Skip to content

fix(pins): recover the 2026-09-03 dirty tree and close its pin chain (#393) - #409

Draft
2233admin wants to merge 9 commits into
mainfrom
wip/adjudicate-36-files
Draft

2233admin wants to merge 9 commits into
mainfrom
wip/adjudicate-36-files

Conversation

@2233admin

Copy link
Copy Markdown
Owner

Recovers 40 files left uncommitted by a 2026-09-03 session, and closes the
pin chain they left open. DR-0013 forbids compiling on the host that owns the
original checkout, which is why this work sat untested for 27 days.

What the recovery found

The 2026-09-03 session did not merely forget to commit. It ran a stash, hit
conflicts, and left three internalization records carrying live
<<<<<<< Updated upstream / >>>>>>> Stashed changes markers. Those files
were not valid JSON, so ast_grep_internalization, internalization_record,
and declared_pins could not parse them. Nothing caught it because no host
could run the suite.

A second defect sat underneath: crates/code-intel-cli/src/snapshot.rs was
edited, and the same session touched orchestration/integrations.json
without updating the declared toolchain digest. capability_contract and
capability_exec both reported it stale.

Commits

  • 4851812 — the 40 files as one reviewable recovery unit
  • 5e40a14 — drop the three conflict-marker files, restore the last committed state
  • b5dc807 — resync repository.snapshot-identity in integrations.json
  • d410af5 — REPO_SNAPSHOT_DIGEST in capability_exec.rs was pinned to the pre-2026-09-03 snapshot.rs, so repo.snapshot failed closed with request implementation differs from declaration
  • 1e79b85 — repin the 9 declared pins that d410af5 invalidated (it changed capability_exec.rs's own digest)

1e79b85 must be the last commit: the chain closes on itself, and the
internalization records are the last link.

Verification

cargo test --workspace --no-fail-fast → exit 0, 70 test targets, 0 failures
on 1e79b85, run on DESKTOP-AL7MNNO (Windows 11 Home, MSVC 14.44.35207,
Rust 1.95.0 per rust-toolchain.toml, ripgrep 14.1.0, ast-grep 0.42.3 —
the versions ci.yml installs).

Baseline for comparison: the same suite on the pre-recovery tree produced
32 failing targets. 35 of those failures were a single missing rg
binary, not code defects — walk.rs::governed_visible_files returns None
when ripgrep is absent, which silently disables the repository_ignored
gate instead of failing loudly. The rest were the conflict markers and the
stale pins above.

Notes for review

  • Snapshot identity does not change. This is a recovery, not a fix.
  • The #403 streaming-hash work is present but incomplete: snapshot.rs
    imports Sha256 and never uses it. hash_records still builds the second
    full-tree buffer. Worth a follow-up, not this PR.
  • flash_ratchet.rs (DR-0012) is wired and its tests pass here. This also
    fixes the README 404 where docs/decisions/README.md listed DR-0012 as
    active while the record existed only in a dirty worktree.

Relates to #403, #393.

Curry and others added 8 commits September 30, 2026 03:29
…handoff

Survey-only commit. No production code changed, so no test suite ran
(DR-0013 suspends compilation on this host while #403 is open).

- DR-0013: this host is isolation-excluded. #403 states "Do not reproduce,
  build, or run the full test suite on the affected Windows host". Measured
  facts recorded: 32 CPUs, 93.7 GB RAM, pagefile peak 1.4 GB, four disks
  Healthy, zero WHEA in 7 days. Crash is real; "compilation exhausted
  memory" is not a supported explanation. Causation stays open.
- DR-0014: convergence means every open issue carries a do/freeze/close
  verdict, not that the backlog reaches zero. 96 open issues include 65
  `backlog`, whose own label reads "Frozen: not in the v1 convergence scope".
- problem-inventory: four read-only survey lanes, every claim cited. Records
  the snapshot.rs whole-tree memory defect (#403) and confirms the Rust
  production path spawns zero PowerShell subprocesses.
- handoff: the open-handoff document for the next session, placed under docs/
  because .superpowers/sdd/.gitignore is "*" and never reaches a worktree.

No commit claim is made for the 42 pre-existing modified files; they remain
unstaged per AGENTS.md on mixed uncommitted work.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The 2026-09-30 convergence pass drove the open queue to an explicit
verdict on every issue. Three things the original DR-0014 did not say
turned out to matter, so they are now part of the rule.

1. A label is not a verdict. 27 of the 65 `backlog` issues carried no
   comment at all -- the label had been applied in bulk on 2026-08-03
   and the required written reason never followed. All 27 now carry
   one. A label may be applied in bulk; the reason may not.

2. `claimed` goes stale silently. Four zombie claims were found
   (#302, #47, #193, #395/#396/#397), all the same shape: a comment
   naming a branch, no push, no PR, 37-40 days stale. #47 was both
   `backlog` and `claimed` at once, which the two label definitions
   make impossible. A claim comment is an assertion, not a branch --
   verifying a claim means confirming the ref exists in local heads,
   origin refs, and anywhere else.

3. "Work exists" is not "work delivered". Five distinct states turned
   up that an open-issue count cannot distinguish: shipped-but-open
   (#383), implemented-on-a-remote-branch-never-PR'd (#123),
   implemented-on-a-local-branch-never-pushed (#363),
   uncommitted-with-evidence-gone (#393), and claimed-then-worktree-
   deleted (#395/#396/#397, 0 commits ahead of main). The last is why
   the others matter: the missing push that would have saved those
   three also separates "delivered" from "written down" elsewhere.

The handoff records the dirty-tree adjudication: the real count is 39,
not 42, falling to 36 after three local excludes. It also flags an
accounting break -- `docs/decisions/README.md` is committed and lists
DR-0012 as active, but that file exists only in an uncommitted
worktree, so a clean clone gets a 404 on that row.

Also corrects the handoff pointer in DR-0014, which still referenced
the gitignored `.superpowers/sdd/` copy rather than `docs/`.

No cargo commands were run: DR-0013 excludes this host while #403 is
open, so the test suite requirement is suspended here and belongs to
another host or CI.
`code-intel lint hardcoded-paths` scans tracked .ps1/.psm1/.md/.yml for
machine-specific paths, and AGENTS.md warns that naming a scanned Windows
user-directory variable bare fails the scan in prose or a comment, not just
in code. This record named two such paths literally: the absolute path of
the user-level agent instructions file, and the absolute checkout path.

Both now read as descriptions instead. The exclusion rule is unchanged;
only the host-specific spelling is gone, so the record no longer names a
machine it is meant to outlive.

Caught by hand because the gate itself cannot run on this host: the
installed binary is 0.7.1 while the command landed in 0.7.2-beta.6, and
DR-0013 forbids compiling the checkout to build a newer one. Filed as #405
so the gap stops recurring per session.
Recover the 40 files left uncommitted by a 2026-09-03 session so they can
be tested rather than guessed about. DR-0013 forbids compiling on the
affected host, which is why this work sat untested for 27 days.

Contains the DR-0012 huashu-flash ratchet (kernel, tests, schemas, the
decision record the committed README already listed as active), a
half-finished #403 streaming-hash change in snapshot.rs that added the
Sha256 import without converting hash_records, and legacy/integration
pin-chain edits whose digests will need a repin.

Snapshot identity must not change: this is a recovery commit, not a fix.
…ion records

The 2026-09-03 session left three internalization records with live
<<<<<<< Updated upstream / >>>>>>> Stashed changes markers. The files were
not valid JSON, so ast_grep_internalization, internalization_record, and
declared_pins all failed to parse them. The failure surfaced only once a
host could actually run the suite.

Restore the last committed state of the four records, then repin.
…gest

The 2026-09-03 session edited crates/code-intel-cli/src/snapshot.rs and
orchestration/integrations.json in the same change but left the declared
toolchain digest behind, so capability_contract reported it stale. This is
the final link of the pin chain: repin --write handles the internalization
records, this one lives in integrations.json and needs a literal
replacement.
capability_exec held the pre-2026-09-03 digest for snapshot.rs, so the
repo.snapshot capability request no longer matched its declaration and the
route failed closed with 'request implementation differs from declaration'.
This is the last link of the pin chain: the internalization records that
declare capability_exec.rs must be repinned after this commit.
Mirrors what `code-intel repin --repo . --write` produced on the LAN build
host. The pin chain closes here: capability_exec.rs declares snapshot.rs,
so fixing REPO_SNAPSHOT_DIGEST changed capability_exec.rs's own digest, and
the three internalization records that declare it had to be repinned last.
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@repowise-bot

repowise-bot Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

🔍 1 thing to check

  1. 5 files that usually change with this PR's files are not in it: crates/code-intel-cli/src/main.rs, crates/code-intel-cli/src/cli/command_catalog/mod.rs, crates/code-intel-cli/src/cli/command_catalog/tests.rs (+2 more)

✅ Health of changed files: 3.5 → 3.7 (+0.2)


📊 See the full report for this PR
Your repo map with this PR's blast radius lit up, every caller of the contracts it changes, and health before and after. No sign-in. · Plain markdown for agents · ⭐ Star Repowise · 📥 Install bot · Silence on a single PR with [skip repowise] in the title · Per-repo toggle on repowise.dev/settings/bot · Updated 2026-09-30 07:59 UTC

@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Code Intel change risk

Score Percentile Level
66/100 54th (vs last 41 commits) 🟢 low

Top signals

  • Diff shape: 46 file(s), +2638/-909 (max file share 0.12)
  • Test asymmetry: source changed, tests touched
  • Bug-magnet: 223 fix commit(s) in touched files (180d)
  • Churn: 570 commit(s) touching these files (90d)

revspec: origin/main..HEAD · threshold: score >= 80 blocks unless labeled risk-accepted; percentile is reported, not gated (#201) · code-intel change risk

The 2026-09-03 recovery brought back a Sha256 implementation that was never
formatted, so `cargo fmt -p code-intel -- --check` failed on all four CI
platforms. Whitespace only; no pinned digest declares this file.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant