Skip to content

fix(cli): make repair rollback state verifiable - #27

Closed
felirami wants to merge 7 commits into
mainfrom
p0/repair-transaction-safety
Closed

felirami wants to merge 7 commits into
mainfrom
p0/repair-transaction-safety

Conversation

@felirami

@felirami felirami commented Jul 27, 2026 •

Copy link
Copy Markdown
Owner

Status: ready for maintainer merge decision. Exact head 34360f6a92242e0feb808006882d509d12da65b2 preserves explicit invalid terminal flags and rejects own non-boolean markers before verification. Exact-head remote gates, independent review, and GitHub CI pass.

Summary

This updates the repair-safety candidate with the remaining fail-closed execution boundaries found during release review.

  • rejects missing, null, malformed, timed-out, aborted, signaled, truncated, and nonzero apply results
  • preserves process-boundary metadata through catalog adapters instead of reducing results to status === 0
  • defaults terminal flags only when absent, preserving explicit null/undefined for fail-closed classification
  • routes known catalog repairs through the transactional engine before any legacy fallback
  • returns immediately after an engine-confirmed repair so legacy code cannot execute the same repair twice
  • prevents a later healthy gateway probe from overwriting a failed restart result
  • keeps unsafe bulk repair disabled unless every item receives preflight, preview, apply, rollback, and verification semantics

Safety contract

A repair is reported as applied only after an unambiguous successful apply result and post-apply verification. Execution ambiguity is failure, not success. Rollback and result evidence remain bounded and do not expose generated token values.

Validation

Exact candidate head: 34360f6a92242e0feb808006882d509d12da65b2

  • Node suite: 472/472 passed
  • focused repair engine/catalog suite: 108/108 passed
  • Remediation contracts: 7/7 passed
  • Repair validation: 50 scripts, 0 blockers
  • npm audit --omit=dev: 0 vulnerabilities
  • source archive SHA-256: b10aea25f19e1ca3fe278bc0a90688924d2d14a8709ec1f6fe007d3b82df0d0a
  • disposable-host gate exited 0; cleanup and empty provider inventory were verified
  • exact-head GitHub CI passed: https://github.com/arcabotai/clawfix/actions/runs/30725309323
  • Syntax, diff, exact-head, and clean-worktree gates passed

Fresh independent exact-head static review: READY, no findings.

No deployment, merge, npm publication, GitHub release, or production mutation is part of this PR update.

Felirami added 2 commits July 27, 2026 13:28
Distinguish unreadable config from empty values, block repairs with unknown starting state, record partial mutations, and roll back every post-change failure.

Co-authored-by: Felirami <feli@arcabot.ai>
Signed-off-by: Felirami <feli@arcabot.ai>
Co-authored-by: Felirami <feli@arcabot.ai>
Signed-off-by: Felirami <feli@arcabot.ai>
@felirami
felirami marked this pull request as ready for review July 27, 2026 14:15
@felirami
felirami requested a review from arcabotai as a code owner July 27, 2026 14:15
Cad from Arca added 5 commits August 1, 2026 21:42
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
@arcabotai arcabotai mentioned this pull request Aug 2, 2026
@arcabotai

Copy link
Copy Markdown
Owner

Superseded by merged release PR #26, which contains the final repair transaction-safety implementation and release evidence. Do not merge this branch separately.

@arcabotai arcabotai closed this Aug 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants