You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Repair tombstone reads and removal now verify the stored address, including when two names sanitize to the same artifact directory. Malformed evidence stays intact; expired owned markers can be removed. Test publication also respects an explicit scoped address.
Capture controls distinguish a different handle under the same token and generation. Record-only capture publishes a new draft record through its declared owner. Legacy cutover tests wait for a complete, parseable verdict rather than file existence.
10 files; 126 gross lines. Addresses review findings on #3132, #3138 and #3140. Part of #3116, stacked on #3141.
Validation
Head 958983efee: 97 focused tests passed; quick checks and parent-scoped Fallow passed. Seven fault-injection runs failed at the intended assertions, including actual child-process partial publication. Restored focused tests pass. The ownership gate failed before declaring the real draft construction owner and passed afterward.
Independent read-only audit found no actionable findings. pnpm check:affected --base refactor/session-snapshot-lifetimes --run passed on this head, including 2,797 related tests and all selected local gates. CI and live device validation remain pending.
The scoped-session tombstone read at src/daemon/request-router.ts:619 does not match where the tombstone is written, so the cleanup guard misses the case it was meant to fix. I reviewed 958983e. repairExpiredIfTombstoned reads sessionStore.readRepairTombstone(req.session) under the raw request name. For an implicit session with meta.cwd (stored as cwd:<hash>:default) or a tenant-scoped one (<tenant>:<name>), the reaper writes the tombstone in the scoped address's directory with owner = ref.address (session-store.ts:338-346). The router looks in the raw name's directory instead, and with the new owner check it would refuse even a file it found. The owner check fixes sanitized-directory collisions, which is a different problem, so this mismatch is unchanged. No router test publishes at a scoped address. A CLI user whose cwd-scoped or tenant-scoped repair session was reaped, or whose commit failed at teardown, still gets a bare SESSION_NOT_FOUND instead of REPAIR_SESSION_EXPIRED or REPAIR_COMMIT_FAILED with re-run guidance. This is the #3140 finding this PR says it addresses. The rule should be that every error-path marker read, repair and idle, uses the address the request itself resolved to. Could you pull the scopeRequestSession plus resolveEffectiveSessionName({ attachesToSession: false }) block out of readIdleExpiryTombstoneSafely into one total helper, and call it from both repairExpiredIfTombstoned and idleExpiredIfTombstoned? Then please add a test in request-router-repair-expired.test.ts that publishes at cwd:<hash>:default, writes the tombstone, retires the session, sends close with session default and meta.cwd, and expects REPAIR_SESSION_EXPIRED, plus a tenant-scoped variant. Both should fail on the current head.
Not blocking, take or leave: findUnrecoveredRepairCommitFailure in src/session-repair-tombstone.ts:131 still reports entry.name (the sanitized directory) as sessionName when tombstone.owner is now authoritative; the test "test session publication uses its explicit scoped address" only exercises a test helper; R68 catches property construction but not member assignment such as session.screenRecording = x; and no behavior test asserts the caller's draft stays unmutated after record-only adoption.
I did not rerun the tests or the fault injection from the PR body, so the regression conclusions come from reading the code before the change. Repo Guards, Coverage and Integration Tests now pass on 958983e. Smoke Tests is still running, and a failure there could not be treated as unrelated, because it overlaps the record-only recording publication in record-runtime.ts:147. There are no conflicts. Before merge, repairExpiredIfTombstoned must read the tombstone under the request's resolved scoped address, with the scoped router test passing.
Consolidated into #3140 as part of reducing #3116 to seven PRs. Session/repair changes are in #3140; timeout-result corrections are in #3127. The composition preserves the complete pre-consolidation source tree, including tests and later review corrections. This PR is superseded; its review discussion and native evidence remain available. Outstanding findings transfer to the owning keeper in the implementation record.
Preview removed because the pull request was closed.
2026-10-03 21:16 UTC
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Repair tombstone reads and removal now verify the stored address, including when two names sanitize to the same artifact directory. Malformed evidence stays intact; expired owned markers can be removed. Test publication also respects an explicit scoped address.
Capture controls distinguish a different handle under the same token and generation. Record-only capture publishes a new draft record through its declared owner. Legacy cutover tests wait for a complete, parseable verdict rather than file existence.
10 files; 126 gross lines. Addresses review findings on #3132, #3138 and #3140. Part of #3116, stacked on #3141.
Validation
Head
958983efee: 97 focused tests passed; quick checks and parent-scoped Fallow passed. Seven fault-injection runs failed at the intended assertions, including actual child-process partial publication. Restored focused tests pass. The ownership gate failed before declaring the real draft construction owner and passed afterward.Independent read-only audit found no actionable findings.
pnpm check:affected --base refactor/session-snapshot-lifetimes --runpassed on this head, including 2,797 related tests and all selected local gates. CI and live device validation remain pending.