# Real rows from the fleet coordination ledger, 2026-09-11 to 2026-09-13.
# Redacted by build_ledger_snapshot.py: local clone and home paths, lab and
# carrier-grade addresses, cluster-local service names, the cloud account id,
# instance ids, operator attribution and personal handles. Ticket identifiers,
# repository references, lane names and prose are untouched, because those are
# what the R2 scorers grade.
# Each task's slice is delimited by its task id so the fed text is
# reconstructible byte for byte.

===== R2-01 (12 rows, 6431 chars) =====
2026-09-13T10:18:39Z | TERMINAL | lane=omn17195-integration-plan-20260913 | ticket=OMN-17195 | committed knowledge-base-internal@84bcafa beta/tracking/2026-09-13-integration-plan.md (17 rows across 6 destination batches, 4 named holds); filed OMN-18298 (omnimarket v0.4.73 release-cut stall); not pushed/PR'd this phase — Goal phase pushes jonah/omn-17195-morning-2026-09-13 and opens the single PR for the day
2026-09-13T10:22:12Z | TERMINAL | lane=board-consistency-fix | OMN-18290 | beta board publishing again. One rule for a met milestone (CLEARED conjunction), derived once by milestone_met() and read by the KPI, the milestone row and the forecast. omninode_infra#1415 squash ac8841d03da85382e0338edf0f4377b38a8adc3d; OCC companion 9322 merged first. Publish run 34751549706 SUCCESS 10:20Z after four consecutive failed runs since 08:46Z. Live board: KPI 1 of 5, one ms-met row, forecast 1 of 5. M2 not met, stated on the row: C1's 24h stability window leaves the 2026-09-13T02:08:48Z failure behind at 2026-09-14T02:08:48Z, computed from the probe's own run history, so the board flips itself at the first tick after that with no further PR.
2026-09-13T10:26:45Z | CLAIM | lane=session-goal-OMN-17195 | scope=beta/GOAL.md refresh + kb-internal PR publish + Linear evidence-less-Done flagging | worktree=$OMNI_HOME/omni_worktrees/OMN-17195/knowledge-base-internal-20260913
2026-09-13T10:26:51Z | TERMINAL | lane=session-goal-OMN-17195 | PUBLISHED knowledge-base-internal#393 (squash-merged 2026-09-13T10:26:51Z) — beta/GOAL.md rewritten (24 open/landed beta-path rows, 6 nested integration sub-rows, 23 lowest-leverage deployed rows dropped per header) | Linear: 0 corrected (no PROBED-vs-not-Done mismatch existed), 26 evidence-less-Done tickets flagged with comments naming the missing/failing probe, 0 reopened | residual: G1/G3/T2 gate rows have no owning ticket, minting deferred to next dispatch
2026-09-13T10:32:53Z | CLAIM | lane=omn18297-local-grounding | OMN-18297 identifier-grounding check in the delegation quality gate + per-backend input-token budget with escalation | scope: omnimarket node_delegation_quality_gate_reducer contract+handler, task_class_contracts.v1.yaml, bifrost_delegation.yaml backend budget field, node_delegate_skill_orchestrator local dispatch port; fixture from recorded delegation d715f096-27b9-444f-9355-3554819ef8a5; lab readback on onex-lab after merge | read-only on prod/stability/judge/lakshman/public cluster | no credential lifecycle change, no new tickets
2026-09-13T11:00:40Z | PROGRESS | lane=omn18296-stuck-published | OMN-18296 In Progress | PRs open: omnibase_infra#3479 (enforcement: typed completion_bound + select_abandoned_rows + terminal-emitting sweeper on its own timer), omnimarket#2510 (contract block + RUNTIME_RESTART_DURING_DELEGATION + codec terminal builder + client reads the declared bound) | cause: inference command offset committed then process lost (rpk: 12 requests / 11 responses, lag 0), recover_stale_rows row-only (state_store_adapter.py:383), sweep traffic-gated (handler_wiring.py:5427) | RED/GREEN recorded both repos | lab in-flight pod-delete proof pending both merges reaching the lane
2026-09-13T11:43:50Z | TERMINAL | lane=wt-pass23-2026-09-13 | ticket=OMN-16901 | OUTCOME: pass2 5 judged/4 removed, pass3 1 judged/0 removed | report=beta/tracking/2026-09-13-worktree-passes-2-3.md pr=https://github.com/OmniNode-ai/knowledge-base-internal/pull/395 merge_sha=9d9252d970a01bd383d292139d6b24befa2f06b1
2026-09-13T11:45:46Z | CLAIM | lane=board-reconcile-gate | ticket=OMN-18299 | repo=omninode_infra | Build the beta-board reconciliation gate: shared reconcile() derivation in tools/beta_board/beta_board.py, tools/beta_board/check_board_reconciliation.py, pre-commit hook scoped to tools/beta_board/**, PR CI workflow on the same paths, post-publish job in publish-beta-board.yml that cannot block the upload. Does NOT touch carrier lists or Linear labels (peer lane board-orphans-c26 owns those). Worktree $OMNI_HOME/omni_worktrees/OMN-18299/omninode_infra
2026-09-13T11:46:12Z | CLAIM | lane=closeout-infra-report | ref=OMN-16106 | read-only investigation of the closeout pipeline (dod_verify, evidence-autoclose sweep, OCC autobind/companion minting, codex merge sweep vs OCC) + one report PR to knowledge-base-internal reports/2026-09-13-closeout-process-infrastructure-report.md | no code changes, no ticket minting, no Linear state changes
2026-09-13T11:54:51Z | CLAIM | lane=omni-home-cleanup | actor=claude:opus5:subagent | ticket=OMN-17994 | scope=phases 1-2 of the operator ask (remove ephemeral artifacts, then commit all remaining files); phase 3 migration NOT in scope | plan=OMN-17994, inventory knowledge-base-internal beta/tracking/2026-09-06-omni-home-refresh-branch-landing.md | method=classification written to session scratchpad before any deletion; deletions limited to untracked ephemeral with a zero-reference positive-control grep; commits only via scripts/commit_lock.py with explicit paths; no push, no PR | no prod/stability/judge/lakshman/cloud contact, no credential action, no ticket minted
2026-09-13T11:59:21Z | CLAIM | lane=board-orphans-c26 | ticket=OMN-18044 | repo=omninode_infra | Classify the 18 orphaned beta-critical tickets against C1-C27, apply only the CLEAR-MAP set to the carrier lists in tools/beta_board/beta_board_data.py, mint the C26 rehearsal carrier plus one readback ticket, verify the four single-carrier criteria. Touches CRITERIA carrier lists ONLY in that file; peer lane board-reconcile-gate (CLAIM :7220, OMN-18299) owns beta_board.py, the reconcile checker, the hook and the workflows and is not touched here. NO Linear label removed on any ticket (CLEAR-DROP and RULING items are reported, not acted on). Worktree $OMNI_HOME/omni_worktrees/OMN-18044-orphans/omninode_infra
2026-09-13T13:05:56Z | CLAIM | lane=merge-sweep-worktree-addendum | actor=claude:opus5:subagent | ref=OMN-16106 | scope=READ-ONLY provenance investigation of the OMN-17341 onex_change_control_9321 worktree (branch manual-merge-sweep/omn-17341-occ-9321-conflict) plus ONE document PR appending an Addendum section to reports/2026-09-13-closeout-process-infrastructure-report.md in knowledge-base-internal (predecessor kb-internal#396). OUT OF SCOPE: any code change, any ticket mint, any Linear state change, any worktree deletion, any runtime or credential contact. No concurrent CLAIM on this subject at claim time.

===== R2-02 (15 rows, 11912 chars) =====
2026-09-13T09:19:17Z | CLAIM | lane=board-consistency-fix | OMN-18290 | beta board: milestones-met KPI and milestone table derive met from two different rules; every publish run has failed the honesty check since 08:46:05Z. Single-rule fix in omninode_infra tools/beta_board. Worktree $OMNI_HOME/omni_worktrees/OMN-18290/omninode_infra
2026-09-13T09:23:50Z | CLAIM | lane=draft-pr-sweep | actor=claude:sonnet5 | scope=org-wide-draft-pr-audit(read-mostly; gh pr ready on 3 PRs) | intent=operator ask 2026-09-13 'if we have any draft prs, see if they should be flipped to non-draft'. Enumerated 25 open draft PRs org-wide (gh search prs --owner OmniNode-ai --draft, cross-checked per-repo against all 16 registry repos, positive control confirmed non-draft query returns rows). Cost: est 0.5 lane-hours; read-heavy, 3 mutating gh pr ready calls, no code/ticket/Slack writes.
2026-09-13T09:49:31Z | CLAIM | lane=morning-plan-reconcile-2026-09-13 | OMN-17195 | Reconcile phase: beta rebaseline vs plan falsifiable rows, verdict ladder, Linear mismatch report | artifact=knowledge-base-internal beta/tracking/2026-09-13-beta-rebaseline.md
2026-09-13T10:02:02Z | TERMINAL | lane=morning-plan-reconcile-2026-09-13 | OMN-17195 | Reconcile delivered: 62 falsifiable rows measured on live reads this run | counts OPEN=20 LANDED=10 DEPLOYED=27 PROBED=5 UNKNOWN=0 | beta_path=50/62, 3 beta-path rows PROBED | 4 rows probe-contradicted (B11, OMN-16984, OMN-15796, OMN-16979); 1 probe unrunnable (OMN-6790, broker SASL) | 26 evidence-less Done, 0 lagging board | artifact=knowledge-base-internal beta/tracking/2026-09-13-beta-rebaseline.md commit 68ffe30, 170 lines, scrub exit 0, not pushed (Goal phase owns the PR) | zero ticket-state mutations
2026-09-13T10:12:03Z | CLAIM | lane=dogfood-r2-tickets | minting 4 Linear tickets from dogfood round 2 findings (2026-09-13-dogfood-r2-summary.md, task files) | scope: OMN tickets for cloud payload-size refusal, gateway quality-gate contradiction, delegation stuck non-terminal on redeploy, local grounding degrades with input size
2026-09-13T10:13:50Z | TERMINAL | lane=dogfood-r2-tickets | minted OMN-18294 (cloud payload-size refusal, parent OMN-18185), OMN-18295 (quality gate fails a score above its own bar, parent OMN-18185), OMN-18296 (Urgent, delegation stuck non-terminal on lab redeploy, parent OMN-18168), OMN-18297 (local grounding degrades with input size, parent OMN-18232, related OMN-18278) | all cited delegation ids from dogfood round 2 | nothing left uncited
2026-09-13T10:15:31Z | CLAIM | lane=omn18296-stuck-published | OMN-18296 delegation stuck at 'published' with no completion bound when owning runtime restarts mid-flight | scope: omnimarket delegation workflow contract + runtime terminalisation bound/sweeper + onex cloud delegate client poll bound; lab proof on onex-lab | read-only on prod/stability/judge/public cluster
2026-09-13T10:18:32Z | CLAIM | lane=omn17195-integration-plan-20260913 | scope=knowledge-base-internal beta/tracking/2026-09-13-integration-plan.md | ticket=OMN-17195 | Integration plan phase: gather LANDED reconcile rows + window merges (2026-09-12..09-13) across 12 registry repos, write integration rows grouped by destination batch
2026-09-13T12:13:23Z | PROGRESS | lane=board-reconcile-gate | ticket=OMN-18299 | claim=docs/tracking/ROLLING_WORK_LEDGER.md:7220 | PR https://github.com/OmniNode-ai/omninode_infra/pull/1420 open, OCC companion OCC#9338 auto-merge armed 12:13:12Z. Shared reconcile()+board_carriers() lifted out of beta_board.main(); render proven byte-identical on the orphan section against the pre-change renderer. 25 tests in tests/scripts/test_beta_board_reconciliation.py (RED first: 19 of 22 failed pre-implementation). POSITIVE CONTROL, live Linear, CI run 34755972212 job <cloud-account>: exit 1 naming 18 orphaned open beta-critical tickets + C26 no-carrier + C2/C12/C23/C27 single-carrier NOTE, matching the rendered board 18/1/4 exactly. MERGE BLOCKER: pre-commit --all-files in CI runs the new hook over beta_board_data.py and fails on C26, so CI Summary is FAILURE until peer PR #1421 (OMN-18302, gives C26 its carrier) merges. Not weakened; waiting on that sequencing.
2026-09-13T13:00:04Z | CLAIM | lane=board-orphans-c26 | ticket=OMN-15651 | repo=omninode_infra | UNBLOCK, not scope creep: the OMN-15651 audited-exclusion pin for omnimarket handler_quality_gate.py went stale when omnimarket#2512 (OMN-18295) merged 2026-09-13T12:23:39Z, and tests/architecture/test_omn_15651_task_class_authority.py now fails on EVERY omninode_infra pull request opened since (measured: my #1421 and the peer lane's #1420 both red; #1310 and #1214, last built 09:23Z, both green). Re-audited per the entry's own recorded command shape: locator _VERIFIABLE_TASK_TYPES byte-identical dfb375aa... on both revisions, 6-line extraction with a 0-line negative control, frozenset membership unchanged, still exactly one consult site, zero diff lines touching either. Exclusion rationale holds; only the pin moves. Same shape and same ticket as precedent omninode_infra#1391 (eaa138be). Does NOT touch OMN-18294/OMN-18295 lane scope (CLAIM :7207 = gateway prompt limit + quality-gate scoring). Worktree $OMNI_HOME/omni_worktrees/OMN-15651-pin/omninode_infra
2026-09-13T13:01:02Z | TERMINAL | lane=closeout-infra-report | ref=OMN-16106 | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7221 | REPORT LANDED. knowledge-base-internal#396 MERGED 2026-09-13T13:00:47Z squash 346f108f2e5525d9b037f374de9aee1f4430935b, reports/2026-09-13-closeout-process-infrastructure-report.md, all 8 checks green. FINDINGS: closer flipped 47 of 473 Done tickets in 14d (9.9%), 426 by hand; binds_ac 68 of 8871 OCC contracts at origin/dev 2abfce96 (was 0 on 09-09); applied flips fell 18/day on 09-05 to 0 on 09-13 on gap_ac_unbound (213 holds); Linear records no bot actor so attribution needs the closer flip marker; 4 closer flips reverted by hand within 2min-6h; dod_verify controls OMN-18292 (28s exit1 EVIDENCE_UNVERIFIABLE product_clone_stale) and OMN-16106 (255s exit1 39/131 verified); OCC companions 707 of 733 merged product PRs over 7d, 4 of 5 gaps are one stamp patch-back race, omniweb companion-effect failing 47% on empty broker credentials; codex merged OCC#9005 and OCC#9009 on 2026-09-11 as actor=codex:/root/m3_receipt and hand-corrected the generated #9009 companion, read-only integration passes only since 09-12. Zero code changes, zero tickets minted, zero Linear state changes.
2026-09-13T13:01:15Z | WITHDRAWN | lane=board-orphans-c26 | ticket=OMN-15651 | closes=CLAIM docs/tracking/ROLLING_WORK_LEDGER.md:7230 | NO PR OPENED, NO COMMIT MADE, worktree and branch removed clean. The pin refresh I claimed was already on dev: omninode_infra e44e2066 (PR #1419, OMN-18293, merged 2026-09-13T12:59:03Z) carries exactly the 0bc7aa81 -> 916f59cc line, landed while I was auditing. My independent re-audit stands as corroboration and is recorded HERE because the fixture entry now carries no audit note for this drift: locator _VERIFIABLE_TASK_TYPES byte-identical dfb375aacf44718cf09971016819f768b7c061ad3206039042111d326dc00344 across omnimarket 8863472c and ddeb8c57, awk extraction 6 lines against a 0-line negative control, membership unchanged at code_generation/test/validator_generation/refactor, still exactly one consult site, and zero diff lines of omnimarket#2512 touching either. Exclusion rationale holds on independent measurement. RESIDUAL, no ticket minted per brief: e44e2066 moved this pin with no re-audit comment beside it, the first drift since 2026-08-31 refreshed without one, breaking the convention every prior refresh followed (precedent #1391 / eaa138be).
2026-09-13T13:08:22Z | CLAIM | lane=lab-dogfood-mint-db-target | actor=claude:opus5:subagent | ticket=OMN-18303 parent=OMN-18185 | SCOPE: fix the onex-lab dogfood mint Job's active-credential predicate to read tenant_inference_credentials from the database that owns it (omnidash_analytics, through the analytics_db binding the OMN-16863 reader already uses and the canonical onex-runtime-credentials Secret), check the house mint Job for the same shape, RED-first persisted test in tests/k8s, and ONE sanctioned apply_lab_lane.sh re-apply on the persistent onex-lab lane with the mint predicate forced to execute. | OUT OF SCOPE and untouched: any tenant key, any store folder or identity, any Secret mutation, any credential mint/rotation/re-issue/revoke; the house and dogfood tenants' rows; staging, prod, stability-test, judge, lakshman and both cloud clusters (read-only); minting more than the one granted ticket; Slack; Linear writes outside OMN-18303. | PRE-CHECK: no live applier CLAIM on the ledger (lab-dogfood-tenant-manifest :7193 and lab-tenants-store-folder :7216 are both TERMINAL). | Worktree: $OMNI_HOME/omni_worktrees/OMN-18303/omninode_infra
2026-09-13T13:13:10Z | TERMINAL | lane=omn18296-stuck-published | OMN-18296 code MERGED, lab in-flight proof NOT obtained | omnibase_infra#3479 squash 0748a4deafaa2efbc15801a4deae165ead635e0d (OCC#9331 8f07f493697cf8e6204f958a949d3166a3a1dc9b), omnimarket#2510 squash 76ce3b56ca53b3e38baee2c8e8ea2027a3381e7b (OCC#9332 403cfd4de64eae727bb6acd9eb9fb70beee7dd60) | cause: inference command offset committed then process lost (12 requests / 11 responses, group lag 0); recover_stale_rows row-only (state_store_adapter.py:383); sweep traffic-gated (handler_wiring.py:5427) | lab now runs onex-lab/omninode-runtime:20260913T124906Z-0748a4de carrying the infra enforcement but omnimarket staged pre-merge (contract completion_bound absent, enum 10 members) so the bound is inert; omnimarket runtime-rebuild-trigger is deliberately workflow_dispatch-only and a bare dispatch is a no-op, and omnibase_infra's fires only on its own PR close, so the next omnibase_infra dev merge is what stages the merged omnimarket | live corroboration: FSM row a2fe0848 flipped FAILED by the legacy row-only sweep at 12:12:11Z while gateway_workflows 16eafedc stayed published with completed_at NULL | 16eafedc cannot be closed by the new sweeper: its FSM row is already terminal so the abandoned-row predicate excludes it | ticket left In Progress
2026-09-13T13:18:28Z | TERMINAL | lane=board-orphans-c26 | ticket=OMN-18302 | closes=CLAIM docs/tracking/ROLLING_WORK_LEDGER.md:7224 | related=OMN-18044,OMN-18100,OMN-18301,OMN-18140 | OUTCOME: ALL 18 ORPHANS CLASSIFIED, THE 5 CLEAR-MAPS LANDED, C26 HAS A CARRIER. MERGED companion-first: onex_change_control#9339 squash 2abfce9639e6d73176d99e7d816fb690cb46a627 at 12:48:53Z, then omninode_infra#1421 squash d6efd07b498721cd2d6e96f3dcf9d3f9ce3922d3 at 13:05:57Z, confirmed ancestor of origin/dev. BOARD REGENERATED AND READ BACK LIVE: publish run 34758902711 head d6efd07b success 13:06:20Z; strip now 13 orphans / 0 criteria with no carrier / 4 single-carrier, from 18 / 1 / 4. C26 renders chip OMN-18301 at 0/1 and proof NOT RUN, NOT green. VERDICTS: CLEAR-MAP 5 (OMN-10856 C1, OMN-15922 C9, OMN-17454 C9, OMN-17374 C19, OMN-18116 C15); CLEAR-DROP 5 (OMN-16030, OMN-16067, OMN-17792, OMN-17810, OMN-17913); RULING 8 (OMN-16875, OMN-17214, OMN-17215 observability family already carrying Jonah interim ruling 2026-09-11 'no criterion is observability, stays an honest unmapped gap until M3'; OMN-17440 grant delivery; OMN-16718, OMN-16719 public-cluster bus plane; OMN-17274, OMN-17276 charter family under the firm 2026-09-05 operator ruling that they are tests not release deliverables). ALSO: C2 gained OMN-18140 which declares that criterion in its own title, so C2 leaves the single-carrier set and C26 joins it, net 4. SINGLE-CARRIER VERDICTS: C23 COVERED; C2, C12, C27 NOT COVERED with the uncovered clause named. ZERO LABELS REMOVED, zero ticket states flipped except my own OMN-18302 to Done on merged-PR plus live-board evidence. No cluster, lane, credential or prod action of any kind. TWO TICKETS MINTED, exactly the grant: OMN-18301, OMN-18302.

===== R2-03 (20 rows, 39943 chars) =====
2026-09-13T08:31:40Z | worktree-prune-2026-09-13 | CLAIM | lane=worktree-prune-sweep-2026-09-13 | task=Run committed worktree_auto_prune.py classifier dry-run, sanity-check safe set, write report to knowledge-base-internal beta/tracking/2026-09-13-worktree-prune.md(.json), commit path-scoped, no removals this phase | ticket=OMN-16901
2026-09-13T09:10:59Z | PROGRESS | lane=omn18287-bp-audit | correction | The preceding TERMINAL row cites closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7218; the correct line is :7157 (this lane's own CLAIM row, timestamp 2026-09-13T07:18:05Z). No other content in that TERMINAL row is affected.
2026-09-13T09:11:33Z | OPERATOR-CONSENT | lane=lab-second-tenant | approved_by=operator | "second tenant is fine" (operator, 2026-09-13T09:11:33Z, in-session, answering: lab tenant key posture, option 1 = a second lab tenant holding a standing provider-key registration the C7 chain never grades) | APPROVED SCOPE: create ONE additional lab tenant on the persistent onex-lab lane; register ONE standing customer provider-key credential for that tenant sourced from the store; this credential is named lab-dogfood-tenant-provider-key | OUT OF SCOPE: the existing lab tenant 6c48114b and its credential rows; any staging or prod tenant; any withdrawal of an existing credential; printing any value | This row is the durable authorization evidence
2026-09-13T09:11:33Z | RULING | lane=orchestrator | subject=OMN-18232 phase 5 items 5-6 (branch-claim refusal) | "fine with your recommendtion on 2" (operator, 2026-09-13T09:11:33Z, in-session) = BOTH: the pull-request check lands first and only records; the pre-push hook that refuses lands after the release path is shown to be easy in practice (measured, not asserted)
2026-09-13T09:11:33Z | OPERATOR-CONSENT | lane=cloud-ci-canary-route | approved_by=operator | "why not try a canary to the cloud?" (operator, 2026-09-13T09:11:33Z, in-session; cloud CI fleet omni-cloud-ci, ASG omninode-ci-runner-asg, OMN-18205) | APPROVED SCOPE: route ONE canary job class to runner group omni-cloud-ci via the narrowest routing variable for that job class (rule 14: CLAIM every scope, enumerate live, per-scope readback, policy yaml in the same action), and build the scale-up trigger that raises fleet capacity for queued jobs, max capacity 4 unchanged | OUT OF SCOPE: OMNI_TRUSTED_CI_RUNS_ON_JSON and OMNI_PUBLIC_PR_RUNS_ON_JSON at every scope; any job class beyond the one canary; ASG max above 4; any credential change; prod | This row is the durable authorization evidence
2026-09-13T09:11:47Z | TERMINAL | lane=m2-board-landing | onex_change_control#9315 merged 56de56b3 at 08:25:56Z | omninode_infra#1410 merged 7ce0b41b at 08:46:05Z (required one companion-gate retrigger empty commit + one PR branch-update-to-dev to clear a BEHIND merge-state) | board not yet flipped 25min post-merge: publish-beta-board.yml run 34748643628 (headSha 7ce0b41b) concluded failure on a transient GitHub App installation-token 500, unrelated to PR content; board still reads Met: M1. Next: M2 as of 09:11Z
2026-09-13T09:31:20Z | CLAIM | lane=omn18292-verify-runbook | ticket=OMN-18292 | Fixing the onex-verify runbook host defect: correcting docs/runbooks/2026-08-24-onex-verify-client-credentials.md (bare auth.omninode.ai -> dev.auth.omninode.ai / live-resolved issuer, same defect class as OMN-16504), relocating it to knowledge-base-internal runbooks/ per kb-doc-gate (mode diff refuses a modify under docs/runbooks/**, not in allowed:), checking the two citing docs (docs/testing/2026-08-26-staging-test-walkthrough.md, docs/tracking/2026-08-28-e2e-walkthrough-runbook.md -- confirmed both already cite dev.auth.omninode.ai correctly, no host fix needed there), adding a guard test in omninode_infra beside test_probe_onex_dev_keycloak_check_targets_dev_issuer.py plus an equivalent doc-lint in knowledge-base-internal, and a read-only SSM proof of the corrected mint against dev.auth.omninode.ai on <instance-id>. No credential action. Reads only on clusters.
2026-09-13T09:40:08Z | CLAIM | lane=lab-dogfood-tenant-manifest | actor=claude:sonnet5:subagent | ticket=OMN-18293 parent=OMN-18282,OMN-18185 | SCOPE: declare the onex-lab-dogfood tenant (cacacbb1-0e64-4521-9712-ed02ee799907) idempotently in omninode_infra k8s/onex-lab/jobs alongside the existing house-tenant mint Job, so a from-scratch lab rebuild does not silently lose it; add a persisted isolation test; sequence the new job in apply_lab_lane.sh after migrations + house mint, before any chain; verify with a real applier run and AC4 readback. | OUT OF SCOPE: tenant 6c48114b (house) and its credential rows; any Infisical store folder/identity creation; any staging/prod/stability/judge/lakshman/cloud-cluster contact; any credential value printed; any chain source-of-truth (provider_key_chain.sh) edit beyond what AC2/AC3 require. | Worktree: $OMNI_HOME/omni_worktrees/OMN-18293/omninode_infra
2026-09-13T10:09:07Z | CLAIM | lane=dogfood-round-2 | actor=claude:sonnet5 | tickets=OMN-18200 related=OMN-18278,OMN-18280,OMN-18282,OMN-18185 | SCOPE: round-2 dogfooding per operator standing rule (delegation-first daily work) -- run five real pieces of tonight's session work through BOTH onex delegate (local-bus) and onex cloud delegate (customer-key, dogfood tenant cacacbb1-0e64-4521-9712-ed02ee799907) once each, ten runs total, zero retries of the delegated work itself; record receipts, accuracy/leak reads, and a routing recommendation to docs/drafts/2026-09-13-dogfood-r2-*.md. Tenant key read in-cluster via kubectl get secret onex-lab-dogfood-tenant-credential -n onex-dev on <lab-host>, piped straight to a 0600 local file, never printed, never in argv/env; ssh-forwarded loopback tunnel to svc/onex-api. OUT OF SCOPE: any credential lifecycle change, ticket minting, Slack, Linear writes, cluster mutation beyond read-only kubectl get and the sanctioned port-forward. NOTE: writes to docs/drafts/ began before this CLAIM was appended (process gap, stated not buried); no destructive or credential-affecting action preceded this row.
2026-09-13T10:26:11Z | CLAIM | lane=omn18294-18295-cloud-gates | actor=claude:opus5:subagent | tickets=OMN-18294,OMN-18295 parent=OMN-18185 | SCOPE: OMN-18294 raise+document the gateway workflow-contract prompt limit (omninode_infra docker/onex-api/workflow-contracts.yaml delegation-inference prompt.maxLength), advertise the payload schema on a discovery surface, and make the omnimarket cloud CLI read that limit, precheck locally with measured size, and surface the gateway's existing field-level errors[] that _detail() currently discards; OMN-18295 make ONE declared rule set decide the quality gate verdict (omnimarket node_delegation_quality_gate_reducer) so a score at/above the bar is not also vetoed by the same axis, move every rule threshold into task_class_contracts.v1.yaml, and carry per-rule score/threshold/verdict on the receipt; RED tests first on both. | OUT OF SCOPE: any credential mint/rotation/re-issue/revoke; prod, stability-test, judge, lakshman compose lanes; both cloud clusters (read-only); ticket minting; Slack; Linear writes beyond these two tickets; running apply_lab_lane.sh concurrently with lane lab-dogfood-tenant-manifest (CLAIM :7193) | worktrees=$OMNI_HOME/omni_worktrees/OMN-18294/{omninode_infra,omnimarket}, $OMNI_HOME/omni_worktrees/OMN-18295/omnimarket
2026-09-13T10:42:05Z | TERMINAL | lane=worktree-prune-sweep-2026-09-13 | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7168 | ticket=OMN-16901 | OUTCOME: dry-run classifier ran twice (first pass scanned=803 superseded; report files lost to an operator-side worktree-path mishap before commit, not a classifier defect); second pass scanned=816 safe=21 triage=795 debris=38 removed=0 is the cited result. Report committed at knowledge-base-internal 254b3d1f6b77cfb34556a30ae415a9481afb5e19 on branch jonah/omn-16901-worktree-prune-sweep-2026-09-13 (beta/tracking/2026-09-13-worktree-prune.md + .json), scrubbed clean via scrub_shared_doc.py (1723 lines repaired, portable paths only), check_no_local_paths.py and check_beta_layout.py both clean, full pre-commit hooks green. NOT PUSHED — Prune phase owns push + PR per contract. All 21 prune-candidate rows verified non-empty eligibility+safety evidence; 0 fenced tickets (none passed this run); 0 rows withheld. DISAGREEMENT RECORDED, NOT ACTED ON: 2 of the 21 safe rows resolve to ticket OMN-16901 itself (this lane's own worktree included) via a cross-lane ticket-ID-collision in ledger claim-keying -- a same-day sibling lane's (friction-report-2026-09-13) TERMINAL row at :7170 (08:45:00Z) postdates this lane's own still-open CLAIM at :7168 (08:31:40Z) and masks it because claim lookup keys on ticket number only, not lane identity; full detail in the report's Run notes. No removal occurred (dry run); this lane's own worktree will drop out of the safe set on next re-classification once its commit lands.
2026-09-13T11:03:02Z | OPERATOR-CONSENT | lane=lab-tenants-store-folder | approved_by=operator | "ok, go ahead and create a tenants folder" (operator, 2026-09-13T11:03:02Z, in-session, answering the OMN-18293 residual: the lab store has no /lab-tenants folder so the dogfood tenant key lives in a namespace Secret) | APPROVED SCOPE: create folder /lab-tenants in the lab secret store (Infisical, environment dev, the lab lane project); grant the EXISTING lab store-resolver identity read access to that folder only; file the existing dogfood tenant API key (Secret onex-lab-dogfood-tenant-credential) and the house tenant API key (Secret onex-lab-tenant-credential) into it by copy; repoint the lab mint jobs to resolve tenant keys from the store | OUT OF SCOPE: any new identity; any rotation, re-issue or revoke of any key; any environment other than dev; any folder other than /lab-tenants; staging or prod stores; printing any value | This row is the durable authorization evidence
2026-09-13T11:05:58Z | CLAIM | lane=lab-tenants-store-folder | actor=claude:opus5:subagent | ticket=OMN-18293 (evidence comment; residual of OMN-18282) | consent=docs/tracking/ROLLING_WORK_LEDGER.md:7215 | SCOPE exactly as the consent row: create folder /lab-tenants in the lab secret store (Infisical instance D http://<lab-host>:8880, project onex-platform 872e00f4-1279-49a4-8e16-a2bd961f4996, environment dev); confirm the EXISTING lab store-resolver identity (client id e9aad20d-5212-4c8d-8b04-6885f3a62161 = identity onex-runtime 5fc7c5e9-13ab-4d94-a14c-7a75201d7c34) can read that folder and only that folder is changed; copy the two EXISTING tenant API keys from namespace Secrets onex-lab-tenant-credential and onex-lab-dogfood-tenant-credential (onex-dev on the lab k3s) into it by value-on-stdin, readback by length + sha256-12 only; repoint k8s/onex-lab/jobs/mint-lab-tenant.yaml and jobs-dogfood/mint-lab-dogfood-tenant.yaml to resolve the tenant key from the store with a structural skip when the lane is unbound, TDD RED first, one idempotent apply_lab_lane.sh re-apply at current image tags; runbook update in knowledge-base-internal. | OUT OF SCOPE: any new identity; any rotation, re-issue or revoke; any environment but dev; any folder but /lab-tenants; staging/prod/stability/judge/lakshman/cloud stores; printing any value | Worktree: $OMNI_HOME/omni_worktrees/OMN-18293/omninode_infra-store
2026-09-13T11:55:41Z | CLAIM | lane=delegation-complexity-ladder | actor=claude:opus5:subagent | ticket=OMN-18300 (epic, minted this run, project Ready, Gate: C14) related=OMN-18278,OMN-18294,OMN-18295,OMN-18296,OMN-18297,OMN-18232,OMN-18185 | SCOPE: build a six-rung task-complexity ladder measuring what the local delegation model can be trusted with, per the operator ask 2026-09-13 ('when can we start using delegation to do actual work'). Harness + committed task-bundle fixtures + mechanical scorers + JSON-emitting runner into a NEW omnimarket benchmarks/delegation_ladder/ (checked first: no benchmarks or evals directory exists in any of the four repos; omnimarket has node_llm_eval_harness which is a node, not a fixture home). Every task run ONCE through onex delegate (local, Qwen3.6-35B-A3B on <lab-host>:8000) and ONCE through onex cloud delegate (dogfood tenant onex-lab-dogfood on the persistent onex-lab lane); zero retries of the delegated work; a cloud refusal on a large bundle is recorded as a result, never dodged by shrinking the bundle. Then a report to knowledge-base-internal reports/ and an UNMERGED proposal to knowledge-base-internal beta/plans/ for the delegated execution surface. | OUT OF SCOPE: any credential lifecycle change (the dogfood tenant key is read in-cluster, piped, shredded, onex cloud logout at close); any cluster mutation beyond read-only kubectl get plus a sanctioned port-forward; prod, stability-test, judge, lakshman and the public cluster (untouched); any lab applier run (none needed, and a concurrent one is already claimed by lane lab-dogfood-tenant-manifest); minting more than the one granted epic plus at most two defect children; Slack; any Linear state change outside OMN-18300. | Worktrees: $OMNI_HOME/omni_worktrees/OMN-18300/{omnimarket,knowledge-base-internal}
2026-09-13T11:59:34Z | TERMINAL | lane=omni-home-cleanup | actor=claude:opus5:subagent | ticket=OMN-17994 | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7222 | outcome=PHASES_1_2_COMPLETE_PHASE_3_NOT_STARTED_ONE_OPERATOR_DECISION_OPEN | PLAN FOUND, not new: the operator sequence (remove ephemeral, then commit all, then migrate) is OMN-17994 and its inventory knowledge-base-internal beta/tracking/2026-09-06-omni-home-refresh-branch-landing.md, which records the 2026-09-06T13:50Z operator ruling in those exact terms. Steps 1-2 and 4 of that ticket already landed (omni_home#258 merged 2026-09-06T15:08Z; kb-internal#178/183/184/185/186/187 all merged 15:05-15:37Z). | PHASE 1: 513 dirty files classified against the pinned validator kb_doc_gate.py@ca98494a; classification at the session scratchpad omni-home-cleanup-classification.md. Only 2 files were EPHEMERAL and were deleted: reclaim-measurement/SCRATCH_LEDGER.md and SCRATCH2.md, untracked synthetic scratch ledger rows written 05:36Z, zero references anywhere in omni_home, omniclaude, omnibase_infra or kb-internal under a grep whose positive control returned rows for two of four probe patterns. Nothing else qualified: the ephemeral classes named in the ruling were already removed and ignore-ruled by #258, and the remaining untracked corpus is content. No tracked file was deleted. mtime was NOT used as a liveness signal (the pre-commit stash-restore stamps every uncommitted tracked file with the last commit instant, as the inventory records); only the ledger is genuinely newer than the last commit. | PHASE 2: 8 commits via scripts/commit_lock.py with explicit paths, no -A, no bypass flag, kb-doc-gate hook Passed on every one: 6737cc94ca gitignore 1, 813294d064 plans 2, fba79474da workflow config 5, aea811c4f3 deep dives 20, 3dac3c92af non-markdown dumps 7, b37d6f88eb evidence bundles 34, 350b7eccc8 article infographics 64, 71de716f2e draft binaries 107. 240 files landed. Zero commit_lock refusals. Nothing pushed, no PR opened; branch jonah/omni-home-refresh-20260820 stays local at 873 ahead of origin/main, 9 behind. | REFUSED AND LEFT UNCOMMITTED: 270 markdown files the gate refuses, by destination: kb-internal beta/tracking 55, beta/handoffs 2, reports 8, runbooks 4, guides 1 (all ruled); articles 19 and marketing 27 (assumed, no ruling); onex_change_control evidence 1; NEEDS-RULING 152 across drafts 111, reviews 22, diagnoses 15, training 2, research 1, external 1, diagnosis 1. | OPERATOR DECISION, not taken by this lane: migrate the refused set straight into knowledge-base-internal without ever committing it here, or grant a one-time snapshot exception requiring a reviewed change to .kb-doc-gate.yaml. Lane recommends the first. | No prod, stability-test, judge, lakshman or cloud contact; no credential action; no Slack; no Linear state change; no ticket minted.
2026-09-13T12:09:04Z | TERMINAL | lane=friction-p5-claim-refusal | actor=claude:opus5:subagent | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7182 | tickets=OMN-18263,OMN-18262 (children of OMN-18232) | BOTH DONE AND MERGED, IN THE ORDER THE RULING AT :7178 SET. THREE PRs, each with its OCC companion merged FIRST: OMN-18263 omniclaude#2143 squash ffbc95fc8a9aa3720a119df3c68d462c4ce82f66 + OCC#9323 d7d0d5f6dfc9b64b833c5eea8a24f8f95d863348; OMN-18262 omniclaude#2144 squash 3a618891dad5eb6cf7a7c589ced6d125a17fa0e1 + OCC#9328 fc7a9934a7725636d95bd463ce7d3fc0c613698a; OMN-18262 follow-up omniclaude#2145 squash 508c451f828d25266166535ccc514927c8340ad9 + OCC#9335 fcb219dfd377f50957a8b26ac5d409f852b0ba20. ONE RESOLUTION, TWO CALLERS: scripts/branch_claim.py is the only comparison; the pull-request check and the pre-push hook both pass through it, and it implements nothing itself -- ticket from claim_index.ticket_from_branch, lane from lane_identity.commit_identity, verdict and refusal text from claim_index.refusal_for_push. FOUR FIXTURE VERDICTS, each its own test: held by same lane -> held-by-pusher clean; held by other WITH a release row -> clean; held by other WITHOUT one -> held-elsewhere, one finding naming holder, ledger file:line and all three release verbs; unclaimed -> clean. Plus handover as a second clearing path, and the zeros that must not read clean: no trailer -> unidentified not clean, stale claim does not hold, absent fence disables the fence half rather than defaulting to zero, and unreadable store / missing module / module without entry points / unresolvable range each exit 2 in BOTH modes, distinct from a finding's exit 0. RELEASE-PATH MEASUREMENT, the evidence the ruling demanded before the hook may refuse: two full cycles 0.438s and 0.388s, every write 0.057-0.061s, probes between every write; the template the refusal PRINTS works verbatim with only the timestamp, the reason and (handover) the receiving slug filled in, HANDOVER clearing to fence 2 and RELEASE to unclaimed; and the reclaim arm with its own falsifier -- 13h-old claim does not hold, the SAME shape at 11h still refuses, a RECLAIM against a still-live claim is refused, the same row against the genuinely stale claim takes it at fence 2. FALSIFICATION CONTROLS RUN ON BOTH HALVES: neutering the refusal turns 5 of 19 resolution tests and 4 of 16 hook tests red; removing the registration gate turns the unregistered-worktree test red, but ONLY after that test was strengthened -- its first fixture used one lane for both the claim and the commit and stayed green with the gate removed, which is the non-probative-test class this phase exists to catch. WHERE THE HOOK IS ENABLED TODAY: NOWHERE, verified live across every registry clone (no pre-push reachable from any of them references branch_claim.py). Enabling is two explicit steps: branch_claim.py install-hook on a clone, then lane_identity.py register on a worktree -- and an unregistered worktree is silent, so a clone armed before its worktrees are registered refuses nobody, which is the 2026-09-13 leaked-GIT_DIR incident not recurring at fleet scale. NO BYPASS VARIABLE EXISTS. THREE DEFECTS FOUND IN MY OWN WORK AND FIXED, NOT ANNOTATED AROUND: (1) the 16 hook tests ran NOWHERE in CI because the consolidated test job does not collect tests/scripts at all -- measured on the run that exercised that directory, with test_lane_identity.py at zero as the positive control; (2) their first real CI run failed 10 of 16 on a RELATIVE claim-index path, because the resolution tests run from the workspace root while the hook tests spawn git push in a scratch clone elsewhere -- reproduced locally at exactly 10 failed 6 passed, fixed in the helper (resolve) and the gate (absolute), 35 pass in CI; (3) the public-repo hygiene ratchet went 175 -> 189 on operator-name from person-prefixed branch names in my own fixtures, back to 175/175 against a pristine-dev control reading exactly 175. ONE PROCESS FACT WORTH CARRYING: #2144 AUTO-MERGED at head c8ab08e78 while its follow-up was being written, because the repo auto-merge workflow arms --squash --auto on PR-open for this author; two later pushes to that branch landed on the ref and fired no event, and the zero-workflow-runs reading looked exactly like a GitHub outage until pulls/2144 was read and said state=closed merged=true. RESIDUAL FOR OMN-18288, concrete: the canonical clones point core.hooksPath at a SHARED directory that already carries a pre-push (the canonical-clone guard), and the installer refuses that directory by design, so the rollout needs a per-clone or composed-hook answer rather than a drop-in. OTHER RESIDUALS: the Onex-Fence trailer is still not stamped by OMN-18260, so the fence half is live only for commits that carry it; the worktree lease is OMN-16294; AC2 of OMN-18262 (four weeks, zero non-holder merges) is not claimable today and the merged check is the instrument that will answer it. ORG VARIABLE CREATED: OMNI_LEDGER_REPO, visibility all, read back, new and owned by nothing else. NOTHING RUNTIME TOUCHED: no container, cluster, broker, database, credential or Slack; no branch-protection change; no ticket minted; no Linear state beyond these two tickets; no bypass flag, skip token, --no-verify or hooksPath override anywhere.
2026-09-13T12:50:51Z | TERMINAL | lane=omn17341-admin-waitlist | ticket=OMN-17341 related=OMN-17340,OMN-18185 | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7149 | DONE ON LIVE EVIDENCE. THE BAR IS GREEN: scheduled staging-green-bar run 34757480044, collected 2026-09-13T12:35:27Z, bar revision r10, verdict GREEN with pass 8 / fail 0 / unproven 0. LEG 8 savings_dashboard_render PASS on BOTH halves - source scan database_drivers_found [] over files_scanned 398 (a read tree, not an unread one), and the render half correlation d2031b00-7119-4c3e-bbb3-1e3ad5b9a4f1 on omniweb:/app in 0.532s without navigation with savings_matches_render true and direct_database_read false. That closes the leg that OMN-17340 left failing on exactly these two surfaces. MERGED, each OCC companion first: omninode_infra#1411 squash 0dfedbdbe43a056a8e67b0ab35372e443661a67c (OCC#9316) adds routers/platform_admin.py - five cross-tenant reads behind the EXISTING onex-admin realm-role gate that GET /v1/platform/savings already used, plus POST /v1/waitlist/signups public at the middleware with a 5/hour per-IP rate limit; omniweb#402 squash 35818ea0e5ee093a1f7b632f7bcf7ca1fe845e64 (OCC#9320) deletes app/_lib/db.ts, rewrites the five query modules and the waitlist write onto the new client, and removes pg and @types/pg from package.json; omninode_infra#1413 squash 896154dd1993a1f4d0aae043e7f6896bcd4e1251 (OCC#9321) drops the dead OMNIDASH_ANALYTICS_DB_URL from the dev omniweb overlay. NO new credential, NO new auth mode, NO cluster mutation: omniweb already forwarded session.accessToken to onex-api and already checked onex-admin in app/_lib/admin-guard.ts. FINDING WORTH KEEPING: the omniweb admin SQL named FOUR schema objects that do not exist - tenants.status (a guardrail RAISEs if the column is ever added), api_keys (really tenant_api_keys), usage_events.created_at (really occurred_at) and waitlist_entries (no migration anywhere creates it). Three of five admin query modules could only ever have raised, so that surface was already dead. It survived for months because every test used a mock repository; a new integration test now runs every query against Postgres 16.14 with the full 44-migration manifest chain applied as CI applies it, with a RED control. The omniweb doctrine check was widened from lib/dashboard/ to all of app/ and lib/ plus a package.json dependency check, both with positive controls and both proven RED. SHARED-CODE FIX: rate_limit_by_ip converted every decorated handler HTTPException into a generic 503; both wrappers now re-raise, proven RED by reverting only that branch. RESIDUALS: OMNIWEB_DB_URL still set by the base manifest (applied to the production-facing cluster too, whose image predates this work) - removal gated on the new image being live on both lanes; the authenticated 200 path is unproven because minting an onex-admin token was not this lane's to do; the lab runs neither omniweb nor Keycloak so neither the role check nor the web-to-api hop is exercisable there; pnpm lint is broken on omniweb dev independently (next lint removed in Next 16) and is not a gate. NO TICKET MINTED - the grant was conditional on a server-side piece being out of reach and none was. For the orchestrator to route: a self-bind OCC receipt is minted pinning the WHOLE contract file with no contract_entry_sha256, so with three companions on one ticket it goes stale on every append and rebinding becomes a race; the newer producer node_occ_companion_compute already mints self-binds as declared dod_evidence entries WITH a per-entry hash. No cloud mutation, no credential work, bar not dispatched.
2026-09-13T12:51:06Z | TERMINAL | lane=cloud-ci-canary-route | actor=claude:opus5:subagent | closes=CLAIM docs/tracking/ROLLING_WORK_LEDGER.md:7185 | ticket=OMN-18291 parent=OMN-18205 | consent=docs/tracking/ROLLING_WORK_LEDGER.md:7179 | OUTCOME: BOTH HALVES LIVE AND PROVEN. MERGED: omninode_infra#1414 squash de6495cc40244caa9f35c5d39d6b05634302965b at 12:25:14Z (scale-up trigger: omninode-ci-runner-scaler Lambda + scaler role + GitHub-OIDC invoker role, the canary workflow's own capacity-request job, 36 tests, and three fleet-image fixes); omnibase_infra#3478 squash a77df3a380d43e8605b8ba39a1a662436f162643 at 10:30:04Z (one job class routed + policy declaration + audit key + 5 tests); knowledge-base-internal#392 squash a76a5ffb18bb7b3106ebf723904023cb99a59b34 at 10:26:39Z (runbook revision 5, sections 13 and 14); OCC companions onex_change_control#9324 squash 3d2db1d1cf3f6035b73521021da776ed9522330a and #9327 squash bb470410b660dc971a8e33a4e4cb133e7bd3f9b6, the second after I rebound one renamed evidence item's receipt to its own entry hash (the autobind's own same-ticket union renamed dod-occ-diff-derived-behavior-proof to dod-occ-proof-node-1414 and left the pre-rename contract_entry_sha256, so occ-preflight failed contract_hash_mismatch; recomputed, all six entry hashes verified). | TRIGGER PROVED, capacity moved by the trigger and by nothing else, run 34751253392 with the group at 0 beforehand and zero hand-run capacity calls: 10:13:07Z desired0/inst0 -> 10:14:09Z desired1/inst1 -> 10:15:11Z job in_progress -> 10:16:13Z job success -> 10:17:31Z desired0/inst0. Zero runners left registered in group 4 with the group listing as the positive control; both guard alarms OK. | ROUTED JOB PROVED: job rebuilt-postgres16-proof ran on runner omni-cloud-<instance-id>, group omni-cloud-ci, instance id <instance-id> read from IMDS not inferred; both containers built and started, postgres logged ready to accept connections, proof-1 exited with code 0, all 8 steps success. | THREE FLEET-IMAGE CAPABILITY GAPS found by running the real job, none visible offline, all fixed in the bootstrap and applied: (1) run 34750171624 inst <instance-id> -- AL2023's docker package ships buildx as its ONLY CLI plugin so docker compose printed usage and exited 125, 50ms after docker info reported a healthy local daemon; (2) run 34750597454 inst <instance-id> -- a buildx IS present so every presence check passes, at 0.12.1, and compose build requires 0.17.0+; (3) run 34751054047 inst <instance-id> -- the boot script's umask 077 for credential hygiene is INHERITED and reached the runner process, so every checked-out file landed mode 0600, COPY preserved it, and the postgres image dropping to its own user got Permission denied on the seed. Gap 3's blast radius is every container-backed job that copies a checked-out file into an image running as non-root; hosted runners use 022 so a hosted-only job cannot have seen it. Fixed: both plugins installed from pinned digest-verified release binaries with the boot asserting each CAPABILITY before registering, and run.sh under umask 022 while config.sh keeps 077. | ROUTING, rule 14 in full: enumerated live org + 11 repo scopes at 09:31:31Z (absent everywhere, positive control OMNI_DOCKER_CI_RUNS_ON_JSON returned a value); ONE write 09:35Z OMNI_CLOUD_CANARY_RUNS_ON_JSON on omnibase_infra only; per-scope readback 09:36:29Z and again 12:49:49Z, present only on omnibase_infra. Out-of-scope variables untouched, proven by their own updated_at: org trusted 2026-08-27, org public-PR 2026-05-02, repo trusted 2026-09-07, repo docker 2026-08-28, repo security-scan 2026-08-25. PLACEMENT from parsed runs-on on the default branch: before (dev ce797b54f) docker-seam 15 hosted-literal 18 trusted-seam 136 total 214; after (dev 0748a4dea) cloud-canary-variable 1 docker-seam 14 hosted-literal 19 trusted-seam 136 total 215. Audit reported the declared-but-absent shadow BEFORE the write (positive control that the later pass is not vacuous) and both passes report 'Runner routing audit passed' from merged dev. | AWS: terraform plan -detailed-exitcode on aws/ci-runners exits 0, no drift; deployed S3 bootstrap object byte-matches merged dev (507 lines, all three fixes present in both). ASG MaxSize UNCHANGED at 4, desired 0, no suspended processes. | NOT DONE, stated: the webhook-shaped trigger is not buildable by an agent -- it needs the fleet App to gain Actions:read AND a workflow-job event subscription, both operator actions on the App; the OIDC path shipped instead needs neither. Only ONE job class is routed; a second needs its own capacity measurement (max 4 ephemeral single-job instances). The missing-credential boot drill remains unrunnable now the credential exists. | Non-routing variable also created and declared in the PROGRESS row: AWS_CI_RUNNER_SCALER_ROLE_NAME on omnibase_infra and omninode_infra, holding an IAM role NAME not a credential, required by omninode_infra's ban-hardcoded-aws-ci-identifiers rule 5 and added to both verified allowlists only after aws iam get-role confirmed the role. | ZERO credential reads, creations, rotations or prints; zero prod, stability, judge, lakshman or cluster contact; no bypass flag, no skip token, no --no-verify, no hooksPath override, no allowlist added to pass a gate.
2026-09-13T13:03:28Z | TERMINAL | lane=lab-tenants-store-folder | actor=claude:opus5:subagent | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7216 | consent=docs/tracking/ROLLING_WORK_LEDGER.md:7215 | ticket=OMN-18293 (evidence comment posted; ticket already Done) | FOLDER CREATED, BOTH TENANT KEYS FILED BY COPY, BOTH MINT JOBS REPOINTED, MERGED AND PROVEN ON THE LAB. | STORE: folder /lab-tenants created in environment dev of instance D (project onex-platform 872e00f4-1279-49a4-8e16-a2bd961f4996), folder id d60946f1-9483-47a2-aed3-cbe93787f64f. Both EXISTING keys filed by copy, values piped Secret->memory->HTTPS body, never argv, never a file, never printed: ONEX_LAB_TENANT_API_KEY len 48 sha12 d4552f08df57 (from onex-lab-tenant-credential) and ONEX_LAB_DOGFOOD_TENANT_API_KEY len 48 sha12 cb67a774170f (from onex-lab-dogfood-tenant-credential); readback digests match the source Secrets exactly. NOTHING minted, rotated, re-issued or revoked; no identity created; no other folder or environment touched -- proven by readback: /lab-provider-keys still exactly OPENROUTER_API_KEY, /tenant-inference-credentials 17 refs, /shared empty, and all three project identity role assignments byte-identical before and after. | THE GRANT, CORRECTED RATHER THAN CLAIMED: there was no read grant to add. The lane's store binding authenticates as identity onex-runtime 5fc7c5e9-13ab-4d94-a14c-7a75201d7c34 (client id e9aad20d-5212-4c8d-8b04-6885f3a62161, sha12 8a7e45ceb8cb, matching the host bootstrap identity recorded at ledger :6817) whose PROJECT ROLE IS ADMIN, so it already reads every path. Narrowing it to per-folder roles needs the store org-admin login and is a scope change to the identity every lane surface uses; not in this consent, not done, recorded in the runbook instead of claiming least privilege that does not exist. | CODE: omninode_infra#1419 squash e44e2066910b5bc1194553e9013384e4cb5052e8 MERGED; OCC companion onex_change_control#9336 squash e831688506997ffd0bb938ddecc8b9ba32676683 merged FIRST at 12:20:06Z. Both mint Jobs resolve their tenant key from /lab-tenants, PROVE it against the tenant-scoped reader (the same call apply_lab_lane.sh's SKIP_MINT guard makes) before adopting, mint only when nothing usable is found, file a minted key back so the store stays source of truth after a rebuild, and skip the step structurally on an unbound lane; a bound store that cannot authenticate/read/write fails the Job by name. The house Job carried no store binding before and now does. TDD RED first 13 failing / 4 passing, GREEN 17/17, 40 pre-existing dogfood+control-plane assertions unchanged, 121 passing across six adjacent lab guard modules, printed-value scanner carries a positive control. | LAB FIRST: the new step was cut VERBATIM from both patched manifests and executed inside the running onex-api pod -- house and dogfood both LAB_TENANT_STORED_KEY_READER_STATUS=200, both adopted, adopted values matching their Secrets at len 48 / sha12 d4552f08df57 and cb67a774170f. NEGATIVE CONTROL, same code same pod, asking for a key name absent from the folder: both adopted nothing and reported the mint path, so the green discriminates. Nothing minted, nothing written by either run. ONE idempotent apply_lab_lane.sh re-apply at the currently deployed tags (runtime 20260912T235940Z-d2cba472, api 5e2f27e6-20260912T235940Z, both migrate bundles matching), no concurrent applier (checked), terminal '== onex-lab is up ==', both mint steps skipped on their own authenticated reader probe; readback IDENTICAL before and after -- both tenants present, created_at byte-unchanged (house 2026-09-12 17:50:33.184705+00, dogfood 2026-09-13 09:20:45.052718+00), dogfood 1 active credential, house keyless by design, both carrier Secrets unchanged by sha12 and creationTimestamp, negative control on the counting query returns 0. Store-binding input file rebuilt from live cluster values and shredded after use (readback absent). | DOCS: knowledge-base-internal#394 squash 5ab3ec94c9f362b4cdd4c869ae34d06e8b34efd2 -- new standing runbook runbooks/onex-lab-secret-store-layout.md (four folders, the binding, the resolution order, the admin-role caveat, the recovery procedure), indexed in runbooks/README.md, and the dogfooding plan's residual marked closed. Scrub exit 0 before the commit; local-path, beta-layout, private-link and invariant gates all pass. | TWO FINDINGS FOR ROUTING, neither mine to fix under this brief and NO TICKET MINTED (none granted): (1) the dogfood mint Job as landed in e8743dd1 reads its active-credential predicate from tenant_inference_credentials through the repository bound to OMNINODE_CLOUD_DB_URL, and that repository connects to omninode_cloud which does NOT hold the table -- on the lab it lives in omnidash_analytics, the database provider_key_chain.sh's own analytics reader uses; probed live from inside the running API image (REPO_DATABASE=omninode_cloud, REPO_SEES_tenants=1, REPO_SEES_tenant_inference_credentials=0). The Job has never run on the lab because the applier skips it while the carrier Secret resolves, so it has never fired; it will fail the Job the first time it runs. (2) omnimarket#2512 (ddeb8c57, OMN-18295) merged at 12:23:39Z and moved handler_quality_gate.py's whole-file hash, staling the OMN-15651 audited exclusion pin for every omninode_infra run starting after it; a peer merge-sweep staged and then committed the refresh (3b51c7b9) into this lane's branch, and I VERIFIED IT AGAINST GIT OBJECTS BEFORE IT LANDED rather than trusting it -- the audited locator _VERIFIABLE_TASK_TYPES hashes to dfb375aacf44718cf09971016819f768b7c061ad3206039042111d326dc00344 at the pre-change commit, the changing commit AND dev head, old pin 0bc7aa81 is the whole-file hash at the pre-change commit and new pin 916f59cc is the whole-file hash at dev head, so the exclusion rationale holds and it is a pin refresh not a re-audit. It rode in on the same squash. | CORRECTION I OWN: I briefly treated omninode_infra#1420's red Repo Scripts Tests as the same drift; reading its log via the API showed a DIFFERENT failure (an unclassified PR-triggered job in its own change), so that inference was wrong and was dropped rather than reported. Separately the OMN-15651 oracle is NOT reproducible on the launching host: it walks the candidate workspace and picks up omninode_infra/docker/onex-api/.venv/.../site-packages, a virtualenv inside the canonical clone CI does not have, failing on 35 unaudited candidates from inside that venv; the git-object hash evidence is what was checked and CI is the surface that evaluated it. | NOT DONE BY DESIGN: no identity created on any instance; no rotation, re-issue or revoke of anything; no environment but dev; no folder but /lab-tenants; no staging, prod, stability, judge, lakshman or cloud-cluster contact; no kubectl set/patch/apply outside the sanctioned applier; no --cold, no raw compose mutation; no psql DDL; no bypass flag, no skip token, no --no-verify, no hooksPath override, no pkill; no directory-wide pytest on the launching host beyond the two named oracle tests; no Slack; no ticket minted; no credential value in any transcript, log, file, artifact, ledger row, PR body or Linear comment -- every value named by key name, byte length and sha256-12 only. | done
2026-09-13T13:09:27Z | TERMINAL | lane=merge-sweep-worktree-addendum | actor=claude:opus5:subagent | ref=OMN-16106 | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7234 | ADDENDUM LANDED; THE REPORT'S CODEX SENTENCE STANDS. knowledge-base-internal#397 MERGED 2026-09-13T13:09:04Z squash 29a0bddbb8e2924696c30d17976559657bf2279d, all 8 checks green, appends 'Addendum, 2026-09-13' to reports/2026-09-13-closeout-process-infrastructure-report.md. FINDING: the worktree at OMN-17341 on branch manual-merge-sweep/omn-17341-occ-9321-conflict was created by lane=omn17341-admin-waitlist (a Claude build lane), NOT codex. Evidence: (1) that lane's PROGRESS row :7186 at 09:20:44Z states the remaining OCC#9321 union and the YAML-dumper-then-text-level sequence that head commit 0adfa77c57 describes in its own message; worktree git admin dir created 09:23:04Z, three minutes later. (2) Every commit unique to the branch is authored+committed under the shared local git identity; zero codex actors in log, reflog or trailers. (3) Only 3 codex-actor ledger rows exist since 2026-09-12T00:00Z (codex-integration-pass-10, -11, plus this report's landing row quoting them); positive control = 1740 codex rows over the full ledger. (4) No tool generates a manual-merge-sweep/ branch name in omniclaude, omnibase_infra/scripts, omninode_infra or docs/runbooks/codex-nightly-controller.md; positive control = the same grep finds the merge_sweep skill files. It is an ad-hoc local convention echoing docs/runbooks/manual-merge-sweep.md, used by lanes of both fleets (12 such local branches in onex_change_control, 3 across omnibase_infra/omnimemory/omnimarket). SHARED STATE: the branch reached NO remote (ls-remote refs/heads/manual-merge-sweep/* = 0 rows in all four repos; positive control refs/heads/dev returns a row). The work reached origin on OCC#9321's own autobind branch auto/omninode-ai-omninode_infra-pr-1413-occ-autobind: head_ref_force_pushed 09:36:41Z and 09:47:13Z, squash-merged 10:30:58Z (merge commit e275f87d, mergedBy a User not a Bot, auto-merge SQUASH). VERDICT: report sentence 'Since 2026-09-12 its only activity has been read-only verification passes' STANDS UNAMENDED; the episode sharpens G9 - with no per-lane identity, misattribution fails in both directions. Read-only investigation plus one document PR; zero code, zero tickets minted, zero Linear state changes, worktree not deleted.

===== R2-04 (25 rows, 61419 chars) =====
2026-09-13T04:41:07Z | PROGRESS | lane=omn17340-pg-imports | ticket=OMN-17340 | claim=docs/tracking/ROLLING_WORK_LEDGER.md:7136 | MERGED. omniweb#401 squash 61a97a77e2c2c60e72915e1f3d7328c63d44f6be, ancestor of origin/dev confirmed; OCC companion onex_change_control#9309 merged FIRST at 04:39Z sha 902466c8f52c19e9a8ac6acf71fa136f81a00a1b, autobind-minted (autobind is working again; no hand-mint needed). DELETED lib/dashboard/source/projection-source.ts (the pg Pool) + projection-sql.ts + their two test files; the selection seam drops the 'projection' mode, leaving fixtures/api/projection-api. TDD: new doctrine check 'no database driver is imported under lib/dashboard/' with the bar's own patterns and a positive control, RED 7pass/1fail before, GREEN 8pass/0fail after; already inside the aggregate test script CI runs, so enforced not advisory. Local: tsc clean, whole test script 50/50 in 32s, topic lint clean, production build succeeds. SCAN READBACK on a FRESH dev checkout post-merge: database_drivers_found went ['app/(marketing)/waitlist/actions.ts:pg','app/_lib/db.ts:pg','lib/dashboard/source/projection-source.ts:pg'] files_scanned=401 -> ['app/(marketing)/waitlist/actions.ts:pg','app/_lib/db.ts:pg'] files_scanned=397. LEG 8 STILL FAILS its scan half: the two remaining imports are OMN-17341's surfaces (admin query layer + marketing waitlist write), neither of which has a projection to read, so neither was convertible here and the pg dependency stays in package.json. No cloud mutation, no credential work, no ticket minted.
2026-09-13T04:54:49Z | CLAIM | lane=friction-p5 | actor=claude:opus5:subagent | tickets=OMN-18258,OMN-18259,OMN-18260,OMN-18261 (children of OMN-18232) | Phase 5 of the process-friction remediation plan (beta/plans/2026-09-12-process-friction-remediation-plan.md in knowledge-base-internal, approved on the merge of #380 2026-09-12T15:53:07Z). Phase 5 children ALREADY EXIST from lane mint-friction-plan at :7068 -- OMN-18258 ruling guard, OMN-18259 design, OMN-18260 commit trailers, OMN-18261 claim index, OMN-18262 pre-push refusal, OMN-18263 CI check -- so this lane mints NOTHING and its four-ticket grant goes unused. I claim the first four in the plan's stated sequencing; OMN-18262/18263 wait on the design AND on open question 1 of the plan (how hard the branch-claim refusal should be), which is an operator call. No concurrent CLAIM on any of the six as of this row. SCOPE: omni_home only for OMN-18258 (committed guard module under docs/workflows/_shared/, its test, a CI workflow and a pre-commit hook; scripts/ledger_lock.py is gitignored local tooling and is wired as a thin caller), knowledge-base-internal for OMN-18259. No runtime mutation, no cluster, no credentials, no Slack, no Linear state beyond these four tickets.
2026-09-13T06:49:23Z | CLAIM | lane=omn17341-admin-waitlist | ticket=OMN-17341 related=OMN-17340,OMN-18185 | Taking the two remaining omniweb raw-pg surfaces off direct Postgres: app/_lib/db.ts (admin query layer behind six /admin pages reading tenants/usage_events/waitlist_entries/admin_events_log) and app/(marketing)/waitlist/actions.ts (the waitlist signup WRITE). Predecessor omniweb#401 (OMN-17340, squash 61a97a77) merged 04:41Z and removed the dashboard arm; staging-green-bar leg 8 savings_dashboard_render still fails its source-scan half on exactly these two. Plan: contract-first read of the onex-api/gateway surfaces in omnibase_infra/omnimarket, then server-side PRs first, then the omniweb PR removing both imports plus the pg dependency and extending the #401 doctrine test to all of app/ and lib/, then one omninode_infra PR dropping the dead OMNIDASH_ANALYTICS_DB_URL plumbing. No competing CLAIM on OMN-17341 at claim time.
2026-09-13T07:14:03Z | CLAIM | lane=p5-residual-tickets | actor=claude:opus5:subagent | Two phase-5 residual tickets granted by team-lead, both children of OMN-18232 (project Ready). No concurrent CLAIM found on either subject at claim time. SCOPE: mint exactly two Linear tickets, no code, no runtime, no credentials, no Slack. TICKET 1 (High): omni_home Branch Protection Guard 'audit' job false-FAILs on onex_change_control main+dev for a codeowner-only review model (required_approving_review_count=0, require_code_owner_reviews=true) already declared compliant by OMN-17491 (onex_change_control#7994, sha 55cb6ccc55f0f575e2e7117ef8f2f6fc8ec766fd, merged 2026-09-01) -- but only for branch==main, and omni_home's pinned ONEX_CHANGE_CONTROL_REF=3d15abea8 predates that fix entirely. TICKET 2 (Medium): Lane Identity Gate (omniclaude#2141/#2142, OMN-18260) is SUCCESS on dev HEAD e6dbbbbb but absent from required_status_checks so it cannot block, and the pre-push hook is unrolled across canonical clones per lane friction-p5's own TERMINAL note (docs/tracking/ROLLING_WORK_LEDGER.md:7153).
| 2026-09-13T08:20:56Z | friction-sweep-scan | TERMINAL | run_date=2026-09-13, handoff=.onex_state/lane_scratch/friction-sweep-candidates-86120-8378cea7b1.json — outcome=SCAN_DONE_4_CANDIDATES_LEDGER_SOURCE_STILL_UNRESOLVED. Source (a) ROLLING_WORK_LEDGER.md: ledger_watermark.py --resolve exit 3 UNRESOLVED again (anchor digest 2d87d7738173 -> 26239c9046de, byte-identical to 2026-09-05, unresolved 8+ days, no re-anchor). Source (b) codex merge-sweep: _codex_merge_sweep/ still absent, resolved to .onex_state/manual-merge-sweep/latest = manual-tick-20260907T173524Z (0 new candidates, stale snapshot only). Source (c) deep-dives: SEPTEMBER_12_2026_DEEP_DIVE.md read in full (0 candidates — customer-readiness/runtime findings, not process friction; Slack external-sharing safety-boundary block read as intended-behavior, not a defect). Source (d) prior report: 2026-09-05-friction-sweep.md (no 09-12 report exists) read in full for match set. Candidates: fr-ledger-watermark-unheaded-rows-invalidate-anchor (matched OMN-17403), fr-ledger-roll-trigger-installer-never-installed (matched OMN-17403, escalated — §5 now 6833 rows vs 4000-row cap), fr-ledger-roll-cap-doc-config-mismatch (matched, recorded/no-ticket, now crosses to occurrence 2), fr-canonical-clone-shallow-git-poisoning (carried, unprovable — source still blocked). Did NOT touch Linear, did NOT write state file, did NOT commit — scan-phase only. |
| 2026-09-13T08:33:00Z | friction-report | CLAIM | lane=friction-report-2026-09-13 | ticket=OMN-16901 related=OMN-17403,OMN-17395,OMN-18289,OMN-18174 | SCOPE: write beta/tracking/2026-09-13-friction-sweep.md + beta/tracking/friction-sweep-state.json in the knowledge-base-internal clone, scrub, commit path-scoped on branch jonah/omn-16901-friction-sweep-2026-09-13, push, open one PR. Baseline re-derived from `git show origin/main:beta/tracking/friction-sweep-state.json` (41 fingerprints, last_run_date 2026-09-12), NOT from the stale KB working tree (4 ahead / 254 behind). One Linear comment: OMN-17395 occurrence 7 (fr-kb-internal-clone-stale-branch-skips-merges), handed forward by the adjudicate phase; active-lane check ran first and found no owner. OUT OF SCOPE: any ticket create, any state flip, any reopen, any ledger anchor hand-edit, any omni_home doc write other than this row pair.
| 2026-09-13T09:05:00Z | ground-state-report | CLAIM | lane=ground-state-report-2026-09-13 | ticket=OMN-17195 related=OMN-16841,OMN-17170,OMN-16961,OMN-17796,OMN-18010 | SCOPE: produce knowledge-base-internal beta/tracking/2026-09-13-morning-ground-state.md per docs/workflows/morning-ground-state/README.md six-section contract, all facts from LIVE reads in this run (Linear MCP + gh check-runs API + git). Also overwrite beta/tracking/ground-state-date-snapshots.json (prior as_of 2026-09-05, 286 tickets) in the SAME path-scoped commit. Branch jonah/omn-17195-morning-2026-09-13 in the kb-internal clone only; no push, no PR from this phase (Goal phase owns the day's single PR). NO ticket-state mutations from this lane; never applies date:committed. Read-only everywhere else, including onex_change_control (6d) and the .201 lanes (section 4). |
2026-09-13T09:10:48Z | TERMINAL | lane=omn18287-bp-audit | actor=claude:sonnet5:subagent | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7218 | ticket=OMN-18287 DONE | onex_change_control#9318 (squash 886264540572fc60cb186e2d1388aff1ddc39d47, merged dev 09:00:20Z) extends REVIEW_GATED_MAIN_REPOS/is_review_gated_main -> REVIEW_GATED_REPOS/is_review_gated, dropping branch==main restriction so the codeowner-review carve-out applies to every audited branch; TDD RED (test_review_gated_occ_dev_requires_approving_and_code_owner_reviews) reproduced the exact dev false-FAIL first, GREEN after fix, 11/11 regression tests, 74 CI checks green; hand-authored contract+self-bound receipts for the in-repo OCC PR structurally unioned with the OCC autobind companion (no duplicate ids, no rebind needed) | omni_home#267 (squash b555a45c386577b8f88d270174c547dfa385009f) bumps ONEX_CHANGE_CONTROL_REF in branch-protection-guard.yml + scheduled-gap-detect.yml to 886264540572fc60cb186e2d1388aff1ddc39d47, adds branch-protection-policy.md section 1a documenting OCC main+dev codeowner model | VERIFIED: omni_home PR 267 audit job run 34748874941 conclusion=success, Summary: 0 failure(s) across 102 checks; local bash scripts/audit_branch_protection.sh from merged OCC worktree also 0 failures/102 checks, [dev] PASS approving and code-owner reviews are enforced (review-gated branch) | Linear OMN-18287 set Done with both PR URLs cited | NOTHING UNVERIFIED
2026-09-13T09:14:35Z | CLAIM | lane=verify-cred-401-ticket | actor=claude:sonnet5 | ticket=TBD related=OMN-16633,OMN-16578,OMN-16504,OMN-16421 | scope: READ-ONLY live verification of onex-dev/onex-verify-client-credentials 401 unauthorized_client finding (recorded only in Linear comment b389afd4-8aed-491a-8b1c-e71f97a6f2f0 on OMN-16633 and ledger:3460) -- enumerate consumers (omninode_infra k8s, omnibase_infra scripts, running workloads on dev-system EC2 <instance-id> ns onex-dev), check Secret metadata and Keycloak onex-verify client status via kcadm, reproduce the token-mint 401 read-only with a positive control, then mint exactly ONE Linear ticket per brief | OUT OF SCOPE: any credential rotation/re-issue/re-sync of any kind, any cluster mutation, any Linear write beyond the one new ticket, no SendMessage to any other lane
2026-09-13T09:15:00Z | CLAIM | lane=friction-p5-claim-refusal | actor=claude:opus5:subagent | tickets=OMN-18263,OMN-18262 (children of OMN-18232) | ruling=docs/tracking/ROLLING_WORK_LEDGER.md:7178 (operator 2026-09-13T09:11:33Z, "fine with your recommendtion on 2") = BOTH, in order: the pull-request check lands FIRST and only RECORDS; the pre-push hook that REFUSES lands only after the release path is shown easy in practice, measured not asserted. | No concurrent CLAIM on either ticket at claim time; lane friction-p5 TERMINAL at :7153 left both explicitly unstarted pending this ruling. | SCOPE: OMN-18263 first -- a reusable pull_request workflow in omniclaude reusing ONE shared resolution (branch ticket + commit lane trailers from OMN-18260 + claim holder from OMN-18261's index), record-only, four TDD fixtures (held by same lane / held by other with release row / held by other without release row / unclaimed); then an end-to-end MEASUREMENT of the release path performed twice on a scratch branch; then OMN-18262, the pre-push hook built to refuse but shipped DISABLED-by-default behind the lane-identity registration mechanism, with that measurement in its PR body. Org Actions variable OMNI_LEDGER_REPO=omni_home created (visibility all, read back) so a PUBLIC workflow never spells a private repository name (rule 23); it is a NEW variable owned by nothing else, not a read-modify-write of a routing variable. | OUT OF SCOPE: installing any hook across the canonical clones (that is OMN-18288's sequenced sweep, and the 2026-09-13 leaked-GIT_DIR incident is why), branch-protection changes, the worktree lease (OMN-16294), any runtime/cluster/broker/credential/Slack surface, and any Linear state beyond these two tickets. No tickets minted.
2026-09-13T09:19:48Z | CLAIM | lane=lab-second-tenant | actor=claude:opus5:subagent | ticket=OMN-18282 parent=OMN-18185 | consent=docs/tracking/ROLLING_WORK_LEDGER.md:7177 | SCOPE, exactly the consented one: create ONE additional tenant on the persistent onex-lab lane (k3s namespace onex-dev on the lab host) through the product surface POST /v1/tenants/bootstrap, mint its first API key through the same in-process path the lane's own mint Job uses, register ONE standing customer provider-key credential named lab-dogfood-tenant-provider-key for that tenant from the lab store value at /lab-provider-keys, prove it with ONE real onex cloud delegate run reaching COMPLETED with credential_source=customer_key, then dispatch omninode_infra provider-key-chain.yml ONCE and read back that the new tenant's row is still present and unrevoked while the chain's own tenant is keyless by design. Also: update knowledge-base-internal PR 386 with the ruling and merge it; update OMN-18282. | OUT OF SCOPE and untouched: the existing lab tenant 6c48114b-cfa9-4125-a390-67a0047a8fcc and every one of its credential rows; any withdrawal or revoke of anything; any staging or prod tenant; any cloud cluster; printing any credential value. | PRE-READ FINDING, chain isolation: provider_key_chain.sh resolves its tenant ONLY from secret onex-lab-tenant-credential .data.TENANT_ID and scopes every SQL read and every HTTP call by that id or by /v1/tenants/me with that tenant's own key, so a second tenant with its own id cannot be selected by it. No chain change is required and none will be made.
2026-09-13T10:10:04Z | TERMINAL | lane=dogfood-round-2 | actor=claude:sonnet5 | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7197 | tickets=OMN-18200 related=OMN-18278,OMN-18280,OMN-18282,OMN-18185 | OUTCOME: FIVE REAL TASKS, TEN DELEGATIONS, ZERO RETRIES OF THE DELEGATED WORK. Local (onex delegate, no credential): 5/5 completed -- run d715f096 (standup, 22 ledger rows, 18245/11401 tok), 6168dd6c (boot-log ticket body, 577/2576), b9b3d07b (OMN-18292 runbook note, 898/2257), 5356e6ab (PR#1412 summary, 2381/3603), 549e46b8 (draft-PR-sweep summary, 1030/4871); all tier=local backend=local-heavy-reasoning model=Qwen3.6-35B-A3B, 1 attempt/0 escalations, cost $0.0, quality_gate passed=true score=1.0 on every run. Cloud (onex cloud delegate, customer_key, tenant cacacbb1-0e64-4521-9712-ed02ee799907 onex-lab-dogfood): workflow ca144d1a (task2) terminal FAILED on the gateway's own gate despite actual_score=0.900 >= required_bar=0.800 (failures=WEAK_OUTPUT not concise); 108e20a3 (task3) and 7f657a5c (task5) COMPLETED clean; 16eafedc (task4, PR#1412 summary) never left status=published -- a concurrent lab-lane redeploy cycled onex-api/runtime/projection-writer pods repeatedly during the poll window, not retried; task1 (standup, 57KB prompt) REFUSED AT SUBMISSION, HTTP 400 ONEX_CORE_007_INVALID_INPUT 'payload does not conform to the workflow contract', no id minted, isolated with an immediate two-word positive control on the same tunnel/tenant that succeeded. | ACCURACY: cloud 4/4 content-bearing runs fully grounded, 0 invented identifiers. Local 4/5 fully grounded; the 22-row standup (run d715f096, the one input an order of magnitude larger than the rest) fabricated PR numbers absent from its input -- e.g. omnibase_infra#3466 and onex_change_control#9273 occur zero times in the fed rows, full invented list in docs/drafts/2026-09-13-dogfood-r2-standup.md -- while getting every OMN ticket number right; a NEW finding this round, grounding degrades with input size, not present in round 1's smaller single-fact tasks. | LEAK: local 5/5 leaked a reasoning trace behind a stray closing think tag (84-95% of the response is preamble, per-run figures in the five docs/drafts/2026-09-13-dogfood-r2-*.md files) despite every prompt explicitly saying not to show reasoning -- reproduces OMN-18278 exactly. Cloud 0/4 content-bearing runs leaked; every cloud response was clean prose from character one. | BLOCKER HIT AND WORKED AROUND PER THE GUIDE, NOT OVERRIDDEN: onex delegate refused every call via the drift guard even through the repo wrapper/alias (OMN-18280) because the orchestrator's own subprocess dispatch resolves a bare onex from inherited PATH, which does not carry shell aliases, landing on a stale uv-tool build at ~/.local/bin/onex. Exact refusal: 'omnimarket is NOT INSTALLED from git in this interpreter ($HOME/.local/share/uv/tools/omnibase-core/bin/python)... A reconcile ran, reported SUCCESS, and the venv is STILL drifted'. Fixed per the guide's own troubleshooting table (fix PATH) by prepending $OMNI_HOME/omnibase_infra/.venv/bin to PATH for the invocation; --allow-omnimarket-drift/ONEX_ALLOW_OMNIMARKET_DRIFT was never used, every local result is from a verified in-sync build. | ARTIFACTS (all uncommitted, local): docs/drafts/2026-09-13-dogfood-r2-standup.md, -cloud-ci-log-ticket.md, -auth-host-runbook-note.md, -pr1412-summary.md, -draft-pr-sweep-summary.md, -summary.md (routing recommendation: small single-fact prose to cloud first, large multi-row rollups to local only and always spot-check identifiers, prefer local during a concurrent lab redeploy). | CLEANUP WITH READBACKS: onex cloud logout ran ('Removed the OmniNode API key from ~/.onex'), onex cloud status readback confirmed no cloud: block remains; the in-pod key file (never printed, piped kubectl get secret | base64 -d straight into a 0600 local file) shred -u'd, readback absent; local ssh tunnel killed, post-close health check to it timed out/refused; remote kubectl port-forward on <lab-host> killed, pgrep readback empty. NO ticket minted, no Slack, no Linear write, no credential rotation/re-issue/revoke of any kind, no mutation to either lab tenant, no cluster mutation beyond read-only kubectl get and the three sanctioned port-forward starts/stops. | done
2026-09-13T10:12:54Z | PROGRESS | lane=friction-p5-claim-refusal | tickets=OMN-18263,OMN-18262 | claim=docs/tracking/ROLLING_WORK_LEDGER.md:7182 | OMN-18263 DONE AND MERGED: omniclaude#2143 squash ffbc95fc8a9aa3720a119df3c68d462c4ce82f66 (merged dev 10:09:34Z), OCC companion #9323 squash d7d0d5f6dfc9b64b833c5eea8a24f8f95d863348 merged FIRST at 09:56:00Z. Two new required-capable contexts both SUCCESS on the merged head: 'branch-claim-check / branch-claim-check' and 'Branch Claim Gate' (19 passed in CI against the real private claim index fetched by installation token). OMN-18262 IN CI: omniclaude#2144 open, rebased onto dev, 16 hook tests driving a real git push through the installed hook. RELEASE-PATH MEASUREMENT, the evidence the ruling required before the hook may refuse: two full cycles on a scratch store, whole cycle 0.438s and 0.388s, every write 0.057-0.061s, with a probe between each write proving each row CLEARS the refusal rather than merely appending. Copy-paste arm: the template the refusal PRINTS works verbatim with only the timestamp, the reason and (handover) the receiving slug filled in -- HANDOVER cleared to fence 2, RELEASE cleared to unclaimed, nothing else edited. RECLAIM arm with a falsifying control: a 13h-old claim does not hold, the SAME shape at 11h still refuses (so the first is staleness not a broken probe), a RECLAIM row against a still-live claim is REFUSED, and the same row against the genuinely stale claim takes it at fence 2. ORG VARIABLE CREATED: OMNI_LEDGER_REPO (visibility all, read back) so a PUBLIC repo workflow never spells a private repository name; new variable, owned by nothing else, not a read-modify-write of a routing variable. THREE GATES FIRED AND WERE FIXED NOT ANNOTATED AROUND: the reusable-inner-checkout sparse assertion (fixed by asserting the file, not annotating), the public-repo hygiene ratchet operator-name 175 -> 189 caused by person-prefixed branch names in my own test fixtures (replaced; back to 175/175 against a pristine-dev control reading exactly 175), and the credential-rotation guard firing on an apostrophe in a heredoc commit message (worked around by writing the message to a file, rule-15 class). NOT DONE: no hook installed in any clone (OMN-18288 owns that sweep); no branch-protection change; no runtime, cluster, broker, credential or Slack surface touched.
2026-09-13T10:18:03Z | PROGRESS | lane=cloud-ci-canary-route | ticket=OMN-18291 | claim=docs/tracking/ROLLING_WORK_LEDGER.md:7185 | AWS MUTATIONS, all in account <cloud-account> us-east-1, all inside the consent scope: terraform apply of aws/ci-runners added 6 resources (omninode-ci-runner-scaler Lambda, its role+inline policy, the GitHub-OIDC omninode-ci-runner-scaler-invoker role+inline policy, the scaler log group) with 0 changed and 0 destroyed; three later applies updated ONLY aws_s3_object.runner_bootstrap. ASG omninode-ci-runner-asg MaxSize UNCHANGED at 4, MinSize 0, desired under ignore_changes as it already was. No credential read, created, rotated or printed. | ADDITIONAL NON-ROUTING VARIABLE WRITE, declared here because the CLAIM enumerated routing variables only: Actions repo variable AWS_CI_RUNNER_SCALER_ROLE_NAME=omninode-ci-runner-scaler-invoker created on omnibase_infra and omninode_infra. It holds an IAM role NAME, not a credential, and exists because omninode_infra's ban-hardcoded-aws-ci-identifiers gate rule 5 forbids a literal role ARN and requires the variable be IAM-verified first -- the role was created by the apply above and read back with aws iam get-role before either variable was written. | ROUTING WRITE: exactly one, OMNI_CLOUD_CANARY_RUNS_ON_JSON='["self-hosted","omni-cloud-ci"]' on OmniNode-ai/omnibase_infra at 2026-09-13T09:35Z. Enumerated live across org + 11 repo scopes at 09:31:31Z (absent everywhere, with a positive control against OMNI_DOCKER_CI_RUNS_ON_JSON returning a value); read back per scope at 09:36:29Z (present only on omnibase_infra). Out-of-scope variables proven untouched by their own updated_at: org trusted seam 2026-08-27, org public-PR 2026-05-02, repo trusted seam 2026-09-07, repo docker seam 2026-08-28, repo security-scan 2026-08-25. | PRs: omninode_infra#1414 (trigger), omnibase_infra#3478 (routing).
2026-09-13T10:48:55Z | PROGRESS | lane=omn17341-admin-waitlist | ticket=OMN-17341 | claim=docs/tracking/ROLLING_WORK_LEDGER.md:7149 | ALL FOUR PRs MERGED AND ALL THREE OCC COMPANIONS MERGED. omninode_infra#1411 squash 0dfedbdbe43a056a8e67b0ab35372e443661a67c (companion OCC#9316); omniweb#402 squash 35818ea0e5ee093a1f7b632f7bcf7ca1fe845e64 (companion OCC#9320); omninode_infra#1413 squash 896154dd1993a1f4d0aae043e7f6896bcd4e1251 (companion OCC#9321). LIVE READBACKS on onex-dev DEV-SYSTEM <instance-id>, reads only, SSM --comment omn17341-admin-waitlist. (a) onex-api: deploy run 34750083111 success for 0dfedbdb; the pod openapi lists all six new paths; every admin read answers 401 unauthenticated AND 401 with a garbage bearer, so the onex-admin gate fails closed. (b) omniweb: CI run 34750570285 on dev, Build-and-push-to-ECR and Deploy-to-onex-dev both success; in the running pod node_modules has NO pg and the pnpm store has zero pg@ entries, so the dependency left the image rather than merely going unimported. (c) after omninode_infra#1413 deployed (run 34752383665 success), both omniweb pods carry DELEGATION_API_BASE_URL and OMNIWEB_DB_URL and NO OMNIDASH_ANALYTICS_DB_URL, and both pods were freshly rolled so the new spec is what is live. OMNIWEB_DB_URL deliberately remains: the base manifest is applied to the production-facing cluster too and the image running there predates this work, so removing it is a follow-up gated on the new image being live on both lanes, stated in the omninode_infra#1413 body rather than left implicit. NO TICKET MINTED: the brief granted one only if a server-side piece was out of reach, and none was. Residual for the orchestrator to route: a self-bind OCC receipt is minted pinning the WHOLE contract file with no contract_entry_sha256, so with three companions on one ticket it goes stale on every append and rebinding becomes a race against the next merge; the newer producer node_occ_companion_compute already mints self-binds as declared dod_evidence entries WITH a per-entry hash, so the fix is to make the older path match. Remaining for this lane: the next scheduled staging-green-bar run (cron 17 */6, so about 12:17Z) for leg 8 both halves and all eight legs.
2026-09-13T11:01:38Z | TERMINAL | lane=lab-dogfood-tenant-manifest | actor=claude:sonnet5:subagent | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7193 | ticket=OMN-18293 DONE parent=OMN-18282,OMN-18185 | DOGFOOD TENANT DECLARED IN LANE MANIFESTS, VERIFIED IDEMPOTENT ON THE REAL LAB. New k8s/onex-lab/jobs-dogfood/mint-lab-dogfood-tenant.yaml mirrors the house jobs/mint-lab-tenant.yaml mechanics exactly (real POST /v1/tenants/bootstrap, in-process auth_api_keys.create_api_key, Secret written through the API server, nothing printed but identities) plus new logic: standing provider-key registration through POST /v1/tenants/me/inference-credentials, gated on SELECT count(*) FROM tenant_inference_credentials WHERE tenant_id=... AND revoked_at IS NULL == 0, value resolved in-process from ConfigMap onex-runtime-config + Secret onex-store-resolver-credentials (never printed, never argv, structural skip when INFISICAL_ADDR is empty i.e. lane not store-bound). apply_lab_lane.sh gained an authenticated-reader skip guard for the dogfood Secret, independent of the house tenant's own guard, so each tenant's mint step is separately idempotent. Kept as its OWN kustomization (jobs-dogfood/, not folded into jobs/) so the two Jobs delete/apply/wait lifecycles never couple. | TDD: RED first (10 failing/4 passing before the files existed), GREEN after (40/40 across new tests/k8s/test_lab_dogfood_tenant_manifest_omn18293.py + existing test_onex_lab_control_plane_omn17537.py, zero regression). AC2 isolation scanner (no lane file selects a tenant by an ambiguous slug pattern) carries a positive control proving it fires on LIKE/regex/startswith shapes and does not false-flag exact equality. | LAB VERIFICATION (real, not simulated): built a scratch checkout of dev at $HOME/lab/omn18293-dogfood-manifest/omninode_infra on <lab-host>, copied this branch's two changed files onto it, rebuilt the store-binding env from live cluster values via the existing read-only lab-persistence-rebuild-store-binding.sh helper (never printed, shredded after use), ran apply_lab_lane.sh for real with the CURRENTLY-DEPLOYED image tags (onex-lab/omninode-runtime:20260912T235940Z-d2cba472 etc, a true idempotent re-apply not a downgrade). Log: both house and dogfood tenants answered HTTP 200 on their own authenticated reader probe and were skipped; terminal line '== onex-lab is up =='. READBACK (AC4): dogfood tenant cacacbb1-0e64-4521-9712-ed02ee799907 present, exactly 1 active credential row, created_at byte-unchanged at 2026-09-13 09:22:45.304257+00, revoked_at still NULL; house tenant 6c48114b untouched. | PR omninode_infra#1417 squash e8743dd14b9009e1586026fd73453749e194002b merged 2026-09-13T11:00:16Z; OCC companion onex_change_control#9326 merged first (auto-merge armed, both required-check sets green, PR#1417 needed one update-branch to clear a BEHIND state after the companion merge, re-ran to 65/65 green). Linear OMN-18293 Done with per-AC dod_evidence table. | RESIDUAL, not blocking any AC: the provider-key value still lives in namespace Secret onex-lab-dogfood-tenant-credential rather than the lab's Infisical store -- that store has no /lab-tenants folder (established by the prior lane, re-confirmed not re-tested here), and creating one plus granting a lab identity a read role is an operator-scope store change out of this ticket's scope. | NOT DONE BY DESIGN: no Infisical store folder or identity created; no credential value printed anywhere (transcript, log, PR body, ledger); the scratch checkout and rebuilt store-binding env were deleted/shredded after verification; house tenant and its rows untouched; no staging/prod/stability/judge/lakshman/cloud-cluster contact; no --cold, no raw compose mutation, no kubectl set/patch/apply outside the sanctioned applier. | done
2026-09-13T11:06:39Z | PROGRESS | lane=friction-p5-claim-refusal | tickets=OMN-18262 | claim=docs/tracking/ROLLING_WORK_LEDGER.md:7182 | OMN-18262 MERGED: omniclaude#2144 squash 3a618891dad5eb6cf7a7c589ced6d125a17fa0e1 (merged dev 10:45:04Z), OCC companion #9328 squash fc7a9934a7725636d95bd463ce7d3fc0c613698a merged FIRST at ~10:40Z. FOLLOW-UP PR OPEN, omniclaude#2145, and the reason is a real finding not a tidy-up: the sixteen tests that drive a REAL git push through the installed hook were passing locally and running NOWHERE in CI, because the consolidated test job does not collect tests/scripts at all -- measured on the run that exercised that very directory, both split jobs' logs carry ZERO mentions of the branch-claim tests, with test_lane_identity.py as the POSITIVE CONTROL at zero as well (that suite is known to run only in its own gate). #2145 names both test files individually in branch-claim-gate.yml, adds the hook script and the new test file to its path triggers, and adds the git identity the push-driving tests need. IT LANDS SEPARATELY BECAUSE #2144 AUTO-MERGED UNDER ME: the repo auto-merge workflow arms --squash --auto on PR-open for this author, so #2144 merged at head c8ab08e78 at 10:45:04Z while the gate fix was being written; two subsequent pushes to that branch (821a4a608, then 2f77cbaa8 after an amend) landed on the ref but fired no PR event and no workflow run, because the PR was already closed -- diagnosed by reading pulls/2144 state=closed merged=true rather than by assuming a GitHub sync lag, after a zero-workflow-runs reading that would otherwise have looked like an outage. MERGED-DEV CODE RE-PROVEN LIVE from a fresh worktree off origin/dev at 3a618891d: a branch naming a ticket another lane holds exits 1 naming holder omn18287-bp-audit, its claim row docs/tracking/ROLLING_WORK_LEDGER.md:7157 and the full release path; the lane's own branch exits 0. Exit codes captured WITHOUT a pipe (a $? after head is head's). Commit bf0c0b61e on the follow-up branch carries Onex-Lane: friction-p5-claim-refusal, so the trailer discipline held across every commit this lane made. NO HOOK INSTALLED IN ANY CLONE -- that sweep is OMN-18288.
2026-09-13T11:13:16Z | TERMINAL | lane=omn18292-verify-runbook | closes=own CLAIM (this file, prior row) | ticket=OMN-18292 | DONE. Fixed by relocating docs/runbooks/2026-08-24-onex-verify-client-credentials.md (omni_home#268 84b96034, deletion -- kb-doc-gate mode diff refuses a modify under docs/runbooks/**) to knowledge-base-internal runbooks/onex-verify-client-credentials-token-mint.md (knowledge-base-internal#391 880f2ff7), rewritten to live-resolve KEYCLOAK_ISSUER from onex-dev/onex-runtime-config instead of hardcoding either host; also fixed the same pairing found independently in runbooks/promotion-rollback-cd.md's Keycloak-troubleshooting section. Checked the two citing docs (docs/testing/2026-08-26-staging-test-walkthrough.md, docs/tracking/2026-08-28-e2e-walkthrough-runbook.md) -- both already cite dev.auth.omninode.ai correctly, no host fix needed (residual: their citation to the runbook's old omni_home path is now stale, out of this ticket's narrow AC, flagged in the Linear dod_evidence comment for whoever next touches that doc). Guard: knowledge-base-internal#391 adds scripts/check_no_bare_prod_auth_host.py (CI+pre-commit) scanning runbooks/guides/reference; omninode_infra#1416 (c6d5263f) generalizes OMN-16504's single-workflow guard to scripts/check-no-bare-prod-auth-host-workflows.py scanning every .github/workflows/*.yml, cross-linked from tests/k8s/test_probe_onex_dev_keycloak_check_targets_dev_issuer.py. Live re-proof 2026-09-13 via SSM --comment omn18292-verify-runbook to <instance-id> (read-only, no secret printed): issuer live-resolved to https://dev.auth.omninode.ai/realms/omninode; corrected mint HTTP 200 with the existing unrotated secret; same secret against bare auth.omninode.ai HTTP 401 unauthorized_client; unauthenticated whoami HTTP 401. NO credential rotation/re-issue/re-sync performed. All 3 PRs merged + CI green (OCC companion OCC#9325 self-bind merged first). Also flagged (not fixed, not re-verified live against current cluster topology) 3 older knowledge-base-internal docs (omnidash-beta-runbook.md, redpanda-events-secret-rotation.md, redpanda-jwt-oauthbearer.md) pairing the bare host with onex-dev but predating the dev-system/public split or cloud Redpanda's decommission -- exempted via <!-- prod-auth-host-ok --> markers + a not-re-verified caveat note, for follow-up triage. Linear OMN-18292 flipped Done with dod_evidence comment + AC checkboxes checked. No SendMessage to any lane.
2026-09-13T11:55:41Z | CLAIM | lane=delegation-complexity-ladder | actor=claude:opus5:subagent | ticket=OMN-18300 (epic, minted this run, project Ready, Gate: C14) related=OMN-18278,OMN-18294,OMN-18295,OMN-18296,OMN-18297,OMN-18232,OMN-18185 | SCOPE: build a six-rung task-complexity ladder measuring what the local delegation model can be trusted with, per the operator ask 2026-09-13 ('when can we start using delegation to do actual work'). Harness + committed task-bundle fixtures + mechanical scorers + JSON-emitting runner into a NEW omnimarket benchmarks/delegation_ladder/ (checked first: no benchmarks or evals directory exists in any of the four repos; omnimarket has node_llm_eval_harness which is a node, not a fixture home). Every task run ONCE through onex delegate (local, Qwen3.6-35B-A3B on <lab-host>:8000) and ONCE through onex cloud delegate (dogfood tenant onex-lab-dogfood on the persistent onex-lab lane); zero retries of the delegated work; a cloud refusal on a large bundle is recorded as a result, never dodged by shrinking the bundle. Then a report to knowledge-base-internal reports/ and an UNMERGED proposal to knowledge-base-internal beta/plans/ for the delegated execution surface. | OUT OF SCOPE: any credential lifecycle change (the dogfood tenant key is read in-cluster, piped, shredded, onex cloud logout at close); any cluster mutation beyond read-only kubectl get plus a sanctioned port-forward; prod, stability-test, judge, lakshman and the public cluster (untouched); any lab applier run (none needed, and a concurrent one is already claimed by lane lab-dogfood-tenant-manifest); minting more than the one granted epic plus at most two defect children; Slack; any Linear state change outside OMN-18300. | Worktrees: $OMNI_HOME/omni_worktrees/OMN-18300/{omnimarket,knowledge-base-internal}
2026-09-13T11:59:34Z | TERMINAL | lane=omni-home-cleanup | actor=claude:opus5:subagent | ticket=OMN-17994 | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7222 | outcome=PHASES_1_2_COMPLETE_PHASE_3_NOT_STARTED_ONE_OPERATOR_DECISION_OPEN | PLAN FOUND, not new: the operator sequence (remove ephemeral, then commit all, then migrate) is OMN-17994 and its inventory knowledge-base-internal beta/tracking/2026-09-06-omni-home-refresh-branch-landing.md, which records the 2026-09-06T13:50Z operator ruling in those exact terms. Steps 1-2 and 4 of that ticket already landed (omni_home#258 merged 2026-09-06T15:08Z; kb-internal#178/183/184/185/186/187 all merged 15:05-15:37Z). | PHASE 1: 513 dirty files classified against the pinned validator kb_doc_gate.py@ca98494a; classification at the session scratchpad omni-home-cleanup-classification.md. Only 2 files were EPHEMERAL and were deleted: reclaim-measurement/SCRATCH_LEDGER.md and SCRATCH2.md, untracked synthetic scratch ledger rows written 05:36Z, zero references anywhere in omni_home, omniclaude, omnibase_infra or kb-internal under a grep whose positive control returned rows for two of four probe patterns. Nothing else qualified: the ephemeral classes named in the ruling were already removed and ignore-ruled by #258, and the remaining untracked corpus is content. No tracked file was deleted. mtime was NOT used as a liveness signal (the pre-commit stash-restore stamps every uncommitted tracked file with the last commit instant, as the inventory records); only the ledger is genuinely newer than the last commit. | PHASE 2: 8 commits via scripts/commit_lock.py with explicit paths, no -A, no bypass flag, kb-doc-gate hook Passed on every one: 6737cc94ca gitignore 1, 813294d064 plans 2, fba79474da workflow config 5, aea811c4f3 deep dives 20, 3dac3c92af non-markdown dumps 7, b37d6f88eb evidence bundles 34, 350b7eccc8 article infographics 64, 71de716f2e draft binaries 107. 240 files landed. Zero commit_lock refusals. Nothing pushed, no PR opened; branch jonah/omni-home-refresh-20260820 stays local at 873 ahead of origin/main, 9 behind. | REFUSED AND LEFT UNCOMMITTED: 270 markdown files the gate refuses, by destination: kb-internal beta/tracking 55, beta/handoffs 2, reports 8, runbooks 4, guides 1 (all ruled); articles 19 and marketing 27 (assumed, no ruling); onex_change_control evidence 1; NEEDS-RULING 152 across drafts 111, reviews 22, diagnoses 15, training 2, research 1, external 1, diagnosis 1. | OPERATOR DECISION, not taken by this lane: migrate the refused set straight into knowledge-base-internal without ever committing it here, or grant a one-time snapshot exception requiring a reviewed change to .kb-doc-gate.yaml. Lane recommends the first. | No prod, stability-test, judge, lakshman or cloud contact; no credential action; no Slack; no Linear state change; no ticket minted.
2026-09-13T12:09:04Z | TERMINAL | lane=friction-p5-claim-refusal | actor=claude:opus5:subagent | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7182 | tickets=OMN-18263,OMN-18262 (children of OMN-18232) | BOTH DONE AND MERGED, IN THE ORDER THE RULING AT :7178 SET. THREE PRs, each with its OCC companion merged FIRST: OMN-18263 omniclaude#2143 squash ffbc95fc8a9aa3720a119df3c68d462c4ce82f66 + OCC#9323 d7d0d5f6dfc9b64b833c5eea8a24f8f95d863348; OMN-18262 omniclaude#2144 squash 3a618891dad5eb6cf7a7c589ced6d125a17fa0e1 + OCC#9328 fc7a9934a7725636d95bd463ce7d3fc0c613698a; OMN-18262 follow-up omniclaude#2145 squash 508c451f828d25266166535ccc514927c8340ad9 + OCC#9335 fcb219dfd377f50957a8b26ac5d409f852b0ba20. ONE RESOLUTION, TWO CALLERS: scripts/branch_claim.py is the only comparison; the pull-request check and the pre-push hook both pass through it, and it implements nothing itself -- ticket from claim_index.ticket_from_branch, lane from lane_identity.commit_identity, verdict and refusal text from claim_index.refusal_for_push. FOUR FIXTURE VERDICTS, each its own test: held by same lane -> held-by-pusher clean; held by other WITH a release row -> clean; held by other WITHOUT one -> held-elsewhere, one finding naming holder, ledger file:line and all three release verbs; unclaimed -> clean. Plus handover as a second clearing path, and the zeros that must not read clean: no trailer -> unidentified not clean, stale claim does not hold, absent fence disables the fence half rather than defaulting to zero, and unreadable store / missing module / module without entry points / unresolvable range each exit 2 in BOTH modes, distinct from a finding's exit 0. RELEASE-PATH MEASUREMENT, the evidence the ruling demanded before the hook may refuse: two full cycles 0.438s and 0.388s, every write 0.057-0.061s, probes between every write; the template the refusal PRINTS works verbatim with only the timestamp, the reason and (handover) the receiving slug filled in, HANDOVER clearing to fence 2 and RELEASE to unclaimed; and the reclaim arm with its own falsifier -- 13h-old claim does not hold, the SAME shape at 11h still refuses, a RECLAIM against a still-live claim is refused, the same row against the genuinely stale claim takes it at fence 2. FALSIFICATION CONTROLS RUN ON BOTH HALVES: neutering the refusal turns 5 of 19 resolution tests and 4 of 16 hook tests red; removing the registration gate turns the unregistered-worktree test red, but ONLY after that test was strengthened -- its first fixture used one lane for both the claim and the commit and stayed green with the gate removed, which is the non-probative-test class this phase exists to catch. WHERE THE HOOK IS ENABLED TODAY: NOWHERE, verified live across every registry clone (no pre-push reachable from any of them references branch_claim.py). Enabling is two explicit steps: branch_claim.py install-hook on a clone, then lane_identity.py register on a worktree -- and an unregistered worktree is silent, so a clone armed before its worktrees are registered refuses nobody, which is the 2026-09-13 leaked-GIT_DIR incident not recurring at fleet scale. NO BYPASS VARIABLE EXISTS. THREE DEFECTS FOUND IN MY OWN WORK AND FIXED, NOT ANNOTATED AROUND: (1) the 16 hook tests ran NOWHERE in CI because the consolidated test job does not collect tests/scripts at all -- measured on the run that exercised that directory, with test_lane_identity.py at zero as the positive control; (2) their first real CI run failed 10 of 16 on a RELATIVE claim-index path, because the resolution tests run from the workspace root while the hook tests spawn git push in a scratch clone elsewhere -- reproduced locally at exactly 10 failed 6 passed, fixed in the helper (resolve) and the gate (absolute), 35 pass in CI; (3) the public-repo hygiene ratchet went 175 -> 189 on operator-name from person-prefixed branch names in my own fixtures, back to 175/175 against a pristine-dev control reading exactly 175. ONE PROCESS FACT WORTH CARRYING: #2144 AUTO-MERGED at head c8ab08e78 while its follow-up was being written, because the repo auto-merge workflow arms --squash --auto on PR-open for this author; two later pushes to that branch landed on the ref and fired no event, and the zero-workflow-runs reading looked exactly like a GitHub outage until pulls/2144 was read and said state=closed merged=true. RESIDUAL FOR OMN-18288, concrete: the canonical clones point core.hooksPath at a SHARED directory that already carries a pre-push (the canonical-clone guard), and the installer refuses that directory by design, so the rollout needs a per-clone or composed-hook answer rather than a drop-in. OTHER RESIDUALS: the Onex-Fence trailer is still not stamped by OMN-18260, so the fence half is live only for commits that carry it; the worktree lease is OMN-16294; AC2 of OMN-18262 (four weeks, zero non-holder merges) is not claimable today and the merged check is the instrument that will answer it. ORG VARIABLE CREATED: OMNI_LEDGER_REPO, visibility all, read back, new and owned by nothing else. NOTHING RUNTIME TOUCHED: no container, cluster, broker, database, credential or Slack; no branch-protection change; no ticket minted; no Linear state beyond these two tickets; no bypass flag, skip token, --no-verify or hooksPath override anywhere.
2026-09-13T12:50:51Z | TERMINAL | lane=omn17341-admin-waitlist | ticket=OMN-17341 related=OMN-17340,OMN-18185 | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7149 | DONE ON LIVE EVIDENCE. THE BAR IS GREEN: scheduled staging-green-bar run 34757480044, collected 2026-09-13T12:35:27Z, bar revision r10, verdict GREEN with pass 8 / fail 0 / unproven 0. LEG 8 savings_dashboard_render PASS on BOTH halves - source scan database_drivers_found [] over files_scanned 398 (a read tree, not an unread one), and the render half correlation d2031b00-7119-4c3e-bbb3-1e3ad5b9a4f1 on omniweb:/app in 0.532s without navigation with savings_matches_render true and direct_database_read false. That closes the leg that OMN-17340 left failing on exactly these two surfaces. MERGED, each OCC companion first: omninode_infra#1411 squash 0dfedbdbe43a056a8e67b0ab35372e443661a67c (OCC#9316) adds routers/platform_admin.py - five cross-tenant reads behind the EXISTING onex-admin realm-role gate that GET /v1/platform/savings already used, plus POST /v1/waitlist/signups public at the middleware with a 5/hour per-IP rate limit; omniweb#402 squash 35818ea0e5ee093a1f7b632f7bcf7ca1fe845e64 (OCC#9320) deletes app/_lib/db.ts, rewrites the five query modules and the waitlist write onto the new client, and removes pg and @types/pg from package.json; omninode_infra#1413 squash 896154dd1993a1f4d0aae043e7f6896bcd4e1251 (OCC#9321) drops the dead OMNIDASH_ANALYTICS_DB_URL from the dev omniweb overlay. NO new credential, NO new auth mode, NO cluster mutation: omniweb already forwarded session.accessToken to onex-api and already checked onex-admin in app/_lib/admin-guard.ts. FINDING WORTH KEEPING: the omniweb admin SQL named FOUR schema objects that do not exist - tenants.status (a guardrail RAISEs if the column is ever added), api_keys (really tenant_api_keys), usage_events.created_at (really occurred_at) and waitlist_entries (no migration anywhere creates it). Three of five admin query modules could only ever have raised, so that surface was already dead. It survived for months because every test used a mock repository; a new integration test now runs every query against Postgres 16.14 with the full 44-migration manifest chain applied as CI applies it, with a RED control. The omniweb doctrine check was widened from lib/dashboard/ to all of app/ and lib/ plus a package.json dependency check, both with positive controls and both proven RED. SHARED-CODE FIX: rate_limit_by_ip converted every decorated handler HTTPException into a generic 503; both wrappers now re-raise, proven RED by reverting only that branch. RESIDUALS: OMNIWEB_DB_URL still set by the base manifest (applied to the production-facing cluster too, whose image predates this work) - removal gated on the new image being live on both lanes; the authenticated 200 path is unproven because minting an onex-admin token was not this lane's to do; the lab runs neither omniweb nor Keycloak so neither the role check nor the web-to-api hop is exercisable there; pnpm lint is broken on omniweb dev independently (next lint removed in Next 16) and is not a gate. NO TICKET MINTED - the grant was conditional on a server-side piece being out of reach and none was. For the orchestrator to route: a self-bind OCC receipt is minted pinning the WHOLE contract file with no contract_entry_sha256, so with three companions on one ticket it goes stale on every append and rebinding becomes a race; the newer producer node_occ_companion_compute already mints self-binds as declared dod_evidence entries WITH a per-entry hash. No cloud mutation, no credential work, bar not dispatched.
2026-09-13T12:51:06Z | TERMINAL | lane=cloud-ci-canary-route | actor=claude:opus5:subagent | closes=CLAIM docs/tracking/ROLLING_WORK_LEDGER.md:7185 | ticket=OMN-18291 parent=OMN-18205 | consent=docs/tracking/ROLLING_WORK_LEDGER.md:7179 | OUTCOME: BOTH HALVES LIVE AND PROVEN. MERGED: omninode_infra#1414 squash de6495cc40244caa9f35c5d39d6b05634302965b at 12:25:14Z (scale-up trigger: omninode-ci-runner-scaler Lambda + scaler role + GitHub-OIDC invoker role, the canary workflow's own capacity-request job, 36 tests, and three fleet-image fixes); omnibase_infra#3478 squash a77df3a380d43e8605b8ba39a1a662436f162643 at 10:30:04Z (one job class routed + policy declaration + audit key + 5 tests); knowledge-base-internal#392 squash a76a5ffb18bb7b3106ebf723904023cb99a59b34 at 10:26:39Z (runbook revision 5, sections 13 and 14); OCC companions onex_change_control#9324 squash 3d2db1d1cf3f6035b73521021da776ed9522330a and #9327 squash bb470410b660dc971a8e33a4e4cb133e7bd3f9b6, the second after I rebound one renamed evidence item's receipt to its own entry hash (the autobind's own same-ticket union renamed dod-occ-diff-derived-behavior-proof to dod-occ-proof-node-1414 and left the pre-rename contract_entry_sha256, so occ-preflight failed contract_hash_mismatch; recomputed, all six entry hashes verified). | TRIGGER PROVED, capacity moved by the trigger and by nothing else, run 34751253392 with the group at 0 beforehand and zero hand-run capacity calls: 10:13:07Z desired0/inst0 -> 10:14:09Z desired1/inst1 -> 10:15:11Z job in_progress -> 10:16:13Z job success -> 10:17:31Z desired0/inst0. Zero runners left registered in group 4 with the group listing as the positive control; both guard alarms OK. | ROUTED JOB PROVED: job rebuilt-postgres16-proof ran on runner omni-cloud-<instance-id>, group omni-cloud-ci, instance id <instance-id> read from IMDS not inferred; both containers built and started, postgres logged ready to accept connections, proof-1 exited with code 0, all 8 steps success. | THREE FLEET-IMAGE CAPABILITY GAPS found by running the real job, none visible offline, all fixed in the bootstrap and applied: (1) run 34750171624 inst <instance-id> -- AL2023's docker package ships buildx as its ONLY CLI plugin so docker compose printed usage and exited 125, 50ms after docker info reported a healthy local daemon; (2) run 34750597454 inst <instance-id> -- a buildx IS present so every presence check passes, at 0.12.1, and compose build requires 0.17.0+; (3) run 34751054047 inst <instance-id> -- the boot script's umask 077 for credential hygiene is INHERITED and reached the runner process, so every checked-out file landed mode 0600, COPY preserved it, and the postgres image dropping to its own user got Permission denied on the seed. Gap 3's blast radius is every container-backed job that copies a checked-out file into an image running as non-root; hosted runners use 022 so a hosted-only job cannot have seen it. Fixed: both plugins installed from pinned digest-verified release binaries with the boot asserting each CAPABILITY before registering, and run.sh under umask 022 while config.sh keeps 077. | ROUTING, rule 14 in full: enumerated live org + 11 repo scopes at 09:31:31Z (absent everywhere, positive control OMNI_DOCKER_CI_RUNS_ON_JSON returned a value); ONE write 09:35Z OMNI_CLOUD_CANARY_RUNS_ON_JSON on omnibase_infra only; per-scope readback 09:36:29Z and again 12:49:49Z, present only on omnibase_infra. Out-of-scope variables untouched, proven by their own updated_at: org trusted 2026-08-27, org public-PR 2026-05-02, repo trusted 2026-09-07, repo docker 2026-08-28, repo security-scan 2026-08-25. PLACEMENT from parsed runs-on on the default branch: before (dev ce797b54f) docker-seam 15 hosted-literal 18 trusted-seam 136 total 214; after (dev 0748a4dea) cloud-canary-variable 1 docker-seam 14 hosted-literal 19 trusted-seam 136 total 215. Audit reported the declared-but-absent shadow BEFORE the write (positive control that the later pass is not vacuous) and both passes report 'Runner routing audit passed' from merged dev. | AWS: terraform plan -detailed-exitcode on aws/ci-runners exits 0, no drift; deployed S3 bootstrap object byte-matches merged dev (507 lines, all three fixes present in both). ASG MaxSize UNCHANGED at 4, desired 0, no suspended processes. | NOT DONE, stated: the webhook-shaped trigger is not buildable by an agent -- it needs the fleet App to gain Actions:read AND a workflow-job event subscription, both operator actions on the App; the OIDC path shipped instead needs neither. Only ONE job class is routed; a second needs its own capacity measurement (max 4 ephemeral single-job instances). The missing-credential boot drill remains unrunnable now the credential exists. | Non-routing variable also created and declared in the PROGRESS row: AWS_CI_RUNNER_SCALER_ROLE_NAME on omnibase_infra and omninode_infra, holding an IAM role NAME not a credential, required by omninode_infra's ban-hardcoded-aws-ci-identifiers rule 5 and added to both verified allowlists only after aws iam get-role confirmed the role. | ZERO credential reads, creations, rotations or prints; zero prod, stability, judge, lakshman or cluster contact; no bypass flag, no skip token, no --no-verify, no hooksPath override, no allowlist added to pass a gate.
2026-09-13T13:03:28Z | TERMINAL | lane=lab-tenants-store-folder | actor=claude:opus5:subagent | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7216 | consent=docs/tracking/ROLLING_WORK_LEDGER.md:7215 | ticket=OMN-18293 (evidence comment posted; ticket already Done) | FOLDER CREATED, BOTH TENANT KEYS FILED BY COPY, BOTH MINT JOBS REPOINTED, MERGED AND PROVEN ON THE LAB. | STORE: folder /lab-tenants created in environment dev of instance D (project onex-platform 872e00f4-1279-49a4-8e16-a2bd961f4996), folder id d60946f1-9483-47a2-aed3-cbe93787f64f. Both EXISTING keys filed by copy, values piped Secret->memory->HTTPS body, never argv, never a file, never printed: ONEX_LAB_TENANT_API_KEY len 48 sha12 d4552f08df57 (from onex-lab-tenant-credential) and ONEX_LAB_DOGFOOD_TENANT_API_KEY len 48 sha12 cb67a774170f (from onex-lab-dogfood-tenant-credential); readback digests match the source Secrets exactly. NOTHING minted, rotated, re-issued or revoked; no identity created; no other folder or environment touched -- proven by readback: /lab-provider-keys still exactly OPENROUTER_API_KEY, /tenant-inference-credentials 17 refs, /shared empty, and all three project identity role assignments byte-identical before and after. | THE GRANT, CORRECTED RATHER THAN CLAIMED: there was no read grant to add. The lane's store binding authenticates as identity onex-runtime 5fc7c5e9-13ab-4d94-a14c-7a75201d7c34 (client id e9aad20d-5212-4c8d-8b04-6885f3a62161, sha12 8a7e45ceb8cb, matching the host bootstrap identity recorded at ledger :6817) whose PROJECT ROLE IS ADMIN, so it already reads every path. Narrowing it to per-folder roles needs the store org-admin login and is a scope change to the identity every lane surface uses; not in this consent, not done, recorded in the runbook instead of claiming least privilege that does not exist. | CODE: omninode_infra#1419 squash e44e2066910b5bc1194553e9013384e4cb5052e8 MERGED; OCC companion onex_change_control#9336 squash e831688506997ffd0bb938ddecc8b9ba32676683 merged FIRST at 12:20:06Z. Both mint Jobs resolve their tenant key from /lab-tenants, PROVE it against the tenant-scoped reader (the same call apply_lab_lane.sh's SKIP_MINT guard makes) before adopting, mint only when nothing usable is found, file a minted key back so the store stays source of truth after a rebuild, and skip the step structurally on an unbound lane; a bound store that cannot authenticate/read/write fails the Job by name. The house Job carried no store binding before and now does. TDD RED first 13 failing / 4 passing, GREEN 17/17, 40 pre-existing dogfood+control-plane assertions unchanged, 121 passing across six adjacent lab guard modules, printed-value scanner carries a positive control. | LAB FIRST: the new step was cut VERBATIM from both patched manifests and executed inside the running onex-api pod -- house and dogfood both LAB_TENANT_STORED_KEY_READER_STATUS=200, both adopted, adopted values matching their Secrets at len 48 / sha12 d4552f08df57 and cb67a774170f. NEGATIVE CONTROL, same code same pod, asking for a key name absent from the folder: both adopted nothing and reported the mint path, so the green discriminates. Nothing minted, nothing written by either run. ONE idempotent apply_lab_lane.sh re-apply at the currently deployed tags (runtime 20260912T235940Z-d2cba472, api 5e2f27e6-20260912T235940Z, both migrate bundles matching), no concurrent applier (checked), terminal '== onex-lab is up ==', both mint steps skipped on their own authenticated reader probe; readback IDENTICAL before and after -- both tenants present, created_at byte-unchanged (house 2026-09-12 17:50:33.184705+00, dogfood 2026-09-13 09:20:45.052718+00), dogfood 1 active credential, house keyless by design, both carrier Secrets unchanged by sha12 and creationTimestamp, negative control on the counting query returns 0. Store-binding input file rebuilt from live cluster values and shredded after use (readback absent). | DOCS: knowledge-base-internal#394 squash 5ab3ec94c9f362b4cdd4c869ae34d06e8b34efd2 -- new standing runbook runbooks/onex-lab-secret-store-layout.md (four folders, the binding, the resolution order, the admin-role caveat, the recovery procedure), indexed in runbooks/README.md, and the dogfooding plan's residual marked closed. Scrub exit 0 before the commit; local-path, beta-layout, private-link and invariant gates all pass. | TWO FINDINGS FOR ROUTING, neither mine to fix under this brief and NO TICKET MINTED (none granted): (1) the dogfood mint Job as landed in e8743dd1 reads its active-credential predicate from tenant_inference_credentials through the repository bound to OMNINODE_CLOUD_DB_URL, and that repository connects to omninode_cloud which does NOT hold the table -- on the lab it lives in omnidash_analytics, the database provider_key_chain.sh's own analytics reader uses; probed live from inside the running API image (REPO_DATABASE=omninode_cloud, REPO_SEES_tenants=1, REPO_SEES_tenant_inference_credentials=0). The Job has never run on the lab because the applier skips it while the carrier Secret resolves, so it has never fired; it will fail the Job the first time it runs. (2) omnimarket#2512 (ddeb8c57, OMN-18295) merged at 12:23:39Z and moved handler_quality_gate.py's whole-file hash, staling the OMN-15651 audited exclusion pin for every omninode_infra run starting after it; a peer merge-sweep staged and then committed the refresh (3b51c7b9) into this lane's branch, and I VERIFIED IT AGAINST GIT OBJECTS BEFORE IT LANDED rather than trusting it -- the audited locator _VERIFIABLE_TASK_TYPES hashes to dfb375aacf44718cf09971016819f768b7c061ad3206039042111d326dc00344 at the pre-change commit, the changing commit AND dev head, old pin 0bc7aa81 is the whole-file hash at the pre-change commit and new pin 916f59cc is the whole-file hash at dev head, so the exclusion rationale holds and it is a pin refresh not a re-audit. It rode in on the same squash. | CORRECTION I OWN: I briefly treated omninode_infra#1420's red Repo Scripts Tests as the same drift; reading its log via the API showed a DIFFERENT failure (an unclassified PR-triggered job in its own change), so that inference was wrong and was dropped rather than reported. Separately the OMN-15651 oracle is NOT reproducible on the launching host: it walks the candidate workspace and picks up omninode_infra/docker/onex-api/.venv/.../site-packages, a virtualenv inside the canonical clone CI does not have, failing on 35 unaudited candidates from inside that venv; the git-object hash evidence is what was checked and CI is the surface that evaluated it. | NOT DONE BY DESIGN: no identity created on any instance; no rotation, re-issue or revoke of anything; no environment but dev; no folder but /lab-tenants; no staging, prod, stability, judge, lakshman or cloud-cluster contact; no kubectl set/patch/apply outside the sanctioned applier; no --cold, no raw compose mutation; no psql DDL; no bypass flag, no skip token, no --no-verify, no hooksPath override, no pkill; no directory-wide pytest on the launching host beyond the two named oracle tests; no Slack; no ticket minted; no credential value in any transcript, log, file, artifact, ledger row, PR body or Linear comment -- every value named by key name, byte length and sha256-12 only. | done
2026-09-13T13:09:27Z | TERMINAL | lane=merge-sweep-worktree-addendum | actor=claude:opus5:subagent | ref=OMN-16106 | closes-CLAIM=docs/tracking/ROLLING_WORK_LEDGER.md:7234 | ADDENDUM LANDED; THE REPORT'S CODEX SENTENCE STANDS. knowledge-base-internal#397 MERGED 2026-09-13T13:09:04Z squash 29a0bddbb8e2924696c30d17976559657bf2279d, all 8 checks green, appends 'Addendum, 2026-09-13' to reports/2026-09-13-closeout-process-infrastructure-report.md. FINDING: the worktree at OMN-17341 on branch manual-merge-sweep/omn-17341-occ-9321-conflict was created by lane=omn17341-admin-waitlist (a Claude build lane), NOT codex. Evidence: (1) that lane's PROGRESS row :7186 at 09:20:44Z states the remaining OCC#9321 union and the YAML-dumper-then-text-level sequence that head commit 0adfa77c57 describes in its own message; worktree git admin dir created 09:23:04Z, three minutes later. (2) Every commit unique to the branch is authored+committed under the shared local git identity; zero codex actors in log, reflog or trailers. (3) Only 3 codex-actor ledger rows exist since 2026-09-12T00:00Z (codex-integration-pass-10, -11, plus this report's landing row quoting them); positive control = 1740 codex rows over the full ledger. (4) No tool generates a manual-merge-sweep/ branch name in omniclaude, omnibase_infra/scripts, omninode_infra or docs/runbooks/codex-nightly-controller.md; positive control = the same grep finds the merge_sweep skill files. It is an ad-hoc local convention echoing docs/runbooks/manual-merge-sweep.md, used by lanes of both fleets (12 such local branches in onex_change_control, 3 across omnibase_infra/omnimemory/omnimarket). SHARED STATE: the branch reached NO remote (ls-remote refs/heads/manual-merge-sweep/* = 0 rows in all four repos; positive control refs/heads/dev returns a row). The work reached origin on OCC#9321's own autobind branch auto/omninode-ai-omninode_infra-pr-1413-occ-autobind: head_ref_force_pushed 09:36:41Z and 09:47:13Z, squash-merged 10:30:58Z (merge commit e275f87d, mergedBy a User not a Bot, auto-merge SQUASH). VERDICT: report sentence 'Since 2026-09-12 its only activity has been read-only verification passes' STANDS UNAMENDED; the episode sharpens G9 - with no per-lane identity, misattribution fails in both directions. Read-only investigation plus one document PR; zero code, zero tickets minted, zero Linear state changes, worktree not deleted.
