Skip to content

fix: harden required checks and lock stealing - #10

Merged
landonbrice merged 3 commits into
mainfrom
fm/fm-merge-lock-safety
Sep 23, 2026
Merged

landonbrice merged 3 commits into
mainfrom
fm/fm-merge-lock-safety

Conversation

@landonbrice

@landonbrice landonbrice commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Fixes kunchenguid#5344
Fixes kunchenguid#5345

Summary:

  • Read base-branch required checks from GitHub branch protection, verify required status contexts and check runs at the exact head, fail closed on unreadable protection or head-check responses, and add attended single-use --allow-missing.
  • Replace recursive .steal acquisition with a fixed steal path and a multi-second deadline that silently backs off through ordinary contention.

Verification for kunchenguid#5344:

  • Passed: bin/fm-test-run.sh tests/fm-pr-merge.test.sh.
  • Passed: bin/fm-test-run.sh tests/fm-captain-hold-lifecycle.test.sh.
  • Covered required-check absent refusal, named --allow-missing, no required checks, unreadable forge query, exact-head status/check-run reads, existing SKIPPED/NEUTRAL behavior, head binding, and unprotected-base fixture reads.

Verification for kunchenguid#5345:

  • Passed: bin/fm-test-run.sh tests/fm-watcher-lock.test.sh, exit=0.
  • The ordinary 40-process stale-lock contention case produced zero lock-steal exhaustion diagnostics; the deliberately stuck steal mutex produced one bounded diagnostic naming the lock.
  • No recursive steal path or File name too long output was observed.

Other verification:

  • Passed: bin/fm-test-run.sh tests/fm-pr-check-security.test.sh.
  • Passed: PATH=:$PATH bin/fm-lint.sh with ShellCheck 0.11.0 and actionlint 1.7.12.
  • No no-mistakes run was used because this task is direct-PR.

@landonbrice
landonbrice merged commit 3950b10 into main Sep 23, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant