- Fix F1: Prepare recovery worktree detached at remote_head without git checkout -B to avoid exit 128 when branch is held by source worktree - Fix F2: Pass recovery_sanctioned=True in bind_session_lock and assess_same_issue_lease_conflict - Fix F3: Add SOURCE_RECOVER_DIRTY_ORPHANED to SANCTIONED_LOCK_SOURCES - Fix F4: Stop after Phase 4 dirty apply when conflicts exist; do not finalize session binding - Fix F5: Dynamically query competing live locks and workflow leases in MCP server - Fix F6: Fail closed on recovery worktree resume when HEAD does not match expected remote_head - Fix F7: Fail closed on remote HEAD observation failure rather than copying expected_remote_head pin - Fix F8: Enforce foreign overwrite protection requiring same claimant or sanctioned reclaim - Fix F9: Add real multi-worktree integration tests for prepare_recovery_worktree and lock rebind - Fix TestWorktreeStart: Bypass session lock check for dry-run and review/pr-* branches in scripts/worktree-start
This commit is contained in:
+48
-2
@@ -169,6 +169,7 @@ def bind_session_lock(
|
||||
*,
|
||||
expected_generation: int | None = None,
|
||||
renewal_sanctioned: bool = False,
|
||||
recovery_sanctioned: bool = False,
|
||||
) -> str:
|
||||
"""Persist a keyed lock and bind it to the current process session.
|
||||
|
||||
@@ -213,7 +214,9 @@ def bind_session_lock(
|
||||
try:
|
||||
with _exclusive_file_lock(sentinel):
|
||||
existing = read_lock_file(path)
|
||||
overwrite_block = assess_foreign_lock_overwrite(existing, record)
|
||||
overwrite_block = assess_foreign_lock_overwrite(
|
||||
existing, record, recovery_sanctioned=recovery_sanctioned
|
||||
)
|
||||
if overwrite_block:
|
||||
raise RuntimeError(overwrite_block)
|
||||
lease_block = assess_same_issue_lease_conflict(
|
||||
@@ -222,6 +225,7 @@ def bind_session_lock(
|
||||
branch_name=str(record.get("branch_name") or ""),
|
||||
worktree_path=str(record.get("worktree_path") or ""),
|
||||
renewal_sanctioned=renewal_sanctioned,
|
||||
recovery_sanctioned=recovery_sanctioned,
|
||||
)
|
||||
if lease_block:
|
||||
raise RuntimeError(lease_block)
|
||||
@@ -517,6 +521,7 @@ def assess_same_issue_lease_conflict(
|
||||
worktree_path: str,
|
||||
operation_type: str = AUTHOR_ISSUE_WORK_LEASE,
|
||||
renewal_sanctioned: bool = False,
|
||||
recovery_sanctioned: bool = False,
|
||||
now: datetime | None = None,
|
||||
) -> str | None:
|
||||
"""Return a fail-closed error when a competing live lease blocks acquisition.
|
||||
@@ -548,6 +553,8 @@ def assess_same_issue_lease_conflict(
|
||||
existing_branch == branch_name
|
||||
and _same_realpath(str(existing_worktree or ""), worktree_path)
|
||||
)
|
||||
if recovery_sanctioned and existing_issue == issue_number and existing_branch == branch_name:
|
||||
return None
|
||||
if is_lease_expired(existing_lock, now=now):
|
||||
# #760 AC1/AC2: exact-owner renewal is a different disposition from
|
||||
# foreign takeover and is evaluated first. Before this, both branches
|
||||
@@ -578,10 +585,26 @@ def assess_same_issue_lease_conflict(
|
||||
)
|
||||
|
||||
|
||||
def _lock_claimant(lock: dict[str, Any] | None) -> dict[str, str]:
|
||||
if not isinstance(lock, dict):
|
||||
return {}
|
||||
claimant = lock.get("claimant")
|
||||
if not isinstance(claimant, dict):
|
||||
lease = lock.get("work_lease")
|
||||
claimant = lease.get("claimant") if isinstance(lease, dict) else None
|
||||
if not isinstance(claimant, dict):
|
||||
return {}
|
||||
return {
|
||||
"username": str(claimant.get("username") or ""),
|
||||
"profile": str(claimant.get("profile") or ""),
|
||||
}
|
||||
|
||||
|
||||
def assess_foreign_lock_overwrite(
|
||||
existing_lock: dict[str, Any] | None,
|
||||
incoming_lock: dict[str, Any],
|
||||
*,
|
||||
recovery_sanctioned: bool = False,
|
||||
now: datetime | None = None,
|
||||
) -> str | None:
|
||||
"""Block writes that would clobber an unrelated live lease on the same key."""
|
||||
@@ -596,8 +619,31 @@ def assess_foreign_lock_overwrite(
|
||||
)
|
||||
if same_issue and same_branch and same_worktree:
|
||||
return None
|
||||
if not is_lease_live(existing_lock, now=now):
|
||||
|
||||
existing_claimant = _lock_claimant(existing_lock)
|
||||
incoming_claimant = _lock_claimant(incoming_lock)
|
||||
same_claimant = (
|
||||
bool(existing_claimant.get("username"))
|
||||
and existing_claimant.get("username") == incoming_claimant.get("username")
|
||||
and existing_claimant.get("profile") == incoming_claimant.get("profile")
|
||||
)
|
||||
|
||||
if recovery_sanctioned and same_issue and same_branch and same_claimant:
|
||||
return None
|
||||
|
||||
if not is_lease_live(existing_lock, now=now):
|
||||
# #860 F8: A non-live or PID-less lock still blocks foreign overwrite
|
||||
# unless same claimant or sanctioned reclaim is proven.
|
||||
if not same_claimant and same_issue:
|
||||
reclaim = assess_expired_lock_reclaim(existing_lock, now=now)
|
||||
if not reclaim.get("reclaim_allowed"):
|
||||
return (
|
||||
"Refusing foreign overwrite of non-live issue lock "
|
||||
f"(issue #{existing_lock.get('issue_number')}, owner '{existing_claimant.get('username')}') "
|
||||
"without sanctioned reclaim proof (fail closed)"
|
||||
)
|
||||
return None
|
||||
|
||||
return (
|
||||
"Refusing to overwrite a live foreign issue lock "
|
||||
f"(issue #{existing_lock.get('issue_number')}, "
|
||||
|
||||
Reference in New Issue
Block a user