No reviewers
Labels
No labels
bump
major
bump
minor
bump
patch
kind/bug
kind/chore
kind/docs
kind/feature
priority/critical
priority/high
priority/low
priority/medium
size/L
size/M
size/S
size/XL
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
frankenbit/release-toolkit!352
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "i/340-register-audit"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
Public-mirror register audit before v1.0.0: scrub release-toolkit's internal
crew register from adopter-facing surfaces, so a first-time reader meets
the toolkit's machinery — not the chamber it was built in. Closes #340
(the consolidated audit), #339 (operations.md residual), and #342
(cold-read framework disambiguation).
Source-of-record for the audit premise: the anonymous external cold-read
(ChatGPT) at BookStack page 210, which flagged two classes — invented
terminology used far beyond what improves clarity and internal AI-review
narration shipped as part of the public product.
The cut line (per QM ruling)
Two axes, one principle: keep design provenance, drop narration provenance.
attributions (
per Surveyor 4a73,Bosun 312c dispatch,per Herald β-refined naming). The why-the-decision survives in git blame + theissue/PR links, which are untouched;
per Surveyor f5b9is conversationaltranscript, not decision-record content.
load-bearing.
substrate-honestand baresubstraterewritten to plainper-context (near-zero information loss — matches the Tier-A precedent
substrate desynced→release state desynced). Load-bearing designvocabulary is kept and glossed on first use:
mechanism-of-touch(self-bootstrap re-pin invariant), path α/β/γ,
mode = noop|update|cut,rolling PR, bake/rebake.
Heading renames (anchors fixed in lockstep)
The recurring coined heading "Substrate-honesty self-check" (ADR-0005,
ADR-0006) → "Falsifier + evidence-completeness self-check"; ADR-0003's
"The forced UI-publish step is substrate-honest" → "…ties deploy to
operator intent." Every inbound cross-ADR anchor reference was updated in
the same commit — verified no dangling
#…substrate-honest…links repo-wide.Coverage
Enumerated adopter surfaces first (README,
docs/*.md,docs/adr/,docs/migration/,scripts/,.forgejo/,release-toolkit.yml), then arepo-wide grep-0 sweep as the backstop — which surfaced three files
outside the initial enumeration (
docs/events-logging.md,docs/migration/tmux-tell.md, the config template). All now clean; thefinal sweep over every tracked file returns zero chamber-name/hex-id/coined
substratehits outside the kept surfaces below.Not in scope — deliberately kept
The register is the crew's working vocabulary and belongs where maintainers
read; scrubbing it there would be lossy, not clarifying. These surfaces keep
it by design:
AGENTS.md(maintainer contributor guide)docs/internal/**(cold-read framework, capture templates)tests/**.batschangelog.batsasserts the humanizer stripsSurveyor 96d8d385, so that string is test data, not narrationCHANGELOG.mdhistorytmux-telldesign-lineage refs in ADRsalcatraz-infra#NN)release-bot,forgejo-actions,NagyReview fix (Surveyor 3533):
repin.shhad also functionally defaultedREPIN_REVIEWERtosurveyor— a chamber-name in a scriptdocs/VERSIONING.mdpublishes as a v1.x CLI contract, and a broken default for adopters (requests a
reviewer that doesn't exist in their repo). Now scrubbed: empty default + gated
request + the
surveyoridentity moved to the maintainer call site (AGENTS.md§2.5, where the register is kept). A
fixedfragment records the publishedbehavior change.
Also folded (per Bosun ruling)
changelog.d/332.changed.mdcarried one chamber-narration phrase ("FixOption A per cold-read + Bosun ratify") that would ship into the v1.0.0
CHANGELOG — the exact provenance-leak class the external cold-read grades
against. Surfaced in the repo-wide sweep and flagged to Bosun, who ruled
fold-it-in-now: it closes the specific v1.0.0 exposure, while the broader
historical-CHANGELOG chamber-narration remains the changelog-humanization
arc's scope (not preempted). Scrubbed to plain adopter release-note prose —
same shape as the 3 backstop surfaces above, one layer down at the
changelog-fragment level.
Sequencing
This lands before the Pilot Cold-Read and the external outside-model
cold-read, so the adopter surfaces are polished when both grade the
v1.0.0-candidate. Success criterion for the external pass: no further
objections of the same class the ChatGPT review raised.
🤖 Generated with Claude Code
Adopter-facing docs should read for adopters, not narrate the crew's internal process. Per the ChatGPT external review (invented terminology + internal process artifacts on the public mirror). Per-instance judgment, not blanket deletion — plain language where the coinage was gratuitous: - integration.md: 'leaving the substrate desynced' -> 'the release state desynced' - conventions.md: 'internal substrate' -> 'internal machinery'; genericized the reviewer-code examples ('Surveyor NNNN'/'Bosun re NNNN' -> 'Reviewer NNNN'/'re NNNN') — removes the chamber-name leak AND makes the example useful to an adopter who has no Surveyor/Bosun - operations.md: de-attributed 'Bosun observed'; 'substrate-honest mechanism' -> 'the mechanism the toolkit uses instead' (#339); 'anti-recursion substrate' -> 'anti-recursion mechanism'; dropped the tmux-tell version-provenance anchor, kept the #273 tracker link - architecture.md: 'substrate gotchas' -> 'build-system gotchas' - SECURITY.md: 'mechanism-of-touch discipline' -> plain descriptions of the baked-ref mechanism, AGENTS.md pointers kept KEPT: README's two tmux-tell links (verified live-consumer proof, not provenance noise). ADRs + code-comment scrub land in follow-up commits. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013sreVuKQfwS7yvxyGL1Z2iStrip chamber-name + hex-id narration ("per Surveyor 71c0", "Bosun 312c dispatch", "Engineer d551 + QM #283 graft", "Herald-narrative-eye") from code comments across 20 scripts + workflows, preserving the technical substance + all #NNN issue-refs. Scrub coined register (substrate-honest, bare "substrate") to plain per-context per the QM ruling; keep-and-gloss mechanism-of-touch (the self-bootstrap re-pin invariant defined in AGENTS.md section 2). Adopter-visible surfaces get the same treatment: the manifest PR-body template string in reusable-release.yml, the auto-merge `:⚠️:` messages, manifest-check.sh's usage text, and preflight log lines all lose the register. Real identifiers kept: release-bot, forgejo-actions, the surveyor REPIN_REVIEWER default. ASCII-only preserved in scripts + workflow YAML per section 11. Comment/string-only; no logic changes; shellcheck clean. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013sreVuKQfwS7yvxyGL1Z2iRepo-wide grep-0 sweep surfaced three adopter-facing surfaces outside the original enumeration: docs/events-logging.md (bare "substrate" x2 -> "layer"), docs/migration/tmux-tell.md ("substrate shape"/"substrate enablement" -> "project shape"/"toolkit enablement"), and the release-toolkit.yml config template ("per Surveyor's #172 review" -> "per the #172 review"). Same cut line; #NNN issue-refs preserved. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013sreVuKQfwS7yvxyGL1Z2iReview — #352 register-audit scrub bundle (#340/#339/#342), head
37f39f3REQUEST_CHANGES — one contained finding on the graded surface; everything else is comprehensive and verified. This is a ~2-line fix + fast re-stamp.
The one finding —
scripts/repin.shstill defaults the reviewer to a chamber nameThe PR scrubbed Surveyor narration from repin.sh comments (removed "request Surveyor review" + the "Surveyor catches b85b + cd3c" line — good), but left the functional default:
repin.sh:55→REVIEWER="${REPIN_REVIEWER:-surveyor}"repin.sh:38→# REPIN_REVIEWER reviewer to request (default: surveyor)This matters because repin.sh is not maintainer-only:
docs/VERSIONING.mdpublishes it as a v1.x-CLI-contract script ("repin.shinvocations from external tooling"), and it's inside this PR's own Tier-B scrub set. So thegrep-0-on-scriptsAC is objectively not met (2surveyorhits), and it's exactly a "chamber-name identifier" — the class the anonymous cold-read flagged. An external cold-reader scanningscripts/before the v1.0.0 grade would surface it. It's also a broken default for any real adopter (requests review from asurveyoruser that doesn't exist in their repo).Clean fix — move the chamber name out of the published script into the toolkit's own invocation:
repin.sh:55→REVIEWER="${REPIN_REVIEWER:-}"(empty default), and gate the review-request block (:179-184) on[[ -n "$REVIEWER" ]]so an unset value skips the request instead of POSTing{reviewers: [""]}.repin.sh:38→ doc the env var without the chamber name.REPIN_REVIEWER=surveyorexplicitly (env, maintainer-scoped) — so the identity lives in the toolkit's CI/call site, not the adopter-facing script.(If instead you deem repin.sh toolkit-self-only and want to KEEP the default, that needs an explicit carve-out entry + a code comment telling adopters to set
REPIN_REVIEWER— but given VERSIONING.md publishes it and the cold-read grades scripts, I lean scrub.)Everything else — verified clean
scriptsexcept the repin.sh default above): chamber names 0,substrate-honest0.substrate-honesty-self-check,the-forced-ui-publish-step-is-substrate-honest,substrate-coverage-completeness,the-three-substrate-constraints,substrate-honesty-caveat) have zero inbound links repo-wide. No dangling anchors. Your lockstep verification holds.#…substrate…inbound link that exists (0006:256→AGENTS.md#10-substrate-grounding-…) is a non-issue: it targets the kept AGENTS.md §10 heading (PR doesn't touch AGENTS.md, so the anchor resolves), and the visible link text is clean. Leave it — scrubbing the slug would break the link.tests/changelog.bats:645/655/660keepsSurveyor 96d8d385because:660asserts the humanizer strips it (output != *"Surveyor 96d8d385"*) — load-bearing fixture, not narration. Same fixture-invariant class as #348 item-5. Correct keep.Comprehensive scrub, anchor integrity solid, KEEP/SCRUB spine applied consistently — just the one published-script default to close before the cold-read grades it. Re-stamp fast on the fixup.
Re-assert REQUEST_CHANGES — #352 head
7a39b53Re-pinning to the live head (the changelog fold-in commit dismissed my prior review 3533 under
dismiss_stale). Two parts:✅ The folded changelog scrub (
7a39b53) — verified goodDelta
37f39f3..7a39b53is exactlychangelog.d/332.changed.md(+1/-1), nothing else. The chamber-narration ("Fix Option A per cold-read + Bosun ratify") is scrubbed to substrate-neutral prose ("The fix restoresdraftas the default…"); the BREAKING framing + #332 accuracy are intact, privacy sweep 0. Correctly prevents the v1.0.0 CHANGELOG shipping the exposure. Good catch on the fold-in.⚠️ Still open — the
scripts/repin.shfinding from review 3533 (unchanged at this head)repin.sh:38+:55still carrysurveyoras the defaultREPIN_REVIEWER:This is the sole remaining blocker. Full rationale + the clean fix (empty default + gate the request block on
[[ -n "$REVIEWER" ]], moveREPIN_REVIEWER=surveyorto the toolkit's own invocation env) are in review 3533. It's the exact "chamber-name identifier on a published script" class the external cold-read grades, and thegrep-0-on-scriptsAC isn't met until it's closed.Everything else remains verified clean (heading-rename anchors, adopter-surface grep-0, KEEP/SCRUB spine, the changelog.bats humanizer-strip fixture). One 2-line fix from APPROVED.
Re-stamp APPROVED — #352 head
f054c81(repin.sh finding closed)The one blocker is fixed, and the two in-scope additions are both correct. Verified at head:
The fix — verified
scripts/repin.sh:REVIEWER="${REPIN_REVIEWER:-}"(empty default); the request block is gated on[[ -n "$REVIEWER" ]]and, when unset, logs "no reviewer requested; set REPIN_REVIEWER to auto-request one" instead of POSTing{reviewers:[""]}. The:38doc drops the chamber name.grep -i surveyor scripts/→ 0 — the grep-0-on-scriptsAC now holds. shellcheck clean,bash -nparses, repin.bats green.REPIN_REVIEWER=surveyor(env), so the chamber name lives in maintainer scope, not the adopter-facing script.The two scope additions — both correct
$REPIN_REVIEWERwhen set; unset skips; toolkit-self runs it assurveyor). AGENTS.md is maintainer-core, so keeping the identity in that call-site framing is right.fixedfragment rather than a silent behavior change. Accurate, privacy-clean.Standing verifications (unchanged — delta is only the 3 files above)
Heading-rename anchor integrity, adopter-surface grep-0, KEEP/SCRUB spine, the changelog.bats humanizer-strip fixture, the folded 332.changed.md narration scrub — all still hold.
Comprehensive register scrub, honestly documented, anchor integrity solid. Ship it — this is the clean adopter-surface state for the cold-reads + v1.0.0 cut. Good ownership on the reclassification.