Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
dc99c15ffa | ||
|
|
9f759150b8 | ||
|
|
347464a057 | ||
|
|
1301a57de4 |
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,223 @@
|
|||||||
|
# ADR: MCP restart governance and authorization policy
|
||||||
|
|
||||||
|
- **Status:** Accepted (policy effective immediately for LLM and operator sessions; enforcement tooling may lag)
|
||||||
|
- **Date:** 2026-07-23
|
||||||
|
- **Tracking issue:** [#656](https://gitea.prgs.cc/Scaled-Tech-Consulting/Gitea-Tools/issues/656)
|
||||||
|
- **Policy version:** `restart-governance/v1`
|
||||||
|
- **Related:**
|
||||||
|
- Umbrella: [#655](https://gitea.prgs.cc/Scaled-Tech-Consulting/Gitea-Tools/issues/655) — governed MCP restart coordination and zero-disruption recovery
|
||||||
|
- Vision: [#652](https://gitea.prgs.cc/Scaled-Tech-Consulting/Gitea-Tools/issues/652) — MCP Control Plane Web Console product vision (§A system health and process control)
|
||||||
|
- Roadmap: [#653](https://gitea.prgs.cc/Scaled-Tech-Consulting/Gitea-Tools/issues/653) — Control Plane Web Console phased delivery (Phase 2 restart controls)
|
||||||
|
- Contamination guard: [#630](https://gitea.prgs.cc/Scaled-Tech-Consulting/Gitea-Tools/issues/630) — blocks manual process-kill recovery
|
||||||
|
- Console restart UX: [#642](https://gitea.prgs.cc/Scaled-Tech-Consulting/Gitea-Tools/issues/642) — sanctioned restart and graceful reload
|
||||||
|
- Existing restart / reconnect paths to inventory: [#591](https://gitea.prgs.cc/Scaled-Tech-Consulting/Gitea-Tools/issues/591) — auto-restart on master advance (closed); [#584](https://gitea.prgs.cc/Scaled-Tech-Consulting/Gitea-Tools/issues/584) — host auto-reconnect on transport flap
|
||||||
|
- Stable-control runtime split: `docs/architecture/mcp-stable-control-runtime-policy-adr.md` (#615)
|
||||||
|
- Client-namespace health: `docs/mcp-namespace-health.md` (#543)
|
||||||
|
- Reconnect-only EOF recovery: `docs/mcp-namespace-eof-recovery.md`
|
||||||
|
|
||||||
|
## 1. Context
|
||||||
|
|
||||||
|
The Gitea MCP server is the **control plane** for real issue and PR mutations
|
||||||
|
(create, comment, lock, review, merge, reconcile). The same process serves every
|
||||||
|
role namespace (`gitea-author`, `gitea-reviewer`, `gitea-merger`,
|
||||||
|
`gitea-reconciler`, `gitea-controller`) and holds the in-memory capability-gate
|
||||||
|
code loaded at startup.
|
||||||
|
|
||||||
|
Restarting that process is destructive to concurrent work:
|
||||||
|
|
||||||
|
- It resets every session's identity, preflight, and capability-lease binding.
|
||||||
|
- It can interrupt a mutation mid-critical-section (a lock acquire, a review
|
||||||
|
submit, a merge), leaving durable state half-written.
|
||||||
|
- Relaunching from the wrong checkout or worktree silently changes which code
|
||||||
|
the control plane runs, defeating master-parity gates (#420 / #615).
|
||||||
|
|
||||||
|
Today there is **no durable written policy** stating who may restart MCP, under
|
||||||
|
what conditions, that restart is a last resort, and how controller approval,
|
||||||
|
automated safety gates, and break-glass interact. Operators and LLM sessions
|
||||||
|
therefore invent restart behavior ad hoc, which makes concurrent multi-role work
|
||||||
|
unsafe. #630 and #642 need this policy as their backbone.
|
||||||
|
|
||||||
|
This ADR defines that policy. It does **not** implement coordinator code or HA
|
||||||
|
multi-instance restart (those are later children of #655).
|
||||||
|
|
||||||
|
## 2. Decision
|
||||||
|
|
||||||
|
### 2.1 v1 decision (recorded)
|
||||||
|
|
||||||
|
**Restart authority in v1 is `controller approval + automated safety gates`.**
|
||||||
|
|
||||||
|
A restart of the stable control runtime is authorized only when **both** hold:
|
||||||
|
|
||||||
|
1. A **controller** role explicitly approves the restart, recording an audit
|
||||||
|
entry (who, why, scope, affected sessions), **and**
|
||||||
|
2. The **automated safety gates** pass: a completed drain acknowledgement (no
|
||||||
|
affected session is mid-critical-section) or a declared break-glass incident
|
||||||
|
(§2.5).
|
||||||
|
|
||||||
|
Quorum among multiple controllers is **not** required day-one. It is deferred
|
||||||
|
unless a later investigation (tracked under #653) proves single-controller
|
||||||
|
approval is insufficient. This ADR records the v1 decision so enforcement code
|
||||||
|
(#630) has a fixed target; changing it requires a superseding ADR.
|
||||||
|
|
||||||
|
### 2.2 Restart is a last resort — the recovery ladder
|
||||||
|
|
||||||
|
Restart is the **last** rung. Before any restart, exhaust the narrower
|
||||||
|
recoveries, in order:
|
||||||
|
|
||||||
|
1. **Reconnect** the IDE/client MCP namespace (transport EOF, `client is
|
||||||
|
closing: EOF`, transient `#584` flap). No process change. See
|
||||||
|
`docs/mcp-namespace-eof-recovery.md`.
|
||||||
|
2. **Refresh / rebind** the session workspace: re-run `gitea_whoami`,
|
||||||
|
`gitea_resolve_task_capability`, and pass an explicit validated
|
||||||
|
`worktree_path`. Fixes stale session context without touching the process.
|
||||||
|
3. **Scoped restart** of a single misbehaving namespace/service (where the
|
||||||
|
deployment supports per-service restart) rather than the whole control plane.
|
||||||
|
4. **Full restart** of the stable control runtime process — operator-owned,
|
||||||
|
controller-approved, drained.
|
||||||
|
5. **Host / infrastructure restart** — the broadest action; same authorization
|
||||||
|
as a full restart plus infrastructure ownership.
|
||||||
|
|
||||||
|
A session **must** try rungs 1–2 and record why they were insufficient before
|
||||||
|
requesting a restart at rung 3 or above. Skipping straight to restart is a
|
||||||
|
policy violation.
|
||||||
|
|
||||||
|
### 2.3 Authorization matrix
|
||||||
|
|
||||||
|
| Role | Reconnect (1) | Refresh/rebind (2) | Scoped restart (3) | Full restart (4) | Host restart (5) |
|
||||||
|
|---|---|---|---|---|---|
|
||||||
|
| **author** | self | self | request only | **forbidden** | forbidden |
|
||||||
|
| **reviewer** | self | self | request only | **forbidden** | forbidden |
|
||||||
|
| **merger** | self | self | request only | **forbidden** | forbidden |
|
||||||
|
| **reconciler** | self | self | request only | **forbidden** | forbidden |
|
||||||
|
| **controller** | self | self | **approve** (+gates) | **approve** (+gates) | request to operator |
|
||||||
|
| **operator** | self | self | execute (controller-approved) | execute (controller-approved) | execute (controller-approved) |
|
||||||
|
| **admin** | self | self | execute | execute | execute (break-glass) |
|
||||||
|
|
||||||
|
Legend: *self* = may perform for its own client session; *request only* = may
|
||||||
|
raise a restart request but not authorize or execute it; *approve* = may
|
||||||
|
authorize under §2.1 gates; *execute* = may perform the process action after the
|
||||||
|
authorization is recorded.
|
||||||
|
|
||||||
|
Key invariants:
|
||||||
|
|
||||||
|
- **No LLM worker role (author/reviewer/merger/reconciler) may perform or
|
||||||
|
authorize a full or host restart.** They may only reconnect/rebind their own
|
||||||
|
client and file a restart request.
|
||||||
|
- **Controller approval authorizes; operator/admin executes.** The approving
|
||||||
|
controller and the executing operator may be the same human, but both the
|
||||||
|
approval and the execution are audited.
|
||||||
|
- Privileged process actions (full restart, host restart) are reserved to
|
||||||
|
**operator/admin**, never to an automated worker.
|
||||||
|
|
||||||
|
### 2.4 Approved conditions
|
||||||
|
|
||||||
|
A restart at rung 3+ is approved only under one of these recorded conditions:
|
||||||
|
|
||||||
|
- **No affected sessions:** the control plane has no live session that would be
|
||||||
|
interrupted (verified, not assumed).
|
||||||
|
- **Full drain acknowledged:** every affected session has drained
|
||||||
|
(no open critical section — no held mutation lease mid-write) and the drain is
|
||||||
|
acknowledged in the audit record.
|
||||||
|
- **Controller + gates:** controller approval plus passing automated safety
|
||||||
|
gates (§2.1), the standard v1 path.
|
||||||
|
- **Quorum:** not required in v1; reserved for a future superseding ADR.
|
||||||
|
- **Break-glass:** an incident-backed emergency exception (§2.5).
|
||||||
|
|
||||||
|
Restart **never** bypasses mutation gates mid-critical-section. Drain before
|
||||||
|
restart is mandatory except under break-glass with a declared incident.
|
||||||
|
|
||||||
|
### 2.5 Break-glass
|
||||||
|
|
||||||
|
Break-glass is a **separate, narrower** authorization path for emergencies where
|
||||||
|
the normal drain-and-approve path cannot complete (e.g. the control plane is
|
||||||
|
wedged and cannot drain).
|
||||||
|
|
||||||
|
Break-glass conditions:
|
||||||
|
|
||||||
|
- A declared incident record exists (id, timestamp, declarer) **before** the
|
||||||
|
action.
|
||||||
|
- The action is taken by **operator or admin** authority only — never by an LLM
|
||||||
|
worker role, and never unilaterally by an operator with active peers when a
|
||||||
|
controller is reachable.
|
||||||
|
- The scope is the minimum necessary rung of the ladder.
|
||||||
|
- A **mandatory post-hoc audit** entry is filed: what was restarted, why the
|
||||||
|
normal path was impossible, which sessions were affected, and the incident id.
|
||||||
|
|
||||||
|
Break-glass suspends the drain requirement, not the audit requirement.
|
||||||
|
|
||||||
|
### 2.6 Explicit prohibitions
|
||||||
|
|
||||||
|
- **A unilateral LLM or operator full restart while active peer sessions
|
||||||
|
exist is forbidden.** An LLM worker role must not kill, restart, or relaunch
|
||||||
|
the MCP process; a lone operator must not full-restart over live peer work
|
||||||
|
without controller approval or a break-glass incident.
|
||||||
|
- Process-kill recovery is forbidden as a routine tool (#630). This ADR does not
|
||||||
|
introduce a kill path.
|
||||||
|
- Ambiguous policy state **denies** restart (§4).
|
||||||
|
|
||||||
|
## 3. Security requirements
|
||||||
|
|
||||||
|
- Full restart and host restart are **privileged**; only operator/admin execute
|
||||||
|
them, only after a controller approval or break-glass incident is recorded.
|
||||||
|
- Break-glass is a distinct authorization path with its own audit mandate; it is
|
||||||
|
never the default and never silent.
|
||||||
|
- **Every approval and every restart action is audited** (who approved, who
|
||||||
|
executed, scope, affected sessions, condition, policy version). No restart is
|
||||||
|
authorized without a durable audit entry.
|
||||||
|
|
||||||
|
## 4. Failure behavior
|
||||||
|
|
||||||
|
**Ambiguous policy → deny restart.** If it cannot be established that a
|
||||||
|
restart is authorized under §2 — unknown affected-session state, missing
|
||||||
|
controller approval, absent break-glass incident, or an unclassifiable request —
|
||||||
|
the safe action is to **refuse** the restart and stop with a recovery report,
|
||||||
|
never to restart on assumption.
|
||||||
|
|
||||||
|
## 5. Policy IDs (for enforcement code)
|
||||||
|
|
||||||
|
Enforcement code — the restart coordinator (a later child of #655), the #630
|
||||||
|
contamination guard, and the #642 console restart UX — binds to these stable
|
||||||
|
policy identifiers rather than to prose:
|
||||||
|
|
||||||
|
| Policy ID | Statement |
|
||||||
|
|---|---|
|
||||||
|
| `RG-01` | Restart is last resort; rungs 1–2 must be tried and recorded first (§2.2). |
|
||||||
|
| `RG-02` | v1 authority = controller approval + automated safety gates (§2.1). |
|
||||||
|
| `RG-03` | No LLM worker role performs or authorizes full/host restart (§2.3). |
|
||||||
|
| `RG-04` | Full/host restart executed by operator/admin only, post approval (§2.3). |
|
||||||
|
| `RG-05` | Drain before restart is mandatory except break-glass with incident (§2.4). |
|
||||||
|
| `RG-06` | Break-glass requires a pre-declared incident and post-hoc audit (§2.5). |
|
||||||
|
| `RG-07` | Unilateral LLM/operator full restart with active peers is forbidden (§2.6). |
|
||||||
|
| `RG-08` | Ambiguous policy state denies restart (§4). |
|
||||||
|
|
||||||
|
The `restart-governance/v1` **policy version** field is emitted on future
|
||||||
|
restart audit events so approvals can be reconciled against the policy revision
|
||||||
|
in force.
|
||||||
|
|
||||||
|
## 6. Dogfooding
|
||||||
|
|
||||||
|
Gitea-Tools governs its own MCP control plane by this policy. Author, reviewer,
|
||||||
|
merger, and reconciler sessions operating on this repository use the recovery
|
||||||
|
ladder (§2.2) — reconnect and rebind, never self-restart — and any real restart
|
||||||
|
of the Gitea-Tools stable control runtime follows the controller-approval +
|
||||||
|
drain path defined here.
|
||||||
|
|
||||||
|
## 7. Acceptance and cross-links
|
||||||
|
|
||||||
|
This ADR is the authoritative restart-governance policy. It **must** stay
|
||||||
|
cross-linked from the safety model and the web-console deployment boundary:
|
||||||
|
|
||||||
|
- `docs/safety-model.md` § Process restart governance references this ADR.
|
||||||
|
- `docs/webui-deployment.md` references this ADR for restart/reload disposition.
|
||||||
|
|
||||||
|
It is linked to its issue lineage — umbrella **#655**, vision **#652**, roadmap
|
||||||
|
**#653**, contamination guard **#630**, and console restart UX **#642** — in
|
||||||
|
§ Related above.
|
||||||
|
|
||||||
|
## 8. Non-goals
|
||||||
|
|
||||||
|
- Implementing the restart coordinator or approval state machine (#630, later
|
||||||
|
children of #655).
|
||||||
|
- Implementing HA multi-instance restart or quorum machinery.
|
||||||
|
- Introducing any process-kill or auto-restart tool; existing auto-restart
|
||||||
|
behavior must be inventoried before any new restart tool is enabled.
|
||||||
@@ -46,3 +46,17 @@ If shell helpers are unavailable and MCP commit cannot run, stop with a recovery
|
|||||||
report (restart session, clear hung terminals, use MCP-native commit). See
|
report (restart session, clear hung terminals, use MCP-native commit). See
|
||||||
[`llm-workflow-runbooks.md`](llm-workflow-runbooks.md) § MCP-native commit path
|
[`llm-workflow-runbooks.md`](llm-workflow-runbooks.md) § MCP-native commit path
|
||||||
(#260) and agent temp artifact cleanup (#261).
|
(#260) and agent temp artifact cleanup (#261).
|
||||||
|
|
||||||
|
## 7. Process restart governance
|
||||||
|
|
||||||
|
Restarting the MCP control-plane process is destructive to concurrent multi-role
|
||||||
|
work and is governed by a dedicated policy. Restart is a **last resort** behind
|
||||||
|
narrower recoveries (reconnect, rebind), full/host restart is reserved to
|
||||||
|
operator/admin under **controller approval + automated safety gates**, a
|
||||||
|
unilateral LLM or operator full restart with active peers is **forbidden**, and
|
||||||
|
ambiguous policy state **denies** restart. Break-glass is a separate,
|
||||||
|
incident-backed path with a mandatory audit.
|
||||||
|
|
||||||
|
See [`architecture/mcp-restart-governance.md`](architecture/mcp-restart-governance.md)
|
||||||
|
(#656) for the authorization matrix, the recovery ladder, break-glass
|
||||||
|
conditions, and the `RG-01`–`RG-08` policy IDs.
|
||||||
|
|||||||
@@ -55,6 +55,15 @@ shipped to the browser.
|
|||||||
assumption paths, and the client-secret policy. Use it to verify an instance is
|
assumption paths, and the client-secret policy. Use it to verify an instance is
|
||||||
configured for internal-only operation.
|
configured for internal-only operation.
|
||||||
|
|
||||||
|
## Process restart / reload disposition
|
||||||
|
|
||||||
|
The console never exposes a restart or reload control; process restart of the
|
||||||
|
MCP control-plane runtime is governed separately. Restart is a last resort behind
|
||||||
|
reconnect/rebind, full restart is operator/admin-only under controller approval
|
||||||
|
plus safety gates, and break-glass is an incident-backed path. See
|
||||||
|
[`architecture/mcp-restart-governance.md`](architecture/mcp-restart-governance.md)
|
||||||
|
(#656).
|
||||||
|
|
||||||
## Non-goals (MVP)
|
## Non-goals (MVP)
|
||||||
|
|
||||||
- Full SSO or session login in the UI
|
- Full SSO or session login in the UI
|
||||||
|
|||||||
+1
-276
@@ -1450,7 +1450,7 @@ def verify_preflight_purity(
|
|||||||
dirty_files = sorted(
|
dirty_files = sorted(
|
||||||
_parse_porcelain_entries(_get_workspace_porcelain(workspace))
|
_parse_porcelain_entries(_get_workspace_porcelain(workspace))
|
||||||
)
|
)
|
||||||
if dirty_files and task != "commit_files":
|
if dirty_files:
|
||||||
raise RuntimeError(
|
raise RuntimeError(
|
||||||
nwb.format_namespace_workspace_binding_error(
|
nwb.format_namespace_workspace_binding_error(
|
||||||
role_kind=role,
|
role_kind=role,
|
||||||
@@ -2031,7 +2031,6 @@ import issue_lock_store # noqa: E402
|
|||||||
import issue_lock_adoption # noqa: E402
|
import issue_lock_adoption # noqa: E402
|
||||||
import issue_lock_recovery # noqa: E402
|
import issue_lock_recovery # noqa: E402
|
||||||
import issue_lock_renewal # noqa: E402
|
import issue_lock_renewal # noqa: E402
|
||||||
import dirty_orphan_worktree_recovery # noqa: E402 # #860 dirty orphan recovery
|
|
||||||
import stacked_pr_support # noqa: E402
|
import stacked_pr_support # noqa: E402
|
||||||
import merge_approval_gate # noqa: E402
|
import merge_approval_gate # noqa: E402
|
||||||
import review_quarantine # noqa: E402 # #695 contaminated formal-review quarantine
|
import review_quarantine # noqa: E402 # #695 contaminated formal-review quarantine
|
||||||
@@ -4343,280 +4342,6 @@ def gitea_lock_issue(
|
|||||||
return result
|
return result
|
||||||
|
|
||||||
|
|
||||||
@mcp.tool()
|
|
||||||
def gitea_recover_dirty_orphaned_issue_worktree(
|
|
||||||
issue_number: int,
|
|
||||||
branch_name: str,
|
|
||||||
source_worktree_path: str,
|
|
||||||
expected_local_head: str,
|
|
||||||
expected_remote_head: str,
|
|
||||||
expected_dirty_fingerprints: dict,
|
|
||||||
remote: str = "dadeschools",
|
|
||||||
host: str | None = None,
|
|
||||||
org: str | None = None,
|
|
||||||
repo: str | None = None,
|
|
||||||
recovery_worktree_path: str | None = None,
|
|
||||||
dry_run: bool = False,
|
|
||||||
) -> dict:
|
|
||||||
"""Recover a dirty orphaned same-claimant author issue worktree (#860).
|
|
||||||
|
|
||||||
Explicit recovery operation — does **not** silently widen ``gitea_lock_issue``.
|
|
||||||
|
|
||||||
Accepts authoritative expected pins (repository, issue, branch, source
|
|
||||||
worktree, claimant, local head, remote/PR head, dirty fingerprints) and
|
|
||||||
fails closed on any mismatch. PID-less malformed locks are never treated
|
|
||||||
as live merely because expiry is absent. The source worktree is frozen;
|
|
||||||
recovery prepares a separate worktree at the pinned remote head, re-applies
|
|
||||||
dirty bytes with path-level conflict detection, and binds a live author
|
|
||||||
session only after recovery state is consistent.
|
|
||||||
|
|
||||||
Args:
|
|
||||||
issue_number: Issue whose durable claim is being recovered.
|
|
||||||
branch_name: Locked branch ``(fix|feat|docs|chore)/issue-N-…``.
|
|
||||||
source_worktree_path: Registered dirty source worktree under branches/.
|
|
||||||
expected_local_head: Full 40-char SHA of the source worktree HEAD.
|
|
||||||
expected_remote_head: Full 40-char SHA of the remote/PR head to sync to.
|
|
||||||
expected_dirty_fingerprints: ``{relative_path: sha256}`` of dirty bytes.
|
|
||||||
remote/host/org/repo: Repository binding.
|
|
||||||
recovery_worktree_path: Optional recovery worktree path under branches/.
|
|
||||||
dry_run: Assess eligibility only; no filesystem or lock mutation.
|
|
||||||
|
|
||||||
Returns:
|
|
||||||
dict with success, outcome, conflicts, recovery_worktree_path, reasons,
|
|
||||||
evidence, and journal metadata.
|
|
||||||
"""
|
|
||||||
task = "recover_dirty_orphaned_issue_worktree"
|
|
||||||
ok, block_reasons = role_session_router.check_author_mutation_after_reviewer_stop(
|
|
||||||
task
|
|
||||||
)
|
|
||||||
if not ok:
|
|
||||||
return {
|
|
||||||
"success": False,
|
|
||||||
"performed": False,
|
|
||||||
"outcome": "REFUSED",
|
|
||||||
"reasons": block_reasons,
|
|
||||||
}
|
|
||||||
blocked = _namespace_mutation_block(task, remote=remote)
|
|
||||||
if blocked:
|
|
||||||
return blocked
|
|
||||||
blocked = _profile_permission_block(
|
|
||||||
task_capability_map.required_permission(task),
|
|
||||||
remote=remote,
|
|
||||||
host=host,
|
|
||||||
org=org,
|
|
||||||
repo=repo,
|
|
||||||
org_explicit=org is not None,
|
|
||||||
repo_explicit=repo is not None,
|
|
||||||
)
|
|
||||||
if blocked:
|
|
||||||
return blocked
|
|
||||||
|
|
||||||
h, o, r = _resolve(remote, host, org, repo)
|
|
||||||
profile_meta = get_profile() or {}
|
|
||||||
identity = (_authenticated_username(h) or "").strip()
|
|
||||||
profile = (profile_meta.get("profile_name") or "").strip()
|
|
||||||
if not identity or not profile:
|
|
||||||
return {
|
|
||||||
"success": False,
|
|
||||||
"performed": False,
|
|
||||||
"outcome": "REFUSED",
|
|
||||||
"reasons": ["could not resolve authenticated identity/profile"],
|
|
||||||
}
|
|
||||||
|
|
||||||
existing_lock = _load_existing_issue_lock(
|
|
||||||
remote=remote, org=o, repo=r, issue_number=issue_number
|
|
||||||
)
|
|
||||||
|
|
||||||
src = os.path.realpath(source_worktree_path)
|
|
||||||
git_state = issue_lock_worktree.read_worktree_git_state(src)
|
|
||||||
observed_local = (git_state.get("head_sha") or "").strip()
|
|
||||||
porcelain = git_state.get("porcelain_status") or ""
|
|
||||||
current_branch = git_state.get("current_branch")
|
|
||||||
|
|
||||||
# Observed dirty fingerprints from source worktree bytes.
|
|
||||||
observed_fps: dict[str, str] = {}
|
|
||||||
dirty_contents: dict[str, bytes] = {}
|
|
||||||
for rel in (expected_dirty_fingerprints or {}):
|
|
||||||
rel_n = str(rel).strip()
|
|
||||||
fpath = os.path.join(src, rel_n)
|
|
||||||
if not os.path.isfile(fpath):
|
|
||||||
continue
|
|
||||||
with open(fpath, "rb") as fh:
|
|
||||||
data = fh.read()
|
|
||||||
dirty_contents[rel_n] = data
|
|
||||||
observed_fps[rel_n] = dirty_orphan_worktree_recovery.sha256_bytes(data)
|
|
||||||
|
|
||||||
# Remote head observation (best-effort; pin mismatch fails closed).
|
|
||||||
observed_remote = ""
|
|
||||||
try:
|
|
||||||
probe = subprocess.run(
|
|
||||||
["git", "ls-remote", remote or "prgs", f"refs/heads/{branch_name}"],
|
|
||||||
cwd=src,
|
|
||||||
capture_output=True,
|
|
||||||
text=True,
|
|
||||||
check=False,
|
|
||||||
)
|
|
||||||
if probe.returncode == 0 and (probe.stdout or "").strip():
|
|
||||||
observed_remote = (probe.stdout or "").strip().split()[0]
|
|
||||||
except Exception:
|
|
||||||
observed_remote = ""
|
|
||||||
|
|
||||||
registered = False
|
|
||||||
try:
|
|
||||||
listing = subprocess.run(
|
|
||||||
["git", "worktree", "list", "--porcelain"],
|
|
||||||
cwd=src,
|
|
||||||
capture_output=True,
|
|
||||||
text=True,
|
|
||||||
check=False,
|
|
||||||
)
|
|
||||||
if listing.returncode == 0:
|
|
||||||
registered = src in (listing.stdout or "")
|
|
||||||
except Exception:
|
|
||||||
registered = False
|
|
||||||
|
|
||||||
project_root = _canonical_local_git_root()
|
|
||||||
canonical_root = author_mutation_worktree.resolve_canonical_repo_root(
|
|
||||||
src, project_root
|
|
||||||
)
|
|
||||||
|
|
||||||
competing_locks: list[dict] = []
|
|
||||||
try:
|
|
||||||
all_live = issue_lock_store.list_live_locks()
|
|
||||||
for l in all_live:
|
|
||||||
if l.get("issue_number") == issue_number:
|
|
||||||
wt = l.get("worktree_path")
|
|
||||||
if not wt or not issue_lock_store._same_realpath(wt, src):
|
|
||||||
competing_locks.append(l)
|
|
||||||
except Exception:
|
|
||||||
competing_locks = []
|
|
||||||
|
|
||||||
wf_active = False
|
|
||||||
wf_expired = True
|
|
||||||
try:
|
|
||||||
db, _ = _control_plane_db_or_error()
|
|
||||||
if db is not None:
|
|
||||||
active_leases_data = lease_lifecycle.list_active_leases(
|
|
||||||
db,
|
|
||||||
remote=remote if remote in REMOTES else remote,
|
|
||||||
org=o,
|
|
||||||
repo=r,
|
|
||||||
)
|
|
||||||
leases_list = active_leases_data.get("leases") or []
|
|
||||||
for l in leases_list:
|
|
||||||
if l.get("work_number") == issue_number and l.get("work_kind") == "issue":
|
|
||||||
fresh = l.get("freshness") or {}
|
|
||||||
if fresh.get("status") == "active":
|
|
||||||
wf_active = True
|
|
||||||
wf_expired = False
|
|
||||||
elif fresh.get("status") in ("expired", "stale_dead_process"):
|
|
||||||
wf_active = False
|
|
||||||
wf_expired = True
|
|
||||||
except Exception:
|
|
||||||
pass
|
|
||||||
|
|
||||||
assessment = dirty_orphan_worktree_recovery.assess_dirty_orphan_recovery(
|
|
||||||
existing_lock,
|
|
||||||
issue_number=issue_number,
|
|
||||||
branch_name=branch_name,
|
|
||||||
source_worktree_path=src,
|
|
||||||
remote=remote if remote else "prgs",
|
|
||||||
org=o,
|
|
||||||
repo=r,
|
|
||||||
identity=identity,
|
|
||||||
profile=profile,
|
|
||||||
expected_local_head=expected_local_head,
|
|
||||||
expected_remote_head=expected_remote_head,
|
|
||||||
expected_dirty_fingerprints=expected_dirty_fingerprints or {},
|
|
||||||
current_branch=current_branch,
|
|
||||||
porcelain_status=porcelain,
|
|
||||||
observed_local_head=observed_local,
|
|
||||||
observed_remote_head=observed_remote,
|
|
||||||
observed_dirty_fingerprints=observed_fps,
|
|
||||||
competing_live_locks=competing_locks,
|
|
||||||
competing_live_sessions=[],
|
|
||||||
workflow_lease_active=wf_active,
|
|
||||||
workflow_lease_expired=wf_expired,
|
|
||||||
canonical_repo_root=canonical_root,
|
|
||||||
worktree_registered=registered,
|
|
||||||
current_pid=os.getpid(),
|
|
||||||
)
|
|
||||||
if dry_run or not assessment.get("eligible"):
|
|
||||||
return {
|
|
||||||
"success": bool(assessment.get("eligible")),
|
|
||||||
"performed": False,
|
|
||||||
"dry_run": dry_run,
|
|
||||||
"outcome": assessment.get("outcome"),
|
|
||||||
"reasons": list(assessment.get("reasons") or []),
|
|
||||||
"evidence": dict(assessment.get("evidence") or {}),
|
|
||||||
"eligible": bool(assessment.get("eligible")),
|
|
||||||
}
|
|
||||||
|
|
||||||
if not recovery_worktree_path:
|
|
||||||
recovery_worktree_path = os.path.join(
|
|
||||||
canonical_root,
|
|
||||||
"branches",
|
|
||||||
f"recovery-issue-{issue_number}-dirty-orphan",
|
|
||||||
)
|
|
||||||
|
|
||||||
# Load blob contents at local/remote heads for conflict detection.
|
|
||||||
def _blob_at(head: str, rel: str) -> bytes | None:
|
|
||||||
try:
|
|
||||||
proc = subprocess.run(
|
|
||||||
["git", "show", f"{head}:{rel}"],
|
|
||||||
cwd=src,
|
|
||||||
capture_output=True,
|
|
||||||
check=False,
|
|
||||||
)
|
|
||||||
if proc.returncode != 0:
|
|
||||||
return None
|
|
||||||
return proc.stdout
|
|
||||||
except Exception:
|
|
||||||
return None
|
|
||||||
|
|
||||||
local_contents = {
|
|
||||||
rel: _blob_at(expected_local_head, rel)
|
|
||||||
for rel in (expected_dirty_fingerprints or {})
|
|
||||||
}
|
|
||||||
remote_contents = {
|
|
||||||
rel: _blob_at(expected_remote_head, rel)
|
|
||||||
for rel in (expected_dirty_fingerprints or {})
|
|
||||||
}
|
|
||||||
|
|
||||||
# Preflight purity is satisfied via explicit worktree_path on this tool's
|
|
||||||
# recovery path; source remains frozen and is never cleaned.
|
|
||||||
result = dirty_orphan_worktree_recovery.run_dirty_orphan_recovery(
|
|
||||||
assessment=assessment,
|
|
||||||
existing_lock=existing_lock or {},
|
|
||||||
issue_number=issue_number,
|
|
||||||
branch_name=branch_name,
|
|
||||||
source_worktree_path=src,
|
|
||||||
recovery_worktree_path=recovery_worktree_path,
|
|
||||||
remote=remote if remote else "prgs",
|
|
||||||
org=o,
|
|
||||||
repo=r,
|
|
||||||
identity=identity,
|
|
||||||
profile=profile,
|
|
||||||
expected_local_head=expected_local_head,
|
|
||||||
expected_remote_head=expected_remote_head,
|
|
||||||
expected_dirty_fingerprints=expected_dirty_fingerprints or {},
|
|
||||||
dirty_contents=dirty_contents,
|
|
||||||
local_head_contents=local_contents,
|
|
||||||
remote_head_contents=remote_contents,
|
|
||||||
canonical_repo_root=canonical_root,
|
|
||||||
bind_lock=True,
|
|
||||||
session_pid=os.getpid(),
|
|
||||||
)
|
|
||||||
# Surface preflight recognition for recovered provenance.
|
|
||||||
if result.get("success") and result.get("lock_record"):
|
|
||||||
result["preflight_provenance"] = (
|
|
||||||
dirty_orphan_worktree_recovery.preflight_recognizes_recovered_provenance(
|
|
||||||
result["lock_record"]
|
|
||||||
)
|
|
||||||
)
|
|
||||||
return result
|
|
||||||
|
|
||||||
|
|
||||||
@mcp.tool()
|
@mcp.tool()
|
||||||
def gitea_assess_work_issue_duplicate(
|
def gitea_assess_work_issue_duplicate(
|
||||||
issue_number: int,
|
issue_number: int,
|
||||||
|
|||||||
@@ -16,13 +16,11 @@ ISSUE_LOCK_FILE = os.environ.get("GITEA_ISSUE_LOCK_FILE", "/tmp/gitea_issue_lock
|
|||||||
SOURCE_LOCK_ISSUE = "gitea_lock_issue"
|
SOURCE_LOCK_ISSUE = "gitea_lock_issue"
|
||||||
SOURCE_LOCK_ADOPTION = "gitea_lock_issue_adoption"
|
SOURCE_LOCK_ADOPTION = "gitea_lock_issue_adoption"
|
||||||
SOURCE_OPERATOR_OVERRIDE = "operator_override"
|
SOURCE_OPERATOR_OVERRIDE = "operator_override"
|
||||||
SOURCE_RECOVER_DIRTY_ORPHANED = "gitea_recover_dirty_orphaned_issue_worktree"
|
|
||||||
|
|
||||||
SANCTIONED_LOCK_SOURCES = frozenset({
|
SANCTIONED_LOCK_SOURCES = frozenset({
|
||||||
SOURCE_LOCK_ISSUE,
|
SOURCE_LOCK_ISSUE,
|
||||||
SOURCE_LOCK_ADOPTION,
|
SOURCE_LOCK_ADOPTION,
|
||||||
SOURCE_OPERATOR_OVERRIDE,
|
SOURCE_OPERATOR_OVERRIDE,
|
||||||
SOURCE_RECOVER_DIRTY_ORPHANED,
|
|
||||||
})
|
})
|
||||||
|
|
||||||
_OPERATOR_OVERRIDE_ENV = "GITEA_ISSUE_LOCK_OPERATOR_OVERRIDE"
|
_OPERATOR_OVERRIDE_ENV = "GITEA_ISSUE_LOCK_OPERATOR_OVERRIDE"
|
||||||
|
|||||||
+4
-81
@@ -169,7 +169,6 @@ def bind_session_lock(
|
|||||||
*,
|
*,
|
||||||
expected_generation: int | None = None,
|
expected_generation: int | None = None,
|
||||||
renewal_sanctioned: bool = False,
|
renewal_sanctioned: bool = False,
|
||||||
recovery_sanctioned: bool = False,
|
|
||||||
) -> str:
|
) -> str:
|
||||||
"""Persist a keyed lock and bind it to the current process session.
|
"""Persist a keyed lock and bind it to the current process session.
|
||||||
|
|
||||||
@@ -214,9 +213,7 @@ def bind_session_lock(
|
|||||||
try:
|
try:
|
||||||
with _exclusive_file_lock(sentinel):
|
with _exclusive_file_lock(sentinel):
|
||||||
existing = read_lock_file(path)
|
existing = read_lock_file(path)
|
||||||
overwrite_block = assess_foreign_lock_overwrite(
|
overwrite_block = assess_foreign_lock_overwrite(existing, record)
|
||||||
existing, record, recovery_sanctioned=recovery_sanctioned
|
|
||||||
)
|
|
||||||
if overwrite_block:
|
if overwrite_block:
|
||||||
raise RuntimeError(overwrite_block)
|
raise RuntimeError(overwrite_block)
|
||||||
lease_block = assess_same_issue_lease_conflict(
|
lease_block = assess_same_issue_lease_conflict(
|
||||||
@@ -225,7 +222,6 @@ def bind_session_lock(
|
|||||||
branch_name=str(record.get("branch_name") or ""),
|
branch_name=str(record.get("branch_name") or ""),
|
||||||
worktree_path=str(record.get("worktree_path") or ""),
|
worktree_path=str(record.get("worktree_path") or ""),
|
||||||
renewal_sanctioned=renewal_sanctioned,
|
renewal_sanctioned=renewal_sanctioned,
|
||||||
recovery_sanctioned=recovery_sanctioned,
|
|
||||||
)
|
)
|
||||||
if lease_block:
|
if lease_block:
|
||||||
raise RuntimeError(lease_block)
|
raise RuntimeError(lease_block)
|
||||||
@@ -384,16 +380,7 @@ def assess_lock_freshness(
|
|||||||
pid = lock_data.get("session_pid")
|
pid = lock_data.get("session_pid")
|
||||||
if pid is None:
|
if pid is None:
|
||||||
pid = lock_data.get("pid")
|
pid = lock_data.get("pid")
|
||||||
pid_missing = pid is None or str(pid).strip() == ""
|
pid_alive = is_process_alive(pid) if pid is not None else False
|
||||||
try:
|
|
||||||
pid_int = int(pid) if not pid_missing else None
|
|
||||||
if pid_int is not None and pid_int <= 0:
|
|
||||||
pid_missing = True
|
|
||||||
pid_int = None
|
|
||||||
except (TypeError, ValueError):
|
|
||||||
pid_missing = True
|
|
||||||
pid_int = None
|
|
||||||
pid_alive = is_process_alive(pid_int) if pid_int is not None else False
|
|
||||||
|
|
||||||
if expires_at and expires_at <= current:
|
if expires_at and expires_at <= current:
|
||||||
return {
|
return {
|
||||||
@@ -402,36 +389,15 @@ def assess_lock_freshness(
|
|||||||
"stale": True,
|
"stale": True,
|
||||||
"reason": f"lease expired at {expires_at.isoformat()}",
|
"reason": f"lease expired at {expires_at.isoformat()}",
|
||||||
"pid_alive": pid_alive,
|
"pid_alive": pid_alive,
|
||||||
"pid_missing": pid_missing,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
# #860: a PID-less lock must never be considered live merely because
|
if pid is not None and not pid_alive:
|
||||||
# expiration / heartbeat fields are absent. Missing PID is insufficient
|
|
||||||
# evidence of a live owner; treat as malformed/stale so recovery routes
|
|
||||||
# can evaluate corroborating pins instead of blocking on a false live flag.
|
|
||||||
if pid_missing:
|
|
||||||
return {
|
|
||||||
"status": "malformed",
|
|
||||||
"live": False,
|
|
||||||
"stale": True,
|
|
||||||
"reason": (
|
|
||||||
"lock has no usable session pid; cannot prove live ownership "
|
|
||||||
"(PID-less locks are never live by missing expiry alone)"
|
|
||||||
),
|
|
||||||
"pid_alive": False,
|
|
||||||
"pid_missing": True,
|
|
||||||
"heartbeat_at": heartbeat_at.isoformat() if heartbeat_at else None,
|
|
||||||
"expires_at": expires_at.isoformat() if expires_at else None,
|
|
||||||
}
|
|
||||||
|
|
||||||
if pid_int is not None and not pid_alive:
|
|
||||||
return {
|
return {
|
||||||
"status": "stale",
|
"status": "stale",
|
||||||
"live": False,
|
"live": False,
|
||||||
"stale": True,
|
"stale": True,
|
||||||
"reason": f"owner pid {pid_int} is not alive",
|
"reason": f"owner pid {pid} is not alive",
|
||||||
"pid_alive": False,
|
"pid_alive": False,
|
||||||
"pid_missing": False,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
@@ -440,7 +406,6 @@ def assess_lock_freshness(
|
|||||||
"stale": False,
|
"stale": False,
|
||||||
"reason": "lock heartbeat and lease are fresh",
|
"reason": "lock heartbeat and lease are fresh",
|
||||||
"pid_alive": pid_alive,
|
"pid_alive": pid_alive,
|
||||||
"pid_missing": False,
|
|
||||||
"heartbeat_at": heartbeat_at.isoformat() if heartbeat_at else None,
|
"heartbeat_at": heartbeat_at.isoformat() if heartbeat_at else None,
|
||||||
"expires_at": expires_at.isoformat() if expires_at else None,
|
"expires_at": expires_at.isoformat() if expires_at else None,
|
||||||
}
|
}
|
||||||
@@ -521,7 +486,6 @@ def assess_same_issue_lease_conflict(
|
|||||||
worktree_path: str,
|
worktree_path: str,
|
||||||
operation_type: str = AUTHOR_ISSUE_WORK_LEASE,
|
operation_type: str = AUTHOR_ISSUE_WORK_LEASE,
|
||||||
renewal_sanctioned: bool = False,
|
renewal_sanctioned: bool = False,
|
||||||
recovery_sanctioned: bool = False,
|
|
||||||
now: datetime | None = None,
|
now: datetime | None = None,
|
||||||
) -> str | None:
|
) -> str | None:
|
||||||
"""Return a fail-closed error when a competing live lease blocks acquisition.
|
"""Return a fail-closed error when a competing live lease blocks acquisition.
|
||||||
@@ -553,8 +517,6 @@ def assess_same_issue_lease_conflict(
|
|||||||
existing_branch == branch_name
|
existing_branch == branch_name
|
||||||
and _same_realpath(str(existing_worktree or ""), worktree_path)
|
and _same_realpath(str(existing_worktree or ""), worktree_path)
|
||||||
)
|
)
|
||||||
if recovery_sanctioned and existing_issue == issue_number and existing_branch == branch_name:
|
|
||||||
return None
|
|
||||||
if is_lease_expired(existing_lock, now=now):
|
if is_lease_expired(existing_lock, now=now):
|
||||||
# #760 AC1/AC2: exact-owner renewal is a different disposition from
|
# #760 AC1/AC2: exact-owner renewal is a different disposition from
|
||||||
# foreign takeover and is evaluated first. Before this, both branches
|
# foreign takeover and is evaluated first. Before this, both branches
|
||||||
@@ -585,26 +547,10 @@ def assess_same_issue_lease_conflict(
|
|||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
def _lock_claimant(lock: dict[str, Any] | None) -> dict[str, str]:
|
|
||||||
if not isinstance(lock, dict):
|
|
||||||
return {}
|
|
||||||
claimant = lock.get("claimant")
|
|
||||||
if not isinstance(claimant, dict):
|
|
||||||
lease = lock.get("work_lease")
|
|
||||||
claimant = lease.get("claimant") if isinstance(lease, dict) else None
|
|
||||||
if not isinstance(claimant, dict):
|
|
||||||
return {}
|
|
||||||
return {
|
|
||||||
"username": str(claimant.get("username") or ""),
|
|
||||||
"profile": str(claimant.get("profile") or ""),
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
def assess_foreign_lock_overwrite(
|
def assess_foreign_lock_overwrite(
|
||||||
existing_lock: dict[str, Any] | None,
|
existing_lock: dict[str, Any] | None,
|
||||||
incoming_lock: dict[str, Any],
|
incoming_lock: dict[str, Any],
|
||||||
*,
|
*,
|
||||||
recovery_sanctioned: bool = False,
|
|
||||||
now: datetime | None = None,
|
now: datetime | None = None,
|
||||||
) -> str | None:
|
) -> str | None:
|
||||||
"""Block writes that would clobber an unrelated live lease on the same key."""
|
"""Block writes that would clobber an unrelated live lease on the same key."""
|
||||||
@@ -619,31 +565,8 @@ def assess_foreign_lock_overwrite(
|
|||||||
)
|
)
|
||||||
if same_issue and same_branch and same_worktree:
|
if same_issue and same_branch and same_worktree:
|
||||||
return None
|
return None
|
||||||
|
|
||||||
existing_claimant = _lock_claimant(existing_lock)
|
|
||||||
incoming_claimant = _lock_claimant(incoming_lock)
|
|
||||||
same_claimant = (
|
|
||||||
bool(existing_claimant.get("username"))
|
|
||||||
and existing_claimant.get("username") == incoming_claimant.get("username")
|
|
||||||
and existing_claimant.get("profile") == incoming_claimant.get("profile")
|
|
||||||
)
|
|
||||||
|
|
||||||
if recovery_sanctioned and same_issue and same_branch and same_claimant:
|
|
||||||
return None
|
|
||||||
|
|
||||||
if not is_lease_live(existing_lock, now=now):
|
if not is_lease_live(existing_lock, now=now):
|
||||||
# #860 F8: A non-live or PID-less lock still blocks foreign overwrite
|
|
||||||
# unless same claimant or sanctioned reclaim is proven.
|
|
||||||
if not same_claimant and same_issue:
|
|
||||||
reclaim = assess_expired_lock_reclaim(existing_lock, now=now)
|
|
||||||
if not reclaim.get("reclaim_allowed"):
|
|
||||||
return (
|
|
||||||
"Refusing foreign overwrite of non-live issue lock "
|
|
||||||
f"(issue #{existing_lock.get('issue_number')}, owner '{existing_claimant.get('username')}') "
|
|
||||||
"without sanctioned reclaim proof (fail closed)"
|
|
||||||
)
|
|
||||||
return None
|
return None
|
||||||
|
|
||||||
return (
|
return (
|
||||||
"Refusing to overwrite a live foreign issue lock "
|
"Refusing to overwrite a live foreign issue lock "
|
||||||
f"(issue #{existing_lock.get('issue_number')}, "
|
f"(issue #{existing_lock.get('issue_number')}, "
|
||||||
|
|||||||
+8
-10
@@ -43,21 +43,19 @@ repo_root="$(cd "$script_dir/.." && pwd)"
|
|||||||
|
|
||||||
# Enforce issue-linked, traceable branch names (issue → branch → worktree → PR).
|
# Enforce issue-linked, traceable branch names (issue → branch → worktree → PR).
|
||||||
if [[ "$allow_unlinked" -eq 0 ]]; then
|
if [[ "$allow_unlinked" -eq 0 ]]; then
|
||||||
if [[ "$dry_run" -eq 0 ]] && [[ ! "$branch" =~ ^review/pr-[0-9]+-.+ ]]; then
|
locked_branch=$(python3 -c "
|
||||||
locked_branch=$(python3 -c "
|
|
||||||
import sys
|
import sys
|
||||||
sys.path.insert(0, '$repo_root')
|
sys.path.insert(0, '$repo_root')
|
||||||
import issue_lock_store
|
import issue_lock_store
|
||||||
print(issue_lock_store.resolve_locked_branch_for_session('$branch'))
|
print(issue_lock_store.resolve_locked_branch_for_session('$branch'))
|
||||||
")
|
")
|
||||||
if [[ -z "$locked_branch" ]]; then
|
if [[ -z "$locked_branch" ]]; then
|
||||||
echo "Error: No session issue lock is bound. Call gitea_lock_issue before branch creation (fail closed)." >&2
|
echo "Error: No session issue lock is bound. Call gitea_lock_issue before branch creation (fail closed)." >&2
|
||||||
exit 2
|
exit 2
|
||||||
fi
|
fi
|
||||||
if [[ "$branch" != "$locked_branch" ]]; then
|
if [[ "$branch" != "$locked_branch" ]]; then
|
||||||
echo "Error: Requested branch '$branch' does not match locked branch '$locked_branch' (fail closed)." >&2
|
echo "Error: Requested branch '$branch' does not match locked branch '$locked_branch' (fail closed)." >&2
|
||||||
exit 2
|
exit 2
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ "$branch" =~ ^(fix|feat|docs|chore)/issue-[0-9]+-.+ ]] \
|
if [[ "$branch" =~ ^(fix|feat|docs|chore)/issue-[0-9]+-.+ ]] \
|
||||||
|
|||||||
@@ -32,15 +32,6 @@ TASK_CAPABILITY_MAP: dict[str, dict[str, str]] = {
|
|||||||
"permission": "gitea.issue.comment",
|
"permission": "gitea.issue.comment",
|
||||||
"role": "author",
|
"role": "author",
|
||||||
},
|
},
|
||||||
# #860: dirty orphaned same-claimant worktree recovery (explicit operation).
|
|
||||||
"recover_dirty_orphaned_issue_worktree": {
|
|
||||||
"permission": "gitea.issue.comment",
|
|
||||||
"role": "author",
|
|
||||||
},
|
|
||||||
"gitea_recover_dirty_orphaned_issue_worktree": {
|
|
||||||
"permission": "gitea.issue.comment",
|
|
||||||
"role": "author",
|
|
||||||
},
|
|
||||||
"set_issue_labels": {
|
"set_issue_labels": {
|
||||||
"permission": "gitea.issue.comment",
|
"permission": "gitea.issue.comment",
|
||||||
"role": "author",
|
"role": "author",
|
||||||
@@ -486,11 +477,6 @@ TASK_CAPABILITY_MAP: dict[str, dict[str, str]] = {
|
|||||||
# merger lease (#763).
|
# merger lease (#763).
|
||||||
_PREFLIGHT_TASK_TRANSITIONS = frozenset({
|
_PREFLIGHT_TASK_TRANSITIONS = frozenset({
|
||||||
("review_pr", "acquire_reviewer_pr_lease"),
|
("review_pr", "acquire_reviewer_pr_lease"),
|
||||||
("work_issue", "lock_issue"),
|
|
||||||
("work_issue", "recover_dirty_orphaned_issue_worktree"),
|
|
||||||
("work_issue", "gitea_recover_dirty_orphaned_issue_worktree"),
|
|
||||||
("work_issue", "commit_files"),
|
|
||||||
("work_issue", "gitea_commit_files"),
|
|
||||||
})
|
})
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -1,483 +0,0 @@
|
|||||||
"""Synthetic regression coverage for dirty orphaned worktree recovery (#860).
|
|
||||||
|
|
||||||
Modeled on the #850 / #855 shape without mutating their real state.
|
|
||||||
"""
|
|
||||||
|
|
||||||
from __future__ import annotations
|
|
||||||
|
|
||||||
import json
|
|
||||||
import os
|
|
||||||
import shutil
|
|
||||||
import tempfile
|
|
||||||
import unittest
|
|
||||||
from unittest import mock
|
|
||||||
|
|
||||||
import dirty_orphan_worktree_recovery as dorec
|
|
||||||
import issue_lock_store
|
|
||||||
|
|
||||||
|
|
||||||
DEAD_PID = 999_999_999
|
|
||||||
LIVE_PID = os.getpid()
|
|
||||||
BRANCH = "fix/issue-901-dirty-orphan"
|
|
||||||
SOURCE_WT = "/repo/branches/issue-901-dirty-orphan"
|
|
||||||
RECOVERY_WT_NAME = "recovery-issue-901-dirty-orphan"
|
|
||||||
LOCAL_HEAD = "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
|
|
||||||
REMOTE_HEAD = "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
|
|
||||||
OTHER_HEAD = "cccccccccccccccccccccccccccccccccccccccc"
|
|
||||||
FP_A = dorec.sha256_bytes(b"dirty-a")
|
|
||||||
FP_B = dorec.sha256_bytes(b"dirty-b")
|
|
||||||
FP_C = dorec.sha256_bytes(b"dirty-c-conflict")
|
|
||||||
|
|
||||||
|
|
||||||
def durable_lock(**overrides):
|
|
||||||
"""#850-shaped PID-less malformed same-claimant lock."""
|
|
||||||
lock = {
|
|
||||||
"issue_number": 901,
|
|
||||||
"branch_name": BRANCH,
|
|
||||||
"worktree_path": SOURCE_WT,
|
|
||||||
"remote": "prgs",
|
|
||||||
"org": "Example-Org",
|
|
||||||
"repo": "Example-Repo",
|
|
||||||
# intentionally no pid / session_pid / work_lease expiry
|
|
||||||
"claimant": {"username": "author-user", "profile": "prgs-author"},
|
|
||||||
}
|
|
||||||
lock.update(overrides)
|
|
||||||
return lock
|
|
||||||
|
|
||||||
|
|
||||||
def base_kwargs(**overrides):
|
|
||||||
kwargs = {
|
|
||||||
"issue_number": 901,
|
|
||||||
"branch_name": BRANCH,
|
|
||||||
"source_worktree_path": SOURCE_WT,
|
|
||||||
"remote": "prgs",
|
|
||||||
"org": "Example-Org",
|
|
||||||
"repo": "Example-Repo",
|
|
||||||
"identity": "author-user",
|
|
||||||
"profile": "prgs-author",
|
|
||||||
"expected_local_head": LOCAL_HEAD,
|
|
||||||
"expected_remote_head": REMOTE_HEAD,
|
|
||||||
"expected_dirty_fingerprints": {"a.py": FP_A, "b.py": FP_B},
|
|
||||||
"current_branch": BRANCH,
|
|
||||||
"porcelain_status": " M a.py\n M b.py\n",
|
|
||||||
"observed_local_head": LOCAL_HEAD,
|
|
||||||
"observed_remote_head": REMOTE_HEAD,
|
|
||||||
"observed_dirty_fingerprints": {"a.py": FP_A, "b.py": FP_B},
|
|
||||||
"competing_live_locks": [],
|
|
||||||
"competing_live_sessions": [],
|
|
||||||
"workflow_lease_active": False,
|
|
||||||
"workflow_lease_expired": True,
|
|
||||||
"canonical_repo_root": "/repo",
|
|
||||||
"worktree_registered": True,
|
|
||||||
"current_pid": LIVE_PID,
|
|
||||||
}
|
|
||||||
kwargs.update(overrides)
|
|
||||||
return kwargs
|
|
||||||
|
|
||||||
|
|
||||||
def assess(lock=None, **overrides):
|
|
||||||
return dorec.assess_dirty_orphan_recovery(
|
|
||||||
durable_lock() if lock is None else lock, **base_kwargs(**overrides)
|
|
||||||
)
|
|
||||||
|
|
||||||
|
|
||||||
class FreshnessPidLess(unittest.TestCase):
|
|
||||||
def test_pid_less_lock_is_not_live(self):
|
|
||||||
freshness = issue_lock_store.assess_lock_freshness(durable_lock())
|
|
||||||
self.assertFalse(freshness["live"])
|
|
||||||
self.assertTrue(freshness.get("pid_missing"))
|
|
||||||
self.assertEqual(freshness["status"], "malformed")
|
|
||||||
|
|
||||||
def test_pid_less_with_far_future_expiry_still_not_live(self):
|
|
||||||
lock = durable_lock(
|
|
||||||
work_lease={
|
|
||||||
"operation_type": "author_issue_work",
|
|
||||||
"expires_at": "2999-01-01T00:00:00Z",
|
|
||||||
"last_heartbeat_at": "2999-01-01T00:00:00Z",
|
|
||||||
}
|
|
||||||
)
|
|
||||||
freshness = issue_lock_store.assess_lock_freshness(lock)
|
|
||||||
self.assertFalse(freshness["live"])
|
|
||||||
self.assertTrue(freshness.get("pid_missing"))
|
|
||||||
|
|
||||||
|
|
||||||
class EligibilityGranted(unittest.TestCase):
|
|
||||||
def test_dead_same_claimant_pid_less_dirty(self):
|
|
||||||
result = assess()
|
|
||||||
self.assertEqual(result["outcome"], dorec.ELIGIBLE)
|
|
||||||
self.assertTrue(result["eligible"])
|
|
||||||
|
|
||||||
def test_expired_workflow_lease_corroboration(self):
|
|
||||||
result = assess(workflow_lease_active=False, workflow_lease_expired=True)
|
|
||||||
self.assertTrue(result["eligible"])
|
|
||||||
|
|
||||||
def test_older_local_newer_remote_heads(self):
|
|
||||||
result = assess()
|
|
||||||
self.assertTrue(result["evidence"].get("heads_diverged"))
|
|
||||||
self.assertTrue(result["eligible"])
|
|
||||||
|
|
||||||
|
|
||||||
class EligibilityRefused(unittest.TestCase):
|
|
||||||
def test_active_owner_with_pid(self):
|
|
||||||
lock = durable_lock(pid=LIVE_PID, session_pid=LIVE_PID)
|
|
||||||
result = assess(lock=lock, owner_process_alive_override=True)
|
|
||||||
self.assertEqual(result["outcome"], dorec.REFUSED)
|
|
||||||
self.assertFalse(result["eligible"])
|
|
||||||
self.assertTrue(any("alive" in r for r in result["reasons"]))
|
|
||||||
|
|
||||||
def test_foreign_claimant(self):
|
|
||||||
result = assess(identity="other-user")
|
|
||||||
self.assertEqual(result["outcome"], dorec.REFUSED)
|
|
||||||
self.assertTrue(any("foreign claimant identity" in r for r in result["reasons"]))
|
|
||||||
|
|
||||||
def test_foreign_profile(self):
|
|
||||||
result = assess(profile="prgs-reviewer")
|
|
||||||
self.assertEqual(result["outcome"], dorec.REFUSED)
|
|
||||||
|
|
||||||
def test_fingerprint_mismatch(self):
|
|
||||||
result = assess(observed_dirty_fingerprints={"a.py": "0" * 64, "b.py": FP_B})
|
|
||||||
self.assertEqual(result["outcome"], dorec.REFUSED)
|
|
||||||
self.assertTrue(any("fingerprint mismatch" in r for r in result["reasons"]))
|
|
||||||
|
|
||||||
def test_head_mismatch(self):
|
|
||||||
result = assess(observed_local_head=OTHER_HEAD)
|
|
||||||
self.assertEqual(result["outcome"], dorec.REFUSED)
|
|
||||||
|
|
||||||
def test_remote_head_mismatch(self):
|
|
||||||
result = assess(observed_remote_head=OTHER_HEAD)
|
|
||||||
self.assertEqual(result["outcome"], dorec.REFUSED)
|
|
||||||
|
|
||||||
def test_path_not_under_branches(self):
|
|
||||||
result = assess(
|
|
||||||
source_worktree_path="/tmp/branches/evil",
|
|
||||||
# lock path also changed so worktree agreement holds
|
|
||||||
lock=durable_lock(worktree_path="/tmp/branches/evil"),
|
|
||||||
)
|
|
||||||
self.assertEqual(result["outcome"], dorec.REFUSED)
|
|
||||||
self.assertTrue(any("canonical branches" in r for r in result["reasons"]))
|
|
||||||
|
|
||||||
def test_unregistered_worktree(self):
|
|
||||||
result = assess(worktree_registered=False)
|
|
||||||
self.assertEqual(result["outcome"], dorec.REFUSED)
|
|
||||||
|
|
||||||
def test_active_workflow_lease(self):
|
|
||||||
result = assess(workflow_lease_active=True, workflow_lease_expired=False)
|
|
||||||
self.assertEqual(result["outcome"], dorec.REFUSED)
|
|
||||||
|
|
||||||
def test_unsafe_dirty_path_pin(self):
|
|
||||||
result = assess(
|
|
||||||
expected_dirty_fingerprints={"../etc/passwd": FP_A},
|
|
||||||
observed_dirty_fingerprints={"../etc/passwd": FP_A},
|
|
||||||
)
|
|
||||||
self.assertEqual(result["outcome"], dorec.REFUSED)
|
|
||||||
|
|
||||||
def test_symlink_escape_rejected_by_ancestry(self):
|
|
||||||
ok, reasons = dorec.is_path_under_canonical_branches(
|
|
||||||
"/tmp/branches/evil", canonical_repo_root="/repo"
|
|
||||||
)
|
|
||||||
self.assertFalse(ok)
|
|
||||||
self.assertTrue(reasons)
|
|
||||||
|
|
||||||
|
|
||||||
class ConflictDetection(unittest.TestCase):
|
|
||||||
def test_overlapping_upstream_change(self):
|
|
||||||
conflicts = dorec.detect_path_conflicts(
|
|
||||||
dirty_paths=["c.py"],
|
|
||||||
local_head_contents={"c.py": b"local-base"},
|
|
||||||
remote_head_contents={"c.py": b"remote-changed"},
|
|
||||||
dirty_contents={"c.py": b"dirty-c-conflict"},
|
|
||||||
)
|
|
||||||
self.assertEqual(len(conflicts), 1)
|
|
||||||
self.assertEqual(conflicts[0]["path"], "c.py")
|
|
||||||
|
|
||||||
def test_unchanged_upstream_no_conflict(self):
|
|
||||||
conflicts = dorec.detect_path_conflicts(
|
|
||||||
dirty_paths=["a.py"],
|
|
||||||
local_head_contents={"a.py": b"same"},
|
|
||||||
remote_head_contents={"a.py": b"same"},
|
|
||||||
dirty_contents={"a.py": b"dirty-a"},
|
|
||||||
)
|
|
||||||
self.assertEqual(conflicts, [])
|
|
||||||
|
|
||||||
|
|
||||||
class CrashSafeRecovery(unittest.TestCase):
|
|
||||||
def setUp(self):
|
|
||||||
self.tmp = tempfile.mkdtemp(prefix="dirty-orphan-")
|
|
||||||
self.repo = os.path.join(self.tmp, "repo")
|
|
||||||
self.branches = os.path.join(self.repo, "branches")
|
|
||||||
self.source = os.path.join(self.branches, "issue-901-dirty-orphan")
|
|
||||||
self.recovery = os.path.join(self.branches, RECOVERY_WT_NAME)
|
|
||||||
os.makedirs(self.source, exist_ok=True)
|
|
||||||
os.makedirs(self.branches, exist_ok=True)
|
|
||||||
# seed dirty files in source
|
|
||||||
with open(os.path.join(self.source, "a.py"), "wb") as fh:
|
|
||||||
fh.write(b"dirty-a")
|
|
||||||
with open(os.path.join(self.source, "b.py"), "wb") as fh:
|
|
||||||
fh.write(b"dirty-b")
|
|
||||||
self.journal_dir = os.path.join(self.tmp, "journals")
|
|
||||||
self.lock = durable_lock(worktree_path=self.source)
|
|
||||||
self.assessment = dorec.assess_dirty_orphan_recovery(
|
|
||||||
self.lock,
|
|
||||||
**base_kwargs(
|
|
||||||
source_worktree_path=self.source,
|
|
||||||
canonical_repo_root=self.repo,
|
|
||||||
),
|
|
||||||
)
|
|
||||||
|
|
||||||
class FakeGit(dorec.GitOps):
|
|
||||||
def __init__(self, recovery_path, head):
|
|
||||||
self.recovery_path = recovery_path
|
|
||||||
self.head = head
|
|
||||||
self.calls = []
|
|
||||||
|
|
||||||
def run(self, args, *, cwd):
|
|
||||||
self.calls.append((args, cwd))
|
|
||||||
if args[:3] == ["git", "worktree", "add"]:
|
|
||||||
os.makedirs(self.recovery_path, exist_ok=True)
|
|
||||||
return mock.Mock(returncode=0, stdout="", stderr="")
|
|
||||||
if args[:2] == ["git", "checkout"]:
|
|
||||||
return mock.Mock(returncode=0, stdout="", stderr="")
|
|
||||||
if args[:2] == ["git", "rev-parse"]:
|
|
||||||
return mock.Mock(returncode=0, stdout=self.head + "\n", stderr="")
|
|
||||||
return mock.Mock(returncode=0, stdout="", stderr="")
|
|
||||||
|
|
||||||
self.git = FakeGit(self.recovery, REMOTE_HEAD)
|
|
||||||
self.written_locks = []
|
|
||||||
|
|
||||||
def lock_writer(record):
|
|
||||||
self.written_locks.append(record)
|
|
||||||
|
|
||||||
self.lock_writer = lock_writer
|
|
||||||
|
|
||||||
def tearDown(self):
|
|
||||||
shutil.rmtree(self.tmp, ignore_errors=True)
|
|
||||||
|
|
||||||
def _run(self, **overrides):
|
|
||||||
kwargs = {
|
|
||||||
"assessment": self.assessment,
|
|
||||||
"existing_lock": self.lock,
|
|
||||||
"issue_number": 901,
|
|
||||||
"branch_name": BRANCH,
|
|
||||||
"source_worktree_path": self.source,
|
|
||||||
"recovery_worktree_path": self.recovery,
|
|
||||||
"remote": "prgs",
|
|
||||||
"org": "Example-Org",
|
|
||||||
"repo": "Example-Repo",
|
|
||||||
"identity": "author-user",
|
|
||||||
"profile": "prgs-author",
|
|
||||||
"expected_local_head": LOCAL_HEAD,
|
|
||||||
"expected_remote_head": REMOTE_HEAD,
|
|
||||||
"expected_dirty_fingerprints": {"a.py": FP_A, "b.py": FP_B},
|
|
||||||
"dirty_contents": {"a.py": b"dirty-a", "b.py": b"dirty-b"},
|
|
||||||
"local_head_contents": {"a.py": b"base-a", "b.py": b"base-b"},
|
|
||||||
"remote_head_contents": {"a.py": b"base-a", "b.py": b"base-b"},
|
|
||||||
"canonical_repo_root": self.repo,
|
|
||||||
"bind_lock": True,
|
|
||||||
"lock_writer": self.lock_writer,
|
|
||||||
"git_ops": self.git,
|
|
||||||
"journal_dir": self.journal_dir,
|
|
||||||
"session_pid": LIVE_PID,
|
|
||||||
}
|
|
||||||
kwargs.update(overrides)
|
|
||||||
return dorec.run_dirty_orphan_recovery(**kwargs)
|
|
||||||
|
|
||||||
def test_success_preserves_dirty_bytes_and_source(self):
|
|
||||||
result = self._run()
|
|
||||||
self.assertTrue(result["success"])
|
|
||||||
self.assertEqual(result["outcome"], dorec.RECOVERY_COMPLETED)
|
|
||||||
self.assertTrue(os.path.isdir(self.source))
|
|
||||||
with open(os.path.join(self.source, "a.py"), "rb") as fh:
|
|
||||||
self.assertEqual(fh.read(), b"dirty-a")
|
|
||||||
with open(os.path.join(self.recovery, "a.py"), "rb") as fh:
|
|
||||||
self.assertEqual(fh.read(), b"dirty-a")
|
|
||||||
with open(os.path.join(self.recovery, "b.py"), "rb") as fh:
|
|
||||||
self.assertEqual(fh.read(), b"dirty-b")
|
|
||||||
self.assertEqual(len(self.written_locks), 1)
|
|
||||||
rec = self.written_locks[0]
|
|
||||||
self.assertEqual(rec["session_pid"], LIVE_PID)
|
|
||||||
self.assertTrue(rec["dirty_orphan_recovery"]["recovered"])
|
|
||||||
self.assertTrue(rec["dirty_orphan_recovery"]["source_frozen"])
|
|
||||||
|
|
||||||
def test_conflict_leaves_governed_state(self):
|
|
||||||
result = self._run(
|
|
||||||
expected_dirty_fingerprints={"c.py": FP_C},
|
|
||||||
dirty_contents={"c.py": b"dirty-c-conflict"},
|
|
||||||
local_head_contents={"c.py": b"local-base"},
|
|
||||||
remote_head_contents={"c.py": b"remote-changed"},
|
|
||||||
)
|
|
||||||
# #860 F4: session binding is NOT finalized while conflicts remain
|
|
||||||
self.assertFalse(result["success"])
|
|
||||||
self.assertEqual(result["outcome"], dorec.CONFLICTS_PRESENT)
|
|
||||||
sidecar = os.path.join(self.recovery, "c.py.recovered-dirty")
|
|
||||||
self.assertTrue(os.path.isfile(sidecar))
|
|
||||||
state = os.path.join(
|
|
||||||
self.recovery, dorec.CONFLICT_STATE_DIR, dorec.CONFLICT_STATE_FILE
|
|
||||||
)
|
|
||||||
self.assertTrue(os.path.isfile(state))
|
|
||||||
with open(state, "r", encoding="utf-8") as fh:
|
|
||||||
payload = json.load(fh)
|
|
||||||
self.assertEqual(payload["resolution"], "author_edit_required")
|
|
||||||
|
|
||||||
def test_interrupt_before_journal_no_artifacts(self):
|
|
||||||
result = self._run(interrupt_after_phase=dorec.PHASE_ELIGIBILITY)
|
|
||||||
self.assertFalse(result["success"])
|
|
||||||
self.assertEqual(result["outcome"], "INTERRUPTED")
|
|
||||||
self.assertFalse(os.path.isdir(self.recovery))
|
|
||||||
|
|
||||||
def test_interrupt_after_journal_then_retry_idempotent(self):
|
|
||||||
first = self._run(interrupt_after_phase=dorec.PHASE_JOURNAL_PERSISTED)
|
|
||||||
self.assertEqual(first["outcome"], "INTERRUPTED")
|
|
||||||
self.assertTrue(first["journal"]["artifacts_created"]["journal"])
|
|
||||||
second = self._run()
|
|
||||||
self.assertTrue(second["success"])
|
|
||||||
# source still recoverable
|
|
||||||
with open(os.path.join(self.source, "a.py"), "rb") as fh:
|
|
||||||
self.assertEqual(fh.read(), b"dirty-a")
|
|
||||||
|
|
||||||
def test_interrupt_after_worktree_then_retry(self):
|
|
||||||
first = self._run(interrupt_after_phase=dorec.PHASE_RECOVERY_WORKTREE)
|
|
||||||
self.assertEqual(first["outcome"], "INTERRUPTED")
|
|
||||||
self.assertTrue(os.path.isdir(self.recovery))
|
|
||||||
second = self._run()
|
|
||||||
self.assertTrue(second["success"])
|
|
||||||
|
|
||||||
def test_interrupt_after_binding_then_retry_complete(self):
|
|
||||||
first = self._run(interrupt_after_phase=dorec.PHASE_BINDING)
|
|
||||||
self.assertEqual(first["outcome"], "INTERRUPTED")
|
|
||||||
second = self._run()
|
|
||||||
self.assertTrue(second["success"])
|
|
||||||
# completed journal makes further retries no-ops
|
|
||||||
third = self._run()
|
|
||||||
self.assertEqual(third["outcome"], dorec.RECOVERY_RESUMED)
|
|
||||||
|
|
||||||
def test_source_worktree_never_deleted(self):
|
|
||||||
self._run()
|
|
||||||
self.assertTrue(os.path.isdir(self.source))
|
|
||||||
self.assertTrue(os.path.isfile(os.path.join(self.source, "a.py")))
|
|
||||||
|
|
||||||
def test_fingerprint_drift_refuses_without_mutation(self):
|
|
||||||
result = self._run(dirty_contents={"a.py": b"CHANGED", "b.py": b"dirty-b"})
|
|
||||||
self.assertFalse(result["success"])
|
|
||||||
self.assertFalse(os.path.isdir(self.recovery))
|
|
||||||
|
|
||||||
|
|
||||||
class SessionBindingPreflight(unittest.TestCase):
|
|
||||||
def test_canonical_session_binding_recognized(self):
|
|
||||||
lock = {
|
|
||||||
"worktree_path": "/repo/branches/recovery",
|
|
||||||
"session_pid": LIVE_PID,
|
|
||||||
"dirty_orphan_recovery": {
|
|
||||||
"recovered": True,
|
|
||||||
"conflicts": [],
|
|
||||||
"recovery_worktree_path": "/repo/branches/recovery",
|
|
||||||
"source_worktree_path": SOURCE_WT,
|
|
||||||
"accepted_head": REMOTE_HEAD,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
result = dorec.preflight_recognizes_recovered_provenance(lock)
|
|
||||||
self.assertTrue(result["recognized"])
|
|
||||||
|
|
||||||
def test_conflicts_block_commit_preflight(self):
|
|
||||||
lock = {
|
|
||||||
"worktree_path": "/repo/branches/recovery",
|
|
||||||
"session_pid": LIVE_PID,
|
|
||||||
"dirty_orphan_recovery": {
|
|
||||||
"recovered": True,
|
|
||||||
"conflicts": [{"path": "c.py"}],
|
|
||||||
},
|
|
||||||
}
|
|
||||||
result = dorec.preflight_recognizes_recovered_provenance(lock)
|
|
||||||
self.assertFalse(result["recognized"])
|
|
||||||
|
|
||||||
def test_active_foreign_does_not_mutate(self):
|
|
||||||
# assess-only path: foreign refused before run
|
|
||||||
result = assess(identity="intruder")
|
|
||||||
self.assertFalse(result["eligible"])
|
|
||||||
|
|
||||||
|
|
||||||
class JournalSymlinkRefusal(unittest.TestCase):
|
|
||||||
def test_symlink_journal_path_refused_on_load(self):
|
|
||||||
tmp = tempfile.mkdtemp()
|
|
||||||
try:
|
|
||||||
real = os.path.join(tmp, "real.json")
|
|
||||||
with open(real, "w", encoding="utf-8") as fh:
|
|
||||||
fh.write("{}")
|
|
||||||
link = os.path.join(tmp, "link.json")
|
|
||||||
os.symlink(real, link)
|
|
||||||
key = "symlink-test"
|
|
||||||
jdir = tmp
|
|
||||||
path = dorec._journal_path(key, journal_dir=jdir)
|
|
||||||
with open(path, "w", encoding="utf-8") as fh:
|
|
||||||
json.dump({"idempotency_key": key}, fh)
|
|
||||||
os.remove(path)
|
|
||||||
os.symlink(real, path)
|
|
||||||
with self.assertRaises(ValueError):
|
|
||||||
dorec.load_journal(key, journal_dir=jdir)
|
|
||||||
finally:
|
|
||||||
shutil.rmtree(tmp, ignore_errors=True)
|
|
||||||
|
|
||||||
|
|
||||||
class RealGitMultiWorktreeIntegration(unittest.TestCase):
|
|
||||||
def setUp(self):
|
|
||||||
import subprocess
|
|
||||||
self.tmp = tempfile.mkdtemp(prefix="git-integration-")
|
|
||||||
self.repo = os.path.join(self.tmp, "repo")
|
|
||||||
os.makedirs(self.repo, exist_ok=True)
|
|
||||||
subprocess.run(["git", "init"], cwd=self.repo, check=True, capture_output=True)
|
|
||||||
subprocess.run(["git", "config", "user.name", "Test User"], cwd=self.repo, check=True)
|
|
||||||
subprocess.run(["git", "config", "user.email", "[email protected]"], cwd=self.repo, check=True)
|
|
||||||
with open(os.path.join(self.repo, "init.txt"), "w") as fh:
|
|
||||||
fh.write("init")
|
|
||||||
subprocess.run(["git", "add", "."], cwd=self.repo, check=True)
|
|
||||||
subprocess.run(["git", "commit", "-m", "init"], cwd=self.repo, check=True)
|
|
||||||
branch = "fix/issue-999-test"
|
|
||||||
subprocess.run(["git", "branch", branch], cwd=self.repo, check=True)
|
|
||||||
self.branches = os.path.join(self.repo, "branches")
|
|
||||||
self.source = os.path.join(self.branches, "issue-999-test")
|
|
||||||
subprocess.run(["git", "worktree", "add", self.source, branch], cwd=self.repo, check=True)
|
|
||||||
self.dirty_path = os.path.join(self.source, "dirty.txt")
|
|
||||||
with open(self.dirty_path, "w") as fh:
|
|
||||||
fh.write("dirty-data")
|
|
||||||
|
|
||||||
def tearDown(self):
|
|
||||||
shutil.rmtree(self.tmp, ignore_errors=True)
|
|
||||||
|
|
||||||
def test_prepare_recovery_worktree_detached_no_exit_128(self):
|
|
||||||
import subprocess
|
|
||||||
head_sha = subprocess.check_output(["git", "rev-parse", "HEAD"], cwd=self.repo, text=True).strip()
|
|
||||||
rec_wt = os.path.join(self.branches, "recovery-issue-999-test")
|
|
||||||
res = dorec.prepare_recovery_worktree(
|
|
||||||
canonical_repo_root=self.repo,
|
|
||||||
recovery_worktree_path=rec_wt,
|
|
||||||
branch_name="fix/issue-999-test",
|
|
||||||
remote_head=head_sha,
|
|
||||||
)
|
|
||||||
self.assertTrue(res["success"], res.get("reasons"))
|
|
||||||
self.assertTrue(os.path.isdir(rec_wt))
|
|
||||||
|
|
||||||
def test_real_lock_rebind_recovery_sanctioned(self):
|
|
||||||
lock_dir = os.path.join(self.tmp, "locks")
|
|
||||||
rec_wt = os.path.join(self.branches, "recovery-issue-999-test")
|
|
||||||
os.makedirs(rec_wt, exist_ok=True)
|
|
||||||
record = {
|
|
||||||
"remote": "prgs",
|
|
||||||
"org": "Example-Org",
|
|
||||||
"repo": "Example-Repo",
|
|
||||||
"issue_number": 999,
|
|
||||||
"branch_name": "fix/issue-999-test",
|
|
||||||
"worktree_path": rec_wt,
|
|
||||||
"claimant": {"username": "author-user", "profile": "prgs-author"},
|
|
||||||
}
|
|
||||||
record_src = dict(record)
|
|
||||||
record_src["worktree_path"] = self.source
|
|
||||||
issue_lock_store.bind_session_lock(record_src, lock_dir=lock_dir)
|
|
||||||
path = issue_lock_store.bind_session_lock(
|
|
||||||
record,
|
|
||||||
lock_dir=lock_dir,
|
|
||||||
recovery_sanctioned=True,
|
|
||||||
)
|
|
||||||
self.assertTrue(os.path.isfile(path))
|
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__":
|
|
||||||
unittest.main()
|
|
||||||
@@ -24,8 +24,6 @@ def _lease(expires_at: str) -> dict:
|
|||||||
|
|
||||||
|
|
||||||
def _lock_record(**overrides) -> dict:
|
def _lock_record(**overrides) -> dict:
|
||||||
# #860: live locks require a usable session pid; PID-less records are never
|
|
||||||
# classified live merely because expiry/heartbeat fields are present.
|
|
||||||
record = {
|
record = {
|
||||||
"issue_number": 420,
|
"issue_number": 420,
|
||||||
"branch_name": "feat/issue-420-server-code-parity",
|
"branch_name": "feat/issue-420-server-code-parity",
|
||||||
@@ -33,8 +31,6 @@ def _lock_record(**overrides) -> dict:
|
|||||||
"org": "Scaled-Tech-Consulting",
|
"org": "Scaled-Tech-Consulting",
|
||||||
"repo": "Gitea-Tools",
|
"repo": "Gitea-Tools",
|
||||||
"worktree_path": "/tmp/wt-420",
|
"worktree_path": "/tmp/wt-420",
|
||||||
"session_pid": os.getpid(),
|
|
||||||
"pid": os.getpid(),
|
|
||||||
"work_lease": _lease("2999-01-01T00:00:00Z"),
|
"work_lease": _lease("2999-01-01T00:00:00Z"),
|
||||||
}
|
}
|
||||||
record.update(overrides)
|
record.update(overrides)
|
||||||
@@ -92,8 +88,6 @@ class TestIssueLockStore(unittest.TestCase):
|
|||||||
existing = _lock_record(
|
existing = _lock_record(
|
||||||
branch_name="feat/issue-420-other",
|
branch_name="feat/issue-420-other",
|
||||||
worktree_path="/tmp/other",
|
worktree_path="/tmp/other",
|
||||||
session_pid=os.getpid(),
|
|
||||||
pid=os.getpid(),
|
|
||||||
work_lease=_lease("2999-01-01T00:00:00Z"),
|
work_lease=_lease("2999-01-01T00:00:00Z"),
|
||||||
)
|
)
|
||||||
path = ils.lock_file_path(
|
path = ils.lock_file_path(
|
||||||
|
|||||||
@@ -0,0 +1,107 @@
|
|||||||
|
"""Documentation acceptance for the MCP restart governance ADR (#656).
|
||||||
|
|
||||||
|
Enforces issue #656 acceptance criteria:
|
||||||
|
|
||||||
|
* AC1 — policy document exists with an authorization matrix and the recorded
|
||||||
|
v1 decision (controller approval + automated safety gates).
|
||||||
|
* AC2 — restart is stated as a last resort with enumerated narrower recoveries.
|
||||||
|
* AC3 — a unilateral LLM full restart with affected sessions is forbidden.
|
||||||
|
* AC4 — break-glass conditions are listed.
|
||||||
|
* AC5 — the ADR is linked to #655, #652, #653, #630, #642, and is cross-linked
|
||||||
|
from the safety model and the web-console deployment boundary docs.
|
||||||
|
"""
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
REPO_ROOT = Path(__file__).resolve().parent.parent
|
||||||
|
ADR = REPO_ROOT / "docs" / "architecture" / "mcp-restart-governance.md"
|
||||||
|
ADR_BASENAME = "mcp-restart-governance.md"
|
||||||
|
|
||||||
|
CROSS_LINK_DOCS = (
|
||||||
|
REPO_ROOT / "docs" / "safety-model.md",
|
||||||
|
REPO_ROOT / "docs" / "webui-deployment.md",
|
||||||
|
)
|
||||||
|
|
||||||
|
LINKED_ISSUES = ("#655", "#652", "#653", "#630", "#642")
|
||||||
|
POLICY_IDS = ("RG-01", "RG-02", "RG-03", "RG-04", "RG-05", "RG-06", "RG-07", "RG-08")
|
||||||
|
|
||||||
|
|
||||||
|
def _read(path: Path) -> str:
|
||||||
|
assert path.is_file(), f"missing {path.relative_to(REPO_ROOT)}"
|
||||||
|
return path.read_text(encoding="utf-8")
|
||||||
|
|
||||||
|
|
||||||
|
def test_ac1_adr_exists_with_matrix_and_v1_decision():
|
||||||
|
text = _read(ADR)
|
||||||
|
lower = text.lower()
|
||||||
|
assert text.lstrip().startswith("#"), "ADR lacks a title"
|
||||||
|
assert "#656" in text
|
||||||
|
assert "authorization matrix" in lower
|
||||||
|
# The matrix is a real table with the worker and privileged roles.
|
||||||
|
for role in ("author", "reviewer", "merger", "reconciler", "controller",
|
||||||
|
"operator", "admin"):
|
||||||
|
assert role in lower, f"authorization matrix missing role {role!r}"
|
||||||
|
# Recorded v1 decision.
|
||||||
|
assert "restart-governance/v1" in text
|
||||||
|
assert "controller approval" in lower and "automated safety gates" in lower
|
||||||
|
|
||||||
|
|
||||||
|
def test_ac2_restart_is_last_resort_with_narrower_recoveries():
|
||||||
|
text = _read(ADR)
|
||||||
|
lower = text.lower()
|
||||||
|
assert "last resort" in lower
|
||||||
|
# Enumerated narrower recoveries precede full restart on the ladder.
|
||||||
|
for rung in ("reconnect", "rebind", "scoped restart", "full restart",
|
||||||
|
"host"):
|
||||||
|
assert rung in lower, f"recovery ladder missing rung {rung!r}"
|
||||||
|
|
||||||
|
|
||||||
|
def test_ac3_forbids_unilateral_llm_full_restart_with_affected_sessions():
|
||||||
|
text = _read(ADR)
|
||||||
|
lower = text.lower()
|
||||||
|
assert "forbidden" in lower
|
||||||
|
assert "llm" in lower and "restart" in lower
|
||||||
|
assert "unilateral" in lower
|
||||||
|
# A worker role must not perform or authorize full/host restart.
|
||||||
|
assert "must not" in lower
|
||||||
|
|
||||||
|
|
||||||
|
def test_ac4_break_glass_conditions_listed():
|
||||||
|
text = _read(ADR)
|
||||||
|
lower = text.lower()
|
||||||
|
assert "break-glass" in lower
|
||||||
|
assert "incident" in lower
|
||||||
|
assert "audit" in lower
|
||||||
|
|
||||||
|
|
||||||
|
def test_ac5_adr_links_issue_lineage():
|
||||||
|
text = _read(ADR)
|
||||||
|
for issue in LINKED_ISSUES:
|
||||||
|
assert issue in text, f"ADR must link issue {issue}"
|
||||||
|
|
||||||
|
|
||||||
|
def test_ac5_safety_model_and_deployment_cross_link_adr():
|
||||||
|
for path in CROSS_LINK_DOCS:
|
||||||
|
text = _read(path)
|
||||||
|
assert ADR_BASENAME in text, (
|
||||||
|
f"{path.relative_to(REPO_ROOT)} must cross-link {ADR_BASENAME} "
|
||||||
|
f"(issue #656 acceptance criterion 5)"
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def test_policy_ids_present_for_enforcement_code():
|
||||||
|
text = _read(ADR)
|
||||||
|
for pid in POLICY_IDS:
|
||||||
|
assert pid in text, f"policy id {pid} missing from ADR"
|
||||||
|
|
||||||
|
|
||||||
|
def test_failure_behavior_denies_on_ambiguity():
|
||||||
|
text = _read(ADR)
|
||||||
|
lower = text.lower()
|
||||||
|
assert "ambiguous" in lower and "deny" in lower
|
||||||
|
|
||||||
|
|
||||||
|
def test_cross_links_do_not_embed_secrets():
|
||||||
|
for path in (ADR,) + CROSS_LINK_DOCS:
|
||||||
|
text = _read(path)
|
||||||
|
for marker in ("ghp_", "BEGIN PRIVATE KEY", "Authorization: Bearer"):
|
||||||
|
assert marker not in text, f"{path} contains {marker!r}"
|
||||||
Reference in New Issue
Block a user