Repository navigation
fix(session): authenticate async task-owner sibling inventories - #6326
Conversation
Expose the complete bounded profile-wide scanner on the trusted protocol API prefix before installing destructive consumers. Genuine scope inspectors remain ephemeral capabilities and every snapshot is revalidated as data, not effect authority. Lore-id: 64b9d2e8 Constraint: protocol present without trusted inspector refuses; no serialized authority Constraint: preserve legacy owner-effect refusal and producer/admission off Tested: real inspector/no-inspector distinction, cross-cwd shared v4 owner patch, reserved protocol alias no-mutation; focused journal/parser tests; full coding-agent package check Not-tested: complete destructive consumer installation or cumulative final gates Confidence: high Scope-risk: bounded Reversibility: revert
Partial or unauthenticated profile inventories cannot establish sibling absence. Record the complete scanner prerequisite without activating owner production or deletion consumers. Lore-id: c6a409d2 Constraint: snapshot data is not deletion authority Tested: journal, transcript, retirement, storage and disk retention suites Tested: coding-agent vendor, Biome and TypeScript checks Confidence: high Scope-risk: narrow Reversibility: revert
d24019b to
7e7d932
Compare
|
Fresh verification update for exact head |
probepark
left a comment
There was a problem hiding this comment.
Review (head 7e7d932, gajae-reviewer on behalf of probepark)
Approve held: CI plan did not run cd packages/coding-agent && bun run check (biome + check:types) on 7e7d932; run it at this head (or add it to the plan) and re-request review.
CI: green: all planned checks pass (Affected path validation incl. 4 targeted coding-agent tests, ts-build, Virtual integration validation, gjc-state-gates). check:@gajae-code/coding-agent was not in the head plan. The PR body reports bun --cwd=packages/coding-agent run check exit 0, but nothing ties that run to this exact head as CI evidence. A comment with the command, head SHA and exit code at 7e7d932 will satisfy this.
Scope: +617 / -1, 3 files: packages/coding-agent/src/session/internal/task-artifact-owner-transcript.ts (+547/-1), test/managed-gc-retirement-journal.test.ts (+68), changelog.d/task-owner-sibling-inventory.md (+2)
Conventions: changelog fragment present; no generated files; no labels; no console.*, new Worker, or mock.module.
Notable:
task-artifact-owner-transcript.ts:163:parseV2ScopeBindinghardcodes".gjc-managed-session-scope.v2.json"althoughMANAGED_SCOPE_BINDING(L54) holds the same value; use the constant so the two paths cannot drift.protocolFileIdentityalso usessnapshot.stat.nlink!(L232);verifyManagedFilealready guaranteesnlink === 1n, so the assertion is safe but could be dropped.hasSiblingTaskArtifactOwnerTranscripthas no production caller in this diff (inert, as the body states). The 3 new tests cover a missing inspector, a cross-cwd v4header_patchowner, and a reserved protocol alias. They do not cover a replaced/foreignv2-binding or a.gjc-recoverytree; consider one fail-closed case for each.
Blocking: none found in the diff. The only hold is the CI-plan gap above.
Suggested verdict line once the hold clears: gajae.pr-review-verdict.v1 merge-approved sha256:05049b50420a93f450182f15ec2bc72c77d6519c63cddba931853537e335665f reviewer:human reviewer-id:probepark evidence:ci-green;inert-new-api;fail-closed-paths-read;need-local-check-pending
|
Responding to the exact-head approve hold: explicitly ran the requested coding-agent package check at immutable # HEAD: 7e7d932313c073d823ced2f59a25a1bcc43a2388
# cwd: packages/coding-agent
bun run check
# equivalent requested invocation: cd packages/coding-agent && bun run check
# EXIT CODE: 0Actual output: Warnings/info were retained, not suppressed. The package test/format/type gate was executed locally on this exact public head; I am not claiming CI plan coverage that the plan did not select, or treating another cumulative head's aggregate as this head's proof. Full local output is retained in the durable goal audit as artifact5346/5347. This responds to the requested local-head run and re-review condition without changing the PR head or source. |
probepark
left a comment
There was a problem hiding this comment.
Review (head 7e7d932, gajae-reviewer on behalf of probepark; re-request rereq1)
need-local satisfied by #6326 (comment): cd packages/coding-agent && bun run check (verify:markit-vendor + biome + check:types) was run at exact head 7e7d932313c073d823ced2f59a25a1bcc43a2388 with EXIT CODE 0. This was the only hold from review 5406441907.
CI: green, 0 pending, 0 failed (approve gate re-run at this head: the only item was need_local check:@gajae-code/coding-agent, now covered by the comment above).
Scope: +617 / -1, 3 files: packages/coding-agent/src/session/internal/task-artifact-owner-transcript.ts, test/managed-gc-retirement-journal.test.ts, changelog.d/task-owner-sibling-inventory.md
Conventions: changelog fragment present; no generated files; no labels; no console.*, new Worker, or mock.module.
Notable (non-blocking, unchanged from the prior review):
task-artifact-owner-transcript.ts:163:parseV2ScopeBindinghardcodes".gjc-managed-session-scope.v2.json"instead of usingMANAGED_SCOPE_BINDING(L54).- The new tests do not cover a replaced/foreign
v2-binding or a.gjc-recoverytree. Add one fail-closed case for each.
Blocking: none.
PR body verdict line count=0, not updated. Suggested verdict line: gajae.pr-review-verdict.v1 merge-approved sha256:05049b50420a93f450182f15ec2bc72c77d6519c63cddba931853537e335665f reviewer:human reviewer-id:probepark evidence:ci-green;inert-new-api;fail-closed-paths-read;need-local-check-exit0-by-author
Verdict: gajae.pr-review-verdict.v1 merge-approved sha256:05049b50420a93f450182f15ec2bc72c77d6519c63cddba931853537e335665f reviewer:human reviewer-id:probepark evidence:ci-green;inert-new-api;fail-closed-paths-read;need-local-check-exit0-by-author
|
Merged into dev as 5197b1e.
Thanks @snowykr. |
Summary
Install the complete authenticated async task-owner sibling inventory after externally merged protocol prerequisite #6323. Do not treat parsed inventories, receipts or matching snapshots as deletion authority.
Exact source / budget
Base dev
3f509b808a4a040c931a9325c2b2d9079400a5a6, containing external #6323 merged11d219b38cfc29670b70640daa69fb8fe85f985, external #6325 tools-type repair, and unrelated upstream #6324 Codex connection-refusal changes, preserved unchanged.Exact head
7e7d932313c073d823ced2f59a25a1bcc43a2388.Owned AND actual dev production review lines 548:
task-artifact-owner-transcript.ts+547/-1. Tests +68 and changelog fragment +2 excluded; 3 files +617/-1 total. This is not a small parent-relative diff masquerading as a dev PR.Exact clean verification
Qualification
08c-independent-after6325-base3f509b80: 220 pass / 9 existing platform skips / 0 fail / 1,138 assertions, 229 tests across 8 files. Clean checkout before/after; all test paths checked to exist.Strict genuine current-source native 0.18.6: addon
ecca056f0c63eca5139c674999a86ca8f4c32926cb18b4c9804efd0d00c32030, path_identity source26555fb71debdd40e0cdb70811847765452facd4cbb4107b646df7cc1a25dcaf, crates-tree parity verified, no manual metadata stamping/QA descriptor rewrite. The separate failed native reaper experiment is NOT included or used as this native dependency.Preservation / limitations
Protected original HEAD
1a12e32f6bbcb5c4a469dd480b4b5dacb37dc95dand its 44 staged files +11023/-1453/no unstaged changes remain untouched. Reference #6240 HEAD7e5f7ef2a745bc1c3d012362f00be9a441bdeb76remains clean and unchanged; no close/rewrite/leader merge.Darwin runtime only; existing warnings/skips remain explicit, including 2 warnings/1 info from package checks. No Linux/Windows/WSL NTFS, arbitrary-FD revocation, LSP readiness, full-stack e2e or repaired published binary claim. All owner deletion consumers and final production/admission activation install separately. Full-cardinality reaper timing and frozen cohort/critic/all-story audit remain outstanding.
Root
check:toolsupstream #6319 type errors were separately repaired and externally merged in #6325. This refreshed head additionally passedbun test scripts/ci-main-native-recovery.test.ts(5 pass, 27 assertions) andbun run check:tools(exit0, existing 4 warnings/4 infos retained). It is not a full aggregate gate claim. Earlier d240/a198 qualification is historical, not transferred to this rebased head. No #6323/#6325 approval or old-head CI transfer; require fresh exact code-event CI and write-access maintainer approval.