Review and delivery
Read the change across repos in one workspace, then push it or land it — preview first, apply against the fingerprint you reviewed.
Review it first
/ivar-reviewOpens the feature in a multi-root VSCode workspace: promoted repos on the feature branch, everyone else on their default branch. One window holding the whole change, instead of four windows you have to correlate by hand.
Deliver — push or land
/ivar-deliverDelivery reaches real remotes, so it is two steps with a human in between. There are two modes: push (the default) opens a pull request per promoted repo, and land merges into each repo's default branch locally.
Push (default)
Pushes each promoted repo's branch to its remote and creates or updates a pull request against that repo's base. The PR carries the full history of the feature branch — no squash, no rewrite. Each repo's PR is independent: if one gets approved and merged before the others, nothing breaks.
Preview — side-effect-free (no writes). Reads local state and the remote for every promoted repo: branch name, remote, base branch, existing PR status, HEAD and base SHAs. Computes a content-based fingerprint. Writes nothing.
ivar feature deliver <feature> --previewApply — pinned to what you read. Validates the fingerprint from the preview you reviewed against current state, then pushes each accepted repo's branch and creates or updates its pull request.
ivar feature deliver <feature> --fingerprint <fp>A repo whose push fails gets no pull request created or edited. Fix the
push problem, then preview and apply again. ivar feature status <feature> shows
each pull request's state, and a feature whose pull requests merged stops
reporting as active.
Deliver a subset of repos
Pass --only <repo> (repeatable) to restrict preview and apply to those
promoted repos. Use it when one repo's PR has already merged and another repo
of the same feature still needs its PR updated.
ivar feature deliver <feature> --only web --preview
ivar feature deliver <feature> --only web --fingerprint <fp>The selection is part of the fingerprint, so apply with the same --only
values the preview used. --repo only scopes PR metadata; it never selects
repos. A partial delivery leaves the Sibling PRs comment untouched.
Land
Merges the feature branch into each promoted repo's default branch locally, fast-forward only, then pushes each default branch to its remote. No pull request is opened.
The merge must be fast-forward; if the default branch has diverged, land refuses and points at ivar feature rebase. Pushes after merge are best-effort per repo; a push failure produces a warning and leaves the local default branch merged, so rerunning the land is safe.
Every check land can make — fast-forwardability, a dirty default worktree, a rebase in progress, remote-default evidence, each repo's verification checks — runs against every repo before the first one is written. A problem in the last repo stops the first from being touched.
Merging itself is all-or-nothing by compensation, not by transaction: the repos have separate Git directories, so nothing spans them. Land records each default's original commit and, if a later merge fails, resets the already-merged repos back to it. When that reset also fails the batch really is half-landed, and deliver.land_rollback_failed reports it — naming the merge that failed and every repo it could not restore. It is never reported as success.
Preview — side-effect-free (no writes). Reads local state and the remote for every promoted repo. Checks whether the feature branch can fast-forward to the default branch in each bare repo (local, no fetch). Computes a content-based fingerprint that includes the delivery mode. Writes nothing.
ivar feature deliver <feature> --preview --landApply — pinned to what you read. Validates the fingerprint, then fast-forward merges into each repo's default branch. If any merge fails, previously merged repos are rolled back. Pushes each default branch to its remote (best-effort — a push failure is a warning, not an abort; rerunning is safe).
ivar feature deliver <feature> --land --fingerprint <fp>The fingerprint is never regenerated for you
Apply refuses if state drifted since the preview, and it never swaps in a freshly computed fingerprint. If someone pushed to one of the branches while you were reading, you find out instead of shipping something you never saw.
The fingerprint also encodes the delivery mode: a fingerprint approved for a push cannot apply as land, and a fingerprint approved for land cannot apply as push.
Side-effect-free means no writes
The preview performs no writes — it does not push, merge, or modify any branch. It does read the remote (for the unpushed-commits blocker and the PR action), because reading local config instead would be cheaper and wrong.
Execution
Run an approved Plan through a provider-native coordinator while Ivar records a durable, provider-neutral Run Receipt.
Hall upkeep
Keeping the hall honest from inside the harness — reconciling against ivar.json, listing what is registered, and authoring the setup script a fresh worktree needs.