CB-632: purge "bridge" from the code, the artefacts and the ops surface #145
Open
opened 2026-08-23 06:21:21 +02:00 by ltms
·
3 comments
No Branch/Tag Specified
main
worker/fleetd-612-unita-87807e-1
worker/612-b3-mcpwirings-da2b58-3
worker/612-b2-cb185-176d3a-2
worker/612-b1-completion-457459-1
worker/612-agaps-73a926-2
worker/608-sleeps-3a64ff-3
worker/621-b4520b-1
worker/618-b83894-2
worker/fleetd-615-e05481-5
worker/lead-autocompact-5f1ab2-3
worker/fleetd-613-f85deb-3
worker/fleetd-608-flaky-nudge-test-d0c2d1-3
worker/lead-context-gauge-ad404f-1
worker/gauge-wiring-9158c1-4
worker/redeploy-slowstart-ead0e5-5
worker/charter-bytes-13668c-6
worker/rollover-outcome-291483-2
worker/589-f64303-2
worker/593-1a8025-5
worker/589-fcd2aa-1
worker/568-9fdaa2-3
worker/571-attempted-outcome-5739f7-2
worker/581-completionresolver-cas-sites-0542b7-6
worker/562-loop-health-wiring-test-99611c-5
worker/562-surface-loop-health-7df5cc-4
worker/575-waiter-cleanup-sites-62ad80-1
worker/572-answer-lock-release-46a9ae-5
worker/567-probe-channel-leak-a38fc5-6
worker/551-record-before-send-7cbf56-1
worker/561-listener-fanout-survives-a-throw-61d538-2
worker/555-redeploy-main-flow-seam-65c2f5-2
worker/556-injector-owns-registration-e027a5-1
worker/552-post-restart-mktemp-abort-bc2672-4
worker/553-onstatus-completion-leak-0da881-2
worker/550-shasum-linux-196132-1
worker/538-loop-dies-on-error-4a5eeb-6
worker/426-health-coverage-ef1fd4-4
worker/504-failed-reported-clean-3cfd66-3
worker/537-capturedlog-close-e4c437-2
worker/459-broken-link-targets-cadc17-5
worker/535-appender-leak-fe74c1-1
worker/512-part2-shutdown-detection-434701-9
worker/529-logger-level-sweep-2a5533-8
worker/528-drain-gate-call-site-5de83d-7
charter/forge-mcp-vs-token
worker/521-swap-guard-unpinned-28e931-5
worker/519-probe-test-harness-d25ab8-4
worker/525-logger-level-leak-1b4eb0-6
worker/518-fleetmcp-resolver-wiring-8ef96c-1
worker/512-drain-complete-line-7edd71-3
worker/517-abort-branch-and-jar-id-41b641-2
worker/500-9e52c9-3
worker/509-4912f4-2
worker/511-9a4b23-1
worker/493-479f45-2
worker/505-03f8b2-1
worker/492-followup-detect-unclear
worker/501-a31fa0-7
worker/498-451d1c-5
worker/494-1015ce-2
worker/492-209647-1
worker/489-001902-2
worker/480-relative-handover-path-906323-1
worker/480-b-handover-skill-45bf1f-5
worker/474-followup-source-pin-f54a55-17
worker/474-charter-check-on-reload-f54a55-17
worker/466-quarantine-repeatcount-report
worker/393-opencode-skill-seeding-71854b-13
worker/469-canonical-tool-names-2a472a-16
worker/466-quarantine-escalation-5ae9c1-15
worker/446-hot-exhausted-pattern-0af580-6
worker/464-charter-tool-name-guard-a85635-12
worker/463-listfleet-default-fails-open-f1c76c-11
worker/458-invariant-5-by-purpose-862f9a-10
worker/439-coordinator-row-gate-bc032a-8
worker/449-herdr-protocol-576015-4
worker/450-abstract-spawn-599e1c-5
worker/437-ack-refuses-177d91-1
worker/444-placement-window-feb56a-2
worker/440-helddurable-derived-d462d7-13
worker/425-rework-placement-resolve-c58ba1-9
worker/421-lead-peek-held-msgs-cdbad2-10
worker/435-fixed-policy-cap-fe11de-12
worker/422-gate-state-observability-9e79d6-11
worker/431-memberregistry-live-readers-cdbad2-10
worker/424-architect-slot-hot-038b41-7
worker/422-model-gate-spawn-c29f48-6
worker/425-default-profile-live-f55534-8
worker/415-coverage-wording-2cbf9c-5
worker/416-3ad1da-1
worker/418-588283-3
worker/deterministic-stamp-race-409-3cb7b6-10
worker/armed-reads-live-config-404-ed931f-9
worker/reply-peer-refusal-391-5a34bd-7
worker/models-allowlist-aa9e9b-3
worker/ttl-stamp-race-399-f1122f-8
worker/scrub-receipt-400-316b3e-5
worker/exhaustion-detection-395-105105-6
worker/scrub-abort-394-316b3e-5
fix/scrub-uid-abort
worker/task-scrub-517574-2
worker/t386-clock-bd5b78-4
worker/t384-scrub-813790-5
worker/t381-cc-748314-2
worker/t373-336973-2
worker/t365-3920c5-3
worker/t358-6e989b-1
worker/t355-8b321c-1
worker/fleetd-369-hermetic-git-tests-e8b19a-3
worker/fleetd-368-stale-lead-binding-f5682e-2
worker/fleetd-360-deploy-units-0d3793-1
worker/359-dead-lead-tabs-f1253b-4
worker/362-worktree-skills-c03e51-3
worker/361-coord-visibility-655144-1
362-plugin-visibility-and-drift
worker/errscan-bed2ca-2
worker/amqp-log-identity-bed2ca-2
worker/withdefaults-guard-561704
worker/sleepguard-82076d-1
worker/fd334-9ee1b6-5
worker/fd348-f1ab27-4
worker/fd335-a71c35-1
worker/fd342-174a17-2
worker/fd345-490d0f-3
worker/fleetd-337-5ec7d4-21
worker/fleetd-341-af5a6b-24
worker/fleetd-339-5ca0a2-23
worker/fleetd-338-83a4a1-22
worker/fleetd-333-281f46-18
worker/fleetd-329-11bdbb-16
worker/fleetd-330-2770fb-17
worker/fix-326-50506e-15
worker/fix-324-3e9bbf-14
worker/fix-323-b8287d-13
worker/fix-316b-bd0860-11
worker/fix-318-76ca36-9
worker/fix-317-486aec-8
worker/fix-315-ce47c5-6
worker/fix-307-275890-6
worker/fix-308-b4f664-7
worker/fix-309-ec3939-8
worker/fix-310-7a3974-9
worker/fix-302-52ad0e-9
worker/fix-298-ce1acb-8
worker/fix-297-66bd11-7
worker/fix-296-104622-6
worker/fix-293-bare-closetab-eb22b5-3
worker/fix-280-gone-ask-lapse-bca98e-2
worker/fix-290-reapidle-guard-coverage-9b0dd1-1
worker/fix-285-trust-seed-8f3565-10
worker/fix-284-backend-error-seat-85912c-11
worker/fix-282-chained-ask-e6d0bb-8
worker/fix-283-teardown-leaks-f40dfa-9
worker/fix-281-pin-handler-actions-4921ac-7
worker/audit-rendezvous-lifecycle-d072ae-2
worker/audit-health-placement-1a2476-6
worker/audit-teardown-exits-e207a5-3
worker/audit-launcher-asymmetry-27e370-4
worker/audit-rest-authz-6ca53c-5
worker/investigate-275-abandon-asking-fdef52-8
worker/fix-274-worktree-leak-b0095d-7
worker/fix-273-exhausted-pattern-9665b5-6
worker/fleetd-267-model-check-bd8068-1
worker/fleetd-131-archunit-18b834-7
worker/fleetd-266-sshagent-rename-a014ff-6
worker/fleetd-184-uid-claim-8e1f31-4
worker/fleetd-184-warn-b381ee-10
worker/fleetd-184-docs-be1d12-9
worker/fleetd-257-9bf010-7
worker/fleetd-103-23a113-6
worker/fleetd-247-342356-5
worker/fleetd-116-04dea8-4
worker/fleetd-252-a830e0-3
worker/fleetd-111-7e8673-9
worker/fleetd-155c-f8ef4b-8
worker/fleetd-176-b928ca-3
worker/fleetd-249-7a7878-2
worker/cb248-composition-root-b-9acdf7-15
worker/cb148-envrc-default-fa6c82-12
worker/cb201-unit5-wiring-6c12e6-8
worker/cb241-fallback-echo-1175e9-11
worker/cb149-trust-dialog-2392a5-9
worker/cb134-148-overlay-visible-c9b986-10
worker/cb234-session-id-keyed-04e1fc-1
worker/cb201-unit3-nudge-abdf5c-6
worker/cb201-unit2-policy-c1102c-5
worker/cb201-unit4-outcome-a13bfa-7
worker/cb201-unit1-classifier-91b9b1-4
worker/cb201-227-refine-831980-3
worker/cb175-model-readback-0f085f-1
worker/cb222-charter-tmpdir-17f013-1
worker/cb226-architect-slot-race-cd3aa8-3
worker/cb224-worktree-root-group-024523-2
worker/cb-123-role-demotion-c600f7-2
worker/cb-219-opencode-roots-1f677e-1
worker/cb214-claude-session-id-b9eab4-4
worker/cb213-zdotdir-wrong-process-dd6de4-3
worker/cb211-exhaustion-classification-9546e0-2
worker/cb137-ambiguous-task-4df3d8-4
worker/cb209-agentsessionid-4dfdb6-2
worker/cb185-hostenvnames-2692b5-3
worker/cb206-opencode-sqlite-128718-2
worker/cb185-worktree-group-fc0c99-1
worker/cb-137-ask-ticket-e7760c-2
worker/cb-172-broker-uri-d36ae4-4
worker/cb-175-model-readback-76ead6-3
worker/cb-161-pane-ancestry-293510-1
worker/cb-164-rebase-885863-8
worker/cb-164-empty-scrape-false-success-1a80af-3
fix/cb-197-ticket-ttl-from-completion
worker/cb-189-remote-url-coverage-4692f3-1
worker/cb-185-blockers-027756-4
worker/cb-192-gap-log-11b631-2
worker/cb-633-fix-5f4396-3
worker/cb185-router-d6436d-3
worker/cb185-router-routing-gaps-9e9d33-3
worker/cb185-paneids-992586-2
worker/cb-633-allow-list-union-ed374b-1
worker/cb-157-credential-in-remote-url-496e44-2
worker/cb-641-health-herdr-evidence-8f1f54-6
worker/cb-640-health-msg-evidence-99c9cd-1
worker/cb-642-fleets-status-skill-bbbc40-5
cb-634-ide-mcp
worker/lead-comms-wiring-c014b9-7
worker/lead-mailbox-c19577-6
worker/autocompact-window-82bc2f-5
worker/cb-634-probe-18056f-4
worker/cb635-broker-urienv
worker/cb-632-config-retry-8e0efa-7
lead/cb-622e-claude-md
lead/cb-622-followup
worker/cb-622a-165dff-1
lead/cb-622d-opencode-mount
worker/cb-622b-717c67-2
worker/cb-622c-ab7759-3
worker/cb-617b2-20ca4b-3
worker/cb-617a-5c2f4a-1
worker/cb596-4e49ef-3
worker/cb586-10500c-1
worker/cb-606-b9343a-25
worker/cb604-1445f8-24
worker/cb582-477374-21
worker/cb584-8c2281-22
worker/cb600-e6b9a9-20
worker/cb602-ce257f-19
worker/cb601-b42837-18
worker/cb598-6c7ba7-17
worker/cb599-740fe4-16
worker/cb597-282224-15
worker/cb590fix-185e9a-10
worker/cb528-recovery-race
worker/cb594-96bead-8
worker/cb590-916766-2
worker/cb527-997d99-3
worker/cb592-env-leak-3cbf9c-1
worker/cb588-async-ticket-nudge-3218f7-5
worker/cb578b-9dcb13-6
worker/cb581-d24826-5
worker/m2-u5-ef8c42-15
worker/cb578a-516499-2
worker/cb576-01a04b-17
worker/cb579-lead-tab-acba06-20
worker/cb580-terminal-health-ed6058-21
worker/cb577-f36fdc-18
worker/cb573b-3db06f-16
worker/cb568c-f36fdc-18
worker/cb568-drop-cause-c3ac1c
worker/cb575-cancelled-notification-c3ac1c
worker/m4-sol-a2cbec-3
worker/cb574-async-ask-c3ac1c
worker/cb573-health-model-8ca857-14
worker/cb572-unknown-target-7f2e35-13
worker/u4-700706-9
worker/u3-b9fcb6-6
worker/u2-ef5b68-4
worker/u1-469dce-1-clean
worker/u1-469dce-1
worker/cb-564-health-events-70cf7e-2
worker/cb-565-recycle-drops-role-98e58f-3
worker/cb-563-missing-reply-df2866-1
worker/cb-562-readiness-gate-silent-6c23c9-3
worker/cb-560-architect-presence-da8155-1
worker/cb-561-architect-silent-off-a71cab-2
worker/cb-548-bind-architect-slot-fe1b8c-1
worker/parity-overlay-settings-5fb711-1
secrets-central-store
cb-559-hot-key-correction
cb-557-fleet-role-pools
worker/cb-553-maxload-explicit-spawn-305ee3-6
worker/cb-551-idle-lead-heartbeat-f1633c-1
worker/cb-544-drain-preserves-worktree-925fad-3
worker/cb-552-docs-sync-1cb9cf-4
worker/cb-548-rendezvous-guard-rebased
worker/cb-548-rendezvous-guard-116b53-10
worker/cb-548-authz-v2-586df6-8
worker/cb-548-authz-264363-5
salvage/cb-528b-codex-home
salvage/cb-528a-codex-launcher
CB-518-primary-flow
feature/peer-launcher-spi
cb-103-injector
v1.1.0
v1.0.0
Labels
Clear labels
blocked
needs-live-proof
ready-to-delegate
silent-default
Cannot start until something else lands. The body says what.
Merged and green, but never shown working on the running daemon. Not the same as done.
Scope, files and acceptance criteria are written. A worker can be briefed from the body alone.
A feature that compiles, passes tests, and ships turned off. Nine recurrences and counting.
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: fleet/fleetd#145
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Part of #125 (CB-621).
Why this ticket exists
The epic renamed the tools (#126, done) and is renaming the checkout path (#128). Neither
touches the code.
bridg*still appears ~2,600 times, including the Java package, everyclass name, the Maven artifact, the config filename, the launchd job and the MCP mount name:
So the product is called
fleetand the daemon is calledfleetd, but nothing a developer oran operator touches says so. The epic is not finished until this is done.
Target names
bridged/fleetd/artifactId/finalNamebridgedfleetddev.ltms.bridgeddev.ltms.fleetBridgedFleetdBridgedConfigFleetConfigBridgeMcpFleetMcpBridgedAppFleetAppBridgedMetricsFleetMetricsbridged.yaml/bridged.example.yamlfleetd.yaml/fleetd.example.yamldeploy/dev.ltms.bridged.plistdeploy/dev.ltms.fleetd.plistdeploy/bridged.servicedeploy/fleetd.servicescripts/redeploy-bridged.shscripts/redeploy-fleetd.shscripts/bridged-launchd-wrapper.shscripts/fleetd-launchd-wrapper.shbridgedfleetdThe package root is
dev.ltms.fleet, notdev.ltms.fleetd. The trailingdmeans daemon,which names a process, not a namespace —
dev.ltms.fleet.mcpreads correctly anddev.ltms.fleetd.mcpdoes not.What must NOT change in this ticket
bridge_*MCP tool aliases stay. #126 shipped both names on purpose, for onerelease.
BridgeMcp.javaregisters 11deprecatedTwin(...)entries — a rename must move theclass, not delete the twins.
BRIDGED_*env var names change only behind a read-both shim. These are an operatorcontract, not internal strings:
BRIDGED_WORKER_TOKEN(57 uses)BRIDGED_MEMBER(13) — read by${SHARED_ENV}/tools/secrets.sh, a file this repo doesnot own. Renaming it without a shim silently turns off the credential guard, which is the
exact shape of a defect we have hit before (#113). Read both
FLEET_MEMBERandBRIDGED_MEMBER; set both at spawn.BRIDGED_API_TOKEN(8),BRIDGED_SUB*(6)bridged.yamlkeeps working as a fallback filename.Fleetd.mainshould tryfleetd.yaml, thenbridged.yaml, and log which one it used. The live plist passes thename explicitly, so a rename with no fallback strands a daemon that is restarted before its
plist is updated.
fleet:->roles:is #130, not this ticket.Units
Unit 1 must land first — it renames files, and every other unit edits the renamed files.
git mvthe module dir and the package dir, rewritepackage/importlines, rename the 5 classes and their test classes, update
pom.xml(
artifactId,name,finalName,mainClass). Verified bymvn clean installalone:if it compiles and 878 tests pass, the rename is right.
BRIDGED_*->FLEET_*reading both, plus a test that the old namestill works.
fleetd.yamlwith thebridged.yamlfallback, plus the example file.redeploy-*.sh,rename-checkout.sh(itsJAR_NAMEand config-file constants change),.gitea/workflows.README.md,docs/**,CLAUDE.md. The canonical block inCLAUDE.mdmust staybyte-identical with the template in wiki
7-Use-Cases.md; the sync check inCLAUDE.mdisthe gate. Commit the wiki in the wiki repo, never from the parent.
Acceptance criteria
git ls-files | grep -v '^wiki' | xargs grep -il bridgreturns only the files that aresupposed to keep the word: the
bridge_*alias registrations, theBRIDGED_*shim, thebridged.yamlfallback, and the changelog/ticket history that records the rename.mvn clean installgreen, test count unchanged.scripts/redeploy-fleetd.sh --checkruns and reports honestly.fleet_whoamistill answersprimary.Ordering against #128
Do this ticket before #128 (the checkout move).
rename-checkout.shhas been written and--checked against today's names; changing the code first means editing that script once, andthen the checkout move is the single cutover step that restarts the daemon.
Unit 1 done —
9b50dd6onlead/cb-632-java-renamePackage
dev.ltms.bridged->dev.ltms.fleet, andBridged/BridgedConfig/BridgeMcp/BridgedApp/BridgedMetrics->Fleetd/FleetConfig/FleetMcp/FleetApp/FleetMetrics.154 files, 149 of them pure renames.
mvn clean installgreen: 51 test classes, 878 tests,0 failures — the same count as before the rename, read out of the surefire XML rather than a
piped tail.
Three things worth recording, because two of them are traps and one is a decision:
sedhas no\b. One command carried eleven-eexpressions; the eleventh wass/\bBridged\b/Fleetd/g. It matched nothing, changed nothing and exited 0 alongside the tenthat worked. Caught by counting leftovers, not by the exit code.
logback.xmlandlogback-test.xmlname the package twice each, once as aturboFilter class=attribute. No compiler checks those. A rename that only satisfiesjavacleaves the daemon failing at startup.viaBridgeandviaFleetfor thetwo halves of the CB-622 dual-name check; renaming collapsed them onto one name and the
compiler caught it.
viaBridgeis correct there — it names the deprecated call — and is back.This is the general hazard for the remaining units: in this codebase the word "bridge" is
sometimes the old name and sometimes the current, deliberate name of a deprecated alias.
Deliberately unchanged, as planned: module directory
bridged/,<finalName>bridged</finalName>,bridged.yaml,BRIDGED_*, and thebridge_*tool aliases.Two units are being resequenced
Unit 2 (the
BRIDGED_*env var shim) is deferred until #144 (CB-633) lands.BRIDGED_MEMBERis read by a guarded block in
${SHARED_ENV}/tools/secrets.sh, a file this repo does not own.Renaming it to
FLEET_MEMBERneeds the operator to edit that file — and #144 replaces that wholemechanism with an allow-list applied at the spawn boundary, which removes the shell-side reader
entirely. Doing unit 2 first means asking the operator for an edit, then throwing it away.
BRIDGED_WORKER_TOKENandBRIDGED_API_TOKENcan ride along with #144's change for the samereason: one operator-facing change instead of two.
Unit 4 (the ops artefacts) is folded into the cutover. The plist, the systemd unit, the
launchd wrapper and
redeploy-bridged.shall namebridged/target/bridged.jar. That path onlychanges when the module directory and
<finalName>change, and the installed plist hasKeepAlivearmed, so renaming the jar on its own strands a restart. Renaming those files earlywould leave
redeploy-fleetd.sh --checkfailing against the live system, which breaks its ownacceptance criterion. So the cutover is one PR: module dir ->
fleetd/,finalName->fleetd,ops files renamed and repointed,
rename-checkout.shconstants updated — then build, install thenew plist, restart, and confirm a fresh
fleetd listeningline.That cutover PR is also where #128 (the checkout move) belongs, since both are path changes
needing one daemon restart.
Remaining before the cutover
fleetd.yamlwith abridged.yamlfallback, andfleetd.example.yaml.Delegated. The fallback is required, not cosmetic: the live config is literally named
bridged.yaml, is gitignored, and is passed to the daemon as an explicit argument.README.md,docs/**,bridged/docs/**. Delegated. Scoped to classnames, the package name, and the daemon's product name only; paths,
bridge_*,BRIDGED_*and
bridged_metrics are explicitly out of scope because they are all still true today.CLAUDE.mdand the wiki template — mine, not delegated. The canonical block has to staybyte-identical with wiki
7-Use-Cases.md, and the wiki is a submodule that must never becommitted from the parent repo.
Correction: the ticket named the wrong MCP mount string
The target table says "MCP mount name
bridged->fleetd". That is wrong, and it matters,because the two mounts are named in two different places by two different owners.
ClaudeCodeLauncher.java:301builds the member's mount inline:So a spawned member's tools are
mcp__bridge__*—bridge, nod. Thebridgedname Iquoted is only what this primary's
.mcp.jsonhappens to use, and.mcp.jsonis gitignoredand
--skip-worktree, so it is a local operator file rather than something this repo controls.CLAUDE.md's canonical block already states exactly this distinction and is correct as written:I went looking because
mcp__bridge__*did not match my ownmcp__bridged__*tools and Isuspected a defect in the fallback ladder. There is none. Checked before changing anything.
Corrected target: the launcher's member mount name
bridge->fleet, atClaudeCodeLauncher.java:301.OpenCodeLauncherneeds the same check — it builds its own configand has a
providerId + " (bridged)"display string at line 359.This is not a free rename, and it does not belong in a code unit. The member mount name is
part of the instruction surface, not just an implementation detail:
CLAUDE.md(mcp__bridge__*->mcp__fleet__*), which must stay byte-identical with the wiki template in7-Use-Cases.md, and must then be propagated to every other project carrying that block.mcp__bridge__*stops matching. The ladder failssafe — its final rung is "still unsure ⇒ act as a worker" — so a stale member is over-
restricted rather than over-privileged. That is the right direction, but it is still a
silent behaviour change.
So: give it its own unit, done by the lead, landing in the same PR as the
CLAUDE.mdand wikiedits. Not delegated, because the wiki is a submodule that must never be committed from the
parent repo.
Also fixed in passing: the
CLAUDE.mdaddendum pointed atmcp/BridgeMcp, which no longerexists after unit 1. It now reads
mcp/FleetMcp. That line is in the project addendum, not thecanonical block, so no wiki sync was needed — verified the sync check still returns True.
Audit against
mainat4ac688b. The purge is complete except for three deliberate retentions, which I am listing rather than closing over, because each is a decision and not an oversight.All ten are in four files, and all ten are one of the three items below. There is no incidental "bridge" left in the Java source — the tool namespace in particular is at zero (#126, now closed).
What remains, and what each would cost
1.
bridged.yamlconfig fallback —Fleetd.java:97-111Reads
bridged.yamlwhenfleetd.yamlis absent. This is intentional backward compatibility and its javadoc says so. It costs nothing to keep and it is the safety net for any deployment not yet migrated.Recommendation: keep. Remove it at 3.0 alongside other breaking changes, not on its own.
2.
BRIDGED_MEMBERmarker —HerdrPeerLauncher.java:950-955, referenced inMemberEnvAllowList.java:65This is a security control, not a name. The operator's
secrets.shguards on it:Renaming it in the daemon without simultaneously editing the operator's shared secret store would silently un-guard that block, and every member would start receiving the credentials the marker exists to withhold. The daemon and the secret store would have to change in the same instant, and the failure mode of getting it wrong is silent credential exposure.
Recommendation: keep, and add a comment at the definition saying why it must not be renamed casually. A cosmetic rename is not worth that risk. If it is ever done, it needs an overlap period where the guard checks both names.
3.
.bridged-worktreesdirectory —GitWorktrees.java:31, 95, 682The live worktree root, currently holding active worker worktrees. Renaming the default strands every existing worktree:
git worktreerecords absolute paths, so old worktrees would keep pointing at the old directory while new ones went elsewhere.Recommendation: keep the default, or do it properly with a migration that reads the old location when the new one is absent. Not a string change.
Suggested disposition
This ticket has done its job for the code. The three remaining items are each a small migration with real failure modes, and none of them is user-visible — no operator reads a directory name or an env marker as product branding.
I am leaving this open as the checklist for those three rather than closing it, so they do not get silently forgotten. But I would not schedule any of them ahead of a real defect. Item 2 in particular I think should stay as it is permanently, with a comment explaining the constraint.