mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-10 23:19:09 +02:00
fix: adversarial round — the P0 finalize fail-safe and 12 hardened findings
Three adversarial passes (Claude fresh-context, Codex chaos, Codex structured with P1 gate) on the full wave diff. Multi-source findings, all fixed: - P0: finalize_queue is now explicit-delete-only — a record is unlinked ONLY when classification proves it staged or dropped; a classifier crash, a missing class file, or a malformed pulled .brain-privacy-map.json (which previously nuked the whole snapshotted queue, remotely triggerable) now retains everything, warns, and re-drains next run. load_privacy_map treats corrupt maps as retain-all, never as empty. - next-version cannot silently drop a live claim: unreadable advertised refs get a targeted --depth=1 fetch + retry; still-unreadable claims surface as UNKNOWN warnings instead of duplicate-version silence. - session-update lock: ownership-checked EXIT trap (a TTL-reclaimed holder can no longer delete the new holder's lock) + a 5-min background heartbeat so a legitimately-slow pull/setup is never reclaimed while alive. - ensure-event collapses ALL same-(event,source) duplicates to one canonical entry; unique per-process tmp path; setup call sites surface (not swallow) the hardened refusals. - memory-ingest: --limit counts only policy-permitted pages (denied records no longer starve permitted ones); --probe applies the same policy filter as --bulk (skipped_policy_* fields on the report). - version-bump repair accepts a genuine literal 0.0.0.0 VERSION file. - slug heal restricted to the stray-.git shape — package.json-anchored wrapper roots keep their legit sticky identity (#2212 preserved). - brain-sync: idle fast path sees leftover .migrating records; unparseable spool records quarantine instead of warning forever; migration comment stops overclaiming the transition-window race. - CDP throttling justifications document override persistence (callers own restoration), pinned in the allowlist test. Deferred with record: deny retroactivity for already-ingested pages (P2 TODO, same semantics as the code-import gate); legacy-migration tail race (transition-window, requires pre-spool writers). 288 pass / 0 fail across the 10 touched suites. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
b7d44c45b4
commit
fd0dbdeea2
@@ -106,11 +106,26 @@ fi
|
||||
|
||||
# Write the HOLDER's PID for stale lock detection (see #2613 note above;
|
||||
# macOS ships bash 3.2 with no BASHPID — the sh child's $PPID IS this
|
||||
# subshell, so the fallback is exact there).
|
||||
echo "${BASHPID:-$(sh -c 'echo $PPID')}" > "$LOCK_DIR/pid" 2>/dev/null
|
||||
# subshell, so the fallback is exact there). MYPID is captured once at
|
||||
# write time so the trap below can prove ownership before removing.
|
||||
MYPID="${BASHPID:-$(sh -c 'echo $PPID')}"
|
||||
echo "$MYPID" > "$LOCK_DIR/pid" 2>/dev/null
|
||||
|
||||
# Clean up lock on exit
|
||||
trap 'rm -rf "$LOCK_DIR" 2>/dev/null' EXIT
|
||||
# In-flight heartbeat: the step-boundary touches below only fire AFTER the
|
||||
# pull / setup return, so a legitimately-slow step (cold clone, huge setup)
|
||||
# older than the TTL got reclaimed while ALIVE. This background loop
|
||||
# freshens the pidfile mtime every 5 minutes for as long as we still own
|
||||
# the lock (ownership re-checked each beat: if another updater reclaimed
|
||||
# and wrote its own pid, the loop exits instead of touching THEIR file).
|
||||
( while :; do sleep 300; [ "$(cat "$LOCK_DIR/pid" 2>/dev/null)" = "$MYPID" ] || exit 0; touch "$LOCK_DIR/pid" 2>/dev/null; done ) &
|
||||
HB_PID=$!
|
||||
|
||||
# Clean up lock on exit — ownership-checked: after a TTL reclaim by another
|
||||
# updater, $LOCK_DIR belongs to the NEW holder, and an unconditional rm -rf
|
||||
# here would delete the live holder's lock (cascading reclaims). Remove the
|
||||
# lock ONLY while $LOCK_DIR/pid still contains MYPID; always stop the
|
||||
# heartbeat.
|
||||
trap 'kill "$HB_PID" 2>/dev/null; [ "$(cat "$LOCK_DIR/pid" 2>/dev/null)" = "$MYPID" ] && rm -rf "$LOCK_DIR" 2>/dev/null' EXIT
|
||||
|
||||
# ── Pull latest ──
|
||||
OLD_HEAD=$(git -C "$GSTACK_DIR" rev-parse HEAD 2>/dev/null)
|
||||
|
||||
Reference in New Issue
Block a user