Repository navigation
docs: post-mortem on the guards arc — what shipped, and what did not work - #256
Merged
Merged
Conversation
Full post-mortem on the arc from PR #239 through the release, in reports/post_mortems/ following the platform convention (views-faoapi's shape: period/scope/final-stats header, why, timeline, what we did, what we learned, process, what remains). WHAT IT RECORDS. We built a cross-repository guard surface, and a post-merge review found fifteen defects in the change that built the newest part of it — every one reproduced. Three would have shipped in the release: the guard against publishing a coordinate value PRINTED it, on the one event it fires for; the drift check fired on 12 of 25 rows this partner never reads; and 15 of 29 markdown assignment forms escaped the no-copy scan. The remedy was deletion three times out of five. The source-reading check broke twice in 24 hours, both times because a consumer improved its own code — commits 8615574 and 0c493ae each introduce the named constant AND add that repository's registry-binding test, so the improvement and the breakage were one edit. THE PROCESS SECTION IS THE POINT, and it is not flattering. 341 lines of code against 452 lines of prose. Commits per story 7, 7, 12, 5. Four named failures: a governance rule repealed in a permanent ADR on a claim that was false by six hours; each remediation introducing a defect of the class it was fixing; numbers quoted from memory and wrong twice in consecutive tracking comments; and a review reported as running when nothing had been launched. The root cause is recorded as architectural rather than personal: ADR-016 and ADR-017 contain DESCRIPTIONS OF CURRENT IMPLEMENTATION, so they rot on every change. An ADR records a decision; the moment it also describes the code it becomes a second copy of the code. Most of #248's twelve commits were repairing that. And what worked: independent review (five parallel reviewers found what four rounds of self-review had not), deletion as the default remedy, refusing to chase five surviving mutations in writing rather than silently, and the maintainer's mid-sprint intervention — after which #248 took twelve commits and #243 took five. Every figure in the document was produced by a command and re-verified before commit, which is the rule this arc had to adopt halfway through. Epic #241. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Full post-mortem in
reports/post_mortems/2026-08-12_the_guards_that_did_not_guard.md, following the platform convention (views-faoapi's shape).Covers PR #239 through the release #240, epic #241, and register C-89…C-97.
The substance
We built a cross-repository guard surface. A post-merge review found fifteen defects in the change that built the newest part of it — all reproduced. Three would have shipped in the release:
The remedy was deletion three times out of five.
The process section is the point
Four named failures, worst first:
in.The root cause is architectural, not personal
ADR-016 and ADR-017 contain descriptions of current implementation — "this is the shape the registry check now has". An ADR records a decision; the moment it also describes the code it becomes a second copy of the code, and it rots on every change. Most of #248's twelve commits were repairing exactly that. It is the rule #250 will land.
What worked
Independent review — five parallel reviewers found what four rounds of self-review had not, and the adversarial mutation reviewer was the single highest-value input. Deletion as default remedy. Refusing to chase five surviving mutations in writing. And the mid-sprint intervention, after which #248 took twelve commits and #243 took five.
Every figure was produced by a command and re-verified before commit — the rule this arc had to adopt halfway through.
🤖 Generated with Claude Code