* fix(board): LEARN decisions name the item, not its per-cycle index
A cycle's reject reasons are rendered into the NEXT cycle's exploration
prompt, but the ref recorded alongside each reason was the item's stored
id (item-0/item-1) — a per-cycle index that means something different
every cycle and appears nowhere the explorer can resolve. The reason
survived the loop; what it was about did not.
Record the item's title instead, via a shared learn_ref() helper (falls
back to the id when title-less, and reads target_task_title for Scales,
whose items name the live task they mutate).
* chore(lint): satisfy ruff 0.16 — keyword-only signatures and markdown formatting
The dev toolchain resolved ruff 0.16.0, which stabilises PLR0917 (too many
positional arguments) and formats python code blocks inside markdown. Both
fired repo-wide and neither had anything to do with the code they flagged.
- 36 signatures gain a `*` so their tail arguments are keyword-only, and
the 104 call sites that passed them positionally are converted. mypy was
the safety net for the static ones; the full suite caught nine more that
only bind at runtime (the MCP tool functions, whose real callers already
pass named JSON arguments).
- 28 markdown files reformatted by 0.16's code-block formatter.
- One RUF036 (`None` mid-union) autofixed in the GitLab provider.
* fix(gateway): log the reason when a verb rejects
A rejected envelope rides an HTTP 200, its body is never logged, and there
is no trace table — so in the access log a verb an agent could not satisfy
looks identical to one that worked. On 2026-07-25 four Board Programs
(Periscope, Sentinel, Scales, Barfly) each POSTed their propose verb three
or four times, persisted nothing, and left their exploration tasks PENDING;
the reason was unrecoverable afterwards, from the logs or from the agents'
own transcripts.
Log error/message/remediate/missing plus the calling agent at
envelope_to_response — the one chokepoint every v1 flow and do route
returns through. Success envelopes stay silent.
---------
Co-authored-by: Renn F <rennf93@users.noreply.github.com>
Seventeen-page sweep of the agent-facing KB against shipped behavior:
required covers_parent_criteria and per-AC criteria_verified reach the
QA/PM/task-tools pages (the QA docs also named non-callable pass_review/
fail_review — the MCP tools are pass/fail); collision_context lands in the
QA/gate/planning evidence docs; the possibilities matrix gets its own
architecture page + config entry; the auditor page gains its missing
waive_finding and playbook-curation verbs; git-pr-types.md is rewritten
off the long-dead is_root_pr model; PR/workspace/git-error pages stop
assuming GitHub (forge-agnostic + env-ladder semantics).
Co-authored-by: Renn F <rennf93@users.noreply.github.com>
* feat(lifecycle): revision findings ledger — structured QA/PR/PM/CEO failure feedback, persisted and delivered down the chain
Every bounce used to survive only as flattened prose: rounds overwrote each
other in notes_structured, request_changes persisted nothing, two raw
dev_notes appends were silently destroyed by the next handoff note, and the
dev prompt pointed at fields (qa_notes via evidence(), pm_notes) the API
never delivered. Agents re-interpreted and re-discovered every failure
before they could start fixing it.
- task_review_findings (migration 071, append-only): file/line/severity/
criterion(AC-id-validated)/expected/actual/fix/evidence per finding, with
origin (qa|pr_gate|pm|ceo), round, and an open->addressed->verified
lifecycle (waived reserved); new tasks.pm_notes + PmReviewContent give
request_changes a structured home
- producers: fail_review/pr_fail/request_changes take findings=[...] (prose
issues shimmed+merged for one release, deprecation-logged); ceo_reject
validates its reason (no 500), lands an origin=ceo finding, and bumps
round+audit on branchless coordination roots; guardrails at the verb
chokepoint (nudge >5, hard reject >10, field caps, traversal-safe file);
the dev_notes data-loss appends are removed; new task.request_changes +
task.ceo_reject audit events close rework attribution
- delivery: qa_notes/pr_reviewer_notes/pm_notes carry the deterministic
[F-id8] rendering; claim briefings, evidence(), the REVISION_REQUIRED
spawn prompt, PM triage bounced-blocks, and A2A bodies deliver open
findings; round-N+1 QA and gate reviewers get the full prior ledger;
panel Findings tab + bounced-xN chip; metrics pm_rejects/ceo_rejects +
findings counts; vault task notes render a Findings section (fail-open)
- resolution closes for every origin: i_am_done and submit_up/submit_root
take resolved_findings gated by FINDINGS_ADDRESSED (owner-gated so a
stale non-owner PM can never mutate the ledger); pass_review/pr_pass/
complete verify-stamp same-transaction; ceo_approve stamps best-effort
- 24 real-DB integration tests drive the full loop through the real
choreographer; full suite 12856 green
* docs: revision findings ledger sweep — CLAUDE.md, map, RAG corpus
- CLAUDE.md: new ledger section + corrected request_changes row
- docs/map/review-findings.md (new subsystem map) + surgical updates to
task-service/pr-gate-review/metrics-observability/vault/panel maps
- docs/rag: producers' findings contract across qa/pr-reviewer/developer/
cell-pm/main-pm/ceo role docs (the PM docs were missing request_changes
entirely), verb references, and a new architecture/review-findings.md
disambiguating ledger findings from convention findings
* test(e2e): resubmit resolves the pr_fail finding per the ledger contract
The scripted pr_fail revision loop resubmitted submit_up without
resolved_findings — correctly rejected now that FINDINGS_ADDRESSED gates
the PM resubmit verbs (green locally, red only in CI since the e2e suite
skips without ROBOCO_E2E_SMOKE=1). The scripted PM now reads the open
ledger row pr_fail persisted (new open_finding_ids arc helper) and
resolves it on resubmit, asserting the open set drains — exercising the
coordinator half of the new contract end to end.
---------
Co-authored-by: Renn F <rennf93@users.noreply.github.com>