From 66e0c779f64bbf0a352792d1417c94ba3598d982 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 9 Sep 2026 09:17:00 +0000 Subject: [PATCH 1/3] developer-experience: fix verdictColor() ANSI leak through --no-color MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit renderDashboard(ledgerMd, { noColor: true }) still emitted a raw ANSI color escape in the verdict column — verdictColor() closed over the always-colored module constant C instead of the noColor-aware color map every other cell already goes through. Flagged unfixed in PR #21 (2026-08-19); reproduced live tonight against main before the fix. Parameter-thread the resolved color map into verdictColor() instead of adding a second no-color check. npm test 697->699 (+2), 0 regressions. Independent critic: CLEAR. Dream Cycle 2026-09-09. Issue #102. Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01D5ee4aky1TGGQqfYpoouad --- .../2026-09-09-developer-experience-report.md | 237 ++++++++++++++++++ docs/dream-cycle/LEDGER.md | 1 + packages/cli/src/index.test.ts | 16 ++ packages/cli/src/tui.ts | 12 +- 4 files changed, 260 insertions(+), 6 deletions(-) create mode 100644 docs/dream-cycle/2026-09-09-developer-experience-report.md diff --git a/docs/dream-cycle/2026-09-09-developer-experience-report.md b/docs/dream-cycle/2026-09-09-developer-experience-report.md new file mode 100644 index 0000000..a04c484 --- /dev/null +++ b/docs/dream-cycle/2026-09-09-developer-experience-report.md @@ -0,0 +1,237 @@ +# Developer Experience SOTA Report — 2026 + +Dream Cycle 2026-09-09 · DEEP=`developer-experience` · SCAN=`cli`,`tui` · SLOT=4 + +## TL;DR + +`renderDashboard(ledgerMd, { noColor: true })` in `packages/cli/src/tui.ts` still +leaked a raw ANSI SGR color escape in the verdict column, 21 nights after PR #21 +(2026-08-19) explicitly flagged it as a known, unfixed follow-up +("`verdictColor()` bypasses the no-color proxy"). Reproduced live tonight against +current `main` (`3edd426`) before touching any code. Fixed by threading the +`noColor`-aware color map (`c`) into `verdictColor()` instead of letting it close +over the always-colored module constant (`C`). Small, deterministic, no +evolvable population — no Darwin run, consistent with this repo's own precedent +for single-function pure fixes. + +## What's New + +- **Bug**: `verdictColor(v: string): string` (pre-fix) returned `C.green` / + `C.red` / `C.yellow` / `C.gray` unconditionally — the module-level, always-on + ANSI palette — regardless of `renderDashboard`'s `noColor` option, which + builds a separate `c` (either `C` itself, or a `Proxy` that maps every color + key to `''`) specifically so `--no-color` output is byte-clean for piping, + snapshotting, or non-tty consumption. +- **Why it matters for this repo specifically**: this TUI is this Dream Machine's + own operator-facing dashboard (`dream-machine tui --no-color`), and + `--no-color` output is exactly the mode a CI log, a snapshot test, or a + screen-reader-friendly render depends on being ANSI-free. A partial leak is + worse than no `--no-color` support at all, because callers trust the flag. +- **Fix**: `verdictColor(v, c)` now takes the resolved color map as a parameter; + its one call site passes the same `c` the rest of `renderDashboard` already + uses. Zero other direct `C.xxx` references remain inside `renderDashboard` or + its helpers (confirmed by grep, both before writing the fix and by an + independent critic afterward). + +## Competitor / Prior-Art Rows (how other agentic dev-tool dashboards treat color-safety) + +| Project | No-color / plain-output handling | Grade | Relevance | +|---|---|---|---| +| Sakana AI Scientist | CLI progress output is plain-text by default; no dedicated ANSI-proxy abstraction observed in its public reporting pipeline | C (public repo inspection, not independently benchmarked tonight) | Shows a simpler alternative design (skip color entirely) that structurally can't leak | +| OpenHands (formerly OpenDevin) | Terminal UI uses `rich`/`textual`-style rendering with theme-aware color; plain-mode output paths are a known recurring source of un-swept color-code issues in `rich`-based tools generally | C (general ecosystem knowledge, not a specific reproduced finding in their repo tonight) | Same class of bug (a color helper bypassing the plain-mode wrapper) is a recognized footgun across `rich`/ANSI-wrapper-style TUIs, not unique to this repo | +| DSPy / GEPA | Evaluation/optimization logs are structured (JSON/plain) rather than ANSI-decorated tables; the color-leak class of bug doesn't apply because there's no colorized table renderer in the hot path | B (documented output format) | Suggests one durable fix direction: keep the machine-readable log path (`ledger append`, `witness stamp`) entirely separate from the human-facing colorized `tui`, which this repo already does | +| SWE-agent | Terminal trajectory viewer supports a `--yolo`/plain trace mode; color is applied via a single wrapper function per rendered line, reducing (but per public issue history, not eliminating) the same bypass risk | C (single-source, not reproduced tonight) | Same architectural lesson as this fix: route *every* color call through one no-color-aware chokepoint, never a second hardcoded palette reference | + +All four rows above are prior-art context for the general failure class (a +color-formatting helper skipping the plain/no-color wrapper), not independent +verification of this repo's specific bug — that was reproduced first-hand, +live, tonight (grade A). + +## Hypothesis (frozen before implementation) + +Given `renderDashboard(ledgerMd, { noColor: true })`, when `verdictColor()` is +changed to resolve its return value through the same no-color-aware color map +(`c`) that every other cell in the same row already uses — instead of closing +over the raw, always-colored `C` constant — then `renderDashboard`'s +`noColor: true` output should contain **zero** ANSI escape sequences for any +verdict value (`ACCEPT`, `REJECT`, `INCONCLUSIVE`, or any other string, +including a `HALT: budget` row), while `noColor: false` (or omitted) output +stays byte-identical to today. Subject to: 0 regressions in the existing +suite, and the change confined to `verdictColor`'s color-source dispatch (no +palette value changes). + +Confirmed. + +## Testability Gate → Candidate → Baseline → Evaluation + +**Testable tonight**: yes — pure, deterministic, no credentials, no model +calls required. + +**Candidate**: `packages/cli/src/tui.ts` — `verdictColor(v: string): string` +→ `verdictColor(v: string, c: typeof C): string`, body changed from `C.green` +etc. to `c.green` etc.; the one call site (`renderDashboard`'s row-rendering +loop) now passes `c`. +2 regression tests in +`packages/cli/src/index.test.ts` (one asserting zero ANSI escapes anywhere in +`noColor: true` output across four verdict values including a non-enum +`HALT: budget` string; one asserting the colored path is unchanged — still +emits `\x1b[32m`/`\x1b[31m` for ACCEPT/REJECT). One conceptual change, ~6 +line diff to source + 16 lines of tests. + +**Baseline**: parent `main @ 3edd426f6c9c4b1e80235f7447dc863e749345cc` +(`npm ci && npm run build` clean, no wasm/NAPI packages in this workspace). +`npx vitest run` → 616/616. `npm run test:governance` → 81/81. Total +697/697 green. + +**Evaluation Receipt** — real evaluator (`npm test` = `vitest run && npm run +test:governance`): + +| | Baseline (`3edd426`) | Candidate | +|---|---|---| +| vitest | 616 passed | 618 passed (+2, 0 removed/modified) | +| governance | 81 passed | 81 passed | +| Total | 697 | 699 | +| Lint | clean | clean | +| Build | clean (7 packages) | clean (7 packages) | + +Live reproduction, pre-fix (stashed candidate, ran against parent): +``` +$ node -e "... renderDashboard(md, { noColor: true }) ..." +contains ANSI escape with noColor:true -> true +"est ACCEPT " +``` +Live reproduction, post-fix: +``` +post-fix noColor contains ANSI escape -> false +colored output still has green -> true +``` +Self-hosting closure: re-ran `node packages/cli/dist/bin.js compile +dream.config.json` before and after the fix — byte-identical output (this +change doesn't touch the compiler, as expected for a `tui`-scoped fix). + +## Darwin Lineage + +Not run — `DARWIN=not-applicable`. A single deterministic color-dispatch +parameterization has no evolvable population, same judgment as every prior +`developer-experience`/`compiler-parity` single-function fix in this ledger +(PRs #11, #21, #29, #33, #46). + +## Evidence + +- OBSERVATION (grade A, first-hand, live): pre-fix `verdictColor()` at + `packages/cli/src/tui.ts:21-26` (pre-diff) references `C.green`/`C.red`/ + `C.yellow`/`C.gray` directly, not the `c` proxy `renderDashboard` builds at + its own line 134. +- OBSERVATION (grade A): PR #21's own body (2026-08-19, merged) names this + exact defect as a known follow-up, explicitly "not fixed" at the time. +- MEASUREMENT (grade A, live): `renderDashboard(md, {noColor:true})` on + parent `3edd426` emits `\x1b[32m` in its verdict cell; on the candidate it + does not, across ACCEPT/REJECT/INCONCLUSIVE/`HALT: budget`. +- MEASUREMENT (grade A): `npm test` 697→699, 0 regressions. +- INFERENCE: this is the same architectural footgun class documented in + public `rich`/ANSI-wrapper ecosystems generally (see competitor rows) — one + hardcoded-palette reference bypassing the single no-color chokepoint — not + specific to this codebase's history. +- DECISION: fix by parameter-threading the resolved color map, not by adding + a second no-color check inside `verdictColor` (which would create a second + place the "is this no-color?" decision could drift from `renderDashboard`'s). + +## Reward-Hack Check + +Independent critic (fresh subagent, no shared authoring context, given only +`git diff` + full repo read access): **CLEAR**. +1. Confirmed the bug is real by reading the pre-fix code and reproducing the + leak directly (not taking the claim on faith). +2. Confirmed the fix fully closes the leak — grepped `packages/cli/src/tui.ts` + post-fix for any remaining direct `C.xxx` reference inside `renderDashboard` + or its helpers; zero found. +3. No reward-hacking signals: no weakened/skipped/`.only` tests, no gold-data + edits, no threshold changes, no evaluator exploitation. +4. Verified by hand that both new tests are bug-exercising: the noColor + regression test fails against the pre-fix code (reproduced the raw escape) + and passes post-fix; the colored-path test passes on both (correctly + proving no regression, not exercising the bug). +5. No regression to colored (`noColor:false`) output — `c === C` in that + branch, so `verdictColor(v, c)` behaves identically to the old + `verdictColor(v)`. +6. Scope minimal: 4-line signature/body change + 1-line call-site change in + source, 2 additive tests. No unrelated code touched. + +## Security Review + +No security-sensitive surface: no prompt-injection vector (no LLM calls in +this path), no MCP/tool-authority change, no credential exposure, no +filesystem/network scope change, no evaluator/gate/safety-constant touched. +Pure string/ANSI-escape formatting logic. + +## Regression Analysis + +0 pre-existing tests modified or removed. All 697 baseline tests (616 vitest ++ 81 governance) pass unchanged; 2 new vitest tests added. `npm run lint` +clean across all packages. `npm run build` clean (7 packages, no wasm/NAPI +degradation to record tonight). Self-hosted `dream.config.json` compile +output confirmed byte-identical before/after (out of scope for this `tui` +change, verified anyway per this repo's self-hosting discipline). + +## Witness + +``` +report_sha256 : 69a97031631f19d559ebc5c0d7601d36cb02efa7708fda9776eb1616e7372ebe +session_commit: 3edd426f6c9c4b1e80235f7447dc863e749345cc +witness : 16c867ef6fc58d714ac698888e99b25e24e6f39a21e45bf4fcc7e03098b23ee0 +``` + +Computed against this file's content *before* this Witness section was filled +in (STEP 16's own hash-then-rewrite order, same convention as every prior +night in this ledger, e.g. PRs #7, #11, #29). + +Verify (5 steps, coreutils only): +```bash +# 1. Obtain this exact report file (committed at +# docs/dream-cycle/2026-09-09-developer-experience-report.md — GIST=LOCAL, +# no gh/gist-creation tool available this session). +# 2. Reconstruct its pre-Witness-section content (everything above this +# section, byte-for-byte) into report.md. +REPORT_HASH=$(sha256sum report.md | awk '{print $1}') +# 3. Confirm REPORT_HASH == 69a97031631f19d559ebc5c0d7601d36cb02efa7708fda9776eb1616e7372ebe +printf '%s%s' "$REPORT_HASH" "3edd426f6c9c4b1e80235f7447dc863e749345cc" | sha256sum +# 4. Confirm that output == 16c867ef6fc58d714ac698888e99b25e24e6f39a21e45bf4fcc7e03098b23ee0 +# 5. Confirm session_commit (3edd426f6c9c4b1e80235f7447dc863e749345cc) matches +# the PR's base commit. +``` + +`GIST=LOCAL` — no `gh` CLI or gist-creation MCP tool available this session +(consistent with every prior night in this ledger). Published as a committed +artifact in the PR instead. + +## Next Steps (concrete) + +1. **Audit for the same bypass class elsewhere in `tui.ts`**: this fix closed + the one instance found tonight (`verdictColor`), but any *future* helper + added to `renderDashboard` that hardcodes `C.xxx` instead of accepting `c` + would reintroduce the same bug silently. A cheap, durable guard: a unit + test (already added tonight, generalizable) that renders a dashboard with + every distinct verdict/finding/date value under `noColor:true` and asserts + zero `\x1b[` bytes anywhere in the frame — this is a stronger regression + guard than checking one hardcoded verdict, and should be kept as the + canonical "no-color contract" test going forward. +2. **Consider a lint rule or code-review checklist item**: "no direct `C.xxx` + reference outside the `c` construction in `renderDashboard`" — this is + exactly the kind of drift a human reviewer or a simple grep-based CI check + could catch before merge, cheaper than relying on a future Dream Cycle + night to notice the leak again. +3. **zeroMergeStreak / merge-state accuracy (process finding, not a code + candidate tonight)**: while re-checking the last 7 ledger rows' PR fates + per STEP 1, the GitHub MCP `list_pull_requests` tool returned `merged: + false` for every single PR in this repository — including ones with a + `merged_at` timestamp set and independently confirmed `merged: true` via + `pull_request_read` (`get`) on PRs #21, #29, #33, #46, #55, #91. This + reproduces, at the *tool* layer rather than this repo's own code, the + exact defect class PR #89 already fixed inside `@dream-machine/ledger`'s + `learningSignals()` (never trust a bulk-list `merged` field; resolve per-PR + or via an explicit `--merged` list). Recommend future nights always derive + `--merged` from `merged_at` presence or individual `pull_request_read` + calls, never from `list_pull_requests`'s own `merged` boolean, until/unless + that tool's behavior is confirmed fixed upstream. Not actionable as a PR + against this repo (the defect is in the calling environment's GitHub MCP + server, out of this repo's blast radius) — recorded here for the ledger's + cross-night memory instead. diff --git a/docs/dream-cycle/LEDGER.md b/docs/dream-cycle/LEDGER.md index 59ab281..f19ab38 100644 --- a/docs/dream-cycle/LEDGER.md +++ b/docs/dream-cycle/LEDGER.md @@ -37,3 +37,4 @@ | 2026-08-25 | compiler-parity | adrConvention object form ({pad,dir}) had zero validation; malformed value silently compiled a corrupted STEP 19 ADR path (empty dir -> absolute-root path); added validateConfig checks | #28 | #29 | yes | ACCEPT | npm test 96->104, 0 regressions | d4958530 | PR #7 merged 2026-08-13, PR #13 merged 2026-08-15; PRs #9,#11,#15,#17,#19,#21,#24,#27 (2026-08-14 through 2026-08-24) still open/draft, human review pending -- their ledger rows never reached main (see Ledger Check audit in issue #28) | | 2026-08-26 | ledger-signals | duplicateDirections only scans merged ledger rows, missing near-duplicate directions across still-open PRs (demonstrated: #15 vs #27); added opt-in pendingFindings option + --pending CLI flag | #32 | #33 | yes | ACCEPT | npm test 96->104, 0 regressions | 7bf7a1d1 | PR #7 MERGED (2026-08-13); PR #13 MERGED (2026-08-15, manual); PRs #15,17,19,21,23,24,27,29,30 still OPEN/unmerged (9-PR backlog, flagged in issue #32, not fixed by this PR) | | 2026-08-28 | security-adversarial | npm audit reports 8 dev-toolchain vulnerabilities (2 critical/1 high/3 moderate/2 low), 0 production; CI did not gate on any of it (issue #43) - added deterministic audit-gate CI job scoped to npm audit --omit=dev | #45 | #46 | yes | ACCEPT | npm test 98->111, 0 regressions; live audit-gate: clear on prod scope, blocked on dev-inclusive scope (proves not a rubber stamp) | fe3d8a92 | #24 closed unmerged (hand-applied by maintainer per commit df9ff40); #19/#21/#27/#29/#33/#30/#35/#40/#42/#44 remain open/draft, zeroMergeStreak=true (6/6 nights, per ledger signals) | +| 2026-09-09 | developer-experience | renderDashboard's verdictColor() leaked ANSI color through --no-color (flagged unfixed in PR #21); parameter-threaded the no-color-aware color map | #102 | #TBD | yes | ACCEPT | npm test 697->699 (+2), 0 regressions; live: noColor:true leaked \x1b[32m pre-fix, clean post-fix; colored path unchanged | 16c867ef6fc58d714ac698888e99b25e24e6f39a21e45bf4fcc7e03098b23ee0 | zeroMergeStreak=false (recomputed with --merged against confirmed merged PRs; large 2026-09-07 batch-merge landed ~40 PRs, including #21/#29/#33/#46/#55/#91); list_pull_requests merged-field bug reproduced live (same class PR #89 fixed in-repo, but this instance is in the calling GitHub MCP tool, out of repo scope) | diff --git a/packages/cli/src/index.test.ts b/packages/cli/src/index.test.ts index 2e7cefb..5f5d48f 100644 --- a/packages/cli/src/index.test.ts +++ b/packages/cli/src/index.test.ts @@ -564,6 +564,22 @@ describe('tui', () => { expect(r.err).toContain('--merged expects a comma-separated PR number list'); }); + it('renderDashboard with noColor:true emits no ANSI escape anywhere, including the verdict cell (regression: verdictColor bypassed the no-color proxy, flagged unfixed in PR #21)', () => { + let md = emptyLedger(); + for (const verdict of ['ACCEPT', 'REJECT', 'INCONCLUSIVE', 'HALT: budget'] as const) { + md = appendRow(md, sampleRow({ pr: `#${verdict}`, verdict })); + } + const frame = renderDashboard(md, { noColor: true }); + expect(frame).not.toMatch(/\x1b\[/); + }); + + it('renderDashboard with noColor:false still colors the verdict cell per verdict (no regression to the colored path)', () => { + const accept = renderDashboard(appendRow(emptyLedger(), sampleRow({ verdict: 'ACCEPT' })), {}); + const reject = renderDashboard(appendRow(emptyLedger(), sampleRow({ verdict: 'REJECT' })), {}); + expect(accept).toContain('\x1b[32m'); // green + expect(reject).toContain('\x1b[31m'); // red + }); + it('displayWidth matches .length for plain ASCII (no regression)', () => { expect(displayWidth('hello world')).toBe('hello world'.length); expect(displayWidth('')).toBe(0); diff --git a/packages/cli/src/tui.ts b/packages/cli/src/tui.ts index af67c72..dffb997 100644 --- a/packages/cli/src/tui.ts +++ b/packages/cli/src/tui.ts @@ -18,11 +18,11 @@ const C = { gray: '\x1b[38;5;245m', }; -function verdictColor(v: string): string { - if (v === 'ACCEPT') return C.green; - if (v === 'REJECT') return C.red; - if (v === 'INCONCLUSIVE') return C.yellow; - return C.gray; +function verdictColor(v: string, c: typeof C): string { + if (v === 'ACCEPT') return c.green; + if (v === 'REJECT') return c.red; + if (v === 'INCONCLUSIVE') return c.yellow; + return c.gray; } const ANSI_TOKEN = '\\x1b\\[[0-9;]*m'; @@ -164,7 +164,7 @@ export function renderDashboard(ledgerMd: string, opts: DashboardOptions = {}): const row = `${pad(r.date, 11)} ` + `${c.magenta}${pad(r.deep, 20)}${c.reset} ` + - `${verdictColor(r.verdict)}${pad(r.verdict, 14)}${c.reset} ` + + `${verdictColor(r.verdict, c)}${pad(r.verdict, 14)}${c.reset} ` + `${pad(r.finding, 28)}`; lines.push(`${c.violet}│${c.reset} ${pad(row, W - 2)} ${c.violet}│${c.reset}`); } From 32adbe2a848c8cf5f3b16f75af40e15a12904973 Mon Sep 17 00:00:00 2001 From: Claude Date: Wed, 9 Sep 2026 09:17:35 +0000 Subject: [PATCH 2/3] docs(ledger): fill in PR #103 for 2026-09-09 developer-experience row Co-Authored-By: Claude Sonnet 5 Claude-Session: https://claude.ai/code/session_01D5ee4aky1TGGQqfYpoouad --- docs/dream-cycle/LEDGER.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/dream-cycle/LEDGER.md b/docs/dream-cycle/LEDGER.md index f19ab38..51b03ed 100644 --- a/docs/dream-cycle/LEDGER.md +++ b/docs/dream-cycle/LEDGER.md @@ -30,11 +30,11 @@ | 2026-09-07 | portfolio 317; RuVector; ruClip; worldgraph; ruflo; metaharness | accept MetaHarness qualification primitive; reject placeholder quantization and unfalsified Ruflo frozen gate; retain persistence/hardware candidates as inconclusive | worldgraph#11; RuVector#968; reuse ruClip#14, ruflo#3220, metaharness#289/#290 | review ruClip#15, worldgraph#10, ruflo#3221, metaharness#291; dream-machine#87 | partial | ACCEPT / REJECT / INCONCLUSIVE | 21 public commits across 3 repos; MetaHarness four workflow groups green; WorldGraph software green/hardware unrun; private activity aggregate-only | report 13fa0ddd | one issue created, one updated, four exact-head reviews; zero implementation PR, direct push, merge, release, deployment, or signed federation claim | | 2026-08-15 | compiler-parity | self-hosted dream.config.json had zero test coverage in @dream-machine/compile; added golden-snapshot + validation test reading the real config | #10 | #11 | yes | ACCEPT | npm test 96->100, 0 regressions | cf2f0711 | PR #7 merged 2026-08-13; PR #9 (2026-08-14) still open/draft, human review pending | | 2026-08-29 | developer-experience | ledger append accepted any --verdict/--evaluated value with no validation, silently allowing schema drift (evidenced by 9 real errors already on main from commit df9ff40); added shared-enum validation, reject on violation | #48 | #49 | yes | ACCEPT | npm test 98->100, 0 regressions; manual replay confirms hash-unchanged rejection of invalid verdict/evaluated | b1e4ed60 | PR #47 (portfolio-cycle) open same base commit; self-hosting dream-cycle PRs #8-#46 remain 0-merged; df9ff40 identified as source of 5 malformed rows on main | -| 2026-08-30 | compiler-parity | STEP 17-18 hard-coded gh gist create with no fallback; made gist publication best-effort (GIST=LOCAL fallback), matching 2026-08-13 precedent | #54 | #TBD | yes | ACCEPT | npm test 98->99, 0 regressions; self-hosted compile output confirmed fixed | c1fe7926ffa1cd4cb49688c30de3115622582682948c001c935fce9d5f664eb5 | issue #48/PR #49 (ledger schema) still open; PR #29 (adrConvention) still open; PR #40 (evaluatorEntrypoint) still open; zeroMergeStreak=true carries forward | +| 2026-08-30 | compiler-parity | STEP 17-18 hard-coded gh gist create with no fallback; made gist publication best-effort (GIST=LOCAL fallback), matching 2026-08-13 precedent | #54 | #103 | yes | ACCEPT | npm test 98->99, 0 regressions; self-hosted compile output confirmed fixed | c1fe7926ffa1cd4cb49688c30de3115622582682948c001c935fce9d5f664eb5 | issue #48/PR #49 (ledger schema) still open; PR #29 (adrConvention) still open; PR #40 (evaluatorEntrypoint) still open; zeroMergeStreak=true carries forward | | 2026-08-30 | compiler-parity | STEP 17-18 hard-coded gh gist create with no fallback; made gist publication best-effort (GIST=LOCAL fallback), matching 2026-08-13 precedent | #54 | #55 | yes | ACCEPT | npm test 98->99, 0 regressions; self-hosted compile output confirmed fixed | c1fe7926ffa1cd4cb49688c30de3115622582682948c001c935fce9d5f664eb5 | issue #48/PR #49 (ledger schema) still open; PR #29 (adrConvention) still open; PR #40 (evaluatorEntrypoint) still open; zeroMergeStreak=true carries forward | | 2026-09-07 | evaluation-adapters | darwin evaluatorEntrypoint bug re-confirmed live on main (missing positional; exit-0 silent misdirection into ./--sandbox/), triplicated across open PRs #17/#40/#65; withheld 4th duplicate fix, posted consolidating review comment on #65 | #90 | #91 | yes | REJECT | 572/572 tests green (491 vitest + 81 governance), 0 regressions (no code shipped); live darwin repro confirms bug unfixed on main; 3 open PRs (#17/#40/#65) already contain fixes, 0 merged | 6421a213e23a5162 | zeroMergeStreak=true (0 merged since #24 on 2026-08-26); #17/#40/#65 remain open/draft/unreviewed, PR #65 has 0 recorded CI checks; ledger verify's 17 pre-existing structural errors (issues #48/#58, PRs #49/#59) also untouched, same duplicate-direction reasoning; no session merge or self-promotion | | 2026-08-19 | developer-experience | tui pad() used raw string length not display width; fixed with Unicode-aware displayWidth/pad, preserved literal newlines in truncation per adversarial critique | #20 | #21 | yes | ACCEPT | npm test 96->103, 0 regressions | 25a4b37f | #7:MERGED #9:OPEN #11:OPEN #15:OPEN #17:OPEN #19:OPEN | | 2026-08-25 | compiler-parity | adrConvention object form ({pad,dir}) had zero validation; malformed value silently compiled a corrupted STEP 19 ADR path (empty dir -> absolute-root path); added validateConfig checks | #28 | #29 | yes | ACCEPT | npm test 96->104, 0 regressions | d4958530 | PR #7 merged 2026-08-13, PR #13 merged 2026-08-15; PRs #9,#11,#15,#17,#19,#21,#24,#27 (2026-08-14 through 2026-08-24) still open/draft, human review pending -- their ledger rows never reached main (see Ledger Check audit in issue #28) | | 2026-08-26 | ledger-signals | duplicateDirections only scans merged ledger rows, missing near-duplicate directions across still-open PRs (demonstrated: #15 vs #27); added opt-in pendingFindings option + --pending CLI flag | #32 | #33 | yes | ACCEPT | npm test 96->104, 0 regressions | 7bf7a1d1 | PR #7 MERGED (2026-08-13); PR #13 MERGED (2026-08-15, manual); PRs #15,17,19,21,23,24,27,29,30 still OPEN/unmerged (9-PR backlog, flagged in issue #32, not fixed by this PR) | | 2026-08-28 | security-adversarial | npm audit reports 8 dev-toolchain vulnerabilities (2 critical/1 high/3 moderate/2 low), 0 production; CI did not gate on any of it (issue #43) - added deterministic audit-gate CI job scoped to npm audit --omit=dev | #45 | #46 | yes | ACCEPT | npm test 98->111, 0 regressions; live audit-gate: clear on prod scope, blocked on dev-inclusive scope (proves not a rubber stamp) | fe3d8a92 | #24 closed unmerged (hand-applied by maintainer per commit df9ff40); #19/#21/#27/#29/#33/#30/#35/#40/#42/#44 remain open/draft, zeroMergeStreak=true (6/6 nights, per ledger signals) | -| 2026-09-09 | developer-experience | renderDashboard's verdictColor() leaked ANSI color through --no-color (flagged unfixed in PR #21); parameter-threaded the no-color-aware color map | #102 | #TBD | yes | ACCEPT | npm test 697->699 (+2), 0 regressions; live: noColor:true leaked \x1b[32m pre-fix, clean post-fix; colored path unchanged | 16c867ef6fc58d714ac698888e99b25e24e6f39a21e45bf4fcc7e03098b23ee0 | zeroMergeStreak=false (recomputed with --merged against confirmed merged PRs; large 2026-09-07 batch-merge landed ~40 PRs, including #21/#29/#33/#46/#55/#91); list_pull_requests merged-field bug reproduced live (same class PR #89 fixed in-repo, but this instance is in the calling GitHub MCP tool, out of repo scope) | +| 2026-09-09 | developer-experience | renderDashboard's verdictColor() leaked ANSI color through --no-color (flagged unfixed in PR #21); parameter-threaded the no-color-aware color map | #102 | #103 | yes | ACCEPT | npm test 697->699 (+2), 0 regressions; live: noColor:true leaked \x1b[32m pre-fix, clean post-fix; colored path unchanged | 16c867ef6fc58d714ac698888e99b25e24e6f39a21e45bf4fcc7e03098b23ee0 | zeroMergeStreak=false (recomputed with --merged against confirmed merged PRs; large 2026-09-07 batch-merge landed ~40 PRs, including #21/#29/#33/#46/#55/#91); list_pull_requests merged-field bug reproduced live (same class PR #89 fixed in-repo, but this instance is in the calling GitHub MCP tool, out of repo scope) | From 23851512fce23003f510d6f34c8c86109bd474d3 Mon Sep 17 00:00:00 2001 From: ruvnet Date: Sat, 26 Sep 2026 11:04:51 -0400 Subject: [PATCH 3/3] docs(ledger): restore unrelated 2026-08-30 row mis-edited by the #103 PR-number fill-in Commit 32adbe2 meant to fill in this PR's own number on the appended 2026-09-09 row, but also rewrote the historical 2026-08-30 compiler-parity row's PR cell from #TBD to #103. That row predates this PR, and any edit to rows 1-37 breaks the grandfathered-prefix digest PR #114 anchors CI to. Co-Authored-By: claude-flow --- docs/dream-cycle/LEDGER.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/dream-cycle/LEDGER.md b/docs/dream-cycle/LEDGER.md index 51b03ed..d40e51c 100644 --- a/docs/dream-cycle/LEDGER.md +++ b/docs/dream-cycle/LEDGER.md @@ -30,7 +30,7 @@ | 2026-09-07 | portfolio 317; RuVector; ruClip; worldgraph; ruflo; metaharness | accept MetaHarness qualification primitive; reject placeholder quantization and unfalsified Ruflo frozen gate; retain persistence/hardware candidates as inconclusive | worldgraph#11; RuVector#968; reuse ruClip#14, ruflo#3220, metaharness#289/#290 | review ruClip#15, worldgraph#10, ruflo#3221, metaharness#291; dream-machine#87 | partial | ACCEPT / REJECT / INCONCLUSIVE | 21 public commits across 3 repos; MetaHarness four workflow groups green; WorldGraph software green/hardware unrun; private activity aggregate-only | report 13fa0ddd | one issue created, one updated, four exact-head reviews; zero implementation PR, direct push, merge, release, deployment, or signed federation claim | | 2026-08-15 | compiler-parity | self-hosted dream.config.json had zero test coverage in @dream-machine/compile; added golden-snapshot + validation test reading the real config | #10 | #11 | yes | ACCEPT | npm test 96->100, 0 regressions | cf2f0711 | PR #7 merged 2026-08-13; PR #9 (2026-08-14) still open/draft, human review pending | | 2026-08-29 | developer-experience | ledger append accepted any --verdict/--evaluated value with no validation, silently allowing schema drift (evidenced by 9 real errors already on main from commit df9ff40); added shared-enum validation, reject on violation | #48 | #49 | yes | ACCEPT | npm test 98->100, 0 regressions; manual replay confirms hash-unchanged rejection of invalid verdict/evaluated | b1e4ed60 | PR #47 (portfolio-cycle) open same base commit; self-hosting dream-cycle PRs #8-#46 remain 0-merged; df9ff40 identified as source of 5 malformed rows on main | -| 2026-08-30 | compiler-parity | STEP 17-18 hard-coded gh gist create with no fallback; made gist publication best-effort (GIST=LOCAL fallback), matching 2026-08-13 precedent | #54 | #103 | yes | ACCEPT | npm test 98->99, 0 regressions; self-hosted compile output confirmed fixed | c1fe7926ffa1cd4cb49688c30de3115622582682948c001c935fce9d5f664eb5 | issue #48/PR #49 (ledger schema) still open; PR #29 (adrConvention) still open; PR #40 (evaluatorEntrypoint) still open; zeroMergeStreak=true carries forward | +| 2026-08-30 | compiler-parity | STEP 17-18 hard-coded gh gist create with no fallback; made gist publication best-effort (GIST=LOCAL fallback), matching 2026-08-13 precedent | #54 | #TBD | yes | ACCEPT | npm test 98->99, 0 regressions; self-hosted compile output confirmed fixed | c1fe7926ffa1cd4cb49688c30de3115622582682948c001c935fce9d5f664eb5 | issue #48/PR #49 (ledger schema) still open; PR #29 (adrConvention) still open; PR #40 (evaluatorEntrypoint) still open; zeroMergeStreak=true carries forward | | 2026-08-30 | compiler-parity | STEP 17-18 hard-coded gh gist create with no fallback; made gist publication best-effort (GIST=LOCAL fallback), matching 2026-08-13 precedent | #54 | #55 | yes | ACCEPT | npm test 98->99, 0 regressions; self-hosted compile output confirmed fixed | c1fe7926ffa1cd4cb49688c30de3115622582682948c001c935fce9d5f664eb5 | issue #48/PR #49 (ledger schema) still open; PR #29 (adrConvention) still open; PR #40 (evaluatorEntrypoint) still open; zeroMergeStreak=true carries forward | | 2026-09-07 | evaluation-adapters | darwin evaluatorEntrypoint bug re-confirmed live on main (missing positional; exit-0 silent misdirection into ./--sandbox/), triplicated across open PRs #17/#40/#65; withheld 4th duplicate fix, posted consolidating review comment on #65 | #90 | #91 | yes | REJECT | 572/572 tests green (491 vitest + 81 governance), 0 regressions (no code shipped); live darwin repro confirms bug unfixed on main; 3 open PRs (#17/#40/#65) already contain fixes, 0 merged | 6421a213e23a5162 | zeroMergeStreak=true (0 merged since #24 on 2026-08-26); #17/#40/#65 remain open/draft/unreviewed, PR #65 has 0 recorded CI checks; ledger verify's 17 pre-existing structural errors (issues #48/#58, PRs #49/#59) also untouched, same duplicate-direction reasoning; no session merge or self-promotion | | 2026-08-19 | developer-experience | tui pad() used raw string length not display width; fixed with Unicode-aware displayWidth/pad, preserved literal newlines in truncation per adversarial critique | #20 | #21 | yes | ACCEPT | npm test 96->103, 0 regressions | 25a4b37f | #7:MERGED #9:OPEN #11:OPEN #15:OPEN #17:OPEN #19:OPEN |