You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CURRENT HARD PRE-TAG PUBLICATION BLOCK — 2026-10-09 (supersedes older fallback wording)
RELEASE = v1.30.0 / NOT ADMITTED
NEXT_V_STAR_TAG_ALLOWED = NO until #911 / QNB-162 mechanical publish gate is implemented, tested and TERMINAL
TAURI_GITHUB_RELEASE_PUBLICATION = BLOCKED pending fresh successful exact-tag OSV gate
GHCR_VERSION_MINOR_LATEST_PUSH = BLOCKED pending fresh successful exact-tag OSV gate
PROCEDURAL_CANCEL_OR_WATCH_SUBSTITUTION = NOT ACCEPTED for next release
R15_GATES_4D_4E_5_6_7 = RETAIN existing sequence/maintainer approval
GitHub #911 / Linear QNB-162 is an unconditional release-tag prerequisite, not simply a preferred improvement: no next release tag, Tauri/GitHub Release, GHCR version/minor/latest push, updater metadata publication or cutover-related release publishing until the independent per-workflow tag-SHA OSV security dependencies and negative/positive tests are proven. Old #926 wording allowing a maintainer-approved procedural watch was temporary for v1.29.1 and is not valid for the next tag. A mere healthy candidate or separate ci.yml Security Audit does not close #911. Gate 4D must not be preempted to implement this; schedule after Gate 6 and before the candidate/tag boundary, with #911 terminal before any tag. Preserve explicit Gate-7 authority and all other Release prerequisites. When #911 closes, the release owner independently re-reads workflow DAG, both failure-path proofs, issue/Linear relations, and exact resulting-main CI/CodeQL/Production/retention evidence before lifting this gate.
CURRENT CONTROL-PLANE CHECKPOINT — 2026-10-06 — v1.30 RELEASE OWNER GATED
The release train has returned from dependency/retention housekeeping to the semantic R-15 critical path. No tag or release publication is admitted yet.
HISTORICAL / SUPERSEDED CONTROL-PLANE CHECKPOINT — 2026-10-04 — SUCCESSOR B / PR #954 ACTIVE
CURRENT_MAIN = 2001e63f3b7b1fbf2faa0270238f0de43ba84db1
PR_953 = MERGED / Successor A read-snapshot slice landed
PR_954 = OPEN / DRAFT / MERGEABLE
PR_954_HEAD = 93384b5a71f8bed4f2cde1428b762d2db0b13790
PR_954_BASE = 2001e63f3b7b1fbf2faa0270238f0de43ba84db1
PR_954_SCOPE = Successor B — Mutation / Root-Recovery / Lifecycle Closure
PR_954_SIZE = 16 files / 2 commits / +2121 -100
CODEANT = Quality / Coverage / SCR / SAST / SCA SUCCESS exact head
CODERABBIT = status SUCCESS, but Draft PR auto-review is disabled; do not call review clean
DEEPSOURCE = Python / Shell / Docker SUCCESS; review grade A; Rust status not inferred
VERCEL_PREVIEW = dpl_2JuoEypL2STM2hXvq9ESVa1Gmz9N BUILDING exact head
CI_CD = IN PROGRESS / not yet terminally proven here
CODEQL = not yet terminally proven here
REVIEWS = no submitted reviewer epoch yet
UNRESOLVED_REVIEW_THREADS = 0 at this checkpoint
PR_952 = OPEN / DRAFT / FROZEN PROVENANCE — DO NOT MERGE
GATE_4B = ACTIVE
4C / 4D / 4E = PENDING
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
Successor B is correctly based on the #953 resulting main and carries the semantic A+B union: #953 SessionBinding/rebind semantics plus the mutation/root-recovery/lifecycle mechanisms extracted from frozen #952. The prepared-root Step-F same-instance recovery R1–R5 proof remains this PR's material closure scope.
Do not close Gate 4B, #922, #445, or advance #359/4D until #954 converges on its exact final head, merges normally, and the exact resulting-main CI/CD + CodeQL + Vercel Production gate is terminal.
HISTORICAL / SUPERSEDED — Successor A exact-head checkpoint — PR #953 — 2026-10-03
PR = #953
HEAD = e9bd7556ab0f8111f843b78038fa56078792a097
BASE = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
FILES = 15
COMMITS = 3 signed
MEANINGFUL_LINES = 1870
PR_952 = OPEN / DRAFT / frozen provenance
CODEQL = SUCCESS
CHANGELOG/TEXT GUARDS = SUCCESS
CODEANT = all gates SUCCESS
CI_CD = IN_PROGRESS; all Rust/Node/platform/signature/security/build jobs green, E2E/VRT downstream still running
VERCEL = SUCCESS exact head
CODEX_EXACT_HEAD = one new P2 race remains open
MERGE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
The Terra/Codex closure commit e9bd7556... is now on the remote despite the executor's final report having observed a delayed remote ref. The earlier transport blocker is therefore RESOLVED / transient.
The three P2s from 12cf7833... are implemented and their threads are now resolved:
admitted snapshot-backed catalog enumeration with raw production list/load paths gated away.
Fresh exact-head Codex review on e9bd7556... found one additional VALID same-slice blocker: a mid-capture TOCTOU can occur when provider.state() observes the old runtime as Unlocked, another process commits root N+1, then the subsequent anchor read sees N+1. Current code publishes N+1 into AuthorityCell.current before proving the provider is bound to N+1; resolve_ref then returns Locked, and future retry cannot take the strict-forward rebind path because N+1 has already poisoned current.
Required invariant for closure: never publish a newer snapshot into current before provider/key usability for that exact anchor is established. Prefer rebinding/validation before publication, or otherwise restore/retain the previous snapshot on resolution failure. Preserve explicit-lock, route-change/rotation, rollback, same-generation mismatch and incompatible-authority refusals.
This is still Read/Snapshot scope, but anti-cascade remains binding. One surgical race fix with a deterministic mid-capture regression is admissible; if it needs broad provider redesign or another architectural expansion, stop/split rather than cascade.
The new CodeScene Large Method warning on the 134-line cross-process integration test is non-material and resolved by evidence; no suppression or proof weakening.
Resource horizon remains unchanged: after #953 protected merge + exact resulting-main CI/CD/CodeQL/Vercel Production + cleanup/retention, executor reports and STOPs. No successor B or 4C.
CURRENT EXECUTION MODE — 2026-10-03 — RESOURCE-BOUNDED GATE 4B SPLIT
Anti-cascade/resource decision: PR #952 is no longer a correction target. It is the immutable reviewed extraction source. The current coding-agent run is deliberately bounded to the first successor PR only and must stop after its normal protected merge, exact resulting-main CI/CD + CodeQL + Vercel Production verification, worktree/branch cleanup, and safe Vercel retention. It must not start successor B or 4C in the same execution epoch.
Control-plane ownership is also split deliberately: GitHub issue, Linear, milestone, release-program and checkpoint curation is performed from the ChatGPT control-plane session; the coding agent should only read those records when needed and should not spend token/week quota duplicating status maintenance.
The prepared-root Step-F coordinator-recovery Critical is Gate 4B successor-B scope, not Gate 4D. Gate 4D remains crash-resumable rotation/rekey after 4B and 4C. #360/QNB-12 remains open until complete Gate 4B closure.
CURRENT_MAIN = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
4A = TERMINAL via 950
4B_FOUNDATION = TERMINAL via 951
4B_INTEGRATION = ACTIVE / PR 952
PR_952_HEAD = e34aae28bba31269a814a9a2778346e568c3577e
PR_BUDGET = 16 files / 3000 meaningful lines / 5 signed commits
CODEQL = 37132489430 SUCCESS
CI_CD = 37132489420 SUCCESS — all required exact-head jobs terminal green
VERCEL_PREVIEW = dpl_FBpTZftnpnum9ZahLkPCeMfAWUtz READY exact head
CODEX = exact e34aae28 review reports no major issue
CODERABBIT = current incremental review 401b81b8 to e34aae28 complete / no actionable finding
CODEANT_QUALITY_SCR = FAILURE — valid material recovery finding is not dismissed
CODEANT = fresh full review completed; validated prepared-root recovery gap remains OPEN
MERGE_READY = NO
GH_360 = OPEN / QNB-12 In Progress
GATE_4 = ACTIVE / QNB-168 In Progress / M3 Active
4C = PENDING
4D = PENDING via 359 / QNB-11
4E = PENDING
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
The minimal stale-CAS correction is signed/pushed and locally verified: success and reconciled stale CAS clear the local mutation latch only after physical/writer/admission revalidation; all uncertain errors remain fail-closed. Normal Git transport works; no sandbox/protection/signing bypass occurred.
New material finding: after an injected step-F COMMIT failure, the public coordinator reconciliation returns PreparationPending even when the provider fault is removed. Existing authenticated recover_root is not integrated into the provider-owning coordinator operation API. Lock/shutdown correctly refuse, but same-instance recovery is incomplete. Diagnostic proof is retained locally; temporary probes were removed from source. Do not merge or close 360/QNB-12 until this is fixed with fault proof and fresh exact-head convergence.
No-op RootBusy is separately proved retryable after contention release; its conservative latch is not the prepared-root recovery defect. Remaining DeepSource Rust / CodeScene reds are understood test-only advisory findings, not green. No 4C journal, 4D rekey, collector, deletion, current-app authority change or Gate-7 switch was introduced. At saturated budget, establish a bounded mutation/root-recovery/lifecycle proof slice rather than expand or delete meaningful safety evidence.
HISTORICAL / SUPERSEDED — prior Gate-4B foundation checkpoint
CURRENT R-15 CHECKPOINT — 2026-10-03 — GATE 4B FOUNDATION TERMINAL VIA #951
CURRENT_MAIN = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
RESULTING_MAIN_VERIFICATION = TERMINAL
4A = TERMINAL via #950
4B_FOUNDATION = TERMINAL via #951
PR_951_FINAL_HEAD = d3c87fe675300b2d29e797625b192516a94fd191
PR_951_MERGED_AT = 2026-10-03T04:51:40Z
RESULTING_MAIN_CI_CD = 37097936085 SUCCESS
RESULTING_MAIN_CODEQL = 37097936105 SUCCESS
VERCEL_PRODUCTION = dpl_9W7p2XZ4dscci5d2sXasPHK7iibz READY / PROMOTED exact CURRENT_MAIN / HTTP 200
HOUSEKEEPING = COMPLETE — clean local main; merged branch/tracking ref removed; other worktrees preserved
RETENTION = COMPLETE — 3 stale predecessor previews deleted; all 15 protected IDs and alias bindings verified
4B_OVERALL = ACTIVE / #360 / QNB-12
4B_INTEGRATION = NEXT — protected operation / authority-key / snapshot / lifecycle integration
GH_360 = OPEN until complete 4B acceptance
4C = PENDING / authenticated journal + paged manifest
4D = PENDING / #359 / QNB-11 / rekey + key-epoch crash window
4E = PENDING / first enable + disable refusal + Gate 4 closure
GATE_4 = ACTIVE
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
All resulting-main CI/CD jobs succeeded, including Security Audit, Verified Signatures, Node 22/24, Core/Tauri Rust, Linux/macOS/Windows platform evidence, Build, Playwright, Deep Coverage, Storybook, Browser Quality, CI Success and Pages. Final-head CodeRabbit/CodeAnt/Codex review converged with no actionable finding and no unresolved thread. The two DeepSource test false positives remain evidence-dispositioned advisory red, not green; unavailable reviewer quotas remain recorded.
This terminal checkpoint is for the kernel admission foundation only. It does not complete issue 360, Gate 4B overall, Gate 4 or production Core authority. The next bounded engineering owner remains 4B integration, not 4C.
HISTORICAL / SUPERSEDED — #951 merged, post-merge proof was pending
CURRENT_MAIN = 3cd2b6a37ab8b5bbe8abe32830cd8170b0c9d052
LAST_VERIFIED_MAIN = 4f33d7786076c1d00e73d5db9c527fbd1ea31693
4A = TERMINAL via #950
4B = ACTIVE / #360 / QNB-12
4B_FOUNDATION_PR = #951 MERGED at 2026-10-03T04:51:40Z
PR_951_FINAL_HEAD = d3c87fe675300b2d29e797625b192516a94fd191
4B_FOUNDATION_TERMINAL = NO — resulting-main + Production + housekeeping pending
RESULTING_MAIN_CI_CD = 37097936085 IN_PROGRESS
RESULTING_MAIN_CODEQL = 37097936105 IN_PROGRESS
VERCEL_PRODUCTION_EXACT_CURRENT_MAIN = PENDING VERIFICATION
GH_360 = OPEN until complete 4B integration acceptance
NEXT_ENGINEERING = 4B protected-operation integration, only after foundation terminal proof
4C = PENDING / journal + paged manifest
4D = PENDING / #359 / QNB-11 / rekey + key-epoch crash window
4E = PENDING / first enable + disable refusal + Gate 4 closure
GATE_4 = ACTIVE
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
Final-head CI/CD and CodeQL succeeded; CodeRabbit, CodeAnt and Codex reviewed the final delta/head without remaining actionable findings. All review threads are resolved. The two DeepSource test findings remain evidence-dispositioned advisory false positives, not a green status; quotas are recorded as unavailable. The normal protected squash merge did not close #360 or switch production Core authority. No next semantic slice or retention deletion starts before the exact resulting-main gate.
CURRENT_MAIN = 4f33d7786076c1d00e73d5db9c527fbd1ea31693
GATE_3 = TERMINAL via #949
GATE_4 = ACTIVE via #922
4A = TERMINAL via #950
PR_950_FINAL_HEAD = f2dde0e65bb4dacfd6753f16a6bce1e28bf13078
RESULTING_MAIN_CI_CD = 36994420903 SUCCESS
RESULTING_MAIN_CODEQL = 36994420828 SUCCESS
VERCEL_PRODUCTION = dpl_7Z1r45ckAp4YeYpdHWtHdzQ8BWNN READY exact CURRENT_MAIN
4B = ACTIVE / #360 / QNB-12 / PR #951 kernel admission foundation; protected-operation integration follows
PR_951_HEAD = d3c87fe675300b2d29e797625b192516a94fd191
PR_951_STATUS = OPEN / exact-head CI and review pending / not terminal
GH_360 = OPEN until full 4B acceptance
4C = PENDING / journal + paged manifest
4D = PENDING / #359 / QNB-11 / rekey + key-epoch crash window
4E = PENDING / first enable + disable refusal + Gate 4 closure
NEXT = 4B → 4C → 4D → 4E → Gate 5 → Gate 6 → explicit Gate 7 authorization
PRE_GATE_7_RESIDUAL = #948
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
Live reconciliation confirms Gate 4A terminal, including exact resulting-main CI/CD, CodeQL and Production evidence. Gate 4B is the current renderer-neutral admission/fencing owner. Historical legacy filesystem defects remain provenance; this checkpoint does not claim a production authority switch or Gate 4 closure.
HISTORICAL / SUPERSEDED — CURRENT RELEASE PROGRAM CHECKPOINT — 2026-10-02 10:21 CEST — superseded by verified Gate 4A terminal checkpoint
The release-critical lane remains R-15. Do not pull the deferred Dependabot/governance/editorial train ahead of Gate 4 absent a fresh material security/data-loss/release blocker. #950 is in its initial exact-head epoch and is not yet merge-ready.
HISTORICAL / SUPERSEDED — CURRENT RELEASE PROGRAM CHECKPOINT — 2026-10-01 23:12 CEST — superseded 2026-10-02 10:21 CEST
TARGET = v1.30.0
M0 = TERMINAL
M1 = TERMINAL
M2 = ACTIVE — Gate 3 / #921 / QNB-167
CURRENT_MAIN = 03a24786f1c9fda76656dbbd2a635e324331ec81 (#941 resulting main)
RESULTING_MAIN_VERIFICATION = TERMINAL
CURRENT_MAIN_CI / CODEQL / SECURITY / SIGNATURES = SUCCESS
VERCEL_PRODUCTION = READY on exact CURRENT_MAIN
GATE_3A = TERMINAL via #930
GATE_3B = TERMINAL via #937 + #940
GATE_3C_PART_1 = TERMINAL via #941
GATE_3C_PART_2 = ACTIVE via #942 @ 48525c99ed20c88774df161b8d8c0d474a785302
NEXT = #942 terminal → 3C part 3 → Gate 3/#357 closure → Gate 4 → Gate 5 → Gate 6 → explicit Gate 7 authorization → Gate 7
PRE_RELEASE_DOC_TRUTH_GATE = #932 / QNB-176 after Gate 7
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
The release-critical lane remains R-15. #941 is terminal; #942 is active and not merge-ready at the latest readback. Do not pull Dependabot/governance/editorial work ahead of this lane absent a fresh material security/data-loss/release blocker. #911 remains a preferred pre-tag publication-security prerequisite, not a Gate 3–6 preemption.
HISTORICAL / SUPERSEDED — CURRENT RELEASE PROGRAM CHECKPOINT — 2026-10-01 — superseded 2026-10-01 23:12 CEST
TARGET = v1.30.0
M0 = TERMINAL
M1 = TERMINAL — Gate 2
M2 = ACTIVE — Gate 3 / #921
CURRENT_MAIN = e43559b9bd6c5a8b6f5ba06ed9a2da42079551e1 (#940 resulting main)
RESULTING_MAIN_VERIFICATION = TERMINAL
CURRENT_MAIN_CI / CODEQL / SECURITY / SIGNATURES = SUCCESS
VERCEL_PRODUCTION = READY on exact CURRENT_MAIN
GATE_3A = TERMINAL via #930
GATE_3B_PART_1 = TERMINAL via #937
GATE_3B_PART_2 = TERMINAL via #940
GATE_3C_PART_1 = ACTIVE via #941, head 7a1edcf1527947e7b75cc8e8c6fbe6e1ea11a701
NEXT = #941 terminal → 3C part 2 → 3C part 3 / #357 reconciliation → Gate 4 → Gate 5 → Gate 6 → explicit Gate 7 approval → Gate 7
PRE_RELEASE_DOC_TRUTH_GATE = #932 / QNB-176 after Gate 7 and before candidate/tag freeze
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO
The release-critical lane remains R-15. Gate 3B is now terminal; do not describe #936/#937/#940 as active prerequisites. Current execution is Gate 3C through #941. #941 remains in exact-head convergence and is not merge-ready at the latest readback because current reviewer findings still need correction/disposition and Node 22/24 are still running.
The active release-critical lane remains R-15. #935/#936 is merged support history now, not an active release-preparation lane. Complete exact-SHA resulting-main proof and continue directly to Gate 3B.
#932 is a release-truth checkpoint, not a broad housekeeping detour. #877/#927 remain the larger post-release cleanup/reset owners.
In particular, do not change current README desktop-at-rest-encryption claims before Gate 7 makes those claims stale.
Milestone mission
Make v1.30.0 the focused milestone release that completes and ships the renderer-neutral desktop at-rest encryption program owned by #445.
A minor-version bump from v1.29.1 to v1.30.0 is intentional: this is a substantial new production security/storage capability and migration boundary, not a patch-only correction.
MILESTONE = COMPLETE_DESKTOP_AT_REST_ENCRYPTION
TARGET_VERSION = 1.30.0
PRIMARY_PROGRAM = #445 / R-15
RELEASE_READY = NO
PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO until Gate 7 authorization
Do not close on tag creation alone. v1.30.0 VERIFIED requires published desktop assets, correct GHCR state, verified signed tag, exact released commit, packaged migration/reopen proof, no stored-data regression, at-rest claims proven against real released artifacts, healthy post-release main and mirrored Linear evidence.
After terminal release
Immediately hand off to #927 for the dedicated post-v1.30 source-truth/audit/housekeeping reset, then resume the highest-priority non-R-15 roadmap work from a freshly audited control plane.
15 files / 1925 meaningful lines / 4 signed commits
final mid-capture publication/rebind race fixed in one-file commit fix(core): make snapshot publication rebind atomic (#445)
deterministic interleaving test proves N→N+1 external commit between state observation and anchor read cannot poison AuthorityCell.current; exact key usability and exact anchor equality are proven before publication; subsequent capture remains usable
earlier read/snapshot P2s remain closed
CodeAnt legacy-write observation is partially valid but explicitly deferred to Successor B mutation/writer-admission owner; it does not invalidate the immutable pinned read proof and does not admit mutation scope into feat(core): admit protected reads through pinned snapshots (#445) #953
CodeQL, CodeAnt gates, Vercel, CHANGELOG/Text guards are green exact-head
DeepSource Rust and CodeScene remain advisory reds for already-dispositioned test-fixture/test-method metrics; no suppression or proof weakening
CI/CD still converging (Node 22/24 currently running at this checkpoint)
fresh Codex review on exact 3c118bc6... still pending
MERGE_READY = NO until terminal CI + fresh exact-head reviewer convergence
no Successor B / 4C; production authority switch remains NO
Fresh Codex exact-head review on 3c118bc652210a5861fe408e9d89e4893a66a3a0 produced three VALID Read/Rebind P2s:
prepared-only anchor changes can currently lock/strand a reader even though committed read authority did not change;
KeyState::Locked cannot distinguish explicit lock from a stale previously-unlocked session, so same-key forward auto-rebind can violate explicit-lock refusal;
before first capture, current=None provides no baseline, so a stale previously-unlocked runtime cannot rebind after an external same-key advance.
NEW EXECUTION POLICY: these findings are explicitly authorized for further correction on #953. Do NOT stop merely because another fixable same-slice P2 appears. Continue correction → local proof → signed push → fresh exact-head review/CI cycles until #953 genuinely converges and can be merged normally. Only an unfixable platform/auth/protection blocker or a scope change into Successor-B mutation/root-recovery/4C may stop execution.
Preferred common design direction: preserve a non-secret provider session-binding witness (scope + committed root, or equivalent) that survives stale-root detection but is cleared by explicit lock. Use it to distinguish explicit lock from stale binding and to establish a safe pre-first-capture baseline. Prepared-root-only changes must not be treated as read-authority changes; compare/revalidate the committed read-authority projection rather than the whole AnchorState where appropriate.
#360 / QNB-12 remain open. Successor B remains mutation/root-recovery/lifecycle. PRODUCTION_AUTHORITY_SWITCH_ALLOWED = NO.
CURRENT HARD PRE-TAG PUBLICATION BLOCK — 2026-10-09 (supersedes older fallback wording)
GitHub #911 / Linear QNB-162 is an unconditional release-tag prerequisite, not simply a preferred improvement: no next release tag, Tauri/GitHub Release, GHCR version/minor/
latestpush, updater metadata publication or cutover-related release publishing until the independent per-workflow tag-SHA OSV security dependencies and negative/positive tests are proven. Old #926 wording allowing a maintainer-approved procedural watch was temporary for v1.29.1 and is not valid for the next tag. A mere healthy candidate or separateci.ymlSecurity Audit does not close #911. Gate 4D must not be preempted to implement this; schedule after Gate 6 and before the candidate/tag boundary, with #911 terminal before any tag. Preserve explicit Gate-7 authority and all other Release prerequisites. When #911 closes, the release owner independently re-reads workflow DAG, both failure-path proofs, issue/Linear relations, and exact resulting-main CI/CodeQL/Production/retention evidence before lifting this gate.CURRENT CONTROL-PLANE CHECKPOINT — 2026-10-06 — v1.30 RELEASE OWNER GATED
The release train has returned from dependency/retention housekeeping to the semantic R-15 critical path. No tag or release publication is admitted yet.
HISTORICAL / SUPERSEDED CONTROL-PLANE CHECKPOINT — 2026-10-04 — SUCCESSOR B / PR #954 ACTIVE
Successor B is correctly based on the #953 resulting main and carries the semantic A+B union: #953 SessionBinding/rebind semantics plus the mutation/root-recovery/lifecycle mechanisms extracted from frozen #952. The prepared-root Step-F same-instance recovery R1–R5 proof remains this PR's material closure scope.
Do not close Gate 4B, #922, #445, or advance #359/4D until #954 converges on its exact final head, merges normally, and the exact resulting-main CI/CD + CodeQL + Vercel Production gate is terminal.
HISTORICAL / SUPERSEDED — Successor A exact-head checkpoint — PR #953 — 2026-10-03
The Terra/Codex closure commit
e9bd7556...is now on the remote despite the executor's final report having observed a delayed remote ref. The earlier transport blocker is therefore RESOLVED / transient.The three P2s from
12cf7833...are implemented and their threads are now resolved:Fresh exact-head Codex review on
e9bd7556...found one additional VALID same-slice blocker: a mid-capture TOCTOU can occur whenprovider.state()observes the old runtime as Unlocked, another process commits root N+1, then the subsequent anchor read sees N+1. Current code publishes N+1 intoAuthorityCell.currentbefore proving the provider is bound to N+1;resolve_refthen returns Locked, and future retry cannot take the strict-forward rebind path because N+1 has already poisonedcurrent.Required invariant for closure: never publish a newer snapshot into
currentbefore provider/key usability for that exact anchor is established. Prefer rebinding/validation before publication, or otherwise restore/retain the previous snapshot on resolution failure. Preserve explicit-lock, route-change/rotation, rollback, same-generation mismatch and incompatible-authority refusals.This is still Read/Snapshot scope, but anti-cascade remains binding. One surgical race fix with a deterministic mid-capture regression is admissible; if it needs broad provider redesign or another architectural expansion, stop/split rather than cascade.
The new CodeScene Large Method warning on the 134-line cross-process integration test is non-material and resolved by evidence; no suppression or proof weakening.
Resource horizon remains unchanged: after #953 protected merge + exact resulting-main CI/CD/CodeQL/Vercel Production + cleanup/retention, executor reports and STOPs. No successor B or 4C.
CURRENT EXECUTION MODE — 2026-10-03 — RESOURCE-BOUNDED GATE 4B SPLIT
Anti-cascade/resource decision: PR #952 is no longer a correction target. It is the immutable reviewed extraction source. The current coding-agent run is deliberately bounded to the first successor PR only and must stop after its normal protected merge, exact resulting-main CI/CD + CodeQL + Vercel Production verification, worktree/branch cleanup, and safe Vercel retention. It must not start successor B or 4C in the same execution epoch.
Control-plane ownership is also split deliberately: GitHub issue, Linear, milestone, release-program and checkpoint curation is performed from the ChatGPT control-plane session; the coding agent should only read those records when needed and should not spend token/week quota duplicating status maintenance.
The prepared-root Step-F coordinator-recovery Critical is Gate 4B successor-B scope, not Gate 4D. Gate 4D remains crash-resumable rotation/rekey after 4B and 4C. #360/QNB-12 remains open until complete Gate 4B closure.
CURRENT R-15 CHECKPOINT — PR 952 / e34aae2 — recovery finding blocks merge
The minimal stale-CAS correction is signed/pushed and locally verified: success and reconciled stale CAS clear the local mutation latch only after physical/writer/admission revalidation; all uncertain errors remain fail-closed. Normal Git transport works; no sandbox/protection/signing bypass occurred.
New material finding: after an injected step-F COMMIT failure, the public coordinator reconciliation returns
PreparationPendingeven when the provider fault is removed. Existing authenticatedrecover_rootis not integrated into the provider-owning coordinator operation API. Lock/shutdown correctly refuse, but same-instance recovery is incomplete. Diagnostic proof is retained locally; temporary probes were removed from source. Do not merge or close 360/QNB-12 until this is fixed with fault proof and fresh exact-head convergence.No-op RootBusy is separately proved retryable after contention release; its conservative latch is not the prepared-root recovery defect. Remaining DeepSource Rust / CodeScene reds are understood test-only advisory findings, not green. No 4C journal, 4D rekey, collector, deletion, current-app authority change or Gate-7 switch was introduced. At saturated budget, establish a bounded mutation/root-recovery/lifecycle proof slice rather than expand or delete meaningful safety evidence.
HISTORICAL / SUPERSEDED — prior Gate-4B foundation checkpoint
CURRENT R-15 CHECKPOINT — 2026-10-03 — GATE 4B FOUNDATION TERMINAL VIA #951
All resulting-main CI/CD jobs succeeded, including Security Audit, Verified Signatures, Node 22/24, Core/Tauri Rust, Linux/macOS/Windows platform evidence, Build, Playwright, Deep Coverage, Storybook, Browser Quality, CI Success and Pages. Final-head CodeRabbit/CodeAnt/Codex review converged with no actionable finding and no unresolved thread. The two DeepSource test false positives remain evidence-dispositioned advisory red, not green; unavailable reviewer quotas remain recorded.
This terminal checkpoint is for the kernel admission foundation only. It does not complete issue 360, Gate 4B overall, Gate 4 or production Core authority. The next bounded engineering owner remains 4B integration, not 4C.
HISTORICAL / SUPERSEDED — #951 merged, post-merge proof was pending
Final-head CI/CD and CodeQL succeeded; CodeRabbit, CodeAnt and Codex reviewed the final delta/head without remaining actionable findings. All review threads are resolved. The two DeepSource test findings remain evidence-dispositioned advisory false positives, not a green status; quotas are recorded as unavailable. The normal protected squash merge did not close #360 or switch production Core authority. No next semantic slice or retention deletion starts before the exact resulting-main gate.
HISTORICAL / SUPERSEDED — pre-merge #951 checkpoint
Live reconciliation confirms Gate 4A terminal, including exact resulting-main CI/CD, CodeQL and Production evidence. Gate 4B is the current renderer-neutral admission/fencing owner. Historical legacy filesystem defects remain provenance; this checkpoint does not claim a production authority switch or Gate 4 closure.
HISTORICAL / SUPERSEDED — CURRENT RELEASE PROGRAM CHECKPOINT — 2026-10-02 10:21 CEST — superseded by verified Gate 4A terminal checkpoint
The release-critical lane remains R-15. Do not pull the deferred Dependabot/governance/editorial train ahead of Gate 4 absent a fresh material security/data-loss/release blocker. #950 is in its initial exact-head epoch and is not yet merge-ready.
HISTORICAL / SUPERSEDED — CURRENT RELEASE PROGRAM CHECKPOINT — 2026-10-01 23:12 CEST — superseded 2026-10-02 10:21 CEST
The release-critical lane remains R-15. #941 is terminal; #942 is active and not merge-ready at the latest readback. Do not pull Dependabot/governance/editorial work ahead of this lane absent a fresh material security/data-loss/release blocker. #911 remains a preferred pre-tag publication-security prerequisite, not a Gate 3–6 preemption.
HISTORICAL / SUPERSEDED — CURRENT RELEASE PROGRAM CHECKPOINT — 2026-10-01 — superseded 2026-10-01 23:12 CEST
The release-critical lane remains R-15. Gate 3B is now terminal; do not describe #936/#937/#940 as active prerequisites. Current execution is Gate 3C through #941. #941 remains in exact-head convergence and is not merge-ready at the latest readback because current reviewer findings still need correction/disposition and Node 22/24 are still running.
Primary execution sequence — current
e43559b9...fully proven.HISTORICAL / SUPERSEDED — release checkpoint before Gate 3B completion — 2026-10-01
The active release-critical lane remains R-15. #935/#936 is merged support history now, not an active release-preparation lane. Complete exact-SHA resulting-main proof and continue directly to Gate 3B.
Pre-release documentation/housekeeping gate — #932
After Gate 7 / #925 is merged and its resulting-main authority state is proven, but before candidate/tag freeze, complete #932:
#932 is a release-truth checkpoint, not a broad housekeeping detour. #877/#927 remain the larger post-release cleanup/reset owners.
In particular, do not change current README desktop-at-rest-encryption claims before Gate 7 makes those claims stale.
Milestone mission
Make v1.30.0 the focused milestone release that completes and ships the renderer-neutral desktop at-rest encryption program owned by #445.
A minor-version bump from v1.29.1 to v1.30.0 is intentional: this is a substantial new production security/storage capability and migration boundary, not a patch-only correction.
Primary execution sequence
c4240125...proven.cd12c104....No unrelated roadmap expansion should preempt this lane unless a fresh P0/P1 security/data-loss/release blocker requires it.
Mandatory release prerequisites
Product/security
Packaging / qualification
Release pipeline
Compliance / distribution
Release execution
Terminal definition
Do not close on tag creation alone. v1.30.0 VERIFIED requires published desktop assets, correct GHCR state, verified signed tag, exact released commit, packaged migration/reopen proof, no stored-data regression, at-rest claims proven against real released artifacts, healthy post-release main and mirrored Linear evidence.
After terminal release
Immediately hand off to #927 for the dedicated post-v1.30 source-truth/audit/housekeeping reset, then resume the highest-priority non-R-15 roadmap work from a freshly audited control plane.