Skip to content

Integration batch R - #1466

Merged
Juliusolsson05 merged 37 commits into
mainfrom
integration/batch-2026-09-27-r
Sep 27, 2026
Merged

Juliusolsson05 merged 37 commits into
mainfrom
integration/batch-2026-09-27-r

Conversation

@Juliusolsson05

@Juliusolsson05 Juliusolsson05 commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Integration batch R (owner-approved merge mode, owner-requested history form). The branch was created from origin/main 2bb6646 (batch Q); each member PR was retargeted here and merged through GitHub.

Every member had GATE PASS (--member) on 2bb6646 and was manager-verified at the review cap. #1388 touches only NEW key-log runs; the 23 existing dirs are untouched (owner decision #1460). #1417 was left out (it conflicts with #1388 in debugRetention.ts and with main in codex.ts). Merged after green exact-head CI and a recorded non-member gate PASS (see comments).

🤖 Generated with Claude Code

Juliusolsson05 and others added 30 commits September 27, 2026 01:38
#1385 (q91 follow-up of #1380): a run dir holding only session-meta.json +
sslkeylog.log was walked into and never collected, so its plaintext TLS
secrets stayed on disk indefinitely (23 dirs, 5.18 MB on the owner's
machine). A run dir is now recognised by either evidence file. Red before.

HOLD for the owner's q91 decision: once collectable, the 48 h TTL pass
removes these months-old dirs on the first prune, so this IS the sweep.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…efore didOpen (#1268)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
#1303)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ocument directory, allow case-only renames (#1412 review a)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tial write (#1414 review a+b)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…never counts as empty (q109, q115)

dirStats skipped any child it could not read, so a run whose fresh data sat
in an unreadable child was dated by its oldest file and TTL-removed. A failed
read of the saved-bundles ledger returned an empty manual set, so manual
legacy bundles were bucketed as prunable autosave. Only ENOENT now means
absent; any other failure leaves the artifact uncollected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
W4's #1417 owns loadManualLegacyBundlePaths and treats an absent ledger as
unknown, stricter than this branch's ENOENT-means-empty. Keep only the
dirStats fix; use #1417's loader as-is after it merges.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
)

A run folder created after startup indexing (a second store sharing the
folder) was absent from the index, read as empty, and deleted by the next
maintenance pass. Retention now deletes only runs it examined.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…y; existing key logs stay (#1385)

The 23 existing key-log-only dirs are an owner decision (q91). Collection
now starts at runs dated on or after 2026-09-28; earlier or undated dirs
are left untouched and never walked into.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ain's rotated-generation run marker)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…s first pass, not a date constant (#1385, #1388 review a)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…tured at run start, not a timestamp (#1385, #1388 review a r2 + b)

A first-prune marker excluded runs made during the boot delay forever, and
any timestamp comparison admits a pre-upgrade run after a clock step back.
The baseline is the set of key-log-only dirs that existed when this build
first started, captured strictly and written once; with none, no key-log-only
dir is collected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…n during capture stay out of it (#1385, #1388 review a round 3)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…91 decision is tracked in #1460 (#1388 review c)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…olves to itself (#1268, #1412 review b)

A pathless document's check returned early when the virtual directory was
missing, without checking the root; a root renamed away and replaced by a
symlink out then let didOpen name root/.agent-code-lsp/... outside.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…uld exclude an old key log from the baseline (#1388 review b round 3)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ead of restarting ids (#1303, #1414 review a round 2)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e and retried, never overwritten (#1414 review a round 3)

Recovery treated any failure as 'no open file' and overwrote open.json with
an empty snapshot, losing the pending interval. Only ENOENT is empty now;
anything else is moved to open.json.unrecovered-<time> (a rename needs no
read permission) and later starts recover each copy they can read.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ted run is no longer examined (#1453, #1455 review a)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…eeps a run touched within the window (#1453, #1455 review b)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…recovered; no reissue-by-size fallback (#1414 review c)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
 review a round 2)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rd is tested on its own (#1455 review c)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…n file that changed since indexing (#1453, #1455 review b round 2)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…e's changed incident file (#1455 review b round 3)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ne shape check (#1388, B6 check)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d is not cached as empty (#1414, B6 check)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ed-run

Keeps both sets of unknown-is-protected rules: main's refused / foreign
incident runs and set-aside scan, and this branch's examinedRuns,
touchedSince and foreign-file fingerprints; main's rewrite path in
writeRunIncidents is behind foreignChanged too.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…1268, #1412 review c)

A pathless document's check validated .agent-code-lsp/ but not the
virtual-<hash>.<ext> leaf; a leaf symlink created in advance resolved
outside the root with no timing window. The leaf must be absent or a
regular contained file; the name comes from the manager's own builder.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Juliusolsson05 and others added 7 commits September 27, 2026 13:42
The #1268 root-identity re-check (realpath(root) === root) refused every
IPC open in lspDocumentOrdering.test.ts, whose fake '/repo' root does not
exist. Production stays strict; the tests now use a realpath'd mkdtemp root.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The same store reads while aliases.jsonl is unreadable, then must group A
and B once readable. Red with a catch-all; the append test could not pin
it because the tail check refuses that append on its own (B6 check 2110).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…sted alone

After merging main, touchedSince kept #1411's fresh 1970-clock fixtures on
its own, so the foreignIncidents, refusedAsideRuns and listing-failure
unindexed guards lost their failing tests. Those tests now use the real
clock and aged() fixtures; each fails without its guard. Adds the two-store
carried-rows retention test (B6 check 2110).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…eylog-run-dirs

fix(debug-retention): collect key-log-only proxy run dirs from new runs only; existing key logs untouched
fix(lsp): re-check physical containment after server startup, right before didOpen (#1268)
…after-write

fix(agent-activity): cache a context id only after its line is written (#1303)
fix(performance): retention keeps a monitor run this store never examined
@Juliusolsson05 Juliusolsson05 added the type:chore Maintenance, deps, tests, docs label Sep 27, 2026
@Juliusolsson05

Copy link
Copy Markdown
Owner Author

Batch disposition (B6): 4 members merged via GitHub after member GATE PASS on 2bb6646; each was manager-verified (#1388 birthtime pin; #1412 root check and a test-only CI fix; #1414 aliases unknown-is-not-empty pin; #1455 both rule sets with aged fixtures). It merges when exact-head CI is green, the body is in past tense and a non-member gate PASS is recorded.

@Juliusolsson05

Copy link
Copy Markdown
Owner Author

OWNER-APPROVED: (B6 owner proxy, recorded on the member PRs) #1412 narrowing accepted as Refs #1268; #1388 collects only NEW key-log runs, and deleting the 23 existing dirs remains an open owner decision (#1460), untouched here; #1455 two-process --packaging-smoke residual accepted.

@Juliusolsson05

Copy link
Copy Markdown
Owner Author

Pre-merge gate record: merge-gate.sh agent-code 1466 --dry → GATE PASS #1466 (2e539f6, 0 behind main, checks green, reviews OK). The body is in past tense; closing refs are #1303, #1385 and #1453 only (#1268 stays open). Merging.

@Juliusolsson05
Juliusolsson05 marked this pull request as ready for review September 27, 2026 21:54
@Juliusolsson05
Juliusolsson05 merged commit 4b7e669 into main Sep 27, 2026
2 checks passed
@Juliusolsson05
Juliusolsson05 deleted the integration/batch-2026-09-27-r branch September 27, 2026 21:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:chore Maintenance, deps, tests, docs

Projects

None yet

1 participant