You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Source: static audit of main@384439634. Candidates are static and not reproduced — confirm each before changing code.
Template: agent-task (agent-ready, docs/ISSUE_TRIAGE.md). Labels: bug, agent-ready.
Goal / Why
State, session, ledger, goal, and job records are written with non-unique temp names, without fsync, or as multi-step commits. A crash, power loss, or a second writer can then leave a truncated file or a half-applied batch that later code reads as valid — losing claims, decisions, or session history, or reviving deleted records. The fix is one atomic durable-write contract per record set: unique temp name, fsync, rename, and batch/transaction semantics for multi-file commits. Non-atomic Windows replacement and mirror-write ordering belong to the same contract.
Confirmed static findings in this class: 8 (reassessed severity noted per line).
Scope / Plan
Re-read each candidate below at the cited file:line on current main; drop anything already fixed or misread.
One owner for atomic durable writes: unique temp file, fsync, rename, and batch/transaction semantics per record set.
Add the smallest regression/gate that would catch a re-introduction (focused test, budget script, or grep guard).
Key files
crates/tui/src/tools/subagent/mod.rs
crates/tui/src/tui/views/fleet_detail.rs
crates/tui/src/runtime_threads.rs
crates/tui/src/tui/session_picker.rs
crates/cli/src/update.rs
web/scripts/sync-latest-release.mjs
integrations/bridge-core/src/lib.mjs
integrations/weixin-bridge/src/index.mjs
Acceptance criteria
Every listed candidate is either fixed with a test, or downgraded with a written reason in the PR.
No new instance of this class is introduced (guarded by the test/budget).
Existing behavior for unrelated paths is unchanged.
Verification
cargo check -p codewhale-tui -p codewhale-cli
cargo test -p codewhale-tui --lib
cargo clippy --workspace --all-targets --locked -- -D warnings
( cd web && npm run check )
( cd integrations/bridge-core && npm run test )
Out of scope
Findings that belong to another systemic class or to the localized backlog.
U08-09 · U08 — Setup, approvals, hotbar, session/config · crates/tui/src/tui/session_picker.rs:97 — full session store sync load; errors become empty, preview cache stale after rename. audit severity: major; reassessed: major
Goal / Why
State, session, ledger, goal, and job records are written with non-unique temp names, without fsync, or as multi-step commits. A crash, power loss, or a second writer can then leave a truncated file or a half-applied batch that later code reads as valid — losing claims, decisions, or session history, or reviving deleted records. The fix is one atomic durable-write contract per record set: unique temp name, fsync, rename, and batch/transaction semantics for multi-file commits. Non-atomic Windows replacement and mirror-write ordering belong to the same contract.
Confirmed static findings in this class: 8 (reassessed severity noted per line).
Scope / Plan
file:lineon currentmain; drop anything already fixed or misread.Key files
crates/tui/src/tools/subagent/mod.rscrates/tui/src/tui/views/fleet_detail.rscrates/tui/src/runtime_threads.rscrates/tui/src/tui/session_picker.rscrates/cli/src/update.rsweb/scripts/sync-latest-release.mjsintegrations/bridge-core/src/lib.mjsintegrations/weixin-bridge/src/index.mjsAcceptance criteria
Verification
Out of scope
Related existing work (do not duplicate)
#4634/#4635 (pin artifact/journal identity), #6432 (exclusive rename publication), #5491 (persist before execution), #6354
Candidate findings (8)
agent/subagent runtime ·crates/tui/src/tools/subagent/mod.rs:3423— shared read lock and process-local sequence allow overlapping writers; the last rename wipes claims/decisions/tasks.audit severity: critical; reassessed: critical
crates/tui/src/tui/views/fleet_detail.rs:641— ordinary Save/rename overwrites an external newer Fleet source without source-version check.audit severity: high; reassessed: major
agent/subagent runtime ·crates/tui/src/tools/subagent/mod.rs:8030— terminal acknowledgement published before durable commit; crash leaves child Running/Interrupted.audit severity: major; reassessed: major
crates/tui/src/runtime_threads.rs:8357— partial seed crash leaves turns/items without thread publication; startup restores partial state.audit severity: major; reassessed: major
crates/tui/src/tui/session_picker.rs:97— full session store sync load; errors become empty, preview cache stale after rename.audit severity: major; reassessed: major
crates/cli/src/update.rs:1904— Windows replacement non-atomic, rollback errors ignored; crash leaves target missing.audit severity: major; reassessed: major
web/scripts/sync-latest-release.mjs:41—--checkfalse-green on outage; target write before mirror validation creates partial state.audit severity: major; reassessed: major
integrations/bridge-core/src/lib.mjs:156,integrations/weixin-bridge/src/index.mjs:778— cursor/message committed before side effect; fixed.tmpno fsync, crash can lose prompt.audit severity: high; reassessed: high