Repository navigation
chore(tasks): weekly queue reconciliation 2026-09-30 - #2198
simple-agent-manager[bot] merged 18 commits into
Conversation
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Each file's unticked items are ticked only where a merged PR, staging run, production deploy or read-only production D1 query proves them; the rest carry a note saying why they stay unticked. Every file gets a provenance footer naming its PR, merge commit and first successful production deploy. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rgency, file update_idea truncation bug - 2026-09-26-trustworthy-task-status moves back to backlog: PR #2153 shipped the callback half, but ten conversation tasks still failed on day 7 after it deployed because the fallback joins a snapshot row the purge deletes. - 2026-09-03-projectdata-production-capacity-emergency stays active with a dated block: 10.30 GB, breaker open since 09-27, next human-gated steps. - New backlog entry: update_idea appends past the 65,536-char cap are silently discarded (found on the ACP interactions Idea). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Fixes the one citation this reconciliation moved plus three pre-existing dangling tasks/active/ references whose targets live in tasks/archive/. Notes that ProjectData Slice C code already exists at 7868bc8 on the unmerged parent branch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…hive/ tasks/completed/ held the two GitLab integration task files that PR #1578 meant to archive (both shipped to production 2026-07-14), and tasks/archive/completed/ held one nested archived file from PR #1974. The lifecycle is backlog -> active -> archive; there is no completed/. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ded but are still cited Each was verified against main by the weekly audit. They are archived rather than deleted because a remaining file (code comment, archived task, or a surviving backlog entry) references them; those references are repointed from backlog/ to archive/. Each file gets a footer naming its verdict and evidence. Code changes are two comment-only path repoints. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…(batches 00, 01, 03, 05, 08, 09) Each file gets a 'Reconciliation 2026-09-30' block right after its title saying what shipped (PR, commit, path:line) and exactly what is still open; OPEN files whose wording had gone stale get a short correction note. Bodies are not rewritten and no checkbox changes. Includes the chat-404 duplicate carried into 2026-09-08-ended-chat-requests-deleted-workspace and the undefined-token sweep folded into the retitled token file. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ywright audit umbrella Adds 2026-09-30 status blocks and folds the unique items from four duplicate spec files (chat-file-viewer, scaling-settings, recoverable-error banner, ai-usage route drift) into 2026-07-17-stale-playwright-audit-specs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…idate their duplicates Adds 2026-09-30 status blocks. Notification phase-1 umbrella items are carried into the security, UI/a11y and test-gap siblings; port-proxy ownership items into port-exposure hardening; the graph execution model is narrowed to the unenforced mission budgets now that Missions/ProjectOrchestrator shipped. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…uperseded or duplicate Each was verified against main by the weekly audit; the one-line rationale for every file is in the PR description and in the ledger. Nothing that remains in the repository references them (checked with a repo-wide grep). Duplicates were carried into their survivors first. One more shipped file (2026-05-12-fix-vm-agent-stability) is archived instead because an archived task cites it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ctData status block Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Three deleted (nothing remaining references them) and two archived because tasks/archive/2026-06-13-app-deployment-system-status.md cites them; that citation is repointed. Evidence per file is in the ledger. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Adds 2026-09-30 status blocks to the partially shipped deployment, test and vm-agent follow-ups, and short correction notes to four open entries, including the unfiled replay_done product bug recorded on 2026-07-04-fix-flaky-tests-at-root. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…al collision risk is tracked Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Method, outcome arithmetic, per-file evidence for every archived and deleted entry, the kept lists, what the audit found, the SAM memory changes made outside this diff, and a ranked list of what is genuinely open for the coming week. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… no longer exists Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d note pre-existing dangling citations Addresses the doc-sync review: the tally split SHIPPED into two rows that mixed a verdict with an action, which did not match the detailed tables. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Important Review skippedToo many files! This PR contains 269 files, which is 169 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configurationConfiguration used: Repository: raphaeltm/simple-agent-manager/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (269)
You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
|
@coderabbitai review |
|



Summary
Weekly queue reconciliation for 2026-09-30 (SAM task
01M3RBQBHV39B9SHDC4BWBR16B). The taskrecords in
tasks/active/andtasks/backlog/, and the four open PRs older than seven days, werechecked against
mainat2c009b565and against read-only production state, so the queue showsonly work that is genuinely open. The SAM memory half of the task (knowledge, ideas, policies) was
done through SAM MCP tools and is not in this diff.
tasks/active/tasks/backlog/tasks/archive/tasks/completed/(non-standard)The full per-file evidence is in the ledger,
tasks/archive/2026-09-30-weekly-queue-reconciliation.md.Active: 16 → 1
mainthrough its own implementation PR, and each of thosePRs has a successful production deploy. Unticked items were ticked only where a merged PR, staging
run, deploy or read-only production D1 query proves them. The rest carry a note saying why they
stay unticked. Every file gets a provenance footer naming its PR, merge commit and deploy run.
2026-09-26-trustworthy-task-status. PR Fix trustworthy terminal task status #2153 shipped thelate-callback half, but its day-7 conversation fallback joins a
session_snapshotsrow that the7-day purge has already deleted. Ten conversation tasks have failed on day 7 since it deployed,
the latest at 02:36Z today.
2026-09-03-projectdata-production-capacity-emergency, with a dated statusblock. The root ProjectData DO is at 10,297,155,584 bytes (103% of the limit, still growing). The
SAM archive breaker has been open since 2026-09-27 16:47Z, and the Triple the ProjectData archive drain (18-min cadence, 2.4M budget) #2161 rollback trigger fired
without anyone acting on it. Slice C code already exists at
7868bc894on the unmerged parentbranch.
tasks/completed/(the two GitLab files PR docs: archive shipped GitLab integration tasks #1578 meant to archive)and a nested
tasks/archive/completed/file intotasks/archive/.Backlog: 300 → 208
All 300 files were audited by ten parallel read-only reviewers (30 files each), checked against the
code in
main, and every removal was re-checked for references before it was removed. Lessons carried fromlast week: a merged landing PR does not prove the work shipped, so grep the whole repo;
wrangler.tomlis not the deployed value; when unsure, keep.Verdicts across the 300 files: 101 PARTIAL, 101 OPEN, 62 SHIPPED, 15 OBSOLETE, 11 SUPERSEDED, 4 DUPLICATE, 1 dissolved into siblings, 1 merged into a sibling, 4 UNSURE (kept).
that remains still cites them (their
backlog/paths are repointed; two of these are codecomments). Every one is listed with its one-line rationale below.
Reconciliation 2026-09-30status block after its title,saying what shipped (with evidence) and exactly what is still open. Bodies were not rewritten and
no checkbox was changed.
2026-07-17-stale-playwright-audit-specs, the notification phase-1 umbrella dissolved into itsthree siblings, the port-proxy file merged into port-exposure hardening, and the chat-404
duplicate merged into
2026-09-08-ended-chat-requests-deleted-workspace. Unique items werecarried into the survivors before the files were removed.
update_ideaappends are silently discarded oncean Idea reaches 65,536 characters (
apps/api/src/routes/mcp/idea-tools.ts:398). Four SAM Ideasare already at the cap, including the priority-10 ProjectData storage plan, which the Monday
health review appends to.
A pattern worth knowing: the July repo reorganization (#1468) moved about 26 files that PRs had
already implemented back into
backlog/unchecked. Most of this week's "shipped" removals arethose.
Open PRs older than seven days
#1788, #1817, #2020 and #2062 each already had four bot comments in two weeks and no human reply,
so each new comment states only what changed since 2026-09-23 and the one decision that ends it:
#1817 is now 657 commits behind (close or commit); #2020's CodeRabbit concern is gone under the
2026-09-29 best-effort rule, but the three Sonar account actions remain; #2062 and #1788 are
unchanged parks. (#2160 is three days old and out of scope.)
Backlog removals, one line each
Deleted (70):
2026-02-20-dashboard-chat-session-navigation(superseded): Spec 017 paused; /chats page (feat: add global active chats page at /chats #574) + dashboard active tasks (Dashboard: show the six most recently active tasks #2152) deliver the user stories2026-02-20-mobile-navbar-redesign(shipped): fix(web): add mobile navigation drawer to prevent header overflow #137 (c58ca22): MobileNavDrawer.tsx, compact UserMenu, z-index tokens + tests2026-02-23-admin-page-padding(shipped): Admin.tsx:35 uses PageLayout (fix(web): loading state, admin padding, task filter layout #176)2026-02-23-loading-state-pattern(shipped): fix(web): loading state, admin padding, task filter layout #176 fixed all 8 guards; principle codified as apps/web rule 482026-02-23-tasks-tab-filter-layout(shipped): TaskFilters.tsx:33-74 flex-wrap row (fix(web): loading state, admin padding, task filter layout #176)2026-02-27-tdf-0-index(shipped): All TDF parts merged (TDF-1: Harden task state machine with exhaustive tests and step validation #210, TDF-2: TaskRunner Durable Object for alarm-driven task orchestration #212-TDF-3 through TDF-8: Task orchestration hardening & frontend state tracking #219); index obsolete2026-02-27-tdf-3-node-selection-provisioning(shipped): TDF-3: Harden node selection & provisioning with comprehensive tests #213 tests shipped; node-selector.ts later replaced by task-runner/node-selection.ts (Complete canonical node pools and safe legacy resource migration #2030)2026-02-27-tdf-4-vm-agent-contract(shipped): TDF-4: Formalize VM Agent communication contract with schemas, tests, and retry #214/TDF-5: Workspace lifecycle event-driven readiness #215: packages/shared/src/vm-agent-contract.ts + TS/Go contract tests + callbackretry2026-02-27-tdf-5-workspace-lifecycle(shipped): /ready and /provisioning-failed call TaskRunner directly (lifecycle.ts:574,644); spec 0332026-02-27-tdf-6-chat-session-management(shipped): TDF-6: Fix duplicate sessions, fallback IDs & workspace-session linking #216: required session creation, no sess-fallback, linkSessionToWorkspace, VM outbox retry2026-02-27-tdf-7-recovery-resilience(shipped): TDF-7: Recovery & Resilience — safety net for durable orchestration #217: stuck-tasks.ts diagnostics + layered orphan sweeps + tests2026-02-27-tdf-8-frontend-state-tracking(shipped): TDF-8: Frontend state tracking — reliable task progress & chat display #218: EXECUTION_STEP_LABELS, ProvisioningIndicator, reconnect/catch-up2026-02-28-project-agent-type-setting(shipped): feat: add per-project default agent type setting #295: schema.ts:425, project-update.ts, ProjectSettings.tsx; precedence explicit->profile->project2026-03-02-fix-admin-logs-query-error(shipped): fix: correct Cloudflare Observability API request body for admin logs #298 (983f00a) restructured the query body (services/observability.ts:612-640); regression tests observability-logs.test.ts:168-215,431; chore: repo reorganization and hygiene cleanup #1468 reorg moved the file back to backlog unchecked2026-03-02-quick-workspace-launch-ux(obsolete): ProjectOverview.tsx (Launch Workspace) deleted in fix: remove dead views (Sessions, Overview, Kanban) and improve mobile chat UX #466; chat is task-driven and Finalize session tool rail: lower tab, remove review knob, workspace link cleanup #1977 made workspaces an implementation detail2026-03-05-agent-session-not-found-404(obsolete): Retry path now re-runs idempotent create then start (agent-session-bootstrap.ts:233,289-371); replay after restart fails closed with 409; crash loop fixed in fix: prevent VM agent crash loop from nil broadcaster and concurrent npm installs #2932026-03-06-acp-session-message-persistence(shipped): fix: message misrouting and tool metadata loss #314 (383e652) gave every SessionHost the message reporter (agent_ws.go:278-287); fix: org installation visibility, project chat agent offline, message history #270 follow-ups persist; DO dedupe (messages.ts:199-236); feat: DO-only chat architecture with typewriter animation #978 DO-only chat2026-03-06-continue-staging-ux-ui-qa(obsolete): Continuation of one interrupted 2026-03-05 QA session against what is now production; flows rebuilt; per-PR staging + Playwright audits now mandatory2026-03-06-project-chat-acp-503-on-new-workspace(obsolete): feat: DO-only chat architecture with typewriter animation #978 removed the client ACP WebSocket from project chat (the path that raced DNS)2026-03-07-chat-continuation-after-workspace-cleanup(superseded): feat: add durable session sleep and recovery for Claude Code and Codex #1785 snapshot sleep/wake (tasks/archive/2026-08-12-persistent-session-sleep-wake.md) + fork (routes/chat-fork.ts)2026-03-08-fix-acp-session-context-loss-on-followup(shipped): Cause 1 Recover crashed ACP agents with LoadSession #1099 (LoadSession on restart, tests session_host_crash_recovery_test.go:317-392); cause 2 fix: resolve Mistral Vibe agent crashes on staging #386 guard + feat: DO-only chat architecture with typewriter animation #978; cause 3 sleep/wake feat: add durable session sleep and recovery for Claude Code and Codex #17852026-03-09-fix-node-workspace-limit-count-filters(shipped): fix: exclude deleted/stopped entities from node and workspace limit checks #290 (ffe0092) status filters + tests (nodes-max-nodes-quota.test.ts, node-provisioning.test.ts); per-node cap removed in Remove legacy per-node workspace caps (maxCoTenants, maxWorkspacesPerNode) #21492026-03-13-workspace-profile-ui-ux-improvements(obsolete): SettingsDrawer.tsx deleted (Remove project settings drawer from chat #1131); TaskSubmitForm.tsx unused by production routes; profile control is now a SelectField2026-03-15-dialog-focus-trap(shipped): useModalInteraction.ts:118-170 Tab wrap + restore; Dialog.tsx:46; packages/ui/tests/Dialog.test.tsx:125,149,214 (Integrate CTO remediation hardening PRs #1637, fix(ui): stop mobile modal focus stealing #2154)2026-03-15-scroll-to-bottom-button(shipped): feat: scroll-to-bottom button + ctrl/cmd+enter to send #411: ConversationPane.tsx:136,153-167 (atBottom toggle, aria-label); overlap fixed fix: offset scroll-to-bottom button when cancel bar is visible #519; the file itself says archive2026-03-16-notification-system-phase1-followups(dissolved): Umbrella file; shipped parts (workerd DO tests, type tabs feat: add priority/updates/all tabs to notification panel #973, 90-day TTL) done; unique open items moved into the security, UI/a11y and test-gap siblings2026-03-17-port-proxy-ownership-verification(merged): Ownership + 401 via fix: harden AI budget accounting and workspace proxy ownership #928/feat: port access tokens for exposed workspace ports #936 and per-port token (jwt.ts:330-400) shipped; unique items carried into port-exposure-security-hardening2026-03-18-mcp-json-session-cleanup(obsolete): workspace_mcp.go deleted in feat: unify workspace-mcp into sam-mcp single MCP server #614 (8bb1324); nothing writes .mcp.json any more2026-03-19-ideas-page-polish(obsolete): All 3 targeted surfaces redesigned away (idea detail page feat: idea detail page with linked conversations #473; sidebar pills removed Redesign chat sidebar: remove clutter, flatten retries #885; status select removed Simplify ideas page to draft backlog #1263)2026-03-19-scroll-button-cancel-button-overlap(shipped): fix: offset scroll-to-bottom button when cancel bar is visible #519 offset fix; cancel strip later replaced by CompletionDock (feat(web): morphing CompletionDock replaces idle/working strips #1474)2026-03-23-task-callback-scope-enforcement(shipped): routes/tasks/callback.ts:77 requires expectedScope 'workspace' (enforced services/jwt.ts:277); tests task-callback-auth-routing.test.ts:353, callback-token-unified-scope.test.ts:492026-03-24-gcp-oidc-ux-fixes(shipped): fix: GcpCredentialForm UX — loading state, done phase, confirm dialog #511: loading-projects phase, ConfirmDialog, tests + Playwright spec; SettingsDrawer item moot (Remove project settings drawer from chat #1131)2026-03-24-remove-legacy-node-callback-fallback(shipped): fix(security): remove legacy node token fallback #674 removed the nodeId fallback (verifyWorkspaceCallbackAuth, _helpers.ts:357-396); tests callback-token-scope-enforcement.test.ts:74-1022026-03-28-files-go-shell-injection-defense(shipped): fix: resolve data races, shell injection, and auth bugs in VM agent #651 removed sh -c/head -n; find runs with direct args (files.go:78-81); test files_test.go:112026-03-31-pr570-remaining-test-doc-gaps(obsolete): fix: OpenCode config for Workers AI proxy + remove Neko browser sidecar #733 (83bdc3e) deleted the whole Neko sidecar these items target2026-04-09-reconnect-button-behavioral-test(obsolete): AgentErrorBanner and its Reconnect button deleted in feat: DO-only chat architecture with typewriter animation #978 (ef889af)2026-04-13-knowledge-graph-ui-accessibility(obsolete): KnowledgePage.tsx deleted in Add Agent Context page consolidating Knowledge, Policies, and Actions #1137; replacement MemoryTab.tsx already has the key fixes2026-04-18-multi-level-configuration-override(shipped): feat(projects): per-project agent defaults (Phase 1 multi-level config) #748 (c32e573) from this file's own branch: migration 0042, schema.ts:434, project-update.ts:162-183, dispatch-tool.ts, ProjectAgentsSection.tsx, tests/unit/project-agent-defaults.test.ts; chore: repo reorganization and hygiene cleanup #1468 moved it back to backlog2026-04-18-nested-chat-sidebar-tree(superseded): Tree shipped in feat(web): support deeply nested chat sessions with context anchors #759 then deliberately replaced by a flat list + hierarchy modal in fix: flatten session list, hash-based hierarchy modal, role icons #1287 (sessionTree.ts deleted); design in archived 2026-06-10/11 hierarchy tasks2026-04-18-staging-migration-v8-corruption(obsolete): v8 is a DO migration tag; fix: preserve Durable Object migration compatibility #1649 resolver reads the deployed tag and fails closed on unknown tags; 7 of the last 8 staging deploys succeeded2026-04-18-trial-onboarding-wave-0-foundation(shipped): All items in e253c08 via feat(trial): zero-friction URL-to-workspace onboarding MVP #758: packages/shared/src/trial.ts, 0043_trial_foundation.sql, schema.ts:3326-3336, wrangler bindings, constant-time compare, routes, tests2026-04-23-expose-platform-opencode-in-project-chat(obsolete): Shipped in Fix platform OpenCode visibility in agent catalog #1051 then intentionally removed in Simplify OpenCode to 3 user-key providers (zen/go/custom) #1431 (OpenCode is bring-your-own-key only; agents-catalog.ts:12)2026-04-25-mcp-token-refresh-for-long-sessions(shipped): Sliding window + 24h cap (mcp-token.ts:109-161, defaults.ts:292) with tests mcp-token-sliding-window.test.ts (6017aea, fix: prevent duplicate workspace dispatch on node-ready race #966)2026-04-29-session-header-agent-info-mobile-fixes(shipped): All findings fixed in feat: add agent info to SessionHeader expanded panel #856 squash (bdaba53): SessionHeader.tsx:413-438, session.ts:31, tests + audit spec2026-04-30-vm-agent-workspace-provisioning-queue(shipped): Complete canonical node pools and safe legacy resource migration #2030 (1d21cb8): system-provisioning barrier (system_provisioning.go, main.go:251-268) with tests2026-05-01-monthly-cost-cap-enforcement(shipped): feat: enforce monthly AI cost caps via cron + KV cache + proxy gate #1060 + Harden monthly cost cron TTL parsing #1420: ai-monthly-cost-cron.ts + gate in ai-token-budget.ts:602-656 called from every proxy path, with tests2026-05-01-tail-worker-log-ingest-auth(shipped): Fix tail-worker ingest auth (service-binding 401s) #890 (d74b178): internal-hostname gate in routes/observability-ingest.ts with tests; duplicate of archived 2026-05-04-fix-tail-worker-ingest-auth.md2026-05-07-convert-eval-backlog-to-task-packets(obsolete): Packet PR docs: staged implementation plan + 20 swarm-ready task packets #924 closed unmerged; source docs/evaluations folder deleted in docs: consolidate documentation in www #1174; findings 5 months stale2026-05-07-unblock-pr-927-ci-fixes(shipped): PR ci: enforce coverage thresholds and add Playwright visual tests #927 merged 2026-05-08 (0ba5469) with every fix (ci.yml:526-527, playwright.config.ts, sonar-project.properties)2026-05-08-project-agent-tools-import-timeout(shipped): All boxes ticked; PROJECT_AGENT_TOOLS_IMPORT_TIMEOUT_MS at project-agent.test.ts:12 (fix: harden provider adapters #932)2026-05-12-prevent-duplicate-workspace-dispatch(shipped): fix: prevent duplicate workspace dispatch #1033 (migration 0050 dispatched_at, node-lifecycle.ts:220-252) + Fix duplicate VM workspace provisioning #1031; twin of archived 2026-05-16-workspace-dispatched-at-race.md2026-05-15-session-icon-mode-enrichment(shipped): All ticked; fix: session icons and mode labels use task data from enrichment #1020 (e8e81b4) + session-icon-data-flow.test.tsx2026-05-15-vertical-slice-cron-triggers(shipped): test: add vertical slice tests for cron triggers and trigger execution cleanup #1017 (aa804c7): workers cron-trigger-sweep.test.ts + trigger-execution-cleanup.test.ts2026-05-15-vertical-slice-tests-background-jobs(shipped): test: add vertical slice tests for cron triggers and trigger execution cleanup #1017: workers scheduled-*.test.ts suites + seed-d1 fixtures2026-05-16-mobile-viewport-scroll-regression(shipped): feat: glassmorphism design system migration #1044 ee6169c scoped overflow:hidden to desktop (index.css:40-49) + mobile-viewport.ts; real-device check not verifiable from code2026-05-17-session-state-mirror(shipped): feat: session state mirror for reliable activity indicator + plan button #1043 (66a7f6c) and extensions: session_host_reporting.go, project-data/session-state.ts, session-state-mirror.test.ts2026-05-30-ai-usage-audit-route-drift(duplicate): Same spec + failures are row 16 of 2026-07-17-stale-playwright-audit-specs.md (survivor); carry the root-cause correction (headings still exist; render after compute usage loads)2026-05-30-github-event-triggers-prototype(shipped): Shipped for real as feat: GitHub event triggers prototype with pre-session filters #1160 (c444b3e): migration 0057, github-trigger-filter.ts, webhook handler, UI, kill switch, tests2026-05-31-resource-override-audit-slice(superseded): Overtaken by shipped compute-pools placement (Complete canonical node pools and safe legacy resource migration #2030; resource-requirements-input.ts layer order; placement-resolver.ts; resolved_reservation_json)2026-06-06-light-mode-slice-c-workspace-node-detail(superseded): Superseded by consolidated light-mode PR feat(web): light mode (consolidated) #1239 (archived twin 2026-06-06-light-mode-slice-c-workspace-chrome.md)2026-06-07-cache-user-installation-repos-spawn-hot-path(shipped): d1a7380: KV cache in assertRepositoryAccess (routes/projects/_helpers.ts:258-289) keyed by user+installation+repo, GITHUB_REPO_ACCESS_CACHE_TTL_SECONDS (default 300s), used by run/submit/workspace-create/chat-start; tests project-repository-access.test.ts:111-175; note: the default TTL is 300 s where the task suggested ~60 s (env-configurable, no production override), and the drift 403 check still runs on cached results2026-06-08-fix-cancel-replays-conversation(shipped): fix(vm-agent): suppress ACP LoadSession replay so cancel does not replay chat #1254 (f33a95c): replaySuppressed field (session_host.go:204-210), deferred clear (session_host_handshake.go:113-114), early return (session_host_client.go:52); tests session_host_replay_suppress_test.go:59,2032026-06-18-deployment-node-observability(shipped): Add app deployment control surface and policy gate #1356 (703b8b5): container log reading/streaming (logreader/docker.go, stream.go), deployment-environments routes, DeploymentMetricsPanel, DeploymentLogsPanel, container picker; Go/TS/Playwright tests2026-08-04-chat-file-viewer-audit-spec-broken(duplicate): Same spec and symptom as the chat-file-viewer row in 2026-07-17-stale-playwright-audit-specs (survivor); carry Surface session controls in a chat tool rail #1976 retarget note2026-08-06-configure-remaining-debugging-safety-bounds(shipped): Complete the same-instance debugging experience #1750 (a857a33) shipped all four bounds (config_load.go:302-304, errorreport, VITE_DEBUG_DIAGNOSIS_EVENT_MAX_PAGES, cloud-init wiring) with tests and docs; no references outside tasks/2026-08-11-project-chat-recoverable-error-banner-missing(superseded): Banner replaced by FailureCard; spec rewritten (integration: batch 2 — priority drafts (#1824 #1779 #1770 #1769 #1678) #1839) and quarantined; folded into 2026-07-17-stale-playwright-audit-specs with the guidance-text assertion2026-08-11-scaling-settings-audit-spec-stale(duplicate): Same failure is a row in 2026-07-17-stale-playwright-audit-specs:18 (survivor); spec quarantined at line 922026-08-11-useprojectlist-options-not-forwarded(obsolete): 6f09122 (via integration: batch 2 — priority drafts (#1824 #1779 #1770 #1769 #1678) #1839) removed status/sort from useProjectList; now TanStack-based2026-08-17-recover-rebase-land-harness-work-sleep-fix(shipped): PR fix: keep sessions awake while harness background work is in flight #1845 (855f701) merged the recovered branch: migrations 030/031, wait_for_subtasks, docs, idea 01M07SW32WP8ZXABWF1ZV3AEMX filed2026-09-29-chat-page-404s-on-deleted-session-workspace(duplicate): Same code path as 2026-09-08-ended-chat-requests-deleted-workspace (survivor); carry the 09-29 staging reproArchived (still referenced) (24):
2026-02-15-user-configurable-mcp-servers(superseded): Shipped as BYO MCP servers (feat(mcp): bring-your-own MCP servers for agent sessions #1892, feat(mcp): custom HTTP headers for bring-your-own MCP servers #2186; mcp_connections schema.ts:2069; SettingsMcpServers.tsx); survivor tasks/archive/2026-08-23-byo-mcp-servers.md; file already bannered "SUPERSEDED, do not execute"2026-02-28-fix-flaky-vm-agent-tests(superseded): Survivor tasks/backlog/2026-07-04-fix-flaky-tests-at-root.md (item 3 says this file's root cause is wrong)2026-02-28-mobile-chat-ux-overhaul(shipped): feat: mobile chat UX overhaul #220: AppShell mobile header, MobileSessionDrawer, full-bleed chat2026-03-06-unify-project-chat-through-do-streaming(superseded): feat: DO-only chat architecture with typewriter animation #978 / tasks/archive/2026-05-12-do-only-chat-typewriter.md: all chat through the DO with typewriter rendering2026-03-09-quick-chat-mode-design(shipped): Design-only task, all 5 criteria checked; approaches since built (sam-session DO, project-agent, Instant sessions)2026-03-12-provisioning-failed-callback-401(shipped): fix: workspace callback auth middleware leak (P0) #325 (9c7875b) same-day fix; route uses callback JWT only (lifecycle.ts:580-583); tests workspace-callback-auth-routing.test.ts:157,2022026-03-14-fix-mistral-vibe-acp-metadata(shipped): fix: resolve Mistral Vibe agent crashes on staging #386 (c3a190e): ACP ClientInfo + VIBE_CLIENT_* (gateway.go:1136-1142) and generated ~/.vibe/config.toml aliases (vibe_config.go:45-143)2026-03-18-docker-exec-env-token-exposure(shipped): fix: pass secrets via --env-file in docker exec #516 (0cd0fc6): /dev/shm 0600 --env-file (process.go:127-160,276-309); tests process_test.go:160-214 assert secrets never in args2026-04-02-fix-codex-mcp-streamable-http-compliance(superseded): Shipped as PR fix: MCP Streamable HTTP compliance for Codex #601 under tasks/archive/2026-04-03-fix-mcp-streamable-http-compliance.md2026-04-11-fix-flaky-useAvailableCommands-test(superseded): Proposed fix landed (25f329b, fix: charge compute usage by node runtime #694); root cause owned by tasks/backlog/2026-07-04-fix-flaky-tests-at-root.md, which says to archive this file2026-05-05-debug-package-fixes(shipped): All seven fix groups landed via fix: devcontainer build network resilience (apt mirrors, timeout, retries) #901 (template.ts mirror script, 15-min timeout), fix: prevent duplicate workspace dispatch on node-ready race #966 (callback 401 + logged bodies), Fix debug package cleanup findings #1010 (cloud-init schema), VERSION pinned in deploy-reusable.yml:10572026-05-05-fix-chat-message-loading-regression(shipped): fix: restore chat message loading limits and preserve earlier messages #898 did every item; the 3000 default was deliberately replaced by paging in Instant chat switching: 24h transcript cache, newest-first loading #21652026-05-12-fix-vm-agent-stability(shipped): Timers fix: disable apt-daily timers and harden IPv6 firewall in cloud-init #968, dispatch dedup fix: prevent duplicate workspace dispatch #1033 + VM idempotency Fix duplicate VM workspace provisioning #1031, callback extraction + MCP sliding window fix: prevent duplicate workspace dispatch on node-ready race #9662026-05-12-vm-agent-cloud-init-firewall-hygiene(shipped): fix: disable apt-daily timers and harden IPv6 firewall in cloud-init #968 (cbd2ad1): template.ts:35-39, :632-650; tests generate.test.ts:1486-1508,1548-15702026-05-27-workspace-forward-local-port-remap(shipped): Resume localhost-preserving CLI forwarding #1370 (2686df3) added --local-port (workspace.go:151-164,233-254) with tests2026-06-13-compose-preview-endpoint-route-targets(shipped): fix: redeploy port rebind — tear down previous release before upping new #1312 (8ccbcee): deployment-releases.ts:353-376 passes routeTargets matching the apply payload; tests compose-preview-parity.test.ts:110,158,2312026-06-13-deployment-per-env-host-port-offset(shipped): fix: redeploy port rebind — tear down previous release before upping new #1312: per-environment port band (deployment-routing.ts:71-100) + teardown-before-start (engine.go:255-275); tests deployment-routing.test.ts, TestEngine_RedeployPortRebind; residual 1-in-305 band collision risk tracked in 2026-06-17-deploy-engine-security-hardening-followups2026-08-07-staging-vm-agent-no-heartbeat-before-workspace(obsolete): Fresh staging VMs have heartbeated repeatedly since (archived 2026-08-09, 2026-09-08, 2026-09-25 evidence); symptom never recurred2026-08-25-build-concurrency-backpressure(shipped): PR Add VM build concurrency backpressure #1904 (1d7fab9): build semaphore server.go:583, creatingWorkspaces health.go:169, build-started callback, TaskRunner reset, TS+Go tests; cited by scaling.ts:69 and generate.test.ts:560 -> archive + repoint2026-08-26-stop-zombie-callback-storms(shipped): PR Stop zombie callback storms after teardown #1922 (01a8270): 410 for tombstoned nodes, JWT 401s, vm-agent terminal latch, MSG_RESPONSE_MAX_BYTES; staging evidence in file; cited by an archived task -> archive2026-09-05-archive-precopy-refusal-should-not-fence-session(shipped): Folded into and shipped by PR Archive drain: run the sweep, unwind pre-copy refusals, 15-min cadence #2027 (refusePreCopyMigration + restoreSessionLocationToRootStatement, project-data-archive-sharding.ts:2127,2171; tests :2753,:2910); leftover session_state decision lives in idea 01M1V3WYT6D88Z41WQWP0ASVC32026-09-19-deployment-provisioning-expression-tree-too-large(shipped): Resolved in PR Port five app-deployment fixes from DefangLabs #45 and stop double-advertising pending releases #2102 (all criteria ticked with staging evidence); regression test tests/workers/deployment-provisioning-expression-depth.test.ts; resolved record -> move to archive2026-09-25-timing-sensitive-workers-tests(shipped): PR Fix flaky worker alarm tests #2156 fixed both named tests (reserved-task-submission-task-runner.test.ts:83/:704; project-data-storage-safety.test.ts:61/:1688); Stabilize storage safety worker alarm test #2158 helper2026-09-26-split-use-session-lifecycle(shipped): PR Instant chat switching: 24h transcript cache, newest-first loading #2165 (77372ab) took useSessionLifecycle.ts 787 -> 489 lines (useSessionTranscript.ts, useFallbackSessionPoll.ts)Validation
pnpm lint: N/A, markdown and two comment lines onlypnpm typecheck: N/A, no type or runtime change (the two code edits are//and/** */comment path swaps)pnpm test: N/A, no behavior changepnpm format:check(the repo's format ratchet) passes at2,083/2,225 unformatted files. No file this PR touches went from prettier-clean to unclean:
the edited files that fail
prettier --checkfailed identically at base, and the new ledgeris formatted. A repo-wide sweep found no reference this PR broke to a moved or deleted task
path. File-count arithmetic reconciles (see the ledger).
