Skip to content

Lane-GC P8: GC enforcement flip — dry-run → kill after ≥2-week zero-false-positive soak (operator-gated) #384

Description

@zxkane

Summary

Lane-GC series P8 — final issue (design §9 rev-3 PR-8). Flip adt-gc.sh from --dry-run default to --kill default, after the operator soak proves the safety predicate on real traffic.

This issue is deliberately NOT autonomous: its core acceptance evidence is a ≥2-week production soak — not pre-merge verifiable by the pipeline. The operator drives it; the code change itself is a one-flag default flip plus the soak-evidence write-up.

Requirements

  • ≥2 weeks of adt-gc.log / ADT_GC_SUMMARY history with zero would_kill_legacy_signature false positives and stable unknown_class
  • All onboarded projects confirmed re-onboarded post-P2 (atomic-install format) — the mid-upgrade legacy-live-wrapper false-kill guard depends on it; audit via --doctor
  • Any macOS enablement follow-up (from P4's Out of Scope) resolved or explicitly waived for a Linux-only fleet
  • Default flip: --dry-run--kill (ADT_GC_ENFORCE=1 opt-in honored earlier); rollback = single conf flag
  • One-time grandfathering decision executed: legacy 26–58-day orphans killed after the dry-run classification validated the legacy matcher against them

Testing Requirements

  • Unit: conf-flag flip test (enforce on/off) — the only pre-merge-testable surface
  • Soak evidence: ADT_GC_SUMMARY roll-up attached to the PR body

Acceptance Criteria

  • Soak roll-up attached, would_kill_legacy_signature = 0 across the window (surface: PR body, operator-verified)
  • Re-onboarding audit attached (surface: PR body)
  • Flip + rollback flag unit test green (surface: CI unit job)

Dependencies

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions