mirror of
https://github.com/garrytan/gstack.git
synced 2026-08-11 00:30:21 +02:00
* fix(careful): warn on chained rm even when the last target is safe The safe-exception block whitelisted rm -rf of build artifacts by extracting targets with a single greedy match (.*rm ...), which only ever inspects the LAST rm in the command. A chain like 'rm -rf /; rm -rf node_modules' was therefore judged solely by its trailing safe target and allowed without warning, waving through the destructive 'rm -rf /'. Gate the shortcut to single rm invocations: when any shell separator (; | & newline, incl. JSON-escaped \n/\r from the grep extraction path) is present, fall through to the destructive-pattern check, which warns on any recursive rm. Single-command artifact cleanups still allow. Adds 3 regression tests covering semicolon and && chains in both orders. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * harden(careful): substitution separators + capital -R recursive flag (#2039) Two residual fail-opens in the same guard PR #2040 hardened, both verified by executing the script pre-fix: - rm -rf $(./wipe-all)/node_modules silently allowed: the substitution token ends in a whitelisted suffix and the safe-exception early exit skipped ALL downstream checks. $( and backtick now count as chain separators; plain $VAR expansion stays allowed. - rm -R / silently allowed: both greps required a lowercase r in the flag cluster; capital -R is the documented BSD/macOS recursive flag. Both greps now match -[a-zA-Z]*[rR]. Six new tests: substitution x2 -> ask, capital-R x2 -> ask, rm -Rf node_modules single-command -> still allowed, escaped-newline branch (existing code, previously untested), and a pinned deliberate FP (cd app && rm -rf node_modules -> ask) documenting the fail-closed direction on chains. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(context-restore): prefer the current branch's own checkpoint (#2052) All worktrees of a repo share one origin-derived slug, so they share one `~/.gstack/projects/<slug>/checkpoints/` dir. `/context-restore` loaded the newest checkpoint across the whole dir, so in one worktree it could silently restore a *sibling worktree's* newer checkpoint. Step 1 now orders candidates current-branch-first (read from each file's `branch:` frontmatter), keeping other branches as a fallback. A branch is checked out in at most one worktree, so this stops cross-worktree contamination while preserving Conductor cross-branch handoff: when the current branch has no checkpoint of its own, the full newest-first set is still used. - scan the 200 newest before partitioning so a current-branch checkpoint sitting below a burst of sibling saves is still found; output still capped at 20 - non-git / detached HEAD / branchless legacy saves fall back to the old newest-first behavior (back-compat) - +5 regression tests in context-save-hardening.test.ts (the #2052 bug case fails on the old pipeline); regenerated SKILL.md + proactive-suggestions.json Fixes #2052 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * fix(gbrain): pass --confirm-destructive on drift re-register (#1985) ensureSourceRegistered() handles match-but-different-path by removing the old source then re-adding it at the new path. The remove was issued as `gbrain sources remove <id> --yes`, but gbrain >= 0.42 gates `sources remove` behind `--confirm-destructive` (`--yes` alone no longer suppresses the data-loss prompt). The remove therefore fails with "To proceed, pass --confirm-destructive", which ensureSourceRegistered surfaces as "source registration failed" — aborting the entire /sync-gbrain code stage for any already-registered source whose path has drifted. The memory and brain-sync stages still pass, so the code index silently stops refreshing. The orchestrator's own safeSourcesRemove() already passes --confirm-destructive; this brings the lib helper in line with that convention. Keeps --yes for older gbrain. Tests: extend the fake gbrain shim in gbrain-sources.test.ts to simulate the gbrain >= 0.42 guard (remove without --confirm-destructive exits 1), update the drift re-register assertion, and add a regression test that proves the drift path no longer throws. Both fail on main with the exact "To proceed, pass --confirm-destructive" error and pass with the fix. Fixes #1985 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * harden(gbrain-sources): route