Skip to content

fix(kanban survivor): hold ignored orphan bytes on in-place repo replacement and unbound cleanup (t_60592755) - #1018

Merged
Kyzcreig merged 4 commits into
mainfrom
kanban/survivor-orphan-bytes-t_60592755
Sep 25, 2026
Merged

Kyzcreig merged 4 commits into
mainfrom
kanban/survivor-orphan-bytes-t_60592755

Conversation

@Kyzcreig

@Kyzcreig Kyzcreig commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Kanban card t_60592755. Argus found two data-loss paths in round 4 of #924. Both were already present before that PR, on merge-base 4a8affe and on its head. I reproduced both on current main (df5eb16) with Argus's probe r4_coverage_probe.py: P8 ended done/landed and P9b ended done/bundle. In both, the workspace was deleted and no stored artifact held the bytes.

P8: a recorded repo re-initialised in place over ignored bytes

Repo key a is recorded at SHA A. The worker then runs rm -rf a/.git && git init a and has the new repo ignore the old committed file. Every existing check still passes: _repos returns a, bases - keys is empty, and status --untracked-files=all is clean. But the new HEAD cannot reach A. The fix is _replaced_orphans(workspace, bases), which runs ahead of every preserve exit (landed, ordinary capture and reclamation). It HOLDs only when both of these are true:

  1. the recorded commit is no longer an object in the repo at that key (the identity was replaced), and
  2. that repo ignores non-derived files (_DERIVED_DIRS are excluded, and so are nested repos).

P9: an unbound claim got deletion authority through the cleanup relaxation

The missing <= absent relaxation used _vouched_repositories(previous), and that set counts UNBOUND refs. So after an unbound --survivor-pr completion, the same call's cleanup deleted the vanished repo's ignored bytes. That is the _reusable one-completion-only contract being bypassed. The new _authoritative_repositories counts bound refs, bundles and sidecar patches, but not unbound refs. Reclamation now HOLDs when coverage comes from an unbound ref alone. _vouched_repositories, which the non-shrink index guard uses, is unchanged.

Evidence

  • The new tests/hermes_cli/test_kanban_survivor_orphan_bytes.py has 8 real kb.complete_task / remove_workspace_dir cases and all 8 pass. They cover P8 on the landed, ordinary and reclamation exits; the P8c positive control; a derived-dirs-only control; a same-identity-with-ignored-.env control; P9 with an unbound claim (the card completes and the bytes are retained); and a P9 bound-claim positive control (it reclaims).
  • Each mutant was killed by the test meant to catch it:
    • M1, orphan gate off: the 3 P8 HOLD tests fail.
    • M2, identity check removed: the same-identity control fails.
    • M3, ignored-bytes check removed: the P8c and derived controls fail.
    • M4, unbound refs treated as authority: the P9 unbound test fails.
  • Neighbouring suites pass: binding, 848_findings and stale_bases, 120 passed.
  • Argus probe after the fix: P8 → HOLD with the bytes kept; P8c → done; P9/P9b → HOLD with the bytes kept; P1/P1b/P4 → reclaim; P5/P5b → HOLD, as before.

This does not overlap #924's missing-key coverage and should not be folded into it.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Apollo and others added 4 commits September 24, 2026 14:37
…acement and unbound cleanup (t_60592755)

P8: a recorded repo re-initialised in place (same key, dispatch commit
unreachable) whose new repo ignores non-derived files now HOLDs on every
preserve exit (landed, ordinary capture, reclamation).

P9: the cleanup 'missing <= absent' relaxation no longer treats an UNBOUND
operator ref as reclamation authority (_authoritative_repositories), so the
same-call cleanup after an unbound completion keeps the ignored bytes.

8 real kb.complete_task / remove_workspace_dir regressions; 4 mutants each
killed by their intended test.
…ps terminal transitions at 38 git spawns (ref-cost gate)
@Kyzcreig

Copy link
Copy Markdown
Collaborator Author

🤖 merged-by: apollo · lane: kanban-merge-pass · gate: BYPASS: FleetReview paused by Ace 2026-09-22 (state/fleetreview-pause marker present) · why: t_60592755: kanban survivor: guard ignored orphan bytes after recorded repo identity replace; Argus off card review (Ace 13:08), CI green

@Kyzcreig
Kyzcreig added this pull request to the merge queue Sep 24, 2026
@Kyzcreig
Kyzcreig removed this pull request from the merge queue due to a manual request Sep 24, 2026
@Kyzcreig

Copy link
Copy Markdown
Collaborator Author

🤖 merged-by: apollo · lane: kanban-merge-pass · gate: BYPASS: FleetReview paused by Ace 2026-09-22 (state/fleetreview-pause marker present) · why: t_ad32cdab: kanban survivor: malformed recorded landed receipt must persist a HOLD on reclam; Argus off card review (Ace 13:08), CI green

@Kyzcreig
Kyzcreig enabled auto-merge September 24, 2026 23:40
@Kyzcreig
Kyzcreig added this pull request to the merge queue Sep 24, 2026
@Kyzcreig

Copy link
Copy Markdown
Collaborator Author

🤖 merged-by: apollo · lane: kanban-merge-pass · gate: BYPASS: FleetReview paused by Ace 2026-09-22 (state/fleetreview-pause marker present) · why: t_60592755: kanban survivor: guard ignored orphan bytes after recorded repo identity replace; worker completed in place, CI green

Merged via the queue into main with commit 6735098 Sep 25, 2026
57 checks passed
@Kyzcreig
Kyzcreig deleted the kanban/survivor-orphan-bytes-t_60592755 branch September 25, 2026 02:13
@Kyzcreig Kyzcreig added the fleetreview:post-merge Ask FleetReview to review this MERGED pull (merge commit vs first parent) label Sep 25, 2026
@ang-prism

ang-prism Bot commented Sep 27, 2026

Copy link
Copy Markdown

FleetReview

Review: post-merge · head 6735098c8b58 · duration 22m 35s
Profile: light (merit: default light: lines 407<800, files 2<1000000, hunks 4<1000000, no hot path) · policy: changed-lines>400
Roster: B-assert-ctx → gpt-6-sol (openai), B-state → gpt-6-sol (openai), F → gpt-6-sol (openai), G → gpt-6-sol (openai)

PARTIAL — ensemble escalated: family floor: too few distinct model families completed

This review did not reach a trusted verdict, so it is not a gate pass and the findings below may be incomplete. They are posted so they can be read rather than lost in a terminal record.

Post-merge review (fleetreview:post-merge override): this reviewed the merge commit against its first parent — the bytes that already shipped. It is not a pre-merge gate pass.

Reviewed with 1 of 2 model families — xai unavailable.

profile: light (rule: default light: lines 407<800, files 2<1000000, hunks 4<1000000, no hot path) · round 0 · members: B-assert-ctx, B-state, F, G · families: openai

Confidence: 1/5

Findings

  • P1 hermes_cli/kanban_survivor.py:1887 — Unverified commit · agreed: B-assert-ctx,B-state (openai)
  • P0 tests/hermes_cli/test_kanban_survivor_orphan_bytes.py:128 — Failing tests · agreed: B-assert-ctx,B-state (openai)
  • P1 hermes_cli/kanban_survivor.py:1932 — A dangling dispatch commit bypasses the orphan-byte guard · agreed: F,G (openai)

FleetReview provenance · models: B=gpt-6-sol, D=grok-4.6, F=gpt-6-sol · cost: $1.86 · duration: 22m 29s · rounds: 2 · files examined: 2

@ang-prism

ang-prism Bot commented Sep 28, 2026

Copy link
Copy Markdown

FleetReview

FleetReview's daily member-call budget is spent (60/600 for 2026-09-28 UTC); review skipped.


FleetReview · reviewKind: skipped-budget

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fleetreview:post-merge Ask FleetReview to review this MERGED pull (merge commit vs first parent)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant