Repository navigation
review-runs-tracking: 2026-10 #881
Description
Activity
- addedreview-runs-trackingMonthly tracking issue for review-runs below-threshold findingsMonthly tracking issue for review-runs below-threshold findings
on Oct 1, 2026 Run 36879007937 — 2026-10-01T14:57:58Z (review-runs)
Window
2026-09-29T14:21:40Z→ run start (~48.5 h, anchored on predecessor 36582088435). The 09-30 sweep 36727612071 still readsqueuedand never ran. That is GitHub bookkeeping: today's run started normally, so nothing is holding the group. 298 tend runs censused (not a page boundary):tend-mention156 (128 success, 27 skipped, 1 cancelled),tend-review56 (54 success, 2 failure),tend-ci-fix38 (1 success, 37 skipped),tend-mention-relay34,tend-notifications10,tend-triage2, and 1 each of nightly and review-runs. Near-timeout: 2. Both failures ran 351 min against the 360-min default cap (notimeout-minutesanywhere). Nightly took 27 min. Token report: $70.71.tend-review$47.10 over 55 runs, nightly $14.36, notifications $5.28, review-runs $2.64, mention $0.88, triage $0.45. 211 runs had no readable artifact (relay and skipped runs).GATE-PASSING, acted on:
tend-reviewpolls hung 351 min on environment-gatedHosted PR previewjobs. Overlay skip in #882- Evidence level: High (structural). 3 occurrences this run: 2 timeouts plus 1 nightly poll held to its end. A further 9 are recorded in the 09-29 entry, where the poll waited out the old 9-min cap.
- Run IDs: 36812253540 (Keep a one-time state through a failed re-read, never past an End #864), 36822903849 (Add the OSC 367 open verb and show failed opens in the preview slot #856), nightly 36715651032 (Fix stale size-hold, relay cache, and rename comments, and a renamed spec test pointer #860
deploystill pending when its poll ended) - Detail: Both reviews approved with every automated check green, and both PRs merged. The post-approval
poll_pr_checks.py pollthen waited on awaitingCheckRun:deployon Keep a one-time state through a failed re-read, never past an End #864, and on Add the OSC 367 open verb and show failed opens in the preview slot #856cleanup, which the merge (closedevent) started on the same head SHA. A merged head never moves, so_settlenever returned, and the harness killed the session at 21000s (exit 137). Each left a redreviewcheck on a merged PR and a row in outage tracker Bot temporarily unavailable #871. Tend 0.3.5 (chore: update tend workflows (0.3.4 → 0.3.5) #858) removed the 9-min cap, which turned the earlier wall-clock cost into a 6-hour hang, as Permission to file upstream: tend's CI poll waits out an environment-approval check it cannot advance #846 predicted. Not Critical: no wrong outward action, since each approval was correct. - Upstream: max-sixty/tend#1473 (by
tend-agent, citing these two runs) merged 2026-10-01T09:58Z. It reportsWAITINGas unverified. It is not in 0.3.5. I closed Permission to file upstream: tend's CI poll waits out an environment-approval check it cannot advance #846 as moot. - Gates: Gate 1 passes (High, structural, 3+9). Gate 2: targeted fix, one overlay paragraph that has polls pass
--skip deploy --skip cleanup(the overlay mechanismmonitor-cidocuments). No other PR workflow has a job by either name. Opened skills(running-tend): skip the environment-gated Hosted preview jobs in CI polls #882. The skip stays valid after the release, because neither job gates a merge.
workflow-audit#880 re-listed 24 already-accounted commits from the same stale bound,2026-09-03T12:03:48Z. Occurrence 2- Evidence level: Low (project workflow, not tend). Occurrence 2. The first was [workflow-audit] 23 unexplained change(s) on 2026-09-28 #811 on 09-28, with the identical timestamp.
- Run ID: 36876128567
- Detail:
runs?status=success&per_page=1returned 09-03 instead of 09-30T13:37:29Z. Landing on the same value twice points to a stuck stale view, not a random stale snapshot. Each of the 24 SHAs was matched to the earlier audit issue that first listed it ([workflow-audit] 5 unexplained change(s) on 2026-09-11 #628 through [workflow-audit] 1 unexplained change(s) on 2026-09-29 #845). Answered on [workflow-audit] 24 unexplained change(s) on 2026-10-01 #880 (comment), left open for the maintainer, who closed [workflow-audit] 23 unexplained change(s) on 2026-09-28 #811 personally. A more robust bound (re-read until two reads agree, asred_default_branch_runs.pydoes) would fix it. A third occurrence warrants proposing that.
Outage tracker drained
- Bot temporarily unavailable #871 held 2 rows, the two hung reviews above. I diagnosed them, commented, and closed the tracker. There was nothing to retry: both PRs merged with green CI.
Pre-registered watches
tend-notificationsunder-delivery, occurrence 25: 10 runs in about 48 h against*/15. No lever.tend-mentionfan-out: 156 dispatches, 1 cancellation, $0.88 across the 4 sessions that had logs. Cheap.tend-weeklycron move: first scheduled Sunday 15:17 slot is 10-04. Not yet observed.- No local dependencies in sessions (Medium structural, 09-29): not re-counted this run.
Maintainer corrections
review_runs_corrections.pyran: 6 dispositions (Make each Hosted preflight test case fail on its own check #842, Reject protocol-relative img sources and parse fences under list items in the docs parser #843, Keep the relay's sealed-push test from matching its plaintext in random ciphertext #844, chore: update tend workflows (0.3.4 → 0.3.5) #858, Keep the playground's ascii-splash running on unhandled keys and wheel events #859, Fix stale size-hold, relay cache, and rename comments, and a renamed spec test pointer #860, all merged), comment rows from Cloudflare, Argos, andnedtwigg, 0 reviews. Everynedtwiggrow acknowledges a bot review finding as fixed (Theme tool iframes and upgrade file viewers with Monaco editing #851 ×3, Add momentum to Pocket edge scrolling #854), apart from the Split Hosted into account, relay, and voice origins #867 manual test plan, which is meant for a person. No maintainer corrections.
Live scan
- Default branch:
red_default_branch_runs.pyconverged (unconverged_listings: []) and reached back to2026-09-15T09:25:55Z.liveheld onlysecurity-audit(2026-10-01 FAIL, [security-audit] FAIL on 2026-10-01 #873). Notifications 36861419115 already opened fix PRs Strip unreadable and oddly-spaced candidates from the offer under Local networks #874, Let loopback-lint see a positional bind whose port is a call #875, and Capture ts ip -4 before taking its first line in manage verify #876. Workflows with a green read: ci, argos, chromatic, hosted-production, security-audit (earlier), and the tend workflows. - Waiting runs: about 80
Hosted PR previewruns, all non-tend, held by thehosted-previewenvironment (reviewersnedtwigg,edgartwigg). No tend queue wedge, apart from the 09-30 review-runs run stuck inqueued, which was left alone. - Dependabot: one alert (
glib), still tracked by Track Tauri GTK upgrade to remediate glib advisory #663. - Threads: Strip unreadable and oddly-spaced candidates from the offer under Local networks #874–Match the test rendezvous to Hosted's one-time room: late joins close 4010, pre-join frames count #878 are bot PRs. Drafts Split Hosted into account, relay, and voice origins #867, Hosted Relay accounts, device-code enrollment, and Pocket at relay.dormouse.sh #868, Hosted Relay sockets: one Durable Object per account #869, Sealed push through the Hosted Relay #870, and Hosted enrollment from the desktop, and paired phones under Local networks and Anywhere #872 each have a successful
tend-reviewsession at their live head. [security-audit] FAIL on 2026-10-01 #873 is answered. [workflow-audit] 24 unexplained change(s) on 2026-10-01 #880 was answered this run.
Run 37017894064 — 2026-10-02T14:21:38Z (review-runs)
Window
2026-10-01T14:46:38Z→ run start (~23.5 h, anchored on predecessor 36879007937). 572 tend runs censused (not a page boundary):tend-mention317 (294 success, 15 skipped, 8 cancelled),tend-review118 (117 success, 1 cancelled),tend-mention-relay94,tend-ci-fix30 (all skipped),tend-triage6,tend-notifications4,tend-nightly2 (1 failure), review-runs 1. The volume came from the maintainer's spec-audit stack (#885–#907) and the Hosted stack (#867–#872). Near-timeout: 1 (the nightly failure below). Nothing else ran past 25 min. Token report: $115.74.tend-review$76.85 over 118 runs, nightly $21.88, mention $8.34, triage $3.62, review-runs $3.48, notifications $1.57.Nightly 36867257260 killed at 351 min. Same Hosted-preview poll hang, already fixed by #882
- Evidence level: High (structural). Occurrence 4 of the class recorded in run 36879007937. No action: the fix has merged.
- Detail: The nightly opened Show an error instead of a 500 when the folder viewer opens a path OSC 367 refuses #877 and Match the test rendezvous to Hosted's one-time room: late joins close 4010, pre-join frames count #878, then ran
poll_pr_checks.py poll 878without--skipat 13:27Z. It waited ondeployuntil exit 137 at 19:05Z. It started at 13:14Z, before skills(running-tend): skip the environment-gated Hosted preview jobs in CI polls #882 merged at 19:28Z. Both PRs merged with green CI. The skip is applied in every post-skills(running-tend): skip the environment-gated Hosted preview jobs in CI polls #882 poll I sampled: review 36934789776 (Move panes between Workspaces by drag, context and dor #887) and nightly 37007523017 (Fix comments left stale by the Hosted, alert-pause, and Surface-move work #909, 16 min). Watch discharged.
workflow-auditstale bound: occurrence 3, deterministic. Acted on: #920- Evidence level: Medium → acted, because the threshold is project-level rather than tend's. Occurrence 3: [workflow-audit] 23 unexplained change(s) on 2026-09-28 #811 (09-28), [workflow-audit] 24 unexplained change(s) on 2026-10-01 #880 (10-01), and [workflow-audit] 24 unexplained change(s) on 2026-10-02 #915 (today, which lists the identical 24 SHAs as [workflow-audit] 24 unexplained change(s) on 2026-10-01 #880).
- Detail:
actions/workflows/workflow-audit.yaml/runs?status=success&per_page=1returnstotal_count: 31, newest success 2026-09-03T12:03:48Z. The unfiltered listing shows 100+ successes, the newest today at 13:48:12Z. The filtered listing itself is stale. This is not a race between two reads. fix(workflow-audit): find the previous successful run without the stale status filter #920 selects the newestconclusion == "success"run from the unfiltered paginated listing. The bound stays a server-setcreated_at, which is the security-ci.md FAIL IF. I commented on [workflow-audit] 24 unexplained change(s) on 2026-10-02 #915.
Live-work handling: I opened a fix PR that conflicted with the maintainer's in-flight PR, then withdrew it
- Evidence level: Low (one occurrence, stochastic, mine). Recorded for the next sweep.
- Detail: Security-audit FAIL [security-audit] FAIL on 2026-10-04 #908 (stale "Rendezvous boundary" pointer in security-remote.md:61) had no bot response. I opened docs(security-remote): name both Hosted spec sections the e2e-lint rules cite #919 with the one-line fix. Then I found that nightly 37007523017 had already identified the same drift and deliberately left it, because the maintainer's Audit foundational specs and fix Tool recovery and Workspace drop ownership #890–specs: audit release, supply-chain, and published security contracts #907 rewrite those specs.
git merge-treeconfirmed that docs(security-remote): name both Hosted spec sections the e2e-lint rules cite #919 conflicts with Audit remote contracts and keep Noise failures terminal #902, which edits line 62. I closed docs(security-remote): name both Hosted spec sections the e2e-lint rules cite #919 and posted the line as a suggestion on #902. Lesson for a live-scan fix:merge-treethe candidate against the open PRs touching the same file before opening, not just grep their diffs for the changed phrase.
Outage tracker drained
- Bot temporarily unavailable #883 had 1 row (the nightly above). I diagnosed it, commented, and closed the tracker. Nothing to retry.
Pre-registered watches
tend-notificationsunder-delivery, occurrence 26: 4 runs in ~23.5 h against*/15. None ran after 08:17Z, so security-audit FAIL [security-audit] FAIL on 2026-10-04 #908 (10:38Z) went without a bot response until this sweep. No lever.tend-mentionfan-out: 317 dispatches, 8 cancellations, $8.34 over 26 sessions. Driven by the maintainer's@dormouse-botreview requests across the two stacks. Cheap per run.tend-weeklycron move: first slot 10-04. Not yet observed.
Maintainer corrections
review_runs_corrections.pyran: 6 dispositions (Strip unreadable and oddly-spaced candidates from the offer under Local networks #874–Match the test rendezvous to Hosted's one-time room: late joins close 4010, pre-join frames count #878, skills(running-tend): skip the environment-gated Hosted preview jobs in CI polls #882, all merged), 5 maintainer approvals of bot PRs, and comment rows fromnedtwigg. All are "Fixed in …" acknowledgements of bot review findings or review requests, except one design decline on Replace the selection popup with an editable copy preview #885 (discussion_r4159736706: keeps the §3.8 shadowed-drag copy behavior the bot's finding would have changed). That is a declined suggestion, not a contradicted factual claim. No maintainer corrections.
Live scan
- Default branch:
red_default_branch_runs.pyconverged (unconverged_listings: []) and reached back to 2026-09-16T09:18:23Z.livecontains onlysecurity-audit: 10-01 ([security-audit] FAIL on 2026-10-01 #873, closed after its fixes) and 10-02 ([security-audit] FAIL on 2026-10-04 #908, handled above). Green reads: ci, argos, chromatic, hosted-production, security-audit, tend-mention, tend-nightly, tend-notifications, tend-review-runs, tend-weekly. - Waiting runs: 132
hosted-preview.yml, all non-tend, environment-gated. No tend queue wedge. - Dependabot: one alert (
glib), still tracked by Track Tauri GTK upgrade to remediate glib advisory #663. - Threads: All 16 open maintainer PRs have a bot review at their live head, or (Audit terminal and activity specs; fix recovery controls, launch state and push preview #891, Audit host contracts and bound peer frames by bytes #892) a silent re-review session I verified at that head that kept the approval. Fix comments left stale by the Hosted, alert-pause, and Surface-move work #909 is a bot PR. RelayRoom keeps a revoked Burrow forwarding when its sweep's row read fails #910 and
/enroll: a stale approval's completion clears a newer link's code #912–One-time phone client: WebCrypto and the socket's open have no deadline #914 have triage replies. Expiry checks insidelockedtransactions read the transaction's start time, before the lock wait #911 triage was in progress. [security-audit] FAIL on 2026-10-04 #908 and [workflow-audit] 24 unexplained change(s) on 2026-10-02 #915 were answered this run.
Run 37123854067 — 2026-10-03T12:54:00Z (review-runs)
Window
2026-10-02T14:09:27Z→ run start (~22.5 h). 665 tend runs censused (not a page boundary):tend-mention343 (322 success, 19 skipped, 2 cancelled),tend-review137 (all success),tend-mention-relay88,tend-ci-fix88 (1 success, 87 skipped),tend-notifications5,tend-triage2, nightly 1, review-runs 1. No long-running or near-timeout jobs: the longest was triage at 28 min wall-clock. The ~16-mintend-mentionruns at 23:37–23:45Z were runner queue time: theirhandlejobs ran for seconds or were skipped. Both cancellations (37115523082, 37115527213) were concurrency supersession from four quick inline replies on #957. Token report: $130.75.tend-review$103.02 over 137 runs (the highest was #957 at $6.31, 33 diagrams across 24 specs with 5 verify agents, and all four findings were applied by the maintainer), nightly $16.69, review-runs $3.23, triage $2.64, mention $2.40, notifications $2.11, ci-fix $0.66.Sessions sampled: nightly and the most expensive review were both sound
- Nightly 37120354611 opened chore: update tend workflows (0.3.5 → 0.3.6) #964 (tend 0.3.5→0.3.6), Open picker files whose names look like a URL scheme in dor o #965, and Repin @xterm/addon-serialize in pnpm bump:xterm #966, each with a regression test that fails without the fix, and polled with
--skip deploy --skip cleanup. All three are green. - Review 37115120173 on Specs: Mermaid diagrams for flows, state machines and ladders #957 posted a COMMENT with 4 suggestions.
nedtwiggapplied all of them in f78e1f2.
workflow-auditstale bound: fix #920 verified in production- [workflow-audit] 1 unexplained change(s) on 2026-10-03 #968, the first run after fix(workflow-audit): find the previous successful run without the stale status filter #920, used the bound
2026-10-02T13:48:12Z(the previous day's run) and listed onlyc66fa14, which is fix(workflow-audit): find the previous successful run without the stale status filter #920's own bot-pushed commit merged by an admin. I accounted for it on [workflow-audit] 1 unexplained change(s) on 2026-10-03 #968 (comment). Watch discharged.
Pre-registered watches
tend-notificationsunder-delivery, occurrence 27: 5 runs in about 22.5 h against*/15, none after 08:07Z. As a result the 10-03 security-audit FAIL on [security-audit] FAIL on 2026-10-04 #908 (10:02Z) had no bot response until this sweep, which is the second day running for the same issue. No lever.tend-mentionfan-out: 343 dispatches, 2 cancellations, $2.40 over 11 sessions with logs. Cheap.tend-weeklycron move: first slot is 10-04. Not yet observed.
Maintainer corrections
review_runs_corrections.pyran and returned 7 dispositions (Fix comments left stale by the Hosted, alert-pause, and Surface-move work #909, fix: end the one-time phone's pre-outcome waits at the room's deadline #916–fix: settle OneTimeRuntime.open() at its deadline while key generation stalls #918, fix(workflow-audit): find the previous successful run without the stale status filter #920, Make the relay's deleted-offer redemption test deterministic #940 merged, and docs(security-remote): name both Hosted spec sections the e2e-lint rules cite #919 closed by the bot itself in the previous sweep), comment rows from Cloudflare,github-actions, andnedtwigg, and 0 reviews. Everynedtwiggrow acknowledges a bot finding as applied (Keep port and process probes off the PTY input thread #928 ×2, Add an MDXEditor Markdown editor to builtin:file #929, Allow interactive drops across contiguous pane groups #905, Specs: Mermaid diagrams for flows, state machines and ladders #957 ×4, Invisible surfaces cost nothing: one resource policy for browser panes #958, Fix bugs exposed by the Mermaid spec survey #959, Dor Tools: reap idle Tools and dehydrate/rehydrate them (D1, D2) #961 ×2, Spec: reopen closed Surfaces, and Labs delayed kill (design) #963, Restore native copy and paste in Tool iframes on macOS #943). No maintainer corrections.
Live scan
- Default branch:
red_default_branch_runs.pyconverged (unconverged_listings: []) and reached back to 2026-09-17T17:45:51Z.liveholds onlysecurity-audit(10-01, 10-02, 10-03, all on [security-audit] FAIL on 2026-10-04 #908). Workflows with a green read: ci, argos, chromatic, hosted-production, security-audit (09-30), tend-mention, tend-nightly, tend-notifications, tend-review-runs, and tend-weekly. - [security-audit] FAIL on 2026-10-04 #908, 10-03 FAIL: I verified all three FAILs at
ae2a17dand answered on #908: the Hosted/api/auth/*Origin gate (code), therequireUserVerificationmirror being snapshotted only at enroll (a policy choice), and the image-paste POST that is not JSON (spec drift). I opened no PRs, because two of the three need a decision on which side to fix. - Waiting runs: only
hosted-preview.yml, which is environment-gated and not tend. No tend queue wedge. No outage trackers. - Dependabot: one alert (
glib), still tracked by Track Tauri GTK upgrade to remediate glib advisory #663. - Threads: Labs: no-confirm delayed kill (pending kills with a restore window) #969 (maintainer) had
tend-reviewandtend-mentionrunning at its live headd56d18b44. chore: update tend workflows (0.3.5 → 0.3.6) #964–Repin @xterm/addon-serialize in pnpm bump:xterm #966 are bot PRs. [workflow-audit] 1 unexplained change(s) on 2026-10-03 #968 was answered this run. RelayRoom keeps a revoked Burrow forwarding when its sweep's row read fails #910 and/enroll: a stale approval's completion clears a newer link's code #912 have triage replies. peer-link: closing a displaced server unlinks the winner's socket #756 has the bot's 10-02 CI-recurrence comment.
Run 37205764571 — 2026-10-04T13:36:03Z (review-runs)
Window
2026-10-03T12:44:37Z→ run start. 445 tend runs censused (not a page boundary):tend-mention236 (220 success, 13 skipped, 3 cancelled),tend-review79 (all success),tend-mention-relay76,tend-ci-fix45 (2 success, 43 skipped),tend-notifications6, nightly 1, triage 1, review-runs 1. No failures, no long-running or near-timeout jobs: longest was ci-fix 37129084869 at 27 min (200/400-run local flake loops; no workflow setstimeout-minutes, so the 360-min default applies). Token report: $86.10 —tend-review$61.96 over 79 runs (top #987 $4.73), nightly $8.33, mention $6.94 over 22 sessions, ci-fix $4.21, review-runs $2.13, notifications $1.52, triage $1.01.Sessions sampled: all sound
- ci-fix 37129084869 opened Fix three flakes in the sidecar's tool-reap test, including a never-exiting run, and bound CI's Test step #970 for the
tool-reap.test.jshang (lost SIGHUP); reproduced 12/200 locally, green atbe189aca. Maintainer merged it. Sibling 37130700995 (attempt-2 notification) found Fix three flakes in the sidecar's tool-reap test, including a never-exiting run, and bound CI's Test step #970, commented instead of duplicating. - Nightly 37201822366 opened chore: update tend workflows (0.3.6 → 0.3.7) #1004–Fix comments and a guide path left stale by the delayed-kill, Run end, and installer work #1006, all green at their live heads.
- Draft reviews on Managed voice in VS Code #1000 (37186410294) and Onboarding walkthrough fixes (five personas) #1003 (37191229225) posted nothing: both logs show a full review plus second pass with no actionable findings. Designed silence per draft-mode.
Pre-registered watches
tend-notificationsunder-delivery, occurrence 28: 6 runs in ~23 h against*/15, none after 08:47Z. The 10-04 security-audit FAIL on [security-audit] FAIL on 2026-10-04 #908 (10:57Z) had no bot response until this sweep — third day running. No lever.tend-mentionfan-out: 236 dispatches, 3 cancellations, $6.94. Cheap.tend-weeklycron move: slot is Sunday 15:17Z, after this sweep. Not yet observed.
Maintainer corrections
review_runs_corrections.pyran: 4 dispositions (chore: update tend workflows (0.3.5 → 0.3.6) #964, Open picker files whose names look like a URL scheme in dor o #965, Repin @xterm/addon-serialize in pnpm bump:xterm #966, Fix three flakes in the sidecar's tool-reap test, including a never-exiting run, and bound CI's Test step #970, all merged), 0 reviews, comment rows from Cloudflare,github-actions, andnedtwigg. Everynedtwiggrow acknowledges a bot finding as applied (Labs: no-confirm delayed kill (pending kills with a restore window) #969 ×3, Spec: Tool designation per run, and Break (scope tool-run) #977, Cut host specs to contracts; transport.md owns rules both hosts share #982 ×2, Cut tiling-engine, layout, alert, glossary to contracts #986, Break: split a Tool into its plain terminal and a browser pane (scope tool-run, part 2) #980 ×2, Security specs: security.md owns every gap, audited rules are FAIL IFs, prompts cite sections; escape C1 in dor output #987 ×7, Restart a hung webview onto the live sidecar (UI watchdog) #993, Hosted: bind the relay and voice Workers to their own least-privilege Hyperdrives #995, A Tool ends with its run; host replacements hold it (scope tool-run, part 1) #979 ×3 incl. "You're right"), plus tool-reap test: never hang the sidecar suite #971 superseded by the maintainer's Fix three flakes in the sidecar's tool-reap test, including a never-exiting run, and bound CI's Test step #970 and one design decline on Restart a hung webview onto the live sidecar (UI watchdog) #993 (keeps the 5 s watchdog threshold). No maintainer corrections.
Live scan
- Default branch:
red_default_branch_runs.pyreached back to 2026-09-17T17:57:48Z; candidates onlysecurity-audit10-01..10-04, all on [security-audit] FAIL on 2026-10-04 #908. 10-04's FAIL is new (UI watchdoghangs/written outsidewrite_file_atomically); verified at0b6968dand answered on #908 with the one-call fix (prepare_owner_only_dir) vs. spec carve-out left to the maintainer. No PR: side-of-fix decision, and the state root's0700already mitigates. - Waiting runs: 214
hosted-preview.yml, all non-tend, environment-gated. No tend queue wedge. No outage trackers. - Dependabot: one alert (
glib), tracked by Track Tauri GTK upgrade to remediate glib advisory #663. - Threads: open maintainer PRs Hosted: bind the relay and voice Workers to their own least-privilege Hyperdrives #995–Onboarding walkthrough fixes (five personas) #1003 all have a bot review at their live head, or (Managed voice in VS Code #1000, Onboarding walkthrough fixes (five personas) #1003 drafts) a silent review session verified above. Bot PRs chore: update tend workflows (0.3.6 → 0.3.7) #1004–Fix comments and a guide path left stale by the delayed-kill, Run end, and installer work #1006 green; Fix Windows PTY graceful shutdown to close ConPTY instead of signaling #985 red by design (failing repro for gracefulKill is a no-op on Windows: node-pty kill(signal) throws and is swallowed #984).
Run 37340496763 — 2026-10-05T16:29:20Z (review-runs)
Window
2026-10-04T13:28:54Z→ run start. 73 tend runs censused (not a page boundary):tend-mention39 (34 success, 5 skipped),tend-review13,tend-mention-relay11,tend-notifications6 (5 success, 1 failure), nightly 1, weekly 1, review-runs 1, triage 1 (skipped). No long-running or near-timeout jobs: longest was nightly 37326344621 at 26 min (360-min default cap). Token report: $24.57: nightly $10.72,tend-review$9.46 over 13 runs (top #1009 $1.46), review-runs $1.81, notifications $1.71, mention $0.63 (2 sessions), and weekly $0.24.Failure:
tend-notifications37311191249 was an Anthropic 529 Overloaded on the first turn- Evidence level: Low (transient upstream outage, not a tend or repo defect)
- Occurrences this run: 1
- Run ID: 37311191249
- Workflow: https://github.com/diffplug/dormouse/actions/runs/37311191249
- Session: a4224b11-8ee2-4113-a4d6-ebae332ec0ce.jsonl (one assistant turn:
API Error: 529 Overloaded) - Detail: Outage tracker Bot temporarily unavailable #1014 opened automatically. I checked what that run might have missed: the unread notifications are Update github-actions #1012, Update cargo #1013, chore: update tend workflows (0.3.7 → 0.3.10) #1015–Hosted docs: only the relay's role is checked before the account deploys #1019, and each has a bot review at its live head or is a bot PR with green CI. I closed Bot temporarily unavailable #1014.
Sessions sampled: all sound
- Nightly 37326344621 opened Keep the playground changelog open on modified arrow and page keys #1018 (a key-parser fix with a test that fails on
main) and Hosted docs: only the relay's role is checked before the account deploys #1019 (a Hosted README fix). Both are green. tend-reviewon Renovate Update cargo #1013 (cargo) found that the bump silently drops thediffplug/taofork patch ([[patch.unused]]), plus the Build & Test dependency-disclosure failure. It posted COMMENT, not APPROVE, and asked a maintainer to cut the fork branch. That is a strong catch.- Weekly 37225248956 had no dependency PRs open on 10-04 and no repo weekly tasks, so it was a correct no-op.
Pre-registered watches
tend-notificationsunder-delivery, occurrence 29: 6 runs in ~24 h against*/15(one failed with a 529). No lever.tend-mentionfan-out: 39 dispatches and 2 sessions, $0.63. Cheap.tend-weeklycron move: discharged. The Sunday17 15slot started at 18:39Z (3 h 22 m GitHub delay), still after the quota reset, and the run succeeded. The Renovate PRs that opened on Monday will reach next week's run;tend-reviewalready reviewed them.
Maintainer corrections
review_runs_corrections.pyran: 1 disposition (chore: update tend workflows (0.3.6 → 0.3.7) #1004 merged), 0 reviews, and comment rows from Cloudflare,github-actions([security-audit] FAIL on 2026-10-04 #908 audit passed 10-05), andnedtwigg. On Workspace tab context menu and pinned-right Workspaces #1009,nedtwiggapplied a bot finding with a test. On Redesign the terminal context: denser, and torn from its source #1010,nedtwiggdeclined a bot review finding as an intentional design choice (the context covers the header), andtend-mention37242646256 handled it. That decline is a design ruling, not a contradiction of a factual claim. No maintainer corrections.
Live scan
- Default branch:
red_default_branch_runs.pyreached back to 2026-09-17T19:00:49Z. Its candidates were olderci.yml,tend-nightly, andtend-notificationsfailures, andobserved_green_by_pathshowed a stale 09-04 green forci.yml. Later green runs onmainclose them all: CI 37239757941 at269b3faon 10-04, nightly 37326344621 today, and notifications 37269000331 on 10-05.security-auditpassed on 10-05 ([security-audit] FAIL on 2026-10-04 #908). - Waiting runs: 222 for
hosted-preview.yml(non-tend, environment-gated). No tend queue wedge. - Dependabot: one alert (
glib), tracked by Track Tauri GTK upgrade to remediate glib advisory #663. - Outage trackers: I drained Bot temporarily unavailable #1014 (above) and closed it.
- Threads: Renovate Update pgstencil to ^0.3.0 #1011–Update cargo #1013, Update dependency @argos-ci/cli to v6.9.6 #1016, and Update dependency @argos-ci/storybook to v6.4.2 #1017 each have a bot review at their head. Bot PRs Leave no Reopen record when a restored Workspace's unused replacement closes #1005, Fix comments and a guide path left stale by the delayed-kill, Run end, and installer work #1006, chore: update tend workflows (0.3.7 → 0.3.10) #1015, Keep the playground changelog open on modified arrow and page keys #1018, and Hosted docs: only the relay's role is checked before the account deploys #1019 are green and mergeable. Fix Windows PTY graceful shutdown to close ConPTY instead of signaling #985 is red by design. [workflow-audit] 1 unexplained change(s) on 2026-10-04 #1007 (workflow-audit 10-04) was answered by the bot.
Run 37479274755 — 2026-10-06T14:34:09Z (review-runs)
Window
2026-10-05T16:23:46Z→ run start. 59 tend runs censused (not a page boundary):tend-mention34 (27 success, 6 skipped, 1 failure),tend-review11 (9 success, 2 failure),tend-mention-relay9,tend-notifications3 (2 success, 1 failure), nightly 1, review-runs 1. Everytend-mentionsession ended atverify(nohandlejob ran). No long-running or near-timeout jobs: the longest was nightly 37469699567 at 28 min (360-min default cap). Token report: $15.86: nightly $7.28,tend-review$5.46 over 9 runs (top #1024 $0.89), notifications $1.84, review-runs $1.28.All four failures were GitHub runner starvation at 20:08–20:47Z on 10-05
- Evidence level: Low (GitHub infrastructure, not tend or repo). Occurrence 1.
- Run IDs: review 37367901506 (Update dependency @mdxeditor/editor to v4.3.2 #1020), review 37367921320 (Update dependency @types/node to v24.19.1 #1021), mention 37368018350, notifications 37371855238
- Detail: Each job ran zero steps and was cancelled at 15 min with the annotation "The job was not acquired by Runner of type hosted even after multiple attempts". Because no step ran, no outage tracker opened either. The same outage cancelled every CI job on Renovate Update dependency @mdxeditor/editor to v4.3.2 #1020 and Update dependency @types/node to v24.19.1 #1021. Notifications 37400221926 picked both PRs back up at 01:38Z.
tend-notificationsapproved #1021 over CI that never ran; I reran it- Evidence level: Low (designed). Occurrence 1.
- Run ID: 37400221926
- Detail:
poll_pr_checks.py approval 1021returnedapproveand listed the 5 cancelled jobs as unverified. That is upstream's intended treatment of CANCELLED since tend#1323. The review body disclosed that CI never verified the head. The session's own narration said "checking the approval rules before rerunning its cancelled CI", but it never reran, so the APPROVE stood over an untested head. This sweep rangh run rerun --failedon CI 37367920310 and Hosted preview 37367920325. Not a bundled defect. A second occurrence of an approval standing over a never-rerun runner-starved CI would justify an overlay line telling the reviewer to rerun it.
Sessions sampled: all sound
- Review 37404543587 on Renovate Update hono #1024 (hono) found the stale
dependencies-npm.jsondisclosure. It applied the diff that CI printed, because the sandbox has no registry access, and pushedfc636a5. The PR is green and approved. Notifications did the same on Update dependency @mdxeditor/editor to v4.3.2 #1020 (d64a6da). This now looks like the steady pattern for Renovate npm bumps. - Nightly 37469699567 moved chore: update tend workflows (0.3.7 → 0.3.10) #1015 to tend 0.3.10 and opened Fix six comments that no longer match the code they describe #1025, which fixes 6 stale comments. Fix six comments that no longer match the code they describe #1025's only red check is
argos/storybook-chromium(1 changed, awaiting a decision). On a comment-only PR that is a baseline issue, and it is disclosed in the PR body. - The notifications session flagged that
@pgstencil/[email protected]is deprecated ("OAuth breaks with better-auth 1.7.7"). Renovate Update pgstencil to ^0.3.0 #1011 (pgstencil ^0.3.0) already proposes the move.
Pre-registered watches
tend-notificationsunder-delivery, occurrence 30: 3 runs in about 22 h against*/15, one of them runner-starved. No lever.tend-mentionfan-out: 34 dispatches, none reachedhandle, $0. Cheap.
Maintainer corrections
review_runs_corrections.pyran and returned 0 dispositions and 0 reviews. The only non-Cloudflare comments were two Renovate "Edited/Blocked" notices on Update github-actions #1012 and Update hono #1024: Update hono #1024's comes from the bot's disclosure commit, and Update github-actions #1012's predates its current head. No maintainer corrections.
Live scan
- Default branch:
red_default_branch_runs.pyreached back to 2026-09-19T08:48:29Z. Its candidates were only the 10-05tend-notificationsfailures (the 529 from the previous sweep and the starvation above). Later green notifications runs 37400221926 and 37434106997 close both. - Waiting runs: 227
hosted-preview.ymlruns (not tend, environment-gated). No tend queue wedge. - Dependabot: one alert (
glib), tracked by Track Tauri GTK upgrade to remediate glib advisory #663. - Outage trackers: none open, and none were closed in the window.
- Threads: Renovate Update github-actions #1012, Update dependency @mdxeditor/editor to v4.3.2 #1020–Update hono #1024 are approved at their live heads. Bot PRs Leave no Reopen record when a restored Workspace's unused replacement closes #1005, Fix comments and a guide path left stale by the delayed-kill, Run end, and installer work #1006, chore: update tend workflows (0.3.7 → 0.3.10) #1015, Keep the playground changelog open on modified arrow and page keys #1018, and Hosted docs: only the relay's role is checked before the account deploys #1019 are green. Fix six comments that no longer match the code they describe #1025 is red only on Argos. Fix Windows PTY graceful shutdown to close ConPTY instead of signaling #985 is red by design. No open issue has unanswered human activity.
Run 37639349476 — 2026-10-07T14:53:01Z
Window
2026-10-06T14:28:36Z→ run start (~24 h). 127 tend runs censused (not a page boundary):tend-mention59 (49 success, 10 skipped — everyhandlejob skipped at the verify gate, no session),tend-ci-fix33 (4 success, 29 skipped),tend-review19,tend-mention-relay9,tend-notifications5 (3 pre-boot exits with no unread notifications), nightly 1, review-runs 1. Zero failures, zero cancellations, no job ≥20 min. Token report: $23.37 over 27 sessions —tend-review$11.04 / 19, nightly $6.74, notifications $2.14, ci-fix $2.10, review-runs $1.35.Maintainer corrections
The Step 4 script ran and returned 7 dispositions (all merges: #985, #1005, #1006, #1015, #1018, #1019, #1025), 0 reviews, and 13 comment rows, all
cloudflare-workers-and-pagesdeploy tables or a Renovate edited/blocked notice. No maintainer corrections.Live scan
- Bot PRs: fix: write the macOS hang sample owner-only under the state root #1028 (security-audit fix for [security-audit] FAIL on 2026-10-07 #1027; its own review finding was applied as
ad01c2e, CI green), docs: describe pty:reap and quit teardown as a graceful stop, not SIGTERM #1029 and test: make two guard tests fail when the guard is removed #1030 (nightly, CI green, no review posted on the bot's own PRs). All three await a maintainer in restricted mode; no post needed. - Red default branch: one candidate,
security-auditrun 37611688358 → tracked by [security-audit] FAIL on 2026-10-07 #1027, fix in fix: write the macOS hang sample owner-only under the state root #1028. Scope:red_default_branch_runs.pypages back to 2026-09-20T11:48Z. status=waitingruns: allhosted-preview.yml(maintainer-approval environment, not tend). No wedged tend queue.- Dependabot: maybe: drop node-pty for a Rust backend #1 glib (tracked by Track Tauri GTK upgrade to remediate glib advisory #663); UI improvements #5 rustls 0.23.40 → 0.23.45 opened 2026-10-07T00:12Z, under a day old, no PR yet — re-check next run (Renovate's cargo update is the usual path).
- Outage trackers: none.
ci-fix sessions on maintainer-cancelled runs — designed, no action
37551824621 and 37551864301 ($0.65 total) opened sessions on CI runs
nedtwiggcancelled while batch-merging Renovate PRs; both correctly concluded "deliberate cancel, nothing failed" and posted nothing. tend 0.2.x fires ci-fix oncancelledtoo (recorded 2026-09-10). Designed no-op.Unguarded PATCH after a failed body edit — occurrence 1, Low, no action
- Run ID: 37561073758 (
tend-reviewon Fix Windows PTY graceful shutdown to close ConPTY instead of signaling #985) - Workflow: https://github.com/diffplug/dormouse/actions/runs/37561073758
- Detail: a python body-rewrite asserted on a paragraph the maintainer had just rewritten; with no
set -e, the same command then PATCHed title + body from the filegh pr viewhad written seconds earlier. The body re-saved unchanged (verified against the live body), so no maintainer text was lost. Stochastic, one occurrence; record only. Would become a finding if a later case PATCHes a stale body over a newer maintainer edit.
Healthy signals worth keeping in the record
- nightly 37628060177 opened docs: describe pty:reap and quit teardown as a graceful stop, not SIGTERM #1029 and test: make two guard tests fail when the guard is removed #1030 after three subagent sweeps; still no local pnpm (known, maintainer-deferred
setup:trade-off from 2026-09), worked around via CI. It slept 900 s in the background twice while subagents ran; harmless, total job < 20 min. - ci-fix 37553077233 and 37560351978 updated ci-fix: CI failing — Windows PowerShell browser-launch test intermittently hangs past 15s #839 with new timing evidence (a 12.6 s pass) rather than opening a duplicate.
- review 37615703034 on bot PR fix: write the macOS hang sample owner-only under the state root #1028 found a real partial-file gap and pushed the fix itself; the follow-up review verified it.
Run 37796665900 — 2026-10-08T15:06:33Z
Window
2026-10-07T14:45:13Z→ run start (~24 h). 512 tend runs censused (not a page boundary):tend-mention273 (246 success, 24 skipped, 3 cancelled by concurrency),tend-review91,tend-mention-relay85,tend-ci-fix54 (4 success, 50 skipped),tend-notifications4,tend-triage3, nightly 1, review-runs 1. Zero failures. The longest jobs weretend-review37699124077 (#1048, 34 min) and 37671569711 (#1031, 31 min). Both spent the time polling CI; #1048's included a rerun after an apt-mirror failure. The cap is 360 min with no override, so no job came near it. Token report: $89.53 over 132 sessions,tend-review$60.67 / 91, nightly $11.76, mention $9.47 / 30, ci-fix $3.96, review-runs $1.79, notifications $1.38, triage $0.50. The cost is high because maintainer PR throughput was high (#1031–#1068). No subject is an outlier; the most expensive is #1057 at $5.56 over 10 runs.ci-fix opened a hardening PR for a one-off apt-mirror stall, and the maintainer closed it as not worth the complexity. Occurrence 1, Medium, stochastic, record only
- Evidence level: Medium
- Occurrences this run: 1 (none found in the 2026-09/10 evidence)
- Run ID: 37678040336
- Workflow: https://github.com/diffplug/dormouse/actions/runs/37678040336
- Session: eafd8be3-8287-4fe9-abb6-f53433bccc77.jsonl
- Detail: An Ubuntu mirror stall made Argos 37674202964 on
mainhit its 30-min cap and be cancelled. ci-fix opened ci(argos): bound and retry the browser system-dependency apt install #1035, which added bounded, retriedinstall-depstoargos.yml. Its verification was careful: two dispatched branch runs, both green.nedtwiggclosed it: "hasn't often been a problem. Not worth the complexity right now". The same day, ci-fix handled the same mirror stalls on Standalone Smoketest astransient failuretrackers, which is the cheaper path. Watch for a second ci-fix PR that hardens against a one-off infra transient. Five or more occurrences would justify an overlay line ("a single infra transient gets a tracker, not a workflow change").
Maintainer clarified a draft-review point on #996. Low, record only
nedtwiggreplied that the page "presents the plan as live on purpose" because #996 heads a stack (#999–#1003) that builds it. The review read #996 in isolation. That is the same shape as the earlier "closed on knowledge the bot could not have had" entry, and it is not a review defect. The other review findings on #996 were applied.Maintainer corrections
The Step 4 script ran and returned 4 dispositions, 75 comment rows and 0 reviews. #1028, #1029 and #1030 merged. #1046 (the bot's spec-budget fix for
main) was closed without comment becausenedtwigg's own merge39702ced7trimmed the spec under budget, so it was superseded rather than corrected. #1035 is covered above. The only correction of a bot claim is #996. Every other non-deploy comment row is a maintainer accepting a review finding ("Applied", "Fixed in", "Agreed"), about 25 in all.Live work
- Dependabot UI improvements #5 (rustls 0.23.40, GHSA-2mjx-qc3c-rqvc) was open about 37 h with no PR. Renovate's
vulnerabilityAlertshas a 1-day cooldown, and 0.23.45 was published 2026-09-14, so its PR was overdue. Acted on: Bump rustls to 0.23.45 to fix GHSA-2mjx-qc3c-rqvc #1073, a lockfile bump (rustls 0.23.45, rustls-webpki 0.103.15) plus the website dependency disclosure. Hand-edited because cargo 1.99 also re-resolved six unrelatedwindows-sysedges.cargo fetch --lockedpasses. Pre-registered watch: if another security alert outlives Renovate's 1-day cooldown with no Renovate PR, Renovate's vulnerability-alert path is not firing here and needs a maintainer to look at the app's Dependabot-alert permission. - workflow-audit [workflow-audit] 2 unexplained change(s) on 2026-10-08 #1072 flagged two unexplained commits,
99af331andb7bdb67. Both are on the closed, unmerged ci(argos): bound and retry the browser system-dependency apt install #1035's branchfix/ci-37674202964, and neither is an ancestor ofmain. I answered on the issue. - Bot PRs Stop a displaced PTY with SIGHUP so an interactive bash actually exits #1070 (green) and Correct stale comments and testing-guide pointers #1071 (nightly; the review session pushed
aec746500and owns its CI) await a maintainer. - Maintainer PRs Privacy and Terms for paid Hosted #997–Onboarding walkthrough fixes (five personas) #1003 each have a bot review at their live head, except the drafts Managed voice in VS Code #1000 and Onboarding walkthrough fixes (five personas) #1003, which were verified as designed silence on 10-04.
- Red default branch: no candidates in the returned pages (back to 2026-09-23T19:09Z).
status=waiting: allhosted-preview.yml, which is maintainer-gated and not tend. Dependabot maybe: drop node-pty for a Rust backend #1 glib is still tracked by Track Tauri GTK upgrade to remediate glib advisory #663. Outage trackers: none.
Healthy signals
- Nightly 37784700821 found a real bug: a displaced PTY got SIGTERM, which interactive bash ignores. It confirmed the bug on a real
bash -iand opened Stop a displaced PTY with SIGHUP so an interactive bash actually exits #1070 (green). It also filed tend check: configuration drift on diffplug/dormouse #1069 ontend checkdrift and correctly declined to run--fix, which would have broken the Hosted tagger. - Review 37699124077 skipped a full re-review for a docs-only fix push, resolved its own thread, and reran an apt-mirror failure to green before it approved.
Run 37946019792 — 2026-10-09T14:50:24Z
Window
2026-10-08T14:56:54Z→ run start (~24 h). 144 tend runs censused (not a page boundary):tend-mention80 (65 success, 15 skipped),tend-review28,tend-ci-fix14 (all skipped),tend-mention-relay11,tend-triage5,tend-notifications4, nightly 1, review-runs 1. Zero failures. Longest job: nightly 37935723024 at 19 min; the cap is 360 min (no override). Token report: $40.01 over 40 sessions —tend-review$23.28 / 28, nightly $9.07, triage $3.09 / 5, review-runs $2.57, notifications $1.30, mention $0.70 / 2. Outlier: review of #1085 at $6.05 in one run (a 100+ file draft); sampled below and sound.Live work: zizmor impostor-commit failure on the
dtolnay/rust-toolchainpin. Acted on: #1088- Evidence level: Critical-for-CI (every PR red), structural, external cause
- Run ID: 37946019792
- Detail: Upstream force-pushed
stableat 2026-10-09T02:03Z (89b12181→686976e1, diverged 1/4), orphaning the commit pinned atci.yml:263,ci.yml:352,release.yml:59.Workflow Lintfailed on Hosted: show a failed account lookup's error instead of redirecting to the devlog #1086 and Fix comments and docs left stale by the alert deferral, tutorial, and Lath tool work #1087;main's last CI (23:50Z 10-08) predates it. Renovate's github-actions group runs Mondays only. Repin dtolnay/rust-toolchain after its stable branch was force-pushed #1088 re-pins to686976e1(upstream change is Safely handle action inputs dtolnay/rust-toolchain#187, input-injection hardening); itsWorkflow Lintpassed. Watch: if upstream rewritesstableagain, consider pinning to amastercommit instead — record occurrences here.
Nightly declined the re-pin on a cooldown that does not cover action pins. Occurrence 1, Medium, stochastic, record only
- Evidence level: Medium
- Occurrences this run: 1
- Run ID: 37935723024
- Workflow: https://github.com/diffplug/dormouse/actions/runs/37935723024
- Session: d4e1bdd8-2143-4e3f-890a-782a929e6f89.jsonl
- Detail: Nightly diagnosed the zizmor failure correctly but left it for Renovate because "the new upstream commit is younger than the 1-day Renovate cooldown".
docs/specs/security-supply-chain.md-> "Cooldown and alerts" covers npm, cargo, zizmor and actionlint only, and.github/renovate.jsongives github-actions nominimumReleaseAge. No wrong outward action — the cost was a known CI break left open. It also posted the cause on Hosted: show a failed account lookup's error instead of redirecting to the devlog #1086/Fix comments and docs left stale by the alert deferral, tutorial, and Lath tool work #1087, saw the review already had, and deleted its own duplicates (self-corrected).
Sessions sampled: sound
- Review 37865014293 on draft One spelling for Surface and Workspace ids: surface:<n>, never reused #1085 ($6.05): two sub-reviews over a 100+ file diff, four low-severity candidates dropped per the overlay's hardening rule, designed draft silence. Cost driven by diff size.
- Nightly 37935723024: opened Hosted: show a failed account lookup's error instead of redirecting to the devlog #1086 (Hosted lookup-error bug) and Fix comments and docs left stale by the alert deferral, tutorial, and Lath tool work #1087 (stale comments); both green except the external
Workflow Lintbreak.
Maintainer corrections
Step 4 script ran: 4 dispositions (#1070, #1071, #1073, #1077 merged — the bot's rustls bump #1073 landed), 12 comment rows, 0 reviews. No maintainer corrections.
nedtwiggclosed #603 as superseded by the implemented history sweep (not a correction of a bot claim); on #1081 they applied a bot finding.Live scan
Bot PRs #1086, #1087 (green but
Workflow Lint, fixed by #1088), each reviewed at their head. Triage on #1074–#1079 each answered. Red default branch: no candidates (back to 2026-09-23T19:09Z).status=waiting: allhosted-preview.yml/hosted-production.yml, maintainer-gated. Dependabot #1 glib still tracked by #663 (#5 rustls closed by #1073). Outage trackers: none.
Monthly tracking issue for below-threshold findings. Each run appends findings as a comment. Future runs read these to build cumulative evidence.
Do not close manually — a new issue is created each month, and prior months are closed automatically.