RT-195/RT-196: watchdog open-gate exemption, mid-run trust accept off by default - #305
Conversation
… by default RT-195: evaluateJob's modal branch had no exemption for a job already at a gate. A blocked-looking pane whose job is at-gate/at-milestone is a human taking their time on a form or milestone -- the single most common healthy wait state in a herd, not a trust modal -- and previously misfired into a park, an un-rate-limited "trust modal" notification, and a shepherd poke. Same AWAITING_ANSWER exemption the backstop already uses. herd-watchdog.test.ts:150 pinned the wrong behavior; flipped, plus a new case for a human taking 3 minutes on a form. RT-196: the mid-run trust-accept driver (the watchdog's own acceptTrustModal, distinct from the spawn-path driver) matches the folder-trust dialog header against the whole screen with no boundary, and has no way to confirm the dialog names the job's own worktree -- herdr exposes no pane-cwd data, and the real dialog's screen text never names a folder either, so that comparison cannot be made airtight tonight. Worst case: a working session shows an unrelated permission prompt with the same numbered-options shape, and the daemon presses Enter on it unattended. New herd.watchdog.midRunTrustAccept setting, off by default, gates the mid-run accept attempt; the spawn-path driver (a fresh pane can only be showing the trust dialog) is untouched. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…t key The exhaustive registry-key inventory test wasn't updated for RT-196's new setting, which would have failed CI (packages is in the test script). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (6)
Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📝 WalkthroughWalkthroughThe watchdog adds a disabled-by-default ChangesWatchdog trust acceptance
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant Registry as rt-client registry
participant Resolver as readWatchdogConfig
participant Watchdog as herd-watchdog
participant Job
participant TrustAcceptance as trust acceptance
Registry->>Resolver: provide midRunTrustAccept
Resolver->>Watchdog: return WatchdogConfig
Watchdog->>Job: evaluate modal state
Job-->>Watchdog: gate, milestone, or modal status
alt enabled and tree is provisioned
Watchdog->>TrustAcceptance: attempt trust acceptance
else disabled or not provisioned
Watchdog->>Job: park and notify
end
Merge Risk: ⚪ Minimal · up to The opt-in setting defaults to disabled and the described fallback behavior remains intact. No actionable merge-blocking risk is identified. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
… by default (#305) * watchdog: RT-195 open-gate modal exemption, RT-196 mid-run accept off by default RT-195: evaluateJob's modal branch had no exemption for a job already at a gate. A blocked-looking pane whose job is at-gate/at-milestone is a human taking their time on a form or milestone -- the single most common healthy wait state in a herd, not a trust modal -- and previously misfired into a park, an un-rate-limited "trust modal" notification, and a shepherd poke. Same AWAITING_ANSWER exemption the backstop already uses. herd-watchdog.test.ts:150 pinned the wrong behavior; flipped, plus a new case for a human taking 3 minutes on a form. RT-196: the mid-run trust-accept driver (the watchdog's own acceptTrustModal, distinct from the spawn-path driver) matches the folder-trust dialog header against the whole screen with no boundary, and has no way to confirm the dialog names the job's own worktree -- herdr exposes no pane-cwd data, and the real dialog's screen text never names a folder either, so that comparison cannot be made airtight tonight. Worst case: a working session shows an unrelated permission prompt with the same numbered-options shape, and the daemon presses Enter on it unattended. New herd.watchdog.midRunTrustAccept setting, off by default, gates the mid-run accept attempt; the spawn-path driver (a fresh pane can only be showing the trust dialog) is untouched. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * settings/registry.test.ts: pin the new herd.watchdog.midRunTrustAccept key The exhaustive registry-key inventory test wasn't updated for RT-196's new setting, which would have failed CI (packages is in the test script). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Two tag-gating fixes from Greg's pre-tag safety audit.
herd.watchdog.midRunTrustAcceptsetting, off by default, gates the mid-run accept attempt; the spawn-path driver (a fresh pane can only be showing the trust dialog) is untouched.RED-first for both; fable-reviewed (found and fixed a red
bun testgap in the registry key inventory test).🤖 Generated with Claude Code
Summary by CodeRabbit
New Features
Bug Fixes