#8692·zeroclaw

[Tracker]: Maintainer decision queue for RFCs and design issues

Author: Audacity88Created Jul 4, 2026Updated Sep 17, 2026
Labelsenhancementdomain:architecturepriority:p2status:acceptedstatus:no-stalerisk:mediumtype:tracker

Tracker kind

Maintainer decision tracker

Purpose

This tracker is the active issue-level decision queue for RFCs, design issues, release-policy questions, and coordination trackers that need maintainer or code-owner attention before acceptance, rejection, deferral, or split follow-up.

This is not a PR review queue. Pull requests already have native GitHub review state, CODEOWNERS, CI, mergeability, and requested-review signals. PRs belong here only when they expose an issue-level decision that should be tracked on the public issue surface.

Current decision queue snapshot

Snapshot date: 2026-09-17 22:14 UTC

Waiting-revision refresh: 2026-09-03

No-RFC reclassification refresh: 2026-09-09

Non-RFC needs-maintainer-review refresh: 2026-09-17 02:02 UTC

Source: active issue-level decision threads carrying needs-maintainer-review, active RFCs with open votes, elapsed discussion deadlines, blocked prerequisites, author revisions, or acceptance reconciliation, non-RFC design and coordination threads that still need maintainer attention, and the accepted-RFC ratification-provenance audit. Accepted-RFC implementation and disposition routing now lives in #10330.

Core vote open

Issue Description Next action
#10526 Append-only session event history, deterministic state replay, and derived agent streams. Renewed vote cycle is open through 2026-09-20 01:30 UTC. Carried APPROVE ballots from Audacity88, JordanTheJet, and Stalesamy are recorded; exceptional unanimous threshold still needs explicit APPROVE from @IftekharUddin and @tidux.
#9487 Runtime-owned conversation sessions and transport surface adapters. Renewed vote cycle is open through 2026-09-20 01:30 UTC. The default two-thirds threshold is satisfied by carried APPROVE ballots unless a Core member casts REVISE or REJECT, but final acceptance remains held pending #10526 because this RFC is contingent on the session-history authority.
#9488 Shared file and attachment architecture across runtime, web, ACP, and channels. Renewed vote cycle is open through 2026-09-20 01:30 UTC. The default two-thirds threshold is satisfied by carried APPROVE ballots unless a Core member casts REVISE or REJECT, but final acceptance remains held pending #10526's projection, redaction, and event-stream authority.
#10076 Composable WASM plugin runtime architecture spanning service definitions, providers, consumers, typed extension points, and replaceable subsystems. Renewed vote cycle is open through 2026-09-20 01:30 UTC. The default two-thirds threshold is satisfied by carried APPROVE ballots unless a Core member casts REVISE or REJECT, but final acceptance remains held pending #10526 because several plugin-session rows are contingent on that authority.

Ready for Core vote

Issue Description Next action

RFC intake / design framing

Issue Description Discussion through Next action
#10929 Delivery receipts for outbound channel messages: stable outbound message identity, transport-acceptance outcomes, durable receipt projection, and scoped query surface. 2026-09-19 02:48 UTC @JordanTheJet tightens the vote contract before opening a vote: adapters create transport-acceptance receipts, wrappers only persist/enrich them, recipient digests use keyed per-install hashing rather than log redaction, provider refs have retention/access rules, and dedup/retry suppression is deferred or explicitly composed with existing outbox authority.
#10930 Durable human-question primitive across SOP gates, tool approvals, and free-form asks, with restart-visible state, one resolve path, timeout policy, and scoped query surface. 2026-09-19 02:48 UTC @JordanTheJet tightens the vote contract before opening a vote: name the canonical waiting-state owner, distinguish restart-resumable SOP questions from process-bound tool approvals and asks, require transport-derived responder identity plus live authorization policy, and define durable payload minimization/retention so old approvals cannot execute stale work or store raw sensitive route data.

