Repository navigation
fix(ship): a failing git status refuses instead of reading as a clean tree (CC-629 b) - #673
Merged
Merged
Conversation
…the injection check names the git failure (CC-629 b) Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011c6rVDk6zyfgLPEfbVrZi9
…on-check tests pin where the gate stops - the unable-to-read refusals carry git's first message and a remedy; the dispatched lane says nothing was committed and re-running is safe - the injection-check message says "git diff HEAD or the hash step failed" (under pipefail the failing stage may be the filter or the hash tool) - tests: the wrapper fails every call from the Nth on, the cases assert the gate stopped at that call (a handler without exit 1 is caught), all six fingerprints are covered (new after-synthesis case, before-dispatch status leg), the finish test runs only as many legs as the control has status calls Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011c6rVDk6zyfgLPEfbVrZi9
…open CC-631, CC-632 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011c6rVDk6zyfgLPEfbVrZi9
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
CC-629 group (b), the same bug class as CC-627 (#671) and CC-629 (a) (#672): a failed
git statusread as a clean tree inpmctl ship.runtime/lib/pmctl-ship.shtested[[ -n "$(git status ...)" ]](or assigned the output without looking at git's status) in these places, so a git that failed (a killed git, a damaged index, asafe.directoryrejection, an unreadable gitdir) was an empty, clean tree:ship finish(after the gate, after the full suite, immediately before the irreversible push/PR): the guard let the push through;.gitignore): the lane went on to the gate with nothing staged;ship prepare: it created its feature branch.The change
_pmctl_ship_require_clean_tree <work_dir> <dirty-message>replaces the three copy-pasted guard blocks: 0 only whengit statuscould be read and is empty; a dirty tree is refused with the same messages as before; a failed status is refused with "unable to read the worktree status (git status failed: <git's first message>) -- refusing ... Fix the repository state, or re-run if the failure was transient." The auto-commit reads andpreparegot explicit checks with the same report (_pmctl_ship_report_status_failure; it runs the status once more to get git's message, empty if it then works).pr-gate.sh: the six working-tree fingerprints of the injection check (before dispatch, after the reviewer sessions, after synthesis) print "unable to fingerprint the working tree (git diff HEAD or the hash step failed)" beforeexit 1.Correction to the CC-629 ticket text: it called the
pr-gate.shfingerprints fail-open ("both sides failing gives equal hashes"). They are not: all six statements sit at top level of the script body underset -euo pipefail(set +eappears once, in a QA helper that does not enclose them), so a failing git already stopped the gate with exit 1, silently. I verified the construct (X=$(false | sha256sum)aborts), the critic and the security review confirmed no call context suppresses errexit, andartifact_filter_porcelainends inreturn 0so it cannot mask a failinggit status. This part only adds the message; BACKLOG is corrected in this PR.No change for a working git: the dirty messages are byte-identical to main's, the status pathspec and exit codes are untouched. A plain revert is safe (nothing is persisted).
Review (critic, qa-tester, security, risk, architecture): nothing blocked; fixed here
exit 1of a pr-gate handler survived, because only the Nth call failed, the gate ran on and exited 1 later on a hash mismatch. The wrapper now fails every call from the Nth on, and the cases assert that exactly N numbered calls happened and that no "modified working tree" line appeared. Mutants killed (handler withoutexit 1at the pre-dispatch diff and the post-synthesis status).git statuscall count)..gitignoremay already carry the bookkeeping patterns); the injection-check message no longer claims git was the failing stage (under pipefail it may be the filter or the hash tool).Not in this PR
gate-git.sh(shared helper for CC-627/629a) and a sharedtests/lib/git-stub.shtest fixture (the wrapper technique now exists in five suites): own PRs, see CC-629 / CC-631 (migrating suites inside a bugfix PR is risky on a host where many suites cannot run cleanly).:(exclude).pm-dispatch-ship-finish.jsonis a prefix pathspec (a directory of that name hides its untracked files from status; the fingerprint still hashes them and trips the last guard); the fingerprint reads do not pin--untracked-files=all --ignore-submodules=none -c core.fsmonitor=false;pr-gate.sh_worktree_is_dirtyandgate-result-verify.sh~1767 readls-filesthrough$(...)in a test.Evidence
Windows (Git Bash): the three ship cases (
ship finishclean GO with every status call failed in turn, the dispatched lane's two reads,prepare) and the three pr-gate cases (injection-check-git-failure-before/after-dispatch/after-synthesis, about 3 / 2 / 2 minutes on this host) pass; real Linux (WSL): the three ship cases pass.Mutants killed: main's
pmctl-ship.sh; the guard helper ignoring the failure; each of the three guard sites reverted to the old form;pre_ensure_status,dirty_statusandprepareignoring the failure; their messages dropped; a pr-gate handler withoutexit 1.lint-shellcheck,lint-test-docstrings,lint-test-suite-registry,lint-script-domain-inventorypass. The wholetest-pmctl-ship-finish.shandtest-pr-gate.shwere not run (a few finish cases fail on this host with and without the change:gh unavailable,publish assessment).Permanent test admissions: six new cases: ship finish (case_finish_unreadable_worktree_status_refuses_push, case_finish_dispatched_lane_unreadable_status_refuses) in tests/shell/test-pmctl-ship-finish.sh, ship prepare (case_prepare_unreadable_worktree_status_refuses) in tests/shell/test-pmctl-ship.sh, and the injection check (test_injection_check_git_failure_before_dispatch_is_reported, test_injection_check_git_failure_after_dispatch_is_reported, test_injection_check_git_failure_after_synthesis_is_reported) in tests/shell/test-pr-gate.sh
🤖 Generated with Claude Code
https://claude.ai/code/session_011c6rVDk6zyfgLPEfbVrZi9