Skip to content

fix(bin): let stale task cleanup skip reassigned pool slots - #3

Merged
markpol merged 2 commits into
mainfrom
fm/teardown-shared-slot-reconcile
Sep 28, 2026
Merged

markpol merged 2 commits into
mainfrom
fm/teardown-shared-slot-reconcile

Conversation

@markpol

@markpol markpol commented Sep 27, 2026

Copy link
Copy Markdown
Member

Intent

Remove all copies and clean up; only the shared copy for the completed tasks.

The completed Android keyboard (kunchenguid#338, merged https://github.com/netabit/draconian-dungeons/pull/346) and MobX upgrade (merged https://github.com/netabit/draconian-dungeons/pull/341) tasks both have a record pointing to the same isolated draconian-dungeons copy. The Android task is its current owner. Cleanup of either completed task refuses because both records name that copy. Do not remove the active campaign-chat kunchenguid#315 copy or the primary project copy.

What Changed

  • Teardown now checks the pool slot’s owner claim before scanning task records. If another task owns the slot, it skips slot operations and cleans up only the stale task record.
  • A current, absent, or unreadable claim does not allow a contested slot to be returned; the architecture docs describe this ownership rule.
  • Added teardown safety cases for shared slots with stale, current, absent, and unsafe claims.

Risk Assessment

⚠️ Medium: The top-level stale-record case is handled, but forced secondmate cleanup can still refuse on the same shared-slot state before it reaches the ownership check.

Testing

Ran the focused teardown endpoint-safety test twice; it passed the shared-slot scenarios, using stubbed runtime commands. No live tmux session was available, so actual backend cleanup and preservation of the separate campaign-chat and primary copies could not be demonstrated. Saved the transcript as evidence; the worktree remained unchanged.

  • Live validation: ⚠️ inconclusive - 0 of 2 scenarios driven live against the product
Scenario Result Live Evidence
Clean up a completed task whose record points to a slot now positively claimed by another task; remove only the stale record and preserve the shared copy and current owner. ⏸️ untested no The focused test passed using stubbed runtime commands, but this scenario was not driven live. tmux is unavailable on PATH, so the real session backend could not be exercised; provide tmux in the…
Try cleanup with a current-owner, absent, or malformed slot claim; refuse without removing either task record or changing the contested copy. ⏸️ untested no The focused test exercised these adversarial cases with stubbed runtime commands. Live verification was blocked because tmux is unavailable on PATH; provide it in the test environment and rerun.
Evidence: Focused teardown regression test transcript

Source: Focused teardown regression test transcript

ok - fm-teardown: missing, empty, malformed, ambiguous, and task-mismatched endpoints refuse before every mutation or runtime call
ok - fm-teardown: a concurrent lifecycle action refuses before mutation
ok - fm-teardown: non-pool cleanup ignores unrelated task publication locks
ok - fm-teardown: destructive cleanup serializes with metadata writers
ok - cleanup identity: valid tmux, Herdr, Zellij, Orca, and cmux records validate while every empty backend target refuses
ok - cleanup identity: an Orca record's real composite worktree id validates while a separatorless or newline-carrying id refuses
ok - tmux backend: direct empty target returns nonzero without invoking tmux
ok - process cleanup: creation-time PID identity removes only the exact child and preserves the control child
skip - tmux not installed
skip - tmux not installed
skip - tmux not installed
skip - tmux not installed
skip - tmux not installed
ok - fm-teardown: an Orca close its missing CLI never attempted refuses even under --force, keeping the record naming the terminal
skip - tmux not installed
ok - Treehouse locking resolves a bare local origin against its source project, matching the provisioned clone
ok - fm-teardown: a pool slot named by a second task record is never returned, killed, or reset
ok - fm-teardown: a positive other-task claim cleans only the stale record; current, absent and unsafe claims cannot release a contested slot
ok - fm-teardown: a pool slot held by another firstmate home is never returned
ok - fm-teardown: a task that solely holds its slot still returns it
ok - fm-teardown: a pool slot claimed by another task is left alone while the task's own cleanup finishes
ok - fm-teardown: a task's own slot claim, and an unclaimed slot, both still tear down
ok - fm-teardown: an exact recorded endpoint still tears down after changing cwd outside its worktree
ok - Treehouse project locking anchors at the local root for main-home, local-secondmate, and remote-seeded layouts
ok - fm-teardown: a remote-seeded secondmate home returns its own uncontested pool slot
ok - fm-teardown: slot ownership across a remote-seeded home and its local child still refuses
ok - Treehouse project locking still serializes two homes across the remote-seeded boundary
- Outcome: ⚠️ 2 warnings across 1 run (3m22s)

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

⚠️ **Review** - 1 warning
  • ⚠️ bin/fm-teardown.sh:3315 - The owner-claim check now lets a stale top-level record skip the exclusivity scan, but forced secondmate cleanup still scans descendants in the opposite order: preflight_descendant_treehouse_slots rejects a shared slot at bin/fm-teardown.sh:2965 before it checks whether the child’s claim names another task at bin/fm-teardown.sh:2967. A secondmate teardown containing a child record for the reassigned slot therefore still refuses, leaving that stale child record behind. Apply the ownership-first rule in this preflight too, while retaining refusal for owned, absent-claim, or unreadable-claim slots.
⚠️ **Test** - 2 warnings
  • ⚠️ The focused regression test passed, but live teardown against a real tmux session could not be driven because tmux is not available on PATH. Make tmux available in the test environment and rerun this phase to demonstrate cleanup against the actual session backend.
  • ⚠️ live validation verdict: inconclusive (0 of 2 scenarios were driven live against the product); untested: Clean up a completed task whose record points to a slot now positively claimed by another task; remove only the stale record and preserve the shared copy and current owner., Try cleanup with a current-owner, absent, or malformed slot claim; refuse without removing either task record or changing the contested copy.
  • Live validation: ⚠️ inconclusive - 0 of 2 scenarios driven live against the product
Scenario Result Live Evidence
Clean up a completed task whose record points to a slot now positively claimed by another task; remove only the stale record and preserve the shared copy and current owner. ⏸️ untested no The focused test passed using stubbed runtime commands, but this scenario was not driven live. tmux is unavailable on PATH, so the real session backend could not be exercised; provide tmux in the…
Try cleanup with a current-owner, absent, or malformed slot claim; refuse without removing either task record or changing the contested copy. ⏸️ untested no The focused test exercised these adversarial cases with stubbed runtime commands. Live verification was blocked because tmux is unavailable on PATH; provide it in the test environment and rerun.
  • tests/fm-teardown-endpoint-safety.test.sh 33210
  • Checked the targeted test transcript at ~/.no-mistakes/evidence/01M3JM682Z4NJTN1NN64TKCJ66/teardown-shared-slot.log
  • Checked git status --short; the test left no worktree changes
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

@markpol
markpol merged commit a230736 into main Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant