← Handoffs

Repository · handoffs

Resolve D3's retention test conflict and finish the remaining BuildTestEmbedded audit reviews

View on GitHub ↗

id: hf-2026-09-23-drive-the-six-buildtestembedded-latent-bug-fix-prs-through-review-fixes-ci-and-merge-then-work-the-ten-queued-audit-candidates url: url://handoff/handoffs/hf-2026-09-23-drive-the-six-buildtestembedded-latent-bug-fix-prs-through-review-fixes-ci-and-merge-then-work-the-ten-queued-audit-candidates title: Correct restart fixture observations, then push and verify https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 summary: Resolve replacement-count and incomplete-test sensitivity findings, then push notes removal and watch one CI run. WIP 8cc328d remote verified; twelve-test restored/final gates first-pass green; combined guard removal 5 failed and 2 passed; PR unchanged at db051473. created: 2026-09-23T18:36:18.802Z completed: null dependencies:

Resolve D3's retention test conflict and finish the remaining BuildTestEmbedded audit reviews

Written 2026-10-02 20:19:02 UTC. RE-VERIFY everything below: gh pr view <n> --repo CodexCoder21Organization/<repo> --json state,mergeStateStatus,headRefOid,statusCheckRollup and git ls-remote. This lane refreshes only its assigned PR/branch rows; other shared snapshots are carried forward.

Mission

Owner request: "The BuildTestEmbedded project has had a LOT of severe bugs in the last few weeks, which went un-caught. I'm fairly certain there are more latent bugs hiding there. Think, are the tests comprehensive? Your goal is to add end-to-end integration tests which identify bugs (the tests should initially fail), and then fix the bug in the implementation. Merge your changes/fixes." Each fix follows: fail-first end-to-end test on main, fix, local targeted gate read from the attempt history in the --log XML (a retried test counts as failing), PR, CI (bld-build is the only required check), adversarial review plus test-comprehensiveness review on the final head, orchestrator final review, then enqueue.

State at pause (the owner asked to stop after in-flight work finished)

Merged in this effort (19): BuildTestEmbedded 1071, 1072, 1073, 1074, 1075, 1076, 1133, 1134, 1135, 1136, 1137, 1140, 1142, 1144, 1146, 1152, 1155, 1156, and BuildTestServerService 378. Merge queue empty.

Open PRs (none enqueued): | PR | Head | CI | Reviews | What remains | |---|---|---|---|---| | https://github.com/CodexCoder21Organization/BuildTestApi/pull/92 (getProjectionChanges failure/wait/close/additive-field/cursor contract in KDoc + README) | ee7f80f352eaa439230dab0706122de594697499 | bld-build green | doc review APPROVE on this head (two majors from the first round fixed); orchestrator final review clean | enqueue only (merge needs owner approval in the current mode) | | https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1158 (retire failed shard before deletion; do not recover queued-deletion assignments) | 8770c4b8e91ea5ea24d35946522e37eaec234b73 | one rebased-head CI run in progress; build-watchman 0.0.21 monitoring bld-build | test-comprehensiveness PASS and adversarial PASS; full evidence and open questions below | CI completion, supervisor final review, merge decision; delegate never enqueues | | https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1160 (repeated finalizeUpload returns the existing run via a durable per-run finalized record, instead of "Unknown upload session") | 13ff1d174f334adf1ae405de023dc7d5428a2ac1 | bld-build green (776/776/778/778) | NONE yet | reviews, final review, enqueue. It changes TWO existing assertions (finalizeUploadSealsSessionAndExcludesFinalizedAssemblyFromWatchdog:71 and closeAfterUploadAssemblyLastCheckRecoversQueuedRun), both pinned the old answer; review whether that is acceptable. Known gaps listed in its description. | | https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1148 (replaces a fixed 10 s latch wait in a test with an event wait) | a6ffb90f7 | green earlier | reviewed | ON HOLD: changes test timing behaviour; needs explicit owner approval. |

Follow-ups not started (each is its own small PR)

  1. README sentence for the journal (from the 1071 review, MINOR 15): a feed read released by close() before startup reconciliation finishes is served from the journal as last committed and can omit rows reconciliation had not appended; the next start includes them.
  2. Ownership-ledger minors from the 1073 reviews: remove leftover println("PROBE ...") lines in the H1/H2 tests; add a restart test for the gone mark written after an authoritative per-ID not-found; tests for the remaining untested decision-table rows (minors 15/22/23); replace the whole-ledger scan per deletion with an index by droplet ID.
  3. D3 candidate: CONFIRMED STILL OPEN by lane bte-audit-d3 below. Aged known-ID ownership pruning still strands an orphan after one omitted successful listing. The actual brief is briefs-2026-09-29/D3.md on the artifacts branch. Supervisor must resolve the conflicting existing retention test before the owner fix proceeds.
  4. Other audit candidates: per-data-directory RSA-2048 key generation cost (0.1-4.6 s), one unexplained dead SSH session, 17 *Main.kt launchers in src/, and the suite-wide fixed real-time-wait sweep (1343 of 2953 test files, 108 rated high; top ten in SW1-findings.md).

Settled designs (do not reopen)

  • Droplet ownership: per-attempt tokened droplet names; the run's own persisted record decides restart cleanup; gone marks only after provider-confirmed delete or authoritative per-ID not-found.
  • Journal: one durable repair-pending record, rate-bounded repair; close() never interrupts inside a publication; abandoned appends release waiters and never mark the journal unavailable.

Branches

All work is on remote branches. Implementation checkpoints: wip/G1o-red 352cdc852, wip/G1o-green e5c8e37a8, wip/G2o-red 8c94eadae, wip/G2o-green 13ff1d174, wip/G2o-green-candidate d91bbe8de (BuildTestEmbedded). Findings, briefs, lane table and the local test helper: https://github.com/CodexCoder21Organization/PlanRepository/tree/wip/bte-audit-artifacts-2026-09-23 under handoffs/artifacts/bte-audit-2026-09-23/ (last synced before this session's final lanes; the G1o/G2o/X2o/R92 findings live in the lane scratchpad and are summarized above and in each PR description).

Nothing was deployed or published by this effort.

Operational knowledge

  • Local targeted runs: prune tests/ to the selected scenarios before each run (a kompile run compiles every test file it can see); at most three concurrent runs on the shared box.
  • kompile retries failing tests automatically; always read the attempt history in the --log XML.
  • Enqueue with gh pr merge <n> --auto --squash --match-head-commit <sha>; watch with build-watchman 0.0.18 --to-merged.

Lane 000g review checkpoint — 2026-10-02 13:47 UTC

RE-VERIFY: this lane snapshot covers only https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1160. Earlier rows and other lanes are carried forward, not claimed freshly checked here. Use gh pr view 1160 --repo CodexCoder21Organization/BuildTestEmbedded --json state,headRefOid,statusCheckRollup and git ls-remote before acting.

Initial live PR remains OPEN at 13ff1d174f334adf1ae405de023dc7d5428a2ac1, five SUCCESS checks; no commits/comments in the last two hours at pickup. Rebased candidate locally onto main f60051a01790c543c081827bd70b1f1ac3abe052 (candidate 07e4677ac6a1b3e173ceff207c1e288491c46c76). The six changed/new PR tests are running locally under the shared compile lock; no verdict yet. No source fix or PR push yet.

Completed static test mapping and code review identified an open write-order question: the permanent origin record precedes the seal marker, while the lookup treats terminal status as sufficient to stop considering an upload open. Drafted a real marker-write-error/cancel/restart reproducer, a canceled-sealed-before-assembly guard, and a concurrent structured retry/archive/restart/delete scenario. These drafts await execution; the question is not reported as a proven defect. Required Testing Architecture sections, Engineering Philosophy, README, and handoff triage guidance were read.

New lane checkpoint SHA Contents / remaining
https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/000g-rev-bte1160-2026-10-02 632d14715d58570782a69c9d09a7a01272c49455 Existing PR implementation unchanged at original head, plus review/000g-rev-bte1160-findings.md. Continue local reproduction, then fix only demonstrated findings, targeted gate, PR push, one CI watch, and supervisor final review.

Nothing deployed, published, merged, enqueued, or completed by this lane. The older operational note about pruning tests is superseded for this lane by the user's no-test-deletion rule and shared flock .../scratchpad/local-build.lock requirement.

Lane 000f-rev-bte1158 review checkpoint — 2026-10-02 13:51 UTC

The standing operator instruction resumed review of https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1158. The earlier whole-effort pause is obsolete for this authorized review. https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1148 stays on hold; no lane may merge, enqueue, deploy, publish, or complete this handoff.

At pickup, the PR was OPEN at 8b7c784d295c405af0956bf8344524e79c72c1fd with five successful checks, last commit September 30 and no comments. Static test-comprehensiveness and adversarial review found no additional proven implementation defect. beginProvisioningAttempt does not read droplet IDs/IPs, and the only early return delegates to sharded recovery, whose pending-intent check runs before preflight and fan-out. pendingDropletIds scans persisted files directly before worker start.

The three new tests passed 3/3 on the first gate, and 3/3 on the pre-checkpoint repeat, all first attempts. The first review checkpoint is remote at a4bfa3fa72989db360ac22ae7312255e572f0f07. Main advanced while testing; the implementation has now been rebased again locally to 8770c4b8e91ea5ea24d35946522e37eaec234b73, and the unchanged tests with only the production fix removed, followed by the fixed 25-scenario neighbor gate, are awaiting the shared compile lock. The PR branch has not been pushed yet; its remote green head remains the pickup head.

Coverage questions (not reproduced defects): direct live enqueue-order assertions, retirement-record write failure, primary/all-shards queued, capped admission while deletion is held, and dynamic-dispatch variants. Also, the existing pending directory scan treats listFiles()==null as empty; a startup unreadable-directory scenario would be needed to establish whether other storage checks already fail loudly before reuse. No code or test change was guessed from those questions.

Repo Branch Remote head SHA PR Contents State
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/000f-rev-bte1158-2026-10-02 a4bfa3fa72989db360ac22ae7312255e572f0f07 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1158 Rebased implementation plus review-notes/000f-rev-bte1158.md; notes stay on WIP branch 3/3 targeted tests passed twice; fail-first and neighbor checks pending

Operational correction: this lane uses the shared local-build.lock for every local kompile invocation; it does not prune/remove tests, run spinners, raise deadlines, or submit concurrent remote runs. The prior three-concurrent-runs/prune guidance above is historical and superseded by the lane rules. gh pr edit failed on the retired projectCards field; authenticated REST PATCH with a JSON input file updated the PR body instead. report-challenge CLI automatically enqueues/merges, so the lane did not run it under its no-merge/no-enqueue restriction. Nothing was deployed or published by this lane.

Lane 000f-rev-bte1158 verified fail-first and pushed review — 2026-10-02 14:11 UTC

Removed only this PR's production changes from BuildTestEmbeddedService.kt, leaving the three new tests unchanged. On main 0e56b9d362ff1efeb9ddc18a0c77a0b59626148a, the two queued-intent tests each failed all three attempts: replacement count expected 1, actual 0. Marker-without-intent passed, as expected. This verifies the named mechanism: baseline recovery reused the still-live assignment despite the durable intent. The deletion latch forces the exact condition, independently of worker scheduling.

Restoring the fix on rebased implementation 8770c4b8e91ea5ea24d35946522e37eaec234b73 produced 25/25 passing neighbor scenarios, all first attempts with no retry history. Earlier green gates were 3/3 and 3/3, likewise first attempts. Static and runtime test-comprehensiveness review PASS for the stated public recovery change; adversarial review PASS with no additional proven defect. The earlier coverage/read-failure questions remain explicit unproved questions for the supervisor, not reasons to claim a new failure or silently shrink the review.

The PR branch was OPEN at its accounted head with no recent comments immediately before source comparison and push. It was pushed with --force-with-lease and git ls-remote confirms 8770c4b8e91ea5ea24d35946522e37eaec234b73. Its one CI run is in progress. Watchman gates on required bld-build and classifies the mature, consistently undispatched kotlin-build-ci-test suite as informational; no rerequest was made. The PR body contains WHY, handoff links, full fail-first evidence, both review verdicts, and the required final attribution. Nothing was merged, enqueued, deployed, published, or completed.

Repo Branch Remote head SHA PR Contents State
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/fix/recovery-never-reattaches-droplet-queued-for-deletion 8770c4b8e91ea5ea24d35946522e37eaec234b73 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1158 Rebased implementation, unchanged three tests, README recovery rules 25/25 first-attempt local gate; CI in progress; both reviews PASS

Exact current neighbor selectors are the original PR's 25 selectors. Full failure stacks and the selector list are being refreshed in review-notes on the WIP checkpoint branch after its mandatory pre-push gate. Both fail-first failures are ordinary AssertionErrors at the exact replacement-count assertion; no test timeout, iteration, assertion, or skip was changed. If CI finishes green, only supervisor final review and merge decision remain for this lane. The broader mission and the other PR rows remain as carried forward above.

Lane 000g-rev-bte1160 — review and correction, 2026-10-02 14:32 UTC

Only this lane's PR state is newly verified here; the Mission, earlier findings, other lane updates, branch rows, and follow-ups above are carried forward. https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1148 stays on owner hold.

PR / branch Current SHA Verification / remaining work
https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1160 5923da41b5b58bcde3f956db47b43dd41f0c0814 OPEN; rebased onto main 0e56b9d362ff1efeb9ddc18a0c77a0b59626148a; both reviews APPROVE after the proven gap was fixed; two local gates 21/21 without retries; one new CI run being watched. Supervisor must finish CI confirmation, final-review, and decide merge.
https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/000g-rev-bte1160-2026-10-02 ac15add8c9df887bdff2aa729afb79aca69cce3e Passing correction plus public-API tests and review evidence under review/; a final evidence checkpoint will follow.

OBSERVED: The original six tests pass on the implementation. Reversing only its production fix yields 1 PASS / 5 FAIL; each failure repeats on all three attempts, while the direct-submission guard passes. The added failed-seal test yields 2 PASS / 1 FAIL for its three-scenario review family, with the failing scenario repeating all three attempts.

The demonstrated mechanism: the origin record is written before the seal. When the seal write fails, the origin remains on an open upload; after cancellation the old status-based lookup falsely answers that upload as finalized. The correction requires either the seal marker or assembled archive independently of status, as well as the origin record. The deterministic test uses a real filesystem write failure, proves the upload remains writable, and requires the full terminal refusal before and after restart. Two companion tests cover a sealed cancellation before archive publication and eight concurrent structured retries through assembly, archive, restart, and deletion.

Test-comprehensiveness review: APPROVE on 5923da41b5b58bcde3f956db47b43dd41f0c0814. Read the required public-API and fail-first Testing Architecture guidance, Engineering Philosophy, and repository upload/lifecycle/recovery contracts. The missing failed-seal row now has a fail-first deterministic public-API test; adjacent lifecycle and concurrency paths pass the 21-selector gate.

Adversarial code review: APPROVE on the same head with these unproved, nonblocking questions retained: parent-directory fsync after origin rename (process restart is tested, power loss is not); leftover .writing file on origin-write failure; existing unreadable archived-record loading behavior. No speculative fix was added. README states that older sessions without origin records do not gain this response. The existing other-instance late-lock refusal remains covered; one coordinator per data directory is the documented configuration.

The PR description was refreshed with the mission and handoff links, mechanism, test evidence, and limits. gh pr edit failed with the Projects classic GraphQL deprecation error; a REST PATCH of the same body succeeded. The report-challenge skill was read, but its automatic merge-queue/merge workflow is excluded by this lane's no-merge rule; the tooling issue is recorded in the findings for the supervisor.

No merge, enqueue, deployment, restart, production route change, Maven publication, or handoff completion was performed. Earlier instructions to prune tests or run concurrent compiles are superseded for this lane by the no-delete rule and shared flock serialization.

Lane 000f-rev-bte1158 final handback — 2026-10-02 14:36 UTC

Test-comprehensiveness review PASS for the public recovery change; adversarial review PASS. No additional proven defect. The supervisor's moved-check concern is refuted: beginProvisioningAttempt and intervening code do not read droplet assignments; the early return enters the sharded path, which filters durable deletion intents before preflight. pendingDropletIds scans persisted files under intentLock before deletion-worker start. Full evidence, invariant table, open questions, required documents read, and baseline failure stacks are preserved in the remote review note below.

Both queued-intent reproducers failed all three attempts each with only the production fix removed (expected replacement 1, actual 0). Restored implementation passed 25/25 scenarios with no retries. Earlier fixed gates passed 3/3 twice. Total fixed executions: 31 passed, 0 failed, 0 retried. Baseline: 1/3 logical scenarios passed, 2 failed; six failed attempts across the two reproducers. The final documentation-only checkpoint repeat could not start: the shared flock wait expired after 1500 seconds, exit 1, empty log, zero tests executed. No lock was bypassed, test weakened, or timeout raised. WIP production/test content is byte-identical to the tested PR head.

The sole rebased-head CI run remains in progress at https://github.com/CodexCoder21Organization/BuildTestEmbedded/actions/runs/37017653614. At 14:32 UTC, all four shard jobs were in progress with no conclusion. Watchman's missing bld-build notice was checked against the workflow: the aggregate job needs all four shards, so it is not dispatched until they finish; shard durations remained within their historical range. This lane's watcher was stopped for handback without canceling CI or rerequesting checks. Supervisor must finish watching this one run, then perform final review and decide whether to merge. Do not call this head CI-green yet.

Repo Branch Verified remote SHA PR Contents / remaining
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/000f-rev-bte1158-2026-10-02 fc420a27b5aa518a6c30c4e3d2418d073e5d0b67 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1158 Exact tested PR implementation plus review-notes/000f-rev-bte1158.md and 25-scenario selector list; CI verdict and supervisor final review/merge decision remain. Earlier a4bfa3fa72989db360ac22ae7312255e572f0f07 row is the first historical checkpoint.

No local code change remains uncommitted. No deployment, publication, merge, enqueue, or handoff completion was performed. https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1148 remains on owner hold. Other lanes' rows and findings above are preserved from the latest shared body, not claimed freshly verified by this lane.

Lane 000g-rev-bte1160 — exit checkpoint, 2026-10-02 14:38 UTC

Preserve all other lane rows above; only this PR and branch are refreshed here.

  • https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1160 remains OPEN at verified remote head 5923da41b5b58bcde3f956db47b43dd41f0c0814. Final fetch/rebase left it unchanged. Both review verdicts APPROVE; two corrected local gates pass 21/21 with no retries.
  • CI confirmation remains: https://github.com/CodexCoder21Organization/BuildTestEmbedded/actions/runs/37020234735 is in progress. Watchman reports four shard checks pending and required bld-build not yet reported, with no buildtest run URL yet. The optional app's zero-run queued suites are also present on all sampled main commits; no rerequest was made. Supervisor should resume the existing run's watch, then final-review and decide merge.
  • Final durable evidence: https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/000g-rev-bte1160-2026-10-02 at e46f529cb4ec2c802b8a5c3e24cd3feeb59d84a0. Source and all added tests are included, plus review/findings, fail-first XML, thread dump, fixed/prepush XML, CI state, watch log snapshot, and PR description. Earlier checkpoint SHAs ac15add8c9df887bdff2aa729afb79aca69cce3e, 8634099fab783b9827006c296317a84a52e5c5c6, and 632d14715d58570782a69c9d09a7a01272c49455 remain in this branch's history.
  • Observed counts: original gate 6/6 PASS; review gap gate 2 PASS/1 FAIL, all three attempts failed; original production reversal 1 PASS/5 FAIL, all three attempts failed; corrected 21/21 PASS; post-rebase 21/21 PASS. Passing gates had no retries.
  • Delegate result INCOMPLETE solely because the single new CI run has not finished during the lane budget. Do not merge until CI and supervisor review are complete. No merge, enqueue, deployment, production restart/route change, Maven publication, or handoff completion occurred. PR 1148 stays on owner hold.

Lane bte-audit-readme documentation checkpoint — 2026-10-02 16:08 UTC

Follow-up 1 is implemented in https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1199. The Mission, historical chain, existing branch/PR rows, and other follow-ups above are preserved. This lane owns only the README sentence; it never merges, enqueues, deploys, publishes, or completes this handoff.

Source verification on main e04680a0429b5dad204adaa966fff19f7eedcd33: getProjectionChanges keeps its journal reference across the startup wait; stopProjectionChangeMaintenance sets stopping and signals waiters, interrupts outside publication, and joins maintenance. Reads served without a reset can use the last committed journal and miss not-yet-appended reconciliation rows. ProjectionChangeJournal.pageInternal separately rejects reset access when shutdown ends incomplete reconciliation. The existing projectionCloseDuringStartupAppendKeepsJournalAvailable test asserts the retained run A page and run B after next-start reconciliation. Current reset behavior is explicitly excluded by the added sentence. No source or test changes.

Repo Branch Remote head SHA PR What is on it State
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte-audit-readme-2026-10-02 802cae64f878cbca4ec77e1d01737c7e628bd94e https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1199 One README sentence for committed feed reads released by close during startup README-only diff and whitespace checks PASS; local unit tests 0 executed; one CI run being watched with build-watchman 0.0.21, gating on bld-build

Next for this lane: finish this one CI watch, then supervisor final review and merge decision. No additional CI submission or rerequest. No local compile was needed for the documentation-only change. Central documentation mentions concern execution/test infrastructure rather than this local feed lifecycle contract; no reflecting central-doc change needed.

Lane bte-audit-ledger-minors — first analysis checkpoint, 2026-10-02 16:16 UTC

OBSERVED: Source https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1073 is MERGED (2026-09-30T03:08:47Z) at 9f0d2833d98268caaa456cfcc46db036a087d61c. GitHub currently returns two coordination comments and no review bodies or inline comments. The linked artifacts branch's earlier R1073 reviews do not contain later minors 15/22/23; the supervisor has been asked for their location. Settled designs are retained.

A deletion index is conditional in this lane's brief. Assessment: not mechanical under current cross-manager and filesystem freshness behavior; multiple DropletManagers can share the directory with separate locks, and records can become unreadable or be pruned. No implementation index change is made. The record and API evidence is captured in review-notes/bte-audit-ledger-minors.md.

Repo Branch Verified remote SHA PR Contents / state
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte-audit-ledger-minors-2026-10-02 5eda98be58795df578eb54c439a273ad5bb62139 no PR yet Scope, invariant table and index assessment; probe-output cleanup and per-ID not-found restart guard are now in a local targeted gate under withlock.sh. No test verdict yet.

No merge, enqueue, deployment, publication, or handoff completion. Other lanes' rows and the Mission above are preserved; their historical state is not claimed freshly checked here.

Lane bte-audit-readme — final handback, 2026-10-02 16:43 UTC

Follow-up 1 delegate work is complete. Re-verify https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1199 and branch below before acting. Supervisor final review and merge decision are the only remaining steps for this lane; broader follow-ups 2–4 and all other lane rows are preserved above and remain outside this lane.

Repo Branch Verified remote head SHA PR Contents Verified state
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte-audit-readme-2026-10-02 802cae64f878cbca4ec77e1d01737c7e628bd94e https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1199 One README sentence documenting journal reads released by close during startup; no source/test changes Required bld-build and all four shards SUCCESS; build-watchman exited GREEN (0); documentation review PASS

Verified source on main e04680a0429b5dad204adaa966fff19f7eedcd33: feed reads keep their journal reference across startup waits; maintenance shutdown signals that wait and stops reconciliation outside publication. A read served without a reset can return the last committed journal without rows reconciliation had not appended. The next start includes them after reconciliation. Reset readiness separately rejects shutdown during incomplete reconciliation, so the sentence expressly qualifies reads needing no reset. Existing projectionCloseDuringStartupAppendKeepsJournalAvailable covers the retained page and next-start rows; existing incomplete-reset shutdown tests cover reset errors. No behavior changed since the premise in a way requiring a source fix.

Local validation: README-only diff and git diff --check PASS; local unit tests 0 passed / 0 failed / 0 executed (documentation-only lane). Separate documentation review found the wording consistent with ordinary page, reset guard, and next-start paths. The single CI run completed successfully: https://github.com/CodexCoder21Organization/BuildTestEmbedded/actions/runs/37031743442. The watcher's missing bld-build notice was explained by the workflow's needs: bld_test_shard; no rerequest or additional run was submitted. The documentation work took less than the small-lane target; waiting for the single full CI run extended total elapsed time.

Exit sweep: branch SHA confirmed with git ls-remote; no uncommitted files, stashes, or local-only commits. No local kompile invocation or build artifacts. No merge, enqueue, deployment, production restart/route change, Maven publication, or handoff completion by this lane. The watcher exited and is no longer running. Earlier checkpoints and all shared Mission/findings/branch rows remain carried forward rather than claimed freshly verified.

Ownership-ledger lane checkpoint — 2026-10-02 16:57 UTC

Follow-up2 now has https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201, OPEN at pushed/verified head db0514735e9b4b3491997cebc27543ef09893c9e. Local final gate12/12passed, no failed attempt; independent test-comprehensiveness findings addressed and separate adversarial reviewPASS (parent independently reviewed the two delegated minor22fixtures). Single PR CI watch is running; no merge/queue/deployment/publication/completion.

Repository Durable branch PR Head and state
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte-audit-ledger-minors-2026-10-02 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 db0514735e9b4b3491997cebc27543ef09893c9e; final local12/12PASS; CIpending

The earlier comments-only lookup was incomplete. The source PR DESCRIPTION has the exact remaining minors at its end:15 in-flight cleanup blocks readmission,22 ProvenAbsent/Refused while replacementpending,23 legacy name-only inside complete run. All four cells now have public-API guards. Seven new scripts include these cells, authoritative per-ID-not-found gone-mark persistence through two manager restarts/stale listings, and two extra incomplete-run settled-attempt cells. Probe output removed from five ledger scenarios. Stale-listing fixture strengthened with exact newer observation, later same-name peer discriminator, and release/join teardown. No production implementation, public interface, or persisted record format changed.

Conditional index item REFUTED as mechanical: record lookup freshness across manager instances sharing a directory, caller-supplied filesystems, unreadable records and pruning require an explicit freshness/invalidation contract. A cached droplet-ID index can miss another manager's published ID or retain a pruned/unreadable mapping; the settled scan remains under the lane's conditional authorization.

Local gates observed:6pass/0fail;6pass/2fail (new fixtures persistedPROVISIONING but expectedPENDING before resume; corrected the fixture precondition toPENDING with exact assertion unchanged);11pass/1compilefailure (new stale-listing assertion named an internal exception; corrected to full public error text); final12pass/0fail, no failed attempt. These were harness corrections, not production bugs. Next for this lane: let the single CI run finish, then supervisor final review and merge decision. Other lanes' mission, holds and rows above remain in force.

Ownership-ledger lane exit — 2026-10-02 17:23 UTC

Follow-up 2: remaining work is the existing CI run, followed by supervisor final review and merge decision for https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201. The lane's 75-minute work boundary is reached; no further submission is made.

Repository Branch PR Head / verified state
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte-audit-ledger-minors-2026-10-02 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 db0514735e9b4b3491997cebc27543ef09893c9e; OPEN; final local 12/12 PASS; CI shards 2 and 4 SUCCESS, shards 1 and 3 IN_PROGRESS

CI continuation: https://github.com/CodexCoder21Organization/BuildTestEmbedded/actions/runs/37037374721. Check page: https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201/checks. Required bld-build is not yet reported; no failing check observed at 17:21 UTC. The local watch process was stopped for exit; the workflow continues. Continue watching this same run, without a blind requeue.

All exact requested rows are covered: minor15 in-flight cleanup blocks readmission until original creation is resolved and deleted; minor22 ProvenAbsent and Refused attempts in a replacement-pending run; minor23 legacy name-only record inside a complete run. The exact text was found at the end of the source PR description. Gone marks following authoritative per-ID not-found survive two fresh manager generations and stale listings. Five probe-output scenarios were cleaned; stale-listing ordering, exact-ID ownership and failure teardown were strengthened. Independent test and adversarial reviews passed after findings were addressed, with parent review of delegated minor22 fixtures.

The optional droplet-ID index is REFUTED as mechanical, for the shared-directory manager, unreadable-record and pruning freshness reasons recorded above. Settled production behavior remains unchanged.

Full local counts: gate1 6 passed / 0 failed; gate2 6 passed / 2 fixture-status failures (persisted PROVISIONING vs expected PENDING; fixture corrected to ordinary PENDING admission with assertions unchanged); gate3 11 passed / 1 compilation failure (internal exception type in test; changed to exact public error text); final gate4 12 passed / 0 failed, no failed attempt. All code is committed and pushed, remote SHA verified, working tree clean. No merge, queue, deployment, artifact publication or handoff completion performed. Existing mission, prior findings, all other lane rows and owner holds remain in force.

Review lane rev-bte1201 — 2026-10-02 17:31 UTC

OBSERVED: Review of https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 found and removed the implementing lane session notes. Decision-row mapping is already in the PR description. Rebased onto main; no production change, README delta or build artifact remains in the diff. The cleanup checkpoint is committed and pushed, while the PR head remains db0514735e9b4b3491997cebc27543ef09893c9e until local gates pass and its existing CI run finishes. Twelve changed scenarios are queued for the first local run under the compile-slot helper. No local test verdict yet. No merge, enqueue, deploy, publication, or completion.

Repository Durable branch PR Head and state
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/rev-bte1201-2026-10-02 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 dcdb6287175282ecf2efd8f4a489056b6c501167; notes removal checkpoint; first local gate waiting for slot

Next: complete test-comprehensiveness and adversarial review, run changed scenarios three times, push the reviewed head to the PR after fetch/rebase and local validation, then watch one new CI run. Literal PR-local fix reversion is inapplicable: this PR changes only tests and claims guards for already-merged behavior, not fail-first production fixes.

Review lane rev-bte1201 exit — 2026-10-02 18:33 UTC

REVIEW_BLOCKING: the session-notes file remains in https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 because the required local gate did not finish before the lane cutoff. The local fix is committed, rebased, pushed and remote-SHA verified on the review checkpoint below. Do not treat the prior green CI as validating that new checkpoint. No PR push, new CI run, merge, enqueue, deployment, publication, or handoff completion occurred.

Repository Durable branch PR Head / state
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/rev-bte1201-2026-10-02 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 dcdb6287175282ecf2efd8f4a489056b6c501167; notes removal checkpoint; unvalidated locally
BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte-audit-ledger-minors-2026-10-02 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 db0514735e9b4b3491997cebc27543ef09893c9e; OPEN; original required build and all four informational shards succeeded; notes still present

Static reviews

Test-comprehensiveness review mapped every changed public behavior and decision row to a public-API scenario. Adversarial review found only the committed session notes; removing them leaves exactly twelve test scripts in the diff (757 additions / 28 removals), no source, README, build-script or other non-test additions. The useful decision-row mapping is already in the PR description. No assertions, iterations or existing limits were weakened. No new reflection, mocks, swallowed exceptions/effects, disabled tests or environment gates. PR description opens with WHY, links the source PR and handoff by full URL, links the Handoff WUI, and carries the required generated-with footer.

The original claim that this PR contains fail-first production fixes is refuted by its exact diff and description: it adds guards for already-merged behavior. However, the separately requested sensitivity of those guards to reverted protecting conditions has NOT been verified dynamically. It remains an open required review item, not a clean-review claim.

Local validation and remaining work

The first twelve-scenario invocation waited under withlock.sh from 17:27:50 to 17:58:21 (about thirty minutes). Fresh workspace preparation parsed scripts and compiled dependencies. The first separate source-build JVM stayed active in Kotlin call resolution/type checking for almost twenty minutes, then exited; another BuildscriptRunner child started. No preparation deadline, test verdict or XML was reported. The invocation was stopped for lane wind-down before any test verdict. Local observed counts: 0 passed, 0 failed, 12 selected scenarios unverified. Three repeated local runs and the guard-reversion proofs are unfinished. No source mutation was applied.

Next owner should re-verify both remote heads and PR activity first, pick up the notes-removal checkpoint, fetch/rebase, run all twelve changed scenarios three times under the slot helper, and verify test sensitivity before issuing a clean review. Then push the tested head to the still-open PR using force-with-lease, update the description validation, watch one CI run, and leave final review/merge to the supervisor. Do not raise limits or use CI to diagnose a local failure.

The review findings are in the supervisor scratchpad out/rev-bte1201-findings.md. Stack snapshots show CLI waiting in JvmBuildScriptLauncher.execute while its child was RUNNABLE in Kotlin type checking; they do not establish a production defect or a host cause. The relevant source paths are src/buildtest/embedded/DropletManager.kt, DeletionWorker.kt and BuildTestEmbeddedService.kt. A proposed sensitivity experiment (not run) removes the per-ID gone-marker publication, the recordedAllocation guard, settled-attempt exclusion and active-create exclusion, and restores the actual d73185213 listing-driven gone-marker block for the two older listing reproducers. Restore all source before the passing gates; distinguish this experiment from an original fail-first baseline.

Public behavior-to-test mapping

Public behavior / invariant Scenario Coverage evidence
Provider-confirmed per-ID absence is durable; stale fleet lists cannot restore deletion authority authoritativeNotFoundGoneMarkSurvivesRestart Lost DELETE reply, exact missing-ID read, emptied pending queue, two serial manager restarts, three reconciliations each, same-base peer survives, exactly one DELETE
In-flight original create keeps allocation cleanup outside admission, then deletion precedes readmission (minor 15) inFlightAttemptBlocksReadmissionDuringAllocationCleanup Genuine create held; third listing held after two empty observations; cleanup/status/pending/create-count checks; original resolves; exact once deletion before PENDING callback
ID-less proven-absent attempt does not reopen cleanup for incomplete allocation incompleteRunWithProvenAbsentAttemptDoesNotReopenCleanup Public failed create, empty provider fleet, two serial restarts at held admission publication, PENDING/no cleanup/no manufactured ID/no deletion inventory/no extra create
ID-less quota-refused attempt does not reopen cleanup for incomplete allocation incompleteRunWithQuotaRefusedAttemptDoesNotReopenCleanup Same incomplete cell with conclusive quota refusal
Settled proven-absent replacement attempt cannot rewrite the live complete-with-replacement-pending allocation (minor 22) replacementPendingRunWithProvenAbsentAttemptDoesNotReopenCleanup Live primary and retired shard IDs created through manager, failed replacement, two restarts held at genuine SSH grant, TESTING/unchanged IDs/non-renewable set/no cleanup/no extra create
Settled refused replacement attempt cannot rewrite that allocation (minor 22) replacementPendingRunWithQuotaRefusedAttemptDoesNotReopenCleanup Same replacement cell with quota refusal
Legacy name-only claim does not rewrite complete allocation or delete an unowned same-name peer (minor 23) completeRunWithLegacyNameOnlyRecordKeepsItsAllocation Older persisted record, two serial service restarts, forced public reconciliation, assigned ID and peer preserved, no cleanup/no DELETE
Stale older listing cannot discard newer exact-ID adoption; same-name later ID stays unowned staleListingNeverDisownsALiveOwnedDroplet Older listing explicitly held across newer public discovery; exact observed-ID assertion; orphan deleted exactly once; later same-name peer survives
Single omitted listing cannot strand an owned orphan singleOmittingListingNeverStrandsAnOwnedOrphan One omitted response followed by absent run and exact once reap; assertion unchanged
Completed allocation survives earlier 502/422/quota ghost cleanup badGatewayGhostReapedBeforeRestartKeepsLiveRun; lateGhostReapedBeforeRestartKeepsLiveRun; quotaGhostCleanedInlineKeepsLiveRunAcrossRestart Existing restart/status/deletion assertions unchanged; only diagnostic prints removed

Lane bte1201-finish — step-one comparison stopped continuation, 2026-10-02 19:01 UTC

OBSERVED: The assigned warm workspace is clean at expected dcdb6287175282ecf2efd8f4a489056b6c501167. However, the mandatory first command git diff db0514735e9b4b3491997cebc27543ef09893c9e..dcdb6287175282ecf2efd8f4a489056b6c501167 --stat reports TWO files: README.md (one insertion and one deletion) and review-notes/bte-audit-ledger-minors.md (48 deletions). This violates the lane's explicit "If anything else differs, stop and report" condition. No tests or source experiment were launched; no rebase, PR edit, new push, CI submission, merge, enqueue, deployment, restart, route change, publication or completion occurred.

OBSERVED: The README difference is the added sentence: "A feed read that close() releases before startup reconciliation finishes, and that needs no reset, is served from the journal as last committed and can omit rows reconciliation had not yet appended; the next service start includes those rows after reconciliation." git log db051473..dcdb6287 --oneline includes https://github.com/CodexCoder21Organization/BuildTestEmbedded/commit/b46945c73, the merged README follow-up, plus rebased ledger commits. The cleanup commit itself (git show --stat dcdb6287) deletes ONLY the notes file. Thus the comparison premise is false because the two-head range also includes the predecessor rebase onto main, not because the cleanup commit edited the README.

INFER: Supervisor should account explicitly for this rebase-only README change or change the first gate to inspect the cleanup commit against its parent. Then resume the twelve changed scenarios in one compile-slot invocation, inspect every XML attempt, run all seven guard-removal/restoration checks, rebase and verify locally, push the notes removal to the existing PR, update its description, and watch one CI run. No dynamic gate is satisfied by this lane. This is an INCOMPLETE stop at the prescribed gate, not a new production bug or an infrastructure blocker.

Repo Branch Remote head SHA PR What is on it State
CodexCoder21Organization/BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/rev-bte1201-2026-10-02 dcdb6287175282ecf2efd8f4a489056b6c501167 https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 Existing rebased notes-removal checkpoint Remote verified; no local dynamic validation; clean warm workspace
CodexCoder21Organization/BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte-audit-ledger-minors-2026-10-02 db0514735e9b4b3491997cebc27543ef09893c9e https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 Original PR with notes file still committed OPEN; bld-build and all four shards SUCCESS at initial lane read

Original CI: https://github.com/CodexCoder21Organization/BuildTestEmbedded/actions/runs/37037374721. No local changes or stashes exist, so nothing new requires a push; the existing checkpoint was verified with git ls-remote. No lane-owned JVM or watcher was started. Local test counts: 0 passed / 0 failed / 0 executed, no XML attempts. Prior implementing-lane 12/12 is provenance only. Findings: supervisor scratchpad out/bte1201-finish-findings.md. All actionable evidence is also captured here so continuation does not depend on scratch files.

Lane bte-audit-d3 exit — 2026-10-02 20:01:31 UTC

OBSERVED: D3 is still open on main f3efa847c6e78233cd006f42528bd6534a578c26, verified by git ls-remote origin refs/heads/main. Source https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1073 is MERGED at 2026-09-30T03:08:47Z, head 9f0d2833d98268caaa456cfcc46db036a087d61c. Its removal of listing-driven gone marks does not close the separate aged record deletion in DropletManager.kt:771-777. No implementation or existing test has been changed by this lane.

Repo Branch Verified remote head SHA PR What is on it State
CodexCoder21Organization/BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte-audit-d3-2026-10-02 3cdc496e292f56554dd5fb334ad85c0686e6dc76 no PR One new public API reproducer, tests/listingGapDoesNotForgetOwnedOrphan.kts; no production fix Two completed local gates fail at the same assertion; all six runner attempts fail; source fix stopped at conflicting-test rule

Mechanism and public reproducer

An aged ID-bearing record is erased by a single successful listing that omits its live provider ID. The next complete listing sees the droplet with no ownership record, so reconciliation keeps it as unowned rather than deleting the orphan. Main's pruneOwnedBuildDropletNames explicitly avoids listing-driven gone markers at lines 732-733, but still deletes an old known-ID record at lines 771-777 without a per-ID absence confirmation. This is independent of the younger-record omitted-listing test already on main.

The new self-contained public test uses real DropletManager and BuildDropletReconciler against FakeDropletService, with an in-process provider adapter injecting exactly one empty successful list. ManualClock ages the record past the configured one-hour retention and the droplet's createdAt; reconciliation grace is zero and run lookup is Absent. It independently checks that the droplet remains live during omission, that no deletion happened during omission, that the next listing contains its exact ID, and that the orphan must then be deleted exactly once. There is no reflection, mock, sleep, test gate or assertion weakening; cleanup runs even on failure.

Exact selector: /tmp/claude-501/-code/4719c767-3557-4cb1-90f8-28975c4c3602/scratchpad/withlock.sh scripts/test.bash --local --test listingGapDoesNotForgetOwnedOrphan --log <outside-repository.xml> from this lane's checkout. The first run waited 420 seconds for slot 2, then compiled source successfully in 346770 ms. Verdict: 0 passed / 1 failed; attempt history has three failed attempts (1597/1463/1726 ms). After a successful fetch/rebase, the checkpoint gate again reported 0 passed / 1 failed, with all three attempts failed. Total: 0 successful / 2 failed test invocations; 0 successful / 6 failed attempts. A redundant queued invocation after a failed commit/rebase was canceled before slot acquisition and executed no tests; it is not counted as a verdict. The fresh checkout initially lacked Git author identity; repository-local identity was configured, with no global change.

FAILED buildtest.embedded.listingGapDoesNotForgetOwnedOrphan -> java.lang.AssertionError: The aged ownership record must survive the listing gap and authorize exactly one orphan deletion.. Expected <[1]>, actual <[]>.
TESTS FAILED (0/1 tests completed successfully, 1 failed)
java.lang.AssertionError: The aged ownership record must survive the listing gap and authorize exactly one orphan deletion.. Expected <[1]>, actual <[]>.
	at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
	at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
	at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
	at kotlin.test.Asserter$DefaultImpls.assertEquals(Assertions.kt:671)
	at kotlin.test.DefaultAsserter.assertEquals(DefaultAsserter.kt:11)
	at kotlin.test.AssertionsKt__AssertionsKt.assertEquals(Assertions.kt:63)
	at kotlin.test.AssertionsKt.assertEquals(Unknown Source)
	at buildtest.embedded.ListingGapDoesNotForgetOwnedOrphanKt.listingGapDoesNotForgetOwnedOrphan(listingGapDoesNotForgetOwnedOrphan.kt:46)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at kompile.TestRunner.executeTest(TestRunner.kt:47)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)

Binding test conflict and next step

OBSERVED: Existing main test tests/ownershipRecordIsKeptWhileItsIdIsListedUnderAnotherName.kts:51-54 sets hidden=true while the provider ID remains alive, then requires the record not to exist. Its provider adapter only empties list results; it never deletes that resource. A correct D3 implementation would retain the record and fail that assertion. README.md:539 documents that old listing-based known-ID retention, while :537 says omitted droplets stay owned and reapable. This is a contract conflict, not a timing or host explanation.

The lane hard rule says: "If you believe a test is genuinely wrong, write that in the findings file with the evidence and stop that sub-step." The fixture-correction/source-fix sub-step is therefore stopped. An asynchronous clarification asked whether the supervisor permits correcting the fixture by deleting the provider droplet before its existing final assertion (without changing the assertion); no answer had arrived at exit. Do not claim D3 closed by the merged source PR, or describe the checkpoint as green.

Supervisor next: decide whether to authorize that fixture correction. Then continue from the clean warm workspace or the pushed checkpoint, confirm absence by each recorded ID before aged pruning, retain records on inconclusive reads, and revalidate current record state after provider IO without holding the ownership lock across it. Add public guards for restart after omission, inconclusive exact-ID reads, multi-ID records and concurrent publication; derive the neighbor gate from ownership/pruning tests and enumerate provider adapters touched by the new read. Keep existing genuine provider-deletion retention and ID-less absence-window behavior. Run red guards first, implement at DropletManager, update the retention README contract, pass local neighbor gates, open one PR and watch one CI run; supervisor owns final review/merge. No implementation patch was guessed or left half-applied.

Brief path correction: https://github.com/CodexCoder21Organization/PlanRepository/blob/wip/bte-audit-artifacts-2026-09-23/handoffs/artifacts/bte-audit-2026-09-23/briefs-2026-09-29/D3.md. The handoff's former briefs3/D3.md path is absent. Read D3 brief, TESTING.md, PHILOSOPHY.md and PlanRepository handoffs/README.md before the test; inspected repository README ownership contracts and read scripts/test.bash. No repository AGENTS.md exists. Current lane's slot helper and no-test-deletion rules supersede the old brief's pruning helper.

Exit sweep: new checkpoint SHA verified remotely, working tree clean, no stashes or local-only commits. No new PR, CI/remote run, merge, enqueue, deployment, production restart/route change, Maven publication or handoff completion. Local XML and verbose runner logs are not committed because they are test artifacts; their verdict, attempt counts and full failure trace are recorded here. The public reproducer is durable on the linked branch. No lane-owned test process or watcher remains running. All existing shared Mission, findings and branch/PR rows are carried forward.

Lane bte1201-finish2 final continuation — 2026-10-02 20:19:02 UTC

This section restores the lane checkpoint that was absent from the latest shared body, carries its findings forward, and supersedes earlier clean-review claims for this assigned PR only. Every existing row above is preserved.

Repo Branch Verified remote SHA PR State and remaining work
CodexCoder21Organization/BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte1201-finish2-2026-10-02 8cc328d471fd7cd08d8433ab539246c8ece48d1d https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 Notes file removed; rebased onto main; exactly twelve tests-only files differ; clean worktree; checkpoint remote verified. Resolve fixture premises before PR code push.
CodexCoder21Organization/BuildTestEmbedded https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte-audit-ledger-minors-2026-10-02 db0514735e9b4b3491997cebc27543ef09893c9e https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 OPEN, PR description updated with dynamic findings; original notes still committed. No new PR code push or CI run.

bte1201-finish2 findings

Started 2026-10-02. Plan: (1) read handoff and predecessor findings, verify checkout and tests-only comparison to main; (2) run twelve changed scenarios and inspect attempt history; (3) run seven guard-removal experiments and restore; (4) rebase, checkpoint/push, update PR, watch one CI run; (5) update handoff and final report. No merging, enqueueing, deployment, publication, test weakening, or timeout changes.

OBSERVED: Mission is to finish the existing tests-only PR and provide gate and sensitivity evidence. INFER: All claimed state must be checked against the current remote before editing.

2026-10-02 19:34 UTC — comparison and local gate

OBSERVED: Read the live handoff, both predecessor findings, README, github-repos/create-handoff/status-report/watch-build skills. Warm workspace is clean at dcdb6287175282ecf2efd8f4a489056b6c501167, on the assigned PR branch. PR OPEN at db051473, no comments, newest commit 16:51 UTC already accounted for. Current main advanced to f3efa847c: origin/main..dcdb6287 showed thirteen tests-only files (an unrelated main test delta), README empty, no non-test file. Rebase succeeded without conflicts; resulting 8cc328d471fd7cd08d8433ab539246c8ece48d1d now differs from main in exactly twelve tests (757 additions/28 removals). Launched one twelve-scenario local invocation under withlock.sh, with XML and log in out/bte1201-finish2-gate.*. INFER: Corrected tests-only gate is satisfied after the mandatory pre-build rebase. The extra initial file was newer-main history, not an unrequested PR edit. Dynamic gate remains pending; no production mutation applied and no CI submitted. Plan: comparison done; twelve-test gate in progress; sensitivity, PR push/watch, handoff exit pending.

2026-10-02 19:34 UTC — planned sensitivity mechanisms

OBSERVED: The gate acquired slot 2 at 19:33:16 after 107 seconds. Predecessor's prepared script is out/rev-bte1201-mutate.py; all five seven-test edit sites match current source exactly. Its final listing-driven gone-mark mutation belongs to the two older listing tests, not the seven assigned new guards; it is excluded from this lane's seven-test experiment. No source mutation has yet been applied. Relevant required reading: DocumentationRepository architecture/TESTING.md (public API, hermetic dependencies, hardware-independent triggers, recovery/ownership coverage), PHILOSOPHY.md, PlanRepository handoffs/README.md, and repository README. INFER: Mechanism mapping for the experiment: authoritativeNotFoundGoneMarkSurvivesRestart must detect omitted DeletionWorker.recordOwnedDropletGone after per-ID absence; completeRunWithLegacyNameOnlyRecordKeepsItsAllocation must detect omission of the recordedAllocation != INCOMPLETE exclusion; both incomplete-run settled-attempt tests must detect treating PROVEN_ABSENT/REFUSED as unresolved; both replacement-pending settled-attempt tests need that same state misclassification plus removal of the allocation-type exclusion to reach the wrong cleanup path; inFlightAttemptBlocksReadmissionDuringAllocationCleanup must detect removing the active provider-call exclusion and the IN_FLIGHT-name exclusion from hasUnobservedBuildDropletClaim. Expected failures are retained cleanup/admission or deletion-contract assertions, never compilation failures. Restore all three source files before the passing gate and before any push.

2026-10-02 19:40 UTC — static review and active compile

OBSERVED: Separate diff review confirms the five old scenarios retain assertions, counts and timing; new incomplete/replacement pairs differ only in provider outcome and corresponding full diagnostics. Source remains untouched, git diff --check passes. Gate source-build child 88105 is RUNNABLE in Kotlin type checking, ~5.5 minutes elapsed; full jstack saved to out/bte1201-finish2-gate-compile.jstack. No XML or execution verdict yet. Initial RUNNING report upload succeeded. INFER: Compilation is the current gate; no evidence of a test hang or a production defect. No broader change is justified by the static review. The next action remains reading the completed XML and its attempts before mutation or PR push.

2026-10-02 19:45 UTC — source compilation finished

OBSERVED: Source-build child exited successfully and logged cached build-rule results. The gate is compiling selected test scripts; only ordinary compiler warnings have appeared. Independently parsed the implementing lane gate4 XML: twelve successful test rows, no failed attempt; this is historical evidence, not validation of the current head. INFER: The warm source cache is now populated for 8cc328d471fd7cd08d8433ab539246c8ece48d1d. Next remains the actual current-head twelve-scenario verdict, then the required checkpoint gate before pushing WIP.

2026-10-02 19:49 UTC — clean-attempt gate failed

OBSERVED: Runner exit 0 reports 12/12 final passes, but XML attempt-history proves replacementPendingRunWithQuotaRefusedAttemptDoesNotReopenCleanup failed attempt 1 and passed attempt 2. Eleven scenarios passed first attempt. Failing attempt took 6780 ms; error: Closing restart generation 2 must not reopen the quota-refused attempt. Expected <1>, actual <2>. Full failed stack:

java.lang.AssertionError: Closing restart generation 2 must not reopen the quota-refused attempt. Expected <1>, actual <2>.
	at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
	at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
	at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
	at kotlin.test.Asserter$DefaultImpls.assertEquals(Assertions.kt:671)
	at kotlin.test.DefaultAsserter.assertEquals(DefaultAsserter.kt:11)
	at kotlin.test.AssertionsKt__AssertionsKt.assertEquals(Assertions.kt:63)
	at kotlin.test.AssertionsKt.assertEquals(Unknown Source)
	at buildtest.embedded.TestReplacementPendingRunWithQuotaRefusedAttemptDoesNotReopenCleanupKt.replacementPendingRunWithQuotaRefusedAttemptDoesNotReopenCleanup(testReplacementPendingRunWithQuotaRefusedAttemptDoesNotReopenCleanup.kt:124)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at kompile.TestRunner.executeTest(TestRunner.kt:47)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)

OBSERVED: Failed console shows primary SSH grant held while a separate shard-1 allocation begins across shutdown; successful retry instead logs abandoned starting recovered shard 1 because service is closing. Production source and tests remain unchanged. INFER: The clean-attempt gate is not satisfied; no PR push or CI submission is justified. Read fix-flakey-test skill and investigate whether the assertion confuses ordinary parallel replacement work with revival of the settled attempt, or exposes a shutdown ordering defect. No source fix will be guessed and no assertion weakened.

2026-10-02 19:52 UTC — fixture premise refuted for the count assertion

OBSERVED: resumeShardedBuild at current head computes a non-renewable shard's persisted ID as zero (27317 onward), starts usable shard threads independently (27749 onward), enqueues/admit missing replacements (27758 onward), then fans those missing shard threads without waiting for the primary (27790 onward). resumeShardOnDroplet provisions a fresh droplet when that ID is zero (28267 onward). DropletManager allocates a fresh unique tokened name with nextDropletAttemptToken (356), not by reopening the prior settled token. Both replacement-pending fixtures enable startupRemoteWorkEnabled=true, leave dropletLimit at zero (admission disabled), and block only addSshKeyToDroplet for the live primary. They do not hold replacement admission. INFER: The quota fixture's assertion that all provider creates remain exactly one through close is not justified by its setup. Ordinary missing-shard replacement can race the primary observation and close; the attempt-count assertion conflates that independent replacement with reopening the settled attempt. The same setup exists in the ProvenAbsent variant, even though its first run passed. Per the hard rule for a genuinely wrong test, leave these tests unchanged and stop the assertion-fix sub-step for supervisor review. This is not a diagnosed production shutdown defect: logs alone do not order the secondary worker's entry against closing's publication. Plan change: preserve the rebased notes-removal head on WIP after the mandatory pre-push targeted gate, run the prepared source-sensitivity experiment for the expected behavior checks, restore source, and record all results. Do not push the PR or submit CI as clean merely because a later run passes; the observed first-attempt failure remains unresolved.

2026-10-02 19:59 UTC — durable checkpoint

OBSERVED: Mandatory pre-push fetch/rebase left HEAD 8cc328d471fd7cd08d8433ab539246c8ece48d1d unchanged. Twelve-scenario pre-checkpoint gate passed 12/12, first attempts only, XML has no attempt-history. PR rechecked OPEN at accounted db051473, no new comments/commits. Pushed notes-removal head to https://github.com/CodexCoder21Organization/BuildTestEmbedded/tree/wip/bte1201-finish2-2026-10-02; git ls-remote confirms 8cc328d471fd7cd08d8433ab539246c8ece48d1d. Original PR branch remains unchanged. Findings and failed stack are mirrored in the handoff report. INFER: Passing the second gate does not resolve the first gate's count-assertion failure. No guessed fix is introduced. Continue the controlled guard experiment and restored gate, while retaining this issue for supervisor review; PR push and new CI remain withheld.

2026-10-02 20:01 UTC — sensitivity running

OBSERVED: First full-body handoff update succeeded from a freshly fetched JSON body with all other lane rows preserved; one of two permitted update attempts used. WIP head is remote verified. Fresh pre-build fetch/rebase left head unchanged; PR remains OPEN at the accounted original head, with no new comments/commits. Applied the five verified source edits from the prepared experiment (excluding the unrelated older-listing mutation), captured the exact patch in out/bte1201-finish2-mutant.diff, and queued seven scenarios under a new withlock.sh acquisition. The runner wrapper restores all three source files in its finally block. No test edits, changed limits, PR push or CI submission. INFER: Mutant failures must be checked against the intended guard mechanism, not merely counted. The quota fixture's first-attempt failure stays open irrespective of sensitivity results.

2026-10-02 20:12 UTC — prepared sensitivity verdict

OBSERVED: Actual mutated-source build succeeded (142165 ms, 135 output files, executions=1). Seven selected scenarios: 5 failed / 2 passed. Each of the five failing scenarios has three failed attempts: fifteen failed attempts total; two successful attempts. Source restored in finally, worktree clean. No test changed.

Scenario Mutant result First failure
authoritativeNotFoundGoneMarkSurvivesRestart FAIL java.lang.AssertionError: A stale listing after restart must not authorize deleting the confirmed-gone ID 1 or peer 2. Expected <[]>, actual <[1, 1, 1]>.
completeRunWithLegacyNameOnlyRecordKeepsItsAllocation FAIL java.lang.AssertionError: A legacy name-only record cannot reopen a complete allocation. Expected value to be null, but was: <AllocationCleanupState(context=allocation interrupted before its result was recorded, rateLimited=false, providerStalled=true, quotaStartedAt=null, providerError=, lastProgressAt=1790971458497, observationComplete=false, observedDropletIds=[], ownershipWriteFailed=false, primaryFailure=)>.
incompleteRunWithQuotaRefusedAttemptDoesNotReopenCleanup PASS No failed attempt
incompleteRunWithProvenAbsentAttemptDoesNotReopenCleanup PASS No failed attempt
inFlightAttemptBlocksReadmissionDuringAllocationCleanup FAIL java.lang.AssertionError: Cleanup must complete two empty observations and enter its third observation
replacementPendingRunWithProvenAbsentAttemptDoesNotReopenCleanup FAIL java.lang.AssertionError: Restart generation 1 must reach the resumed SSH grant and remain held
replacementPendingRunWithQuotaRefusedAttemptDoesNotReopenCleanup FAIL java.lang.AssertionError: Restart generation 1 must reach the resumed SSH grant and remain held

OBSERVED: completeRunWithLegacyNameOnlyRecordKeepsItsAllocation first two attempts failed the intended cleanup assertion; third attempt instead exceeded its unchanged 30000 ms test deadline while service.close waited. That teardown failure is not counted as a third clean sensitivity assertion. Full stacks for each distinct failure follow.

buildtest.embedded.authoritativeNotFoundGoneMarkSurvivesRestart

java.lang.AssertionError: A stale listing after restart must not authorize deleting the confirmed-gone ID 1 or peer 2. Expected <[]>, actual <[1, 1, 1]>.
	at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
	at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
	at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
	at kotlin.test.Asserter$DefaultImpls.assertEquals(Assertions.kt:671)
	at kotlin.test.DefaultAsserter.assertEquals(DefaultAsserter.kt:11)
	at kotlin.test.AssertionsKt__AssertionsKt.assertEquals(Assertions.kt:63)
	at kotlin.test.AssertionsKt.assertEquals(Unknown Source)
	at buildtest.embedded.TestAuthoritativeNotFoundGoneMarkSurvivesRestartKt.authoritativeNotFoundGoneMarkSurvivesRestart(testAuthoritativeNotFoundGoneMarkSurvivesRestart.kt:67)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at kompile.TestRunner.executeTest(TestRunner.kt:47)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)

buildtest.embedded.completeRunWithLegacyNameOnlyRecordKeepsItsAllocation

java.lang.AssertionError: A legacy name-only record cannot reopen a complete allocation. Expected value to be null, but was: <AllocationCleanupState(context=allocation interrupted before its result was recorded, rateLimited=false, providerStalled=true, quotaStartedAt=null, providerError=, lastProgressAt=1790971458497, observationComplete=false, observedDropletIds=[], ownershipWriteFailed=false, primaryFailure=)>.
	at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
	at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
	at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
	at kotlin.test.Asserter$DefaultImpls.assertNull(Assertions.kt:707)
	at kotlin.test.DefaultAsserter.assertNull(DefaultAsserter.kt:11)
	at kotlin.test.AssertionsKt__AssertionsKt.assertNull(Assertions.kt:159)
	at kotlin.test.AssertionsKt.assertNull(Unknown Source)
	at buildtest.embedded.TestCompleteRunWithLegacyNameOnlyRecordKeepsItsAllocationKt.completeRunWithLegacyNameOnlyRecordKeepsItsAllocation(testCompleteRunWithLegacyNameOnlyRecordKeepsItsAllocation.kt:56)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at kompile.TestRunner.executeTest(TestRunner.kt:47)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)

buildtest.embedded.inFlightAttemptBlocksReadmissionDuringAllocationCleanup

java.lang.AssertionError: Cleanup must complete two empty observations and enter its third observation
	at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
	at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
	at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
	at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:662)
	at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
	at kotlin.test.AssertionsKt__AssertionsKt.assertTrue(Assertions.kt:44)
	at kotlin.test.AssertionsKt.assertTrue(Unknown Source)
	at buildtest.embedded.TestInFlightAttemptBlocksReadmissionDuringAllocationCleanupKt.inFlightAttemptBlocksReadmissionDuringAllocationCleanup(testInFlightAttemptBlocksReadmissionDuringAllocationCleanup.kt:79)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at kompile.TestRunner.executeTest(TestRunner.kt:47)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)

buildtest.embedded.replacementPendingRunWithProvenAbsentAttemptDoesNotReopenCleanup

java.lang.AssertionError: Restart generation 1 must reach the resumed SSH grant and remain held
	at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
	at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
	at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
	at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:662)
	at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
	at kotlin.test.AssertionsKt__AssertionsKt.assertTrue(Assertions.kt:44)
	at kotlin.test.AssertionsKt.assertTrue(Unknown Source)
	at buildtest.embedded.TestReplacementPendingRunWithProvenAbsentAttemptDoesNotReopenCleanupKt.replacementPendingRunWithProvenAbsentAttemptDoesNotReopenCleanup(testReplacementPendingRunWithProvenAbsentAttemptDoesNotReopenCleanup.kt:105)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at kompile.TestRunner.executeTest(TestRunner.kt:47)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)

buildtest.embedded.replacementPendingRunWithQuotaRefusedAttemptDoesNotReopenCleanup

java.lang.AssertionError: Restart generation 1 must reach the resumed SSH grant and remain held
	at kotlin.test.DefaultAsserter.fail(DefaultAsserter.kt:16)
	at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:652)
	at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
	at kotlin.test.Asserter$DefaultImpls.assertTrue(Assertions.kt:662)
	at kotlin.test.DefaultAsserter.assertTrue(DefaultAsserter.kt:11)
	at kotlin.test.AssertionsKt__AssertionsKt.assertTrue(Assertions.kt:44)
	at kotlin.test.AssertionsKt.assertTrue(Unknown Source)
	at buildtest.embedded.TestReplacementPendingRunWithQuotaRefusedAttemptDoesNotReopenCleanupKt.replacementPendingRunWithQuotaRefusedAttemptDoesNotReopenCleanup(testReplacementPendingRunWithQuotaRefusedAttemptDoesNotReopenCleanup.kt:105)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at kompile.TestRunner.executeTest(TestRunner.kt:47)
	at java.base/jdk.internal.reflect.DirectMethodHandleAccessor.invoke(DirectMethodHandleAccessor.java:103)
	at java.base/java.lang.reflect.Method.invoke(Method.java:580)
	at community.kotlin.kompile.testrunner.bootstrap.BootstrapRunner.main(BootstrapRunner.java:416)

INFER: The prepared experiment does not establish sensitivity for incompleteRunWithProvenAbsentAttemptDoesNotReopenCleanup or incompleteRunWithQuotaRefusedAttemptDoesNotReopenCleanup; both pass with their proposed settled-state guard removed. The predecessor claim that startupRemoteWorkEnabled=false alone guarantees the wrong classification remains observable is not supported by this experiment. Investigate exact startup callback ordering before attributing a test gap or production defect. The replacement count finding remains open; no PR push or CI run. Plan: source restored; restored twelve-scenario run queued after fresh fetch/rebase; final handoff update will retain incomplete validation and full per-test evidence.

2026-10-02 20:18 UTC — restored verdict and callback-order finding

OBSERVED: Restored-source twelve-scenario run exited 0: 12 passed / 0 failed; zero attempt-history nodes. Fresh final fetch/rebase left HEAD 8cc328d471fd7cd08d8433ab539246c8ece48d1d unchanged. Worktree clean, exact twelve tests-only diff, README/source/build scripts unchanged. PR OPEN at db051473 with no new commits/comments; WIP remote SHA matches HEAD. OBSERVED: BuildTestEmbeddedService init unconditionally starts startupRunResumeThread before the separate startupRemoteWorkEnabled switch (15470–15490). The recovered worker reads allocationCleanup and calls resumeAllocationFailureCleanup (25717–25720); that public path lists an empty fleet, resolves settled claims, clears allocationCleanup, sets PENDING (16388 onward), and publishes admission. The incomplete fixtures observe only the later afterAdmissionQueuePublished boundary. INFER: The prepared guard-removal passes for both incomplete fixtures are consistent with wrong classification being repaired before the held callback. Disabling startupRemoteWorkEnabled does not disable this recovered-worker cleanup. The predecessor inference is refuted by the actual mutant results and these unconditional source paths. A fixture must hold the provider observation or recovered worker before cleanup repair, then observe classification through the public API; do not add a second production defect merely to make the old fixture fail. No test edits are made here under the lane instruction to stop when a test premise is wrong. Plan: comparison, controlled sensitivity and restored gate done with the reported gaps; PR code push and new CI withheld because count assertion and two sensitivity rows remain unresolved. Finish PR description, canonical handoff and final RUNNING report; no new code or further CI.

2026-10-02 20:13:19 UTC — final checkpoint and remaining work

OBSERVED: PR description updated through GitHub REST, preserving its WHY and handoff links, actual newlines and generated-with footer. Response confirms OPEN at unchanged db051473. Final source and tests match the pushed WIP 8cc328d471fd7cd08d8433ab539246c8ece48d1d. There are no uncommitted changes or newly tracked build/test artifacts. All local code changes already exist remotely; no untested PR push or CI run was launched. OBSERVED: Timestamp correction: the two preceding progress blocks labelled 20:12 and 20:18 were written during roughly 20:10–20:12 UTC, not at the estimated labels. Their commands, XML counts and conclusions are unchanged. Report upload3 succeeded with RUNNING. INFER: The correct next step is supervisor review of the replacement count premise and incomplete-test observation boundary. Under the hard rule for a wrong test premise, this lane leaves the tests unchanged and stops those sub-steps. Notes removal stays durable on WIP until those gates are satisfied; the PR branch still contains the notes file.

Final plan: comparison DONE (exact twelve tests-only files, README empty); twelve-scenario gate DONE with first-attempt failure explicitly retained; prepared sensitivity experiment DONE with 5/7 failing and 2/7 insensitive; source restoration and restored gate DONE 12/12 first passes; notes removal checkpoint DONE and remote verified; PR description DONE; PR code push and new CI INCOMPLETE pending fixture premise corrections; final shared handoff/report IN PROGRESS.

2026-10-02 20:15:36 UTC — shared handoff update observation

OBSERVED: First handoff-cli update exited 0 and printed Updated; submitted body contains the bte1201-finish2 checkpoint and 8cc328d WIP row. A later get --json body carries a newly appended D3 lane but contains neither our checkpoint heading nor SHA. The earlier submitted full body remains in out/bte1201-finish2-handoff-body.md. INFER: This is consistent with another shared whole-body writer replacing the earlier checkpoint from an older snapshot; it does not establish a service defect. Final update must restore our missing chain while preserving every latest row. Retain the complete lane findings in the final report too. Checked the report-challenge skill at /home/hostusr/.codex/skills/report-challenge/SKILL.md: it automatically enqueues and waits for merge, which conflicts with this lane's no-enqueue/no-merge hard rule. No challenge CLI invocation is permitted; concrete evidence is preserved here for the supervisor. Suggested durable fix: conditional body updates using a revision value, so a stale writer must refresh before overwriting.

2026-10-02 20:18:46 UTC — final push verified

OBSERVED: The final pre-push twelve-scenario gate passed 12/12 first attempts; XML contains no attempt history. Explicit WIP force-with-lease push returned Everything up-to-date; git ls-remote matches HEAD 8cc328d471fd7cd08d8433ab539246c8ece48d1d. Worktree clean, commit retains required coauthor footer. PR description updated; no PR code push, CI submission, merge, enqueue, deploy, publication or completion.

RESULT

INCOMPLETE Correct the replacement-count fixture premise and the two insensitive incomplete-run observation boundaries, then prove all seven sensitivity rows, push notes removal from WIP 8cc328d471fd7cd08d8433ab539246c8ece48d1d to https://github.com/CodexCoder21Organization/BuildTestEmbedded/pull/1201 and watch its one new CI run. The lane stops these test sub-steps under the explicit wrong-premise rule; no assertions or tests were changed.

Full local observed counts:

  • Gate 1: 12 final passes / 0 final failures; 13 attempts, 12 passed / 1 failed (quota replacement count first attempt).
  • Pre-checkpoint gate: 12 passed / 0 failed, no retry.
  • Combined prepared guard-removal experiment: 2 passed / 5 failed; 17 attempts, 2 passed / 15 failed, including one legacy-fixture teardown deadline. Two incomplete-run tests remained insensitive.
  • Restored-source gate: 12 passed / 0 failed, no retry.
  • Final pre-push gate: 12 passed / 0 failed, no retry.
  • Aggregate normal-head execution attempts: 48 passed / 1 failed; mutant execution attempts: 2 passed / 15 failed. No remote run or new CI head.

Exact prepared combined guard-removal patch

The patch below was applied only for the experiment and fully restored before all restored/final passing gates and push. No production mutation is committed.

diff --git a/src/buildtest/embedded/BuildTestEmbeddedService.kt b/src/buildtest/embedded/BuildTestEmbeddedService.kt
index 5520f73a9..c7a7336d3 100644
--- a/src/buildtest/embedded/BuildTestEmbeddedService.kt
+++ b/src/buildtest/embedded/BuildTestEmbeddedService.kt
@@ -632,7 +632,7 @@ private fun interruptedAllocationClaims(
     retirementHistory: RetiredDynamicDropletHistory,
 ): List<OwnedAllocationClaim> {
     if (run.status in TERMINAL_STATUSES || run.allocationCleanup != null) return emptyList()
-    if (recordedAllocation(run) != RecordedAllocation.INCOMPLETE) return emptyList()
+    // Review experiment: allow ledger claims to rewrite complete allocations.
     val assignedIds = (listOf(run.dropletId) + run.shardDropletIds).filter { it > 0L }.toSet()
     // An ID the run already recorded as non-renewable is covered by the run's own deletion
     // decision. Each provider attempt keeps its own ownership record, so a replaced attempt's ID
diff --git a/src/buildtest/embedded/DeletionWorker.kt b/src/buildtest/embedded/DeletionWorker.kt
index c14aa97c9..1b1c8f1e7 100644
--- a/src/buildtest/embedded/DeletionWorker.kt
+++ b/src/buildtest/embedded/DeletionWorker.kt
@@ -507,7 +507,7 @@ class DeletionWorker(
                     }
                     if (!absent) throw deletionFailure
                     // Authoritative absence: record it in the ownership ledger before completing.
-                    dropletManager.recordOwnedDropletGone(dropletId)
+                    Unit // Review experiment: omit the durable ownership gone mark.
                 }
                 enterCommitPhase()
                 if (!stillCurrent()) throw RetiredWorkerGenerationException(dropletId)
diff --git a/src/buildtest/embedded/DropletManager.kt b/src/buildtest/embedded/DropletManager.kt
index 66d3e15f8..9fbc7be65 100644
--- a/src/buildtest/embedded/DropletManager.kt
+++ b/src/buildtest/embedded/DropletManager.kt
@@ -562,7 +562,8 @@ class DropletManager @JvmOverloads constructor(
                         java.util.Collections.unmodifiableSet(view.observedDropletIds),
                         // Only an attempt whose outcome nobody knows is an interrupted allocation.
                         when (view.state) {
-                            OwnershipAttemptState.IN_FLIGHT, OwnershipAttemptState.OUTCOME_UNKNOWN -> true
+                            OwnershipAttemptState.IN_FLIGHT, OwnershipAttemptState.OUTCOME_UNKNOWN,
+                            OwnershipAttemptState.PROVEN_ABSENT, OwnershipAttemptState.REFUSED -> true
                             OwnershipAttemptState.LEGACY_NAME_ONLY -> view.legacyUnresolved
                             else -> false
                         },
@@ -647,9 +648,7 @@ class DropletManager @JvmOverloads constructor(
         observedDroplets: Collection<DropletInfo>,
     ): Boolean {
         ownedDropletsLock.withLock {
-            if (provisioningAttemptsByName.any { (name, count) ->
-                    count > 0 && runIdForDropletName(name) == runId
-                }) return true
+            // Review experiment: omit active provider-call exclusion.
             val files = listOwnershipRecordFiles(ownershipFileSystem, ownedDropletsDir)
             for (file in files) {
                 if (!file.name.endsWith(".json") || !ownershipFileMayBelongToRun(file, runId)) continue
@@ -668,7 +667,7 @@ class DropletManager @JvmOverloads constructor(
                 val view = attemptView(record)
                 if (view.state != OwnershipAttemptState.LEGACY_NAME_ONLY) {
                     // Only an attempt whose outcome nobody knows blocks a new create.
-                    if (view.state in setOf(OwnershipAttemptState.IN_FLIGHT, OwnershipAttemptState.OUTCOME_UNKNOWN) &&
+                    if (view.state in setOf(OwnershipAttemptState.OUTCOME_UNKNOWN) &&
                         observedDroplets.none { it.name == view.name }) return true
                     continue
                 }

Next: supervisor reviews and corrects the replacement fixtures so primary SSH hold cannot race normal replacement admission, and the incomplete fixtures so observation precedes cleanup repair. Then establish all seven guard-removal failures and restored passes, push the notes-removal head to the still-open PR, and watch one new CI run through required bld-build and every informational shard. This delegate did not merge, enqueue, deploy, publish or complete the handoff.