# WIP and Worktree Triage

audience: AI coding agents first.

status: ACTIVE
task IDs: #1, #2, #3; current session task #2
source request: Owner requests complete read-only triage of overdeck worktrees, branches, WIP, linked plans/specs, activity dates, landed state, merge readiness, conflict risk, progress, and time-to-land. Owner needs plain recommendations preserving all relevant WIP and avoiding rebase/merge pain. Branch deletion may be recommended only when proven landed; tag first so recovery is never one-way. Supplied `/wip-triage` contract defaults this request to `--audit` because no mutation mode was selected. On 2026-08-13 owner requested recovery of interrupted `od-wip-triage` session `3ecd0cda-4096-4058-b37e-0db3b0b4011a` and continuation of its tasks. Buildbox-admission recovery landed and deployed at `origin/main` commit `1fd1271e4`. Owner now requests continued triage of all remaining preserved worktrees, specifically: isolate work that is still unfinished, categorize it by product intent and completion state, then interview owner with the question tool to decide which categories or lanes remain wanted. Continue in `--audit` mode until those intent decisions are recorded. NEVER mutate audited worktrees, branches, stashes, or recovery refs during categorization.

## Outcome

Produce evidence-based audit and consolidation order. Preserve uncertainty. Do not mutate audited Git state.

## Acceptance criteria

1. Inventory every registered worktree, local branch, remote-tracking branch, detached worktree, stash, dirty/staged/untracked state, and potentially valuable ignored state.
2. Link each workstream to authoritative plan/spec/task where evidence permits; mark missing or contradictory links.
3. Record verified canonical remote/default branch/SHA/fetch receipt.
4. Classify every worktree and branch using exactly one disposition: `RETIRE — LANDED`, `RETIRE — REDUNDANT`, `RECOVER`, `KEEP — ACTIVE`, or `UNKNOWN`; add independent flags and confidence.
5. Prove landed/redundant work with content evidence beyond ancestry. Never recommend deletion below `HIGH` confidence.
6. Report first/latest unique commit date and latest meaningful activity. Say `inactive since`, never infer abandonment.
7. Report progress, remaining work, conflict risk, evidence-based time-to-land range, and concrete next action for every retained lane.
8. Produce conflict-minimizing consolidation and landing order. Prefer reimplementation of stale intent on current baseline over replay when architecture drift makes replay costly.
9. Produce executive recommendation, worktree ledger, branches-without-worktrees ledger, risks, and immediate next actions in plain language.
10. Audit only: create no recovery refs, tags, snapshots, bundles, stashes, commits, branch mutations, worktree removals, or remote mutations.
11. Identify existing project primitive, if any, that keeps incomplete real WIP disabled and permits agent activation only after verified completion. Record exact contract, enforcement seam, and WIP-triage integration; do not invent a new switch when an authoritative primitive exists.
12. Review every file and archived payload under `temp-user/overdeck-git-automation`; reconcile its short-lived trunk-based/feature-flag proposal with current audit recommendations. Distinguish steady-state development policy from one-time recovery of 117 uncertain lanes. Report package defects, unsafe assumptions, usable components, and final project-specific operating model.

## Preserved WIP

- Shared checkout `/home/user/Projects/overdeck` is read-only and already contains unrelated modified/untracked state.
- Audit planning lane: `/home/user/Projects/overdeck/.worktrees/wip-triage-audit`, branch `wt/wip-triage-audit`, created from `origin/main` at `8d36d1468`.
- No audited worktree or branch has been mutated.

## Constraints

- Follow owner-supplied `/wip-triage` audit contract.
- Read `/home/user/Projects/0 DOCS/GIT_FATIGUE.md`; NEVER modify it.
- Preserve first; verify second; mutate only in a separately authorized mode.
- Never inspect or expose secret contents while assessing ignored paths.
- Never use age, name, ancestry, clean status, or divergence alone as deletion proof.
- Never ask owner to choose Git mechanics; provide ranked recommendations.
- Repository instructions require isolated worktree for authored plan files.

## Execution steps

1. Verify canonical remote/default branch; fetch/prune if available; record timestamp and SHA.
2. Capture read-only machine inventory of worktrees, refs, branches, statuses, stashes, dates, divergence, and changed paths.
3. Identify ignored-path categories without reading credentials, dependencies, caches, builds, or logs.
4. Read plan/spec/task registry and map workstreams by branch, commits, paths, and intent.
5. Compare unique commits, trees, patch IDs, and current implementations to prove landed/redundant states.
6. Measure overlap, stale-base risk, progress, missing verification, and remaining acceptance work.
7. Build worktree and branch ledgers with dispositions, flags, confidence, estimates, evidence, and next actions.
8. Recommend preservation/consolidation/landing sequence and safe-retirement candidates. Do not execute it.
9. Update this receipt with audit artifacts and findings before reporting.

## Package reconciliation decision

Reviewed every outer file plus all 49 verified archive entries under `temp-user/overdeck-git-automation`.

1. Correct steady-state policy: short-lived task worktrees; small green slices; continuous current-main integration; applicable behavior lands default-off; exact-SHA controller gate/publish/deploy; automatic retirement.
2. Correct recovery policy: preserve 117 uncertain lanes first; NEVER mass-rebase or merge stale source branches; build disposable fresh-main candidates; keep original refs until landed/archive proof.
3. Prior response correction: “incomplete WIP normally stays off-main” is valid only during current recovery or for an indivisible red slice. It is NOT the target steady-state model. Green incomplete feature slices SHOULD land dark to prevent branch aging.
4. Reject package application as-is. Required test is already red. Implementation creates a parallel standalone controller, deploys from enrolled working tree rather than verified candidate artifact, lacks crash reconciliation around publication, exposes broad filesystem/network in sandbox, cleans without required verified recovery bundle, runs heavy gates locally, lacks content-addressed receipt reuse, and destructively rewrites entrypoints by filename.
5. Reuse concepts, not patch: tracked change-class/feature definition, fail-closed evaluation, candidate isolation, exact-SHA receipts, CAS publication, automatic checkpoint/import/retirement, one lifecycle owner.
6. Activation authority: agent MUST NOT directly toggle runtime state. Controller MAY auto-activate after exact deployed-SHA acceptance and smoke receipts when task acceptance already authorizes activation. Require owner decision only for genuine rollout/product scope (`internal`, `canary`, `on`) not determined by request. This matches ship-end-to-end policy and avoids making owner operate routine delivery.
7. Feature flags are temporary delivery controls, not permanent architecture. Require owner, expiry, rollback default, off/on tests, observability, and cleanup task. Do not flag refactors/docs/tests or ordinary verified fixes.

## Current receipt

- 2026-08-11: Task #1 created and marked for execution.
- 2026-08-11: Read owner-supplied triage contract and canonical Git-fatigue strategy.
- 2026-08-11: Indexed non-secret documentation under `/home/user/Projects/0 DOCS/`; secret and temporary paths excluded.
- 2026-08-11: Created isolated audit planning lane at `8d36d1468`; audited repository state remains untouched.
- 2026-08-11: Read-only baseline verified by `git ls-remote`: `origin/main` = `8d36d146804931c33a0e5fe026de03029f35572b`; local recorded `origin/main` matched. Fetch/prune intentionally skipped because audit mode forbids Git-state mutation.
- 2026-08-11: Inventoried 272 worktrees, 99 local branches without worktrees, 8 stashes, 16 existing recovery refs, 75 dirty worktrees, and 8 detached worktrees.
- 2026-08-11: Generated `.wip-triage-enriched.json`, `.wip-triage-ledger.md`, and `.wip-triage-summary.md` in the audit lane. No audited Git state changed.
- 2026-08-11: Conservative first pass identifies 117 recovery lanes and 254 landed-candidate worktree/branch refs. All 254 retirement candidates remain `MEDIUM` confidence until a second independent strong landing proof, preservation, and active-process check complete; therefore zero deletion recommendations currently pass the deletion gate.
- 2026-08-11: Flags: 63 dirty, 40 untracked-WIP, 16 potentially important ignored-path lanes, 249 stale-base, 8 detached. Ignored contents and secret-named paths were not read.
- 2026-08-11: Automated plan/spec links are candidate links only; semantic review is still required for authoritative consolidation grouping and accurate plan-level progress/ETA.
- 2026-08-11: Feature-completion switch audit: no generic project primitive currently binds incomplete feature state to verified completion and runtime enablement. `GOLIVE.md` is an observed acceptance ledger consumed read-only by `collector/src/adapters/golive.ts`; plan statuses govern workflow; `packaging/web-release.sh activate` atomically activates a whole verified web release; subsystem `enabled` settings are bespoke. Recommended default: incomplete work stays isolated off-main and therefore off. Use an explicit fail-closed feature flag only when partial code must land before activation; require acceptance receipt before the agent changes it from off to on.

- 2026-08-11: Reviewed all four outer package files and all 49 archive entries; manifest hashes and sizes pass. Package required validation is red (`TEST_REPORT.md`: focused exit 2). Reconciled policy: preservation-first is current debt recovery; trunk-based dark launch is steady state. Prior off-main-default recommendation corrected for steady state. Package rejected as executable patch; selected architecture concepts retained in this plan.

- 2026-08-11: External broken-ref signal resolved by owning session, not this lane. `refs/heads/wt/factory-gpt-engine` previously caused `fatal: bad object refs/heads/wt/factory-gpt-engine` and `error: https://github.com/alexcodeplace/overdeck.git did not send all necessary objects`; owner repaired it to `05fff831f3d5971f1be1cee635978d5fac8afe83`. Coordinator independently verified ref resolution, commit-object existence, and clean origin fetch dry-run. Task #24 performed no mutation of that lane.

- 2026-08-13: Recovered interrupted session from transcript and durable Git state. Recovery lane `/home/user/Projects/overdeck/.worktrees/recover-session-progress` contains commit `9b9eace3c` (`Restore trusted local buildbox admission`) and captured `.collector-stress.log`. Session recovery now reports prior session clean; no deferred tool call remains. Full stress log tail contains passing command-runner tests and no final failure summary, so it does not yet prove a current blocker or a defect related to buildbox admission.

- 2026-08-13: Buildbox-admission recovery landed and deployed at `origin/main` commit `1fd1271e4`; installed strict remote-only probe refused local-only work with exit 97.
- 2026-08-13: Owner requested continued triage. Created task #2 and isolated audit-authoring lane `/home/user/Projects/overdeck/.worktrees/continue-wip-triage`. Verified canonical remote `https://github.com/alexcodeplace/overdeck.git`, default `main`, and remote baseline `47ff6693277273ca6746b3130d28997d1bc0d730`. Existing audit artifacts remain in `/home/user/Projects/overdeck/.worktrees/wip-triage-audit`; that lane is 420 commits behind current main and contains preserved uncommitted audit/package-review state. NEVER rebase or overwrite it.

- 2026-08-13 owner intent interview: Kubernetes migration is active now and may supersede old Factory/buildbox lanes; compare old lanes with current plans and active work before recommending recovery. Git/worktree landing and deployment automation may already be complete; verify current background queue, lander, and deployer behavior before recommending any old lane. Agent runtime safety requires current-state review and recommendation. Preserve Observability/UI, Security/auth, and uncategorized remnants for review. GPT/provider tooling requires separation of active tooling from retired approaches before owner decides. NEVER treat category-level preservation as proof every old lane is still wanted.

- 2026-08-13 owner asks whether any lanes now pass safe-deletion proof after preservation and landing work. This remains an audit request, not deletion authorization. Identify exact `RETIRE — LANDED`/`RETIRE — REDUNDANT` candidates meeting every deletion-gate condition; report count and examples. NEVER remove until owner explicitly requests cleanup or `--execute-safe-retirements`.

- 2026-08-14: Verified recovery manifest `/home/user/Projects/overdeck/.worktrees/wip-triage-audit/.wip-recovery-manifest.json`: 787 refs resolve, 275 worktree heads preserved, 75 full-WIP snapshots, 9 staged snapshots, 8 stashes, zero failed carriers, six sampled full restores, no original carrier deleted.
- 2026-08-14: Re-evaluated current registered worktrees against current `origin/main` `e49aaa1de38f7581139d969bdedc1d28655aea2d`. Found 24 clean manifest-preserved worktrees whose heads are ancestors of main and whose patch sets contain no unique positive patch. All 24 had no original staged/dirty/untracked/ignored-important WIP in manifest. Exact-path process scan found zero active processes. These now satisfy technical `RETIRE — LANDED`, `HIGH` evidence except mode authorization; audit mode still forbids removal.
- 2026-08-14 safe-retirement set: `prov-wt`, `base`, `mainclean`, `bounddispatch2`, `cdx-dispatch`, `claudex-proxy-slice`, `cluster-machines-hero`, `enginebundle`, `factory-adw`, `factory-kill-copy`, `factory-run1`, `fleetvis`, `hook-control-toggle`, `hostbreak`, `incbrief-collector`, `incident-selector-clean`, `k3s-foundation-verify`, `landred`, `logsui2`, `obs-p2`, `t159routingui`, `t91incidents`, `timeline-time-axis`, `untrack-target`. First three are probe/scratch paths outside `.worktrees`; review exact registration before any execution.

- 2026-08-14 current-state comparison: `2026-08-10-factory-k3s.md` is DONE, installed, and cleanup-proven. Old Kubernetes/Factory lanes are not automatically wanted; current active Kubernetes redo supersedes their broad direction. Treat old lanes as evidence sources only unless they contain unique behavior absent from current main.
- 2026-08-14 delivery comparison: `2026-08-12-deploy-queue-coalescing.md` is DONE and installed; agents already enqueue land/deploy work and background controller completes it. Old land/deploy/worktree lanes should default to superseded or landed, subject to per-lane unique-content proof.
- 2026-08-14 runtime comparison: `2026-08-10-runtime-session-safety.md` is IDLE. Core runtime protection landed; only attachability-ref reconciliation remains explicitly unclaimed, while frozen-source retirement is separately gated. Recover old runtime lanes only if they implement that remaining contract or unique safety behavior absent from main.
- 2026-08-14 observability comparison: `2026-08-10-agent-observability.md` remains ACTIVE. Preserve relevant old observability lanes until mapped against active task #2; do not recover competing stale implementations blindly.
- 2026-08-14 GPT comparison: ask-gpt account registry is DONE. Factory GPT provider runtime plan lacks a valid status/next action and needs current implementation comparison. Only three old registered unfinished lanes match GPT terms (`incident-dispatch-selector-options`, `incident-resolution-coordinator`, `gptarm`); first two are primarily incident orchestration and only incidentally GPT-related. Review `gptarm` as the likely unique GPT remnant.
- 2026-08-14 security comparison: security-gate containment is IDLE and not implemented; next action requires measuring current `llm_runner.py`. Preserve `security-guard-codex-only` and any current containment lane until that measurement; runtime provenance guard is explicitly superseded by landed provenance behavior.

- 2026-08-14 owner explicitly authorizes execution: retire proven old Kubernetes/Factory lanes and proven old automatic landing/deployment lanes; continue unique-behavior checks before touching uncertain lanes. Mode advances from audit to `--execute-safe-retirements` only for candidates already meeting every deletion condition. Owner also asks who currently owns active observability work and requests continued recommendations/review for remaining categories.

- 2026-08-14 execution receipt: removed 10 verified `RETIRE — LANDED` worktrees without force: `cdx-dispatch`, `claudex-proxy-slice`, `cluster-machines-hero`, `enginebundle`, `factory-adw`, `factory-kill-copy`, `factory-run1`, `k3s-foundation-verify`, `landred`, `untrack-target`. Verified registrations absent afterward. Original branches and recovery refs remain.
- 2026-08-14 skipped `bounddispatch2`: target is a standalone nested Git repository (`.git` directory, common dir `.git`), not a removable linked worktree. `git worktree remove` failed closed before mutation. Keep until separately classified; NEVER force or delete its directory.
- 2026-08-14 observability ownership: authoritative plan is ACTIVE with task #2 ACTIVE but names no worker/owner. Therefore work is marked active without attributable executor. Check live task/process evidence before claiming anybody is currently doing it.
- 2026-08-14 archive-worktrees: added fail-closed archival CLI and focused hermetic test at commits `719678c20`, `2c50d87a1`, `ca720d030`, and `380178da3`. Commands: `audit`, `preserve`, `retire`, `restore`. Sol/low adversarial review found three blocking gaps: staged-boundary restoration, canonical-remote binding during retirement, and retry safety after post-push verification failure. Luna/max repair closed all three; follow-up hardening added NUL rename parsing, rename-source secret/generated checks, per-worktree locking, and concurrent-change refusal. Independent Sol/low review approved with zero blocking findings. Coordinator reran Python syntax check, diff check, and focused suite: `PASS=30 FAIL=0`. Local commits exist. `packaging/deploy-local.sh` completed but correctly deployed landed source, so the new unlanded CLI is not yet installed. Deploy also reported pre-existing shim-drift hazards across other preserved worktrees; this task did not alter those lanes. Landing, post-land deployment, and installed-entrypoint proof remain pending.

- 2026-08-15: Independent consolidation pass executed from claimed lane `.worktrees/wip-consolidate` (branch `wt/wip-consolidate`), separate from the `archive-worktrees` CLI track above. `~/.claude/skills/wip-triage/SKILL.md`, cited as installed by the sibling `2026-08-11-global-wip-triage-skill.md` plan (status DONE), is not present on disk (checked live path and the `skills-clobbered` backup) — flagged, not repaired; out of scope here. Before this pass: 36 registered worktrees, 589 local branches, 9 stashes.
- 2026-08-15: **Worktree tier (reversible — branch/commits never touched).** Candidate = registered worktree, `git status --porcelain` empty, not detached, not locked, not one of the 7 hands-off names, no live process with cwd inside it (`/proc/*/cwd` check). 8 were clean; 2 (`auto-deploy-on-main`, `intake-finish`) excluded after the live-process check found running collector processes inside. Removed 6 via `git worktree remove` (recreatable with `git worktree add <path> <branch>`, no commit lost):
  - `agent-slice-fix` @ `045916ccd` (not yet ancestor of `origin/main`)
  - `astryx-cutover-recon` @ `fdcbb1ff8` (not yet ancestor of `origin/main`)
  - `fix-npm-node-reentry` @ `31bcec9fb` (not yet ancestor of `origin/main`)
  - `list-sessions-slug` @ `833a8fb17` (**is** ancestor of `origin/main` — fully landed)
  - `reject-scheduler` @ `649b12d86` (not yet ancestor of `origin/main`)
  - `transcript-sot` @ `c49b62245` (not yet ancestor of `origin/main`)
  - Full per-worktree evidence (path/branch/sha/ancestor flag/recreate command): `wt-removal-evidence.jsonl` in this session's scratchpad.
- 2026-08-15: **Branch tier (irreversible — evidence-gated, no vault step needed).** Enumerated all 555 local branches without a registered worktree; ran `git merge-base --is-ancestor <branch> origin/main` individually per branch (448 true). Cross-checked those 448 against a fresh `plan-audit.json` built from `docs/plans/INDEX.md`: 3 are cited by an ACTIVE/IDLE plan (kept despite ancestor status). Deleted the remaining 445 with `git branch -D`, one merge-base proof recorded per branch before deletion in `branch-retire-evidence.jsonl` (session scratchpad) — every deleted branch's commits stay reachable from `origin/main`, so no content was lost and no tag/vault step was required (the ancestor proof itself is the preservation). One deletion (`wt/task176-cpu`) hit a stale `.lock` file (~40 min old, `fuser`/`lsof` showed no holder — left by an unrelated crashed process, not this pass); removed only the stale lock and retried successfully.
- 2026-08-15: **After counts:** 29 registered worktrees (one fewer than the expected `36 - 6 = 30`: `plan-reconcile-record`, a hands-off worktree this pass never touched, disappeared mid-session — consistent with the task brief's own note that another lane was landing it concurrently), 142 local branches, 9 stashes (stash tier untouched, out of scope). No `tmp_pack_*` debris found in `.git/objects/pack`.
- 2026-08-15: **Explicitly not touched this pass, named for the next one:** the 8 dirty-tier worktrees (`accounts-vanish`, `astryx-cutover`, `deploy-unwedge`, `dispatch-verify`, `factory-k3s-spark-canary`, `fix-rot-extractor`, `systray-token-readonly`, `tool-registry`), the 7 hands-off worktrees, 8 locked worktrees (`agent-a830a7486ad1eb504`, `git-cycle-enrollment2`, `git-cycle-final`, `ledger-bulk-tmux`, `session-bulk-tmux`, `session-index`, `session-transcript-farm2`, `transcript-farm3` — all locked `initializing`; `session-bulk-tmux`/`ledger-bulk-tmux` were named in the brief as salvage-check candidates but their lock excluded them from this pass's clean-tier method), 2 detached-HEAD worktrees, 1,130 `refs/rescue/*` refs, 5 `refs/heads/wip/*` refs, and all 9 stashes. `refs/vault/*` does not exist as a namespace here; the closest analog is `refs/archive/*` and its count was not separately reconciled against the earlier "27 vault entries" figure — flagged unverified.

## Next executable action

Install `archive-worktrees` through the project deployment path, prove the installed entrypoint, then land and deploy commits through guarded shipping. Continue unique-behavior review and authorized retirement only after the archival tool is live. Separately: dirty-worktree tier (8 worktrees) still needs per-lane uncommitted-diff review and `od-wip` salvage confirmation before any removal.

## Main checkout parking receipt — 2026-08-16

Loose WIP formerly in `/home/user/Projects/overdeck` was parked on `wip/main-checkout-park-20260816`; it holds the shared checkout's pre-sync scratch changes, including the three stranded FIRE-plan drafts. After each successful deploy, `packaging/deploy-local.sh` now records one `main-checkout-ff-sync` JSONL attempt under `~/.local/state/overdeck/main-checkout-sync/` and fast-forwards that checkout only when clean, undiverged, and unlocked. Dirty, diverged, and index-locked checkouts are retained untouched and recorded as non-failing refusals.

## Recovery surface measured 2026-08-15 (not covered by the original inventory)

The original inventory above (272 worktrees / 99 branch-only refs / 8 stashes) did not
cover several other places WIP survives. Measured 2026-08-15:

- 1,130 refs under `refs/rescue/*`.
- 27 entries in the worktree vault (`~/.local/state/overdeck/worktree-vault`).
- 9 stashes (original inventory above said 8 — already stale, which is the point).
- 6 `origin` `wip/*` branches.
- 577 local branches.
- 21 worktrees currently on disk.

Per-plan artifact counts (branches/rescue-refs/vault-entries per plan) are recorded at
`.../scratchpad/lost-search.json` from the same session. Largest surfaces found:

- `security-gate-containment`: 28 branches, 47 rescue refs, 1 vault entry.
- `deck-podman-network-child-lifetime`: 17 branches, 14 rescue refs.

This matters for the same reason as the rest of this plan: before treating any of this
surface as safe to delete, check it against landed `origin/main` history the way
[2026-08-15-plan-status-self-reconciling.md](2026-08-15-plan-status-self-reconciling.md)
describes — a branch with no unlanded unique commits is not lost work, and a plan marked
stale may already be shipped.
