Block a user
CB-189: cover every remote, both URLs, and any non-SSH scheme in the credential check
CB-157 follow-up: the remote-URL credential checks only see
origin, only https, and never a push URL
CB-185: fix two blockers to switching on memberHerdrSocket
Run members on a second herdr under a dedicated user (optional; single-herdr stays the default)
CB-192: fix false credential-gap WARN under allow-list+zsh, split its log guard
Async ticket TTL runs from creation, so a long task's report is destroyed on arrival
CB-638: the wiki describes a system that no longer exists — audit index of pages to revise, build and retire
Audit done and merged —
Audit done and merged — docs/wiki-audit.md (PR #193)
All 15 pages have a verdict with quoted lines and file:line evidence for every claim.
#168: audit current wiki snapshot
capacity counts panes, not subscription seats, so a subscription profile reports a free slot that cannot be filled
A structural gap that matches the symptom exactly: the spawn gate cannot resolve UNKNOWN
Read against main @ 23ada19. This is not the root cause of the mid-session break, but it is a
real…
CB-633 follow-up: the credential-gap WARN says "inherited UNBLOCKED" about names the scrub does blank, and one guard can hide the real one
CB-633: SSH_AUTH_SOCK block wins over allow:, non-zsh fallback reports its gap
CB-633: SSH_AUTH_SOCK block wins over allow:, non-zsh fallback reports its gap
Closing — my brief was wrong, not your work
I asked for this fix without first diffing #174 against current main. main had already
superseded it, so two of the three defects I sent…
CB-633: honor explicit member credential keeps
CB-633: honor explicit member credential keeps
Closing —
Closing — main already does this, and does it correctly
82e7be5 CB-633 follow-up: union memberCredentials.allow into the derived env allow-list landed on
main after this PR was opened.…