drift remove through #1734 guards + realpath drift check Absorbing #2031 un-blocked a destructive remove that bypassed the #1734 data-loss guards: ensureSourceRegistered's drift path issued `gbrain sources remove` directly, without the detectAutopilot + decideSourceRemove checks every other remove routes through via safeSourcesRemove. gbrain >= 0.42's own prompt was accidentally blocking that path; with --confirm-destructive passed it is live again. - Drift remove now refuses LOUDLY (throws, actionable message) while an autopilot is active or when decideSourceRemove disallows; a silent changed=false would hide the drifted registration. - decideSourceRemove's extraArgs (--keep-storage when supported) propagate to the remove call, matching safeSourcesRemove. - Drift is realpath-normalized before being declared: a symlink alias of the same directory (macOS /tmp -> /private/tmp) is a match, not drift — the probable cause of #1985's reporter hitting the remove on an unmoved repo. - Drift fires a loud stderr line (old -> new path); perpetual drift in logs is the trigger for promoting #1985's reindex-in-place design. Tests: autopilot-active refusal (no remove in call log), fail-closed refusal on unreadable sources list, --keep-storage propagation, symlink-alias no-drift; existing drift tests pin the guard probes so a live autopilot on the dev machine can't flip them. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(developer-profile): exclude mode:resources rows from SESSION_COUNT, TIER, NUDGE_ELIGIBLE (#2067) Every /office-hours run appends a mode:"resources" bookkeeping row alongside the real session row, so --read double-counted sessions (~2x): tiers promoted early and the builder-to-founder nudge armed prematurely. The file already filtered resources rows for LAST_*/CROSS_PROJECT; the same realSessions filter now feeds SESSION_COUNT/TIER, and the nudge predicate is the faithful allowlist (mode === 'builder') so a future mode #4 fails closed instead of re-opening this bug. 8 regression tests: count vs resources noise, tier boundaries both sides, nudge false-with-noise / true-at-3-builders, cross-project trailing row. Absorbed from PR #1991 by @mvann (fix + tests commits; the PR's version-bump commit is superseded by this wave's consolidated release commit). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(hooks): passThrough() two-branch contract — never emit permissionDecision:'defer' (#2035, #2006) Every AskUserQuestion died with "Tool result missing due to internal error" on current Claude Code builds (Desktop 1.14271.0, CC 2.1.177). Root cause: the question-preference-hook emitted permissionDecision:'defer' on every pass-through path. 'defer' is a real PreToolUse value, but since CC v2.1.89 its semantics are "pause this tool call for external resumption" (headless resume) — never "abstain". Interactive sessions have nothing to resume the paused call, so the tool orphaned. Pre-2.1.89 builds ignored the unknown value, which is why the hook worked when it shipped and broke later. The fix is the two-branch pass-through contract: - no context -> exit 0 with EXACTLY empty stdout - memory nuggets present -> hookSpecificOutput with hookEventName + additionalContext ONLY (the documented shape; plan-tune Layer 8 memory injection ships through this branch and keeps working) defer() is renamed passThrough() so the function says what it does, and docs/spikes/claude-code-hook-mutation.md's protocol contract (cited by the hook header) is corrected in the same commit — it taught '"defer" — let permission flow continue' and was the reintroduction vector. Test contract rewritten in the same commit (13 assertions across 3 files, verified fail-first against the unfixed hook): pass-through paths assert exact-empty stdout (a garbage/partial write cannot slip past an optional-chained parse), the nugget path asserts permissionDecision is ABSENT while additionalContext survives, and a new tripwire asserts no non-deny path ever puts the string "permissionDecision" on stdout. The deny (auto-decide) and Conductor prose-redirect paths are unchanged. Deployment: no migration needed — settings.json points at the absolute bash shim which execs the .ts live; /gstack-upgrade delivers the fix. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(one-way-doors): unify credential noun net + wire it into the runtime (#2024) Library fix: revoke/reset/rotate now share ONE noun alternation (api key, token, secret, credential, access key, password) with optional plural s?. Pre-fix leaks: "reset my secret", "reset my access key", "revoke my secret" (mismatched per-verb lists) and every plural form ("rotate the credentials", "revoke all tokens" — \b(...)\b cannot match a trailing s). Runtime wiring — the regexes could never fire in production before: - gstack-question-preference --check gains --summary-stdin: the question text pipes via stdin (never argv — summaries carry quotes/newlines/shell metacharacters) and feeds isOneWayDoor alongside the id, so an ad-hoc destructive question with a stored never-ask preference now forces ASK_NORMALLY. Empty/absent stdin keeps exact id-only semantics. - question-preference-hook falls back to classifyQuestion(question text) when the registry lookup misses, so unregistered destructive questions pass through to a human instead of auto-deciding. - question-tuning resolver prose shows the piped form (SKILL.md regen lands in the wave's release commit). Tripwires (verified fail-first): full verbs x nouns x singular/plural matrix with the #2024 repro rows, benign-summary no-over-match rows, stdin transport survival (quotes/newlines), empty-stdin fail-safe, and hook fallback both directions (destructive -> pass-through, benign -> deny). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(design): loud integer-flag contract for --count/--retry/--timeout (#2032) design variants --count abc silently generated ZERO variants and exited 0: parseInt(NaN) flowed through Math.min into the generation loop bound. The same NaN class was live on the two sibling flags in the same file: --retry abc made generate() a silent no-op (attempt <= NaN never true, null output, exit 0) and --timeout abc killed the serve board ~immediately (setTimeout(NaN)). New design/src/flag-utils.ts: parseIntFlag (pure, unit-testable) + normalizeIntFlag (CLI wrapper). Contract matches the --viewports precedent (error loudly on nonsense — these commands spend real image-API money, a silent fixup hides typos from calling agents): undefined -> default; bare flag/empty/non-integer ("3.7" rejected, not truncated)/below-min -> exit 1 with usage hint; above-max -> clamp with stderr warning. --count normalizes at the variants() consumption site so programmatic callers are covered, with the ceiling derived from STYLE_VARIATIONS.length instead of a magic 7; the CLI passes the raw flag through (a pre-parseInt would truncate "3.7"). Tripwires live in test/design-flag-utils.test.ts — deliberately under test/, not design/test/, which is invisible to the bun test glob, TEST_ROOTS, and every workflow (wiring design/test/ into CI is a captured TODO). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(gbrain): thin-client state — remote-MCP brains no longer classify as broken-config (#2051) A thin client (remote-HTTP MCP brain, no local engine by design) probed `gbrain sources list`, which gbrain's dispatch guard REFUSES on thin clients (exit 1, no recognized error string), so the classifier fell to its defensive broken-config default and every suppression gate silently hid brain-aware blocks from exactly the users on a shared team brain. New 'thin-client' state, detected PRE-probe from gbrain's own remote_mcp config marker via the existing gbrainConfigPath() helper (mirrors gbrain's isThinClient(); honors GBRAIN_HOME; zero network, immune to error-string drift), with a /thin[- ]client/ stderr backstop in the probe catch. Remote reachability is deliberately NOT probed by the classifier — that is the #1964 pathology; gbrain calls degrade gracefully at use time, and the detect JSON says so honestly (gbrain_thin_client: {probed: false}). The state is admitted at every suppression gate — gstack-gbrain-detect --is-ok (drives setup + gbrain-refresh), gen-skill-docs' detection override, gstack-config gbrain-refresh — while the sync stages (code/memory/dream) SKIP with an accurate reason: code indexing runs on the brain server, memory syncs via the remote brain's artifacts pull. The two consumer classes need opposite answers, which is why this is a distinct state and not a skip-the-probe special case. sync-gbrain Step 1.5 and setup-gbrain prose route thin-client to proceed, never into broken-config remediation. detectMcpMode secondary generalization: url-match against the config's remote_mcp.mcp_url (deterministic — gbrain mounts at the generic /mcp path) -> name pattern gbrain[-_]* -> stdio command token; gbrain_mcp_mode stays a 3-value enum. Tripwires: end-to-end --is-ok exits 0 on a thin-client fixture AND still exits 1 on broken-config (the gate didn't widen); pre-probe + stderr-fallback classifier paths; 4 detectMcpMode identification cases incl. a non-matching url that must NOT false-positive. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * release: v1.60.0.0 — regen SKILL.md, VERSION, CHANGELOG, TODOS follow-ups - Regenerate all SKILL.md from templates (question-tuning --summary-stdin prose from #2024, context-restore branch preference from PR #2054, sync-gbrain/setup-gbrain thin-client prose from #2051) + llms.txt. - VERSION + package.json -> 1.60.0.0 (bin/gstack-next-version, queue-aware: #1815 claims 1.59.0.0, #2213 claims 1.59.1.0). - CHANGELOG release summary + itemized entry crediting @jbetala7 (x3) and @mvann. - TODOS.md: three eng-review follow-ups (design/test CI wiring + documented pre-existing retry-after flake, /context-save worktree identity, gbrain reindex-in-place conditional on the new drift log). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(resolvers): compress --summary-stdin preamble prose to fit parity budget; re-bless ship goldens The v1.57.7.0 parity suite caps investigate's generated size at 1.09x baseline; the #2024 question-tuning prose (duplicated into every tier->=2 skill) tipped it to 1.092. Compressed to a single inline command + short pointer (the full rationale lives in bin/gstack-question-preference's header and the one-way-doors module docs). Ship goldens re-blessed against the final resolver text (conscious template-change acknowledgment, per the golden-file regression contract). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(e2e): office-hours-spec-review turn budget fits the carved skill layout (#2473) The test failed deterministically with error_max_turns at 9 turns on main and this branch alike (CI attempt logs + local main repro). Root cause from the failing transcript: the Spec Review Loop content is carved out of office-hours/SKILL.md into office-hours/sections/, so the agent needs discovery hops (grep SKILL.md -> ls sections/ -> read the section) before it can write — 8 tool turns + the closing text turn = 9 > the 8-turn budget, which predates the carve. Observed failures wrote a CORRECT summary on tool turn 8 and died on the closing turn. maxTurns 8 -> 12. Verified: PASS locally post-fix (7 turns this run — the extra headroom absorbs discovery-path nondeterminism). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(e2e): review-dashboard-via session budget survives runner contention (#2473) The test failed on CI (and its baseline run) with the timeout signature: 0 turns, $0.00, exactly 183s, 3/3 attempts — the spawned claude -p session never emitted a single stream event before the 180s inner timeout. The file's tests run concurrently on one runner; session startup queues behind sibling sessions, and this test had the tightest budget in the file (the 240s-budget tests in the same job passed). A clean local run takes 270s wall for 4 turns, confirming 180s was too tight even without contention. Inner timeout 180s -> 300s; outer bun timeout 240s -> 360s to keep headroom over the inner budget. Verified: PASS locally post-fix (4 turns, 270s). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(e2e): retro-base-branch session budget survives runner contention (#2473) Same class as review-dashboard-via, one test over in the same file: /retro is a long multi-step flow whose clean pass measures 225-239s — a coin flip against the 240s inner budget. First CI run passed at 225s; the rerun timed out at the 240s line on all 3 attempts (exitReason "timeout"); the local verification run passed at 239s, ONE second under the old cap. Inner timeout 240s -> 360s; outer bun timeout 300s -> 480s for headroom. Verified: PASS locally post-fix (17 turns, 239s). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Jayesh Betala <jayesh.betala7@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Co-authored-by: Michael Vann <9221873+mvann@users.noreply.github.com>
347 lines
13 KiB
TypeScript
347 lines
13 KiB
TypeScript
/**
|
|
* gbrain-sources — TypeScript helper for idempotent gbrain federated source registration.
|
|
*
|
|
* Mirrors the bash logic in bin/gstack-gbrain-source-wireup:204-310 but in a form
|
|
* importable by other TS callers (currently bin/gstack-gbrain-sync.ts; future
|
|
* callers welcome). gbrain has no `sources update` — drift recovery is
|
|
* `sources remove` followed by `sources add`.
|
|
*
|
|
* Per /plan-eng-review D3 (DRY extraction).
|
|
*/
|
|
|
|
import { execFileSync, spawnSync } from "child_process";
|
|
import { realpathSync } from "fs";
|
|
import { withErrorContext } from "./gstack-memory-helpers";
|
|
import { execGbrainJson, NEEDS_SHELL_ON_WINDOWS } from "./gbrain-exec";
|
|
import {
|
|
detectAutopilot,
|
|
decideSourceRemove,
|
|
type AutopilotProbe,
|
|
type DecideRemoveOpts,
|
|
} from "./gbrain-guards";
|
|
|
|
export interface SourceState {
|
|
/** "absent" — id not registered. "match" — id at expected path. "drift" — id at different path. */
|
|
status: "absent" | "match" | "drift";
|
|
/** Path gbrain has registered for this id. Only set when status !== "absent". */
|
|
registered_path?: string;
|
|
}
|
|
|
|
export interface EnsureResult {
|
|
/** True if registration state changed (added or re-registered). False on no-op. */
|
|
changed: boolean;
|
|
/** Final source state after the call. */
|
|
state: SourceState;
|
|
}
|
|
|
|
/**
|
|
* One row of `gbrain sources list --json`. `config.remote_url` distinguishes
|
|
* URL-managed sources (gbrain owns the clone, may auto-reclone) from
|
|
* path-managed ones (user owns the working tree) — load-bearing for the #1734
|
|
* destructive-op guards.
|
|
*/
|
|
export interface GbrainSourceRow {
|
|
id?: string;
|
|
local_path?: string;
|
|
page_count?: number;
|
|
config?: { remote_url?: string | null } | null;
|
|
}
|
|
|
|
/**
|
|
* Normalize `gbrain sources list --json` output to an array of source rows.
|
|
*
|
|
* gbrain has shipped two shapes: a wrapped `{ sources: [...] }` object (v0.20+)
|
|
* and, in older/other variants, a bare top-level array. #1576 was a crash when a
|
|
* reader assumed one shape; the parse is centralized here so every reader
|
|
* (probeSource, sourcePageCount, sourceLocalPath, the #1734 remote_url audit)
|
|
* agrees on the shape in ONE place. Returns [] for null/garbage rather than
|
|
* throwing — callers treat "no rows" as absent.
|
|
*/
|
|
export function parseSourcesList(raw: unknown): GbrainSourceRow[] {
|
|
if (Array.isArray(raw)) return raw as GbrainSourceRow[];
|
|
if (raw && typeof raw === "object" && Array.isArray((raw as { sources?: unknown }).sources)) {
|
|
return (raw as { sources: GbrainSourceRow[] }).sources;
|
|
}
|
|
return [];
|
|
}
|
|
|
|
export interface EnsureOptions {
|
|
/** Pass --federated to `gbrain sources add`. Default false. */
|
|
federated?: boolean;
|
|
/** When status=drift, force a remove+add to update the registered path. Default true. */
|
|
reregister_on_drift?: boolean;
|
|
/**
|
|
* Optional env override for the spawned `gbrain` calls. Production callers
|
|
* leave this unset (inherit process.env). Tests pass a custom env to point
|
|
* at a fake `gbrain` on PATH (Bun's execFileSync does not respect runtime
|
|
* mutations of process.env.PATH unless env is passed explicitly).
|
|
*/
|
|
env?: NodeJS.ProcessEnv;
|
|
/**
|
|
* #1734 test hooks for the drift-remove guards. Production callers leave
|
|
* these unset (real autopilot detection + real remove decision). Tests pin
|
|
* them so a live autopilot on the dev machine can't flip test outcomes.
|
|
*/
|
|
autopilotProbe?: AutopilotProbe;
|
|
removeDecision?: DecideRemoveOpts;
|
|
}
|
|
|
|
/**
|
|
* Path equality with realpath normalization (macOS /tmp -> /private/tmp,
|
|
* symlinked worktrees). A registered path that resolves to the same real
|
|
* directory is NOT drift — declaring it drift triggers a destructive
|
|
* remove+add and a full re-index for a no-op (#1985 reporter hit the remove
|
|
* on an unmoved repo).
|
|
*/
|
|
function samePath(registered: string | undefined, requested: string): boolean {
|
|
if (!registered) return false;
|
|
if (registered === requested) return true;
|
|
const real = (p: string): string => {
|
|
try {
|
|
return realpathSync(p);
|
|
} catch {
|
|
return p;
|
|
}
|
|
};
|
|
return real(registered) === real(requested);
|
|
}
|
|
|
|
/**
|
|
* Probe the registration state of a source by id.
|
|
*
|
|
* Errors:
|
|
* - "gbrain CLI not on PATH" (exit 127) — caller should treat as absent + skip stage.
|
|
* - "gbrain DB connection failed" — caller should treat as absent + skip stage.
|
|
* - JSON parse error — propagate via withErrorContext caller.
|
|
*/
|
|
export function probeSource(id: string, env?: NodeJS.ProcessEnv): SourceState {
|
|
let stdout: string;
|
|
try {
|
|
stdout = execFileSync("gbrain", ["sources", "list", "--json"], {
|
|
encoding: "utf-8",
|
|
timeout: 30_000,
|
|
stdio: ["ignore", "pipe", "pipe"],
|
|
env,
|
|
shell: NEEDS_SHELL_ON_WINDOWS, // #1731: gbrain is a .cmd shim on Windows
|
|
});
|
|
} catch (err) {
|
|
const e = err as NodeJS.ErrnoException & { stderr?: Buffer };
|
|
const stderr = e.stderr?.toString() || "";
|
|
if (e.code === "ENOENT" || stderr.includes("command not found")) {
|
|
throw new Error("gbrain CLI not on PATH");
|
|
}
|
|
if (stderr.includes("Cannot connect to database") || stderr.includes("config.json")) {
|
|
throw new Error("gbrain not configured (run /setup-gbrain)");
|
|
}
|
|
throw err;
|
|
}
|
|
|
|
let parsed: unknown;
|
|
try {
|
|
parsed = JSON.parse(stdout);
|
|
} catch (err) {
|
|
throw new Error(`gbrain sources list returned non-JSON output: ${(err as Error).message}`);
|
|
}
|
|
|
|
const sources = parseSourcesList(parsed);
|
|
const match = sources.find((s) => s.id === id);
|
|
if (!match) return { status: "absent" };
|
|
return {
|
|
status: "match",
|
|
registered_path: match.local_path,
|
|
};
|
|
}
|
|
|
|
/**
|
|
* Ensure source <id> is registered at <path>. Idempotent.
|
|
*
|
|
* Behavior:
|
|
* - status=absent → `gbrain sources add <id> --path <path> [--federated]`, returns changed=true.
|
|
* - status=match + same path → no-op, returns changed=false.
|
|
* - status=match + different path → `sources remove --confirm-destructive` + `sources add`, returns changed=true.
|
|
* (Skip when reregister_on_drift=false; returns changed=false.)
|
|
*
|
|
* Caller is responsible for catching errors. The function uses withErrorContext for
|
|
* forensic logging to ~/.gstack/.gbrain-errors.jsonl.
|
|
*/
|
|
export async function ensureSourceRegistered(
|
|
id: string,
|
|
path: string,
|
|
options: EnsureOptions = {}
|
|
): Promise<EnsureResult> {
|
|
const federated = options.federated ?? false;
|
|
const reregister_on_drift = options.reregister_on_drift ?? true;
|
|
const env = options.env;
|
|
|
|
return withErrorContext(`ensureSourceRegistered:${id}`, () => {
|
|
const probed = probeSource(id, env);
|
|
|
|
// Disambiguate match-but-different-path (realpath-normalized: a symlink
|
|
// alias of the same directory is a match, not drift).
|
|
let state: SourceState = probed;
|
|
if (probed.status === "match" && !samePath(probed.registered_path, path)) {
|
|
state = { status: "drift", registered_path: probed.registered_path };
|
|
}
|
|
|
|
if (state.status === "match") {
|
|
return { changed: false, state };
|
|
}
|
|
|
|
if (state.status === "drift" && !reregister_on_drift) {
|
|
return { changed: false, state };
|
|
}
|
|
|
|
// For drift, remove first.
|
|
//
|
|
// #1985: gbrain >= 0.42 gates `sources remove` behind --confirm-destructive
|
|
// (`--yes` alone no longer suppresses the data-loss prompt). Without it the
|
|
// remove fails with "To proceed, pass --confirm-destructive", which surfaces
|
|
// as "source registration failed" and aborts the whole /sync-gbrain code
|
|
// stage for any source that has drifted to a new path. This matches the
|
|
// flag the orchestrator's own safeSourcesRemove() already passes.
|
|
if (state.status === "drift") {
|
|
// Loud drift observability: if this line shows up on every sync for some
|
|
// environment, drift is perpetual there and the reindex-in-place design
|
|
// from #1985 should be promoted (drop+rebuild re-embeds the full index).
|
|
console.error(
|
|
`[gbrain-sources] drift: ${id} registered at ${state.registered_path} -> re-registering at ${path}`,
|
|
);
|
|
|
|
// #1734: this remove deletes the source's pages/chunks/embeddings, so it
|
|
// runs only behind the same data-loss guards as the orchestrator's
|
|
// safeSourcesRemove(). A refusal is FATAL here (not best-effort): without
|
|
// the remove the add cannot proceed, and returning changed=false would
|
|
// silently hide the drifted registration.
|
|
const ap = detectAutopilot(env ?? process.env, options.autopilotProbe ?? {});
|
|
if (ap.active) {
|
|
throw new Error(
|
|
`refusing drift re-register of ${id}: autopilot active (${ap.signal}). ` +
|
|
`Stop autopilot, then re-run /sync-gbrain.`,
|
|
);
|
|
}
|
|
const decision = decideSourceRemove(id, env ?? process.env, options.removeDecision ?? {});
|
|
if (!decision.allow) {
|
|
throw new Error(`refusing drift re-register of ${id}: ${decision.reason}`);
|
|
}
|
|
|
|
const rm = spawnSync(
|
|
"gbrain",
|
|
["sources", "remove", id, "--yes", "--confirm-destructive", ...decision.extraArgs],
|
|
{
|
|
encoding: "utf-8",
|
|
timeout: 30_000,
|
|
env,
|
|
shell: NEEDS_SHELL_ON_WINDOWS, // #1731: gbrain is a .cmd shim on Windows
|
|
},
|
|
);
|
|
if (rm.status !== 0) {
|
|
throw new Error(`gbrain sources remove ${id} failed: ${rm.stderr || rm.stdout || `exit ${rm.status}`}`);
|
|
}
|
|
}
|
|
|
|
// Add.
|
|
const addArgs = ["sources", "add", id, "--path", path];
|
|
if (federated) addArgs.push("--federated");
|
|
const add = spawnSync("gbrain", addArgs, {
|
|
encoding: "utf-8",
|
|
timeout: 30_000,
|
|
env,
|
|
shell: NEEDS_SHELL_ON_WINDOWS, // #1731: gbrain is a .cmd shim on Windows
|
|
});
|
|
if (add.status !== 0) {
|
|
throw new Error(`gbrain sources add ${id} failed: ${add.stderr || add.stdout || `exit ${add.status}`}`);
|
|
}
|
|
|
|
return {
|
|
changed: true,
|
|
state: { status: "match", registered_path: path },
|
|
};
|
|
}, "gbrain-sources");
|
|
}
|
|
|
|
/**
|
|
* Get page_count for a registered source. Returns null if source is absent or if
|
|
* page_count is missing/invalid in the JSON. Used by the verdict block + preamble
|
|
* variant selection.
|
|
*/
|
|
export function sourcePageCount(id: string, env?: NodeJS.ProcessEnv): number | null {
|
|
let stdout: string;
|
|
try {
|
|
stdout = execFileSync("gbrain", ["sources", "list", "--json"], {
|
|
encoding: "utf-8",
|
|
timeout: 30_000,
|
|
stdio: ["ignore", "pipe", "pipe"],
|
|
env,
|
|
shell: NEEDS_SHELL_ON_WINDOWS, // #1731: gbrain is a .cmd shim on Windows
|
|
});
|
|
} catch {
|
|
return null;
|
|
}
|
|
|
|
try {
|
|
const match = parseSourcesList(JSON.parse(stdout)).find((s) => s.id === id);
|
|
if (!match) return null;
|
|
if (typeof match.page_count !== "number") return null;
|
|
return match.page_count;
|
|
} catch {
|
|
return null;
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Whether a source's call graph has been built.
|
|
*
|
|
* "completed" — `gbrain dream` has run a full maintenance cycle, so the
|
|
* brain-global `resolve_symbol_edges` phase populated this
|
|
* source's call graph (`gbrain code-callers`/`code-callees`
|
|
* return edges).
|
|
* "never" — a cycle has provably NOT completed for this source.
|
|
* "unknown" — doctor is unavailable, unparseable, or reports a failure
|
|
* that doesn't name this source. Callers MUST treat unknown
|
|
* conservatively (the orchestrator skips auto-dream and WARNs
|
|
* rather than launch a ~35-min cycle on a flaky-doctor signal —
|
|
* see the `gbrain-doctor-overstrict` learning).
|
|
*/
|
|
export type CycleStatus = "completed" | "never" | "unknown";
|
|
|
|
interface DoctorCheck {
|
|
name?: string;
|
|
status?: string;
|
|
message?: string;
|
|
}
|
|
interface DoctorReport {
|
|
checks?: DoctorCheck[];
|
|
}
|
|
|
|
/**
|
|
* Read `gbrain doctor --json --fast` and decide whether <sourceId>'s call
|
|
* graph is built, by inspecting the `cycle_freshness` check.
|
|
*
|
|
* Decision table (cycle_freshness.status / message):
|
|
* - ok → "completed"
|
|
* - fail|warn AND message names <sourceId> → "never"
|
|
* - fail|warn AND message omits <sourceId> → "unknown" (a real failure
|
|
* about OTHER sources must not be silently read as completed for us)
|
|
* - check absent / doctor null / other status → "unknown"
|
|
*
|
|
* `sourceId` is matched as a LITERAL substring (not a regex) so an id with
|
|
* regex metacharacters can never misfire. Routes through `execGbrainJson` so
|
|
* DATABASE_URL is seeded from gbrain's config (consistent with every other
|
|
* gstack-side gbrain call). `env` is the caller's base env (tests inject a
|
|
* shim on PATH).
|
|
*/
|
|
export function cycleCompleted(sourceId: string, env?: NodeJS.ProcessEnv): CycleStatus {
|
|
const report = execGbrainJson<DoctorReport>(["doctor", "--json", "--fast"], { baseEnv: env });
|
|
if (!report || !Array.isArray(report.checks)) return "unknown";
|
|
|
|
const check = report.checks.find((c) => c.name === "cycle_freshness");
|
|
if (!check) return "unknown";
|
|
|
|
if (check.status === "ok") return "completed";
|
|
if (check.status === "fail" || check.status === "warn") {
|
|
const msg = check.message || "";
|
|
return msg.includes(sourceId) ? "never" : "unknown";
|
|
}
|
|
return "unknown";
|
|
}
|