fix: frontmatter and named directories each follow one rule, and the trailer and identity gates judge every pull request - #741
Merged
Merged
Conversation
The build's open-question check read `resolved:` or `deferred:` anywhere in an item, so "Which id wins once the split is resolved: the old or the new?" read as settled and build would start past a real question. The label now counts opening a line of the item, after a closing bold, or after a dash; the bold-span marker keeps its reach. Every intent in the tree reads the same open-question count under the tightened rule, so no record changes verdict. The brief's build chapter says so, and DECISIONS.md carries a dated correction to the 2026-09-25 entry. Refs: iss-2609260932374727 Assisted-by: Claude:claude-opus-5-5
…-sentence Resolves: iss-2609260932374727 Assisted-by: Claude:claude-opus-5-5
Both refusals of --impact at a close that ships nothing (another spec still open, or a remainder minted) said only to supply the impact at the close that ships. They now also name `abcd intent plan <itd-N> --impact <value>`, which stamps the judgement on the planned record at once, after which the close that ships needs no flag. The value is echoed only when shipped/ would accept it, so the refusal never hands back a command that is itself refused. The test walks the named route end to end: plan stamps, the remainder close and the shipping close both go through without the flag. Refs: iss-2609240646522330 Assisted-by: Claude:claude-opus-5-5
…ent plan --impact Resolves: iss-2609240646522330 Assisted-by: Claude:claude-opus-5-5
…otes The dead-letter reason is free text a host's payload supplied, and the reader cuts only OUR retention clause off it, so a reason quoting a clause of the same shape put a local-tier path into `intent audit --json`, which promises never to hand one out. Every token naming the local tier is now withheld from the reported reason, and the rest of the reason is kept. The property test forges such a reason instead of trusting the fixture's own. The review's second note: the corroboration paragraph of iss-2609100509537730 sat inside its Grounds section, between the promote's pursued entry and the resolve's near-identical one. It moves into the body, above the section; both entries stay, because the section is append-only and each records its own act. Refs: iss-2609252038344132 Refs: iss-2609100509537730 Assisted-by: Claude:claude-opus-5-5
…oted local-tier path Resolves: iss-2609252038344132 Assisted-by: Claude:claude-opus-5-5
…imitive The finding named SetPromotedFrom returning a populated intent beside ErrBackEdgeTaken, with the primitive's own test discarding the return. The promote join under itd-4 AC3's names (48c6108) replaced that primitive with AddRelatedIssue, which returns the zero Intent on every refusal and the record's list on success. Its tests asserted the list on the append path only; they now assert it on the idempotent no-op too, the return the promote route reads the kept edge from on a re-run, and assert the zero Intent beside every refusal. Each assertion was watched fail against a mutated copy. Refs: iss-2609021815563506 Assisted-by: Claude:claude-opus-5-5
…erted directly Resolves: iss-2609021815563506 Assisted-by: Claude:claude-opus-5-5
…ast a BOM
frontmatter.Fields trims a BOM ahead of the opening delimiter, but the sibling
walks that promise parity with it did not: intent's writers refused a
BOM-led record the reader loads ("no leading frontmatter block"), the
changelog took its whole frontmatter for the body, and record-lint took its
`---` for an issue's title.
frontmatter.Close is the reader's own walk, exported: the index of the
closing delimiter, the BOM trimmed at line 0 and nowhere else, every
delimiter judged by IsDelimiter. Intent's three writers (setFrontmatterFields,
removeFrontmatterField, frontmatterClose), the changelog's bodyStart, the
record page's body reader and peers' title reader route through it.
record-lint's body start and agent capability scope ask frontmatterOpen,
which already trims; the disposition parser, the launch prose gate and the
site's frontmatter stripper trim the BOM at line 0 as every reader does. A
writer keeps the file's BOM: it edits keys, never the first bytes.
Refs: iss-2608221126066379
Assisted-by: Claude:claude-opus-5-5
… past a BOM Resolves: iss-2608221126066379 Assisted-by: Claude:claude-opus-5-5
… condition capture disposition redacted --grounds and --exit-condition but never passed them through termsafe.EncodeHiddenRunes, so a bidi override or a zero-width rune landed in the committed dsp-N record verbatim. Every other free-text capture write (capture body, resolve and wontfix notes, defer reason, admit, surprise and reframe grounds, reading items upstream in the reading package) already encodes; the sweep found the disposition the only gap. Refs: iss-2609251823551349 Assisted-by: Claude:claude-opus-5-5
…idden runes Resolves: iss-2609251823551349 Assisted-by: Claude:claude-opus-5-5
FindPrincipleStatement read ATX H1s only, so a principle whose title is underlined with `===` travelled to a reading as a bare paragraph, and principle_claims never judged its title. The one derivation now reads a setext H1 too: the paragraph directly above a `===` underline, its lines joined, skipping masked lines and lines that open another block. Refs: iss-2609261140284421 Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609261140284421 Assisted-by: Claude:claude-opus-5-5
…r cycle capture defer appended a second `## Deferral` section when a record was deferred twice past the same anchor, where the record's shape is one section per cycle. The verb now rewrites that cycle's section (its heading date and its `Deferred past <anchor>:` line) in place; a deferral past a different anchor still appends. Chosen over refusing, because a refusal would send a corrected reason back to a hand edit of the record, which is what the verb exists to replace; the superseded wording stays in git history. A section of any other shape is a hand edit the verb does not own and is left alone. The capture command page and the brief's capture chapter say so. Refs: iss-2609251823555125 Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609251823555125 Assisted-by: Claude:claude-opus-5-5
mapEscape classifies os.Root's escape by matching the text "path escapes from parent", because the os package does not export the error, and nothing pinned the match: both race tests asserted only err != nil, so a Go release that rewords the message would degrade ErrPathUnsafe to a generic error with every test green. Both race tests now assert errors.Is(err, ErrPathUnsafe), and a direct test feeds mapEscape the error a real os.Root escape returns. Refs: iss-2609251823559111 Assisted-by: Claude:claude-opus-5-5
…inned Resolves: iss-2609251823559111 Assisted-by: Claude:claude-opus-5-5
…ble answer The widening-run summary took the admitted case before the stand-down check, so a run whose only admitted proposal carried a contested, cyclic, unsafe or illegible disposition still reported "admitted 1, outstanding []", against the WideningRun doc: such a run supports no count. The stand-down case now comes first. Refs: iss-2609251842112266 Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609251842112266 Assisted-by: Claude:claude-opus-5-5
The ledger identity every capture verb reports (the `ledger` member in --json and the `ledger of` line on stderr, and the record dispatcher's for an iss-N) was home-redacted only, so a checkout outside HOME was printed as its full absolute path. It is now reduced to its directory name, the base-name rule scrubPaths already applies to an absolute path outside both identity roots, built from the existing fsutil.RedactHome rather than a second primitive. renderLedger silently skipped the `ledger` member for a result that is not a JSON object. Every caller passes a struct, so it is now an internal error rather than an envelope that loses its identity without a word; the splice itself stays, because it keeps the result's own member order. Refs: iss-2609251823560369 Assisted-by: Claude:claude-opus-5-5
…pture output Resolves: iss-2609251823560369 Assisted-by: Claude:claude-opus-5-5
record_schema passed silently over a link at a bucketed store root whose name ends in .md without being a record filename (notes.md pointing at a directory). A real directory of that name is reported; the link was not, because telling what it points at would mean following it. Every such link is now named without being followed; README.md and dot-names stay exempt, and a record-named link keeps its store-root finding. Refs: iss-2609261208193041 Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609261208193041 Assisted-by: Claude:claude-opus-5-5
…scan misses TestNoSecondFenceRule's scan is delimiter-only, so a private toggle written as a regexp literal matching a fence run, or as a comparison of a line's first byte against a backtick or tilde, escaped it. A second detector reads the parsed source for both shapes, pinned per file with a reason like the first; a pattern spelling a delimiter stays the first scan's, and a pattern taking a run of letters whole is an alphabet, not a reader. The first test's doc now says what each reaches. Refs: iss-2609251600029607 Assisted-by: Claude:claude-opus-5-5
…s detected Resolves: iss-2609251600029607 Assisted-by: Claude:claude-opus-5-5
…l's pair The widening ordering gate read "committed comparative run" as any run.json under the readings family decoding to position comparative with a candidate_run, so an id-less, manifest-less two-key marker written by hand opened it. ComparativeRunFor now holds a run record that names the widening run to the pair the channel's ingest leaves: its run_id names its own directory, and the manifest the ingest promotes beside it (before it writes the record) agrees on the run id, the position and the candidate_run. A record naming the widening run that fails either is refused by name as ErrInvariantViolation, never read as "no run yet". Not checked, and why: whether git tracks the pair (the gate answers between an ingest and the commit that carries it, the order the channel is used in), and the manifest's hash against the record's manifest_sha256 (a writer who can place both files can compute the hash too, so it would add a step, not a bar). A writer with the tree can still forge the pair; the gate now names the channel's artefacts, which is what the spec's "committed comparative run whose manifest names rdg-N" states. The manifest's file name and its read ceiling move to issueschema (RunManifestFileName, RunArtefactReadLimit), which core/reading now reads, so the writer and the gate share one statement of each. A reading-package test joins the channel's real ingest, exercised and not, to the gate. Fixtures in capture, scribe, the CLI and the rehearsal eval write the pair. Refs: iss-2609251842111593 Assisted-by: Claude:claude-opus-5-5
Resolves: iss-2609251842111593 Assisted-by: Claude:claude-opus-5-5
The whole reframe write reads back to the previous distinct state along first parents, so a rewrite that lands as several commits on that line, a rebased branch among them, is recorded as its last step alone (two commits moving the construal then the glossary give changed=[glossary]), where a squash or a --no-ff merge of the same rewrite gives [construal glossary]. The command page and the brief's capture chapter claimed only the squash equivalence; both now name the series case and the route that records such a rewrite whole (--open before the first commit, --complete after the last). The record offered a line on the page or a spec ruling; no ruling is owed on it in the rulings list, so the page states the behaviour spc-2609020626048705's first-differing-state rule already produces, and a test pins it. Refs: iss-2609261325441711 Assisted-by: Claude:claude-opus-5-5
… is named Resolves: iss-2609261325441711 Assisted-by: Claude:claude-opus-5-5
…ckout's absolute path Refs: iss-2609281613094952 Assisted-by: Claude:claude-opus-5-5
Bare `abcd` printed the checkout's absolute path as its first line and as `dir` in --json, with no redaction at all, so under HOME it named the account and outside HOME the whole local path, in the output a person pastes most often. The board now routes the directory through fsutil.DisplayPath (home-relative under HOME, the base name outside it) in both forms. `dir` is a display field: its readers are the plugin page, which relays it to the person, and two tests that check it is present; no consumer acts on it. The sweep of the board's other lines found one more of the class: the peers notice on stderr carried the reader's error through RedactHome alone, and an unreadable record folder's error names the folder by its absolute path. It is named by DisplayPathsIn against the checkout root. Refs: iss-2609281613094952 Assisted-by: Claude:claude-opus-5-5
TestPeersNamesAWorktreeOutsideHomeByItsDirectoryName and TestThePeerRefusalNamesAWorktreeOutsideHomeByItsDirectoryName chmod a record folder to 0 to force a not-read peer; root reads through it, so in a root container the assertion failed on the fixture, not the code. Every other chmod-0 test in the tree already skips or probes for root. Assisted-by: Claude:claude-opus-5-5
…kout by the display rule Resolves: iss-2609281613094952 Assisted-by: Claude:claude-opus-5-5
The reading floor closes its block on any column-0 line opening with three dashes, so `----` or `--- x` ends it before the canonical reader's close and an excluded key between the two reaches the corpus. Found by the review of this branch; captured before the fix. Refs: iss-2609281627055603 Assisted-by: Claude:claude-opus-5-5
… close The exclusion floor closed its frontmatter block on any column-0 line opening with three dashes, so a `----` or a `--- x` ended the key and shape scans while frontmatter.Fields read on to the real `---`: an excluded key between the two was frontmatter to the canonical reader, invisible to the floor, and travelled under a manifest asserting its refusal. The key and shape scans now run to blockScanEnd, the later of the floor's own close and frontmatter.Close. The floor's close is kept for where the body begins (the fence mask and the heading scan), so each scan takes the reading that refuses more. The reviewer's suggested closer (IsDelimiter, `--- ` or `...`) was not taken: it still fires on `--- x`, which the canonical reader reads through. The delimiter detector also counts literals led by a byte-order mark, and the floor's allowlist reason states the property that now holds. Every committed markdown file (2748) reads identically through the floor before and after: same block, same redaction, same verdict. Refs: iss-2609281627055603 Assisted-by: Claude:claude-opus-5-5
…r than the canonical close Resolves: iss-2609281627055603 Assisted-by: Claude:claude-opus-5-5
The issue-resolution gate derived a record id from a path's basename alone at every reader that turns a path into an id: the entering readers for resolved/ and wontfix/ and for shipped/, the merge-base and base listings of what is already terminal, and terminal_moves, which decides what a revert withdraws. So a nested file (resolved/x/<id>.md) or a non-markdown one (resolved/<id>.txt) under a terminal folder counted as that record entering or leaving it: adding one satisfied a Resolves: or Delivers: trailer, reverting it withdrew the trailer, and one sitting in the folder at the fork made an honest resolution read as already terminal. record_path alone required the record shape. record_files is now the one reading of which paths are records: a file directly in a folder of its store, named <id>.md or <id>-<slug>.md, the shape record_path and intent_path look an id up by. Every such reader goes through it (record_id for a single path), for iss and itd alike. Twelve cases pin it, each watched fail against the previous gate: the nested and non-.md add refused as not entering, for both rules; a revert of odd files withdrawing nothing; and an odd file at the fork or base not making the real record terminal. Refs: iss-2609240646533487 Assisted-by: Claude:claude-opus-5-5
Lands drainFm b72f31d, which contains drainInt 3423af9: frontmatter walks routed through frontmatter.Close/CloseAfter, the BOM sweep, the settled-label narrowing and the exclusion floor's scan extent. Conflict in internal/core/reading/project.go, excludedKeyInFirstBlock's doc comment and signature: main added a fourth return (the escaped-key flag, iss-2608301421381157); the lane replaced the "looseness kept" paragraph with the blockScanEnd paragraph (iss-2609281627055603). Kept the lane's paragraph, main's third-return paragraph and main's four-value signature; the body merged cleanly. Semantic conflict: the lane's TestNoPrivateDelimiterCompare refused internal/core/implement/loop/brief.go, which main added after the lane branched. Its one `---` literal is the lane brief's thematic break in the body, a writer, so it is allowlisted with that reason and count 1. Refs: iss-2608301421381157, iss-2609281627055603 Assisted-by: Claude:claude-opus-5-5
Lands drainRedact b892f43, which contains drainCap c36ba15: the capture cluster's six fixes and one display rule for a directory a surface names (fsutil.DisplayPath: home-relative under HOME, the directory's name outside it), the status board included. Merged cleanly; docs/reference/cli/commands.md and surface.json regenerate unchanged. Assisted-by: Claude:claude-opus-5-5
Lands drainLint 06d801f: a setext principle title carried into the statement, a widening summary that stands down past an admitted but unreadable answer, a markdown-named link at a record store root named, the fence-run detector widened, and the privacy backstop's two blind spots over the issue ledger closed. Merged cleanly. The fence-shape allowlist is left as the lane wrote it: integ11 (drainSpan) is not on main at this base, so its reconciliation (drop internal/termsafe/prose.go, add internal/core/lifeboat/mdrender.go) belongs to the re-merge after integ11 lands. Assisted-by: Claude:claude-opus-5-5
Lands drainScr 8e49fe9 (after fix4): the issue-resolution gate judges entering at the merge base, withdraws a declaration only by a live revert that takes out what the reverted commit put in, reads a record id from a record file only, and feeds grep from here-strings; the attribution gate refuses a configured automation's name shape. Conflict in scripts/check-attribution.sh: main moved every identity pattern into internal/core/identity/tool-identities.txt, read by the script and by identity.IsToolIdentity (one list, two readers, pinned by TestToolIdentityListIsTheGatesOwn); the lane added its two word patterns inline. Kept main's loader and added the two as list keys (machine_name_word, machine_local_word) read through identity_pattern, with the lane's reasoning moved into the list beside them. Semantic: the list's rule is that an identity added there is refused by both readers, so IsToolIdentity now applies the two keys as well (the ahoy identity gate flags `semantic-release-bot` before the first commit). IsMachineName and IsMachineAddress, which the contributors page reads, stay structural, as the lane chose. Tests: TestIsToolIdentity's new name-shape cases watched fail before the Go change, and TestStructuralSignalsLeaveTheNameShapeOut; the dialects test lists seven keys. The ahoy brief chapter names the shape. Refs: iss-2609090951276167 Assisted-by: Claude:claude-opus-5-5
…s not sanitised Refs: iss-2609281736483740 Assisted-by: Claude:claude-opus-5-5
The board wrote the checkout's display name raw, so a directory name carrying an ESC sequence or a bidi override reached the terminal. The text line now goes through termsafe.Sanitize. The --json dir is left as the true name: encoding/json escapes a control byte, a machine reader needs the real name rather than a masked one, and the board's other JSON fields are likewise unsanitised data for the reader to render. TestBoardFirstLineMasksControlsInTheCheckoutName watched fail (ESC and U+202E directory names printed raw) before the change, pass after. Refs: iss-2609281736483740 Assisted-by: Claude:claude-opus-5-5
…ntrols Resolves: iss-2609281736483740 Assisted-by: Claude:claude-opus-5-5
The two resolved records quoted a generic login as C:\\Users\\LOGIN, which the privacy backstop (widened by drainLint to the escaped spellings) reads as an absolute local path. The examples now use the persona home carol; record text only, and abcd lint's four privacy lines for them are gone (review-drainLint LOW). Refs: iss-2609251543293588, iss-2609251638574543 Assisted-by: Claude:claude-opus-5-5
drainLint armed harness_leak over .abcd/work and exempted the reviews tree, mirroring links_resolve. The exemption was inert (the reviews tree holds no session-URL shape) and a receipt names the commit it read, never a session, so it bought only a blind spot the leak class does not need. Dropped; record-lint stays green (review-drainLint LOW). Assisted-by: Claude:claude-opus-5-5
record_path and intent_path still found a nested <folder>/x/<id>.md by id, and open_specs_for derived spc ids from any .md under specs/open/, nested files included, so a lookup could disagree with the derivation fix4-drainScr routed through record_files. All three now go through it: record_files takes a spc kind and a `path` form printing "<id> <path>", record_path and intent_path compare the id whole (itd zero padding admitted) and read the listing to the end, and open_specs_for reads its ids from the predicate. Cases watched fail against the unchanged gate (4 FAIL, 111 ok) and pass after (115 ok): an intent nested under planned/ is no record, a nested spec under specs/open/ is not an open spec and the refusal names no close for it, and the nested-issue case's diagnosis is now "has no record", as for its non-.md sibling. Refs: iss-2609240646533487 Assisted-by: Claude:claude-opus-5-5
Measured on a clean clone of c629a04 by dry-run assemble. Widening measures 1,294,728 tokens (4,984,706 bytes), 0.41% under its 1,300,000 window, so the window moves to 1,310,000; detection measures 1,303,764 (5,019,494), 0.48% under 1,310,000, so it moves to 1,320,000; entailment measures 382,666 (1,473,266) and keeps 390,000 with 1.92% headroom. The growth is the drained lanes' capture, intent and lint sources and tests, which the widening and detection objects read. The comparative position is not measured this way, as its preset comment states. Refs: iss-2609251455354719 Assisted-by: Claude:claude-opus-5-5
Brings integ11 (#736), the v0.11.1 release (#737, #738) and integ12 (#739) into integ/land-13. Release files take main's side; `## [Unreleased]` stays empty. Conflicts, by hunk: - reading-presets.json: main's figures (re-measured in the next commit). - scripts/check-issue-resolution.sh: both RS001 and RS005 stale-branch refusals keep this branch's merge-base-tree test and add/rename placer, and ask main's merge-queue probe (landed_while_waiting) first, with main's wording; the case suite is all ok. - commands/abcd.md: this branch's dir rule (home-relative, else the directory name), which the board applies over core.Status's home-redacted value. - build_surface_test.go: both sides' added tests kept. - fsutil paths.go and displaypath_test.go (add/add): see below. - DECISIONS.md auto-merged with this branch's entry between main's; rebuilt as main's ledger plus this branch's one tail entry (0 lines removed against either parent). Semantic: - fsutil.DisplayPath collision: this branch's DisplayPath(p) and DisplayPathsIn stay; main's DisplayPath(repoRoot, p) is renamed RepoRelativePath and its 11 callers rerouted (launch archive/bundle/render, memory lint x4, site build x2 and check, gitutil operand); its test moves to reporelativepath_test.go. The doc comment names the three rules. - The fence allowlist (mdrecord/fence_shape_canonical_test.go) drops internal/termsafe/prose.go and adds internal/core/lifeboat/mdrender.go (count 2), the reviewer's reconciliation now that drainSpan is on main. - The board comment says the encoder escapes a C0 byte only. Assisted-by: Claude:claude-opus-5-5
Measured on a clean clone of db30f1a (dry-run assemble): widening 1,344,909 tokens / 5,177,902 bytes, 1,350,000 -> 1,360,000; entailment 387,939 / 1,493,566 keeps 400,000 (3.11% headroom); detection 1,353,945 / 5,212,690, 1,360,000 -> 1,370,000. Each window is ceil(t*1.01/10000)*10000. Refs: iss-2609251455354719 Assisted-by: Claude:claude-opus-5-5
Assisted-by: Claude:claude-opus-5-5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request lands four reviewed drain lanes of autonomous run A as one change: frontmatter is read by one rule everywhere, a directory a command names is shown by one display rule, the lint cluster's five fixes, and the two gate scripts that judge every pull request's trailers and commit identities. It also carries five small follow-ups the reviews asked for and recalibrates the cold-reading windows once for the lot.
Frontmatter walks (drainInt, drainFm). Every reader of a record's frontmatter now opens and closes the block by the same delimiter rule, so a byte-order mark, a CRLF line or an indented rule no longer makes one reader see a block another reader does not. The build's open-question check reads a settled label only where a label is written, the early-close refusal names the command that declares an impact, the owed listing withholds a local-tier path, and the reading exclusion floor scans every line the canonical reader treats as frontmatter.
One display rule for a directory (drainCap, drainRedact). A command that names a checkout, a worktree or a repository root shows it home-relative under HOME and by its own name outside it, never as an absolute path: the capture verbs,
abcd peers, the build status, history ingest and recovery, and the status board all follow it. The capture cluster's other fixes land with it: hidden characters in a disposition are encoded, a second deferral past the same release rewrites its section, and the comparative-run gate holds a run to the channel's own manifest.Lint cluster (drainLint). A setext principle title is carried into its statement, a widening summary stands down past an unreadable answer, a link to a record store root is named, the fence-run detector sees more shapes, and the privacy backstop reads escaped Windows home paths and the issue ledger.
Gate scripts (drainScr). The issue-resolution gate judges a record entering a terminal folder at the merge base, withdraws a declaration only when a real revert takes out what the reverted commit put in, reads a record id from a record file only, and no longer fails at random on a long record. The attribution gate refuses a configured automation's name, such as
semantic-release-bot, while a person named Jan Bot still passes.At the integration. The configured-automation name shape joins the shared machine-identity list, so
abcd ahoyflags it before the first commit as the gate refuses it after; the contributors page stays on the structural signals. The status board's first line masks control and bidi characters in the directory name. The gate's record lookups use the same record-file rule as its derivations. Two resolved records' Windows-path examples use a persona home, and the reviews tree is no longer exempt from the session-leak rule. The widening and detection reading windows rise by 10,000 tokens each.Re-merge after integration branches 11 and 12 and v0.11.1 (#736-#739). Main is merged in by hunk, and the release files keep main's text with an empty
## [Unreleased]. Two path helpers had landed under one name: this branch'sDisplayPathkeeps naming a directory a surface points at, and main's repository-relative helper becomesRepoRelativePath, so the launch, memory-lint, site and git-operand reports keep their paths relative to the repository. The fence-run detector's allowlist trades the code-span helper, which no longer reads a fence character, for the lifeboat renderer, which does. The issue-resolution gate asks main's merge-queue question first and this branch's merge-base question second, with main's wording in both refusals. A board comment now says the JSON encoder escapes only C0 bytes. Both lanes' new build tests are kept, and the decision log keeps main's order with this branch's entry last. The generated command reference did not drift. The widening and detection windows are re-measured at the merged tip. The two open records named below as Refs stay open. The four resolved ones are declarations carried from the lanes' own commits.Reviews: drainInt SHIP · drainFm SHIP (fix2 SHIP) · drainCap SHIP · drainRedact SHIP (fix2 SHIP) · drainLint SHIP · drainScr FIX FIRST, then fix2 SHIP, fix3 SHIP, fix4 applied.
Resolves: iss-2608221126066379
Resolves: iss-2608270655499478
Resolves: iss-2608270908348042
Resolves: iss-2608301306580014
Resolves: iss-2608301744300631
Resolves: iss-2609012047551175
Resolves: iss-2609012047566360
Resolves: iss-2609021815563506
Resolves: iss-2609090951276167
Resolves: iss-2609240646522330
Resolves: iss-2609240646533487
Resolves: iss-2609251600029607
Resolves: iss-2609251823551349
Resolves: iss-2609251823555125
Resolves: iss-2609251823559111
Resolves: iss-2609251823560369
Resolves: iss-2609251842111593
Resolves: iss-2609251842112266
Resolves: iss-2609252038344132
Resolves: iss-2609260932374727
Resolves: iss-2609261140284421
Resolves: iss-2609261208193041
Resolves: iss-2609261325441711
Resolves: iss-2609281314564762
Resolves: iss-2609281329007423
Resolves: iss-2609281613094952
Resolves: iss-2609281627055603
Resolves: iss-2609281736483740
Resolves: iss-263
Refs: iss-2609221820487644
Refs: iss-2609100509537730
Refs: iss-2608301421381157
Refs: iss-2609251543293588
Refs: iss-2609251638574543
Refs: iss-2609251455354719
Assisted-by: Claude:claude-opus-5-5