diff --git a/docs/plans/2026-10-04_queue-follow-ups.md b/docs/plans/2026-10-04_queue-follow-ups.md new file mode 100644 index 00000000..1dc08bf0 --- /dev/null +++ b/docs/plans/2026-10-04_queue-follow-ups.md @@ -0,0 +1,90 @@ +# Queue follow-ups from rows 12, 13 and 31 + +Brief for one queue row under #1508. Written by Sage on 2026-10-04. It +collects four small items from `docs/plans/DEFERRED.md`, all found in +review, all confined to the queue package and `scripts/queue-commit.sh`. +The two ledger items there (the metric call can orphan curl, a missing +`timeout` reads as a Gitea failure) wait for row 32, which owns the ledger +files. + +## Queue: genesis owner-not-reviewer check, assign wording, queue-commit HEAD-moved message, calendar dates, cold-start flake + +### Problem + +Four DEFERRED items and one unexplained test failure: + +1. **Genesis skips the owner-not-reviewer rule.** Row 31 (bb2fa970) made + `add`, `set reviewers` and `assign` refuse a row's owner as its reviewer. + A genesis map can still create that row. Filbert, row 31 r1, #1508 + comment 26629. +2. **The assign refusal calls the seat "owner" too early.** The message + calls the seat the owner before the assign makes it one. Same source. +3. **queue-commit.sh blames the guard when HEAD moves.** The canary reads H + into its index (`scripts/queue-commit.sh`, `guard_check`, the + `read-tree "$h"` line). The hook diffs against the live HEAD. If another + queue commit moves the branch after H is recorded, the clean canary + fails and the script says "git is not running the queue guard as + installed". That message is wrong, and the fix it prints does nothing. + The refusal itself is correct. Filbert, row 12 live round. +4. **The queue validator checks a date's shape, not the calendar.** + `ISO_RE` and `DATE_RE` accept month 13, and V8 turns 2026-02-30 into + March 2 without an error. The CLI can't write such a value today. A hand + edit or a future verb could. Filbert and Darkwing, Piece E r2. +5. **One queue test failed once on a cold start.** Darkwing's first run of + the D candidate in a fresh clone gave 141 passed and 1 failed, and nobody + captured which test failed. 15 reruns passed. The suspected cause is the + 300 ms deadline case in the transport test, but that isn't confirmed. + +### Owner and reviewer + +- Owner: filbert, who found items 1 to 4. +- Reviewer: darkwing. + +### Files owned + +- `packages/queue/src/*.mjs` +- `packages/queue/tests/` (new or changed test files and fixtures) +- `packages/queue/README.md` +- `scripts/queue-commit.sh` +- `scripts/test-queue.sh`, only if a check moves there +- `docs/plans/DEFERRED.md`, to close the items this row fixes + +### What ships + +1. `genesis` refuses a map row whose owner is among its reviewers. Like + every other genesis refusal, it exits 2 and writes nothing. Test it. +2. The assign refusal names the seat as the proposed owner, for example + "can't assign row N to SEAT: SEAT is one of its reviewers". Update the + test that matches the message. +3. `guard_check` compares the live HEAD with H before the canary. If they + differ, it refuses with exit 2: "HEAD moved since H was recorded + (another queue commit landed); run queue-commit.sh again". The + guard-tampering message stays for a real guard failure. Test both paths + in a scratch repository. +4. Every date the validator accepts round-trips. Parse it, format it back, + and refuse the value if the result differs. That catches month 13, day + 32 and 2026-02-30 for both `ISO_RE` and `DATE_RE` fields. Test each one, + plus a leap day that's valid (2028-02-29) and one that isn't (2027-02-29). + The live log (rev 40 or later) must still replay cleanly. +5. Run `node --test packages/queue/tests/` 20 times from cold, each time in + a fresh clone or export, and record the pass counts. + - If a failure shows up, capture the test name and fix the cause in this + row. + - If nothing fails, close the DEFERRED item as "not reproduced in 20 cold + runs" with the counts. Keep the 300 ms deadline test as it is. + +`node --test packages/queue/tests/` passes. `bash scripts/test-queue.sh` +gives 27/0 on an export and 29/0 in the canonical checkout. + +### Out of scope + +- The two ledger items in DEFERRED. They wait for row 32. +- Any change to who may run which verb, the review flow, or the log format. +- Existing rows. None has its owner as a reviewer or an invalid date, so + nothing needs migrating. + +### Gate + +Darkwing approves through the queue (`queue review record`). Then Sage +commits the candidate, and the suites above must pass on it. `queue verify +--current` must be ok afterwards.