You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A consumer repository's level.yml run cannot reconcile the organisation's population, because a private org member is invisible to github.token in every repo but its own. Measured on iiif-server's first successful publish (level run 32521684488): the reconciliation reads the correctly-declared private monumental-archive as unseen and refuses — from every repository except one holding a broader token. The refusal is right in general (an unseen repository is unchecked, not clean); the credential makes it fire on every consumer at every pin bump past v1.51.0. stele level refused rather than publishing a partial board; no published evidence is wrong.
Decided build
Ruled 2026-08-21 (orchestrator, recorded in-thread): option (c). A consumer's level.yml judges its OWN cells; the org-wide population reconciliation (listing vs roster) moves to the canon's audit, which already holds AUDIT_TOKEN with the private member in scope (#749). No standing org-read secret in nine repositories to publish a badge; nothing softened — a deleted repo still reads as absent where the roster is reconciled, in one place.
Two halves, strictly ordered:
Engine half — stele#252 (a per-repo mode that judges the caller's cells without reconciling the roster): owned by the 2026-08-24 stele batch, proof ledger release-lab#262. Not this issue's work.
Canon half — this issue, after the stele release carrying chore(canon): update monumental-archive/signer digest to 9adecf6 #252 and the pin handover:level.yml moves to the per-repo mode (its stub/workflow invocation stops reconciling); the canon's audit population leg owns the roster reconciliation under AUDIT_TOKEN. The exact flag/mode spelling is the engine's surface at that pin — read it from stele#252's merged reality, never from this spec (a spec written before the code is not trusted for surface details).
Until then, every consumer's level run reds on the private member as a known org-wide refusal, gating nothing (level runs after publish, publishes to its own branch) — documented, owned here, never re-filed.
Rejected, recorded so they are not re-proposed: an org-read secret in every consumer (a standing credential to publish a badge — #604's own finding cuts against it); softening the engine's refusal (a deleted repo would read as clean); declaring the private repo out of the population (#672 chose the by-name roster entry precisely so it is accounted for).
Canon consequence
level.yml (consumer stub surface) and the canon audit's population leg. Consumers' level runs go green at the pin bump that carries both halves; the roster reconciliation runs Mondays under AUDIT_TOKEN. stele#251 (partiality expressible in the engine) remains the long-term guard that a revoked scope stays distinguishable from a deleted repo — cross-linked, not this issue's work either.
Done when
a consumer repository's level.yml run publishes its cells with the private member declared — measured on a real run after the pin handover
the canon audit's population leg reconciles the full roster green over the 9-member population — run linked
release-lab's level run is green after its pin bump — measured on the run
the known-red is confirmed cleared on every consumer that had it
Sequencing
BLOCKED — do not start: hard-blocked by stele#252 merging AND its engine release AND the batched pin handover (ledger release-lab#262's ordering: canon edits ride the pin handover, never before the engine release). One lane once unblocked; shares level.yml and audit population leg with nothing else open. Refs stele#252, stele#251, #749, #672, #604, release-lab#262.
Defect
A consumer repository's
level.ymlrun cannot reconcile the organisation's population, because a private org member is invisible togithub.tokenin every repo but its own. Measured on iiif-server's first successful publish (level run 32521684488): the reconciliation reads the correctly-declared privatemonumental-archiveas unseen and refuses — from every repository except one holding a broader token. The refusal is right in general (an unseen repository is unchecked, not clean); the credential makes it fire on every consumer at every pin bump past v1.51.0.stele levelrefused rather than publishing a partial board; no published evidence is wrong.Decided build
Ruled 2026-08-21 (orchestrator, recorded in-thread): option (c). A consumer's
level.ymljudges its OWN cells; the org-wide population reconciliation (listing vs roster) moves to the canon's audit, which already holdsAUDIT_TOKENwith the private member in scope (#749). No standing org-read secret in nine repositories to publish a badge; nothing softened — a deleted repo still reads as absent where the roster is reconciled, in one place.Two halves, strictly ordered:
level.ymlmoves to the per-repo mode (its stub/workflow invocation stops reconciling); the canon's audit population leg owns the roster reconciliation underAUDIT_TOKEN. The exact flag/mode spelling is the engine's surface at that pin — read it from stele#252's merged reality, never from this spec (a spec written before the code is not trusted for surface details).Until then, every consumer's
levelrun reds on the private member as a known org-wide refusal, gating nothing (level runs after publish, publishes to its own branch) — documented, owned here, never re-filed.Rejected, recorded so they are not re-proposed: an org-read secret in every consumer (a standing credential to publish a badge — #604's own finding cuts against it); softening the engine's refusal (a deleted repo would read as clean); declaring the private repo out of the population (#672 chose the by-name roster entry precisely so it is accounted for).
Canon consequence
level.yml(consumer stub surface) and the canon audit's population leg. Consumers' level runs go green at the pin bump that carries both halves; the roster reconciliation runs Mondays underAUDIT_TOKEN. stele#251 (partiality expressible in the engine) remains the long-term guard that a revoked scope stays distinguishable from a deleted repo — cross-linked, not this issue's work either.Done when
level.ymlrun publishes its cells with the private member declared — measured on a real run after the pin handoverSequencing
BLOCKED — do not start: hard-blocked by stele#252 merging AND its engine release AND the batched pin handover (ledger release-lab#262's ordering: canon edits ride the pin handover, never before the engine release). One lane once unblocked; shares
level.ymland audit population leg with nothing else open. Refs stele#252, stele#251, #749, #672, #604, release-lab#262.