fix(kanban survivor): hold ignored orphan bytes on in-place repo replacement and unbound cleanup (t_60592755) - #1018
Conversation
…acement and unbound cleanup (t_60592755) P8: a recorded repo re-initialised in place (same key, dispatch commit unreachable) whose new repo ignores non-derived files now HOLDs on every preserve exit (landed, ordinary capture, reclamation). P9: the cleanup 'missing <= absent' relaxation no longer treats an UNBOUND operator ref as reclamation authority (_authoritative_repositories), so the same-call cleanup after an unbound completion keeps the ignored bytes. 8 real kb.complete_task / remove_workspace_dir regressions; 4 mutants each killed by their intended test.
…ps terminal transitions at 38 git spawns (ref-cost gate)
…sions (Windows footgun lint)
|
🤖 merged-by: apollo · lane: kanban-merge-pass · gate: BYPASS: FleetReview paused by Ace 2026-09-22 (state/fleetreview-pause marker present) · why: t_60592755: kanban survivor: guard ignored orphan bytes after recorded repo identity replace; Argus off card review (Ace 13:08), CI green |
|
🤖 merged-by: apollo · lane: kanban-merge-pass · gate: BYPASS: FleetReview paused by Ace 2026-09-22 (state/fleetreview-pause marker present) · why: t_ad32cdab: kanban survivor: malformed recorded landed receipt must persist a HOLD on reclam; Argus off card review (Ace 13:08), CI green |
|
🤖 merged-by: apollo · lane: kanban-merge-pass · gate: BYPASS: FleetReview paused by Ace 2026-09-22 (state/fleetreview-pause marker present) · why: t_60592755: kanban survivor: guard ignored orphan bytes after recorded repo identity replace; worker completed in place, CI green |
FleetReviewReview: post-merge · head
Post-merge review ( Reviewed with 1 of 2 model families — xai unavailable. profile: light (rule: default light: lines 407<800, files 2<1000000, hunks 4<1000000, no hot path) · round 0 · members: B-assert-ctx, B-state, F, G · families: openai Confidence: 1/5 Findings
FleetReview provenance · models: B=gpt-6-sol, D=grok-4.6, F=gpt-6-sol · cost: $1.86 · duration: 22m 29s · rounds: 2 · files examined: 2 |
FleetReviewFleetReview's daily member-call budget is spent (60/600 for 2026-09-28 UTC); review skipped. FleetReview · reviewKind: skipped-budget |
Kanban card t_60592755. Argus found two data-loss paths in round 4 of #924. Both were already present before that PR, on merge-base 4a8affe and on its head. I reproduced both on current main (df5eb16) with Argus's probe
r4_coverage_probe.py: P8 endeddone/landed and P9b endeddone/bundle. In both, the workspace was deleted and no stored artifact held the bytes.P8: a recorded repo re-initialised in place over ignored bytes
Repo key
ais recorded at SHA A. The worker then runsrm -rf a/.git && git init aand has the new repo ignore the old committed file. Every existing check still passes:_reposreturnsa,bases - keysis empty, andstatus --untracked-files=allis clean. But the new HEAD cannot reach A. The fix is_replaced_orphans(workspace, bases), which runs ahead of everypreserveexit (landed, ordinary capture and reclamation). It HOLDs only when both of these are true:_DERIVED_DIRSare excluded, and so are nested repos).P9: an unbound claim got deletion authority through the cleanup relaxation
The
missing <= absentrelaxation used_vouched_repositories(previous), and that set counts UNBOUND refs. So after an unbound--survivor-prcompletion, the same call's cleanup deleted the vanished repo's ignored bytes. That is the_reusableone-completion-only contract being bypassed. The new_authoritative_repositoriescounts bound refs, bundles and sidecar patches, but not unbound refs. Reclamation now HOLDs when coverage comes from an unbound ref alone._vouched_repositories, which the non-shrink index guard uses, is unchanged.Evidence
tests/hermes_cli/test_kanban_survivor_orphan_bytes.pyhas 8 realkb.complete_task/remove_workspace_dircases and all 8 pass. They cover P8 on the landed, ordinary and reclamation exits; the P8c positive control; a derived-dirs-only control; a same-identity-with-ignored-.envcontrol; P9 with an unbound claim (the card completes and the bytes are retained); and a P9 bound-claim positive control (it reclaims).binding,848_findingsandstale_bases, 120 passed.This does not overlap #924's missing-key coverage and should not be folded into it.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.