@codex-reviewer-andresmgsl's three operational corrections.
1. ARMING REWRITES THE COORDINATE. The candidate SHA exists only in the
identity fork, so a stub still saying heavy-duty/ceremony/...@<sha> cannot
resolve it — and the candidate's own self-checkout hardcodes
`repository: heavy-duty/ceremony` beside the ref, so rewriting only
CEREMONY_SELF_REF makes it fetch the candidate SHA from the canonical
repository, where it does not exist. Both halves are now explicit, plus a
grep that enumerates every remaining heavy-duty/ceremony carrier so a
PARTIAL rewrite refuses instead of silently testing canonical main.
2. RESULT ISSUES ARE NOT RESET SCOPE. I had step 6 keep them as durable
evidence and the reset section delete them as stale — contradictory, and
the deleting half would recreate the expiring-log problem the venue exists
to avoid. Reset removes candidate-specific EXECUTABLE state only; result
issues may be closed or relabelled, never deleted.
3. NO UNMEASURED CLAIMS. I wrote that a personal namespace is where "the org's
runner and secrets do not reach". That was not measured — the probe repo was
deleted immediately and established only 403-on-org / 201-on-personal. The
no-workaround rule now rests on what was actually ruled: @andres chose an
ORG-OWNED standing venue, so a personally-owned repo is a different thing
from the one decided on and cannot satisfy #202's acceptance target. If
runner reach matters, it gets measured once the venue exists.
test/run.sh 28/28; shellcheck 0.10.0, changelog-armed clean.
Refs #202
@codex-reviewer-andresmgsl's four gaps.
1. BRANCH UPDATED TO CURRENT MAIN. The commit's parent was pre-#204 dad99dd, so
its green 22-file run did not contain the six test files and rules that
landed with the sync. Merged main in — no rewrite — and re-verified against
the 28-file suite the operator would actually receive.
2. WHO MAY RESET IT is now a section, and it says operator-owned until ruled
otherwise, with content reset separated from archive/delete/admin. The
access policy is set when the repo is created, which is the operator's step,
so the two belong together. Flagged for @andres rather than assumed.
3. AN EXECUTABLE ARMING PROCEDURE replaces "install whatever the probe needs":
fork ref and canonical SHA, caller stubs pinned to it, BOTH
CEREMONY_SELF_REF carriers rewritten, the event invoked recorded by name,
and what reset removes afterwards. It reuses the drill rehearsal's fork-ref
pattern rather than inventing a floating pin, including its rule against
ever creating a tag-shaped branch on heavy-duty/ceremony.
4. THE EVIDENCE CONTRADICTION IS RESOLVED. "Write results into an issue in this
repo" and "no probe touches ceremony's board" could not both be followed in
a file where "this repo" reads as ceremony. The job now writes raw results
into the PROBE repo, and a human carries the issue URL and run number to the
ceremony issue. The probe workflow holds no credential and no code path that
can write to ceremony, which is what makes the two rules compatible.
Placement: the operational contract moves to docs/RUNNER-PROBES.md, with a
short cross-link in drills/README.md beside the disposal rule it excepts — the
exception stays visible where the dangerous habit lives, and neither document
grows a second top-level heading.
test/run.sh 28/28 on the updated branch; shellcheck 0.10.0, actionlint,
self-ref, marker, vendored and changelog-armed clean.
Refs #202