feat(routing)!: autorouting with policy-derived tiers, preset layer removed - #4543
feat(routing)!: autorouting with policy-derived tiers, preset layer removed#4543Yeachan-Heo wants to merge 53 commits into
Conversation
daca464 to
874c59f
Compare
Draft hold — reconciliation evidence vs current dev and #4561Recorded heads before any action (exact-head discipline): this draft PR head Reconciliation findings1. Absorption by dev: none. 0 of the 30 PR commit patch-ids appear in dev since the base; dev contains no 2. Textual conflicts vs current dev: exactly 1 file, mechanical. A real trial merge of this PR head into dev 3. Overlap with #4561 (oMLX presets): 4 files, 1 real conflict. Trial merge of #4561 onto this PR's head conflicts only in 4. Not supersession — disjoint preset layers. The breaking removal here ( 5. Residual semantic risk. #4561's thinking-level fallback changes the same resolution path this PR's routed Owner decision (blocking)
This lane stays an explicitly owned draft hold: not marked ready, not pushed, not merged, not closed. All merge trials ran in throwaway worktrees and were aborted; no branch or ref was mutated. — gaebal-gajae |
Evidence refresh — dev advanced to
|
OWNER-CONTROLLED DRAFT HOLD — verdict + evidence update (needs-human)Verdict: NEEDS-HUMAN — owner decision required. Bound to the submitted PR digest via Conflict / supersession matrix (recomputed against exact
|
| Surface | Result |
|---|---|
| Absorption of this PR by dev | 0 of 30 commit patch-ids in dev since base; 0 autorouting files/symbols anywhere on 96e718a2 |
This PR → dev 96e718a2 trial merge |
1 conflict file: scripts/telegram-daemon-generation-manifest.json (single digest hunk, createNotificationsExtension: dev 32faaf97… vs PR ba9b4354…); mechanical — regenerate digest as commit 874c59f949 did before. #4540's session-runtime.ts/CHANGELOG.md edits auto-merge with this PR's |
#4561 (49e790f4f8) → this PR head trial merge |
2 conflict files: task/executor.ts (~line 1713 explicitThinkingLevel hunk; #4561 commit bb1403448b removes it and switches to resolvedThinkingLevel ?? thinkingLevel) and telegram-daemon-generation-manifest.json (new: #4561's rebase brought manifest edits). Overlap set: model-registry.ts, model-selector.ts, executor.ts, task/index.ts, CHANGELOG.md |
| Supersession | None. Preset layers are disjoint: this PR removes only AUTOROUTING_PRESETS, AUTOROUTING_PRESET_IDS, AutoroutingPresetId, resolveTierMap, task.autorouting.preset; #4561 never touches those symbols (0 matches) and builds model-profiles() presets + oMLX provider plumbing, untouched here. Partial overlap, not replacement |
| Residual semantic risk | #4561's thinking-level fallback changes the same resolution path this PR's routed :effort selectors depend on (AUTOROUTING_SELECTOR_PATTERN → explicitThinkingLevel → effectiveThinkingLevel at executor.ts:1786) — the executor hunk must be hand-re-resolved at rebase time |
Exact owner choices (pick one)
- (a) Rebase this draft onto post-feat(ai,config): add oMLX hybrid role-optimized presets #4561 dev: 1 mechanical digest regeneration + 1 hand-re-resolved
executor.tshunk +CHANGELOG.md. Requires feat(ai,config): add oMLX hybrid role-optimized presets #4561 to merge first; until then "post-feat(ai,config): add oMLX hybrid role-optimized presets #4561 dev" does not exist. - (b) Hold as competing direction: draft stays as-is; revisit after feat(ai,config): add oMLX hybrid role-optimized presets #4561 merges or is rejected.
- (c) Close as superseded: not supported by evidence (0/30 absorbed, disjoint layers).
Lane state (unchanged by this update)
Draft, open, head 874c59f949, not pushed, not marked ready, not merged, not closed. Local worktree fast-forwarded to 96e718a2 (read-only bookkeeping; no push). All trial merges ran in throwaway worktrees, aborted and removed. Resumption of this lane requires fresh owner direction; the agent must not pick (a)/(b)/(c) on its own — choosing is a product-default decision reserved to the owner.
— gaebal-gajae
|
Correction (exact-head discipline): #4561 head moved again after the hold comment posted. Current — gaebal-gajae |
874c59f to
4b9fea8
Compare
|
Rebased onto Rebase: 29 of 30 commits replayed with no conflicts. The only conflict was the regenerable telegram digest commit, which was skipped and regenerated against the new base instead of hand-merged. Two adaptations dev forced:
Focused verification on this base: Pre-existing dev failures (unchanged conclusion, re-measured against a pristine
Still a draft for the reason #3764 was closed: the MERGE_READY bar wants green current CI, and those surfaces are red at this base independent of this branch. |
Draft CI classification at exact head
|
4b9fea8 to
d28445e
Compare
|
CI repair pushed to Fixed product blockers:
Validation on the rebased head:
Run — |
|
Additional local fresh-process evidence: — |
|
A queued affected-path regression exposed an additional PR-scope staging bug before its job terminalized. Fixed and pushed
Validation: — |
|
Terminal Dev CI classification for exact Draft head Green repaired surfaces include Telegram generation guard ( Failures are classified as:
Explicit owner-controlled Draft dependency hold: #4575 ( — |
4ead72d to
c9b6e0e
Compare
|
Rebased the owner-controlled Draft onto exact #4577 overlap review: Command Code GOAT is retained as its own bundled model profile/provider recommendation and preset. Autorouting remains policy-tier derived and does not restore the removed preset layer; no duplicate profile removal or selector collision was introduced. Focused validation: routing/model/ACP cohort 117 pass; replay/staging/Telegram cohort 162 pass; Command Code GOAT profile catalog 16 pass; provider onboarding 28 pass; coding-agent check and generation authority/current-tree validation pass.
— |
|
Terminal replacement CI classification: run Only product failure is shard-1
— |
c9b6e0e to
15f657c
Compare
|
Freshness reset completed after #4575 merged. PR #4543 is rebased onto current Semantic overlap review retained #4575 Chrome default-root repair and later detached-managed snapshot work from dev; #4543 preserves policy-derived autorouting tiers and does not restore the removed preset layer. Protected Telegram lifecycle changes were regenerated atomically at generation 170. Current evidence: routing/model/ACP/staging cohort 83 pass; replay/Telegram/browser cohort 190 pass; coding-agent check, binary build, guard authority/current-tree validation, and affected planner passed. Replacement Dev CI Honest Draft needs-human verdict: code and local verification are current, but readiness remains owner-controlled and CI must terminalize before any completion assessment. The obsolete #4575 dependency hold is removed; the live Ultragoal G001 ledger records this current-dev hold. Draft remains Draft: no Ready, approval request, merge, close, release, or tag action. — |
15f657c to
1152631
Compare
|
Current exact-head terminal classification for owner-controlled Draft #4543:
This remains a Draft, owner-controlled readiness hold. No review, ready transition, merge, close, release, or tag action was taken. — |
f2ade94 to
44f9e7b
Compare
|
Current-head CI failure classification for Draft #4543 (
PR #4543 remains an owner-controlled Draft with — |
Verdict: Request changesBlocking findings:
No tests or gates were run as part of this review. |
Correction / superseding verdictThe earlier review comment on this PR was based on an incorrect diff scope and is superseded. A subsequent exact-head review of Corrected verdict: Approve / no actionable findings. No tests or gates were run as part of the read-only review. |
Final correction / superseding verdictThe previous approval correction was also based on an incomplete/local diff inspection and is superseded. The live PR has 44 commits and 71 changed files at the exact head. Corrected verdict: Request changes.
No tests or gates were run as part of this read-only review. |
Additional exact-head finding
This supplements the existing P1 provider-ID case-normalization finding. Overall verdict remains Request changes. |
…settings The cleaner lane caught me repeating the exact mistake the terminal critic had just corrected: the policy-derived golden rebuilt the catalog, spelling map, and projection inline instead of calling projectCatalogProviderOrder, so it could not fail if that function broke. It now calls the shipped function, which is what ModelRegistry.autoroutingProviderOrder delegates to. The real-registry suite also only assumed the global settings singleton was uninitialized. A prior test setting modelProviderOrder would have silently reordered the expected catalog projection and made those assertions accidental, so the precondition is now reset around each test and asserted outright. Lore-id: 6a4c0e93 Constraint: a golden must exercise shipped code, never a copy of it Confidence: high Scope-risk: narrow Reversibility: clean Tested: autorouting-generator 8 pass, autorouting-provider-order 19 pass; removing the spelling restore now fails 5 across both files where it previously failed 4, proving the golden is bound to the real function
…t rebase Rebasing onto the current dev tip pulled in 44 new catalog keys the autorouting tier map has never seen, so check:autorouting-map failed closed on uncurated coverage. Record them as baseline skips with an explicit rationale rather than inventing tier/rank data nobody reviewed. Lore-id: 9d1f6b3a Constraint: an uncurated catalog key is a skip with a rationale, never a guessed tier Confidence: high Scope-risk: narrow Reversibility: clean Tested: check-autorouting-tier-map gate passed (4264 in-scope keys); autorouting suites 98 pass
…lution Removing the #writeTerminalBreadcrumb wrapper during the dev rebase left a double blank line that check:tools rejects. Kept as its own commit rather than folded into the regenerable telegram digest commit, which a later rebase skips and would have discarded this fix with it. Lore-id: 4e7a2b81 Confidence: high Scope-risk: narrow Reversibility: clean Tested: biome check across 3714 files exits 0
Managed session opens must sanitize stale OpenAI Responses metadata in memory without appending durable patches. The autorouting selector must also tolerate minimal settings adapters while retaining its provider-order listener when available.\n\nLore-id: 4543-ci-fixforward-0647\nConstraint: preserve replay safety without rewriting managed transcripts on open\nTested: focused replay, onboarding, session-storage, model-selector, and daemon guard suites\nConfidence: high\nScope-risk: narrow\nReversibility: simple
The autorouting ACP fixture closed only its connection signal, leaving its session adapter alive while broker-root cleanup removed the fixture. Register and await the owned ACP session teardown before releasing the broker lease.\n\nLore-id: 4543-ci-fixforward-0647\nConstraint: fixture roots must remain absent after teardown\nTested: repeated fresh Bun ACP notice regression\nConfidence: high\nScope-risk: narrow\nReversibility: simple
Unpublished autorouting candidates must not replace the terminal continuation breadcrumb. Publish it only when a staged candidate is finalized; give the durable staged regression its required bounded test window.\n\nLore-id: 4543-ci-fixforward-0647\nConstraint: failed candidates leave no durable discovery residue\nTested: autorouting boundary and preflight regressions; coding-agent check\nConfidence: high\nScope-risk: narrow\nReversibility: simple
SDK patches and config CLI writes could bypass nested autorouting validation, while task creation prefiltered credential failures as recoverable absences.\n\nValidate typed autorouting objects at every mutation ingress and leave credential classification to executor preflight so unexpected lookup faults fail closed.\n\nLore-id: pr4543-fixforward\nConstraint: preserve owner-controlled Draft state\nConfidence: high\nScope-risk: focused\nReversibility: revertable\nTested: focused autorouting ingress and preflight suites
Autorouting preflight resolved exact keys against the execution session instead of the distinct credential session.\n\nUse the propagated credential session identity so managed credentials remain available to pinned candidates.\n\nLore-id: pr4543-credential-scope\nConstraint: preserve fail-closed autorouting preflight\nConfidence: high\nScope-risk: focused\nReversibility: revertable\nTested: task-autorouting-preflight
Reject malformed autorouting tier maps before SDK config.patch persists them.\n\nTested: autorouting-settings-contract
Keep truthful missing-credential skips while propagating unexpected lookup errors and using the credential session scope.\n\nTested: autorouting boundary and preflight suites
Defer unexpected TaskTool credential probe failures to executor preflight so routing receipts remain fail-closed and auditable.\n\nTested: autorouting preflight, integration, boundary suites
Root TypeScript validation requires the optional credential session argument to exclude null.\n\nTested: ci-dev-affected root-check
Carry TaskTool credential lookup exceptions into the authoritative preflight ledger instead of retrying and losing one-shot failures.\n\nTested: routing preflight, integration, and boundary suites
Ensure TaskTool transfers an observed credential lookup fault into executor preflight without retrying it.\n\nTested: routing preflight, integration, boundary suites
Use Map presence rather than value truthiness so every captured JavaScript throw reaches terminal preflight evidence.\n\nTested: routing preflight, integration, boundary suites
…nsensitively Review P1: task.autorouting.setup accepts provider ids in arbitrary casing, but tier generation matched provider prefixes and catalog keys with exact case-sensitive startsWith, so a hand-edited providers: ["OpenAI"] against openai/... keys silently produced empty fast/balanced/strong tiers while autorouting stayed enabled. Comparison now normalizes both sides while persistence keeps catalog spelling, and provider de-duplication plus the allowlist run on normalized ids so two spellings of one provider cannot double-declare or filter past each other. Lore-id: a7c3e1f2 Constraint: selectors must stay catalog-spelled in persisted tiers Tested: mixed-case setup/allowlist/dedup generator regressions Confidence: high Scope-risk: narrow Reversibility: trivial
Review P2: AUTOROUTING_SELECTOR_PATTERN accepted arbitrarily long model ids while assertRoutingEvidenceInvariant rejects an effectiveModel or requestedSelector longer than 256 characters, so a routed custom model id could execute successfully and then fail during routing-evidence finalization. The shared AUTOROUTING_SELECTOR_MAX_LENGTH constant now enforces the same bound at validation time, so no accepted selector can be rejected after execution. Lore-id: b8d4f2a3 Constraint: invariant in task/types.ts and grammar must share one bound Tested: over-long selector rejected at config time; 200-char accepted Confidence: high Scope-risk: narrow Reversibility: trivial
…card Review P1: the managed durable preflight adopted its attempt staging twice -- once inside ManagedTaskPersistence.openStagedSession() and again through the generic preflightDurable branch in runSubprocessOnce -- leaving the first manager unreachable from commit/discard so managed autorouting retries could orphan staging roots. Generic adoption is now conditional on !options.managedPersistence, and commitStaged/discardStaged fail closed when a staging manager with a foreign attempt id was adopted over the publication's own root. Lore-id: c9e5a3b4 Constraint: fail closed, never silently skip, on root mismatch Tested: double-root commit and discard regressions; single-root lifecycle Confidence: high Scope-risk: moderate Reversibility: moderate
…keys Review P2: the tier-map gate accepted skip entries with empty rationales, malformed keys, out-of-catalog keys, and keys that were both labeled and skipped, so future catalog additions could bypass curation behind a stale skip entry. The gate now enforces selector grammar, non-empty rationale, catalog scope, and label/skip exclusivity, which surfaced five genuinely dead baseline keys (lowercase minimax-m3 spellings plus a nonexistent minimax-v3) that are removed rather than carried as permanent skips. Lore-id: d0f6b4c5 Tested: four new gate rejection cases; gate green at 4272 in-scope keys Confidence: high Scope-risk: narrow Reversibility: trivial
…contracts The boundary red-team suite pinned the old contract where an over-long tier selector produced no local validation issue and only the executor's evidence bounding stood between it and finalization. With the grammar now capped at the routing-evidence bound, the over-long entry fails closed at validation time, so the hostile-selector case asserts the early rejection while the control-only/traversal/homoglyph shapes still flow to executor sanitization, and the shared skip-projection case stays under the grammar bound so the 16/4 aggregation remains the exercised bound. Lore-id: e1a8c5d6 Tested: autorouting-boundary-redteam 41 pass Confidence: high Scope-risk: narrow Reversibility: trivial
…ants Independent-review hardening (architect approve, zero P1s, three recommendations applied): - AUTOROUTING_SELECTOR_MAX_LENGTH is now imported and reused by the routing-evidence invariant (task/types.ts), the receipt bounding (task/receipt.ts), and executor boundedSelector, so the grammar and every post-execution bound share one constant by reference instead of four coincidental 256 literals. - commitStaged/discardStaged require strict attempt-root equality while a staged publication is uncommitted: an adopted manager that is absent or foreign fails closed, closing the released/id-less adoption hole. - the tier-map gate reports both-labeled-and-skipped keys as invalid skips (matching its remediation text) instead of folding them into stale skips. Lore-id: f2b9c6d7 Tested: tier-map gate green (4272 in-scope, 3927 baseline); gate/preflight/settings suites 52 pass Confidence: high Scope-risk: narrow Reversibility: trivial
Align selector grammar, generated tiers, schema, evidence, and summary rendering so malformed routing data fails closed without prompt-boundary injection. Preserve text-capable multimodal catalog coverage and make sessionless preflight acceptance explicit. Tested: coding-agent check; focused autorouting, schema, daemon-guard, and affected integration suites Not-tested: Windows native AVX2 fallback and unrelated packages/ai baseline failures Confidence: high Scope-risk: wide Reversibility: revertable
Do not infer durable preflight publication authority from a shared artifact manager when no session file or managed persistence exists. Align generated selector schemas with the runtime length and role-alias contract. Tested: coding-agent check; preflight, red-team, settings-contract, and schema-generation tests Confidence: high Scope-risk: wide Reversibility: revertable
Reuse the shared thinking suffix parser when preflighting routed candidates so :max, :inherit, and :off selectors cannot be discarded as snapshot misses. Tested: coding-agent check; autorouting task, preflight, and red-team suites Confidence: high Scope-risk: medium Reversibility: revertable
…itor container Dev's composer-detach hardening (#4687) made SelectorController.showSelector detach the reusable editor before clearing its container, so overlay opens no longer terminally dispose the composer. The smart-routing panel integration fixture predates that call site and its editorContainer double lacked detachChild, so every panel test died on TypeError before asserting anything. Add the missing no-op to the double, matching the established mock shape in the sibling model-selector suites. Reconciliation-only change while rebasing the approved autorouting lane (b9a6992) onto dev fd70094; runtime autorouting behavior is untouched. Lore-id: pr4543oxv1 Constraint: preserve the reviewed autorouting contract byte-for-byte Tested: bun test packages/coding-agent/test/model-selector-smart-routing.integration.test.ts (17/17) Confidence: high Scope-risk: none Reversibility: trivial
b9a6992 to
349e04c
Compare
Round 3 reconciliation onto current dev
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 349e04c7d0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const sessionManager = options.preflightProbe | ||
| ? SessionManager.inMemory(worktree ?? cwd) |
There was a problem hiding this comment.
Keep disposable preflight probes from running extensions
When autorouting evaluates an initial task, this new probe branch creates a complete agent session and continues through extension initialization and session_start emission before deliberately discarding the probe at the provider fence; the durable attempt then repeats the same bootstrap. With subagent extensions enabled, every accepted candidate therefore runs startup hooks twice—and rejected candidates can run them repeatedly—so hooks that write files, mutate settings, send messages, or call external services produce duplicate side effects. Make the probe bootstrap side-effect-free or reuse the probed session for the durable attempt.
Useful? React with 👍 / 👎.
| return this.#reportSmartRoutingValidationError(error); | ||
| } | ||
| return this.#runSmartRoutingIntent("Apply", async () => { | ||
| await this.ctx.settings.commitAtomicBatchWithCurrent(() => |
There was a problem hiding this comment.
Recheck hand edits inside the locked settings transaction
When another GJC process edits the stored tiers after #assertSmartRoutingNotHandEdited() runs but before this atomic operation acquires the config lock, Apply silently overwrites that edit without the required confirmation. commitAtomicBatchWithCurrent() supplies the lock-current YAML specifically for this case, but the callback ignores it; validate the current tiers/provenance inside that callback (and do the same in Refresh) before returning replacement patches.
Useful? React with 👍 / 👎.
probepark
left a comment
There was a problem hiding this comment.
Delta review at exact head 349e04c7 — approved. Prior autorouting approval remains valid.
67 of 71 approved autorouting surface blobs are identical. The four differences are dev package/changelog integration, generic composer detach-before-clear calls, and a one-line test-double update adding detachChild. Core routing, selector resolution, credential preflight, task execution, staged persistence, schemas, and evidence are unchanged.
No concrete wrong-model routing, trust issue, data loss, or durable wedge found.
Reviewed by @probepark — method: exact blob comparison against approved b9a6992c; only reconciliation delta reviewed.
gajae.pr-review-verdict.v1 merge-approved sha256:8efd4c975a9ffbf24b45b3cf0397f16f251598f48a298cd7497310464bdcd23a reviewer:human reviewer-id:probepark evidence:exact-head-349e04c7-autorouting-reconciliation-only
gajae.pr-review-verdict.v1 merge-approved sha256:8efd4c975a9ffbf24b45b3cf0397f16f251598f48a298cd7497310464bdcd23a reviewer:human reviewer-id:probepark evidence:exact-head-349e04c7-autorouting-reconciliation-only
high-riskScope
Breaking autorouting/preset-removal change for Task subagents. Autorouting remains opt-in (
task.autorouting.enabled: falseby default), uses the fixedfast/balanced/strongvocabulary, derives tiers from declared provider priority, and removestask.autorouting.presetrather than retaining a compatibility layer.Owner reconciliation selected the documented rebase-and-repair path. Round 2 transplanted the submitted semantic commits from
cd48850135c1b1f7072583dc227346b94b3c6367onto then-current dev. Round 3 (this head) re-transplanted the identical reviewed lane onto fresh current dev after it advanced again.Round 3 exact integration state
Rebased owned branch onto exact current
origin/devfd700948fc784f46d3427284f8e1da947cd8a10e: 52 semantic commits replayed with zero conflicts; commit subject multiset identical to the approved range.Content equality proven against the approved round-2 diff (
fa205dc5e...b9a6992ce, sha256c760c85872f3883dee5e3ae8ce029c8139056437cb459ab3dc283f9074d6d4c7): full-index diff of old vs new differs in exactly 12 lines — 2 blob index lines where dev advancedpackage.json/CHANGELOG.md, and 4 hunk-offset lines inselector-controller.ts. All added/removed content hunks are byte-identical.Auto-merged files verified to carry both sides: dev's OIDC release
test:releaseadditions plus composer-detach/SdkClient changelog entries alongside all autorouting additions.One reconciliation-only commit
349e04c7d01d7825f62888c76a16b33fe174b6d6: the smart-routing panel test double gains theeditorContainer.detachChildno-op that dev's composer-detach hardening (fix(tui): detach reusable composer before clear() at remaining overlay open paths #4687) now requires atSelectorController.showSelector; without it every panel integration test dies on TypeError before asserting. No runtime autorouting behavior changed.Repository:
Yeachan-Heo/gajae-codePR: feat(routing)!: autorouting with policy-derived tiers, preset layer removed #4543
Base branch:
devCurrent GitHub base:
fd700948fc784f46d3427284f8e1da947cd8a10eCurrent head:
349e04c7d01d7825f62888c76a16b33fe174b6d6Branch:
feat/autoroutingWorktree branch:
owner/pr-4543-ox-v1Reviewed diff SHA-256 (validator method,
git diff --binary --full-index --no-ext-diff fd700948f...349e04c7d):8efd4c975a9ffbf24b45b3cf0397f16f251598f48a298cd7497310464bdcd23aPrior approval lineage: probepark merge-approved at
cd488501(2026-08-20) and at exact headb9a6992ce(2026-08-22T01:17Z, sha256c760c858…). This verdict line is intentionallyneeds-humanuntil a fresh authenticated approval lands on exact head349e04c7d.Latest review blockers closed
schemas/config.schema.json.tier,effectiveModel, andnotevalues are NFKC-normalized, control/line-separator sanitized, bounded, then XML-escaped before thenoEscapetask-summary template.:max,:inherit, and:off, with regressions covering both cases.openai/gpt-image-2andopenai-codex/gpt-image-2entries are explicitly baseline-skip-listed with rationale.Unreleased.ReturnType<>and inline type imports with concrete/top-level types.Verification (round 3 lane)
Passed locally on exact head
349e04c7d:bun --cwd=packages/coding-agent run check(biome + tsc clean)bun run generate-schemasleavesschemas/+types/clean;check:autorouting-mapgate passed (4274 in-scope keys, 3929 baseline skips)--validate-current-tree; gjc-state-gates static/runtime/integrity/read all passedcheck-visible-definitions,verify-g002-gates,rebrand-inventory --strict, default-GJC-definitions suitebun scripts/verify-gjc-state-writers.ts --fail: 0 write sites outside sanctioned writersKnown unrelated baseline reds (identical on dev's own CI run #15848, not attributable to this diff):
@gajae-code/aimodel-manager context-cap metadata, sdk-broker lifecycle e2e exit-134 pair, issue-4508.gjchome-fixture cleanup, perf-corpus RLM driver admission. These are being fixed dev-side through a separate auxiliary PR so this PR's affected validation can go green without widening the reviewed autorouting contract.Merge gate
This PR is not represented as merge-ready until an independent authenticated approval is posted on exact head
349e04c7d01d7825f62888c76a16b33fe174b6d6. No release, tag, publish, ormainmutation is part of this change.— gaebal-gajae