Split out from #34 (upstream sync, 283 commits) so the merge itself stays reviewable. Findings come from a Codex review of the merge commit, each verified locally.
Only the items below were introduced by our merge — that is, fork-owned content that now contradicts what upstream brought in. Upstream's own pre-existing bugs are listed separately at the bottom and are deliberately out of scope.
P1 — operational, must happen right after #34 merges
Upstream adds .github/workflows/update-skill-sources.yaml (nightly, 06:30). It authenticates through ./.github/actions/setup-git-bot using RYOPPIPPI_NIX_UPDATER_APP_ID / _PRIVATE_KEY, which this fork does not have, so it fails every night at setup-git-bot — the same failure mode that got the other five bot workflows disabled.
The existing API-side disables are keyed to the five older workflow IDs and do not cover this one. It registers as active the moment the merge reaches the default branch, so this cannot be done ahead of time and is not a code change. This is exactly the case CLAUDE.md warns about: "upstream renaming a workflow file resurfaces it as a new, active workflow — re-check gh workflow list --all after a large sync."
P2 — fork-owned content contradicting the merged tree
The guide describes holding Fn for Hyper, holding Tab for Workspace, a Workspace+Return alias, and a Ctrl+arrow scheme shelling out to omniwmctl. #34 deliberately kept our karabiner.ts, which has only the application Enter/Shift+Enter swaps and the Cmd-tap Kana/Eisuu rule — none of those mappings exist. Following the guide as written does not work here. Rewrite it around the literal OmniWM modifier chords, or around whatever bindings we settle on in settings.toml.
Line 20 (from upstream) forbids git add -A, git add ., and git add -u, requiring explicit paths. Line 115 (our Worktree Workflow section) requires git add -A before every build. docs/maintenance.md likewise prescribes git add . / git add -A. An agent following the later instruction stages unrelated or private working-tree changes. Settle on explicit paths throughout.
P3 — stale references in fork-owned docs
Out of scope — upstream's own bugs, inherited verbatim
Confirmed present on upstream/main too, so fixing them here only widens our diff and makes the next sync heavier. Better reported upstream.
.github/workflows/update-node-packages.yaml:47 runs bash nix/packages/node/update.sh, but only update.nu survives. Latent — the workflow is disabled on this fork.
agents/README.md:10, agents/shared/git-staging.md:6, and agents/skills/skill-creator/SKILL.md:18 still reference nix/modules/home/programs/codex.nix after the move to codex/default.nix.
.github/workflows/nix-build.yaml path filters cover flake.*, nix/**, and the setup actions, but not the newly added registry/sources/** or registry/sources.lock.json. PRs touching only the registry skip both activation-package build jobs.
Verified clean, for the record
The Codex review found no defects in the areas flagged as highest-risk: the hand-merged flake.lock (no orphaned or unreachable nodes, no broken follows chains, no inconsistent _2/_3 suffixes), the retained karabiner.ts / karabiner.json pair (identical and structurally consistent, so skipping regeneration was correct), and the fork's personal.nix / username plumbing.
Split out from #34 (upstream sync, 283 commits) so the merge itself stays reviewable. Findings come from a Codex review of the merge commit, each verified locally.
Only the items below were introduced by our merge — that is, fork-owned content that now contradicts what upstream brought in. Upstream's own pre-existing bugs are listed separately at the bottom and are deliberately out of scope.
P1 — operational, must happen right after #34 merges
gh workflow disable "Bot: Update skill source pins"Upstream adds
.github/workflows/update-skill-sources.yaml(nightly, 06:30). It authenticates through./.github/actions/setup-git-botusingRYOPPIPPI_NIX_UPDATER_APP_ID/_PRIVATE_KEY, which this fork does not have, so it fails every night atsetup-git-bot— the same failure mode that got the other five bot workflows disabled.The existing API-side disables are keyed to the five older workflow IDs and do not cover this one. It registers as active the moment the merge reaches the default branch, so this cannot be done ahead of time and is not a code change. This is exactly the case CLAUDE.md warns about: "upstream renaming a workflow file resurfaces it as a new, active workflow — re-check
gh workflow list --allafter a large sync."P2 — fork-owned content contradicting the merged tree
nix/modules/darwin/programs/omniwm/README.md:23-29documents Karabiner behaviour this fork does not have.The guide describes holding Fn for Hyper, holding Tab for Workspace, a
Workspace+Returnalias, and aCtrl+arrow scheme shelling out toomniwmctl. #34 deliberately kept ourkarabiner.ts, which has only the application Enter/Shift+Enter swaps and the Cmd-tap Kana/Eisuu rule — none of those mappings exist. Following the guide as written does not work here. Rewrite it around the literal OmniWM modifier chords, or around whatever bindings we settle on insettings.toml.CLAUDE.mdcontradicts itself about staging.Line 20 (from upstream) forbids
git add -A,git add ., andgit add -u, requiring explicit paths. Line 115 (our Worktree Workflow section) requiresgit add -Abefore every build.docs/maintenance.mdlikewise prescribesgit add ./git add -A. An agent following the later instruction stages unrelated or private working-tree changes. Settle on explicit paths throughout.P3 — stale references in fork-owned docs
docs/cheatsheet.md:232documents thenrnabbreviation, which upstream removed fromfish/config/abbrs_aliases.fishin favour of a regex abbreviation expanding inputs such asnixpkgs:ripgrep. As written it is passed to the shell as an unknown command.docs/maintenance.md:56,docs/cheatsheet.md:16, anddocs/cheatsheet.md:342point atnix/modules/home/programs/cmux.nix, which upstream relocated tocmux/default.nix(same forcodex.nix).CLAUDE.md:90-92callsgh-graph"fork-only and therefore never updated by upstream". This was never true — it came from upstream, and upstream removed the extension and its flake input ina43969d5, which chore: sync upstream/main (283 commits) #34 takes. Either restore it or correct the sentence.Out of scope — upstream's own bugs, inherited verbatim
Confirmed present on
upstream/maintoo, so fixing them here only widens our diff and makes the next sync heavier. Better reported upstream..github/workflows/update-node-packages.yaml:47runsbash nix/packages/node/update.sh, but onlyupdate.nusurvives. Latent — the workflow is disabled on this fork.agents/README.md:10,agents/shared/git-staging.md:6, andagents/skills/skill-creator/SKILL.md:18still referencenix/modules/home/programs/codex.nixafter the move tocodex/default.nix..github/workflows/nix-build.yamlpath filters coverflake.*,nix/**, and the setup actions, but not the newly addedregistry/sources/**orregistry/sources.lock.json. PRs touching only the registry skip both activation-package build jobs.Verified clean, for the record
The Codex review found no defects in the areas flagged as highest-risk: the hand-merged
flake.lock(no orphaned or unreachable nodes, no brokenfollowschains, no inconsistent_2/_3suffixes), the retainedkarabiner.ts/karabiner.jsonpair (identical and structurally consistent, so skipping regeneration was correct), and the fork'spersonal.nix/usernameplumbing.