Skip to content

Owner decision sheet D1–D48: one answerable place for #637 + #715 + #709 + #658 and this week's unfiled decisions #787

Description

@hyperpolymath

Four registers currently hold owner decisions — #637 (17 rows), #715 (O1–O10), #709 (4 of 7 still open), #658 (blocker 1) — plus decisions arising from this week's measurements that are filed nowhere. Answering them today means opening four threads and reconstructing what each question was.

This is the single answerable sheet. 48 decisions, stable IDs. Answer format that works: D3c, D7a, D19a. Each of #637 / #715 / #709 / #658 gets a pointer comment to here; none of them is closed, and the evidence stays where it is.

Every option marked (E) is the arm judged most elegant and correct long-term under the 2026-09-14 standing methodology — correctness, no deferred breakage, no special cases, fix the generator not the instance; never effort, speed or convenience. Where the recommendation departs from (E), the departure is stated rather than merged into the label.

Read this first — three rulings and their surfaces now disagree

Finding
#756 MERGED. The 09-09 ruling held it until the owner said the leaked Cloudflare token was dead, and stated the resume trigger was a sentence, not an observation. It landed without one. → D1
affinescriptiser#69 CLOSED, mergedAt=null, 2026-09-14T17:15:51Z. The 09-14 TokenPermissions ruling was "close the whole 21-PR family, land only affinescriptiser #69". The one PR ruled to land is the one that did not. → D2
hypatia #72/#82/#83 All three are merged Dependabot bumps, not the test-gate item the 09-14 sequencing referred to. The order #72 → #82 → merge #780 → #83 cannot be executed as written. → D3

The pattern is that rulings are being given but not closed on the surface they govern — which is the same failure already recorded as "a ruling living only in memory must be given twice".


TIER 1 — blocks work right now

D1. Is the leaked Cloudflare token dead?

→ RULED 2026-09-15, estate-wide: D1a — the leaked Cloudflare token is DEAD; hold CLEARED. stapeln's measured 19→0 gitleaks cure proceeds. This is the sentence the 09-09 ruling required as its resume trigger. (ruling comment)

(a) Yes — clear the hold; stapeln's measured 19→0 cure proceeds (E) · (b) Not yet — the merge was premature, re-hold anything reading that credential · (c) Rolled, so the audit-log actor census is moot.
A hold whose resume trigger is a sentence must be closed by a sentence, or the trigger was never real.

D2. affinescriptiser#69 closed unmerged against the ruling.

→ RULED 2026-09-15, estate-wide: D2a — reopen affinescriptiser#69 and land it as originally ruled. ⚠ Overrode the recommended (c) regenerate-first. (ruling comment)

(a) Reopen and land it as ruled (E) · (b) The ruling is superseded — leave closed, record why · (c) Regenerate it after the hypatia ^permissions: column-0 anchor fix and land the regenerated version.
Recommended: (c) — departs from (E) because the same ruling said regenerate, never revert, and landing the old diff re-lands output from the generator that is still broken.

D3. hypatia#780 — the hold is unsatisfiable as written.

→ RULED 2026-09-15, estate-wide: D3a — keep holding hypatia#780 until the test gate genuinely works. ⚠ Overrode the recommended (c). Consequence accepted knowingly: the hold has no finite completion date, and curing startup death is now the critical path for #780. (ruling comment)

Measured: tests.yml has never succeeded once, and 10 of 22 workflows startup-die, so the gate cannot pass until startup death is cured separately. Meanwhile 449 consumers are red with no SARIF.
(a) Keep holding until the test gate genuinely works (E) · (b) Merge #780 now on its own verification (18 tests 18 fail → 0) · (c) Merge #780 and open the startup-death cure as its own unit, gate re-armed after.
Recommended: (c) — departs from (E) because (E) has no finite completion date here and 449 red consumers is breakage happening now, not deferred. (c) still fixes the gate rather than absorbing the failure.

D4. Who owns the 61 orphan-pin rows? (#782, #42)

→ RULED 2026-09-15, estate-wide: D4c — neither session repins the 61 orphan-pin rows until the bumper asserts ancestry. Fix the generator, not the 61 instances. (ruling comment)

They are R-2-EXTENDED's 17 refs / 11 repos; the 09-09 ruling says the owner names who stands down.
(a) This session stands down, pin-repair owns all 61 · (b) This session takes them · (c) Neither repins until the bumper asserts ancestry (E).
Recommended: (c) — pinning the PR head is what manufactured these, so repairing 61 instances while the generator still captures PR heads recreates them on the next run.

D5. Where does the ancestry assertion live?

→ RULED 2026-09-15, estate-wide: D5c — one shared ancestry assertion in standards, called by every bumper. With D4 this is what unblocks the 61 rows; D19 makes it mandatory, not optional. (ruling comment)

(a) PR the peer-owned pin-repair.sh · (b) Stays a filed issue, peer implements · (c) One shared assertion in standards that every bumper calls (E).
Recommended: (c) — (b) leaves each bumper to reimplement the same four checks; (a) writes on another session's surface.

D6. Manifesto + explainmes (#783, #43)

→ RULED 2026-09-15, estate-wide: D6b — a separate follow-up PR after #783 merges for CCCP-MANIFESTO.adoc and the 4 uncovered EXPLAINME files. (ruling comment)

PR #783 covers 6 files including 1 of 5 EXPLAINME files, and not CCCP-MANIFESTO.adoc; the instruction was "plus the manifesto and the explainmes".
(a) Extend #783 · (b) Separate follow-up PR after #783 merges (E) · (c) The RSR-PHILOSOPHY.adoc text is sufficient propagation, close #43.
Recommended: (b)#783 explicitly asks not to be merged as a formality, so loading it with a second concern works against its own review.

D7. Re-run the pin-consumption census?

→ RULED 2026-09-15, estate-wide: D7a — re-run the pin-consumption census. ⚠ Execution waits for a fresh credit window: ~1,400 calls is not safely budgetable against GitHub's secondary rate limit, which a peer hit twice on plain GETs while core read 5000/5000. (ruling comment)

The published 10.3% background rate came off a table contaminated by a grep -m1 defect (script fixed, TSV still dirty). Cost ≈1,400 API calls.
(a) Re-run (E) · (b) Annotate the TSV as superseded and stop quoting the rate.


TIER 2 — the standing register

From #709 — 3 of 7 answered 2026-09-03, these remain

D8. #662 wordpress-tools. (a) retire/archive (E) · (b) restore CI to green · (c) close as-is, mark dormant. Carries wordpress-tools#66 (246 files in .git_corrupted/) and #67 (15 orphaned .res.js); their disposition follows.

D9. #331 AGENTIC.md fleet — two confirms. delete vs replace-with-guarded-template; and scope ~30 worst offenders vs ~252 all. (E) = guarded template at ~252 — a template fixes the generator, and a partial scope is how the last sweep ended dead at 152 of 313 with nothing tracking the stall.

D10. #658 affinescript package — standing since 08-28, holds 18 builds red under every runtime. (a) publish a real affinescript compiler CLI to npm at a real version (E) · (b) consume the compiler by git/path · (c) restore rescript specifiers until AffineScript can build them. affinescript@^12.0.0 requests a version that has never existed, and the manifests still name .res.js / .bs.js entry points.

D11. #446 badge pilot — confirm boj-server? (E) = yes, one pilot before any engine is built.

From #715 — O1–O10, 11 comments, none answered

D12. O1 GitHub Team for metadatastician — is it listed at education.github.com? Until then org rulesets 403 and it stays on per-repo rulesets.
D13. O2 Probot Settings App — installed anywhere? If not, every .github/settings.yml in the estate is dead. (E) = delete the dead files.
D14. O3 Dispositions: boj-build.yml (255 repos — drop if BoJ is retired) · mirror.yml (142 repos skip for missing forge secrets — keep on which?) · rhodibot.yml (93 repos, 78% red — retire or remake?) · ClusterFuzzLite cflite_* (keep on which Rust/Zig repos?).
D15. O4 Repo moves beyond the first cut — any others, or "later"?
D16. O5 Three bypass-actor app IDs the API will not resolve: 1561, 85455, 946600. Settings → Applications shows the names. (E) = remove if unrecognised.
D17. O6 Gates vs bypass. (a) single ruleset as planned · (b) a second checks-only ruleset with bypass = claude, dependabot, github-actions, oikosbot, so the AI reviewers are held to the gates (E). This is the same decision as #40 — see D42.

→ RULED 2026-09-15, estate-wide: D17b — a second checks-only ruleset with bypass = claude, dependabot, github-actions, oikosbot. The AI actors are HELD TO THE GATES, not exempt. This is the direct answer to #40, and therefore also settles D42. (ruling comment)

D18. O7 Julia private registry — Renovate stays on those repos only if Dependabot cannot read julia-professional-registry. Acceptable?
D19. O8 Squash-only, knowingly. (a) add linear history + squash-only estate-wide (E) — squash is the only method GitHub can sign server-side while keeping history linear · (b) keep merge commits allowed, no linear-history rule. allow_rebase_merge is true on 435/435, the signature of a policy never applied anywhere. This is also the root fix for D4/D5: squash is precisely what orphans a PR-head pin.

→ RULED 2026-09-15, estate-wide: D19a — squash-only + linear history, estate-wide, knowingly. Squash is the only method GitHub can sign server-side while keeping history linear. Two live consequences: it authorises a ruleset change previously barred under D40/D42/D17, and because squash is what orphans a PR-head pin, D5's assertion becomes mandatory. (ruling comment)

D20. O9 Five metadatastician app installs with no ruling: slack, microsoft-teams-for-github, thanks-dev, linear-data-importer, linear-code. (E) = uninstall anything with no named owner.
D21. O10 workflow-templates/ on a User-account .github — no action needed unless another distribution route is preferred.

From #637 — the register, 17 rows, none closed

D22. #403 hyperpolymath/manifesto exists but its root carries no doctrine — checkbox 1 is "Owner edits doctrine to his voice". Nobody else can write this, and it is the highest single-item leverage on the register.

→ RULED 2026-09-15, estate-wide: D22 — I scaffold hyperpolymath/manifesto; the owner writes the voice. Structure, section prompts and cross-links from me; prose from him. (ruling comment)

D23. #408 Approve the canonical merge-options / branch-protection shape and rule the governance / * → new-context rename mapping for ~190 repos. Overlaps D19.
D24. #306 Pages across 48 repos — enable, or delete the Pages workflow? Pages enablement is API/UI-only, so there is no implementable middle path.
D25. #343 Which repo is canonical for .editorconfig / .gitattributes / .gitignore? standards and rsr-template-repo still differ on all three. And how much per-language .gitignore divergence is legitimate? Blocks the #31 phase-2 sweep. (E) = standards is canon, one file, documented per-language additions only.

→ RULED 2026-09-15, estate-wide: D25 — standards is canon for .editorconfig / .gitattributes / .gitignore, one file each, per-language additions documented as explicit additions. Unblocks the #31 phase-2 sweep. ⚠ Hazard unchanged: installing a canonical file silently deletes per-repo SPDX-FileCopyrightText lines, so phase 2 needs an SPDX-preserving merge, never an overwrite. (ruling comment)

D26. #342 Force the-nash-equilibrium from contractile schema v1.0.0 to v2.0.0 (two new files per verb), or bless it as a permanent holdout? SPDX-headered files are owner-only. Note the repo is separately guard-defective — it dies after git push, leaving two corrupt remote branches.
D27. #399 When is the credential behind the 40 unbaselined secret findings revoked and purged? Nothing else keeps that gate red; the issue closes on its own afterwards.
D28. #443 Provision SonarCloud — one global token, auto-provision projects, set a resume date; and secure admin on the 3 shared repos. Self-parked since 2026-06-29.
D29. #245 Which plugin hosts to bind at all — WordPress / WebExtensions / Thunderbird MailExt / React-Next — given WP-PHP cannot load WASM? Four questions posted 2026-05-28, none answered. Blocks #246 and #280.
D30. #438 Provide the authoritative protected-repo list and authorise a full-access recovery session; confirm revert-vs-keep-as-.md scope. Blocks the AffineScript port (#26).

→ RULED 2026-09-15, estate-wide: D30 — recovery session AUTHORISED, with the authoritative protected-repo list derived from measured state and put back for confirmation before anything runs. Unblocks the AffineScript port (#26). (ruling comment)

D31. #493 Five satellite destinations in .gitmodules do not exist and two entries are aliased. Per entry: recreate, redirect to a successor, or accept the vendored copy as the survivor and delete the claim? (E) = delete the claim where a vendored survivor exists — a dead submodule URL is a lie in the tree.
D32. #462 DYADT — orphaned inside patallm-gallery and diverging from the authoritative spec. Mint the repo and reconcile, or rewrite against the spec from the reference verifier?
D33. #95 Narrow this tracker to the governance-audit items and close the rest as discharged, or close it entirely and re-file?
D34. #636 Does a minting workflow get to create repos unattended? This crosses the standing no-unattended-mutations guardrail. (E) = no; a workflow_dispatch-only phase 1 still delivers enrollment.
D35. #634 Build scaffoldia's composer, or revive the dormant Haskell engine? Two halves of one tool are being maintained and neither mints a repo today.
D36. #633 After a week of reviewed decision manifests, wire actuate.sh? The deferred second half of observe-only.
D37. gitbot-fleet's local checkout has a corrupt packfile and 3 commits that exist nowhere on GitHub, including 632b54a "fix: recover phase-zero CI and governance". Keep or discard — needed before anyone tidies that directory. (E) = recover to a branch first, then decide; discarding is irreversible.


TIER 3 — arising from this week's measurements, filed nowhere else

D38. Two enforced policies contradict each other. sha_pinning_required is live on 385 of 391 repos while 2,272 refs are still @main — and actions.lock matches the literal ref string, not the resolved commit, so SHA-pinning an action the lockfile keys by tag is refused as "not present in the lockfile" and startup-kills the workflow. (a) regenerate lockfiles estate-wide, then pin (E) · (b) relax sha_pinning_required until lockfiles are regenerated · (c) accept the startup deaths.

D39. allowed_actions=selected with patterns_allowed:[] on ~85% of a 60-repo sample, including standards and rsr-template-repo — the posture was applied and the canon payload never was. Every core reusable but secret-scanner calls a third-party action, so a pin bump cannot cure this and must not be scored on "gates go green". (a) apply the canon payload (E) · (b) revert the posture to all until the payload is ready · (c) leave it.

D40. Ruleset 14285635 / #748 — the echidna fix. Reserved as an owner decision. The required context Idris2 — a2ml proofs is vacuously green on every PR and red otherwise.

D41. 4,595 uncommitted .github/workflows files across 365 worktrees are the only copy (214 on chore/bump-standards-pins; 119 of 126 sampled carry real pin/permissions work, not just splice damage). Commit them as audited campaign work, or leave them uncommitted and exposed to any git clean? (E) = commit; the only copy of real work does not live in a worktree.

D42. #40 — Admin bypass voids branch protection for every session holding the admin PAT, owner or agent. Same decision as D17 — answering once closes both.

D43. When is the A2ML / .deed agent clear? #19 (161 repos left, resumable at line 153 lcb-website) and #35 are held on this and nothing else.

D44. Two public-face gaps. repo-guardian has no README and no LICENSE; oikosbot-estate has no LICENSE while its README header declares MPL-2.0. (E) = close both, with a status-banner README only — a README describing what the scaffold will do manufactures exactly the hollow-code-behind-a-good-README case. Must not use branch fix/agentic-licence-and-validate-pin, which the #19 sweep force-pushes.

D45. 85 of 774 memory topic files are indexed in no index file, so they are never recalled. Sweep them into tier-2 indexes, or accept the backlog? (E) = sweep; an unindexed memory is a memory that does not exist.

D46. MEMORY.md has N concurrent writers, a hard truncation cap and no eviction policy. It has been pruned by peers three times this week and grew 21,224 → 23,835B inside one session. Who evicts, and by what rule? (E) = a written eviction policy any session can apply identically (tier-2 by date, tier-1 by doctrine-vs-finding) — otherwise every session prunes by taste and the index is unstable.

D47. The 45 empty-index clones that make git status report an entire tree as staged-deleted, and manufactured the false 83,441-file emergency. Repair, delete, or mark? (E) = repair or delete; a clone that fakes an emergency will fake it again.

D48. #664 stub density — 43% of estate .affine files are 200-byte Harvard Engine stubs, 726 in panll. The ruling was (a) declare debt per repo. Confirm the status-banner approach for the public READMEs sitting above them?


Needs no decision — recorded so it is not re-asked

Privacy verdict: nothing should go private. 384 of 385 public non-fork repos have a README (median 6,252B, p10 2,433B, none under 400B), 383 licensed, 378 described, smallest repo 57KB; oikosbot-estate was checked as the one exposure candidate and is clean. Nothing private is polished enough to promote.
Estate settings: already 97–100% compliant — 435 repos, three read-only passes, 0 errors; Dependabot alerts 435/435, private vulnerability reporting 387/387 public.
#41 workflow scope — restored and present; premise falsified, closed.
#22 startup-failure census — complete; its one open question is diagnosed, and the diagnosis itself has been corrected twice (see #782).

Three structural observations

  1. D17 and D42 are one decision, and D19 is the root cause of D4 and D5 — squash-merge is precisely what orphans a PR-head pin. Answering D17 and D19 closes five rows.
  2. D22 (Build the Estate Manifesto & Atlas (front-door, owner-gated) #403) is the only item nobody else can do. Every other row is executable by an agent once ruled.
  3. The register grows because rulings are given but not closed on the surface they govern. D1, D2 and D3 are all cases where a ruling and its surface now disagree — which is why this sheet records the surface state next to the question rather than only the question.

⚠ Sheet-state repair — 2026-09-15

This sheet is the declared standing decision surface (F4a), and until this edit it
misreported its own state. Three defects, all now corrected or surfaced:

1. Twelve rulings existed only in a comment. grep -o '~~' | wc -l on this body
returned 0 — no row was struck through, despite D1–D7, D17, D19, D22, D25 and D30 all
having been ruled on 2026-09-15. That is precisely the failure this sheet was created to
end, and which its own body names: "rulings are being given but not closed on the surface
they govern."
The twelve rows are now struck in place with their answers beside them, per
the F4a convention (strike, never delete).

2. Eleven rows were silently dropped. The ruling comment lists D8–D16, D18, D20, D21,
D23, D24, D26–D29 and D31–D37 as deliberately still open — 25 rows. With the 12 ruled,
that accounts for 37 of 48. D38–D48 appear in neither list: not ruled, not acknowledged
as open. They are open. Their current status, measured:

Row Status as at 2026-09-15
D38 Open. Identical in substance to F9 (the sha_pinning_required contradiction), which was ruled neither record governs, re-ask. Live on 385/391 repos while 2,272 refs remain @main.
D39 Open, no ruling anywhere. allowed_actions=selected with patterns_allowed:[] on ~85% of a 60-repo sample, standards included. A pin bump cannot cure it.
D40 Superseded in part — D19 explicitly authorises the ruleset change previously barred under D40. Needs restating, not re-deciding.
D41 Discharged by execution on 2026-09-15. Re-measured as 1,654 workflow files across 504 clones (not 4,595 across 365 worktrees), of which 195 were untracked and destroyable. The rollout has now been committed estate-wide under owner authorisation.
D42 Answered by D17b. The sheet's own text says they are the same decision; D17 is ruled, so D42 closes with it.
D43 Open, no ruling. #19 (161 repos left) and #35 are held on this and nothing else.
D44 Open, no ruling. repo-guardian has no README/LICENSE; oikosbot-estate declares MPL-2.0 with no LICENSE.
D45 Open, no ruling — and the evidence contradicts itself: one record says 85 of 774 memory files are indexed nowhere, another says 94 of 860. Re-measure before ruling.
D46 Open, no ruling. Partially mitigated by the #48 / F11a inbox-marker guard.
D47 Open, no ruling. The 45 empty-index clones that manufactured the false 83,441-file emergency.
D48 Open, no ruling. 43% of estate .affine files are 200-byte stubs, 726 in panll.

3. The succession rule has fired and was not honoured. F4a clause 4 says this issue is
re-compiled into a fresh consolidated issue once it passes ~30 open rows. Open rows
today: 25 acknowledged + 11 recovered above − D41 and D42 now discharged = 34. Above
threshold. Re-compilation is due.

Also: D10 still offers an arm that is banned. Arm (c), "restore rescript specifiers",
is prohibited by the 2026-09-15 bun-only doctrine, which D30's ruling notes explicitly
("rescript is now banned estate-wide"). D10 cannot be answered (c) as written.

Repair performed under owner authorisation given 2026-09-15. Nothing was deleted; the 12
ruled rows keep their full question text struck through beside their answers.

🤖 Generated with Claude Code

https://claude.ai/code/session_01VG5AnnA12E8GikbXZS7NbD

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    auditVerification & compliancecicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesdecisionA ruling is required before work can proceedmeta:umbrellaParent issue aggregating child issuesscope:estateAffects many or all repos across the estatestatus:needs-ownerUnassigned and needs someone to take it

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions