f02504b863
version = "0.2.189" -> "0.2.189+rb0.3.2", per local/AGENTS.md "Version conventions": every Cat 2 fork is <upstream>+rb<branch>. The label is what makes the fork traceable to both its upstream base and the Red Bear branch it was built for. +rb is build metadata, which semver ignores when matching, so ^0.2 requirements still resolve to the fork -- confirmed, the rust lockfile now reads libc v0.2.189+rb0.3.2 from the path source. A -rb suffix would be read as a pre-release and would NOT satisfy them, which is exactly why the project mandates +rb. Two things this surfaced: - fork-upstream-map: libc moved from snapshot to diverged. The fork is vendored from the crates.io PACKAGE, whose file set differs from the upstream git tag by construction (no .github/, adds .cargo_vcs_info.json), so a tag content-diff reported differences that mean nothing -- 'missing files that exist in upstream' for files the package never ships. diverged states the real relationship. - local/recipes/dev/gcc16/.vendored-upstream added. Extracting GCC 16.1.0 put upstream's vendored Rust crates under local/recipes/*/source/, so sync-versions.sh treated datafrog/log/polonius-engine as Cat 1 in-house crates and wanted to stamp them 0.3.2. The marker is the documented escape hatch (BUILD-SYSTEM.md section 7). Both gates clean: verify-fork-versions reports no violations, sync-versions --check reports no gcc16 drift.