Architecture coordination / owner assigned

Issue Description Next action
#6293 Air-gapped/enclave companion-daemon execution boundary over Unix socket and vsock. @JordanTheJet has the architecture follow-up. Define the relay's allowlisted operations, request/response types, authentication model, denied-by-default behavior, and failure/replay handling before implementation starts.

Non-RFC design review

Issue Description Next action
#10756 Agent-shell marker preservation after TUI environment overlays. PR #9826 has a public merge hold because maintainer reviews conflict on whether the TUI-overlay marker bypass can be deferred. Reconcile the maintainer review state before merge by fixing the bypass, narrowing the PR's guarantee, or recording explicit maintainer agreement that this is follow-up risk despite the active change-request review.
#10755 Memory preference provenance: preserve subtype authority when consolidation merges into typed rows. PR #10007 has a public merge hold because maintainer reviews conflict on whether typed survivor merges can be deferred. Reconcile the maintainer review state before merge by fixing or narrowing the PR guarantee, or by recording explicit maintainer agreement that this is follow-up risk despite the active change-request review.
#10754 Memory preference provenance: distinguish content authorship from transport origin. PR #10007 has a public merge hold because maintainer reviews conflict on whether this provenance issue can be deferred. Reconcile the maintainer review state before merge by fixing or narrowing the PR guarantee, or by recording explicit maintainer agreement that this is follow-up risk despite the active change-request review.
#10793 Mixed Advisory Windows failures: PowerShell timeouts and control-plane process-liveness assertions. Decide whether this parent should remain a coordination issue now that #10811 covers the PowerShell slice and #10805 carries the control-plane race. If the split issues are sufficient, remove this parent from the maintainer-decision queue and drop status:in-progress because no single PR covers the whole mixed report.
#10853 OpenCode x-opencode-session follow-ups after #10604. Review #10864 or otherwise settle the three accepted follow-up choices: malformed pinned-header fallback versus config rejection, docs narrowing versus GET-path coverage, and cross-host redirect stripping versus an explicit accept-risk decision.
#9687 SOP engine operator-initiated pause for running SOPs. Define the pause lifecycle contract before pickup: request versus parked state, claim release and re-acquisition, restart rehydration, and precedence when pause races with cancellation or authored checkpoints.
#9686 ZeroCode SOP pane mouse Run/Resume controls deferred from the MVP. If draft PR #9693 is reactivated, refresh it against current master and update its body to drop the old #9476 blocker wording while keeping Stop/cancel under #9685.
#10781 Context/history config keys with inert or misleading semantics. Decide per-key disposition: wire to real behavior, warn/deprecate, or remove/rename in a schema cut; keep this narrower than #10780's compaction design.
#10780 Proactive token-budget context compaction and old-tool-result clearing after removal of context_compression.*. Decide whether to restore a first-class compaction design with summary/tool-result collapse semantics or keep accepted work split across #10702, #10781, #9535, and trim-observability follow-ups.
#10758 Cron and heartbeat model-visible delivery wording for persistence and send guarantees. PR #9842 has a public merge hold because maintainer reviews conflict on whether the prompt-contract mismatch can be deferred. Reconcile the maintainer review state before merge by narrowing the model-visible wording to runtime behavior, or by recording explicit maintainer agreement that this is follow-up risk despite the active change-request review.
#10778 Multimodal image-cap eviction mutates earlier provider-facing history and breaks prompt-cache prefix stability. Decide the eviction contract before implementation: once an old image is evicted, later requests without new images should serialize prior history identically, with trace/accounting evidence for any one-time mutation.

Waiting on revision

Issue Description Waiting since Last check-in Next action
#8424 Workspace-relative forbidden-path proposal. 2026-08-05 2026-08-23 @rakaarwaky reconciles glob, directory, shell, escalation, and load-failure semantics.
#9825 Publish-safe exceptions for public blockchain identifiers in outbound leak detection. 2026-08-13 2026-08-23 @bitsbyritik revises around a default-off, operator-managed publish-safe allowlist; keep #9486 as the prerequisite bug fix, and explain auditability plus fail-closed private-key protection before renewing discussion.
#9810 Agent Plugins 1.0 compatibility for portable skill and MCP packages. 2026-08-15 2026-08-23 @NiuBlibing reconciles the body with accepted #9346 before renewing discussion or opening a Core vote: package admission, inert discovery, component-scoped activation grants, manifest trust, MCP process/network permissions, and secret/environment handling should consume the accepted catalog contract instead of creating another registry.
#10025 Ephemeral agent swarms with a zeroclaw swarm TUI, runtime-owned swarm state, roster-only delegation, shared-memory scope, board state, budgets, RPC, and steering priority. 2026-08-20 2026-08-20 @IftekharUddin revises the body or posts a clear ratification framing that chooses whether this is one staged swarm RFC or split ratification for steering, RPC, TUI, state board, budget, and shared-memory boundaries; then reopen discussion or a vote against the stable shape.
#10069 Agent portability export/import, skill and MCP package handling, provenance, secret handling, and dropped-capability reporting. 2026-08-20 2026-08-20 Revise the body around the pre-import guarantees that must be locked before import: provenance, secret handling, dropped capabilities, untrusted bundles, collisions, and native-versus-agent-plugins compatibility. #9986 can continue as the export-only first slice, but the RFC should own the import/security contract before a vote.
#10346 Shared daemon-scoped MCP registry reuse across heartbeat, gateway, and channels. 2026-08-26 2026-08-26 @cheng315ncu folds the 2026-08-26 design-comment contract into the body before opening a vote: daemon boot ownership/drop order, the gateway and channel consumers that currently pass mcp_registry: None, missing_or_dead_servers reuse, fail-open behavior, no process-global cache, and the one-stdio-spawn regression target.
#10360 Opt-in household edge mesh with pull workers and signed execution receipts. 2026-08-28 2026-09-14 @kvnloo folds the protocol-first two-host canary reply into the body, or confirms that this should be taken over or parked: dedicated protocol/receipt crate or narrow runtime module, coordinator-only task/SOP completion authority, no scheduler/plugin/public-ingress commitment, and the pinned identity, revocation, replay-domain, lease, artifact-transfer, receipt, resource-limit, and fail-closed contract needed before a vote.
#8396 Wire-first provider construction and prospective canonical-family intake policy. 2026-09-03 2026-09-03 @Taswen chooses one vote contract for the provider-family intake policy: remove it from ratified commitments and keep it as non-binding direction, or keep it as accepted policy with an owner, enforcement surface, and acceptance criteria before the next vote.

Blocked on prerequisite

Issue Description Next action
#9703 Goal Mode V3 durable supervision for concurrent and asynchronous child work. #9702 is accepted and #9323 now records the execution-tree budget contract as ordinary accepted issue work; keep blocked until #9593/#9726 settle TaskRecord as the background-delegation lifecycle owner, then revise or open the V3 vote against those reconciled lifecycle and budget semantics.
#9880 Typed resolved peer policy for grants, denies, wildcards, and channel aliases. Wait for #9428 to land, then open a Core vote if the typed policy proposal remains stable; the first implementation should add the resolved policy type plus one low-coupling consumer, preserving #9428's deny-first, whole-identity, alias-owner, and shadowed-grant regressions.
#9802 Emergency-stop enforcement for in-flight cancellation and shared network egress. Wait for #9440 to land, then reconcile the active cancellation and egress work before renewing discussion or opening a Core vote.
#9945 Browser tool action coverage across agent-browser, rust-native, and computer-use backends. Wait for #9824/#9830 and #9946's #10210 timeout/kill-on-drop implementation, then start Phase 1 with backend warning surfacing, dialog status/accept/dismiss, and frame/main-frame support; leave eval, cookies, storage, credentials, headers, and broader upload behavior to separate policy decisions.
#9929 Headless SOP and cron turns receive session identities but do not persist transcripts. Wait for #9841, then add SOP headless step transcript capture to the SOP run store; keep cron and general one-shot transcript persistence on the #9487/#9600 runtime-session path.
#9887 Oversized-image downscaling and disabled multimodal limits. Wait for #9819 and #9883, then implement downscale-only image handling with bounded decode, resize-aware cache keys, GIF behavior, and post-resize size checks; defer unlimited 0 semantics to a separate resource-policy decision.
#7497 OCI-compliant registry, distribution, signing, provenance, and lockfile model for WASM plugins. Keep parked until the public plugin registry/distribution launch becomes active after 1.0. When it returns, reconcile it with #10169's proposed/open host-owned plugin-egress ADR work, #9346's catalog contract, and the active plugin rollout tracker before opening a vote.
#10634 Network-interrupted provider turn recovery without replaying tool or approval side effects. Wait for the #10526 and #9487 closing records, then implement the post-output continuation contract: classify interruption causes, preserve partial progress, make automatic continuation positive-proof only, and expose Continue/Retry only when the runtime can explain why automatic continuation is not safe.

The accepted-RFC implementation and disposition map belongs in #10330 rather than being duplicated here.

Correction rules:

  • Review the current body before changing labels so completed work, material proposal drift, and active implementation are not flattened into one mechanical action.
  • For short-discussion RFCs, remove status:accepted, reconcile the live proposal, and record a valid discussion period before voting.
  • For RFCs whose minimum discussion period elapsed, remove status:accepted and open a vote directly when the proposal remains materially stable. Do not restart discussion merely to consolidate the already-discussed contract.
  • Process the corrections in bounded batches and keep urgent security or release work moving under explicit maintainer judgment.

Scope and non-goals

In scope:

  • Track open RFC/design issues that need maintainer/code-owner review.
  • Track non-RFC issue-level decisions that carry needs-maintainer-review.
  • Identify decisions that need broader review because they affect runtime, control plane, security, gateway, providers, channels, tools, governance, release process, public interfaces, or project direction.
  • Keep reviewer asks and next decisions visible.

Out of scope:

  • Tracking ordinary PR review state.
  • Auditing the full historical ADR baseline.
  • Deciding that every RFC must become an ADR.
  • Reopening all accepted RFCs by default.
  • Blocking urgent security or release fixes on a new process unless maintainers explicitly decide the process applies.
  • Replacing maintainer judgment with an automated gate.

Linked work

  • #6808 - work-lane and board-automation RFC that created the current need for visible RFC review state.
  • #8303 - goal-mode RFC returned to renewed discussion after a material bounded-V1 revision superseded its first vote.
  • #8682 - ADR-008 PR spawned from #8303.
  • #8681 - goal-mode implementation split tracker.
  • #8691 - ADR/RFC audit tracker for accepted RFC decision-record follow-through.
  • #10330 - accepted RFC implementation index and disposition map.
  • docs/book/src/foundations/fnd-003-governance.md - describes RFC-to-ADR flow and architecture decision governance.
  • docs/book/src/foundations/fnd-002-documentation-standards.md - describes ADR lifecycle and status rules.

Routing evidence and next decision

Reason to stay open:

Tracks items needing maintainer review. The table above is the live decision queue. It currently includes four open Core votes, no rows ready for Core vote, two RFC intake/design-framing rows, one architecture-coordination row, eleven non-RFC design review rows, eight rows waiting on revision, eight rows blocked on prerequisite, and a completed accepted-RFC initial-correction sweep.

Next decision/revisit:

Complete each row's next action and update or remove the row when its state changes. Continue routing new issue-level decisions here; do not add ordinary pull-request review state.

Visible owner, assignee, milestone, linked tracker, or review cadence:

Use this issue as the public queue until the process is documented in maintainer/contributor docs or replaced by a more specific RFC governance mechanism.

Close criteria

Close when:

  • Current open RFC/design issues and issue-level decision threads have a visible review/routing state.
  • The project has a documented or agreed recurring way to keep maintainer decision state current.
  • The process is reflected in relevant contributor/maintainer docs or superseded by a newer governance tracker.

Stale-exemption requested?

Yes - tracker itself is the active coordination surface