review or completion credit. If startup values and a permitted telemetry command are available, run **Telemetry (run last)** once with `OUTCOME=error` and the actual `ERROR_MESSAGE`/`FAILED_STEP`. Do not call ExitPlanMode. Resume at the failed step using Recovery routing.
## Section self-check (before you finish)
Confirm you read the section and completed Scope Challenge, Sections 1–4,
Outside Voice and outputs. If evidence is missing, Read `sections/review-sections.md`
Outside Voice and outputs. If evidence is missing, Read `~/.claude/skills/gstack/plan-eng-review/sections/review-sections.md`
and use Recovery routing above. Preserve verified work.
{{EXIT_PLAN_MODE_GATE}}
+41 -42
View File
@@ -12,7 +12,6 @@ Then run **Scope Challenge A → B → C**, followed by Sections 1–4 in order.
## Review record and write policy
Use these terms throughout the review:
- **Target:** the plan, diff or code path selected at the Scope gate. It stays fixed.
- **Working plan:** the proposed work and its current approvals. For a plan target,
start with that plan; for code, build a remedy plan from the findings. This is
@@ -50,10 +49,9 @@ path authorizes no other; implementation edits require explicit authority.
| Required Review Log | The helper's state location | Present its fields as **not persisted**; the final gate cannot pass without this log. |
| Best-effort metadata/learning logs | Helper-defined locations | Skip forbidden writes; otherwise keep their best-effort behavior. |
The QA Test Plan and task JSONL intentionally use legacy discovery paths under
`~/.gstack/projects/{slug}/`: `{user}-{branch}-eng-review-test-plan-{datetime}.md`
and `tasks-eng-review-{datetime}.jsonl`. QA and /autoplan require these paths even
with a different report root. Use their formats/commands below; do not relocate them.
QA Test Plan/task JSONL keep discovery paths `~/.gstack/projects/{slug}/`:
`{user}-{branch}-eng-review-test-plan-{datetime}.md` and
`tasks-eng-review-{datetime}.jsonl`. Keep their formats; do not relocate.
A failed permitted save uses **Recovery routing → Repairable write/read failure**,
not the forbidden-write branches above. Do not ask from an unsaved record.
@@ -183,17 +181,19 @@ higher confidence.
## Decision procedure
Run this six-step loop for findings from Scope Challenge, Sections 1–4, Outside
Voice, late changes and TODO choices. Finish one choice before the next.
For Scope Challenge, Sections 1–4, Outside Voice, late changes and TODOs, finish
one choice at a time through steps 1–6.
Setup gates—Context Recovery/prerequisites, Prior Learnings configuration,
target and Scope Challenge complexity selectors—use local rules without a
pre-answer ledger. Scope Challenge B saves actual selector answers afterward;
it does not use this remedy loop. These answers approve no engineering remedy.
pre-answer ledger. Scope Challenge B saves actual selector answers afterward,
outside this remedy loop. These answers approve no engineering remedy.
One question for one choice per AskUserQuestion call. Use the preamble for
question transport/fallback and authorized auto-decisions. Use Review
record/write policy only for saved records, reports and logs.
One question for one choice per AskUserQuestion call. Authorities:
- Preamble: question format, transport/fallback and authorized auto-decisions.
- Steps 1–6: substantive choices/answers; Review record/write policy: persistence.
- Entrypoint: **Paused question** for pending answers; **Blocked outcome** for missing work or failed recovery.
- Finish: Approval readiness → Required outputs → entrypoint verification.
### 1. Establish current state
@@ -732,7 +732,7 @@ Repo: {owner/repo}
This file is consumed by `/qa` and `/qa-only` as primary test input. Include only the information that helps a QA tester know **what to test and where** — not implementation details.
After the Test Plan Artifact is saved or presented, report the Test review findings and their dispositions and continue to Performance review.
After **Add missing tests to the plan** resolves test/eval decisions and the Test Plan Artifact is saved or presented, report the Test review findings and their dispositions and continue to Performance review.
### 4. Performance review
Evaluate:
@@ -993,12 +993,11 @@ Retain the historical review-log skill ID; add `"host":"claude","outside_provide
### Continue after Outside Voice
Only completed reviews enter Cross-model tension. Record the actual coverage,
including disabled or unavailable outcomes, then continue below.
Finish the Outside Voice branch. Only completed reviews enter Cross-model tension. Record the actual coverage, including disabled or unavailable outcomes, in the Completion summary, then continue below.
## Final planning decisions
Resolve the TODO choices, then check Approval readiness before Required outputs.
After Sections 1–4 and Outside Voice, resolve the TODO choices, then check Approval readiness before Required outputs.
### TODOS.md updates
Review every potential TODO. Reuse an exact prior disposition under Decision procedure; ask about each unanswered proposal in its own AskUserQuestion. Never batch TODOs or silently skip them. Use `~/.claude/skills/gstack/review/TODOS-format.md`.
@@ -1028,31 +1027,31 @@ unresolved decisions in the report.
## Required outputs
Run this finish sequence after Approval readiness passes. Use the references
below for each step, not as another review cycle.
After Approval readiness passes, follow this finish sequence using the reference
sections below; those references are not another review cycle.
For recovery or changed outputs, use the entrypoint's **Recovery routing**.
Reuse a successful Review Log only for unchanged saved outputs; changed outputs
must pass steps 1–4 again.
1. **Prepare the review body.** Use the output reference below to complete the
working plan, Implementation Tasks and Completion summary. Derive unresolved
choices from each record's current State, actual answer and accepted scope;
leave them pending. Save permitted auxiliary artifacts under the write policy.
1. **Prepare the review body.** Complete the working plan, Implementation Tasks
and Completion summary below. Leave choices pending according to each record's
current State, actual answer and accepted scope. Save permitted auxiliary artifacts under the write policy.
2. **Save and Read back.** Use Plan File Review Report to save the complete body
and append its terminal `## GSTACK REVIEW REPORT`. Pass that writer's Read-back
gate. If report persistence is forbidden or the save cannot be recovered,
follow **Blocked outcome**; do not continue to logging.
3. **Log the saved review.** Run Review Log with the saved Completion summary's
values. If the required log is forbidden, show its fields as not persisted
and take **Blocked outcome**. If it fails, apply the write policy's recovery.
Neither case supplies completion or saved-dashboard credit.
and terminal `## GSTACK REVIEW REPORT`; pass its Read-back gate. Forbidden
persistence or an unrecovered save requires **Blocked outcome**, not logging.
3. **Log the saved review.** Run Review Log with saved Completion summary values.
If the required log is forbidden, show fields as not persisted and take **Blocked outcome**;
failures use the write policy's recovery. Neither supplies completion or saved-dashboard credit.
4. **Publish.** Display the Review Readiness Dashboard, then present the saved
Completion summary to the user.
5. **Choose navigation.** Use Next Steps — Review Chaining and wait for its answer.
5. **Choose navigation.** Use Next Steps — Review Chaining; wait for its answer.
Navigation grants no implementation authority. A substantive change follows
**Recovery routing → Late change or missing work** before navigation resumes.
6. **Finish.** Run Learning hooks, then return to the entrypoint's Section
self-check and read-only EXIT PLAN MODE GATE. Run these checks in every host
mode; its final instructions govern telemetry, cache refresh and exit.
6. **Finish.** Run Learning hooks, including gated Brain Calibration Write-Back;
then return to the entrypoint's Section self-check and read-only EXIT PLAN MODE GATE in
every host mode. Only after both pass, run success telemetry and cache refresh;
call ExitPlanMode only in host plan mode.
### Output reference — review body
@@ -1288,7 +1287,7 @@ Do NOT replace the section in place; delete it and append the new report at EOF.
## Review Log
Use these commands in finish step 3, after successful Read-back. The required review log and best-effort decision log each follow the write policy.
Use these commands in finish step 3, after successful Read-back. Both logs follow the write policy: required review log, best-effort decision log.
```bash
~/.claude/skills/gstack/bin/gstack-review-log '{"skill":"plan-eng-review","timestamp":"TIMESTAMP","status":"STATUS","unresolved":N,"critical_gaps":N,"issues_found":N,"mode":"MODE","commit":"COMMIT"}' || exit $?
@@ -1298,7 +1297,6 @@ Use these commands in finish step 3, after successful Read-back. The required re
Second command: `ARCH_SUMMARY` = findings/dispositions; `KEY_DECISION` = durable
architecture choice. Omit it when none exists.
Substitute values from the Completion Summary:
- **TIMESTAMP**: current ISO 8601 datetime
- **STATUS**: "clean" if `issues_found=0`, `unresolved=0` and `critical_gaps=0`; else "issues_open". Count resolved findings too; "issues_open" can mean mapped work, not failure.
- **unresolved**: this review's "Unresolved decisions" count; do not include prior reviews
@@ -1376,16 +1374,15 @@ Flag stale CEO/design reviews from contradictory assumptions or significant comm
drift. If no further review is needed or `skip_eng_review: true`, state
"All relevant reviews complete. Run /ship when ready."
AskUserQuestion with only the applicable options. This is **navigation only**:
copy the working plan's task prerequisites, dependencies and execution order
without adding or strengthening them in the question or descriptions. A test
required before editing one function does not make every independent lane wait.
A next-step answer approves no implementation change.
AskUserQuestion with only applicable options. This is **navigation only**: copy
the working plan's prerequisites, dependencies and execution order without adding
or strengthening them. Do not serialize independent lanes. A next-step answer
approves no implementation change.
## Learning hooks
In finish step 6, keep the working plan/approvals fixed. Review operational learnings
per preamble; use Capture Learnings below for other discoveries. Never log twice.
Keep the working plan/approvals fixed. Use the preamble for
operational learnings, Capture Learnings for other discoveries. Never log twice.
## Capture Learnings
@@ -1414,6 +1411,8 @@ already knows. A good test: would this insight save time in a future session? If
**Calibration gate status:** No supported preamble/config produces `BRAIN_CALIBRATION_WRITEBACK`. Skip unless that source explicitly enables it. Personal trust/MCP availability cannot enable it; never set it yourself.
## Brain Calibration Write-Back (gated)
`BRAIN_CALIBRATION_WRITEBACK` is a reserved default-off gate; this runtime does not set it. Skip this section and continue the finish sequence. Do not enable it or infer permission from brain availability. The contract below is retained for future gated integration, not an instruction to write now.
@@ -10,7 +10,6 @@ Then run **Scope Challenge A → B → C**, followed by Sections 1–4 in order.
## Review record and write policy
Use these terms throughout the review:
- **Target:** the plan, diff or code path selected at the Scope gate. It stays fixed.
- **Working plan:** the proposed work and its current approvals. For a plan target,
start with that plan; for code, build a remedy plan from the findings. This is
@@ -48,10 +47,9 @@ path authorizes no other; implementation edits require explicit authority.
| Required Review Log | The helper's state location | Present its fields as **not persisted**; the final gate cannot pass without this log. |
| Best-effort metadata/learning logs | Helper-defined locations | Skip forbidden writes; otherwise keep their best-effort behavior. |
The QA Test Plan and task JSONL intentionally use legacy discovery paths under
`~/.gstack/projects/{slug}/`: `{user}-{branch}-eng-review-test-plan-{datetime}.md`
and `tasks-eng-review-{datetime}.jsonl`. QA and /autoplan require these paths even
with a different report root. Use their formats/commands below; do not relocate them.
QA Test Plan/task JSONL keep discovery paths `~/.gstack/projects/{slug}/`:
`{user}-{branch}-eng-review-test-plan-{datetime}.md` and
`tasks-eng-review-{datetime}.jsonl`. Keep their formats; do not relocate.
A failed permitted save uses **Recovery routing → Repairable write/read failure**,
not the forbidden-write branches above. Do not ask from an unsaved record.
@@ -84,17 +82,19 @@ building proposed code. Keep suppressed findings for the output appendix.
## Decision procedure
Run this six-step loop for findings from Scope Challenge, Sections 1–4, Outside
Voice, late changes and TODO choices. Finish one choice before the next.
For Scope Challenge, Sections 1–4, Outside Voice, late changes and TODOs, finish
one choice at a time through steps 1–6.
Setup gates—Context Recovery/prerequisites, Prior Learnings configuration,
target and Scope Challenge complexity selectors—use local rules without a
pre-answer ledger. Scope Challenge B saves actual selector answers afterward;
it does not use this remedy loop. These answers approve no engineering remedy.
pre-answer ledger. Scope Challenge B saves actual selector answers afterward,
outside this remedy loop. These answers approve no engineering remedy.
One question for one choice per AskUserQuestion call. Use the preamble for
question transport/fallback and authorized auto-decisions. Use Review
record/write policy only for saved records, reports and logs.
One question for one choice per AskUserQuestion call. Authorities:
- Preamble: question format, transport/fallback and authorized auto-decisions.
- Steps 1–6: substantive choices/answers; Review record/write policy: persistence.
- Entrypoint: **Paused question** for pending answers; **Blocked outcome** for missing work or failed recovery.
- Finish: Approval readiness → Required outputs → entrypoint verification.
### 1. Establish current state
@@ -404,7 +404,7 @@ Rejected extractions still need coverage for real duplicated-code defects.
{{TEST_COVERAGE_AUDIT_PLAN}}
After the Test Plan Artifact is saved or presented, report the Test review findings and their dispositions and continue to Performance review.
After **Add missing tests to the plan** resolves test/eval decisions and the Test Plan Artifact is saved or presented, report the Test review findings and their dispositions and continue to Performance review.
### 4. Performance review
Evaluate:
@@ -414,12 +414,11 @@ Evaluate:
### Continue after Outside Voice
Only completed reviews enter Cross-model tension. Record the actual coverage,
including disabled or unavailable outcomes, then continue below.
Finish the Outside Voice branch. Only completed reviews enter Cross-model tension. Record the actual coverage, including disabled or unavailable outcomes, in the Completion summary, then continue below.
## Final planning decisions
Resolve the TODO choices, then check Approval readiness before Required outputs.
After Sections 1–4 and Outside Voice, resolve the TODO choices, then check Approval readiness before Required outputs.
### TODOS.md updates
Review every potential TODO. Reuse an exact prior disposition under Decision procedure; ask about each unanswered proposal in its own AskUserQuestion. Never batch TODOs or silently skip them. Use `~/.claude/skills/gstack/review/TODOS-format.md`.
@@ -436,31 +435,31 @@ Option C records accepted implementation scope; still do not edit product code.
## Required outputs
Run this finish sequence after Approval readiness passes. Use the references
below for each step, not as another review cycle.
After Approval readiness passes, follow this finish sequence using the reference
sections below; those references are not another review cycle.
For recovery or changed outputs, use the entrypoint's **Recovery routing**.
Reuse a successful Review Log only for unchanged saved outputs; changed outputs
must pass steps 1–4 again.
1. **Prepare the review body.** Use the output reference below to complete the
working plan, Implementation Tasks and Completion summary. Derive unresolved
choices from each record's current State, actual answer and accepted scope;
leave them pending. Save permitted auxiliary artifacts under the write policy.
1. **Prepare the review body.** Complete the working plan, Implementation Tasks
and Completion summary below. Leave choices pending according to each record's
current State, actual answer and accepted scope. Save permitted auxiliary artifacts under the write policy.
2. **Save and Read back.** Use Plan File Review Report to save the complete body
and append its terminal `## GSTACK REVIEW REPORT`. Pass that writer's Read-back
gate. If report persistence is forbidden or the save cannot be recovered,
follow **Blocked outcome**; do not continue to logging.
3. **Log the saved review.** Run Review Log with the saved Completion summary's
values. If the required log is forbidden, show its fields as not persisted
and take **Blocked outcome**. If it fails, apply the write policy's recovery.
Neither case supplies completion or saved-dashboard credit.
and terminal `## GSTACK REVIEW REPORT`; pass its Read-back gate. Forbidden
persistence or an unrecovered save requires **Blocked outcome**, not logging.
3. **Log the saved review.** Run Review Log with saved Completion summary values.
If the required log is forbidden, show fields as not persisted and take **Blocked outcome**;
failures use the write policy's recovery. Neither supplies completion or saved-dashboard credit.
4. **Publish.** Display the Review Readiness Dashboard, then present the saved
Completion summary to the user.
5. **Choose navigation.** Use Next Steps — Review Chaining and wait for its answer.
5. **Choose navigation.** Use Next Steps — Review Chaining; wait for its answer.
Navigation grants no implementation authority. A substantive change follows
**Recovery routing → Late change or missing work** before navigation resumes.
6. **Finish.** Run Learning hooks, then return to the entrypoint's Section
self-check and read-only EXIT PLAN MODE GATE. Run these checks in every host
mode; its final instructions govern telemetry, cache refresh and exit.
6. **Finish.** Run Learning hooks, including gated Brain Calibration Write-Back;
then return to the entrypoint's Section self-check and read-only EXIT PLAN MODE GATE in
every host mode. Only after both pass, run success telemetry and cache refresh;
call ExitPlanMode only in host plan mode.
### Output reference — review body
@@ -531,7 +530,7 @@ From final decisions/outputs; publish after report Read-back and Review Log:
## Review Log
Use these commands in finish step 3, after successful Read-back. The required review log and best-effort decision log each follow the write policy.
Use these commands in finish step 3, after successful Read-back. Both logs follow the write policy: required review log, best-effort decision log.
```bash
~/.claude/skills/gstack/bin/gstack-review-log '{"skill":"plan-eng-review","timestamp":"TIMESTAMP","status":"STATUS","unresolved":N,"critical_gaps":N,"issues_found":N,"mode":"MODE","commit":"COMMIT"}' || exit $?
@@ -541,7 +540,6 @@ Use these commands in finish step 3, after successful Read-back. The required re
Second command: `ARCH_SUMMARY` = findings/dispositions; `KEY_DECISION` = durable
architecture choice. Omit it when none exists.
Substitute values from the Completion Summary:
- **TIMESTAMP**: current ISO 8601 datetime
- **STATUS**: "clean" if `issues_found=0`, `unresolved=0` and `critical_gaps=0`; else "issues_open". Count resolved findings too; "issues_open" can mean mapped work, not failure.
- **unresolved**: this review's "Unresolved decisions" count; do not include prior reviews
@@ -565,19 +563,20 @@ Flag stale CEO/design reviews from contradictory assumptions or significant comm
drift. If no further review is needed or `skip_eng_review: true`, state
"All relevant reviews complete. Run /ship when ready."
AskUserQuestion with only the applicable options. This is **navigation only**:
copy the working plan's task prerequisites, dependencies and execution order
without adding or strengthening them in the question or descriptions. A test
required before editing one function does not make every independent lane wait.
A next-step answer approves no implementation change.
AskUserQuestion with only applicable options. This is **navigation only**: copy
the working plan's prerequisites, dependencies and execution order without adding
or strengthening them. Do not serialize independent lanes. A next-step answer
approves no implementation change.
## Learning hooks
In finish step 6, keep the working plan/approvals fixed. Review operational learnings
per preamble; use Capture Learnings below for other discoveries. Never log twice.
Keep the working plan/approvals fixed. Use the preamble for
operational learnings, Capture Learnings for other discoveries. Never log twice.
{{LEARNINGS_LOG}}
{{GBRAIN_SAVE_RESULTS}}
**Calibration gate status:** No supported preamble/config produces `BRAIN_CALIBRATION_WRITEBACK`. Skip unless that source explicitly enables it. Personal trust/MCP availability cannot enable it; never set it yourself.
{{BRAIN_WRITE_BACK}}