Staging Verification (REQUIRED for all code changes — merge-blocking)
N/A: docs-only. Zero runtime behavior changes.git diff main...HEAD -- . ':!tasks'is twocomment lines, each swapping
tasks/backlog/…fortasks/archive/…:packages/shared/src/constants/scaling.tsandpackages/cloud-init/tests/generate.test.ts..claude/rules/13exempts documentation-only changes, and comment text is documentation.N/A: docs-onlyN/A: docs-onlyN/A: docs-onlyN/A: docs-onlyN/A: no infra changesN/A: no UI changesStaging Verification Evidence
N/A: docs-only.The deployed artifact is unchanged by this PR. Verdicts that needed productionevidence used read-only queries instead: production D1 (task failures, stuck nodes, ProjectData
storage telemetry, archive breaker and migration states) and the GitHub
productionEnvironmentvariables.
UI Compliance Checklist (Required for UI changes)
N/A: no UI changes.UI Screenshot Evidence
N/A: no UI changes — ui-change is not checked in Agent Preflight.End-to-End Verification (Required for multi-component changes)
N/A: no multi-component change.This PR moves, narrows and deletes markdown records.Data Flow Trace
N/A: no runtime data flow is changed by this PR.Untested Gaps
The thing that matters here is whether each verdict is correct, which CI cannot test. Each verdict
cites its evidence in the ledger so a reviewer can re-check any row, and the local reviewers
re-verified them (see below).
Post-Mortem (Required for bug fix PRs)
N/A: not a bug fix.Specialist Review Evidence (Required for agent-authored PRs)
needs-human-reviewlabel added and merge deferred to human — N/A, every reviewer completed.main; no falsely removed open work. LOW: two disclosed scope narrowings (--local-portrather than--local; paging rather than a 3000-message default), verdicts correct.2026-06-17-deploy-engine-security-hardening-followups, which tracks it as a placement-time check. LOW: an archived status doc's Mermaid still styles archived items as open (pre-existing; left).tasks/README.mdand rules 09/14 still accurate; outcome arithmetic exact. MEDIUM: the ledger's verdict tally split SHIPPED into SHIPPED/SHIPPED-ARCHIVE, mixing verdict with action; fixed to one row of 62. Informational: about 32–39 task-path citations were already dangling at base (unchanged, now noted in the ledger); the prettier validation wording was clarified.CodeRabbit Review Evidence (Required for agent-authored PRs)
CodeRabbit Notes
CodeRabbit did not review this PR.
coderabbit-reviewlabel.coderabbit-bot-review.yml(run 36683707491) succeeded and posted the request at 07:26:41Z.Review in progressat 07:26:54Z.Review skipped: 269 files exceed the limit of 100. The bot's comment reads "Too many files! This PR contains 269 files, which is 169 over the limit of 100."Review skipped: bot user not eligible for reviewstatus.excluded by label configuration.Rule 25 counts a
Review skippedstatus as "did not review", so this PR merges on its remaining gates.main.Exceptions (If any)
/doPhase 1 says to push the task file straight tomain. This run kept it on the branch, as last week's run (chore(tasks): reconcile the queue against shipped reality (182 active -> 1) #2138) did, so a one-file markdown commit does not trigger a production deploy of its own.Agent Preflight (Required)
Classification
External References
N/A: no external API is involved.Evidence came from the repository itself, the GitHub REST API (gh pr list,gh pr view,gh run list,gh api .../environments/production/variables),git log, and read-only production D1 queries through the Cloudflare API, all first-party to this project.Codebase Impact Analysis
tasks/only:tasks/active/(16 → 1),tasks/backlog/(300 → 208),tasks/archive/(1,118 → 1,159), andtasks/completed/removed. Two comment lines outsidetasks/are path swaps:packages/shared/src/constants/scaling.tsandpackages/cloud-init/tests/generate.test.ts. Read-only inspection coveredapps/api/,apps/web/,apps/www/,packages/vm-agent/,packages/providers/,packages/cli/,packages/shared/,scripts/and.github/workflows/to verify shipped claims.Documentation & Specs
No www docs or specs needed updating: no user-facing behavior changed.
tasks/README.mdstill describes the backlog → active → archive lifecycle correctly; this PR removes thecompleted/directories that contradicted it. Specs were deliberately not edited (rule 01 forbids editing specs outside their own context).Constitution & Risk Check
Principle XI (no hardcoded values) is not engaged, because no business logic changed. The real risk is losing open work, and it was handled directly:
main.git mvwas used so history follows each archived file.🤖 Generated with Claude Code