Skip to content

fix(claude-code): harden concurrent action correlation - #92

Merged
SignalLayerLabs merged 2 commits into
SignalLayerLabs:mainfrom
adity982:fix/issue-58-claude-correlation
Sep 24, 2026
Merged

SignalLayerLabs merged 2 commits into
SignalLayerLabs:mainfrom
adity982:fix/issue-58-claude-correlation

Conversation

@adity982

Copy link
Copy Markdown
Contributor

Summary

  • validate Claude/hook completions against the pending action's stable session, call, tool, and turn identities before consuming the proposal
  • preserve the legitimate pending action when a malformed or cross-wired completion arrives
  • add adversarial interleaving coverage proving two identical tool calls with different turns settle independently and out of order

Validation

  • focused HookSessionRuntime suite: 15 passed
  • Claude Code + HookKit integration suites: 133 passed; one existing spawned-service test fails on this Windows host because its subprocess PATH is hard-coded to Unix paths
  • Ruff format check: passed
  • Ruff lint: passed
  • git diff --check: passed
  • mypy was unavailable in the active Python environment

The original cross-wired completion no longer removes the legitimate proposal; the regression test then settles both real completions successfully. Existing completions with engine-enriched tool input remain compatible because correlation uses only stable identity fields.

Closes #58

@SignalLayerLabs
SignalLayerLabs marked this pull request as ready for review September 21, 2026 05:53
@SignalLayerLabs
SignalLayerLabs self-requested a review as a code owner September 21, 2026 05:53

@SignalLayerLabs SignalLayerLabs left a comment •

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for your contribute, I only require you to fix the CI issue and then we are going to publish it on the repo

Signed-off-by: Aditya Datta <crazyme07071996@gmail.com>
@adity982

Copy link
Copy Markdown
Contributor Author

Fixed the CI issue on signed head fd89dad by regenerating the checked-in Codex runtime archive and provenance with the repository's scripts/build_codex_plugin.py. The branch source change had made that deterministic artifact stale.

Validation on the pushed head:

  • scripts/build_codex_plugin.py --check: passed
  • focused Claude correlation + runtime provenance tests: 16 passed
  • Ruff format check: 214 files already formatted
  • Ruff lint: passed
  • git diff --check: passed

The broader local plugin slice had 24 passed / 1 skipped; three additional plugin subprocess tests hit Windows/Python 3.14-only timeout/access-violation behavior. The GitHub Linux matrix is the authoritative full-suite check and has restarted on this head.

@SignalLayerLabs
SignalLayerLabs merged commit e2084ef into SignalLayerLabs:main Sep 24, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

claude-code: harden concurrent and subagent evidence isolation

2 participants