Skip to content

fix(kanban): malformed recorded landed receipt HOLDs on reclamation (t_ad32cdab) - #1034

Merged
Kyzcreig merged 1 commit into
mainfrom
kanban/survivor-malformed-landed-hold-t_ad32cdab
Sep 25, 2026
Merged

Kyzcreig merged 1 commit into
mainfrom
kanban/survivor-malformed-landed-hold-t_ad32cdab

Conversation

@Kyzcreig

@Kyzcreig Kyzcreig commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Argus r4 on #924 (P10, P12a-c): a malformed persisted kind: landed receipt made reclamation raise TypeError/KeyError out of preserve() and remove_workspace_dir(). The workspace was kept, but no held_reason and no workspace_held event were written, so the card's recovery state was silent.

Reproduced on main 67202e8 with the Argus probe: P10 (refs=null) TypeError; P12a (landed=null) TypeError; P12b (no sha) KeyError; P12c (['junk']) TypeError. After the fix all four HOLD. Each writes a persisted reason and a workspace_held event. P11/P4/P7 controls unchanged. P12d (refs=null with no missing repo) still reclaims correctly, because the live landed commits are re-verified.

Changes (hermes_cli/kanban_survivor.py):

  • _recorded_landed_claims() checks the recorded receipt shape. A bad shape raises a named SurvivorUnavailable reason.
  • _recorded_refs(): a non-list refs vouches for nothing, which gives the ordinary 'recorded repository missing' HOLD.
  • Backstop in preserve(): TypeError/KeyError/AttributeError/IndexError from any unchecked persisted shape now HOLDs with a persisted reason. The traceback is logged.

Tests (tests/hermes_cli/test_kanban_survivor_malformed_receipt.py): 7 malformed shapes, each through remove_workspace_dir and kb.safe_remove_workspace_dir, HOLD with a reason and an event. The valid receipt still reclaims through both. The backstop is tested with 4 exception types. On the pre-fix module 18/20 fail; the 2 valid-receipt controls pass. Locally, landed + live_tree + new file: 71 passed.

Hotspot: #1018 (t_60592755) also edits preserve(). Its hunk inserts above landed = ...; this PR changes the lines below it. They don't overlap, but merge order matters.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

…nstead of escaping _hold (t_ad32cdab)

Reclamation rebuilt the landed claim by indexing the persisted receipt
(previous["landed"], entry["repository"], entry["sha"]) and iterated
previous.get("refs", ()) -- a null refs is not the default. Malformed rows
(landed null / not a list / junk entry / missing sha, refs null with a
missing recorded repo) raised TypeError/KeyError, which neither preserve()
nor remove_workspace_dir() catch: workspace retained, but no held_reason
and no workspace_held event (Argus r4 P10/P12a-c on #924).

- _recorded_landed_claims(): validate the recorded receipt, refuse with a
  named SurvivorUnavailable reason.
- _recorded_refs(): non-list refs vouch for nothing -> ordinary
  'recorded repository missing' HOLD.
- preserve() backstop: TypeError/KeyError/AttributeError/IndexError from an
  unvalidated persisted shape HOLD with a persisted reason (traceback logged).

Tests: 7 malformed shapes x {remove_workspace_dir, safe_remove_workspace_dir}
HOLD with reason + event; valid receipt still reclaims; backstop x4. 18/20
fail on the pre-fix module (the 2 valid-receipt controls pass on both).
@Kyzcreig

Copy link
Copy Markdown
Collaborator Author

🤖 merged-by: apollo · lane: kanban-merge-pass · gate: BYPASS: FleetReview paused by Ace 2026-09-22 (state/fleetreview-pause marker present) · why: t_ad32cdab: kanban survivor: malformed recorded landed receipt must persist a HOLD on reclam; Argus off card review (Ace 13:08), CI green

@Kyzcreig
Kyzcreig enabled auto-merge September 24, 2026 23:40
@Kyzcreig
Kyzcreig added this pull request to the merge queue Sep 24, 2026
@Kyzcreig
Kyzcreig removed this pull request from the merge queue due to a manual request Sep 25, 2026
@Kyzcreig
Kyzcreig added this pull request to the merge queue Sep 25, 2026
Merged via the queue into main with commit c0c2d2b Sep 25, 2026
57 checks passed
@Kyzcreig
Kyzcreig deleted the kanban/survivor-malformed-landed-hold-t_ad32cdab branch September 25, 2026 03:15
@Kyzcreig Kyzcreig added the fleetreview:post-merge Ask FleetReview to review this MERGED pull (merge commit vs first parent) label Sep 25, 2026
@ang-prism

ang-prism Bot commented Sep 27, 2026

Copy link
Copy Markdown

FleetReview

Review: post-merge · head c0c2d2b7a1e3 · duration 4m 43s
Profile: light (merit: default light: lines 228<800, files 2<1000000, hunks 5<1000000, no hot path) · policy: below-size-and-path-gates
Roster: B-assert-ctx → gpt-6-sol (openai), B-state → gpt-6-sol (openai), F → gpt-6-sol (openai), G → grok-4.6 (xai)

Post-merge review (fleetreview:post-merge override): this reviewed the merge commit against its first parent — the bytes that already shipped. It is not a pre-merge gate pass.

profile: light (rule: default light: lines 228<800, files 2<1000000, hunks 5<1000000, no hot path) · round 0 · members: B-assert-ctx, B-state, F, G · families: openai,xai

Confidence: 3/5

Findings

  • P1 hermes_cli/kanban_survivor.py:2530 — Malformed survivor state can still bypass the new HOLD backstop · agreed: F (openai)

FleetReview provenance · models: B=gpt-6-sol, D=grok-4.6, F=gpt-6-sol · cost: $0.45 · duration: 4m 38s · rounds: 1 · files examined: 2

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fleetreview:post-merge Ask FleetReview to review this MERGED pull (merge commit vs first parent)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant