Repository navigation
Integration batch R - #1466
Merged
Merged
Integration batch R#1466
Conversation
#1385 (q91 follow-up of #1380): a run dir holding only session-meta.json + sslkeylog.log was walked into and never collected, so its plaintext TLS secrets stayed on disk indefinitely (23 dirs, 5.18 MB on the owner's machine). A run dir is now recognised by either evidence file. Red before. HOLD for the owner's q91 decision: once collectable, the 48 h TTL pass removes these months-old dirs on the first prune, so this IS the sweep. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…efore didOpen (#1268) Co-Authored-By: Claude Opus 5.5 <[email protected]>
#1303) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…ocument directory, allow case-only renames (#1412 review a) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…tial write (#1414 review a+b) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…never counts as empty (q109, q115) dirStats skipped any child it could not read, so a run whose fresh data sat in an unreadable child was dated by its oldest file and TTL-removed. A failed read of the saved-bundles ledger returned an empty manual set, so manual legacy bundles were bucketed as prunable autosave. Only ENOENT now means absent; any other failure leaves the artifact uncollected. Co-Authored-By: Claude Opus 5.5 <[email protected]>
W4's #1417 owns loadManualLegacyBundlePaths and treats an absent ledger as unknown, stricter than this branch's ENOENT-means-empty. Keep only the dirStats fix; use #1417's loader as-is after it merges. Co-Authored-By: Claude Opus 5.5 <[email protected]>
Co-Authored-By: Claude Opus 5.5 <[email protected]>
) A run folder created after startup indexing (a second store sharing the folder) was absent from the index, read as empty, and deleted by the next maintenance pass. Retention now deletes only runs it examined. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…y; existing key logs stay (#1385) The 23 existing key-log-only dirs are an owner decision (q91). Collection now starts at runs dated on or after 2026-09-28; earlier or undated dirs are left untouched and never walked into. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…ain's rotated-generation run marker) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…s first pass, not a date constant (#1385, #1388 review a) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…tured at run start, not a timestamp (#1385, #1388 review a r2 + b) A first-prune marker excluded runs made during the boot delay forever, and any timestamp comparison admits a pre-upgrade run after a clock step back. The baseline is the set of key-log-only dirs that existed when this build first started, captured strictly and written once; with none, no key-log-only dir is collected. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…n during capture stay out of it (#1385, #1388 review a round 3) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…91 decision is tracked in #1460 (#1388 review c) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…olves to itself (#1268, #1412 review b) A pathless document's check returned early when the virtual directory was missing, without checking the root; a root renamed away and replaced by a symlink out then let didOpen name root/.agent-code-lsp/... outside. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…uld exclude an old key log from the baseline (#1388 review b round 3) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…ead of restarting ids (#1303, #1414 review a round 2) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…e and retried, never overwritten (#1414 review a round 3) Recovery treated any failure as 'no open file' and overwrote open.json with an empty snapshot, losing the pending interval. Only ENOENT is empty now; anything else is moved to open.json.unrecovered-<time> (a rename needs no read permission) and later starts recover each copy they can read. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…ted run is no longer examined (#1453, #1455 review a) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…eeps a run touched within the window (#1453, #1455 review b) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…recovered; no reissue-by-size fallback (#1414 review c) Co-Authored-By: Claude Opus 5.5 <[email protected]>
review a round 2) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…rd is tested on its own (#1455 review c) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…n file that changed since indexing (#1453, #1455 review b round 2) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…e's changed incident file (#1455 review b round 3) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…ne shape check (#1388, B6 check) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…d is not cached as empty (#1414, B6 check) Co-Authored-By: Claude Opus 5.5 <[email protected]>
…ed-run Keeps both sets of unknown-is-protected rules: main's refused / foreign incident runs and set-aside scan, and this branch's examinedRuns, touchedSince and foreign-file fingerprints; main's rewrite path in writeRunIncidents is behind foreignChanged too. Co-Authored-By: Claude Opus 5.5 <[email protected]>
…1268, #1412 review c) A pathless document's check validated .agent-code-lsp/ but not the virtual-<hash>.<ext> leaf; a leaf symlink created in advance resolved outside the root with no timing window. The leaf must be absent or a regular contained file; the name comes from the manager's own builder. Co-Authored-By: Claude Opus 5.5 <[email protected]>
The #1268 root-identity re-check (realpath(root) === root) refused every IPC open in lspDocumentOrdering.test.ts, whose fake '/repo' root does not exist. Production stays strict; the tests now use a realpath'd mkdtemp root. Co-Authored-By: Claude Opus 5.5 <[email protected]>
The same store reads while aliases.jsonl is unreadable, then must group A and B once readable. Red with a catch-all; the append test could not pin it because the tail check refuses that append on its own (B6 check 2110). Co-Authored-By: Claude Opus 5.5 <[email protected]>
…sted alone After merging main, touchedSince kept #1411's fresh 1970-clock fixtures on its own, so the foreignIncidents, refusedAsideRuns and listing-failure unindexed guards lost their failing tests. Those tests now use the real clock and aged() fixtures; each fails without its guard. Adds the two-store carried-rows retention test (B6 check 2110). Co-Authored-By: Claude Opus 5.5 <[email protected]>
…eylog-run-dirs fix(debug-retention): collect key-log-only proxy run dirs from new runs only; existing key logs untouched
fix(lsp): re-check physical containment after server startup, right before didOpen (#1268)
…after-write fix(agent-activity): cache a context id only after its line is written (#1303)
fix(performance): retention keeps a monitor run this store never examined
Owner
Author
|
Batch disposition (B6): 4 members merged via GitHub after member GATE PASS on 2bb6646; each was manager-verified (#1388 birthtime pin; #1412 root check and a test-only CI fix; #1414 aliases unknown-is-not-empty pin; #1455 both rule sets with aged fixtures). It merges when exact-head CI is green, the body is in past tense and a non-member gate PASS is recorded. |
Owner
Author
Owner
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Integration batch R (owner-approved merge mode, owner-requested history form). The branch was created from origin/main 2bb6646 (batch Q); each member PR was retargeted here and merged through GitHub.
Every member had GATE PASS (--member) on 2bb6646 and was manager-verified at the review cap. #1388 touches only NEW key-log runs; the 23 existing dirs are untouched (owner decision #1460). #1417 was left out (it conflicts with #1388 in debugRetention.ts and with main in codex.ts). Merged after green exact-head CI and a recorded non-member gate PASS (see comments).
🤖 Generated with Claude Code