Re-approve — 20f4b28. The generator/count fixes are the driven kind (the literal-\t count bug found by running, not reading, is the same lesson as the checker one commit earlier — recorded as such). Suite 28/28, shellcheck clean, all five ci.yml jobs green on the runner (runs 1413–1417), refs-guard correctly skipped.
Approve — a55fbae. The verb is the right shape, and the tests pin both halves of the asymmetry.
Re-approve — 745944e. The manifest comparison is the right end state for the arming gate: path+kind+expected-value as a set, generated from the tree being armed, so all six weaker shapes (absence checks, value-equality without count, role swaps, suffix matches, known-caller lists) collapse into one failure. And it was driven against an actual armed/probe pair — all six classes refused — which is the evidence standard this repo keeps asking for. Docs-only delta over the approved dc87051; suite 28/28, shellcheck clean, all five ci.yml jobs green on the runner (runs 1387–1391), refs-guard correctly skipped. @andres — ready.
.pull_request == null, not has(), or this forge has no issues (#210)
Re-approve — 5b78d29 (test-only refinement over the approved 087ea4a: the scalar guard isolated — list row admits, payload stands down). Driven: suite 28/28, issueflow 512/512, shellcheck clean; full reconciler revert → 6 red (stronger than the previous head's 4); runner all five ci.yml jobs green (run 1380–1384), refs-guard correctly skipped. @andres — ready.
.pull_request == null, not has(), or this forge has no issues (#210)
Re-approve — 087ea4a. All three sites now fail through the real path, not through the expression they contain.
.pull_request == null, not has(), or this forge has no issues (#210)
Approve — 877e09e. The right fix, all three sites, and the evidence is the shape this class demands.
Re-approve — dc87051 (main with !206 merged in, no rewrite). The carrier enumeration + totality snippet now executable, consumer checkouts spared. Verified: 28/28 suite, shellcheck clean, all five ci.yml jobs green on the runner (run 1327-1331), refs-guard skipped by design.
Re-approve — a48cc71. Discovery from git ls-files is the right end state: "tracked" becomes executable rather than a glob list to maintain, and the fixture git repo means deleting a discovery class must make the teeth red. Verified: 29/29 suite, guard 28/28, shellcheck clean, all five ci.yml jobs green on the runner (runs 1320-1324), refs-guard skipped by design.
Post-merge finding — run 368's "no open issues." is the #188 blind sweep, back one layer in, and it is measured live
The hourly sweep did fire on merged main ([run 368](https://forgejo.h…
Re-approve — e27acd8. The two-layer arming resolves a real self-reference.
Re-approve — 634e7a3. The guard is now as strong as the document it defends.
Re-approve — f3f7538. Codex's two additions are in, and both are written as the runbook will need them.
Re-approve — b80767e. The respin fixes the two things that most needed fixing.
Approve — e965b15. The runbook is the sync's scar tissue, written down while it still hurt.
Approve — 0871453. The doc says the true things, including the uncomfortable ones.
Re-approve — a35a77f, now also verified against post-merge main
Re-review as requested, @andres — still an approve, now proven against the post-0.6.0 tree
Re-approve — 062e016. The four changes are all improvements, including the one that reverses a contract I approved.
Re-approved on 018489a. The delta from my approved 0f20f4b is one line of changelog prose ((ceremony#128) (#192) → per ceremony#128 (#192) — the issue citation terminal), no code. Re-verified anyway: 22/22, shellcheck clean, all five ci.yml jobs green on the runner for this head. My earlier review (#5597) stands as written, including the !204-before-!206 ordering note.