Skip to content

chore: rolling promotion dev -> main - #2712

Merged
namastex888 merged 29 commits into
mainfrom
dev
Jul 27, 2026
Merged

namastex888 merged 29 commits into
mainfrom
dev

Conversation

@automagik-genie

@automagik-genie automagik-genie commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

Rolling dev→main promotion (recreates #2702/#2711 with the correct author identity — automagik-genie authors, maintainer approves).

What promotes (dev releases v5.260727.6 → .10, all green)

Merging triggers version.yml's promotion path → mints the next stable candidate tag (release_ready=false; manual dispatch per runbook).

Summary by CodeRabbit

  • New Features
    • Added genie doctor diagnostics for launch worktrees, including safe detection and optional cleanup of eligible merged worktrees.
    • Added safeguards to retain dirty, unmerged, foreign, or uncertain worktrees.
    • Reviews can now use read-only snapshots pinned to the exact commit under review.
  • Documentation
    • Clarified workspace isolation, Git state ownership, dispatch rules, and review procedures.
    • Recorded completion of the stable release security gate.
  • Chores
    • Bumped the plugin and package version to 5.260727.11.

automagik-genie and others added 24 commits July 27, 2026 12:38
…table shipped

v5.260727.5 (run 30240023804, dispatched 2026-07-27): 40/41 jobs green
(1 structural skip), 36 assets, immutable, latest/homolog/dev manifests
all advanced to 5.260727.5. The two open criteria are demonstrated:
production approval ran live with dispatcher != approver
(prevent_self_review), and channel manifests published reviewer-free
via the genie-release-bot App across v5.260726.12→v5.260727.5.
docs(wish): stable-release-security-gate DONE — first full-pipeline stable shipped
…n of PR #2594

Adapt, not adopt: keep the two-mode concurrency contract and add the
git-state freeze (shared-workspace subagents never checkout/switch/
reset/stash/rebase; only the orchestrator moves HEAD) — the invariant
the recorded incident actually violated. Doctor grows a worktrees
residue check with fail-closed --fix (no new commands); reviews get
read-only snapshot worktrees pinned to the reviewed commit. Flip
conditions recorded so the policy self-revises on evidence. Declines
the unconditional mandate and defers the integration-worktree protocol
behind a recorded trigger. Credits lirazsiri (isolation diagnosis,
reviewer-snapshot design, GC design); #2594 closes in favor on landing.

Council: 4 lenses, 2 rounds, consensus + dissent recorded 2026-07-27.
Applies the FIX-FIRST verdict from the independent plan review:
H1 Simplicity Case section; H2 premise rewritten from live probe
evidence (native worktree isolation EXISTS in the harness — verified
by a dispatched probe agent: real linked worktree, persistent when
changed, named branches, shared object store — but is not /work-ready:
guard false positives, untracked nested placement, unverified in-place
task-state access; flip condition (i) sharpened to those three gaps);
H3 review-snapshot gets a real code surface (src/lib/review-snapshot.ts)
plus the freeze carve-out for snapshot plumbing; H4 red validation gate
replaced; H5 parity check added to validations (bun run check never
enforced mirrors); H6 plugins/genie/references/dispatch-contract.md
rule 3 in scope; H7 doctor work isolated in doctor-worktrees.ts with
complexity-ceiling constraint; M1-M7 + L1 (genie.ts flag text,
greppable canonical phrase, Wave-2 dependency narrowed to policy,
enumeration via git worktree list --porcelain, integration-branch
resolution rule, post-merge closure checklist, test naming).
H8: probe gap (b) was cross-repo contamination — the probe ran in the
workspace repo; the genie repo ignores .claude/worktrees/ (since
225a56d). Deleted from Decision 1 and flip condition (i).
H9: gap (c) closed by design evidence — genie-db.ts resolves the DB
via git-common-dir so all linked worktrees share one genie.db
(production precedent: launch panes). Flip condition (i) collapses to
the one real gap: isolation-guard ergonomics.
M8 (deliberate): review-snapshot goes prose-only — a helper whose only
caller is its own test is the #2594 decoration pattern this wish
condemns; the raw commands are natively fail-safe (worktree add
--detach touches no branch; worktree remove refuses dirty). Doctor
stays the janitor for crashed reviews. Immutability check moved to QA.
M9 QA scoped to CI (macOS ui-bridge failure named as non-gate).
M10 carve-out single-owned by policy. M11 grep -eq 4 with ':!.genie'.
M12 config tier dropped (no such surface exists; present-need gate).
…+ 4 advisory residuals

Final verdict SHIP after 2 fix loops. Residuals applied: issue text
for the native-isolation pilot names the single remaining gap (guard
ergonomics); the snapshot-immutability success criterion is owned by
manual QA (prose-only group by design); Simplicity Case wording
matches the helper drop; Wave 2 re-rated 3/opus-high -> 1/opus-low
(docs edit — was a live mis-dispatch per the reviewer).
…ardening

docs(wish): worktree-isolation-hardening — APPROVED plan (adapts #2594)
…conditions

Group 'policy' of wish worktree-isolation-hardening. Keeps the two-mode
contract (disjoint file ownership OR dedicated worktrees), adds the
freeze: shared-workspace subagents never run checkout/switch/reset/
stash/rebase — only the orchestrator moves HEAD; repo-level mutation
gets a worktree via genie launch or gets sequenced. Snapshot carve-out
(worktree add/remove/prune = orchestrator plumbing) at all canonical
sites. Flip conditions (i)-(iv) recorded in AGENTS.md with links to
investigate issues #2705 (mechanical freeze enforcement) and #2706
(native isolation:worktree pilot — one gap left: guard ergonomics).
Canonical phrase single-sourced to exactly 4 sites; paraphrase sites
(dream, native-surfaces x2, genie-hacks catalog, codex-integration-map)
now point instead of restating. Work-skill briefs gain a File-scope
item + freeze stanza. Review: SHIP (1 MEDIUM folded in: plugin
native-surfaces pointer).

Co-authored-by: Liraz Siri <liraz@liraz.org>
Group 'doctor-residue' of wish worktree-isolation-hardening. genie
doctor now enumerates launch-created worktrees via git worktree list
--porcelain (identity = wish/<slug>-<group> branch AND path under the
exported resolveWorktreesBase), classifies merged+clean / unmerged /
dirty / foreign, and reports per-entry disposition + reclaimable size.
doctor --fix removes only merged+clean entries: ancestry proof AND
clean tree chained in code, branch deleted with the worktree,
idempotent, any git error refuses that entry with the reason.
Integration branch: local dev, else remote default, else refuse all.

Review found (and reproduced) a HIGH before landing: bare refnames in
the ancestry probe let a colliding tag shadow the branch and authorize
deleting unmerged work. Both probe sides now use fully-qualified refs
({name, ref} split typed so display and probe forms cannot mix), with
branch-side and integration-side tag-shadow regression tests proving
refusal. New logic lives in doctor-worktrees.ts (doctorCommand delta
minimal; complexity 41/42). 617 tests green in src/genie-commands/.

Co-authored-by: Liraz Siri <liraz@liraz.org>
…rator-torn-down

Group 'review-snapshot' of wish worktree-isolation-hardening. The
review skill's Dispatch section now carries the snapshot contract:
provision git worktree add --detach at the exact commit under review,
reviewer works read-only and the verdict cites the pinned commit,
teardown via git worktree remove after the verdict. Pin by default
while other groups still write in the primary checkout; uncommitted
trees cannot be pinned. Prose-only by design — the commands are
natively fail-safe (add --detach touches no branch; remove refuses a
dirty tree).

Review caught a false claim before landing: doctor does NOT janitor
crashed snapshots (detached worktrees classify as foreign, never
touched by --fix) — the prose now states the confirmed reality and
instructs explicit removal for crash leftovers; the wish's risk row
records the same. Mirror in parity; canonical-phrase grep gate held
at 4.

Co-authored-by: Liraz Siri <liraz@liraz.org>
Ticks the five tree-verified success criteria (criterion 6, #2594
closure, stays open for post-merge), fixes the final-gate LOW (the
deliverable text still carried the disproven doctor-janitor claim the
fix loop corrected everywhere else), and records the execution trail
in the status header.
…ardening

feat: worktree isolation hardening — git-state freeze, doctor residue GC, reviewer snapshots
…ardening

docs(wish): worktree-isolation-hardening criterion 6 closed — #2594 dispositioned
…onstration

Codex P2 on PR #2702 caught the closure commit leaving the wish
internally contradictory: the G2 acceptance criterion, the QA
criterion, two Review Results closure sentences, and INDEX's pr-2545
line still said no live two-maintainer run had been captured / stable
promotion remained BLOCKED. All five sites now record the evidence:
stable run 30240023804 (v5.260727.5) — automagik-genie dispatched,
independent maintainer approved (prevent_self_review), 36 immutable
assets, all three manifests advanced; credential half landed as the
genie-release-bot App (#2643/#2644).
…econcile

docs(wish): reconcile stable-gate record with the live demonstration (Codex P2 on #2702)
…t code

CodeRabbit on the #2702 promotion caught the residual TOCTOU the group
review had classed acceptable: the ancestry proof authorizing the
forced branch delete ran only at scan time, so a commit landing on a
launch branch between cleanup's scan and 'branch -D' would be orphaned
(the tree stays clean, so 'worktree remove' cannot object).
removeLaunchWorktree now re-runs the fully-qualified is-ancestor probe
immediately before removal and refuses on any non-zero result; once
the worktree is removed the branch can gain no commits (git refuses a
second same-branch checkout), so the re-proof closes the whole window.
cleanup re-resolves the integration branch fail-closed and the fn is
exported for a direct-layer regression test (the outer API re-scans on
entry, making the inner window unreachable from public-API tests —
proven while writing the test).

Also (CodeRabbit trivial): the doctor wiring tests now capture and
assert process.exitCode === 0, locking in that launch-worktree residue
is warn-only. 618 tests green in src/genie-commands/.
fix(doctor): re-prove ancestry at removal time (CodeRabbit Major on #2702)
@coderabbitai

coderabbitai Bot commented Jul 27, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@github-actions[bot], you've reached your PR review limit, so we couldn't start this review.

Next review available in: 7 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ab801ee8-cb2a-4db2-825d-a86294ea04b0

📥 Commits

Reviewing files that changed from the base of the PR and between 40005c2 and bafbd64.

📒 Files selected for processing (14)
  • .claude-plugin/marketplace.json
  • .genie/wishes/worktree-isolation-hardening/WISH.md
  • package.json
  • plugins/genie/.claude-plugin/plugin.json
  • plugins/genie/.codex-plugin/plugin.json
  • plugins/genie/package.json
  • plugins/genie/references/native-surfaces.md
  • plugins/genie/skills/review/SKILL.md
  • plugins/genie/skills/work/references/native-surfaces.md
  • plugins/hermes-genie/plugin.yaml
  • skills/review/SKILL.md
  • skills/work/references/native-surfaces.md
  • src/genie-commands/doctor-worktrees.test.ts
  • src/genie-commands/doctor-worktrees.ts
📝 Walkthrough

Walkthrough

The PR adds genie doctor detection and fail-closed cleanup for launch worktrees, integrates reviewer snapshot and shared-workspace Git rules across documentation, adds end-to-end coverage, bumps package/plugin versions, and records stable release-gate completion.

Changes

Worktree isolation

Layer / File(s) Summary
Shared-workspace policy contract
.genie/wishes/worktree-isolation-hardening/WISH.md, skills/..., plugins/genie/...
Shared-workspace subagents are prohibited from mutating repo-level Git state; dispatch briefs now include file scope and the canonical freeze rule.
Reviewer snapshot procedure
skills/review/SKILL.md, plugins/genie/skills/review/SKILL.md
Committed reviews use detached, read-only worktrees pinned to the reviewed commit.
Launch-worktree detection and cleanup
src/genie-commands/doctor-worktrees.ts, src/genie-commands/doctor.ts, src/genie.ts, src/term-commands/launch.ts
genie doctor reports launch worktree states and --fix removes only merged, clean entries after ancestry revalidation.
End-to-end validation
src/genie-commands/doctor-worktrees.test.ts
Real Git fixtures test parsing, classification, refusal paths, race handling, JSON output, and doctor integration.

Release metadata and gate closure

Layer / File(s) Summary
Package and plugin version bump
package.json, .claude-plugin/marketplace.json, plugins/genie/*, plugins/hermes-genie/plugin.yaml
Version metadata changes from 5.260727.4 to 5.260727.11.
Stable release gate closure
.genie/INDEX.md, .genie/wishes/stable-release-security-gate/WISH.md
Release records mark the security gate complete and document production approval and stable-run evidence.

Estimated code review effort: 4 (Complex) | ~45 minutes

Possibly related issues

Possibly related PRs

Suggested reviewers: namastex888

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 70.97% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change as a rolling promotion from dev to main.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

namastex888
namastex888 previously approved these changes Jul 27, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c8c6091354

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread src/genie-commands/doctor-worktrees.ts
Comment thread src/genie-commands/doctor-worktrees.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.genie/wishes/worktree-isolation-hardening/WISH.md:
- Around line 127-130: Update the Validation sections in WISH.md to document the
full repository validation gate: include bun install --frozen-lockfile, bun run
check, and the relevant targeted bun test command, or explicitly name the full
CI check and provide its evidence. Apply this consistently to both referenced
validation blocks.

In `@plugins/genie/references/native-surfaces.md`:
- Line 12: Update the native-surfaces references at
plugins/genie/references/native-surfaces.md:12 and
skills/work/references/native-surfaces.md:11 with identical wording that
includes dispatch-contract.md as the authoritative concurrency-policy reference,
or explicitly identifies the single source of truth. Ensure both mirrored
documents consistently point readers to the contract governing parallel writers
and shared-workspace subagents.

In `@plugins/genie/skills/review/SKILL.md`:
- Around line 148-150: Make reviewer worktree snapshot paths collision-resistant
by adding a unique review/group identifier to the provisioning path and reusing
that exact path for teardown in plugins/genie/skills/review/SKILL.md:148-150;
apply the same unique-path command requirement in
.genie/wishes/worktree-isolation-hardening/WISH.md:141 and mirror it exactly in
skills/review/SKILL.md:148-150.

In `@src/genie-commands/doctor-worktrees.ts`:
- Around line 193-198: Export the IntegrationBranch interface so callers can
name and construct the third-parameter type accepted by the public
removeLaunchWorktree function. Keep its fields and documentation unchanged, and
apply the same export visibility wherever the interface is defined or
referenced.
- Around line 116-124: Update the git helper used by doctor probes to enforce an
explicit timeout on spawnSync calls, ensuring blocked git processes fail closed
through the existing res.error/non-zero handling. Keep maxBuffer explicitly
configured for the worktree list probe, using the appropriate spawn options for
both timeout protection and large output.
- Around line 413-425: Move the ancestry re-proof from before git worktree
remove to after a successful removal and immediately before git branch -D in the
cleanup flow. Keep the branch-null early return intact, and return the existing
“branch advanced past … after the scan” result when the post-removal merge-base
check fails; only invoke the forced deletion after this check succeeds.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 6de7f505-cb87-4afe-bba1-e26b58038b65

📥 Commits

Reviewing files that changed from the base of the PR and between fca1da2 and 40005c2.

⛔ Files ignored due to path filters (1)
  • AGENTS.md is excluded by !*.md
📒 Files selected for processing (27)
  • .claude-plugin/marketplace.json
  • .genie/INDEX.md
  • .genie/wishes/stable-release-security-gate/WISH.md
  • .genie/wishes/worktree-isolation-hardening/WISH.md
  • package.json
  • plugins/genie/.claude-plugin/plugin.json
  • plugins/genie/.codex-plugin/plugin.json
  • plugins/genie/package.json
  • plugins/genie/references/codex-integration-map.md
  • plugins/genie/references/dispatch-contract.md
  • plugins/genie/references/native-surfaces.md
  • plugins/genie/skills/dream/SKILL.md
  • plugins/genie/skills/genie-hacks/references/catalog.md
  • plugins/genie/skills/review/SKILL.md
  • plugins/genie/skills/work/SKILL.md
  • plugins/genie/skills/work/references/native-surfaces.md
  • plugins/hermes-genie/plugin.yaml
  • skills/dream/SKILL.md
  • skills/genie-hacks/references/catalog.md
  • skills/review/SKILL.md
  • skills/work/SKILL.md
  • skills/work/references/native-surfaces.md
  • src/genie-commands/doctor-worktrees.test.ts
  • src/genie-commands/doctor-worktrees.ts
  • src/genie-commands/doctor.ts
  • src/genie.ts
  • src/term-commands/launch.ts

Comment thread .genie/wishes/worktree-isolation-hardening/WISH.md
Comment thread plugins/genie/references/native-surfaces.md Outdated
Comment thread plugins/genie/skills/review/SKILL.md Outdated
Comment thread src/genie-commands/doctor-worktrees.ts
Comment thread src/genie-commands/doctor-worktrees.ts Outdated
Comment thread src/genie-commands/doctor-worktrees.ts Outdated
…(review on #2712)

Both bots on the promotion PR caught that the ancestry re-proof ran
BEFORE 'git worktree remove', leaving the same window open between the
probe and the delete. The authoritative probe now runs AFTER removal —
the only race-free point: with the worktree gone no checkout holds the
branch, so the answer cannot be invalidated before 'branch -D'. The
pre-removal probe stays as an early refusal that preserves the worktree.

Codex P1: gitignored files are deleted by 'worktree remove' (git
semantics) and are usually the reclaim's point (node_modules), but
user-owned secret material must never ride a cleanup — classification
now refuses when an ignored basename matches a sensitive-pattern set
(.env*, *.pem, *.key, id_rsa*, credential/secret), listed via
--ignored=traditional so fully-ignored dirs stay one bounded line.

Also from the pass: git probes bounded (10s timeout, 8MB maxBuffer);
IntegrationBranch exported alongside removeLaunchWorktree; reviewer
snapshot paths gain a required <unique> suffix (collision across
concurrent reviews/repos sharing a basename) in skill+mirror+wish;
native-surfaces pointers name dispatch-contract.md rule 3; wish
validation blocks record full 'bun run check' on CI as the merge gate.
619 tests green.

Co-authored-by: Liraz Siri <liraz@liraz.org>
…ew-2712

fix(doctor): race-free branch delete + ignored-secret guard (review findings on #2712)
namastex888
namastex888 previously approved these changes Jul 27, 2026
@namastex888
namastex888 merged commit f6967b4 into main Jul 27, 2026
23 checks passed
@coderabbitai coderabbitai Bot mentioned this pull request Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants