Skip to content

fix(repository): harden filesystem, Git, and verification boundaries — prevent race conditions, ambiguous rollback, and unsafe execution - #759

Closed
unohee wants to merge 9 commits into
mainfrom
swarm/AGT-3447-fix-repository-harden-filesystem-git-and
Closed

unohee wants to merge 9 commits into
mainfrom
swarm/AGT-3447-fix-repository-harden-filesystem-git-and

Conversation

@unohee

@unohee unohee commented Sep 26, 2026

Copy link
Copy Markdown
Collaborator

Summary

Published because this run stopped and needs a human: autonomous execution failed 4 times

It has not been reviewed and is very likely incomplete — this PR is a draft on purpose. It exists so the work is reviewable instead of sitting on a branch that was never pushed.

Change shape

545 file(s): 262 source · 240 test · 9 docs · 34 other

Base freshness

Branch base is 244 commit(s) behind main at publication.

⚠ Conflicts with main in: src/verify/runner.ts
GitHub runs no pull_request workflows on a PR it cannot merge, so any green checks here are not the verification gate. Opened as a draft; rebase before review.

⚠️ File overlap with in-flight work

This branch changes files that other open PRs / active branches also touch. Coordinate before merging to avoid divergent parallel edits (INT-2388 #3):

Linear

Closes AGT-3447


🤖 Generated with OpenSwarm

This was referenced Sep 26, 2026
unohee pushed a commit that referenced this pull request Sep 28, 2026
Salvages drafts #759, #762 and #765 onto current main:

- eventHub (#762): MAX_EVENT_PAYLOAD_BYTES frame cap, MAX_LOG_LINE_CHARS /
  MAX_CHAT_TEXT_CHARS field bounds, per-client SSE backpressure counters
  (WeakMap, one drain listener per socket) with disconnectClient.
- chatStream / chatBackend / LogLine (#762): retention caps for partial SSE
  frames, parsed chunks, assembled content, CLI stdout/stderr and rendered
  log lines.
- rollback (#759): resolve the checkpoint stash by EXACT subject match
  (stash@{N} is a position, and 'abc' must not match 'abcd').
- gitStatus (#759): 10 MiB maxBuffer and reject-on-error so a failed git
  call can no longer masquerade as a clean tree.
- httpBody (#759): streaming TextDecoder so a multi-byte char split across
  chunks is decoded correctly.
- workSessionRoutes (#759): diff I/O through the containment-validated
  canonical worktree.
- inputDebug (#759): contain diagnostic writes to ~/.openswarm.
- gitInfo (#759): sentinel-prefixed churn parser that cannot read a
  numeric filename as a timestamp nor the next commit's timestamp as a path.
- ciWorker / fixCommand (#765): subprocess timeouts and buffer bounds.
unohee added a commit that referenced this pull request Sep 28, 2026
…#789)

Salvages drafts #759, #762 and #765 onto current main:

- eventHub (#762): MAX_EVENT_PAYLOAD_BYTES frame cap, MAX_LOG_LINE_CHARS /
  MAX_CHAT_TEXT_CHARS field bounds, per-client SSE backpressure counters
  (WeakMap, one drain listener per socket) with disconnectClient.
- chatStream / chatBackend / LogLine (#762): retention caps for partial SSE
  frames, parsed chunks, assembled content, CLI stdout/stderr and rendered
  log lines.
- rollback (#759): resolve the checkpoint stash by EXACT subject match
  (stash@{N} is a position, and 'abc' must not match 'abcd').
- gitStatus (#759): 10 MiB maxBuffer and reject-on-error so a failed git
  call can no longer masquerade as a clean tree.
- httpBody (#759): streaming TextDecoder so a multi-byte char split across
  chunks is decoded correctly.
- workSessionRoutes (#759): diff I/O through the containment-validated
  canonical worktree.
- inputDebug (#759): contain diagnostic writes to ~/.openswarm.
- gitInfo (#759): sentinel-prefixed churn parser that cannot read a
  numeric filename as a timestamp nor the next commit's timestamp as a path.
- ciWorker / fixCommand (#765): subprocess timeouts and buffer bounds.

Co-authored-by: SalvageD <salvage@local>
@unohee

unohee commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator Author

Closing: superseded — the salvageable work in this draft was rebased onto current main, verified, and re-published as a reviewed PR: absorbed into #789 (salvage/streaming-bounds). Closing the stale draft instead of merging it, because it was 170-250 commits behind, carried scratch files, and (in several cases) reverted main's later hardening.

@unohee unohee closed this Sep 28, 2026
@unohee
unohee deleted the swarm/AGT-3447-fix-repository-harden-filesystem-git-and branch September 28, 2026 07:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant