Skip to content

fix: frontmatter and named directories each follow one rule, and the trailer and identity gates judge every pull request - #741

Merged
REPPL merged 84 commits into
mainfrom
integ/land-13
Sep 29, 2026
Merged

REPPL merged 84 commits into
mainfrom
integ/land-13

Conversation

@REPPL

@REPPL REPPL commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator

This pull request lands four reviewed drain lanes of autonomous run A as one change: frontmatter is read by one rule everywhere, a directory a command names is shown by one display rule, the lint cluster's five fixes, and the two gate scripts that judge every pull request's trailers and commit identities. It also carries five small follow-ups the reviews asked for and recalibrates the cold-reading windows once for the lot.

Frontmatter walks (drainInt, drainFm). Every reader of a record's frontmatter now opens and closes the block by the same delimiter rule, so a byte-order mark, a CRLF line or an indented rule no longer makes one reader see a block another reader does not. The build's open-question check reads a settled label only where a label is written, the early-close refusal names the command that declares an impact, the owed listing withholds a local-tier path, and the reading exclusion floor scans every line the canonical reader treats as frontmatter.

One display rule for a directory (drainCap, drainRedact). A command that names a checkout, a worktree or a repository root shows it home-relative under HOME and by its own name outside it, never as an absolute path: the capture verbs, abcd peers, the build status, history ingest and recovery, and the status board all follow it. The capture cluster's other fixes land with it: hidden characters in a disposition are encoded, a second deferral past the same release rewrites its section, and the comparative-run gate holds a run to the channel's own manifest.

Lint cluster (drainLint). A setext principle title is carried into its statement, a widening summary stands down past an unreadable answer, a link to a record store root is named, the fence-run detector sees more shapes, and the privacy backstop reads escaped Windows home paths and the issue ledger.

Gate scripts (drainScr). The issue-resolution gate judges a record entering a terminal folder at the merge base, withdraws a declaration only when a real revert takes out what the reverted commit put in, reads a record id from a record file only, and no longer fails at random on a long record. The attribution gate refuses a configured automation's name, such as semantic-release-bot, while a person named Jan Bot still passes.

At the integration. The configured-automation name shape joins the shared machine-identity list, so abcd ahoy flags it before the first commit as the gate refuses it after; the contributors page stays on the structural signals. The status board's first line masks control and bidi characters in the directory name. The gate's record lookups use the same record-file rule as its derivations. Two resolved records' Windows-path examples use a persona home, and the reviews tree is no longer exempt from the session-leak rule. The widening and detection reading windows rise by 10,000 tokens each.

Re-merge after integration branches 11 and 12 and v0.11.1 (#736-#739). Main is merged in by hunk, and the release files keep main's text with an empty ## [Unreleased]. Two path helpers had landed under one name: this branch's DisplayPath keeps naming a directory a surface points at, and main's repository-relative helper becomes RepoRelativePath, so the launch, memory-lint, site and git-operand reports keep their paths relative to the repository. The fence-run detector's allowlist trades the code-span helper, which no longer reads a fence character, for the lifeboat renderer, which does. The issue-resolution gate asks main's merge-queue question first and this branch's merge-base question second, with main's wording in both refusals. A board comment now says the JSON encoder escapes only C0 bytes. Both lanes' new build tests are kept, and the decision log keeps main's order with this branch's entry last. The generated command reference did not drift. The widening and detection windows are re-measured at the merged tip. The two open records named below as Refs stay open. The four resolved ones are declarations carried from the lanes' own commits.

Reviews: drainInt SHIP · drainFm SHIP (fix2 SHIP) · drainCap SHIP · drainRedact SHIP (fix2 SHIP) · drainLint SHIP · drainScr FIX FIRST, then fix2 SHIP, fix3 SHIP, fix4 applied.

Resolves: iss-2608221126066379
Resolves: iss-2608270655499478
Resolves: iss-2608270908348042
Resolves: iss-2608301306580014
Resolves: iss-2608301744300631
Resolves: iss-2609012047551175
Resolves: iss-2609012047566360
Resolves: iss-2609021815563506
Resolves: iss-2609090951276167
Resolves: iss-2609240646522330
Resolves: iss-2609240646533487
Resolves: iss-2609251600029607
Resolves: iss-2609251823551349
Resolves: iss-2609251823555125
Resolves: iss-2609251823559111
Resolves: iss-2609251823560369
Resolves: iss-2609251842111593
Resolves: iss-2609251842112266
Resolves: iss-2609252038344132
Resolves: iss-2609260932374727
Resolves: iss-2609261140284421
Resolves: iss-2609261208193041
Resolves: iss-2609261325441711
Resolves: iss-2609281314564762
Resolves: iss-2609281329007423
Resolves: iss-2609281613094952
Resolves: iss-2609281627055603
Resolves: iss-2609281736483740
Resolves: iss-263
Refs: iss-2609221820487644
Refs: iss-2609100509537730
Refs: iss-2608301421381157
Refs: iss-2609251543293588
Refs: iss-2609251638574543
Refs: iss-2609251455354719

Assisted-by: Claude:claude-opus-5-5

The build's open-question check read `resolved:` or `deferred:` anywhere in
an item, so "Which id wins once the split is resolved: the old or the new?"
read as settled and build would start past a real question. The label now
counts opening a line of the item, after a closing bold, or after a dash;
the bold-span marker keeps its reach. Every intent in the tree reads the
same open-question count under the tightened rule, so no record changes
verdict. The brief's build chapter says so, and DECISIONS.md carries a
dated correction to the 2026-09-25 entry.

Refs: iss-2609260932374727
Assisted-by: Claude:claude-opus-5-5
…-sentence

Resolves: iss-2609260932374727
Assisted-by: Claude:claude-opus-5-5
Both refusals of --impact at a close that ships nothing (another spec still
open, or a remainder minted) said only to supply the impact at the close that
ships. They now also name `abcd intent plan <itd-N> --impact <value>`, which
stamps the judgement on the planned record at once, after which the close
that ships needs no flag. The value is echoed only when shipped/ would accept
it, so the refusal never hands back a command that is itself refused. The
test walks the named route end to end: plan stamps, the remainder close and
the shipping close both go through without the flag.

Refs: iss-2609240646522330
Assisted-by: Claude:claude-opus-5-5
…ent plan --impact

Resolves: iss-2609240646522330
Assisted-by: Claude:claude-opus-5-5
…otes

The dead-letter reason is free text a host's payload supplied, and the reader
cuts only OUR retention clause off it, so a reason quoting a clause of the
same shape put a local-tier path into `intent audit --json`, which promises
never to hand one out. Every token naming the local tier is now withheld from
the reported reason, and the rest of the reason is kept. The property test
forges such a reason instead of trusting the fixture's own.

The review's second note: the corroboration paragraph of
iss-2609100509537730 sat inside its Grounds section, between the promote's
pursued entry and the resolve's near-identical one. It moves into the body,
above the section; both entries stay, because the section is append-only and
each records its own act.

Refs: iss-2609252038344132
Refs: iss-2609100509537730
Assisted-by: Claude:claude-opus-5-5
…oted local-tier path

Resolves: iss-2609252038344132
Assisted-by: Claude:claude-opus-5-5
…imitive

The finding named SetPromotedFrom returning a populated intent beside
ErrBackEdgeTaken, with the primitive's own test discarding the return. The
promote join under itd-4 AC3's names (48c6108) replaced that primitive with
AddRelatedIssue, which returns the zero Intent on every refusal and the
record's list on success. Its tests asserted the list on the append path only;
they now assert it on the idempotent no-op too, the return the promote route
reads the kept edge from on a re-run, and assert the zero Intent beside every
refusal. Each assertion was watched fail against a mutated copy.

Refs: iss-2609021815563506
Assisted-by: Claude:claude-opus-5-5
…erted directly

Resolves: iss-2609021815563506
Assisted-by: Claude:claude-opus-5-5
…ast a BOM

frontmatter.Fields trims a BOM ahead of the opening delimiter, but the sibling
walks that promise parity with it did not: intent's writers refused a
BOM-led record the reader loads ("no leading frontmatter block"), the
changelog took its whole frontmatter for the body, and record-lint took its
`---` for an issue's title.

frontmatter.Close is the reader's own walk, exported: the index of the
closing delimiter, the BOM trimmed at line 0 and nowhere else, every
delimiter judged by IsDelimiter. Intent's three writers (setFrontmatterFields,
removeFrontmatterField, frontmatterClose), the changelog's bodyStart, the
record page's body reader and peers' title reader route through it.
record-lint's body start and agent capability scope ask frontmatterOpen,
which already trims; the disposition parser, the launch prose gate and the
site's frontmatter stripper trim the BOM at line 0 as every reader does. A
writer keeps the file's BOM: it edits keys, never the first bytes.

Refs: iss-2608221126066379
Assisted-by: Claude:claude-opus-5-5
… past a BOM

Resolves: iss-2608221126066379
Assisted-by: Claude:claude-opus-5-5
… condition

capture disposition redacted --grounds and --exit-condition but never passed
them through termsafe.EncodeHiddenRunes, so a bidi override or a zero-width
rune landed in the committed dsp-N record verbatim. Every other free-text
capture write (capture body, resolve and wontfix notes, defer reason, admit,
surprise and reframe grounds, reading items upstream in the reading package)
already encodes; the sweep found the disposition the only gap.

Refs: iss-2609251823551349
Assisted-by: Claude:claude-opus-5-5
…idden runes

Resolves: iss-2609251823551349
Assisted-by: Claude:claude-opus-5-5
FindPrincipleStatement read ATX H1s only, so a principle whose title is
underlined with `===` travelled to a reading as a bare paragraph, and
principle_claims never judged its title. The one derivation now reads a
setext H1 too: the paragraph directly above a `===` underline, its lines
joined, skipping masked lines and lines that open another block.

Refs: iss-2609261140284421
Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609261140284421
Assisted-by: Claude:claude-opus-5-5
…r cycle

capture defer appended a second `## Deferral` section when a record was
deferred twice past the same anchor, where the record's shape is one section
per cycle. The verb now rewrites that cycle's section (its heading date and
its `Deferred past <anchor>:` line) in place; a deferral past a different
anchor still appends. Chosen over refusing, because a refusal would send a
corrected reason back to a hand edit of the record, which is what the verb
exists to replace; the superseded wording stays in git history. A section of
any other shape is a hand edit the verb does not own and is left alone.

The capture command page and the brief's capture chapter say so.

Refs: iss-2609251823555125
Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609251823555125
Assisted-by: Claude:claude-opus-5-5
mapEscape classifies os.Root's escape by matching the text "path escapes from
parent", because the os package does not export the error, and nothing pinned
the match: both race tests asserted only err != nil, so a Go release that
rewords the message would degrade ErrPathUnsafe to a generic error with every
test green. Both race tests now assert errors.Is(err, ErrPathUnsafe), and a
direct test feeds mapEscape the error a real os.Root escape returns.

Refs: iss-2609251823559111
Assisted-by: Claude:claude-opus-5-5
…inned

Resolves: iss-2609251823559111
Assisted-by: Claude:claude-opus-5-5
…ble answer

The widening-run summary took the admitted case before the stand-down
check, so a run whose only admitted proposal carried a contested,
cyclic, unsafe or illegible disposition still reported "admitted 1,
outstanding []", against the WideningRun doc: such a run supports no
count. The stand-down case now comes first.

Refs: iss-2609251842112266
Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609251842112266
Assisted-by: Claude:claude-opus-5-5
The ledger identity every capture verb reports (the `ledger` member in --json
and the `ledger of` line on stderr, and the record dispatcher's for an iss-N)
was home-redacted only, so a checkout outside HOME was printed as its full
absolute path. It is now reduced to its directory name, the base-name rule
scrubPaths already applies to an absolute path outside both identity roots,
built from the existing fsutil.RedactHome rather than a second primitive.

renderLedger silently skipped the `ledger` member for a result that is not a
JSON object. Every caller passes a struct, so it is now an internal error
rather than an envelope that loses its identity without a word; the splice
itself stays, because it keeps the result's own member order.

