01-projects/printables-product/reviews

charter kill criteria hardening check

Reviewed: charter (org table/QA gate map lines 39-77; §8c line 430; kill-criteria lines 19,409); charter-rebaseline-draft.md (status: pending-founder); queue/rounds/escalations tails; 4 sw-*-handoffs; gh pr list #76-95 (author/mergedBy/baseRefName).

Findings

  1. Kill criteria: dormant, correctly (charter:19,409) — no "launched," no non-family download signal seen. No early flag.

  2. §8c breaker: never tripped — every closed round (rounds.md:57,104,135,180) logged "0 consecutive gate failures." Fleet's first live night (09-05) had two real but single, non-consecutive gate issues, both handled honestly (rounds.md:171,185) — the 2-consecutive threshold itself is untested, so no evidence it's miscalibrated. Tonight's Fable spend-limit 429s (escalations.md #33, "blocked by billing limit, not a gate failure") are infra, not QA. Charter:430 ("2 consecutive artifacts fail their gates") arguably already excludes pre-gate 429s, but only by inference — and escalations.md warns this failure class "will keep tripping" until the cap resets. Recommend making the carve-out explicit.

  3. Org drift: rounds.md:185 flagged handoffs as stale ("still say ONE artifact per round"). Confirmed FIXED — all 4 current handoffs (timestamped 09-05 09:37) read "up to FOUR artifacts per round," bundled into that morning's release-branch update (queue.md:268). No open drift.

  4. Release flow: every PR merged since the 09:37 ET branch cut, checked via gh pr list. Only post-cut PR targeting main is #93 — headRef release, merged by the founder — the sanctioned release→main ship, not drift. All others (#85-#92,#94,#95) correctly targeted release. Clean since shipping.

  5. Security: PR #95 ("Fix household authorization, tray isolation, and privacy copy") merged to release 8 minutes before #93 shipped release→main — the HOLD was heeded fast. But Codex named FOUR P0s (codex review, line 12); P0-1 ("mixed migration directory," line 163) isn't in #95's scope. Verified directly against origin/main: wrangler.toml:266-270 (UGC db) and wrangler-accounts-preview.toml:17-21 (accounts-preview db) both still set migrations_dir = "migrations" — the same directory, guarded only by a warning comment, no structural fix. This is NOT new: it was already queued 2026-09-02 (queue.md:225, "split the dirs before any further migration") and never done. Codex's review just re-confirms it's still open and calls it P0 severity — worth a priority bump, not a new ticket. QA gate map (62-70) has no security row today; this was a one-off founder-ordered review, not a standing gate.

Proposed queue.md change

Bump queue.md:225 (existing S item, "wrangler.toml: UGC and accounts DBs share migrations_dir") to P0/blocking — re-confirmed live on main by an independent security review, not just a hygiene nit. No new item needed; it was already tracked.

Decisions needed (not mine to apply)