Skip to main content

0.7.12 Integrated Qualification

Task: 202609261720-KKE9ZN.

This record supplements the accepted PL-12 handoff. It does not replace its canonical output or claim that version 0.7.12 has been published.

Operator Actions​

The user explicitly authorized the release, required repairs, and policy overrides. After all twelve WorkItems completed, the operator merged main 81fc89167d9d7655bd29664849af6fa2eb4bb054 into the feature branch. The merge commit is 87dff8943313659c15d9937aa491beca79be2eb0. It includes the release workflow recovery repairs from PR 6027.

The controller rejected a thirteenth qualification WorkItem because its amendment contract does not permit changing the WorkItem set. The operator preserved the accepted twelve-item plan and used the user's explicit override for this narrowly scoped compatibility registry update.

The update registers only the implemented task create --plan-file <path> option and its source task. It refreshes generated topology hashes and counts. The frozen compatibility baseline, package delta attribution, and all unrelated compatibility assertions remain unchanged.

Interrupted Checks​

The pre-merge final validation reached bun run ci:local:full. The operator stopped that check to integrate the required main repair. Its native result is recorded in exchange b3775d90b6b877ab662a61c5402e3ca41ac7d704759d86616628124df3f2495d.

A post-merge advance began final validation again. The operator stopped its broad task test subprocess to attempt the qualification plan amendment. Its native result is recorded in exchange ea50db123e2707030a76af7393d0fe63c605a1f534d14cc073b2f28e921c592a.

Neither interrupted invocation is reported as a pass or as an assertion failure. A fresh complete final validation is required.

A third invocation on 24165f47c was stopped during the installed-package smoke check after a concurrent read-only CI plan inspection exposed a test discovery race. Its native result is recorded in exchange 28e00905684953c8438630691bae6138982478941d1613a9f7aeb0337d1e7a89. The plan inspection tried to scan a generated package dist directory while the package build was replacing it. It failed with ENOENT.

The operator corrected test discovery to exclude package-root generated dist directories and installed node_modules before traversal. The regression test failed before the fix because generated and dependency tests were discovered. It preserves legitimate src/dist directories and keeps missing source roots as errors. This repair does not suppress filesystem errors or remove source tests from the verification contract.

The discovery regression suite passes both tests. A comparison with the previous traversal on the quiescent checkout finds the same 823 source test files. bun run vitest:projects:check passes with 823 tests and 10 primary routes. node scripts/checks/run-local-ci.mjs --mode full --explain also passes after the repair.

The next native attempt on 8784d01ec completed the declared implementation, package, replay, and documentation checks. Its full CI run failed because ESLint exhausted the Node heap near 2 GiB and received SIGABRT. Runtime, docs/schema, and CLI CI groups passed. The native failure is preserved in exchange 2f4496d9d041d1c2b5cade5b028e12a67150fa3816423ea00e50ddfde863e28d.

The operator increased the local Node heap ceiling to 4 GiB with NODE_OPTIONS=--max-old-space-size=4096 and selected two fast-test workers with AGENTPLANE_FAST_VITEST_MAX_WORKERS=2 for this two-CPU host. These are local execution settings, not repository defaults or exemptions. All selected tests, assertion criteria, and per-test deadlines remain unchanged. NODE_OPTIONS=--max-old-space-size=4096 bun run lint:core subsequently passed with exit code 0.

The subsequent native full-CI attempt passed runtime, docs/schema, and CLI groups, but the core group exhausted its 15-minute combined lint/test budget. The native exchange is cc1a45e79d7167bf76f65406daedfd684ee65f79c724068dc529791d1f4901a7. This is an incomplete test run, not a passed suite or a reported assertion failure. The operator selected AGENTPLANE_LOCAL_VITEST_SUITE_TIMEOUT_MS=2700000 for this host. The individual 60-second test and hook deadlines remain unchanged.

With that group budget, native full CI passed all four primary groups on 84e9cf84c96abe8c86abc21073aa848f8a67c2fd. The core group completed in 1,875,584 ms. The later docs-site build failed on two M04 report links to roadmap sources outside the Docusaurus docs plugin. This attempt is retained in exchange 4ec1946b0b9725fb4e8a262a23c069d3fffb65caaae86c63052cc07500be4d26.

The operator replaced those links with GitHub source URLs pinned to the report's existing candidate commit. Both target blobs were verified with git cat-file. The source hashes, measurement disposition, and all measurement claims remain unchanged. The original accepted PL-11 output remains available in its immutable implementation commit; this is a publication-link correction, not a new measurement result. Broken-link enforcement remains enabled.

