Before submitting
Problem
In runProfilesPanelAction case "apply" (extensions/gentle-ai.ts, populated-profile confirmation), the confirmation dialog computes its per-agent diff from the global routing read at prompt time. If another session (or process) changes global routing while the ctx.ui.confirm dialog is open, the operator approves a diff that no longer matches reality, and the apply then overwrites the newer routing without ever showing its changes.
This is a read-then-decide-then-write window: the routing authority is read before the confirm and the write happens after approval with no re-validation.
Reproduction
- Open
/gentle:profiles, select a populated profile, press enter so the "Apply profile?" dialog is open.
- From a second session, modify the global routing (for example, save a
/gentle:models change with Ctrl+S).
- Approve the still-open dialog in the first session.
Observed (from code-path analysis): the apply writes the profile snapshot over the newer routing; the second session's change is discarded and was never named in the approved diff.
Expected: the apply re-reads the routing after approval and, if the relevant state changed while the dialog was open, requests a fresh confirmation (or aborts with an actionable message) instead of overwriting unobserved changes.
Expected and actual behavior
Expected:
A diff the operator approves must describe the write that actually happens. If routing changed between read and approval, the operator should be re-asked with the updated diff.
Actual:
Approval validates a stale diff; concurrent changes are silently overwritten.
gentle-pi version
source, PR #1384 head 777ac6d
Pi version
0.99.1
Operating system
Linux
Relevant logs or error output (optional)
Flagged by CodeRabbit as a "Heavy lift" Major on PR #1384 (thread 2026-10-02, "Reject a routing diff that changes while confirmation is open"), and recorded as an informational reliability finding (R3-toctou-read-then-write, extensions/gentle-ai.ts:4155-4158) during the native review of the same candidate. Related context: #1349, #1384.
Before submitting
Problem
In
runProfilesPanelActioncase "apply"(extensions/gentle-ai.ts, populated-profile confirmation), the confirmation dialog computes its per-agent diff from the global routing read at prompt time. If another session (or process) changes global routing while thectx.ui.confirmdialog is open, the operator approves a diff that no longer matches reality, and the apply then overwrites the newer routing without ever showing its changes.This is a read-then-decide-then-write window: the routing authority is read before the confirm and the write happens after approval with no re-validation.
Reproduction
/gentle:profiles, select a populated profile, pressenterso the "Apply profile?" dialog is open./gentle:modelschange withCtrl+S).Observed (from code-path analysis): the apply writes the profile snapshot over the newer routing; the second session's change is discarded and was never named in the approved diff.
Expected: the apply re-reads the routing after approval and, if the relevant state changed while the dialog was open, requests a fresh confirmation (or aborts with an actionable message) instead of overwriting unobserved changes.
Expected and actual behavior
Expected:
A diff the operator approves must describe the write that actually happens. If routing changed between read and approval, the operator should be re-asked with the updated diff.
Actual:
Approval validates a stale diff; concurrent changes are silently overwritten.
gentle-pi version
source, PR #1384 head 777ac6d
Pi version
0.99.1
Operating system
Linux
Relevant logs or error output (optional)
Flagged by CodeRabbit as a "Heavy lift" Major on PR #1384 (thread 2026-10-02, "Reject a routing diff that changes while confirmation is open"), and recorded as an informational reliability finding (R3-toctou-read-then-write, extensions/gentle-ai.ts:4155-4158) during the native review of the same candidate. Related context: #1349, #1384.