9.7 KiB
Session 0040.0 — Transcript
Date: 2026-05-29 Goal: Answer the operator's question about non-UX RFC contributions (ROADMAP #35), then "do it" — stand up the operator RFC-authoring lane. Along the way, settle the repo-per-RFC topology question the operator kept raising.
Outcome: #35 proven end-to-end (Informed Consent super-draft live in the OHM corpus, authored + merged natively via a new
rfc-authoring.shlane). The operator's "does each RFC need its own repo?" pushback overturned the session's first answer — topology is now captured as ROADMAP #36 (leaning meta-only), RFC-0002 graduation paused. A real rfc-app bug the operator spotted (phantom pending-idea after a merge-with-branch-delete) was fixed, tested, released as v0.30.1, and deployed (deploys.id=43).Highlights:
- rfc-app v0.30.1 — phantom-pending-idea reconcile fix, 375 tests green.
- New durable tooling:
ohm-infra/scripts/rfc-authoring.sh+RFC-AUTHORING-LANE-RUNBOOK.md. Token in macOS Keychain, never in a transcript.- ROADMAP: #35 layout note corrected (wrong SPEC §1 premise), #36 added.
Pre-session state
- ohm-rfc pin: rfc-app 0.30.0; OHM live on 0.30.0 (healthy).
- rfc-app main at
1558cc3(v0.30.0). - Corpus: one active RFC (
human→ RFC-0001,wiggleverse/rfc-0001-human)- the
wiggleverse/ohm-metamanifest.
- the
- ROADMAP #35 (operator RFC authoring lane) open, captured 2026-05-29 in a prior session; no tooling built yet.
- No gitea token configured anywhere (clean slate).
Turn-by-turn arc
Arc 1 — "Any roadmap work for non-UX git contributions?"
Identified ROADMAP #35 as exactly that item. Walked its open questions; the operator zeroed in on one sub-question — "does each RFC really need its own repo? it's a single document" — asked three times across the session, which signaled it was the real decision.
Arc 2 — First (wrong) topology answer, then the correction
Initially folded a "maturity-gated, manifest-glued" decision into #35 (keep per-RFC repos at graduation). The operator pushed back. Reading SPEC §1 showed two of the three pro-per-repo arguments were nullified by the design: (a) per-repo Gitea permissions — wrong, all git ops go through a single bot and auth is app-side; (b) fork-to-contribute — wrong, raw git push isn't a supported path. What survives (isolated history, multi-file-bundle container) is thin for a single document. Corrected the #35 note, added #36 (decide repo-per-RFC vs. meta-only; operator leans meta-only — a SPEC §1 + §13 framework change, not something #35 bakes in). RFC-0002 graduation paused so a second per-repo data point isn't canonized while #36 is open.
Arc 3 — Build the authoring lane (credential hygiene)
Operator chose "file I read by reference," then improved on it
mid-build: "create a script you run so you never read that file. Can it
be encrypted?" — which is the better shape. Built
ohm-infra/scripts/rfc-authoring.sh: verb-based gitea-API wrapper,
token in the macOS Keychain (encrypted at rest, no plaintext file),
piped to curl --config - so it never enters argv/stdout/transcript.
Several subshell-scope bugs found and fixed during smoke-testing
(token-resolution exit not propagating; HTTP status not surviving the
command-substitution subshell). Trace-verified the token never appears
on a curl argv line. Operator loaded a write:repository-scoped PAT;
whoami (needs read:user) 403s but that's irrelevant — authorship is
confirmed from PR author fields instead.
Arc 4 — Prove #35 end-to-end with a real RFC
Operator's working title: Informed Consent (already named in
RFC-0001 as a future entity — a real corpus entry, not a throwaway).
Drafted rfcs/informed-consent.md as a super-draft matching the
original human propose-commit shape. Branch propose/informed-consent
→ commit (authored Ben Stull, not the bot) → push →
pr-create (PR #7) → pr-merge --method merge --delete-branch. File
landed on ohm-meta main; /api/rfcs showed the super-draft live —
the webhook reconciled a CLI merge automatically, answering #35's
named failure-mode question in the affirmative for ohm-meta merges.
Arc 5 — The operator catches a real bug
Operator: "I see Informed Consent as both a Super-Draft and a Pending
Idea in the UX." Investigated: gitea truth = PR #7 closed+merged, but
/api/proposals still listed it. Root cause: I merged with
--delete-branch; gitea then reports the PR head.ref as the
refs/pull/7/head sentinel; refresh_meta_pulls parses the slug from
the branch name → None → row skipped → cached_prs.state frozen at
open forever. cached_rfcs reconciled off the push event (super-draft
appeared) but cached_prs never did (phantom idea). The web UX never
hit this because it leaves branches in place
(default_delete_branch_after_merge=false).
Arc 6 — Fix, test, release, deploy
Fixed in backend/app/cache.py: when gitea reports an empty or
refs/pull/ sentinel ref, recover the real branch name from the stored
cached_prs.head_branch row (migration 002 retains it). Applied to both
refresh_meta_pulls and refresh_rfc_repo. Added regression test
test_merged_idea_pr_with_deleted_branch_clears_proposal — proven by
reverting the fix and watching it fail with the exact phantom, then
restoring. Full suite 375 green. Released rfc-app v0.30.1
(branch → bump VERSION + package.json → CHANGELOG → commit → tag →
push origin + benstull mirror, SHAs match → ff-merge main). Bumped
ohm-rfc pin 0.30.0 → 0.30.1. Deploy hit a stale-ADC reauth wall twice
(operator's gcloud auth application-default login had to actually
complete — first attempts didn't rewrite the credential file); once the
ADC minted a token, deploy succeeded, deploys.id=43, v0.30.1 live.
Verified: /api/health = 0.30.1, /api/proposals = [] (phantom
gone), informed-consent intact as a super-draft.
Arc 7 — Durable artifacts + protocol close
Wrote ohm-infra/RFC-AUTHORING-LANE-RUNBOOK.md (#35's required
gesture-note). Confirmed ohm-infra is not a git repo (only transcripts
publish, via the script, to ohm-session-history), so the script +
runbook simply live on disk.
Cut state (end of session)
| rfc-app | 732b23b v0.30.1 — phantom-pending-idea reconcile fix; pushed origin + benstull |
| OHM live | deploys.id=43, v0.30.1, healthy |
| ohm-rfc | 470251b — ROADMAP #35 correction + #36 added; pin → 0.30.1; pushed |
| ohm-meta | informed-consent super-draft live (PR #7 merged) |
| ohm-infra | rfc-authoring.sh + RFC-AUTHORING-LANE-RUNBOOK.md on disk (not a git repo) |
| gitea token | Ben-owned PAT, write:repository, in macOS Keychain ohm-gitea-token |
| Wave ledger | Status |
|---|---|
| #35 operator RFC authoring lane | ✅ proven end-to-end (super-draft path); tooling + runbook shipped |
| #36 RFC topology (meta-only) | 🟡 captured, operator leans meta-only, decision deferred |
| rfc-app v0.30.1 (phantom fix) | ✅ shipped + deployed (deploys.id=43) |
§19.2 / process candidates surfaced
- #36 — RFC repository topology. The big one. SPEC §1 says "each RFC is its own repo," but the bot-mediated app-auth model nullifies most of the benefit for single-document RFCs. Decide meta-only vs. per-repo deliberately; it's a §1 + §13 framework change.
- Stale open graduation PR.
ohm-metaPR #2 ("Graduate human → RFC-0001", ohm-bot) is still open — a leftover from RFC-0001's creation. Harmless but should be cleaned up. - Idea-PR merge hygiene. Even with the v0.30.1 fix, omit
--delete-branchon idea-PR merges to match the web UX. Encoded in the runbook; could be enforced inrfc-authoring.sh(refuse--delete-branchforpropose/*heads).
What lands on the operator's plate
- Decide #36 (meta-only vs. per-repo). Until then, do not graduate RFC-0002 into its own repo. Authoring super-drafts is unblocked.
- Flesh out Informed Consent — it's a live super-draft; the body
can grow via
edit/informed-consent/*branches on ohm-meta (the meta-only revision path, safe regardless of #36). - GCP ADC expires;
gcloud auth application-default loginneeds to actually complete (watch for "Credentials saved to file") before a deploy.
Prompt the operator can paste into the next Claude Code session
OHM driver session. Reserve your own session ID first
(~/git/ohm-infra/scripts/claim-session-id.sh --start <YYYY-MM-DDTHH-MM>).
Context from session 0040.0:
- ROADMAP #35 (operator RFC authoring lane) is PROVEN. The tool is
~/git/ohm-infra/scripts/rfc-authoring.sh (verbs: whoami/pr-create/
pr-merge/pr-list/pr-get/api); credential is a Ben-owned gitea PAT
(write:repository) in the macOS Keychain service `ohm-gitea-token`.
Full gesture + caveats: ~/git/ohm-infra/RFC-AUTHORING-LANE-RUNBOOK.md.
When merging idea PRs, do NOT pass --delete-branch (see runbook).
- "Informed Consent" is a live super-draft in wiggleverse/ohm-meta
(rfcs/informed-consent.md). To flesh out its body, use the meta-only
edit path: edit/informed-consent/* branch + PR on ohm-meta. This is
safe regardless of #36.
- ROADMAP #36 is OPEN and BLOCKING: decide repo-per-RFC vs. meta-only
topology (operator leans meta-only). It's a SPEC §1 + §13 framework
change. DO NOT graduate any RFC into its own repo until #36 is
decided. If the operator wants to settle #36, that's the next big
piece — draft the SPEC §1/§3/§13 revision + the rfc-app graduation-
flow change (in-place state flip, no repo creation).
- OHM live: v0.30.1 (deploys.id=43). rfc-app main 732b23b.
- Loose end: ohm-meta PR #2 (stale "Graduate human" PR from ohm-bot)
is still open — close it if convenient.