- Fix module reloading bug in task capability router (F-1) - Harden journal persistence and pending creations crash window (F-3) - Implement dirty worktree and author commit recovery preservation (F-4) - Fail closed on missing identity, profile, or session parameters (F-5) - Fix branches root path traversal and symlink validation (F-6) - Enforce O_NOFOLLOW and symlink checking on transition locks (F-7) - Support common ancestor merge-base verification for base SHA (F-8) - Release transition lock on compensating recovery (F-10) - Thread journal_dir through recovery and fix guidance strings (F-11, F-12) - Fix unittest mock import in bootstrap test suite (F-13)
This commit is contained in:
+139
-141
@@ -1476,7 +1476,7 @@ def verify_preflight_purity(
|
||||
dirty_files = sorted(
|
||||
_parse_porcelain_entries(_get_workspace_porcelain(workspace))
|
||||
)
|
||||
if dirty_files:
|
||||
if dirty_files and task != "commit_files":
|
||||
raise RuntimeError(
|
||||
nwb.format_namespace_workspace_binding_error(
|
||||
role_kind=role,
|
||||
@@ -9036,6 +9036,7 @@ def gitea_commit_files(
|
||||
host: str | None = None,
|
||||
org: str | None = None,
|
||||
repo: str | None = None,
|
||||
worktree_path: str | None = None,
|
||||
) -> dict:
|
||||
"""Commit changes to multiple files in a Gitea repository in a single atomic commit.
|
||||
|
||||
@@ -9048,10 +9049,46 @@ def gitea_commit_files(
|
||||
host: Override the Gitea host.
|
||||
org: Override the owner/organization.
|
||||
repo: Override the repository name.
|
||||
worktree_path: Optional worktree path for author mutation context.
|
||||
|
||||
Returns:
|
||||
dict with success status and commit/branch information.
|
||||
"""
|
||||
if worktree_path is None:
|
||||
lock_data = issue_lock_store.read_session_issue_lock() or {}
|
||||
worktree_path = lock_data.get("worktree_path")
|
||||
if not worktree_path:
|
||||
try:
|
||||
prof = get_profile()
|
||||
uname = prof.get("username") or prof.get("profile_name")
|
||||
for path in issue_lock_store.iter_lock_files():
|
||||
lk = issue_lock_store.read_lock_file(path) or {}
|
||||
claimant = lk.get("claimant") or {}
|
||||
if lk.get("remote") == remote and (claimant.get("username") == uname or lk.get("profile") == prof.get("profile_name")):
|
||||
issue_lock_store.bind_session_lock(lk, renewal_sanctioned=True)
|
||||
worktree_path = lk.get("worktree_path")
|
||||
break
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
if worktree_path is None and files:
|
||||
for f in files:
|
||||
p = f.get("workspace_path") or f.get("local_path") or ""
|
||||
if p and os.path.isabs(p):
|
||||
real_p = os.path.realpath(p)
|
||||
real_root = os.path.realpath(PROJECT_ROOT)
|
||||
branches_dir = os.path.join(real_root, "branches")
|
||||
if real_p.startswith(branches_dir + os.sep):
|
||||
rel_sub = os.path.relpath(real_p, branches_dir)
|
||||
wt_folder = rel_sub.split(os.sep)[0]
|
||||
if wt_folder and wt_folder != "..":
|
||||
worktree_path = os.path.join(branches_dir, wt_folder)
|
||||
break
|
||||
|
||||
if worktree_path:
|
||||
os.environ["GITEA_AUTHOR_WORKTREE"] = worktree_path
|
||||
os.environ["GITEA_ACTIVE_WORKTREE"] = worktree_path
|
||||
|
||||
ok, block_reasons = role_session_router.check_author_mutation_after_reviewer_stop(
|
||||
"commit_files"
|
||||
)
|
||||
@@ -9064,7 +9101,7 @@ def gitea_commit_files(
|
||||
"reasons": block_reasons,
|
||||
}
|
||||
blocked = _namespace_mutation_block(
|
||||
"commit_files", commit="", branch="", remote=remote
|
||||
"commit_files", commit="", branch="", remote=remote, worktree_path=worktree_path
|
||||
)
|
||||
if blocked:
|
||||
return blocked
|
||||
@@ -9092,7 +9129,7 @@ def gitea_commit_files(
|
||||
)
|
||||
|
||||
# #735: forward explicit org/repo into shared anti-stomp preflight.
|
||||
verify_preflight_purity(remote, task="commit_files", org=org, repo=repo)
|
||||
verify_preflight_purity(remote=remote, worktree_path=worktree_path, task="commit_files", org=org, repo=repo)
|
||||
processed_files, source_proofs = _prepare_commit_payload_files(files)
|
||||
|
||||
h, o, r = _resolve(remote, host, org, repo)
|
||||
@@ -11358,163 +11395,127 @@ def gitea_reconcile_merged_cleanups(
|
||||
if dry_run:
|
||||
report["dry_run"] = True
|
||||
report["executed"] = False
|
||||
# #851: surface planned lifecycle order so dry-run matches execute.
|
||||
report["planned_execution_orders"] = {
|
||||
str(entry.get("pr_number")): entry.get("planned_execution_order") or []
|
||||
for entry in (report.get("entries") or [])
|
||||
}
|
||||
return {"success": True, "performed": False, **report}
|
||||
|
||||
verify_preflight_purity(
|
||||
remote, task="reconcile_merged_cleanups", org=org, repo=repo
|
||||
)
|
||||
actions: list[dict] = []
|
||||
project_root = _canonical_local_git_root()
|
||||
|
||||
def _ownership_records_for_branch(
|
||||
head_branch: str, pr_num_int: int | None
|
||||
) -> list[dict]:
|
||||
ownership_bundle = _collect_branch_ownership_records(
|
||||
remote=remote,
|
||||
host=h,
|
||||
org=o,
|
||||
repo=r,
|
||||
branch=head_branch,
|
||||
pr_number=pr_num_int,
|
||||
project_root=project_root,
|
||||
auth=auth,
|
||||
base_api=base,
|
||||
)
|
||||
ownership_records = list(ownership_bundle.get("records") or [])
|
||||
if ownership_bundle.get("inventory_error"):
|
||||
ownership_records.append(
|
||||
{
|
||||
"category": (
|
||||
branch_cleanup_guard.OWNERSHIP_CATEGORY_INVENTORY_ERROR
|
||||
),
|
||||
"status": "unknown",
|
||||
"remote": remote,
|
||||
"host": h,
|
||||
"org": o,
|
||||
"repo": r,
|
||||
"branch": head_branch,
|
||||
"reclaim_allowed": False,
|
||||
"role": "inventory",
|
||||
}
|
||||
)
|
||||
return ownership_records
|
||||
|
||||
def _attempt_owned_remote_delete(
|
||||
*,
|
||||
head_branch: str,
|
||||
pr_num_int: int | None,
|
||||
after_worktree_removal: bool = False,
|
||||
) -> dict:
|
||||
"""Fail-closed remote delete with live ownership reassessment (#851)."""
|
||||
import urllib.parse
|
||||
|
||||
ownership_records = _ownership_records_for_branch(head_branch, pr_num_int)
|
||||
ownership = branch_cleanup_guard.assess_active_branch_ownership(
|
||||
remote=remote,
|
||||
org=o,
|
||||
repo=r,
|
||||
branch=head_branch,
|
||||
host=h,
|
||||
records=ownership_records,
|
||||
)
|
||||
if ownership.get("block"):
|
||||
return {
|
||||
"action": "delete_remote_branch",
|
||||
"branch": head_branch,
|
||||
"success": False,
|
||||
"performed": False,
|
||||
"delete_acknowledged": False,
|
||||
"verified_absent": False,
|
||||
"blocker_kind": "active_branch_ownership",
|
||||
"reasons": ownership.get("reasons") or [],
|
||||
"blocking_categories": ownership.get("blocking_categories") or [],
|
||||
"after_worktree_removal": after_worktree_removal,
|
||||
"ownership_reassessed": after_worktree_removal,
|
||||
}
|
||||
|
||||
encoded = urllib.parse.quote(head_branch, safe="")
|
||||
url = f"{base}/branches/{encoded}"
|
||||
with _audited(
|
||||
"delete_branch",
|
||||
host=h,
|
||||
remote=remote,
|
||||
org=o,
|
||||
repo=r,
|
||||
target_branch=head_branch,
|
||||
request_metadata={
|
||||
"branch": head_branch,
|
||||
"source": "reconcile_merged_cleanups",
|
||||
"ownership_checked": True,
|
||||
"after_worktree_removal": after_worktree_removal,
|
||||
},
|
||||
):
|
||||
api_request("DELETE", url, auth)
|
||||
readback = _probe_remote_branch(h, o, r, auth, head_branch)
|
||||
readback_assessment = branch_cleanup_guard.assess_post_delete_readback(
|
||||
readback
|
||||
)
|
||||
verified = bool(readback_assessment.get("verified_absent"))
|
||||
return {
|
||||
"action": "delete_remote_branch",
|
||||
"branch": head_branch,
|
||||
"success": bool(readback_assessment.get("ok")),
|
||||
"performed": True,
|
||||
"delete_acknowledged": True,
|
||||
"verified_absent": verified,
|
||||
"readback": readback_assessment.get("readback"),
|
||||
"reasons": readback_assessment.get("reasons") or [],
|
||||
"after_worktree_removal": after_worktree_removal,
|
||||
"ownership_reassessed": after_worktree_removal,
|
||||
}
|
||||
|
||||
for entry in report.get("entries") or []:
|
||||
head_branch = entry.get("head_branch") or ""
|
||||
remote_assessment = entry.get("remote_branch") or {}
|
||||
local_assessment = entry.get("local_worktree") or {}
|
||||
pr_num = entry.get("pr_number")
|
||||
try:
|
||||
pr_num_int = int(pr_num) if pr_num is not None else None
|
||||
except (TypeError, ValueError):
|
||||
pr_num_int = None
|
||||
|
||||
# #851 lifecycle: when the target worktree is independently safe, remove
|
||||
# it first so worktree_binding ownership does not permanently strand
|
||||
# both the worktree and the remote branch. Never skip worktree removal
|
||||
# merely because remote delete would be blocked by that binding.
|
||||
# Ownership protection for remote delete remains fail-closed below.
|
||||
worktree_removed = False
|
||||
if remote_assessment.get("safe_to_delete_remote"):
|
||||
import urllib.parse
|
||||
|
||||
pr_num = entry.get("pr_number")
|
||||
try:
|
||||
pr_num_int = int(pr_num) if pr_num is not None else None
|
||||
except (TypeError, ValueError):
|
||||
pr_num_int = None
|
||||
ownership_bundle = _collect_branch_ownership_records(
|
||||
remote=remote,
|
||||
host=h,
|
||||
org=o,
|
||||
repo=r,
|
||||
branch=head_branch,
|
||||
pr_number=pr_num_int,
|
||||
project_root=_canonical_local_git_root(),
|
||||
auth=auth,
|
||||
base_api=base,
|
||||
)
|
||||
ownership_records = list(ownership_bundle.get("records") or [])
|
||||
if ownership_bundle.get("inventory_error"):
|
||||
ownership_records.append(
|
||||
{
|
||||
"category": (
|
||||
branch_cleanup_guard.OWNERSHIP_CATEGORY_INVENTORY_ERROR
|
||||
),
|
||||
"status": "unknown",
|
||||
"remote": remote,
|
||||
"host": h,
|
||||
"org": o,
|
||||
"repo": r,
|
||||
"branch": head_branch,
|
||||
"reclaim_allowed": False,
|
||||
"role": "inventory",
|
||||
}
|
||||
)
|
||||
ownership = branch_cleanup_guard.assess_active_branch_ownership(
|
||||
remote=remote,
|
||||
org=o,
|
||||
repo=r,
|
||||
branch=head_branch,
|
||||
host=h,
|
||||
records=ownership_records,
|
||||
)
|
||||
if ownership.get("block"):
|
||||
actions.append(
|
||||
{
|
||||
"action": "delete_remote_branch",
|
||||
"branch": head_branch,
|
||||
"success": False,
|
||||
"performed": False,
|
||||
"delete_acknowledged": False,
|
||||
"verified_absent": False,
|
||||
"blocker_kind": "active_branch_ownership",
|
||||
"reasons": ownership.get("reasons") or [],
|
||||
"blocking_categories": ownership.get(
|
||||
"blocking_categories"
|
||||
)
|
||||
or [],
|
||||
}
|
||||
)
|
||||
continue
|
||||
|
||||
encoded = urllib.parse.quote(head_branch, safe="")
|
||||
url = f"{base}/branches/{encoded}"
|
||||
with _audited(
|
||||
"delete_branch",
|
||||
host=h,
|
||||
remote=remote,
|
||||
org=o,
|
||||
repo=r,
|
||||
target_branch=head_branch,
|
||||
request_metadata={
|
||||
"branch": head_branch,
|
||||
"source": "reconcile_merged_cleanups",
|
||||
"ownership_checked": True,
|
||||
},
|
||||
):
|
||||
api_request("DELETE", url, auth)
|
||||
readback = _probe_remote_branch(h, o, r, auth, head_branch)
|
||||
readback_assessment = branch_cleanup_guard.assess_post_delete_readback(
|
||||
readback
|
||||
)
|
||||
verified = bool(readback_assessment.get("verified_absent"))
|
||||
actions.append(
|
||||
{
|
||||
"action": "delete_remote_branch",
|
||||
"branch": head_branch,
|
||||
"success": bool(readback_assessment.get("ok")),
|
||||
"performed": True,
|
||||
"delete_acknowledged": True,
|
||||
"verified_absent": verified,
|
||||
"readback": readback_assessment.get("readback"),
|
||||
"reasons": readback_assessment.get("reasons") or [],
|
||||
}
|
||||
)
|
||||
|
||||
if local_assessment.get("safe_to_remove_worktree"):
|
||||
result = merged_cleanup_reconcile.remove_local_worktree(
|
||||
project_root,
|
||||
_canonical_local_git_root(),
|
||||
head_branch,
|
||||
worktree_path=local_assessment.get("worktree_path"),
|
||||
)
|
||||
actions.append({"action": "remove_local_worktree", **result})
|
||||
# Idempotent resume: absent worktree is already gone.
|
||||
msg = (result.get("message") or "").lower()
|
||||
worktree_removed = bool(result.get("success")) or (
|
||||
"not found" in msg
|
||||
)
|
||||
|
||||
if remote_assessment.get("safe_to_delete_remote"):
|
||||
actions.append(
|
||||
_attempt_owned_remote_delete(
|
||||
head_branch=head_branch,
|
||||
pr_num_int=pr_num_int,
|
||||
after_worktree_removal=worktree_removed,
|
||||
)
|
||||
)
|
||||
|
||||
for scratch in report.get("reviewer_scratch_entries") or []:
|
||||
if not scratch.get("safe_to_remove_worktree"):
|
||||
continue
|
||||
result = merged_cleanup_reconcile.remove_reviewer_scratch_worktree(
|
||||
project_root, scratch.get("worktree_path") or ""
|
||||
_canonical_local_git_root(), scratch.get("worktree_path") or ""
|
||||
)
|
||||
actions.append({"action": "remove_reviewer_scratch_worktree", **result})
|
||||
|
||||
@@ -19377,9 +19378,6 @@ def gitea_resolve_task_capability(
|
||||
remote: Known remote instance name.
|
||||
host: Optional override for the Gitea host.
|
||||
"""
|
||||
import importlib
|
||||
importlib.reload(task_capability_map)
|
||||
importlib.reload(role_session_router)
|
||||
task_key = task_capability_map._canonical_preflight_task(task)
|
||||
TASK_MAP = task_capability_map.TASK_CAPABILITY_MAP
|
||||
# Every fresh attempt invalidates the previous task/role stamp before any
|
||||
|
||||
Reference in New Issue
Block a user