commit 63a1bc8fde9ebffeddef9ffbebbf63488ac36b30
parent 4372e5cccb38555134acc2762c8dfd08cff5299a
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date: Mon, 28 Sep 2026 15:00:09 -0400
plans: slice R's re-review record — R2-L1…L4 fixed (296b8a04, 4372e5cc), each key test proved by reverting its fix, the gates re-run
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Diffstat:
| M | plans/release-12.md | | | 70 | ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ |
1 file changed, 70 insertions(+), 0 deletions(-)
diff --git a/plans/release-12.md b/plans/release-12.md
@@ -704,4 +704,74 @@ rollout record), merged at `439eb106` with no conflict.
- **homepage e2e with `E2E_EXPECT_SOURCE=1`:** **36 passed**, 0 skipped, 51 s, with the manifest
present. The bite run is above: 3 failed and 2 passed in the empty state.
+**Re-review** (verdict **SHIP**; `$T/r-review.md`, "Re-review"). M1 is confirmed closed, and every
+deploy path goes through the check. The coordinator ruled that `--check` not withdrawing is
+accepted as built, and that the four new Lows be closed before the merge:
+- **R2-L1 — fixed** (`831763da`). A refusal that names a tree path (the symlink, `index.html` and
+ `404.html` refusals) printed a literal that spans path components (`a/b`) in full. The object
+ walk reads entry names one at a time, so it cannot see such a literal.
+ - `[source] REFUSED: …` now goes through `maskLiterals` with the loaded literals, in both
+ `publishSource` and `auditSource`.
+ - The kept-scratch path, the report's scrub-file path and the audit's "auditing <dir>" line are
+ masked too.
+ - Child stderr was already masked wherever it is quoted or echoed: git's refusal tails,
+ filter-repo's echo, gitleaks' lines. `subject` comes from the scrubbed mirror.
+ - The test plants `plant/secret` as a denied literal above a tracked symlink, then above a
+ tracked `index.html`. Both refusals print `[REDACTED]/…`.
+- **R2-L2 — fixed** (`831763da`). The state carries `contentDigest`, from `sourceDigest()`:
+ - it covers every published file: `source/archilyzer.git/**`, `source/tree/**`,
+ `source/manifest.json`, the tarball and `snapshot.json`;
+ - it hashes the sorted path, the size and a streamed sha256 of each; a symlink or a missing
+ piece only makes it differ;
+ - the skip recomputes it over `public/`, and the deploy check over `out/`.
+
+ A swapped tree file and a flipped pack byte are refused. On the real `out/` (2,640 files) the
+ whole check takes **0.58–0.76 s**, of which the digest is **0.48–0.54 s** (three runs).
+- **R2-L3 — fixed** (`831763da`).
+ - **The skip:** each part of the key (filter-repo, gitleaks, content digest, rules) and an edited
+ `public/` file is changed alone, through a publish that REACHES the skip. The filter-repo is
+ `false`, so a skip returns 0 and a miss returns 1.
+ - **The step version:** `rulesHashOf` is shown to move with it, and `loadSourceRules` uses
+ `SOURCE_STEP_VERSION`.
+ - **The deploy check's mirror-head and gitleaks comparisons** each refuse with their own
+ sentence.
+ - **Proved by reverting each fix** (`$T/r-m-mutate.py` against `source.ts`, restored after):
+ every revert fails its test. The eight reverts are:
+ - the deploy check's mirror-head comparison;
+ - the step version in the hash;
+ - filter-repo, gitleaks and the digest in the skip key (three reverts);
+ - gitleaks and the digest in the deploy check (two reverts);
+ - the refusal masking.
+- **R2-L4 — fixed** (`831763da`).
+ - The state carries `gitleaksIdentity()`: "skipped", "absent", or the version line plus the
+ binary's sha256. The sha is there because this machine's gitleaks prints "version is set by
+ build process" for every release.
+ - The skip and the deploy check compare it.
+ - `SOURCE_STEP_VERSION` is 3.
+- **The rollout note** (PUBLISH.md, `7940cb0c`, and here): **after the merge, rebuild and restart
+ the live editor (:3001) before any /sites Homepage job.** It runs its built bundle, so until then
+ its Build homepage job has no source step and its Deploy homepage job no source check.
+- **The reviewer's "minor" is left:** a real checkout that unexpectedly reads as "not a git
+ repository" (a worktree whose primary moved) builds with the empty state, withdrawing the
+ source. It is safe for privacy, and it is logged.
+
+| sha | what |
+|---|---|
+| `831763da` | `common:` refusals masked; `contentDigest` and `gitleaksIdentity` in the key; step version 3; the key's tests bite (R2-L1…L4) |
+| `7940cb0c` | `docs:` PUBLISH.md — the deploy key, masking, and rebuilding the editor after the merge |
+| _this_ | `plans:` this re-review record |
+
+**Gates after the re-review fixes:**
+- **tsc:** clean, 35 s.
+- **Unit:** common **2,149/2,149** (+3); the three filter-repo tests ran, 0 skipped. Homepage unit
+ **7/7**. `docs env --check` exits 0.
+- **`source publish --check` with the real files** exits **0** (19 s, would publish mirror head
+ `20c367613f75`). The count-only user-name grep of its log gives **0**.
+- **A real `build homepage`** is ok in 38 s (18 s for the source step). The source step's lines
+ hold 0 user-name occurrences.
+- **The deploy check, called read-only** on that `out/`, says **ok (would deploy)**.
+- **A rebuild with nothing changed** logs `up to date … skipping` (20 s), and the check still says
+ ok.
+- Nothing was deployed. `main` had not moved.
+
## Rollout