fix(kanban): C4 backfill — close 11 board-gate bypasses (t_027d7fe7) - #1358
Conversation
…t_027d7fe7) 11 confirmed instances fixed with RED-on-base/GREEN regressions: #951 gateway sessionless slash identity, #956 run-scoped runtime cap, #960 goal CLI child fails closed, #999 can't contraction + dashboard claimed-review exit, #1021 no SIGTERM without spawn evidence, #1034 malformed survivor row HOLDs, #1074 session owner profile over env profile (x2), #1081 tool send-back needs a bindable session, #1234 arm only the card's own handoff PR. Verified: 5 affected test files 187 passed; same tests on base source 20 failed (the new/changed regressions only). #985 -> t_becb0042; FP/drops in PR body.
…st seam Missing spawned upper bound now makes _real_pid_started_in_claim answer None (unverified) instead of True: termination holds, liveness still fails closed to alive. Moving it out of _terminate_reclaimed_worker keeps the test seam authoritative (CI slice 2: 3 fixtures with stubbed identity). progress_stall fixtures now record the pid via _set_worker_pid (spawned event), as the dispatcher does; the reclaim_unprovable fixture edit is reverted. Verified: progress_stall, core_functionality, c4_board_gates, second_claim, reclaim_unprovable, termination_identity, kanban_db: 339 passed; the 2 failures also fail on unmodified base (worker-env CLI tests).
|
🤖 merged-by: apollo · lane: kanban-merge-pass · gate: ADVISORY (FleetReview not green for 66dfd3e): fleetreview-advisory-20260927-standing.md · why: t_027d7fe7: C4 backfill slice: hermes-agent kanban/board gates — 21 instances (kanban_db.py ; Argus off card review (Ace 13:08), CI green |
FleetReviewReview: post-merge · head Post-merge review ( profile: light (rule: default light: lines 558<800, files 13<1000000, hunks 27<1000000, no hot path) · round 0 · members: B-assert-ctx, B-state, F, G · families: openai,xai Confidence: 1/5 Findings
FleetReview provenance · models: B=gpt-6-sol, D=grok-4.6, F=gpt-6-sol · cost: $2.24 · duration: 17m 04s · rounds: 1 · files examined: 13 |
C4 retro-backfill (FleetReview 2026-09-27), kanban/board gates slice. Card t_027d7fe7, parent t_a2bf7813. Base 5a9d284.
Every one of the 21 instances was re-checked at base. Result: 11 confirmed and fixed here, 1 confirmed and routed to a follow-up card, 4 false positives, 5 dropped. That is 9 of 21 not fixed (43%), well above the report's 15-20% estimate.
Fixed (each has a test that fails on base and passes with the fix, plus a control)
_caller_session_idos.environfallback returns whichever chat's session is in the shared env, so a sessionless/kanbannow resolves to None_spawned_owner_alivemax_runtime_seconds, not the card's current value (which can be shortened after release)_REVIEW_NA_INABILITYcan'tand curly-apostrophen’trunningcard whose run was claimed fromreviewcan no longer be moved to todo/triage/scheduled. The move is refused before the reviewer worker is signalled;readystill resumes review_terminate_reclaimed_worker_state()and the row-shape check moved inside a HOLD handler. A malformedsurvivorrow now HOLDs withworkspace_held_actor_profiles/check_home_session--operatorand assignee authority can no longer come from a root-home repoint that readsdefault_operator_review_session_ref). Sessionless, cron and delegate-child callers are refusedmetadata.pr_url/pr/pr_urls,--survivor-pr) are armed for fleet-merge. A PR mentioned only in the prose still routes the card to review but is never armedExisting tests I changed (each one encoded the bypass):
test_e2e_green_slice_armed_milestone_not: now names the PR inmetadata.pr_url.test_expired_bounded_run_*: bounds the RUN, not the card afterwards.test_reclaim_requeues_when_termination_actually_succeeded: seeds the dispatcher'sspawnedevent.Confirmed, not fixed here
admitted_this_tick, and the reservation only holds back a spawn slot. This is a scheduling design change, so it goes to follow-up card t_becb0042.False positives (no change)
_caller_session_lineagemonkeypatch and ran the file: 22 passed, and the cross-key refusal still holds with the real fallback. The mock hides no bypass._worker_owns_cardany link kind:@_home_session_guarded("link", task_param="child_id")onlink_tasks. A worker cannot link itself onto a foreign card without a takeover, which is audited._review_na_reason_ok('n/a: couldnot run mutation tests')→ False. The existing param'n/a: could not run'already covers it.complete_taskitself runsif not _parents_satisfied(conn, task_id): return Falsefirst, and inside its write txn.Dropped
authorspoof: the dashboard has no trusted per-user identity to derive from (comments use the samepayload.author). There is nothing to fix without adding an auth identity.Verification
Local runs are narrow only, through ~/.hermes/scripts/test-gate on the runtime venv (py3.11); CI is the suite. The 5 directly affected files: 187 passed with the fix. With the source reverted to base and the tests kept: 20 failed. The failures are exactly the new and changed regressions; controls pass on base. On a wider neighbour set, every other failure also fails identically on unmodified base (CLI tests that pick up this worker's env). ruff F/E9: no new findings.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.