Skip to content

Enforce literal substrate convergence - #1705

Open
4444J99 wants to merge 12 commits into
mainfrom
feat/omega-substrate-literal
Open

Enforce literal substrate convergence#1705
4444J99 wants to merge 12 commits into
mainfrom
feat/omega-substrate-literal

Conversation

@4444J99

@4444J99 4444J99 commented Jul 31, 2026

Copy link
Copy Markdown
Member

Summary

  • add the recursive, bidirectional Workspace manifest court with repository, private-custody, compatibility, ephemeral-lifecycle, and residue enforcement
  • query live origin custody, audit every local branch, stash, ignored payload, and sealed inventory, and fail closed on bounded unmeasured state
  • replace executable/config legacy path consumers with canonical substrate indirection while keeping declared bridge executables usable through cutover
  • preserve active doorway safety, reject compatibility cycles, and bind durable receipts to the canonical live Workspace identity
  • add the redacted live-state report and finite continuation contract; active sessions and private payloads remain protected

Verification

  • exact correction head: a854191
  • 42 substrate-convergence fixtures and 50 focused correction/path/reaper tests passed
  • full CLI suite: 4,650 passed, 2 skipped; API suite: 45 passed
  • full clone-reaper safety suite: 38 passed
  • mypy, Ruff, formatting, path-contract, validate, worker, and Python checks passed
  • scoped cheap wave passed 25/25 gates; the reproducibly bootstrapped web/schema production build passed
  • all 29 Limen review threads were replied to and resolved after independent verification, including all 22 prior and 7 second-wave findings
  • two final live receipt passes are byte-identical at SHA-256 0f2982e5b348b6db3df9353a0aa1020779d30efdacb63749438e4cfff4dded44

Live migration receipt

The implementation is ready; physical convergence intentionally remains red and owner-recorded. The current court records 42 manifest rows, 1 discovered canonical repository location, 3 compatibility paths, 4 private roots, 77 violations, and zero unmeasured state. No repository checkout or private payload is moved by this PR.

Merge condition

Merge only through the repository merge queue from this exact reviewed head after pr-gate is terminal green. The live red migration gates remain inputs to the separately receipted successor workstream; they are not represented as completed Omega convergence.

@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 31, 2026

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 143 files, which is 43 over the limit of 100.

To get a review, narrow the scope:
• coderabbit review --committed # exclude uncommitted changes
• coderabbit review --dir # limit to a subdirectory
• coderabbit review --base # compare against a closer base

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: d2bea846-1a64-4077-bd20-613b2f4247a3

📥 Commits

Reviewing files that changed from the base of the PR and between b81ca62 and 7911425.

⛔ Files ignored due to path filters (2)
  • container/manifest-extended.tsv is excluded by !**/*.tsv
  • container/manifest.tsv is excluded by !**/*.tsv
📒 Files selected for processing (143)
  • apps/vision-board-studio/photos-restore/2_build_gallery.py
  • cli/src/limen/capacity.py
  • cli/src/limen/cli.py
  • cli/src/limen/conduct/campaign_relay.py
  • cli/src/limen/dispatch.py
  • cli/src/limen/provider_health.py
  • cli/src/limen/repository_ignored.py
  • cli/src/limen/substrate_convergence.py
  • cli/src/limen/substrate_paths.py
  • cli/src/limen/work_loan_journal.py
  • cli/src/limen/worktree_debt.py
  • cli/src/limen/worktree_layout.py
  • cli/src/limen/worktree_receipts.py
  • cli/src/limen/worktree_roots.py
  • cli/tests/test_agent_state_tree_pipeline.py
  • cli/tests/test_always_working.py
  • cli/tests/test_campaign_relay.py
  • cli/tests/test_campaign_relay_effector.py
  • cli/tests/test_capacity.py
  • cli/tests/test_cartridge_connected.py
  • cli/tests/test_container_migrate_contract.py
  • cli/tests/test_continuation_beat.py
  • cli/tests/test_install_script.py
  • cli/tests/test_lead_spawn.py
  • cli/tests/test_overnight_launchd_runtime.py
  • cli/tests/test_reap_clones.py
  • cli/tests/test_reclaim_worktrees.py
  • cli/tests/test_substrate_convergence.py
  • cli/tests/test_substrate_paths.py
  • cli/tests/test_sync_reclaim.py
  • cli/tests/test_workstream_branch_prefix.py
  • cli/tests/test_workstream_command.py
  • cli/tests/test_worktree_debt.py
  • cli/tests/test_worktree_reap_command.py
  • cli/tests/test_worktree_roots.py
  • container/launchd/com.limen.claude-stub-heal.plist
  • container/launchd/com.limen.creds-hydrate.plist
  • container/launchd/com.limen.heartbeat.plist
  • container/launchd/com.limen.overnight-watch.plist
  • container/launchd/com.limen.watchdog.plist
  • container/migrate.sh
  • container/rollback.sh
  • docs/continuations/omega-substrate-literal/README.md
  • docs/continuations/omega-substrate-literal/live-substrate-report.json
  • docs/continuations/omega-substrate-literal/migration-blockers.json
  • docs/continuations/omega-substrate-literal/workstream.json
  • docs/runbooks/workstream-kickstart.md
  • his-hand-levers.json
  • ianva/src/ianva/cli.py
  • ianva/upstreams.example.json
  • install.sh
  • institutio/governance/gates.yaml
  • institutio/governance/parameters.yaml
  • institutio/governance/private-substrate-custody.json
  • mcp/src/limen_mcp/server.py
  • organs/media/scheduler/social_scheduler.py
  • pillars.yaml
  • scripts/agent-board-log-review.py
  • scripts/agent-code-review-queue.py
  • scripts/agent-reconstruction-review.py
  • scripts/agent-session-full-stack-review.py
  • scripts/agy-clock.py
  • scripts/always-working.py
  • scripts/append-tasks.py
  • scripts/async-run-one.py
  • scripts/autonomy-governor.py
  • scripts/board.py
  • scripts/capture-session-claim.py
  • scripts/capture.sh
  • scripts/cartridge-connected.py
  • scripts/cells.sh
  • scripts/check-correspondence-terminal.py
  • scripts/check-live-checkout.py
  • scripts/check-mail-answered.py
  • scripts/check-main-green.py
  • scripts/check-substrate-paths.py
  • scripts/clone-maintenance.sh
  • scripts/codex-token-accounting.py
  • scripts/consolidation-owner-rewrite-apply.sh
  • scripts/consolidation-transfer-apply.sh
  • scripts/continuation-beat.py
  • scripts/converge-organ.py
  • scripts/corpus-converge.py
  • scripts/current-session-fanout-plan.py
  • scripts/deploy-corpus-organs.sh
  • scripts/dispatch-async.py
  • scripts/dispatch-parallel.py
  • scripts/done-session-orient.sh
  • scripts/drain.sh
  • scripts/emit-tick.py
  • scripts/evocator.py
  • scripts/gen-launchd-plist.sh
  • scripts/harvest-pull-completed.py
  • scripts/heal-board.py
  • scripts/heal-dispatch.py
  • scripts/heal-hook-drift.sh
  • scripts/heartbeat-loop.sh
  • scripts/heartbeat.sh
  • scripts/hooks/worktree-commit-guard.sh
  • scripts/horrevm-custody.py
  • scripts/ingest-backlog.py
  • scripts/jules-land.py
  • scripts/jules-quota.py
  • scripts/jules-supply.py
  • scripts/lead-spawn.py
  • scripts/ledger.sh
  • scripts/library-preserve.py
  • scripts/mail-beat.sh
  • scripts/media-atomize.py
  • scripts/metabolize.sh
  • scripts/open-streams.sh
  • scripts/reap-branches.py
  • scripts/reap-clones.py
  • scripts/reap-remote-branches.py
  • scripts/reclaim-generated-caches.py
  • scripts/reclaim-generated-state.py
  • scripts/reclaim-worktrees.py
  • scripts/reconcile-closeouts.py
  • scripts/refresh-web.sh
  • scripts/resolve-codex-family-batch.py
  • scripts/resolve-legacy-session-batch.py
  • scripts/route.py
  • scripts/run-pytest-hermetic.sh
  • scripts/saturate.sh
  • scripts/self-heal.py
  • scripts/shims/claude
  • scripts/start-worktree-session.sh
  • scripts/substrate-convergence.py
  • scripts/substrate-storage-pressure.py
  • scripts/sync-release.sh
  • scripts/tests/allow-trusted-cd-git.test.sh
  • scripts/tests/test_worktree_preserve_dirty.py
  • scripts/tests/verify-resolver.test.sh
  • scripts/tests/worktree-pr-receipts.test.py
  • scripts/usage-telemetry.py
  • scripts/verify-dispatch.py
  • scripts/verify-fable-gate.sh
  • scripts/verify-hot-cache.sh
  • scripts/vltima-absorb-cadence.py
  • scripts/watchdog.py
  • scripts/worktree-pr-receipts.py
  • scripts/worktree-preserve-dirty.py
  • spec/contracts/workspace-manifest-v1.schema.json

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

Multi-agent review roll call
@codex review

(CodeRabbit and Claude review automatically. Reviewers: post substantive findings only. Authors/agents: address every thread, push fixes to this branch, reply and resolve, then re-request review.)

@chatgpt-codex-connector

Copy link
Copy Markdown

To use Codex here, create a Codex account and connect to github.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b4ee52d699

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread cli/src/limen/substrate_convergence.py Outdated
Comment thread cli/src/limen/substrate_convergence.py Outdated
Comment thread cli/src/limen/substrate_paths.py
Comment thread cli/src/limen/substrate_convergence.py Outdated
Comment thread cli/src/limen/substrate_convergence.py
Comment thread cli/src/limen/substrate_convergence.py Outdated
Comment thread cli/src/limen/substrate_convergence.py Outdated
Comment thread container/launchd/com.limen.heartbeat.plist
Comment thread scripts/substrate-convergence.py Outdated
Comment thread cli/src/limen/substrate_convergence.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0b13a8cf9d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread install.sh
Comment thread cli/src/limen/substrate_paths.py
Comment thread cli/src/limen/substrate_convergence.py
Comment thread cli/src/limen/substrate_convergence.py
Comment thread cli/src/limen/substrate_convergence.py
Comment thread scripts/substrate-convergence.py
Comment thread cli/src/limen/substrate_convergence.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f77931aa67

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/continuations/omega-substrate-literal/README.md Outdated
Comment thread cli/src/limen/substrate_convergence.py Outdated
Comment thread cli/src/limen/substrate_convergence.py
Comment thread scripts/substrate-convergence.py Outdated
Comment thread cli/src/limen/substrate_convergence.py Outdated
Comment thread cli/src/limen/substrate_convergence.py
Comment thread cli/src/limen/substrate_convergence.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a8541912f1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +1039 to +1042
if candidate.get("restoration_passed") is True
and _copy_count(candidate.get("copy_count", 0)) >= 2
and candidate.get("independent_physical_devices") is True
),

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bind restoration receipts to the sealed inventory

When a custody label has an older successful restoration receipt and the inventory is subsequently replaced or resealed under the same label, this check still accepts the old receipt because it validates only the three booleans/count and never compares the emitted inventory_sha256, plan_sha256, or content identity with the sealed inventory. The court can therefore authorize moving a private root without proving that either restored copy covers the current inventory; require the receipt to cryptographically identify the inventory and plan being approved.

AGENTS.md reference: AGENTS.md:L326-L327

Useful? React with 👍 / 👎.

Comment on lines +581 to +586
violations.append(
Violation(
"undeclared_nested_repository",
f"{manifest_path}/{rel}",
"nested checkout is not a registered Git submodule; use the canonical "
"Workspace row or runtime/worktrees",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Reconcile the court with the mandated worktree launcher

Fresh evidence after the prior thread is that this exact tree still sets wt="$repo/.worktrees/$slug" in scripts/start-worktree-session.sh:610, while this branch classifies the resulting worktree's .git file as an undeclared nested repository. Thus every capsule created through the repository-mandated launcher makes convergence fail by construction; place launcher worktrees under the declared ephemeral root or explicitly recognize that sanctioned location.

AGENTS.md reference: AGENTS.md:L396-L400

Useful? React with 👍 / 👎.

Comment thread scripts/substrate-convergence.py Outdated
Comment on lines +35 to +36
configured = os.environ.get("WORKSPACE_ROOT", str(Path.home() / "Workspace"))
return Path(os.path.abspath(os.path.expandvars(configured))).expanduser()

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Expand a tilde before canonicalizing the live root

When WORKSPACE_ROOT is exported as a literal tilde path such as ~/Workspace, audit() correctly expands it, but this helper calls abspath first, producing a path like /current/dir/~/Workspace that expanduser() can no longer fix. A live audit is then marked workspace_root_is_canonical_live: false, and its receipt retains the unredacted local path instead of the canonical $WORKSPACE_ROOT identity; expand the user component before computing the absolute path.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 525b059525

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread cli/src/limen/worktree_layout.py Outdated
Comment on lines +129 to +131
namespace = root / "runtime" / "worktrees" / repository_storage_key(repo)
_validate_runtime_container(root, namespace)
return namespace / slug

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Register runtime worktrees with the lifecycle reaper

When this launcher creates a capsule for any repository outside the default Limen/Portvs set, the new $WORKSPACE_ROOT/runtime/worktrees/<repo-key>/<slug> location is absent from every default source in iter_worktree_targets(): the inventory scans legacy dispatch roots, repo-local .worktrees, and linked worktrees of only its registered repositories. Such capsules therefore never appear in debt reports or reclaim-worktrees.py, allowing stale worktrees to accumulate while the exact-zero lifecycle predicate reports success; enumerate this runtime root or register every launcher repository.

AGENTS.md reference: AGENTS.md:L388-L400

Useful? React with 👍 / 👎.

Comment thread cli/src/limen/worktree_layout.py Outdated
Comment on lines +59 to +64
hostname = (parsed.hostname or "").lower()
port = f":{parsed.port}" if parsed.port else ""
path_text = parsed.path.rstrip("/")
if path_text.endswith(".git"):
path_text = path_text[:-4]
identity = urlunsplit((parsed.scheme.lower(), f"{hostname}{port}", path_text, "", ""))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Normalize transport-equivalent origins before hashing

When an existing repository changes its origin between equivalent HTTPS and SSH forms, such as https://github.com/organvm/limen.git and git@github.com:organvm/limen.git, this preserves the scheme and produces different storage keys. The launcher then searches a new namespace for an already-existing slug and can fail because the expected branch remains checked out at the old path; canonicalize equivalent provider transports to one repository identity before hashing.

Useful? React with 👍 / 👎.

Comment thread cli/src/limen/capacity.py Outdated
Comment on lines +524 to +527
def _root() -> Path:
return Path(os.environ.get("LIMEN_ROOT", str(Path.home() / "Workspace" / "limen")))
return Path(
os.environ.get("LIMEN_ROOT", str(Path.home() / "Workspace" / "library" / "engine" / "organvm" / "limen"))
)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Derive capacity state from WORKSPACE_ROOT

When Limen runs from a non-default WORKSPACE_ROOT without an explicit LIMEN_ROOT—a supported configuration for direct, non-host-mutating installs—this helper still reads ~/Workspace/library/engine/organvm/limen/logs/usage.json. _load_usage() consequently returns an empty meter, so capacity_census() can classify depleted or rate-limited lanes using only stale board budgets; derive the fallback Limen path from WORKSPACE_ROOT, as the dispatch root helper already does.

Useful? React with 👍 / 👎.

Comment on lines +672 to +674
repo_common="$(git -C "$repo" rev-parse --path-format=absolute --git-common-dir)"
wt_common="$(git -C "$wt" rev-parse --path-format=absolute --git-common-dir)"
if [[ "$(cd "$repo_common" && pwd -P)" != "$(cd "$wt_common" && pwd -P)" ]]; then

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Reject symlinked worktree leaf paths

When the canonical slug path is a symlink to a linked worktree outside runtime/worktrees, these repository-identity and branch checks both succeed because git -C follows the symlink. The launcher then reports the path as reused and writes the capsule into the external target, bypassing the physical-container validation performed only for the namespace; reject a symlinked $wt and verify its resolved top level is the canonical leaf before reuse.

Useful? React with 👍 / 👎.

Comment thread cli/src/limen/substrate_convergence.py Outdated
try:
if path.suffix == ".jsonl":
rows: list[Mapping[str, Any]] = []
for line in path.read_text(encoding="utf-8").splitlines():

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Bound custody ledger reads

When a referenced append-only custody JSONL grows large, this materializes the entire file with read_text().splitlines() and retains every parsed row, and _audit_private_custody() repeats that work for each private manifest row sharing the ledger. Such a ledger can make the aggregate convergence command consume unbounded memory and runtime despite its declared scan limits; stream with a shared byte/row/deadline ceiling and report excess as unmeasured state.

AGENTS.md reference: AGENTS.md:L436-L440

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7911425f8f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

fi
created="reused"
elif git -C "$repo" show-ref --verify --quiet "refs/heads/$branch"; then
git -C "$repo" worktree add "$wt" "$branch" >/dev/null

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Reuse legacy worktrees before adding the branch

Fresh evidence after relocating the launcher is that an existing pre-upgrade capsule still has work/<slug> checked out at <repo>/.worktrees/<slug>; the canonical target is absent, so this branch runs git worktree add for a branch Git refuses to check out twice and the mandated launcher cannot resume that capsule. Detect the branch's registered legacy worktree and migrate or reuse it during cutover.

AGENTS.md reference: AGENTS.md:L396-L400

Useful? React with 👍 / 👎.

min_age_h=min_age_h,
source=f"canonical-runtime-worktree:{namespace.name}",
)
for unit in units

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Reap empty repository namespaces

When the reaper removes the last <slug> from a canonical <repo-key> namespace, the empty namespace directory remains, but this inventory creates targets only for entries in units. The convergence court then emits ephemeral_empty_namespace, while subsequent reaper runs see nothing to remove, so normal accepted cleanup can never reach the required idempotent fixed point; explicitly own and remove empty physical namespaces.

AGENTS.md reference: AGENTS.md:L184-L187

Useful? React with 👍 / 👎.

def provider_outcome_ledger_path() -> Path:
root = Path(os.environ.get("LIMEN_ROOT", Path.home() / "Workspace" / "limen")).expanduser()
root = Path(
os.environ.get("LIMEN_ROOT", Path.home() / "Workspace" / "library" / "engine" / "organvm" / "limen")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Derive the provider ledger from WORKSPACE_ROOT

When a direct installation sets a non-default WORKSPACE_ROOT without exporting LIMEN_ROOT, this fallback still selects ~/Workspace/library/.../limen. Provider outcomes are consequently read from and appended to a newly created stale tree rather than the installed checkout, so dispatch can lose current cooldown and failure state; derive this fallback from WORKSPACE_ROOT, as the corrected capacity resolver does.

AGENTS.md reference: AGENTS.md:L194-L197

Useful? React with 👍 / 👎.

Comment thread scripts/lead-spawn.py
Comment on lines +139 to +140
if common.name != ".git" or not common.is_dir():
raise SpawnError("lead capsule does not share a primary non-bare Git checkout")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Resolve primary checkouts with separate Git directories

When a lead capsule belongs to a valid non-bare checkout created with git init --separate-git-dir, --git-common-dir names that external administration directory rather than a directory literally named .git. This check therefore rejects the lead before it can spawn a battle, although the previous repo-local layout worked for such checkouts; derive the primary worktree from git worktree list --porcelain and verify its common-directory identity instead of assuming the basename.

Useful? React with 👍 / 👎.

for line in proc.stdout.splitlines():
_, _, value = line.partition(" ")
if value.strip():
result.add((repo / value.strip()).resolve(strict=False))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Validate declared submodules against index gitlinks

When .gitmodules names a path that is not actually a mode-160000 gitlink in the repository index, this code still exempts any nested .git found there. A stale or fabricated declaration can therefore hide an ad-hoc clone from undeclared_nested_repository—including unique commits the outer repository's custody checks never inspect—and let convergence authorize cleanup without proving that nested state is remote-preserved; only exempt paths verified as current index gitlinks.

AGENTS.md reference: AGENTS.md:L301-L305

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 03c0046624

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +1135 to +1136
violations.extend(_audit_local_branch_custody(repo, row.path, remote_refs))
violations.extend(_audit_stash_custody(repo, row.path, remote_refs))

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Audit all local refs before accepting repository custody

When a declared checkout has a unique commit reachable only from refs/tags, refs/notes, or the reflog—for example after resetting a branch while retaining a local tag—the report can still be green because this audits only local branches and stashes. The repository's own scripts/reap-clones.py:273-285 treats those namespaces and --reflog as local-only data-loss sources; cleanup authorized by this report can therefore discard the objects. Compare every local ref and reflog object with the freshly fetched origin refs before accepting custody.

AGENTS.md reference: AGENTS.md:L301-L305

Useful? React with 👍 / 👎.

Violation("repository_custody_missing", row.path, f"live custody ref is absent: {custody_ref}")
)

status = _run_git(repo, "status", "--porcelain=v1", "--untracked-files=all")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Bound repository-status output before buffering it

When a repository has a very large untracked or ignored tree, these status probes bypass ScanBudget; local git status -h confirms that --untracked-files=all enumerates untracked files and --ignored=matching includes ignored entries, while _run_git uses capture_output=True and buffers the complete stdout. Thus max_scan_entries does not bound memory or subprocess output, and the aggregate court can be killed before producing its receipt. Apply an output ceiling or use a bounded counting/streaming probe.

AGENTS.md reference: AGENTS.md:L436-L440

Useful? React with 👍 / 👎.

return creation_root.parent / "_limen-worktree-abandonment"
candidate = Path(ABANDONMENT_QUARANTINE).expanduser()
else:
candidate = xdg_data_home() / "limen" / "worktree-abandonment"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Keep quarantine on the source filesystem

When WORKSPACE_ROOT or a worktree root is on an external SSD while the default $XDG_DATA_HOME remains on the internal home volume, this new default always selects a cross-device quarantine. quarantine_path() then rejects it with cross-filesystem-quarantine-denied, so both generated-payload cleanup and orphan_quarantine_root() fail for exactly the external-substrate configuration the repository supports, preventing the reaper from reaching its fixed point. Derive a persistent quarantine on the source device or provide a safe same-device fallback.

AGENTS.md reference: AGENTS.md:L317-L325

Useful? React with 👍 / 👎.

violations: list[Violation] = []
if not (repo / ".git").exists():
return [Violation("repository_missing_git", row.path, "declared repository is not a Git worktree")]
top = _run_git(repo, "rev-parse", "--show-toplevel")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Audit every registered linked worktree

When a declared repository has a linked worktree outside the Workspace with dirty or untracked changes, this audit can still pass because git status is run only in the primary checkout; a local probe confirms the primary status remains empty while the linked worktree reports its modification. The repository's own scripts/reclaim-worktrees.py:958-963 treats registered sibling worktrees as a cleanup blocker, but this court never enumerates them, so moving or deleting the primary Git directory can strand the linked worktree's local state. Audit every git worktree list --porcelain entry or report it as unmeasured.

AGENTS.md reference: AGENTS.md:L388-L392

Useful? React with 👍 / 👎.

import re


_SCAN_ROOTS = (

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Include tracked agent settings in the legacy-path scan

After the compatibility doorway is removed, .gemini/settings.json:4 still launches the MCP server with uv --directory /Users/4jp/Workspace/limen/mcp, and .claude/settings.json:94 still falls back to $HOME/Workspace/limen. The new checker nevertheless reports zero findings because _SCAN_ROOTS omits both tracked settings directories, so the path gate can authorize a cutover that breaks Gemini MCP startup and Claude closeout outside a Limen checkout. Include these operational settings in the scan and migrate their commands to the canonical root contract.

Useful? React with 👍 / 👎.

@4444J99 4444J99 added the lifecycle:blocked Delivery intent exists but an explicit external or technical gate blocks it label Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lifecycle:blocked Delivery intent exists but an explicit external or technical gate blocks it

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant