You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Ten issues are open from #310 up. They are not ten pieces of work: several share files, several are already delivered, and two pairs are the same defect at different sites. This issue records how they group into deliverable pull requests, what order those land in, and what deliberately stays out.
It is a routing document. Each item is worked in its own issue; this one only says what travels with what.
Why one PR. All four touch scripts/check-binding-fidelity.ts and its triage file. #341 R1 lands with a triage pass by its own admission ("expect a first-run finding set"); #342 R1 lands with one too, because scoping the check re-opens findings. Splitting them means two triage passes over the same file and a guard that is red in between.
Corpus PR — close the artifacts-checkout defect class
Blocker to resolve before scoping.#319's "~23 Med/Low from the two catalogue sweeps" is not enumerated in the issue — it points at a planning register on engineering. Read that register before committing to a scope manifest, or the PR's size is unknown at Gate 2.
Corpus binding debt: close the 125 fix-later seams #327 triaged #336 last for the same reason as the first bullet — it is a burn-down of a ledger whose instrument is being repaired one step earlier. Measuring the debt before fixing the meter is how you get a number nobody trusts.
A workflows pointer bump is needed after the corpus PR, as always. The protocol is recorded in tests/e2e/__snapshots__/corpus-sha.json — stamp it in the same commit. b41aaacc is a worked example.
Big, mechanical, per-class sweep across work-package and substrate-node-security-audit. Collides with the corpus PR's files, and combining makes the diff unreviewable. Its own PR — probably several, following its own R3 → R5 → R2 → R1 → R4 sequence.
Needs a design call between four stated directions before a single line changes. Direction 2 ("make the timer real") is server work; the rest is corpus. Not batchable until settled.
The gap is real and reproduces, but the target moved: workflow-authoring binds zero graph operations, and its activity set is now four with impact-analysis demoted to a technique. That is a workflow-authoring enhancement with its own scope, not a documentation fix.
Nine F-items in requirements-refinement, a third workflow. F-12 and F-13 are human design calls, and F-13 is additionally blocked on an AP-80 preservation audit.
Self-deferred by its own text, and it is repo configuration rather than either repo's code. Its stated revisit trigger — a second, non-admin operator — has not fired.
Delivered by #339 (S1–S4, S6) and #340 (S5). What remains is the drain-to-zero retirement policy, not a code change.
Staleness found while routing this
Verified 2026-07-28 against origin/main at b41aaacc and origin/workflows at f84fe02b. Several issues carry content that merged work has overtaken; a reader following them as written would do dead work. #337 and #338 have been corrected in place. The rest are listed here so the corrections are not lost:
Part 1's target is deprecated. The gap reproduces in workflow-authoring, which binds zero graph ops — but the fix needs remapping onto four activities, not the three named. Part 4 (embeddings: 0) is not this repo.
Both defects survived the rewrite: workflow-authoring/workflow.yaml:21-22 restates the auto-resolve licence and 06-scope-and-draft.yaml:44 carries autoAdvanceMs: 30000. Live against a live workflow.
Header says PR #318 is open — it merged. C-1 is fixed by #328. C-2 is half-stale: the three names are now declared at meta/workflow.yaml:41,44,47, so the literal-fallthrough mechanism is gone and only the no-producer half stands. C-3 is half-stale: usage landed in #329; only _meta.trace_token remains. B-3 is fixed by construction. Groups A and B die with workflow-design.
The ledger reads 123 as of b41aaacc, but the real debt is still 125: two workflow-design entries were pruned because #342's masking defect made them invisible, not because they closed. The distribution table's workflow-design row moves 3/4 → 3/2 for the same reason.
Purpose
Ten issues are open from #310 up. They are not ten pieces of work: several share files, several are already delivered, and two pairs are the same defect at different sites. This issue records how they group into deliverable pull requests, what order those land in, and what deliberately stays out.
It is a routing document. Each item is worked in its own issue; this one only says what travels with what.
Two PRs
Server PR — guard reach and measurement honesty
Closes #341, closes #342, closes #337 S6 C4.
whenorvalidate targetnaming a value nothing produces is a finding. 80 sites (33 stepwhen, 47validate).check:site/check:svgsteps fromdeploy-docs.yml; both are registry entriescheck:allalready runs.dead-outputconsumer resolution to the declaring workflow, restore the two entries pruned inb41aaacc, and make a stale report distinguish "seam closed" from "guard stopped seeing it".resources/README.mdid-shadowing decision, if it is resolved server-side rather than by a corpus naming rule.Why one PR. All four touch
scripts/check-binding-fidelity.tsand its triage file. #341 R1 lands with a triage pass by its own admission ("expect a first-run finding set"); #342 R1 lands with one too, because scoping the check re-opens findings. Splitting them means two triage passes over the same file and a guard that is red in between.Corpus PR — close the artifacts-checkout defect class
Closes #319, closes #338 W2, closes #310 Part 2, partially closes #320.
manage-git::artifact-commitsinto a13-submit-for-review.yamlsteps[]bind, then fix the activity-13 mermaid atactivities/README.md:418, which the new step makes staler still.update-pr/TECHNIQUE.md:76,pr-description.md:143,manage-artifacts/TECHNIQUE.md,agent-conduct.md); the fifth iscommit-and-persist.md:35, which still prescribescommit-regular-filesfor a path that is a submodule here. Fixing either alone leaves the class live — that is Outstanding and deferred items from the review-mode friction continuation session #319's own argument, extended by one file.end-workflow's three technique bindings still have no producer.meta/techniques/gitnexus-operations/TECHNIQUE.md. One file, no overlap with anything above; a cheap ride-along.Blocker to resolve before scoping. #319's "~23 Med/Low from the two catalogue sweeps" is not enumerated in the issue — it points at a planning register on
engineering. Read that register before committing to a scope manifest, or the PR's size is unknown at Gate 2.Order
work-package/techniques/. Corpus binding debt: close the 125 fix-later seams #327 triaged #336 R1 alone works 69 findings across that tree; Outstanding and deferred items from the review-mode friction continuation session #319's semantic fixes land in the same files and are far harder to review under a mechanical diff.A
workflowspointer bump is needed after the corpus PR, as always. The protocol is recorded intests/e2e/__snapshots__/corpus-sha.json— stamp it in the same commit.b41aaaccis a worked example.What stays out, and why
work-packageandsubstrate-node-security-audit. Collides with the corpus PR's files, and combining makes the diff unreviewable. Its own PR — probably several, following its own R3 → R5 → R2 → R1 → R4 sequence.workflow-authoringbinds zero graph operations, and its activity set is now four withimpact-analysisdemoted to a technique. That is aworkflow-authoringenhancement with its own scope, not a documentation fix.requirements-refinement, a third workflow. F-12 and F-13 are human design calls, and F-13 is additionally blocked on an AP-80 preservation audit.Staleness found while routing this
Verified 2026-07-28 against
origin/mainatb41aaaccandorigin/workflowsatf84fe02b. Several issues carry content that merged work has overtaken; a reader following them as written would do dead work. #337 and #338 have been corrected in place. The rest are listed here so the corrections are not lost:workflow-authoring, which binds zero graph ops — but the fix needs remapping onto four activities, not the three named. Part 4 (embeddings: 0) is not this repo.workflow-authoring/workflow.yaml:21-22restates the auto-resolve licence and06-scope-and-draft.yaml:44carriesautoAdvanceMs: 30000. Live against a live workflow.meta/workflow.yaml:41,44,47, so the literal-fallthrough mechanism is gone and only the no-producer half stands. C-3 is half-stale:usagelanded in #329; only_meta.trace_tokenremains. B-3 is fixed by construction. Groups A and B die withworkflow-design.b41aaacc, but the real debt is still 125: twoworkflow-designentries were pruned because #342's masking defect made them invisible, not because they closed. The distribution table'sworkflow-designrow moves 3/4 → 3/2 for the same reason.Related
b41aaacc— the pointer bump that surfaced Guard reach: dead-output resolves consumers across workflow boundaries, so duplicate technique names mask real seams #342 and the stale-count correction to Corpus binding debt: close the 125 fix-later seams #327 triaged #336.