Skip to content

fix(config): report a corrupt profile config instead of defaults - #2820

Merged
ScriptedAlchemy merged 4 commits into
masterfrom
fleet/audit-leftovers-warn-drop
Oct 1, 2026
Merged

ScriptedAlchemy merged 4 commits into
masterfrom
fleet/audit-leftovers-warn-drop

Conversation

@ScriptedAlchemy

Copy link
Copy Markdown
Owner

Recovered from the audit-leftovers/warn-drop lane, which died in the 2026-10-01 restart; re-verified after rebasing on d363101. Covers the session-memory user_config warn-and-drop item. The lane's other items (activation failed mount, privacy-withheld reason, #2332 trim results) were not started.

Root cause

A torn or unreadable profile config.toml was read through parse_or_warn_default: one process-deduplicated stderr line, then every entry became its default. A stored dashboard or memory-injection opt-out silently turned back on, tracked hosts and the pending upload count vanished, and GitHub review sources registered nothing. A review source with os_keyring access but no keyring service/account was also skipped silently.

Change

  • UserConfig::load is the one strict reader (a missing file is still defaults). The lenient loader, load_strict, parse_or_warn_default and its warn-once set are deleted.
  • tracedecay doctor reports a corrupt profile config, and each unregistered GitHub review source, as an issue naming the file, the error and the repair.
  • Commands that cannot read the config say so and skip the counter flush. Lifecycle passes refuse. An MCP shutdown that cannot save the counter delta records it in its shutdown failures.
  • Review-source classification is split so doctor and registration share one classifier.

Evidence

  • CLI journey (built tracedecay, isolated profile, real profile daemon): host_journeys_suite ... doctor_fails_a_corrupt_profile_config_with_its_repair asserts exit 1 with the literal line Profile config is unusable: config file <path> is corrupt at line 2: TOML parse error at line 2, column 6 ... Fix it, or delete it to regenerate defaults, exit 0 after repair, and exit 1 naming GitHub review source ScriptedAlchemy/keyring-unnamed uses os_keyring access without keyring_service and keyring_account, so it is not registered; .... On master the lenient loader makes doctor exit 0 for the same file.
  • Tests (rebased tree): host_journeys_suite 54, tracedecay-cli bin 356, tracedecay lib doctor|ledger|connection 57, agent-hosts 485, application 483, session-memory 303, configuration 37 (all pass).
  • clippy -D warnings (six touched crates, --all-targets, test features), cargo fmt --all -- --check: clean. Windows cross-check (cargo check --workspace --all-targets --target x86_64-pc-windows-gnu ...): exit 0.

A torn or unreadable profile config.toml was read through
parse_or_warn_default: one process-deduplicated stderr line, then every
entry became its default. A stored dashboard or memory-injection
opt-out silently turned back on, the tracked hosts and pending upload
count vanished, and the GitHub review sources registered nothing.

UserConfig::load is now the one strict reader (a missing file is still
defaults); the lenient loader, load_strict, parse_or_warn_default and
its warn-once set are deleted. `tracedecay doctor` reports a corrupt
profile config, or unusable github_review_sources, as an issue naming
the file, the parse error and its repair. Commands that cannot read
the config say so and skip the counter flush; lifecycle passes refuse;
an MCP shutdown that cannot save the counter delta records it in its
shutdown failures.
@changeset-bot

changeset-bot Bot commented Oct 1, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 77e9760

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@ScriptedAlchemy
ScriptedAlchemy merged commit f2e1bc9 into master Oct 1, 2026
4 of 6 checks passed
@ScriptedAlchemy
ScriptedAlchemy deleted the fleet/audit-leftovers-warn-drop branch October 1, 2026 23:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant