2026-07-27 - 2026-08-03
Overview
16 Pull requests merged by 1 user
Merged
#988 feat(governance): land authoritative PROJECT_CHARTER.md (Closes #987)
Merged
#984 fix(guard): derive target base ref for cross-repository checkouts
Merged
#979 feat(controller): expose instance-level fleet identity and health snapshots (Closes #978)
Merged
#976 fix(runtime): recognize client identity environment and refresh worker registrations
Merged
#974 fix(runtime): support validated cross-repository canonical roots (#973)
Merged
#972 fix(reconcile): safely resolve worktree bindings whose paths are missing (Closes #970)
Merged
#968 feat(mcp): client/session-aware runtime ownership and provenance (Closes #948)
Merged
#967 feat(mcp): gate Connected-but-unattached MCP namespaces (Closes #708)
Merged
#966 feat(transport): add transport-neutral MCP bind seam (Closes #931)
Merged
#965 docs(remote-mcp): threat model, trust boundaries, and decomposition ruling (Closes #956)
Merged
#954 fix(author): unify the bootstrap and lock_issue issue-lock contract (Closes #953)
Merged
#944 fix(author bootstrap): restore missing runtime identity and session helpers (Closes #943)
Merged
#946 fix(gate): preserve exact-owner renewal evidence across duplicate rechecks (Closes #945)
Merged
#928 fix(test): add pytest.ini to restrict testpaths and ignore worktree branches (#927)
Merged
#918 feat(mcp): expose sanctioned Codex MCP reconnect request (Closes #678)
Merged
#917 feat(webui): Sentry/GlitchTip observability console & correlation view (Closes #649)
3 Pull requests proposed by 1 user
Proposed
#971 fix(reconcile): retire workflow session rows whose owners are no longer live
Proposed
#982 feat(fleet): add CAS-protected stale worker retirement capability (Closes #980)
Proposed
#986 feat(launcher): trusted client-instance identity for project-scoped launches (Closes #985)
16 Issues closed from 1 user
Closed
#987 feat(governance): require an authoritative project charter for every managed project
Closed
#983 fix(guard): derive target base ref for cross-repository checkouts
Closed
#978 feat(controller): expose native instance-level fleet identity and health snapshots
Closed
#975 fix(runtime): recognize client identity environment and refresh worker registrations
Closed
#973 fix(runtime): support validated cross-repository canonical roots for dedicated namespaces
Closed
#970 fix(reconcile): safely resolve worktree bindings whose paths are missing
Closed
#948 Make MCP runtime generation ownership client/session-aware so multiple LLMs can work concurrently
Closed
#708 MCP servers report Connected but tool namespaces are not attached to the active session
Closed
#931 Remote-MCP 02: Introduce a transport-neutral bind seam accepting a remote transport
Closed
#956 Remote-MCP: threat model, trust boundaries, and service-per-boundary decomposition
Closed
#953 fix(author): prevent bootstrap lock-provenance dead ends before PR creation
Closed
#943 fix(author bootstrap): restore missing runtime identity and session helpers
Closed
#945 fix(gate): preserve exact-owner renewal evidence across owning-PR duplicate rechecks
Closed
#927 pytest test collection fails with 199 errors due to recursing into branches directory
Closed
#678 Expose sanctioned MCP reconnect action to Codex workflow sessions
Closed
#649 Web Console: Sentry/GlitchTip connections, correlation, and durable issue creation (Phase 4)
32 Issues created by 1 user
Opened
#949 feat(control-plane): add authoritative native MCP fleet inventory and duplicate-process detection
Opened
#950 fix(runtime-context): align controller role metadata and capability routing
Opened
#951 feat(control-plane): persist authoritative fleet synchronization and restart receipts
Opened
#952 fix(leases): align stale-lease inspection, dashboard, and cleanup enforcement
Opened
#953 fix(author): prevent bootstrap lock-provenance dead ends before PR creation
Opened
#955 Epic: certify safe multi-LLM execution through securely isolated remote MCP
Opened
#956 Remote-MCP: threat model, trust boundaries, and service-per-boundary decomposition
Opened
#957 Remote-MCP: deny-by-default server-side authorization over the full request tuple, read-only by default
Opened
#958 Remote-MCP: host hardening and reproducible service packaging
Opened
#959 Remote-MCP: tamper-evident audit, full-surface secret redaction, and attribution-is-not-authentication
Opened
#960 Remote-MCP: credential rotation, revocation, and emergency client/session invalidation
Opened
#961 Remote-MCP: decommission Gitea credentials and privileged local MCP processes from LLM workstations
Opened
#962 Canary: credential-exfiltration probe against the remote MCP endpoint
Opened
#963 Canary: five concurrent LLM clients with a negative concurrency suite
Opened
#964 Gate: block unattended scheduling until the concurrency and exfiltration canaries both certify
Opened
#969 fix(reconcile): retire workflow session rows whose owners are no longer live
Opened
#970 fix(reconcile): safely resolve worktree bindings whose paths are missing
Opened
#973 fix(runtime): support validated cross-repository canonical roots for dedicated namespaces
Opened
#975 fix(runtime): recognize client identity environment and refresh worker registrations
Opened
#977 feat(config): add six-client MCP configuration doctor and safe repair tool
Opened
#978 feat(controller): expose native instance-level fleet identity and health snapshots
Opened
#980 feat(fleet): add CAS-protected stale worker retirement capability
Opened
#981 feat(bootstrap): add controller-authorized recovery lane for fleet-safety deadlocks
Opened
#983 fix(guard): derive target base ref for cross-repository checkouts
Opened
#985 Production launcher cannot issue trusted client-instance identity for project-scoped LLM launches
Opened
#987 feat(governance): require an authoritative project charter for every managed project
Opened
#989 MCP Control Plane: charter-compliant autonomous task selection (umbrella)
Opened
#990 Authoritative Gitea candidate-state schema, claims, and relationships
Opened
#991 Neutral unified project-state inspection
Opened
#992 Neutral worker activation, caller-selected validation, and atomic claim
Opened
#993 Thin task-oriented completion, release, and reassessment workflow
Opened
#994 Remove allocator-first and role-first normal operation
54 Unresolved Conversations
Open
#792
Terminal retirement of author issue leases (Issue #790 Slice B)
Open
#816
gitea_publish_unpublished_issue_branch fails closed for every caller: its own preflight discards the worktree_path it requires
Open
#873
feat(workflow): add native author workflow loading for work-issue mode
Open
#891
[P0] Add atomic author finalization
Open
#895
[P1] Preserve failure reporting after hard stops
Open
#916
Enforce exact-head reviewer approval as a mandatory PR merge gate
Open
#793
Complete lease fencing and align remaining task classes (Issue #790 Slice C)
Open
#889
[P0] Replace capability-call adjacency with consumable mutation grants
Open
#890
[P0] Unify author ownership and add fenced recovery
Open
#650
Web Console: AI-provider connections and evidence-backed operational insights (Phase 4)
Open
#906
feat(webui): AI-provider connections and evidence-backed insights (Closes #650)
Open
#900
Supervise MCP daemon cohort lifecycle: one eligible cohort per profile, drain and reap superseded cohorts
Open
#652
Product vision: MCP Control Plane Web Console (canonical)
Open
#887
Epic: Make author workflows transactional and safe for multiple LLM clients
Open
#929
Epic: Migrate the Gitea MCP fleet from local stdio processes to a remote MCP deployment
Open
#689
Deterministic MCP namespace attachment (from incident: client transport-pinning to obsolete cohort head 22698c1)
Open
#934
Remote-MCP 05: Define remote-session provenance to replace the stdio client-managed guard
Open
#908
feat(mcp): implement emergency break-glass MCP restart workflow (#664)
Open
#664
Implement emergency break-glass MCP restart workflow
Open
#584
Gitea MCP namespaces returned Transport closed; recovered via host auto-reconnect at session startup
Open
#711
Standalone issue-close has no sanctioned path: capability resolution silently cross-switches instances, gitea_close_issue lacks worktree_path, and no mdcps reconciler route exists
Open
#932
Remote-MCP 03: Replace per-process profile binding with per-request principal resolution
Open
#938
Remote-MCP 09: Stand up the authenticated remote MCP endpoint
Open
#936
Remote-MCP 07: Split local-filesystem tools from remotable tools and fail closed on the boundary
Open
#909
feat(restart): audit lifecycle events and durable incidents (Closes #665)
Open
#921
fix(mcp): include untracked files in preflight porcelain parsing (Closes #700, Closes #697)
Open
#922
fix(auth): prevent repository .env files from injecting workspace bindings (Closes #704)
Open
#923
feat(mcp): enforce strict cross-project mutation boundaries (Closes #707)
Open
#924
fix(mcp): invalidate review session state on cross-profile activation (Closes #690)
Open
#933
Remote-MCP 04: Replace macOS-keychain token resolution with a server-side credential provider
Open
#939
Remote-MCP 10: Dual-run cutover, parity validation, and rollback runbook
Open
#888
[P0] Isolate tests from live workflow state
Open
#896
fix(reviewer): isolate final-decision locks by PR and exact head
Open
#899
Enforce administrative loop-disable for scheduled author workers
Open
#700
incident: contaminated controller run (PR #696/#695) — credential exposed via shell args/curl, direct API+script fallback, provenance-env spoof, unmanaged MCP kill, false "no credential leaked" report
Open
#935
Remote-MCP 06: Redefine the master-parity mutation gate for a remote deployment
Open
#937
Remote-MCP 08: Move session, lock, and lease state to a store safe for concurrent remote sessions
Open
#893
[P1] Stabilize transient dirty-checkout verification
Open
#894
[P1] Enforce native MCP commits
Open
#797
Centralized management for scheduled multi-LLM workers
Open
#805
Gated worker controls
Open
#807
Role, namespace, and credential isolation
Open
#820
Architecture program — role-delivery-reliability control plane
Open
#947
Dirty same-claimant rebind cannot continue its owning open PR because no sanctioned path mints continuation evidence (#864 AC5 unmet)
Open
#655
Umbrella: Governed MCP restart coordination and zero-disruption recovery
Open
#659
Implement graceful MCP maintenance-drain mode
Open
#665
Add MCP restart audit events and incident creation
Open
#690
Harden formal-review runs against cross-role profile activation mid-session
Open
#722
incident: unreviewed direct-to-master commit 970e68b remapped 10 reviewer tasks to merger, disabling the repository's formal review capability
Open
#726
Bug: gitea_resolve_task_capability returns internal_error for acquire_reviewer_pr_lease
Open
#707
Enforce strict cross-project boundaries (permit issues, block codebase mutations)
Open
#704
Prevent repository .env files from injecting MCP runtime workspace bindings
Open
#697
Native workspace preflight explicitly ignores untracked files
Open
#913
Prevent, attribute, and recover unknown task files written into the control checkout