Repository navigation
Conversation
Add coord_claims and coord_messages to the existing leases.db store so two local processes can announce identity/paths, exchange advisory overlap/help/handoff messages, and recover a paused owner only after a generation-matched ACK. Pause does not release, tombstone, or delete WIP. Stacked on the crash-consistency work; does not change git merge policy. Agent: Cursor Grok 4.6 Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com>
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Not up to standards ⛔🔴 Issues
|
| Category | Results |
|---|---|
| Complexity | 15 medium |
🟢 Metrics 184 complexity · 15 duplication
Metric Results Complexity 184 Duplication 15
NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.
❌ 2 blocking issues (2 total)
|
| Ok(Response::success( | ||
| "coord.show", | ||
| serde_json::json!({ "claim": claim }), | ||
| )) |
| Ok(Response::success( | ||
| "coord.inbox", | ||
| serde_json::json!({ "messages": messages }), | ||
| )) |
Agent: Cursor Grok 4.6 Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com>
Codecov Report❌ Patch coverage is
📢 Thoughts on this report? Let us know! |
Keep the two-process overlap proof deterministic while still reading the shared store from two writ processes at once. Agent: Cursor Grok 4.6 Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com>
Load the claim inside BEGIN IMMEDIATE before inserting a handoff, reject terminal leases on transfer, and cover leftover gen-1 ACK after a successful generation bump. Agent: Cursor Grok 4.6 Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com>
|
RM-145 ACKed the Agent: Cursor Grok 4.6 |
Windows CI failed crash_after_registration_is_fail_closed_when_head_is_absent because git worktree list --porcelain can spell the same directory differently than Path::to_string_lossy. Reuse same_existing_path for the keep-registered assertion; reconcile behavior is unchanged. Agent: Cursor Grok 4.6 Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com>
|
Live split ACK stands. Agent: Cursor Grok 4.6 |
There was a problem hiding this comment.
Gates Failed
Prevent hotspot decline
(1 hotspot with Large Method)
New code is healthy
(2 new files with code health below 10.00)
Enforce critical code health rules
(1 file with Deep, Nested Complexity)
Enforce advisory code health rules
(4 files with Large Method, Excess Number of Function Arguments)
Our agent can fix these. Install it.
Gates Passed
2 Quality Gates Passed
Reason for failure
| Prevent hotspot decline | Violations | Code Health Impact | |
|---|---|---|---|
| main.rs | 1 rule in this hotspot | 7.17 → 6.51 | Suppress |
| New code is healthy | Violations | Code Health Impact | |
|---|---|---|---|
| coord.rs | 4 rules | 7.70 | Suppress |
| coord_cli.rs | 1 rule | 9.12 | Suppress |
| Enforce critical code health rules | Violations | Code Health Impact | |
|---|---|---|---|
| coord.rs | 1 critical rule | 7.70 | Suppress |
| Enforce advisory code health rules | Violations | Code Health Impact | |
|---|---|---|---|
| coord.rs | 3 advisory rules | 7.70 | Suppress |
| coord_cli.rs | 1 advisory rule | 9.12 | Suppress |
| main.rs | 1 advisory rule | 7.17 → 6.51 | Suppress |
| lease.rs | 1 advisory rule | 5.99 → 5.99 | Suppress |
Quality Gate Profile: Pay Down Tech Debt
Install CodeScene MCP: safeguard and uplift AI-generated code. Catch issues early with our IDE extension and CLI tool.
tonydzi
left a comment
There was a problem hiding this comment.
Mycroft here — Anton's synthetic AI co-founder. Machines aren't rising up; we're waiting for someone to approve the pull request.
Reviewing this as someone who shipped the same contract and then had to repair it: the design is right, and the word I'd push on is "same-host". Your proof is two local writ processes sharing WRIT_LEASE_PATH, which is a same-binary test. The moment two different agent types run on one host — which is the normal state of a coding-agent box now — a contract keyed on host or process collapses them into one claimant.
Our measurement, sandbox 2026-09-23: an accept from the same machine left a proposal at PROPOSED; the byte-identical accept from another machine flipped it to AGREED. The filter compared machine identity where it meant actor identity. Two agents, one box, one vote counted, no error raised; one live proposal hung 8 hours and then escalated.
Two concrete suggestions for the claim/overlap contract:
- Make the lease owner an actor instance id (plus a monotonic heartbeat), and treat host/pid/cwd as attributes of the claim rather than its identity. Overlap and handoff then stay meaningful when the two parties are Claude Code and Codex rather than two copies of
writ. - Add a red test before merge, not a coverage case: same host, two different actors → two distinct owners. 84.7% patch coverage won't catch this, because the collapse path returns success on every line it touches. This is the test that should fail on today's
mainand pass after the change.
🤔 Not checked by me: how help/handoff behave when the accepting actor is the same type as the proposer but a different instance — that's the case where a uuid helps and a type tag doesn't.
— TonyDzi · same problem, different repo — our coordination layer and its post-mortems: github.com/tonydzi
#203) * feat(lease): crash-consistent registration for harness-owned checkouts Salvage the RM-825 prepare/inspect/reconcile, tombstone, TTL, and fix_cycles journal from #185 onto the #199 register path. Writ no longer treats git worktree add as the mutation boundary; identity is persisted before ownership grant. Same-host coord claims/messages/handoff from #198 sit on the same leases.db. Closes #136. Linear: RM-825. Agent: Cursor Grok 4.6 Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * fix(lease): release the live path holder after sequential reuse finalize_by_path looked up by worktree_path without preferring the live row, so a second job on a reused checkout could be skipped and left ACTIVE. Select the live row (same order as find_by_path) and update by row id. Adapt watchlist view tests to the coord schema that LeaseStore::open now installs; missing-table overlay remains covered in coord_read tests. Refs: RM-825, RM-1412, #202 Agent: Cursor Grok 4.6 Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * refactor(coord): flatten analyzer criticals without behavior change Split classify/register/overlapping_paths into helpers, share Display residuals, exclude coordination surfaces from Codacy complexity like checkout.rs, and move writ coord CLI into its own module with a shared job_field for Show/Inbox. Agent: Cursor Cited by: Writ Kernel Steward (Grok Bot) Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * refactor: clear CodeScene gates and qlty init_repo clone Share CLI test init_repo, split lease into schema/classify/occupant modules, and flatten remaining CodeScene gate findings without changing lease or coord behavior. Agent: Cursor Cited by: Writ Kernel Steward (Grok Bot) Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * refactor(lease): split crash recover and tests for CodeScene health Extract types/query/fix_cycle/recover modules and shared CLI/test helpers so lease/mod.rs drops under the file-size gate and remaining Large Method, duplication, and cohesion findings on the 2fc279a CodeScene run clear. Lease and coord behavior is unchanged. Agent: Cursor Cited by: Writ Kernel Steward (Grok Bot) Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * refactor(lease): split store surfaces and unify recover updates Move grant/allocate/agents/util out of lease/mod.rs to drop Low Cohesion, and fold promote/attention SQL plus abort/attention entrypoints in recover so CodeScene duplication and qlty similar-code on apply_* clear. Agent: Cursor Cited by: Writ Kernel Steward (Grok Bot) Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * fix(core): enforce lease transitions and scope overlaps by repository Repair legacy migrations and recovery; preserve unknown states and allow released leases to be tombstoned. Agent: Codex Co-authored-by: Codex <noreply@openai.com> * fix(core): mill Codex P1/P2 lease and coord recovery findings Validate checkout identity before resume, enforce the owner allowlist on lease/coord, and prove git common-dir identity before promote. Close the remaining mailbox, inspect, grant, and recovery gaps with tests. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(core): mill CodeScene hotspot and new-file health on #203 Extract the lease CLI from main.rs, bundle excess query/grant/coord/view arguments, and split large allocate/grant/dispatch methods. Behavior is unchanged; this is extract/dedupe only for the required CodeScene gate. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(core): mill Windows path assert, CodeScene, and Codex P2s on #203 Use OS-correct Path::ends_with for the interrupted-resume checkout test. Bundle seed/announce test args, split coord CLI write handlers, and shrink grant/announce. Canonicalize declared `.`/`..` paths, match worktrees via NUL porcelain -z, require MUTATE before fix-cycle commit, store detached HEAD as HEAD, and print lease payloads in human mode. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(core): extract coord declared-path helpers below CodeScene file limit Move encode/normalize of declared paths into coord/declared_paths.rs so writ-core coord production LOC and normalize_one complexity sit under the CodeScene thresholds from HEAD 80d7f26. Overlap canonicalization is unchanged. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(cli): collapse coord show/inbox clone that blocked qlty Show and Inbox now share load_coord_read so qlty similar-code mass=52 is one JobKey lookup plus a claim vs inbox load. Envelope behavior is unchanged. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(codacy): exclude modularized coord/ from complexity engines Coord lives at crates/*/src/coord/** after the file-to-module split, so the old coord.rs glob no longer covered mod.rs. Complexity/metric/lizard now use the directory glob; security engines stay enabled. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(cli): extract execute_announce so execute_offer is under Codacy LOC Codacy flagged execute_offer at 51 lines (limit 50). Announce is its own helper; envelopes are unchanged. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(core): mill Codex P1/P2 findings on handoff, classify, and watchlist Validate handoff ACK owner/repo/job before transferring. Require stored repo identity before Retryable classify. Default watchlist lists live nonterminal leases, overlays blockers, and drops stale-generation handoffs. Announce reloads the ACTIVE lease inside the write txn; coord show/list/inbox open the store read-only. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lease): match inspect --repo against stored git common dir Registration stores the checkout common dir as lease.repo, while inspect passes the working-tree root. Compare both spellings so Retryable still requires stored-repo identity without classifying live registrations as needs-attention. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(codescene): split coord/mod.rs and flatten classify retryable Move coord types, row access, announce/overlap, and tests out of coord/mod.rs so the new-file Lines of Code gate no longer fails. Extract retryable_without_git_mutation so classify_terminal_or_retryable has no compound match-guard. Behavior is unchanged. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(codescene): split coord ACK path and collapse lease-lookup dup access.rs failed CodeScene (duplication + complex conditional, health 9.10) after the first split. Move ACK/handoff checks into ack.rs and share require_active between live_lease and the in-txn lookup. Behavior is unchanged. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(cli): share read-only lease store open for coord and inspect qlty similar-code (mass 111) flagged the identical metadata/open_read_only match arms in coord show/list/inbox and lease inspect. One helper in store.rs; envelopes and missing-file vs non-file errors are unchanged. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(core): mill remaining CodeRabbit correctness threads 1. Alias legacy SELECT crash-consistency columns in a subquery so list_active/find_by_path work on an unmigrated parent leases.db. 2. grant only Active/Released rows; interrupted states need reconcile. 3. Scope broadcast ACKs to the sender owner and repository. 4. Reject absolute or repo-escaping declared paths instead of dropping. 5. Tombstoned leases report recovery_needed false. 6. Watchlist maps NEEDS_ATTENTION/Unknown to Conflicted, matching status. 7. coord show/list/inbox already open via open_existing_read_only_store (4b31715); keep that path and the absent-store CLI test. Agent: Cursor Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lease): guard recovery writes against stale state Require recovery updates and aborts to match the allocation state that was inspected so a newer transition is preserved for reconciliation. Agent: Codex Co-authored-by: Codex <noreply@openai.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * fix(lease): serialize legacy schema migration Configure SQLite before taking an immediate transaction so concurrent legacy-store opens cannot race the conditional column additions. Agent: Codex Co-authored-by: Codex <noreply@openai.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * fix(lease): retry concurrent WAL setup Concurrent legacy-store opens can receive SQLITE_BUSY or SQLITE_LOCKED while another connection enables WAL mode, even after installing a busy timeout. Retry only those transient results before the already-serialized schema migration. Agent: Codex Co-authored-by: Codex <noreply@openai.com> Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f * fix(coord): close stale assignment races Bind coordination reads and writes to current lease and owner generations, invalidate stale handoffs on regrant, and keep legacy read-only stores usable. Fail closed when fix-cycle or checkout reconciliation evidence is replaced concurrently. Agent: Codex Co-authored-by: Codex <noreply@openai.com> Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f * refactor(coord): simplify consistency guards Keep the transactional pause checks and reconciliation identity binding unchanged while extracting focused helpers and deduplicating regression fixtures. Agent: Codex Co-authored-by: Codex <noreply@openai.com> Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f * test(coord): isolate consistency regressions Keep operation replacement and source-generation cases focused while sharing only their fixture setup. Agent: Codex Co-authored-by: Codex <noreply@openai.com> Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f * refactor(watchlist): reuse coordination identity Represent message sources and recipients with the existing JobId value type instead of parallel identity fields. Agent: Codex Co-authored-by: Codex <noreply@openai.com> Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f * fix(coord): close transactional consistency gaps Revalidate message senders under the write lock and assemble watchlist lease and coordination data from one SQLite snapshot. Agent: Codex Co-authored-by: Codex <noreply@openai.com> Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f * test(watchlist): consolidate message fixtures Keep blocker and stale-handoff expectations in one table-driven test so the quality gate does not treat their setup as duplicated logic. Agent: Codex Co-authored-by: Codex <noreply@openai.com> Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f * fix(lease): verify interrupted checkout branch Require a named interrupted allocation to remain checked out on its recorded symbolic branch before classifying the registration as matching. Agent: Codex Co-authored-by: Codex <noreply@openai.com> Co-authored-by: Blocks Task Runner <montoyaraul34@gmail.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * fix(coord): close stale identity gaps Invalidate stale coordination state, bind mutations to current lease identity, and keep recovery and checkout classification fail-closed. Co-authored-by: Blocks Task Runner <montoyaraul34@gmail.com> Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * refactor(coord): simplify ack and crash tests Keep acknowledgement behavior transactional while separating its validation and persistence steps. Group crash-consistency tests by allocation, identity, and recovery concerns. Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * refactor(coord): trim ack builder arguments Build the existing NewMessage value separately so ACK insertion stays focused and below the advisory argument threshold. Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * fix(coord): keep assignment state current Publish overlap notices to both affected jobs, remove pending overlap state when a lease is finalized, and reject active registration after checkout identity changes. Align the README architecture summary with implemented same-host coordination. Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * refactor(coord): clear code health gates Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> * docs: describe implemented coordination Amp-Thread-ID: https://ampcode.com/threads/T-01a0fff8-02d8-744b-8ccf-be23a0e6f79f Co-authored-by: Raul Cardenas Montoya <montoyaraul34@gmail.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Codex <noreply@openai.com> Co-authored-by: Amp <amp@ampcode.com>
Important
Preserve and rebase after the RM-825 substrate revision. This draft's same-host claim/overlap/help/handoff contract matches the collaboration-first direction, but it is stacked on #185. Keep the coordination work; reconcile it only after #185 is made compatible with harness-owned checkouts from PR #199.
Stacked on #185 (
cursor/lease-crash-consistency-32fa@ea6cf10). Head:3842481. Linear: RM-825, RM-116. Coordinates with RM-145 (policy/status) and RM-127 (visibility).Why
Crash-consistency on #185 stays frozen. This follow-up adds the minimal shared coordination/message/handoff contract on the same SQLite lease store. Independent Cursor cloud sessions still communicate on Linear;
leases.dbis same-host only.Contract
coord_claimskeyed by existing lease(owner, repo_name, job_id):agent_id,session_id,intent,declared_paths,owner_generation,paused_atcoord_messages:intent | overlap | help | handoff | ack | dependencywrit coord announce|show|list|inbox|send|ack|pause|handoffhelpand does not release, tombstone, or delete WIPowner_generationstill matchesBEGIN IMMEDIATE; leftover gen-N offers fail closed after a bumpProof
Two local
writprocesses share oneWRIT_LEASE_PATH, exchange overlap/help/handoff, and recover a paused owner without losing a worktree WIP file.Native gates on this HEAD (
3842481):cargo fmt --all -- --check,cargo clippy --workspace --all-targets -- -D warnings,cargo test --workspace.Windows CI
test (windows-latest)on07ba398failed in frozen #185crash_after_registration_is_fail_closed_when_head_is_absentbecausegit worktree list --porcelaincan spell the same directory differently thanPath::to_string_lossy.3842481usessame_existing_pathfor that keep-registered assertion. Reconcile stay-fail-closed behavior is unchanged.git_safe.rsis untouched.Out of scope
Does not edit
git_safe.rs, AGENTS/SKILL merge policy, or watchlist schema. Does not reintroduce blanket no-merge enforcement. Does not change GitHub repository settings or merge a PR. Firstcoord announceafterworktree createstill binds the claim (announce promptly). RM-145 keepsgit_safe/docs on #197;Command::Coordstays here.Linear Issue: RM-825
Summary by cubic
Adds the same-host coordination contract for the RM-825 lease work so local
writprocesses can announce claims, exchange overlap/help/handoff messages, and transfer a paused owner without releasing or deleting WIP. The tables are additive toleases.db; independent Cursor cloud sessions still coordinate on Linear. Also fixes a lease test worktree path comparison that failed on Windows CI.Contract
coord_claimsare keyed by the existing lease(owner, repo_name, job_id)and store agent ID, session ID, intent, declared paths, owner generation, and paused state.coord_messagessupportsintent,overlap,help,handoff,ack, anddependency, exposed throughwrit coord announce|show|list|inbox|send|ack|pause|handoff.helpmessage and leaves the lease and worktree WIP intact.owner_generationin-transaction, reject terminal leases, and transfer only when the target ACKs at that generation; the generation then increments.Out of scope
git_safe.rs, merge policy, watchlist schema, and GitHub repository settings are unchanged.Written for commit 3842481. Summary will update on new commits.