Repository navigation
fix: harden handoff execution integrity - #130
Open
stanleyrprose wants to merge 9 commits into
Open
stanleyrprose wants to merge 9 commits into
stanleyrprose wants to merge 9 commits into
Conversation
Author
|
Implementation/review update for exact head
|
Author
|
Cross-platform CI update for exact head A CI-only mirror PR in the fork was used because upstream fork checks remained unstarted. After re-registering the fork's existing CI workflow (no code/workflow-content change), run
The CI-only fork PR has now been closed without merge. Upstream PR #130 remains the canonical integration PR; no upstream merge or npm publish was performed. |
Add a read-only resolved revision, branch, dirty-state, and stable workspace fingerprint projection without changing permissions or execution behavior.
Bind generated handoff plans to plan hash, Git revision, stable workspace identity, and non-.ai-bridge worktree state. Reject stale baselines before launching the local agent and expose reconcile-required evidence without changing legacy handoffs or bounded loop semantics.
fix: preserve workspace ids across rotated MCP sessions
fix: make workspace handles restart-stable
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Harden long/cross-agent handoff execution around two concrete failure modes observed in a real SignalForge run: stale in-flight receipts after executor termination and unintended remote Git/GitHub mutation before review.
What changes:
execute-handoffnow publishes parent/child PIDs and records non-terminalinterruptingwhile SIGINT/SIGTERM child termination is in progress; terminalinterruptedis written only after the child has actually exited.child.killedflag as proof of process exit; stubborn children that ignore SIGTERM escalate to SIGKILL.execution_outcome=unknownandreconcile_required=true.wait_for_handoffkeeps reporting an in-flight state if the recorded child executor is still alive even when the parent is gone; only when both recorded parent and child are gone does it deriveorphanedand require reconciliation.git push/send-pack push paths andghare blocked; common GitHub token env vars are not inherited.--allow-remote-mutationsexplicitly restores the previous behavior.Scope intentionally excluded: no persistent PTY/job management, workflow service, DB, queue, new MCP, npm release, or publish.
Verification on macOS from baseline
587f7fd3a4644a847bba13aeb49336056052e1f6, final head77b56d4512a5aa8cc081db67aa7cb94ce140f0da:npm ci— success (registry currently reports 2 moderate + 1 high dependency advisories; not introduced by this change)npm run build— PASSnode scripts/execute-handoff-smoke.mjs— PASSnode scripts/smoke.mjs— PASSnpm run smoke— PASSnpm run stress— PASSgit diff --check— PASSNew regression coverage includes:
git pushblocked and explicit opt-in allowed against a local bare remote;interrupting, then terminalinterruptedonly after a stubborn child is actually terminated;