You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Follow up post-cap legacy restart validation and preservation races #159
PR #121 received further automated comments after AGENTS.md's two-round Copilot limit. These five distinct follow-ups are deferred under the 2026-09-16 ruling, not claimed fixed. Read-only reliability review confirmed their scope at 733557c and the runtime-identical 69838c5; no additional code changes are requested for this held stabilization.
Verify Git checkout membership. Both restart entrypoints verify an absolute, existing, accessible directory and exact recorded-directory agreement, but those checks do not establish Git membership. Add a Git worktree check before preservation/respawn and at the direct launch gate; test an existing nonrepository directory and a valid Git worktree. Discussions: the lane-handoff and lane-start checkout comments on Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121.
Fence all ordinary handoff mutations. Plain handoff's ownership preflight does not reserve ownership before its window, log and row writes. A concurrent /ctx can reserve preparing after that read. Handoff-byte publication has a locked ownership fence, but its refusal only prints diagnostics while later preservation writes continue. Test that overlap and preserve every canonical input on refusal, retaining legacy behavior without nested helper-lock deadlocks. The handoff file itself is not shown to bypass its publication fence.
Separate unsupported-command detection from current read refusals. Current restart-intent can return 2 for canonicalization failures, while lane-start also treats 2 as an older helper. Static collisions are already rejected by earlier checks; an actual collision-induced launch requires a changing-register interleaving and has not been reproduced. Inject that interleaving and ensure read failure cannot fall through to ordinary resume, while retaining genuine old-helper compatibility.
Reject completed operation tokens in direct lane-start. A matching explicit token for a ready historical intent currently passes into ordinary resume or explicit --fresh. The supervisor already refuses ready operations. Test matching completed tokens with and without --fresh, preserving operation-less ordinary resume and unchanged history.
Require positive holder pane evidence for readiness. ready_check calls pane_agrees for the holder target, but that compatibility predicate treats missing/none targets as agreement. An otherwise matching single live holder can therefore satisfy this part of readiness without proving its pane binding. Refuse or retain indeterminate readiness when holder target evidence is absent, while preserving ordinary compatibility callers. Test one matching UUID/name holder with tmux none, followed by a correctly bound record. Child liveness, unique-holder and exact fresh UUID checks still apply; this does not demonstrate an unrelated-transcript launch or duplicate process. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment).
Evidence: PR #121 discussions and read-only expert inspection of final head 733557c. The review performed no edits or tests. This issue follows the explicit post-cap policy and does not release the existing merge hold. Implemented fixes and validation are tracked separately in #156; legacy rename crash durability is #158. This issue is intentionally not linked with an automatic closing keyword in PR #121.
Additional post-cap triage at reconciliation head 774d189
Honor the explicit checkout when selecting a reservation root.--restart reserves preparing before its later directory resolution, and the initial CAS does not carry an explicit checkout hint. If all ordinary control-root rungs are unavailable, a valid explicit --dir cannot establish the reservation. Separately, direct set-restart-intent --dir ... chooses its root before considering the supplied field. Add an explicit-root-hint case and preserve no-mutation/no-respawn refusal. The broader claim that invalid directories cause canonical preservation before checkout validation is not supported: checkout validation precedes window rename, diagnostic lifecycle transitions, handoff publication, PAUSED and row writes (lane-handoff 1794–1802 before 1809/1854/1985/2256). An invalid checkout may leave a failed reservation as diagnostic history, not partially preserved canonical inputs. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment).
Specify flag-shaped values for restart helper options. Optional manifest fields currently accept leading-hyphen words: a sandbox probe of set-restart-intent ... --mode --operation returns 0 and writes that optional mode while preserving the existing operation. Decide whether those values must require the equals spelling or be refused, retaining intentional empty/prose values and both supported flag spellings. The supplied example with a trailing op returns usage exit 64 (unknown option 'op') and preserves the intent; it does not silently generate a different operation. Add parser/refusal coverage for the narrower accepted-value cases. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment).
These two comments arrived in another Copilot round after the explicit two-round cap. Their remaining cases are recorded here and are not claimed fixed by the #97 reconciliation. They do not release the merge hold.
Preparation recovery identity hardening at 6b92e35
Define same-operation mutation detection for failed preparation recovery. The recovery snapshot compares state, mode, attempt, new transcript, operation and generation. A direct set-restart-intent ... failed --expect failed can retain those values while changing additional recorded launch facts. Normal failure writers cannot perform that failed-to-failed transition; ordinary recovery chooses its launch from normal lane records and arguments rather than those omitted intent fields. Read-only reliability review confirms the mutable-field observation but does not establish the claimed P1 impact, a wrong-checkout launch or a supervised-ownership bypass. Define whether recovery must also detect changes to agent/profile, directory, pane/window, handoff/digest and old transcript; enforce the chosen policy and test a same-operation update between each recovery checkpoint. Current FR-009 explicitly fences unchanged operation/generation and the qualifying preparation fields. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment) .
This later Copilot finding is deferred under AGENTS.md's explicit two-round cap. The user released the original #97 merge hold on 2026-10-05; earlier hold wording above is historical. This issue remains open after #121 lands.
Clear empty forwarded launch values.lane-handoff omits empty assignments for forwarded roots/protocol and launcher host/OS/container variables. Respawn can therefore inherit a stale tmux server value. Serialize explicit empty assignments, or documented unset semantics, for the variables already forwarded; evaluate the respawn command against conflicting server environment and empty/unset/nonempty/quoted caller values. The narrower environment/read-identity drift is valid. The broader unrelated-intent launch claim is unproven: the supervisor compares the exact minted operation before its state/mode/pane/digest/holder gates, so an unrelated stale intent normally refuses. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment) .
Reserve operation none for absence. Shared record validation and explicit --operation none currently accept this sentinel, and launch entrypoints can compare it as a matching token. Normal /ctx and absent-token helper creation generate real ctx-/op- identifiers. Reject the reserved sentinel in argument and record validation; test unchanged-byte refusal, existing pending/failed records classified INCOMPLETE with no launch, and preserved valid custom IDs. This establishes token hardening, not a bypass of generation/attempt/mode/agent/pane/digest/holder gates or a wrong-transcript launch. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment) .
Read-only contract triage confirmed these narrower cases. They arrived after the repository's explicit two-round Copilot cap and remain open follow-ups, not claimed fixed or additional landing requirements.
Require positive pane evidence for direct active launches. The active restart gate compares pane identities only when both the parsed recorded pane and TMUX_PANE are nonempty. Missing current pane evidence therefore skips that comparison. Require a parseable recorded pane and a matching current pane before transcript reservation/exec; test unset, empty, none, mismatched and matching evidence. Read-only inspection confirms the conditional omission; an end-to-end wrong-pane or duplicate launch was not exercised, and operation/digest/agent/profile/directory/binding/holder checks still apply. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment) .
Define the mutation policy for a sole intent-file symlink. A sole existing leaf symlink is followed for validation, but atomic publication replaces the link entry and leaves its target stale. Refuse symlink mutation under the CAS mutex without changing either entry, or define and verify target publication with the temporary file beside that target. Test the link/target bytes across transitions, dangling links and directory aliases. Distinct occupied root entries, including file aliases, are already refused by fb28987; this does not reopen that fixed case. Ordinary bounded readers continue to select the single candidate entry after replacement; the remaining topology concern involves external or explicitly rooted readers. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment) .
Read-only contract review confirmed these bounded observations. This review arrived after the repository's explicit two-round Copilot cap. These remain open follow-ups and do not add landing requirements or assert that the omitted cases are fixed. The user-released merge hold remains cleared.
PR #121 received further automated comments after AGENTS.md's two-round Copilot limit. These five distinct follow-ups are deferred under the 2026-09-16 ruling, not claimed fixed. Read-only reliability review confirmed their scope at 733557c and the runtime-identical 69838c5; no additional code changes are requested for this held stabilization.
Verify Git checkout membership. Both restart entrypoints verify an absolute, existing, accessible directory and exact recorded-directory agreement, but those checks do not establish Git membership. Add a Git worktree check before preservation/respawn and at the direct launch gate; test an existing nonrepository directory and a valid Git worktree. Discussions: the lane-handoff and lane-start checkout comments on Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121.
Fence all ordinary handoff mutations. Plain handoff's ownership preflight does not reserve ownership before its window, log and row writes. A concurrent /ctx can reserve preparing after that read. Handoff-byte publication has a locked ownership fence, but its refusal only prints diagnostics while later preservation writes continue. Test that overlap and preserve every canonical input on refusal, retaining legacy behavior without nested helper-lock deadlocks. The handoff file itself is not shown to bypass its publication fence.
Separate unsupported-command detection from current read refusals. Current restart-intent can return 2 for canonicalization failures, while lane-start also treats 2 as an older helper. Static collisions are already rejected by earlier checks; an actual collision-induced launch requires a changing-register interleaving and has not been reproduced. Inject that interleaving and ensure read failure cannot fall through to ordinary resume, while retaining genuine old-helper compatibility.
Reject completed operation tokens in direct lane-start. A matching explicit token for a ready historical intent currently passes into ordinary resume or explicit --fresh. The supervisor already refuses ready operations. Test matching completed tokens with and without --fresh, preserving operation-less ordinary resume and unchanged history.
Require positive holder pane evidence for readiness. ready_check calls pane_agrees for the holder target, but that compatibility predicate treats missing/none targets as agreement. An otherwise matching single live holder can therefore satisfy this part of readiness without proving its pane binding. Refuse or retain indeterminate readiness when holder target evidence is absent, while preserving ordinary compatibility callers. Test one matching UUID/name holder with tmux none, followed by a correctly bound record. Child liveness, unique-holder and exact fresh UUID checks still apply; this does not demonstrate an unrelated-transcript launch or duplicate process. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment).
Evidence: PR #121 discussions and read-only expert inspection of final head 733557c. The review performed no edits or tests. This issue follows the explicit post-cap policy and does not release the existing merge hold. Implemented fixes and validation are tracked separately in #156; legacy rename crash durability is #158. This issue is intentionally not linked with an automatic closing keyword in PR #121.
Additional post-cap triage at reconciliation head 774d189
Honor the explicit checkout when selecting a reservation root.
--restartreserves preparing before its later directory resolution, and the initial CAS does not carry an explicit checkout hint. If all ordinary control-root rungs are unavailable, a valid explicit--dircannot establish the reservation. Separately, directset-restart-intent --dir ...chooses its root before considering the supplied field. Add an explicit-root-hint case and preserve no-mutation/no-respawn refusal. The broader claim that invalid directories cause canonical preservation before checkout validation is not supported: checkout validation precedes window rename, diagnostic lifecycle transitions, handoff publication, PAUSED and row writes (lane-handoff 1794–1802 before 1809/1854/1985/2256). An invalid checkout may leave a failed reservation as diagnostic history, not partially preserved canonical inputs. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment).Specify flag-shaped values for restart helper options. Optional manifest fields currently accept leading-hyphen words: a sandbox probe of
set-restart-intent ... --mode --operationreturns 0 and writes that optional mode while preserving the existing operation. Decide whether those values must require the equals spelling or be refused, retaining intentional empty/prose values and both supported flag spellings. The supplied example with a trailingopreturns usage exit 64 (unknown option 'op') and preserves the intent; it does not silently generate a different operation. Add parser/refusal coverage for the narrower accepted-value cases. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment).These two comments arrived in another Copilot round after the explicit two-round cap. Their remaining cases are recorded here and are not claimed fixed by the #97 reconciliation. They do not release the merge hold.
Preparation recovery identity hardening at 6b92e35
set-restart-intent ... failed --expect failedcan retain those values while changing additional recorded launch facts. Normal failure writers cannot perform that failed-to-failed transition; ordinary recovery chooses its launch from normal lane records and arguments rather than those omitted intent fields. Read-only reliability review confirms the mutable-field observation but does not establish the claimed P1 impact, a wrong-checkout launch or a supervised-ownership bypass. Define whether recovery must also detect changes to agent/profile, directory, pane/window, handoff/digest and old transcript; enforce the chosen policy and test a same-operation update between each recovery checkpoint. Current FR-009 explicitly fences unchanged operation/generation and the qualifying preparation fields. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment) .This later Copilot finding is deferred under AGENTS.md's explicit two-round cap. The user released the original #97 merge hold on 2026-10-05; earlier hold wording above is historical. This issue remains open after #121 lands.
Further post-cap hardening at b20882a
Clear empty forwarded launch values.
lane-handoffomits empty assignments for forwarded roots/protocol and launcher host/OS/container variables. Respawn can therefore inherit a stale tmux server value. Serialize explicit empty assignments, or documented unset semantics, for the variables already forwarded; evaluate the respawn command against conflicting server environment and empty/unset/nonempty/quoted caller values. The narrower environment/read-identity drift is valid. The broader unrelated-intent launch claim is unproven: the supervisor compares the exact minted operation before its state/mode/pane/digest/holder gates, so an unrelated stale intent normally refuses. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment) .Reserve operation
nonefor absence. Shared record validation and explicit--operation nonecurrently accept this sentinel, and launch entrypoints can compare it as a matching token. Normal/ctxand absent-token helper creation generate real ctx-/op- identifiers. Reject the reserved sentinel in argument and record validation; test unchanged-byte refusal, existing pending/failed records classified INCOMPLETE with no launch, and preserved valid custom IDs. This establishes token hardening, not a bypass of generation/attempt/mode/agent/pane/digest/holder gates or a wrong-transcript launch. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment) .Read-only contract triage confirmed these narrower cases. They arrived after the repository's explicit two-round Copilot cap and remain open follow-ups, not claimed fixed or additional landing requirements.
Post-cap triage at fb28987
Require positive pane evidence for direct active launches. The active restart gate compares pane identities only when both the parsed recorded pane and
TMUX_PANEare nonempty. Missing current pane evidence therefore skips that comparison. Require a parseable recorded pane and a matching current pane before transcript reservation/exec; test unset, empty, none, mismatched and matching evidence. Read-only inspection confirms the conditional omission; an end-to-end wrong-pane or duplicate launch was not exercised, and operation/digest/agent/profile/directory/binding/holder checks still apply. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment) .Define the mutation policy for a sole intent-file symlink. A sole existing leaf symlink is followed for validation, but atomic publication replaces the link entry and leaves its target stale. Refuse symlink mutation under the CAS mutex without changing either entry, or define and verify target publication with the temporary file beside that target. Test the link/target bytes across transitions, dangling links and directory aliases. Distinct occupied root entries, including file aliases, are already refused by fb28987; this does not reopen that fixed case. Ordinary bounded readers continue to select the single candidate entry after replacement; the remaining topology concern involves external or explicitly rooted readers. Discussion: Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 (comment) .
Specify holder witnesses versus process identity. The optional all-witness helper deduplicates by PID and UUID, so historical/current UUID witnesses for one live PID can both appear. Current readiness already deduplicates by PID and prefers the exact current UUID; its claimed ambiguity is not established. Other restart consumers require holder absence and do not count witness lines. Test multiple UUID witnesses for one PID and two PIDs sharing one UUID. If changing the helper contract, preserve current UUID evidence through grouped witnesses or requested-UUID preference; blind PID-only deduplication could discard it. This item comes from the overview of Copilot review 5417942630; the pair-key path is PR Keep supervised manual ctx as legacy compatibility and refuse managed lanes #121 code, while the base holder identity helpers were inherited from Crash-consistent lane worktree recovery: a lane now says WHERE its session stopped — RUNNING → SWAPPING → SWAPPED with a generation/operation fence, a machine-readable worktree inventory taken at every handoff, and a resume reconciliation that reports and resets nothing #97.
Read-only contract review confirmed these bounded observations. This review arrived after the repository's explicit two-round Copilot cap. These remain open follow-ups and do not add landing requirements or assert that the omitted cases are fixed. The user-released merge hold remains cleared.