Skip to content

docs: surface two post-hoc control-plane disclosures in SC-10 - #2564

Merged
Chris0Jeky merged 4 commits into
mainfrom
coord/sc10-disclosures-2026-09-04
Sep 4, 2026
Merged

docs: surface two post-hoc control-plane disclosures in SC-10#2564
Chris0Jeky merged 4 commits into
mainfrom
coord/sc10-disclosures-2026-09-04

Conversation

@Chris0Jeky

@Chris0Jeky Chris0Jeky commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Summary

Docs-only. Adds two post-hoc disclosures to the SC-10 maintainer queue in OUTSTANDING_TASKS.md, so the items the maintainer triages sit in the same place as the existing #2479 disclosure rather than only inside a dated docs/STATUS.md block.

  • #2529 merged on 2026-09-04 at 06:33:08Z while its ci-required.yml run had concluded cancelled (the Frontend Unit (windows-latest) leg hit its 20-minute budget and was never re-run). Docs-only change, no revert warranted, but a red required gate was treated as non-blocking.
  • #2548, #2556 (both scripts/ci/dev-up.test.mjs) and #2549 (frontend/taskdeck-web/package.json plus lockfile) touch declared ci/policy.v1.json control paths and merged on a fresh-context review alone. They are already recorded in the tenth STATUS block; this surfaces them in the queue.

Two facts a maintainer reading the disclosures will want:

  • Branch protection did not prevent the #2529 merge and could not have: only the three security contexts are required on main, and all three passed. The ci-required.yml red is enforced by agents only, so the lesson generalizes beyond #2529.
  • Nothing was lost. Measured here on 2026-09-04 against the local origin/main: all 80 head and merge SHAs of the 40 most recently merged PRs (#2559 back) are ancestors of origin/main. This is a governance gap, not a code-integrity one.

Both disclosures were measured by the open-PR reconciliation session on 2026-09-04 and re-verified here against the Actions API (run 33842570671, conclusion cancelled, head 62f21d847) and the PR file lists before recording. OUTSTANDING_TASKS.md matches no controlPaths glob in ci/policy.v1.json, so this PR is not itself a control-plane change.

Refs #2337 (SC-10 queue), #2378 (Windows timeout cohort).

Changes

  • OUTSTANDING_TASKS.md: two sentences appended to the SC-10 item. No item ticked, no other file touched.

Test plan

Verified:

  • node scripts/check-docs-governance.mjs
  • git diff --check
  • git merge-base --is-ancestor for 80 SHAs (40 heads, 40 merge commits): 0 non-ancestors

NOT verified: nothing executable changed.

Boundaries and risks

No code, workflow or policy change. The disclosures record facts only; the merge disposition of the listed PRs is unchanged and remains the maintainer's.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@Chris0Jeky

Copy link
Copy Markdown
Owner Author

Review gate (Codex credits exhausted, SC-9): one fresh-context reviewer on commit 1 (6e5718d), verdict SHIP, docs-only.

Findings and disposition:

  • MEDIUM, fixed in 9b2aa40: the "only non-success ci-required outcome in 40 PRs" figure had no stated scope; it now names the merged-PR-head scope and points at the separate red main push run at 17e48815e (ninth STATUS block).
  • MEDIUM, fixed in 9b2aa40: disclosure (3) now states that #2548 merged after its own review-gate comment had declared it parked for the maintainer.
  • LOW, fixed in 9b2aa40: revert language now leaves the choice with the maintainer, mirroring the #2479 disclosure; "Both disclosures" became "Disclosures (2) and (3)"; "Tracked with" became "Belongs to"; the #2529 timing is stated from the run's own updated_at.
  • LOW, declined: #2157 is not named in the cohort list; it is not in the current Windows-timeout set the STATUS blocks cite.

Also in 9b2aa40 and 81b3ab6, measured facts from the open-PR reconciliation session, each re-verified here against the API or local git before recording: the SC-10 base-currency softening (queued PR bases are 46 to 138 commits behind main), new human item SC-11 (delete_branch_on_merge is false; 448 remote branches), the #2531 inert closing reference and #2562 red, the #2535 review and red cause, and the #2506 review-record gap.

A scoped second-pass review on the fix diff is running. Head 81b3ab6 pushed 2026-09-04 21:49Z; merge after the aging floor with ci-required green at that head. No item was ticked; no maintainer decision is inferred.

@Chris0Jeky

Copy link
Copy Markdown
Owner Author

Round 2: scoped second-pass fresh-context review of the fix diff (6e5718d..81b3ab6), verdict SHIP. The four round-1 findings were confirmed resolved. Disposition of its own findings:

  • MEDIUM x3 on the new SC-11 sentence (the branch sweep excluded open-PR heads but not open-PR bases; it required no tip-ancestry proof; and it read as standing authorization for a destructive sweep once the setting is flipped). Fixed in 95c68e6: the sweep is now a separate, recorded maintainer authorization (destructive, never run unasked, as with SC-2); only tips proven ancestors of origin/main immediately before deletion; every open-PR head and every open-PR base excluded per global law 4; unclassified branches listed, not deleted. This is a work-loss guard on text this PR introduced, so it was tightened rather than tracked.
  • LOW, fixed in 95c68e6: the 17e48815e pointer now names the eighth STATUS block (back-referenced by the ninth); the base-change remedy now names the review re-check as well as the hosted run; the 434-of-448 class sum is stated.
  • LOW, declined: moving #2535 into the queued list. It stays in the "not merge-ready" clause because its T2 parking is the same maintainer gate as the queue; the clause states its SHIP verdict and check state.

Round count: 2 reviews. 95c68e6 is a wording tightening of the authorization clause, self-verified (docs governance, diff check), no third review round. Pushed 2026-09-04 21:57Z; merge after the aging floor with ci-required green at that head.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant