You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
F: publish only ledger-recorded commits (snapshot head may hold others) #113
From the #103 review (PR #110). The publisher pushes snapshot.head, and for a review the snapshot head can come from the user's checkout (runner/review.ts). GitBranchPusher only checks that the remote branch's current commit is ledger-owned, before it overwrites the branch. It does not check the commits being pushed. So commits the ledger does not record can reach the codeboost/ branch and the PR. These could be the user's own local commits, or an unrelated commit like the demo's "Unrelated diagnostic output". Otherwise, the push fails with "the runner repository has no commit".
This overlaps #22: rebasing writes foreign ledger entries. When #22 lands, ownedCommits must also be revisited (finding 4 of the #101 review).
Needed
Decide which head a task publishes: the runner's last commit, or the snapshot head checked against the ledger.
Before pushing, refuse a head whose base..head range holds a commit the ledger does not record as owned, unless a person accepted it.
Decision, made 2026-10-03: keep publishing the whole task head, as the design intends. Implemented in PR #119, which is stacked on #110.
What a task's head contains. First the user's own branch (base..HEAD), which the review records before the runner makes its first commit. Then the runner's commits on top.
How the user's commits are handled. The ledger has no entry for them, so they count as foreign. Review shows their changes in the Unplanned row, and the merge gate blocks until each one is assigned or accepted.
Why
From the #103 review (PR #110). The publisher pushes
snapshot.head, and for a review the snapshot head can come from the user's checkout (runner/review.ts).GitBranchPusheronly checks that the remote branch's current commit is ledger-owned, before it overwrites the branch. It does not check the commits being pushed. So commits the ledger does not record can reach thecodeboost/branch and the PR. These could be the user's own local commits, or an unrelated commit like the demo's "Unrelated diagnostic output". Otherwise, the push fails with "the runner repository has no commit".This overlaps #22: rebasing writes
foreignledger entries. When #22 lands,ownedCommitsmust also be revisited (finding 4 of the #101 review).Needed
base..headrange holds a commit the ledger does not record asowned, unless a person accepted it.Tests
🤖 Generated with Claude Code