Summary
Cloud sessions install gh from Ubuntu's own archives, which ships 2.45.0. The work-item-tracker seam requires >= 2.94, so every seam verb fails in every cloud session — including claim, which /work-items:work treats as a non-optional prerequisite of dispatch.
Observed in this session:
$ gh --version
gh version 2.45.0 (2025-07-18 Ubuntu 2.45.0-1ubuntu0.3)
$ plugins/work-items/tools/work-item-tracker/work-item-tracker.sh capabilities
work-item-tracker: gh >= 2.94 required for native sub-issue/dependency flags (found: 2.45)
$ plugins/work-items/tools/work-item-tracker/work-item-tracker.sh list-frontier --autonomous
work-item-tracker: gh >= 2.94 required for native sub-issue/dependency flags (found: 2.45)
Why this matters
/work-items:work is coordination-dependent. Step 0 reclaim, Step 1 list-frontier, and the Step 5 claim are all seam verbs. With the seam unusable:
- No race-safe claim is available.
claim (assignee + lease) is the atomic acquisition point and the only collision signal between concurrent lanes; worktree isolation is explicitly not a substitute. A cloud lane can only degrade to an assignee-only claim with no lease, which the tracker-seam reference calls out as a parked decision, not yet a supported mode.
- Stale leases never get reclaimed. Step 0's idempotent
reclaim cannot run, so leases from crashed cloud sessions accumulate until an operator clears them.
- Frontier selection falls back to hand-rolled REST.
list-frontier derives open ∧ unblocked ∧ unassigned and applies --autonomous; without it, a lane must reimplement that filter per-invocation, which is exactly what the seam exists to prevent.
This is not a work-items-only blocker — it is every seam verb (create-item, get-item, claim, renew-lease, reclaim, link-blocks, add-sub-item, list-sub-items, list-frontier, capabilities).
Root cause
melodic-software/standards → components/cloud-environment/setup.sh, Track A:
# gh comes from Ubuntu's own archives: the official cloud-environments
# worked example is exactly `apt update && apt install -y gh`, and
# cli.github.com (the newer upstream apt repo) is NOT on the default
# allowlist. A silent miss is caught by the verification checklist.
if apt-get install -y gh >>"$LOG" 2>&1; then
The comment is accurate about why the archive was chosen. What it does not account for is that the archive's gh is far behind the floor a fleet component now depends on. Ubuntu ships 2.45.0; the seam needs 2.94+.
The stated "silent miss is caught by the verification checklist" does not cover this case: gh is installed, so the presence check passes. Nothing checks its version against consumers' floors.
Constraint on the fix
Two obvious remedies are both blocked by the environment's network allowlist, so neither is a drop-in:
-
cli.github.com (upstream apt repo) — the setup script's own comment records it as not on the default allowlist.
-
Release tarball from github.com/cli/cli/releases — verified unreachable from this session:
$ curl -sIL -o /dev/null -w "%{http_code}\n" https://github.com/cli/cli/releases/latest
403
So this likely needs an allowlist change alongside the script change, not a script change alone. Recording that here so whoever picks it up does not burn a cycle discovering it.
Suggested approach
- Add whichever host the chosen install path needs (
cli.github.com, or objects.githubusercontent.com for release assets) to the environment's Custom allowlist.
- Install a pinned
gh >= 2.94 in Track A, keeping the apt install as the fallback so a blocked allowlist costs an outdated gh rather than none.
- Add a version assertion to the verification checklist, not just a presence check — this class of failure is invisible to
command -v.
Alternative worth considering
The seam's floor exists for native sub-issue/dependency flags. Verbs that need none of that (claim, renew-lease, reclaim, capabilities) arguably should not be gated behind the same version check as add-sub-item / link-blocks. A per-verb floor would let cloud sessions claim work race-safely on an older gh while only the native-hierarchy verbs hard-fail. That is a work-items change rather than a standards one, and may be the cheaper half of the fix.
Generated by Claude Code
Summary
Cloud sessions install
ghfrom Ubuntu's own archives, which ships 2.45.0. The work-item-tracker seam requires >= 2.94, so every seam verb fails in every cloud session — includingclaim, which/work-items:worktreats as a non-optional prerequisite of dispatch.Observed in this session:
Why this matters
/work-items:workis coordination-dependent. Step 0reclaim, Step 1list-frontier, and the Step 5claimare all seam verbs. With the seam unusable:claim(assignee + lease) is the atomic acquisition point and the only collision signal between concurrent lanes; worktree isolation is explicitly not a substitute. A cloud lane can only degrade to an assignee-only claim with no lease, which the tracker-seam reference calls out as a parked decision, not yet a supported mode.reclaimcannot run, so leases from crashed cloud sessions accumulate until an operator clears them.list-frontierderives open ∧ unblocked ∧ unassigned and applies--autonomous; without it, a lane must reimplement that filter per-invocation, which is exactly what the seam exists to prevent.This is not a work-items-only blocker — it is every seam verb (
create-item,get-item,claim,renew-lease,reclaim,link-blocks,add-sub-item,list-sub-items,list-frontier,capabilities).Root cause
melodic-software/standards→components/cloud-environment/setup.sh, Track A:The comment is accurate about why the archive was chosen. What it does not account for is that the archive's
ghis far behind the floor a fleet component now depends on. Ubuntu ships 2.45.0; the seam needs 2.94+.The stated "silent miss is caught by the verification checklist" does not cover this case:
ghis installed, so the presence check passes. Nothing checks its version against consumers' floors.Constraint on the fix
Two obvious remedies are both blocked by the environment's network allowlist, so neither is a drop-in:
cli.github.com(upstream apt repo) — the setup script's own comment records it as not on the default allowlist.Release tarball from
github.com/cli/cli/releases— verified unreachable from this session:So this likely needs an allowlist change alongside the script change, not a script change alone. Recording that here so whoever picks it up does not burn a cycle discovering it.
Suggested approach
cli.github.com, orobjects.githubusercontent.comfor release assets) to the environment's Custom allowlist.gh>= 2.94 in Track A, keeping the apt install as the fallback so a blocked allowlist costs an outdatedghrather than none.command -v.Alternative worth considering
The seam's floor exists for native sub-issue/dependency flags. Verbs that need none of that (
claim,renew-lease,reclaim,capabilities) arguably should not be gated behind the same version check asadd-sub-item/link-blocks. A per-verb floor would let cloud sessions claim work race-safely on an olderghwhile only the native-hierarchy verbs hard-fail. That is awork-itemschange rather than astandardsone, and may be the cheaper half of the fix.Generated by Claude Code