
# Auto-lander & dev-pipeline settings

These decide what the **auto-lander** — the part of Omniscio that merges your finished branches into
your main branch on its own — has to see before it will land something, and how much it is allowed
to spend rescuing a branch that gets stuck. Most are set from the CLI or by an agent rather than
from a switch on a Settings screen, which is why the **?** drawer is where they are explained.

---

## PR checklist mode {#autoLanderPrChecklistMode}

What the auto-lander does when a branch it is about to merge never went through the pre-merge PR
checklist. **Off** (the default) means the checklist is not consulted at all, so nothing is ever held
on its account. **Advisory** means it works out and records what it would have refused, but blocks
nothing — that is how you measure the real cost before arming it. **Enforce** means it refuses the
branch and hands it back to you to finish. Accepted values: off / advisory / enforce. Kill switch
`AMC_DISABLE_LANDER_PR_CHECKLIST_VETO=1`.

---

## Require a tests receipt before landing {#landerTestsReceiptRequired}

On by default. A branch must carry proof that its tests ran at the exact commit it is being tagged
from, or its ready-to-merge tag is not believed and the branch is held. Note what this asks for: the
receipt has to exist and cover that commit — it does **not** have to be green, because a red that is
already on your main branch is not this branch's fault. It is read live on every land, so suspending
it needs no restart. Turn it off only while the system that produces receipts is down, or no branch
can earn one and the auto-lander quietly stops landing **everything**. `AMC_DISABLE_LANDER_GATE_PROOF_VETO=1`
overrides the whole family.

---

## A missing tests receipt is not a pass {#landerTestsPresenceRequired}

On by default. This is the _presence_ half of the rule above, on its own lever: turn it off and a
branch with **no** tests receipt at all is allowed through — for the window where the receipt lane
cannot run, so absence stops being treated as something a person has to wave through by hand. A
receipt that records a real regression is still refused, because that half keeps reading the
tests-receipt switch above. Accepted values: on / off.

---

## Require a passing typecheck before landing {#landerTypecheckReceiptRequired}

On by default. The auto-lander refuses to merge a branch unless that exact version of it has a
recorded **passing** typecheck — proof the code compiles, rather than a promise that it does. Turn it
off only when the system that produces those receipts is broken: then no branch can earn one, and the
auto-lander stops merging everything, which looks like it forgetting to stamp finished sessions.
Turning it off suspends only this one check; the translation, receipt and checklist checks keep
blocking. Read live per land, so no restart is needed.

---

## Land-time tests arm {#landerGateProofTestsEnforced}

Whichever way this is set, it refuses a branch whose tests are red **because your main branch is
already red** — it refuses the ones nobody checked. On means a missing, stale, or "the cloud could
not say" answer is treated exactly like a failure, because no answer is not a pass. Off (the default)
is warn-only: it still works out what it would have refused and writes it down, so you can see the
real cost — measured at roughly one land in six — before switching it on. This is the land-time check
and is deliberately separate from the tag-time one, which runs once when a branch is first marked
ready and never again.

---

## Pause landing while master is broken {#landerMasterBuildFreezeEnforced}

On means a **confirmed** broken main branch actually stops merging, on every route and not just the
in-app one: after each merge the app builds your main branch, and if that build genuinely fails,
landing pauses for up to 20 minutes so nothing else piles onto the breakage. The pause clears itself
the moment your main branch builds again, and expires on its own regardless, so it can never get
stuck. The scripts that repair your main branch by pulling from the remote are never blocked —
blocking those would trap you. Off (the default) is warn-only, which is the safe way to watch it for
a day first.

---

## Auto-preserve uncommitted changes so landing can resume {#landerAutoPreserveClearEnabled}

When on, the auto-lander copes by itself with the commonest reason a landing stalls: uncommitted
changes sitting in a paused checkout. It saves them to a recovery ref, clears the checkout, and
carries on landing — **nothing is discarded**, and you get an inbox alert telling you how to get the
work back. When off (the default) the same situation pauses landing and asks you to clear it
yourself. This is the one setting on this page with a switch of its own: **Settings → Performance**.

---

## The auto-lander still lands while the machine is busy {#landerOutranksAgents}

On by default. The auto-lander gets priority over agent sessions for git capacity, so landing keeps
flowing on a busy machine: it skips the load-gate defer while agents yield. Off restores the original
behaviour, where landing defers behind load exactly like everything else. The boot-settle defer is
unaffected either way, and `AMC_DISABLE_LANDER_OUTRANK=1` is the kill switch.

---

## Stuck conflicts are handed back even under load {#autoLanderLoadTriageEnabled}

On by default. While the machine is too busy to land, a branch whose merge conflicts is still handed
back to you instead of sitting un-handed-off for hours behind the load gate. It is cheap and
rate-limited, and it **never** lands under load — it only hands back. Set it to `false` to disable, or
use `AMC_DISABLE_LANDER_LOAD_TRIAGE=1`, which always wins.

---

## Gate the git repair helper {#landerGitExecUserHarmGateEnabled}

Off by default. This is whether the helper that watches for git itself failing on this machine may
**repair** it on its own, rather than only reporting. It stays off until there is real evidence of how
often its judgement would have been right, because the repair can touch every other agent's git at
once — a wrong call is felt across the whole machine, not just by the session it was watching. While
off it still notices, and raises an inbox card describing what it saw.

---

## How many paid rescue sessions may run at once {#autoLanderMaxConcurrentRemediations}

How many **paid** AI rescue sessions the auto-lander may run at once when a branch gets stuck — the
sessions that rebase, re-gate and re-tag a stranded branch so it can land on its own. **Each one is a
billed session**, so raising this drains a stranded backlog several-at-a-time instead of about two per
half hour, and costs more in parallel. Default **4**, maximum **12**; capped so a churn storm cannot
spawn a swarm and load your machine, and the spawn pacer still paces the actual starts.

---

## Which model the rescue sessions use {#autoLanderRemediationModel}

Which AI model the auto-lander's **paid** rescue sessions run on — the sessions that rebase, re-gate
and re-tag a stranded branch. The default is the cheap Claude **worker** tier (`claude-worker`), not
your Claude default model: a rescue runs the most mechanical work in the product against a
fully-specified prompt, so the cheap tier drains the same backlog for far less money. Choosing
**Default** instead runs rescues on whatever your Claude default model is — on a normal install the
flagship, which costs materially more per attempt. A stronger model is more likely to succeed on a
genuinely hard conflict, so it may produce fewer attempts at a higher cost each. Read at spawn, with a
Claude fallback if the chosen tier is unavailable.

---

## How many re-tag sessions may run at once {#autoLanderStaleTagHealMaxConcurrent}

How many concurrent stale-tag self-heal sessions the auto-lander may run — the sessions that re-gate
and re-tag a branch whose tip moved past its ready tag. Each is a billed session, though a short one,
because a stale-tag heal is a fast re-tag rather than a full rescue. **0 (the default) means
uncapped**, which is safe for work this short; set a positive number to impose a limit. It uses its
own budget, so raising it never starves the conflict or translation rescues.
