A pre-push adversarial review refuted this round's own completeness claim, and it
was right on all three counts. Fixes, in the order they matter:
1. The watch enumeration was still a hand-list, and it was measurably incomplete.
It missed kilo's SINGULAR `command/`, hermes' `skills/gsd` (a whole directory
whose name carries no `gsd-` prefix, so no prefix rule could ever reach it),
`plugins/gsd-core.js`, and the unprefixed subtrees the installer fills --
`hooks/lib`, `hooks/package.json`, `scripts/lib`, `scripts/changeset`.
The parents are now DERIVED from the capability registry's own
artifactLayout.global destSubpath values, exactly as TEST_ENV_BASE derives its
keys, plus a named list for the non-registry paths the installer writes
directly. A capability declaring a new destination now extends the watch set
in the commit that declares it. Scope note: only `global` is walked --
`workflows` is declared LOCAL-only (windsurf) and is not a config-root parent.
2. resolveExtraWatchTargets carried the identical ambient-only defect that
Blocker 3 closed one function over: it resolved $GSD_HOME/.gsd and each kimi
descriptor from the ambient env alone, so a child that BLANKED those vars
wrote to the HOME-derived fallback while the guard watched the override. Both
legs are now unioned, matching resolveLiveConfigRoots.
3. The order-independence claim for the scan budget was too strong. It holds
BELOW the global ceiling; once MAX_TOTAL_ENTRIES is exhausted, which targets
get curtailed still depends on iteration order -- inherent to any shared
aggregate bound. The residual is now named in the docblock and the test title
says which regime it pins, instead of asserting the general claim. Negative
limits are clamped at 0 so an injected value cannot masquerade as a scan bound.
The module's KNOWN GAP now names its remaining residuals (the loose generator
scripts, the kimi native-root hook bundle) rather than implying completeness --
an unqualified claim here just invites the same refutation next round. Both
under-watch, which fails quiet.
Reverting the derivation fails two tests; reverting the fallback leg fails a
third.