fix: post-merge audit follow-ups for estop, cron monitor/notepad, delegation batch gate - #81696
Merged
Merged
Conversation
Four fix-forwards from the adversarial post-merge audit of the Aug 7 unreviewed merge batch: - estop (#81148): is_engaged() now fails SAFE (engaged) on stat errors; the gateway estop gate lets recognized slash commands and replies owned by in-flight work (update prompts, clarify, slash-confirm, tool approvals, running sessions) through instead of consuming them; new gateway /pause [reason|off] command gives messaging-only operators an in-band engage/resume path (busy_policy=dispatch so it works mid-run). - cron monitor mode (#81138): execution-mode invariants (monitor x no_agent, monitor_script x monitor_url, no_agent-requires-script) now have ONE owner (_validate_job_mode_invariants) called from BOTH create_job and update_job, so the create-time invariant can no longer be silently violated through the update door. - cron notepad (#81139): remove_job now clears the job's notepad rows (clear_notepad was dead code -> orphaned KV state forever); clear is best-effort and no-ops without creating notepad.db. - delegation batch gate (#81141): template-marker regex narrowed to multi-word placeholder shapes only (<feature name>, {file_path}) so generics (Vec<T>), HTML tags, JSON snippets, glob braces and f-string style no longer reject legitimate batches; duplicate-goal rejection removed (best-of-N fan-outs are legitimate).
૮ >ﻌ< ა ci reviewran on c7da396
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes the four fix-forward findings from the adversarial post-merge audit of the Aug 7 unreviewed merge batch (#81138, #81139, #81141, #81148) — no reverts needed, each gap closed in place.
Changes
agent/estop.py,gateway/run.py,hermes_cli/commands.py):is_engaged()now fails safe (engaged) on stat errors, matching the module's own corrupt-sentinel doctrine — previously a permission/I/O error silently lifted the pause./pause [reason | off]command — the in-band engage/resume path for messaging-only operators who have no host shell (busy_policy="dispatch"so it works mid-run). Slack routes it via/hermes pause(50-slash cap).cron/jobs.py): execution-mode invariants (monitor×no_agent, monitor_script×monitor_url, no_agent-requires-script) extracted to one owner_validate_job_mode_invariants()called from bothcreate_jobandupdate_job— flippingno_agent=Trueon a monitor job via update previously disabled the monitor silently (the scheduler's no_agent short-circuit runs before the monitor gate). Scoped to changed fields so legacy records keep loading; clearing the monitor and flipping no_agent in one update stays valid.cron/jobs.py,cron/notepad.py):remove_jobnow callsclear_notepad(it was dead code — deleted jobs orphaned their KV rows in notepad.db forever). Best-effort: a notepad failure never blocks removal, and clearing no-ops without creating the DB.tools/delegate_tool.py): template-marker regex narrowed to multi-word placeholder shapes only (<feature_name>,{file path},<FEATURE-NAME>) — generics (Vec<T>), HTML tags, JSON snippets, glob braces, and f-string style no longer reject legitimate batches. Duplicate-goal rejection removed entirely: identical-goal fan-outs (best-of-N / ensemble sampling) are legitimate.Validation
/pause offcronjob updateno_agent=True on monitor jobcronjob removewith notepad rowsRefactor to Vec<T>Targeted suites: 133/133 (
tests/test_estop.py+5 new,tests/cron/test_monitor_kind.py+5 new,tests/cron/test_notepad.py+3 new,tests/tools/test_delegate_batch_validation.pyreshaped,tests/hermes_cli/test_commands.py), plus 549/549 acrosstests/cron/+ delegate tool suites and 26/26 gateway slash-access/busy suites. E2E with real files in a temp HERMES_HOME: estop roundtrip, regex accept/reject sets, update-path invariant, remove→notepad cleanup.Infographic