Approved by Garry: asking gstack-qa-evidence or gstack-qa-deadline for usage
is read-only, so both helpers print usage and exit 0 on --help (the evidence
usage now names the annotation shape), and the functional and caller command
allowlists accept exactly 'bun <path>/bin/gstack-qa-{evidence,deadline} --help'.
Two CI runs failed only on that call.
- materialize measures revision, runtime and cwd itself and rejects supplied
values that differ (CI run wrote revision "HEAD" and runtime "bun"), and
refuses learning checkpoints that replay the same probe, naming the fix.
- The docs write observer treats Claude Code's atomic temp for the authorized
doc target as transient, so a temp renamed before its per-file watch no
longer marks the observation incomplete (ship-docsync-completion flake).
Per-file monitoring outside declared targets stays fail-closed.
- ship-docsync-completion: yesterday's audit-scope result dropped the section's
status, so /ship spliced one in; the section now opens with **Status:**.
- ship-docsync-missing-asset: a missing section or old Ship-owned mode blocks
before launch.
- ship-docsync-late-result: the invocation record says prepare already saves
the candidate selection (no extra Read; budget unchanged).
- qa exploratory: await the method Reads before the first probe.
- qa-callers fixture: quote the real review-log record template; allow the
git log command plan-completion prescribes.
- qa functional observer: a receipt caught mid-link(2) is checked at stop
instead of failing with ENOENT (reproduced from CI).
Each repaired case passed a focused paid run.