You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Add foreign rebase conflict engine boundary - #138
route missing-ledger and explicit unowned rebase conflicts through an injected, deadline-bound resolver and enforce exact ordinary conflict-file writes
persist agent-resolved foreign provenance across rewrite/recovery and keep those lines Unplanned with a visible conflict resolved by agent label
make that provenance review-significant while preserving legacy choice keys and approval fingerprints for ordinary segments
harden the resolver boundary with pinned replay state, batched raw-path auditing, gitlink refusal/auditing, and original cancellation reasons
bound rebase-state directory enumeration before retaining names and reject already-expired conflict-resolution work before entering the resolver
document the safety boundary: the production rebase-fix container adapter remains intentionally unwired until it can own storage durably under the active rebase marker
focused F4/recovery/store suite — 265 passed, 1 skipped
targeted latest regressions — 3 passed
npm run test:browser — 66 passed
exact-head CI — all three jobs passed (test 4m28s, test 3m57s, real-docker 19m01s)
local Docker project: not verified; the local Docker daemon stopped responding during image build, so Docker evidence comes from CI
Review rounds
Independent review found provenance missing from choices/approvals, adjacent lines merging mismatched provenance, and explicit-null recovery normalization. Fixed with regressions.
Independent review found ordinary review identities had lost backward compatibility. Fixed by serializing the new field only when true, with legacy-shape regressions.
Independent full pass found no new issues.
Final ordering check after moving ledger validation before Git/process work found no new issues.
Copilot found four issues: missing submodule guard, rejection of clean siblings in multi-file commits, masked cancellation reasons, and inaccurate callback-path documentation. Fixed, replied, and resolved with failing-before regressions.
Independent review found an index-only gitlink pointer escape. Fixed with raw gitlink-state hashing and unchanged/mutated regressions.
Independent review found mutable HEAD, allowed gitlink-conflict ambiguity, undersized path transport, and literal U+FFFD rejection. Fixed by pinning HEAD, routing gitlink conflicts to manual review, sharing explicit bounds, and using fatal raw-byte decoding.
Full-function reread and independent review found mutable rebase-control state and an allowed-file-to-embedded-repository conversion. Fixed with a byte-exact rebase-state digest, post-stage gitlink audit, and failing-before regressions.
Independent review found an unbounded per-path outside-file audit. Fixed with one batched, bounded, killable helper. Its shared-Git-metadata scenario was declined because the callback is trusted host orchestration, not agent code; the production adapter remains unwired and is required to expose only bounded lane-D storage, never the host worktree or shared Git metadata.
Independent full pass on d4ec5de found no actionable issues under that documented trust boundary.
Fresh Copilot review on d4ec5de found unbounded rebase-state name enumeration and an already-expired deadline that could enter the resolver. Fixed with fail-closed enumeration budgets and synchronous deadline admission, with regressions.
Independent full pass over all 19 changed files, including the round-11 fixes, found no actionable issues. Focused tests, typecheck, and diff check passed.
Fresh Copilot review on 2005f96 found that the deadline regression expired at the resolver eligibility check rather than resolver admission. Fixed by delaying expiry until the second resolver lookup and asserting that lookup occurred.
Independent full pass and mutation analysis confirmed the corrected regression reaches admission, passes the fix, and fails the pre-fix 0 ms timer path. No new actionable issues.
Fresh Copilot review on aee9851 found a symlink-ancestor escape, missing runtime validation of the ledger origin enum, and synchronous resolver fulfillment/rejection that could outrun its timer. Fixed with failing-before regressions.
Independent full pass over all 19 changed files found no new issues. It confirmed raw-byte ancestor rejection occurs before outside-file reads, malformed origins fail before Git, and both resolver settlement paths preserve deadline failure.
Fresh Copilot review on 8123477 found regular index-only changes missing from the outside-state audit and a conflict-path diff without the submodule guard. Fixed with a cached diff union, --ignore-submodules=all, and failing-before regressions.
Independent review found rename detection could collapse two different identical-content source deletions to one destination-only digest. Fixed both scans with --no-renames; the final full pass found no further issues.
Fresh Copilot review on e542a1a had no inline findings but found summary-only unbounded retention in the gitlink/index record splitter. Fixed by checking the entry budget before each retained view.
Independent full pass over all 19 changed files found no new issues, including the splitter boundary and all recent raw-path/digest/lifecycle fixes.
Fresh Copilot review on 0b41b4e returned no findings and no inline comments. Its general final-human-review note introduced no concrete defect.
Review lesson audit
Covered by existing AGENTS.md rules: missing submodule guards, gitlink pointer/embedded-repository escapes, mutable replay state, symlink ancestors, raw-byte path handling, and trust-root checks are covered by Agent-controlled content and Owned host and Docker resources.
Covered by existing AGENTS.md rules: masked cancellation, already-expired and synchronously outrun deadlines, and bounded/awaited subprocess settlement are covered by Async jobs and polling, Required race regressions, and Guarded external actions.
Covered by existing AGENTS.md rules: unbounded outside-path, rebase-state-name, and index-record retention are covered by the fail-closed bounded safety scan and aligned payload-limit rules under Guarded external actions.
Covered by existing AGENTS.md rules: malformed ledger origins, missing/explicit-null identity distinctions, approval/provenance staleness, and index-only state omissions are covered by the authorization-metadata, coupled-lifecycle, replacement-generation, and separate-state-holder rules.
Covered by existing AGENTS.md rules: the deadline fixture that originally missed resolver admission is covered by Review readiness, which requires disputed intermediate state and production-faithful setup.
One-off implementation findings, now regression-covered: adjacent provenance merging, legacy review-identity serialization, clean siblings in multi-file commits, callback-path wording, gitlink-conflict ambiguity, rename detection collapsing identical-content paths, and the regular index-only digest omission. These are local representation/contract defects rather than reusable missing policy.
Declined as one-off boundary hypothesis: mutation of shared Git metadata by the injected callback. The callback is trusted host orchestration, the production adapter remains unwired, and its eventual implementation is constrained to bounded lane-D storage rather than the host worktree or shared Git metadata.
No new AGENTS.md rule is required: every reusable lesson is already stated by the cited rules; the remaining findings are implementation-specific and have targeted regressions.
Abort synchronously when the work deadline has elapsed
runner/rebase.ts:427
If the work deadline has already elapsed here, a 0 ms timer is deferred to a later timers turn, so throwIfAborted() still passes and the resolver is invoked after its deadline. Abort synchronously when no budget remains, and add a controllable-clock regression proving the callback is not entered in this case.
Copilot round 2 is addressed in 2005f96. The inline enumeration finding is fixed and resolved. The summary-only deadline finding is also fixed: if the conflict-resolution work deadline is already exhausted, the resolver is synchronously aborted before its callback is entered. The regression controls the clock at resolver lookup and asserts zero callback entries. Fresh independent full-diff review found no new issues.
The runtime validator treats every non-owned value as the foreign branch, so a deserialized entry such as { origin: 'typo', owner: null } passes as a trusted ledger entry. Validate the origin enum explicitly so malformed ledger data fails before any Git or process work begins.
Recheck deadline after resolver completion
runner/rebase.ts:426
A synchronous resolver can block past workDeadline and then resolve successfully: while it blocks, the timer cannot run, and the await continuation clears that timer before the timers phase. Recheck the monotonic deadline immediately after both resolver fulfillment and rejection, aborting with deadlineError() before throwIfAborted(), so expired work cannot be accepted.
Copilot round 4 is addressed in 8123477. In addition to the resolved symlink-ancestor thread, runtime ledger validation now accepts only the explicit owned/foreign enum values before any Git work, and conflict resolution rechecks its monotonic deadline after both fulfillment and rejection so a synchronous blocker cannot outrun the timer. Four regressions failed before and pass after. Independent round 15 found no new issues across the full diff.
This conflict-path git diff lacks the explicit submodule guard used by the surrounding conflict probes and outside-file audit. A populated submodule can make Git inspect nested repository state while processing resolver-controlled content; pass --ignore-submodules=all on this invocation too.
Copilot round 5 is addressed in e542a1a. The inline cached-index gap is fixed and resolved. The summary-only conflict-path finding is also fixed: that exact Git diff now passes --ignore-submodules=all, with an argv-level regression. Independent review additionally found and verified the --no-renames digest-collision fix; its final full pass found no further issues.
MAX_INDEX_ENTRIES is enforced only after split0() has retained the entire listing. A valid 32 MiB staged listing can contain well over 262,144 short records, so the new repeated gitlink audit can allocate hundreds of thousands of extra Buffer views before failing the advertised entry bound. Enforce the limit before appending each record.
Copilot round 6 summary-only finding is addressed in 0b41b4e. Index record splitting now enforces the entry limit before retaining each Buffer view; the post-allocation length checks were removed. A small-limit regression exercises the admission boundary. Independent round 19 reread the full diff and found no further issues.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
conflict resolved by agentlabelrebase-fixcontainer adapter remains intentionally unwired until it can own storage durably under the active rebase markerValidation
Validated head:
0b41b4ed4eeb45fc8b28a8858e3e4a7dc1958c44git diff --checknpm run typechecknpx vitest run --project parallel— 69 files, 1,774 passed, 1 skippednpm run test:browser— 66 passedtest4m28s,test3m57s,real-docker19m01s)Review rounds
HEAD, allowed gitlink-conflict ambiguity, undersized path transport, and literal U+FFFD rejection. Fixed by pinningHEAD, routing gitlink conflicts to manual review, sharing explicit bounds, and using fatal raw-byte decoding.d4ec5defound no actionable issues under that documented trust boundary.d4ec5defound unbounded rebase-state name enumeration and an already-expired deadline that could enter the resolver. Fixed with fail-closed enumeration budgets and synchronous deadline admission, with regressions.2005f96found that the deadline regression expired at the resolver eligibility check rather than resolver admission. Fixed by delaying expiry until the second resolver lookup and asserting that lookup occurred.aee9851found a symlink-ancestor escape, missing runtime validation of the ledger origin enum, and synchronous resolver fulfillment/rejection that could outrun its timer. Fixed with failing-before regressions.8123477found regular index-only changes missing from the outside-state audit and a conflict-path diff without the submodule guard. Fixed with a cached diff union,--ignore-submodules=all, and failing-before regressions.--no-renames; the final full pass found no further issues.e542a1ahad no inline findings but found summary-only unbounded retention in the gitlink/index record splitter. Fixed by checking the entry budget before each retained view.0b41b4ereturned no findings and no inline comments. Its general final-human-review note introduced no concrete defect.Review lesson audit
AGENTS.mdrules: missing submodule guards, gitlink pointer/embedded-repository escapes, mutable replay state, symlink ancestors, raw-byte path handling, and trust-root checks are covered by Agent-controlled content and Owned host and Docker resources.AGENTS.mdrules: masked cancellation, already-expired and synchronously outrun deadlines, and bounded/awaited subprocess settlement are covered by Async jobs and polling, Required race regressions, and Guarded external actions.AGENTS.mdrules: unbounded outside-path, rebase-state-name, and index-record retention are covered by the fail-closed bounded safety scan and aligned payload-limit rules under Guarded external actions.AGENTS.mdrules: malformed ledger origins, missing/explicit-null identity distinctions, approval/provenance staleness, and index-only state omissions are covered by the authorization-metadata, coupled-lifecycle, replacement-generation, and separate-state-holder rules.AGENTS.mdrules: the deadline fixture that originally missed resolver admission is covered by Review readiness, which requires disputed intermediate state and production-faithful setup.AGENTS.mdrule is required: every reusable lesson is already stated by the cited rules; the remaining findings are implementation-specific and have targeted regressions.Remaining #22 work
rebase-fixchild-attempt/storage lifecycleDoes not close #22.