[Tracker]: Maintainer decision queue for RFCs and design issues
Tracker kind
Maintainer decision tracker
Purpose
This tracker is the active issue-level decision queue for RFCs, design issues, release-policy questions, and coordination trackers that need maintainer or code-owner attention before acceptance, rejection, deferral, or split follow-up.
This is not a PR review queue. Pull requests already have native GitHub review state, CODEOWNERS, CI, mergeability, and requested-review signals. PRs belong here only when they expose an issue-level decision that should be tracked on the public issue surface.
Current decision queue snapshot
Snapshot date: 2026-09-17 22:14 UTC
Waiting-revision refresh: 2026-09-03
No-RFC reclassification refresh: 2026-09-09
Non-RFC needs-maintainer-review refresh: 2026-09-17 02:02 UTC
Source: active issue-level decision threads carrying needs-maintainer-review, active RFCs with open votes, elapsed discussion deadlines, blocked prerequisites, author revisions, or acceptance reconciliation, non-RFC design and coordination threads that still need maintainer attention, and the accepted-RFC ratification-provenance audit. Accepted-RFC implementation and disposition routing now lives in #10330.
Core vote open
| Issue | Description | Next action |
|---|---|---|
| #10526 | Append-only session event history, deterministic state replay, and derived agent streams. | Renewed vote cycle is open through 2026-09-20 01:30 UTC. Carried APPROVE ballots from Audacity88, JordanTheJet, and Stalesamy are recorded; exceptional unanimous threshold still needs explicit APPROVE from @IftekharUddin and @tidux. |
| #9487 | Runtime-owned conversation sessions and transport surface adapters. | Renewed vote cycle is open through 2026-09-20 01:30 UTC. The default two-thirds threshold is satisfied by carried APPROVE ballots unless a Core member casts REVISE or REJECT, but final acceptance remains held pending #10526 because this RFC is contingent on the session-history authority. |
| #9488 | Shared file and attachment architecture across runtime, web, ACP, and channels. | Renewed vote cycle is open through 2026-09-20 01:30 UTC. The default two-thirds threshold is satisfied by carried APPROVE ballots unless a Core member casts REVISE or REJECT, but final acceptance remains held pending #10526's projection, redaction, and event-stream authority. |
| #10076 | Composable WASM plugin runtime architecture spanning service definitions, providers, consumers, typed extension points, and replaceable subsystems. | Renewed vote cycle is open through 2026-09-20 01:30 UTC. The default two-thirds threshold is satisfied by carried APPROVE ballots unless a Core member casts REVISE or REJECT, but final acceptance remains held pending #10526 because several plugin-session rows are contingent on that authority. |
Ready for Core vote
| Issue | Description | Next action |
|---|
RFC intake / design framing
| Issue | Description | Discussion through | Next action |
|---|---|---|---|
| #10929 | Delivery receipts for outbound channel messages: stable outbound message identity, transport-acceptance outcomes, durable receipt projection, and scoped query surface. | 2026-09-19 02:48 UTC | @JordanTheJet tightens the vote contract before opening a vote: adapters create transport-acceptance receipts, wrappers only persist/enrich them, recipient digests use keyed per-install hashing rather than log redaction, provider refs have retention/access rules, and dedup/retry suppression is deferred or explicitly composed with existing outbox authority. |
| #10930 | Durable human-question primitive across SOP gates, tool approvals, and free-form asks, with restart-visible state, one resolve path, timeout policy, and scoped query surface. | 2026-09-19 02:48 UTC | @JordanTheJet tightens the vote contract before opening a vote: name the canonical waiting-state owner, distinguish restart-resumable SOP questions from process-bound tool approvals and asks, require transport-derived responder identity plus live authorization policy, and define durable payload minimization/retention so old approvals cannot execute stale work or store raw sensitive route data. |
Architecture coordination / owner assigned
| Issue | Description | Next action |
|---|---|---|
| #6293 | Air-gapped/enclave companion-daemon execution boundary over Unix socket and vsock. | @JordanTheJet has the architecture follow-up. Define the relay's allowlisted operations, request/response types, authentication model, denied-by-default behavior, and failure/replay handling before implementation starts. |
Non-RFC design review
| Issue | Description | Next action |
|---|---|---|
| #10756 | Agent-shell marker preservation after TUI environment overlays. | PR #9826 has a public merge hold because maintainer reviews conflict on whether the TUI-overlay marker bypass can be deferred. Reconcile the maintainer review state before merge by fixing the bypass, narrowing the PR's guarantee, or recording explicit maintainer agreement that this is follow-up risk despite the active change-request review. |
| #10755 | Memory preference provenance: preserve subtype authority when consolidation merges into typed rows. | PR #10007 has a public merge hold because maintainer reviews conflict on whether typed survivor merges can be deferred. Reconcile the maintainer review state before merge by fixing or narrowing the PR guarantee, or by recording explicit maintainer agreement that this is follow-up risk despite the active change-request review. |
| #10754 | Memory preference provenance: distinguish content authorship from transport origin. | PR #10007 has a public merge hold because maintainer reviews conflict on whether this provenance issue can be deferred. Reconcile the maintainer review state before merge by fixing or narrowing the PR guarantee, or by recording explicit maintainer agreement that this is follow-up risk despite the active change-request review. |
| #10793 | Mixed Advisory Windows failures: PowerShell timeouts and control-plane process-liveness assertions. | Decide whether this parent should remain a coordination issue now that #10811 covers the PowerShell slice and #10805 carries the control-plane race. If the split issues are sufficient, remove this parent from the maintainer-decision queue and drop status:in-progress because no single PR covers the whole mixed report. |
| #10853 | OpenCode x-opencode-session follow-ups after #10604. |
Review #10864 or otherwise settle the three accepted follow-up choices: malformed pinned-header fallback versus config rejection, docs narrowing versus GET-path coverage, and cross-host redirect stripping versus an explicit accept-risk decision. |
| #9687 | SOP engine operator-initiated pause for running SOPs. | Define the pause lifecycle contract before pickup: request versus parked state, claim release and re-acquisition, restart rehydration, and precedence when pause races with cancellation or authored checkpoints. |
| #9686 | ZeroCode SOP pane mouse Run/Resume controls deferred from the MVP. | If draft PR #9693 is reactivated, refresh it against current master and update its body to drop the old #9476 blocker wording while keeping Stop/cancel under #9685. |
| #10781 | Context/history config keys with inert or misleading semantics. | Decide per-key disposition: wire to real behavior, warn/deprecate, or remove/rename in a schema cut; keep this narrower than #10780's compaction design. |
| #10780 | Proactive token-budget context compaction and old-tool-result clearing after removal of context_compression.*. |
Decide whether to restore a first-class compaction design with summary/tool-result collapse semantics or keep accepted work split across #10702, #10781, #9535, and trim-observability follow-ups. |
| #10758 | Cron and heartbeat model-visible delivery wording for persistence and send guarantees. | PR #9842 has a public merge hold because maintainer reviews conflict on whether the prompt-contract mismatch can be deferred. Reconcile the maintainer review state before merge by narrowing the model-visible wording to runtime behavior, or by recording explicit maintainer agreement that this is follow-up risk despite the active change-request review. |
| #10778 | Multimodal image-cap eviction mutates earlier provider-facing history and breaks prompt-cache prefix stability. | Decide the eviction contract before implementation: once an old image is evicted, later requests without new images should serialize prior history identically, with trace/accounting evidence for any one-time mutation. |
Waiting on revision
| Issue | Description | Waiting since | Last check-in | Next action |
|---|---|---|---|---|
| #8424 | Workspace-relative forbidden-path proposal. | 2026-08-05 | 2026-08-23 | @rakaarwaky reconciles glob, directory, shell, escalation, and load-failure semantics. |
| #9825 | Publish-safe exceptions for public blockchain identifiers in outbound leak detection. | 2026-08-13 | 2026-08-23 | @bitsbyritik revises around a default-off, operator-managed publish-safe allowlist; keep #9486 as the prerequisite bug fix, and explain auditability plus fail-closed private-key protection before renewing discussion. |
| #9810 | Agent Plugins 1.0 compatibility for portable skill and MCP packages. | 2026-08-15 | 2026-08-23 | @NiuBlibing reconciles the body with accepted #9346 before renewing discussion or opening a Core vote: package admission, inert discovery, component-scoped activation grants, manifest trust, MCP process/network permissions, and secret/environment handling should consume the accepted catalog contract instead of creating another registry. |
| #10025 | Ephemeral agent swarms with a zeroclaw swarm TUI, runtime-owned swarm state, roster-only delegation, shared-memory scope, board state, budgets, RPC, and steering priority. |
2026-08-20 | 2026-08-20 | @IftekharUddin revises the body or posts a clear ratification framing that chooses whether this is one staged swarm RFC or split ratification for steering, RPC, TUI, state board, budget, and shared-memory boundaries; then reopen discussion or a vote against the stable shape. |
| #10069 | Agent portability export/import, skill and MCP package handling, provenance, secret handling, and dropped-capability reporting. | 2026-08-20 | 2026-08-20 | Revise the body around the pre-import guarantees that must be locked before import: provenance, secret handling, dropped capabilities, untrusted bundles, collisions, and native-versus-agent-plugins compatibility. #9986 can continue as the export-only first slice, but the RFC should own the import/security contract before a vote. |
| #10346 | Shared daemon-scoped MCP registry reuse across heartbeat, gateway, and channels. | 2026-08-26 | 2026-08-26 | @cheng315ncu folds the 2026-08-26 design-comment contract into the body before opening a vote: daemon boot ownership/drop order, the gateway and channel consumers that currently pass mcp_registry: None, missing_or_dead_servers reuse, fail-open behavior, no process-global cache, and the one-stdio-spawn regression target. |
| #10360 | Opt-in household edge mesh with pull workers and signed execution receipts. | 2026-08-28 | 2026-09-14 | @kvnloo folds the protocol-first two-host canary reply into the body, or confirms that this should be taken over or parked: dedicated protocol/receipt crate or narrow runtime module, coordinator-only task/SOP completion authority, no scheduler/plugin/public-ingress commitment, and the pinned identity, revocation, replay-domain, lease, artifact-transfer, receipt, resource-limit, and fail-closed contract needed before a vote. |
| #8396 | Wire-first provider construction and prospective canonical-family intake policy. | 2026-09-03 | 2026-09-03 | @Taswen chooses one vote contract for the provider-family intake policy: remove it from ratified commitments and keep it as non-binding direction, or keep it as accepted policy with an owner, enforcement surface, and acceptance criteria before the next vote. |
Blocked on prerequisite
| Issue | Description | Next action |
|---|---|---|
| #9703 | Goal Mode V3 durable supervision for concurrent and asynchronous child work. | #9702 is accepted and #9323 now records the execution-tree budget contract as ordinary accepted issue work; keep blocked until #9593/#9726 settle TaskRecord as the background-delegation lifecycle owner, then revise or open the V3 vote against those reconciled lifecycle and budget semantics. |
| #9880 | Typed resolved peer policy for grants, denies, wildcards, and channel aliases. | Wait for #9428 to land, then open a Core vote if the typed policy proposal remains stable; the first implementation should add the resolved policy type plus one low-coupling consumer, preserving #9428's deny-first, whole-identity, alias-owner, and shadowed-grant regressions. |
| #9802 | Emergency-stop enforcement for in-flight cancellation and shared network egress. | Wait for #9440 to land, then reconcile the active cancellation and egress work before renewing discussion or opening a Core vote. |
| #9945 | Browser tool action coverage across agent-browser, rust-native, and computer-use backends. | Wait for #9824/#9830 and #9946's #10210 timeout/kill-on-drop implementation, then start Phase 1 with backend warning surfacing, dialog status/accept/dismiss, and frame/main-frame support; leave eval, cookies, storage, credentials, headers, and broader upload behavior to separate policy decisions. |
| #9929 | Headless SOP and cron turns receive session identities but do not persist transcripts. | Wait for #9841, then add SOP headless step transcript capture to the SOP run store; keep cron and general one-shot transcript persistence on the #9487/#9600 runtime-session path. |
| #9887 | Oversized-image downscaling and disabled multimodal limits. | Wait for #9819 and #9883, then implement downscale-only image handling with bounded decode, resize-aware cache keys, GIF behavior, and post-resize size checks; defer unlimited 0 semantics to a separate resource-policy decision. |
| #7497 | OCI-compliant registry, distribution, signing, provenance, and lockfile model for WASM plugins. | Keep parked until the public plugin registry/distribution launch becomes active after 1.0. When it returns, reconcile it with #10169's proposed/open host-owned plugin-egress ADR work, #9346's catalog contract, and the active plugin rollout tracker before opening a vote. |
| #10634 | Network-interrupted provider turn recovery without replaying tool or approval side effects. | Wait for the #10526 and #9487 closing records, then implement the post-output continuation contract: classify interruption causes, preserve partial progress, make automatic continuation positive-proof only, and expose Continue/Retry only when the runtime can explain why automatic continuation is not safe. |
The accepted-RFC implementation and disposition map belongs in #10330 rather than being duplicated here.
Correction rules:
- Review the current body before changing labels so completed work, material proposal drift, and active implementation are not flattened into one mechanical action.
- For short-discussion RFCs, remove
status:accepted, reconcile the live proposal, and record a valid discussion period before voting. - For RFCs whose minimum discussion period elapsed, remove
status:acceptedand open a vote directly when the proposal remains materially stable. Do not restart discussion merely to consolidate the already-discussed contract. - Process the corrections in bounded batches and keep urgent security or release work moving under explicit maintainer judgment.
Scope and non-goals
In scope:
- Track open RFC/design issues that need maintainer/code-owner review.
- Track non-RFC issue-level decisions that carry
needs-maintainer-review. - Identify decisions that need broader review because they affect runtime, control plane, security, gateway, providers, channels, tools, governance, release process, public interfaces, or project direction.
- Keep reviewer asks and next decisions visible.
Out of scope:
- Tracking ordinary PR review state.
- Auditing the full historical ADR baseline.
- Deciding that every RFC must become an ADR.
- Reopening all accepted RFCs by default.
- Blocking urgent security or release fixes on a new process unless maintainers explicitly decide the process applies.
- Replacing maintainer judgment with an automated gate.
Linked work
- #6808 - work-lane and board-automation RFC that created the current need for visible RFC review state.
- #8303 - goal-mode RFC returned to renewed discussion after a material bounded-V1 revision superseded its first vote.
- #8682 - ADR-008 PR spawned from #8303.
- #8681 - goal-mode implementation split tracker.
- #8691 - ADR/RFC audit tracker for accepted RFC decision-record follow-through.
- #10330 - accepted RFC implementation index and disposition map.
docs/book/src/foundations/fnd-003-governance.md- describes RFC-to-ADR flow and architecture decision governance.docs/book/src/foundations/fnd-002-documentation-standards.md- describes ADR lifecycle and status rules.
Routing evidence and next decision
Reason to stay open:
Tracks items needing maintainer review. The table above is the live decision queue. It currently includes four open Core votes, no rows ready for Core vote, two RFC intake/design-framing rows, one architecture-coordination row, eleven non-RFC design review rows, eight rows waiting on revision, eight rows blocked on prerequisite, and a completed accepted-RFC initial-correction sweep.
Next decision/revisit:
Complete each row's next action and update or remove the row when its state changes. Continue routing new issue-level decisions here; do not add ordinary pull-request review state.
Visible owner, assignee, milestone, linked tracker, or review cadence:
Use this issue as the public queue until the process is documented in maintainer/contributor docs or replaced by a more specific RFC governance mechanism.
Close criteria
Close when:
- Current open RFC/design issues and issue-level decision threads have a visible review/routing state.
- The project has a documented or agreed recurring way to keep maintainer decision state current.
- The process is reflected in relevant contributor/maintainer docs or superseded by a newer governance tracker.
Stale-exemption requested?
Yes - tracker itself is the active coordination surface
Source: zeroclaw-labs/zeroclaw