Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -92,6 +92,7 @@ state/ volatile runtime signals; gitignored
<id>.check-trust private content binding created by fm-check-register.sh for an intentional custom check
<id>.pr-poll private validated data sidecar for the byte-static PR merge poll
<id>.pr-poll-registration private transactional provenance record binding the task, canonical metadata identity, sidecar, and static poll publication
<id>.pr-poll-retirement private identity-bound crash-recovery receipt for one exact validated merged result; removed after its provider poll artifacts retire
.pr-check-quarantine/ private non-runnable storage for checks neutralized by the non-executing migration
.pr-check-migration.log private per-task outcomes distinguishing rebuilt or canonically registered replacement polls, quarantined unarmed polls, and incomplete migrations
.pr-check-migration-scan-v1 private marker proving the non-executing scan disabled every unsafe legacy check; .pr-check-migration-v1 separately records completed private repairs
Expand Down
24 changes: 19 additions & 5 deletions bin/fm-pr-check-migrate.sh
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
#!/usr/bin/env bash
# Non-executing migration for watcher PR checks created by older Firstmate
# versions. Legacy check files are never run, sourced, or parsed by Bash.
# Canonical polls are rebuilt from validated metadata, provenance-bound polls
# and registered custom checks remain armed, and every other task poll is
# Pending validated merged-poll retirements finish first. Canonical polls are
# rebuilt from validated metadata, provenance-bound polls and registered custom
# checks remain armed, and every other task poll is
# quarantined for private review. A current X-mode shim is preserved by exact
# content, while the recognized older byte-static shim is refreshed in place.
# Usage: fm-pr-check-migrate.sh [--checks-safe]
Expand Down Expand Up @@ -253,9 +254,18 @@ x_shim_locked_scan_needed() {
return 0
}

# Marker short-circuits apply only when generated artifact identities are current.
# Otherwise watcher exclusion comes before every check scan and state mutation.
if ! x_shim_locked_scan_needed; then
retirement_recovery_needed() {
local receipt
for receipt in "$STATE"/*.pr-poll-retirement; do
[ -e "$receipt" ] || [ -L "$receipt" ] || continue
return 0
done
return 1
}

# Marker short-circuits apply only when generated artifact identities are current
# and no identity-bound retirement remains to finish under watcher exclusion.
if ! x_shim_locked_scan_needed && ! retirement_recovery_needed; then
migration_complete && exit 0
[ "$ALLOW_INCOMPLETE_REPAIRS" -eq 1 ] && scan_complete && exit 0
fi
Expand Down Expand Up @@ -333,6 +343,10 @@ if [ ! -d "$STATE" ] || [ -L "$STATE" ]; then
fi
STATE_DEVICE=$(fm_pr_file_device "$STATE") || exit 1
[ -n "$STATE_DEVICE" ] || exit 1
if ! fm_pr_poll_retirement_recover_all "$STATE" "$TEMPLATE"; then
echo "PR_CHECK_MIGRATION: pending review poll retirement could not be validated:$FM_PR_POLL_RETIREMENT_REJECTED" >&2
exit 1
fi
refresh_v1_x_shim() {
local shim="$STATE/x-watch.check.sh"
fmx_poll_shim_v1_valid "$shim" "$FM_HOME" "$FM_ROOT" "$STATE_DEVICE" || return 0
Expand Down
8 changes: 8 additions & 0 deletions bin/fm-pr-check.sh
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,14 @@ if [ ! -f "$META" ] || [ -L "$META" ] || [ "$(fm_pr_file_link_count "$META")" !=
exit 1
fi

# A prior exact merged result may have queued its durable notification before an
# interruption. Finish only its identity-bound receipt before publishing a
# replacement poll.
fm_pr_poll_retirement_recover_one "$STATE" "$ID" "$SCRIPT_DIR/fm-pr-poll.sh" || {
echo "error: pending review poll retirement could not be validated" >&2
exit 1
}

# Neutralize any pre-fix poll before recording or arming this task. The
# migration never executes legacy artifacts and holds watcher exclusion while
# it quarantines or rebuilds them.
Expand Down
Loading