| 1 | # Codewhale v0.9.2 completion ledger |
| 2 | |
| 3 | > **Living release source of truth.** Update it in place; do not append session |
| 4 | > narrative. It authorizes local version/changelog preparation and dogfood, but |
| 5 | > no tag, GitHub Release, package publication, deployment, push to protected |
| 6 | > `main`, paid/live-provider request, or customer communication. Nothing below |
| 7 | > is a claim that unfinished work is done. |
| 8 | |
| 9 | ## Candidate identity |
| 10 | |
| 11 | | Boundary | Exact state | |
| 12 | | --- | --- | |
| 13 | | Authoritative release lane | protected `main` in `/Volumes/VIXinSSD/CW/codewhale` | |
| 14 | | Current landed runtime candidate | PR #4953 merge `823280557235f57866d13c726110df427ace662b`; later ledger-only bookkeeping does not change the built runtime candidate | |
| 15 | | Integration campaign | PR #4911 merged at `8fff533e6203193984c34552d837c47845e51f51`; focused PRs #4912–#4927 are represented in its landed history | |
| 16 | | Final runtime follow-up | PR #4943 restored account-owned `/rc`; merged at `e3fbb6a915af0460dd12b03d88d92b295932ef8e` | |
| 17 | | Final web follow-up | PR #4944 aligned the public landing with the CWC visual system; merged at `d2a5b2253e8d939eb74a1024d44babb6958200bb` | |
| 18 | | Final Operate startup + capture follow-up | PR #4953 tested at content head `6f2de8ec0183de3dd856e2e71b1fffb59fdb0c06`; merged at `823280557235f57866d13c726110df427ace662b` | |
| 19 | | Workspace version (`Cargo.toml`) | `0.9.2` — bumped at `0faa44a74` | |
| 20 | | npm `npm/codewhale` | `0.9.2` — bumped at `0faa44a74` (`npm/deepseek-tui` 0.8.49 and `npm/runtime-sdk` 0.8.60 are separate legacy/SDK lines) | |
| 21 | | Tag / Release | none for v0.9.2; no tag created, moved, or planned by this ledger | |
| 22 | | Publication state | no crates/npm publish, no artifact upload, no web deploy | |
| 23 | |
| 24 | ## Final landing gate (current) |
| 25 | |
| 26 | This table is the release decision surface. The longer tables below retain |
| 27 | historical engineering evidence but do not override this current state. |
| 28 | |
| 29 | | Gate | Status | Receipt | |
| 30 | | --- | --- | --- | |
| 31 | | Integration candidate | **PASS** | PR #4911 merged to `main` at `8fff533e6203193984c34552d837c47845e51f51`; focused PRs #4912–#4927 are landed in that history | |
| 32 | | Full release verification | **PASS** | Final content head `6f2de8ec0183`: full workspace 11,254 passed / 0 failed / 7 ignored; exact CI clippy and every release gate below passed; hosted Ubuntu, macOS including offline eval, Windows, web, OHOS, CodeQL, Buildkite, DCO, and link gates passed before merge `8232805572` | |
| 33 | | ACP numeric request IDs | **PASS** | PR #4929 landed client-aware behavior: Avante numeric IDs are preserved and Zed numeric IDs retain the compatibility conversion | |
| 34 | | Thinking expansion | **PASS** | PR #4928 merged and closed #4925 | |
| 35 | | Web deploy workflow | **PASS (code path)** | #4907 is repaired; validation runs on push/PR and deployment remains manual-dispatch-only | |
| 36 | | Real-session capture harness | **PASS (harness only)** | PR #4940 merged at `6acc5dd367547a12b31fccb473da30954ca35d72`; real human-operated capture remains #4906 | |
| 37 | | Account-owned remote control | **PASS** | PR #4943 exact head passed hosted Ubuntu, Windows, and macOS; merged at `e3fbb6a915af0460dd12b03d88d92b295932ef8e` | |
| 38 | | Public landing redesign | **PASS** | PR #4944 exact combined head `2d7b7590bda0f983d7d99541482c151b95dc5132`: web tests/lint/build, Claude, CodeQL, Buildkite, Windows (17m52s), and macOS including offline eval (20m42s) all passed; merged at `d2a5b2253e8d939eb74a1024d44babb6958200bb` | |
| 39 | | Operate startup + current-session capture | **PASS** | PR #4953 exposes Act / Plan / Operate in native Startup settings, preserves `operate`, keeps permission posture independent, installs Hunter's byte-identical 1562×1256 capture on README/site, and makes no release-version claim because the capture binary was not recorded; merged at `8232805572` | |
| 40 | | Final dogfood binaries | **PASS** | Fresh external target `backups/v092-final-release-8232805572.TaAugU`; `codew`, `codewhale`, and `codewhale-tui` all report `0.9.2 (823280557235)` from a fresh login shell; clean-source receipt `backups/dogfood-installs/20260728T084840Z-823280557235.txt`; the earlier `2d7b7590bda0` and interim `ffde4edc75dc` installs are superseded | |
| 41 | | Milestone | **HUMAN-GATED** | #4906 is the only open v0.9.2 milestone issue: record and accept a real provider/local-Ollama session for the site and README | |
| 42 | | Publication | **HUMAN-GATED** | no v0.9.2 tag, GitHub Release, crates/npm publication, artifact upload, web deploy, or customer communication has occurred | |
| 43 | |
| 44 | ## Approval rails (hard) |
| 45 | |
| 46 | No agent takes these without explicit, per-action approval from Hunter: |
| 47 | |
| 48 | - push to protected `origin/main`; force-push or rewrite of any shared ref |
| 49 | - tag creation or move, GitHub Release |
| 50 | - crates.io / npm publication, artifact upload, Homebrew tap update |
| 51 | - any deployment (Codewhale web, `app.codewhale.net`, CWC #123) |
| 52 | - production credentials, billing/Stripe, DNS, customer-data mutation |
| 53 | - paid/live-provider entitlement tests (e.g. Kimi Code K3), signing/notarization |
| 54 | - approving `action_required` fork workflow runs — running an outside |
| 55 | contributor's code on org runners is a trust decision, not a CI chore |
| 56 | - contributor-facing communication that closes or rejects community work |
| 57 | |
| 58 | Standing engineering rails: land through small reviewable commits or PRs; |
| 59 | preserve contributor authorship and `Co-authored-by` / `Harvested from PR #N` |
| 60 | credit; never close an issue without per-criterion receipts on the landed SHA; |
| 61 | never run probes or tests against the real `~/.codewhale` — isolate through a |
| 62 | task-specific `CODEWHALE_HOME` without repurposing `HOME`. |
| 63 | |
| 64 | ## Release gates (exact, from live `.github/workflows/ci.yml`) |
| 65 | |
| 66 | Jobs: **Change detection**, **Version drift**, **Lint**, **Workflow RLM cache**, |
| 67 | **Test** (matrix), **npm wrapper smoke**, **Mobile runtime smoke**, |
| 68 | **Workflow lint**, **Documentation**. Change detection sets a `heavy` flag; |
| 69 | light (docs-only) changes skip the Rust legs, and non-`workflow_dispatch` runs |
| 70 | skip the ubuntu leg of Test/npm-smoke by design. |
| 71 | |
| 72 | | Gate | Exact command | |
| 73 | | --- | --- | |
| 74 | | Version drift | `./scripts/release/check-versions.sh` | |
| 75 | | OHOS deps | `./scripts/release/check-ohos-deps.sh` | |
| 76 | | Release helper contracts | `bash .github/scripts/agent-task-metadata.test.sh`, `bash scripts/release/generate-release-body.test.sh`, `bash scripts/release/install-dogfood.test.sh`, `bash scripts/release/prepare-release.test.sh`, `bash scripts/release/require-release-tag-checkout.test.sh`, `bash scripts/release/verify-remote-tag.test.sh`, `bash .github/scripts/update-homebrew-tap.test.sh`, `node .github/scripts/release-workflows.test.js`, `node --test scripts/release/assemble-release-assets.test.js`, `node --test scripts/release/ensure-release-assets-absent.test.js` | |
| 77 | | Format | `cargo fmt --all -- --check` | |
| 78 | | Clippy | `cargo clippy --workspace --all-features --locked -- -D warnings -A clippy::uninlined_format_args -A clippy::too_many_arguments -A clippy::unnecessary_map_or -A clippy::collapsible_if -A clippy::assertions_on_constants` | |
| 79 | | Registry / docs parity | `python3 scripts/check-provider-registry.py`, `check-readme-translations.py`, `bash scripts/check-readme-locales.sh`, `python3 scripts/check-tui-locale-parity.py` | |
| 80 | | Contributor credit | `python3 scripts/check-coauthor-trailers.py --author-map .github/AUTHOR_MAP --range <base..HEAD> --check-authors` | |
| 81 | | Workflow RLM cache | `cargo test -p codewhale-workflow --locked rlm_cache_change` | |
| 82 | | Test | `cargo test --workspace --all-features --locked` (ubuntu / macOS / Windows) + lockfile drift guard; offline eval harness on macOS | |
| 83 | | npm wrapper smoke | `cargo build --release --locked -p codewhale-cli -p codewhale-tui` then `node scripts/release/npm-wrapper-smoke.js` | |
| 84 | | Mobile runtime smoke | `./scripts/mobile-smoke.sh` | |
| 85 | | Workflow lint | `actionlint -color -ignore SC2129 -ignore SC2221 -ignore SC2222` (the exact arguments pinned by CI; an unsuppressed local run reports only those documented style/intent warnings) | |
| 86 | | Documentation | `cargo doc --workspace --no-deps` | |
| 87 | |
| 88 | Two standing facts about these gates, both load-bearing: |
| 89 | |
| 90 | - The clippy step runs **without `--all-targets`**, so `cfg(test)` and |
| 91 | integration-test code is never linted. A bare `--all-targets -D warnings` run |
| 92 | surfaces pre-existing errors in test code. Those are not regressions; do not |
| 93 | "fix" them, and do not treat a locally-remembered clippy command as CI's. |
| 94 | - The current `link` (PR↔issue) gate fetches the live PR body. Older campaign |
| 95 | notes describing stale event-payload behavior are historical and must not be |
| 96 | used to diagnose a current failure. |
| 97 | |
| 98 | ### 2026-07-27 final-candidate gate run (content head `462858207` + changelog sync) |
| 99 | |
| 100 | | Gate | Result | |
| 101 | | --- | --- | |
| 102 | | Locale parity | PASS — 13 complete packs at full parity (the seven new packs' merge-reconciliation strings were translated, placeholders machine-validated, native review recorded as pending human evidence); zh-Hant declared partial | |
| 103 | | Provider registry, README translations (8), README locales | PASS | |
| 104 | | Contributor credit (`--check-authors`, 175 commits) | PASS | |
| 105 | | Version drift + changelog sync | PASS after `sync-changelog.sh` (workspace/npm/lockfile 0.9.1 pre-bump) | |
| 106 | | OHOS deps, actionlint (CI's suppressions), all release-helper shell+node contracts | PASS | |
| 107 | | Web | 187/187 tests, ESLint clean, tsc clean, check-locales PASS | |
| 108 | | Full `cargo test --workspace --all-features --locked --no-fail-fast` | **COMPLETED, exit 0: 11,215 passed / 3 failed**, and all three failures were dispositioned before the bump — two were superseded test contracts fixed in follow-up commits (the fleet-help acceptance feature encoding the pre-parity `/fleet status` semantics, now 46/46; the qa_pty interactive-init walk missing the new Appearance step, now 35/35 and the first PTY-level proof of that step's event-loop wiring), and one is an order-sensitive flake (`minimax_requires_an_explicit_saved_billing_mode`) that passes 1/1 in isolation | |
| 109 | | Exact CI clippy (workspace, `--all-features --locked`, five `-A` allows, no `--all-targets`) | **PASS, exit 0** | |
| 110 | | `cargo doc --workspace --no-deps` | PASS, exit 0, 23 non-denied rustdoc warnings open for cleanup | |
| 111 | | Version bump | **`0faa44a74` — workspace/npm/lockfile/changelog band all 0.9.2**, cut via `prepare-release.sh` with `check-versions.sh` agreeing | |
| 112 | | Release build | `cargo build --release --locked -p codewhale-cli -p codewhale-tui` finished in 10m29s; binaries embed `0.9.2 (0faa44a74b74)` | |
| 113 | | Dogfood install | **DONE** — `scripts/release/install-dogfood.sh` succeeded; globally installed `codew`, `codewhale`, and `codewhale-tui` all report `0.9.2 (0faa44a74b74)`; receipt at `backups/dogfood-installs/20260727T130954Z-0faa44a74b74.txt` | |
| 114 | | Hosted-CI repair verification | **PASS locally through `17f6ae848`** — exact CI clippy exited 0; the web prebuild/facts/docs/test/lint/build sequence passed (187/187 tests and production build), and the exact hosted `npx tsc --noEmit` follow-up plus the affected 12-test public-surface file passed; workflow redaction tests passed 15/15; after isolating the MiniMax test's ambient environment, the complete `codewhale-tui` target compiled under `RUSTFLAGS=-Dwarnings` and passed 9,299 / failed 0 / ignored 5, with all 11 MiniMax billing tests also passing together. The Windows-only zero-read race in `concurrent_readers_never_observe_a_truncated_settings_file` now uses an explicit reader-ready handshake and passed five consecutive exact strict runs. Final Claude-review repairs passed the complete Lane crate (60/60), both OpenCode Zen resolver tests (2/2), the exact protocol-change client test (1/1), exact CI clippy, format, and diff checks. Hosted checks remain the landing authority after this head is pushed. | |
| 115 | |
| 116 | Per-merge focused receipts (each taken on the integrated head at merge time, all |
| 117 | zero failures): cost 85→87, route_billing 46→48, pricing 64, receipt 144→157, |
| 118 | scorecard 31, goal 60, localization 30, engine 461, subagent 507, |
| 119 | subagent_routing 18, tool_routing 11, prompt_suggestion 23, model_inventory 17, |
| 120 | model_picker 89, model_routing 34, fleet::exact 37, execution_envelope 11, |
| 121 | workflow (tui) 150 + crate 244+16, lane_control 8, config 458, tui::app 383, |
| 122 | ui::tests 653, sessions 341, sessions_rail 7, sidebar 174, runtime_api 119, |
| 123 | views 157, menu_style 7, focus_texture 12, sound_policy 14, ambient_life 19, |
| 124 | palette 93, widgets 286, onboarding 61, setup 269, remote 48, appearance 7, |
| 125 | skills 193, stepfun 15, provider_picker 105, opencode 16, tool_inspection 8, |
| 126 | request_snapshot 4, markdown_render 53, structcopy 32, safe_label 10, |
| 127 | codewhale-config 469, vitest rail 19 within web 187. |
| 128 | |
| 129 | ### Latest local gate run |
| 130 | |
| 131 | Replace this block whenever the candidate head advances; it describes exactly |
| 132 | one head and is worthless if it is allowed to describe "roughly the candidate". |
| 133 | All Rust runs used `CARGO_BUILD_JOBS=2`, the external |
| 134 | `backups/v092-rebuild-candidate/check-target`, and a task-specific `mktemp` |
| 135 | `CODEWHALE_HOME`; the real `~/.codewhale` was never a test target. |
| 136 | |
| 137 | | Gate | Head | Result | |
| 138 | | --- | --- | --- | |
| 139 | | `cargo fmt --all -- --check` + `git diff --check` | `6f2de8ec0183` | PASS | |
| 140 | | Exact CI clippy (the command above, no `--all-targets`) | `6f2de8ec0183` | PASS, exit 0 | |
| 141 | | `cargo test --workspace --all-features --locked --no-fail-fast` | `6f2de8ec0183` | PASS, exit 0: 11,254 passed / 0 failed / 7 ignored; TUI 9,332/0/5, `qa_pty` 35/0/1, release runtime QA 17/0/1, terminal matrix 19/0/0 | |
| 142 | | Version drift + OHOS dependency contracts | `6f2de8ec0183` | PASS; workspace/npm/lockfile consistently 0.9.2 | |
| 143 | | Release helper shell + Node contracts | `6f2de8ec0183` | PASS: seven shell helpers, workflow contracts, asset assembly 4/4, absent-asset immutability 6/6 | |
| 144 | | Provider registry + README + locale parity | `6f2de8ec0183` | PASS: 8 README translations, no orphaned locale READMEs, 13 complete TUI packs at 1228/1228, zh-Hant declared partial at 499/1228 | |
| 145 | | Contributor credit over `origin/main..HEAD` | `6f2de8ec0183` | PASS for both PR commits | |
| 146 | | Workflow RLM cache command | `6f2de8ec0183` | PASS, exit 0; current filter selects 0 tests in the workflow targets | |
| 147 | | Mobile runtime smoke against exact external binary | `6f2de8ec0183` | PASS, 9/9 after supplying the helper's documented `BINARY` override; an initial invocation set only `CARGO_TARGET_DIR`, so the helper looked for the repo-local default and exited 1 before runtime verification | |
| 148 | | Exact CI workflow lint | `6f2de8ec0183` | PASS with CI's three documented suppressions | |
| 149 | | `cargo doc --workspace --no-deps` | `6f2de8ec0183` | PASS, exit 0, with 18 non-denied rustdoc warnings retained as cleanup work | |
| 150 | | Web source/facts/docs/tests/lint/build | `6f2de8ec0183` | PASS: 223/223 tests, ESLint clean, production build generated 260 static pages; screenshot destinations equal requested source SHA-256 `418b5a590094c76626dab455b82f635222faa78bb22612b1452146f690b3cc77` | |
| 151 | | Release build + npm wrapper smoke | `6f2de8ec0183` | PASS: all three binaries report `0.9.2 (6f2de8ec0183)` and npm wrapper smoke passed against those preassembled exact assets | |
| 152 | | Hosted PR #4953 | merge `8232805572` | PASS: Claude review, CodeQL, GitGuardian, Buildkite, Ubuntu, macOS including offline eval, Windows, web, OHOS, DCO, version drift, npm wrapper, and issue link all green; zero review threads | |
| 153 | | Fresh external release build | merge `8232805572` | PASS: `cargo build --release --locked -p codewhale-cli -p codewhale-tui` completed from the landed runtime candidate in new target `backups/v092-final-release-8232805572.TaAugU`; all three artifacts report `0.9.2 (823280557235)` | |
| 154 | | npm wrapper smoke against final artifacts | merge `8232805572` | PASS against the exact fresh-target binaries; wrapper resolved `codew` as `0.9.2 (823280557235)` | |
| 155 | | Dogfood install + fresh login shell | merge `8232805572` | PASS via `scripts/release/install-dogfood.sh`; clean-source receipt `backups/dogfood-installs/20260728T084840Z-823280557235.txt`; fresh shell resolves all three commands from `~/.local/bin` and reports `0.9.2 (823280557235)`. macOS ad-hoc signing intentionally changes installed-file hashes; the receipt records both source and installed SHA-256 values. | |
| 156 | |
| 157 | ## Scope table |
| 158 | |
| 159 | Status vocabulary: **must-land** (confirmed remaining code), **human-gated** |
| 160 | (no agent can do it), **verify-and-close** (believed implemented; needs a |
| 161 | receipted audit on the landed SHA before the issue is closed), **deferred** |
| 162 | (legitimately out of v0.9.2). |
| 163 | |
| 164 | | Item | Class | Status | Note | |
| 165 | | --- | --- | --- | --- | |
| 166 | | #4411 privacy | must-land | **not done — promoted into v0.9.2** | Explicitly promoted from the catalog lane. New exact Fleets must never inspect or route across credentials/models outside the selected Fleet. | |
| 167 | | #4404 prompt-suggestion privacy | must-land | **landed `eb38100cd`; independently reviewed PASS** | Turn start now mints immutable non-secret authority from the installed client, and suggestions require exact provider, model, canonical chat base route, and key-generation continuity. Injected clients, configured path overrides (including blank suffixes), route/key drift, and absent receipts fail closed. Focused `prompt_suggestion` suite: 23/23; route-authority, injected-client lifecycle, TurnStarted, and URL-redaction filters also passed before integration. | |
| 168 | | #1004 request preview | must-land inspectability slice | **landed `e57554ad9`; independently reviewed PASS** | `/preview-request` now derives its redacted manifest from the same prepared outbound value used for Chat, Anthropic Messages, and Responses dispatch. It reports typed route, role/Lane, requested-to-wire reasoning, stable hashes and canonical sizes while withholding prompt/message/tool content and leaving provider usage unavailable because no request occurs. Current-head focused preview/manifest/Work grounding filters pass 53/53. PR #1099 credit for @GTC2080 is preserved. | |
| 169 | | #4810 todo isolation | must-land | **landed `36fb13ddc`; independently reviewed PASS** | Direct, nested, sibling, and background workers retain distinct private To-do lists. A child publishes only real changes as typed, agent-addressed transient state; only its matching delegate card shows a bounded projection, terminal cards retain the last snapshot, and fanout cards truthfully show none. The parent/sibling/fanout leak boundaries and Pending→Running lifecycle were reviewed. `cargo check -p codewhale-tui --locked` passed; final focused work-grounding, agent-card, routing, mailbox, and child-work-state filters passed 89/89. | |
| 170 | | #4797 | must-land | **independent audit NOT PASS; repair required before integration** | Focused implementation tests passed 669/669, but the release audit found nine blocker groups: official endpoint fail-closed classification; effective-route/currency receipt provenance; per-currency and legacy-zero coverage; reset/load cache telemetry; cumulative and runtime aggregates that still turn unknown into complete zero; dual-mode scorecard surface truth; invalid price rejection; shared-accounting test isolation; and localized subtotal/audited-route copy. Reasoning-token and cache-write separation passed subject to those fixes. | |
| 171 | | #4785 | verify / no-new-growth | **audited PASS at `c46eb2936`** | Independent audit: 469 `allow(dead_code)` occurrences on both `origin/main` (`b49423631`) and the candidate — zero net growth. The single new occurrence is a correctly `cfg_attr(not(test), …)`-scoped receipt field (`core/engine.rs:5418`, read by a test in `engine/preview.rs`); one baseline suppression was genuinely removed (`dependencies.rs` `available()` now has five production call sites). Adjacent lint-escape check flat except one redundant `allow(unused_imports)` on live re-exports (`hooks.rs:27`, cosmetic). No repair items. | |
| 172 | | #4698 | must-land | **landed `9d8cacab7`; independently reviewed PASS** | The shipped bundle now has an authored bijective expectation matrix covering every skill, aliases, invocation tier, ambient eligibility, locale fallback, and prompt-budget invariants. The new `help` skill is explicit-only and never enters ambient context. Provider-free matrix/load/skill filters passed 16/16, 287/287, and 11/11; exact TUI clippy passed. Live-smoke docs are opt-in, use only a task-specific `CODEWHALE_HOME`, restore terminal echo on all interruption paths, never persist credentials, and treat provider responses as unclassified evidence rather than entitlement truth. | |
| 173 | | #4707 | must-land | confirmed open — gap analysis complete at `c46eb2936` | All four provider wire-truths are already proven at the wire (GLM-5.2 `reasoning_effort=high\|max`+thinking, GLM-5-Turbo no invented granularity, direct-K3 `off`→visible `low` + `max_completion_tokens`, MiniMax M3 `max_completion_tokens` + adaptive thinking; exact test names recorded in the audit). The missing matrix work is the JOIN: extend `assert_preview_matches_first_wire_body` (`core/engine/preview.rs:1421`) beyond DeepSeek/Anthropic with zai/minimax/moonshot/kimi-code fixtures; assert per-route manifest size estimates against captured bodies; prove cross-route tool-catalog-hash stability; assert the manifest's requested→effective reasoning triple matches each route's actual body; and pin `provider_reported_usage` unavailable-in-preview/populated-post-turn. Note: the issue as literally filed is a larger ablation-gate epic; the four-route matrix is the release cutline, and the ablation harness remains honestly out of this release. | |
| 174 | | #4909 non-UTF-8 `fetch_url` | must-land community PR | **landed `97e501191`; independently reviewed PASS after repair** | Rebuilt the contribution on the candidate head with BOM-first decoding, recognized transport charset precedence, bounded HTML-only meta sniffing (including legacy `http-equiv` and leading comment/XML declarations), complete-body NUL rejection, and a direct `encoding_rs` dependency. Focused extract 19/19 and fetch URL 12/12 passed; contributor credit and `Harvested from PR #4909` are preserved. | |
| 175 | | #4526 | must-land (audit overturned verify-and-close) | **re-audited NOT closeable at `c46eb2936`** | Registry/routing/catalog/auth/docs criteria PASS with receipts (StepFun Plan URL recognized in `pricing.rs`, OpenCode Go route/models/billing chip all tested). The retained v0.9.2 scope FAILS: no setup-flow billing-route choice exists — `provider_picker.rs`/`onboarding`/`setup` contain zero StepFun/OpenCode strings. Required: a StepFun PAYG-vs-Step-Plan stage mirroring the shipped `Stage::PlanTier`/`KimiCodePlanTier` pattern, skip-guard for pre-existing custom `base_url` (never silently rewrite), endpoint verification before key persistence, `providers.stepfun.base_url`-only persistence, visible subscription-vs-PAYG framing for Go vs Zen, plus tests and doc updates. | |
| 176 | | #3983 / #3984 | must-land | **landed `ed7e83127`; independently reviewed PASS** | One bounded graph-backed To-do tail now grounds each parent turn-loop and sub-agent step request, and the byte-identical body is reused for fork/relay while remaining outside history, compaction rehydration, and the stable prefix. Verified before integration: work-grounding 12/12, work-state 13/13, work-tail 4/4, fork-state 1/1, structured-state 2/2, relay 3/3, preflight 1/1, child-request 1/1, sibling-isolation 1/1; final static review found no overbroad auxiliary-request claims. | |
| 177 | | #3928 constitution / base-prompt provenance | must-land inspectability slice | **landed with request manifest `e57554ad9`; independently reviewed PASS** | Explicit base-prompt preview is exact and base-only, runtime provenance no longer names a source-tree path, and protected effective system hashes remain available without dumping the full composed request. | |
| 178 | | #4039 Workflow row truth | must-land narrow slice | **landed `bc3e1f097`; independently reviewed PASS** | Workflow spawn now captures exact role, provider, model, requested→effective reasoning, and closed routing source and preserves that receipt through the JSONL journal, live panel, and history card. Missing usage remains unknown through task, run, and shared Workflow IR while genuine provider-reported zero survives; direct agent cards do not invent Workflow receipts. Verified: shared Workflow 111/111, panel 32/32, real spawn/journal 1/1, unknown-versus-zero 1/1. | |
| 179 | | #3897 | must-land | **cherry-picked `89b73bdd1`; compile/test receipt pending** | The persistent rendered-prefix cache landed via cherry-pick of `f2358387c` from the md-incremental lane: `IncrementalMarkdownRenderCache` with resumable syntect highlighter state, `StreamingSourceReceipt` verified-append provenance (no quadratic byte compare), deterministic `MarkdownRenderWork` counters in production state, and differential exactness + linearity + invalidation tests. Known honest bound: the tail path still clones tail blocks, so unbounded open tables/paragraph tails are linear-in-common-case, not hard-bounded — the lane's uncommitted plain-tail/table follow-up does NOT compile (missing `IncrementalTableState.blocks` field) and was deliberately left out. Focused suite receipt on the candidate is still required before this row is PASS. | |
| 180 | | #2342 | deferred product decision | not started | Click-to-preview needs a defined action and is not allowed to grow a decorative affordance without backend behavior. | |
| 181 | | #998 | deferred product decision | not started | `hover_layer.rs` exists but remains unwired; do not surface it until its interaction contract is settled. | |
| 182 | | #4906 | post-candidate media | **human-gated; harness landed** | PR #4940 landed the executable capture harness. Record and accept one real provider/local-Ollama dogfood session for the site + README GIF; this is the only open v0.9.2 milestone issue and does not reopen runtime correctness. | |
| 183 | | #4907 web CI | must-land | **candidate commit `990489c9b`; combined-candidate re-verified at `c46eb2936`** | Push/PR still validate; deploy is manual-dispatch-only at the exact SHA. Combined-candidate receipts: web suite 143/143 (21 files), ESLint clean, `tsc --noEmit` clean. | |
| 184 | | #4904 mention review follow-ups | must-land | **candidate commits `9dd481072`, `9df3218fa`** | Preserved original authorship; PR checks were green before local integration. Re-verify on the combined candidate. | |
| 185 | | #4808 visual-language baseline | must-land slice | **landed `2fe849f1d`; independently reviewed PASS after repair** | Pickers, Fleet/skills rows, hotbar, and workflow surfaces now share one selection marker/background vocabulary and compact action hints. The review blocked two false verbs (`cancel` where Esc only closes, `select` where feedback opens a browser); both were repaired before landing. Full release runtime QA passed 9/9 (1 ignored), exact CI clippy passed, and the four repaired blocker-size/selection tests passed 4/4. This is a baseline slice only: the remaining visual-program rows below stay active. | |
| 186 | | Saved Fleets + reasoning Router | must-land (live product decision) | first pass blocked; adversarial repair in progress | A Router is a reusable optional profile, not a Fleet worker. It has two phase-separated jobs: during Fleet setup it may inspect only the user's explicit configured model pool and propose provider/model assignments for roles, which take effect only after human review and save; during a Workflow it may choose only reasoning for the frozen exact member route, never provider/model/role/tools/permissions. One Router may be reused by many saved Fleets. Exact Fleet capture and run-scoped dispatch are wired, but review blocked integration until gates and worker preflight precede Router spend, child ceilings are enforced, durable receipts contain no task text/path/secret, and they show exact Router identity plus requested→effective Router and worker reasoning. Strict parsing rejects trailing content; exact Auto always uses Router; snapshots omit absolute paths; collisions/capability fallbacks/ceilings fail closed. No hidden DeepSeek Flash default, runtime model switching, or heuristic fallback is allowed inside an exact Fleet. | |
| 187 | | Workflow vocabulary | must-land compatibility preservation | **landed `55207ea78`; independently reviewed PASS** | Workflow remains the current public and technical execution unit: Fleet = who, Workflow = what order, Lane = one running Workflow, Runtime = where/how. Configuration rows now state their scope in every shipped locale. No `/operation` or `codewhale operation` was added; Operation remains reserved for a future continuous objective coordinating multiple Fleets and Workflows. Focused configuration-section, legacy-fallback, and locale-filter tests passed 3/3; exact TUI clippy passed. | |
| 188 | | Agent route labels | must-land | **Workflow slice landed `bc3e1f097`; Router identity still pending** | Every Workflow worker now visibly and durably retains role, exact provider/model, requested→effective reasoning, and routed-by source from launch onward. Router-selected launches must still identify the exact Router provider/model once the saved-Fleet Router slice lands; provider controls such as GLM thinking enabled/disabled remain a separate provider-truth item. | |
| 189 | | Consultant Fleet role | must-land compatibility slice | **landed through `a3cdaf751`; independently reviewed PASS** | `consultant` is the only public/canonical advisory role; `oracle` and `advisor` survive only at parse, replay, and config-compatibility boundaries and repersist canonically. Consultant defaults to high reasoning unless explicit Auto/Effort wins, remains read-only/no-shell/network-off, and production headless execution enforces the network cap by disabling WebSearch and installing deny-all tool network policy. Canonical model overrides win alias collisions; exact provider/model routes remain explicit and unresolved evidence stays unresolved. Integrated focused filters pass 16/16 Consultant and 6/6 tool authority. | |
| 190 | | #4751 Fleet settings information architecture | must-land narrow slice | **landed `55207ea78`; independently reviewed PASS** | Configuration now labels the saved DeepSeek fallback as a legacy off-route setting and keeps Fleet/member/Router, Workflow, Lane, Runtime, and session settings in truthful sections. The broader historical request to bury Fleets under Models remains superseded by the first-class Fleet shelf. | |
| 191 | | Paste — real-PTY trace | must-land (unlabeled report) | **candidate commits `a77d2e5cd`, `a62e6a72c`, `e4a892fb7`** | Modified Enter no longer enters bare-Enter paste suppression; guessed trailing newlines cannot re-arm suppression indefinitely; lone CJK IME commits use the short window. Focused unit groups 10/10, 11/11, 55/55 and both real PTY regressions passed. The combined 8,373-test TUI run exposed one superseded bare-Enter-steers assertion; its corrected queue contract passes. Full rerun remains required after all lanes integrate. | |
| 192 | | Mode / effort persistence | must-land (unlabeled report) | **landed `feef1846e`; independently reviewed PASS** | Mode, reasoning, model, provider, and permission aliases share one busy-turn lock; same-live selections persist the startup default with a truthful receipt. Whole-file settings changes use a process mutex plus adjacent cross-process lock and atomic replacement; legacy migration is locked and no-clobber. Shutdown drains queued writes and surfaces late failures. `cargo check -p codewhale-tui --locked` is warning-free; settings 79/79 (1 helper ignored), startup-default 18/18, live-route 4/4, preset 2/2, approval alias 1/1, selection/hotbar/reasoning/localization/config focused filters all passed. | |
| 193 | | Hooks runtime + documentation | must-land (unlabeled report) | **landed `5e3d84307`; independently reviewed PASS** | The TUI hook lifecycle now has bounded background supervision, timeout/tree termination and reaping, stable session identity across rebind, real exit-code conditions, `on_error` coverage for tool failures including ignored completions, bounded nonblocking background `message_submit` stdin, actual local/external `shell_env` behavior, and truthful TUI-only documentation including side effects. Focused audit passed hooks 142/142, message-submit 29/29, exit-code 1/1, and ignored-completion failure-hook 1/1. Windows Job Object runtime and physical-terminal behavior remain UNRUN. | |
| 194 | | Provider verification 401 (Kimi / MiniMax) | must-land (unlabeled report) | Kimi defect confirmed; MiniMax theory corrected | Fresh Kimi setup verifies before Platform vs Kimi Code product selection, so a membership key can be probed against `api.moonshot.ai` and 401. Require product before key and test both routes provider-free. Current MiniMax `/models` paths and auth headers match official contracts; GroupId is not required. Retain that report as a key/product/entitlement incident and add mock path/header/200/401 tests rather than a live gate. | |
| 195 | | Provider request truth | must-land (benchmark prerequisite) | confirmed gaps | GLM-5.2 must emit documented `reasoning_effort=high|max` in addition to thinking control, while GLM-5-Turbo must not receive invented granularity. MiniMax M3 must use `max_completion_tokens`. Kimi fixed-K3 `off` must fail or visibly normalize to `low`; Kimi membership catalog and subscription billing are stale. | |
| 196 | | Context / tool-surface accounting | must-land (benchmark prerequisite) | confirmed gap | Active pressure and compaction omit serialized tool schemas even though the source map knows them; Standard and Full are currently behaviorally identical. Use one estimator with per-class byte/token estimates and stable tool hash, and either make the labels measurably distinct or collapse them. | |
| 197 | | Notification app icon (#4847) | human-gated | **not fixed** | `display notification` runs through unbundled `/usr/bin/osascript`, so macOS attributes the banner to Script Editor. Requires a real signed `.app` bundle → signing/notarization, which is Hunter-gated. The separate OSC control-byte leak is fixed (#4905). | |
| 198 | | Version bump + changelog band | release preparation | **done at `0faa44a74`** | Workspace, npm wrapper, lockfile, and changelog band are consistently `0.9.2`. | |
| 199 | | Tag, GitHub Release, publication | human-gated | pending | | |
| 200 | | Dogfood install of the release SHA | required local gate | **done** | Installed final runtime candidate `823280557235`; all three fresh-shell binaries report `0.9.2 (823280557235)`. Clean-source receipt: `backups/dogfood-installs/20260728T084840Z-823280557235.txt`; prior candidate installs are superseded. | |
| 201 | | Web deploy / CWC #123 | human-gated | **pending; code merged, deploy not run** | PR #4944 landed the CWC-aligned public design. Production remains unchanged until explicit deployment approval. | |
| 202 | | Live-provider entitlement test (K3) | human-gated | pending | | |
| 203 | | Manual multi-terminal QA (#3758) | split gate | **automated slice landed `14960d2c9`; physical-terminal matrix human-gated** | Provider-free terminal/key/modal matrix passed 19/19; release runtime QA passed 17/17 with one explicit 32-worker stress ignore; shortcut audit passed 15/15. Cell-by-cell record: `docs/releases/v0.9.2-terminal-matrix.md`; target `crates/tui/tests/terminal_matrix_qa.rs` plus harness additions (`modes.rs` control-stream ledger, `view_log.rs` view-stack trace reader). The matrix covers sizes, `TERM`/`COLORTERM` capability tiers, Unicode/ASCII fallback, bracketed/raw/multiline/CJK paste and IME-style commits, mouse/resize/focus, provider-free modal open/Esc lifecycle, terminal-mode restoration on every exit path, and exactly-once ordered queued follow-ups. Literal iTerm2, Terminal.app, WezTerm, SSH, tmux, ConPTY, listening, and visual observations remain `UNRUN`; provider-dependent modals remain a named automation gap. | |
| 204 | | #4067 `@git`/`@diff` mentions | verify-and-close | closed by #4899 | Re-verify on the release SHA before the release notes claim it. | |
| 205 | | #3947 policy-narrowing events | verify-and-close | closed by #4900 | | |
| 206 | | #3874 background shell completion | verify-and-close | closed by #4894 + #4901 | Exactly-once and heartbeat carve-out each have a named test. | |
| 207 | | #3738 prompt-cache regression | verify-and-close | closed by #4902 | Whole-serialized-message test pins it. | |
| 208 | | #4089, #4812, #4867, #4717, #4763, #4405, #4811, #4834 | verify-and-close | closed by audit with receipts | Each was audited against the then-current `origin/main`; re-confirm against the release SHA. | |
| 209 | | #2494 macOS/iTerm2 report | verify-and-close | **item 7 landed and verified at `4ac0c6ea7`** | Exported Markdown now lists the workspace side-git restore points without creating a repository on read, labels the index as time-sensitive, retains stable snapshot ids, and correlates user prompts through the same bounded snippet producer used by snapshot labels. Missing, unreadable, empty, unmatched, and ambiguous evidence remain distinct rather than guessed. Combined-candidate receipts: export 17/17, snapshot labels 6/6, format and diff checks clean. | |
| 210 | | Wave A/B/C visual + supervision programs (13) | must-land | active implementation/audit | Existing visual-wave worktrees contain candidate implementations. Each issue needs a testable v0.9.2 slice plus review; no item may be deferred merely because it began as a design program. | |
| 211 | | Localization + website locales (9) | must-land + human language review | active implementation/audit | Existing localization lanes cover the requested locales and website surfaces. Deterministic parity/layout/script gates must land; any remaining native-speaker sign-off is recorded separately as human evidence, not used to discard the implementation. | |
| 212 | | Onboarding / constitution / slash-command product design (16) | must-land | active implementation/audit | Maintainer judgment supplies the product decisions for this release. Existing setup and command lanes are candidate work, not reasons to defer. | |
| 213 | | Multi-surface epics (control plane, monitor UX, workflow driver, plugin registry) (11) | must-land | active implementation/audit | Land coherent bounded implementations with truthful unavailable states where an external service is absent; size alone is not a deferral criterion. | |
| 214 | | Manual QA / `needs-human` (2) | split gate | automate everything possible; physical/manual rows remain human-gated | Human-only evidence cannot be fabricated, but its automatable harness and documentation still gate v0.9.2. | |
| 215 | |
| 216 | ## The 51 moved issues |
| 217 | |
| 218 | Fifty-one issues were moved off the v0.9.2 milestone with a per-issue comment. |
| 219 | Hunter explicitly put all of them back on the release audit table. Their live |
| 220 | tracker state remains: |
| 221 | |
| 222 | - **milestone:** v0.9.3 |
| 223 | - **label:** every one of them has the `v0.9.2` label. Sixteen missing labels |
| 224 | were restored during this campaign. Do not strip them merely to match the |
| 225 | milestone; each item must receive a maintainer disposition and receipt. |
| 226 | |
| 227 | Measured against the live tracker at 2026-07-26 21:30 PDT, so the release is |
| 228 | never sized from this document's own prose: **109** issues carry the `v0.9.2` |
| 229 | label — 37 CLOSED and 72 OPEN, of which 57 sit on the v0.9.3 milestone, 4 on |
| 230 | v0.9.2, and 11 on no milestone. Of the full v0.9.2 scope Hunter restored, |
| 231 | **54 are OPEN and none are CLOSED**. Eight scoped items carry no `v0.9.2` |
| 232 | label at all and so are invisible to a label query — #4797, #3897, #4785, |
| 233 | #2494, #2342, #998, #4906, #4847 — which is exactly why the scope table above, |
| 234 | not a tracker query, is the release disposition. Two of those eight need their |
| 235 | tracker state stated plainly rather than inferred: **#2494 is CLOSED on GitHub |
| 236 | while its item 7 remains genuinely unimplemented**, and **#4847 carries no |
| 237 | milestone**. |
| 238 | |
| 239 | Exact issue set: |
| 240 | |
| 241 | `#1004`, `#1888`, `#1891`, `#2026`, `#2033`, `#2934`, `#2974`, `#3091`, |
| 242 | `#3092`, `#3093`, `#3409`, `#3413`, `#3758`, `#3792`, `#3793`, `#3832`, |
| 243 | `#3927`, `#3928`, `#3930`, `#3937`, `#3996`, `#4022`, `#4039`, `#4227`, |
| 244 | `#4397`, `#4398`, `#4400`, `#4404`, `#4411`, `#4749`, `#4751`, `#4754`, |
| 245 | `#4782`, `#4788`, `#4789`, `#4790`, `#4791`, `#4807`, `#4808`, `#4810`, |
| 246 | `#4813`, `#4814`, `#4815`, `#4816`, `#4817`, `#4819`, `#4820`, `#4821`, |
| 247 | `#4822`, `#4823`, `#4836`. |
| 248 | |
| 249 | | Category | Count | |
| 250 | | --- | --- | |
| 251 | | Wave A/B/C visual + supervision programs | 13 | |
| 252 | | Localization + website locales | 9 | |
| 253 | | Onboarding / constitution / slash-command product design | 16 | |
| 254 | | Multi-surface epics | 11 | |
| 255 | | Manual QA / `needs-human` | 2 | |
| 256 | | **Total** | **51** | |
| 257 | |
| 258 | The earlier maintainer re-audit reduced this list to seven code gaps and called |
| 259 | 43 items deferred or human/design-gated. **That disposition is superseded.** On |
| 260 | 2026-07-26 Hunter clarified that all 51 moved items are v0.9.2 completion work. |
| 261 | Every technically actionable item below therefore remains active until it is |
| 262 | implemented and verified. Only evidence that literally requires a person or |
| 263 | physical environment (native-language approval, listening/visual sign-off, |
| 264 | real-terminal rows) may remain human-gated, and its automatable slice must still |
| 265 | land. The large existing completion worktrees are candidate implementations to |
| 266 | audit and harvest; they are not proof by themselves. |
| 267 | |
| 268 | | Issue | v0.9.2 disposition | Exact cutline | |
| 269 | | --- | --- | --- | |
| 270 | | #1004 | **must-land · request-manifest lane** | Redacted, actual-builder request manifest; full raw-body mode may remain optional. | |
| 271 | | #1888 | **active · command-parity lane** | Complete the cross-command control-plane surface with truthful hooks/persistence receipts and consistent command semantics. | |
| 272 | | #1891 | **landed `21ce3a46d`; independently reviewed PASS** | `/tools [text|json]` and the `/tool-studio` compatibility alias inspect a bounded projection of the latest prepared internal request tool field in a pager, never transcript history. Present-empty and absent remain distinct; hashes/bytes and truncation are bounded. Provider delivery, provider wire body, provider/model, approval, provenance, and capabilities stay explicitly unknown/unavailable because this slice cannot observe them. Current-head focused projection, command, and request-snapshot filters pass 3/3 each; physical-terminal, native-language, and visual observations remain UNRUN. | |
| 273 | | #2026 | **active · Fleet lane; reinterpretation required** | Replace obsolete whale-size aliases with clear, exact Fleet/reasoning labels that fulfill the discoverability intent without hiding model identity. | |
| 274 | | #2033 | **landed human-only slice `c5751fbe7`; independently reviewed PASS** | `/structcopy` provides bounded, deterministic plan/turn/tool/Workflow projections with pre-serialization secret/path/URL scrubbing, exact omission receipts, explicit clipboard/stdout delivery, and no model-visible tool-catalog cost because it is excluded from the model catalog. Focused tests pass 32/32; any model-callable structural-copy tool remains outside this human-only slice. | |
| 275 | | #2934 | **active · session-control lane** | Finish the persistent multi-session sidebar, auto-resume, and history browsing with truthful backend state. | |
| 276 | | #2974 | **satisfied on main** | `82bcb0aa5`: bounded Workflow journal events and task/run usage telemetry with compatibility tests. | |
| 277 | | #3091 | **active · localization lane + human language review** | Land Japanese/Vietnamese website parity and deterministic route/layout checks; record native-language review separately. | |
| 278 | | #3092 | **active · localization lane + human language review** | Land Russian README/site/TUI coverage and Cyrillic shaping checks; record native-language review separately. | |
| 279 | | #3093 | **active · localization lane + human language review** | Land Korean/Spanish/Portuguese website coverage and deterministic layout/parity checks; record native-language review separately. | |
| 280 | | #3409 | **active · onboarding lane** | Complete remote/mobile/chat-bridge/runtime onboarding with truthful unavailable states for unconfigured services. | |
| 281 | | #3413 | **active · web-maturity lane** | Complete the website maturity and information-architecture slice, including the real-session media surface once dogfood is stable. | |
| 282 | | #3758 | **automated slice landed `14960d2c9`; split human gate** | The PTY/key/modal matrix and running-turn queue contract are green. Only literal physical-terminal observations remain `UNRUN`, plus the documented provider-dependent modal automation gap. | |
| 283 | | #3792 | **active · onboarding lane** | Finish conversational first-run onboarding with a concrete, tested maintainer-selected flow. | |
| 284 | | #3793 | **active · constitution-review lane** | Finish guided constitution authoring, revision, persistence, and localization using the maintainer-selected interaction contract. | |
| 285 | | #3832 | **active · constitution-review lane; reinterpretation required** | Fulfill bounded review-repair automation without inventing a fourth Mode; keep Mode, permission posture, Workflow, and Router responsibilities separate. | |
| 286 | | #3927 | **active · onboarding lane** | Add an explicit provider-independent offline first-run path and verify it without credentials or network. | |
| 287 | | #3928 | **must-land · request-manifest + constitution-review lanes** | Exact effective base-prompt preview plus truthful bundled/config/embedder provenance. | |
| 288 | | #3930 | **active · constitution-review lane** | Implement the recommendation/ratification flow with explicit revision and acceptance states. | |
| 289 | | #3937 | **active · onboarding lane** | Complete appearance onboarding and contextual teaching without obscuring current state. | |
| 290 | | #3996 | **active · durable-controls lane** | Implement internal URI/GitHub Actions read surfaces with explicit trust boundaries and measured tool-catalog growth. | |
| 291 | | #4022 | **active · command-parity lane** | Complete CLI/TUI Fleet and runtime control parity with shared receipts and compatibility tests. | |
| 292 | | #4039 | **must-land · workflow-live lane; narrow slice** | Workflow rows consume exact route/reasoning plus completed tokens/tools/duration; shelf/paging/grouping defer. | |
| 293 | | #4227 | **active · onboarding lane** | Deliver a welcoming, grounded project-map/tutorial surface with maintainer-selected naming and no fabricated capability. | |
| 294 | | #4397 | **active · session-control lane** | Complete the multi-session dashboard and approval control plane against real runtime state. | |
| 295 | | #4398 | **active · durable-controls lane** | Complete durable monitor subscriptions, `/loop`, restart, and truthful notifications. | |
| 296 | | #4400 | **active · durable-controls lane** | Complete agent hunk attribution and selective rewind with conflict detection, preview, and recovery evidence. | |
| 297 | | #4404 | **must-land** | Fail-closed, exact-route prompt suggestions; no cross-provider credential inspection or context transfer. | |
| 298 | | #4411 | **must-land · Fleet lane** | Exact Fleet scopes runnable inventory and credentials; no provider/model inspection outside the selected Fleet. | |
| 299 | | #4749 | **active · localization lane + human language review** | Land Catalan and the scoped Galician/Basque assessment with deterministic locale checks; record language review separately. | |
| 300 | | #4751 | **must-land narrow slice** | Remove stale DeepSeek fallback row and keep Fleet settings limited to Fleet/member/Router concerns. | |
| 301 | | #4754 | **active · workflow-live lane** | Complete Workflow live monitoring, chat-side authoring, and goal staging. Workflow remains the current execution noun; Operation stays reserved for a future continuous multi-Fleet/multi-Workflow layer. | |
| 302 | | #4782 | **active · constitution-review lane** | Complete Constitution v2 with byte-stable prompt/cache evidence, migration, preview, and ratification tests. | |
| 303 | | #4788 | **active · localization lane + human language review** | Land French/German/Catalan TUI/README/site coverage and deterministic layout/parity checks. | |
| 304 | | #4789 | **active · localization lane + human language review** | Land Indonesian localization and deterministic fallback/parity checks. | |
| 305 | | #4790 | **active · localization + terminal-matrix lanes; physical shaping review** | Land Hindi localization and automated Devanagari width/grapheme/PTY coverage; record physical terminal/browser observations separately. | |
| 306 | | #4791 | **active · localization lane + human language review** | Land Ukrainian localization and Cyrillic shaping/parity checks. | |
| 307 | | #4807 | **active · visual-supervision lane** | Complete the ambient jellyfish silhouette and verify narrow-terminal/performance behavior. | |
| 308 | | #4808 | **partial landed + active · visual-supervision lane** | Complete the v0.9.2 visual-language slice with measurable hierarchy, accessibility, and render-cost gates. | |
| 309 | | #4810 | **must-land / partial candidate** | Isolation core is `571f8b751`; bounded child-To-do projection under delegate rows remains. | |
| 310 | | #4813 | **active · visual-supervision lane** | Land cross-theme luminance/accessibility semantics with palette assertions and non-color labels. | |
| 311 | | #4814 | **active · agent-telemetry lane** | Land stable agent identity hues alongside exact text provenance labels and collision/accessibility tests. | |
| 312 | | #4815 | **active · agent-telemetry lane** | Land a shared recoverable/fatal/retried/blocked/resumable vocabulary across runtime surfaces. | |
| 313 | | #4816 | **active · agent-telemetry lane** | Land read/change persistence marks with bounded storage and render-performance evidence. | |
| 314 | | #4817 | **active · visual-supervision lane + human listening sign-off** | Land the opt-in sound/event contract, platform-safe fallback, and deterministic tests; record pleasantness/listening approval separately. | |
| 315 | | #4819 | **active · agent-telemetry lane** | Land bounded deviation-aware salience and time gutters with explicit baselines and deterministic policy tests. | |
| 316 | | #4820 | **active · agent-telemetry lane** | Land low-cost context/token/activity meters with motion-off and render-budget gates. | |
| 317 | | #4821 | **active · agent-telemetry lane** | Land stable agent anchoring, swimlanes, and live write-scope topology from real coordination state. | |
| 318 | | #4822 | **active · agent-telemetry lane** | Land per-delegate re-entry recap from durable unread/attention/monitor state. | |
| 319 | | #4823 | **active · visual-supervision lane + visual sign-off** | Land a bounded, toggleable texture/focus-context prototype with fallback and performance evidence; record subjective approval separately. | |
| 320 | | #4836 | **active · durable-controls lane** | Land a starter plugin pack and reviewed install registry with provenance, trust, offline/error states, and measured tool-surface impact. | |
| 321 | |
| 322 | This table, not the milestone move, is the release disposition. Every active row |
| 323 | needs a landed-SHA receipt. Human-only evidence is named explicitly and cannot |
| 324 | be fabricated, but it does not convert the corresponding technical work into a |
| 325 | deferral. |
| 326 | |
| 327 | ## Parallel lane reconciliation |
| 328 | |
| 329 | The scope table's "active implementation/audit" rows are being worked in |
| 330 | per-topic worktrees under `/Volumes/VIXinSSD/CW/worktrees/codewhale-v092-*`. |
| 331 | Two facts about them govern how they must be handled, and both are easy to get |
| 332 | wrong from a handoff document alone: |
| 333 | |
| 334 | - **Nearly all of that work is uncommitted.** It lives as dirty working trees, |
| 335 | not as branch commits, so it is invisible to `git log` and is destroyed by any |
| 336 | `reset`, `clean`, `checkout`, or `worktree remove --force`. Roughly 55,000 |
| 337 | patch lines and ~100 untracked files across 20 lanes were in this state at the |
| 338 | 2026-07-26 21:25 PDT reconciliation. A read-only archive of every dirty lane |
| 339 | (per-lane `HEAD`, `status`, `git diff HEAD` patch, and verbatim untracked |
| 340 | copies) is at `backups/v092-lane-archive-20260726-2125/`. Re-take it before |
| 341 | any operation that could discard a lane. |
| 342 | - **Lanes drift from the candidate.** Several sit on bases many commits behind |
| 343 | the candidate head. Per `AGENTS.md`, a far-behind lane is recovered as intent |
| 344 | and re-implemented against the current head; it is not merged wholesale. |
| 345 | |
| 346 | A lane being dirty is not evidence it is finished. Each still needs an |
| 347 | independent PASS audit and its own gate receipts before any of it is integrated, |
| 348 | and no scope-table row may be marked landed on the strength of a worktree diff. |
| 349 | |
| 350 | ### Lane audit verdicts (2026-07-27, read-only, against candidate `1d3d81591`) |
| 351 | |
| 352 | All audited lanes have **zero unique commits** — every lane's value is its |
| 353 | dirty tree, re-archived at `backups/v092-lane-archive-20260727-0212/`. Lane |
| 354 | worktrees were not committed on (that action is approval-gated); harvests land |
| 355 | on the candidate. |
| 356 | |
| 357 | | Lane | Verdict | Key facts | |
| 358 | | --- | --- | --- | |
| 359 | | fleet-operation (Router) | **HARVEST, staged leaf-first** | The dirty tree is a rewritten design that addresses nearly every review blocker in code (two-phase admission with the cost boundary before Router spend, fingerprint-verified child ceilings, strict parser refusing trailing/duplicate/mutation content, exact-Auto-always-Router, path-free hash-verified snapshots, no implicit Flash default, oracle/advisor→consultant aliases, raw-shell deny by ceiling). ~15k uncompiled lines, 172 tests. Gaps: `fleet_composition.rs` (setup-time proposal→ratify UI) is an unwired schema; internal enum variant still named `Oracle` (cosmetic). | |
| 360 | | command-parity (#1888/#4022) | **HARVEST — land its `main.rs` extraction before session-control** | 3,250-line control-plane contract; `/lane interrupt` is new, real, and nonblocking (sync validation, off-loop named-thread teardown, "queued is never success", bounded queue, fence checked under the mutation lock). `lane restart`/`resume` declared `NotImplemented` and gated honestly. ~169 tests. | |
| 361 | | session-control (#2934/#4397) | **HARVEST Rust; JS rail needs vitest before closing #4397** | Auto-resume decision layer with double workspace re-check, bounded redacted peek with no invented turn-status, typed session-vs-thread targets failing closed on stale-target/stale-approval with user-visible refusals. The truth-critical `app.mjs` rail has zero automated tests. | |
| 362 | | localization (9 issues) | **HARVEST ALL, gated on compile + 1153→1177 key reconciliation** | 14 packs at in-lane parity (its `en.json` is 1153 keys; candidate is 1177 — harvested packs must gain the missing keys). New ru/uk/hi/ca/fr/de/id packs with machine-checked script purity; RU/UK READMEs; 8 website dictionaries + new `check-locales.mjs` CI gate; grapheme-cluster `truncate_to_width` rewrite (highest-risk/highest-value, benefits all locales); gl/eu deferral is a real written assessment. #4788/#4789 are TUI-only (no fr/de/ca/id READMEs or site pages) — do not close on merge. #4790 keeps its human terminal-QA half open. | |
| 363 | | visual-supervision | **HARVEST #4813, #4823, #4817, #4807, #4808-slice; 7 issues honestly not-started** | Substantive+tested: theme contrast audit (#4813), default-off provably-static focus texture (#4823), off-by-default BEL-only sound policy (#4817, needs test-env lock guard), jellyfish + frame budget (#4807 — ambient idle-ocean decoration is sanctioned by the issue itself; the no-decoration-animation rail governs status indication, and the reduced-motion path is static), unlabeled `menu_style` selection-vocabulary slice (#4808). Not started: #4814, #4815 (hook only), #4816, #4819, #4820, #4821, #4822. | |
| 364 | | onboarding (#3409/#3792/#3927/#3937/#4227) | **HARVEST #3409 + #3927; SPLIT #3937; re-label #4227; #3792 honestly not-started** | #3409 remote-mode matrix with exemplary secret/truthfulness tests; #3927 offline explore path complete. #3937 Appearance step is wired, but the new tip taxonomy has zero call sites and would fail CI clippy dead-code — wire or drop. #4227 delivered as a contributor-sync skill, not a project-map surface. #3792 as scoped (conversational onboarding) is not-started; the resume-at-first-unsettled-step helper is a separate harvestable slice. High `ui.rs` rebase risk. | |
| 365 | | web-maturity (#3413) | **HARVEST (web-only)** | New /docs/guide + /docs/vocabulary routes, homepage getting-started, media manifest landing in explicit `pending` state (no placeholder footage), 35+ web tests. Genuinely unlanded. The media plan doc authorizes nothing. | |
| 366 | | durable-controls (#3996/#4398/#4400/#4836) | **HARVEST code as foundation; CHANGELOG must be rewritten** | ~4,600-line `crates/tui/src/durable/` tree with 128 tests, cleanly one-module-per-issue — but zero consumers beyond `mod durable;`. Its CHANGELOG block claims shipped behavior that is not reachable and must not land as written. Harvesting does not close any of the four issues. | |
| 367 | | agent-telemetry (#4814–#4822 slices) | **HARVEST; only #4815 (+partial #4814) are user-reachable** | ~3,800-line `supervision/` tree, 65 tests; `agent_details.rs` consumes status vocabulary + route provenance. #4816/#4819/#4820/#4821/#4822 slices exist as tested library code without consumers. | |
| 368 | | workflow-live (#4754) | **already-landed-discard** | Its one commit is patch-identical to `ac4c38f8a` on the candidate; the dirty file is authoring scaffolding. Honest scope note: only the route-receipts slice of #4754 ever existed — live monitoring/authoring/goal staging remain not-started. | |
| 369 | | terminal-matrix (#3758) | **already-landed-discard; ledger row enriched** | Its commit is patch-identical to `14960d2c9`; the one-line ledger improvement was merged into the row above. | |
| 370 | | request-manifest | **SUPERSEDED — archived, nothing unique** | Twin landed at `e57554ad9` as a byte-identical superset of all 7 new files; residue is changelog prose and whitespace drift. | |
| 371 | | mode-hooks | **SUPERSEDED except one ~10-line hunk (being harvested)** | Hooks/persistence twins `5e3d84307`/`feef1846e` contain everything (docs/HOOKS.md byte-identical). Unique: the `take_shortcut_queued_message` queued-draft dispatch branch + its steering test. | |
| 372 | | provider-truth | **UNIQUE VALUE — being harvested (truth-critical)** | Candidate already has the reasoning-control work under newer names; 8 unharvested clusters remain, including immutable dispatched-receipt billing, the Moonshot direct-platform vs kimi-code product split (candidate currently lumps Moonshot into one flat quota label), MiniMax Token Plan credential-product billing (absent entirely), child billing provenance, Option-al output ceilings (killing a silent 4096 clamp), and per-provider base-URL isolation. | |
| 373 | | auto-scope (#4411) | **UNIQUE VALUE, 100% unharvested — being harvested** | No twin ever landed (prior ledger assumption wrong). Today's candidate will silently route an Auto turn to a provider the user did not select; the lane adds active-provider default scope, persisted `[auto] cross_provider` opt-in, classifier-prompt scope declaration, fail-closed refusal of out-of-scope recommendations, and truthful ActiveProvider receipts. | |
| 374 | | tool-inspectability | **UNIQUE VALUE — being harvested** | The landed #1891 slice declares provenance unavailable; the lane derives real registry provenance (builtin/MCP/synthetic), MCP server attribution with a single-definition invariant, per-step snapshot identity, and a provider receipt following the resolved client. Harvest extends the landed design and must share the request manifest's catalog digest. | |
| 375 | | constitution-review (#3930/#4782/#3832/+#3928 slice) | **HARVEST; land before the onboarding lane (lower conflict surface)** | #3930 suggestions/ratification fail closed and are structurally excluded from law/render/cache digest; #4782 receipted schema migration with byte-identical rejection and rollback; #3928 exact-bytes base-prompt preview from the same composition path as dispatch. #3832's `review_repair.rs` is finished, tested infrastructure with zero consumers — harvest as infrastructure, do not describe as user-reachable. ~49 tests, low compile risk. | |
| 376 | |
| 377 | ## Open PR reconciliation |
| 378 | |
| 379 | - **#4908** — @SparkofSpike's zh-Hans translation quality pass. Harvested |
| 380 | locally as merge `1d3d81591` with `Co-authored-by: Sh1Zuku` and |
| 381 | `Harvested from PR #4908`. Seven conflict hunks were resolved to the |
| 382 | candidate's deliberate terminology decision (`ed8bdf395`): 协作准则 and |
| 383 | 运行姿态 retained, public Fleet vocabulary in English; the PR's UTF-8 BOM |
| 384 | additions and its localization/setup test flips encoding 宪法 were not |
| 385 | taken. 44 non-conflicting translation refinements survive. Locale parity |
| 386 | and JSON validity re-verified after resolution. Merging the hosted PR |
| 387 | remains a separate maintainer action. |
| 388 | - **#4904** — follow-ups to #4899's review (`@git`/`@diff` composer mentions). |
| 389 | Integrated locally with original authorship as `9dd481072` + `9df3218fa`; |
| 390 | re-run combined-candidate gates before calling it landed. |
| 391 | - **#4467** — @snail-vs's OpenCode Zen provider. The complete contributor |
| 392 | history was harvested locally in merge `228690751`; review follow-up |
| 393 | `4a836689f` takes the shared environment lock so sibling provider tests cannot |
| 394 | leak `CODEWHALE_PROVIDER`. @snail-vs then pushed the same repair as |
| 395 | contributor-authored `fbbedbe1`; merge `50989a4d0` reconciles that updated PR |
| 396 | head into the candidate ancestry without changing the resulting source. The |
| 397 | live PR later exposed a real web facts-drift failure. With Hunter's explicit |
| 398 | maintainer approval, the missing provider maps and source-candidate facts were |
| 399 | added as `c3647fea2`, the branch was merged with current `main` as |
| 400 | `e701645ac`, and all six fresh fork workflow runs were approved. The PR is |
| 401 | mergeable again. Every current hosted check is green, including Ubuntu, |
| 402 | macOS, Windows, web, mobile, OpenHarmony, wrapper, DCO, issue-link, and Claude |
| 403 | review; deploy remained correctly skipped. The equivalent facts amendment is |
| 404 | integrated locally as `e805213d8`; the umbrella #1481 remains open because |
| 405 | this PR intentionally omits OpenCode Go. Prior branch evidence was |
| 406 | clippy-clean with `codewhale-tui` 8336/8336; the combined candidate still |
| 407 | needs its own gates before this is called landed. Merging the hosted PR remains |
| 408 | a separate maintainer action and is not required to preserve its code in the |
| 409 | local candidate. |
| 410 | |
| 411 | ## Working model: direct local `main`, no PR |
| 412 | |
| 413 | Release-lane work in this worktree lands as **small, reviewable commits on the |
| 414 | local branch**, not as GitHub PRs. Consequences to hold onto: |
| 415 | |
| 416 | - No `link` check and no PR review gate runs, so the discipline they enforce is |
| 417 | yours: one concern per commit with a real body, and no closing keyword unless |
| 418 | the acceptance criteria are actually met on the landed tree. |
| 419 | - CI gates still apply and must be run locally with the exact commands above |
| 420 | before anything is proposed for `main`; local green is the evidence, but it is |
| 421 | not hosted-green and must not be described as such. |
| 422 | - Pushing this branch to protected `main` remains Hunter-gated. The branch is a |
| 423 | candidate, not a landing. |
| 424 | - Contributor work never enters this way. Anything with an outside author goes |
| 425 | through the harvest path with `Co-authored-by` / `Harvested from PR #N` intact |
| 426 | and a merge or rebase (never a squash, which rewrites the credit line). |
| 427 | |
| 428 | ## Stop line |
| 429 | |
| 430 | Completing this ledger means one reviewed, gate-green, honestly receipted |
| 431 | v0.9.2 candidate with every scoped item given an evidence-backed disposition. |
| 432 | It does authorize the local version/changelog preparation and local dogfood |
| 433 | install required to test that candidate. It does **not** authorize a push, tag, |
| 434 | GitHub Release, crates/npm publish, artifact upload, deployment, DNS or billing |
| 435 | change, paid/live-provider request, signing/notarization, or public release. |
| 436 |