Record overnight human actions and failure evidence - #1336
Conversation
Self-review — head
|
There was a problem hiding this comment.
Code Review
This pull request updates OUTSTANDING_TASKS.md and docs/agentic/FAILURE_LEDGER.md to document several overnight deferrals and pre-existing test/CI failures identified on 2026-07-13. The feedback suggests prefixing the 'Future fix' column for the github/project-sync entry in the failure ledger with '#1327:' to maintain consistency with the other newly added entries.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3544c138cd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Review fix evidence on head |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
Added the explicit #1323 prompt-rail remainder in @codex review |
|
Codex Review: Didn't find any major issues. Chef's kiss. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Durable failure capture update —
|
|
Codex Review: Didn't find any major issues. 🚀 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Required Windows API failure investigationThe docs-only branch did not change API/runtime code. Windows API Integration failed because Evidence is added to #1335: #1335. This is not dismissed as flaky; #1335 owns the hosted-worker/test-lifecycle repair. I am rerunning the failed job after investigation. The E2E check is separately |
|
The unchanged-head Windows API rerun passed: https://github.com/Chris0Jeky/Taskdeck/actions/runs/29225697410/job/86740437756. The original failure remains mapped to #1335 with exact 5/5 local evidence. This clears the failed API job, but the docs-only E2E check was skipped by path filtering and CI Extended remains red under #1330; #1336 is still never-automerge. |
Final overnight deferral update (
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1a060f63ab
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Review fix evidence —
|
|
@codex review Please run a fresh independent docs-only review of exact head |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Required E2E failure investigation — run
|
|
The unchanged-head failed-job rerun passed: CI run The original |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 67c86f1777
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| - [ ] **#1303** — Push the `v0.1.0` release tag only after the maintainer accepts the release deck and its pipeline evidence. Agents may repair the pipeline but must not push the tag. | ||
| - [ ] **#1299 trademark check** — Complete the human-only Taskdeck name/trademark clearance step; the licensing/DCO implementation does not substitute for legal-name clearance. | ||
| - [ ] **#1327 project sync access** — Run `gh auth refresh -s project`, then rerun `scripts/github/Sync-TaskdeckProjectPriority.ps1` in audit and apply modes and verify no issue/PR project item has an empty Priority. | ||
| - [ ] **#1330** — Repair the CI Extended reusable-workflow permission contract; affected PRs remain ineligible while the workflow startup failure is red. |
There was a problem hiding this comment.
Remove the stale #1330 blocker
Because this commit is based on cf08c69, the #1330 fix is already present in the parent: .github/workflows/ci-extended.yml now guards the Gitleaks reusable job to PR events and grants contents: read plus pull-requests: read on the job. Keeping this new OUTSTANDING entry as an open repair item that says affected PRs remain ineligible will make the start-of-session checklist tell future agents to keep blocking PRs for a workflow startup failure that has already been repaired; please drop it or rewrite it as verification/historical ledger evidence, including the matching open ledger source row.
Useful? React with 👍 / 👎.
| - [ ] **#1282 / #1332 / #1335** — Stabilize the required full-suite harness: SQLite concurrency, Redis connect/dispose, and hosted-worker/presence lifecycle isolation. Narrow passes do not clear the recorded full-suite failures. | ||
| - [ ] **#1338** — Map HTTP MCP and its API-key middleware to the same `/mcp` route before documenting or exposing HTTP transport; the current parameterless mapping serves MCP at an unintended unauthenticated root route. | ||
| - [ ] **#1343** — Prevent late Home/Today summary responses from overwriting a newer local workspace-mode choice; add deterministic ordering tests and repeated error-recovery E2E proof. | ||
| - [ ] **#1345** — Resolve or formally mitigate GHSA-2m69-gcr7-jv3q in the transitive `SQLitePCLRaw.lib.e_sqlite3` package once a patched release exists or a safe provider change is proven; current published releases through 2.1.11 are affected. |
There was a problem hiding this comment.
Reframe the SQLite advisory task around available releases
This durable task tells agents to wait until a patched release exists, but the current package metadata no longer matches that framing: the GitHub advisory marks SQLitePCLRaw.lib.e_sqlite3 affected only through <= 2.1.11, while NuGet already lists stable 3.53.3 published on July 6, 2026. Leaving this as a wait-for-upstream item can delay the security mitigation; please rewrite it to evaluate/prove the available 3.x override or another runtime mitigation rather than waiting for a nonexistent future trigger, including the matching ledger source row.
Useful? React with 👍 / 👎.
| ## E. Revival overnight deferrals (added 2026-07-13) | ||
|
|
||
| - [ ] **#1173** — Apply and verify the required branch-protection settings in GitHub. This is repository-settings work and remains maintainer-only. | ||
| - [ ] **#1303** — Push the `v0.1.0` release tag only after the maintainer accepts the release deck and its pipeline evidence. Agents may repair the pipeline but must not push the tag. |
There was a problem hiding this comment.
Gate the release tag on the staging-trigger fix
When this new checklist item is followed and v0.1.0 is pushed, .github/workflows/release-desktop.yml runs on v* tags and creates a GitHub Release, while .github/workflows/cd-staging-gate.yml still triggers on release: published and waits on the production environment. Since the repo already tracks that auto-trigger hang as #1228, this handoff should name fixing/gating that workflow as a prerequisite to the tag; otherwise the durable checklist can send the maintainer into a known-hanging release side effect.
Useful? React with 👍 / 👎.
…to the maintainer's prerequisite merges
Summary
This intentionally does not rewrite the stale archive-direction sections; #1296/#1328 own that direction update.
Verification
dotnet test backend/Taskdeck.sln -c Release(not run: docs-only handoff)python scripts/agent_hooks/render_failure_ledger.pyConvertFrom-Jsonnode scripts/check-docs-governance.mjsgit diff --checkDocumentation
docs/STATUS.mdupdated (not applicable; no shipped behavior and direction is maintainer-owned)docs/IMPLEMENTATION_MASTERPLAN.mdupdated (not applicable; no roadmap change)OUTSTANDING_TASKS.mdanddocs/agentic/FAILURE_LEDGER.mdupdatedTracking
Refs #1327
Related: #1173, #1282, #1299, #1303, #1330, #1332, #1335
Project Priority/status could not be audited because the current token lacks
read:project/project write scope; that limitation is itself recorded as a human action.CI Workflow Validation
Risk Notes
OUTSTANDING_TASKS.md; this PR is not eligible for autonomous merge under the overnight grant.Review fixes
c8ff7a58adds the complete curated JSONL source, regenerates the Markdown view, and prefixes the project-scope action with GEN-00 [TRACKER]: Generalist expansion wave (ADR-0046) - artefact intake beyond transcripts, project dossiers, generalist reach #1327.