After the link correction, bun run docs:site:check passed, including the production Docusaurus build and design check. A supplemental bun run ci:contract also passed before the following timeout repair.

Prepublish Deadline Repair​

The operator found that native release:prepublish still inherited the ordinary 30-minute check deadline. The 0.7.8 preparation record already documents a successful 39-minute prepublish run. The current command includes contract checks, builds, 815 release-base test files, coverage, and release smoke checks. This is a deadline regression risk, not an observed 0.7.12 prepublish failure.

Under the same user-authorized release repair override, the operator assigned release:prepublish a bounded 150-minute default. Explicit task check limits retain priority. Other commands and individual test/group limits are unchanged. The regression test failed on the old implementation: it observed 1,800,000 ms instead of the release-specific 9,000,000 ms. The test also covers an explicit 1,000 ms limit and the unchanged 30-minute release:prepublish:fast default.

The corrected verification suite passed all 32 tests. Focused ESLint and root typecheck passed. The operator also ran the remaining full-CI steps: workflows:lint passed, all 98 platform-critical tests passed, and all 101 guard coverage tests passed. coverage:significant passed its contract check for 17 source targets. These supplemental results do not replace a complete native final validation or hosted integration evidence.

The operator repair commit bypasses local lifecycle hooks under the explicit user override. Native final validation remains required before integration.

Compatibility Verification​

  • bun run bench:compatibility:candidate:check: pass; candidate is current.
  • bun run bench:compatibility:check: pass; 253 commands, 174 positional arguments, 849 options, and the frozen registry inventory of 3 packages and 162 files.

M04 qualification remains not established as documented in docs/releases/v0.7.12-m04.md. This update makes no new containment or performance claim.

Hosted and Evaluator Recovery​

The native final validation on 34bf5f29ed51d6f7155fac7666e1e45e93deab8d passed all 20 checks. ci:local:full completed in 2,325,998 ms. The controller persisted canonical completion, and the operator granted the exact pr.open request under the user's release authorization. AgentPlane opened PR 6029.

The subsequent native independent-review attempt stopped before obtaining a verdict. Its supervisor journal contained a completed EXECUTOR operation for worktree.prepare, with no pending provider intent. Evaluator startup accepted only a ready journal or its own completed outcome. The new regression reproduced the real Evaluator supervisor journal is not ready error.

The operator reused task 202609261720-KKE9ZN under the explicit repair override. Evaluator startup now uses the existing journal transition primitive to advance a completed non-evaluator operation. It preserves prior operations, result digests, telemetry, evaluator-result replay, and stopped/pending-state guards. The fixture test also proves that human_review remains stopped. The existing fixture helpers moved into their companion testkit to preserve the test-file size limit. All 15 evaluator execution tests pass.

Hosted Core CI 36436089308 reported two real-E2E failures. The mixed-scope fixture requested documentation and task.verify authority only in its Plan, outside its intake-owned contract. Its task creation now declares the exact source, test, documentation, and metadata paths, the required repository effects, and task.verify explicitly. The authority guard remains unchanged. The hosted-close fixture passed literal newlines through --text; it now supplies the same content with --file. Its original failure reproduced locally, and all four hosted-close tests pass after correction.

The qualification contract tests initially failed because seven historical owner-task directories were absent from the sparse checkout. Git restored only those tracked directories from the current commit without changing their contents. All 40 contract tests then passed. Focused ESLint, root typecheck, format checks, and git diff --check also passed. Packaged mixed-scope qualification, fresh hosted CI, and the real independent verdict still require successful execution on the repaired source. Controlled test-provider results are not substitutes for the real review.

Current Review and Pre-Merge Recovery​

The repaired implementation at c0b3be603d850883aae69d3117428609ce446761 passed all six native branch checks, including install smoke, release-critical tests, typecheck, routing validation, doctor, and full local CI. Full CI completed in 2,409,222 ms. The actual packaged mixed-scope lifecycle also passed.

The real Codex review transport first produced an invalid evidence reference, then timed out. A diagnostic proved that this host rejects Bubblewrap namespace setup. No sandbox was disabled and neither failed attempt was accepted as a review. Under the explicit operator recovery authorization, all nine frozen evidence items were hash-checked and embedded directly in a read-only Codex invocation. Its blocked result identified missing current workspace evidence. After native evidence commits, both the full Git status and the implementation diff outside task artifacts were empty. A second independent invocation received that observation and the fresh frozen packet, and returned pass. Native evaluator apply validated and recorded the unmodified result. Provider JSONL and the current workspace observation are preserved in the task evidence.

Pre-merge closure then exposed a separate code defect: fresh verification and review passed, but the mutation guard accepted only a review matching the old last-WorkItem operational projection. The task's immutable Kernel completion remained valid; the subsequent qualified repair had a different implementation SHA and review identity. Native execution failed with the legacy-mutation refusal.

The operator reused 202609261720-KKE9ZN for this bounded closure repair under the user's explicit override. The closure path now permits preservation of an already completed, digest-valid Kernel with passed final-validation evidence, only after the existing current-SHA verification and independent-review gate. The original operational-projection shortcut and all Kernel mutation guards remain unchanged. The repair does not rewrite historical Kernel evidence.

The regression failed on the old code because allowCanonicalProjection was false after fresh checks. All 30 related tests pass after the correction. Negative cases cover rejected current evidence, non-pre-merge mutations, incomplete Kernel state, failed or missing final-validation evidence, and digest tampering. The repaired closure source still requires new full native checks, independent review, hosted CI, and exact-SHA release qualification. The earlier passing results do not certify this later source change or production publication.

Recovered Cursor Readback​

During R0XP40 pre-merge closure, the canonical local coordinator reported route refresh unavailable after the supervisor successfully advanced a previously completed journal cursor. No closure operation ran in that invocation. The persisted supervisor returned an inspection result without the fresh route, and the coordinator required an executed operation result. The exact native operator closure command subsequently succeeded.

Under the same explicit user override, KKE9ZN carries a bounded recovery repair. The supervisor now returns the actual refreshed route after cursor advancement. The canonical local coordinator treats a ready, running journal with that readback and no operation result as cursor progress. It requests a new route before any subsequent operation. This does not create an execution receipt, replay the completed operation, or grant authority at an approval boundary.

Before the repair, two regression assertions failed with the observed missing readback and lifecycle error. All 37 tests across the persisted supervisor, canonical coordinator, integration parity, and branch-publication parity now pass. Negative cases cover missing readback, stopped and pending journals, and failed operations. An approval-boundary case confirms that recovery itself does not execute the operation.

The c950ef9 native branch-check run was intentionally terminated before full CI so this additional repair could be included. Its interruption is not a passing verification result. The final source still requires a complete native check run, independent review, hosted CI, and stable release qualification.

Hosted Concurrent Verification Repair​

The source at 300d2399b1bd6b392e6ec61cb5922b3a88bd4ac3 passed all six native local checks, including full CI, and a real independent review. Native pre-merge closure succeeded. PR 6029 was then updated from protected main through GitHub's exact-head update-branch operation and reconciled locally by fast-forward. The earlier hosted run was cancelled as superseded, not accepted as passing evidence.

Core CI run 36464866219, at 73d84fd18bcc67cfa2762b87bf05ce63ed7d92f0, passed runtime, Windows, security, contract, static, and real end-to-end checks. Its fast test gate failed one concurrent-verification test: 6004 tests passed, one failed, and one was skipped. Integration stopped without merging.

Temporary local diagnostics reproduced the same failure in four of twenty concurrent runs. The observed-path and repository-effect helpers reread the Task README after the verification transaction had already captured its task. A concurrent verification could change the directory during that redundant contained read. The unchanged fail-closed reader correctly rejected it.

Under the user's explicit operator-recovery authorization, KKE9ZN carries the bounded repair. Both helpers now require the caller's task snapshot. Verification passes its current transactional task, and external implementation recovery passes its existing task snapshot. The frozen direct execution base therefore comes from one observation for both paths and effects. No filesystem security checks, revision guards, or durable-result assertions are weakened.

A deterministic regression rejects all backend rereads and checks the complete two-commit direct range and its repository effects. It failed before the fix. After the fix, all 46 tests passed in the diagnostic run, including twenty concurrent repetitions and sixteen durability cases. Temporary instrumentation was removed. This later source change still requires fresh full checks, independent review, and hosted qualification before publication. M04 remains NOT ESTABLISHED.

The next native verification attempt exposed a persisted recovery boundary: the earlier branch executor had recorded a stale_state stop after the last operation had completed, without recording a new intent. Explicit replacement could recover a failure but not this already persisted stale completion. The formal-operation adapter now uses the existing core stale-state reopening transition while holding the execution lease, only for explicit replacement and a completed latest operation. The prior operations remain unchanged. It starts a distinct current verification operation rather than replaying the completed provider operation. The new regression failed on the old adapter. Negative cases retain the stop without explicit replacement and retain effect-in-doubt stops even with replacement. No journal was edited manually.