Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
24 commits
Select commit Hold shift + click to select a range
d5c8161
docs(plan): Branch 4 upstream watch live code-level plan
pacphi Sep 27, 2026
520b361
feat(upstream): split lastCheckedAt from conformance-verified dates (…
pacphi Sep 27, 2026
72c5c01
feat(upstream-watch): read fixing pull requests and tag containment
pacphi Sep 27, 2026
d91f263
feat(upstream-watch): confirm releases from the merged fixing change
pacphi Sep 27, 2026
f374412
feat(upstream-watch): count AgentDB fixes released only when Ruflo bu…
pacphi Sep 27, 2026
9203a4a
feat(upstream-watch): record the ledger issue pacphi/agentic-kit#243
pacphi Sep 27, 2026
b641f09
feat(upstream-watch): let a reviewed thread leave the reply queue
pacphi Sep 27, 2026
1b0c619
feat(upstream-watch): register every upstream thread user-facing docs…
pacphi Sep 27, 2026
29f93df
chore(upstream-watch): migrate the #213 and #240 upstream remainder i…
pacphi Sep 27, 2026
64750a8
chore(upstream-watch): map, retire or query the three stale threads
pacphi Sep 27, 2026
08f8cea
docs(upstream-watch): record Branch 4 decisions and the live watch
pacphi Sep 27, 2026
8fad8e2
fix(upstream-watch): keep an AgentDB released line stable across Rufl…
pacphi Sep 27, 2026
f4af45f
fix(upstream-watch): name the first release not ruled out as unconfirmed
pacphi Sep 27, 2026
6e4722d
fix(upstream-watch): report a failed bundle resolution as could not c…
pacphi Sep 27, 2026
66976d7
refactor(upstream-watch): define the package and owner/repo patterns …
pacphi Sep 27, 2026
5b325df
fix(upstream-watch): start the release walk when the fixing change me…
pacphi Sep 27, 2026
2007194
fix(upstream-watch): look past the first five releases through the ne…
pacphi Sep 27, 2026
b6780df
fix(upstream-watch): keep the thread when its release confirmation fails
pacphi Sep 27, 2026
680f3cb
fix(upstream-watch): name #213 and #240 our tracking issues, not issu…
pacphi Sep 27, 2026
b498db8
fix(upstream-watch): keep the partial fix agentic-qe#719 from dispatc…
pacphi Sep 27, 2026
fefca3d
docs(upstream-watch): state that a reviewed line covers its whole UTC…
pacphi Sep 27, 2026
040f6b8
docs(upstream-watch): record that the watch runs on POSIX only
pacphi Sep 27, 2026
b38a886
docs(audit): record Branch 4's implementation status and open items
pacphi Sep 27, 2026
9bfb6d4
docs(upstream-watch): keep the previous checked-at when a thread coul…
pacphi Sep 27, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 8 additions & 5 deletions .agents/skills/upstream-status/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,17 +24,20 @@ dependency policies, constraints, and the `watch` list of upstream threads.
2. Give the counts first, in plain language, from `counts`. Leave out groups with zero items.
3. Then list the action items with their links, one report group at a time, in this order
(the report's group titles):
- "Could not check" first, each thread with its error from `fetchErrors`: nothing about it
is known;
- "Could not check" first, each thread with its error from `fetchErrors`. When the thread
itself could not be read nothing about it is known; when only its release could not be
confirmed, its other groups still hold;
- "Needs our reply";
- "Released and actionable";
- "Released, fix not confirmed": offer to confirm by hand and record `minVersion`; never
dispatch it;
- "Fixed upstream, ak still carries the workaround";
- "Reopened upstream after ak recorded a fix";
- "Closed upstream as not planned";
- "No upstream activity for the stale limit";
- "Ready to retire";
- "Constraints past their retest date";
- "Tracking issues to migrate".
- "Our tracking issues".

For each item give the id, title, URL and a one-line reason: who replied and when, which
release, or which ak change is pending. Give "Fixed upstream, not yet released",
Expand All @@ -52,8 +55,8 @@ dependency policies, constraints, and the `watch` list of upstream threads.
comment on the ledger issue, push, open a pull request or merge without the maintainer's
explicit confirmation of that specific action.
- Never merge a dispatch pull request. The maintainer merges.
- A "candidate" release is the first version published after the fix. Confirm the fix is in
it before dispatching.
- A release is actionable only when it contains the merged fixing pull request or commit
(`release.basis` says which). An unconfirmed release is never dispatched.
- Issue closure alone does not prove a fix (ADR-0041 §7).
- For events since a date, run `node scripts/upstream-watch.mjs check --since <iso-date>`.
Each line is a ledger line: `UPSTREAM-WATCH <id> <event> <date> …`.
Expand Down
13 changes: 8 additions & 5 deletions .claude/skills/upstream-status/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,17 +24,20 @@ dependency policies, constraints, and the `watch` list of upstream threads.
2. Give the counts first, in plain language, from `counts`. Leave out groups with zero items.
3. Then list the action items with their links, one report group at a time, in this order
(the report's group titles):
- "Could not check" first, each thread with its error from `fetchErrors`: nothing about it
is known;
- "Could not check" first, each thread with its error from `fetchErrors`. When the thread
itself could not be read nothing about it is known; when only its release could not be
confirmed, its other groups still hold;
- "Needs our reply";
- "Released and actionable";
- "Released, fix not confirmed": offer to confirm by hand and record `minVersion`; never
dispatch it;
- "Fixed upstream, ak still carries the workaround";
- "Reopened upstream after ak recorded a fix";
- "Closed upstream as not planned";
- "No upstream activity for the stale limit";
- "Ready to retire";
- "Constraints past their retest date";
- "Tracking issues to migrate".
- "Our tracking issues".

For each item give the id, title, URL and a one-line reason: who replied and when, which
release, or which ak change is pending. Give "Fixed upstream, not yet released",
Expand All @@ -52,8 +55,8 @@ dependency policies, constraints, and the `watch` list of upstream threads.
comment on the ledger issue, push, open a pull request or merge without the maintainer's
explicit confirmation of that specific action.
- Never merge a dispatch pull request. The maintainer merges.
- A "candidate" release is the first version published after the fix. Confirm the fix is in
it before dispatching.
- A release is actionable only when it contains the merged fixing pull request or commit
(`release.basis` says which). An unconfirmed release is never dispatched.
- Issue closure alone does not prove a fix (ADR-0041 §7).
- For events since a date, run `node scripts/upstream-watch.mjs check --since <iso-date>`.
Each line is a ledger line: `UPSTREAM-WATCH <id> <event> <date> …`.
Expand Down
117 changes: 83 additions & 34 deletions docs/UPSTREAM-WATCH.md

Large diffs are not rendered by default.

27 changes: 19 additions & 8 deletions docs/adr/0041-host-neutral-hook-configuration-assurance.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,11 @@

- **Status:** Accepted; static assurance, transactional healing, bounded receipts, and read model implemented
- **Date:** 2026-09-01
- **Updated:** 2026-09-26 — §7: the registry ships inside `src/`, holds the watched upstream
- **Updated:** 2026-09-27 — §7: schema 6 separates `lastCheckedAt` (state re-read) from
`lastVerifiedAt`/`nextRetestAt` (conformance); a release counts only when it contains the
merged fixing change; AgentDB fixes count when Ruflo bundles them; the guard covers
user-facing docs; the ledger is pacphi/agentic-kit#243
- **Earlier update:** 2026-09-26 — §7: the registry ships inside `src/`, holds the watched upstream
threads beside the constraints, and feeds the deterministic upstream watch, whose ledger is
read from the routine's and our logins' comments only
- **Earlier update:** 2026-09-09 — reconciled against repository source and tests for issue #211
Expand Down Expand Up @@ -199,23 +203,30 @@ does not prove a fix; an open issue does not by itself prove the installed versi
affected.

The same file is the only upstream registry. It ships beside its loader because the hook audit
reads it at runtime. Schema 5 adds a watch policy and a watch list: every upstream issue or
pull request ak filed, commented on, or cites in `src/`, `bin/`, `claude/` or `tests/`, plus
ak's own tracking issues that migrate into it. Each watched thread names its dependency, whose
reads it at runtime. Schema 6 holds a watch policy and a watch list: every upstream issue or
pull request ak filed, commented on, or cites in `src/`, `bin/`, `claude/`, `tests/`,
`README.md` or a top-level `docs/` guide (dated audits, proposals and research references are
exempt by name), plus ak's own tracking issues. Schema 6 also keeps two dates apart:
`lastCheckedAt` is the weekly state re-read (and the tests' clock), while `lastVerifiedAt` and
each constraint's `nextRetestAt` move only after a conformance run. Each watched thread names its dependency, whose
policy supplies the publication rule and the removal proof; what done means (closed as
completed or merged, and the release channel and first fixed version when known); the ak files
and plan references it affects; the adjustment ak makes; linked constraints; and dated history.
Every constraint with an issue has a watch entry naming it, and an invalid watch list makes the
whole registry invalid, for the hook audit too. A guard test fails when source cites a
watched-repository thread the list lacks.
whole registry invalid, for the hook audit too. A guard test fails when source or a user-facing
doc cites a watched-repository thread the list lacks.

A watched thread moves through `watching`, `fixed-unreleased`, `released`, `dispatched`,
`adopted` and `retired`. The deterministic `scripts/upstream-watch.mjs` (maintainer tooling,
not shipped) reads GitHub and npm and never writes. It reports replies we owe, released fixes
ready for ak, workarounds ak still carries, stale threads (no upstream activity for 90 days),
not-planned closures, retirement candidates, constraints past their retest date, and a registry
with nothing left to watch. Its ledger lines, `UPSTREAM-WATCH <id> <event> <date> …`, go to one
pinned, locked "Upstream watch" issue; the routine reads only its own and our logins' comments
with nothing left to watch. A release counts only when its tag contains the merged pull request
or commit that fixed the thread, or the registry records the first fixed version; a later
release it cannot prove is reported as "fix not confirmed" and never dispatched. AgentDB, which
ak gets through Ruflo, counts as released only when the newest Ruflo (npm `latest`) resolves to
a fixed agentdb. Its ledger lines, `UPSTREAM-WATCH <id> <event> <date> …`, go to one
pinned, locked "Upstream watch" issue (pacphi/agentic-kit#243); the routine reads only its own and our logins' comments
there, so an exact line it recorded is never acted on twice and nobody else can suppress one. Dispatch of a released
thread is a branch `upstream/<id>` and a draft pull request that makes the adjustment
test-first and passes the dependency's removal proof. It never merges. Publishing upstream
Expand Down
Loading
Loading