mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-11 23:49:01 +02:00
fix: adversarial round — the P0 finalize fail-safe and 12 hardened findings
Three adversarial passes (Claude fresh-context, Codex chaos, Codex structured with P1 gate) on the full wave diff. Multi-source findings, all fixed: - P0: finalize_queue is now explicit-delete-only — a record is unlinked ONLY when classification proves it staged or dropped; a classifier crash, a missing class file, or a malformed pulled .brain-privacy-map.json (which previously nuked the whole snapshotted queue, remotely triggerable) now retains everything, warns, and re-drains next run. load_privacy_map treats corrupt maps as retain-all, never as empty. - next-version cannot silently drop a live claim: unreadable advertised refs get a targeted --depth=1 fetch + retry; still-unreadable claims surface as UNKNOWN warnings instead of duplicate-version silence. - session-update lock: ownership-checked EXIT trap (a TTL-reclaimed holder can no longer delete the new holder's lock) + a 5-min background heartbeat so a legitimately-slow pull/setup is never reclaimed while alive. - ensure-event collapses ALL same-(event,source) duplicates to one canonical entry; unique per-process tmp path; setup call sites surface (not swallow) the hardened refusals. - memory-ingest: --limit counts only policy-permitted pages (denied records no longer starve permitted ones); --probe applies the same policy filter as --bulk (skipped_policy_* fields on the report). - version-bump repair accepts a genuine literal 0.0.0.0 VERSION file. - slug heal restricted to the stray-.git shape — package.json-anchored wrapper roots keep their legit sticky identity (#2212 preserved). - brain-sync: idle fast path sees leftover .migrating records; unparseable spool records quarantine instead of warning forever; migration comment stops overclaiming the transition-window race. - CDP throttling justifications document override persistence (callers own restoration), pinned in the allowlist test. Deferred with record: deny retroactivity for already-ingested pages (P2 TODO, same semantics as the code-import gate); legacy-migration tail race (transition-window, requires pre-spool writers). 288 pass / 0 fail across the 10 touched suites. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
b7d44c45b4
commit
fd0dbdeea2
@@ -552,6 +552,45 @@ function fetchGitClaimed(
|
||||
// read from the local remote-tracking ref.
|
||||
show = runCommand("git", ["show", `refs/remotes/origin/${branch}:${versionPath}`]);
|
||||
}
|
||||
if (!show.ok && sha) {
|
||||
// ls-remote advertises SHAs without objects: a branch pushed after our
|
||||
// last fetch has NO local object, so both reads above fail. The old
|
||||
// `continue` here silently dropped a LIVE claim — the exact duplicate-
|
||||
// allocation this fallback exists to prevent. Distinguish "object
|
||||
// missing" from "branch has no VERSION file" before deciding.
|
||||
const haveObject = runCommand("git", ["cat-file", "-e", sha]);
|
||||
if (haveObject.ok) {
|
||||
// Object is local and the path read still failed → the branch simply
|
||||
// carries no version file. Genuinely not a claim; skip quietly.
|
||||
continue;
|
||||
}
|
||||
// Fetch just this ref shallowly (no prompts, no tags, bounded) and
|
||||
// retry reading VERSION from the now-local object (or FETCH_HEAD).
|
||||
const fetch = spawnSync(
|
||||
"git",
|
||||
["fetch", "origin", `refs/heads/${branch}`, "--depth=1", "--no-tags"],
|
||||
{ encoding: "utf8", timeout: 10000, env: { ...process.env, GIT_TERMINAL_PROMPT: "0" } },
|
||||
);
|
||||
if (fetch.status === 0 && !fetch.error) {
|
||||
show = runCommand("git", ["show", `${sha}:${versionPath}`]);
|
||||
if (!show.ok) show = runCommand("git", ["show", `FETCH_HEAD:${versionPath}`]);
|
||||
if (!show.ok && runCommand("git", ["cat-file", "-e", sha]).ok) {
|
||||
// Fetched and the object exists but the path doesn't → no VERSION
|
||||
// file on this branch. Not a claim.
|
||||
continue;
|
||||
}
|
||||
}
|
||||
if (!show.ok) {
|
||||
// STILL unreadable — never skip silently. Surface it as an UNKNOWN
|
||||
// claim so the caller knows the allocation may be unsafe.
|
||||
warnings.push(
|
||||
`origin/${branch}: VERSION unreadable even after a targeted fetch — ` +
|
||||
`counted as an UNKNOWN claim; allocation may collide with this branch. ` +
|
||||
`Run \`git fetch origin ${branch}\` and re-run to verify.`,
|
||||
);
|
||||
continue;
|
||||
}
|
||||
}
|
||||
if (!show.ok) continue;
|
||||
const raw = extractVersion(show.stdout, versionPath);
|
||||
if (!raw || !parseVersion(raw)) continue;
|
||||
|
||||
Reference in New Issue
Block a user