Skip to content

S483 Main-Track Delta Audit — what changed since S462

S483 Main-Track Delta Audit — what changed since S462

Section titled “S483 Main-Track Delta Audit — what changed since S462”

Audit date: 2026-07-17 · Baseline audited: continuation-prompt-ca-s462-main-track-spine.md (authored ~2026-07-11) Repo state at audit: branch pr-procurement-baseline-merge, HEAD 37011f49 (the procurement baseline merge — id-145/147/156/161 — landed during this audit; working tree now clean, pushed). Read-only audit.

Headline: The single biggest delta is that the procurement form-first re-architecture (id-145) has MERGED to the main line as commit 37011f49. That merge is the “ID-145 DDL batch” the S462 spine was waiting on. Its landing supersedes or reshapes several S462 claims — most importantly {127.34} (manifest), {135.28} (Assign-to-Workspace toolbar), the id-128 pause, and spine precondition (b).


1. id-135 close-out (25/29): STILL-VALID (unchanged count) but {135.28} RESHAPED by id-145.

  • Current: 25 done, 1 blocked ({135.21} hybrid_search keyword-facet), 3 pending ({135.28}, {135.29}, {135.30}). No movement since S462.
  • {135.28} “Gate /library bulk toolbar Delete + Assign-to-Workspace behind role checks” — the S462 prompt hedged “check ID-145 direction, relabel may be the right fix.” id-145 has now LANDED, and {145.35} “Remodel browse bulk Assign-to-workspace onto engagement groups” is DONE (workspace tier retired, DR-038). So {135.28} must be re-baselined onto engagement groups, not merely relabeled.
  • Drift flag: {135.25} (done) built the workspace-labelled /library toolbar; id-145.35 remodeled /browse bulk onto engagement groups. /library and /browse bulk-assign surfaces may now disagree — verify before investing in {135.28}.
  • {135.29} loading.tsx spike + {135.30} Edit→View relabel are cheap and unaffected.

2. Latest backlog (bl-449/450/451): STILL-VALID but stale-priority.

  • bl-449 spec_needed (dead activity feed — RPC dropped), bl-450 needs_research (guide-feed 405 GET/POST), bl-451 ready (Radix focus-shim helper). All unchanged, all still open.
  • These are now out-competed by a newer, more urgent cluster (see §4): the content_items-drop residue (bl-205/215/455/495) and the Coolify/pipeline items (bl-346/368/224/227/441/444/475). 56 ready backlog items total.

3. id-127 tail (was 30/36): PARTIALLY SUPERSEDED — see §2 for the close-out path.

  • No id-127 subtask journaled since ~2026-07-09; statuses are as at S462 except the content_items-removal wave ({127.25}-{127.33},{127.36}) that was already landing at S456-458 is all done.
  • The webhook-completion / stuck-pipeline_runs fix that S462 said “unblocks {127.34}” did NOT land (git log since 2026-07-11 has no webhook/pipeline_runs/cron-secret fix). Still live under {127.18}.

4. id-137 / id-143 / id-142: STILL-VALID (all unchanged).

  • id-137 pending (worktree-isolation leak root-cause). id-142 pending (pipeline-run actor capture / GDPR — TECH+PLAN tier). id-143 in_progress with {143.2} pending = “Adjudicate prod↔staging row-count divergence” — the owner/ops decision the S462 prompt said to surface. Unchanged.

5. Spine toward ID-45: TWO of three preconditions now SATISFIED; a NEW pre-{45.3} step appeared.

  • (a) ingestion_source / OQ-45-1: RATIFIED — cv13, per Liam, S377 ({45.1} journal). The later “NOT ratified/PENDING” note was itself superseded. Strike the “Liam residual” framing — it is settled. ✅
  • (b) ID-145 DDL batch landed: NOW SATISFIED — the W1 M1-M6 form-first cutover is merged (37011f49). ✅
  • (c) explicit Liam GO: still outstanding.
  • NEW since S462: {45.3} TECH and {45.4} PLAN still do not exist as subtasks. id-45 gained {45.8} “Re-baseline PRODUCT.md keep-set filter (post-M6 + DR-025 R4) pre-{45.3}” (no work yet), plus new scope {45.9} client OKF bundle production, {45.10} new-client-deploy ontology-seeding runbook, {45.11} entity-canonicalisation dedupe. So {45.3}/{45.4} authoring is now gated on {45.8} + Liam GO (not the DDL, which is done).

6. {128.3} cocoindex go-live-tier adjudication: STILL-VALID (in_progress).

  • {128.3} journal (2026-07-11): two failure classes confirmed — STALE-SCHEMA assertions (reconcile to OKF grains) + TIMEOUT-CLASS (walk-triggering tests serialise behind the writer fence / cold-model latency blows 120s budgets). Next step is the per-file go-live ruling. NB many stale-schema failures will now read differently post-M6/form-first.

1. {71.32} four-layer eval sync: code side LANDED, subtask still pending → now CLOSEABLE.

  • Commit c28ee957 “four-layer FC-95 eval sync” IS in the log since 2026-07-11; its precondition id-131.19 is done. Remaining work is only the PRODUCT.md B-INV-4 five→four-layer docs edit + close. (S462 prompt cited “c28e957”; actual c28ee957.)

2. {71.29}/{71.30}/{71.31}: STILL-VALID (all pending, unchanged). Post-trim drift cleanup; {71.30} create_content_item enum→CONTENT_TYPE_VALUES; {71.31} get_reorientation TE-05 token-budget breach.

3. Goose {71.26}/{71.27}: STILL-VALID (both in_progress, pilot-gated). G4 unblock + OQ-71.26-COST remain Liam decisions.

4. New impl requirements (agent_runs telemetry, ID-138 vs id-71): no movement observed.

5. completing-forms (WS-9): now OPENABLE. {145.2} PRODUCT is done and DR-075 settles the form-first id contract ([id] = form_instances.id), which was the gate the S462 prompt set for opening this as its own Task.


Remaining subtasks and what each needs:

SubtaskStatusDisposition / what it needs
{127.18} CRON-secret splitin_progressThe real remaining defect. Its diagnosis lane owns the stuck-pipeline_runs/completion-webhook bug: each /walk writes a start row (in_progress, never updated) + a separate completion row; suspect the webhook emits run-start and run-complete as independent INSERTs. No fix landed since S462. Fix shape: correlate on requestId/op_id (UPDATE the start row) or stop emitting the start row.
{127.20} private ingress gatependingTask-close blocker. Unblocked at S456 (DR-042..046 ratified: Cloudflare Tunnel + Access default). Now dispatchable infra: tunnel + Access token, nameserver move (owner OQ-5), /health monitor retirement.
{127.24} flow.py content_items mount verify/repairpendingSUPERSEDED — mark done/superseded. {127.25} (done, keystone) removed the flow.py content_items row-mount and {127.26}-{127.32} cleared the fallout (full pytest green). {127.24} was the verify/repair that the 25-33 wave executed.
{127.34} reset route:forms manifest + prove prod walkpendingSUPERSEDE (per owner manifest correction). Manifest reset was PROVEN on prod at S457 (stale route:"forms" file corrected + removed). Forms no longer walk — id-136 retired the "forms" route (now a hard ManifestLoadError); id-134 + id-145 reframe the corpus shape (forms = manual upload, DR-014). “Prove a completed prod forms walk” is moot. Residual webhook-completion concern → {127.18}. Full manifest retirement (owner: forms was “the only remaining reason”) is a separate planned item (with id-131 qa_sidecar + the {45.3} prefix-freeze; bl-368 renames the constant kh→ca).
{127.35} Coolify env-vars reveal-scope runbook notependingTrivial doc note, no journal, no blocker. Cheap close (lands in docs-site live-ops runbook).
{127.19} secret-rotation runbookdeferredStays deferred. Owner answered: no rotation requirement (S455). Runbook authored to scratch; lands in docs-site runbooks/secret-rotation.md when a rotation trigger arises.

Net: id-127 closes on {127.18} (webhook-completion — real work) + {127.20} (private ingress — the hard task-close blocker) + {127.35} (doc note); with ledger dispositions for {127.24}→done/superseded, {127.34}→superseded, {127.19} stays deferred.

Manifest correction — how {127.34} reads today vs the truth

Section titled “Manifest correction — how {127.34} reads today vs the truth”
  • {127.34} title today: “Reset platform-prod stale route:forms pipeline route-tag manifest (.kh-workspace-map.json) + prove a completed prod walk.” Framed as unblocked-by-the-webhook-fix.
  • Corrected framing: id-134 (done) reframes the corpus shape / release gate; id-136 (done) retired the corpus "forms" route (forms = app-side manual upload) — this removed the only route the manifest served for forms; id-145 (in_progress, merged) resolves the form-first re-architecture. The pipeline-side manifest still exists (flow.py, server.py, workspace_resolver.py) but now serves only content + qa_sidecar routes; route:"forms" fails loudly. So {127.34}‘s objective is spent — SUPERSEDED, not “fix webhook then prove a walk.”

  • Pause reason is CLEARED. S462 paused id-128 excl {128.3} “pending the procurement-domain overhaul; the procurement track owns e2e reconciliation” ({128.14} journal 2026-07-11). id-145 has now landed the form-first UI + e2e reconciliation ({145.23} close-gate, {145.49} nightly triage). So {128.14} “e2e suite reconciliation for the IMS surface removal” is RESUMABLE (re-baseline against the post-overhaul UI).
  • New subtasks since S462: {128.18} staging E2E data-debris teardown gap, {128.19} qa-library checkbox flake, {128.20} racy id138-writer-fence test, {128.21} scope claim_next_job so CI test-doubles can’t intercept live Platform-staging jobs.
  • {128.21} state: pending, no journal yet. Dispatchable any time (S481 prompt item 4 — un-races all future live queue smokes vs CI; precedent {128.20}; its migration must follow DR-081 stamp discipline).
  • {128.3} cocoindex nightly lane: in_progress, the go-live-tier adjudication (see §1.6). {128.10} in_progress “ephemeral Supabase branch per run” needs cost/time RATIFY first. {128.17} deferred.

§4 New-since-S462 constraints the next main-track session MUST honour

Section titled “§4 New-since-S462 constraints the next main-track session MUST honour”

Baseline / merge state

  • Procurement baseline MERGED (37011f49) — id-145 form-first W1 M1-M6 DDL cutover is on the main line: content_items dropped, form_templatesform_instances rename, workspace tier retired, [id]=form_instances.id. id-145 is 49/51 (only {145.23} close-gate + {145.49} nightly triage remain, both e2e). id-147/156/161 also closed in the same merge.
  • Coolify platform pipeline apps clone compose from main (both apps git_branch=main). Compose changes need a main PR (surgical-PR pattern, PR #120 precedent); the image may deploy from a track ref per DR-080. Prod bid-worker heals (polls for the first time ever) at the next prod pipeline deploy — no prod redeploy was forced at S481.
  • CNB entrypoint fix ({145.31}, PR #120 merged): the bid-worker had NEVER polled anywhere; fixed on main + staging redeployed; poller verified live. Worker NEXT_PUBLIC_APP_URL stale-host fix applied.
  • .env.local SUPABASE_SERVICE_ROLE_KEY is DELIBERATELY DISABLED (Liam, cost control — daily classification was running on platform staging). Value is correct — do NOT rotate/“fix”. Local e2e global-setup/teardown + any service-key script vs staging fail with Unregistered API key; CI secrets unaffected. Re-enable is Liam’s call.
  • bl-492: Coolify compose apps must always redeploy, never bare-restart (env-injection gap). Doc intent owed to onprem runbook.
  • DB migration state (S481): both Platform DBs — staging is AHEAD of prod by the api-views migration; prod convergence rides the next owner-gated batch push. (Was staging 20260716214500 / prod 20260716140000; may have advanced with the merge.)

Decision register (new entries)

  • DR-075 (S474) — procurement procurement/[id]/* re-keys form-first; templates/[templateId] sub-collection retires; [id]=form_instances.id.
  • DR-076 (S478) — q_a_pair verify audit → generalised polymorphic verification_history.
  • DR-077 (S477) — create-initiative is minimal CLI + server, no UI create surface.
  • DR-078 (S477, renumbered from DR-076 at S479) — substrate_doc kept, optional, must resolve from the docs-site repo root.
  • DR-079 (S479) — OKF bundle doctrine: four bundle classes, two production paths. Non-client bundles run on OpenRouter GLM-5.2; client bundles stay Anthropic.
  • DR-080 (S480) — staging pipeline gate-runs may deploy from a feature-track ref (workflow_dispatch --ref <track>, staging scope only); NEVER merge a track into the staging branch ahead of main (deploy branches sync FROM main).
  • DR-081 (S481) — two entries share this number (register housekeeping defect — flag it): (a) A19 confidence reserved-value policy — producer emits strong|partial only, deterministic (strong iff per-row anchor AND ≥2 record-anchor citations); (b) migration-stamp discipline on the shared staging DB — allocate against the REMOTE supabase_migrations.schema_migrations, verify by object existence (to_regclass), non-round time-anchored stamps, adopt-don’t-repair on cross-lane version presence.
  • DR-082 (S481) — OKF ontology IRI namespace authority = https://w3id.org/canonical/ontology. A one-time w3id GitHub PR registering /canonical/ is an owner prereq before the FIRST published client-bundle mint.

Tooling / ledger surface

  • id-148 DONE: roadmap/umbrella verb-surface RETIRED; initiatives ledger CLI verbs live (create/update/link/move project+initiative; product-roadmap.json→server-managed initiatives.json).
  • id-156 DONE: ledger QoL incl the journal-search cross-task journal verb (now available on main — read-only, bounded).
  • id-160 DONE: ledger-server spawn source hardened (refuse symlinked/drifted spawn source; real tag-pinned clones).
  • id-132 grew to 44 subtasks (was 29/30 at S462) — the OKF bundle-doctrine wave (DR-054/055/060/079/082): concept-frontmatter routing hints + A19 confidence, IRI projection, memo-delta, context.jsonld, platform/client overlay discriminator. {132.35} G-DEPLOY-PROOF is in_progress — deploy the producer flow to the VPS pipeline + prove BI-18 delta-only determinism; this is the active pipeline/Coolify-touching item (recent HEAD commits 86c7bb08/45b9e55f are its slices). Coordinate with id-127 pipeline work. {132.36}/{132.39} pending.
  • GitNexus index stale (~15+ commits behind) — run bun run gitnexus:analyze before a code-heavy wave.

content_items retirement residue (coherent cleanup cluster — new priority):

  • bl-495 “Scripts still query the dropped content_items table — broken at runtime” (already surfaced as a live task), bl-455 “content_items vocabulary/reference retirement — repo-wide residual sweep”, bl-215 “eval-procurement-drafting reads dropped column cited_items”, bl-205 “Perf advisory: partial index on content_items sentinel rows” (now moot — the table is gone). bl-368 “Rename cocoindex workspace-manifest constant kh→ca (.ca-workspace-map.json)” (manifest still present).

§5 What the next main-track continuation prompt should say DIFFERENTLY

Section titled “§5 What the next main-track continuation prompt should say DIFFERENTLY”
  • Drop the “coordinate with the procurement track” framing entirely. The procurement baseline is MERGED (37011f49). id-145 is effectively closed (49/51; residual is two e2e items on the close-gate). Rebase the whole “spine waits on ID-145 DDL” section — that gate is satisfied.
  • {127.34} → SUPERSEDED, not “webhook-fix unblocks it.” Manifest reset done on prod S457; forms don’t walk. Re-home the webhook-completion defect explicitly under {127.18}. Note full manifest retirement is a separate future item (id-131 qa_sidecar + {45.3} freeze; bl-368).
  • {127.24} → done/superseded (the content_items-removal wave {127.25}-{127.33} did it).
  • Spine preconditions: mark (a) ingestion_source ratified — strike “Liam residual”; mark (b) ID-145 DDL landed. Replace them with the real remaining gates: {45.8} (re-baseline PRODUCT.md keep-set post-M6/DR-025-R4) then {45.3}/{45.4} authoring + Liam GO. Note the new {45.9/10/11} scope (client bundle, deploy runbook, dedupe pass).
  • id-135 {135.28}: strike the “relabel may be the right fix” hedge — id-145 LANDED; re-baseline onto engagement groups (workspace tier retired). Flag the {135.25}↔id-145.35 surface drift.
  • id-128: stop describing it as “paused excl {128.3}” — the pause reason (procurement overhaul) is cleared; {128.14} e2e reconciliation is resumable and {128.21} is dispatchable now. Enumerate new subtasks {128.18}-{128.21}.
  • Track C: {71.32} is now closeable (code c28ee957 landed, id-131.19 done — only the PRODUCT.md B-INV-4 docs edit remains). completing-forms (WS-9) is now openable ({145.2}/DR-075 settled the form-first id contract).
  • Add a “new constraints” block carrying: SUPABASE_SERVICE_ROLE_KEY disabled (don’t rotate), Coolify compose-clones-from-main + always-redeploy-never-restart (bl-492), DR-078..082, the DR-081 stamp discipline, staging-ahead-of-prod migration state, GitNexus-stale.
  • Re-point the backlog focus: the S462 bl-449/450/451 trio is stale-priority; lead with the content_items retirement cluster (bl-495/455/215/205) and the Coolify/pipeline items (bl-346/368/224/227/441/444/475).
  • Housekeeping to flag: the DR-081 numbering collision in the decision register (two DR-081 entries) needs a renumber.
  • id-132 is now a live pipeline-touching track ({132.35} VPS producer deploy in_progress) — the next main-track session should coordinate id-127 pipeline hardening with the id-132 producer-deploy lane rather than treating id-127 pipeline as sole owner.