Repository navigation
fix(bin): identify a task record by path identity in the slot-collision scan - #5487
Closed
taimurrabuske wants to merge 1 commit into
Closed
taimurrabuske wants to merge 1 commit into
taimurrabuske wants to merge 1 commit into
Conversation
…on scan The pool-slot exclusivity scan compared record file paths as strings while collecting state directories from both the caller's FM_HOME spelling and the physically resolved root home. A home reached through a symlinked spelling (a /home path whose target is /nobackup) therefore appeared twice, so the task's single record was read twice and the second reading was reported as a different task holding the same slot. Teardown refused with "task X's recorded worktree is also task X's recorded worktree", and the stale worker could not be retired at all, not even with --force. State directories are now collected once per physical directory, and records are compared by identity - the state directory's physical path plus the record's own name - so equivalent spellings of one home resolve to one record. Only the directory is resolved: two records in one directory, and one record name in two genuinely different directories, remain distinct, so a real slot collision across tasks or homes still refuses without touching the slot, and the claim, endpoint, and unlanded-work safeguards are unchanged. Regression coverage recovers the focused endpoint-safety cases for a symlinked home spelling (sole slot returns, real collision still refuses) and adds one for a Firstmate home registered through a symlinked path, which must still be scanned rather than collapsed into the record's own home.
|
Closed as superseded — this work already landed on main via #5635. — Kun's Firstmate |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Retiring a stale worker was impossible in a home reached through a symlinked path spelling.
The pool-slot exclusivity scan in
bin/fm-teardown.shcollected state directories from both the caller'sFM_HOMEspelling and the physically resolved root home, then compared record files as raw path strings. When a home is reached through an equivalent spelling - a/home/<user>/worksymlink beside its physical/nobackup/<user>/worktarget - the same state directory was collected twice, so the task's single record was read twice and the second reading looked like a different task holding the same slot:Cleanup then refused, not even with
--force, and the stale record could not be retired at all.Fix
add_treehouse_owner_state).task_record_identity) - instead of by the spelling each was reached through.Only the directory is resolved, so two records in one directory, and one record name in two genuinely different directories, stay distinct identities. Genuine shared-slot collisions across tasks and across homes still refuse without touching the slot, and the slot-owner claim check, endpoint identity validation, worktree ownership claims, and uncommitted/unlanded-work refusals are untouched.
Validation
tests/fm-teardown-endpoint-safety.test.sh: 29/29 pass.tests/fm-teardown.test.sh: identical results before and after this change; its one failure is a pre-existing environment gap (installedtasks-axi0.2.5, test requires 0.2.6+).bin/fm-lint.shclean (ShellCheck 0.11.0 pinned, actionlint 1.7.12, 3 workflow files valid), including a full extended-analysis pass over both changed files.