Execution handoff (originally 2026-07-19, end of day; status refreshed 2026-08)
Hand this file to a fresh session to continue. It is the operational companion to ADR 030 and the plan (gaps · workstreams · metrics). Read the plan first; this file is only state + next steps + gotchas.
2026-08 status refresh: the narrative below (verification notes, gotchas, next-steps rationale) is preserved as written on 2026-07-19. The merge status of every PR referenced has been re-checked directly against GitHub as of this refresh and corrected where it changed — most of the "OPEN" PRs below have since merged. Look for the "(verified 2026-08)" markers.
Where the work stands
| Item | State |
|---|---|
| Plan authored (ADR 030 + gaps/workstreams/metrics) | Merged to alphaswarm_docs development (PR #46) |
| Docs build/lint breakage (dead sidebar ids, MD010/MD004) | Merged (PR #47) — this was a pre-existing development breakage (gap G2/G8 live) |
| WS0 "stop the bleeding" across the estate | Merged — 40 repos, one PR each (batch-created + merged) |
WS7 P0 baseline metrics (scripts/ci/agent_dev_metrics.py + nightly workflow) | Merged (alphaswarm PR #237) |
WS2 pilot (alphaswarm_config, leaf/uv reference implementation) | Merged (alphaswarm_config PR #54) — CI green |
| WS2 spine fan-out (13 repos + monolith aliases) | (verified 2026-08) 9 of 14 PRs merged, 5 still open — see table below |
WS1.1 reusable workflow_call files (python-ci / node-ci / build-sign-push) | (verified 2026-08) Merged — alphaswarm_platform PR #96 |
| Fix PRs discovered by verification | (verified 2026-08) Both merged: alphaswarm_mcp #14 and alphaswarm_platform #95 |
Everything else (WS1 remainder, WS3–WS6) is not started. WS1's enforce-flag flips + quarantine ratchets and all WS3 monolith work are parked until the WS2 PRs merge (same branch everywhere — additional commits would pollute the open PRs).
The 14 WS2 PRs (opened 2026-07-19; merge status verified against GitHub 2026-08)
Each was implemented by a dedicated agent seeded with a per-repo recon
dossier, locally verified in a fresh python3.12 venv (make agent-bootstrap
&& agent-lint && full agent-test, except the monolith: aliases + dry-run),
then adversarially verified by an independent pass (branch hygiene,
tab-indentation, no green-by-skip, CI auth prelude preserved, docs/Makefile
drift). All 14 verdicts: pass at implementation time. 9 of the 14 have
since merged; 5 remain open (re-checked directly against GitHub, 2026-08).
| Repo | PR | Merge status (2026-08) | Local verification (2026-07-19) |
|---|---|---|---|
| alphaswarm_core | #66 | Merged (2026-07-20) | 1421 passed / 1 pre-existing skip; ruff 180 + mypy 12 report-only (dated ratchet carried from CI) |
| alphaswarm_data | #18 | Merged (2026-08-02) | full suite green |
| alphaswarm_finops | #2 | Open | full suite green |
| alphaswarm_auth | #8 | Merged (2026-07-20) | full suite green |
| alphaswarm_bots | #11 | Merged (2026-07-22) | tests 93/93 green; agent-lint fails locally only (container-root ruff-config leak, see gotchas) — green in CI's isolated checkout |
| alphaswarm_agents | #42 | Merged (2026-07-20) | full suite green (hermetic) |
| alphaswarm_controller | #42 | Merged (2026-07-20) | green; bootstrap deliberately installs core[config] (required for the suite to run at all — documented in PR) |
| alphaswarm_worker | #19 | Open | green; agent-lint self-installs the ruff==0.15.17 pin because CI's lint job runs sibling-free |
| alphaswarm_local | #21 | Open | full suite green |
| alphaswarm_kb | #10 | Merged (2026-07-31) | fails honestly: 10 ruff / 7 mypy pre-existing, incl. a real development bug (composition_root.py:51 undefined name, 5 runtime test failures) and an unguarded monolith import breaking bare collection — targets kept blocking since kb CI never used continue-on-error |
| alphaswarm_mcp | #13 | Merged (2026-07-19) | green locally; CI lint job now fails at bootstrap (PAT) instead of at ruff — same red, earlier step |
| alphaswarm_catalog | #4 | Open | full suite green; repo had no CI — pilot-shaped ci.yml added with core's auth prelude |
| alphaswarm_eval | #6 | Open | full suite green |
| alphaswarm (monolith) | #238 | Merged (2026-07-19) | agent-* aliases only onto existing Makefile targets + docs repoint; no CI workflow touched |
The alphaswarm_kb#10 merge (2026-07-31) landed 12 days after the rest of
the initial batch (all others merged 2026-07-19/20 or remain open) — its
"honest-failure" pre-existing debt (composition_root.py:51) apparently did
not block the eventual merge; whether that bug was fixed separately was not
re-verified here.
Post-push CI triage (all 14 PRs): 4 green (agents, worker, local, eval);
9 red only at the loud agent-bootstrap PAT failure (expected — blocker
1); mcp additionally red on the pre-existing structural docker-build and on
bundle-check (fix = mcp PR #14). The monolith PR's six failing ci.yml
jobs (AGENTS hard-rule lints, Central Auth Scope Guard, Lint + type-check,
smoke tests, cli mypy wave-1, cli tests) are pre-existing for every PR:
the identical set fails on an unrelated PR and on main itself hours before
this change, and ci.yml never runs on development (PR-only triggers) so
the breakage was invisible there. The alphaswarm_cli failure is the
sibling-checkout gap (./alphaswarm_core is not a valid editable requirement). Monolith PR CI being red-for-everyone is an urgent G1-class
item — nobody's monolith PR can show green until it is fixed. Separately,
the #237 merge push tripped actionlint on development (17779bd).
Exact git / PR state
- Branch (all repos):
claude/agentic-workflows-enhancement-l51fmg. Develop there;git push -u origin <branch>. - Default branch is
developmenteverywhere (NOTmain). Several repos have nomainat all — any workflow triggering onmain-only never fires. - Merged-PR restart discipline: if a repo's PR is already merged, restart its branch from the latest default branch —
git fetch origin development && git checkout -B <branch> origin/development; force-with-lease push is fine when the branch only carries merged history. - This handoff file itself merged via docs PR #48; updates to it follow the same restart discipline.
CI reality (unchanged blocker, now failing loudly)
- Sibling-dependent repos (core, data, auth, finops, bots, kb, mcp, catalog, eval, controller-family) stay red at
make agent-bootstrapuntilWORKSPACE_CHECKOUT_PATis configured — the WS2 change preserves the loud fork-aware::errorpath; nothing is green-by-skip. alphaswarm_client— red on 149 pre-existing TypeScript errors (not introduced here). Needs a fix-or-baseline decision; client is not in the WS2 spine set yet.- Report-only lint semantics now live in each repo's Makefile (
|| true+ datedTODO(ratchet 2026-08)), not in CIcontinue-on-error— one source of truth for blockingness.
Blockers that need a human / admin (a fresh agent cannot do these)
- Set
WORKSPACE_CHECKOUT_PAT(read-only PAT, repo scope) on the CI'd repos — or, better, stand up the WS1 org GitHub App (actions/create-github-app-token) and, medium-term, publishalphaswarm-core/-config/-agents/-catalogwheels to the CodeArtifact index already proven inalphaswarm_admin/build-publish.yml. This is the #1 unblock for green CI across the dependency spine. Not independently re-verified whether the secret has since been set. - Review/merge (or batch-authorize) the remaining open WS2 PRs:
alphaswarm_finops#2,alphaswarm_worker#19,alphaswarm_local#21,alphaswarm_catalog#4,alphaswarm_eval#6 (verified 2026-08 — the other 9 of the original 14 have merged; see table above). - Resolve the two-world-model fork (gaps G6): the per-tool config boilerplate teaches QAP/three-planes/ArcticDB which contradicts hard rules 3/46 (Iceberg-only). WS3 cannot regenerate the per-tool files from AGENTS.md until an owner says which doctrine is real.
- EU AI Act 2026-08-02 applicability — the reports' claim did not survive verification; route to counsel before encoding any compliance machinery (workstreams.md WS-G). Note: 2026-08-02 has now passed; this determination has not been confirmed done here.
alphaswarm_indexpointer row for this plan must go through the index curator process (sole-writer invariant) — do not write it directly.- Org-level
.githubrepo creation (for WS1 reusable workflows), org rulesets/merge-queues, and Kyverno admission are admin actions. Note:alphaswarm_platformPR #96 (staged reusable workflows) has since merged, but that repo's ownorg-github-staging/still awaits the org.githubrepo to actually adopt it — not independently re-verified whether that repo now exists.
Next steps, in order
Human merges promptly:— done (both merged; verified 2026-08).alphaswarm_platform#95 andalphaswarm_mcp#14- Human merges (or batch-authorizes) the remaining 5 open WS2 PRs (finops #2, worker #19, local #21, catalog #4, eval #6); confirm whether
alphaswarm_kb'scomposition_root.py:51undefined name (noted in PR #10, merged 2026-07-31) was fixed as part of that merge or still needs a follow-up PR — not re-verified here. - Diagnose/fix the monolith's red-for-everyone PR CI (six failing
ci.ymljobs incl. onmain; see triage note above) — without it, "green = done" is meaningless in the biggest repo. Not re-verified whether this is still red. - After the remaining WS2 merges land: WS1 remainder — flip the report-only enforce flags (
LICENSE_GATE_ENFORCE,EVAL_GATE_ENFORCE,ALPHASWARM_WORKER_CI_FULL,RUN_CONTRACT_RESOLUTION) on a dated ratchet; convert the quarantine--ignorelists to a shrinking CI-enforced count. - Extend WS2 to the remaining Python repos and the JS repos (node-ci reusable already staged; JS repos need the four package scripts), same recon → implement → adversarial-verify pattern.
- WS3 canon restructure (guidance CI, AGENTS.md split, slug-keyed rule registry) — mechanical gates + split can proceed now that monolith #238 has merged; the per-tool regeneration waits on blocker #3 (doctrine fork).
- WS4/WS5/WS6/WS7-full per the plan.
Operational gotchas for the next session
- Ultracode is on: prefer the Workflow tool for multi-repo fan-outs (recon → implement → adversarial verify worked well); don't optimize for speed.
- Environment varies by session. Cloud sessions: repos at
/home/user/<repo>, GitHub viamcp__github__*(nogh). Local-Mac sessions: repos are nested inside the container dir~/AlphaSwarm/code/<repo>(the container itself is no longer a git repo — see itsREPO_CONTAINER_NOTICE.md), andghCLI is authenticated — prefergh apiREST (GraphQL quota can be exhausted; REST usually isn't). - Container-root ruff-config leak (local Mac only):
~/AlphaSwarm/code/pyproject.tomldefines[tool.ruff], and ruff's hierarchical discovery applies it to any nested repo lacking its own ruff config (bots hit this: 60 phantom findings locally, green in CI). Judge lint results against CI's isolated checkout; longer-term fix is per-repo ruff config (WS2.2 toolchain pinning). - Do not blind-merge multi-repo sweeps. Verify locally, review, then let the human merge or explicitly authorize batches. Self-created-then-self-merged PRs trip a "merge without review" classifier.
- Stage only files you edited — working trees may carry untracked runtime junk (
alphaswarm_auth/alphaswarm_auth.db,alphaswarm_agents/data/) and unrelated in-flight edits (alphaswarm_config/src/.../settings.pyhas uncommitted flags from other programs). Nevergit add -A. Local trees can be behindorigin/development— alwayscheckout -Bfrom the fetched ref, never author from a stale tree. - Scope: only the 42
alpha-swarm-ai/alphaswarm*repos are in session scope. - The
/data-context-extractorskill referenced in the original request is not available — its intent was folded into the research phase. - Two source reports live at the session upload path; their distilled framework + the web-verified findings are captured in gaps.md §4 (including which external claims did not survive verification).