Skip to content

RT-195/RT-196: watchdog open-gate exemption, mid-run trust accept off by default - #305

Merged
m4ttheweric merged 2 commits into
mainfrom
rt-195-196
Sep 17, 2026
Merged

m4ttheweric merged 2 commits into
mainfrom
rt-195-196

Conversation

@m4ttheweric

@m4ttheweric m4ttheweric commented Sep 17, 2026 •

Copy link
Copy Markdown
Collaborator

Two tag-gating fixes from Greg's pre-tag safety audit.

  • RT-195: evaluateJob's modal branch had no exemption for a job already at a gate. A blocked-looking pane whose job is at-gate/at-milestone is a human taking their time on a form or milestone -- the single most common healthy wait state in a herd -- and previously misfired into a park, an un-rate-limited "trust modal" notification, and a shepherd poke. Same AWAITING_ANSWER exemption the backstop already uses.
  • RT-196: the watchdog's own mid-run trust-accept driver matches the folder-trust dialog against the whole screen with no boundary, and has no way to confirm the dialog names the job's own worktree (herdr exposes no pane-cwd data, and the real dialog's screen text never names a folder, so that comparison can't be made airtight tonight). Worst case: a working session shows an unrelated permission prompt with the same shape, and the daemon presses Enter on it unattended. New herd.watchdog.midRunTrustAccept setting, off by default, gates the mid-run accept attempt; the spawn-path driver (a fresh pane can only be showing the trust dialog) is untouched.

RED-first for both; fable-reviewed (found and fixed a red bun test gap in the registry key inventory test).

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added an optional watchdog setting to automatically handle mid-run folder-trust prompts on daemon-provisioned trees.
    • The setting is disabled by default and can be enabled through machine-level configuration.
    • Jobs awaiting gate or milestone responses are no longer incorrectly treated as stalled.
  • Bug Fixes

    • Improved watchdog handling for modal jobs, preserving existing park-and-notify behavior when automatic trust acceptance is unavailable.

m4ttheweric and others added 2 commits September 17, 2026 01:03
… by default

RT-195: evaluateJob's modal branch had no exemption for a job already at
a gate. A blocked-looking pane whose job is at-gate/at-milestone is a
human taking their time on a form or milestone -- the single most common
healthy wait state in a herd, not a trust modal -- and previously misfired
into a park, an un-rate-limited "trust modal" notification, and a
shepherd poke. Same AWAITING_ANSWER exemption the backstop already uses.
herd-watchdog.test.ts:150 pinned the wrong behavior; flipped, plus a new
case for a human taking 3 minutes on a form.

RT-196: the mid-run trust-accept driver (the watchdog's own
acceptTrustModal, distinct from the spawn-path driver) matches the
folder-trust dialog header against the whole screen with no boundary,
and has no way to confirm the dialog names the job's own worktree --
herdr exposes no pane-cwd data, and the real dialog's screen text never
names a folder either, so that comparison cannot be made airtight
tonight. Worst case: a working session shows an unrelated permission
prompt with the same numbered-options shape, and the daemon presses
Enter on it unattended. New herd.watchdog.midRunTrustAccept setting,
off by default, gates the mid-run accept attempt; the spawn-path driver
(a fresh pane can only be showing the trust dialog) is untouched.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…t key

The exhaustive registry-key inventory test wasn't updated for RT-196's
new setting, which would have failed CI (packages is in the test script).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 7ba686a4-4ad9-443b-b36e-177fafa023ab

📥 Commits

Reviewing files that changed from the base of the PR and between e92ca96 and 154aaac.

📒 Files selected for processing (6)
  • lib/daemon/__tests__/herd-watchdog-adapters.test.ts
  • lib/daemon/__tests__/herd-watchdog.test.ts
  • lib/daemon/herd-watchdog-adapters.ts
  • lib/daemon/herd-watchdog.ts
  • packages/rt-client/src/settings/__tests__/registry.test.ts
  • packages/rt-client/src/settings/registry-defs.ts

Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour.


📝 Walkthrough

Walkthrough

The watchdog adds a disabled-by-default midRunTrustAccept setting. It resolves this setting from the machine registry, updates modal-job evaluation, conditionally accepts trust for provisioned trees, and adds tests for these paths.

Changes

Watchdog trust acceptance

Layer / File(s) Summary
Setting and configuration resolution
packages/rt-client/src/settings/registry-defs.ts, packages/rt-client/src/settings/__tests__/registry.test.ts, lib/daemon/herd-watchdog-adapters.ts
Adds the machine-scoped herd.watchdog.midRunTrustAccept boolean with a default of false. The watchdog configuration resolver returns the setting.
Watchdog modal and trust handling
lib/daemon/herd-watchdog.ts
Adds WatchdogConfig.midRunTrustAccept. Gate and milestone waits are exempt from modal detection. Trust acceptance is attempted only when the setting is enabled and the tree is daemon-provisioned.
Watchdog behavior coverage
lib/daemon/__tests__/herd-watchdog.test.ts, lib/daemon/__tests__/herd-watchdog-adapters.test.ts
Covers configuration defaults, gate and milestone handling, trust-acceptance attempts, fallback parking, one-time attempts, non-provisioned trees, and disabled behavior.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant Registry as rt-client registry
  participant Resolver as readWatchdogConfig
  participant Watchdog as herd-watchdog
  participant Job
  participant TrustAcceptance as trust acceptance

  Registry->>Resolver: provide midRunTrustAccept
  Resolver->>Watchdog: return WatchdogConfig
  Watchdog->>Job: evaluate modal state
  Job-->>Watchdog: gate, milestone, or modal status
  alt enabled and tree is provisioned
    Watchdog->>TrustAcceptance: attempt trust acceptance
  else disabled or not provisioned
    Watchdog->>Job: park and notify
  end
Loading

Merge Risk: ⚪ Minimal · up to 154aa

The opt-in setting defaults to disabled and the described fallback behavior remains intact. No actionable merge-blocking risk is identified.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 6 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes both primary changes: the open-gate exemption and the disabled-by-default mid-run trust acceptance setting.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch rt-195-196

Comment @coderabbitai help to get the list of available commands.

@m4ttheweric
m4ttheweric merged commit 1fa920b into main Sep 17, 2026
4 checks passed
@m4ttheweric
m4ttheweric deleted the rt-195-196 branch September 17, 2026 06:29
m4ttheweric added a commit that referenced this pull request Sep 17, 2026
… by default (#305)

* watchdog: RT-195 open-gate modal exemption, RT-196 mid-run accept off by default

RT-195: evaluateJob's modal branch had no exemption for a job already at
a gate. A blocked-looking pane whose job is at-gate/at-milestone is a
human taking their time on a form or milestone -- the single most common
healthy wait state in a herd, not a trust modal -- and previously misfired
into a park, an un-rate-limited "trust modal" notification, and a
shepherd poke. Same AWAITING_ANSWER exemption the backstop already uses.
herd-watchdog.test.ts:150 pinned the wrong behavior; flipped, plus a new
case for a human taking 3 minutes on a form.

RT-196: the mid-run trust-accept driver (the watchdog's own
acceptTrustModal, distinct from the spawn-path driver) matches the
folder-trust dialog header against the whole screen with no boundary,
and has no way to confirm the dialog names the job's own worktree --
herdr exposes no pane-cwd data, and the real dialog's screen text never
names a folder either, so that comparison cannot be made airtight
tonight. Worst case: a working session shows an unrelated permission
prompt with the same numbered-options shape, and the daemon presses
Enter on it unattended. New herd.watchdog.midRunTrustAccept setting,
off by default, gates the mid-run accept attempt; the spawn-path driver
(a fresh pane can only be showing the trust dialog) is untouched.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* settings/registry.test.ts: pin the new herd.watchdog.midRunTrustAccept key

The exhaustive registry-key inventory test wasn't updated for RT-196's
new setting, which would have failed CI (packages is in the test script).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant