Skip to content

Unify Builder and Thing sharing audiences - #683

Merged
lopugit merged 8 commits into
developfrom
codex/unified-builder-thing-sharing
Sep 8, 2026
Merged

Unify Builder and Thing sharing audiences#683
lopugit merged 8 commits into
developfrom
codex/unified-builder-thing-sharing

Conversation

@lopugit

@lopugit lopugit commented Sep 7, 2026

Copy link
Copy Markdown
Owner

✅ Develop S3 preview ready

The alias passed the develop bucket CORS preflight and a final live PR/SHA fence.

Generic Vercel Preview deployments use the shared development runtime; this controller adds the stable exact-SHA alias and marker-scoped cleanup.

Summary

  • reuse the post ACL grammar and custom audience picker across Builder pages, component version saves, and general Things
  • add key-aware hidden-link readers for standalone pages and universal Thing links without caching bearer-key reads
  • publish the additive webpages-resolve capability contract and refresh Graphify outputs

Validation

  • focused ACL, Builder, Things, audience-cancel, and capability tests: 29 passed
  • focused ESLint: 0 errors (5 existing ThingsPage hook warnings)
  • typecheck ratchet: 108 errors, at baseline
  • full Vercel-shaped build and output verification: passed

Depends on and is based on merged PR #613.

@lopugit

lopugit commented Sep 7, 2026

Copy link
Copy Markdown
Owner Author

🧹 Develop S3 preview removed

The PR-specific alias and every workflow-created develop deployment were removed when this PR closed.

The ordinary generated Vercel Preview remains available on the shared development runtime.

@lopugit lopugit added the preview: develop building tt-preview-state:v1:develop:building label Sep 7, 2026
@github-actions github-actions Bot added the lopu: mergeable The PR branches can currently be merged without conflicts label Sep 7, 2026
@lopugit
lopugit temporarily deployed to develop-pr-683 September 7, 2026 06:11 Destroyed
@lopugit lopugit added last preview built 08/09 19:40 AEST #683 tt-pv1:683:develop:73a49242c663b59387e5cecaff0e3fd7c719415d:1788860453741 preview: develop ready tt-preview-state:v1:develop:ready and removed preview: develop building tt-preview-state:v1:develop:building labels Sep 7, 2026
github-actions Bot added a commit that referenced this pull request Sep 7, 2026
# Conflicts:
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/cost.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/graph.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/manifest.json
@github-actions github-actions Bot added the lopu: queued The current PR snapshot is waiting in Lopu's PR-management queue label Sep 7, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

🤖 Lopu detected an out-of-date PR branch

Status: Work detected — Lopu is taking ownership.

Current phase: Entering Lopu's serialized PR-resolution queue.

Estimated completion: around 07:12 UTC (~20 minutes; this adjusts as the queue moves).

Next automatic check-in: within 10 minutes while work remains active. You can stay on this PR; there is no need to find the Actions run.

Time conversion (UTC source)

Moment UTC Los Angeles Melbourne
Updated 2026-09-07 06:52 UTC (UTC+00:00) 2026-09-06 23:52 PDT (UTC-07:00) 2026-09-07 16:52 AEST (UTC+10:00)
Estimated finish 2026-09-07 07:12 UTC (UTC+00:00) 2026-09-07 00:12 PDT (UTC-07:00) 2026-09-07 17:12 AEST (UTC+10:00)

Los Angeles and Melbourne use their real IANA time zones, so PDT/PST and AEST/AEDT offsets change automatically.

Lopu queue and PR pulse

Scope Metric Count
Repository Open PRs 27
Repository Conflicting 4
Repository Out-of-date with target 8
Repository GitHub state unknown 4
Repository Part of an open stack 2
Repository Touch files changed by another open PR 20
Repository Target a non-root branch without an open parent PR 0
This resolver batch Admitted snapshots 7
This resolver batch Currently resolving 0
This resolver batch Waiting 7
This resolver batch Finished 0

Related PR context

  • Stack: No open parent or child PR currently links to this branch.
  • Target: develop is a repository root/integration branch.
  • Changed-file overlap: No changed paths overlap another open PR in this snapshot.

Exact branch pair: developcodex/unified-builder-thing-sharing.

Timeline

  • 06:52 UTC — Detected that develop needs to be merged into codex/unified-builder-thing-sharing; assigning the exact snapshot to the resolver queue.

@github-actions github-actions Bot removed the lopu: queued The current PR snapshot is waiting in Lopu's PR-management queue label Sep 7, 2026
@github-actions github-actions Bot added lopu: unknown state GitHub is still computing the PR branch state lopu: queued The current PR snapshot is waiting in Lopu's PR-management queue and removed lopu: mergeable The PR branches can currently be merged without conflicts labels Sep 7, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

🤖 Lopu detected an out-of-date PR branch

Status: Work detected — Lopu is taking ownership.

Current phase: Entering Lopu's serialized PR-resolution queue.

Estimated completion: around 07:40 UTC (~20 minutes; this adjusts as the queue moves).

Next automatic check-in: within 10 minutes while work remains active. You can stay on this PR; there is no need to find the Actions run.

Time conversion (UTC source)

Moment UTC Los Angeles Melbourne
Updated 2026-09-07 07:20 UTC (UTC+00:00) 2026-09-07 00:20 PDT (UTC-07:00) 2026-09-07 17:20 AEST (UTC+10:00)
Estimated finish 2026-09-07 07:40 UTC (UTC+00:00) 2026-09-07 00:40 PDT (UTC-07:00) 2026-09-07 17:40 AEST (UTC+10:00)

Los Angeles and Melbourne use their real IANA time zones, so PDT/PST and AEST/AEDT offsets change automatically.

Lopu queue and PR pulse

Scope Metric Count
Repository Open PRs 29
Repository Conflicting 4
Repository Out-of-date with target 6
Repository GitHub state unknown 4
Repository Part of an open stack 2
Repository Touch files changed by another open PR 22
Repository Target a non-root branch without an open parent PR 0
This resolver batch Admitted snapshots 7
This resolver batch Currently resolving 0
This resolver batch Waiting 7
This resolver batch Finished 0

Related PR context

  • Stack: No open parent or child PR currently links to this branch.
  • Target: develop is a repository root/integration branch.
  • Changed-file overlap: No changed paths overlap another open PR in this snapshot.

Exact branch pair: developcodex/unified-builder-thing-sharing.

Timeline

  • 07:20 UTC — Detected that develop needs to be merged into codex/unified-builder-thing-sharing; assigning the exact snapshot to the resolver queue.

@github-actions github-actions Bot added lopu: mergeable The PR branches can currently be merged without conflicts lopu: queued The current PR snapshot is waiting in Lopu's PR-management queue and removed lopu: unknown state GitHub is still computing the PR branch state lopu: queued The current PR snapshot is waiting in Lopu's PR-management queue labels Sep 7, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

🤖 Lopu detected an out-of-date PR branch

Status: Work detected — Lopu is taking ownership.

Current phase: Entering Lopu's serialized PR-resolution queue.

Estimated completion: around 08:09 UTC (~20 minutes; this adjusts as the queue moves).

Next automatic check-in: within 10 minutes while work remains active. You can stay on this PR; there is no need to find the Actions run.

Time conversion (UTC source)

Moment UTC Los Angeles Melbourne
Updated 2026-09-07 07:49 UTC (UTC+00:00) 2026-09-07 00:49 PDT (UTC-07:00) 2026-09-07 17:49 AEST (UTC+10:00)
Estimated finish 2026-09-07 08:09 UTC (UTC+00:00) 2026-09-07 01:09 PDT (UTC-07:00) 2026-09-07 18:09 AEST (UTC+10:00)

Los Angeles and Melbourne use their real IANA time zones, so PDT/PST and AEST/AEDT offsets change automatically.

Lopu queue and PR pulse

Scope Metric Count
Repository Open PRs 28
Repository Conflicting 5
Repository Out-of-date with target 8
Repository GitHub state unknown 4
Repository Part of an open stack 2
Repository Touch files changed by another open PR 18
Repository Target a non-root branch without an open parent PR 0
This resolver batch Admitted snapshots 7
This resolver batch Currently resolving 0
This resolver batch Waiting 7
This resolver batch Finished 0

Related PR context

  • Stack: No open parent or child PR currently links to this branch.
  • Target: develop is a repository root/integration branch.
  • Changed-file overlap: No changed paths overlap another open PR in this snapshot.

Exact branch pair: developcodex/unified-builder-thing-sharing.

Timeline

  • 07:49 UTC — Detected that develop needs to be merged into codex/unified-builder-thing-sharing; assigning the exact snapshot to the resolver queue.

@github-actions github-actions Bot removed the lopu: queued The current PR snapshot is waiting in Lopu's PR-management queue label Sep 7, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Lopu review — PR #683 @ 55239027

Both red checks are explained, and both are fixed at their cause. Changes are staged in my review worktree for the trusted publisher.


1. Unit tests — a real defect in this PR ✅ fixed

lopuBuildBridge.test.ts"mergeSavedWebpage adopts the saved page as the viewer-owned resolved page":

+ linkKey: undefined,
AssertionError [ERR_ASSERTION]: Expected values to be strictly deep-equal

In useWebpage.ts, mergeSavedWebpage ended with:

...(savedAclPresent ? { linkKey } : linkKey ? { linkKey } : {})

When a save carries an acl but no linkKey — the ordinary "page is public now" case — that spreads { linkKey: undefined }, materialising an own linkKey property. deepEqual (strict) counts own-property presence, so the merged page stopped matching a page that never had a key.

The branch wasn't pointless: ...(prev?.page || {}) carries a stale key forward, so an explicit override was genuinely needed to revoke it. The fix keeps that revocation but drops the key from the carried base instead of overwriting it with undefined:

const { linkKey: _supersededLinkKey, ...carried } = prev?.page || {};
...
...carried,
...(linkKey ? { linkKey } : {})

All three behaviours survive: a saved key is adopted, a save carrying an acl without a key revokes it, and a partial save with no acl keeps it. Your new saved webpages adopt and clear owner-only hidden-link keys with their ACL test still passes unchanged.

2. CodeQL — not an alert, and not a controller bug ✅ addressed at its cause

The check reads timed_out / "1 configuration not found: /language:javascript-typescript". The timeline:

event UTC
/language:actions uploaded (0 results) 06:09:21
aggregate CodeQL check opened 06:09:20
aggregate check closed timed_out 06:09:32
/language:javascript-typescript uploaded (12 results) 06:15:53

Both configurations analysed fine for refs/pull/683/merge — the check was just finalised 6m21s before the second one existed and never re-evaluated. Exactly one run owned the analysis (34089507431), so there was no duplicate-scan race and nothing to fix in .github/workflows/**.

What did come from this PR is the slowdown that widened the gap:

PR javascript-typescript analysis check
#680 3m24s
#681 3m02s
#682 2m52s
#683 7m31s timed_out

No CodeQL alerts are open on this head, so nothing was dismissed and no disposition was recorded.

3. Graphify snapshot retention ✅ fixed (and the cause of #2)

The Auto-merged main into codex/unified-builder-thing-sharing commit unioned branch snapshots, so the tree carried two portable snapshots — graph.json at 58,701,355 B and 57,149,465 B — roughly doubling the JSON the CodeQL extractor walks. That tracks the ~2.4× slowdown above.

That's the exact case graphify-cas.test.mjs documents ("a merge unions branch snapshots and pruning restores the retention bound"); the post-merge prune just hadn't run. Rather than hand-delete, I ran the repo's own selectSnapshot + pruneSnapshots at the default retention of 1:

active   = …/95196e45…/9f49f42a…  nodes=40108 links=100054
retained = …/95196e45…/9f49f42a…
removed  = …/94433d17…/a72fe54e…  (nodes=40008)

Your fresher snapshot is kept, develop's superseded one is dropped (~56 MB), and the documented one-snapshot invariant is restored. Pruning is branch-local and safe by the doc's own statement — develop keeps its snapshot on its own ref.


On the feature itself

The hidden-link bearer-key path is the risky part and it reads as sound. withLinkKeys trims and drops empty keys (a blank ?key= can't match) and synthesises an anonymous viewer as { id: '' } — safe, because every owner comparison guards on viewer?.id truthiness first, so a key-bearer can never be mistaken for an owner with a falsy id. Acceptance requires a non-empty doc.linkKey, exact membership, and that the acl still includes tt:hidden, so un-hiding retires shared links immediately; it also runs after the PAT visibility fence, so a scope-limited token can't be widened by presenting a key. linkKey is only echoed back to the owner. Replacing the isPublic boolean with an explicit acl?: string[] also removes the old read-modify-write that could clobber a concurrently-changed acl — good direction.

Two non-blocking notes:

  1. save() still writes ...(nextLinkKey ? { linkKey: nextLinkKey } : { linkKey: undefined }). That one spreads over ...prev.page! so the clearing is correct, but it leaves the same undefined-valued own property that broke the merge test. Nothing deep-compares it today; worth aligning if a test ever asserts that shape. I left it rather than churn a passing path.
  2. Even at baseline there's a ~2-minute window between the fast actions upload and the slow javascript-typescript one where GitHub could finalise the aggregate check early. [Promote][things-tokens #1] feat(things,tokens): re-land hidden 🕵️ links + PAT GET bridge + custom audiences 🎭 (#413/#431 never reached develop) (#613) #680Manage Desktop Node lifecycle and refresh privacy access reliably #682 are green at that gap so it's tolerated in practice, and I did not treat it as a controller defect. If it ever recurs on a PR without an inflated tree, staging the matrix so the slow language uploads first is the thing to look at.

Validation

Ran against the edited source (worktree has no node_modules; real files run under tsx with only unrelated UI packages stubbed):

  • lopuBuildBridge.test.ts18/18 pass
  • app/components/Builder/*.test.ts54/54 pass
  • fix reverted in a scratch copy → reproduces + linkKey: undefined exactly as CI did
  • scripts/graphify-cas.test.mjs after the prune — 21/21 pass

webpageAttachments.test.ts couldn't run in my sandbox (Cannot find module 'mongodb') — harness limitation, not a code failure; CI only ever reported the single lopuBuildBridge failure.

— Lopu

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Lopu repository review

Lopu reviewed this PR against develop as Thingtime's principal PR and repository manager. Using Claude Opus 5.

Lopu made justified improvements and pushed 71f8589 to codex/unified-builder-thing-sharing.

Lopu review — PR #683 · Unify Builder and Thing sharing audiences

codex/unified-builder-thing-sharing @ c36c23ccdevelop @ d49e2d5a

What I compared

Full head against the target base (61 files; ~+3.6k/−455 lines of source, the
rest Graphify snapshot churn). I read the whole audience/ACL change end to end
rather than sampling it:

  • Grammar coreapp/schemas/registry.ts (tt:hidden, tt:custom,
    tt:group/<id>, capability suffixes, splitCapability, aclCapabilityFor,
    sanitizeAcl normalization, MAX_ACL_ENTRIES 16→64) and
    app/components/Sharing/audienceCore.ts.
  • Enforcementapi/utils/things/things.ts: canView, withLinkKeys,
    withFriendIds, customEngageBlocks, visibilityQueryFor, circleClause,
    patVisibilityBlocksAcl/patVisibilityMatchClause, updateThing,
    upsertThing, createThing, and the toPublicPosts/toPublicThings
    projections.
  • New API surfaceroutes/api/v1/get/_get.tsx (the GET bridge),
    routes/api/v1/groups/*, api/utils/groups/groups.ts,
    api/utils/users/social.ts (groupIdsOf), api/utils/webpages/webpages.ts
    • webpages/resolve, and the Nitro import map / apiDocs registration.
  • Auth + raw-query surfaceauth/patTokens.ts (resolveGetBridgeActor,
    resolveGetBridgeSelf, the extracted resolvePatSessionActor),
    auth/patScopes.ts, auth/registerUser.ts, mongodb/queryContract.ts,
    mongodb/querySafety.ts.
  • ClientCustomAudienceModal, ThingAudienceControl, PostCard,
    PostComposer, BuilderDrawer, useWebpage, ThingsDialogs,
    ComponentDetailPage, TokenMinter, hooks/useApi, routes/{p,post,thing}.
  • Repository conventions (AI_ALL.md, FUNDAMENTALS.md §3), the three-place
    endpoint registration rule, the things index set in collections.ts, and
    the live check state on the PR.

Check state

gh pr checks 683 is fully green at this head — CodeQL, Analyze (actions),
Analyze (javascript-typescript), Build + typecheck ratchet + unit tests,
API suite (headless /tests runner), product-contract advisories, and the
control-plane routing jobs all pass; everything else is a legitimately skipped
matrix leg. No failure, cancellation, or timeout to diagnose.

CodeQL: the trusted snapshot for this head is empty ([]). No alerts to
fix and no dispositions to write, so 683.json in the dispositions directory
is left as [].

Change I made

remix/package.json — wire app/components/Sharing/*.test.ts into
test:things.

This PR adds app/components/Sharing/audienceCore.test.ts (3 tests) alongside
the new audienceCore.ts, but no npm script matched that path: test:unit
enumerates per-directory globs (app/components/Feed/*.test.ts,
app/components/Builder/*.test.ts, …) and there has never been a Sharing
entry — grep -c Sharing remix/package.json returned 0. Every other test
file the PR adds is covered by an existing glob (acl.test.ts by
test:schemas; the two Feed contract tests by test:feed;
hiddenPageContract.test.ts and useWebpage.test.ts by test:webpages), so
this one file was the only orphan.

That matters more than a normal missing-glob: audienceCore.ts is the module
whose entire purpose is keeping Builder, component versions, and generic Things
from drifting apart on the audience grammar, and its only regression test was
invisible to CI. It would have stayed green locally and silently stopped
guarding anything.

Added the glob to test:things (which already owns
app/components/Things/* and is in the test:unit chain) rather than minting a
new script, keeping the existing shape.

Validation

The worktree has no node_modules and no tsx, so I ran the suites under
Node 22's native type stripping with a small review-only resolver shim
(written to $RUNNER_TEMP, not the repo) that maps the repo's extensionless
relative TS imports:

  • Newly wired file — app/components/Sharing/audienceCore.test.ts:
    3/3 pass. It was already green; it simply never ran.
  • Glob resolution — test:things now expands to 8 files including
    app/components/Sharing/audienceCore.test.ts; package.json still parses and
    test:unit still chains test:things.
  • Re-ran the PR's other new contract tests to confirm the stated claims:
    app/schemas/acl.test.ts, Feed/audienceCancelContract.test.ts,
    Feed/hiddenLinkContract.test.ts,
    api/utils/webpages/hiddenPageContract.test.ts23/23 pass.

26/26 green. No other file in the worktree is modified.

Findings

Security and correctness — no blocking issues found

The risky parts of this change are handled correctly, and I verified each
rather than trusting the (unusually good) comments:

  • updateThing dropping ownerId from the lookup filter is the highest-risk
    edit here, and it is fenced properly: app lens → 404; non-tt:custom or
    non-viewable → 404 (no existence oracle); capability ≠ write → 403; and
    acl/visibility/folderId/tokenAcl are refused for non-owners. Storage
    ledgers still key off doc.ownerId, hasFolderChange can't be true for a
    writer, and the returned projection uses the writer's viewer, so linkKey
    can't leak through the shared-edit path. upsertThing still hard-404s on
    existing.ownerId !== ownerId, so PUT stays owner-only.
  • aclCapabilityFor floors on aclAllows — a subject holding both a
    /write grant and a same-specificity exclusion gets none, not write.
    Every current caller proves view first, so this was defensive rather than a
    live fix, but anchoring it in the function is the right call.
  • splitCapability requires a non-empty subject under the prefix, so an
    account literally named write or comment still round-trips
    (tt:user/write → subject write, cap read) instead of collapsing to the
    owner entry. parseCustomAcl in the modal mirrors that logic exactly — I
    traced both against tt:user/write and tt:user/bob/write. The '/'
    guard in createUserAccount closes the other side, and that is genuinely the
    single insertion path: service accounts slugify to [a-z0-9._-], temporary
    users are guest-<suffix>, and there is no username-change endpoint.
  • linkKey is treated as a credential, not content. It is minted at 192
    bits, re-minted on every re-entry into hidden (so retired links never
    resurrect), owner-only in both projections and gated on the acl still
    saying hidden, and it is added to MONGO_PROTECTED_THING_FIELDS — which
    means the raw-query surface refuses to filter, sort, or project it and strips
    it at every pipeline ingress. That last part is what closes the real attack:
    without it, { linkKey: { $regex: '^a' } } would be a binary-search oracle
    against the secret. Deriving protectedThingFieldSet from the shared
    constant instead of re-spelling it is the right fix for the drift risk.
  • withLinkKeys' anonymous shell ({ id: '' }) is safe: '' is falsy, so
    every viewer?.id && guard — including the two linkKey projection gates
    and the own-things clause in visibilityQueryFor — reads it as anonymous.
  • The GET bridge is the largest new attack surface and is fenced sensibly:
    cookies are never read (so a mutating GET can't ride ambient credentials),
    meta.allowGet is opt-in at mint time, scope check precedes use consumption,
    rate-limit keys mirror the normal routes, prototype-pollution keys are
    dropped on both the body and param paths over a null-prototype base, and
    responses carry no-store + no-referrer. The resolvePatSessionActor
    extraction is behaviour-preserving — the only difference is null vs
    anonymous, and each caller maps it correctly (Bearer → anonymous,
    bridge → 401).
  • Feed/search leakage. unfiltered correctly replaced the old
    wanted.length === VISIBILITIES.length shortcut; hidden/custom are
    absent from the default VISIBILITIES but present in
    REQUESTABLE_VISIBILITIES, so a dropped circle can no longer silently widen
    a filter back to everything. circleClause('private') $nins tt:hidden
    and tt:custom so they don't answer the private chip. The new grant clause
    is gated on the custom chip and then narrowed, and it's a DB superset with
    canView still judging the fetched page exactly.
  • Groups follow FUNDAMENTALS §3 (own things docs by kind, no unbounded
    embedded array), are PROTECTED_THINGTIME so generic CRUD can't mint them,
    clean up their member docs on delete (the generic cascade can't reach them,
    since targetId carries the member), and reuse the existing
    {thingtime, ownerId, createdAt, shareId} and {targetId, thingtime, …}
    indexes — no new index, as claimed. Stale tt:group/<id> entries left on
    things after a group delete are inert, since a deleted group is in nobody's
    groupIds and ids are UUIDs.

Non-blocking — for the author to decide

Usernames outside the ACL character class can't be granted.
ACL_ENTRY_PATTERN is /^-?tt:[A-Za-z0-9][A-Za-z0-9._/-]*$/, but
createUserAccount only rejects / (plus the admin reservation) — it does not
constrain the username charset. So an account named e.g. bob smith or
bob@x is registrable, and picking that person in the new custom-audience
modal composes tt:user/bob smith, which sanitizeAcl rejects. The whole save
then 400s with acl entries look like tt:all, tt:user, … — an error about ACL
syntax for what the user experiences as "I picked a friend".

The grammar predates this PR, but the picker is what first makes it reachable
from normal UI, since nothing else composed tt:user/<username> from a chosen
account.

I did not change this. The two plausible fixes are both product calls, not
review calls: widening the registerUser guard to a charset restriction
changes registration for everyone (and still wouldn't repair existing accounts),
and filtering un-grantable people out of the picker silently drops someone the
user explicitly chose, which is arguably worse than the 400. The / guard here
was clearly a considered decision with its rationale written down, so widening
it unilaterally on this branch would be scope creep on that decision. Flagging
it for a deliberate choice instead.

Two smaller notes, neither worth a change:

  • CustomAudienceModal doesn't bound the selection against
    MAX_ACL_ENTRIES (64), so a very large hand-picked audience surfaces as a
    server 400 rather than in-picker feedback.
  • listGroups/audienceSources can fan out to 64 groups × 128 members of
    resolveProfiles work in one response. Bounded and it's the caller's own
    data, so correct — just worth knowing it's the ceiling if the picker ever
    feels slow.

Verdict

The audience unification is well constructed: one grammar, enforced in one
place, with the coarse DB clause and the exact in-memory check kept
deliberately separate and the reasoning written down where the next reader will
need it. The security-sensitive edges I probed — shared-write scoping, link-key
handling as a credential, the mutating-GET bridge, and circle-filter narrowing
— all hold. My one change closes the gap between the tests this PR wrote and
the tests CI actually runs.

View Lopu workflow run

@github-actions github-actions Bot added the lopu: overlapping files This PR changes files also changed by another open PR label Sep 7, 2026
@lopugit lopugit added the preview: develop building tt-preview-state:v1:develop:building label Sep 7, 2026
@lopugit
lopugit temporarily deployed to develop-pr-683 September 8, 2026 04:40 Destroyed
github-actions Bot added a commit that referenced this pull request Sep 8, 2026
# Conflicts:
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/cost.json
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/graph.json
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/manifest.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/cost.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/graph.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/manifest.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/cost.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/graph.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/manifest.json
@github-actions github-actions Bot removed the lopu: queued The current PR snapshot is waiting in Lopu's PR-management queue label Sep 8, 2026
github-actions Bot added a commit that referenced this pull request Sep 8, 2026
# Conflicts:
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/cost.json
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/graph.json
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/manifest.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/cost.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/graph.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/manifest.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/cost.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/graph.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/manifest.json
github-actions Bot added a commit that referenced this pull request Sep 8, 2026
# Conflicts:
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/cost.json
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/graph.json
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/manifest.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/cost.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/graph.json
#	graphify-out/snapshots/v1/95196e45522305972af04a7d90d027c390f414a90a389d94a64a808fe5811acf/9f49f42aa2f34f739cf9264021eafd8ce58936c4a812cc88d2e247da6cd4f63e/manifest.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/cost.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/graph.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/manifest.json
Lopu sync resolver added 2 commits September 8, 2026 19:30
# Conflicts:
#	remix/app/components/Builder/useWebpage.ts
@lopugit lopugit added preview: develop building tt-preview-state:v1:develop:building and removed preview: develop ready tt-preview-state:v1:develop:ready labels Sep 8, 2026
@github-actions github-actions Bot added the lopu: queued The current PR snapshot is waiting in Lopu's PR-management queue label Sep 8, 2026
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

🤖 Lopu detected merge conflicts

Status: Work detected — Lopu is taking ownership.

Current phase: Entering Lopu's serialized PR-resolution queue.

Estimated completion: around 09:55 UTC (~20 minutes; this adjusts as the queue moves).

Next automatic check-in: within 10 minutes while work remains active. You can stay on this PR; there is no need to find the Actions run.

Time conversion (UTC source)

Moment UTC Los Angeles Melbourne
Updated 2026-09-08 09:35 UTC (UTC+00:00) 2026-09-08 02:35 PDT (UTC-07:00) 2026-09-08 19:35 AEST (UTC+10:00)
Estimated finish 2026-09-08 09:55 UTC (UTC+00:00) 2026-09-08 02:55 PDT (UTC-07:00) 2026-09-08 19:55 AEST (UTC+10:00)

Los Angeles and Melbourne use their real IANA time zones, so PDT/PST and AEST/AEDT offsets change automatically.

Lopu queue and PR pulse

Scope Metric Count
Repository Open PRs 27
Repository Conflicting 6
Repository Out-of-date with target 0
Repository GitHub state unknown 4
Repository Part of an open stack 2
Repository Touch files changed by another open PR 23
Repository Target a non-root branch without an open parent PR 0
This resolver batch Admitted snapshots 1
This resolver batch Currently resolving 0
This resolver batch Waiting 1
This resolver batch Finished 0

Related PR context

  • Stack: No open parent or child PR currently links to this branch.
  • Target: develop is a repository root/integration branch.
  • Changed-file overlap: 8 changed files are also touched by #10, #295, #557, #564, #590, #595, #602, #607, #611, #638, #662, #665, +2 more.

Exact branch pair: developcodex/unified-builder-thing-sharing.

Timeline

  • 09:35 UTC — Detected conflicts between develop and codex/unified-builder-thing-sharing; assigning the exact snapshot to the resolver queue.

@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

🤖 Lopu live PR update

Status: ✅ Lopu finished — this PR is closed or merged

Current phase: The resolver branch work is complete

Estimated completion: Done — no further active-work ETA.

Time conversion (UTC source)

Moment UTC Los Angeles Melbourne
Updated 2026-09-08 10:07 UTC (UTC+00:00) 2026-09-08 03:07 PDT (UTC-07:00) 2026-09-08 20:07 AEST (UTC+10:00)

Los Angeles and Melbourne use their real IANA time zones, so PDT/PST and AEST/AEDT offsets change automatically.

Lopu queue and PR pulse

Scope Metric Count
Repository Open PRs 25
Repository Conflicting 5
Repository Out-of-date with target 8
Repository GitHub state unknown 4
Repository Part of an open stack 2
Repository Touch files changed by another open PR 23
Repository Target a non-root branch without an open parent PR 0
This resolver batch Admitted snapshots 1
This resolver batch Currently resolving 0
This resolver batch Waiting 0
This resolver batch Finished 1

Related PR context

  • Stack: No open parent or child PR currently links to this branch.
  • Target: develop is a repository root/integration branch.
  • Changed-file overlap: 8 changed files are also touched by #10, #295, #557, #564, #590, #595, #602, #607, #611, #638, #662, #665, +2 more.

Exact branch pair: developcodex/unified-builder-thing-sharing.

Timeline

  • 09:35 UTC — Detected conflicts between develop and codex/unified-builder-thing-sharing; assigning the exact snapshot to the resolver queue.
  • 09:36 UTC — The immutable head/base selection is reserved; waiting for its worker job to enter the serialized lane.
  • 09:36 UTC — Still safely queued behind earlier admitted Lopu work; no duplicate resolver was spawned.
  • 09:37 UTC — Still safely queued behind earlier admitted Lopu work; no duplicate resolver was spawned.
  • 09:47 UTC — 10-minute check-in: still working — Waiting in Lopu's serialized PR-management lane.
  • 09:48 UTC — 10-minute check-in: still working — Waiting in Lopu's serialized PR-management lane.
  • 09:57 UTC — 10-minute check-in: still working — Waiting in Lopu's serialized PR-management lane.
  • 09:58 UTC — 10-minute check-in: still working — Waiting in Lopu's serialized PR-management lane.
  • 10:05 UTC — Working inside the isolated resolver environment.
  • 10:07 UTC — The resolver worker completed successfully and the PR is no longer open.
  • 10:07 UTC — The resolver worker completed successfully and the PR is no longer open.

Technical run details — optional; this comment is the human-facing source of truth.

@lopugit
lopugit temporarily deployed to develop-pr-683 September 8, 2026 09:35 Destroyed
@lopugit lopugit added preview: develop ready tt-preview-state:v1:develop:ready and removed preview: develop building tt-preview-state:v1:develop:building labels Sep 8, 2026
# Conflicts:
#	graphify-out/snapshots/v1/1c9a192e14eb662267aa0a284184c5def31608fcf54268ad577b1e16307e7e0f/6a18453e2dda611a3efac182903115e9b22390aa5de58e9078df06399f732987/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/1c9a192e14eb662267aa0a284184c5def31608fcf54268ad577b1e16307e7e0f/6a18453e2dda611a3efac182903115e9b22390aa5de58e9078df06399f732987/cost.json
#	graphify-out/snapshots/v1/1c9a192e14eb662267aa0a284184c5def31608fcf54268ad577b1e16307e7e0f/6a18453e2dda611a3efac182903115e9b22390aa5de58e9078df06399f732987/graph.json
#	graphify-out/snapshots/v1/1c9a192e14eb662267aa0a284184c5def31608fcf54268ad577b1e16307e7e0f/6a18453e2dda611a3efac182903115e9b22390aa5de58e9078df06399f732987/manifest.json
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/cost.json
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/graph.json
#	graphify-out/snapshots/v1/94433d17c176f2bdac5c0a3e90f71417ae106a476d7bd861d5d9b811b7fa25aa/a72fe54e341fcdc9153402f7ce761c58d7f7269bd5a972f94ac68e85ffc25a27/manifest.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/GRAPH_REPORT.md
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/cost.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/graph.json
#	graphify-out/snapshots/v1/ee04f76fce5f4c1bd59095b93a6fd734fa837f598813724f39638b4d01722954/fe2f568053e68e6a5b83948cc344de498b028e2e6b34973449a7848ad8b293ba/manifest.json
#	remix/package.json
@lopugit lopugit added preview: develop building tt-preview-state:v1:develop:building and removed preview: develop ready tt-preview-state:v1:develop:ready labels Sep 8, 2026
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

🤖 Lopu detected merge conflicts

Status: Work detected — Lopu is taking ownership.

Current phase: Entering Lopu's serialized PR-resolution queue.

Estimated completion: around 09:57 UTC (~20 minutes; this adjusts as the queue moves).

Next automatic check-in: within 10 minutes while work remains active. You can stay on this PR; there is no need to find the Actions run.

Time conversion (UTC source)

Moment UTC Los Angeles Melbourne
Updated 2026-09-08 09:37 UTC (UTC+00:00) 2026-09-08 02:37 PDT (UTC-07:00) 2026-09-08 19:37 AEST (UTC+10:00)
Estimated finish 2026-09-08 09:57 UTC (UTC+00:00) 2026-09-08 02:57 PDT (UTC-07:00) 2026-09-08 19:57 AEST (UTC+10:00)

Los Angeles and Melbourne use their real IANA time zones, so PDT/PST and AEST/AEDT offsets change automatically.

Lopu queue and PR pulse

Scope Metric Count
Repository Open PRs 27
Repository Conflicting 6
Repository Out-of-date with target 0
Repository GitHub state unknown 4
Repository Part of an open stack 2
Repository Touch files changed by another open PR 23
Repository Target a non-root branch without an open parent PR 0
This resolver batch Admitted snapshots 1
This resolver batch Currently resolving 0
This resolver batch Waiting 1
This resolver batch Finished 0

Related PR context

  • Stack: No open parent or child PR currently links to this branch.
  • Target: develop is a repository root/integration branch.
  • Changed-file overlap: 6 changed files are also touched by #10, #295, #564, #590, #595, #602, #607, #638, #662, #665, #680, #682.

Exact branch pair: developcodex/unified-builder-thing-sharing.

Timeline

  • 09:37 UTC — Detected conflicts between develop and codex/unified-builder-thing-sharing; assigning the exact snapshot to the resolver queue.

@github-actions github-actions Bot added lopu: mergeable The PR branches can currently be merged without conflicts and removed lopu: conflicting GitHub reports merge conflicts for the current PR snapshot labels Sep 8, 2026
@lopugit
lopugit temporarily deployed to develop-pr-683 September 8, 2026 09:39 Destroyed
@lopugit lopugit added preview: develop ready tt-preview-state:v1:develop:ready and removed preview: develop building tt-preview-state:v1:develop:building labels Sep 8, 2026
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

🤖 Lopu detected an out-of-date PR branch

Status: Work detected — Lopu is taking ownership.

Current phase: Entering Lopu's serialized PR-resolution queue.

Estimated completion: around 10:03 UTC (~20 minutes; this adjusts as the queue moves).

Next automatic check-in: within 10 minutes while work remains active. You can stay on this PR; there is no need to find the Actions run.

Time conversion (UTC source)

Moment UTC Los Angeles Melbourne
Updated 2026-09-08 09:43 UTC (UTC+00:00) 2026-09-08 02:43 PDT (UTC-07:00) 2026-09-08 19:43 AEST (UTC+10:00)
Estimated finish 2026-09-08 10:03 UTC (UTC+00:00) 2026-09-08 03:03 PDT (UTC-07:00) 2026-09-08 20:03 AEST (UTC+10:00)

Los Angeles and Melbourne use their real IANA time zones, so PDT/PST and AEST/AEDT offsets change automatically.

Lopu queue and PR pulse

Scope Metric Count
Repository Open PRs 26
Repository Conflicting 5
Repository Out-of-date with target 8
Repository GitHub state unknown 4
Repository Part of an open stack 2
Repository Touch files changed by another open PR 22
Repository Target a non-root branch without an open parent PR 0
This resolver batch Admitted snapshots 6
This resolver batch Currently resolving 0
This resolver batch Waiting 6
This resolver batch Finished 0

Related PR context

  • Stack: No open parent or child PR currently links to this branch.
  • Target: develop is a repository root/integration branch.
  • Changed-file overlap: 5 changed files are also touched by #10, #295, #564, #590, #595, #602, #607, #638, #662, #665, #680.

Exact branch pair: developcodex/unified-builder-thing-sharing.

Timeline

  • 09:43 UTC — Detected that develop needs to be merged into codex/unified-builder-thing-sharing; assigning the exact snapshot to the resolver queue.

@lopugit

lopugit commented Sep 8, 2026

Copy link
Copy Markdown
Owner Author

🤖 Promotion conflict resolution was queued automatically for promote/pr-683-unified-builder-thing-sharing--to-main at exact base main (2fea784bb85d6fdf11cdca715ce8d44bcce78281).

Conflicted source paths: TESTING.md, remix/app/components/Feed/feedTypes.ts.

The trusted worker will reconstruct, verify, publish, and attest the review branch; no manual branch update is needed.

@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

🔄 Promotion state moved or could not be revalidated while this run was active; the promoter is replanning safely.

Branch: promote/pr-683-unified-builder-thing-sharing--to-main · base: main at 2fea784bb85d6fdf11cdca715ce8d44bcce78281 · plan: 5229eb004ef34094ae4a4c0f0847c8dfe840a5013e9d13aafa900521cce03b61.

No pause was recorded because develop, the base, or the reserved branch no longer matches this transient run snapshot. A fresh promoter run was requested to re-derive authority and continue. Review the run.

@github-actions github-actions Bot mentioned this pull request Sep 8, 2026
@lopugit

lopugit commented Sep 8, 2026

Copy link
Copy Markdown
Owner Author

🤖 Promotion conflict resolution was queued automatically for promote/pr-683-unified-builder-thing-sharing--to-main at exact base main (2fea784bb85d6fdf11cdca715ce8d44bcce78281).

Conflicted source paths: TESTING.md, remix/app/components/Feed/feedTypes.ts.

The trusted worker will reconstruct, verify, publish, and attest the review branch; no manual branch update is needed.

⚠️ Source lineage is review-required-ambiguous; the resulting PR will carry source-lineage-unverified and must be reviewed for restoration intent.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

last preview built 08/09 19:40 AEST #683 tt-pv1:683:develop:73a49242c663b59387e5cecaff0e3fd7c719415d:1788860453741 preview: develop removed tt-preview-state:v1:develop:removed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant