gstack 1.91.2.0: gbrain readiness, fail-closed secret scans, Aside on zsh

36 minutes ago

@gstackSubscribe

What changed in gstack 1.91.2.0: /sync-gbrain checks readiness without writing to your brain, memory ingest scans the page it imports and fails closed, the Aside browser check works in zsh, plus fixes to /plan-eng-review, /review, /investigate, /freeze, browse upload and ARM Chromium setup. https://github.com/garrytan/gstack/blob/main/CHANGELOG.md#19120---2026-09-25 https://github.com/garrytan/gstack/commit/01593aa67c94780528e8f5121e47362502410ced

Ask

Ask about this presentation

Answers are generated from this presentation.

Chapters

  1. 0:00gstack 1.91.2.0
  2. 0:13Readiness starts from this worktree
  3. 0:24Uncertain means unknown
  4. 0:36Secret scan checks the imported page
  5. 0:49Unfinished scans block the import
  6. 1:0202: The Aside browser
  7. 1:04Aside check works in zsh
  8. 1:17Aside failures say why
  9. 1:2803: Reviews and debugging
  10. 1:30Engineering review runs in order
  11. 1:44Codex findings enter Fix-First
  12. 1:54Investigate releases only its own lock
  13. 2:05Freeze lasts until unfreeze
  14. 2:1604: Browse and setup
  15. 2:18Upload checks real paths
  16. 2:29ARM Chromium on Ubuntu 26.04
  17. 2:42Extension APIs, displays, PGLite
Show transcript

gstack 1.91.2.0

gstack logo

gstack 1.91.2.0 checks your gbrain without writing to it

/sync-gbrain confirms this worktree's pages are readable, and keeps your guidance when the answer is uncertain.

01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · CHANGELOG.md

In gstack 1.91.2.0, /sync-gbrain can check whether this worktree's pages are readable without writing a probe page. And when the answer is uncertain, it keeps your existing guidance.

Readiness starts from this worktree

Readiness starts from this worktree's own source

1Match the registered source
→
2Check its page count
→
3Read one page back
01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · CHANGELOG.md

Readiness first matches the registered source to this worktree. Then it checks that source's page count, and reads one page back from the same source before it calls the worktree ready.

Uncertain means unknown

When it can't tell, the answer is unknown and your guidance stays

foreign pinfailed readinvalid countservice unavailable
→ unknown · existing guidance kept
verified empty source → can still offer reindexing
01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · CHANGELOG.md

A foreign pin, a failed read, an invalid count, or an unavailable service all come back as unknown, and your guidance stays in place. A source verified as empty can still offer a reindex.

Secret scan checks the imported page

Secret scanning now checks the page that gets imported

BEFORE · RAW TRANSCRIPT
KEY=\"v\"

Escaped quote, missed by the scan

NOW · RENDERED PAGE
KEY="v"

The exact markdown gbrain imports

01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · bin/gstack-memory-ingest.ts

With scan secrets turned on, memory ingest now runs gitleaks on the rendered page, the exact markdown it imports. The raw transcript escapes its quotes, so a key written that way slipped past the scan.

Unfinished scans block the import

A secret scan that doesn't finish now blocks the import

gitleaks missingscan errorover 60 secondsreport over 16 MiB
→ file skipped, never imported unscanned
skipped files stay pending and retry on the next run
01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · setup-gbrain/memory.md

If gitleaks is missing, errors out, runs past a minute, or writes an oversized report, that file is skipped instead of imported unscanned. Skipped files stay pending and get retried on the next run.

02: The Aside browser

02

The Aside browser

The readiness check, on zsh and on failure.

Next, the Aside browser.

Aside check works in zsh

The Aside check now works in zsh, the Mac's default shell

BEFORE
$_T aside repl …

zsh looks for one command named "gtimeout 30"

NOW
_gs_d aside repl …

A function, so sh, bash and zsh all agree

01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · scripts/resolvers/aside.ts

The Aside readiness check now works under zsh. It kept its timeout in a variable that zsh won't split, so a stock Mac always answered not running, and browsing skills fell back to bundled Chromium.

Aside failures say why

A failed Aside check now says which way it failed

ASIDE_TIMEOUTprobe deadline exceeded
ASIDE_UNAVAILABLEno way to bound the probe
ASIDE_CLI_ERRORthe CLI's exit code
ASIDE_NOT_RUNNINGopen the app and retry
01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · scripts/resolvers/aside.ts

A failed check now reports a timeout, a missing way to bound the call, a command error with its exit code, or a missing ready signal. Only that last case asks you to open the app.

03: Reviews and debugging

03

Reviews and debugging

/plan-eng-review, /review, /investigate, /freeze

Reviews and debugging.

Engineering review runs in order

/plan-eng-review runs its steps in order

1Preparation
→
2Complexity gate
→
3Checkable decisions
calibration write-back stays off without its explicit gate
01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · CHANGELOG.md

/plan-eng-review now follows its preparation and complexity gate paths in order, and every decision and required report write stays checkable. Calibration write-back stays off unless its explicit gate turns it on.

Codex findings enter Fix-First

In /review, supported Codex findings go through Fix-First

The outside challenge is still informational. Its supported findings now face Fix-First's approval and convergence gates.

01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · review/sections/adversarial.md

In /review, the outside Codex challenge is still informational. But its supported findings now enter the Fix-First step, where its approval and convergence gates apply.

Investigate releases only its own lock

/investigate releases only the edit lock it took

ITS OWN LOCK
acquire → FREEZE_OWNER

Released with that token when the run ends

YOUR /freeze BOUNDARY
FREEZE_PRESERVED

Left exactly where you set it

01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · investigate/SKILL.md.tmpl

/investigate now takes its edit lock with an owner token, and releases only that lock when the run ends. A freeze boundary you set beforehand stays exactly where you put it.

Freeze lasts until unfreeze

A /freeze boundary lasts until you run /unfreeze

Ending or killing the conversation leaves the boundary in place.

01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · freeze/SKILL.md.tmpl

A /freeze boundary now persists until you run /unfreeze. Ending the conversation, or killing it, leaves the boundary in place, so run /unfreeze when you want your edits unrestricted again.

04: Browse and setup

04

Browse and setup

Uploads, ARM Linux, and three quieter fixes.

Browse and setup.

Upload checks real paths

browse upload checks every file's real path

BEFORE
absolute paths only

A relative path skipped the directory check

NOW
realpath → validateReadPath

Every path, resolved through symlinks

01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · browse/src/write-commands.ts

The browse upload command now resolves every file through its symlinks and checks the real path against the allowed directories. Before, a relative path skipped that directory check.

ARM Chromium on Ubuntu 26.04

Setup installs ARM Chromium on ARM Ubuntu 26.04

x86_64ubuntu24.04-x64 build
aarch64 · arm64ubuntu24.04-arm64 build
anything elseinstall skipped, reason in the summary
01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · setup

On Ubuntu 26.04, setup now picks Playwright's ARM Chromium build on ARM machines, instead of forcing the x64 build. On any other chip, it skips the install and says why.

Extension APIs, displays, PGLite

Browse keeps real extension APIs and leaves busy displays alone

Stealth mode keeps Chrome's own runtime.connect and sendMessage
On Linux, browse won't take over an X display already in use
A busy local PGLite database reports as locked
01 gbrain02 Aside03 Reviews04 Browse & setup
garrytan/gstack · stealth.ts · xvfb.ts · gbrain-local-status.ts

Browse's stealth mode now keeps Chrome's own extension messaging calls. On Linux, it won't take over an X display that's already in use. And a busy local PGLite database reports as locked.