gstack 1.91.2.0
gstack 1.91.2.0 checks your gbrain without writing to it
/sync-gbrain confirms this worktree's pages are readable, and keeps your guidance when the answer is uncertain.
In gstack 1.91.2.0, /sync-gbrain can check whether this worktree's pages are readable without writing a probe page. And when the answer is uncertain, it keeps your existing guidance.
Readiness starts from this worktree
Readiness starts from this worktree's own source
Readiness first matches the registered source to this worktree. Then it checks that source's page count, and reads one page back from the same source before it calls the worktree ready.
Uncertain means unknown
When it can't tell, the answer is unknown and your guidance stays
A foreign pin, a failed read, an invalid count, or an unavailable service all come back as unknown, and your guidance stays in place. A source verified as empty can still offer a reindex.
Secret scan checks the imported page
Secret scanning now checks the page that gets imported
KEY=\"v\"Escaped quote, missed by the scan
KEY="v"The exact markdown gbrain imports
With scan secrets turned on, memory ingest now runs gitleaks on the rendered page, the exact markdown it imports. The raw transcript escapes its quotes, so a key written that way slipped past the scan.
Unfinished scans block the import
A secret scan that doesn't finish now blocks the import
If gitleaks is missing, errors out, runs past a minute, or writes an oversized report, that file is skipped instead of imported unscanned. Skipped files stay pending and get retried on the next run.
02: The Aside browser
The Aside browser
The readiness check, on zsh and on failure.
Next, the Aside browser.
Aside check works in zsh
The Aside check now works in zsh, the Mac's default shell
$_T aside repl …zsh looks for one command named "gtimeout 30"
_gs_d aside repl …A function, so sh, bash and zsh all agree
The Aside readiness check now works under zsh. It kept its timeout in a variable that zsh won't split, so a stock Mac always answered not running, and browsing skills fell back to bundled Chromium.
Aside failures say why
A failed Aside check now says which way it failed
ASIDE_TIMEOUTprobe deadline exceededASIDE_UNAVAILABLEno way to bound the probeASIDE_CLI_ERRORthe CLI's exit codeASIDE_NOT_RUNNINGopen the app and retryA failed check now reports a timeout, a missing way to bound the call, a command error with its exit code, or a missing ready signal. Only that last case asks you to open the app.
03: Reviews and debugging
Reviews and debugging
/plan-eng-review, /review, /investigate, /freeze
Reviews and debugging.
Engineering review runs in order
/plan-eng-review runs its steps in order
/plan-eng-review now follows its preparation and complexity gate paths in order, and every decision and required report write stays checkable. Calibration write-back stays off unless its explicit gate turns it on.
Codex findings enter Fix-First
In /review, supported Codex findings go through Fix-First
The outside challenge is still informational. Its supported findings now face Fix-First's approval and convergence gates.
In /review, the outside Codex challenge is still informational. But its supported findings now enter the Fix-First step, where its approval and convergence gates apply.
Investigate releases only its own lock
/investigate releases only the edit lock it took
acquire → FREEZE_OWNERReleased with that token when the run ends
FREEZE_PRESERVEDLeft exactly where you set it
/investigate now takes its edit lock with an owner token, and releases only that lock when the run ends. A freeze boundary you set beforehand stays exactly where you put it.
Freeze lasts until unfreeze
A /freeze boundary lasts until you run /unfreeze
Ending or killing the conversation leaves the boundary in place.
A /freeze boundary now persists until you run /unfreeze. Ending the conversation, or killing it, leaves the boundary in place, so run /unfreeze when you want your edits unrestricted again.
04: Browse and setup
Browse and setup
Uploads, ARM Linux, and three quieter fixes.
Browse and setup.
Upload checks real paths
browse upload checks every file's real path
absolute paths onlyA relative path skipped the directory check
realpath → validateReadPathEvery path, resolved through symlinks
The browse upload command now resolves every file through its symlinks and checks the real path against the allowed directories. Before, a relative path skipped that directory check.
ARM Chromium on Ubuntu 26.04
Setup installs ARM Chromium on ARM Ubuntu 26.04
x86_64ubuntu24.04-x64 buildaarch64 · arm64ubuntu24.04-arm64 buildanything elseinstall skipped, reason in the summaryOn Ubuntu 26.04, setup now picks Playwright's ARM Chromium build on ARM machines, instead of forcing the x64 build. On any other chip, it skips the install and says why.
Extension APIs, displays, PGLite
Browse keeps real extension APIs and leaves busy displays alone
Browse's stealth mode now keeps Chrome's own extension messaging calls. On Linux, it won't take over an X display that's already in use. And a busy local PGLite database reports as locked.

















