commit e81c921a779e643ef3a98a37cbd7daad0c9ff490
parent 5c0832e2de53e87f212d50fc4548857b693b5c70
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date: Tue, 6 Oct 2026 10:55:00 -0400
plans: release 18 — S2's last cleanup (the malformed-token codes) and the gates after merging S5 complete
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Diffstat:
1 file changed, 4 insertions(+), 0 deletions(-)
diff --git a/plans/release-18.md b/plans/release-18.md
@@ -678,6 +678,10 @@ no user ever saw it.
| L3 | `deployStage.ts`'s header: S1 has landed; `builtAfter` is `needs()`'s; the exit codes per step | `c5f9100f` |
| L4 | `stageRun.test.ts` proves the local copy by files the destination did not have (`corpus.json`, `site.json`) and the replaced `index.html` | `c5f9100f` |
| L7 | The smoke row: the mismatched homepage deploy exits 2; the changelog's tombstone bullet says "a channel only on a private site, or on no site"; the "hub builds again" changelog bullet removed (the statement above stays) | `c5f9100f` |
+| S5 smoke | A malformed token (`CLOUDFLARE_API_TOKEN=bogus`) gets `Invalid request headers [code: 6003]` / `Invalid format for Authorization header [code: 6111]` from Cloudflare; both now read as `[deploy] REFUSED by Cloudflare — the API token was not accepted` (9109, a well-formed wrong token, already did); a test line each | `51ef7fd1` |
+
+Gates after the cleanups (at `51ef7fd1`, after merging `r18/integration` `f9f7cfbf`, S5 complete, clean): tsc clean;
+**common 3,282/3,282**; **editor unit 142/142**.
### Slice S1, as shipped — the stage contract, the stamps, the lock, per-target bundles and the CLI (2026-10-06)
Branch `r18/stage-core` off `ce66f2d3` (the plan commit on `r18/integration`), worktree `~/Projects/r18-stage-core`