Skip to content

chore(gates): enforce session patch and record-copy ownership - #3155

Open
thymikee wants to merge 1 commit into
fix/session-admission-reviewfrom
chore/session-state-write-ownership
Open

thymikee wants to merge 1 commit into
fix/session-admission-reviewfrom
chore/session-state-write-ownership

Conversation

@thymikee

@thymikee thymikee commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

Summary

Session field ownership now covers named SessionStore.update patches and whole-record copies, including the capture-admission adapter. Opaque, computed, spread, async and reentrant patches fail R7. Only the store and three declared draft constructors may copy a whole session.

The same scanner measures baseline and head: 24 written fields remain, with owner/module claims reduced from 35 to 32. No ratchet or baseline was raised.

Three tooling files changed. Part of #3116, stacked on #3154.

Validation

Validated 54e813a807: 44 scanner/model tests and the complete layering gate pass. Nineteen new controls fail against the previous scanner. Six real planted regressions—including aliased/destructured app-log copies and foreign-owner writes—fail R7; original production bytes were restored.

pnpm check:affected --base fix/session-admission-review --run passes every selected runnable check. Lint, typecheck and Fallow pass. Local alias controls failed before their fix. Independent read-only review found alias gaps; their controls now pass, and re-review found no remaining findings. CI is pending; this tooling layer does not change a device route.

@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Size Report

Metric Base Current Diff
Installed (including dependencies) 4.96 MB 4.96 MB 0 B
Package (unpacked) 4.96 MB 4.96 MB 0 B
Package (download) 1.49 MB 1.49 MB 0 B

Startup median (7 runs, lower is better):

Scenario Base Current Diff
CLI --version 28.2 ms 28.9 ms +0.7 ms
CLI --help 82.4 ms 84.5 ms +2.1 ms

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread scripts/layering/session-state.ts Outdated
Comment thread scripts/layering/session-state.ts
Comment thread scripts/layering/session-state.ts
Comment thread scripts/layering/check.ts
@thymikee
thymikee force-pushed the chore/session-state-write-ownership branch from a06cdd8 to 27315df Compare October 3, 2026 11:55

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread scripts/layering/session-state.ts
@thymikee
thymikee force-pushed the chore/session-state-write-ownership branch from 27315df to 54e813a Compare October 3, 2026 12:11

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files (changes from recent commits).

Tip: Review your code locally with the cubic CLI to iterate faster.

Re-trigger cubic

Comment thread scripts/layering/session-state.ts
@thymikee

thymikee commented Oct 3, 2026

Copy link
Copy Markdown
Member Author

I reviewed 54e813a and found no blocking problems in the code. CI is still pending: Smoke Tests is running, and it covers daemon and device routes this diff does not touch, so a failure there would be unrelated. There are no conflicts. I did not run the layering gate or the scanner tests, and I did not check every production update() call site for false positives. I relied on your report that the gate passes, and I did not verify the field and claim counts or the claim that 19 controls fail on the old scanner.

Not blocking, and you can take or leave these: restore the Catches/Evidence/Cost/Kill-criterion header in session-state.ts and update Cost to the new LOC, since the sibling rule files still carry it. The [whole-record-spread] and [patch-shape] checks at line 330 skip the declared-field filter that the isSessionBinding comment says must pair with the /session/i name test, so { ...providerSession } or any { ...x.session } under src/daemon now fails R7. A spread should count as a record copy only when its operand comes from a store read or has a SessionState type. The publishedDraft rule is also hard-coded to /session-open-state.ts, so it could move into the SESSION_DRAFT_CONSTRUCTORS entry and leave one table that defines it.

The four open Cubic threads still apply: the nested-return false positive in patchObjects, the missed copies via Object.assign, structuredClone and rest patterns, the optional-chain gap in unwrapExpression, and the computed destructure key. Please fix them, or narrow the whole-record-copy rule so that it matches what the scanner can check. Then let Smoke Tests finish.

Could a smaller design close this class of bypass instead? Cubic keeps finding one syntax form at a time, because the scanner tracks aliases by name. If SessionStore returned a readonly SessionState from get() and exposed owner-keyed update methods, a whole-record copy could not be written back except through the store. The scanner would then only check that each owner method comes from its declared module. That change to the SessionStore type, under #3116, would have to land before the scanner grows further. Would that work here?

@thymikee
thymikee added this pull request to stack #3146 October 3, 2026 13:46
@thymikee
thymikee force-pushed the chore/session-state-write-ownership branch from 54e813a to 1be1932 Compare October 3, 2026 14:41
@thymikee
thymikee force-pushed the chore/session-state-write-ownership branch from 1be1932 to 99e8d0c Compare October 3, 2026 15:16
@thymikee
thymikee force-pushed the chore/session-state-write-ownership branch from 99e8d0c to 801a4ba Compare October 3, 2026 16:41
@thymikee
thymikee force-pushed the chore/session-state-write-ownership branch from 801a4ba to 61ef999 Compare October 3, 2026 16:56
@thymikee
thymikee force-pushed the chore/session-state-write-ownership branch from 61ef999 to 624321d Compare October 3, 2026 17:49
@thymikee
thymikee removed this pull request from stack #3146 October 3, 2026 19:38
@thymikee
thymikee force-pushed the chore/session-state-write-ownership branch from 624321d to a3e7316 Compare October 3, 2026 19:39
@thymikee
thymikee added this pull request to stack #3187 October 3, 2026 19:45

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant