Build ErsatzTV Image / CI toolchain image resolves (pull_request) Successful in 6s
PR Gates / CI image pin matches docker/ci (pull_request) Successful in 16s
Build ErsatzTV Image / Delimiter ban (release path) (pull_request) Successful in 19s
PR Gates / Docs update reminder (pull_request) Successful in 22s
PR Gates / decisions lifecycle (pull_request) Successful in 20s
review-verdict/h10 Awaiting review verdict for c2c70e5
Review verdict / Set review-verdict status (pull_request_target) Successful in 13s
PR Gates / Fix proofs (Proves trailers) (pull_request) Successful in 17s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 14m56s
PR Gates / Script lint and tests (ruff + pytest) (pull_request) Successful in 15m30s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 10m8s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Skipped
Build ErsatzTV Image / Functional E2E (curl + UI contracts) (pull_request) Successful in 9m36s
Build ErsatzTV Image / API docs in sync (OpenAPI + endpoint index) (pull_request) Successful in 13s
Build ErsatzTV Image / Formatting (changed .cs conform to .editorconfig) (pull_request) Successful in 9s
The round-8 cross-family review found two more Blockers. Both are cases where a principle this branch had already established was applied in one place and not the adjacent one. ## Sentinel text is not sentinel state `ex_repair` and `ex_unverified` were set from the DESCRIPTION alone. A `success` carrying `$REPAIR_DESC` verbatim — from a machine or an off-list account — therefore read as a sentinel: the mid-run guard exited on it, and the mark's already-there test matched it and returned without POSTing. A green stood on an unreviewed head, on a first-push event with no successor guaranteed. This is the same reasoning that removed the "this job's own output" exclusion one round earlier: a description is not provenance. It is not state either. Both sentinels this job writes are `pending` by construction, so requiring it costs nothing. ## An unreadable neighbour cannot be shown to be unrelated Round 8 refused only when NO readable target row was found, reasoning that a malformed row beside a good one is noise. An element whose `.context` cannot be read cannot be shown to be a DIFFERENT context — so it may be a mangled rendering of this head's own rejection, and the one-row-per-context invariant that would rule that out is exactly what a schema-corrupt response has already broken. The branch's own POSITIVE CONTROL encoded the failing case: a scalar beside an off-list `success`, which this branch re-derived and greened where `origin/main` errored on the scalar and posted nothing. That test is inverted, not adjusted. The cost is a stall on any head carrying a malformed element — the correct direction for a required check, since it withholds a green rather than granting one. ## Two clauses deleted rather than proved Chasing a proof for the mark's repair promotion showed its three clauses were MUTUALLY REDUNDANT: each alone produces the outcome, so no single-clause mutation could show harm. Tracing why revealed that two are unreachable as a sole cause — a repair sentinel at the first read sets `ex_repair`, which forces `desc="$REPAIR_DESC"`, and one arriving mid-run is caught by the sentinel guard unless this run is itself writing that string. So they are redundant rather than unprovable, and they are gone. One clause, one mechanism, one proof. refs #849 Refs: #849 Decisions-Edit: yes Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019T79beF1Ufid3dXju4yqkF