Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .agents/pm/extensions/.managed-extensions.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"version": 1,
"updated_at": "2026-09-26T22:20:41.276Z",
"updated_at": "2026-09-27T03:46:20.555Z",
"entries": [
{
"name": "pm-changelog",
Expand Down
1 change: 1 addition & 0 deletions .agents/pm/history/pm-erogk1.jsonl
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
{"hash_algorithm":"sha256","ts":"2026-09-27T00:37:15.358Z","author":"harness:codex","author_source":"detected","agent_harness":"codex","agent_model":"gpt-6-sol","agent_model_source":"probe","agent_instance":"f9d60a3a144e8d9ec3f9b203","agent_provenance":{"model":{"value":"gpt-6-sol","source":"probe"},"effort":{"value":"high","source":"probe"},"role":{"value":"implementer","source":"inferred","confidence":"medium","rule_version":"v2","evidence":["claim:pm-kynkl8","claim:pm-t05d8d","lineage:pm-t05d8d","lineage:pm-ugqx","lineage:pm-doxj"]},"topic":{"value":"workset:pm-kynkl8+pm-t05d8d","source":"inferred","confidence":"medium","rule_version":"v2","evidence":["claim:pm-kynkl8","claim:pm-t05d8d","lineage:pm-t05d8d","lineage:pm-ugqx","lineage:pm-doxj"]}},"op":"create","patch":[{"op":"add","path":"/metadata/id","value":"pm-erogk1"},{"op":"add","path":"/metadata/title","value":"Refuse local package installation when source scan stops at entry limit"},{"op":"add","path":"/metadata/description","value":"GitHub #1321: local package source inspection reaches max_entries=10000, reports copy.complete=false and stop_reason=entry_limit, yet dry-run and real install return ok=true, warnings=[] and exit 0; real path may activate a partial package. Fail closed before write/activation, give a packed-package recovery hint, and align dry-run readiness."},{"op":"add","path":"/metadata/type","value":"Issue"},{"op":"add","path":"/metadata/status","value":"open"},{"op":"add","path":"/metadata/priority","value":1},{"op":"add","path":"/metadata/tags","value":[]},{"op":"add","path":"/metadata/created_at","value":"2026-09-27T00:37:15.358Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-09-27T00:37:15.358Z"},{"op":"add","path":"/metadata/author","value":"harness:codex"},{"op":"add","path":"/metadata/parent","value":"pm-x6jf"},{"op":"add","path":"/metadata/dependencies","value":[{"id":"pm-x6jf","kind":"discovered_from","created_at":"2026-09-27T00:37:15.358Z","author":"harness:codex","source_kind":"cli:create:dep","author_source":"detected"}]},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-09-27T00:37:15.358Z","author":"harness:codex","text":"Duplicate check across all PM statuses: searched GH #1321, entry_limit, incomplete source scan, partial package copy, and package install. Earlier lifecycle items cover different completed fixes; no existing item owns this limit-truncation defect. Source: https://github.com/unbraind/pm-cli/issues/1321. Intake only; item remains open and unclaimed."}]}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"7d0efe9810572cf2effbaaf56994e8fee9f0a849b034f9b039a6137804e49865","item_hash_version":3,"message":"Track GitHub #1321 partial package install defect without claiming work","context":{"agent_provenance_outcomes":{"model":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"effort":{"status":"resolved","resolver":"codex_session_file","rule_version":"v1"},"version":{"status":"unavailable","reason":"harness_unavailable","resolver":"ai_agent_version","rule_version":"v1"}}},"event_class":"substantive","record_hash_version":1,"record_hash":"af88212bdba8fe77db3868942ac531e3cdc616f1463a94e13e95246876468498"}
28 changes: 28 additions & 0 deletions .agents/pm/history/pm-kynkl8.jsonl

Large diffs are not rendered by default.

17 changes: 17 additions & 0 deletions .agents/pm/history/pm-t05d8d.jsonl

Large diffs are not rendered by default.

16 changes: 16 additions & 0 deletions .agents/pm/issues/pm-erogk1.toon
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
id: pm-erogk1
title: Refuse local package installation when source scan stops at entry limit
description: "GitHub #1321: local package source inspection reaches max_entries=10000, reports copy.complete=false and stop_reason=entry_limit, yet dry-run and real install return ok=true, warnings=[] and exit 0; real path may activate a partial package. Fail closed before write/activation, give a packed-package recovery hint, and align dry-run readiness."
type: Issue
status: open
priority: 1
tags: []
created_at: "2026-09-27T00:37:15.358Z"
updated_at: "2026-09-27T00:37:15.358Z"
author: "harness:codex"
parent: pm-x6jf
dependencies[1]{id,kind,created_at,author,source_kind,author_source}:
pm-x6jf,discovered_from,"2026-09-27T00:37:15.358Z","harness:codex","cli:create:dep",detected
comments[1]{created_at,author,text}:
"2026-09-27T00:37:15.358Z","harness:codex","Duplicate check across all PM statuses: searched GH #1321, entry_limit, incomplete source scan, partial package copy, and package install. Earlier lifecycle items cover different completed fixes; no existing item owns this limit-truncation defect. Source: https://github.com/unbraind/pm-cli/issues/1321. Intake only; item remains open and unclaimed."
body: ""
98 changes: 98 additions & 0 deletions .agents/pm/issues/pm-kynkl8.toon
Original file line number Diff line number Diff line change
@@ -0,0 +1,98 @@
id: pm-kynkl8
title: Preserve every tracker merge fence during nested init and detect lost active mappings
description: "Nested pm init replaces the root tracker merge-driver attributes, and strict health misses the lost mappings. Reconcile distinct tracker fences in a shared Git repository without erasing other trackers, and make active-tracker strict health fail when the merge fence is missing or stale. GitHub #1320."
type: Issue
status: closed
priority: 1
tags[4]: "area:init","area:merge",gh-1320,multi-tracker
created_at: "2026-09-26T23:39:49.274Z"
updated_at: "2026-09-27T03:45:14.301Z"
closed_at: "2026-09-27T01:49:16.819Z"
completed_at: "2026-09-27T01:49:16.819Z"
author: "harness:codex"
acceptance_criteria: "Nested init and subsequent merge install preserve both root and nested merge mappings; Strict health detects lost active-tracker mappings; Focused regression, full coverage, and temporary packed CLI acceptance pass"
parent: pm-dj98
resolution: "Reconciled only the active tracker managed .gitattributes block, preserved sibling and mixed legacy blocks, repaired truncated block audit, and added strict-health remediation for missing or drifted fences."
expected_result: "Root, nested, and root-mounted trackers retain field-aware Git attributes across init and reinstall; strict health rejects a lost active fence."
actual_result: "Four focused merge integration cases and linked PM test passed; 9,371 repository tests passed with exact 100/100/100/100 coverage; packed disposable-project health passed; graph, record-integrity, docstring, lint, and mutation checks passed."
dependencies[5]{id,kind,created_at,author,source_kind,author_source}:
pm-1w3ljt,verifies,"2026-09-27T00:30:21.598Z","harness:codex","cli:update:dep",detected
pm-i4fx,verifies,"2026-09-27T00:30:21.598Z","harness:codex","cli:update:dep",detected
pm-t05d8d,discovered_from,"2026-09-27T00:30:21.598Z","harness:codex","cli:update:dep",detected
pm-g5sx,implements,"2026-09-27T01:47:42.715Z","harness:codex","cli:update:dep",detected
pm-l56d0o,verifies,"2026-09-27T01:47:42.715Z","harness:codex","cli:update:dep",detected
comments[10]{created_at,author,text}:
"2026-09-26T23:39:49.274Z","harness:codex","created_at=now,text=Duplicate check 2026-09-27: all-status searches for GH-1320, nested init merge attributes, merge fence ownership, and tracker fence drift found closed pm-1w3ljt, pm-i4fx, pm-l56d0o, and pm-g5sx. They delivered initial fence installation, coverage, and version-skew handling but not preservation across nested trackers. Source report https://github.com/unbraind/pm-cli/issues/1320."
"2026-09-27T00:32:56.876Z","harness:codex","Root cause: shared .gitattributes reconciliation removed the first managed block without checking tracker ownership, so a nested tracker install could erase the root tracker fence (and vice versa). The fix preserves sibling blocks, replaces only the active tracker block, collapses duplicate owned blocks, and makes strict health report missing/drifted active fences. Focused integration tests passed (2/2), including git check-attr and reinstall for both roots. GitHub #1320 carries the canonical PM link; tracker validation now reports zero orphaned paths."
"2026-09-27T00:56:03.425Z","harness:codex","Full coverage run surfaced a real truncated-fence audit edge case: an unterminated managed block still contained expected patterns, so the audit marked drift but reported zero missing patterns. The parser now records whether each block closed, excludes unclosed content from committed mappings, and retains a drift verdict. Updated strict-health expectation; the focused merge and health suite now passes 25 tests."
"2026-09-27T01:37:13.523Z","harness:codex","Final verification: pnpm test:coverage passed 748 test files / 9,371 tests with exact 100/100/100/100 coverage (65,708 statements; 50,236 branches; 13,602 functions; 62,756 lines), 2 Windows-only tests skipped on Linux. pm test pm-kynkl8 --run passed 4 integration cases after the final edits. The new cases cover mixed legacy/versioned fences, root-mounted trackers with siblings, ownerless legacy migration, and lone nested-block preservation. pnpm build, pnpm typecheck, ESLint, docstring/static scanner, docs-skills gate, and npm audit high passed. Packaged CLI smoke in a disposable Git project passed, including strict health and npx/bunx version commands."
"2026-09-27T01:49:01.054Z","harness:codex",Graph-composition gate identified two prose-only references in this item’s duplicate-check history. Added typed verifies link to closed version-skew issue pm-l56d0o and implements link to closed merge-semantics feature pm-g5sx; graph-composition now passes with prose-edge gaps at its 1236 ceiling. Record-integrity assurance and the mandatory mutation gate also passed (323/330 mutants killed; seven classified equivalent).
"2026-09-27T02:40:30.447Z","harness:codex","PR #1322 review follow-up: CodeRabbit identified ancestor/descendant fence ownership and inferred concurrent shared-file write loss. A new integration regression first failed when parent reinstall erased a child tracker fence. Exact generated-pattern matching now preserves that child; legacy direct type-folder rows remain attributable for drift diagnostics. A separate Git-directory merge-attributes lock serializes shared .gitattributes read/modify/write across trackers, and the existing atomic file writer publishes the result. The focused merge/validate suite passed 122 tests, including concurrent refresh and child extension exclusion. The first full coverage attempt exposed two test contract mismatches and one 10.265 s performance ceiling under host load; the two contract failures are fixed and the performance case passed focused at 5.78 s. Full rerun pending."
"2026-09-27T03:03:27.480Z","harness:codex","PR #1322 review-fix verification complete: node scripts/run-tests.mjs test -- tests/unit/sdk/merge-safety.spec.ts tests/unit/commands/governance/validate-command.spec.ts tests/integration/merge-fence-version-skew.integration.spec.ts passed 122/122; linked pm test passed 6/6; pnpm test:coverage passed 748 files and 9,373 tests (2 Windows-only skipped) with exact 100/100/100/100 coverage (65,706 statements, 50,238 branches, 13,601 functions, 62,755 lines); pnpm build, pnpm typecheck, focused ESLint, and full pnpm quality:static passed, including CLI transport, graph composition, record integrity, docstring, and mutation gates (323 killed, 7 equivalent). pm-changelog 2026.9.25 --check reported unchanged. The new concurrent refresh and ancestor-child cases are part of the same merge-fence contract."
"2026-09-27T03:16:54.898Z","harness:codex","PR #1322 CI static gate failed because the 2026.9.27 daily release commit landed on main while this PR was running. A clean temporary merge preview reproduced the pm-changelog --check mismatch: the merged release heading said 2026.9.27 while latest pm-changelog 2026.9.25 generated Unreleased for this PR lineage. Merged current main into the PR branch without rewriting history, regenerated CHANGELOG.md through pm-changelog, and verified changelog:pm:check against the combined tree. No pm-changelog package code change was needed."
"2026-09-27T03:29:25.443Z","harness:codex","Correction to the previous CI note: the new main commit also has an existing remote v2026.9.27 tag. The local checkout had not fetched that tag, so pm-changelog placed earlier released items under Unreleased and local --check gave a false green for CI parity. After git fetch --tags origin, the check reproduced CI failure; pm-changelog 2026.9.25 regenerated the correct two sections: this PR items under Unreleased and prior items under 2026.9.27. The tagged local --check now passes. No tag was created or rewritten."
"2026-09-27T03:45:14.301Z","harness:codex","PR #1322 review disposition: CodeRabbit suggested returning not_installed when a sibling tracker has a fence but the active tracker has none. The existing audit intentionally returns drift in that case: expected patterns are missing from a managed .gitattributes file, so validate.ts emits validate_merge_fence_drift and strict health emits merge_fence_drift. The integration regression removes the active block while retaining a sibling and asserts the strict failure. Returning not_installed without changing validation would suppress this warning; changing the public status/diagnostic contract is unnecessary for this defect. Kept the tested drift behavior and explained it in the inline review thread."
learnings[2]{created_at,author,text}:
"2026-09-27T00:40:54.856Z","harness:codex","A repository may host multiple PM roots sharing one .gitattributes. Merge-fence maintenance must identify ownership by tracker-relative pattern prefix, preserve sibling blocks, and audit the active tracker separately from clone-local Git driver configuration."
"2026-09-27T03:03:41.872Z","harness:codex","Correction to the earlier prefix-ownership note: a tracker can live inside another tracker root, so a broad prefix can claim and erase its descendant fence. Match exact generated lines, admit legacy direct type-folder rows for drift diagnostics, serialize shared .gitattributes edits through the Git directory, and publish the file atomically."
files[10]{path,scope}:
src/core/diagnostics/remediation.ts,project
src/sdk/generated/generated-error-code-catalog-part-1.ts,project
src/sdk/generated/generated-error-code-catalog-part-2.ts,project
src/sdk/governance/health-merge-evidence.ts,project
src/sdk/governance/health.ts,project
src/sdk/merge/install.ts,project
tests/fixtures/contracts/full.json,project
tests/integration/merge-fence-version-skew.integration.spec.ts,project
tests/unit/sdk/governance/health-verdict-authority.spec.ts,project
tests/unit/sdk/merge-safety.spec.ts,project
tests[1]{command,scope,timeout_seconds,provenance{author,created_at,source_kind,source_ref}}:
node scripts/run-tests.mjs test -- tests/integration/merge-fence-version-skew.integration.spec.ts,project,2400,"harness:codex","2026-09-27T00:31:51.396Z",local_mutation,fix/isolated-project-context-and-merge-fences
test_runs[3]:
- run_id: test-local-muj33ain-jamd0w
kind: test
status: passed
started_at: "2026-09-27T00:31:59.684Z"
finished_at: "2026-09-27T00:32:09.983Z"
recorded_at: "2026-09-27T00:32:09.983Z"
passed: 1
failed: 0
skipped: 0
executions[1]{command,requested_pm_context_mode,pm_context_mode,workspace_context_mode,trust_reason}:
node scripts/run-tests.mjs test -- tests/integration/merge-fence-version-skew.integration.spec.ts,schema,schema,source,local_source_ref
- run_id: test-local-muj5eq4p-ult72v
kind: test
status: passed
started_at: "2026-09-27T01:36:51.877Z"
finished_at: "2026-09-27T01:37:02.665Z"
recorded_at: "2026-09-27T01:37:02.665Z"
passed: 1
failed: 0
skipped: 0
executions[1]{command,requested_pm_context_mode,pm_context_mode,workspace_context_mode,trust_reason}:
node scripts/run-tests.mjs test -- tests/integration/merge-fence-version-skew.integration.spec.ts,schema,schema,source,local_source_ref
- run_id: test-local-muj7opjs-mdcpnq
kind: test
status: passed
started_at: "2026-09-27T02:40:35.690Z"
finished_at: "2026-09-27T02:40:47.704Z"
recorded_at: "2026-09-27T02:40:47.704Z"
passed: 1
failed: 0
skipped: 0
executions[1]{command,requested_pm_context_mode,pm_context_mode,workspace_context_mode,trust_reason}:
node scripts/run-tests.mjs test -- tests/integration/merge-fence-version-skew.integration.spec.ts,schema,schema,source,local_source_ref
docs[3]{path,scope}:
CHANGELOG.md,project
docs/generated/REFUSAL_CLOSURE_CENSUS.md,project
docs/TESTING.md,project
close_reason: Nested tracker merge fences are preserved and strict health detects missing active mappings.
escape_class: production_defect
gate_evidence:
disposition: gate_strengthened
owner: pm-kynkl8
gate_id: merge-fence-active-tracker-ownership
negative_control: "node scripts/run-tests.mjs test -- tests/integration/merge-fence-version-skew.integration.spec.ts against the pre-fix merge installer: nested init loses root merge=pm-item-toon and strict health passes"
local_checks[3]: node scripts/run-tests.mjs test -- tests/integration/merge-fence-version-skew.integration.spec.ts,node scripts/run-tests.mjs coverage,"pnpm quality:static"
hosted_checks[2]: CI / Gates (static),CI / Gates (coverage)
body: ""
Loading
Loading