# Task Registry Reconciliation

audience: AI coding agents first.

status: ACTIVE
worker: main session
task IDs: #40–#238 registry audit
source request: Start recovery from stale TODO list; it contains forgotten, stale, half-done, and falsely-completed tasks. Reconcile in bounded batches, then recover requests absent from TODOs.

## Outcome

Every task-registry entry maps to one primary indexed plan and evidence-based state. No task is lost because its registry status was stale or falsely completed.

## Rules

- Registry status is a lead, not evidence.
- Process in bounded ID batches; update this file after each batch.
- Deduplicate by outcome. Several task IDs may map to one plan.
- `ACTIVE` requires named live worker/process. Otherwise open approved work is `IDLE`.
- `DONE` requires installed/deployed owner-visible receipt.
- Preserve suspicious completed tasks as unresolved until verified.

## Batch 1 — currently non-completed and known suspicious completions

| Task IDs | Registry claim | Primary plan | Reconciled state | Evidence/gap |
|---|---|---|---|---|
| #40 | pending | `recovery-doors` | IDLE | Reboot proof absent |
| #41/#148/#164 | in progress | `runtime-session-safety` | IDLE | No named worker; attachability/visibility incomplete |
| #96/#175 | in progress | `factory-k3s` | IDLE | Worker stopped; no live k3s Job |
| #125 | in progress | `live-report-sync` | IDLE | No named worker; report stale after current transitions |
| #140 | completed | `security-gate-containment` | OPEN-SUSPICIOUS | Task description itself says persistent/pooled containment design unresolved |
| #147 | in progress | `master-delivery-plan` | ACTIVE | Main session coordinating plan recovery |
| #169/#172/#178 | in progress/pending | `runtime-session-safety` | IDLE | No named workers; installed proof absent |
| #170 | in progress | `emergency-offload` | IDLE | Single-host remote proof exists; whole-agent/spill incomplete |
| #171 | completed | `factory-reliability` | OPEN-SUSPICIOUS | UI repair cannot prove offline backend functional |
| #176/#219–225 | in progress/pending | `quietcontext-product` | IDLE | No named worker; design sequence incomplete |
| #179/#233/#234/#236 | in progress/pending | `incidents-completion` | IDLE | Worker stopped; taxonomy/backfill/security unresolved |
| #181/#182/#183 | in progress | `factory-reliability` | IDLE | No named workers; preserved WIP and P1s unresolved |
| #231 | pending | `owner-request-recovery` | ACTIVE | Main session performing registry-first recovery |
| #235 | pending | `prompt-journal-restoration` | IDLE | Installed entrypoint absent |
| #238 | in progress | `flow-first-operating-model` + this plan | ACTIVE | Main session writing index/plans |
| #121 | completed | `prompt-journal-restoration` | OPEN-SUSPICIOUS | `/home/user/.local/bin/prompt-journal` absent despite completion claim |

## Batch 2 — task IDs #1–#39

Mapped without redoing delivered work:

- #1/#5/#26–28/#33/#36 → `workstation-agent-safety` (DONE; installed cgroup/kill protections and danger-lab follow-up evidence).
- #3/#10/#16/#18/#20/#35 → `agent-containment` (DONE; sandbox/escape/deck-sudo/danger-lab delivered).
- #23/#24/#34/#39 → `recovery-doors` (delivered configuration; #40 reboot proof remains IDLE).
- #2/#22/#25 → incident/documentation evidence retained by master/report; no executable remainder.
- #4/#7/#15/#21 → `runtime-session-safety`; original terminal recovery delivered, later attachability #41 remains IDLE.
- #6/#9/#11/#12 → installed tooling/harness history; no current contradictory signal. Mark historical DONE, reopen only on measured regression.
- #13/#14 → `emergency-offload`; registry/inventory delivered, current #170 remainder separately recorded.
- #17/#37/#38 → delivery/runtime safety history; delivered protections remain source doctrine.
- #19/#31/#32 → session ledger/observability delivered; later visibility tasks tracked separately.
- #29/#30 → notification controls delivered; no current contradictory request.

No #1–#39 task is silently dropped. Only executable remainder inherited from this batch is #40 plus later attachability work already indexed.

## Batch 3 — task IDs #40–#95

- #40 → `recovery-doors` IDLE; only unproven reboot acceptance remains.
- #41/#54/#55/#59 → `runtime-session-safety`; historical tmux/modal/escape work delivered, attachability #41 still IDLE.
- #42/#51/#52/#63/#68/#73/#74/#76 → delivery machinery historical DONE. Current flow-first model removes these rituals from unrelated item critical paths; reopen only on measured land failure.
- #80/#81 → ACTIVE in `wt/factory-timeout-state-machine`: timeout shutdown defect found. After process-group `SIGTERM`, leader exit returned from `process.wait()` and triggered immediate `SIGKILL` without preserving bounded grace for surviving descendants. Acceptance delta: source and reference wait full `TERMINATE_GRACE_SECONDS` before group `SIGKILL`; timeout tests prove leader-exits/child-survives real-process case and existing fake-leader expectation follows lifecycle.
- #43/#45/#57/#60/#67/#82 → `workstation-agent-safety`; delivered controls, but current workstation pressure is tracked under #170 rather than redoing old fixes.
- #44/#47/#58 → botmaster proxy credentials/D1 path historical DONE; no current contradiction.
- #46/#83–86/#90–92 → observability/report/UI historical delivery; current report drift remains #125 under `live-report-sync`.
- #48/#49/#50 → durable docs/report/dead-advisor historical DONE.
- #53/#56 → UI component deliveries historical DONE; revalidate only if current UI evidence fails.
- #61/#62/#64–66/#69–72/#77–79/#87–89/#93–95 → `emergency-offload`; earlier offload/fleet work delivered, but current #170 receipt proves partial regression. Do not redo all tasks: repair only current doctor/whole-agent/spill gaps.
- #75/#80 → shim safety historical DONE; danger-lab proof exists.

No new standalone outcome emerged. Executable remainders are #40, #41, and #170, already indexed.

## Batch 4 — task IDs #96–#146

- #96/#98/#139 → `factory-k3s`; image/provision work preserved, live execution remains IDLE/incomplete.
- #97 → `agent-containment`; rootless Podman limitation resolved by execution design, historical DONE.
- #99–104/#107/#114–116/#120/#122/#128/#134/#135 → `emergency-offload`; historical fixes preserved, current regression narrowed to #170 gaps.
- #105/#108/#124/#126 → historical review/release/land work DONE; no executable remainder evidenced.
- #106/#119/#129/#130/#146 → plan/task orchestration. New indexed-plan contract supersedes ad-hoc transcript/task-only coordination; #238/#231 now authoritative.
- #109/#111/#112/#123/#138 → observability/log surfaces historical DONE; current report sync remains #125.
- #110/#113/#127 → `workstation-agent-safety` + `emergency-offload`. Danger-lab/stall fixes delivered. #127 completion is suspicious because current statusline was again observed hot and workstation pressure persists; diagnose only through #170, not a duplicate task.
- #117/#118/#131/#136/#145 → `runtime-session-safety`; historical classification/visibility work preserved, current attach/recovery remainder indexed.
- #121 → `prompt-journal-restoration`; false completion, installed entrypoint absent.
- #125 → `live-report-sync` IDLE.
- #132/#133/#141 → explicitly dismissed/non-actionable notifications; no plan work.
- #137 → `quietcontext-product`; reinstall fix preserved, broader product plan IDLE.
- #140 → `security-gate-containment`; false completion/open design.
- #142 → status request, not independent outcome; covered by `incidents-completion`.
- #143 → historical harness dialect delivery DONE.
- #144 → `incidents-completion`; sidebar delivery preserved, full product incomplete.

Executable contradictions discovered: #121, #127, #140. All are mapped; no duplicate implementation launched.

## Batch 5 — task IDs #147–#218

- #147 → master coordination ACTIVE in main session.
- #148/#164/#169/#172/#178 → `runtime-session-safety` IDLE; no named workers.
- #149/#150 → historical task-gate/status interactions, no independent remainder.
- #151 → `emergency-offload` contradiction: task says `ca.sh` fixed, but installed `ca.sh` could not be located during current recovery. Whole-agent remote path remains unproven; reopen within #170.
- #152 → AuthWriteDO validation historical DONE; no current contradictory request in registry.
- #153 → `jpr06-integration` IDLE; commit preserved, not deployed.
- #154–160/#163 → historical toolchain/proxy/UI routing fixes preserved. Current remote/runtime remainders remain #170/#169; do not redo all.
- #161/#162 → `incidents-completion`; selector/brief phase work preserved, classification/backfill/security still incomplete.
- #165–168 → `factory-k3s`; provisioner/image work preserved, no live Job.
- #170 → `emergency-offload` IDLE; partial remote proof only.
- #171/#173 → `factory-reliability`; UI/flow investigation preserved, backend acceptance incomplete.
- #174/#177 → workstation/runtime emergency controls historical DONE; current pressure handled by #170.
- #175 → `factory-k3s` IDLE.
- #176 → `quietcontext-product` IDLE.
- #179/#181–183 → Incidents/Factory plans IDLE.
- #180 → historical recovery dispatch claim does not prove current delivery; superseded by plan index.
- #184 → capacity recovery DONE; its wording “retry review” does not make #236 review complete.
- #185–217 → review/audit implementation microtasks. Preserve their receipts under target plans; NEVER infer target delivery from review-task completion. Candidate #178/k3s/Factory work remains open where installed proof is absent.
- #218 → `quietcontext-product`; exploration output must be recovered, not repeated.

New contradiction: #151 installed whole-agent wrapper absent. Mapped to FIRE offload.

## Batch 6 — task IDs #219–#238

- #219–225 → `quietcontext-product` IDLE; no named worker. #218 findings must be recovered first.
- #226–228 → review microtasks; preserve under their target plan, do not equate review completion with delivery.
- #229/#230/#232/#237 → durable recovery planning work delivered and incorporated into index/master files.
- #231 → `owner-request-recovery` ACTIVE in main session.
- #233/#234/#236 → `incidents-completion` IDLE; no named worker.
- #235 → `prompt-journal-restoration` IDLE; completion claim #121 contradicted.
- #238 → plan registry ACTIVE in main session until live installation/landing and request inventory complete.

All registry tasks #1–#238 now have a primary plan or explicit historical/dismissed classification. Remaining recovery source is owner requests absent from registry.

## Owner-corpus reconciliation

Mechanical extraction produced 137 genuine owner messages from the three-day transcript. Outcome comparison found these TaskList-unrepresented acceptance deltas:

- New primary plan: `agent-observability` — unified actual-event logs, DataTable drill-down, time-range charts, per-project filters, node/session placement, and terminal attach. Historical #32/#83/#84/#109/#111/#112/#117/#118 are partial evidence, not proof of this complete outcome.
- Updated `incidents-completion` — incident-specific base prompt, bounded all-incident tool, similar-incident summaries with KB IDs, type-selected skills, evidence-gated learn-from-mistakes knowledge updates.
- Updated `runtime-session-safety` — `cld-human` automatic unsafe human mode and incremental consolidation into `~/.overdeck/` / `~/Projects/overdeck/`.
- Existing plans already cover corpus demands for transparent CDX/SSH offload, Factory/k3s/Podman, report synchronization/dark mode, prompt journal, task orchestration, disk admission, runtime provenance, recovery doors, security containment, QuietContext simplification, and install-before-land emergency sequencing.
- Non-actionable acknowledgements, status questions, repeated urgency, corrections already encoded in operating rules, pasted assistant summaries, task notifications, and cross-session messages do not create duplicate plans.

## Current receipt

Tasks #80/#81 lifecycle fixed in `wt/factory-timeout-state-machine`. Source and reference now preserve `TERMINATE_GRACE_SECONDS` after group `SIGTERM` even when `process.wait()` returns because leader exited. Timeout tests cover fake leader grace accounting and real leader-exits/child-survives group termination. Verification: focused timeout test repeated four times passed; `python3 -m pytest modules/harness/factory/tests/ -q` passed 144 tests in 114.05s. Local commit created.

## Next executable action

Commit source/reference/test/plan delta locally; hand receipt to orchestrator for landing.
