mirror of https://github.com/garrytan/gstack.git
writeReceipt (fail-closed, sha256:null — a subprocess or SDK owns the wire bytes) before every TS-module network-bearing operation: - bin/gstack-gbrain-sync.ts: before the gbrain code walk that ships repo content to the user's gbrain DB (may be remote Postgres). A refused receipt fails the stage with status refused-egress-receipt. - bin/gstack-memory-ingest.ts: before the gbrain batch import of transcript pages. A refused receipt returns a system_error verdict without spawning the import. - browse/src/server.ts: before both ngrok.forward call sites (start-up BROWSE_TUNNEL=1 path and the /tunnel/start endpoint). A receipt failure lands in the existing catch that tears the tunnel listener back down and refuses the start. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> (cherry picked from commit 5677d618a48fcd0ae2b068bf868781d90f809cb5) |
||
|---|---|---|
| .. | ||
| bin | ||
| scripts | ||
| src | ||
| test | ||
| PLAN-snapshot-dropdown-interactive.md | ||
| SKILL.md | ||
| SKILL.md.tmpl | ||