Files
silo-server/docs/superpowers/plans
CoffeeKnyte 8a9cf04a41 docs(playback): score the serve-path fixes and record the settled decisions
The two coverage matrices and the plan's as-built deltas described GAP-10..GAP-15
as open and asserted things the code did not do. Rescored against the code as it
now stands, and made the remaining overclaims explicit rather than leaving them
to be discovered by the next reviewer.

Marked resolved with the reasoning that produced each fix: GAP-10 (ABS Unwrap),
GAP-11 (ebook observability), GAP-12 (rolling-deadline cut latch, pulled forward
from the revocation batch because it makes GAP-10's fix inert), GAP-13
(BytesServed merged as a max). GAP-14 and GAP-15 stay open with their batch and,
for GAP-14, decision A7 attached.

Two claims are called out as STILL FALSE wherever they appear, so the blanket
phrasing does not creep back: the kill switch does not "keep a stream dead" (an
over-cap kill reopens after 5m until A1 lands) and monitoring does not "never
trust client progress" (the LastActivityAt fallback survives until A5 lands).

Documents a bound the plan never stated: the in-flight watcher polls, so a cut
lands within one interval -- 5s in production -- not instantly. Every "cut" claim
in these docs now says so.

Corrects two pieces of stale guidance that would have misled the next
implementer. Follow-up 0b said to reuse guardRevocationCut for the ebook routes:
that wrapper keys on a session_id URL param and an ?st= token those routes do not
carry, so it compiles and silently guards nothing. Follow-up 0c suggested a
sticky flag on RollingDeadlineWriter: unreachable as written, because the rolling
writer is constructed inside the serve helpers and wraps the writer the watcher
holds, so Unwrap() -- which walks toward the socket -- can never reach it.

Records decisions A1-A8 in one table so the follow-up issues inherit them, plus
one new finding for the A3 batch: streamRequestIdentity verifies a stream token's
signature but never checks its SessionID against the URL's session_id.

Expands the AI-use disclosure to the standard docs/ai-contributions.md requires:
tool, exact model IDs, involvement classification, and the adversarial findings
and resolution from both directions of the cross-model review -- including the
five defects found in the AI implementation and the one found in the AI review of
it. Also states plainly that pnpm is absent on the host used for this round, so
frontend evidence must come from CI, and that the jellycompat test package does
not compile on main, so the compat changes here are verified by reading only.

Part of #305.
2026-07-30 08:37:22 +00:00
..