Refs: iss-2609251823560369
Assisted-by: Claude:claude-opus-5-5
…pture output

Resolves: iss-2609251823560369
Assisted-by: Claude:claude-opus-5-5
record_schema passed silently over a link at a bucketed store root whose
name ends in .md without being a record filename (notes.md pointing at a
directory). A real directory of that name is reported; the link was not,
because telling what it points at would mean following it. Every such
link is now named without being followed; README.md and dot-names stay
exempt, and a record-named link keeps its store-root finding.

Refs: iss-2609261208193041
Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609261208193041
Assisted-by: Claude:claude-opus-5-5
…scan misses

TestNoSecondFenceRule's scan is delimiter-only, so a private toggle
written as a regexp literal matching a fence run, or as a comparison of
a line's first byte against a backtick or tilde, escaped it. A second
detector reads the parsed source for both shapes, pinned per file with a
reason like the first; a pattern spelling a delimiter stays the first
scan's, and a pattern taking a run of letters whole is an alphabet, not
a reader. The first test's doc now says what each reaches.

Refs: iss-2609251600029607
Assisted-by: Claude:claude-opus-5-5
…s detected

Resolves: iss-2609251600029607
Assisted-by: Claude:claude-opus-5-5
…l's pair

The widening ordering gate read "committed comparative run" as any run.json
under the readings family decoding to position comparative with a
candidate_run, so an id-less, manifest-less two-key marker written by hand
opened it. ComparativeRunFor now holds a run record that names the widening
run to the pair the channel's ingest leaves: its run_id names its own
directory, and the manifest the ingest promotes beside it (before it writes
the record) agrees on the run id, the position and the candidate_run. A
record naming the widening run that fails either is refused by name as
ErrInvariantViolation, never read as "no run yet".

Not checked, and why: whether git tracks the pair (the gate answers between
an ingest and the commit that carries it, the order the channel is used in),
and the manifest's hash against the record's manifest_sha256 (a writer who
can place both files can compute the hash too, so it would add a step, not a
bar). A writer with the tree can still forge the pair; the gate now names
the channel's artefacts, which is what the spec's "committed comparative run
whose manifest names rdg-N" states.

The manifest's file name and its read ceiling move to issueschema
(RunManifestFileName, RunArtefactReadLimit), which core/reading now reads, so
the writer and the gate share one statement of each. A reading-package test
joins the channel's real ingest, exercised and not, to the gate. Fixtures in
capture, scribe, the CLI and the rehearsal eval write the pair.

Refs: iss-2609251842111593
Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609251842111593
Assisted-by: Claude:claude-opus-5-5
The whole reframe write reads back to the previous distinct state along first
parents, so a rewrite that lands as several commits on that line, a rebased
branch among them, is recorded as its last step alone (two commits moving the
construal then the glossary give changed=[glossary]), where a squash or a
--no-ff merge of the same rewrite gives [construal glossary]. The command page
and the brief's capture chapter claimed only the squash equivalence; both now
name the series case and the route that records such a rewrite whole (--open
before the first commit, --complete after the last). The record offered a line
on the page or a spec ruling; no ruling is owed on it in the rulings list, so
the page states the behaviour spc-2609020626048705's first-differing-state rule
already produces, and a test pins it.

Refs: iss-2609261325441711
Assisted-by: Claude:claude-opus-5-5
… is named

Resolves: iss-2609261325441711
Assisted-by: Claude:claude-opus-5-5
…ckout's absolute path

Refs: iss-2609281613094952

Assisted-by: Claude:claude-opus-5-5
Bare `abcd` printed the checkout's absolute path as its first line and as
`dir` in --json, with no redaction at all, so under HOME it named the
account and outside HOME the whole local path, in the output a person
pastes most often. The board now routes the directory through
fsutil.DisplayPath (home-relative under HOME, the base name outside it) in
both forms. `dir` is a display field: its readers are the plugin page,
which relays it to the person, and two tests that check it is present; no
consumer acts on it.

The sweep of the board's other lines found one more of the class: the
peers notice on stderr carried the reader's error through RedactHome
alone, and an unreadable record folder's error names the folder by its
absolute path. It is named by DisplayPathsIn against the checkout root.

Refs: iss-2609281613094952

Assisted-by: Claude:claude-opus-5-5
TestPeersNamesAWorktreeOutsideHomeByItsDirectoryName and
TestThePeerRefusalNamesAWorktreeOutsideHomeByItsDirectoryName chmod a
record folder to 0 to force a not-read peer; root reads through it, so in
a root container the assertion failed on the fixture, not the code. Every
other chmod-0 test in the tree already skips or probes for root.

Assisted-by: Claude:claude-opus-5-5
…kout by the display rule

Resolves: iss-2609281613094952
Assisted-by: Claude:claude-opus-5-5
The reading floor closes its block on any column-0 line opening with
three dashes, so `----` or `--- x` ends it before the canonical reader's
close and an excluded key between the two reaches the corpus. Found by
the review of this branch; captured before the fix.

Refs: iss-2609281627055603

Assisted-by: Claude:claude-opus-5-5
… close

The exclusion floor closed its frontmatter block on any column-0 line
opening with three dashes, so a `----` or a `--- x` ended the key and
shape scans while frontmatter.Fields read on to the real `---`: an
excluded key between the two was frontmatter to the canonical reader,
invisible to the floor, and travelled under a manifest asserting its
refusal.

The key and shape scans now run to blockScanEnd, the later of the
floor's own close and frontmatter.Close. The floor's close is kept for
where the body begins (the fence mask and the heading scan), so each
scan takes the reading that refuses more. The reviewer's suggested
closer (IsDelimiter, `--- ` or `...`) was not taken: it still fires on
`--- x`, which the canonical reader reads through.

The delimiter detector also counts literals led by a byte-order mark,
and the floor's allowlist reason states the property that now holds.
Every committed markdown file (2748) reads identically through the
floor before and after: same block, same redaction, same verdict.

Refs: iss-2609281627055603

Assisted-by: Claude:claude-opus-5-5
…r than the canonical close

Resolves: iss-2609281627055603
Assisted-by: Claude:claude-opus-5-5
The issue-resolution gate derived a record id from a path's basename
alone at every reader that turns a path into an id: the entering
readers for resolved/ and wontfix/ and for shipped/, the merge-base and
base listings of what is already terminal, and terminal_moves, which
decides what a revert withdraws. So a nested file (resolved/x/<id>.md)
or a non-markdown one (resolved/<id>.txt) under a terminal folder
counted as that record entering or leaving it: adding one satisfied a
Resolves: or Delivers: trailer, reverting it withdrew the trailer, and
one sitting in the folder at the fork made an honest resolution read as
already terminal. record_path alone required the record shape.

record_files is now the one reading of which paths are records: a file
directly in a folder of its store, named <id>.md or <id>-<slug>.md, the
shape record_path and intent_path look an id up by. Every such reader
goes through it (record_id for a single path), for iss and itd alike.

Twelve cases pin it, each watched fail against the previous gate: the
nested and non-.md add refused as not entering, for both rules; a
revert of odd files withdrawing nothing; and an odd file at the fork
or base not making the real record terminal.

Refs: iss-2609240646533487
Assisted-by: Claude:claude-opus-5-5
Lands drainFm b72f31d, which contains drainInt 3423af9: frontmatter
walks routed through frontmatter.Close/CloseAfter, the BOM sweep, the
settled-label narrowing and the exclusion floor's scan extent.

Conflict in internal/core/reading/project.go, excludedKeyInFirstBlock's
doc comment and signature: main added a fourth return (the escaped-key
flag, iss-2608301421381157); the lane replaced the "looseness kept"
paragraph with the blockScanEnd paragraph (iss-2609281627055603). Kept
the lane's paragraph, main's third-return paragraph and main's
four-value signature; the body merged cleanly.

Semantic conflict: the lane's TestNoPrivateDelimiterCompare refused
internal/core/implement/loop/brief.go, which main added after the lane
branched. Its one `---` literal is the lane brief's thematic break in
the body, a writer, so it is allowlisted with that reason and count 1.

Refs: iss-2608301421381157, iss-2609281627055603
Assisted-by: Claude:claude-opus-5-5
Lands drainRedact b892f43, which contains drainCap c36ba15: the
capture cluster's six fixes and one display rule for a directory a
surface names (fsutil.DisplayPath: home-relative under HOME, the
directory's name outside it), the status board included. Merged
cleanly; docs/reference/cli/commands.md and surface.json regenerate
unchanged.

Assisted-by: Claude:claude-opus-5-5
Lands drainLint 06d801f: a setext principle title carried into the
statement, a widening summary that stands down past an admitted but
unreadable answer, a markdown-named link at a record store root named,
the fence-run detector widened, and the privacy backstop's two blind
spots over the issue ledger closed. Merged cleanly.

The fence-shape allowlist is left as the lane wrote it: integ11
(drainSpan) is not on main at this base, so its reconciliation
(drop internal/termsafe/prose.go, add internal/core/lifeboat/mdrender.go)
belongs to the re-merge after integ11 lands.

Assisted-by: Claude:claude-opus-5-5
Lands drainScr 8e49fe9 (after fix4): the issue-resolution gate judges
entering at the merge base, withdraws a declaration only by a live
revert that takes out what the reverted commit put in, reads a record
id from a record file only, and feeds grep from here-strings; the
attribution gate refuses a configured automation's name shape.

Conflict in scripts/check-attribution.sh: main moved every identity
pattern into internal/core/identity/tool-identities.txt, read by the
script and by identity.IsToolIdentity (one list, two readers, pinned by
TestToolIdentityListIsTheGatesOwn); the lane added its two word
patterns inline. Kept main's loader and added the two as list keys
(machine_name_word, machine_local_word) read through identity_pattern,
with the lane's reasoning moved into the list beside them.

Semantic: the list's rule is that an identity added there is refused by
both readers, so IsToolIdentity now applies the two keys as well (the
ahoy identity gate flags `semantic-release-bot` before the first
commit). IsMachineName and IsMachineAddress, which the contributors page
reads, stay structural, as the lane chose. Tests: TestIsToolIdentity's
new name-shape cases watched fail before the Go change, and
TestStructuralSignalsLeaveTheNameShapeOut; the dialects test lists
seven keys. The ahoy brief chapter names the shape.

Refs: iss-2609090951276167
Assisted-by: Claude:claude-opus-5-5
…s not sanitised

Refs: iss-2609281736483740

Assisted-by: Claude:claude-opus-5-5
The board wrote the checkout's display name raw, so a directory name
carrying an ESC sequence or a bidi override reached the terminal. The
text line now goes through termsafe.Sanitize. The --json dir is left as
the true name: encoding/json escapes a control byte, a machine reader
needs the real name rather than a masked one, and the board's other
JSON fields are likewise unsanitised data for the reader to render.

TestBoardFirstLineMasksControlsInTheCheckoutName watched fail (ESC and
U+202E directory names printed raw) before the change, pass after.

Refs: iss-2609281736483740
Assisted-by: Claude:claude-opus-5-5
…ntrols

Resolves: iss-2609281736483740
Assisted-by: Claude:claude-opus-5-5
The two resolved records quoted a generic login as C:\\Users\\LOGIN,
which the privacy backstop (widened by drainLint to the escaped
spellings) reads as an absolute local path. The examples now use the
persona home carol; record text only, and abcd lint's four privacy
lines for them are gone (review-drainLint LOW).

Refs: iss-2609251543293588, iss-2609251638574543
Assisted-by: Claude:claude-opus-5-5
drainLint armed harness_leak over .abcd/work and exempted the reviews
tree, mirroring links_resolve. The exemption was inert (the reviews
tree holds no session-URL shape) and a receipt names the commit it
read, never a session, so it bought only a blind spot the leak class
does not need. Dropped; record-lint stays green (review-drainLint LOW).

Assisted-by: Claude:claude-opus-5-5
record_path and intent_path still found a nested <folder>/x/<id>.md by
id, and open_specs_for derived spc ids from any .md under specs/open/,
nested files included, so a lookup could disagree with the derivation
fix4-drainScr routed through record_files. All three now go through
it: record_files takes a spc kind and a `path` form printing
"<id> <path>", record_path and intent_path compare the id whole (itd
zero padding admitted) and read the listing to the end, and
open_specs_for reads its ids from the predicate.

Cases watched fail against the unchanged gate (4 FAIL, 111 ok) and pass
after (115 ok): an intent nested under planned/ is no record, a nested
spec under specs/open/ is not an open spec and the refusal names no
close for it, and the nested-issue case's diagnosis is now "has no
record", as for its non-.md sibling.

Refs: iss-2609240646533487
Assisted-by: Claude:claude-opus-5-5
Measured on a clean clone of c629a04 by dry-run assemble. Widening
measures 1,294,728 tokens (4,984,706 bytes), 0.41% under its 1,300,000
window, so the window moves to 1,310,000; detection measures 1,303,764
(5,019,494), 0.48% under 1,310,000, so it moves to 1,320,000; entailment
measures 382,666 (1,473,266) and keeps 390,000 with 1.92% headroom. The
growth is the drained lanes' capture, intent and lint sources and tests,
which the widening and detection objects read. The comparative position
is not measured this way, as its preset comment states.

Refs: iss-2609251455354719
Assisted-by: Claude:claude-opus-5-5
Brings integ11 (#736), the v0.11.1 release (#737, #738) and integ12 (#739)
into integ/land-13. Release files take main's side; `## [Unreleased]` stays
empty.

Conflicts, by hunk:
- reading-presets.json: main's figures (re-measured in the next commit).
- scripts/check-issue-resolution.sh: both RS001 and RS005 stale-branch
  refusals keep this branch's merge-base-tree test and add/rename placer, and
  ask main's merge-queue probe (landed_while_waiting) first, with main's
  wording; the case suite is all ok.
- commands/abcd.md: this branch's dir rule (home-relative, else the
  directory name), which the board applies over core.Status's home-redacted
  value.
- build_surface_test.go: both sides' added tests kept.
- fsutil paths.go and displaypath_test.go (add/add): see below.
- DECISIONS.md auto-merged with this branch's entry between main's; rebuilt
  as main's ledger plus this branch's one tail entry (0 lines removed
  against either parent).

Semantic:
- fsutil.DisplayPath collision: this branch's DisplayPath(p) and
  DisplayPathsIn stay; main's DisplayPath(repoRoot, p) is renamed
  RepoRelativePath and its 11 callers rerouted (launch archive/bundle/render,
  memory lint x4, site build x2 and check, gitutil operand); its test moves
  to reporelativepath_test.go. The doc comment names the three rules.
- The fence allowlist (mdrecord/fence_shape_canonical_test.go) drops
  internal/termsafe/prose.go and adds internal/core/lifeboat/mdrender.go
  (count 2), the reviewer's reconciliation now that drainSpan is on main.
- The board comment says the encoder escapes a C0 byte only.

Assisted-by: Claude:claude-opus-5-5
Measured on a clean clone of db30f1a (dry-run assemble): widening
1,344,909 tokens / 5,177,902 bytes, 1,350,000 -> 1,360,000; entailment
387,939 / 1,493,566 keeps 400,000 (3.11% headroom); detection 1,353,945 /
5,212,690, 1,360,000 -> 1,370,000. Each window is ceil(t*1.01/10000)*10000.

Refs: iss-2609251455354719

Assisted-by: Claude:claude-opus-5-5
Assisted-by: Claude:claude-opus-5-5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant