Skip to content

fix(doctor): report stored settings the pin leaves unapplied - #2813

Merged
ScriptedAlchemy merged 1 commit into
masterfrom
fleet/audit-leftovers-truth
Oct 1, 2026
Merged

ScriptedAlchemy merged 1 commit into
masterfrom
fleet/audit-leftovers-truth

Conversation

@ScriptedAlchemy

Copy link
Copy Markdown
Owner

Refs #2514, #2728.

Root cause

The daemon Doctor kernel's configuration read (configuration_read_from_pin) answered InSync for every pinned snapshot by assumption. #2728 made a stored index pattern the pin leaves unapplied a typed finding (setting_findings), but only ConfigurationGet and a CLI-only check in tracedecay doctor consulted it. The canonical report (MCP, dashboard and the CLI's "Canonical Doctor findings") still printed configuration: effective configuration matches the resolved authority (configuration.resolved.in-sync) beside the CLI's own issue line: two authorities that contradicted each other.

Change

  • ConfigurationDriftV1::Unapplied(Vec<UnappliedConfigurationSettingV1>): the kernel read runs setting_findings (the fix(config): report uncompilable stored index patterns #2728 authority) over the pinned snapshot; any finding makes the read Unapplied. The mapper emits a degraded configuration.resolved.unapplied finding naming the key, pattern, compiler message and the repair.
  • Deleted the CLI-only check_project_index_paths: the canonical finding is now the single authority and the CLI renders it as an issue (exit code 1 via the existing degraded → issue mapping), so the defect is counted once.
  • The kernel read types are not on a generated wire (no contracts/SDK regeneration).

Fails on origin/master (test kept, production files from origin/master)

---- doctor_kernel::tests::configuration_finding_reports_a_stored_pattern_the_pin_leaves_unapplied stdout ----
assertion `left == right` failed
  left: (HealthyCompleteCoverage, "configuration.resolved.in-sync", "effective configuration matches the resolved authority")
 right: (Degraded, "configuration.resolved.unapplied", "index.exclude.v1 stores pattern \"src/[abc\" that does not compile (unclosed character class; missing ']'); indexing runs without it. Set index.exclude.v1 to patterns that compile or unset it (tracedecay_configuration_set / tracedecay_configuration_unset)")

The test pairs the unapplied pin with a clean pin (docs/** only) that must still read in-sync.

Runtime journey (debug CLI from this branch, isolated HOME, capped daemon scope)

Healthy profile, branch daemon + tracedecay doctor (exit 0):

  ✔ configuration: effective configuration matches the resolved authority (configuration.resolved.in-sync)
6 warning(s), no issues.
doctor_exit=0

Seeding the legacy state: beta.63 (the last release that stored patterns unchecked) accepted index.exclude.v1 = ["src/[abc","docs/**"] in an isolated profile, but this branch (like origin/master since #2747) refuses that beta.63 profile with a typed reset (Store profile authority requires reset ... graph_scopes has an incompatible number of columns ... run tracedecay wipe --all --yes), and the current write path refuses the pattern (tracedecay_configuration_set refused the request (configuration.invalid_request)). So no master-readable profile can hold the state today; the falsifiable evidence is the kernel test above. Forging the stored revision digests to seed it was deliberately not done.

Verification

  • cargo test -p tracedecay-daemon-service -p tracedecay-contracts -p tracedecay --lib doctor: 9 + 35 + 39 passed
  • cargo test -p tracedecay-contracts --test contracts_suite doctor: 14 passed
  • cargo clippy -p tracedecay-contracts -p tracedecay-daemon-service -p tracedecay --all-targets -- -D warnings: clean
  • cargo fmt --all -- --check: clean; ripwire --quality-delta and --edit-check on the changed symbols: no contract change, no pre-existing symbol made worse.

@changeset-bot

changeset-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: d0c0768

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@ScriptedAlchemy
ScriptedAlchemy merged commit 838a4db into master Oct 1, 2026
5 of 7 checks passed
@ScriptedAlchemy
ScriptedAlchemy deleted the fleet/audit-leftovers-truth branch October 2, 2026 00:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant