feat(bin): surface documentation-vault drift during bootstrap - #22
Merged
Merged
Conversation
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
* feat(bin): widen the remote runtime PATH and add a remote doctor preflight The fixed remote entrypoint hard-coded a four-directory PATH, so a remote account whose tools live under nix or a per-user profile could not run basic Firstmate work without a login shell. The entrypoint now composes its child PATH from the code root's bin, the account's ~/.local/bin, the common package-manager directories that actually exist on the host, and the portable system tail, deduplicated and in a fixed order, still under env -i with the same variable allowlist and no shell command string. fm-remote-doctor.sh reports that exact PATH by inheriting it from its own entrypoint launch rather than recomposing it, so the ordering keeps one owner. It is read-only, reports where each required and optional tool resolved, and exits non-zero naming every required tool that did not. Remote seeding runs it as a preflight before anything is created on the host and restores the registry when it fails. * no-mistakes(review): Harden remote git authorization and missing-tool diagnostics * no-mistakes(document): Document remote PATH doctor and safe shims * no-mistakes(lint): Fix ShellCheck findings in remote path tests * no-mistakes(lint): Suppress exported fixture's false-positive ShellCheck warning
A project's knowledge vault could fall dozens of commits behind with nothing surfacing it, because noticing depended entirely on someone remembering to look. fm-vault-drift.sh closes that gap as a cheap, read-only inspection of every registered project clone, relayed by bootstrap as a VAULT_DRIFT diagnostic line in both normal and detect-only sessions. It is detection only: a vault is curated knowledge, so an automated writer would manufacture exactly the stale-but-confident prose the check exists to catch. The two vault shapes are told apart by inspecting the clone, never by trusting registry prose, because they need different remedies: an in-repo vault a crewmate can refresh in its own worktree, and an external symlinked vault living in a separate repo that an isolated project worktree structurally cannot write. An absent or broken link reports distinctly from staleness, since "drift cannot be measured at all" is the failure that hides staleness rather than a form of it. Staleness carries the commit count behind and the drift window, both derived from commit timestamps so a run is deterministic. A directory that merely shares the name vault/ without the OKF bundle marker is never reported, so test fixtures and sample trees raise no false alarm. Also fixes two pre-existing test problems found while validating: the session-start ordering and composition cases forced a MISSING diagnostic by removing node, which a host-installed /usr/bin/node silently satisfied again, and the test-runner coverage guard compared LC_ALL=C-sorted files with an ambient-locale comm, so it failed outright in any non-C locale.
HelloWorldSungin
force-pushed
the
fm/fm-vault-drift-check
branch
from
August 4, 2026 04:05
bd374bd to
1a541eb
Compare
CI runs on Git 2.54, which enables automatic maintenance by default. Against this file's rapid fixture commits that maintenance races the index and deletes loose objects the pending commit still references, so the fixture dies with "invalid object ... Error building trees" partway through the 52-commit case and the stale external vault is never measured. Reproduced at 8/8 under Git 2.54 and 0/8 after disabling maintenance on the fixture repos; Git 2.51 and 2.43 never trip it, which is why it passed locally and only surfaced in CI. gc.auto=0 does not cover it - this is the maintenance path, not the gc one. The detector is unchanged: this only makes fixture history deterministic.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Re-landed on the fork from the already-validated branch (previously opened as kunchenguid#1634, which this account cannot merge upstream). Code unchanged.
Intent
Build a cheap, deterministic check that surfaces documentation-vault drift for every registered project, so a vault can never again silently fall dozens of commits behind (an ArkNode-AI vault fell 52 commits / 7 days behind on 2026-07-27 and nothing surfaced it - detection depended entirely on a human remembering to look).
Settled design constraints that were given up front, so they are deliberate choices rather than oversights:
Integration was specified to follow the EXISTING detect-only bootstrap convention rather than inventing a new alarm channel, so it emits a VAULT_DRIFT: diagnostic line from bin/fm-bootstrap.sh's detect path (running in detect-only/lock-refused sessions too, since it is read-only), with the handling playbook added to the bootstrap-diagnostics skill and the load trigger added to AGENTS.md section 13.
Two pre-existing, unrelated problems were also found while validating this work, and the standing instruction is to fix test failures encountered along the way. One of them - the session-start suite forcing its MISSING diagnostic by deleting fake node, which a host-installed /usr/bin/node silently satisfied again - was deliberately REVERTED in a follow-up commit on this branch because the same fix already exists on another branch with an open PR, and carrying two copies would guarantee a merge conflict. That revert commit is intentional, not an accidental regression. The other one is kept: bin/fm-test-run.sh's coverage guard compared LC_ALL=C-sorted files using an ambient-locale comm, so --check-coverage failed outright in any non-C locale; nothing else is addressing it.
What Changed
Risk Assessment
✅ Low: The detector is read-only and well bounded, and the prior post-sync, marker-validation, and same-repository false-negative paths are now addressed at their shared boundaries with focused regression coverage.
Testing
After branch-diff inspection, all three targeted behavior scripts and the non-C-locale coverage check passed; fixed-timestamp direct and detect-only bootstrap CLI runs produced attached transcripts proving correct classifications, deterministic counts and windows, marker suppression, and read-only behavior, with a clean worktree afterward.
Evidence: Direct vault-drift CLI transcript
Evidence: Detect-only bootstrap relay transcript
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 2 issues found → auto-fixed (2) ✅
bin/fm-bootstrap.sh:906- The required goal says vault drift must not silently fall dozens of commits behind, but this check runs before normal-modefleet_sync. A clone can initially appear current, then bootstrap fast-forwards it by 52 commits and exits without checking the resulting state. Run detection afterfleet_syncin normal mode while retaining a read-only detect-only path.bin/fm-vault-drift.sh:141- The required no-false-alarm criterion relies on00-Home.mdto distinguish a vault, but every rootvaultsymlink is accepted andcheck_externalnever verifies that marker. A project with an unrelatedvaultsymlink to any Git repository can therefore emit a stale-vault diagnostic. Validate the marker before stale classification, distinguishing declared-but-invalid targets from undeclared non-vault symlinks.🔧 Fix: Fix post-sync vault drift and marker validation
1 error still open:
bin/fm-vault-drift.sh:191- The required external shape is “an external symlinked vault pointing at a separate git repo,” butrev-parse --show-toplevelaccepts an ancestor repository. A declared ignoredvault/directory containing00-Home.mdbut no separate.gitresolves to the project repo, makingvault_tsequal project HEAD and silently reporting no drift. Before measuring timestamps, require the resolved vault repository to differ from the project repository and reporttarget invalidotherwise.🔧 Fix: Reject project repository as external vault target
✅ Re-checked - no issues remain.
✅ **Test** - passed
✅ No issues found.
Inspectedgit diff --statand changed files for1e247571aa75e00b00c7a01c4830025ecd44dc61..838f0195e7c0a5bee94ae7c63c3e6a140665875ebin/fm-test-run.sh tests/fm-vault-drift.test.sh tests/fm-bootstrap.test.sh tests/fm-test-run.test.shLC_ALL=en_US.utf8 bin/fm-test-run.sh --check-coverageRanbin/fm-vault-drift.shtwice against fixed-timestamp external, in-repo, absent-link, and markerless fixtures; compared output byte-for-byte and verified unchanged Git signaturesRanFM_BOOTSTRAP_DETECT_ONLY=1 bin/fm-bootstrap.shagainst the fixture and captured the relayed diagnosticsgit status --porcelainconfirmed no testing artifacts remained in the worktree✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.