commit ecdcf38cdff0704434f6ec881032c5e0144483ac
parent d859520f578dcd7e793a021aad12db1c6d933435
Author: I Mean I'm Just Saying <imeanimjustsaying@kiwifarms.st>
Date: Sat, 26 Sep 2026 00:51:06 -0400
plans: brand S3 review fixes — the runbook's final-commit check and fail-stop rollout scripts; the test nits
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Diffstat:
3 files changed, 48 insertions(+), 8 deletions(-)
diff --git a/plans/STATE.md b/plans/STATE.md
@@ -4,9 +4,10 @@ The working memory for the local-AI derived-corpus work. Rewritten at the end of
session, before context is cleared. See [`README.md`](README.md) for the protocol.
**Now (2026-09-26, just after midnight): the brand is merged to `main` and NOT rolled out.** `main` =
-`2c76f6b2` + the S3 `plans:` record commit. It is release 10's first content, the Found-line mark and
-base × accent reader themes: S0 `7c9e3bdf`, S1 `575ae1d4`, S2 `b9772e53`, then S3 (integrate: review
-carry-overs, a coherence pass, the full gates, the records, the runbook) fast-forwarded. Record:
+`85cf6e81` + the S3 review-fix `plans:` record (review: SHIP AFTER FIXES, the fixes were in the
+runbook). It is release 10's first content, the Found-line mark and base × accent reader themes: S0
+`7c9e3bdf`, S1 `575ae1d4`, S2 `b9772e53`, then S3 (integrate: review carry-overs, a coherence pass, the
+full gates, the records, the runbook) fast-forwarded. Record:
[`release-10.md`](release-10.md); the plan and the per-slice records:
[`brand-and-themes.md`](brand-and-themes.md).
- **The live :3001 editor still runs the pre-brand build**, `0213f6c8` / `BUILD_ID`
diff --git a/plans/brand-and-themes.md b/plans/brand-and-themes.md
@@ -1,7 +1,7 @@
# Brand + themes: the Found-line mark, and base × accent
-Status: SHIPPED to main 2026-09-25 (S0 `7c9e3bdf`, S1 `575ae1d4`, S2 `b9772e53`, S3 `2c76f6b2` + its
-`plans:` record commit), not rolled out. Worked on `brand/found-line` (worktree `../brand-found-line`,
+Status: SHIPPED to main 2026-09-25 (S0 `7c9e3bdf`, S1 `575ae1d4`, S2 `b9772e53`, S3 `85cf6e81` + its
+`plans:` records), not rolled out. Worked on `brand/found-line` (worktree `../brand-found-line`,
pnpm wt block #1), with S1 and S2 as `brand/mark` and `brand/themes` off S0's tip. The release is
[`release-10.md`](release-10.md); the operator's runbook is `~/reports/release-10/RUNBOOK.html`.
@@ -1116,7 +1116,9 @@ wrote "IBM Plex Sans ships TrueType hinting", but the Google-served font has no
| `dc7ff1cf` | the scope starts at 1.5dppx (measured), test updated |
| `a4542721` | `fonts.ts`: IBM Plex Sans requested variable (the `l/font` build failure) |
| `2c76f6b2` | the `tokens.css` comment: why Plex hints on Linux, why the scope starts at 1.5x |
-| _this_ | `plans:` this record, `release-10.md`, FACTS, STATE, the rollout section |
+| `5a433aa9` | `plans:` this record, `release-10.md`, FACTS, STATE, the rollout section |
+| `85cf6e81` | review nits: the token parser comment; the SW test's no-cache network-error case |
+| _this_ | `plans:` the review fixes |
**Gates** (the code tip is `2c76f6b2`).
- **tsc** clean before every code commit (four runs: `s3-tsc-1..4.log`; the changelog commit is markdown).
@@ -1188,6 +1190,32 @@ header. They match the S2 post-merge shots and the canvas.
`homepage/public` holds copied data (gitignored). The worktree's `export/public` links are intact
and `sw.js` is a copy.
+**Review fixes** (review verdict SHIP AFTER FIXES, `$T/s3-review.md`; the code was approved, the
+must-fix and should-fix were in the runbook). `main` was fast-forwarded to `5a433aa9` first.
+- **Must-fix, the ancestor check.** The runbook checked that `b9772e53` (S2's merge) was on `main`, so
+ it passed while S3 was not merged, and step 1.2's `git log -1` could not tell the two apart. It now
+ checks that the brand's FINAL commit (this record's tip) is an ancestor of the primary's HEAD, at the
+ top of step 0 and in step 1.2, with a STOP banner when it is not; every rollout script refuses to run
+ without it.
+- **Should-fix, fail-stop scripts.** Every script is `set -eu` with an explicit guard on each step that
+ must stop the run, and prints its real status (no unconditional `exit=0`). `r10-home.sh` never deploys
+ after a failed build (`homepage/out` still holds release 9's build, and `deployHomepage` only checks
+ `out/index.html` exists) and refuses a `homepage/out` without `data-accent`. `r10-sites.sh` stops
+ before the hub when the sites run fails, and names a skipped site's `"reason"` (exit 1).
+ `r10-restart.sh` refuses while `editor/.next` is still the pre-brand `P0VMdKX7gbdsaiS5GvorF` unless
+ `--force`, and fails on a non-200 or any ZodError. Step 1.4 says: `BUILD_FAILED` → stop, do not
+ restart; and restart right after the build (a build into the live `.next` can break chunks the old
+ server has not loaded). A new `r10-rollback-editor.sh` (after `git switch --detach 0213f6c8`) shares
+ the restart checks.
+- **Runbook nits.** The smoke's ZodError line (it reads the r8 log name) is explained;
+ step 2's md5 check filters to `site.json` (a runner may stamp a `config.json`); the hand commit covers
+ `editor/CHANGELOG.md` when the editor notes are cut too, and the homepage's `/changelog` renders the
+ export changelog; the settings table says "unset", not `None`.
+- **Test nits** (`85cf6e81`). `themeTokens.test.ts`'s parser comment names the nested `@media` rule. The
+ service-worker test's "failed online icon fetch" case duplicated the first test's offline half; it
+ now covers the other branch, a failed fetch with nothing cached, which answers `Response.error()`.
+ Common stays **1,913**; tsc clean.
+
**Runbook:** `~/reports/release-10/RUNBOOK.html`, generated by `~/reports/release-10/make-runbook.py`
(the release 8/9 generator's shape; screenshots embedded as base64). It writes the rollout scripts to
`~/reports/release-10/scripts/` (`r10-build`, `r10-restart`, `r10-preview`, `r10-sites`, `r10-home`,
diff --git a/plans/release-10.md b/plans/release-10.md
@@ -27,7 +27,7 @@ S0 alone, then S1 and S2 in parallel worktrees off S0's tip, then S3 on the merg
| **S0** palette + data | `brand/found-line` off `d8dd98b8` → `02295a94` (+ `dbf12219`, the Archilyzer Media proposal) | SHIP | `7c9e3bdf` |
| **S1** mark, icons, wordmark | `brand/mark` off `02295a94` → `03a0ce06` | SHIP (fixes `541a46e0`, `405fccd5`, `951a0ff5`, `4a7641af`; re-read SHIP) | `575ae1d4` |
| **S2** base × accent | `brand/themes` off `02295a94` → `42e84f68` (merged `main` as `6456ac6c`) | SHIP AFTER FIXES (7 fixes; re-read SHIP) | `b9772e53` |
-| **S3** integrate | `brand/found-line` fast-forwarded to `b9772e53` → `2c76f6b2` + the `plans:` record | — | fast-forward |
+| **S3** integrate | `brand/found-line` fast-forwarded to `b9772e53` → `85cf6e81` + the `plans:` records | SHIP AFTER FIXES (the fixes were in the runbook; test nits `85cf6e81`) | fast-forward |
**Gates per slice** (full numbers in each slice's record in `brand-and-themes.md`):
@@ -93,7 +93,9 @@ left — is [`brand-and-themes.md`](brand-and-themes.md) "Slice S3, as shipped".
| `dc7ff1cf` | the scope starts at 1.5dppx (measured), test updated |
| `a4542721` | `fonts.ts`: IBM Plex Sans requested variable (the `l/font` build failure) |
| `2c76f6b2` | the `tokens.css` comment: why Plex hints on Linux, why the scope starts at 1.5x |
-| _this_ | `plans:` this record, `release-10.md`, FACTS, STATE, the rollout section |
+| `5a433aa9` | `plans:` the S3 record, `release-10.md`, FACTS, STATE, the rollout section |
+| `85cf6e81` | review nits: the token parser comment; the SW test's no-cache network-error case |
+| _this_ | `plans:` the review fixes |
**Gates** (the code tip is `2c76f6b2`).
- **tsc** clean before every code commit (four runs: `s3-tsc-1..4.log`; the changelog commit is markdown).
@@ -143,6 +145,12 @@ left — is [`brand-and-themes.md`](brand-and-themes.md) "Slice S3, as shipped".
`_headers` kept their sizes and mtimes before, between and after every run.
- Numbers tools: none.
+**Review** (SHIP AFTER FIXES): the must-fix and should-fix were in the runbook, not the code. The
+runbook now checks that the brand's final commit is in the primary's HEAD (it had checked S2's merge,
+which passed while S3 was unmerged), and every rollout script is fail-stop: no homepage deploy after a
+failed build, no hub step after a failed sites run, a skipped site named, no restart on the pre-brand
+`BUILD_ID`. Details: `brand-and-themes.md`, S3 "Review fixes".
+
## Rollout
Nothing is rolled out. The live :3001 editor still runs `0213f6c8` (the pre-brand build); the five
@@ -150,6 +158,9 @@ official sites are at release 8's Z + E; the hub and homepage at release 9's C1b
operator's runbook is `~/reports/release-10/RUNBOOK.html` (generated by `make-runbook.py` beside it,
with the rollout scripts in `scripts/`). The steps:
+0. **Check the primary contains the brand's final commit** (this release's `plans:` review-fix
+ commit): `git -C /home/user/Projects/yt-dlp-transcript-browser merge-base --is-ancestor <final>
+ HEAD`. The runbook names the sha, and every rollout script refuses to run without it.
1. **Cut the export release notes first.** `export/CHANGELOG.md`'s `[Unreleased]` is rendered on
every site's public `/changelog` until it is cut: `/sites` → Release notes → Cut release (the
form suggests `0.8.8`). With "Commit changelog" ticked the form refuses a dirty tree, and the