Repository navigation
Sweep spec publish session for unlinked public issues - #654
Merged
Merged
Conversation
After the staged spec and its Tickets are created and linked, re-sweep the publishing session window. Anything in it that is neither the spec nor one of its Tickets is a side-effect leak outside the validated staged path: close it and fail loudly, as the pre-creation sweep does.
…648) The staged-spec Blocked by trailer parsed only its first line, silently dropping a stated ordering edge while every other malformation rejects the staged text. Reject non-blank lines after the trailer's first line. Rename fail_on_side_effects sides to leaks, the term the surrounding comments use.
This was referenced Oct 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #648. Spec-size public Security fixes are now published through a post-linking window sweep, and staged
Blocked by:trailers fail closed.Seams tested: staged-spec text parsing (
parse_staged_spec_proposal,parse_blocked_by); the spec publish window sweep (publish_staged_specagainst fakeghthroughsecure security-fixscenarios); the single-fix staged path as regression.Evidence
staged_spec_rejects_a_trailing_blocked_by_edge_on_its_own_linefails — aBlocked by: 1line followed by a2line parsed with edge[0], silently dropping the stated edge.After: that test passes;
cargo test --bin thirdshiftfixing tests green;cargo test --test security_run92 passed, 0 failed; fullcargo test44 binaries, 1732 passed, 0 failed;cargo clippy --all-targets -- -D warningsandcargo fmt --checkclean.Merge Danger
Door: two-way — reverting the two commits restores the pre-creation-sweep-only behavior; no migration, no stored state.
Blast Radius: security-fix publishing. The post-linking sweep no-ops when the window holds only the staged spec and its Tickets; the trailer strictness only rejects staged text that previously parsed with silently dropped edges.
Unaddressed findings
Standards
tests/fakes/gh.rs(api_add_sub_issueat line 724 vsapi_add_blocked_byat line 758) — skipped by plan decision: the reviewer de-escalated it in the same breath ("kept as-is is defensible (fake handlers favor explicitness), so not flagged further"). No behavior claim, no test attached.src/github.rs(post_by_idat line 218, endpoint+field pair) — skipped: the reviewer judges "the current shape is fine" for a private helper with exactly two callers; it is Stage spec proposal text and validate before creating public issues #647's enabling code, untouched by Sweep spec publish session for unlinked public issues #648.Spec
startedis captured before the session and both sweeps query the sameissues_created_sincewindow (src/security/fixing.rs:72,75,88), so no session leak can appear between the pre-creation and post-linking sweeps; no integration test can trip the post-sweep failure branch through the session interface. Covered instead by theunlinked_issuesunit test (src/security/fixing.rs:441, run:cargo test --bin thirdshift unlinked_issues) and happy-path assertions that the sweep leaves staged issues alone (a_bigger_public_fix_publishes_tickets_and_ends_as_the_spec_runasserts issue Keeping the PR mergeable: merge the Base branch and conflict Repair #8 stays OPEN with no "outside the staged path" in stderr;cargo test --test security_run92 passed).staged_spec_rejects_a_multiline_blocked_by_trailertest — ran as written on pre-fix code and PASSED: its first ticket isBlocked by: 1on a two-ticket spec, i.e. a self-edge, so it passes via the pre-existing self-edge rejection without exercising truncation. Declined as defective proof, citing that run; the underlying truncation finding was accepted and fixed, proven by the correctedstaged_spec_rejects_a_trailing_blocked_by_edge_on_its_own_linetest (failed pre-fix, passes post-fix).The review left no changed file unread.
Built with muse · default model · default effort