Skip to content

chore: rolling promotion dev -> main - #2702

Closed
namastex888 wants to merge 22 commits into
mainfrom
dev
Closed

namastex888 wants to merge 22 commits into
mainfrom
dev

Conversation

@namastex888

@namastex888 namastex888 commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

Rolling Promotion PR

Auto-maintained rolling promotion PR from dev to main.

Process:

  • This PR is automatically created and kept open
  • Human reviews and merges when ready
  • Label ready-to-merge added when all checks pass

IMPORTANT: Merge with "Create a merge commit" — NEVER squash.
Squash merging breaks history sync between dev and main,
causing the next rolling PR to show all commits again.

Human approval required for merge to production.

Summary by CodeRabbit

  • Release
    • Updated Genie plugin/package versions to 5.260727.9 across supported manifests.
  • New Features
    • Added Worktree isolation hardening wish defining concurrency rules, safety checks, and reviewer snapshot guidance.
  • Documentation
    • Marked stable-release security gate as complete and updated remediation status.
    • Expanded workspace concurrency/dispatch docs (including reviewer snapshot and shared-workspace freeze rules).
  • Bug Fixes
    • Enhanced genie doctor with worktree scanning and a safer --fix cleanup for accumulated genie launch worktrees.
  • Tests
    • Added end-to-end coverage for doctor-worktrees behavior and --fix safety guarantees.

automagik-genie and others added 3 commits July 27, 2026 12:38
…table shipped

v5.260727.5 (run 30240023804, dispatched 2026-07-27): 40/41 jobs green
(1 structural skip), 36 assets, immutable, latest/homolog/dev manifests
all advanced to 5.260727.5. The two open criteria are demonstrated:
production approval ran live with dispatcher != approver
(prevent_self_review), and channel manifests published reviewer-free
via the genie-release-bot App across v5.260726.12→v5.260727.5.
docs(wish): stable-release-security-gate DONE — first full-pipeline stable shipped
@coderabbitai

coderabbitai Bot commented Jul 27, 2026 •

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

The release gate is marked complete and all Genie manifests are synchronized to 5.260727.9. Documentation centralizes shared-workspace and reviewer-snapshot rules, while genie doctor gains fail-closed launch-worktree scanning, cleanup, reporting, and end-to-end tests.

Changes

Release, policy, and worktree hardening

Layer / File(s) Summary
Release records and version metadata
.genie/INDEX.md, .genie/wishes/stable-release-security-gate/WISH.md, package.json, .claude-plugin/marketplace.json, plugins/genie/..., plugins/hermes-genie/plugin.yaml
Marks the stable-release gate complete and updates manifests from 5.260727.4 to 5.260727.9.
Isolation and reviewer-snapshot contract
.genie/wishes/worktree-isolation-hardening/WISH.md, plugins/genie/references/*, plugins/genie/skills/*, skills/*
Defines orchestrator-controlled Git state, shared-workspace freeze rules, detached review snapshots, cleanup behavior, and mirrored guidance.
Launch worktree scanning and cleanup
src/genie-commands/doctor-worktrees.ts, src/term-commands/launch.ts
Parses and classifies launch worktrees, resolves integration branches, reports fail-closed dispositions, and removes only merged, clean worktrees.
Doctor integration and CLI behavior
src/genie-commands/doctor.ts, src/genie.ts
Integrates scanning and cleanup into genie doctor, exports CheckResult, and expands --fix help text.
End-to-end worktree validation
src/genie-commands/doctor-worktrees.test.ts
Tests Git parsing, branch resolution, safety classification, cleanup idempotency, foreign-worktree handling, JSON reporting, and doctor wiring.

Estimated code review effort: 4 (Complex) | ~60 minutes

Possibly related issues

Possibly related PRs

Suggested reviewers: automagik-genie

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 70.97% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title matches the PR’s main purpose: an automated rolling promotion from dev to main.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4d23459198

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .genie/wishes/stable-release-security-gate/WISH.md
automagik-genie and others added 6 commits July 27, 2026 13:30
…n of PR #2594

Adapt, not adopt: keep the two-mode concurrency contract and add the
git-state freeze (shared-workspace subagents never checkout/switch/
reset/stash/rebase; only the orchestrator moves HEAD) — the invariant
the recorded incident actually violated. Doctor grows a worktrees
residue check with fail-closed --fix (no new commands); reviews get
read-only snapshot worktrees pinned to the reviewed commit. Flip
conditions recorded so the policy self-revises on evidence. Declines
the unconditional mandate and defers the integration-worktree protocol
behind a recorded trigger. Credits lirazsiri (isolation diagnosis,
reviewer-snapshot design, GC design); #2594 closes in favor on landing.

