[ { "id": "s3-judgment-evidence-before-claimed-limitations", "title": "SHARED-JUDGMENT clause 13: evidence before claimed limitations (absorbed)", "kind": "judgment-rule", "fork_refs": [ "fork PR #47 (merge 21a4fdfc, commit 38f0c0ef, branch time-attack/appleship-evidence-clause, v1.64.17.0)", "38f0c0ef", "5757efc6" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s3-judgment-evidence-before-claimed-limitations] ABSORBED as a preamble directive: scripts/resolvers/preamble/generate-evidence-directive.ts:15-17 ('## Claimed Limitations Need Evidence \u2014 A claimed limitation or requirement... is a material claim. State one only with the verbatim error, the documen" ], "notes": "" }, { "id": "s3-judgment-third-party-web-actions-contract", "title": "THIRD-PARTY-ACTIONS.md contract (agentic browser first, per-task consent) (absorbed)", "kind": "judgment-rule", "fork_refs": [ "fork PR #24 (merge 18e0c840, branch time-attack/third-party-actions, v1.63.0.0)", "c8c0c259", "71b54789" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s3-judgment-third-party-web-actions-contract] ABSORBED and extended: scripts/resolvers/third-party-actions.ts:29-45 carries all five rules ('Adapted from time-attack/gstack's THIRD-PARTY-ACTIONS.md'), now recommending Aside by name with detect-and-defer (2026-08-27) and adding CAPTCHA to user-perfo" ], "notes": "" }, { "id": "s3-judgment-apple-release-journey-core", "title": "Apple App Store release adapter roll-ups (APPLE-RELEASE.md) (absorbed; s3 sub-rules stay separate)", "kind": "feature", "fork_refs": [ "fork PR #29 (merge 729134b3, branch time-attack/appleship, v1.64.0.0)", "fork PRs #31-#50 (merges efa24a1e..a6bc2de3)", "df7f296d", "547afe49", "2bbd8a06", "d71162b3", "6452b82e", "8dee3c2b", "0095fec2", "ed070a75", "f20e6102", "b506b4ca" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s3-judgment-apple-release-journey-core] ABSORBED (wave 2, then hardened): ship/sections/apple-release.md.tmpl (58 lines, header credits 'Ported from time-attack/gstack (GStack 2) APPLE-RELEASE.md, refined across 21 live App Store releases'), covering membership gate + free-account ceiling (para 'No" ], "notes": "" }, { "id": "s4-fleet-egress-receipts", "title": "Egress receipts / gstack-egress CLI / verify Stop hook / context-bill calibration (absorbed wave 1)", "kind": "security", "fork_refs": [ "f29966d9", "a78c9a0f", "docs/gstack-2/EGRESS-RECEIPTS.md", "fcd2e444", "24899e7c", "08459f9f", "e933731c", "9606ea63", "7b4fb1a7" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s4-fleet-egress-receipts] ABSORBED: bin/gstack-egress + lib/egress-receipt.ts + bin/gstack-egress-lib.sh per CLAUDE.md; test/egress-receipt-wiring.test.ts:9 ('Every enumerated off-machine sink must route its send through the receipt'), :115 SCANNER_EXEMPT. The per-surface call-site table doc has no" ], "notes": "" }, { "id": "s5-beta-make-pdf-sibling-browse-before-path", "title": "make-pdf resolves sibling browse binary before PATH (6b00ca6b)", "kind": "fix", "fork_refs": [ "6b00ca6b" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s5-beta-make-pdf-sibling-browse-before-path] ABSORBED / pre-existing (00f966b3 v1.30.0.0): make-pdf/src/browseClient.ts:10-20 order GSTACK_BROWSE_BIN -> BROWSE_BIN -> sibling via execPath (#2156) -> ~/.claude/skills/gstack -> Bun.which -> error with hint; :153-162 candidate listing.\n[s4-fleet-make-" ], "notes": "" }, { "id": "s5-beta-ship-multi-ecosystem-markers", "title": "/ship test detection: Django/JVM/Elixir/Rust markers as evidence for the ask (e3259078)", "kind": "fix", "fork_refs": [ "e3259078" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s5-beta-ship-multi-ecosystem-markers] ABSORBED: scripts/resolvers/testing.ts:8-50 contains the identical marker block (manage.py :13, mix.exs :20, pom.xml :21, gradle :22, TESTFILES :32, rust in-source :34) and offer table (:43-50).\n[s4-fleet-django-test-detection] ABSORBED: scripts/resolvers/testi" ], "notes": "" }, { "id": "s5-beta-decision-log-supersede-replacement", "title": "gstack-decision-log --supersede writes the replacement (b4d7abd1)", "kind": "fix", "fork_refs": [ "b4d7abd1" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s5-beta-decision-log-supersede-replacement] ABSORBED (2be6c06b wave 2): bin/gstack-decision-log:57 jsonArg found by leading `{`; :97 `{ ...validPayload(jsonArg), supersedes: targetId }`.\n[s4-fleet-decision-log-supersede] ABSORBED: bin/gstack-decision-log:78-97 (`const replacement = jsonArg ? { ...v" ], "notes": "" }, { "id": "s7-docs-method-telemetry-domain-hashing-policy", "title": "Telemetry privacy: salted-hash security_url_domain + anonymous tier local-only (b79f41ee)", "kind": "security", "fork_refs": [ "evals/privacy/egress-audit-2026-07-28.md residual risk #1", "b79f41ee", "e1cd3096", "94e46742" ], "final": "NOT_APPLICABLE", "basis": "cross-reference", "evidence": [ "browse/src/security.ts:311-316 \u2014 NOTE: logAttempt + salted payload hashing + telemetry spawn plumbing were ripped with sidebar-agent.ts (#2557, CHANGELOG.md:902 v1.67.0.0 / :990-995); grep hashPayload|gstack-telemetry-log|buildTelemetrySpawnCommand in browse/src \u2192 0 hits", "bin/gstack-telemetry-log:46,65,239,253,261 \u2014 `--url-domain` flag still parsed and emitted raw via json_safe only; repo-wide grep url-domain|urlDomain|url_domain|attack_attempt|--event-type outside this file \u2192 0 producers (only supabase/migrations/004_attack_telemetry.sql:9,29,38 and supabase/functions/community-pulse/index.ts:135,156-159 consume it)", "supabase/functions/community-pulse/index.ts:156-159 \u2014 aggregates domainCounts keyed by raw security_url_domain for the 'top domains last 7 days' index (migration 004 line 18) \u2014 upstream's dashboard design intends raw hostnames" ], "notes": "Fork b79f41ee changed 3 things: (1) hash security_url_domain in browse/src/security.ts reportAttemptTelemetry \u2014 upstream deleted that entire producer in v1.67.0.0 (#2557), so no raw domain leaves the " }, { "id": "s5-beta-brain-context-load-cold-probe", "title": "brain-context-load cold-probe latency fix (2fdf6d02, absorbed)", "kind": "fix", "fork_refs": [ "2fdf6d02" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s5-beta-brain-context-load-cold-probe] ABSORBED (2be6c06b wave 2): bin/gstack-brain-context-load.ts:72-73 GSTACK_BRAIN_TIMEOUT_MS override; :199-200 same '500ms budget misreported gbrain as missing whenever a cold process spawn exceeded the timeout' comment.\n[s4-fleet-brain-context-load-cold-probe]" ], "notes": "" }, { "id": "s5-beta-gbrain-policy-ingest-staging-pdf-sanitizer", "title": "gbrain-sync per-repo policy + memory-ingest gbrain 0.42 staging + make-pdf offline sanitizer (absorbed wave 2)", "kind": "security", "fork_refs": [ "b41b4a78", "cca23b2d", "3a082841" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s5-beta-gbrain-policy-ingest-staging-pdf-sanitizer] ABSORBED (wave 2): bin/gstack-gbrain-sync.ts:45,839,870,880 repoPolicyTier chokepoint + skipped-policy-read-only; bin/gstack-memory-ingest.ts:1408-1416 policy counters and #2392 policyError abort; make-pdf/src/render.ts:214,265-281 @import/url()/s" ], "notes": "" }, { "id": "s4-fleet-browse-lock-error-honesty", "title": "browse acquireServerLock reports real errno, only EEXIST is contention (#1084/#1725, absorbed)", "kind": "fix", "fork_refs": [ "4a8833cc", "d947d2e1", "113717b0", "upstream PR #1725 @jbetala7 (OPEN)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s4-fleet-browse-lock-error-honesty] ABSORBED: browse/src/cli.ts:608-641 (ServerLockError, '#1084' comment, ENOENT retry), :263-281 Chromium profile lock helpers (#1781). Busy-daemon preservation (#2231/#2219) belongs to another slice.\n[gap1-s10-browsewave-lock-acquisition-errors] ABSORBED: upstream" ], "notes": "" }, { "id": "s1-prewave-no-suicide-exit-guard", "title": "Remove delayed process.exit test teardowns + no-suicide-exit static guard (#2172/#2252/#2230, absorbed)", "kind": "test-infra", "fork_refs": [ "e7c37d76", "upstream PR #2230", "a26de527", "d947d2e1", "4dced295", "269acaf6", "7741b754", "f0beb1a7", "af10edb1", "2eefdea4", "045bdaa5", "628c76b6", "upstream PR #2172 @sneakygriff (OPEN)", "upstream PR #2252 @whd4 (OPEN)", "upstream PR #2230 @time-attack (OPEN)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s1-prewave-no-suicide-exit-guard] ABSORBED: /home/vercel-sandbox/gstack/test/no-suicide-exit.test.ts exists; v1.77 strict shard classifier also fails a shard without bun's summary line (CLAUDE.md).\n[s4-fleet-no-suicide-exit-test] ABSORBED: test/no-suicide-exit.test.ts exists; no `setTimeout(() => p" ], "notes": "" }, { "id": "s1-prewave-closetab-last-tab-race", "title": "closeTab captures wasActive before page.close() (absorbed 3aab7654)", "kind": "fix", "fork_refs": [ "38381436", "pr-2172-test-env", "upstream PR #2230", "b6572ebb" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s1-prewave-closetab-last-tab-race] ABSORBED: upstream commit 3aab7654 'capture active-tab state before close()'; browse/src/browser-manager.ts:986-1020 (`const wasActive`, 'only reassign when activeTabId no longer points at a live tab').\n[s2-runtime-closetab-wasactive] ABSORBED: upstream browse/src" ], "notes": "" }, { "id": "gap2-skillwave-investigate-hook-paths-claude-skill-dir-1873", "title": "investigate hook paths drop Claude-only CLAUDE_SKILL_DIR (#1873, absorbed)", "kind": "fix", "fork_refs": [ "cdf3531a (maxpetrusenkoagent)", "c896016b (t)", "upstream PR #1873 OPEN (maxpetrusenkoagent); issue #2469 CLOSED 2026-08-15", "8bc0a04f" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[gap2-skillwave-investigate-hook-paths-claude-skill-dir-1873] ABSORBED: investigate/SKILL.md.tmpl:33-38 hooks use `$HOME/.claude/skills/gstack/freeze/bin/check-freeze.sh`; :121-124 comment 'frontmatter hooks ... run before CLAUDE_SKILL_DIR exists ... (#2469)'.\n[s4-fleet-investigate-claude-skill-dir]" ], "notes": "" }, { "id": "s5-beta-windows-spawn-dacl-hardening", "title": "Windows windowsHide spawns (#1835) + .gstack ACL inheritance repair (#1605) (2aa255b7, absorbed)", "kind": "security", "fork_refs": [ "2aa255b7" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s5-beta-windows-spawn-dacl-hardening] ABSORBED (2be6c06b wave 2 and later): browse/src/file-permissions.ts:15-32 icacls inheritance break + explicit grant; windowsHide across browse/src spawns (config.ts:35,90,165; browse-client.ts:106; meta-commands.ts:780,844).\n[s4-fleet-windows-hardening] ABSORB" ], "notes": "" }, { "id": "gap1-s10-browsewave-playwright-bump-headed-executable-pin", "title": "Playwright ^1.60 bump (#1565/#1703, absorbed)", "kind": "fix", "fork_refs": [ "d947d2e1", "de47bf4f", "upstream PR #1565 @stevenbarragan (OPEN)", "6a614f8a" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[gap1-s10-browsewave-playwright-bump-headed-executable-pin] ABSORBED: /home/vercel-sandbox/gstack/package.json:62 `\"playwright\": \"^1.62.1\"` (with patchedDependencies at :90); browse/src/browser-manager.ts:717 `const chromePath = executablePath || chromium.executablePath()` and :757 explicit executab" ], "notes": "" }, { "id": "s7-docs-method-platform-bakeoff", "title": "Model-benchmark lib / Braintrust rewrite / eval-platform bakeoff (NOT_APPLICABLE direction decision)", "kind": "tooling", "fork_refs": [ "evals/platform-bakeoff/README.md", "evals/platform-bakeoff/platform_bakeoff.py", "evals/platform-bakeoff/results/REAL-BAKEOFF.md", "ce8088d5", "36f972f2", "7f4574e1", "0645f52f", "b6572ebb" ], "final": "NOT_APPLICABLE", "basis": "cross-reference", "evidence": [ "grep -rli 'braintrust|langfuse|deepeval|autoevals|bake-off|bakeoff' across upstream .ts/.md/.json/.py (excluding node_modules/dist) \u2192 only scripts/brain-cache-spec.ts (BrainTrustPolicy = gbrain trust policy, unrelated)", "ls lib/model-benchmark evals \u2192 both missing; bin/gstack-model-benchmark:1-40 imports test/helpers/benchmark-runner.ts + providers/{claude,gpt,gemini}; `--judge` = Anthropic SDK judge (test/helpers/benchmark-judge.ts)", "grep -i 'rubric|required.term|requiredTerm|upload|writeReceipt|fetch(' bin/gstack-model-benchmark test/helpers/benchmark-runner.ts test/helpers/benchmark-judge.ts \u2192 0 (no deterministic rubric scorer, no upload sink)" ], "notes": "The fork's arc (b6572ebb in-house runner/judge/pricing \u2192 36f972f2/7f4574e1 Braintrust owns scoring \u2192 0645f52f consent gate \u2192 ce8088d5 Python bake-off) ends in a recommendation to stay provider-neutral" }, { "id": "s4-fleet-runtime-cli-main-guard", "title": "runtime/cli.js direct-execution main() guard (fork runtime only)", "kind": "fix", "fork_refs": [ "020b84a2", "5cc8ba1c" ], "final": "NOT_APPLICABLE", "basis": "pre-classified from sweep (fork-runtime-only)", "evidence": [ "[s4-fleet-runtime-cli-main-guard] NOT_APPLICABLE: no runtime/ directory upstream; gen-skill-docs main() guard noted in CLAUDE.md.\n[s6-branches-runtime-cli-direct-entry-fix] ls /home/vercel-sandbox/gstack \u2192 no runtime/ directory." ], "notes": "" }, { "id": "s5-beta-ios-stateserver-loopback-bind", "title": "ios-qa StateServer binds loopback only (d22c034e, absorbed)", "kind": "security", "fork_refs": [ "d22c034e" ], "final": "ABSORBED", "basis": "cross-reference (skeptic confirmed)", "evidence": [ "ios-qa/templates/StateServer.swift.template:154-167 \u2014 IPv4 listener uses params.requiredLocalEndpoint = 127.0.0.1 (`NWListener(using: params)`), IPv6 keeps the wildcard port bind; landed in 2be6c06b v1.65.0.0 (fork port wave 2), diff shows the identical switch/case as fork d22c034e.", "ios-qa/templates/StateServer.swift.template:176-184 \u2014 newConnectionHandler gates every connection through isLoopbackPeer(); :198-215 accepts loopback or RFC 4193 ULA fc00::/7 (CoreDevice tunnel) and cancels everything else.", "ios-qa/templates/StateServer.swift.template:4 ('Loopback-only'), :32-33 (dual-stack listeners; 'The fork's single-listener IPv6-only binding was caught in eng + outside-voice review as incomplete')." ], "notes": "The fork's bug (wildcard IPv4 bind with dead loopback config) does not exist at upstream HEAD; the fix landed with wave 2 (v1.65.0.0). Only a comment/dead-code tidy remains \u2014 fold into any future ios-" }, { "id": "gap5-hygiene-beta-first-measurement-recalibration", "title": "2026-08-09 eval timeout recalibration / auq-format-gate demotion (dispatcher-surface specific)", "kind": "test-infra", "fork_refs": [ "35a39e58", "21bb1dd7" ], "final": "NOT_APPLICABLE", "basis": "cross-reference", "evidence": [ "test/helpers/eval-budgets.ts:2-15 \u2014 'Timeout policy for paid tests \u2014 five tiers instead of hand-tuned sprawl\u2026 46\u00d7300s, 46\u00d7120s, 44\u00d7360s\u2026 hand-ratcheted per test'; :19 JUDGE_MS=120_000, :22 CAPTURE_MS=300_000, :25 CAPTURE_LONG_MS=600_000, :28 PTY_MS=900_000, :35 PTY_LONG_MS=1_200_000", "test/eval-budgets-policy.test.ts:1-14 \u2014 FIT invariant (every tier fits the sharded runner wall minus 120s overhead) + RATCHET invariant ('raw numeric timeout literals in paid test files only shrink\u2026 a literal is legal only with justification, and the count is pinned')", "CHANGELOG.md:311 (v1.74.0.0, 2026-08-29) '| Hand-tuned paid timeout literals | 395 | 97 (46 justified) | 5 tiers |', :332 (seven 28-min timeouts inside 25-min jobs trimmed; eval-budgets fit test), :339 ('298 paid timeout literals swept onto five named tiers\u2026 round-up only')" ], "notes": "Resolves the earlier UNKNOWN: the fork's premises (dispatcher-tree turn counts; 'measured the REAL 2.0 surface for the first time'; no green baseline for auq-format-gate) are all specific to the GStac" }, { "id": "gap5-hygiene-windows-setup-e2e-runtime-lane", "title": "windows-setup-e2e.yml rewrite around GStack 2 runtime installer", "kind": "ci", "fork_refs": [ "git diff upstream/main origin/main -- .github/workflows/windows-setup-e2e.yml (origin/main 0aca1f77)", "f14445bb" ], "final": "NOT_APPLICABLE", "basis": "cross-reference", "evidence": [ "/home/vercel-sandbox/gstack/.github/workflows/windows-setup-e2e.yml:72-113 \u2014 lane is `bun run build` (GSTACK_SKIP_PLAYWRIGHT=1) + .exe presence + find-browse + gstack-paths checks; it never runs ./setup, so there is no state root to isolate", "/home/vercel-sandbox/gstack/.github/workflows/windows-setup-e2e.yml:28-36 \u2014 PR-number concurrency key with the explicit comment that head_ref (the fork's shape) collides across forks; `permissions: contents: read` (secretless lane)", "/home/vercel-sandbox/gstack/setup:18-42 \u2014 usage block lists --host/--model/--prefix/--no-prefix/--team/--no-team/-q/-h only; `grep -nE 'dry-run|DRY_RUN|dry_run|--preview' setup` \u2192 0 hits (no preview mode to assert non-mutation against)" ], "notes": "Fork commit f14445bb (2026-07-20, on fork main) is the 'componentize GStack 2 runtime' wave; the workflow rewrite is a consequence of that architecture. Upstream is not adopting the runtime, so the la" }, { "id": "gap2-skillwave-autoplan-tasks-aggregator-jq-bind-2021", "title": "autoplan tasks aggregator jq .commit bind (#2021/#2018, absorbed)", "kind": "fix", "fork_refs": [ "703e2027, a1997cbc (0xDevNinja)", "upstream PR #2021 OPEN (0xDevNinja); issue #2018 CLOSED 2026-08-15", "fork PR #8 (377b0747)", "upstream issue #2021 (OPEN)", "upstream issue #2018" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[gap2-skillwave-autoplan-tasks-aggregator-jq-bind-2021] ABSORBED: scripts/resolvers/tasks-section.ts:123-128 ('.commit must be bound BEFORE piping to the split commit array' + `.commit as $c | select(...)`); test/tasks-section-jq.test.ts:1-18 regression pin for #2018; CHANGELOG.md:1233,1306.\n[s1-pre" ], "notes": "" }, { "id": "gap2-skillwave-diff-dep-bump-1599", "title": "diff ^7 \u2192 ^9 GHSA bump (#1599, absorbed)", "kind": "security", "fork_refs": [ "ac2c88aa (genisis0x)", "upstream PR #1599 OPEN (genisis0x); issue #1588 CLOSED 2026-08-15", "d0fd2c0f" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[gap2-skillwave-diff-dep-bump-1599] ABSORBED: package.json:59 `\"diff\": \"^9.0.0\"`; CHANGELOG.md:1613 'diff 9.0.0 (GHSA-73rr-hh4g-fpgx, @genisis0x)'.\n[s1-prewave-diff-pkg-ghsa-bump] ABSORBED: package.json:59 `\"diff\": \"^9.0.0\"`; bun.lock resolves `diff@9.0.0`." ], "notes": "" }, { "id": "gap2-skillwave-extension-getport-token-withhold-1822", "title": "extension getPort withholds token from non-extension senders (#1822, absorbed via sender-auth.js)", "kind": "security", "fork_refs": [ "2e7fcd73 (Mike Ilog / Mike-E-Log)", "c6b466e1 (t, test)", "upstream PR #1822 OPEN (Mike-E-Log)", "0af2add8", "upstream PR #1822 (OPEN)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[gap2-skillwave-extension-getport-token-withhold-1822] ABSORBED: extension/sender-auth.js exists; extension/background.js:317-328 'Privileged types ... are for this extension's own pages only ... gstackSenderAuth.denialFor(msg.type, sender, chrome.runtime.id)' before the getPort handler at :330.\n[s1" ], "notes": "" }, { "id": "s2-runtime-dependency-review-osv-workflows", "title": "dependency-review.yml + osv-scanner.yml CI gates (#2038, absorbed)", "kind": "ci", "fork_refs": [ "09492d34", "6fe51219 (Jayesh Betala / jbetala7)", "964602a3 (Sinabina, fork-only removal)", "upstream PR #2038 OPEN (jbetala7)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s2-runtime-dependency-review-osv-workflows] ABSORBED in wave 2 (v1.65.0.0 'supply-chain CI'): upstream .github/workflows/dependency-review.yml and osv-scanner.yml exist (both listed in .github/workflows; osv-scanner.yml has 1 SHA-pinned ref, dependency-review.yml 2), plus test/osv-config-wiring.tes" ], "notes": "" }, { "id": "s2-runtime-release-pipeline-windows-archive", "title": "GStack 2 runtime packaging, attestation, release lane and npm/CI plumbing (NOT_APPLICABLE cluster)", "kind": "ci", "fork_refs": [ "dbf94804", "b0047cc5", "75b35766", "f7d44a4e", "bec9b9be", ".github/workflows/release-artifacts.yml", "docs/gstack-2/RELEASE-INTEGRITY.md", ".github/scripts/create-runtime-release-manifest.mjs", ".github/scripts/stage-runtime-components.mjs", "f9afa73d", "c1e45019", "2f19f0b5", "f14445bb", "d6ef673e", "b6572ebb", "31ae801c" ], "final": "NOT_APPLICABLE", "basis": "pre-classified from sweep (fork-runtime-only)", "evidence": [ "[s2-runtime-release-pipeline-windows-archive] Upstream has no release-artifacts workflow, cosign, or runtime bootstrap; windows-free-tests.yml:135 uses actions/upload-artifact rather than tar.\n[s7-docs-method-release-artifacts-attestation] NOT CHECKED beyond confirming absence: grep -i 'cosign|sigst" ], "notes": "" }, { "id": "s2-runtime-execution-result-contract", "title": "GStack 2 runtime internals: execution-result envelope, locks, deadlines, identity plumbing (NOT_APPLICABLE cluster)", "kind": "methodology", "fork_refs": [ "9b5ae407", "9b3188e7", "9bb382f2", "b6e4ad5a", "b6572ebb", "f14445bb", "d6ef673e", "a84a6e23", "e1cd3096", "b79f41ee", "231fb9d7", "f19d6cda", "a9399ad3", "682f6d03", "d7908b25", "b85497d7" ], "final": "NOT_APPLICABLE", "basis": "pre-classified from sweep (fork-runtime-only)", "evidence": [ "[s2-runtime-execution-result-contract] grep schemaVersion/EXECUTION_RESULT/'execution result' across lib/*.ts bin/*.ts scripts/resolvers/*.ts returns nothing; upstream has no shared CLI result envelope to attach this to.\n[s2-runtime-runcommand-deadline-kill-grace] Upstream has no runtime/; grep Abor" ], "notes": "" }, { "id": "s9-skills-dispatcher-header-and-alias-tables", "title": "GStack 2 six-dispatcher architecture scaffolding: headers, alias/compat tables, migration map, runtime-absent probe, parity fixtures (NOT_APPLICABLE cluster)", "kind": "judgment-rule", "fork_refs": [ "b6572ebb", "682f6d03", "a9399ad3", "docs/gstack-2/SKILL-MIGRATION.md", "1b38be6a", "44221ac7", "ac06a37d", "3ebde802", "e6f602bc", "8502961b", "fork PRs #18, #19, #21, #25, #26, #30 (regression fixtures)" ], "final": "NOT_APPLICABLE", "basis": "pre-classified from sweep (fork-runtime-only)", "evidence": [ "[s9-skills-dispatcher-header-and-alias-tables] Upstream architecture unchanged (44 skill dirs, scripts/gen-skill-docs.ts, _gstack-command router); TODOS.md:460-505 and PACING_UPDATES_V0.md:97-110 record what upstream chose to fold in from the fork instead. grep 'Skipped modules|Context\\.dev|Global C" ], "notes": "" }, { "id": "s2-runtime-shard-isolation-heuristics", "title": "GStack 2 dispatcher-surface test-runner and tier adjustments (NOT_APPLICABLE cluster)", "kind": "test-infra", "fork_refs": [ "d7357c28", "37144e8b", "8fd8bf43", "37042b68", "9504b703", "a3ed7a68", "44221ac7" ], "final": "NOT_APPLICABLE", "basis": "pre-classified from sweep (fork-runtime-only)", "evidence": [ "[s2-runtime-shard-isolation-heuristics] Upstream scripts/test-free-shards.ts has none of containsScheduledProcessExitZero/planBoundedFreeTestShards (grep empty), scripts/test-free-strict.ts does not exist; test/no-suicide-exit.test.ts fails the suite on any scheduled process.exit in a test file, and" ], "notes": "" }, { "id": "s6-branches-windows-isolated-gates-harness", "title": "Windows isolated cloud gates harness for specific upstream PR heads (NOT_APPLICABLE cluster)", "kind": "ci", "fork_refs": [ "fe868994", "9c1ddd79", "60863a71", "f915a246", "808bb546", "codex/windows-gates-20260715-central" ], "final": "NOT_APPLICABLE", "basis": "pre-classified from sweep (fork-runtime-only)", "evidence": [ "[s6-branches-windows-isolated-gates-harness] Upstream .github/workflows has windows-free-tests.yml and windows-setup-e2e.yml (curated subset + fresh-install gate), no per-PR isolated harness. `gh pr view` 1743/1981/2260/2243/2245/2246/2247 \u2192 all OPEN, unmerged. `gh run list -R time-attack/gstack --b" ], "notes": "" }, { "id": "gap3-design-daemon-reset-cancels-shutdown-timers", "title": "design daemon resetForTest clears shutdown/exit timers", "kind": "test-infra", "fork_refs": [ "467161bd", "b6572ebb" ], "final": "SUPERSEDED", "basis": "cross-reference", "evidence": [ "design/src/daemon.ts:206 `setTimeout(() => process.exit(exitCode), 50);` \u2014 untracked handle (fork stores it in exitTimer)", "design/src/daemon.ts:489 `setTimeout(() => gracefulShutdown(0), 50);` \u2014 untracked handle (fork stores it in shutdownTimer)", "design/src/daemon.ts:570-581 __testInternals__.resetForTest clears boards/boardMutex/lastMeaningfulActivity/idleExtensions/shuttingDown only; grep 'clearTimeout|shutdownTimer|exitTimer|shutdownRequestTimer' design/src/daemon.ts -> 0" ], "notes": "The fork's stated failure (an in-process /shutdown test process.exit(0)s the bun runner mid-suite, later files silently skipped, CI green) can no longer occur upstream: the one such test stubs exit, t" }, { "id": "s2-runtime-handoff-singleton-lock-cleanup", "title": "Handoff uses resolveChromiumProfile() + SingletonLock cleanup (absorbed)", "kind": "fix", "fork_refs": [ "b6572ebb", "7b3f391b" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s2-runtime-handoff-singleton-lock-cleanup] ABSORBED: upstream browse/src/browser-manager.ts:1796 `const userDataDir = resolveChromiumProfile();` and :1798 `cleanSingletonLocks(userDataDir);` inside handoff().\n[s1-prewave-handoff-resolve-chromium-profile] ABSORBED: browse/src/browser-manager.ts:663 " ], "notes": "" }, { "id": "s2-runtime-stop-ack-before-shutdown", "title": "browse stop/restart acknowledge before shutdown (#2020, absorbed)", "kind": "fix", "fork_refs": [ "b6572ebb", "9919c4cd", "d947d2e1", "d8c64ee2", "upstream PR #2020 @devkd111 (OPEN)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s2-runtime-stop-ack-before-shutdown] ABSORBED (wave 2 'browse stop fix'): upstream browse/src/meta-commands.ts:424-436 contains the identical comment and deferred shutdown; browse/test/stop-ack-before-shutdown.test.ts is byte-identical to the fork's.\n[gap1-s10-browsewave-daemon-stop-restart-defer] " ], "notes": "" }, { "id": "s1-prewave-live-daemon-preservation", "title": "Never kill a live-but-busy browse daemon / loaded-machine lifecycle (#2219/#1732/#1847, absorbed)", "kind": "fix", "fork_refs": [ "d8a7d014", "time-attack/2219", "upstream PR #2231", "upstream issue #2219", "d947d2e1", "94deed4b", "efebbff9", "83f872cc", "upstream PR #1732 @mplatts (OPEN)", "upstream PR #1847 @harjothkhara (CLOSED)", "upstream PR #2231 @time-attack (OPEN)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s1-prewave-live-daemon-preservation] ABSORBED: browse/src/cli.ts:684-686 daemonPidAlive + probeHealthWithBackoff, :733-745 '#2219 IRON RULE' + forceRestart, :871-895 decideDaemonRestart/report-busy; issue #2219 CLOSED 2026-08-17.\n[gap1-s10-browsewave-loaded-machine-daemon-lifecycle] ABSORBED: brows" ], "notes": "" }, { "id": "gap4-s13-ios-xcuitest-executor-planner", "title": "ios-qa/executor: IOSQAFlow \u2192 XCUITest xcodebuild argv planner (466b1ec7)", "kind": "tooling", "fork_refs": [ "466b1ec7", "time-attack/gstack PR #14" ], "final": "NOT_APPLICABLE", "basis": "cross-reference", "evidence": [ "ls /home/vercel-sandbox/gstack/ios-qa/ \u2192 SKILL.md, SKILL.md.tmpl, daemon, docs, scripts, templates (no executor/)", "grep -rnE 'IOSQAFlow|selectorCandidates|xcuitest-plan|GSTACK_IOS_QA_FLOW|buildXCUITestPlan|XCUITestRunnerConfig' across upstream \u2192 0", "ls test/fixtures/ios-qa/FixtureApp/Tests \u2192 DebugBridgeCoreTests only (no AdaptiveFixtureUITests / GStackFlowRunnerUITests.swift)" ], "notes": "Upstream still has no flow\u2192xcodebuild planner, but the planner only makes sense as the argv side of an XCUITest runner target, and upstream's ios-qa architecture (SKILL.md.tmpl:41; CHANGELOG 'no XCTes" }, { "id": "s1-prewave-sidebar-chat-era-test-deletion", "title": "Delete chat-queue-era sidebar tests, re-pin surviving invariants (#1984, absorbed)", "kind": "test-infra", "fork_refs": [ "514e5294", "upstream PR #2230", "d947d2e1", "045bdaa5", "upstream PR #1984 @maxpetrusenkoagent (OPEN)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "[s1-prewave-sidebar-chat-era-test-deletion] ABSORBED: `ls browse/test/security-sidepanel-dom.test.ts browse/test/sidebar-integration.test.ts` \u2192 No such file; browse/test/sidebar-ux.test.ts present.\n[gap1-s10-browsewave-sidebar-ux-test-refresh] NOT_APPLICABLE: upstream browse/test/sidebar-ux.test.ts " ], "notes": "" }, { "id": "s3-judgment-design-docs-repo-local", "title": "Design docs written to docs/designs/.md in the repo; reviews prefer the repo-local copy (#703)", "kind": "judgment-rule", "fork_refs": [ "fork PR #18 (merge c3dbec14, v1.61.0.0)", "upstream issue #703 (CLOSED 2026-08-15)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED (wave 2): office-hours/sections/design-and-handoff.md.tmpl:20-35 'Repo copy (dual-write, #703 + #2000)... ALSO write the doc to docs/designs/{topic-slug}.md' with a redaction scan-at-sink the fork did not have; scripts/resolvers/design-doc-discovery.ts:6-7,32-39 'Repo-local docs win when at" ], "notes": "" }, { "id": "s3-judgment-design-doc-concision", "title": "Design doc is a decision record: bullets, one line per ruled-out approach, omit settled/empty sections (#2000)", "kind": "judgment-rule", "fork_refs": [ "fork PR #19 (merge 7d5c110b, branch time-attack/designdocs, v1.61.1.0)", "upstream issue #2000 (CLOSED 2026-08-15)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED: office-hours/sections/design-and-handoff.md.tmpl:37-42 'Decision-record concision (#2000). The doc is a decision record, not a transcript: one bullet per decision with its why; an approach the user ruled out DURING the session gets one line (name + rejection reason)... No page cap'; CHANGE" ], "notes": "" }, { "id": "s3-judgment-founder-resources-optout", "title": "Founder resources honor a persistent 'Never show me these again' opt-out (#538)", "kind": "judgment-rule", "fork_refs": [ "fork PR #26 (merge a1afacea, branch time-attack/motiviation, v1.61.2.0)", "upstream issue #538 (CLOSED 2026-08-15)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED with an upstream improvement: office-hours/sections/design-and-handoff.md.tmpl:343-366 ('Standing opt-out check (#538) \u2014 run FIRST... skip this entire section silently... VERIFY the write... before promising anything'); bin/gstack-config:164 default true, :400-401 validation; test/founder-r" ], "notes": "" }, { "id": "s3-judgment-apple-adapter-before-branch-gate", "title": "Store distribution is not repository landing: Apple adapter loads before the branch gate; never abort over branch topology (#41)", "kind": "judgment-rule", "fork_refs": [ "fork PR #41 (merge a28f0b59, branch time-attack/appleship-mode-routing, v1.64.11.0)", "fork PR #29 step 10" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED: ship/SKILL.md.tmpl:80-90 'Step 0.9: Apple target detection \u2014 Shipping to the App Store is not landing a PR... STOP and Read ship/sections/apple-release.md FIRST \u2014 before the branch gate and any preflight... The branch gate and repository-landing pipeline below apply ONLY to repository-land" ], "notes": "" }, { "id": "s3-judgment-apple-two-permitted-interactions", "title": "The Apple journey permits exactly two interactions: the authorization/sign-in moment and the missing-assets question (#35, #36, #37)", "kind": "judgment-rule", "fork_refs": [ "fork PR #35 (merge 65b65013, v1.64.6.0)", "fork PR #36 (merge fdb68f88, v1.64.7.0)", "fork PR #37 (merge c6f8f1f1, v1.64.8.0)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED verbatim: ship/sections/apple-release.md.tmpl 'The one authorization moment' para ('The whole journey permits exactly two interactions, and no others... Auth menus, tool-choice questions, plan confirmations, and step-by-step narration requests are contract violations.') and para 2 ('One too" ], "notes": "" }, { "id": "s3-judgment-apple-sticky-assets-decision-store", "title": "Store-assets question asked once per app, ever \u2014 decision store checked before asking, persisted after (#38)", "kind": "judgment-rule", "fork_refs": [ "fork PR #38 (merge 7d4529d3, branch time-attack/appleship-sticky-assets, v1.64.9.0)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED verbatim: ship/sections/apple-release.md.tmpl 'Store assets' para ('Once per app, EVER: before asking, check the decision store (`bin/gstack-decision-search --scope repo --query \"store assets\"`)... persist it (`~/.claude/skills/gstack/bin/gstack-decision-log` with scope `repo`)'). Header co" ], "notes": "" }, { "id": "s3-judgment-apple-deck-editor-no-key-live-check", "title": "Marketing screenshots never require an API key; the free deck editor leads; options built from a LIVE installed-skill check (#39, #42)", "kind": "judgment-rule", "fork_refs": [ "fork PR #39 (merge bdcd6e13, v1.64.10.0)", "fork PR #42 (merge 9c75ec20, v1.64.12.0)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED verbatim: ship/sections/apple-release.md.tmpl 'Store assets' section \u2014 bullet 'Marketing screenshots, free and local, no API key... never claim screenshots need an API key while this skill is installed' and closing para 'Build this question's options from a LIVE check of installed skills at" ], "notes": "" }, { "id": "s3-judgment-apple-session-mints-upload-key", "title": "Session-minted App Store Connect upload key; nobody types an app-specific password (#43, #48)", "kind": "judgment-rule", "fork_refs": [ "fork PR #43 (merge 2de5c36f, v1.64.13.0)", "fork PR #48 (merge ba82dc01, branch time-attack/upload-key-mint, v1.64.18.0)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED and hardened: ship/sections/apple-release.md.tmpl step 4 carries the full mint procedure verbatim plus upstream's least-privilege change \u2014 `allAppsVisible:false` with an explicit app-scoped `apps` relationship instead of the fork's `allAppsVisible:true`, and PATCH re-association for a secon" ], "notes": "" }, { "id": "s3-judgment-apple-credential-browser-ban-and-escalation-ladder", "title": "Browser-driven credential creation banned; auth failures escalate mint \u2192 re-sign-in \u2192 self-service ASP only on permissions refusal (#44, #45)", "kind": "judgment-rule", "fork_refs": [ "fork PR #44 (merge 9b5ad8a2, v1.64.14.0)", "fork PR #45 (merge fe194ef0, v1.64.15.0)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED and triple-pinned: ship/sections/apple-release.md.tmpl step 5 verbatim ('NEVER offer or recommend a browser drive to create credentials \u2014 no agentic browser of any kind, for any password, key, or token, under any framing'); scripts/resolvers/third-party-actions.ts:39 'Creating Apple credent" ], "notes": "" }, { "id": "s3-judgment-apple-classify-errors-before-credentials", "title": "Classify errors before touching credentials (metadata vs auth); adapter overrides the third-party browser offer for the whole Apple journey (#46)", "kind": "judgment-rule", "fork_refs": [ "fork PR #46 (merge 05ef17b8, branch time-attack/appleship-cli-only, v1.64.16.0)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED verbatim: ship/sections/apple-release.md.tmpl step 4 ('CLASSIFY the error before touching credentials... lootBox, ageAssurance, parentalControls, messagingAndChat') and step 5 ('this adapter OVERRIDES the Third-Party Web Actions contract (earlier in this skill)... the ONLY browser use this " ], "notes": "" }, { "id": "s3-judgment-apple-pricing-in-authorization", "title": "Pricing (free/paid + price) folded into the authorization moment, once per app, decision-store persisted; storefront pricing via appPriceSchedules because fastlane price_tier is broken (#49)", "kind": "judgment-rule", "fork_refs": [ "fork PR #49 (merge 138e7138, branch time-attack/pricing-question, v1.64.19.0)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED verbatim: ship/sections/apple-release.md.tmpl 'The one authorization moment' ('Pricing belongs to this same breath, once per app EVER... a free launch cannot be un-launched') and 'Storefront completion' ('`POST /v1/appPriceSchedules`... fastlane's `price_tier` option is broken against the c" ], "notes": "" }, { "id": "s3-judgment-apple-non-mac-macos-ci-runner", "title": "Non-macOS hosts: honest Mac-required split \u2014 build/sign/upload legs route through a macOS CI runner with the minted key as a secret; API legs stay local (#50)", "kind": "judgment-rule", "fork_refs": [ "fork PR #50 (merge a6bc2de3, commit df7f296d, branch time-attack/windows-ci-lane, v1.64.20.0)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED verbatim: ship/sections/apple-release.md.tmpl para 3 ('A Mac is required only for the build legs... route exactly those legs through a macOS CI runner (a GitHub Actions `macos` runner...)... Never claim the whole release is impossible off a Mac, and never pretend the build leg is possible t" ], "notes": "" }, { "id": "s3-judgment-apple-intermediate-browser-drive-and-asc-cli", "title": "Intermediate Apple-adapter states: agentic-browser drive of App Store Connect forms (#31), asc CLI app-record creation (#32), .p8-first auth (#29/#33) \u2014 superseded within the fork", "kind": "judgment-rule", "fork_refs": [ "fork PR #31 (v1.64.2.0)", "fork PR #32 (v1.64.3.0)", "fork PR #33 (merge efa24a1e, v1.64.4.0)", "fork PR #34 (merge 1a67db98, v1.64.5.0)" ], "final": "NOT_APPLICABLE", "basis": "pre-classified from sweep (fork-runtime-only)", "evidence": [ "NOT_APPLICABLE by design: upstream ship/sections/apple-release.md.tmpl encodes only the final state \u2014 fastlane `produce` for the app record ('never call the app record a manual gate'), no `asc`, browser only for 'the paid Apple Developer Program membership purchase itself... and, for PAID apps only," ], "notes": "" }, { "id": "s1-prewave-health-token-removal", "title": "/health status-only, token via pinned-origin bootstrap", "kind": "security", "fork_refs": [ "7b3f391b", "upstream PR #2226" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED: browse/src/server.ts:1870-1915 (`POST /extension-token \u2014 pinned-origin token bootstrap`, 'Health check ... NEVER carries a token in any mode'); extension/manifest.json:6 `key`; extension/background.js:41-56." ], "notes": "" }, { "id": "s1-prewave-extension-storage-session-auth", "title": "Provision extension auth via chrome.storage.session (TRUSTED_CONTEXTS) instead of HTTP", "kind": "security", "fork_refs": [ "7b3f391b", "upstream PR #2226" ], "final": "NOT_APPLICABLE", "basis": "pre-classified from sweep (fork-runtime-only)", "evidence": [ "NOT_APPLICABLE (alternative design shipped): browse/src/server.ts:1885-1908; extension/sender-auth.js:29-60 (PRIVILEGED_TYPES incl. getPort/getToken, denialFor); browse/test/extension-token.test.ts, server-auth.test.ts, dual-listener.test.ts reference /extension-token; grep storage.session/TRUSTED_C" ], "notes": "" }, { "id": "s1-prewave-ws-subprotocol-duplicate-header", "title": "Fix WS upgrade 1006 from duplicated Sec-WebSocket-Protocol echo", "kind": "fix", "fork_refs": [ "7b3f391b", "upstream PR #2226" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED: browse/src/terminal-agent.ts:640 'No explicit Sec-WebSocket-Protocol echo: Bun >= 1.3 auto-echoes'; extension/sidepanel-terminal.js:308,585,807 still use `gstack-pty.${token}` (upstream's chosen format)." ], "notes": "" }, { "id": "s1-prewave-artifacts-init-push-protocol", "title": "gstack-artifacts-init honors configured push protocol / preserves explicit URLs (--push-protocol)", "kind": "fix", "fork_refs": [ "d6b300cf", "test-issue-1348", "upstream PR #2225", "fork PR #7 commit f036446f" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED: bin/gstack-artifacts-init:11 usage, :67-82 PUSH_PROTOCOL/REMOTE_SOURCE, :218-256 resolution incl. `preserve` and `gh config get git_protocol`; test/gstack-artifacts-init.test.ts:277-380 (same test titles as fork incl. '--push-protocol overrides the inferred protocol')." ], "notes": "" }, { "id": "s1-prewave-basic-ftp-pin", "title": "Pin basic-ftp to 5.3.1 (four HIGH advisories)", "kind": "security", "fork_refs": [ "fork PR #2 (5ca87456)", "upstream PR #2227" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED: `git log -S basic-ftp -- package.json` shows f55e2709 'override basic-ftp to 5.3.1' then ae8914af (v1.67.0.0); grep basic-ftp in package.json/bun.lock now empty (dependency gone)." ], "notes": "" }, { "id": "s1-prewave-catalog-lead-embedded-periods", "title": "gen-skill-docs catalog lead: don't split on embedded periods (filenames, URLs, versions)", "kind": "fix", "fork_refs": [ "fork PR #3 (2f6c3e96)", "upstream issue #2171 (OPEN)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED: scripts/gen-skill-docs.ts:344-353 regex `^((?:[^.!?]|[.!?](?!\\s|$))*[.!?])(?:\\s|$)` with comment naming 'TODOS.md', URLs, 'v1.45.0.0'; test/catalog-trim.test.ts:132-145 regression tests for DESIGN.md/v1.45.0.0/'TODOS.md backlog'." ], "notes": "" }, { "id": "s1-prewave-hermes-namespaced-frontmatter", "title": "Hermes-generated frontmatter `name:` matches the namespaced directory", "kind": "fix", "fork_refs": [ "fork PR #4 (bb68b1c2)" ], "final": "NOT_APPLICABLE", "basis": "pre-classified from sweep (fork-runtime-only)", "evidence": [ "NOT_APPLICABLE: hosts/hermes.ts:32-37 'No full install arm \u2014 users can hand-copy the instruction-only digest', instructionTier rulesFile; grep nameTransform|emittedName|external-skill-name in scripts/gen-skill-docs.ts and scripts/host-config.ts empty; .gitignore:23 `.hermes/`." ], "notes": "" }, { "id": "s1-prewave-codex-web-search-flag", "title": "Drop deprecated `--enable web_search_cached` from every codex exec/review invocation", "kind": "fix", "fork_refs": [ "fork PR #5 (5f9d132e)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED (different judgment): scripts/resolvers/constants.ts:50-65 CODEX_WEB_SEARCH_FLAG with comment 'codex >=0.144 deprecated the legacy --enable-based web_search_cached'; codex/SKILL.md.tmpl:245 documents the -c override." ], "notes": "" }, { "id": "s1-prewave-gstack-paths-get", "title": "`gstack-paths --get ` scalar output; codex skill avoids eval", "kind": "tooling", "fork_refs": [ "fork PR #5 (deed6e85)" ], "final": "NOT_APPLICABLE", "basis": "pre-classified from sweep (fork-runtime-only)", "evidence": [ "NOT_APPLICABLE: bin/gstack-paths:16 'values are emitted shell-quoted (printf %q) so eval round-trips them'; codex/SKILL.md.tmpl:130 still `eval \"$(~/.claude/skills/gstack/bin/gstack-paths)\"`; no `--get` (grep empty)." ], "notes": "" }, { "id": "s1-prewave-design-variant-count-validation", "title": "design `--count` rejects non-integer/zero/negative instead of silently generating nothing", "kind": "fix", "fork_refs": [ "fork PR #6 (03c0d24d, 9a04c05f)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED: design/src/flag-utils.ts:1-45 (`--count abc \u2192 for (i < NaN) never runs \u2192 ZERO variants, exit 0`, parseIntFlag; landed 94993f74 v1.61.0.0)." ], "notes": "" }, { "id": "s1-prewave-design-timeout-message", "title": "Design image timeout message matches the real 240s timer", "kind": "fix", "fork_refs": [ "fork PR #6 (8ae097d9, 6bdfe770)" ], "final": "ABSORBED", "basis": "absorbed per sweep evidence (not re-verified)", "evidence": [ "ABSORBED: design/src/variants.ts:68 `240_000` and :135 `\"Timeout (240s)\"`." ], "notes": "" }, { "id": "s1-prewave-make-pdf-invisible-preamble", "title": "make-pdf: a leading