Council: 4 lenses, 2 rounds, consensus + dissent recorded 2026-07-27.
Applies the FIX-FIRST verdict from the independent plan review:
H1 Simplicity Case section; H2 premise rewritten from live probe
evidence (native worktree isolation EXISTS in the harness — verified
by a dispatched probe agent: real linked worktree, persistent when
changed, named branches, shared object store — but is not /work-ready:
guard false positives, untracked nested placement, unverified in-place
task-state access; flip condition (i) sharpened to those three gaps);
H3 review-snapshot gets a real code surface (src/lib/review-snapshot.ts)
plus the freeze carve-out for snapshot plumbing; H4 red validation gate
replaced; H5 parity check added to validations (bun run check never
enforced mirrors); H6 plugins/genie/references/dispatch-contract.md
rule 3 in scope; H7 doctor work isolated in doctor-worktrees.ts with
complexity-ceiling constraint; M1-M7 + L1 (genie.ts flag text,
greppable canonical phrase, Wave-2 dependency narrowed to policy,
enumeration via git worktree list --porcelain, integration-branch
resolution rule, post-merge closure checklist, test naming).
H8: probe gap (b) was cross-repo contamination — the probe ran in the
workspace repo; the genie repo ignores .claude/worktrees/ (since
225a56d). Deleted from Decision 1 and flip condition (i).
H9: gap (c) closed by design evidence — genie-db.ts resolves the DB
via git-common-dir so all linked worktrees share one genie.db
(production precedent: launch panes). Flip condition (i) collapses to
the one real gap: isolation-guard ergonomics.
M8 (deliberate): review-snapshot goes prose-only — a helper whose only
caller is its own test is the #2594 decoration pattern this wish
condemns; the raw commands are natively fail-safe (worktree add
--detach touches no branch; worktree remove refuses dirty). Doctor
stays the janitor for crashed reviews. Immutability check moved to QA.
M9 QA scoped to CI (macOS ui-bridge failure named as non-gate).
M10 carve-out single-owned by policy. M11 grep -eq 4 with ':!.genie'.
M12 config tier dropped (no such surface exists; present-need gate).
…+ 4 advisory residuals

Final verdict SHIP after 2 fix loops. Residuals applied: issue text
for the native-isolation pilot names the single remaining gap (guard
ergonomics); the snapshot-immutability success criterion is owned by
manual QA (prose-only group by design); Simplicity Case wording
matches the helper drop; Wave 2 re-rated 3/opus-high -> 1/opus-low
(docs edit — was a live mis-dispatch per the reviewer).
…ardening

docs(wish): worktree-isolation-hardening — APPROVED plan (adapts #2594)

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 4

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.genie/wishes/worktree-isolation-hardening/WISH.md:
- Around line 60-62: The worktree cleanup requirements must distinguish detached
review snapshots from launch worktrees: define a snapshot-specific safety proof
allowing clean snapshots at the reviewed commit to be removed even when
unmerged, while retaining unmerged launch worktrees. Update the related doctor
--fix behavior and regression tests to verify clean unmerged snapshots are
removable and clean unmerged launch worktrees are refused.
- Around line 141-143: The snapshot naming contract in the review dispatch
documentation must avoid collisions for concurrent reviews of the same commit.
Update the documented worktree path to include a unique per-dispatch identifier
or define explicit lease/reference-counting behavior, and update teardown
accordingly; ensure the contract includes coverage for concurrent same-commit
reviews.
- Around line 118-124: The doctor --fix cleanup flow must be failure-safe across
worktree and branch deletion. In the relevant doctor cleanup implementation, add
preflight validation for both removals, then handle branch-deletion failure
after successful worktree removal with rollback or explicit partial-state
recovery and a clear refusal reason; preserve the rule that any git error
prevents claiming successful reclamation. Add a regression test covering branch
deletion failure after worktree removal.
- Around line 116-119: The worktree cleanup flow must require positive Genie
ownership proof before deleting entries, rather than relying only on paths or
branch naming. Update the worktree enumeration/classification and doctor --fix
removal logic around resolveWorktreesBase and the existing launch worktree
metadata to verify durable provenance, retain entries without valid proof as
foreign, and add coverage for a matching non-Genie worktree that is not removed.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: b67d1f36-bde6-431a-b67a-fd79d5bb9b6c

📥 Commits

Reviewing files that changed from the base of the PR and between 4d23459 and d99cea2.

📒 Files selected for processing (1)
  • .genie/wishes/worktree-isolation-hardening/WISH.md

Comment thread .genie/wishes/worktree-isolation-hardening/WISH.md Outdated
Comment thread .genie/wishes/worktree-isolation-hardening/WISH.md
Comment thread .genie/wishes/worktree-isolation-hardening/WISH.md
Comment thread .genie/wishes/worktree-isolation-hardening/WISH.md Outdated
automagik-genie and others added 8 commits July 27, 2026 15:20
…conditions

Group 'policy' of wish worktree-isolation-hardening. Keeps the two-mode
contract (disjoint file ownership OR dedicated worktrees), adds the
freeze: shared-workspace subagents never run checkout/switch/reset/
stash/rebase — only the orchestrator moves HEAD; repo-level mutation
gets a worktree via genie launch or gets sequenced. Snapshot carve-out
(worktree add/remove/prune = orchestrator plumbing) at all canonical
sites. Flip conditions (i)-(iv) recorded in AGENTS.md with links to
investigate issues #2705 (mechanical freeze enforcement) and #2706
(native isolation:worktree pilot — one gap left: guard ergonomics).
Canonical phrase single-sourced to exactly 4 sites; paraphrase sites
(dream, native-surfaces x2, genie-hacks catalog, codex-integration-map)
now point instead of restating. Work-skill briefs gain a File-scope
item + freeze stanza. Review: SHIP (1 MEDIUM folded in: plugin
native-surfaces pointer).

Co-authored-by: Liraz Siri <liraz@liraz.org>
Group 'doctor-residue' of wish worktree-isolation-hardening. genie
doctor now enumerates launch-created worktrees via git worktree list
--porcelain (identity = wish/<slug>-<group> branch AND path under the
exported resolveWorktreesBase), classifies merged+clean / unmerged /
dirty / foreign, and reports per-entry disposition + reclaimable size.
doctor --fix removes only merged+clean entries: ancestry proof AND
clean tree chained in code, branch deleted with the worktree,
idempotent, any git error refuses that entry with the reason.
Integration branch: local dev, else remote default, else refuse all.

Review found (and reproduced) a HIGH before landing: bare refnames in
the ancestry probe let a colliding tag shadow the branch and authorize
deleting unmerged work. Both probe sides now use fully-qualified refs
({name, ref} split typed so display and probe forms cannot mix), with
branch-side and integration-side tag-shadow regression tests proving
refusal. New logic lives in doctor-worktrees.ts (doctorCommand delta
minimal; complexity 41/42). 617 tests green in src/genie-commands/.

Co-authored-by: Liraz Siri <liraz@liraz.org>
…rator-torn-down

Group 'review-snapshot' of wish worktree-isolation-hardening. The
review skill's Dispatch section now carries the snapshot contract:
provision git worktree add --detach at the exact commit under review,
reviewer works read-only and the verdict cites the pinned commit,
teardown via git worktree remove after the verdict. Pin by default
while other groups still write in the primary checkout; uncommitted
trees cannot be pinned. Prose-only by design — the commands are
natively fail-safe (add --detach touches no branch; remove refuses a
dirty tree).

Review caught a false claim before landing: doctor does NOT janitor
crashed snapshots (detached worktrees classify as foreign, never
touched by --fix) — the prose now states the confirmed reality and
instructs explicit removal for crash leftovers; the wish's risk row
records the same. Mirror in parity; canonical-phrase grep gate held
at 4.

Co-authored-by: Liraz Siri <liraz@liraz.org>
Ticks the five tree-verified success criteria (criterion 6, #2594
closure, stays open for post-merge), fixes the final-gate LOW (the
deliverable text still carried the disproven doctor-janitor claim the
fix loop corrected everywhere else), and records the execution trail
in the status header.
…ardening

feat: worktree isolation hardening — git-state freeze, doctor residue GC, reviewer snapshots
…ardening

docs(wish): worktree-isolation-hardening criterion 6 closed — #2594 dispositioned

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@plugins/genie/skills/dream/SKILL.md`:
- Line 49: Update Dream’s worker-isolation instruction in SKILL.md so it matches
the actual native delegation behavior and the shared-workspace contract: either
ensure worktrees are provisioned before dispatching workers, or remove the
mandatory dedicated branch/worktree requirement and explicitly require disjoint
file ownership with Git-state freezing. Keep the guidance consistent with the
contract defined in AGENTS.md and the work skill’s Dispatch section.

In `@src/genie-commands/doctor-worktrees.test.ts`:
- Around line 372-396: Update the runDoctor helper to capture process.exitCode
before its finally block restores the prior value, and return or otherwise
expose that captured code alongside the output. In the wiring tests that
exercise launch-worktree residue, assert the captured exit code is 0 alongside
the existing detail assertions, preserving the helper’s restoration behavior.

In `@src/genie-commands/doctor-worktrees.ts`:
- Around line 402-411: Update removeLaunchWorktree and its
cleanupLaunchWorktrees caller to re-verify the worktree branch’s ancestry
immediately before branch deletion, using the scanned IntegrationBranch.ref or a
re-resolved equivalent and the same fully qualified --is-ancestor probe. If the
probe fails or is inconclusive, retain the branch and return the existing
keep-branch error instead of running branch -D.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ace78630-7f51-4e57-9804-4f9d51341dec

📥 Commits

Reviewing files that changed from the base of the PR and between f5c6dc2 and cd4b8f5.

⛔ Files ignored due to path filters (1)
  • AGENTS.md is excluded by !*.md
📒 Files selected for processing (25)
  • .claude-plugin/marketplace.json
  • .genie/wishes/worktree-isolation-hardening/WISH.md
  • package.json
  • plugins/genie/.claude-plugin/plugin.json
  • plugins/genie/.codex-plugin/plugin.json
  • plugins/genie/package.json
  • plugins/genie/references/codex-integration-map.md
  • plugins/genie/references/dispatch-contract.md
  • plugins/genie/references/native-surfaces.md
  • plugins/genie/skills/dream/SKILL.md
  • plugins/genie/skills/genie-hacks/references/catalog.md
  • plugins/genie/skills/review/SKILL.md
  • plugins/genie/skills/work/SKILL.md
  • plugins/genie/skills/work/references/native-surfaces.md
  • plugins/hermes-genie/plugin.yaml
  • skills/dream/SKILL.md
  • skills/genie-hacks/references/catalog.md
  • skills/review/SKILL.md
  • skills/work/SKILL.md
  • skills/work/references/native-surfaces.md
  • src/genie-commands/doctor-worktrees.test.ts
  • src/genie-commands/doctor-worktrees.ts
  • src/genie-commands/doctor.ts
  • src/genie.ts
  • src/term-commands/launch.ts

Comment thread plugins/genie/skills/dream/SKILL.md
Comment thread src/genie-commands/doctor-worktrees.test.ts Outdated
Comment thread src/genie-commands/doctor-worktrees.ts Outdated
…onstration

Codex P2 on PR #2702 caught the closure commit leaving the wish
internally contradictory: the G2 acceptance criterion, the QA
criterion, two Review Results closure sentences, and INDEX's pr-2545
line still said no live two-maintainer run had been captured / stable
promotion remained BLOCKED. All five sites now record the evidence:
stable run 30240023804 (v5.260727.5) — automagik-genie dispatched,
independent maintainer approved (prevent_self_review), 36 immutable
assets, all three manifests advanced; credential half landed as the
genie-release-bot App (#2643/#2644).
namastex888 and others added 3 commits July 27, 2026 16:22
…econcile

docs(wish): reconcile stable-gate record with the live demonstration (Codex P2 on #2702)
…t code

CodeRabbit on the #2702 promotion caught the residual TOCTOU the group
review had classed acceptable: the ancestry proof authorizing the
forced branch delete ran only at scan time, so a commit landing on a
launch branch between cleanup's scan and 'branch -D' would be orphaned
(the tree stays clean, so 'worktree remove' cannot object).
removeLaunchWorktree now re-runs the fully-qualified is-ancestor probe
immediately before removal and refuses on any non-zero result; once
the worktree is removed the branch can gain no commits (git refuses a
second same-branch checkout), so the re-proof closes the whole window.
cleanup re-resolves the integration branch fail-closed and the fn is
exported for a direct-layer regression test (the outer API re-scans on
entry, making the inner window unreachable from public-API tests —
proven while writing the test).

Also (CodeRabbit trivial): the doctor wiring tests now capture and
assert process.exitCode === 0, locking in that launch-worktree residue
is warn-only. 618 tests green in src/genie-commands/.
fix(doctor): re-prove ancestry at removal time (CodeRabbit Major on #2702)
@automagik-genie

Copy link
Copy Markdown
Contributor

Closing and recreating this promotion authored by automagik-genie, so the maintainer can act as the independent approver instead of authoring their own promotion (same identity split the release process already uses everywhere else).

All four bot findings were dispositioned before the swap: the Codex P2 record contradiction is fixed on dev (#2709 — the stable-gate wish now records the live run 30240023804 at all five previously-contradicting sites); CodeRabbit's TOCTOU Major and exit-code Trivial are fixed on dev (#2710 — ancestry re-proof at removal time + warn-only exit-code assertions); the provenance Major is dispositioned as accepted-risk with recorded mitigations (merged+clean proofs bound the blast radius to a re-creatable checkout; gitignored-content loss is disclosed in output; --fix is operator-invoked) and flagged as future hardening alongside #2706. The replacement PR therefore carries strictly more than this one.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants